[crypto] Visual demonstration of why two-time pads are bad
http://ift.tt/2gldi8i
Submitted August 31, 2017 at 03:26PM by k3170makan
via reddit http://ift.tt/2x8BTr1
http://ift.tt/2gldi8i
Submitted August 31, 2017 at 03:26PM by k3170makan
via reddit http://ift.tt/2x8BTr1
Gist
Simple visual demonstration of the affect of key entropy and key re-use on a simple one time bad
Reverse Engineering the OBi200 Google Voice Appliance: Part 1
http://ift.tt/2eHjnfi
Submitted August 31, 2017 at 06:35PM by rwestergren
via reddit http://ift.tt/2gskzHi
http://ift.tt/2eHjnfi
Submitted August 31, 2017 at 06:35PM by rwestergren
via reddit http://ift.tt/2gskzHi
Randy Westergren
Reverse Engineering the OBi200 Google Voice Appliance: Part 1 - Randy Westergren
The OBi200 by Obihai is a VoIP gateway for home/SOHO that integrates with Google Voice. It supports most standard VoIP features out of the box and can integrate with virtually any “bring your own device” SIP service. I purchased one earlier this year to act…
CertReq Exfiltration – Getting Data via Native Tools & CSRs!
http://ift.tt/2eseb27
Submitted August 31, 2017 at 07:04PM by doylersec
via reddit http://ift.tt/2vMoikY
http://ift.tt/2eseb27
Submitted August 31, 2017 at 07:04PM by doylersec
via reddit http://ift.tt/2vMoikY
doyler.net
CertReq Exfiltration - Getting Data via Native Tools & CSRs! | doyler.net
Now, finally sharing something new again, I present CertReq exfiltration! The Spark It all started one Thursday that I was on the bench with an innocuous looking tweet from subTee. He mentioned that it seemed like certreq.exe could arbitrarily POST … Continue…
A look at the shortfalls of SIEM and how EDR can pick up the slack.
http://ift.tt/2vLXz81
Submitted August 31, 2017 at 06:49PM by Leeor18
via reddit http://ift.tt/2x9gDSd
http://ift.tt/2vLXz81
Submitted August 31, 2017 at 06:49PM by Leeor18
via reddit http://ift.tt/2x9gDSd
Secdo
Is EDR picking up SIEM’s slack?
As headlines about breaches increase, it becomes clear that the current IR capabilities of SIEM providers are not meeting the needs of today’s security teams
WINspect - Powershell-based Windows Security Auditing Toolbox
http://ift.tt/2vIuzPf
Submitted August 31, 2017 at 07:59PM by hack4net
via reddit http://ift.tt/2glt4jU
http://ift.tt/2vIuzPf
Submitted August 31, 2017 at 07:59PM by hack4net
via reddit http://ift.tt/2glt4jU
Hack4Net ☠
WINspect - Powershell-based Windows Security Auditing Toolbox
WINspect is part of a larger project for auditing different areas of Windows environments. It focuses on enumerating different parts of a...
