GitHub - threatexpress/domainhunter: Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
https://ift.tt/2GxHDMj
Submitted May 20, 2018 at 05:27PM by tiger6700
via reddit https://ift.tt/2KHnkyp
https://ift.tt/2GxHDMj
Submitted May 20, 2018 at 05:27PM by tiger6700
via reddit https://ift.tt/2KHnkyp
GitHub
threatexpress/domainhunter
domainhunter - Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names
Is this a fake? Or is it legit? Scared to click it.
https://ift.tt/2LiHq38
Submitted May 20, 2018 at 07:05PM by Bango-Fett
via reddit https://ift.tt/2IDcY1F
https://ift.tt/2LiHq38
Submitted May 20, 2018 at 07:05PM by Bango-Fett
via reddit https://ift.tt/2IDcY1F
Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps
https://ift.tt/1hwynHJ
Submitted May 20, 2018 at 07:58PM by dengorilla1
via reddit https://ift.tt/2rXJRzg
https://ift.tt/1hwynHJ
Submitted May 20, 2018 at 07:58PM by dengorilla1
via reddit https://ift.tt/2rXJRzg
Ars Technica
Meet “badBIOS,” the mysterious Mac and PC malware that jumps airgaps
Like a super strain of bacteria, the rootkit plaguing Dragos Ruiu is omnipotent.
Hacking GOT
https://ift.tt/2IMfE0o
Submitted May 20, 2018 at 09:36PM by r0hi7
via reddit https://ift.tt/2IBWBCO
https://ift.tt/2IMfE0o
Submitted May 20, 2018 at 09:36PM by r0hi7
via reddit https://ift.tt/2IBWBCO
GitHub
r0hi7/BinExp
BinExp - Linux Binary Exploitation
Reuse an untrusted hard drive?
My mom in law let someone remote into her pc to “repair it”. Upon realizing it we shut down the pc.I swapped the hard drive with another one, reinstalled Windows, and plugged in the original hard drive and formatted it.Was this risky? Assume nothing autoran. Is it safe to reuse the old formatted hard drive now, as a system drive or storage drive? Also, I heard of viruses that live in the bios and survive is os reinstallations. Is this something that exists out in the wild?Thanks!
Submitted May 20, 2018 at 10:01PM by theone_2099
via reddit https://ift.tt/2wXwdBO
My mom in law let someone remote into her pc to “repair it”. Upon realizing it we shut down the pc.I swapped the hard drive with another one, reinstalled Windows, and plugged in the original hard drive and formatted it.Was this risky? Assume nothing autoran. Is it safe to reuse the old formatted hard drive now, as a system drive or storage drive? Also, I heard of viruses that live in the bios and survive is os reinstallations. Is this something that exists out in the wild?Thanks!
Submitted May 20, 2018 at 10:01PM by theone_2099
via reddit https://ift.tt/2wXwdBO
reddit
r/security - Reuse an untrusted hard drive?
0 votes and 0 so far on reddit
Here's a friendly reminder to encrypt your drives! It's one of the most overlooked and easy-to-exploit attacks.
https://youtu.be/0NfvKci3WF0
Submitted May 21, 2018 at 12:03AM by myfeetsmellallday
via reddit https://ift.tt/2rZv0Ej
https://youtu.be/0NfvKci3WF0
Submitted May 21, 2018 at 12:03AM by myfeetsmellallday
via reddit https://ift.tt/2rZv0Ej
YouTube
You Need To Encrypt Your Drives! (Seriously...)
