Phishy Basic Authentication prompts
http://ift.tt/2j3gn1F
Submitted September 06, 2017 at 07:53PM by Matasareanu13
via reddit http://ift.tt/2wGisFk
http://ift.tt/2j3gn1F
Submitted September 06, 2017 at 07:53PM by Matasareanu13
via reddit http://ift.tt/2wGisFk
Security Café
Phishy Basic Authentication prompts
In one of our previous posts, we noted that a popular tool – Responder – uses Basic Authentication prompts to harvest user credentials when they accidentally enter invalid domains in we…
All the Pretty Pwnies
http://ift.tt/2eGT2xG
Submitted September 07, 2017 at 12:12AM by tedcarstensen
via reddit http://ift.tt/2gMJUvR
http://ift.tt/2eGT2xG
Submitted September 07, 2017 at 12:12AM by tedcarstensen
via reddit http://ift.tt/2gMJUvR
LaunchDarkly
All the Pretty Ponies
August is always full of security awareness in the wake of DefCon, BlackHat USA and t...
Evading CloudFlare: Bypass Cloud Security Protections with CFire
http://ift.tt/2gHN00l
Submitted September 07, 2017 at 01:06AM by cslakin
via reddit http://ift.tt/2j24vNa
http://ift.tt/2gHN00l
Submitted September 07, 2017 at 01:06AM by cslakin
via reddit http://ift.tt/2j24vNa
Rhino Security Labs
Cloudflare: Evading Cloud Security Protections | Rhino Security Labs
CloudFlare can be subverted, exposing the real IP addresses of cloud targets. You can use CFire to identify misconfigurations in your cloud architecture.
Vulnerability Spotlight: Content Security Policy bypass in Microsoft Edge, Google Chrome and Apple Safari
http://ift.tt/2wGmSvY
Submitted September 07, 2017 at 02:14AM by majorllama
via reddit http://ift.tt/2f3KgKD
http://ift.tt/2wGmSvY
Submitted September 07, 2017 at 02:14AM by majorllama
via reddit http://ift.tt/2f3KgKD
Talosintelligence
Vulnerability Spotlight: Content Security Policy bypass in Microsoft Edge, Google Chrome and Apple Safari
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
Uber Bug Bounty: Gaining Access To An Internal Chat System
http://ift.tt/2vN3JtE
Submitted September 07, 2017 at 02:09AM by mishre
via reddit http://ift.tt/2f4XQO4
http://ift.tt/2vN3JtE
Submitted September 07, 2017 at 02:09AM by mishre
via reddit http://ift.tt/2f4XQO4
(ISC)² Announces Showcased Honorees and Community Service Star Award for 11th Annual ISLA Recognition Program
http://ift.tt/2w8NG4J
Submitted September 07, 2017 at 05:39AM by bloon_hack
via reddit http://ift.tt/2vNc9RH
http://ift.tt/2w8NG4J
Submitted September 07, 2017 at 05:39AM by bloon_hack
via reddit http://ift.tt/2vNc9RH
New Microsoft Kernel Bug Could Permit Malicious Modules
http://ift.tt/2vJcxAQ
Submitted September 07, 2017 at 06:27AM by majorllama
via reddit http://ift.tt/2vNhh8q
http://ift.tt/2vJcxAQ
Submitted September 07, 2017 at 06:27AM by majorllama
via reddit http://ift.tt/2vNhh8q
Hunting Pastebin with YaraRules
http://ift.tt/2iXfbwR
Submitted September 07, 2017 at 12:55PM by kev-thehermit
via reddit http://ift.tt/2wINTih
http://ift.tt/2iXfbwR
Submitted September 07, 2017 at 12:55PM by kev-thehermit
via reddit http://ift.tt/2wINTih
TechAnarchy
Hunting Pastebin with PasteHunter
From a security analytics and Threat Intelligence perspective pastebin is a treasure trove of information. All content that is uploaded to pastebin and not explicitly set to private (which requires an account) is listed and can be viewed by anyone. tl;dr…
Intro. to Windows Kernel Driver Exploitation - Setup
http://ift.tt/2xcMEcW
Submitted September 07, 2017 at 04:45PM by Glenny5
via reddit http://ift.tt/2f79VT0
http://ift.tt/2xcMEcW
Submitted September 07, 2017 at 04:45PM by Glenny5
via reddit http://ift.tt/2f79VT0
glem
Introduction to Windows Kernel Driver Exploitation (Pt. 1)
This is the first part of a series of posts I am going to do about Windows kernel exploitation, via vulnerable drivers. The project I will be using for the exploit is HackSys Extreme Vulnerable Driver, which is a really cool little vulnerable windows driver…
RHME3 Quals - Exploitation Solution
http://ift.tt/2vOxIS3
Submitted September 07, 2017 at 05:58PM by Glenny5
via reddit http://ift.tt/2j6YvTp
http://ift.tt/2vOxIS3
Submitted September 07, 2017 at 05:58PM by Glenny5
via reddit http://ift.tt/2j6YvTp
glem
RHME3 Quals - Exploitation
This was a fun challenge, a lot of mistakes were made and a lot of things were learnt! Shout out to 0x4a47 my team mate for the RHME3 CTF aswell. As a good exploit challenge starts, we begin by running file on the binary to see what we learn about
Reliable sleep-based detection payload for the new Struts REST vulnerability (CVE-2017-9805)
http://ift.tt/2wL4dOa
Submitted September 07, 2017 at 06:46PM by 0xdea
via reddit http://ift.tt/2xdguOm
http://ift.tt/2wL4dOa
Submitted September 07, 2017 at 06:46PM by 0xdea
via reddit http://ift.tt/2xdguOm
Expired domain names and malvertising - Malwarebytes Labs
http://ift.tt/2j0nXKa
Submitted September 07, 2017 at 06:19PM by majorllama
via reddit http://ift.tt/2eJnPK8
http://ift.tt/2j0nXKa
Submitted September 07, 2017 at 06:19PM by majorllama
via reddit http://ift.tt/2eJnPK8
Malwarebytes Labs
Expired domain names and malvertising - Malwarebytes Labs
A look at how expired domain names can be turned into a lucrative malicious traffic redirection tool.
