Homographs, Attack!
http://ift.tt/2HkwEaF
Submitted February 21, 2018 at 08:51PM by speckz
via reddit http://ift.tt/2EWkW7q
http://ift.tt/2HkwEaF
Submitted February 21, 2018 at 08:51PM by speckz
via reddit http://ift.tt/2EWkW7q
The Practical Dev
Homographs, Attack!
Background on a decades-old hack that just keeps coming back.
Cisco Elastic Services Controller Service Portal Auth Bypass Vuln
http://ift.tt/2or51nJ
Submitted February 21, 2018 at 10:35PM by ghost-train
via reddit http://ift.tt/2FjfABd
http://ift.tt/2or51nJ
Submitted February 21, 2018 at 10:35PM by ghost-train
via reddit http://ift.tt/2FjfABd
Cisco
Cisco Security Threat and Vulnerability Intelligence
The Cisco Security portal provides actionable intelligence for security threats and vulnerabilities in Cisco products and services and third-party products.
Code Exection in IDA via Strings
http://ift.tt/2FhIjWU
Submitted February 21, 2018 at 10:11PM by MalwareSeattle
via reddit http://ift.tt/2FnGyaZ
http://ift.tt/2FhIjWU
Submitted February 21, 2018 at 10:11PM by MalwareSeattle
via reddit http://ift.tt/2FnGyaZ
reddit
Code Exection in IDA via Strings • r/netsec
2 points and 0 comments so far on reddit
Trend Micro Email Encryption Gateway Multiple Vulnerabilities
http://ift.tt/2CAKUYU
Submitted February 21, 2018 at 11:18PM by pepit0r
via reddit http://ift.tt/2sL686P
http://ift.tt/2CAKUYU
Submitted February 21, 2018 at 11:18PM by pepit0r
via reddit http://ift.tt/2sL686P
Core Security
Trend Micro Email Encryption Gateway Multiple Vulnerabilities
1. Advisory InformationTitle: Trend Micro Email Encryption Gateway Multiple VulnerabilitiesAdvisory ID: CORE-2017-0006Advisory URL: http://www.coresecurity.com/advisories/trend-micro-email-encryption-gateway-multiple-vulnerabilitiesDate published: 2018-02…
Need help to solve the problew with record in the sudoers file Linux
Hi folks! Can someone pls help me with this record in the /etc/sudoers file:
Submitted February 21, 2018 at 10:44PM by Brain2life
via reddit http://ift.tt/2GAnpSt
Hi folks! Can someone pls help me with this record in the /etc/sudoers file:
non_root_user ALL=(ALL) NOPASSWD: /usr/sbin/lessDoes it safe to write like this?I think that this record will allow non root users launch less text editor and view documents that they are not authorized to do so.What do you think? Do I need to erase this record or rewrite it in a more safe way?
Submitted February 21, 2018 at 10:44PM by Brain2life
via reddit http://ift.tt/2GAnpSt
reddit
Need help to solve the problew with record in the... • r/security
Hi folks! Can someone pls help me with this record in the /etc/sudoers file: non_root_user ALL=(ALL) NOPASSWD: /usr/sbin/less Does it...
IBM X-Force IRIS Uncovers Active Business Email Compromise Campaign Targeting Fortune 500 Companies
http://ift.tt/2EY2ueG
Submitted February 21, 2018 at 10:16PM by cloudster314
via reddit http://ift.tt/2sJrb9P
http://ift.tt/2EY2ueG
Submitted February 21, 2018 at 10:16PM by cloudster314
via reddit http://ift.tt/2sJrb9P
Security Intelligence
IBM X-Force IRIS Uncovers Active Business Email Compromise Campaign Targeting Fortune 500 Companies
IBM X-Force IRIS observed a widespread business email compromise (BEC) campaign targeting many Fortune 500 companies that exploits flaws in common accounts payable processes.
