SafeSpec: Banishing the Spectre of a Meltdown with Leakage-Free Speculation [PDF Paper]
https://ift.tt/2JKy42K
Submitted June 16, 2018 at 11:16PM by Scene_News
via reddit https://ift.tt/2yg8BsD
https://ift.tt/2JKy42K
Submitted June 16, 2018 at 11:16PM by Scene_News
via reddit https://ift.tt/2yg8BsD
reddit
r/netsec - SafeSpec: Banishing the Spectre of a Meltdown with Leakage-Free Speculation [PDF Paper]
3 votes and 0 so far on reddit
Hacking Amazon's #1 seller Smart Pet Food Dispenser
https://ift.tt/2teclFr
Submitted June 17, 2018 at 06:58AM by Expect3
via reddit https://ift.tt/2yf1wsE
https://ift.tt/2teclFr
Submitted June 17, 2018 at 06:58AM by Expect3
via reddit https://ift.tt/2yf1wsE
Collections of Infosec Tweets
https://ift.tt/2liPXH6
Submitted June 17, 2018 at 09:20AM by fireh7nter
via reddit https://ift.tt/2JZAOZm
https://ift.tt/2liPXH6
Submitted June 17, 2018 at 09:20AM by fireh7nter
via reddit https://ift.tt/2JZAOZm
Infosec Tweets
Tweets are of others
Spectre Attacks: Exploiting Speculative Execution
https://ift.tt/2EORJIX
Submitted June 17, 2018 at 09:09AM by Scene_News
via reddit https://ift.tt/2JQgW7H
https://ift.tt/2EORJIX
Submitted June 17, 2018 at 09:09AM by Scene_News
via reddit https://ift.tt/2JQgW7H
WebUSB Vulnerabilities, actions of YubiCo, and disclosure madness
https://ift.tt/2lf0B1G
Submitted June 17, 2018 at 10:49AM by Kikawala
via reddit https://ift.tt/2yokb5o
https://ift.tt/2lf0B1G
Submitted June 17, 2018 at 10:49AM by Kikawala
via reddit https://ift.tt/2yokb5o
The Complete Beginner Guide to Learn Ethical Hacking
https://ift.tt/2HMRtuq
Submitted June 17, 2018 at 07:42PM by jbvmt
via reddit https://ift.tt/2JXvi6E
https://ift.tt/2HMRtuq
Submitted June 17, 2018 at 07:42PM by jbvmt
via reddit https://ift.tt/2JXvi6E
Medium
The Complete Beginner Guide to Learn Ethical Hacking
If you want to learn ethical hacking so that you can hack computer systems like black hat hackers and secure them like security experts…
BTRSys v2.1 Walkthrough [TR]
https://ift.tt/2JWPzcb
Submitted June 17, 2018 at 08:42PM by rdincel1
via reddit https://ift.tt/2LYv8MM
https://ift.tt/2JWPzcb
Submitted June 17, 2018 at 08:42PM by rdincel1
via reddit https://ift.tt/2LYv8MM
DEAD - An attack vector on web services, due to e-mail's faults due to DNS
https://ift.tt/2tbF2CZ
Submitted June 17, 2018 at 08:30PM by 1g14gw
via reddit https://ift.tt/2MAfMiP
https://ift.tt/2tbF2CZ
Submitted June 17, 2018 at 08:30PM by 1g14gw
via reddit https://ift.tt/2MAfMiP
Private Internet Access Blog
DEAD - An attack vector on web services, due to e-mail's faults due to DNS | Private Internet Access Blog
Domain Emails Are Dead (DEAD) A security reminder that e-mail and DNS should never be a critical component of a secure system architecture. PROBLEM DEAD is a potential vulnerability in the DNS system that exists due to the poor method in which it was implemented…
Bypass macOS rootless by sandboxing
https://ift.tt/2JOhfEc
Submitted June 18, 2018 at 10:55AM by CodeColorist
via reddit https://ift.tt/2LXjstA
https://ift.tt/2JOhfEc
Submitted June 18, 2018 at 10:55AM by CodeColorist
via reddit https://ift.tt/2LXjstA
Medium
Bypass macOS rootless by sandboxing
This bug has been fixed in Mojave Beta, but sill present in latest High Sierra (10.13.5). It’s a logical bug that an ennoscriptd binary tries…
AREA 41 - Switzerland. Conference talk videos.
