Adobe Flash Zero-Day Leveraged For Targeted Attack In Middle East
https://ift.tt/2LwE5wy
Submitted June 07, 2018 at 11:42PM by RamblinWreckGT
via reddit https://ift.tt/2Hsaulu
https://ift.tt/2LwE5wy
Submitted June 07, 2018 at 11:42PM by RamblinWreckGT
via reddit https://ift.tt/2Hsaulu
ICEBRG | Streaming Network Forensics™
Streaming Network Forensics™ for Real-Time Threat Detection and Response | ICEBRG | Streaming Network Forensics™
ICEBRG reduces network security risk by accelerating threat detection, triage, and response to rapidly-evolving breaches across global networks.
apkast - APK fAST analysis
https://ift.tt/2sPO7B8
Submitted June 08, 2018 at 02:14AM by nervium7331
via reddit https://ift.tt/2Lw9NKj
https://ift.tt/2sPO7B8
Submitted June 08, 2018 at 02:14AM by nervium7331
via reddit https://ift.tt/2Lw9NKj
GitLab
prisma / apkast
A bash noscript to automatize the analysis of APKs: unzip, decompile, analyze and extract information.
A blog post about discovering and disclosing Supermicro firmware issues
https://ift.tt/2Hx89FQ
Submitted June 08, 2018 at 07:53AM by laplinker
via reddit https://ift.tt/2kWbo0V
https://ift.tt/2Hx89FQ
Submitted June 08, 2018 at 07:53AM by laplinker
via reddit https://ift.tt/2kWbo0V
Eclypsium Blog
Firmware Vulnerabilities in Supermicro Systems
As part of our ongoing security research efforts, we recently reviewed various Supermicro systems and discovered serious firmware vulnerabilities.
Steam, Fire, and Paste – A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper
https://ift.tt/2M9sXHh
Submitted June 08, 2018 at 08:39AM by mandatoryprogrammer
via reddit https://ift.tt/2JBUnqI
https://ift.tt/2M9sXHh
Submitted June 08, 2018 at 08:39AM by mandatoryprogrammer
via reddit https://ift.tt/2JBUnqI
Thehackerblog
Steam, Fire, and Paste - A Story of UXSS via DOM-XSS & Clickjacking in Steam Inventory Helper | The Hacker Blog
The “Steam Inventory Helper” Chrome extension version 1.13.6 suffered from both a DOM-based Cross-site Scripting (XSS) and a clickjacking vulnerability. By
The Seven Properties of Highly Secure Devices - Microsoft Research
https://ift.tt/2oD3zRh
Submitted June 08, 2018 at 05:45PM by bella_sm
via reddit https://ift.tt/2HtPScE
https://ift.tt/2oD3zRh
Submitted June 08, 2018 at 05:45PM by bella_sm
via reddit https://ift.tt/2HtPScE
Microsoft Research
The Seven Properties of Highly Secure Devices - Microsoft Research
Industry largely underestimates the critical societal need to embody the highest levels of security in every network-connected device—every child’s toy, every household’s appliances, and every industry’s equipment. High development and maintenance costs have…
Exploiting an Implementation flaw in Mycroft AI Vocal assistant to reach RCE
https://ift.tt/2sTy8Ck
Submitted June 09, 2018 at 05:49PM by Nhoya
via reddit https://ift.tt/2sJz24N
https://ift.tt/2sTy8Ck
Submitted June 09, 2018 at 05:49PM by Nhoya
via reddit https://ift.tt/2sJz24N
GitHub
Nhoya/MycroftAI-RCE
MycroftAI-RCE - "Zero Click" Remote Code Execution in Mycroft AI vocal assistant
m4ngl3m3! v0.1 (Common password pattern generator using strings list)
https://ift.tt/2HADvLO
Submitted June 10, 2018 at 12:04AM by localh0t
via reddit https://ift.tt/2JqJjNR
https://ift.tt/2HADvLO
Submitted June 10, 2018 at 12:04AM by localh0t
via reddit https://ift.tt/2JqJjNR
Medium
m4ngl3m3! v0.1
Hi there!
