Generate OpenConnect CSD files to bypass Cisco AnyConnect hostscan
https://ift.tt/2Ocp9pC
Submitted July 24, 2018 at 06:17PM by krieger_0x00
via reddit https://ift.tt/2v0eMwk
https://ift.tt/2Ocp9pC
Submitted July 24, 2018 at 06:17PM by krieger_0x00
via reddit https://ift.tt/2v0eMwk
reddit
r/netsec - Generate OpenConnect CSD files to bypass Cisco AnyConnect hostscan
1 vote and 0 comments so far on Reddit
Going Proactive on Security: Driving Encryption Adoption Intelligently
https://ift.tt/2JPDTaB
Submitted July 24, 2018 at 11:52PM by civicode
via reddit https://ift.tt/2ObwtBX
https://ift.tt/2JPDTaB
Submitted July 24, 2018 at 11:52PM by civicode
via reddit https://ift.tt/2ObwtBX
Cloudflare Blog
Going Proactive on Security: Driving Encryption Adoption Intelligently
It's no secret that Cloudflare operates at a huge scale. Cloudflare provides security and performance to over 9 million websites all around the world, from small businesses and WordPress blogs to Fortune 500 companies. That means one in every 10 web requests…
The IT security researchers at Israel Institute of Technology have discovered a critical security vulnerability in some implementations of the Bluetooth standard in which not all the parameters involved are appropriately validated by the cryptographic algorithm.
https://ift.tt/2uMNdaz
Submitted July 25, 2018 at 07:37AM by longevitytech
via reddit https://ift.tt/2A7AODf
https://ift.tt/2uMNdaz
Submitted July 25, 2018 at 07:37AM by longevitytech
via reddit https://ift.tt/2A7AODf
Longevity Technology
Update your devices: New Bluetooth flaw lets attackers monitor traffic
The Bluetooth flaw also opens door to a man-in-the-middle attack.
The IT security researchers at Israel Institute of Technology have discovered a critical s
The IT security researchers at Israel Institute of Technology have discovered a critical s
GhostPack: a collection of new offensive security C# tools
https://ift.tt/2mEXi4M
Submitted July 25, 2018 at 11:29AM by 0xdea
via reddit https://ift.tt/2v4KW9Z
https://ift.tt/2mEXi4M
Submitted July 25, 2018 at 11:29AM by 0xdea
via reddit https://ift.tt/2v4KW9Z
harmj0y
GhostPack
Anyone who has followed myself or my teammates at SpecterOps for a while knows that we’re fairly big fans of PowerShell. I’ve been involved in offensive PowerShell for about 4 years, @m…
Dirhunt: directory listing without bruteforce
https://ift.tt/2L9PhzC
Submitted July 25, 2018 at 11:14AM by toxicosmico
via reddit https://ift.tt/2Oeu6hG
https://ift.tt/2L9PhzC
Submitted July 25, 2018 at 11:14AM by toxicosmico
via reddit https://ift.tt/2Oeu6hG
GitHub
Nekmo/dirhunt
dirhunt - Find web directories without bruteforce
Attacking Private Networks from the Internet with DNS Rebinding
https://ift.tt/2I3OzRT
Submitted July 25, 2018 at 01:48PM by vasiliborodin
via reddit https://ift.tt/2LjCvCx
https://ift.tt/2I3OzRT
Submitted July 25, 2018 at 01:48PM by vasiliborodin
via reddit https://ift.tt/2LjCvCx
Medium
Attacking Private Networks from the Internet with DNS Rebinding
TL;DR Following the wrong link could allow remote attackers to control your WiFi router, Google Home, Roku, Sonos speakers, home…
UNDER THE HOODIE: Lessons from a Season of Penetration Testing (2018)
https://ift.tt/2LAOjzu
Submitted July 25, 2018 at 02:21PM by shleimeleh
via reddit https://ift.tt/2LzZ9WJ
https://ift.tt/2LAOjzu
Submitted July 25, 2018 at 02:21PM by shleimeleh
via reddit https://ift.tt/2LzZ9WJ
CVE-2018-14533: From writing to /tmp to a root shell on Inteno IOPSYS
https://ift.tt/2OdYAAt
Submitted July 25, 2018 at 09:32PM by AVERAGE_TEST_DUMMY
via reddit https://ift.tt/2A9jg9P
https://ift.tt/2OdYAAt
Submitted July 25, 2018 at 09:32PM by AVERAGE_TEST_DUMMY
via reddit https://ift.tt/2A9jg9P
neonsea.uk
From writing to /tmp to a root shell on Inteno IOPSYS
In this blog post, I describe how multiple safe features and configurations can be used to gain full filesystem read-write access - and a root shell - on dev...
