I hate the “secret questions”. I think it is appropriate to treat the answer to all such authentication systems as if it is a password. So use a random string for each answer and save that and the question in a protected file.
https://ift.tt/2H4VD4m
Submitted April 09, 2018 at 01:03PM by Majortom80
via reddit https://ift.tt/2qieIGw
https://ift.tt/2H4VD4m
Submitted April 09, 2018 at 01:03PM by Majortom80
via reddit https://ift.tt/2qieIGw
reddit
I hate the “secret questions”. I think it is... • r/security
1 points and 0 comments so far on reddit
An enterprise guide to ensuring IoT security
https://ift.tt/2IFurGH
Submitted April 09, 2018 at 04:30PM by Iot_Security
via reddit https://ift.tt/2JvGEih
https://ift.tt/2IFurGH
Submitted April 09, 2018 at 04:30PM by Iot_Security
via reddit https://ift.tt/2JvGEih
www.aiia.net
An enterprise guide to ensuring IoT security | AiiA
“Security of an Internet of Things (IoT) device will only get worse before it gets better,” says Yotam Gutman. However, organizations can act now with simple measures
The dots do matter: how to scam a Gmail user
https://ift.tt/2Et7weU
Submitted April 09, 2018 at 05:43PM by speckz
via reddit https://ift.tt/2JsYzGa
https://ift.tt/2Et7weU
Submitted April 09, 2018 at 05:43PM by speckz
via reddit https://ift.tt/2JsYzGa
jameshfisher.com
The dots do matter: how to scam a Gmail user
I recently received an email from Netflix which nearly caused caused me to add my card details to someone else’s Netflix account. Here I show that this is a new kind of phishing scam which is enabled by an obscure feature of Gmail called “the dots don’t matter”.…
Security In 5: Episode 212 - Panera Bread Breach - They Knew And Did Nothing.
https://ift.tt/2HmvwDw
Submitted April 09, 2018 at 06:34PM by BinaryBlog
via reddit https://ift.tt/2uY8e4F
https://ift.tt/2HmvwDw
Submitted April 09, 2018 at 06:34PM by BinaryBlog
via reddit https://ift.tt/2uY8e4F
Libsyn
Security In Five Podcast: Episode 212 - Panera Bread Breach - They Knew And Did Nothing.
If you shopped online with Panera Bread or did business through their catering arm chances are your data was compromised. Panera Bread's website had a gaping vulnerability that exposed millions of user's account information. The scary part is they were told…
Binance Hacker Bounty or how to Secure your Binance Account
https://ift.tt/2qjdaeO
Submitted April 09, 2018 at 06:24PM by CyberTemek
via reddit https://ift.tt/2HnXIWA
https://ift.tt/2qjdaeO
Submitted April 09, 2018 at 06:24PM by CyberTemek
via reddit https://ift.tt/2HnXIWA
Medium
Binance Hacker Bounty or how to Secure your Binance Account
Do you use cryptocurrency exchange no matter what type? How aware are you of the vulnerabilities of those platforms? Most of the exchanges…
CyberArk Password Vault Web Access Remote Code Execution
https://ift.tt/2GK2ahu
Submitted April 09, 2018 at 07:01PM by vysec
via reddit https://ift.tt/2qfP8SE
https://ift.tt/2GK2ahu
Submitted April 09, 2018 at 07:01PM by vysec
via reddit https://ift.tt/2qfP8SE
www.redteam-pentesting.de
CyberArk Password Vault Web Access Remote Code Execution
The CyberArk Password Vault Web Access application uses authentication tokens which consist of serialized .NET objects. By crafting manipulated tokens, attackers are able to gain unauthenticated...
