The Tale of SettingContent-ms Files
https://ift.tt/2HGyXnf
Submitted June 12, 2018 at 07:57PM by albinowax
via reddit https://ift.tt/2sZ8qw8
https://ift.tt/2HGyXnf
Submitted June 12, 2018 at 07:57PM by albinowax
via reddit https://ift.tt/2sZ8qw8
Posts By SpecterOps Team Members
The Tale of SettingContent-ms Files – Posts By SpecterOps Team Members
As an attacker, initial access can prove to be quite the challenge against a hardened target. When selecting a payload for initial access…
Why Outdated Anti-Phishing Advice Will Not Protect You from Phishing
https://ift.tt/2LHysf2
Submitted June 12, 2018 at 07:44PM by msp_guru
via reddit https://ift.tt/2MiIh4a
https://ift.tt/2LHysf2
Submitted June 12, 2018 at 07:44PM by msp_guru
via reddit https://ift.tt/2MiIh4a
Iron Bastion Security Blog
Why Outdated Anti-Phishing Advice Leaves You Exposed (Part 2)
A showcase of real-world phishing emails caught by our anti-phishing technology
Evil Teacher: Moodle Code Injection
https://ift.tt/2JNaOQR
Submitted June 12, 2018 at 10:36PM by zit-hb
via reddit https://ift.tt/2JHcxrd
https://ift.tt/2JNaOQR
Submitted June 12, 2018 at 10:36PM by zit-hb
via reddit https://ift.tt/2JHcxrd
X Brute Forcer Tool 🔓 WordPress , Joomla , DruPal , OpenCart , Magento
https://ift.tt/2LGX9ID
Submitted June 13, 2018 at 12:13AM by moham3driahi
via reddit https://ift.tt/2HHOK5l
https://ift.tt/2LGX9ID
Submitted June 13, 2018 at 12:13AM by moham3driahi
via reddit https://ift.tt/2HHOK5l
GitHub
Moham3dRiahi/XBruteForcer
XBruteForcer - X Brute Forcer Tool 🔓 WordPress , Joomla , DruPal , OpenCart , Magento
How Machine Learning Techniques Helped Us Find Massive Certificate Abuse by BrowseFox
https://ift.tt/2MkigSe
Submitted June 13, 2018 at 02:25AM by EvanConover
via reddit https://ift.tt/2JtFQho
https://ift.tt/2MkigSe
Submitted June 13, 2018 at 02:25AM by EvanConover
via reddit https://ift.tt/2JtFQho
Trendmicro
How Machine Learning Techniques Helped Us Find Massive Certificate Abuse by BrowseFox
By employing machine learning algorithms, we were able to discover an enormous certificate signing abuse by BrowseFox, a potentially unwanted application (PUA) detected by Trend Micro as PUA_BROWSEFOX.SMC.
CAA record issues
https://ift.tt/2MkZaLu
Submitted June 13, 2018 at 02:16AM by binaryfigments
via reddit https://ift.tt/2y4r8YZ
https://ift.tt/2MkZaLu
Submitted June 13, 2018 at 02:16AM by binaryfigments
via reddit https://ift.tt/2y4r8YZ
Binary Figments
CAA record issues
In February 2018 I wrote about CAA records. CA’s must check and respect these records when a customer orders a certificate. This is a good thing and it can be a good security measure to use t…
Extracting the Private Key from a TREZOR
https://ift.tt/1Om89o4
Submitted June 13, 2018 at 07:53AM by RookieJoey
via reddit https://ift.tt/2JEoCdm
https://ift.tt/1Om89o4
Submitted June 13, 2018 at 07:53AM by RookieJoey
via reddit https://ift.tt/2JEoCdm
jochen-hoenicke.de
Extracting the Private Key from a TREZOR
Homepage of Jochen Hoenicke
Influential Security Papers - A ranking of top-cited papers from the area of computer security
https://ift.tt/2JGGYuc
Submitted June 13, 2018 at 10:35AM by Gallus
via reddit https://ift.tt/2MlIuDC
https://ift.tt/2JGGYuc
Submitted June 13, 2018 at 10:35AM by Gallus
via reddit https://ift.tt/2MlIuDC
Attacks via external data and means of dealing with them
https://ift.tt/2sS6wxZ
Submitted June 13, 2018 at 01:49PM by 46ppc
via reddit https://ift.tt/2y7vKh7
https://ift.tt/2sS6wxZ
Submitted June 13, 2018 at 01:49PM by 46ppc
via reddit https://ift.tt/2y7vKh7
Medium
Attacks via external data and means of dealing with them
For a start, it is worth to remember what is vulnerability, and why one shouldn’t trust data received from outside.
