How to Pwn one of the CREST exam Postgres boxes
https://medium.com/@panagiotis84/a-penetration-testers-guide-to-postgresql-e0eafd1a1028?lipi=urn%3Ali%3Apage%3Ad_flagship3_feed%3BkQdiQJgtRUy3YVAgXSIn1g%3D%3D
Submitted July 20, 2017 at 12:20PM by johnsmithe99
via reddit https://www.reddit.com/r/netsec/comments/6oektf/how_to_pwn_one_of_the_crest_exam_postgres_boxes/?utm_source=ifttt
https://medium.com/@panagiotis84/a-penetration-testers-guide-to-postgresql-e0eafd1a1028?lipi=urn%3Ali%3Apage%3Ad_flagship3_feed%3BkQdiQJgtRUy3YVAgXSIn1g%3D%3D
Submitted July 20, 2017 at 12:20PM by johnsmithe99
via reddit https://www.reddit.com/r/netsec/comments/6oektf/how_to_pwn_one_of_the_crest_exam_postgres_boxes/?utm_source=ifttt
Medium
A Penetration Tester’s Guide to PostgreSQL
PostgreSQL is an open source database which can be found mostly in Linux operating systems. However it has great compatibility with…
Notes and Analysis for RE and Pwning tasks in CTFs
http://ift.tt/2udBIYe
Submitted July 20, 2017 at 10:00PM by Fuzz_Stati0n
via reddit http://ift.tt/2ttPIje
http://ift.tt/2udBIYe
Submitted July 20, 2017 at 10:00PM by Fuzz_Stati0n
via reddit http://ift.tt/2ttPIje
GitHub
jaybosamiya/security-notes
:notebook: Some security related notes. Contribute to jaybosamiya/security-notes development by creating an account on GitHub.
How I tricked Symantec with a Fake Private Key
http://ift.tt/2uCVWNo
Submitted July 20, 2017 at 10:49PM by pheedrus
via reddit http://ift.tt/2udhwFD
http://ift.tt/2uCVWNo
Submitted July 20, 2017 at 10:49PM by pheedrus
via reddit http://ift.tt/2udhwFD
reddit
How I tricked Symantec with a Fake Private Key • r/netsec
2 points and 0 comments so far on reddit
Disarming a home alarm using PandwaRF Rogue Pro – RF analysis tool for physical pentesters
https://www.youtube.com/watch?v=zKXKO7Zsa4Y
Submitted July 20, 2017 at 03:06PM by Tartopom06
via reddit http://ift.tt/2udtVtm
https://www.youtube.com/watch?v=zKXKO7Zsa4Y
Submitted July 20, 2017 at 03:06PM by Tartopom06
via reddit http://ift.tt/2udtVtm
YouTube
PandwaRF vs PandwaRF Rogue: Brute Force Attack
Are your alarm systems secure?
PandwaRF is a pocket-sized, portable RF analysis tool operating the sub-1 GHz range. It allows the capture, analysis and re-transmission of RF via an Android device or a Linux PC.
PandwaRF Rogue is an improved variant of the…
PandwaRF is a pocket-sized, portable RF analysis tool operating the sub-1 GHz range. It allows the capture, analysis and re-transmission of RF via an Android device or a Linux PC.
PandwaRF Rogue is an improved variant of the…
Limitations of Android AntiVirus Scanners
http://ift.tt/2uE11oW
Submitted July 21, 2017 at 12:20AM by _Z_
via reddit http://ift.tt/2udFzV8
http://ift.tt/2uE11oW
Submitted July 21, 2017 at 12:20AM by _Z_
via reddit http://ift.tt/2udFzV8
reddit
Limitations of Android AntiVirus Scanners • r/netsec
1 points and 0 comments so far on reddit
Building a Content Security Policy configuration with CSP Auditor
http://ift.tt/2voAjhI
Submitted July 21, 2017 at 12:47AM by becojo
via reddit http://ift.tt/2gO9QGQ
http://ift.tt/2voAjhI
Submitted July 21, 2017 at 12:47AM by becojo
via reddit http://ift.tt/2gO9QGQ
GoSecure
Building a Content Security Policy configuration with CSP Auditor - GoSecure
In this blog post, we discuss the basic strategy to integrate CSP into an existing website. It covers the theory and the new features of CSP Auditor.