m4ngl3m3! - A common password pattern generator using strings list
https://ift.tt/2sV2ynw
Submitted June 10, 2018 at 12:56AM by localh0t
via reddit https://ift.tt/2LA2p0C
https://ift.tt/2sV2ynw
Submitted June 10, 2018 at 12:56AM by localh0t
via reddit https://ift.tt/2LA2p0C
GitHub
localh0t/m4ngl3m3
m4ngl3m3 - Common password pattern generator using strings list
Endpoint detection Superpowers on the cheap — part 1
https://ift.tt/2Htk1cd
Submitted June 11, 2018 at 01:56AM by Olafhartong
via reddit https://ift.tt/2sMdTal
https://ift.tt/2Htk1cd
Submitted June 11, 2018 at 01:56AM by Olafhartong
via reddit https://ift.tt/2sMdTal
Medium
Endpoint detection Superpowers on the cheap — part 1
In this blog series, I will talk about my endpoint detection stack focused on Windows environments and mostly based on Sysmon.
Replacing Socat with Nginx for Redirection
https://ift.tt/2JAT37k
Submitted June 11, 2018 at 07:20AM by audrummer15
via reddit https://ift.tt/2LBn0ld
https://ift.tt/2JAT37k
Submitted June 11, 2018 at 07:20AM by audrummer15
via reddit https://ift.tt/2LBn0ld
The Coffeegist
Resilient Red Team HTTPS Redirection Using Nginx
On a typical red team assessment, a redirector is a crucial part of the infrastructure in use. A redirector is basically a box that sits out on the internet (usually in some type of cloud service provider’s network) and forwards traffic for the red team so…
Cookies for dummies Part 3: Secure, HttpOnly and SameSite
https://ift.tt/2l3yLpp
Submitted June 11, 2018 at 05:46PM by silentsniffer
via reddit https://ift.tt/2sZlVfd
https://ift.tt/2l3yLpp
Submitted June 11, 2018 at 05:46PM by silentsniffer
via reddit https://ift.tt/2sZlVfd
WST
Cookies for dummies Part 3: Secure, HttpOnly and SameSite
What are the uses of cookie flags such as SameSite, Secure and HttpOnly. Man in the middle attack. Cookie stealing. Cross site request forgery.
Siaberry’s Command Injection Vulnerability
https://ift.tt/2sUq7g8
Submitted June 11, 2018 at 07:10PM by mtlynch
via reddit https://ift.tt/2l1DxU5
https://ift.tt/2sUq7g8
Submitted June 11, 2018 at 07:10PM by mtlynch
via reddit https://ift.tt/2l1DxU5
Space Duck
Siaberry’s Command Injection Vulnerability
A write up of several security vulnerabilities I discovered in Siaberry, including command-injection, clickjacking, and more.
Firefox uXSS and CSS XSS
https://ift.tt/2HBbQKD
Submitted June 10, 2018 at 01:20PM by albinowax
via reddit https://ift.tt/2JKCF4b
https://ift.tt/2HBbQKD
Submitted June 10, 2018 at 01:20PM by albinowax
via reddit https://ift.tt/2JKCF4b
Leucosite
Firefox uXSS and CSS XSS
CSS XSS came back for a bit which lead to an unusual uXSS
YubiKey as an OpenPGP smart card for SSH on macOS — a missing manual
https://ift.tt/2JrXa6o
Submitted June 11, 2018 at 11:28PM by progapandist
via reddit https://ift.tt/2y21GmR
https://ift.tt/2JrXa6o
Submitted June 11, 2018 at 11:28PM by progapandist
via reddit https://ift.tt/2y21GmR
Martian Chronicles
Stick with security: YubiKey, SSH, GnuPG, macOS — Martian Chronicles
See how to go beyond standard U2F functionality of your YubiKey and authenticate via SSH from a Mac with a PGP key on a USB stick.
