Fuzzing x86 instruction set
https://youtu.be/KrksBdWcZgQ
Submitted September 01, 2017 at 07:22AM by fproulx
via reddit http://ift.tt/2wmM36B
https://youtu.be/KrksBdWcZgQ
Submitted September 01, 2017 at 07:22AM by fproulx
via reddit http://ift.tt/2wmM36B
YouTube
Breaking the x86 Instruction Set
A processor is not a trusted black box for running code; on the contrary, modern x86 chips are packed full of secret instructions and hardware bugs. In this talk, we'll demonstrate how page fault analysis and some creative processor fuzzing can be used to…
Detecting debuggers by abusing a bad assumption within Windows
http://ift.tt/2wn8Uza
Submitted September 01, 2017 at 09:49AM by 0xNemi
via reddit http://ift.tt/2vOo7pn
http://ift.tt/2wn8Uza
Submitted September 01, 2017 at 09:49AM by 0xNemi
via reddit http://ift.tt/2vOo7pn
www.triplefault.io
Detecting debuggers by abusing a bad assumption within Windows
A blog about general reverse engineering, security research, poking around Windows internals, and messing with the Intel x86/AMD64 architecture.
Stealing contact form data on www.hackerone.com using Marketo Forms XSS with postMessage frame-jumping and jQuery-JSONP
http://ift.tt/2wWV08j
Submitted September 01, 2017 at 03:46PM by albinowax
via reddit http://ift.tt/2ep3sSh
http://ift.tt/2wWV08j
Submitted September 01, 2017 at 03:46PM by albinowax
via reddit http://ift.tt/2ep3sSh
HackerOne
HackerOne disclosed on HackerOne: Stealing contact form data on...
Hi,
I just discovered that there's a scenario where the Marketo Forms solution being used on www.hackerone.com can actually be abused, using a few fun techniques, to trigger an XSS in the...
I just discovered that there's a scenario where the Marketo Forms solution being used on www.hackerone.com can actually be abused, using a few fun techniques, to trigger an XSS in the...
Mining Adminers - Hackers Scan the Internet For DB Scripts
http://ift.tt/2vsrvLo
Submitted September 01, 2017 at 09:25PM by majorllama
via reddit http://ift.tt/2wpLZTJ
http://ift.tt/2vsrvLo
Submitted September 01, 2017 at 09:25PM by majorllama
via reddit http://ift.tt/2wpLZTJ
Sucuri Blog
Mining Adminers - Hackers Scan the Internet For DB Scripts
Hackers are scanning the Internet for sites using Adminers. If your site uses temporary maintenance or admin noscripts, learn how you can minimize the risks.
Why BlackBerry's security sucks
http://ift.tt/2iPnuKL
Submitted September 02, 2017 at 01:09AM by pacific_research
via reddit http://ift.tt/2wqwBX9
http://ift.tt/2iPnuKL
Submitted September 02, 2017 at 01:09AM by pacific_research
via reddit http://ift.tt/2wqwBX9
reddit
Why BlackBerry's security sucks • r/netsec
0 points and 0 comments so far on reddit
6 Million Account For Sale On DoxaGram
http://ift.tt/2wqmPEx
Submitted September 02, 2017 at 02:22AM by abhihpes
via reddit http://ift.tt/2wYSCh9
http://ift.tt/2wqmPEx
Submitted September 02, 2017 at 02:22AM by abhihpes
via reddit http://ift.tt/2wYSCh9
www.techposts.net
6 Million Celebrities Instagram High-Profiles Data Up For Sale On DoxaGram |
An unknown hacker has stolen personal details of 6 million "High-Profile" Instagram account and made it available for sale on a website, called Doxagram
0patching the RSRC Arbitrary NULL Write Vulnerability in LABView (CVE-2017-2779)
http://ift.tt/2ewmmuc
Submitted September 01, 2017 at 10:48PM by dielel
via reddit http://ift.tt/2gqE7bc
http://ift.tt/2ewmmuc
Submitted September 01, 2017 at 10:48PM by dielel
via reddit http://ift.tt/2gqE7bc
0patch.blogspot.co.uk
0patching the RSRC Arbitrary NULL Write Vulnerability in LabVIEW (CVE-2017-2779)
Whether Vendors Patch Their Products or Not, We Have Your Back by Mitja Kolsek, the 0patch Team Three days ago, Cisco Talos published a...