Oracle Privilege Escalation via XML Deserialization
https://ift.tt/2v3kJbF
Submitted July 25, 2018 at 10:12PM by Bowserjklol
via reddit https://ift.tt/2Lp6gBO
https://ift.tt/2v3kJbF
Submitted July 25, 2018 at 10:12PM by Bowserjklol
via reddit https://ift.tt/2Lp6gBO
Syfrtext
Oracle Privilege Escalation via Deserialization
TLDR: Oracle Database is vulnerable to user privilege escalation via a java deserialization vector that bypasses built in Oracle JVM secur...
Cracking the Walls of the Safari Sandbox: Fuzzing the macOS WindowServer for Exploitable Vulnerabilities
https://ift.tt/2JVawna
Submitted July 25, 2018 at 10:25PM by gaasedelen
via reddit https://ift.tt/2mGMXoV
https://ift.tt/2JVawna
Submitted July 25, 2018 at 10:25PM by gaasedelen
via reddit https://ift.tt/2mGMXoV
Ret2 Systems Blog
Cracking the Walls of the Safari Sandbox
When exploiting real world software or devices, achieving arbitrary code execution on a system may only be the first step towards total compromise. For high ...
Oracle Privilege Escalation via XML Deserialization
https://ift.tt/2v3kJbF
Submitted July 25, 2018 at 10:12PM by Bowserjklol
via reddit https://ift.tt/2Lp6gBO
https://ift.tt/2v3kJbF
Submitted July 25, 2018 at 10:12PM by Bowserjklol
via reddit https://ift.tt/2Lp6gBO
Syfrtext
Oracle Privilege Escalation via Deserialization
TLDR: Oracle Database is vulnerable to user privilege escalation via a java deserialization vector that bypasses built in Oracle JVM secur...
Solving the Atredis BlackHat 2018 CTF Challenge
https://ift.tt/2JRLaXg
Submitted July 25, 2018 at 10:01PM by rolfr
via reddit https://ift.tt/2mNSlH7
https://ift.tt/2JRLaXg
Submitted July 25, 2018 at 10:01PM by rolfr
via reddit https://ift.tt/2mNSlH7
Möbius Strip Reverse Engineering
The Atredis BlackHat 2018 CTF Challenge
This post covers my solution to the Atredis BlackHat 2018 challenge , for which I won second place and a ticket to BlackHat. I'd like to express my gratitude to the author, the increasingly-reclusive Dionysus Blazakis, as well as Atredis for running the…
Top HTTP Security Headers and How to Deploy Them
https://ift.tt/2LP0MN2
Submitted July 25, 2018 at 11:43PM by isityoupaul
via reddit https://ift.tt/2OeiQ4Z
https://ift.tt/2LP0MN2
Submitted July 25, 2018 at 11:43PM by isityoupaul
via reddit https://ift.tt/2OeiQ4Z
Templarbit Inc.
Top HTTP Security Headers and How to Deploy Them
HTTP response headers can be used to increase the security...
Introducing BYOB (Build Your Own Botnet)
https://ift.tt/2OfqsnE
Submitted July 26, 2018 at 06:40AM by PoonSafari
via reddit https://ift.tt/2A7QNBe
https://ift.tt/2OfqsnE
Submitted July 26, 2018 at 06:40AM by PoonSafari
via reddit https://ift.tt/2A7QNBe
GitHub
malwaredllc/byob
BYOB (Build Your Own Botnet). Contribute to malwaredllc/byob development by creating an account on GitHub.
