CloudScraper: Tool to scrape targets in search of cloud resources. AWS, Azure, Digital Ocean.
https://ift.tt/2rPxLZF
Submitted May 17, 2018 at 11:03AM by ok_bye_now_
via reddit https://ift.tt/2GpYTTC
https://ift.tt/2rPxLZF
Submitted May 17, 2018 at 11:03AM by ok_bye_now_
via reddit https://ift.tt/2GpYTTC
GitHub
jordanpotti/CloudScraper
CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.
Best Planning & Architectural Services in Chandigarh
https://ift.tt/2rPZoRD
Submitted May 17, 2018 at 11:35AM by akdesignss
via reddit https://ift.tt/2k1JoIE
https://ift.tt/2rPZoRD
Submitted May 17, 2018 at 11:35AM by akdesignss
via reddit https://ift.tt/2k1JoIE
Akcreativatorss
Best Planning & Architectural Services in Chandigarh| AK Designs
Best Planning & Architectural Services in Chandigarh provides by AK Designs and Creativatorss. Top Interior designer have provided planning and architecture for small projects and renovations to the architecture and construction of large businesses and new…
Understanding the core of System Security
https://ift.tt/2k1MI6v
Submitted May 17, 2018 at 02:37PM by r0hi7
via reddit https://ift.tt/2KwckE1
https://ift.tt/2k1MI6v
Submitted May 17, 2018 at 02:37PM by r0hi7
via reddit https://ift.tt/2KwckE1
GitHub
r0hi7/BinExp
BinExp - Linux Binary Exploitation
Eavesdropping Devices Found in Restaurant
https://ift.tt/2rLDtf1
Submitted May 17, 2018 at 02:12PM by QCCGlobal
via reddit https://ift.tt/2k2pwFf
https://ift.tt/2rLDtf1
Submitted May 17, 2018 at 02:12PM by QCCGlobal
via reddit https://ift.tt/2k2pwFf
QCC Global
Eavesdropping Devices Found in Restaurant - QCC Global
Police investigators believe two eavesdropping devices found inside a Europort restaurant placed on the underside of a table, could be related to comparable bugging cases in 2014 that targeted financial executives and prominent lawyers. Past Devices The two…
Artists hacks multiple surveillance cameras worldwide, presents a series of landscape photographs
https://ift.tt/2GmbDuv
Submitted May 17, 2018 at 03:11PM by Iot_Security
via reddit https://ift.tt/2IsYYvK
https://ift.tt/2GmbDuv
Submitted May 17, 2018 at 03:11PM by Iot_Security
via reddit https://ift.tt/2IsYYvK
British Journal of Photography
Marcus DeSieno records the No Man's Land of surveillance cameras worldwide
Hacking into the live feed of a CCTV camera is “shockingly easy” says Marcus DeSieno, whose new book, No Man's Land, presents a series of landscape photographs captured on surveillance cameras around the world. He got the idea for the project back in 2013…
DNC Hacker Denies Russian Link, Says Attack Was His ‘Personal Project'
https://ift.tt/29648Io
Submitted May 17, 2018 at 05:26PM by dengorilla1
via reddit https://ift.tt/2Kw1WvL
https://ift.tt/29648Io
Submitted May 17, 2018 at 05:26PM by dengorilla1
via reddit https://ift.tt/2Kw1WvL
Motherboard
DNC Hacker Denies Russian Link, Says Attack Was His ‘Personal Project'
In a new blog post, Guccifer 2.0 calls Hillary Clinton “false” and Donald Trump "sincere."
How to use the NIST Cybersecurity Framework
https://ift.tt/2ItEU8i
Submitted May 17, 2018 at 05:40PM by celticuki
via reddit https://ift.tt/2IrWde9
https://ift.tt/2ItEU8i
Submitted May 17, 2018 at 05:40PM by celticuki
via reddit https://ift.tt/2IrWde9
E-Volvellc
How to use the NIST Cybersecurity Framework | Information Technology Governance for Executives
By Jeffrey Morgan Follow @evolvejsmorgan NIST Cybersecurity Framework Version 1.0 of the NIST Framework for Improving Critical Infrastructure Cybersecurity (CSF) celebrated its fourth birthday in February. The CSF is a "risk-based approach to managing cybersecurity…
Security In 5: Episode 240 - Internet Security Myths You Should Know About
https://ift.tt/2k6jLqg
Submitted May 17, 2018 at 06:33PM by BinaryBlog
via reddit https://ift.tt/2KxOUOt
https://ift.tt/2k6jLqg
Submitted May 17, 2018 at 06:33PM by BinaryBlog
via reddit https://ift.tt/2KxOUOt
Libsyn
Security In Five Podcast: Episode 240 - Internet Security Myths You Should Know About
The Internet is a wild and crazy place. A vast array of computers, networks, and data. There are also lots of misconceptions, misunderstandings, and myths around security. This episode goes through some of the biggest security myths on security when using…
Signal Desktop gatecrashed by web vulnerabilities
https://ift.tt/2rPJ9ns
Submitted May 17, 2018 at 08:00PM by albinowax
via reddit https://ift.tt/2Im5rbw
https://ift.tt/2rPJ9ns
Submitted May 17, 2018 at 08:00PM by albinowax
via reddit https://ift.tt/2Im5rbw
The Daily Swig | Web security digest
Signal Desktop gatecrashed by web vulnerabilities
Two classic web flaws found in privacy-focused app within a week.
