New Microsoft Kernel Bug Could Permit Malicious Modules
http://ift.tt/2vJcxAQ
Submitted September 07, 2017 at 06:27AM by majorllama
via reddit http://ift.tt/2vNhh8q
http://ift.tt/2vJcxAQ
Submitted September 07, 2017 at 06:27AM by majorllama
via reddit http://ift.tt/2vNhh8q
Hunting Pastebin with YaraRules
http://ift.tt/2iXfbwR
Submitted September 07, 2017 at 12:55PM by kev-thehermit
via reddit http://ift.tt/2wINTih
http://ift.tt/2iXfbwR
Submitted September 07, 2017 at 12:55PM by kev-thehermit
via reddit http://ift.tt/2wINTih
TechAnarchy
Hunting Pastebin with PasteHunter
From a security analytics and Threat Intelligence perspective pastebin is a treasure trove of information. All content that is uploaded to pastebin and not explicitly set to private (which requires an account) is listed and can be viewed by anyone. tl;dr…
Intro. to Windows Kernel Driver Exploitation - Setup
http://ift.tt/2xcMEcW
Submitted September 07, 2017 at 04:45PM by Glenny5
via reddit http://ift.tt/2f79VT0
http://ift.tt/2xcMEcW
Submitted September 07, 2017 at 04:45PM by Glenny5
via reddit http://ift.tt/2f79VT0
glem
Introduction to Windows Kernel Driver Exploitation (Pt. 1)
This is the first part of a series of posts I am going to do about Windows kernel exploitation, via vulnerable drivers. The project I will be using for the exploit is HackSys Extreme Vulnerable Driver, which is a really cool little vulnerable windows driver…
RHME3 Quals - Exploitation Solution
http://ift.tt/2vOxIS3
Submitted September 07, 2017 at 05:58PM by Glenny5
via reddit http://ift.tt/2j6YvTp
http://ift.tt/2vOxIS3
Submitted September 07, 2017 at 05:58PM by Glenny5
via reddit http://ift.tt/2j6YvTp
glem
RHME3 Quals - Exploitation
This was a fun challenge, a lot of mistakes were made and a lot of things were learnt! Shout out to 0x4a47 my team mate for the RHME3 CTF aswell. As a good exploit challenge starts, we begin by running file on the binary to see what we learn about
Reliable sleep-based detection payload for the new Struts REST vulnerability (CVE-2017-9805)
http://ift.tt/2wL4dOa
Submitted September 07, 2017 at 06:46PM by 0xdea
via reddit http://ift.tt/2xdguOm
http://ift.tt/2wL4dOa
Submitted September 07, 2017 at 06:46PM by 0xdea
via reddit http://ift.tt/2xdguOm
Expired domain names and malvertising - Malwarebytes Labs
http://ift.tt/2j0nXKa
Submitted September 07, 2017 at 06:19PM by majorllama
via reddit http://ift.tt/2eJnPK8
http://ift.tt/2j0nXKa
Submitted September 07, 2017 at 06:19PM by majorllama
via reddit http://ift.tt/2eJnPK8
Malwarebytes Labs
Expired domain names and malvertising - Malwarebytes Labs
A look at how expired domain names can be turned into a lucrative malicious traffic redirection tool.
TrickBot Banking Trojan Dropper Analysis
http://ift.tt/2j60g3k
Submitted September 07, 2017 at 07:27PM by majorllama
via reddit http://ift.tt/2wKkq7J
http://ift.tt/2j60g3k
Submitted September 07, 2017 at 07:27PM by majorllama
via reddit http://ift.tt/2wKkq7J
Ringzerolabs
TrickBot Banking Trojan - DOC00039217.doc
Malware Analysis - VBA noscripts used to download TrickBot banking trojan
Chaos Computer Club finds fundamental security problems in "PC-Wahl'-software which is used for general elections
http://ift.tt/2xQfzk3
Submitted September 07, 2017 at 08:44PM by Skaarj
via reddit http://ift.tt/2xe0ewo
http://ift.tt/2xQfzk3
Submitted September 07, 2017 at 08:44PM by Skaarj
via reddit http://ift.tt/2xe0ewo
reddit
Chaos Computer Club finds fundamental security problems... • r/netsec
9 points and 0 comments so far on reddit
Cryptographic vulnerabilities in cryptocurrency IOTA - custom hash function has practical collisions
http://ift.tt/2eO19fB
Submitted September 08, 2017 at 01:49AM by cybergibbons
via reddit http://ift.tt/2j96Sy1
http://ift.tt/2eO19fB
Submitted September 08, 2017 at 01:49AM by cybergibbons
via reddit http://ift.tt/2j96Sy1
Medium
Cryptographic vulnerabilities in IOTA
Last month, Ethan Heilman, Tadge Dryja, Madars Virza, and I took a look at IOTA, currently the 8th largest cryptocurrency with a $1.9B…
Broadpwn: Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets
https://www.youtube.com/watch?v=TDk2RId8LFo
Submitted September 08, 2017 at 04:48AM by bool101
via reddit http://ift.tt/2gLd62H
https://www.youtube.com/watch?v=TDk2RId8LFo
Submitted September 08, 2017 at 04:48AM by bool101
via reddit http://ift.tt/2gLd62H
YouTube
Broadpwn: Remotely Compromising Android and iOS via a Bug in Broadcom's Wi-Fi Chipsets
