Netsec – Telegram
Netsec
7.36K subscribers
22.3K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
Reviewing Android Webviews fileAccess attack vectors.
https://ift.tt/2IKRBz7

Submitted May 15, 2018 at 03:37PM by clviper
via reddit https://ift.tt/2IjHFZF
Is there a CloudGen firewall that also have WAF features?
Hi, please excuse me for any technical mistake, I am a novice in terms of security.We are hosting an infrastructure on the cloud that contains multiple machines and a web application. Is there any CloudGen firewall that also could monitor and block threats coming on the web application? We also would like to have the less expensive one that covers everything we need.This should contain those features:SQL injection protectionCross site noscripting protectionCommon Web Attacks Protection such as command injection, HTTP request smuggling, HTTP response splitting, and remote file inclusion attackProtection against HTTP protocol violationsProtection against HTTP protocol anomalies such as missing host user-agent and accept headersPrevention against bots, crawlers, and scannersDetection of common application misconfigurations (for example, Apache, IIS, and so on.)Also OWASP protection.Thank you.

Submitted May 15, 2018 at 05:16PM by Gretyzdee
via reddit https://ift.tt/2L4917V
Facebook Hack Shows It’s Time to Upgrade Our Method of Verifying Identity
https://ift.tt/292LeDh

Submitted May 15, 2018 at 08:26PM by dengorilla1
via reddit https://ift.tt/2GiExLH
Nethammer: Inducing Rowhammer Faults through Network Requests
https://ift.tt/2KXyuzP

Submitted May 15, 2018 at 09:12PM by albinowax
via reddit https://ift.tt/2ImdJA4
Dan Guido on Efail Vulnerability: "As an attacker, I could not care less about this technique. It's intellectually neat, but operationally stupid."
https://ift.tt/2KmxhB2

Submitted May 15, 2018 at 10:48PM by Derbel__McDillet
via reddit https://ift.tt/2L05CqC
Is there any way a HTTPS proxy can forward traffic without decryption?
Normally a HTTPS proxy decrypts the traffic and re-encrypts it. It basically sees all traffic unencrypted.Is there any web standard or proxy software that forwards HTTPS handshake and does not decrypt the traffic?

Submitted May 15, 2018 at 11:49PM by kickass_turing
via reddit https://ift.tt/2ImWivl
Sending Inaudible Commands to Voice Assistants. In the wrong hands, the technology could be used to unlock doors, wire money or buy stuff online ­-- simply with music playing over the radio
https://ift.tt/2jZvHtU

Submitted May 16, 2018 at 12:36AM by magenta_placenta
via reddit https://ift.tt/2Gkj2tX
Linux Random Number Generator: A New Approach - Stephan Müller
https://ift.tt/1U8fgIt

Submitted May 16, 2018 at 01:01AM by rain5
via reddit https://ift.tt/2L1LTHa
Vote on your favorite incident response playbook
We recently held an incident response playbook contest on SecOps Hub. It's now time to vote on your favorite. These playbooks cover topics such as malware, ransomware, Crit/high event monitoring, and automating WildFire responses.Visit the community to vote today! https://www.secopshub.com/t/show-off-your-security-expertise-join-our-community-driven-contest/263/8

Submitted May 16, 2018 at 01:20AM by SecOpsHub
via reddit https://ift.tt/2L11bvM
315 Red Team Tips
https://ift.tt/2Il19kP

Submitted May 16, 2018 at 03:30AM by piedpiperpivot
via reddit https://ift.tt/2wJG4uT