Netsec – Telegram
Netsec
7.41K subscribers
22.4K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
Boost.Beast security assessment technical report
http://ift.tt/2Bsf9Rg

Submitted January 25, 2018 at 07:25AM by ryanaraine
via reddit http://ift.tt/2n8PysC
Quora and you
Do you have a Quora (quora.com) account? Quora has acknowledged and claimed as a feature a very serious authentication(-less?) issue. You may have noticed that when you receive an email digest (possibly others), you appear to auto-login to the site. This might not seem unusual, although still questionable, and it has been brought up before. It logs you into a new session.What you may not realize is that if you forward those emails to someone, say you wanted to share an interesting article, the recipient of your forwarded email WILL be able to login as YOU. Quora says the auto-login link ability expires at some point, but the countdown only begins after the link is clicked initially. As for how long this countdown is, I can't say, but the deeper issue is that every account that I can tell is vulnerable, since an auto-login feature comes with all those emails. Initially I thought that it required a google account connected and it may, but now I am not sure. I alerted Quora who acknowledged the risk of forwarded email recipients being able to login as the original recipient and concluded it was an acceptable risk. I would not have typed this up without the bug report having been marked closed by quora.Full access to the users quora account is given, which means you can unlink trusted accounts and link your own twitter, facebook, google or linkedin, effectively hi-jacking the account completely. You can impersonate, edit and modify comments and articles, or just delete the account altogether. So next time you want to forward an article to a friend, or receive a forward, keep that in mind.

Submitted January 25, 2018 at 08:06AM by sman2428
via reddit http://ift.tt/2n9P45v
What is a good security system to hide in my bedroom where I can track movement and record what someone is doing for a brief moment in time?
My step dad has been stealing money from me, and I know this for a fact but he doesnt know that I know. I have set up traps in my room and then the traps go off and he is the only one home. I need to get 100% concrete proof of it even though im 100% positive, I need it on video. I have been looking to get a pretty small camera of some sort that will record my room when I am gone and my mom is not home which is rare, but if it does happens we are only gone at an hour at a time, and that is when he does it. I need something that will ping my phone when movement occurs and maybe takes pictures or records it. Since he has taken several hundred from me, id prefer a recording device that isnt super expensive. Do you guys have any ideas? Thanks much!

Submitted January 25, 2018 at 09:23AM by ElvisDimera
via reddit http://ift.tt/2FcUiUw
Commercial Security Services at Tate Security Technology Ltd in UK
http://ift.tt/2Eb9sKR

Submitted January 25, 2018 at 03:46PM by TateSecurity
via reddit http://ift.tt/2DxIxHY
Exploit Mitigation Techniques - Stack Canaries - Exploit Development
http://ift.tt/2rF6ueH

Submitted January 25, 2018 at 04:09PM by Jen0vah
via reddit http://ift.tt/2n6pC0I
ASUS routers LAN-side unauthenticated remote code execution
http://ift.tt/2BsEyKX

Submitted January 25, 2018 at 05:13PM by jose_boneh
via reddit http://ift.tt/2Fce4iR
Reddit now offers two-factor authentication to all !
http://ift.tt/2Bs9HxQ

Submitted January 25, 2018 at 04:54PM by time-pass
via reddit http://ift.tt/2DMDy9L
Students asking basic pointers for a hackathon (beginner level)
Hello,My school had an open invitation to attend a hackathon. I registered and was put into a group. There are several groups of students from my school participating in the same hackathon. There are 4 of us in this group. Apart from me and one other, we have some decent knowledge of linux, and use of the software. The other two students didn't really understand what and how KALI even was.Assuming you participate, and even if you don't find any vulnerabilities, we get credits for being apart of it.That said, we would like to at least have a fighting chance. We have been given some basic instructions. I'm not sure where to start once we are connected to the network and have scanned it.Note, I have set up my Kali linux. It's dist-upgraded and ready to go.These are my basic assumptions. Scan network with nmap, to find all available devices. We have been told they are 'hidden' somehow. I think this means scan the network with nmap at like T4? But what are the best options that I should be looking at?Once we find all the devices. Nmap should help with OS detection etc. As well as open ports and versions.This is where I get confused. They told us that the computers are like Windows 7 and full of holes.How do I know what program/port to use so that I can apply metasploit exploits to it?Clearly from reading this you can probably see my gaps in knowledge.If you would kindly point out some tips and tricks, we would appreciate having a fighting chance. :)

Submitted January 25, 2018 at 08:44PM by beangay
via reddit http://ift.tt/2naWs0u
Why more sites don't use PGP/GPG for 2FA?
Reddit just enabled 2FA for all accounts using Google Authenticator. Many sites are using this method or text messaging. What if I don't want to use my phone or don't have it. If I forget my phone and head out for the day, I'm stuck.This made me curious about another form of 2FA which is not used all that often: PGP (or GPG). Given the nature of Reddit, I would think there would be a good number of us who would use it if it was offered.I assume it is because the number of people using PGP is relatively small when you consider the entire population of internet users. Other than that, is there another reason why more sites don't offer PGP as an option for 2FA?

Submitted January 25, 2018 at 09:15PM by flipjargendy
via reddit http://ift.tt/2E7pN2P
Developers + GDPR/PCI question
Does anyone know if PCI or GDPR policy restrict the app developers having access to customers data? (e.g. some basic, some sensitive such as last 4 digits of card number).Ive been told yes but I don't believe thats reasonable. Fixing certain bugs seems impossible without setting the state of the data.

Submitted January 25, 2018 at 10:27PM by craigtaub
via reddit http://ift.tt/2naAY2F
High Risk Vulnerabilities within the DoD from Coldfusion, Dotnet Nuke, Oracle, and more
http://ift.tt/2DD4VUi

Submitted January 26, 2018 at 12:18AM by alyssathegryphon
via reddit http://ift.tt/2Gh43m0
Microsoft releases updated VS compiler for Spectre V2. Let the builds begin. GCC backports to v7
http://ift.tt/2DKCVNU

Submitted January 26, 2018 at 02:02AM by kn1ght
via reddit http://ift.tt/2FdFjcX