Major websites still fail to steer users towards better passwords - Help Net Security
https://ift.tt/2Li1zd4
Submitted July 27, 2018 at 07:03PM by iHatePasswordz
via reddit https://ift.tt/2Lpyb4R
https://ift.tt/2Li1zd4
Submitted July 27, 2018 at 07:03PM by iHatePasswordz
via reddit https://ift.tt/2Lpyb4R
Help Net Security
Major websites still fail to steer users towards better passwords - Help Net Security
Until the death of passwords happens, it would be helpful if popular online services would steer users towards choosing better passwords.
New Underminer Exploit Kit Delivers Bootkit and Cryptocurrency-mining Malware with Encrypted TCP Tunnel
https://ift.tt/2uTNU1A
Submitted July 27, 2018 at 09:45PM by EvanConover
via reddit https://ift.tt/2LUQGKF
https://ift.tt/2uTNU1A
Submitted July 27, 2018 at 09:45PM by EvanConover
via reddit https://ift.tt/2LUQGKF
Trendmicro
New Underminer Exploit Kit Delivers Bootkit and Cryptocurrency-mining Malware with Encrypted TCP Tunnel - TrendLabs Security Intelligence…
We discovered an exploit kit we named Underminer that uses capabilities to deter researchers from tracking its activity or reverse engineering the payloads
SQL Injection and A silly WAF
https://ift.tt/2K0PYJX
Submitted July 27, 2018 at 04:31AM by Bitsplz
via reddit https://ift.tt/2Lq01hn
https://ift.tt/2K0PYJX
Submitted July 27, 2018 at 04:31AM by Bitsplz
via reddit https://ift.tt/2Lq01hn
Blogspot
SQL Injection and A silly WAF
Hi Folks, Today I'll be writing about some interesting SQL injection vulnerabilities I recently found. This is a private program so ...
A tcpdump Tutorial and Primer with Examples
https://ift.tt/1IwtXLs
Submitted July 27, 2018 at 11:30PM by danielrm26
via reddit https://ift.tt/2AhMljg
https://ift.tt/1IwtXLs
Submitted July 27, 2018 at 11:30PM by danielrm26
via reddit https://ift.tt/2AhMljg
Daniel Miessler
Practical tcpdump Examples - Daniel Miessler
Practical tcpdump examples that gives you maximum packet carving in the minimum amount of time. Includes numerous examples and explanations ranging from basic to advanced—including how to isolate hosts, networks, and specific protocols.
Better slow than sorry – VirtualBox 3D acceleration considered harmful
https://ift.tt/2uTz0sr
Submitted July 28, 2018 at 03:54AM by bkth_
via reddit https://ift.tt/2LGSvxW
https://ift.tt/2uTz0sr
Submitted July 28, 2018 at 03:54AM by bkth_
via reddit https://ift.tt/2LGSvxW
reddit
Better slow than sorry – VirtualBox 3D acceleration... • r/netsec
2 points and 1 comments so far on reddit
Raccoon: A new offensive security tool for reconnaissance and vulnerability scanning
https://ift.tt/2JUuUoi
Submitted July 28, 2018 at 06:35AM by GoatInABoat
via reddit https://ift.tt/2mNdPUn
https://ift.tt/2JUuUoi
Submitted July 28, 2018 at 06:35AM by GoatInABoat
via reddit https://ift.tt/2mNdPUn
GitHub
evyatarmeged/Raccoon
A high performance offensive security tool for reconnaissance and vulnerability scanning - evyatarmeged/Raccoon
Azure Security Center Documentation - Tutorials, API Reference
https://ift.tt/2mNEP5Z
Submitted July 28, 2018 at 07:12AM by shehackspurple
via reddit https://ift.tt/2AhGc6D
https://ift.tt/2mNEP5Z
Submitted July 28, 2018 at 07:12AM by shehackspurple
via reddit https://ift.tt/2AhGc6D
Docs
Azure Security Center Documentation - Tutorials, API Reference
potentially new evidence in the SingHealth breach
https://ift.tt/2OiGL3b
Submitted July 28, 2018 at 09:23AM by ksigler
via reddit https://ift.tt/2LUG4eM
https://ift.tt/2OiGL3b
Submitted July 28, 2018 at 09:23AM by ksigler
via reddit https://ift.tt/2LUG4eM
Trustwave
New Indicators Suggest Penetration Vectors and Earlier Dates for the SingHealth Breach
The Trustwave SpiderLabs team has found additional information that we believe may be associated with the recent SingHealth breach. You can read a summary of the breach in a previous post, but as a quick summary, Singaporean authorities announced on...