Pentester's NTFS Tricks Collection (CVE-2018-1036, NTFS Elevation of Privileges)
https://ift.tt/2y6N9X0
Submitted June 13, 2018 at 03:51PM by SecABC
via reddit https://ift.tt/2LOqBfV
https://ift.tt/2y6N9X0
Submitted June 13, 2018 at 03:51PM by SecABC
via reddit https://ift.tt/2LOqBfV
Sec-Consult
Pentester's Windows NTFS Tricks Collection | SEC Consult
In this blog post René Freingruber (@ReneFreingruber) from the SEC Consult Vulnerability Lab shares different filesystem tricks which were collected over the last years from various blog posts or found by himself. These tricks don't lead to a directly exploitable…
Unlocking a smart padlock using MD5... and that's it
https://ift.tt/2l4in7T
Submitted June 13, 2018 at 07:28PM by cybergibbons
via reddit https://ift.tt/2sUzFsl
https://ift.tt/2l4in7T
Submitted June 13, 2018 at 07:28PM by cybergibbons
via reddit https://ift.tt/2sUzFsl
Pentestpartners
Totally Pwning the Tapplock Smart Lock | Pen Test Partners
TL;DR – How to open a Tapplock over BLE in under two seconds: Totally Pwning the Tapplock Smart Lock A couple of weekends ago, a YouTuber called JerryRigEverything posted a teardown of a "smart" padlock, called the Tapplock. He discovered that, using a sticky…
Asking for your help in improving the navigation of an Endpoint Security Platform’s website. Please help us and take this screener. If you get selected, you will get a task to group some labels. Thanks so much!
https://ift.tt/2JCAUqR
Submitted June 13, 2018 at 06:47PM by Kisbolygo
via reddit https://ift.tt/2JS6AYg
https://ift.tt/2JCAUqR
Submitted June 13, 2018 at 06:47PM by Kisbolygo
via reddit https://ift.tt/2JS6AYg
Google Docs
Apply for testing the navigation of an Endpoint Protection Platform's Website
We are looking for cybersecurity professionals to test the navigation of an Endpoint Protection Platform's Website, with a method called card sorting.
The test could be easily completed in appr. 15-25 minutes remotely, online, whenever, and wherever with…
The test could be easily completed in appr. 15-25 minutes remotely, online, whenever, and wherever with…
Vulnerability disclosure – Cisco Meeting Server (CMS) arbitrary TCP relaying
https://ift.tt/2JAu30T
Submitted June 13, 2018 at 08:45PM by Nitr4x
via reddit https://ift.tt/2JzCWrJ
https://ift.tt/2JAu30T
Submitted June 13, 2018 at 08:45PM by Nitr4x
via reddit https://ift.tt/2JzCWrJ
PowerShell Process Hollowing (RunPE) Script
https://ift.tt/2sVeOFm
Submitted June 13, 2018 at 10:11PM by PhisherPrice
via reddit https://ift.tt/2LInRjS
https://ift.tt/2sVeOFm
Submitted June 13, 2018 at 10:11PM by PhisherPrice
via reddit https://ift.tt/2LInRjS
GitHub
FuzzySecurity/PowerShell-Suite
PowerShell-Suite - My musings with PowerShell
How I Found CVE-2018-8819: Out-of-Band (OOB) XXE in WebCTRL
https://ift.tt/2JyOTxI
Submitted June 13, 2018 at 10:04PM by coalfirelabs
via reddit https://ift.tt/2HPkRjG
https://ift.tt/2JyOTxI
Submitted June 13, 2018 at 10:04PM by coalfirelabs
via reddit https://ift.tt/2HPkRjG
Coalfire.com
Post
Coalfire Labs blog posts with opinions, findings and research from the technical testing of IT perspective.