Seccomp filter in Android O
http://ift.tt/2tLadTG
Submitted July 21, 2017 at 04:22AM by invapid
via reddit http://ift.tt/2uEIrNq
http://ift.tt/2tLadTG
Submitted July 21, 2017 at 04:22AM by invapid
via reddit http://ift.tt/2uEIrNq
Android Developers Blog
Seccomp filter in Android O
The latest Android and Google Play news and tips for app and game developers.
REcon 2017 slides
http://ift.tt/2ug5DR8
Submitted July 21, 2017 at 05:15AM by alain_proviste
via reddit http://ift.tt/2uO9nKW
http://ift.tt/2ug5DR8
Submitted July 21, 2017 at 05:15AM by alain_proviste
via reddit http://ift.tt/2uO9nKW
recon.cx
Slides
REcon is a computer security conference with a focus on reverse engineering and advanced exploitation techniques.
Investigating a 5 year old bug deep within the Windows kernel
http://ift.tt/2vpr4h2
Submitted July 21, 2017 at 06:18AM by 0xNemi
via reddit http://ift.tt/2ufOAg8
http://ift.tt/2vpr4h2
Submitted July 21, 2017 at 06:18AM by 0xNemi
via reddit http://ift.tt/2ufOAg8
www.triplefault.io
Breaking backwards compatibility: a 5 year old bug deep within Windows
A blog about general reverse engineering, security research, poking around Windows internals, and messing with the Intel x86/AMD64 architecture.
A simple Android app security checklist with links to testing instructions and best practices
http://ift.tt/2tkY9cH
Submitted July 21, 2017 at 09:27AM by berndtzl
via reddit http://ift.tt/2uggNFm
http://ift.tt/2tkY9cH
Submitted July 21, 2017 at 09:27AM by berndtzl
via reddit http://ift.tt/2uggNFm
GitHub
b-mueller/android_app_security_checklist
android_app_security_checklist - Android App Security Checklist
Black Hat Arsenal USA 2017 [UPDATED]
http://ift.tt/2slQNFF
Submitted July 21, 2017 at 10:10AM by bnchandrapal
via reddit http://ift.tt/2uFhWHx
http://ift.tt/2slQNFF
Submitted July 21, 2017 at 10:10AM by bnchandrapal
via reddit http://ift.tt/2uFhWHx
Medium
Black Hat Arsenal USA 2017
On June 1, 2017 @toolswatch announced the tools selected for Black Hat Arsenal USA 2017.
Briar - Darknet Messenger Releases Beta, Passes Security Audit
http://ift.tt/2uPDCBg
Submitted July 21, 2017 at 08:02PM by tovok7
via reddit http://ift.tt/2gQeMew
http://ift.tt/2uPDCBg
Submitted July 21, 2017 at 08:02PM by tovok7
via reddit http://ift.tt/2gQeMew
briarproject.org
Briar - Darknet Messenger Releases Beta, Passes Security Audit
Secure messaging, anywhere
SickOS 1.2 Walkthrough - a CTF/Boot2Root VulnHub vm that I worked on while studying for the OSCP. Enjoy! 😊
http://ift.tt/2uJkggg
Submitted July 21, 2017 at 09:57PM by InfoSecJim
via reddit http://ift.tt/2uQ6klB
http://ift.tt/2uJkggg
Submitted July 21, 2017 at 09:57PM by InfoSecJim
via reddit http://ift.tt/2uQ6klB
Jim Wilbur's Blog
SickOS 1.2 Walkthrough - VulnHub
SickOS 1.2 Walkthrough - VulnHub - Boot2Root. Step by step walkthrough of SickOS 1.2 from Vulnhub.com created by D4rk.
