Practical Attacks with DNS Rebinding
https://ift.tt/2IucP09
Submitted April 04, 2018 at 02:49PM by nanooonanooo
via reddit https://ift.tt/2GPLYi5
https://ift.tt/2IucP09
Submitted April 04, 2018 at 02:49PM by nanooonanooo
via reddit https://ift.tt/2GPLYi5
The State of Security
Practical Attacks with DNS Rebinding
One of the tools I expect to see gain in popularity in the wild is DNS rebinding. DNS rebinding is a technique that turns a victim’s browser into a proxy.
WhatsApp Forensics: Decryption of Encrypted WhatsApp Databases on Non-Rooted Android Devices
https://ift.tt/2GQy5jD
Submitted April 04, 2018 at 04:02PM by TechLord2
via reddit https://ift.tt/2Itibsm
https://ift.tt/2GQy5jD
Submitted April 04, 2018 at 04:02PM by TechLord2
via reddit https://ift.tt/2Itibsm
Leveraging *.google.com domains to Obfuscate C2 Traffic via Domain Fronting
https://ift.tt/2GybgSk
Submitted April 04, 2018 at 03:49PM by karmicSec
via reddit https://ift.tt/2uHmqi6
https://ift.tt/2GybgSk
Submitted April 04, 2018 at 03:49PM by karmicSec
via reddit https://ift.tt/2uHmqi6
Holey Beep
https://ift.tt/2EgUIs2
Submitted April 04, 2018 at 05:01PM by netsec_burn
via reddit https://ift.tt/2GQI0pn
https://ift.tt/2EgUIs2
Submitted April 04, 2018 at 05:01PM by netsec_burn
via reddit https://ift.tt/2GQI0pn
holeybeep.ninja
Holey Beep
Holey Beep (CVE-2018-0492) is a very beepy bug.
Security In 5: Episode 209 - IoT Strikes Again - Most Devices Can Be Hacked Using Only Google
https://ift.tt/2GRLF6i
Submitted April 04, 2018 at 06:31PM by BinaryBlog
via reddit https://ift.tt/2Gy29wX
https://ift.tt/2GRLF6i
Submitted April 04, 2018 at 06:31PM by BinaryBlog
via reddit https://ift.tt/2Gy29wX
Libsyn
Security In Five Podcast: Episode 209 - IoT Strikes Again - Most Devices Can Be Hacked Using Only Google
IoT, the Internet of Things, is the thorn in my security side. The unregulated, uncertified, unreasonable devices with minimal to no security flooding our homes and child's toy boxes. This episode talks about how easy it is to hack and find these things,…
Russia attacked the US power grid for two years. Now, what can we do to strengthen our cybersecurity efforts?
https://ift.tt/2GuvaO9
Submitted April 04, 2018 at 07:08PM by fabsonaboat
via reddit https://ift.tt/2uKWX7H
https://ift.tt/2GuvaO9
Submitted April 04, 2018 at 07:08PM by fabsonaboat
via reddit https://ift.tt/2uKWX7H
www.realclearenergy.org
Russia Attacked the US Power Grid for Two Years. Now What? | RealClearEnergy
The Trump administration has accused Russia of a two-year cyberattack campaign against the U.S. electric grid. This is the first time the U.S. has openly accused Moscow of threatening Americas...
