git RCE - CVE-2018-11235 write-up. Discovery, stumbling, exploitation and disclosure
https://ift.tt/2srzDIf
Submitted June 04, 2018 at 12:30AM by bluedoehunter
via reddit https://ift.tt/2JmhDZA
https://ift.tt/2srzDIf
Submitted June 04, 2018 at 12:30AM by bluedoehunter
via reddit https://ift.tt/2JmhDZA
Windows reuse shellcode based on socket's lifetime
https://ift.tt/2kLRZzJ
Submitted June 04, 2018 at 04:00AM by bmerino
via reddit https://ift.tt/2xKUWdc
https://ift.tt/2kLRZzJ
Submitted June 04, 2018 at 04:00AM by bmerino
via reddit https://ift.tt/2xKUWdc
Shelliscoming
Windows reuse shellcode based on socket's lifetime
I've always been a big fan of the old sockets reuse techniques : findtag , findport , etc.; each with its advantages and disadvantages. Thi...
Securing the Spectrum: An Intensive Wireless Security Video Course
https://ift.tt/2Jb2aYX
Submitted June 04, 2018 at 03:17AM by i_rsX
via reddit https://ift.tt/2LSmgca
https://ift.tt/2Jb2aYX
Submitted June 04, 2018 at 03:17AM by i_rsX
via reddit https://ift.tt/2LSmgca
rootsh3ll
Securing the Spectrum: An Intensive Wireless Security Course for Red and Blue Teams - rootsh3ll
Introduction Today I’m proud to announce a first-of-its-kind Wi-Fi security course – beta. Spanning 12 intensive weeks, this course goes well beyond what’s possible in traditional trainings and will transform you into a wireless security professional. Goal…
Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.
https://ift.tt/2w97ie3
Submitted June 04, 2018 at 12:19PM by prajalkulkarni
via reddit https://ift.tt/2syDl26
https://ift.tt/2w97ie3
Submitted June 04, 2018 at 12:19PM by prajalkulkarni
via reddit https://ift.tt/2syDl26
GitHub
flipkart-incubator/watchdog
Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool. - flipkart-incubator/watchdog
Are Your Cookies Telling Your Fortune? - An analysis of weak cookie secrets and OSINT
https://ift.tt/2sIpiHw
Submitted June 04, 2018 at 03:41PM by Scene_News
via reddit https://ift.tt/2JaS9iw
https://ift.tt/2sIpiHw
Submitted June 04, 2018 at 03:41PM by Scene_News
via reddit https://ift.tt/2JaS9iw
Collection of IoT security resources
https://ift.tt/2slpcoM
Submitted June 04, 2018 at 08:26PM by v33ru
via reddit https://ift.tt/2LlMfrw
https://ift.tt/2slpcoM
Submitted June 04, 2018 at 08:26PM by v33ru
via reddit https://ift.tt/2LlMfrw
GitHub
V33RU/IoTSecurity101
IoTSecurity101 - From IoT Pentesting to IoT Security
Java: Exploiting your "unreachable" JRMP/RMI/JMX endpoints [CVE-2018-2800]
https://ift.tt/2s0Fnb6
Submitted June 04, 2018 at 08:23PM by albinowax
via reddit https://ift.tt/2sAJo68
https://ift.tt/2s0Fnb6
Submitted June 04, 2018 at 08:23PM by albinowax
via reddit https://ift.tt/2sAJo68
mbechler.github.io
Java: Exploiting your
Up to the April 2018 CPU (6u191, 7u181, 8u171) Java’s RMI endpoints allowed HTTP tunneling of requests.
Failing to implement further restrictions on these requests it was possible to perform them as
cross-origin requests from third-party websites. This…
Failing to implement further restrictions on these requests it was possible to perform them as
cross-origin requests from third-party websites. This…
netmap.js - Fast browser-based network discovery module (because there wasn't one)
https://ift.tt/2HlGR5c
Submitted June 04, 2018 at 09:37PM by alexksak
via reddit https://ift.tt/2JfbHOL
https://ift.tt/2HlGR5c
Submitted June 04, 2018 at 09:37PM by alexksak
via reddit https://ift.tt/2JfbHOL
GitHub
serain/netmap.js
Fast browser-based network discovery module. Contribute to serain/netmap.js development by creating an account on GitHub.
joincap - Merge multiple pcap files together, gracefully
https://ift.tt/2HkyB5u
Submitted June 05, 2018 at 01:06AM by assafmo
via reddit https://ift.tt/2kNRc19
https://ift.tt/2HkyB5u
Submitted June 05, 2018 at 01:06AM by assafmo
via reddit https://ift.tt/2kNRc19
GitHub
assafmo/joincap
Merge multiple pcap files together, gracefully. Contribute to assafmo/joincap development by creating an account on GitHub.
WhaleTail - Generates Dockerfile that created a Docker Image
https://ift.tt/2xJ79it
Submitted June 05, 2018 at 09:43AM by pegleg2060
via reddit https://ift.tt/2JrxPsF
https://ift.tt/2xJ79it
Submitted June 05, 2018 at 09:43AM by pegleg2060
via reddit https://ift.tt/2JrxPsF
GitHub
P3GLEG/WhaleTail
WhaleTail - Program to reverse Docker images into Dockerfiles
XSStrike - An advanced XSS detection and exploitation suite
https://ift.tt/2rVZ4iR
Submitted June 05, 2018 at 07:41AM by RookieJoey
via reddit https://ift.tt/2sFaxFa
https://ift.tt/2rVZ4iR
Submitted June 05, 2018 at 07:41AM by RookieJoey
via reddit https://ift.tt/2sFaxFa
GitHub
UltimateHackers/XSStrike
XSStrike is an advanced XSS detection and exploitation suite.
