315 Red Team Tips
https://ift.tt/2Il19kP
Submitted May 16, 2018 at 03:30AM by piedpiperpivot
via reddit https://ift.tt/2wJG4uT
https://ift.tt/2Il19kP
Submitted May 16, 2018 at 03:30AM by piedpiperpivot
via reddit https://ift.tt/2wJG4uT
Vincent Yiu
Red Team Tips
Red Team Tips by Vincent Yiu (@vysecurity).
Security policies applied by the employer/institution after linking Exchange/Office365 account
Hello everyone!I don't know if this is the right place to consult for this as it's a question geared towards the Windows platform.Whenever I wanted to sync my university email with the stock Android email app, it would pop out with a dialog that said that the account would become an administrator on my phone which basically could do as it liked remotely so that was always a deal breaker for me and I would check my email through the browser or third-party apps on my phone.This wasn't the case for the default mail app on the Windows 10, at least I hadn't noticed before. After not having used the app with any account for a long time and the OS itself receiving many updates such the Creator's I decided to set up all my mailboxes again on the default "Mail" app. This time, however, while linking the university's mailbox it said something along the lines of "setting company policies, please wait" very briefly. Now, this is the same account that wanted to be able to wipe out my phone remotely without notice which is an Office365 service that my university uses. Looking into what I could find, the result were vague.Thanks Microsoft! You could just tell me, y'know.I don't know how to go about finding the repercussions of what this has done and something tells me that simply removing the email account won't change anything. Any help would be appreciated, many thanks!
Submitted May 16, 2018 at 03:08AM by Ere-Eye
via reddit https://ift.tt/2Ihf9vM
Hello everyone!I don't know if this is the right place to consult for this as it's a question geared towards the Windows platform.Whenever I wanted to sync my university email with the stock Android email app, it would pop out with a dialog that said that the account would become an administrator on my phone which basically could do as it liked remotely so that was always a deal breaker for me and I would check my email through the browser or third-party apps on my phone.This wasn't the case for the default mail app on the Windows 10, at least I hadn't noticed before. After not having used the app with any account for a long time and the OS itself receiving many updates such the Creator's I decided to set up all my mailboxes again on the default "Mail" app. This time, however, while linking the university's mailbox it said something along the lines of "setting company policies, please wait" very briefly. Now, this is the same account that wanted to be able to wipe out my phone remotely without notice which is an Office365 service that my university uses. Looking into what I could find, the result were vague.Thanks Microsoft! You could just tell me, y'know.I don't know how to go about finding the repercussions of what this has done and something tells me that simply removing the email account won't change anything. Any help would be appreciated, many thanks!
Submitted May 16, 2018 at 03:08AM by Ere-Eye
via reddit https://ift.tt/2Ihf9vM
The HTTP headers we don't want
https://ift.tt/2rxDLWO
Submitted May 16, 2018 at 05:42AM by rmddos
via reddit https://ift.tt/2IrklcM
https://ift.tt/2rxDLWO
Submitted May 16, 2018 at 05:42AM by rmddos
via reddit https://ift.tt/2IrklcM
DHCP Client Code Execution Vulnerability - CVE-2018-1111
https://ift.tt/2rJjRaA
Submitted May 16, 2018 at 08:10AM by Gallus
via reddit https://ift.tt/2rKlvK0
https://ift.tt/2rJjRaA
Submitted May 16, 2018 at 08:10AM by Gallus
via reddit https://ift.tt/2rKlvK0
reddit
r/netsec - DHCP Client Code Execution Vulnerability - CVE-2018-1111
4 votes and 1 so far on reddit
Opportunity: Cybersecurity @ Siemens
Are you passionate about cybersecurity and want to make immediate difference in a global conglomerate? How about learning how to be a better leader and better anticipating risks while building your technical skillset?If you’re up to the challenge then let’s get started! Let’s be awesome! Send me a message.*Must be authorized to work in the US based at least 2 - 5 years of pentesting experience.
Submitted May 16, 2018 at 08:15AM by xpeditor
via reddit https://ift.tt/2Is9LSR
Are you passionate about cybersecurity and want to make immediate difference in a global conglomerate? How about learning how to be a better leader and better anticipating risks while building your technical skillset?If you’re up to the challenge then let’s get started! Let’s be awesome! Send me a message.*Must be authorized to work in the US based at least 2 - 5 years of pentesting experience.