Do you need to encrypt your hard drive or solid state drive using an encryption tool like Bitlocker, FileVault, or Veracrypt for your Windows or MacOS laptop/desktop? ABSOLUTELY! In this Techlore video tutorial/guide, I discuss and demonstrate the reasons…
Extracting SSH Private Keys from Windows 10 ssh-agent
https://ift.tt/2wZAg0w
Submitted May 21, 2018 at 01:09AM by tiger6700
via reddit https://ift.tt/2IBqh6T
https://ift.tt/2wZAg0w
Submitted May 21, 2018 at 01:09AM by tiger6700
via reddit https://ift.tt/2IBqh6T
ropnop blog
Extracting SSH Private Keys From Windows 10 ssh-agent
The newest Windows 10 update includes OpenSSH utilities, including ssh-agent. Here’s how to extract unencrypted saved private keys from the registry
IBM bans USB drives – but will it work?
https://ift.tt/2IbCsHl
Submitted May 21, 2018 at 01:47AM by DrinkMoreCodeMore
via reddit https://ift.tt/2IYL04d
https://ift.tt/2IbCsHl
Submitted May 21, 2018 at 01:47AM by DrinkMoreCodeMore
via reddit https://ift.tt/2IYL04d
Naked Security
IBM bans USB drives – but will it work?
Can you blindly ban all USB drives, or will it lead to “shadow IT” where staff use them anyway? Sophos CISO Ross McKerchar has his say…
Exploiting HTTP PUT method To Hack A Server
https://ift.tt/2IxccYe
Submitted May 21, 2018 at 06:10AM by TheOddGod
via reddit https://ift.tt/2wYrwrp
https://ift.tt/2IxccYe
Submitted May 21, 2018 at 06:10AM by TheOddGod
via reddit https://ift.tt/2wYrwrp
Hackmydevice
How To Exploit HTTP PUT Method Using Metasploitable
Learn Hacking The Right Way Learn How To Hack, WiFi Hacking, Kali Linux, Metasploit, Exploits, Ethical Hacking, Information Security And Scanning.
ReconPi: extensive recon scans using Raspberry Pi & Docker
https://ift.tt/2LfoCSd
Submitted May 21, 2018 at 05:59AM by X1M_
via reddit https://ift.tt/2wVom7G
https://ift.tt/2LfoCSd
Submitted May 21, 2018 at 05:59AM by X1M_
via reddit https://ift.tt/2wVom7G
GitHub
x1mdev/ReconPi
ReconPi - A lightweight recon tool that performs extensive scanning with the latest tools.
Protect Yourself Against Identity Theft
https://ift.tt/2Gz3YsB
Submitted May 21, 2018 at 10:22AM by Puppy_Snugglez
via reddit https://ift.tt/2GBDp68
https://ift.tt/2Gz3YsB
Submitted May 21, 2018 at 10:22AM by Puppy_Snugglez
via reddit https://ift.tt/2GBDp68
Medium
Response to
I’m not going to lie to you, your life is about to get a hell of a lot harder.
CVE-2008-4250 Hacking Windows XP Machines Using IP address and Take Full Control
https://ift.tt/2wuwlIR
Submitted May 21, 2018 at 03:07PM by TheOddGod
via reddit https://ift.tt/2KIgRD4
https://ift.tt/2wuwlIR
Submitted May 21, 2018 at 03:07PM by TheOddGod
via reddit https://ift.tt/2KIgRD4
Hackmydevice
How To Hack Windows XP Using IP address With Metasploit
Learn Hacking The Right Way Learn How To Hack, WiFi Hacking, Kali Linux, Metasploit, Exploits, Ethical Hacking, Information Security And Scanning.
$36k Google App Engine RCE
https://ift.tt/2s2ZCWz
Submitted May 21, 2018 at 01:39PM by albinowax
via reddit https://ift.tt/2rYOYPv
https://ift.tt/2s2ZCWz
Submitted May 21, 2018 at 01:39PM by albinowax
via reddit https://ift.tt/2rYOYPv
Google
$36k Google App Engine RCE - Ezequiel Pereira
Testing
Remote smart car hacking with just a phone
https://ift.tt/2rFKAps
Submitted May 21, 2018 at 03:54PM by Iot_Security
via reddit https://ift.tt/2GCk4ld
https://ift.tt/2rFKAps
Submitted May 21, 2018 at 03:54PM by Iot_Security
via reddit https://ift.tt/2GCk4ld
Medium
Remote smart car hacking with just a phone.
tl;dr: Calamp which provides the backend for a lot of really well known car alarm systems had a misconfigured reporting server that gave…
Exploit HTTP PUT method To Hack A Server
https://ift.tt/2kdjBNW
Submitted May 21, 2018 at 04:15PM by TheOddGod
via reddit https://ift.tt/2rZws9Q
https://ift.tt/2kdjBNW
Submitted May 21, 2018 at 04:15PM by TheOddGod
via reddit https://ift.tt/2rZws9Q
Hackmydevice
How To Exploit HTTP PUT Method Using Metasploitable
Learn Hacking The Right Way Learn How To Hack, WiFi Hacking, Kali Linux, Metasploit, Exploits, Ethical Hacking, Information Security And Scanning.