Safari Accidentally Treating ';' as an Assignment Operator
http://ift.tt/2epSNqP
Submitted September 02, 2017 at 05:40AM by fagnerbrack
via reddit http://ift.tt/2ewnWfQ
http://ift.tt/2epSNqP
Submitted September 02, 2017 at 05:40AM by fagnerbrack
via reddit http://ift.tt/2ewnWfQ
reddit
Safari Accidentally Treating ';' as an Assignment Operator • r/netsec
6 points and 1 comments so far on reddit
PowerPoint Presentations Exploiting CVE-2017-0199 found
http://ift.tt/2wrDMP6
Submitted September 02, 2017 at 08:02AM by greenterminal
via reddit http://ift.tt/2wv8xAQ
http://ift.tt/2wrDMP6
Submitted September 02, 2017 at 08:02AM by greenterminal
via reddit http://ift.tt/2wv8xAQ
Hackers Grid
PowerPoint Presentation Exploiting CVE-2017-0199
Researchers at FortiGaurd had discrovered a new Power Point Presentation File named "ADVANCED DIPLOMATIC PROTOCOL AND ETIQUETTE SUMMIT.ppsx" spreading via E Mail targeting UN agencies, Foreign Ministries, International Organizations, and those who interact…
Android tap-jacking can be turned into ransomware
https://youtu.be/FRpcGwCedZ0
Submitted September 02, 2017 at 11:45PM by fproulx
via reddit http://ift.tt/2etlFOC
https://youtu.be/FRpcGwCedZ0
Submitted September 02, 2017 at 11:45PM by fproulx
via reddit http://ift.tt/2etlFOC
YouTube
Cloak & Dagger: From Two Permissions to Complete Control of the UI Feedback Loop
While both the SYSTEM_ALERT_WINDOW and the BIND_ACCESSIBILITY_SERVICE Android permissions have been abused individually (e.g., in UI redressing attacks, accessibility attacks), previous attacks based on these permissions failed to completely control the UI…
This Week in Security News -
http://ift.tt/2wXBUPA
Submitted September 03, 2017 at 04:47AM by del_hack
via reddit http://ift.tt/2eQubrQ
http://ift.tt/2wXBUPA
Submitted September 03, 2017 at 04:47AM by del_hack
via reddit http://ift.tt/2eQubrQ
Trendmicro
This Week in Security News -
Welcome to our weekly roundup, where we share what you need to know about the cybersecurity news and events that happened over the past few days. Below you’ll find a quick recap of topics followed by links to news articles and/or our blog posts providing…
Step by Step Guide to Automating Web Apps Input fuzzing via Burp Macros
http://ift.tt/2wvi4d3
Submitted September 03, 2017 at 05:50PM by sandeep1337
via reddit http://ift.tt/2gCsYb6
http://ift.tt/2wvi4d3
Submitted September 03, 2017 at 05:50PM by sandeep1337
via reddit http://ift.tt/2gCsYb6
SecureLayer7
Automating Web Apps Input fuzzing via Burp Macros - SecureLayer7
Hi Readers, This article is about Burp Suite Macros which helps us in automating efforts of manual input payload fuzzing. While it may be known to many testers, this article is written for those who are yet to harness the power of burp suite’s macro automation.…
Advanced Flash Vulnerabilities in Youtube
http://ift.tt/2vCM5bK
Submitted September 03, 2017 at 05:09PM by albinowax
via reddit http://ift.tt/2gv6LrX
http://ift.tt/2vCM5bK
Submitted September 03, 2017 at 05:09PM by albinowax
via reddit http://ift.tt/2gv6LrX
OpnSec
Advanced Flash Vulnerabilities in Youtube – Part 1 | OpnSec
Why Flash Security still matters? Flash is still an active threat. In 2017, I reported Flash vulnerabilities to Facebook, Youtube, Wordpress, Yahoo, Paypal and Stripe. Over the last 3 years, I reported more than 50 Flash vulnerabilities to Bug Bounty programs…
A journey into radare2 - Exploitation
http://ift.tt/2evYinF
Submitted September 04, 2017 at 07:43AM by Megabeets
via reddit http://ift.tt/2wzKRLy
http://ift.tt/2evYinF
Submitted September 04, 2017 at 07:43AM by Megabeets
via reddit http://ift.tt/2wzKRLy
Megabeets
A journey into Radare 2 – Part 2: Exploitation – Megabeets
In this part of the series we'll focus on exploiting a simple binary. radare2 has many features which will help us in exploitation, such as...
