4 free tools to help lock down your web security
https://ift.tt/2PpEyDF
Submitted August 20, 2018 at 07:05PM by KeyDutch
via reddit https://ift.tt/2vZfYBs
https://ift.tt/2PpEyDF
Submitted August 20, 2018 at 07:05PM by KeyDutch
via reddit https://ift.tt/2vZfYBs
securitybrief.eu
Four free tools to help lock down your web security
With ever-tightening budgets it can be difficult to convince your managers to invest in security tools.
Open Sourcing ModSecurity for Envoy Proxy
https://ift.tt/2N2nYYJ
Submitted August 20, 2018 at 06:58PM by jekapats
via reddit https://ift.tt/2OPRbXj
https://ift.tt/2N2nYYJ
Submitted August 20, 2018 at 06:58PM by jekapats
via reddit https://ift.tt/2OPRbXj
GitHub
octarinesec/ModSecurity-envoy
ModSecurity-envoy - ModSecurity V3 Envoy Filter
Solid write up for some vulnerabilities exploits found in embedded electronics. TerraMaster NAS Exploited.
https://ift.tt/2N5EneT
Submitted August 20, 2018 at 08:17PM by goopcat
via reddit https://ift.tt/2OMh36v
https://ift.tt/2N5EneT
Submitted August 20, 2018 at 08:17PM by goopcat
via reddit https://ift.tt/2OMh36v
Independent Security Evaluators
TerraMaster NAS Vulnerabilities Discovered and Exploited
ISE Labs Earns 24 CVEs for New Vulnerabilities in TOS, TerraMaster’s NAS OS
Burp's new REST API
https://ift.tt/2OOlspu
Submitted August 20, 2018 at 11:03PM by IamJacksLackOf
via reddit https://ift.tt/2nQxyD7
https://ift.tt/2OOlspu
Submitted August 20, 2018 at 11:03PM by IamJacksLackOf
via reddit https://ift.tt/2nQxyD7
Web Security Blog | PortSwigger
Burp's new REST API
Burp is getting a brand new REST API, which can be used by other tools to integrate with Burp Suite: In the initial release, the REST API supports launching vulnerability scans and obtaining the resul
Android P Enables DNS Over TLS By Default
https://ift.tt/2MqGKgi
Submitted August 21, 2018 at 12:31AM by PrimeMover17
via reddit https://ift.tt/2Pqh9lc
https://ift.tt/2MqGKgi
Submitted August 21, 2018 at 12:31AM by PrimeMover17
via reddit https://ift.tt/2Pqh9lc
Decipher
How Android P Upgrades User and Device Security
Security in Android P is significantly different than in previous versions, as Google has added many new defensive measures.
Reversing the Toshiba FlashAir Wi-Fi SD card - discover its CPU, it’s OS and how you can execute native code!
https://ift.tt/2w3xCDU
Submitted August 21, 2018 at 06:15PM by guedou
via reddit https://ift.tt/2LerQnY
https://ift.tt/2w3xCDU
Submitted August 21, 2018 at 06:15PM by guedou
via reddit https://ift.tt/2LerQnY
Google Docs
BHUS18 - flashre
Reversing a Japanese Wireless SD Card From Zero to Code Execution Guillaume VALADON - @guedou Before the talk Chromebook console zoom: 175%/200% ./setup.sh zoom the presenter notes
OpenSSH User Enumeration Vulnerability: a Close Look
https://ift.tt/2PsaRS9
Submitted August 21, 2018 at 08:41PM by daanraman
via reddit https://ift.tt/2Bskcq8
https://ift.tt/2PsaRS9
Submitted August 21, 2018 at 08:41PM by daanraman
via reddit https://ift.tt/2Bskcq8
NVISO Labs
OpenSSH User Enumeration Vulnerability: a Close Look
Intro An OpenSSH user enumeration vulnerability (CVE-2018-15473) became public via a GitHub commit. This vulnerability does not produce a list of valid usernames, but it does allow guessing of user…
How we could hack law firms with their abandoned domain names
https://ift.tt/2wbAYE4
Submitted August 21, 2018 at 10:28PM by msp_guru
via reddit https://ift.tt/2BxaWkL
https://ift.tt/2wbAYE4
Submitted August 21, 2018 at 10:28PM by msp_guru
via reddit https://ift.tt/2BxaWkL
Rainbow and Unicorn
Hacking law firms with abandoned domain names
Domain name abandonment is a major cyber threat to your businesses. This report shows how cybercriminals can hijack your emails and online services.