Microsoft emergency update patches critical remote code execution flaw in Malware Protection Engine
https://ift.tt/2H8RaLn
Submitted April 04, 2018 at 07:05PM by jonathancrowe
via reddit https://ift.tt/2q3HU3e
https://ift.tt/2H8RaLn
Submitted April 04, 2018 at 07:05PM by jonathancrowe
via reddit https://ift.tt/2q3HU3e
reddit
Microsoft emergency update patches critical remote code... • r/netsec
9 points and 0 comments so far on reddit
70% of VPN Chrome Extensions Leak Your DNS
https://ift.tt/2q44VUs
Submitted April 04, 2018 at 08:12PM by KingHeenrry
via reddit https://ift.tt/2q4kpHe
https://ift.tt/2q44VUs
Submitted April 04, 2018 at 08:12PM by KingHeenrry
via reddit https://ift.tt/2q4kpHe
TheBestVPN.com
70% of VPN Chrome Extensions Leak Your DNS | TheBestVPN.com
Update: Please note that this not a WebRTC leak. This involves DNS prefetching which is activated by default on all Chrome browsers. We’ve already informed some of the VPN providers about this issue and they’re in the middle of fixing this. If your VPN provider…
GPKI issued wildcard cert on *.co.kr (public suffix)
https://ift.tt/2GwW9Vm
Submitted April 04, 2018 at 08:47PM by perillamint
via reddit https://ift.tt/2q70GHG
https://ift.tt/2GwW9Vm
Submitted April 04, 2018 at 08:47PM by perillamint
via reddit https://ift.tt/2q70GHG
crt.sh
crt.sh | 8169164
Free CT Log Certificate Search Tool from COMODO
Stealing Credit Cards from FUZE via Bluetooth (CVE-2018-9119) with exploit and X-ray teardown
https://ift.tt/2uI8R1U
Submitted April 04, 2018 at 09:32PM by mpeg4codec
via reddit https://ift.tt/2q7ppvq
https://ift.tt/2uI8R1U
Submitted April 04, 2018 at 09:32PM by mpeg4codec
via reddit https://ift.tt/2q7ppvq
blog.ice9.us
Stealing Credit Cards from FUZE via Bluetooth
This article covers FUZE Card , a Bluetooth-enabled reprogrammable credit card. The size and shape of a regular credit card, FUZE promises t...
GPKI issued wildcard cert on *.co.kr (public suffix)
https://ift.tt/2GwW9Vm
Submitted April 04, 2018 at 09:23PM by perillamint
via reddit https://ift.tt/2qamzp1
https://ift.tt/2GwW9Vm
Submitted April 04, 2018 at 09:23PM by perillamint
via reddit https://ift.tt/2qamzp1
crt.sh
crt.sh | 8169164
Free CT Log Certificate Search Tool from COMODO
EXPAND YOUR HORIZON RED TEAM – MODERN SAAS C2
https://ift.tt/2CCGDZ9
Submitted April 04, 2018 at 07:02PM by pentest4life
via reddit https://ift.tt/2q6N8v9
https://ift.tt/2CCGDZ9
Submitted April 04, 2018 at 07:02PM by pentest4life
via reddit https://ift.tt/2q6N8v9
Cybersyndicates
Expand Your Horizon Red Team – Modern SaaS C2
Python WSGI C2
Free Virgin Atlantic tickets? No, it’s a WhatsApp scam
https://ift.tt/2EiTL2q
Submitted April 04, 2018 at 09:43PM by volci
via reddit https://ift.tt/2JkzM7a
https://ift.tt/2EiTL2q
Submitted April 04, 2018 at 09:43PM by volci
via reddit https://ift.tt/2JkzM7a
Naked Security
Free Virgin Atlantic tickets? No, it’s a WhatsApp scam
Two free tickets for every family? It sounds great! It has to be a scam.
Secure Your facebook account. Know about Facebook controversy? 50 Million users data compromised. Secure your facebook account from hackers, data harvesting companies.
https://www.youtube.com/watch?v=gE96uPi1P-g
Submitted April 04, 2018 at 09:40PM by hemantjoshi_in
via reddit https://ift.tt/2uQBEBI
https://www.youtube.com/watch?v=gE96uPi1P-g
Submitted April 04, 2018 at 09:40PM by hemantjoshi_in
via reddit https://ift.tt/2uQBEBI
YouTube
Secure your Facebook account
Learn how to Secure your facebook account. Learn how to do privacy checkup Configure Privacy Setting Timeline and Tagging How to Block users in Facebook Rest...
