Netsec – Telegram
Netsec
7.41K subscribers
22.4K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
memcachedump - Use your Shodan API Key to dump all the contents of exposed memcached servers. (There are +108000 on Shodan as of today.)
http://ift.tt/2FyMvEr

Submitted March 08, 2018 at 11:42PM by jalospinoso
via reddit http://ift.tt/2FlhjZW
memcachedump - Use your Shodan API Key to dump all the contents of exposed memcached servers. (There are +108000 on Shodan as of today.)
http://ift.tt/2FyMvEr

Submitted March 08, 2018 at 11:42PM by jalospinoso
via reddit http://ift.tt/2FlhjZW
Look-Alike Domains and Visual Confusion
http://ift.tt/2FBUbFH

Submitted March 09, 2018 at 12:12AM by volci
via reddit http://ift.tt/2G82jf1
Kill Switch Can Mitigate Massive DDoS Attacks Via Memcached Servers
http://ift.tt/2G7JoRH

Submitted March 09, 2018 at 12:55AM by Horus_Sirius
via reddit http://ift.tt/2D92Zxz
Monitors for DCSYNC and DCSHADOW attacks and create custom Windows Events for these events.
http://ift.tt/2G826Zq

Submitted March 09, 2018 at 01:24AM by digicat
via reddit http://ift.tt/2FqyDJ2
What dangers/exploits might present if you were to add servers to the NTP Pool?
DO has a tutorial on adding Ubuntu servers to the NTP Pool (https://www.digitalocean.com/community/tutorials/how-to-configure-ntp-for-use-in-the-ntp-pool-project-on-ubuntu-16-04).I'm all for helping-out others (I run a couple mirrors in Germany for CentOS and Haiku OS, for example - but those are "just" websites).Are there any inherent dangers or possibe exploits in adding servers to the public NTP Pool, presuming you have the estimated bandwidth available (that article claims peak demand shouldn't exceed 150KB/s, which totals to <300GB, if it sits at that theoretical peak for 30 days).

Submitted March 09, 2018 at 05:31AM by volci
via reddit http://ift.tt/2oTwQpA
Facebook lets me log in when I have a typo in my e-mail adress, is this on purpose?
I just realized that I mistyped my e-mail adress the last time I logged into my FB account, so I gave it another try and again I could just log in without a problem. I tried a different character in different positions of the e-mail adress and it always worked. So I tried changing two and then three characters to something else, and I can still log in. Not sure what to think about that.

Submitted March 09, 2018 at 05:16PM by debtsnbooze
via reddit http://ift.tt/2Db3gjL
comparison vulnerability scanners
Hi everyone,I'm looking for a site or document where commercial vulnerability scanners are compared in a (semi)professional way.Is there anyone here that knows of the existence of such an comparison? I have been searching but unfortunately I couldn't find any.Thanks in advance.

Submitted March 09, 2018 at 06:35PM by koningsvh
via reddit http://ift.tt/2DdAQpf
Looking back at a Windows Kernel info leak bug involving improper checks from Pwn2Own 2016.
http://ift.tt/2trDMim

Submitted March 09, 2018 at 06:59PM by RedmondSecGnome
via reddit http://ift.tt/2tx9meA
#0daytoday #Tor Browser ( Firefox 41 &amp;lt; 50 ) - Code Execution 0day Exploit [#0day #Exploit]
http://ift.tt/2Hkqnuz

Submitted March 09, 2018 at 08:28PM by Horus_Sirius
via reddit http://ift.tt/2FDAVYB
Best Security Conference Session You've Ever Attended
With RSA 2018 coming up next month, I'm interested to hear what keynote or breakout sessions have stood out as being particularly interesting or educational for everyone here (not necessarily at RSA, but at any security conferences you've been to).

Submitted March 09, 2018 at 08:07PM by Forgetful_Prophet
via reddit http://ift.tt/2HkqqGL