Microsoft Azure Application Gateway Exposes Your Backend Health API Server
https://ift.tt/2MhgJfD
Submitted June 12, 2018 at 08:36AM by Gallus
via reddit https://ift.tt/2sNCyvi
https://ift.tt/2MhgJfD
Submitted June 12, 2018 at 08:36AM by Gallus
via reddit https://ift.tt/2sNCyvi
Chris408
Microsoft Azure Application Gateway Exposes Your Backend Health API Server
Firewall Weakness in Microsoft Azure’s Backplane Health Check I decided to do this write up because Microsoft doesn’t really give the full story on their website when describing why ports 65503-65534 need to be open to everything on the internet. Azure customers…
phpMyAdmin 4.7.x XSRF/CSRF Vulnerability (PMASA-2017-9) Exploit
https://ift.tt/2JyDgHf
Submitted June 12, 2018 at 09:22AM by Ambulong
via reddit https://ift.tt/2JKSjg5
https://ift.tt/2JyDgHf
Submitted June 12, 2018 at 09:22AM by Ambulong
via reddit https://ift.tt/2JKSjg5
Vulnspy Blog
phpMyAdmin 4.7.x XSRF/CSRF Vulnerability (PMASA-2017-9) Exploit
Author: Ambulong 1 phpMyAmin 4.7.x XSRF/CSRF Vulnerability (PMASA-2017-9)phpMyAdmin is a well-known MySQL/MariaDB online management tool, phpMyAdmin team released the version 4.7.7 that addresses the
Web App Security 101: How to Defend Against a Brute Force Attack
https://ift.tt/2Jwst09
Submitted June 12, 2018 at 07:00PM by Slavos17
via reddit https://ift.tt/2JHy9QH
https://ift.tt/2Jwst09
Submitted June 12, 2018 at 07:00PM by Slavos17
via reddit https://ift.tt/2JHy9QH
Kruschecompany
Web App Security: How to Defend Against a Brute Force Attack
What a Brute Force Attack is? How to defend yourself or even prevent it? Get all the information about Brute Force Attack, and be armed and ready for all the fraud schemes which may be implemented on your resource.
I can be apple and so can you by Josh Pitts from Okta REX Team
https://ift.tt/2MmWHjF
Submitted June 12, 2018 at 07:19PM by project_ishikawa
via reddit https://ift.tt/2y3CxIn
https://ift.tt/2MmWHjF
Submitted June 12, 2018 at 07:19PM by project_ishikawa
via reddit https://ift.tt/2y3CxIn
Okta
I can be Apple, and so can you
A Public Disclosure of Issues Around Third
The Tale of SettingContent-ms Files
https://ift.tt/2HGyXnf
Submitted June 12, 2018 at 07:57PM by albinowax
via reddit https://ift.tt/2sZ8qw8
https://ift.tt/2HGyXnf
Submitted June 12, 2018 at 07:57PM by albinowax
via reddit https://ift.tt/2sZ8qw8
Posts By SpecterOps Team Members
The Tale of SettingContent-ms Files – Posts By SpecterOps Team Members
As an attacker, initial access can prove to be quite the challenge against a hardened target. When selecting a payload for initial access…
Why Outdated Anti-Phishing Advice Will Not Protect You from Phishing
https://ift.tt/2LHysf2
Submitted June 12, 2018 at 07:44PM by msp_guru
via reddit https://ift.tt/2MiIh4a
https://ift.tt/2LHysf2
Submitted June 12, 2018 at 07:44PM by msp_guru
via reddit https://ift.tt/2MiIh4a
Iron Bastion Security Blog
Why Outdated Anti-Phishing Advice Leaves You Exposed (Part 2)
A showcase of real-world phishing emails caught by our anti-phishing technology
Evil Teacher: Moodle Code Injection
https://ift.tt/2JNaOQR
Submitted June 12, 2018 at 10:36PM by zit-hb
via reddit https://ift.tt/2JHcxrd
https://ift.tt/2JNaOQR
Submitted June 12, 2018 at 10:36PM by zit-hb
via reddit https://ift.tt/2JHcxrd