The Seven Properties of Highly Secure Devices - Microsoft Research
https://ift.tt/2oD3zRh
Submitted June 08, 2018 at 05:45PM by bella_sm
via reddit https://ift.tt/2HtPScE
https://ift.tt/2oD3zRh
Submitted June 08, 2018 at 05:45PM by bella_sm
via reddit https://ift.tt/2HtPScE
Microsoft Research
The Seven Properties of Highly Secure Devices - Microsoft Research
Industry largely underestimates the critical societal need to embody the highest levels of security in every network-connected device—every child’s toy, every household’s appliances, and every industry’s equipment. High development and maintenance costs have…
Exploiting an Implementation flaw in Mycroft AI Vocal assistant to reach RCE
https://ift.tt/2sTy8Ck
Submitted June 09, 2018 at 05:49PM by Nhoya
via reddit https://ift.tt/2sJz24N
https://ift.tt/2sTy8Ck
Submitted June 09, 2018 at 05:49PM by Nhoya
via reddit https://ift.tt/2sJz24N
GitHub
Nhoya/MycroftAI-RCE
MycroftAI-RCE - "Zero Click" Remote Code Execution in Mycroft AI vocal assistant
m4ngl3m3! v0.1 (Common password pattern generator using strings list)
https://ift.tt/2HADvLO
Submitted June 10, 2018 at 12:04AM by localh0t
via reddit https://ift.tt/2JqJjNR
https://ift.tt/2HADvLO
Submitted June 10, 2018 at 12:04AM by localh0t
via reddit https://ift.tt/2JqJjNR
Medium
m4ngl3m3! v0.1
Hi there!
m4ngl3m3! - A common password pattern generator using strings list
https://ift.tt/2sV2ynw
Submitted June 10, 2018 at 12:56AM by localh0t
via reddit https://ift.tt/2LA2p0C
https://ift.tt/2sV2ynw
Submitted June 10, 2018 at 12:56AM by localh0t
via reddit https://ift.tt/2LA2p0C
GitHub
localh0t/m4ngl3m3
m4ngl3m3 - Common password pattern generator using strings list
Endpoint detection Superpowers on the cheap — part 1
https://ift.tt/2Htk1cd
Submitted June 11, 2018 at 01:56AM by Olafhartong
via reddit https://ift.tt/2sMdTal
https://ift.tt/2Htk1cd
Submitted June 11, 2018 at 01:56AM by Olafhartong
via reddit https://ift.tt/2sMdTal
Medium
Endpoint detection Superpowers on the cheap — part 1
In this blog series, I will talk about my endpoint detection stack focused on Windows environments and mostly based on Sysmon.
Replacing Socat with Nginx for Redirection
https://ift.tt/2JAT37k
Submitted June 11, 2018 at 07:20AM by audrummer15
via reddit https://ift.tt/2LBn0ld
https://ift.tt/2JAT37k
Submitted June 11, 2018 at 07:20AM by audrummer15
via reddit https://ift.tt/2LBn0ld
The Coffeegist
Resilient Red Team HTTPS Redirection Using Nginx
On a typical red team assessment, a redirector is a crucial part of the infrastructure in use. A redirector is basically a box that sits out on the internet (usually in some type of cloud service provider’s network) and forwards traffic for the red team so…
Cookies for dummies Part 3: Secure, HttpOnly and SameSite
https://ift.tt/2l3yLpp
Submitted June 11, 2018 at 05:46PM by silentsniffer
via reddit https://ift.tt/2sZlVfd
https://ift.tt/2l3yLpp
Submitted June 11, 2018 at 05:46PM by silentsniffer
via reddit https://ift.tt/2sZlVfd
WST
Cookies for dummies Part 3: Secure, HttpOnly and SameSite
What are the uses of cookie flags such as SameSite, Secure and HttpOnly. Man in the middle attack. Cookie stealing. Cross site request forgery.