Meet Broadpwn, a vulnerability in Broadcom's Wi-Fi chipsets which affects millions of Android and iOS devices, and can be triggered remotely, without user interaction. The Broadcom BCM43xx family of Wi-Fi chips is found in an extraordinarily wide range of…
ES6 for penetration testers
http://ift.tt/1tdkHrG
Submitted September 08, 2017 at 04:45AM by nohohC0i
via reddit http://ift.tt/2vQZgpB
http://ift.tt/1tdkHrG
Submitted September 08, 2017 at 04:45AM by nohohC0i
via reddit http://ift.tt/2vQZgpB
Zer0con slides - Owning embedded devices and network protocols
http://ift.tt/2vQSPmr
Submitted September 08, 2017 at 04:25AM by PierreKimSec
via reddit http://ift.tt/2vQKFKZ
http://ift.tt/2vQSPmr
Submitted September 08, 2017 at 04:25AM by PierreKimSec
via reddit http://ift.tt/2vQKFKZ
Pwning the Dlink 850L routers and abusing the MyDlink Cloud protocol
http://ift.tt/2wcWvdT
Submitted September 08, 2017 at 04:25AM by PierreKimSec
via reddit http://ift.tt/2xSUxkS
http://ift.tt/2wcWvdT
Submitted September 08, 2017 at 04:25AM by PierreKimSec
via reddit http://ift.tt/2xSUxkS
Equifax data leak could involve 143 million consumers
http://ift.tt/2xeWmeM
Submitted September 08, 2017 at 04:16AM by marks13
via reddit http://ift.tt/2gPZd73
http://ift.tt/2xeWmeM
Submitted September 08, 2017 at 04:16AM by marks13
via reddit http://ift.tt/2gPZd73
TechCrunch
Equifax data leak could involve 143 million consumers
Data leaks have become so commonplace that it’s incredibly easy to become numb to them, but credit reporting service Equifax announced a doozy today that when all is said and done could involve…
2017 Best Cities for Cybersecurity Professionals
http://ift.tt/2kUX5qP
Submitted September 08, 2017 at 06:22AM by PalwaJoko
via reddit http://ift.tt/2eQAuij
http://ift.tt/2kUX5qP
Submitted September 08, 2017 at 06:22AM by PalwaJoko
via reddit http://ift.tt/2eQAuij
GoodCall DataCenter
2017 Best Cities for Cybersecurity Professionals | GoodCall
As hackers increase attacks, more people are needed to fight back. GoodCall analysts compiled a list of the Best Cities for Cybersecurity Professionals.
Tracing arbitrary Methods and Function calls on Android and iOS
http://ift.tt/2xheHrI
Submitted September 08, 2017 at 02:34PM by 0xdea
via reddit http://ift.tt/2wNcWSl
http://ift.tt/2xheHrI
Submitted September 08, 2017 at 02:34PM by 0xdea
via reddit http://ift.tt/2wNcWSl
A roundup of all PandwaRF versions - Sub 1 GHz RF analysis tool
http://ift.tt/2xaTuPk
Submitted September 08, 2017 at 04:41PM by Tartopom06
via reddit http://ift.tt/2xTLno5
http://ift.tt/2xaTuPk
Submitted September 08, 2017 at 04:41PM by Tartopom06
via reddit http://ift.tt/2xTLno5
PandwaRF
What PandwaRF Version Is Right For You? - PandwaRF
PandwaRF is a portable RF analysis tool available in several versions. We often get asked which version to choose, and […]
Simple noscript that notifies you of the ngrok TCP URL after the tunnel is created.
http://ift.tt/2gNHbP9
Submitted September 08, 2017 at 06:54PM by callahanrazor
via reddit http://ift.tt/2wegrwI
http://ift.tt/2gNHbP9
Submitted September 08, 2017 at 06:54PM by callahanrazor
via reddit http://ift.tt/2wegrwI
GitHub
chargz/RemoteSSH
RemoteSSH - Starts an ngrok TCP tunnel and notifies you of the URL. Perfect for automated remote SSH connections.
how to hack the uk tax system, i guess
http://ift.tt/2wewzON
Submitted September 08, 2017 at 07:46PM by Zemnmez
via reddit http://ift.tt/2gOog6H
http://ift.tt/2wewzON
Submitted September 08, 2017 at 07:46PM by Zemnmez
via reddit http://ift.tt/2gOog6H
Medium
how to hack the uk tax system, i guess
a 3 step guide to a 57 day journey
Public API for Vulners. Seems to be world's largest vulnerabilities database.
http://ift.tt/2eS8wT6
Submitted September 08, 2017 at 07:32PM by cr1ys
via reddit http://ift.tt/2jbwx91
http://ift.tt/2eS8wT6
Submitted September 08, 2017 at 07:32PM by cr1ys
via reddit http://ift.tt/2jbwx91
GitHub
vulnersCom/api
api - Vulners Python API wrapper
Abusing JavaScript frameworks to bypass XSS mitigations [PortSwigger Web Security Blog]
http://ift.tt/2xUudGY
Submitted September 08, 2017 at 08:19PM by chloeeeeeeeee
via reddit http://ift.tt/2xhvvP3
http://ift.tt/2xUudGY
Submitted September 08, 2017 at 08:19PM by chloeeeeeeeee
via reddit http://ift.tt/2xhvvP3
blog.portswigger.net
Abusing JavaScript frameworks to bypass XSS mitigations
At AppSec Europe Sebastian Lekies, Krzysztof Kotowicz and Eduardo Vela Nava showed how to use JavaScript frameworks to bypass XSS mitigation...