Netsec – Telegram
Netsec
7.42K subscribers
22.4K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
APT Attacks Targetting Financial Institutions [Blackhat Asia 2018 Study Presentation]
https://ift.tt/2Gg3ThD

Submitted March 23, 2018 at 11:37PM by TechLord2
via reddit https://ift.tt/2pCzpvE
What to do if you can't delete Facebook because of work?
If your job requires you to use Facebook, what options do you have to help limit the social behemoth's intrusion into your personal details?I'm not an expert but here's what I've come up with so far:Use a separate browser (or at least a separate profile) for anything Facebook-related.For your primary, non-Facebook browser, log out of Facebook, delete all cookies, and use an extension that allows you to customize hosts entries. Here's one for Chrome. I've also heard about people setting up Ublock Origin for this purpose, although I haven't tried it.From within Facebook, delete absolutely everything that's not directly related to work.Unfriend everybody.Mark your profile as private.Go through your privacy settings and make sure only friends of friends can send you friend requests. Since you don't have any friends that takes care of that.What do you think? Am I missing anything?

Submitted March 24, 2018 at 05:54AM by njbair
via reddit https://ift.tt/2pFAHX4
Why do so many websites allow poor authentication? (and how it drives me to light social hacking for spam avoidance)
It seems like a lot of websites are at the mercy of users who type in an incorrect email address.tldr; I feel justified resetting users passwords if they give my email address by mistake. Is there a better way to deal with this? What security best practices are these websites failing at?My email address is like this: flast at gmail.comf is the first character of my first namelast is my last name.It seems that I become the unintended the target of lazy / absentminded / forgetful people about once a month that write or type their email address for some login or membership form.So I get an email saying please click here to confirm your email address.Whereupon, I click to confirm, go to a login page, click on forgot password, get emailed a reset link, then set the password to something like abcd123, login and change the name to first name:invalid login, last name: invalid login, username: invalidlogin, email invalidlogin@example.com. Basically hacking my way in the most low tech way possible to get my email address removed from the website.The funny recent example was xfinity comcast, which asked me an extra security question: "what's your favorite beverage?" It took me six tries to guess. This has to be one of the weakest security questions in the world, assuming the average person isn't paranoid enough to intentionally obfuscate their answer.Another example, someone must have bought a new jeep or at least shown interest and wrote my email on the form, by mistake or by lack of thought and consideration; giving a "dummy" email address.So, in part I guess I understand the problem. If someone's buying a new jeep and have to write their email on a form, they don't bother to give their real email address, the website doesn't feel any obligation to verify the email address correctly.Or in the previous above example, I think it was some trial free web usage, so they also don't feel obliged to check the email address thoroughly.But can someone comment on the best way these things should be done?, from the website's perspective. Perhaps the website should require you to remember your email address for the first login before any reset password requests or otherwise time out the verification links after a few hours and make the user recreate their login?I guess there's the time-old balance between ease of use for customers and (businesses that have a top priority of making it easy for customers to spend money) versus security.I feel somewhat justified logging in to reset the email address, so that my email address is no longer in a big database somewhere and I'm not going to get endless marketing spam in the future.Of course, I'm referring to big companies that have no-reply email address don't have a one-two click way of dealing with these mistakes. If I think it's going to take me more than a couple of minutes to deal with this issue, I'll do it the grey-hat hacker instead of jumping through hoops.To summarize, I thought I'd share my story because I'm sure some of you will find it funny (and I'm sure some of you will chide me too). And I wondered what people think. Any stories to tell? Better ways to do this?

Submitted March 24, 2018 at 10:59AM by johnnyjohnsmith
via reddit https://ift.tt/2G1bQIb
I work security at a bar and last night when I turned someone away because he was so drunk he could badly stand, he said it was because I was racist and he could see it in my face that was the reason he wasn’t allowed in. What is a professional response to this?
I just said ‘you’re wrong, it’s because you can badly stand up’, luckily to which his mates all agreed.This isn’t the first time it’s happened. It seems to be thrown around as the first excuse when someone hears something they disagree with quite a lot recently. I’m an Asian guy of Chinese decent and got quite frustrated when this was fired at me, so wanna learn a good way to deal with it, but like I say it seems to be getting more and more common as some kind of defence. I’ve seen other security guards actually get quite uncomfortable and actually reverse their decision through fear of being called racist in front of other people if the person escalates it.That seems insane to me.Is there a good, professional answer or response to give in this situation?

Submitted March 24, 2018 at 10:26PM by Bloc101
via reddit https://ift.tt/2I22okr
Encryption Testing.
How does one test the level of encryption on a network?I have been searching online for some information on this for my assignment, but i haven't found much at all.Does anyone know anything about encryption testing and could lend a hand? maybe submit a few links for me, i would appreciate all the help i can getDan

Submitted March 25, 2018 at 02:15AM by Danjdunham_
via reddit https://ift.tt/2DVxQhO
Delete Fb without deleting your profile. Stop targeted advertising and information gathering! Shoot me a message if you need advice. If you’re wondering what this is about, watch the news! lol
https://ift.tt/2G1WK5g

Submitted March 25, 2018 at 03:17AM by rweedn
via reddit https://ift.tt/2HYmhsg
Shodan Search Exposes Thousands of Servers Hosting Passwords and Keys
https://ift.tt/2pE8tvK

Submitted March 25, 2018 at 12:18PM by Horus_Sirius
via reddit https://ift.tt/2GlRSqN
Discovering Smart Contract Vulnerabilities with GOATCasino
https://ift.tt/2G2pvys

Submitted March 25, 2018 at 01:45PM by digicat
via reddit https://ift.tt/2pIetUn