Bypassing Memory Scanners with Cobalt Strike and Gargoyle
https://ift.tt/2O22xYD
Submitted July 20, 2018 at 01:50AM by jalospinoso
via reddit https://ift.tt/2uMpxSU
https://ift.tt/2O22xYD
Submitted July 20, 2018 at 01:50AM by jalospinoso
via reddit https://ift.tt/2uMpxSU
How to instrument Electron-based applications for in-depth security testing.
https://ift.tt/2LbFoVO
Submitted July 20, 2018 at 01:27PM by nibblesec
via reddit https://ift.tt/2NuqB5m
https://ift.tt/2LbFoVO
Submitted July 20, 2018 at 01:27PM by nibblesec
via reddit https://ift.tt/2NuqB5m
Doyensec
Instrumenting Electron Apps for Security Testing · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Top 10 Web Hacking Techniques of 2017 - Nominations Open
https://ift.tt/2Lqd9yU
Submitted July 20, 2018 at 02:28PM by 0xdea
via reddit https://ift.tt/2L6FjTo
https://ift.tt/2Lqd9yU
Submitted July 20, 2018 at 02:28PM by 0xdea
via reddit https://ift.tt/2L6FjTo
Web Security Blog | PortSwigger
Top 10 Web Hacking Techniques of 2017 - Nominations Open
Nominations are now open for the Top 10 Web Hacking Techniques of 2017. Every year, numerous security researchers choose to share their findings with the community through conference presentations, bl
Unbound DNS Server Tutorial @ Calomel.org
https://ift.tt/1wWoivv
Submitted July 20, 2018 at 03:09PM by unquietwiki
via reddit https://ift.tt/2Nsva02
https://ift.tt/1wWoivv
Submitted July 20, 2018 at 03:09PM by unquietwiki
via reddit https://ift.tt/2Nsva02
SSL/TLS for dummies part 4 - Understanding the TLS Handshake Protocol | First second of HTTPS
https://ift.tt/2LpecT6
Submitted July 20, 2018 at 05:38PM by silentsniffer
via reddit https://ift.tt/2zRD4hH
https://ift.tt/2LpecT6
Submitted July 20, 2018 at 05:38PM by silentsniffer
via reddit https://ift.tt/2zRD4hH
WST
SSL/TLS for dummies part 4 - Understanding the TLS Handshake Protocol | WST
First few milliseconds of ssl tls connection.TLS handshake protocol explained in depth with wireshark. RSA,Diffie Hellman.TLS records.CA cert
Into the Borg - SSRF inside Google production network
https://ift.tt/2uN8DU5
Submitted July 20, 2018 at 09:25PM by geekadi
via reddit https://ift.tt/2JF4c2U
https://ift.tt/2uN8DU5
Submitted July 20, 2018 at 09:25PM by geekadi
via reddit https://ift.tt/2JF4c2U
OpnSec
Into the Borg – SSRF inside Google production network | OpnSec
Intro - Testing Google Sites and Google Caja In March 2018, I reported an XSS in Google Caja, a tool to securely embed arbitrary html/javanoscript in a webpage. In May 2018, after the XSS was fixed, I realised that Google Sites was using an unpatched version…
Backdoors Keep Appearing In Cisco's Routers
https://ift.tt/2LcMFES
Submitted July 20, 2018 at 09:09PM by GoHomeGrandmaUrHigh
via reddit https://ift.tt/2zW7S0z
https://ift.tt/2LcMFES
Submitted July 20, 2018 at 09:09PM by GoHomeGrandmaUrHigh
via reddit https://ift.tt/2zW7S0z
Tom's Hardware
Backdoors Keep Appearing In Cisco's Routers
Five different backdoors were found in Cisco's software this year, and Cisco's history with backdoors goes back many years.
New Mirai and Gafgyt IoT/Linux Botnet Campaigns - Palo Alto Networks Blog
https://ift.tt/2uBjkdf
Submitted July 20, 2018 at 09:03PM by todhsals
via reddit https://ift.tt/2uCsw0U
https://ift.tt/2uBjkdf
Submitted July 20, 2018 at 09:03PM by todhsals
via reddit https://ift.tt/2uCsw0U
Palo Alto Networks Blog
Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet Campaigns - Palo Alto Networks Blog
Unit 42 documents the emergence of three malware campaigns built on publicly available source code for the Mirai and Gafgyt malware families that incorporate multiple known exploits affecting Internet of Things (IoT) device.
