PowerShell Inside a Certificate? – Part 1
https://ift.tt/2Arvue1
Submitted July 31, 2018 at 03:01PM by daanraman
via reddit https://ift.tt/2As7vvd
https://ift.tt/2Arvue1
Submitted July 31, 2018 at 03:01PM by daanraman
via reddit https://ift.tt/2As7vvd
NVISO Labs
PowerShell Inside a Certificate? – Part 1
With the help of a specifically crafted YARA rule developed by NVISO analysts, we found multiple certificate files (.crt) that do not contain a certificate, but instead a malicious PowerShell scrip…
Multiple vulnerabilities in OCS Inventory 2.4.1 (RCE, SQLI & XXE)
https://ift.tt/2NXSNOa
Submitted July 31, 2018 at 02:35PM by gid0rah
via reddit https://ift.tt/2LL9Hm1
https://ift.tt/2NXSNOa
Submitted July 31, 2018 at 02:35PM by gid0rah
via reddit https://ift.tt/2LL9Hm1
Tarlogic Security - Cyber Security and Ethical hacking
Vulnerabilities in OCS Inventory 2.4.1
During a Red Team operation, multiple vulnerabilities were discovered in OCS Inventory (version 2.4.1). The following CVEs have been assigned to the vulnerabilities:
CVE-2018-12482 (Multiple SQL Injections in the search engine)
CVE-2018-12483 (Remote…
CVE-2018-12482 (Multiple SQL Injections in the search engine)
CVE-2018-12483 (Remote…
Learning Packet Analysis with Data Science
https://ift.tt/2mWQGPh
Submitted July 31, 2018 at 06:42PM by secdevops
via reddit https://ift.tt/2LGoMGb
https://ift.tt/2mWQGPh
Submitted July 31, 2018 at 06:42PM by secdevops
via reddit https://ift.tt/2LGoMGb
SecDevOps
Learning Packet Analysis with Data Science – SecDevOps
Have you ever opened Wireshark and thought, “this is nice, but sometimes filtering and following TCP streams is tedious?” If not, open…
CloudGoat: Intentionally vulnerable AWS Environment in Terraform
https://ift.tt/2OwtVyj
Submitted July 31, 2018 at 07:38PM by hackers_and_builders
via reddit https://ift.tt/2LOcWZS
https://ift.tt/2OwtVyj
Submitted July 31, 2018 at 07:38PM by hackers_and_builders
via reddit https://ift.tt/2LOcWZS
Windows privilege escalation
https://ift.tt/2AoLRrO
Submitted July 31, 2018 at 09:32PM by vitalysim
via reddit https://ift.tt/2v4EPDv
https://ift.tt/2AoLRrO
Submitted July 31, 2018 at 09:32PM by vitalysim
via reddit https://ift.tt/2v4EPDv
Memory Corruption
Notes on Windows Privilege Escalation
Hello friends!
Identifying web user social accounts, by exploiting user-blocking mechanisms
https://ift.tt/2KdYSE4?
Submitted July 31, 2018 at 10:04PM by pimterry
via reddit https://ift.tt/2LSe6DB
https://ift.tt/2KdYSE4?
Submitted July 31, 2018 at 10:04PM by pimterry
via reddit https://ift.tt/2LSe6DB
NTT official website
NTT Discovers Novel Privacy Threat “Silhouette” in Social Web Services
NTT Latest News Release
🔒UPASH - Node.js Unified API for Password Hashing Algorithms
https://ift.tt/2FiU66u
Submitted July 31, 2018 at 10:57PM by simonepri
via reddit https://ift.tt/2KdC2fC
https://ift.tt/2FiU66u
Submitted July 31, 2018 at 10:57PM by simonepri
via reddit https://ift.tt/2KdC2fC
GitHub
simonepri/upash
upash - 🔒Unified API for password hashing algorithms
Multiple Cobalt Personality Disorder
https://ift.tt/2Oxuzvu
Submitted July 31, 2018 at 10:55PM by zelyahzub
via reddit https://ift.tt/2Ovm6Zy
https://ift.tt/2Oxuzvu
Submitted July 31, 2018 at 10:55PM by zelyahzub
via reddit https://ift.tt/2Ovm6Zy
Talosintelligence
Multiple Cobalt Personality Disorder
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
Practical Protection Against DNS Rebinding Attacks
https://ift.tt/2n1jqXm
Submitted August 01, 2018 at 01:37AM by mazen160
via reddit https://ift.tt/2v4GGbc
https://ift.tt/2n1jqXm
Submitted August 01, 2018 at 01:37AM by mazen160
via reddit https://ift.tt/2v4GGbc
blog.mazinahmed.net
Practical Protection Against DNS Rebinding Attacks
DNS rebinding is a known attack against the same origin policy of modern browsers. The attack works by abusing DNS where a request wit...