Submitted May 16, 2018 at 08:15AM by xpeditor
via reddit https://ift.tt/2Is9LSR
reddit
r/security - Opportunity: Cybersecurity @ Siemens
1 votes and 0 so far on reddit
Another breach due to admin:admin user/pass combination
https://ift.tt/2rFuwmE
Submitted May 16, 2018 at 12:23PM by Majortom80
via reddit https://ift.tt/2KscDPZ
https://ift.tt/2rFuwmE
Submitted May 16, 2018 at 12:23PM by Majortom80
via reddit https://ift.tt/2KscDPZ
Naked Security
2 million lines of source code left exposed by phone company EE
What should be secret AWS and API keys were (un)secured with the default password credentials: “admin” as the name, “admin” for a password.
cyber attacks on the power grid may not happen the way we expect. Instead of one big cataclysmic event, they can manifest in a subtler manner, utilizing numerous smaller IoT devices but with severe consequences.
https://ift.tt/2wOLCob
Submitted May 16, 2018 at 11:56AM by Iot_Security
via reddit https://ift.tt/2KrDDiw
https://ift.tt/2wOLCob
Submitted May 16, 2018 at 11:56AM by Iot_Security
via reddit https://ift.tt/2KrDDiw
reddit
cyber attacks on the power grid may not happen the... • r/security
1 points and 0 comments so far on reddit
Plugbounty – The Bug Bounty Platform for Plugins & Extensions - Cybrary 0p3n
https://ift.tt/2IorhqQ
Submitted May 16, 2018 at 02:37PM by ded1cated
via reddit https://ift.tt/2IL7pSd
https://ift.tt/2IorhqQ
Submitted May 16, 2018 at 02:37PM by ded1cated
via reddit https://ift.tt/2IL7pSd
Cybrary
Plugbounty - The Bug Bounty Platform for Plugins & Extensions - Cybrary
As a researcher, I’ve been doing responsive disclosures for some time and for the last couple of years my focus has been on CMS security. There are so many Plugins and Extensions which usually can’t be applied to bigger bug-bounty platforms, but the risk…
How do we Stop Spilling the Beans Across Origins?
https://ift.tt/2wJsEit
Submitted May 16, 2018 at 02:19PM by albinowax
via reddit https://ift.tt/2rKBmYT
https://ift.tt/2wJsEit
Submitted May 16, 2018 at 02:19PM by albinowax
via reddit https://ift.tt/2rKBmYT
DHCP Client Script Code Execution Vulnerability in Red Hat Enterprise Linux 6 and 7 - CVE-2018-1111
https://ift.tt/2rJjRaA
Submitted May 16, 2018 at 04:06PM by Prav123
via reddit https://ift.tt/2IoHn7O
https://ift.tt/2rJjRaA
Submitted May 16, 2018 at 04:06PM by Prav123
via reddit https://ift.tt/2IoHn7O
reddit
DHCP Client Script Code Execution Vulnerability in Red... • r/netsec
9 points and 2 comments so far on reddit
pwn910nd - abusing OpenWRT's printer server to become root - CVE-2018-10123
https://ift.tt/2InJuVC
Submitted May 16, 2018 at 05:28PM by AVERAGE_TEST_DUMMY
via reddit https://ift.tt/2IKUvDK
https://ift.tt/2InJuVC
Submitted May 16, 2018 at 05:28PM by AVERAGE_TEST_DUMMY
via reddit https://ift.tt/2IKUvDK
neonsea.uk
pwn910nd - abusing OpenWRT's printer server to become root
I have discovered yet another vulnerability in Inteno’s IOPSYS firmware - but I believe this to affect all OpenWRT or LEDE based routers that ship with the p...
Lateral Movement – WinRM
https://ift.tt/2IhIGWd
Submitted May 16, 2018 at 05:27PM by TheUglyStranger
via reddit https://ift.tt/2IoMFME
https://ift.tt/2IhIGWd
Submitted May 16, 2018 at 05:27PM by TheUglyStranger
via reddit https://ift.tt/2IoMFME
Penetration Testing Lab
Lateral Movement – WinRM
WinRM stands for Windows Remote Management and is a service that allows administrators to perform management tasks on systems remotely. Communication is performed via HTTP (5985) or HTTPS SOAP (598…
Adobe Reader zero-day discovered alongside Windows vulnerability - Malwarebytes Labs
https://ift.tt/2rM2MwC
Submitted May 16, 2018 at 05:04PM by PeterG45
via reddit https://ift.tt/2KrVndB
https://ift.tt/2rM2MwC
Submitted May 16, 2018 at 05:04PM by PeterG45
via reddit https://ift.tt/2KrVndB
Malwarebytes Labs
Adobe Reader zero-day discovered alongside Windows vulnerability - Malwarebytes Labs
A new Adobe Reader zero-day exploit has been discovered, including a full sandbox escape.
Residential Locksmiths
Leading Residential Locksmiths, yes we do provide an quality Residential Locksmiths Service in Melbourne to get you inside of your house in no time in case of any emergency. Call 03 4444 2495.
Submitted May 16, 2018 at 05:54PM by EmergencyLocksmithsM
via reddit https://ift.tt/2rN9PFt
Leading Residential Locksmiths, yes we do provide an quality Residential Locksmiths Service in Melbourne to get you inside of your house in no time in case of any emergency. Call 03 4444 2495.