Abusing CVE-2017-9506 to access internal services and hacking the Department of the Defense in the process
https://ift.tt/2IEmFMS
Submitted April 09, 2018 at 07:05PM by alyssathegryphon
via reddit https://ift.tt/2qmofvI
https://ift.tt/2IEmFMS
Submitted April 09, 2018 at 07:05PM by alyssathegryphon
via reddit https://ift.tt/2qmofvI
Medium
Piercing the Veil: Server Side Request Forgery to NIPRNet access
During my reconnaissance of military websites as part of the Department of Defense’s vulnerability disclosure, I noticed two particular…
Do not protect your website from scraping (part 1, technology barriers)
https://ift.tt/2qgjAMh
Submitted April 09, 2018 at 07:43PM by gajus0
via reddit https://ift.tt/2HbO4ZF
https://ift.tt/2qgjAMh
Submitted April 09, 2018 at 07:43PM by gajus0
via reddit https://ift.tt/2HbO4ZF
Medium
Do not protect your website from scraping (part 1, technology barriers)
Resistance is futile
DNS Market Share Analysis — Identifying the Most Popular DNS providers
https://ift.tt/2qfL7h3
Submitted April 09, 2018 at 08:07PM by nykzhang
via reddit https://ift.tt/2JvIoIh
https://ift.tt/2qfL7h3
Submitted April 09, 2018 at 08:07PM by nykzhang
via reddit https://ift.tt/2JvIoIh
Medium
DNS Market Share Analysis — Identifying the Most Popular DNS providers
There has never been so many DNS options for us to use right now. From Google's 8.8.8.8, to Quad9, OpenDNS, CloudFlare, CleanBrowsing or…
The Truth Hurts: "Cisco appears to be using their dominant position in vulnerability identification and disclosure to attack their competitors in the router equipment market."
https://ift.tt/2H0MMRj
Submitted April 09, 2018 at 08:18PM by EliteSpamSniper
via reddit https://ift.tt/2GJZC6T
https://ift.tt/2H0MMRj
Submitted April 09, 2018 at 08:18PM by EliteSpamSniper
via reddit https://ift.tt/2GJZC6T
Compromising OpenDrive's Cloud Storage Accounts – Or How Not to Design Session Management
https://ift.tt/2EwVLnY
Submitted April 09, 2018 at 08:16PM by rwestergren
via reddit https://ift.tt/2ql7elc
https://ift.tt/2EwVLnY
Submitted April 09, 2018 at 08:16PM by rwestergren
via reddit https://ift.tt/2ql7elc
Randy Westergren
Compromising OpenDrive's Cloud Storage Accounts – Or How Not to Design Session Management - Randy Westergren
While recently comparing cloud storage solutions, I was surprised to learn there are still companies offering unlimited storage plans. OpenDrive is one such company — not to be confused with the OpenDRIVE format specification — offering unlimited options…
RFD Checker - security CLI tool to test Reflected File Download issues
https://ift.tt/2GINbIw
Submitted April 09, 2018 at 08:55PM by s0pas
via reddit https://ift.tt/2qhuiBu
https://ift.tt/2GINbIw
Submitted April 09, 2018 at 08:55PM by s0pas
via reddit https://ift.tt/2qhuiBu
GitHub
dsopas/rfd-checker
rfd-checker - RFD Checker - security CLI tool to test Reflected File Download issues
Bitdefender vs Eset. Who will win?
https://ift.tt/2qiGamY
Submitted April 09, 2018 at 09:23PM by tomasstatkus
via reddit https://ift.tt/2GKpXlp
https://ift.tt/2qiGamY
Submitted April 09, 2018 at 09:23PM by tomasstatkus
via reddit https://ift.tt/2GKpXlp
Reviewedbypro
Bitdefender Total Security 2018 VS ESET Internet Security Premium 2018
An increasing number of malware targeting Windows devices are not a surprise. Today, consumers have to be aware of other cyber threats, hacks, identity thefts
The NVD by NIST misses a major amount of (critical) vulnerabilities.
https://ift.tt/2EIKuWD
Submitted April 09, 2018 at 09:32PM by PoweedL
via reddit https://ift.tt/2GKruYH
https://ift.tt/2EIKuWD
Submitted April 09, 2018 at 09:32PM by PoweedL
via reddit https://ift.tt/2GKruYH
BleepingComputer
Nearly 8,000 Security Flaws Did Not Receive a CVE ID in 2017
A record-breaking number of 20,832 vulnerabilities have been discovered in 2017 but only 12,932 of these received an official CVE identifier last year, a Risk Based Security (RBS) report reveals.