How modern containerization trend is exploited by attackers
https://ift.tt/2t0Qote
Submitted June 13, 2018 at 10:01PM by Chris911
via reddit https://ift.tt/2JHvpTu
https://ift.tt/2t0Qote
Submitted June 13, 2018 at 10:01PM by Chris911
via reddit https://ift.tt/2JHvpTu
reddit
How modern containerization trend is exploited by attackers • r/netsec
0 points and 0 comments so far on reddit
Kicking the Rims – A Guide for Securely Writing and Auditing Chrome Extensions
https://ift.tt/2JKHeIJ
Submitted June 13, 2018 at 09:39PM by mandatoryprogrammer
via reddit https://ift.tt/2HMaRY6
https://ift.tt/2JKHeIJ
Submitted June 13, 2018 at 09:39PM by mandatoryprogrammer
via reddit https://ift.tt/2HMaRY6
Thehackerblog
Kicking the Rims - A Guide for Securely Writing and Auditing Chrome Extensions | The Hacker Blog
This guide attempts to outline extension security anti-patterns, as well as provide a usable service (tarnish) to aide developers and security researchers in
Internet of Insecure Things
https://ift.tt/2t3ZgP2
Submitted June 13, 2018 at 10:12PM by nishaanthguna
via reddit https://ift.tt/2l8AzNy
https://ift.tt/2t3ZgP2
Submitted June 13, 2018 at 10:12PM by nishaanthguna
via reddit https://ift.tt/2l8AzNy
ifc0nf1g.xyz
Internet of Insecure Things
A couple of weeks back, I got the opportunity of pentesting an IoT device. To give a brief background, it was a Pi running Apache which served static content. Recently, there has been a lot of focus on IoT security, especially after the havoc created by malware…
Index access of an ABC news server (ABC 11) Thought some of you might enjoy a live one, the ISpy.jpg is hilarious!
https://ift.tt/2t4POuF
Submitted June 13, 2018 at 11:08PM by Olivero
via reddit https://ift.tt/2t45ezq
https://ift.tt/2t4POuF
Submitted June 13, 2018 at 11:08PM by Olivero
via reddit https://ift.tt/2t45ezq
A new Intel CPU bug is revealed - Intel FP security issue
https://ift.tt/2HMfaTr
Submitted June 13, 2018 at 11:01PM by xJRWR
via reddit https://ift.tt/2y7zUpc
https://ift.tt/2HMfaTr
Submitted June 13, 2018 at 11:01PM by xJRWR
via reddit https://ift.tt/2y7zUpc
reddit
r/netsec - A new Intel CPU bug is revealed - Intel FP security issue
1 votes and 1 so far on reddit
Want to Break Into a Locked Windows 10 Device? Ask Cortana (CVE-2018-8140)
https://ift.tt/2Jxyyte
Submitted June 14, 2018 at 12:29AM by 0xdea
via reddit https://ift.tt/2HMMI3P
https://ift.tt/2Jxyyte
Submitted June 14, 2018 at 12:29AM by 0xdea
via reddit https://ift.tt/2HMMI3P
McAfee Blogs
Want to Break Into a Locked Windows 10 Device? Ask Cortana (CVE-2018-8140)
June’s “Patch Tuesday” (June 12) is here, but it is likely many Windows 10 users have not yet applied these updates. If you have not, just be sure not to leave your laptop lying around!