Validating Leaked Passwords with k-Anonymity
http://ift.tt/2ogpOLf
Submitted February 22, 2018 at 12:38AM by civicode
via reddit http://ift.tt/2ELED2D
http://ift.tt/2ogpOLf
Submitted February 22, 2018 at 12:38AM by civicode
via reddit http://ift.tt/2ELED2D
The Cloudflare Blog
Validating Leaked Passwords with k-Anonymity
Today, v2 of Pwned Passwords was released as part of the Have I Been Pwned service offered by Troy Hunt. Containing over half a billion real world leaked passwords, this database provides a vital tool for correcting the course of how the industry combats…
How Developers got Password Security so Wrong
http://ift.tt/2CdawQ3
Submitted February 22, 2018 at 12:38AM by civicode
via reddit http://ift.tt/2CzjTW1
http://ift.tt/2CdawQ3
Submitted February 22, 2018 at 12:38AM by civicode
via reddit http://ift.tt/2CzjTW1
Cloudflare Blog
How Developers got Password Security so Wrong
Both in our real lives, and online, there are times where we need to authenticate ourselves - where we need to confirm we are who we say we are. This can be done using three things: Something you know Something you have Something you are Passwords are an…
FOSS slides for explaining Meltdown and Spectre
http://ift.tt/2Fofqsp
Submitted February 22, 2018 at 02:16AM by xux-xux
via reddit http://ift.tt/2GxEnRi
http://ift.tt/2Fofqsp
Submitted February 22, 2018 at 02:16AM by xux-xux
via reddit http://ift.tt/2GxEnRi
GitHub
neuhalje/presentation_meltdown_spectre
presentation_meltdown_spectre - Meltdown and spectre explained -- for normal people
Cybersecurity professionals in the San Francisco Bay area needed for a Paid Research Study - $250 for a 45 min. phone/web interview
We are a company that locates people for various market research studies nationwide. Our current study is happening this week and next and we are short a half dozen security analysts. If interested please fill out the survey located here: https://survey.zohopublic.com/zs/nCCuSYMore information can be found on our website blog here: http://www.focusinsite.com/250-45-minutes-cybersecurity-professionals-needed-san-francisco-bay-area/Not in the S.F. area, but want to be notified of upcoming studies? Please fill in this survey with your best contact information: http://www.focusinsite.com/survey
Submitted February 22, 2018 at 01:58AM by FocusInsite
via reddit http://ift.tt/2HCWdE0
We are a company that locates people for various market research studies nationwide. Our current study is happening this week and next and we are short a half dozen security analysts. If interested please fill out the survey located here: https://survey.zohopublic.com/zs/nCCuSYMore information can be found on our website blog here: http://www.focusinsite.com/250-45-minutes-cybersecurity-professionals-needed-san-francisco-bay-area/Not in the S.F. area, but want to be notified of upcoming studies? Please fill in this survey with your best contact information: http://www.focusinsite.com/survey
Submitted February 22, 2018 at 01:58AM by FocusInsite
via reddit http://ift.tt/2HCWdE0
Zohopublic
18-119 Cybersecurity
Please take this survey. Your response is important!
Hacking Tinder Accounts using Facebook Accountkit
http://ift.tt/2odMax4
Submitted February 20, 2018 at 09:53PM by bugbountydude
via reddit http://ift.tt/2ogAd9J
http://ift.tt/2odMax4
Submitted February 20, 2018 at 09:53PM by bugbountydude
via reddit http://ift.tt/2ogAd9J
Medium
Hacking Tinder Accounts using Facebook Accountkit
Note: This is being published with the permission of Facebook under the responsible disclosure policy.
Phishing on Twitter Automatically
http://ift.tt/2BHoSao
Submitted February 22, 2018 at 01:49AM by gunmr
via reddit http://ift.tt/2CdhuEH
http://ift.tt/2BHoSao
Submitted February 22, 2018 at 01:49AM by gunmr
via reddit http://ift.tt/2CdhuEH
GitHub
omergunal/PoT
PoT - Phishing on Twitter
The Many Hats Club: An InfoSec Group For All Skill Levels
http://ift.tt/2BK726K
Submitted February 22, 2018 at 02:48AM by DJRWolf
via reddit http://ift.tt/2HAsrPX
http://ift.tt/2BK726K
Submitted February 22, 2018 at 02:48AM by DJRWolf
via reddit http://ift.tt/2HAsrPX
BleepingComputer
The Many Hats Club: An InfoSec Group For All Skill Levels
The Many Hats Club is a group where members of the InfoSec community can share information, build connections, and get to know each other. This group caters to all experience levels and if you are interested in getting into InfoSec or want to have discussions…
[SAD] Garmin is still not using 2FA for their cloud based Garmin Connect service.
It's 2018 and Garmin has no option to enable 2FA for their Garmin Connect service. If you are not familiar with the Garmin Connect service, it's a service where all the Garmin fitness tracker upload all the data. The data is highly sensitive, which includes GPS tracks, steps, heart ratio, sleep time and so on. I've asked Garmin if they could provide the service with 2FA but without any response until today.
Submitted February 22, 2018 at 02:43AM by Radi1229
via reddit http://ift.tt/2GxN5Ps
It's 2018 and Garmin has no option to enable 2FA for their Garmin Connect service. If you are not familiar with the Garmin Connect service, it's a service where all the Garmin fitness tracker upload all the data. The data is highly sensitive, which includes GPS tracks, steps, heart ratio, sleep time and so on. I've asked Garmin if they could provide the service with 2FA but without any response until today.