Some fun with a miner
https://ift.tt/2GBSXH5
Submitted May 21, 2018 at 04:17PM by tiger6700
via reddit https://ift.tt/2IAbzgz
https://ift.tt/2GBSXH5
Submitted May 21, 2018 at 04:17PM by tiger6700
via reddit https://ift.tt/2IAbzgz
Fumik0
Some fun with a miner
A few weeks ago I came across a malware that gave me some interests to dig more into it. It has a curious way to deploy itself, set up a miner on the machine and hide it behind some legit processes…
Kerberoasting, exploiting unpatched systems – a day in the life of a Red Teamer
https://ift.tt/2IzPPgM
Submitted May 21, 2018 at 05:34PM by sandmaxprime
via reddit https://ift.tt/2KHliyl
https://ift.tt/2IzPPgM
Submitted May 21, 2018 at 05:34PM by sandmaxprime
via reddit https://ift.tt/2KHliyl
Checkmate
Kerberoasting, exploiting unpatched systems – a day in the life of a Red Teamer - Checkmate
The Scope Recently, we conducted a red team assessment for a large enterprise client where the scenarios allowed were to either use the hardened laptop of the client or to [more]
GitBucket RCE explanation, weak 4 digit secret token
https://ift.tt/2wYw9BF
Submitted May 21, 2018 at 05:28PM by kszurek
via reddit https://ift.tt/2LfK8X0
https://ift.tt/2wYw9BF
Submitted May 21, 2018 at 05:28PM by kszurek
via reddit https://ift.tt/2LfK8X0
Security In 5: Episode 242 - Net Neutrality Is Not Quite Dead
https://ift.tt/2x2Asfy
Submitted May 21, 2018 at 06:34PM by BinaryBlog
via reddit https://ift.tt/2IBVZRu
https://ift.tt/2x2Asfy
Submitted May 21, 2018 at 06:34PM by BinaryBlog
via reddit https://ift.tt/2IBVZRu
Libsyn
Security In Five Podcast: Episode 242 - Net Neutrality Is Not Quite Dead
Last year the government voted to remove 'Net Neutrality' which forced Internet providers to treat all Internet traffic equally, they couldn't speed up one service and slow down another. Recently the Senate voted to bring it back. This episode goes into what…
Student snags $36k Google bounty for RCE vulnerability
https://ift.tt/2x1IuoU
Submitted May 21, 2018 at 07:38PM by albinowax
via reddit https://ift.tt/2IUOsNc
https://ift.tt/2x1IuoU
Submitted May 21, 2018 at 07:38PM by albinowax
via reddit https://ift.tt/2IUOsNc
The Daily Swig | Web security digest
Student snags $36k Google bounty for RCE vulnerability
Top-tier payout for Google App Engine flaw that enabled access to hidden APIs.
DrayTek Router Zero-Day Under Attack
https://ift.tt/2k70WTN
Submitted May 21, 2018 at 07:18PM by Iot_Security
via reddit https://ift.tt/2IyHlKR
https://ift.tt/2k70WTN
Submitted May 21, 2018 at 07:18PM by Iot_Security
via reddit https://ift.tt/2IyHlKR
BleepingComputer
DrayTek Router Zero-Day Under Attack
DrayTek, a Taiwan-based manufacturer of broadband CPE (Customer Premises Equipment) such as routers, switches, firewalls, and VPN devices, announced today that hackers are exploiting a zero-day vulnerability to change DNS settings on some of its routers.