Mac/BSD + Corporate Outlook/Exchange + p≡p (Pretty Easy Privacy) + GnuPG -- Is there a solution that doesn't cost €60 besides save-as, decrypt/verify?
The only thing I've found so far is gpg4o which is really expensive.I know that there is an open-source plugin for windows outlook available on GitHub called the Outlook Privacy Plugin, but it stresses that it doesn't work on any platform other than windows.Right now verification of my emails requires people to go through a PITA manual process of saving the attachments and then using the console gpg on them. That's just not a good way to get people to handle sensitive information well.My company offers a certificate, but it's shared and technically invalid. The other problem is that it's just not widely used outside of exchange, so it works fine for in-house but doesn't work well for anyone using gmail or outlook.com or yahoo mail or other sources. Also, AFAIK the certificate specifically uses S/MIME and I would really prefer PEP.Even the PEP foundation's open-source outlook plugin charges for the binary and obfuscates building the sources. I'd still try to build, except (again) it's Windows only.I'm feeling a bit like nobody wants secure email in outlook :-/note: I use a custom IMAP thunderbird client for my own email and have no issues using either PEP or s/mime with enigmail. Some messages are actually stipulated in my employment agreement to go through the corporate email. The rare cases when I need a signature or encryption and I must use my corporate mail are where the PITA happens.
Submitted May 17, 2018 at 07:51PM by skyleach
via reddit https://ift.tt/2GqD2eE
The only thing I've found so far is gpg4o which is really expensive.I know that there is an open-source plugin for windows outlook available on GitHub called the Outlook Privacy Plugin, but it stresses that it doesn't work on any platform other than windows.Right now verification of my emails requires people to go through a PITA manual process of saving the attachments and then using the console gpg on them. That's just not a good way to get people to handle sensitive information well.My company offers a certificate, but it's shared and technically invalid. The other problem is that it's just not widely used outside of exchange, so it works fine for in-house but doesn't work well for anyone using gmail or outlook.com or yahoo mail or other sources. Also, AFAIK the certificate specifically uses S/MIME and I would really prefer PEP.Even the PEP foundation's open-source outlook plugin charges for the binary and obfuscates building the sources. I'd still try to build, except (again) it's Windows only.I'm feeling a bit like nobody wants secure email in outlook :-/note: I use a custom IMAP thunderbird client for my own email and have no issues using either PEP or s/mime with enigmail. Some messages are actually stipulated in my employment agreement to go through the corporate email. The rare cases when I need a signature or encryption and I must use my corporate mail are where the PITA happens.
Submitted May 17, 2018 at 07:51PM by skyleach
via reddit https://ift.tt/2GqD2eE
www.giepa.de
Mail Encryption with gpg4o® › Giegerich & Partner GmbH
Protect your sensitive mail content - with IT-Security made in Germany Preserve the privacy of your electronic correspondence. Send ...
What Learning to Lockpick Taught Me About Digital Security
https://ift.tt/2agQUfd
Submitted May 17, 2018 at 07:30PM by dengorilla1
via reddit https://ift.tt/2GqD2va
https://ift.tt/2agQUfd
Submitted May 17, 2018 at 07:30PM by dengorilla1
via reddit https://ift.tt/2GqD2va
Motherboard
What Learning to Lockpick Taught Me About Digital Security
Until you pick a lock, or challenge a password, you'll never know if it's really secure.
Privacy Tool uBlock (NOT uBlock Origin) Adds User Tracking Feature
https://ift.tt/2IPDlF0
Submitted May 17, 2018 at 07:28PM by speckz
via reddit https://ift.tt/2Isio3T
https://ift.tt/2IPDlF0
Submitted May 17, 2018 at 07:28PM by speckz
via reddit https://ift.tt/2Isio3T
soylentnews.org
Privacy Tool uBlock (NOT uBlock Origin) Adds User Tracking Feature - SoylentNews
Privacy Tool uBlock (NOT uBlock Origin) Adds User Tracking Feature -- article related to Software and The Main Page.