KLEE 1.4 is now available
http://ift.tt/2uJcqDA
Submitted July 21, 2017 at 11:33PM by Fuzz_Stati0n
via reddit http://ift.tt/2uitfVi
http://ift.tt/2uJcqDA
Submitted July 21, 2017 at 11:33PM by Fuzz_Stati0n
via reddit http://ift.tt/2uitfVi
GitHub
klee/klee
klee - KLEE Symbolic Virtual Machine
Inject All the Things - DLL injection
http://ift.tt/2ujTdWD
Submitted July 22, 2017 at 02:25AM by muhh198
via reddit http://ift.tt/2txrCUN
http://ift.tt/2ujTdWD
Submitted July 22, 2017 at 02:25AM by muhh198
via reddit http://ift.tt/2txrCUN
blog.deniable.org
Inject All the Things - Shut Up and Hack
Well, its 2017 and I’m writing about DLL injection. It could be worse. DLL injection is a technique used by legitimate software to add/extend …
Free Daily Dark Web Reports - New Hidden Services Discovered, What's Up/Down
http://ift.tt/2gQN5SS
Submitted July 22, 2017 at 02:22AM by jms_dot_py
via reddit http://ift.tt/2tOt5BC
http://ift.tt/2gQN5SS
Submitted July 22, 2017 at 02:22AM by jms_dot_py
via reddit http://ift.tt/2tOt5BC
darkweb.hunch.ly
Daily Dark Web Monitoring Reports from Hunchly
Receive free daily dark web monitoring reports that tell you of any newly discovered Tor hidden services.
http://ift.tt/2uOkqnD
http://ift.tt/2uOkqnD
Submitted July 22, 2017 at 04:15AM by klrgrz
via reddit http://ift.tt/2gRoEVa
http://ift.tt/2uOkqnD
Submitted July 22, 2017 at 04:15AM by klrgrz
via reddit http://ift.tt/2gRoEVa
The Daily Beast
Putin’s Hackers Now Under Attack—From Microsoft
Microsoft is going after Fancy Bear, the Russian hacking group that targeted the DNC, by wresting control of domain names controlled by the foreign spies.
From PayPal Server's Unrestricted File Upload to RCE
http://ift.tt/2gRVEwO
Submitted July 22, 2017 at 10:59AM by rootsh3ll
via reddit http://ift.tt/2uS48Km
http://ift.tt/2gRVEwO
Submitted July 22, 2017 at 10:59AM by rootsh3ll
via reddit http://ift.tt/2uS48Km
Vikas Anil Sharma
How i Hacked into a PayPal's Server - Unrestricted File Upload to Remote Code Execution
Hello World, Hope you'll are doing well & i know you are reading this post after reading the post noscript , RCE in PayPal's server ? dafaq ? seriously ? Trust me the POC is piece of cake , Only thing is I was lucky enough to enumerate & find the domain vulnerable…
Twistlock 2.1 Container Security Suite Released
http://ift.tt/2vvj2TQ
Submitted July 22, 2017 at 07:51PM by talonx
via reddit http://ift.tt/2uT1a8s
http://ift.tt/2vvj2TQ
Submitted July 22, 2017 at 07:51PM by talonx
via reddit http://ift.tt/2uT1a8s
InfoQ
Twistlock 2.1 Container Security Suite Released
Twistlock announced the general availability of version 2.1 of their container security product. Highlights of the release include an integrated firewall that understands application traffic, vulnerability detection, secrets management via integration with…
How the ethereum hack was possible: An In-Depth Look at the Parity Multisig Bug
http://ift.tt/2gSwzBP
Submitted July 23, 2017 at 04:52PM by maxxori
via reddit http://ift.tt/2vNlapc
http://ift.tt/2gSwzBP
Submitted July 23, 2017 at 04:52PM by maxxori
via reddit http://ift.tt/2vNlapc
Hacking Distributed
An In-Depth Look at the Parity Multisig Bug
We do a deep-dive into Parity's multisig bug.
Frameworks needed for secure data collaboration – Nick Halstead – Medium
http://ift.tt/2u6FzVJ
Submitted July 23, 2017 at 05:43PM by milly1993
via reddit http://ift.tt/2uMAaqD
http://ift.tt/2u6FzVJ
Submitted July 23, 2017 at 05:43PM by milly1993
via reddit http://ift.tt/2uMAaqD
Medium
Frameworks needed for secure data collaboration
GDPR should be seen as a “call for changing how we view data” rather than a regulation, was one of the key assertions of the Data Privacy…