Exploitation Framework for Embedded Devices (Updated May 2018)
https://ift.tt/2I6sbrY
Submitted June 05, 2018 at 07:44AM by RookieJoey
via reddit https://ift.tt/2LXzcha
https://ift.tt/2I6sbrY
Submitted June 05, 2018 at 07:44AM by RookieJoey
via reddit https://ift.tt/2LXzcha
GitHub
threat9/routersploit
Exploitation Framework for Embedded Devices. Contribute to threat9/routersploit development by creating an account on GitHub.
Highlights of AI Village at DefCon China 2018
https://ift.tt/2J7wcwV
Submitted June 05, 2018 at 03:22PM by alexander_polyakov
via reddit https://ift.tt/2JlEwJh
https://ift.tt/2J7wcwV
Submitted June 05, 2018 at 03:22PM by alexander_polyakov
via reddit https://ift.tt/2JlEwJh
ERPScan
Highlights of AI Village at DefCon China 2018
At the DefCon2018 conference held in China, hackers and data scientists raised vivid discussions on cyberattacks with the use and abuse of machine learning and possible solutions. The AI Village talk topics cover vulnerabilities of machine learning tools…
F-Secure Anti-Virus: Remote Code Execution via Solid RAR Unpacking
https://ift.tt/2HlQLnB
Submitted June 05, 2018 at 06:08PM by landave
via reddit https://ift.tt/2sDjtL6
https://ift.tt/2HlQLnB
Submitted June 05, 2018 at 06:08PM by landave
via reddit https://ift.tt/2sDjtL6
landave's blog
F-Secure Anti-Virus: Remote Code Execution via Solid RAR Unpacking
Blog about anti-virus software and its issues.
Desktop security scanner
https://ift.tt/2Lo1ujK
Submitted June 05, 2018 at 08:21PM by Hardbeattt
via reddit https://ift.tt/2Jx9xxe
https://ift.tt/2Lo1ujK
Submitted June 05, 2018 at 08:21PM by Hardbeattt
via reddit https://ift.tt/2Jx9xxe
Secapps
Advanced Web Security Scanner
WebReaver is a desktop-based, web security scanner, designed to help you find security vulnerabilities easily. Try it today!
Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)
https://ift.tt/2M3IVlQ
Submitted June 05, 2018 at 09:00PM by mandatoryprogrammer
via reddit https://ift.tt/2xRdxnY
https://ift.tt/2M3IVlQ
Submitted June 05, 2018 at 09:00PM by mandatoryprogrammer
via reddit https://ift.tt/2xRdxnY
reddit
r/netsec - Reading Your Emails With A Read&Write Chrome Extension Same Origin Policy Bypass (~8 Million Users Affected)
4 votes and 0 so far on reddit
Pwn2Own 2018: A Methodical Approach to Browser Exploitation
https://ift.tt/2M1wXct
Submitted June 05, 2018 at 09:00PM by itsZN
via reddit https://ift.tt/2JfwqC2
https://ift.tt/2M1wXct
Submitted June 05, 2018 at 09:00PM by itsZN
via reddit https://ift.tt/2JfwqC2
Ret2 Systems Blog
A Methodical Approach to Browser Exploitation
Pwn2Own is an industry-level security competition organized annually by Trend Micro’s Zero Day Initiative. Pwn2Own invites top security researchers to showca...
MyHeritage Genealogy Site Announces Breach Affecting 92 Million Accounts - larger than Equifax.
https://ift.tt/2swJjkG
Submitted June 06, 2018 at 01:35AM by axslayer33
via reddit https://ift.tt/2xKugcx
https://ift.tt/2swJjkG
Submitted June 06, 2018 at 01:35AM by axslayer33
via reddit https://ift.tt/2xKugcx
BleepingComputer
MyHeritage Genealogy Site Announces Mega Breach Affecting 92 Million Accounts
Family genealogy and DNA testing site MyHeritage announced on Monday a security breach during which an attacker made off with account details for over 92 million MyHeritage users.
A cartoon intro to DNS over HTTPS – Mozilla Hacks - the Web developer blog
https://ift.tt/2H7p0yR
Submitted June 06, 2018 at 04:08AM by unquietwiki
via reddit https://ift.tt/2LZVSxa
https://ift.tt/2H7p0yR
Submitted June 06, 2018 at 04:08AM by unquietwiki
via reddit https://ift.tt/2LZVSxa
Mozilla Hacks – the Web developer blog
A cartoon intro to DNS over HTTPS – Mozilla Hacks - the Web developer blog
At Mozilla, we closely track threats to users' privacy and security. This is why we've added tracking protection to Firefox and created the Facebook container extension. In today's cartoon intro, ...
Zip Slip - A widespread Arbitrary File Overwrite Critical Vulnerability which typically results in Remote Command Execution
https://ift.tt/2Jil7sF
Submitted June 06, 2018 at 08:41AM by TechLord2
via reddit https://ift.tt/2M4ylLI
https://ift.tt/2Jil7sF
Submitted June 06, 2018 at 08:41AM by TechLord2
via reddit https://ift.tt/2M4ylLI
Zero to Account Takeover: How I ‘Impersonated’ Someone Else Using Auth0
https://ift.tt/2HoomNA
Submitted June 06, 2018 at 12:21PM by whitehattracker
via reddit https://ift.tt/2JfkzYP
https://ift.tt/2HoomNA
Submitted June 06, 2018 at 12:21PM by whitehattracker
via reddit https://ift.tt/2JfkzYP
Blog | Imperva
Zero to Account Takeover: How I ‘Impersonated’ Someone Else Using Auth0 – Blog | Imperva
There’s a fine line between an unintended use and a bug; this was my conclusion after taking a look at Auth0, an identity-as-a-service offering with 2000 enterprise customers.