What Learning to Lockpick Taught Me About Digital Security
https://ift.tt/2agQUfd
Submitted May 17, 2018 at 07:30PM by dengorilla1
via reddit https://ift.tt/2GqD2va
https://ift.tt/2agQUfd
Submitted May 17, 2018 at 07:30PM by dengorilla1
via reddit https://ift.tt/2GqD2va
Motherboard
What Learning to Lockpick Taught Me About Digital Security
Until you pick a lock, or challenge a password, you'll never know if it's really secure.
Privacy Tool uBlock (NOT uBlock Origin) Adds User Tracking Feature
https://ift.tt/2IPDlF0
Submitted May 17, 2018 at 07:28PM by speckz
via reddit https://ift.tt/2Isio3T
https://ift.tt/2IPDlF0
Submitted May 17, 2018 at 07:28PM by speckz
via reddit https://ift.tt/2Isio3T
soylentnews.org
Privacy Tool uBlock (NOT uBlock Origin) Adds User Tracking Feature - SoylentNews
Privacy Tool uBlock (NOT uBlock Origin) Adds User Tracking Feature -- article related to Software and The Main Page.
Exposing GraphQL to Penetration Testers
https://ift.tt/2Grptvr
Submitted May 17, 2018 at 09:26PM by nibblesec
via reddit https://ift.tt/2IpEvI8
https://ift.tt/2Grptvr
Submitted May 17, 2018 at 09:26PM by nibblesec
via reddit https://ift.tt/2IpEvI8
Doyensec
GraphQL - Security Overview and Testing Tips · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
One Year After WannaCry: A Fundamentally Changed Threat Landscape | Threatpost
https://ift.tt/2wYRSd5
Submitted May 17, 2018 at 09:07PM by LindseyOD123
via reddit https://ift.tt/2L6MZBw
https://ift.tt/2wYRSd5
Submitted May 17, 2018 at 09:07PM by LindseyOD123
via reddit https://ift.tt/2L6MZBw
Threatpost | The first stop for security news
One Year After WannaCry: A Fundamentally Changed Threat Landscape
It's been one year this week since the ransomware known as WannaCry infected more than 200,000 machines in 150 countries, causing billions of dollars in damages and grinding global business to a halt.
Fake Malwarebytes helpline scammer caught in the act
https://ift.tt/2rQ0UmK
Submitted May 17, 2018 at 09:59PM by EvanConover
via reddit https://ift.tt/2KAj8Az
https://ift.tt/2rQ0UmK
Submitted May 17, 2018 at 09:59PM by EvanConover
via reddit https://ift.tt/2KAj8Az
Malwarebytes Labs
Fake Malwarebytes helpline scammer caught in the act - Malwarebytes Labs
In this blog, we take you through a phone call to a fake Malwarebytes helpline run by Blue Eye Ventures, and show you how to spot the scam in action.