Dot-cm Typosquatting Sites Visited 12M Times So Far in 2018
https://ift.tt/2H7IogK
Submitted April 04, 2018 at 09:37PM by volci
via reddit https://ift.tt/2He5lzb
https://ift.tt/2H7IogK
Submitted April 04, 2018 at 09:37PM by volci
via reddit https://ift.tt/2He5lzb
reddit
Dot-cm Typosquatting Sites Visited 12M Times So Far... • r/security
1 points and 0 comments so far on reddit
Vulnerability Modeling with Binary Ninja
https://ift.tt/2q6bvZV
Submitted April 04, 2018 at 09:46PM by TechLord2
via reddit https://ift.tt/2q5VlQb
https://ift.tt/2q6bvZV
Submitted April 04, 2018 at 09:46PM by TechLord2
via reddit https://ift.tt/2q5VlQb
Trail of Bits Blog
Vulnerability Modeling with Binary Ninja
Plenty of static analyzers can perform vulnerability discovery on source code, but what if you only have the binary? How can we model a vulnerability and then check a binary to see if it is vulnera…
Windows Defender Unrar Vulnerability (SYSTEM RCE)
https://ift.tt/2GAGgNE
Submitted April 04, 2018 at 10:34PM by overflowingInt
via reddit https://ift.tt/2q5idjv
https://ift.tt/2GAGgNE
Submitted April 04, 2018 at 10:34PM by overflowingInt
via reddit https://ift.tt/2q5idjv
OpenSSH 7.7 (2018-04-03): ssh(1)/sshd(8): Drop compatibility support for some very old SSH implementations, released in or before 2001
https://ift.tt/2GDro0I
Submitted April 04, 2018 at 10:28PM by Mcnst
via reddit https://ift.tt/2q5v1ql
https://ift.tt/2GDro0I
Submitted April 04, 2018 at 10:28PM by Mcnst
via reddit https://ift.tt/2q5v1ql
Cisco Smart Install Remote Code Execution
https://ift.tt/2H9SXAd
Submitted April 04, 2018 at 10:22PM by overflowingInt
via reddit https://ift.tt/2GDwF8U
https://ift.tt/2H9SXAd
Submitted April 04, 2018 at 10:22PM by overflowingInt
via reddit https://ift.tt/2GDwF8U
Embedi
Cisco Smart Install Remote Code Execution
Introduction Application: Cisco IOS, Cisco IOS-XE Vendor: Cisco Bugs: Stack-based buffer overflow [CWE-20], [CWE-121] Risk: Critical; AV:N/AC:L/Au:N/C:C/I:C/A:C (10.0) A stack-based buffer overflow vulnerability was found in Smart Install Client code. This…
"Attacking an FTP Client: MGETting more than you bargained for"
https://ift.tt/2GxmCSE
Submitted April 04, 2018 at 10:43PM by root_trainingwheels
via reddit https://ift.tt/2HdzeQ4
https://ift.tt/2GxmCSE
Submitted April 04, 2018 at 10:43PM by root_trainingwheels
via reddit https://ift.tt/2HdzeQ4
snyk.io
Snyk - Attacking an FTP Client: MGETting more than you bargained for
Snyk identified and responsibly disclosed a directory traversal vulnerability found in FTP clients that connect to malicious servers. This post contains the full details of the vulnerability and what you can do to avoid it.
Intel won't ever patch Spectre variant 2 flaw in chips
https://ift.tt/2uHKBNi
Submitted April 05, 2018 at 12:32AM by hightechbridge
via reddit https://ift.tt/2q5iKlw
https://ift.tt/2uHKBNi
Submitted April 05, 2018 at 12:32AM by hightechbridge
via reddit https://ift.tt/2q5iKlw
ZDNet
Intel: We now won't ever patch Spectre variant 2 flaw in these chips | ZDNet
A handful of CPU families that Intel was due to patch will now forever remain vulnerable.