BYOB (Build Your Own Botnet)
https://ift.tt/2OfqsnE
Submitted July 29, 2018 at 01:29AM by PoonSafari
via reddit https://ift.tt/2LJjKId
https://ift.tt/2OfqsnE
Submitted July 29, 2018 at 01:29AM by PoonSafari
via reddit https://ift.tt/2LJjKId
GitHub
malwaredllc/byob
BYOB (Build Your Own Botnet). Contribute to malwaredllc/byob development by creating an account on GitHub.
NetShell's Little Helper: Maintain Persistence by Importing Evil Helper DLL's
https://ift.tt/2K3zNf5
Submitted July 29, 2018 at 07:56AM by _creosote
via reddit https://ift.tt/2OoK4Wx
https://ift.tt/2K3zNf5
Submitted July 29, 2018 at 07:56AM by _creosote
via reddit https://ift.tt/2OoK4Wx
Liberty
Hack the Helpers | Liberty
Bug bounty write-ups
https://ift.tt/2MoteGk
Submitted July 29, 2018 at 09:53PM by vitalysim
via reddit https://ift.tt/2vfJRMC
https://ift.tt/2MoteGk
Submitted July 29, 2018 at 09:53PM by vitalysim
via reddit https://ift.tt/2vfJRMC
Improving PHP extensions as a persistence method
https://ift.tt/2OrVbhf
Submitted July 30, 2018 at 12:34AM by gid0rah
via reddit https://ift.tt/2AnDPzi
https://ift.tt/2OrVbhf
Submitted July 30, 2018 at 12:34AM by gid0rah
via reddit https://ift.tt/2AnDPzi
x-c3ll.github.io
Improving PHP extensions as a persistence method ::
DoomsDay Vault
DoomsDay Vault
Article about how to build backdoors for the Zend Engine.
Making a Blind SQL Injection a Little Less Blind
https://ift.tt/2mP2qU1
Submitted July 30, 2018 at 12:52PM by albinowax
via reddit https://ift.tt/2vfsxHC
https://ift.tt/2mP2qU1
Submitted July 30, 2018 at 12:52PM by albinowax
via reddit https://ift.tt/2vfsxHC
Medium
Making a Blind SQL Injection a Little Less Blind
Someone told me the other day that “no-one does SQL Injection by hand any more”. I want to tell you about a SQL Injection bug that I found…
Exploiting Server-Side Template Injection in Craft CMS plugin SEOmatic
https://ift.tt/2K72cRj
Submitted July 30, 2018 at 03:38PM by albinowax
via reddit https://ift.tt/2M4N60I
https://ift.tt/2K72cRj
Submitted July 30, 2018 at 03:38PM by albinowax
via reddit https://ift.tt/2M4N60I
ha.cker.info
Exploitation of Server Side Template Injection with Craft CMS plugin SEOmatic <=3.1.3 [CVE-2018-14716]
During a recent webapplication testing I decided to perform some fuzzing of certain paths within the URI of a CMS and happened to find a potential SSTI (server side template injection) within one of t
Pegasus: analysis of network behavior
https://ift.tt/2Ao0Odt
Submitted July 30, 2018 at 05:10PM by alexlash
via reddit https://ift.tt/2LL0Not
https://ift.tt/2Ao0Odt
Submitted July 30, 2018 at 05:10PM by alexlash
via reddit https://ift.tt/2LL0Not
Ptsecurity
Pegasus: analysis of network behavior
Source code for Pegasus, a banking Trojan, was recently published online. Although the Carbanak cybercrime gang was referenced in the arch...