Into the Borg – SSRF inside Google production network
https://ift.tt/2uN8DU5
Submitted July 21, 2018 at 01:46AM by PrimeMover17
via reddit https://ift.tt/2LwyZAL
https://ift.tt/2uN8DU5
Submitted July 21, 2018 at 01:46AM by PrimeMover17
via reddit https://ift.tt/2LwyZAL
OpnSec
Into the Borg – SSRF inside Google production network | OpnSec
Intro - Testing Google Sites and Google Caja In March 2018, I reported an XSS in Google Caja, a tool to securely embed arbitrary html/javanoscript in a webpage. In May 2018, after the XSS was fixed, I realised that Google Sites was using an unpatched version…
New Multi-Exploit Mirai and Gafgyt Campaigns
https://ift.tt/2uBjkdf
Submitted July 21, 2018 at 04:28AM by todhsals
via reddit https://ift.tt/2LnIZQ2
https://ift.tt/2uBjkdf
Submitted July 21, 2018 at 04:28AM by todhsals
via reddit https://ift.tt/2LnIZQ2
Palo Alto Networks Blog
Unit 42 Finds New Mirai and Gafgyt IoT/Linux Botnet Campaigns - Palo Alto Networks Blog
Unit 42 documents the emergence of three malware campaigns built on publicly available source code for the Mirai and Gafgyt malware families that incorporate multiple known exploits affecting Internet of Things (IoT) device.
XSS protection disappears from Microsoft Edge
https://ift.tt/2JCHAjI
Submitted July 19, 2018 at 08:32PM by albinowax
via reddit https://ift.tt/2uOg1i1
https://ift.tt/2JCHAjI
Submitted July 19, 2018 at 08:32PM by albinowax
via reddit https://ift.tt/2uOg1i1
The Daily Swig | Web security digest
XSS protection disappears from Microsoft Edge
#NoFilter
Gitleaks v1.0.0 -- Audit git repos for secrets. Updated with some performance gains, ui improvements, and new features.
https://ift.tt/2zULZPk
Submitted July 22, 2018 at 12:53AM by pr0tocol_7
via reddit https://ift.tt/2Lrbrk8
https://ift.tt/2zULZPk
Submitted July 22, 2018 at 12:53AM by pr0tocol_7
via reddit https://ift.tt/2Lrbrk8
GitHub
zricethezav/gitleaks
gitleaks - Audit git repos for secrets 🔑
RCE in Intel AMT for all current CPU's
https://ift.tt/2ubDJ8l
Submitted July 22, 2018 at 07:17PM by steak_and_icecream
via reddit https://ift.tt/2LspIwV
https://ift.tt/2ubDJ8l
Submitted July 22, 2018 at 07:17PM by steak_and_icecream
via reddit https://ift.tt/2LspIwV
Intel
Intel | Data Center Solutions, IoT, and PC Innovation
Intel's innovation in cloud computing, data center, Internet of Things, and PC solutions is powering the smart and connected digital world we live in.
"Bank Grade Security" - On Virgin Money and Authentication
https://ift.tt/2NDltw5
Submitted July 23, 2018 at 04:26PM by civicode
via reddit https://ift.tt/2JN57hN
https://ift.tt/2NDltw5
Submitted July 23, 2018 at 04:26PM by civicode
via reddit https://ift.tt/2JN57hN
Icyapril
"Bank Grade Security" - On Virgin Money and Authentication
The phrase “Bank Grade Security” usually provides little comfort for those of us in the information security world, but nevertheless, buzzword-driven markete...
Creating an Emojis PHP WebShell
https://ift.tt/2LvLsYI
Submitted July 23, 2018 at 06:41PM by mazen160
via reddit https://ift.tt/2uXSfQK
https://ift.tt/2LvLsYI
Submitted July 23, 2018 at 06:41PM by mazen160
via reddit https://ift.tt/2uXSfQK
blog.mazinahmed.net
Creating an Emojis PHP WebShell
I recently came across an interesting behaviour on PHP. Apparently, PHP permits the usage of Unicode characters as variable names. There...