Submitted February 22, 2018 at 02:43AM by Radi1229
via reddit http://ift.tt/2GxN5Ps
reddit
[SAD] Garmin is still not using 2FA for their cloud... • r/security
It's 2018 and Garmin has no option to enable 2FA for their Garmin Connect service. If you are not familiar with the Garmin Connect service, it's a...
I've Just Launched "Pwned Passwords" V2 With Half a Billion Passwords for Download
http://ift.tt/2Cedgwo
Submitted February 22, 2018 at 04:22AM by rmddos
via reddit http://ift.tt/2EEv9Cb
http://ift.tt/2Cedgwo
Submitted February 22, 2018 at 04:22AM by rmddos
via reddit http://ift.tt/2EEv9Cb
Troy Hunt
I've Just Launched "Pwned Passwords" V2 With Half a Billion Passwords for Download
Last August, I launched a little feature within Have I Been Pwned (HIBP) I called Pwned Passwords. This was a list of 320 million passwords from a range of different data breaches which organisations could use to better protect their own systems. How? NIST…
Google's Project Zero reveals elevation of privilege bug in Windows
http://ift.tt/2EHeWQO
Submitted February 22, 2018 at 04:04AM by raincan
via reddit http://ift.tt/2Fkrw5G
http://ift.tt/2EHeWQO
Submitted February 22, 2018 at 04:04AM by raincan
via reddit http://ift.tt/2Fkrw5G
reddit
Google's Project Zero reveals elevation of privilege... • r/netsec
3 points and 0 comments so far on reddit
Hiding in plain sight: XXE Zeroday In HP Project and Portfolio Management Center Application
http://ift.tt/2onNYCY
Submitted February 22, 2018 at 05:11AM by hackers_and_builders
via reddit http://ift.tt/2EXhZDC
http://ift.tt/2onNYCY
Submitted February 22, 2018 at 05:11AM by hackers_and_builders
via reddit http://ift.tt/2EXhZDC
Rhino Security Labs
Hiding in Plain Sight: XXE Vulnerability in HP Project & Portfolio Mgmt Center - Rhino Security Labs
Rhino Security Labs explores an XXE vulnerability. This flaw can lead to confidential data disclosure, DoS attacks, server-side request forgery, and more.
FinSpy VM Unpacking Tutorial Part 3: Devirtualization
http://ift.tt/2HBN6TY
Submitted February 22, 2018 at 07:36AM by TechLord2
via reddit http://ift.tt/2EJsSps
http://ift.tt/2HBN6TY
Submitted February 22, 2018 at 07:36AM by TechLord2
via reddit http://ift.tt/2EJsSps
Möbius Strip Reverse Engineering
FinSpy VM Unpacking Tutorial Part 3: Devirtualization
1. Overview This is the third and final part in my series on statically unpacking the FinSpy VM. After having deobfuscated the x86 implementation of FinSpy in part one and after having analyzed the VM and written a disassembler for the bytecode format for…
wotmate: a GnuPG keyring paths grapher
http://ift.tt/2HAHTvD
Submitted February 22, 2018 at 07:24AM by mricon
via reddit http://ift.tt/2sGOYHK
http://ift.tt/2HAHTvD
Submitted February 22, 2018 at 07:24AM by mricon
via reddit http://ift.tt/2sGOYHK
GitHub
mricon/wotmate
wotmate - Web of trust grapher
Finding a mentor
How and where do I find one? What are some learning resources that I can use to actually do instead of read only? I've been doing picoctf and am learning a lot, but want to know and learn more " real life" every day skills. Can soneone help?
Submitted February 22, 2018 at 08:10AM by TSTEAD
via reddit http://ift.tt/2FjRUfU
How and where do I find one? What are some learning resources that I can use to actually do instead of read only? I've been doing picoctf and am learning a lot, but want to know and learn more " real life" every day skills. Can soneone help?
Submitted February 22, 2018 at 08:10AM by TSTEAD
via reddit http://ift.tt/2FjRUfU
reddit
Finding a mentor • r/security
How and where do I find one? What are some learning resources that I can use to actually do instead of read only? I've been doing picoctf and am...
Devirtualizing FinSpy, Phases #1-4 : Deobfuscating FinSpy VM Bytecode Programs
http://ift.tt/2Fl4hIJ
Submitted February 22, 2018 at 10:05AM by TechLord2
via reddit http://ift.tt/2osntfJ
http://ift.tt/2Fl4hIJ
Submitted February 22, 2018 at 10:05AM by TechLord2
via reddit http://ift.tt/2osntfJ
Möbius Strip Reverse Engineering
Devirtualizing FinSpy, Phase #1: Deobfuscating FinSpy VM Bytecode Programs
1. Introduction In part one of this series, we analyzed the obfuscation on the x86 implementation of the FinSpy VM, and wrote a tool to deobfuscate it to allow easier analysis. In the second part of this series, we analyzed the VM instruction set, wrote a…