"Bank Grade Security" - On Virgin Money and Authentication
https://ift.tt/2NDltw5
Submitted July 23, 2018 at 04:26PM by civicode
via reddit https://ift.tt/2JN57hN
https://ift.tt/2NDltw5
Submitted July 23, 2018 at 04:26PM by civicode
via reddit https://ift.tt/2JN57hN
Icyapril
"Bank Grade Security" - On Virgin Money and Authentication
The phrase “Bank Grade Security” usually provides little comfort for those of us in the information security world, but nevertheless, buzzword-driven markete...
Creating an Emojis PHP WebShell
https://ift.tt/2LvLsYI
Submitted July 23, 2018 at 06:41PM by mazen160
via reddit https://ift.tt/2uXSfQK
https://ift.tt/2LvLsYI
Submitted July 23, 2018 at 06:41PM by mazen160
via reddit https://ift.tt/2uXSfQK
blog.mazinahmed.net
Creating an Emojis PHP WebShell
I recently came across an interesting behaviour on PHP. Apparently, PHP permits the usage of Unicode characters as variable names. There...
Open ADB Ports Being Exploited to Spread Possible Satori Variant in Android Devices
https://ift.tt/2ObE8Af
Submitted July 23, 2018 at 08:33PM by EvanConover
via reddit https://ift.tt/2mFoG2C
https://ift.tt/2ObE8Af
Submitted July 23, 2018 at 08:33PM by EvanConover
via reddit https://ift.tt/2mFoG2C
Trendmicro
Open ADB Ports Being Exploited to Spread Possible Satori Variant in Android Devices - TrendLabs Security Intelligence Blog
Recently, we found a new exploit using port 5555 after detecting two suspicious spikes in activity on July 9-10 and July 15. In this scenario, the activity involves the command line utility called Android Debug Bridge (ADB), a part of the Android SDK that…
Blind XXE via Powerpoint files
https://ift.tt/2mBFF5S
Submitted July 23, 2018 at 08:54PM by albinowax
via reddit https://ift.tt/2NAucz6
https://ift.tt/2mBFF5S
Submitted July 23, 2018 at 08:54PM by albinowax
via reddit https://ift.tt/2NAucz6
HackerOne
Open-Xchange disclosed on HackerOne: Blind XXE via Powerpoint files
## Summary
During the parsing of Powerpoint files it seems that it is possible to include XXE payload which will be executed on the Open-XChange server. I was able to identify which files exist on...
During the parsing of Powerpoint files it seems that it is possible to include XXE payload which will be executed on the Open-XChange server. I was able to identify which files exist on...
Detecting Same-Origin Redirections with a bug in Firefox's CSP Implementation
https://ift.tt/2ObemvD
Submitted July 23, 2018 at 08:53PM by albinowax
via reddit https://ift.tt/2Lk8ClG
https://ift.tt/2ObemvD
Submitted July 23, 2018 at 08:53PM by albinowax
via reddit https://ift.tt/2Lk8ClG
diary.shift-js.info
Detect the Same-Origin Redirection with a bug in Firefox's CSP Implementation
Summary
Firefox’s bug in CSP implementation, which will be fixed in Firefox 62, provides us the way to detect the redirection of any given URL when accessed with the victim’s Firefox. Practically, OAuth is one of interesting features which requires redirections.…
Firefox’s bug in CSP implementation, which will be fixed in Firefox 62, provides us the way to detect the redirection of any given URL when accessed with the victim’s Firefox. Practically, OAuth is one of interesting features which requires redirections.…
Intel patches new ME vulnerabilities
https://ift.tt/2L53Ok5
Submitted July 23, 2018 at 11:10PM by b1rch_b0y
via reddit https://ift.tt/2LkiD27
https://ift.tt/2L53Ok5
Submitted July 23, 2018 at 11:10PM by b1rch_b0y
via reddit https://ift.tt/2LkiD27
Ptsecurity
Intel patches new ME vulnerabilities
In early July, Intel issued security advisories SA-00112 and SA-00118 regarding fixes for vulnerabilities in Intel Management Engine. ...
