Useless CSP - A list useless CSP of big websites
https://uselesscsp.com/
Submitted August 19, 2018 at 07:41PM by jvoisin
via reddit https://ift.tt/2nQYkLK
https://uselesscsp.com/
Submitted August 19, 2018 at 07:41PM by jvoisin
via reddit https://ift.tt/2nQYkLK
reddit
r/netsec - Useless CSP - A list useless CSP of big websites
8 votes and 0 comments so far on Reddit
Login Bypass on Pizza Hut India website & iPhone app to view user's personal details, order history
https://ift.tt/2nOEr7P
Submitted August 19, 2018 at 09:19PM by purplex21
via reddit https://ift.tt/2BqrWsW
https://ift.tt/2nOEr7P
Submitted August 19, 2018 at 09:19PM by purplex21
via reddit https://ift.tt/2BqrWsW
Bhumish Gajjar's Blog
Login Bypass on Pizza Hut India website & iPhone app
TLDR: You can bypass the OTP login (only available method to login) for Pizza Hut’s Indian website and iPhone app. I have tried contacting Pizza Hut on Twitter and Phone,…
BygoneSSL: Previous owners of your domains may own valid SSL certificates... And new owners of your old domains may be able to revoke your production colocated certificates
https://ift.tt/2Ple7yG
Submitted August 20, 2018 at 01:07PM by wifihack
via reddit https://ift.tt/2Bq3aJg
https://ift.tt/2Ple7yG
Submitted August 20, 2018 at 01:07PM by wifihack
via reddit https://ift.tt/2Bq3aJg
reddit
r/netsec - BygoneSSL: Previous owners of your domains may own valid SSL certificates... And new owners of your old domains may…
25 votes and 1 comment so far on Reddit
Disabling MacOS SIP via a VirtualBox kext Vulnerability
https://ift.tt/2OKuTpO
Submitted August 20, 2018 at 04:14PM by dmchell
via reddit https://ift.tt/2PpLOPZ
https://ift.tt/2OKuTpO
Submitted August 20, 2018 at 04:14PM by dmchell
via reddit https://ift.tt/2PpLOPZ
4 free tools to help lock down your web security
https://ift.tt/2PpEyDF
Submitted August 20, 2018 at 07:05PM by KeyDutch
via reddit https://ift.tt/2vZfYBs
https://ift.tt/2PpEyDF
Submitted August 20, 2018 at 07:05PM by KeyDutch
via reddit https://ift.tt/2vZfYBs
securitybrief.eu
Four free tools to help lock down your web security
With ever-tightening budgets it can be difficult to convince your managers to invest in security tools.
Open Sourcing ModSecurity for Envoy Proxy
https://ift.tt/2N2nYYJ
Submitted August 20, 2018 at 06:58PM by jekapats
via reddit https://ift.tt/2OPRbXj
https://ift.tt/2N2nYYJ
Submitted August 20, 2018 at 06:58PM by jekapats
via reddit https://ift.tt/2OPRbXj
GitHub
octarinesec/ModSecurity-envoy
ModSecurity-envoy - ModSecurity V3 Envoy Filter
Solid write up for some vulnerabilities exploits found in embedded electronics. TerraMaster NAS Exploited.