Siaberry’s Command Injection Vulnerability
https://ift.tt/2sUq7g8
Submitted June 11, 2018 at 07:10PM by mtlynch
via reddit https://ift.tt/2l1DxU5
https://ift.tt/2sUq7g8
Submitted June 11, 2018 at 07:10PM by mtlynch
via reddit https://ift.tt/2l1DxU5
Space Duck
Siaberry’s Command Injection Vulnerability
A write up of several security vulnerabilities I discovered in Siaberry, including command-injection, clickjacking, and more.
Firefox uXSS and CSS XSS
https://ift.tt/2HBbQKD
Submitted June 10, 2018 at 01:20PM by albinowax
via reddit https://ift.tt/2JKCF4b
https://ift.tt/2HBbQKD
Submitted June 10, 2018 at 01:20PM by albinowax
via reddit https://ift.tt/2JKCF4b
Leucosite
Firefox uXSS and CSS XSS
CSS XSS came back for a bit which lead to an unusual uXSS
YubiKey as an OpenPGP smart card for SSH on macOS — a missing manual
https://ift.tt/2JrXa6o
Submitted June 11, 2018 at 11:28PM by progapandist
via reddit https://ift.tt/2y21GmR
https://ift.tt/2JrXa6o
Submitted June 11, 2018 at 11:28PM by progapandist
via reddit https://ift.tt/2y21GmR
Martian Chronicles
Stick with security: YubiKey, SSH, GnuPG, macOS — Martian Chronicles
See how to go beyond standard U2F functionality of your YubiKey and authenticate via SSH from a Mac with a PGP key on a USB stick.
Microsoft Azure Application Gateway Exposes Your Backend Health API Server
https://ift.tt/2MhgJfD
Submitted June 12, 2018 at 08:36AM by Gallus
via reddit https://ift.tt/2sNCyvi
https://ift.tt/2MhgJfD
Submitted June 12, 2018 at 08:36AM by Gallus
via reddit https://ift.tt/2sNCyvi
Chris408
Microsoft Azure Application Gateway Exposes Your Backend Health API Server
Firewall Weakness in Microsoft Azure’s Backplane Health Check I decided to do this write up because Microsoft doesn’t really give the full story on their website when describing why ports 65503-65534 need to be open to everything on the internet. Azure customers…
phpMyAdmin 4.7.x XSRF/CSRF Vulnerability (PMASA-2017-9) Exploit
https://ift.tt/2JyDgHf
Submitted June 12, 2018 at 09:22AM by Ambulong
via reddit https://ift.tt/2JKSjg5
https://ift.tt/2JyDgHf
Submitted June 12, 2018 at 09:22AM by Ambulong
via reddit https://ift.tt/2JKSjg5
Vulnspy Blog
phpMyAdmin 4.7.x XSRF/CSRF Vulnerability (PMASA-2017-9) Exploit
Author: Ambulong 1 phpMyAmin 4.7.x XSRF/CSRF Vulnerability (PMASA-2017-9)phpMyAdmin is a well-known MySQL/MariaDB online management tool, phpMyAdmin team released the version 4.7.7 that addresses the
Web App Security 101: How to Defend Against a Brute Force Attack
https://ift.tt/2Jwst09
Submitted June 12, 2018 at 07:00PM by Slavos17
via reddit https://ift.tt/2JHy9QH
https://ift.tt/2Jwst09
Submitted June 12, 2018 at 07:00PM by Slavos17
via reddit https://ift.tt/2JHy9QH
Kruschecompany
Web App Security: How to Defend Against a Brute Force Attack
What a Brute Force Attack is? How to defend yourself or even prevent it? Get all the information about Brute Force Attack, and be armed and ready for all the fraud schemes which may be implemented on your resource.
