Your website needs a Content Security Policy. Here's why
https://ift.tt/2IuC2HL
Submitted April 05, 2018 at 08:07PM by deblona
via reddit https://ift.tt/2Jnb5XS
https://ift.tt/2IuC2HL
Submitted April 05, 2018 at 08:07PM by deblona
via reddit https://ift.tt/2Jnb5XS
The new, easy to use tool to finding subdomains for open source intelligence and pentest
https://ift.tt/2q9WEOT
Submitted April 05, 2018 at 09:46PM by xrna
via reddit https://ift.tt/2uRz5iJ
https://ift.tt/2q9WEOT
Submitted April 05, 2018 at 09:46PM by xrna
via reddit https://ift.tt/2uRz5iJ
Cyber Sins Security Blog
Finding subdomains for open source intelligence and pentest
Many of us are in the security consulting business, or bug bounties, or even network intelligence and have now and then come across a need to find subdomains. The requirement can be from either side of the table - a consultant assessing a client's internet…
Scammers abused Facebook phone number search - Facebook has discovered that "malicious actors" have been harvesting profiles for years by abusing its phone number and email search facility.
https://ift.tt/2Elhb7t
Submitted April 05, 2018 at 09:40PM by GayQuiz
via reddit https://ift.tt/2GB9ShR
https://ift.tt/2Elhb7t
Submitted April 05, 2018 at 09:40PM by GayQuiz
via reddit https://ift.tt/2GB9ShR
BBC News
Scammers abused Facebook phone number search
The company was warned by security researchers that the search tool could be abused.
This new tool is easy to use in finding subdomains for open source intelligence and pentest
https://ift.tt/2q9WEOT
Submitted April 05, 2018 at 10:06PM by xrna
via reddit https://ift.tt/2ElU4K1
https://ift.tt/2q9WEOT
Submitted April 05, 2018 at 10:06PM by xrna
via reddit https://ift.tt/2ElU4K1
Cyber Sins Security Blog
Finding subdomains for open source intelligence and pentest
Many of us are in the security consulting business, or bug bounties, or even network intelligence and have now and then come across a need to find subdomains. The requirement can be from either side of the table - a consultant assessing a client's internet…
Reverse engineering Dofoil/SmokeLoader
https://ift.tt/2GAVTbW
Submitted April 05, 2018 at 10:11PM by ohjeongwook
via reddit https://ift.tt/2GzOR2X
https://ift.tt/2GAVTbW
Submitted April 05, 2018 at 10:11PM by ohjeongwook
via reddit https://ift.tt/2GzOR2X
Microsoft
Hunting down Dofoil with Windows Defender ATP
Dofoil is a sophisticated threat that attempted to install coin miner malware on hundreds of thousands of computers in March, 2018. In previous blog posts we detailed how behavior monitoring and machine learning in Windows Defender AV protected customers…
Fake Software Update Abuses NetSupport Remote Access Tool
https://ift.tt/2qbKYKu
Submitted April 05, 2018 at 09:57PM by TechLord2
via reddit https://ift.tt/2GUtiOd
https://ift.tt/2qbKYKu
Submitted April 05, 2018 at 09:57PM by TechLord2
via reddit https://ift.tt/2GUtiOd
FireEye
Fake Software Update Abuses NetSupport Remote Access Tool « Fake Software Update Abuses NetSupport Remote Access Tool
FireEye is tracking an in-the-wild campaign that leverages compromised sites to spread fake updates, and sometimes NetSupport Manager remote access tool is the payload.