https://www.youtube.com/user/defconswitzerland/videos
Submitted June 17, 2018 at 08:20PM by Cyph3r151
via reddit https://ift.tt/2JWeLjd
https://www.youtube.com/user/defconswitzerland/videos
Submitted June 17, 2018 at 08:20PM by Cyph3r151
via reddit https://ift.tt/2JWeLjd
YouTube
DEFCON Switzerland
Share your videos with friends, family, and the world
Cracking SSL pinning in AFNetwork
https://ift.tt/2lkkS6p
Submitted June 18, 2018 at 12:37PM by xaocuc
via reddit https://ift.tt/2LZHFzq
https://ift.tt/2lkkS6p
Submitted June 18, 2018 at 12:37PM by xaocuc
via reddit https://ift.tt/2LZHFzq
kov4l3nko.github.io
Cracking SSL pinning in AFNetworking
SSTIC research paper on smart TVs
https://ift.tt/2HZq20g
Submitted June 18, 2018 at 01:32PM by hemorro
via reddit https://ift.tt/2HY4lxD
https://ift.tt/2HZq20g
Submitted June 18, 2018 at 01:32PM by hemorro
via reddit https://ift.tt/2HY4lxD
Tessian Raises $13M to Build a Machine Learning Approach For Enterprise Email Security
https://ift.tt/2tgEAmR
Submitted June 18, 2018 at 03:17PM by cpt_snowcrash
via reddit https://ift.tt/2lhKLUn
https://ift.tt/2tgEAmR
Submitted June 18, 2018 at 03:17PM by cpt_snowcrash
via reddit https://ift.tt/2lhKLUn
All about Robots - All you need to know about robots.txt (For noobs)
https://ift.tt/2t5XD4a
Submitted June 18, 2018 at 03:08PM by silentsniffer
via reddit https://ift.tt/2MCZ3vc
https://ift.tt/2t5XD4a
Submitted June 18, 2018 at 03:08PM by silentsniffer
via reddit https://ift.tt/2MCZ3vc
WST
All about Robots - All you need to know about robots.txt | WST
What are crawlers a.k.a spiders? Content of robots.txt. Allow and Disallow commands. How secure is robots.txt. Robot exclusion standard or simply robot.txt
F-Secure to buy MWR InfoSecurity for ~$106M+ to offer better threat hunting
https://ift.tt/2t4Qm4y
Submitted June 18, 2018 at 04:30PM by beautify
via reddit https://ift.tt/2M2J4p9
https://ift.tt/2t4Qm4y
Submitted June 18, 2018 at 04:30PM by beautify
via reddit https://ift.tt/2M2J4p9
TechCrunch
F-Secure to buy MWR InfoSecurity for ~$106M+ to offer better threat hunting
The ongoing shift of emphasis in the cyber security industry from defensive, reactive actions towards pro-active detection and response has fueled veteran Finnish security company F-Secure’s …
Advanced CORS Exploitation Techniques
https://ift.tt/2JQMNFy
Submitted June 17, 2018 at 02:12AM by sxcurity
via reddit https://ift.tt/2JUx20k
https://ift.tt/2JQMNFy
Submitted June 17, 2018 at 02:12AM by sxcurity
via reddit https://ift.tt/2JUx20k
www.sxcurity.pro
Advanced CORS Exploitation Techniques
Preface
I’ve seen some fantastic research done by Linus Särud and by Bo0oM on how Safari’s handling of special characters could be abused.
I’ve seen some fantastic research done by Linus Särud and by Bo0oM on how Safari’s handling of special characters could be abused.
Dissecting a Bug in the EternalRomance Client
https://ift.tt/2t5Gacb
Submitted June 18, 2018 at 06:03PM by Scene_News
via reddit https://ift.tt/2Mzt3rO
https://ift.tt/2t5Gacb
Submitted June 18, 2018 at 06:03PM by Scene_News
via reddit https://ift.tt/2Mzt3rO
Blogspot
Dissecting a Bug in the EternalRomance Client (FuzzBunch)
Note: This post does not explain the EternalRomance exploit chain, just a quirky bug in the Equation Group's client. For comprehensive expl...
Exploring PowerShell AMSI and Logging Evasion
https://ift.tt/2tj7dzM
Submitted June 18, 2018 at 07:00PM by dmchell
via reddit https://ift.tt/2MBqCFe
https://ift.tt/2tj7dzM
Submitted June 18, 2018 at 07:00PM by dmchell
via reddit https://ift.tt/2MBqCFe
VDOO Discovers Significant Vulnerabilities in Axis Cameras
https://ift.tt/2tjfwf1
Submitted June 18, 2018 at 06:55PM by KenjiKawai
via reddit https://ift.tt/2t9f4kc
https://ift.tt/2tjfwf1
Submitted June 18, 2018 at 06:55PM by KenjiKawai
via reddit https://ift.tt/2t9f4kc
VDOO
VDOO Discovers Significant Vulnerabilities in Axis Cameras
For the past several months, VDOO’s security research teams have been undertaking broad-scale security research of leading IoT products, from the fields of safety and security. In most cases, the r…
SSTIC2018: Backdooring your server through its BMC: the HPE iLO4 case [PDF]
https://ift.tt/2ynPPzO
Submitted June 18, 2018 at 09:00PM by alain_proviste
via reddit https://ift.tt/2tmu4e6
https://ift.tt/2ynPPzO
Submitted June 18, 2018 at 09:00PM by alain_proviste
via reddit https://ift.tt/2tmu4e6
Using radare2 and its new GUI to reverse engineer APT33's Dropshot malware - Part 2
https://ift.tt/2JWQ6Le
Submitted June 18, 2018 at 09:54PM by Megabeets
via reddit https://ift.tt/2yo1E9a
https://ift.tt/2JWQ6Le
Submitted June 18, 2018 at 09:54PM by Megabeets
via reddit https://ift.tt/2yo1E9a
Megabeets
Decrypting APT33's Dropshot Malware with Radare2 and Cutter – Part 2
In this part, we'll continue the analysis of APT33's Dropshot using Cutter, a GUI for radare2. We'll learn how to decrypt Dropshot's payload and write a noscript to do it quickly.