I can be apple and so can you by Josh Pitts from Okta REX Team
https://ift.tt/2MmWHjF
Submitted June 12, 2018 at 07:19PM by project_ishikawa
via reddit https://ift.tt/2y3CxIn
https://ift.tt/2MmWHjF
Submitted June 12, 2018 at 07:19PM by project_ishikawa
via reddit https://ift.tt/2y3CxIn
Okta
I can be Apple, and so can you
A Public Disclosure of Issues Around Third
The Tale of SettingContent-ms Files
https://ift.tt/2HGyXnf
Submitted June 12, 2018 at 07:57PM by albinowax
via reddit https://ift.tt/2sZ8qw8
https://ift.tt/2HGyXnf
Submitted June 12, 2018 at 07:57PM by albinowax
via reddit https://ift.tt/2sZ8qw8
Posts By SpecterOps Team Members
The Tale of SettingContent-ms Files – Posts By SpecterOps Team Members
As an attacker, initial access can prove to be quite the challenge against a hardened target. When selecting a payload for initial access…
Why Outdated Anti-Phishing Advice Will Not Protect You from Phishing
https://ift.tt/2LHysf2
Submitted June 12, 2018 at 07:44PM by msp_guru
via reddit https://ift.tt/2MiIh4a
https://ift.tt/2LHysf2
Submitted June 12, 2018 at 07:44PM by msp_guru
via reddit https://ift.tt/2MiIh4a
Iron Bastion Security Blog
Why Outdated Anti-Phishing Advice Leaves You Exposed (Part 2)
A showcase of real-world phishing emails caught by our anti-phishing technology
Evil Teacher: Moodle Code Injection
https://ift.tt/2JNaOQR
Submitted June 12, 2018 at 10:36PM by zit-hb
via reddit https://ift.tt/2JHcxrd
https://ift.tt/2JNaOQR
Submitted June 12, 2018 at 10:36PM by zit-hb
via reddit https://ift.tt/2JHcxrd
X Brute Forcer Tool 🔓 WordPress , Joomla , DruPal , OpenCart , Magento
https://ift.tt/2LGX9ID
Submitted June 13, 2018 at 12:13AM by moham3driahi
via reddit https://ift.tt/2HHOK5l
https://ift.tt/2LGX9ID
Submitted June 13, 2018 at 12:13AM by moham3driahi
via reddit https://ift.tt/2HHOK5l
GitHub
Moham3dRiahi/XBruteForcer
XBruteForcer - X Brute Forcer Tool 🔓 WordPress , Joomla , DruPal , OpenCart , Magento
How Machine Learning Techniques Helped Us Find Massive Certificate Abuse by BrowseFox
https://ift.tt/2MkigSe
Submitted June 13, 2018 at 02:25AM by EvanConover
via reddit https://ift.tt/2JtFQho
https://ift.tt/2MkigSe
Submitted June 13, 2018 at 02:25AM by EvanConover
via reddit https://ift.tt/2JtFQho
Trendmicro
How Machine Learning Techniques Helped Us Find Massive Certificate Abuse by BrowseFox
By employing machine learning algorithms, we were able to discover an enormous certificate signing abuse by BrowseFox, a potentially unwanted application (PUA) detected by Trend Micro as PUA_BROWSEFOX.SMC.
CAA record issues
https://ift.tt/2MkZaLu
Submitted June 13, 2018 at 02:16AM by binaryfigments
via reddit https://ift.tt/2y4r8YZ
https://ift.tt/2MkZaLu
Submitted June 13, 2018 at 02:16AM by binaryfigments
via reddit https://ift.tt/2y4r8YZ
Binary Figments
CAA record issues
In February 2018 I wrote about CAA records. CA’s must check and respect these records when a customer orders a certificate. This is a good thing and it can be a good security measure to use t…
Extracting the Private Key from a TREZOR
https://ift.tt/1Om89o4
Submitted June 13, 2018 at 07:53AM by RookieJoey
via reddit https://ift.tt/2JEoCdm
https://ift.tt/1Om89o4
Submitted June 13, 2018 at 07:53AM by RookieJoey
via reddit https://ift.tt/2JEoCdm
jochen-hoenicke.de
Extracting the Private Key from a TREZOR
Homepage of Jochen Hoenicke