Oracle E-Business Suite security testing solution
https://ift.tt/2IwHw50
Submitted April 05, 2018 at 11:46PM by q123asa1
via reddit https://ift.tt/2JiMwex
https://ift.tt/2IwHw50
Submitted April 05, 2018 at 11:46PM by q123asa1
via reddit https://ift.tt/2JiMwex
New macOS Backdoor Linked to Cyber-espionage Group
https://ift.tt/2Emy9lY
Submitted April 05, 2018 at 11:06PM by Horus_Sirius
via reddit https://ift.tt/2GAmcPs
https://ift.tt/2Emy9lY
Submitted April 05, 2018 at 11:06PM by Horus_Sirius
via reddit https://ift.tt/2GAmcPs
TSecurity Portal
New macOS Backdoor Linked to Cyber-espionage Group
Check to see if your browser (and, possibly, your VPN) is leaking IPs via WebRTC data
https://ip.voidsec.com/
Submitted April 06, 2018 at 12:03AM by volci
via reddit https://ift.tt/2HbWb67
https://ip.voidsec.com/
Submitted April 06, 2018 at 12:03AM by volci
via reddit https://ift.tt/2HbWb67
reddit
Check to see if your browser (and, possibly, your... • r/security
1 points and 0 comments so far on reddit
CORS Findings: Another Way to Comprehend
https://ift.tt/2IjQSRe
Submitted April 06, 2018 at 12:18AM by albinowax
via reddit https://ift.tt/2H0Yk74
https://ift.tt/2IjQSRe
Submitted April 06, 2018 at 12:18AM by albinowax
via reddit https://ift.tt/2H0Yk74
TrustedSec
CORS Findings: Another Way to Comprehend - TrustedSec
by Ryan Leese When I first started learning about Cross Origin Resource Sharing (CORS) as it applies to web application pentesting, I found it was difficult to gather information needed to fully grasp the security implications of common CORS misconfigurations.…
Dynamic analysis of android applications using inspeckage
https://ift.tt/2GBMb90
Submitted April 04, 2018 at 10:49PM by Oxf0xtr0t
via reddit https://ift.tt/2IvlOhI
https://ift.tt/2GBMb90
Submitted April 04, 2018 at 10:49PM by Oxf0xtr0t
via reddit https://ift.tt/2IvlOhI
0x11sec.blogspot.co.uk
Inspeckage : Dynamic Assessment Tool for Android
If you are pen-testing android application, you will need to monitor/check many things at the same time. While doing dynamic analysis, ...
VirusTotal launches 'Droidy' sandbox to detect malicious Android apps
https://ift.tt/2GDCsz5
Submitted April 06, 2018 at 01:06AM by Horus_Sirius
via reddit https://ift.tt/2EnIf5N
https://ift.tt/2GDCsz5
Submitted April 06, 2018 at 01:06AM by Horus_Sirius
via reddit https://ift.tt/2EnIf5N
TSecurity Portal
VirusTotal launches 'Droidy' sandbox to detect malicious Android apps
How to locate Security Services In Hammersmith
https://ift.tt/2EovNCS
Submitted April 06, 2018 at 04:46AM by cctvman68
via reddit https://ift.tt/2H1mcas
https://ift.tt/2EovNCS
Submitted April 06, 2018 at 04:46AM by cctvman68
via reddit https://ift.tt/2H1mcas
How to locate Security Services In Hammersmith
https://ift.tt/2H0udwv
Submitted April 06, 2018 at 04:33AM by alarmpro42
via reddit https://ift.tt/2IxcVUW
https://ift.tt/2H0udwv
Submitted April 06, 2018 at 04:33AM by alarmpro42
via reddit https://ift.tt/2IxcVUW
SportSpyder.com
safetywiz56's Fan Profile
The best online source for sports news articles from around the web.
New to this sub, any physical security installers or engineers hang out here?
I work for a security integrator and I enjoy talking security, answering and asking questions and sharing ideas. Its how we get better. I was thinking about a solution tonight and I wondered if Reddit had a sub for this so I'm here.
Submitted April 06, 2018 at 07:19AM by Megaseth
via reddit https://ift.tt/2HbVklK
I work for a security integrator and I enjoy talking security, answering and asking questions and sharing ideas. Its how we get better. I was thinking about a solution tonight and I wondered if Reddit had a sub for this so I'm here.