https://ift.tt/2N5EneT
Submitted August 20, 2018 at 08:17PM by goopcat
via reddit https://ift.tt/2OMh36v
https://ift.tt/2N5EneT
Submitted August 20, 2018 at 08:17PM by goopcat
via reddit https://ift.tt/2OMh36v
Independent Security Evaluators
TerraMaster NAS Vulnerabilities Discovered and Exploited
ISE Labs Earns 24 CVEs for New Vulnerabilities in TOS, TerraMaster’s NAS OS
Burp's new REST API
https://ift.tt/2OOlspu
Submitted August 20, 2018 at 11:03PM by IamJacksLackOf
via reddit https://ift.tt/2nQxyD7
https://ift.tt/2OOlspu
Submitted August 20, 2018 at 11:03PM by IamJacksLackOf
via reddit https://ift.tt/2nQxyD7
Web Security Blog | PortSwigger
Burp's new REST API
Burp is getting a brand new REST API, which can be used by other tools to integrate with Burp Suite: In the initial release, the REST API supports launching vulnerability scans and obtaining the resul
Android P Enables DNS Over TLS By Default
https://ift.tt/2MqGKgi
Submitted August 21, 2018 at 12:31AM by PrimeMover17
via reddit https://ift.tt/2Pqh9lc
https://ift.tt/2MqGKgi
Submitted August 21, 2018 at 12:31AM by PrimeMover17
via reddit https://ift.tt/2Pqh9lc
Decipher
How Android P Upgrades User and Device Security
Security in Android P is significantly different than in previous versions, as Google has added many new defensive measures.
Reversing the Toshiba FlashAir Wi-Fi SD card - discover its CPU, it’s OS and how you can execute native code!
https://ift.tt/2w3xCDU
Submitted August 21, 2018 at 06:15PM by guedou
via reddit https://ift.tt/2LerQnY
https://ift.tt/2w3xCDU
Submitted August 21, 2018 at 06:15PM by guedou
via reddit https://ift.tt/2LerQnY
Google Docs
BHUS18 - flashre
Reversing a Japanese Wireless SD Card From Zero to Code Execution Guillaume VALADON - @guedou Before the talk Chromebook console zoom: 175%/200% ./setup.sh zoom the presenter notes
OpenSSH User Enumeration Vulnerability: a Close Look
https://ift.tt/2PsaRS9
Submitted August 21, 2018 at 08:41PM by daanraman
via reddit https://ift.tt/2Bskcq8
https://ift.tt/2PsaRS9
Submitted August 21, 2018 at 08:41PM by daanraman
via reddit https://ift.tt/2Bskcq8
NVISO Labs
OpenSSH User Enumeration Vulnerability: a Close Look
Intro An OpenSSH user enumeration vulnerability (CVE-2018-15473) became public via a GitHub commit. This vulnerability does not produce a list of valid usernames, but it does allow guessing of user…
How we could hack law firms with their abandoned domain names
https://ift.tt/2wbAYE4
Submitted August 21, 2018 at 10:28PM by msp_guru
via reddit https://ift.tt/2BxaWkL
https://ift.tt/2wbAYE4
Submitted August 21, 2018 at 10:28PM by msp_guru
via reddit https://ift.tt/2BxaWkL
Rainbow and Unicorn
Hacking law firms with abandoned domain names
Domain name abandonment is a major cyber threat to your businesses. This report shows how cybercriminals can hijack your emails and online services.
Introducing Pacu: The Open Source AWS Exploitation Framework
https://ift.tt/2nTAoHk
Submitted August 21, 2018 at 10:28PM by hackers_and_builders
via reddit https://ift.tt/2BwvF8g
https://ift.tt/2nTAoHk
Submitted August 21, 2018 at 10:28PM by hackers_and_builders
via reddit https://ift.tt/2BwvF8g
reddit
r/netsec - Introducing Pacu: The Open Source AWS Exploitation Framework
4 votes and 0 comments so far on Reddit
All BlackHat Attendee registration data available via unauthenticated API - names, emails, phone numbers, addresses
https://ift.tt/2nR5jUO
Submitted August 21, 2018 at 10:20PM by n00py
via reddit https://ift.tt/2LisMHI
https://ift.tt/2nR5jUO
Submitted August 21, 2018 at 10:20PM by n00py
via reddit https://ift.tt/2LisMHI
ninja.style
How I Hacked BlackHat 2018
Enumerating registered BlackHat attendees with the BCard API
It’s Time for Token Binding
https://ift.tt/2ORcYOr
Submitted August 22, 2018 at 01:33AM by shehackspurple
via reddit https://ift.tt/2MnLwuV
https://ift.tt/2ORcYOr
Submitted August 22, 2018 at 01:33AM by shehackspurple
via reddit https://ift.tt/2MnLwuV
Microsoft
It’s Time for Token Binding
Howdy Folks, The last few months have been some VERY exciting times in the world of identity and security standards. Due to the efforts of a broad set of experts across the industry, we’ve made incredible progress in finalizing a broad set of new and improved…
CVE-2018-0952: Finding a Privilege Escalation Vulnerability in Windows 10, Server 2016, and Visual Studio (includes PoC)
https://ift.tt/2Na2F7x
Submitted August 22, 2018 at 03:15AM by ryhanson
via reddit https://ift.tt/2PtxENC
https://ift.tt/2Na2F7x
Submitted August 22, 2018 at 03:15AM by ryhanson
via reddit https://ift.tt/2PtxENC
Atredis Partners
CVE-2018-0952: Privilege Escalation Vulnerability in Windows Standard Collector Service — Atredis Partners
In this write-up, Ryan Hanson describes his process for identifying and exploiting CVE-2018-0952, an arbitrary file creation vulnerability in the Windows Diagnostics Hub Standard Collector service, allowing for elevation of privileges.