Open ADB Ports Being Exploited to Spread Possible Satori Variant in Android Devices
https://ift.tt/2ObE8Af
Submitted July 23, 2018 at 08:33PM by EvanConover
via reddit https://ift.tt/2mFoG2C
https://ift.tt/2ObE8Af
Submitted July 23, 2018 at 08:33PM by EvanConover
via reddit https://ift.tt/2mFoG2C
Trendmicro
Open ADB Ports Being Exploited to Spread Possible Satori Variant in Android Devices - TrendLabs Security Intelligence Blog
Recently, we found a new exploit using port 5555 after detecting two suspicious spikes in activity on July 9-10 and July 15. In this scenario, the activity involves the command line utility called Android Debug Bridge (ADB), a part of the Android SDK that…
Blind XXE via Powerpoint files
https://ift.tt/2mBFF5S
Submitted July 23, 2018 at 08:54PM by albinowax
via reddit https://ift.tt/2NAucz6
https://ift.tt/2mBFF5S
Submitted July 23, 2018 at 08:54PM by albinowax
via reddit https://ift.tt/2NAucz6
HackerOne
Open-Xchange disclosed on HackerOne: Blind XXE via Powerpoint files
## Summary
During the parsing of Powerpoint files it seems that it is possible to include XXE payload which will be executed on the Open-XChange server. I was able to identify which files exist on...
During the parsing of Powerpoint files it seems that it is possible to include XXE payload which will be executed on the Open-XChange server. I was able to identify which files exist on...
Detecting Same-Origin Redirections with a bug in Firefox's CSP Implementation
https://ift.tt/2ObemvD
Submitted July 23, 2018 at 08:53PM by albinowax
via reddit https://ift.tt/2Lk8ClG
https://ift.tt/2ObemvD
Submitted July 23, 2018 at 08:53PM by albinowax
via reddit https://ift.tt/2Lk8ClG
diary.shift-js.info
Detect the Same-Origin Redirection with a bug in Firefox's CSP Implementation
Summary
Firefox’s bug in CSP implementation, which will be fixed in Firefox 62, provides us the way to detect the redirection of any given URL when accessed with the victim’s Firefox. Practically, OAuth is one of interesting features which requires redirections.…
Firefox’s bug in CSP implementation, which will be fixed in Firefox 62, provides us the way to detect the redirection of any given URL when accessed with the victim’s Firefox. Practically, OAuth is one of interesting features which requires redirections.…
Intel patches new ME vulnerabilities
https://ift.tt/2L53Ok5
Submitted July 23, 2018 at 11:10PM by b1rch_b0y
via reddit https://ift.tt/2LkiD27
https://ift.tt/2L53Ok5
Submitted July 23, 2018 at 11:10PM by b1rch_b0y
via reddit https://ift.tt/2LkiD27
Ptsecurity
Intel patches new ME vulnerabilities
In early July, Intel issued security advisories SA-00112 and SA-00118 regarding fixes for vulnerabilities in Intel Management Engine. ...
Emojis webshell
https://ift.tt/2A3za5s
Submitted July 23, 2018 at 10:56PM by vitalysim
via reddit https://ift.tt/2Lx1CRx
https://ift.tt/2A3za5s
Submitted July 23, 2018 at 10:56PM by vitalysim
via reddit https://ift.tt/2Lx1CRx
GitHub
mazen160/public
Contribute to public development by creating an account on GitHub.
Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again
https://ift.tt/2LJh7CX
Submitted July 24, 2018 at 01:19AM by albinowax
via reddit https://ift.tt/2AaLroS
https://ift.tt/2LJh7CX
Submitted July 24, 2018 at 01:19AM by albinowax
via reddit https://ift.tt/2AaLroS
blog.bentkowski.info
Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again
A few mongth ago, Google released a new product - Hangouts Chat application, which is surely an answer to Slack . Hangouts Chat might be us...