Submitted April 06, 2018 at 07:19AM by Megaseth
via reddit https://ift.tt/2HbVklK
reddit
New to this sub, any physical security installers or... • r/security
I work for a security integrator and I enjoy talking security, answering and asking questions and sharing ideas. Its how we get better. I was...
Bootable & Encrypted Win7/10 USB drive?
I need to create a bootable Win7 or Win10 on an encrypted USB flash drive. I understand/expect the bootloader on the USB would have to remain unencrypted, but the rest of it, hopefully, would be encrypted. Is there a way to do this? Thanks!
Submitted April 06, 2018 at 09:37AM by zot2007
via reddit https://ift.tt/2qbkUPI
I need to create a bootable Win7 or Win10 on an encrypted USB flash drive. I understand/expect the bootloader on the USB would have to remain unencrypted, but the rest of it, hopefully, would be encrypted. Is there a way to do this? Thanks!
Submitted April 06, 2018 at 09:37AM by zot2007
via reddit https://ift.tt/2qbkUPI
reddit
Bootable & Encrypted Win7/10 USB drive? • r/security
I need to create a bootable Win7 or Win10 on an encrypted USB flash drive. I understand/expect the bootloader on the USB would have to remain...
8 Important Tips to Fight Against CyberBullying
https://ift.tt/2HhFdU0
Submitted April 06, 2018 at 10:45AM by JohnnyDoran
via reddit https://ift.tt/2GD6TFT
https://ift.tt/2HhFdU0
Submitted April 06, 2018 at 10:45AM by JohnnyDoran
via reddit https://ift.tt/2GD6TFT
The Next Scoop
8 Important Tips to Fight Against CyberBullying - The Next Scoop
Whenever we talk about data security – the first thing, which comes to our minds, is the protection of our data and all the important information that our website possess. With this note, we all know that we are living in the world of digitization and almost…
Week 14 in Information Security, 2018
https://ift.tt/2GBpRMV
Submitted April 06, 2018 at 11:30AM by undercomm
via reddit https://ift.tt/2q8Kl4H
https://ift.tt/2GBpRMV
Submitted April 06, 2018 at 11:30AM by undercomm
via reddit https://ift.tt/2q8Kl4H
Malgregator
InfoSec Week 14, 2018
There is a critical flaw in Microsoft Malware Protection Engine (CVE-2018-0986). They have used the open source unrar code, changed all...
Introducing FindSubDomains, a new subdomain enumeration and information gathering tool
https://ift.tt/2HdtQwa
Submitted April 06, 2018 at 01:16PM by xrna
via reddit https://ift.tt/2GGyvpz
https://ift.tt/2HdtQwa
Submitted April 06, 2018 at 01:16PM by xrna
via reddit https://ift.tt/2GGyvpz
Github users make commits with sensitive data!
https://ift.tt/2GU4xSj
Submitted April 06, 2018 at 02:17PM by maratmkhitaryan
via reddit https://ift.tt/2Jlo5x0
https://ift.tt/2GU4xSj
Submitted April 06, 2018 at 02:17PM by maratmkhitaryan
via reddit https://ift.tt/2Jlo5x0
Livejournal
Тупые Django юзеры + Github = халявные аккаунты почты
В Django есть файл setting.py, который отвечает за настройки разных вещей, в нашем случае интерес представляет конфигурация SMTP, вот его пример: EMAIL_HOST_USER = "vasya@pypkin.ru" EMAIL_HOST_PASSWORD = "qwerty" В Github можно искать просто искать EMAIL_HOST_PASSWORD…
On-site Request Forgery
https://ift.tt/2uW594K
Submitted April 06, 2018 at 02:04PM by 1lastBr3ath
via reddit https://ift.tt/2GGFFKa
https://ift.tt/2uW594K
Submitted April 06, 2018 at 02:04PM by 1lastBr3ath
via reddit https://ift.tt/2GGFFKa