Why No HTTPS? The World's Largest Websites Not Redirecting Insecure Requests to HTTPS
https://whynohttps.com
Submitted July 26, 2018 at 02:37PM by anonyymi
via reddit https://ift.tt/2vedj5N
https://whynohttps.com
Submitted July 26, 2018 at 02:37PM by anonyymi
via reddit https://ift.tt/2vedj5N
Whynohttps
Why No HTTPS? The World's Largest Websites Not Redirecting Insecure Requests to HTTPS
With the web rapidly becoming secure by default, "Why No HTTPS?" is a who's who of the world's biggest websites globally and by country still not defaulting to HTTPS.
Evilginx 2 - Next Generation of Phishing 2FA Tokens (Tool)
https://ift.tt/2JTHIeF
Submitted July 26, 2018 at 03:31PM by kgretzky
via reddit https://ift.tt/2LrIAgf
https://ift.tt/2JTHIeF
Submitted July 26, 2018 at 03:31PM by kgretzky
via reddit https://ift.tt/2LrIAgf
reddit
r/netsec - Evilginx 2 - Next Generation of Phishing 2FA Tokens (Tool)
3 votes and 0 comments so far on Reddit
Running Kali Linux 2018.2 on a GPD Pocket mini-laptop.
https://ift.tt/2mLvc85
Submitted July 26, 2018 at 03:25PM by vasiliborodin
via reddit https://ift.tt/2v7Sk4i
https://ift.tt/2mLvc85
Submitted July 26, 2018 at 03:25PM by vasiliborodin
via reddit https://ift.tt/2v7Sk4i
Hacker Noon
Kali Linux 2018.2 on your Pocket with the GPD 7 mini-laptop.
So after ten years, are netbooks finally cool again? In 2008 saw the zenith of this with regards to personal computing. The Netbook as…
Network Security - The Complete Nmap Ethical Hacking Course
http://sumo.ly/VNj9
Submitted July 26, 2018 at 06:04PM by algbra
via reddit https://ift.tt/2uQNpW6
http://sumo.ly/VNj9
Submitted July 26, 2018 at 06:04PM by algbra
via reddit https://ift.tt/2uQNpW6
Gain From Here
Ethical Hacking and Cyber Security Courses Online
If you are interested in learning Ethical Hacking and Cyber Security Courses online then you can consider some best courses here
A Story About Three Bluetooth Vulnerabilities in Android
https://ift.tt/2Ohz5hm
Submitted July 26, 2018 at 07:09PM by vamediah
via reddit https://ift.tt/2LAksrd
https://ift.tt/2Ohz5hm
Submitted July 26, 2018 at 07:09PM by vamediah
via reddit https://ift.tt/2LAksrd
Another way to get to a system shell – Assistive Technology
https://ift.tt/2v6fGY3
Submitted July 26, 2018 at 07:53PM by oddvarmoe
via reddit https://ift.tt/2mJzKM7
https://ift.tt/2v6fGY3
Submitted July 26, 2018 at 07:53PM by oddvarmoe
via reddit https://ift.tt/2mJzKM7
Oddvar Moe's Blog
Another way to get to a system shell – Assistive Technology
TL;DR Manipulate HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\ATs\magnifier – StartExe to run other binary when pressing WinKey and plus to zoom. Can load bin…
Code Similarities and Mitigation of Emotet, The Most Common Banking Trojan
https://ift.tt/2LRCCl1
Submitted July 26, 2018 at 09:04PM by desegel
via reddit https://ift.tt/2uP2YOg
https://ift.tt/2LRCCl1
Submitted July 26, 2018 at 09:04PM by desegel
via reddit https://ift.tt/2uP2YOg
Intezer
Mitigating Emotet, The Most Common Banking Trojan - Intezer
Recently, Proofpoint released a fairly surprising report, stating that Banking Trojans have surpassed Ransomware as the top malware threat found in email. This is not too surprising, due to the rising difficulty of cashing out cyber-ransom operations, and…