Anyone was able to host arbitrary files to the FCC.gov domain
http://ift.tt/2gliLfz
Submitted August 31, 2017 at 07:39PM by xorflame
via reddit http://ift.tt/2vuyrro
http://ift.tt/2gliLfz
Submitted August 31, 2017 at 07:39PM by xorflame
via reddit http://ift.tt/2vuyrro
Hacker Noon
The FCC.gov Website Lets You Upload Malware Using Its Own Public API Key
Somewhat incredibly I am the first tech writer on the planet to break this story, but even more incredibly the FCC lets you upload any file…
Analysis of a recent Poison Ivy sample
http://ift.tt/2vHORsj
Submitted August 31, 2017 at 09:01PM by rexrage
via reddit http://ift.tt/2glv23s
http://ift.tt/2vHORsj
Submitted August 31, 2017 at 09:01PM by rexrage
via reddit http://ift.tt/2glv23s
Writeup of RHME3 exploitation challenge (use-after-free vulnerability)
http://ift.tt/2wkV5Be
Submitted August 31, 2017 at 08:13PM by _gipi_
via reddit http://ift.tt/2xB7WxU
http://ift.tt/2wkV5Be
Submitted August 31, 2017 at 08:13PM by _gipi_
via reddit http://ift.tt/2xB7WxU
AngelFire - CIA Implant For Windows Machines
http://ift.tt/2elV0U1
Submitted August 31, 2017 at 10:04PM by greenterminal
via reddit http://ift.tt/2wldxtu
http://ift.tt/2elV0U1
Submitted August 31, 2017 at 10:04PM by greenterminal
via reddit http://ift.tt/2wldxtu
Hackers Grid
AngelFire – CIA Implant For Windows Machines
Vault 7 is a series of documents and tools released by WikiLeaks, that gives information about detailed activities and capabilities of the US CIA to perform spying and cyber warfare. Today, 31 August 2017, Wikileaks
ROPEMAKER: Stop Trying to Make it Happen; ROPEMAKER is Not Going to Happen
http://ift.tt/2wVKRZC
Submitted September 01, 2017 at 03:06AM by xor_al_al
via reddit http://ift.tt/2vNfoDU
http://ift.tt/2wVKRZC
Submitted September 01, 2017 at 03:06AM by xor_al_al
via reddit http://ift.tt/2vNfoDU
Fuzzing x86 instruction set
https://youtu.be/KrksBdWcZgQ
Submitted September 01, 2017 at 07:22AM by fproulx
via reddit http://ift.tt/2wmM36B
https://youtu.be/KrksBdWcZgQ
Submitted September 01, 2017 at 07:22AM by fproulx
via reddit http://ift.tt/2wmM36B
YouTube
Breaking the x86 Instruction Set
A processor is not a trusted black box for running code; on the contrary, modern x86 chips are packed full of secret instructions and hardware bugs. In this talk, we'll demonstrate how page fault analysis and some creative processor fuzzing can be used to…
Detecting debuggers by abusing a bad assumption within Windows
http://ift.tt/2wn8Uza
Submitted September 01, 2017 at 09:49AM by 0xNemi
via reddit http://ift.tt/2vOo7pn
http://ift.tt/2wn8Uza
Submitted September 01, 2017 at 09:49AM by 0xNemi
via reddit http://ift.tt/2vOo7pn
www.triplefault.io
Detecting debuggers by abusing a bad assumption within Windows
A blog about general reverse engineering, security research, poking around Windows internals, and messing with the Intel x86/AMD64 architecture.
Stealing contact form data on www.hackerone.com using Marketo Forms XSS with postMessage frame-jumping and jQuery-JSONP
http://ift.tt/2wWV08j
Submitted September 01, 2017 at 03:46PM by albinowax
via reddit http://ift.tt/2ep3sSh
http://ift.tt/2wWV08j
Submitted September 01, 2017 at 03:46PM by albinowax
via reddit http://ift.tt/2ep3sSh
HackerOne
HackerOne disclosed on HackerOne: Stealing contact form data on...
Hi,
I just discovered that there's a scenario where the Marketo Forms solution being used on www.hackerone.com can actually be abused, using a few fun techniques, to trigger an XSS in the...
I just discovered that there's a scenario where the Marketo Forms solution being used on www.hackerone.com can actually be abused, using a few fun techniques, to trigger an XSS in the...
Mining Adminers - Hackers Scan the Internet For DB Scripts
http://ift.tt/2vsrvLo
Submitted September 01, 2017 at 09:25PM by majorllama
via reddit http://ift.tt/2wpLZTJ
http://ift.tt/2vsrvLo
Submitted September 01, 2017 at 09:25PM by majorllama
via reddit http://ift.tt/2wpLZTJ
Sucuri Blog
Mining Adminers - Hackers Scan the Internet For DB Scripts
Hackers are scanning the Internet for sites using Adminers. If your site uses temporary maintenance or admin noscripts, learn how you can minimize the risks.