Emojis webshell
https://ift.tt/2A3za5s
Submitted July 23, 2018 at 10:56PM by vitalysim
via reddit https://ift.tt/2Lx1CRx
https://ift.tt/2A3za5s
Submitted July 23, 2018 at 10:56PM by vitalysim
via reddit https://ift.tt/2Lx1CRx
GitHub
mazen160/public
Contribute to public development by creating an account on GitHub.
Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again
https://ift.tt/2LJh7CX
Submitted July 24, 2018 at 01:19AM by albinowax
via reddit https://ift.tt/2AaLroS
https://ift.tt/2LJh7CX
Submitted July 24, 2018 at 01:19AM by albinowax
via reddit https://ift.tt/2AaLroS
blog.bentkowski.info
Vulnerability in Hangouts Chat a.k.a. how Electron makes open redirect great again
A few mongth ago, Google released a new product - Hangouts Chat application, which is surely an answer to Slack . Hangouts Chat might be us...
Deobfuscating Emotet’s powershell payload
https://ift.tt/2v0zxry
Submitted July 24, 2018 at 12:21AM by Lasq
via reddit https://ift.tt/2LuzI8W
https://ift.tt/2v0zxry
Submitted July 24, 2018 at 12:21AM by Lasq
via reddit https://ift.tt/2LuzI8W
reddit
r/netsec - Deobfuscating Emotet’s powershell payload
2 votes and 0 comments so far on Reddit
Bug Bounty write-up : DNS rebinding in EOSIO keosd wallet
https://ift.tt/2NFvDw2
Submitted July 24, 2018 at 03:29AM by fproulx
via reddit https://ift.tt/2LHWXsU
https://ift.tt/2NFvDw2
Submitted July 24, 2018 at 03:29AM by fproulx
via reddit https://ift.tt/2LHWXsU
Medium
The call is coming from inside the house — DNS rebinding in EOSIO keosd wallet
(Before I begin — this bug was responsibly disclosed and has been fixed in the version 1.0.9 and later of EOSIO software, so I highly…
Russian Hackers Reach U.S. Utility Control Rooms, Homeland Security Officials Say
https://ift.tt/2LIwc7Q
Submitted July 24, 2018 at 09:45AM by mycall
via reddit https://ift.tt/2NFyLrJ
https://ift.tt/2LIwc7Q
Submitted July 24, 2018 at 09:45AM by mycall
via reddit https://ift.tt/2NFyLrJ
WSJ
Russian Hackers Reach U.S. Utility Control Rooms, Homeland Security Officials Say
Hackers working for Russia claimed “hundreds of victims” last year in a long-running campaign that put them inside the control rooms of U.S. electric utilities where they could have caused blackouts, federal officials said.
Red Alert 2.0: Android Trojan targets security-seekers
https://ift.tt/2A5el9I
Submitted July 24, 2018 at 12:35PM by Goovscoov
via reddit https://ift.tt/2NFcp9H
https://ift.tt/2A5el9I
Submitted July 24, 2018 at 12:35PM by Goovscoov
via reddit https://ift.tt/2NFcp9H
elfbac - runtime intent-level ABI-granular memory protection for Linux
http://elfbac.org/
Submitted July 24, 2018 at 12:57PM by wademealing
via reddit https://ift.tt/2A3ary1
http://elfbac.org/
Submitted July 24, 2018 at 12:57PM by wademealing
via reddit https://ift.tt/2A3ary1
TR | Web Application Penetration Tests With Netsparker
https://ift.tt/2mHFgim
Submitted July 24, 2018 at 04:14PM by berkdusunurx
via reddit https://ift.tt/2A6TPp6
https://ift.tt/2mHFgim
Submitted July 24, 2018 at 04:14PM by berkdusunurx
via reddit https://ift.tt/2A6TPp6
www.berkdusunur.net
TR | Netsparker ile Web Uygulama Sızma Testleri
Herkese Selamlar, Bu post Netsparker ile yapılan bir web uygulama testini simüle edip false positive oranları, optimizasyon ve diğer uy...