A new security header: Feature Policy
https://ift.tt/2uF2F7y
Submitted July 30, 2018 at 06:09PM by nickadam
via reddit https://ift.tt/2vbZoNo
https://ift.tt/2uF2F7y
Submitted July 30, 2018 at 06:09PM by nickadam
via reddit https://ift.tt/2vbZoNo
Scott Helme
A new security header: Feature Policy
We have a new Security Header!! Feature Policy will allow a site to enable or disable certain browser features and APIs in the interest of better security and privacy. Let's take a look! Feature Policy Feature Policy is being created to allow site owners…
NCSC 2018 Foreign Economic Espionage in Cyberspace
https://ift.tt/2NRxa2n
Submitted July 30, 2018 at 09:08PM by PrimeMover17
via reddit https://ift.tt/2M1TUfv
https://ift.tt/2NRxa2n
Submitted July 30, 2018 at 09:08PM by PrimeMover17
via reddit https://ift.tt/2M1TUfv
www.dni.gov
2018 Foreign Economic Espionage in Cyberspace
NEWS RELEASE FOR IMMEDIATE RELEASEJuly 26, 2018 NCSC Releases 2018 Foreign Economic Espionage in Cyberspace Report The National Counterintellig...
CVE-2017-16245 & CVE-2017-16246: Avecto Defendpoint Multiple Vulnerabilities
https://ift.tt/2v0L2A3
Submitted July 30, 2018 at 08:38PM by eth_
via reddit https://ift.tt/2mVgKdK
https://ift.tt/2v0L2A3
Submitted July 30, 2018 at 08:38PM by eth_
via reddit https://ift.tt/2mVgKdK
Nettitude Labs
CVE-2017-16245 & CVE-2017-16246: Avecto Defendpoint Multiple Vulnerabilities
Avecto Defendpoint is an endpoint protection product which, according to the Avecto website, will: “Prevent breaches without hindering productivity. Avecto combines best-in-class privilege manageme…
A Malvertising Campaign of Secrets and Lies
https://ift.tt/2LQoY4O
Submitted July 31, 2018 at 01:43AM by EvanConover
via reddit https://ift.tt/2K9IfJD
https://ift.tt/2LQoY4O
Submitted July 31, 2018 at 01:43AM by EvanConover
via reddit https://ift.tt/2K9IfJD
Check Point Research
A Malvertising Campaign of Secrets and Lies - Check Point Research
Check Point Research has uncovered a large Malvertising campaign that starts with thousands of compromised WordPress websites, involves multiple parties in the online advertising chain and ends with distributing malicious content, via multiple Exploit Kits…
Foreign Economic Espionage in Cyberspace (pdf)
https://ift.tt/2vheQrC
Submitted July 31, 2018 at 03:46AM by gr3yasp
via reddit https://ift.tt/2OvYOTI
https://ift.tt/2vheQrC
Submitted July 31, 2018 at 03:46AM by gr3yasp
via reddit https://ift.tt/2OvYOTI
Hakluke’s Guide to Hacking Without Metasploit (for OSCP)
https://ift.tt/2vkzyXK
Submitted July 31, 2018 at 11:12AM by hakluke
via reddit https://ift.tt/2LP63Y8
https://ift.tt/2vkzyXK
Submitted July 31, 2018 at 11:12AM by hakluke
via reddit https://ift.tt/2LP63Y8
Medium
Hakluke’s Guide to Hacking Without Metasploit
Ah the old “try harder” wisdom nugget. If taken in the right context, it is a slogan to live by. Unfortunately, most people don’t take it…