Netsec – Telegram
Netsec
7.37K subscribers
22.3K links
This channel posts the feed from r/netsec.
For any suggestions dm @streaak
Donate to keep the bot running https://www.paypal.me/akhilgv
Download Telegram
"I too like to live dangerously", Accidentally Finding RCE in Signal Desktop via HTML Injection in Quoted Replies (CVE-2018-11101)
https://ift.tt/2rNVjx4

Submitted May 16, 2018 at 07:37PM by mandatoryprogrammer
via reddit https://ift.tt/2k2k5WZ
A detailed look at bugs in the Class_Terminate method of VBScript that allow code execution and have been seen in the wild.
https://ift.tt/2wItjRv

Submitted May 15, 2018 at 09:32PM by FloodleSnot
via reddit https://ift.tt/2Io0mzo
Apple TV Gen3 (Model# A1469) Security Patches?
Does anyone know if the Apple TV Gen 3 (Model# A1469) is still receiving security patches? I found the list of devices from Apple that determines the length of time before a device becomes vintage or obsolete, but it’s still unclear whether or not it’s receiving patches? It seems as though it’s been awhile since the last update was rolled out. Any info is appreciated. Thanks in advance!

Submitted May 17, 2018 at 04:06AM by pearlescentq
via reddit https://ift.tt/2IlHyB3
CloudScraper: Tool to scrape targets in search of cloud resources. AWS, Azure, Digital Ocean.
https://ift.tt/2rPxLZF

Submitted May 17, 2018 at 11:03AM by ok_bye_now_
via reddit https://ift.tt/2GpYTTC
Understanding the core of System Security
https://ift.tt/2k1MI6v

Submitted May 17, 2018 at 02:37PM by r0hi7
via reddit https://ift.tt/2KwckE1
Mac/BSD + Corporate Outlook/Exchange + p≡p (Pretty Easy Privacy) + GnuPG -- Is there a solution that doesn't cost €60 besides save-as, decrypt/verify?
The only thing I've found so far is gpg4o which is really expensive.I know that there is an open-source plugin for windows outlook available on GitHub called the Outlook Privacy Plugin, but it stresses that it doesn't work on any platform other than windows.Right now verification of my emails requires people to go through a PITA manual process of saving the attachments and then using the console gpg on them. That's just not a good way to get people to handle sensitive information well.My company offers a certificate, but it's shared and technically invalid. The other problem is that it's just not widely used outside of exchange, so it works fine for in-house but doesn't work well for anyone using gmail or outlook.com or yahoo mail or other sources. Also, AFAIK the certificate specifically uses S/MIME and I would really prefer PEP.Even the PEP foundation's open-source outlook plugin charges for the binary and obfuscates building the sources. I'd still try to build, except (again) it's Windows only.I'm feeling a bit like nobody wants secure email in outlook :-/note: I use a custom IMAP thunderbird client for my own email and have no issues using either PEP or s/mime with enigmail. Some messages are actually stipulated in my employment agreement to go through the corporate email. The rare cases when I need a signature or encryption and I must use my corporate mail are where the PITA happens.

Submitted May 17, 2018 at 07:51PM by skyleach
via reddit https://ift.tt/2GqD2eE