Exposing GraphQL to Penetration Testers
https://ift.tt/2Grptvr
Submitted May 17, 2018 at 09:26PM by nibblesec
via reddit https://ift.tt/2IpEvI8
https://ift.tt/2Grptvr
Submitted May 17, 2018 at 09:26PM by nibblesec
via reddit https://ift.tt/2IpEvI8
Doyensec
GraphQL - Security Overview and Testing Tips · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
One Year After WannaCry: A Fundamentally Changed Threat Landscape | Threatpost
https://ift.tt/2wYRSd5
Submitted May 17, 2018 at 09:07PM by LindseyOD123
via reddit https://ift.tt/2L6MZBw
https://ift.tt/2wYRSd5
Submitted May 17, 2018 at 09:07PM by LindseyOD123
via reddit https://ift.tt/2L6MZBw
Threatpost | The first stop for security news
One Year After WannaCry: A Fundamentally Changed Threat Landscape
It's been one year this week since the ransomware known as WannaCry infected more than 200,000 machines in 150 countries, causing billions of dollars in damages and grinding global business to a halt.
Fake Malwarebytes helpline scammer caught in the act
https://ift.tt/2rQ0UmK
Submitted May 17, 2018 at 09:59PM by EvanConover
via reddit https://ift.tt/2KAj8Az
https://ift.tt/2rQ0UmK
Submitted May 17, 2018 at 09:59PM by EvanConover
via reddit https://ift.tt/2KAj8Az
Malwarebytes Labs
Fake Malwarebytes helpline scammer caught in the act - Malwarebytes Labs
In this blog, we take you through a phone call to a fake Malwarebytes helpline run by Blue Eye Ventures, and show you how to spot the scam in action.
Tampering with OpenPGP digitally signed messages by exploiting multi-part messages
https://ift.tt/2IiCDke
Submitted May 17, 2018 at 09:49PM by sjmurdoch
via reddit https://ift.tt/2LaOIWn
https://ift.tt/2IiCDke
Submitted May 17, 2018 at 09:49PM by sjmurdoch
via reddit https://ift.tt/2LaOIWn
[oss-security] Qualys Security Advisory - Procps-ng Audit Report
https://ift.tt/2wW2vgK
Submitted May 17, 2018 at 11:27PM by dabacaba
via reddit https://ift.tt/2Iqg1OH
https://ift.tt/2wW2vgK
Submitted May 17, 2018 at 11:27PM by dabacaba
via reddit https://ift.tt/2Iqg1OH
Wrote this simple vocabulary.com hack to automatically answer questions correctly (write-up in comments)
https://ift.tt/2rPvKMk
Submitted May 18, 2018 at 12:01AM by wy35
via reddit https://ift.tt/2k72BZy
https://ift.tt/2rPvKMk
Submitted May 18, 2018 at 12:01AM by wy35
via reddit https://ift.tt/2k72BZy
GitHub
williamyeny/vocabulary.com.js
vocabulary.com.js - Lightweight Javanoscript exploit to automatically generate points in vocabulary.com
MEWKit report gives details on recent Amazon BGP hijack and the phishing campaigns leading up to it
https://ift.tt/2KuyVkb
Submitted May 17, 2018 at 11:40PM by _0x3a_
via reddit https://ift.tt/2GunV3M
https://ift.tt/2KuyVkb
Submitted May 17, 2018 at 11:40PM by _0x3a_
via reddit https://ift.tt/2GunV3M
reddit
r/netsec - MEWKit report gives details on recent Amazon BGP hijack and the phishing campaigns leading up to it
13 votes and 0 so far on reddit
Cross Site Scripting via GIFs on Pornhub
https://ift.tt/2dsQwfx
Submitted May 18, 2018 at 01:04AM by ZephrX112
via reddit https://ift.tt/2wPSRMv
https://ift.tt/2dsQwfx
Submitted May 18, 2018 at 01:04AM by ZephrX112
via reddit https://ift.tt/2wPSRMv
ZeroSec - Adventures In Information Security
gif it time it'll come to you - Finding More Holes in The Hub
Following suit of stored cross site noscripting vulnerabilities this post will talk about another issue I found in Pornhub. Unfortunately someone found before me and as a result this bug was a duplicate. However, this is my write-up of it and how it was possible…
Prototype pollution attack on NodeJS [PDF paper + HTML slides]
https://ift.tt/2Iqaacs
Submitted May 18, 2018 at 12:23AM by holyvier
via reddit https://ift.tt/2Gp8VEt
https://ift.tt/2Iqaacs
Submitted May 18, 2018 at 12:23AM by holyvier
via reddit https://ift.tt/2Gp8VEt
GitHub
HoLyVieR/prototype-pollution-nsec18
Content released at NorthSec 2018 for my talk on prototype pollution - HoLyVieR/prototype-pollution-nsec18