Submitted May 16, 2018 at 05:54PM by EmergencyLocksmithsM
via reddit https://ift.tt/2rN9PFt
Locksmith Melbourne
Residential Locksmiths Services Melbourne - Call 03 4444 2495
We provide an quality Residential Locksmiths Service in Melbourne to get you inside of your house in no time in case of any emergency. Call 03 4444 2495.
Residential Locksmiths
https://ift.tt/2IiGVbg
Submitted May 16, 2018 at 05:43PM by EmergencyLocksmithsM
via reddit https://ift.tt/2rNNhnZ
https://ift.tt/2IiGVbg
Submitted May 16, 2018 at 05:43PM by EmergencyLocksmithsM
via reddit https://ift.tt/2rNNhnZ
Phishing Spy Campaign Targets Top Mideast Officials
https://ift.tt/2IHBqm6
Submitted May 16, 2018 at 05:28PM by LindseyOD123
via reddit https://ift.tt/2L6kvrt
https://ift.tt/2IHBqm6
Submitted May 16, 2018 at 05:28PM by LindseyOD123
via reddit https://ift.tt/2L6kvrt
Threatpost | The first stop for security news
Phishing Spy Campaign Targets Top Mideast Officials
Researchers have discovered a phishing campaign that infected Android devices with custom surveillance-ware bent on extracting data from top officials, primarily in the Middle East.Researchers at
DNS Protection Services April 2018 Tests
https://ift.tt/2L5DDG1
Submitted May 16, 2018 at 05:51PM by redsedit
via reddit https://ift.tt/2wLmVc0
https://ift.tt/2L5DDG1
Submitted May 16, 2018 at 05:51PM by redsedit
via reddit https://ift.tt/2wLmVc0
Automotive Locksmiths
Best Automotive Locksmiths Near You! Yes we provide an quality Automotive Locksmiths Service in Melbourne to get you inside of your Car in no time. In case of any emergency, Call 03 4444 2495.
Submitted May 16, 2018 at 06:18PM by EmergencyLocksmithsM
via reddit https://ift.tt/2rR2ztd
Best Automotive Locksmiths Near You! Yes we provide an quality Automotive Locksmiths Service in Melbourne to get you inside of your Car in no time. In case of any emergency, Call 03 4444 2495.
Submitted May 16, 2018 at 06:18PM by EmergencyLocksmithsM
via reddit https://ift.tt/2rR2ztd
Locksmith Melbourne
Automotive Locksmiths Services Melbourne - Call 03 4444 2495
We provide an quality Automotive Locksmiths Service in Melbourne to get you inside of your Car in no time. In case of any emergency, Call 03 4444 2495.
Commercial Locksmiths
Qualified Commercial Locksmiths, yes we offer Commercial Locksmiths services in Melbourne that offer affordable rates without compromising the quality. Give us a call at 03 4444 2495.
Submitted May 16, 2018 at 06:07PM by EmergencyLocksmithsM
via reddit https://ift.tt/2KqzSdq
Qualified Commercial Locksmiths, yes we offer Commercial Locksmiths services in Melbourne that offer affordable rates without compromising the quality. Give us a call at 03 4444 2495.
Submitted May 16, 2018 at 06:07PM by EmergencyLocksmithsM
via reddit https://ift.tt/2KqzSdq
Locksmith Melbourne
Qualified Commercial Locksmiths Melbourne – Call 03 4444 2495
We offer Commercial Locksmiths services in Melbourne that offer affordable rates without compromising the quality. Give us a call at 03 4444 2495.
New DDoS Attack Method Demands a Fresh Approach to Amplification Assault Mitigation
https://ift.tt/2Is0LNr
Submitted May 16, 2018 at 06:39PM by whitehattracker
via reddit https://ift.tt/2k1POYs
https://ift.tt/2Is0LNr
Submitted May 16, 2018 at 06:39PM by whitehattracker
via reddit https://ift.tt/2k1POYs
reddit
r/security - New DDoS Attack Method Demands a Fresh Approach to Amplification Assault Mitigation
1 votes and 0 so far on reddit
Security In 5: Episode 239 - Firefox 60 Makes A Push For Enterprise Deployments
https://ift.tt/2IshW1c
Submitted May 16, 2018 at 06:35PM by BinaryBlog
via reddit https://ift.tt/2INJ0LR
https://ift.tt/2IshW1c
Submitted May 16, 2018 at 06:35PM by BinaryBlog
via reddit https://ift.tt/2INJ0LR
Libsyn
Security In Five Podcast: Episode 239 - Firefox 60 Makes A Push For Enterprise Deployments
Mozilla is making sure that Firefox is a valid option for full browser switching. The big gap with the top browsers, outside of Internet Explorer/Edge, is in the large Enterprise deployments and controlling the configurations on thousands of computers. The…