Tampering with OpenPGP digitally signed messages by exploiting multi-part messages
https://ift.tt/2IiCDke
Submitted May 17, 2018 at 09:49PM by sjmurdoch
via reddit https://ift.tt/2LaOIWn
https://ift.tt/2IiCDke
Submitted May 17, 2018 at 09:49PM by sjmurdoch
via reddit https://ift.tt/2LaOIWn
[oss-security] Qualys Security Advisory - Procps-ng Audit Report
https://ift.tt/2wW2vgK
Submitted May 17, 2018 at 11:27PM by dabacaba
via reddit https://ift.tt/2Iqg1OH
https://ift.tt/2wW2vgK
Submitted May 17, 2018 at 11:27PM by dabacaba
via reddit https://ift.tt/2Iqg1OH
Wrote this simple vocabulary.com hack to automatically answer questions correctly (write-up in comments)
https://ift.tt/2rPvKMk
Submitted May 18, 2018 at 12:01AM by wy35
via reddit https://ift.tt/2k72BZy
https://ift.tt/2rPvKMk
Submitted May 18, 2018 at 12:01AM by wy35
via reddit https://ift.tt/2k72BZy
GitHub
williamyeny/vocabulary.com.js
vocabulary.com.js - Lightweight Javanoscript exploit to automatically generate points in vocabulary.com
MEWKit report gives details on recent Amazon BGP hijack and the phishing campaigns leading up to it
https://ift.tt/2KuyVkb
Submitted May 17, 2018 at 11:40PM by _0x3a_
via reddit https://ift.tt/2GunV3M
https://ift.tt/2KuyVkb
Submitted May 17, 2018 at 11:40PM by _0x3a_
via reddit https://ift.tt/2GunV3M
reddit
r/netsec - MEWKit report gives details on recent Amazon BGP hijack and the phishing campaigns leading up to it
13 votes and 0 so far on reddit
Cross Site Scripting via GIFs on Pornhub
https://ift.tt/2dsQwfx
Submitted May 18, 2018 at 01:04AM by ZephrX112
via reddit https://ift.tt/2wPSRMv
https://ift.tt/2dsQwfx
Submitted May 18, 2018 at 01:04AM by ZephrX112
via reddit https://ift.tt/2wPSRMv
ZeroSec - Adventures In Information Security
gif it time it'll come to you - Finding More Holes in The Hub
Following suit of stored cross site noscripting vulnerabilities this post will talk about another issue I found in Pornhub. Unfortunately someone found before me and as a result this bug was a duplicate. However, this is my write-up of it and how it was possible…
Prototype pollution attack on NodeJS [PDF paper + HTML slides]
https://ift.tt/2Iqaacs
Submitted May 18, 2018 at 12:23AM by holyvier
via reddit https://ift.tt/2Gp8VEt
https://ift.tt/2Iqaacs
Submitted May 18, 2018 at 12:23AM by holyvier
via reddit https://ift.tt/2Gp8VEt
GitHub
HoLyVieR/prototype-pollution-nsec18
Content released at NorthSec 2018 for my talk on prototype pollution - HoLyVieR/prototype-pollution-nsec18
Windows 10 OpenSSH Client Installed by Default in April 2018 Update
https://ift.tt/2L25Hdw
Submitted May 18, 2018 at 12:10AM by QuirkySpiceBush
via reddit https://ift.tt/2KAgIlp
https://ift.tt/2L25Hdw
Submitted May 18, 2018 at 12:10AM by QuirkySpiceBush
via reddit https://ift.tt/2KAgIlp
BleepingComputer
Windows 10 OpenSSH Client Installed by Default in April 2018 Update
With the release of the April 2018 Update, the OpenSSH Client is now officially out of beta and is also installed by default in Windows 10. The OpenSSH Server for Windows is also out of beta, but still needs to be manually installed.
'Voice-Squatting' Turns Alexa, Google Home into Silent Spies | Threatpost
https://ift.tt/2rPJ2JD
Submitted May 18, 2018 at 01:18AM by LindseyOD123
via reddit https://ift.tt/2rOYZyM
https://ift.tt/2rPJ2JD
Submitted May 18, 2018 at 01:18AM by LindseyOD123
via reddit https://ift.tt/2rOYZyM
reddit
'Voice-Squatting' Turns Alexa, Google Home into... • r/security
1 points and 0 comments so far on reddit
Fake Fortnite Apps for Android Spread Spyware, Cryptominers
https://ift.tt/2k7MwD1
Submitted May 18, 2018 at 01:27AM by LindseyOD123
via reddit https://ift.tt/2KAVZOr
https://ift.tt/2k7MwD1
Submitted May 18, 2018 at 01:27AM by LindseyOD123
via reddit https://ift.tt/2KAVZOr
Threatpost | The first stop for security news
Fake Fortnite Apps for Android Spread Spyware, Cryptominers
An array of malicious Android apps purporting to be the popular game known as Fortnite are accessing cameras, harvesting and wiping device data, and recording audio on victims' phones.Researchers
Analysis of a Win32K Null Pointer Dereference by Matching the May Patch
https://ift.tt/2KuIyPK
Submitted May 18, 2018 at 02:14AM by TheUglyStranger
via reddit https://ift.tt/2Gu4o3o
https://ift.tt/2KuIyPK
Submitted May 18, 2018 at 02:14AM by TheUglyStranger
via reddit https://ift.tt/2Gu4o3o
LocationSmart Leaked Location Data for Customers of All Major U.S. Mobile Carriers Without Consent in Real Time
https://ift.tt/2rPz8Yf
Submitted May 18, 2018 at 03:22AM by Sephr
via reddit https://ift.tt/2IrkMUo
https://ift.tt/2rPz8Yf
Submitted May 18, 2018 at 03:22AM by Sephr
via reddit https://ift.tt/2IrkMUo
Robert Xiao
LocationSmart API Vulnerability
On May 16th, I found a vulnerability in the LocationSmart website which allowed anyone, with no prior authentication or consent, to obtain the realtime location of any cellphone in the US to within…
IT Security industry groups in the Los Angeles / Orange County area.