Compromised JavaScript Package Caught Stealing npm Credentials
https://ift.tt/2L9TdA5
Submitted July 24, 2018 at 06:13PM by vietthang0705
via reddit https://ift.tt/2uIRoEk
https://ift.tt/2L9TdA5
Submitted July 24, 2018 at 06:13PM by vietthang0705
via reddit https://ift.tt/2uIRoEk
BleepingComputer
Compromised JavaScript Package Caught Stealing npm Credentials
A hacker has gained access to a developer's npm account and injected malicious code into a popular JavaScript library, code that was designed to steal the npm credentials of users who utilize the poisoned package inside their projects.
Generate OpenConnect CSD files to bypass Cisco AnyConnect hostscan
https://ift.tt/2Ocp9pC
Submitted July 24, 2018 at 06:17PM by krieger_0x00
via reddit https://ift.tt/2v0eMwk
https://ift.tt/2Ocp9pC
Submitted July 24, 2018 at 06:17PM by krieger_0x00
via reddit https://ift.tt/2v0eMwk
reddit
r/netsec - Generate OpenConnect CSD files to bypass Cisco AnyConnect hostscan
1 vote and 0 comments so far on Reddit
Going Proactive on Security: Driving Encryption Adoption Intelligently
https://ift.tt/2JPDTaB
Submitted July 24, 2018 at 11:52PM by civicode
via reddit https://ift.tt/2ObwtBX
https://ift.tt/2JPDTaB
Submitted July 24, 2018 at 11:52PM by civicode
via reddit https://ift.tt/2ObwtBX
Cloudflare Blog
Going Proactive on Security: Driving Encryption Adoption Intelligently
It's no secret that Cloudflare operates at a huge scale. Cloudflare provides security and performance to over 9 million websites all around the world, from small businesses and WordPress blogs to Fortune 500 companies. That means one in every 10 web requests…
The IT security researchers at Israel Institute of Technology have discovered a critical security vulnerability in some implementations of the Bluetooth standard in which not all the parameters involved are appropriately validated by the cryptographic algorithm.
https://ift.tt/2uMNdaz
Submitted July 25, 2018 at 07:37AM by longevitytech
via reddit https://ift.tt/2A7AODf
https://ift.tt/2uMNdaz
Submitted July 25, 2018 at 07:37AM by longevitytech
via reddit https://ift.tt/2A7AODf
Longevity Technology
Update your devices: New Bluetooth flaw lets attackers monitor traffic
The Bluetooth flaw also opens door to a man-in-the-middle attack.
The IT security researchers at Israel Institute of Technology have discovered a critical s
The IT security researchers at Israel Institute of Technology have discovered a critical s
GhostPack: a collection of new offensive security C# tools
https://ift.tt/2mEXi4M
Submitted July 25, 2018 at 11:29AM by 0xdea
via reddit https://ift.tt/2v4KW9Z
https://ift.tt/2mEXi4M
Submitted July 25, 2018 at 11:29AM by 0xdea
via reddit https://ift.tt/2v4KW9Z
harmj0y
GhostPack
Anyone who has followed myself or my teammates at SpecterOps for a while knows that we’re fairly big fans of PowerShell. I’ve been involved in offensive PowerShell for about 4 years, @m…
Dirhunt: directory listing without bruteforce
https://ift.tt/2L9PhzC
Submitted July 25, 2018 at 11:14AM by toxicosmico
via reddit https://ift.tt/2Oeu6hG
https://ift.tt/2L9PhzC
Submitted July 25, 2018 at 11:14AM by toxicosmico
via reddit https://ift.tt/2Oeu6hG
GitHub
Nekmo/dirhunt
dirhunt - Find web directories without bruteforce
Attacking Private Networks from the Internet with DNS Rebinding
https://ift.tt/2I3OzRT
Submitted July 25, 2018 at 01:48PM by vasiliborodin
via reddit https://ift.tt/2LjCvCx
https://ift.tt/2I3OzRT
Submitted July 25, 2018 at 01:48PM by vasiliborodin
via reddit https://ift.tt/2LjCvCx
Medium
Attacking Private Networks from the Internet with DNS Rebinding
TL;DR Following the wrong link could allow remote attackers to control your WiFi router, Google Home, Roku, Sonos speakers, home…