TrickBot Banking Trojan Dropper Analysis
http://ift.tt/2j60g3k
Submitted September 07, 2017 at 07:27PM by majorllama
via reddit http://ift.tt/2wKkq7J
http://ift.tt/2j60g3k
Submitted September 07, 2017 at 07:27PM by majorllama
via reddit http://ift.tt/2wKkq7J
Ringzerolabs
TrickBot Banking Trojan - DOC00039217.doc
Malware Analysis - VBA noscripts used to download TrickBot banking trojan
Chaos Computer Club finds fundamental security problems in "PC-Wahl'-software which is used for general elections
http://ift.tt/2xQfzk3
Submitted September 07, 2017 at 08:44PM by Skaarj
via reddit http://ift.tt/2xe0ewo
http://ift.tt/2xQfzk3
Submitted September 07, 2017 at 08:44PM by Skaarj
via reddit http://ift.tt/2xe0ewo
reddit
Chaos Computer Club finds fundamental security problems... • r/netsec
9 points and 0 comments so far on reddit
Cryptographic vulnerabilities in cryptocurrency IOTA - custom hash function has practical collisions
http://ift.tt/2eO19fB
Submitted September 08, 2017 at 01:49AM by cybergibbons
via reddit http://ift.tt/2j96Sy1
http://ift.tt/2eO19fB
Submitted September 08, 2017 at 01:49AM by cybergibbons
via reddit http://ift.tt/2j96Sy1
Medium
Cryptographic vulnerabilities in IOTA
Last month, Ethan Heilman, Tadge Dryja, Madars Virza, and I took a look at IOTA, currently the 8th largest cryptocurrency with a $1.9B…
Broadpwn: Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets
https://www.youtube.com/watch?v=TDk2RId8LFo
Submitted September 08, 2017 at 04:48AM by bool101
via reddit http://ift.tt/2gLd62H
https://www.youtube.com/watch?v=TDk2RId8LFo
Submitted September 08, 2017 at 04:48AM by bool101
via reddit http://ift.tt/2gLd62H
YouTube
Broadpwn: Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets
Meet Broadpwn, a vulnerability in Broadcom's Wi-Fi chipsets which affects millions of Android and iOS devices, and can be triggered remotely, without user interaction. The Broadcom BCM43xx family of Wi-Fi chips is found in an extraordinarily wide range of…
ES6 for penetration testers
http://ift.tt/1tdkHrG
Submitted September 08, 2017 at 04:45AM by nohohC0i
via reddit http://ift.tt/2vQZgpB
http://ift.tt/1tdkHrG
Submitted September 08, 2017 at 04:45AM by nohohC0i
via reddit http://ift.tt/2vQZgpB
Zer0con slides - Owning embedded devices and network protocols
http://ift.tt/2vQSPmr
Submitted September 08, 2017 at 04:25AM by PierreKimSec
via reddit http://ift.tt/2vQKFKZ
http://ift.tt/2vQSPmr
Submitted September 08, 2017 at 04:25AM by PierreKimSec
via reddit http://ift.tt/2vQKFKZ
Pwning the Dlink 850L routers and abusing the MyDlink Cloud protocol
http://ift.tt/2wcWvdT
Submitted September 08, 2017 at 04:25AM by PierreKimSec
via reddit http://ift.tt/2xSUxkS
http://ift.tt/2wcWvdT
Submitted September 08, 2017 at 04:25AM by PierreKimSec
via reddit http://ift.tt/2xSUxkS
Equifax data leak could involve 143 million consumers
http://ift.tt/2xeWmeM
Submitted September 08, 2017 at 04:16AM by marks13
via reddit http://ift.tt/2gPZd73
http://ift.tt/2xeWmeM
Submitted September 08, 2017 at 04:16AM by marks13
via reddit http://ift.tt/2gPZd73
TechCrunch
Equifax data leak could involve 143 million consumers
Data leaks have become so commonplace that it’s incredibly easy to become numb to them, but credit reporting service Equifax announced a doozy today that when all is said and done could involve…
2017 Best Cities for Cybersecurity Professionals
http://ift.tt/2kUX5qP
Submitted September 08, 2017 at 06:22AM by PalwaJoko
via reddit http://ift.tt/2eQAuij
http://ift.tt/2kUX5qP
Submitted September 08, 2017 at 06:22AM by PalwaJoko
via reddit http://ift.tt/2eQAuij
GoodCall DataCenter
2017 Best Cities for Cybersecurity Professionals | GoodCall
As hackers increase attacks, more people are needed to fight back. GoodCall analysts compiled a list of the Best Cities for Cybersecurity Professionals.