Hi all-I am moving into systems Admin and Security for my company and need to find some industry groups to attend to get “my head into the game”.Anyone know of any good ones in the Los Angeles or Orange County area?
Submitted May 18, 2018 at 02:32AM by Nimmerzz_IT
via reddit https://ift.tt/2rMpmp0
Hi all-I am moving into systems Admin and Security for my company and need to find some industry groups to attend to get “my head into the game”.Anyone know of any good ones in the Los Angeles or Orange County area?
Submitted May 18, 2018 at 02:32AM by Nimmerzz_IT
via reddit https://ift.tt/2rMpmp0
reddit
IT Security industry groups in the Los Angeles /... • r/security
Hi all- I am moving into systems Admin and Security for my company and need to find some industry groups to attend to get “my head into the...
Tracking Firm LocationSmart Leaked Location Data for Customers of All Major U.S. Mobile Carriers Without Consent in Real Time Via Its Web Site
https://ift.tt/2k5j68h
Submitted May 18, 2018 at 02:32AM by Rodeopants
via reddit https://ift.tt/2rMpqVM
https://ift.tt/2k5j68h
Submitted May 18, 2018 at 02:32AM by Rodeopants
via reddit https://ift.tt/2rMpqVM
reddit
r/security - Tracking Firm LocationSmart Leaked Location Data for Customers of All Major U.S. Mobile Carriers Without Consent in…
4 votes and 1 so far on reddit
PDF sample malicious and very powerful when vulnerabilities combined
https://ift.tt/2Inojmw
Submitted May 18, 2018 at 09:52AM by PeterG45
via reddit https://ift.tt/2k8tEDU
https://ift.tt/2Inojmw
Submitted May 18, 2018 at 09:52AM by PeterG45
via reddit https://ift.tt/2k8tEDU
WeLiveSecurity
PDF sample malicious and very powerful when vulnerabilities combined
ESET researchers identified a malicious PDF sample that revealed that the sample exploited two unknown vulnerabilities, a remote-code execution vulnerability in Adobe Reader and a privilege escalation vulnerability in Microsoft Windows, that when combined…
Malicious PDF Analysis Booklet by Didier Stevens (Free)
https://ift.tt/2Iu48TW
Submitted May 18, 2018 at 11:10AM by TechLord2
via reddit https://ift.tt/2rPhKmj
https://ift.tt/2Iu48TW
Submitted May 18, 2018 at 11:10AM by TechLord2
via reddit https://ift.tt/2rPhKmj
Fool Linux utils search by changing the path.
https://ift.tt/2IvhCyX
Submitted May 18, 2018 at 11:56AM by r0hi7
via reddit https://ift.tt/2rQOcFf
https://ift.tt/2IvhCyX
Submitted May 18, 2018 at 11:56AM by r0hi7
via reddit https://ift.tt/2rQOcFf
GitHub
r0hi7/BinExp
BinExp - Linux Binary Exploitation