Cyberinsurance Tackles the Wildly Unpredictable World of Hacks
https://ift.tt/2GCcHPH
Submitted April 09, 2018 at 09:34PM by EvanConover
via reddit https://ift.tt/2GMOi6e
https://ift.tt/2GCcHPH
Submitted April 09, 2018 at 09:34PM by EvanConover
via reddit https://ift.tt/2GMOi6e
WIRED
Cyberinsurance Tackles the Wildly Unpredictable World of Hacks
Insuring against hacks and breaches can be a lucrative business—but also presents unique challenges.
Vegas Shooting researcher Mike Turber demonstrates flawless security audit by riding Steve Wynn's service elevator, debunking Wynn's claims about how secure his resort is
https://youtu.be/QxmvNnfTx7g
Submitted April 09, 2018 at 10:07PM by robert_brooks
via reddit https://ift.tt/2HkqTdf
https://youtu.be/QxmvNnfTx7g
Submitted April 09, 2018 at 10:07PM by robert_brooks
via reddit https://ift.tt/2HkqTdf
YouTube
Las Vegas Shooting Investigative Reporter Mike Turber takes Steve Wynn's security test challenge
After testing security at Mandalay Bay, and never getting caught or even approached by security there, Mike Turber sets his eyes on another hotel and casino,...
Cyberinsurance Tackles the Wildly Unpredictable World of Hacks
https://ift.tt/2GCcHPH
Submitted April 09, 2018 at 09:34PM by EvanConover
via reddit https://ift.tt/2GMOi6e
https://ift.tt/2GCcHPH
Submitted April 09, 2018 at 09:34PM by EvanConover
via reddit https://ift.tt/2GMOi6e
WIRED
Cyberinsurance Tackles the Wildly Unpredictable World of Hacks
Insuring against hacks and breaches can be a lucrative business—but also presents unique challenges.
Understanding and Evading Get-InjectedThread
https://ift.tt/2GNyUq7
Submitted April 09, 2018 at 11:20PM by xpnsecurity
via reddit https://ift.tt/2GO8KYo
https://ift.tt/2GNyUq7
Submitted April 09, 2018 at 11:20PM by xpnsecurity
via reddit https://ift.tt/2GO8KYo
XPN InfoSec Blog
Understanding and Evading Get-InjectedThread
One of the many areas of this field that I really enjoy is the "cat and mouse" game played between RedTeam and BlueTeam, each forcing the other to up their game. Often we see some awesome tools being released to help defenders detect malware or shellcode…
OK Google, How do I red team GSuite? - BSides Orlando Talk Slides
https://ift.tt/2GKIM3W
Submitted April 09, 2018 at 11:54PM by ustayready
via reddit https://ift.tt/2Hn79G0
https://ift.tt/2GKIM3W
Submitted April 09, 2018 at 11:54PM by ustayready
via reddit https://ift.tt/2Hn79G0
Certifications are mentioned quite frequently in this sub, so I thought this article might be useful. Not all certs are security related, but explanations of each one can be useful. Enjoy!
https://ift.tt/2zHtwot
Submitted April 10, 2018 at 12:25AM by techguru830
via reddit https://ift.tt/2qkMgmy
https://ift.tt/2zHtwot
Submitted April 10, 2018 at 12:25AM by techguru830
via reddit https://ift.tt/2qkMgmy
CIO
The 13 most valuable IT certifications today
Looking for a leg up in your IT career? IT certifications remain a proven way to quickly gain valuable skills and demonstrate deeper interest and know-how in a domain that will further your career.
Adding DNS-Over-TLS support to OpenWRT (LEDE) with Unbound
https://ift.tt/2qhZmBT
Submitted April 10, 2018 at 12:51AM by civicode
via reddit https://ift.tt/2qlRs9R
https://ift.tt/2qhZmBT
Submitted April 10, 2018 at 12:51AM by civicode
via reddit https://ift.tt/2qlRs9R
Cloudflare Blog
Privacy-Protecting Portable Router: Adding DNS-Over-TLS support to OpenWRT (LEDE) with Unbound
This blog post explains how you can configure an OpenWRT router to encrypt DNS traffic to Cloudflare Resolver using DNS-over-TLS.