Attacking the attackers: Execute code on the attacker's c&c
https://ift.tt/2M3uEW5
Submitted August 01, 2018 at 02:22AM by aaabbbaaabb
via reddit https://ift.tt/2mXHHgJ
https://ift.tt/2M3uEW5
Submitted August 01, 2018 at 02:22AM by aaabbbaaabb
via reddit https://ift.tt/2mXHHgJ
DNSRBL - Real-time Blackhole List (RBL)
https://dnsrbl.org/
Submitted August 01, 2018 at 08:03AM by unquietwiki
via reddit https://ift.tt/2v6M7GH
https://dnsrbl.org/
Submitted August 01, 2018 at 08:03AM by unquietwiki
via reddit https://ift.tt/2v6M7GH
Breaking the Bluetooth Pairing: A Fixed Coordinate Invalid Curve Attack
https://ift.tt/2AlidUf
Submitted August 01, 2018 at 09:23AM by TechLord2
via reddit https://ift.tt/2M7Y3yl
https://ift.tt/2AlidUf
Submitted August 01, 2018 at 09:23AM by TechLord2
via reddit https://ift.tt/2M7Y3yl
PowerShell Inside a Certificate? – Part 2
https://ift.tt/2KeKbRj
Submitted August 01, 2018 at 01:03PM by daanraman
via reddit https://ift.tt/2vsOvqw
https://ift.tt/2KeKbRj
Submitted August 01, 2018 at 01:03PM by daanraman
via reddit https://ift.tt/2vsOvqw
NVISO Labs
PowerShell Inside a Certificate? – Part 2
We developed a method to detect certificate files that do not contain a real certificate. Trojanized certificates like these are often not detected by AV and IDS. Fake certificates containing a Win…
Threat Intelligence Report - Campaign DOKKAEBI(a.k.a Malware analysis using HWP documents)
https://ift.tt/2v8qjdQ
Submitted August 01, 2018 at 07:00PM by 2runjack2
via reddit https://ift.tt/2Khf87g
https://ift.tt/2v8qjdQ
Submitted August 01, 2018 at 07:00PM by 2runjack2
via reddit https://ift.tt/2Khf87g
Inside Look at Emotet's Global Victims and Malspam Qakbot Payloads
https://ift.tt/2LVvQ0O
Submitted August 01, 2018 at 07:36PM by not_2sec4u
via reddit https://ift.tt/2M85bec
https://ift.tt/2LVvQ0O
Submitted August 01, 2018 at 07:36PM by not_2sec4u
via reddit https://ift.tt/2M85bec
Kryptoslogic
Inside Look at Emotet's Global Victims and Malspam Qakbot Payloads
The Emotet botnet reputation precedes it; historically aggressive and malicious, today it has evolved and incorporated a number of advancements to create a m...
Disclose Facebook Internal Server Information With A Strange Poll [Bug Bounty]
https://ift.tt/2NZ54SQ
Submitted August 01, 2018 at 09:02PM by wongmjane
via reddit https://ift.tt/2OBEno3
https://ift.tt/2NZ54SQ
Submitted August 01, 2018 at 09:02PM by wongmjane
via reddit https://ift.tt/2OBEno3
CRLF Injection Into PHP’s cURL Options
https://ift.tt/2LL8Ces
Submitted August 01, 2018 at 09:12PM by albinowax
via reddit https://ift.tt/2LJw77J
https://ift.tt/2LL8Ces
Submitted August 01, 2018 at 09:12PM by albinowax
via reddit https://ift.tt/2LJw77J
Medium
CRLF Injection Into PHP’s cURL Options
This is a post about injecting carriage return and line feed characters into a internal API call. I wrote this up a year ago as a Gist on…
Reddit had a security incident. Here's what you need to know.
https://ift.tt/2LSMr5z
Submitted August 01, 2018 at 11:23PM by sanitybit
via reddit https://ift.tt/2OBX9vF
https://ift.tt/2LSMr5z
Submitted August 01, 2018 at 11:23PM by sanitybit
via reddit https://ift.tt/2OBX9vF
reddit
We had a security incident. Here's what you need to know.
**TL;DR**: A hacker broke into a few of Reddit’s systems and managed to access some user data, including some current email addresses and a 2007...
Creating a key generator to reset a Hikvision IP camera's admin password
https://ift.tt/2LHAUGS
Submitted August 02, 2018 at 12:00AM by AVERAGE_TEST_DUMMY
via reddit https://ift.tt/2O4Opxg
https://ift.tt/2LHAUGS
Submitted August 02, 2018 at 12:00AM by AVERAGE_TEST_DUMMY
via reddit https://ift.tt/2O4Opxg
neonsea.uk
Creating a key generator to reset a Hikvision IP camera's admin password
Unfortunately, generic IP cameras are notorious for their poor security practices. Most of the time, the manufacturer’s don’t force secure passwords, and mor...
IMPLEMENTING A TRUSTED THIRD-PARTY SYSTEM FOR SECURE SHELL
https://ift.tt/2AwGGG5
Submitted August 02, 2018 at 01:28PM by kavanutz
via reddit https://ift.tt/2LKFqoe
https://ift.tt/2AwGGG5
Submitted August 02, 2018 at 01:28PM by kavanutz
via reddit https://ift.tt/2LKFqoe
Sshkeybox
KeyBox - Documentation: Whitepaper
Implementing a Trusted Third-Party System for Secure Shell
Escaping the Sandbox - Microsoft Office on MacOS
https://ift.tt/2n12YGy
Submitted August 02, 2018 at 01:47PM by dmchell
via reddit https://ift.tt/2AzEPAv
https://ift.tt/2n12YGy
Submitted August 02, 2018 at 01:47PM by dmchell
via reddit https://ift.tt/2AzEPAv
www.mdsec.co.uk
Escaping the Sandbox – Microsoft Office on MacOS – MDSec
A post describing how to escape the MacOS sandbox from within Office