Why BlackBerry's security sucks
http://ift.tt/2iPnuKL
Submitted September 02, 2017 at 01:09AM by pacific_research
via reddit http://ift.tt/2wqwBX9
http://ift.tt/2iPnuKL
Submitted September 02, 2017 at 01:09AM by pacific_research
via reddit http://ift.tt/2wqwBX9
reddit
Why BlackBerry's security sucks • r/netsec
0 points and 0 comments so far on reddit
6 Million Account For Sale On DoxaGram
http://ift.tt/2wqmPEx
Submitted September 02, 2017 at 02:22AM by abhihpes
via reddit http://ift.tt/2wYSCh9
http://ift.tt/2wqmPEx
Submitted September 02, 2017 at 02:22AM by abhihpes
via reddit http://ift.tt/2wYSCh9
www.techposts.net
6 Million Celebrities Instagram High-Profiles Data Up For Sale On DoxaGram |
An unknown hacker has stolen personal details of 6 million "High-Profile" Instagram account and made it available for sale on a website, called Doxagram
0patching the RSRC Arbitrary NULL Write Vulnerability in LABView (CVE-2017-2779)
http://ift.tt/2ewmmuc
Submitted September 01, 2017 at 10:48PM by dielel
via reddit http://ift.tt/2gqE7bc
http://ift.tt/2ewmmuc
Submitted September 01, 2017 at 10:48PM by dielel
via reddit http://ift.tt/2gqE7bc
0patch.blogspot.co.uk
0patching the RSRC Arbitrary NULL Write Vulnerability in LabVIEW (CVE-2017-2779)
Whether Vendors Patch Their Products or Not, We Have Your Back by Mitja Kolsek, the 0patch Team Three days ago, Cisco Talos published a...
Safari Accidentally Treating ';' as an Assignment Operator
http://ift.tt/2epSNqP
Submitted September 02, 2017 at 05:40AM by fagnerbrack
via reddit http://ift.tt/2ewnWfQ
http://ift.tt/2epSNqP
Submitted September 02, 2017 at 05:40AM by fagnerbrack
via reddit http://ift.tt/2ewnWfQ
reddit
Safari Accidentally Treating ';' as an Assignment Operator • r/netsec
6 points and 1 comments so far on reddit
PowerPoint Presentations Exploiting CVE-2017-0199 found
http://ift.tt/2wrDMP6
Submitted September 02, 2017 at 08:02AM by greenterminal
via reddit http://ift.tt/2wv8xAQ
http://ift.tt/2wrDMP6
Submitted September 02, 2017 at 08:02AM by greenterminal
via reddit http://ift.tt/2wv8xAQ
Hackers Grid
PowerPoint Presentation Exploiting CVE-2017-0199
Researchers at FortiGaurd had discrovered a new Power Point Presentation File named "ADVANCED DIPLOMATIC PROTOCOL AND ETIQUETTE SUMMIT.ppsx" spreading via E Mail targeting UN agencies, Foreign Ministries, International Organizations, and those who interact…
Android tap-jacking can be turned into ransomware
https://youtu.be/FRpcGwCedZ0
Submitted September 02, 2017 at 11:45PM by fproulx
via reddit http://ift.tt/2etlFOC
https://youtu.be/FRpcGwCedZ0
Submitted September 02, 2017 at 11:45PM by fproulx
via reddit http://ift.tt/2etlFOC
YouTube
Cloak & Dagger: From Two Permissions to Complete Control of the UI Feedback Loop
While both the SYSTEM_ALERT_WINDOW and the BIND_ACCESSIBILITY_SERVICE Android permissions have been abused individually (e.g., in UI redressing attacks, accessibility attacks), previous attacks based on these permissions failed to completely control the UI…
This Week in Security News -
http://ift.tt/2wXBUPA
Submitted September 03, 2017 at 04:47AM by del_hack
via reddit http://ift.tt/2eQubrQ
http://ift.tt/2wXBUPA
Submitted September 03, 2017 at 04:47AM by del_hack
via reddit http://ift.tt/2eQubrQ
Trendmicro
This Week in Security News -
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. Below you’ll find a quick recap of topics followed by links to news articles and/or our blog posts providing…