Inception Framework - Provides In-memory compilation and reflective loading of C# apps for AV evasion
https://ift.tt/2BnuCrn
Submitted August 22, 2018 at 01:00PM by PeterG45
via reddit https://ift.tt/2Mq4Wzs
https://ift.tt/2BnuCrn
Submitted August 22, 2018 at 01:00PM by PeterG45
via reddit https://ift.tt/2Mq4Wzs
GitHub
two06/Inception
Inception - Provides In-memory compilation and reflective loading of C# apps for AV evasion.
Ghostnoscript Remote Execution Bug
https://ift.tt/2LdOtJ5
Submitted August 22, 2018 at 11:51AM by le-quack
via reddit https://ift.tt/2N8jIHl
https://ift.tt/2LdOtJ5
Submitted August 22, 2018 at 11:51AM by le-quack
via reddit https://ift.tt/2N8jIHl
seclists.org
oss-sec: More Ghostnoscript Issues: Should we disable PS coders in policy.xml by default?
In-memory powershell reverse SSH+proxy noscript
https://ift.tt/2LhljIY
Submitted August 22, 2018 at 08:02PM by fridgehead
via reddit https://ift.tt/2w1Ww6O
https://ift.tt/2LhljIY
Submitted August 22, 2018 at 08:02PM by fridgehead
via reddit https://ift.tt/2w1Ww6O
GitHub
fridgehead/Powershell-SSHTools
Powershell-SSHTools - A bunch of useful SSH tools for powershell
Targeted ransomware dubbed Ryuk is hitting organizations worldwide, appears related to previous North Korean malware Hermes
https://ift.tt/2Mq3FIv
Submitted August 22, 2018 at 07:54PM by _marklech_
via reddit https://ift.tt/2LiSAmZ
https://ift.tt/2Mq3FIv
Submitted August 22, 2018 at 07:54PM by _marklech_
via reddit https://ift.tt/2LiSAmZ
Check Point Research
Ryuk Ransomware: A Targeted Campaign Break-Down - Check Point Research
Over the past two weeks, Ryuk, a targeted and well-planned Ransomware, has attacked various organizations worldwide. So far the campaign has targeted several enterprises, while encrypting hundreds of PC, storage and data centers in each infected company.…
Lessons Learned Deploying a Generic CSRF Solution
https://ift.tt/2Pxaczd
Submitted August 22, 2018 at 08:40PM by jrozner
via reddit https://ift.tt/2MGFi8K
https://ift.tt/2Pxaczd
Submitted August 22, 2018 at 08:40PM by jrozner
via reddit https://ift.tt/2MGFi8K
Medium
Lessons Learned Deploying a Generic CSRF Solution
The summer of 2017 culminated the substantial research and development effort of a generic solution to CSRF that could be easily applied…