Enhancing nmap probes for SAP services detection
http://ift.tt/2gmnEss
Submitted September 04, 2017 at 12:10PM by gelim
via reddit http://ift.tt/2eUjHYk
http://ift.tt/2gmnEss
Submitted September 04, 2017 at 12:10PM by gelim
via reddit http://ift.tt/2eUjHYk
CVE-2017-12712 etc. - Pacemaker with multiple vulnerabilities recalled
http://ift.tt/2x4vON1
Submitted September 04, 2017 at 05:22PM by cryptogeeky
via reddit http://ift.tt/2xIRag4
http://ift.tt/2x4vON1
Submitted September 04, 2017 at 05:22PM by cryptogeeky
via reddit http://ift.tt/2xIRag4
Security Taco
Pacemaker? Check your firmware! Recall Alert
If you or a loved one has a pacemaker, you need to read this. On August 29, 2017, the FDA issued a recall for Abbott’s (formerly St. Jude Medical’s) Implantable Cardiac Pacemakers. Th…
[PDF] GDB PEDA exploit development
http://ift.tt/2wyJbDX
Submitted September 04, 2017 at 05:59PM by _____WINTERMUTE_____
via reddit http://ift.tt/2gDGjzU
http://ift.tt/2wyJbDX
Submitted September 04, 2017 at 05:59PM by _____WINTERMUTE_____
via reddit http://ift.tt/2gDGjzU
Taringa: Over 28 Millions User’s Account Leaked In The Massive Data Breach
http://ift.tt/2vFkarQ
Submitted September 04, 2017 at 10:01PM by abhihpes
via reddit http://ift.tt/2iXtQI3
http://ift.tt/2vFkarQ
Submitted September 04, 2017 at 10:01PM by abhihpes
via reddit http://ift.tt/2iXtQI3
www.techposts.net
Taringa: Over 28 Millions User's Account Leaked In The Massive Data Breach |
Taringa, also called as "The Latin American Reddit", have been breached and over 28 Million users login details are exposed in the massive data breach
SharknAT&To: Vulnerabilities in AT&T U-verse modems
http://ift.tt/2wpIfQl
Submitted September 04, 2017 at 10:52PM by 300BLK_Lives_Matter
via reddit http://ift.tt/2wBE6cn
http://ift.tt/2wpIfQl
Submitted September 04, 2017 at 10:52PM by 300BLK_Lives_Matter
via reddit http://ift.tt/2wBE6cn
Nomotion Blog
SharknAT&To - Nomotion Blog
Introduction When evidence of the problems described in this report were first noticed, it almost seemed hard to believe. However, for those familiar with the technical history of Arris and their careless lingering of hardcoded accounts on their products…
Kioptrix: Level 1 Walkthrough - VulnHub Boot2Root/CTF - Samba 2.2.x RCE
http://ift.tt/2ez3APz
Submitted September 05, 2017 at 05:21AM by InfoSecJim
via reddit http://ift.tt/2iZdE9B
http://ift.tt/2ez3APz
Submitted September 05, 2017 at 05:21AM by InfoSecJim
via reddit http://ift.tt/2iZdE9B
Jim Wilbur's Blog
Kioptrix: Level 1 Walkthrough - VulnHub - Jim Wilbur's Blog
A walkthrough of Kioptrix: Level 1 from VulnHub. This is the first vm in the Kioptrix series. More to come!
Exploiting React CSS-in-JS
http://ift.tt/2xAv938
Submitted September 05, 2017 at 02:42PM by albinowax
via reddit http://ift.tt/2x6V31q
http://ift.tt/2xAv938
Submitted September 05, 2017 at 02:42PM by albinowax
via reddit http://ift.tt/2x6V31q
React Armory
How can I securely use CSS-in-JS with React? — React Armory
CSS-in-JS is a bit like eval for CSS. It is incredibly powerful, but it also makes it easy to shoot yourself in the foot.