Introducing Pacu: The Open Source AWS Exploitation Framework
https://ift.tt/2nTAoHk
Submitted August 21, 2018 at 10:28PM by hackers_and_builders
via reddit https://ift.tt/2BwvF8g
https://ift.tt/2nTAoHk
Submitted August 21, 2018 at 10:28PM by hackers_and_builders
via reddit https://ift.tt/2BwvF8g
reddit
r/netsec - Introducing Pacu: The Open Source AWS Exploitation Framework
4 votes and 0 comments so far on Reddit
All BlackHat Attendee registration data available via unauthenticated API - names, emails, phone numbers, addresses
https://ift.tt/2nR5jUO
Submitted August 21, 2018 at 10:20PM by n00py
via reddit https://ift.tt/2LisMHI
https://ift.tt/2nR5jUO
Submitted August 21, 2018 at 10:20PM by n00py
via reddit https://ift.tt/2LisMHI
ninja.style
How I Hacked BlackHat 2018
Enumerating registered BlackHat attendees with the BCard API
It’s Time for Token Binding
https://ift.tt/2ORcYOr
Submitted August 22, 2018 at 01:33AM by shehackspurple
via reddit https://ift.tt/2MnLwuV
https://ift.tt/2ORcYOr
Submitted August 22, 2018 at 01:33AM by shehackspurple
via reddit https://ift.tt/2MnLwuV
Microsoft
It’s Time for Token Binding
Howdy Folks, The last few months have been some VERY exciting times in the world of identity and security standards. Due to the efforts of a broad set of experts across the industry, we’ve made incredible progress in finalizing a broad set of new and improved…
CVE-2018-0952: Finding a Privilege Escalation Vulnerability in Windows 10, Server 2016, and Visual Studio (includes PoC)
https://ift.tt/2Na2F7x
Submitted August 22, 2018 at 03:15AM by ryhanson
via reddit https://ift.tt/2PtxENC
https://ift.tt/2Na2F7x
Submitted August 22, 2018 at 03:15AM by ryhanson
via reddit https://ift.tt/2PtxENC
Atredis Partners
CVE-2018-0952: Privilege Escalation Vulnerability in Windows Standard Collector Service — Atredis Partners
In this write-up, Ryan Hanson describes his process for identifying and exploiting CVE-2018-0952, an arbitrary file creation vulnerability in the Windows Diagnostics Hub Standard Collector service, allowing for elevation of privileges.
Inception Framework - Provides In-memory compilation and reflective loading of C# apps for AV evasion
https://ift.tt/2BnuCrn
Submitted August 22, 2018 at 01:00PM by PeterG45
via reddit https://ift.tt/2Mq4Wzs
https://ift.tt/2BnuCrn
Submitted August 22, 2018 at 01:00PM by PeterG45
via reddit https://ift.tt/2Mq4Wzs
GitHub
two06/Inception
Inception - Provides In-memory compilation and reflective loading of C# apps for AV evasion.
Ghostnoscript Remote Execution Bug
https://ift.tt/2LdOtJ5
Submitted August 22, 2018 at 11:51AM by le-quack
via reddit https://ift.tt/2N8jIHl
https://ift.tt/2LdOtJ5
Submitted August 22, 2018 at 11:51AM by le-quack
via reddit https://ift.tt/2N8jIHl
seclists.org
oss-sec: More Ghostnoscript Issues: Should we disable PS coders in policy.xml by default?
In-memory powershell reverse SSH+proxy noscript
https://ift.tt/2LhljIY
Submitted August 22, 2018 at 08:02PM by fridgehead
via reddit https://ift.tt/2w1Ww6O
https://ift.tt/2LhljIY
Submitted August 22, 2018 at 08:02PM by fridgehead
via reddit https://ift.tt/2w1Ww6O
GitHub
fridgehead/Powershell-SSHTools
Powershell-SSHTools - A bunch of useful SSH tools for powershell
Targeted ransomware dubbed Ryuk is hitting organizations worldwide, appears related to previous North Korean malware Hermes
https://ift.tt/2Mq3FIv
Submitted August 22, 2018 at 07:54PM by _marklech_
via reddit https://ift.tt/2LiSAmZ
https://ift.tt/2Mq3FIv
Submitted August 22, 2018 at 07:54PM by _marklech_
via reddit https://ift.tt/2LiSAmZ
Check Point Research
Ryuk Ransomware: A Targeted Campaign Break-Down - Check Point Research
Over the past two weeks, Ryuk, a targeted and well-planned Ransomware, has attacked various organizations worldwide. So far the campaign has targeted several enterprises, while encrypting hundreds of PC, storage and data centers in each infected company.…
Lessons Learned Deploying a Generic CSRF Solution
https://ift.tt/2Pxaczd
Submitted August 22, 2018 at 08:40PM by jrozner
via reddit https://ift.tt/2MGFi8K
https://ift.tt/2Pxaczd
Submitted August 22, 2018 at 08:40PM by jrozner
via reddit https://ift.tt/2MGFi8K
Medium
Lessons Learned Deploying a Generic CSRF Solution
The summer of 2017 culminated the substantial research and development effort of a generic solution to CSRF that could be easily applied…
CVE-2018–4991: Adobe Creative Cloud Desktop Local Privilege Escalation via Signature Bypass”
https://ift.tt/2wqDczV
Submitted August 22, 2018 at 09:23PM by CodeColorist
via reddit https://ift.tt/2PstvJE
https://ift.tt/2wqDczV
Submitted August 22, 2018 at 09:23PM by CodeColorist
via reddit https://ift.tt/2PstvJE
Medium
CVE-2018–4991: Adobe Creative Cloud Desktop Local Privilege Escalation via Signature Bypass
The patch was issued in APSB18–12:
CVE-2018–8412: MS Office 2016 for Mac Privilege Escalation via a Legacy Package
https://ift.tt/2Pt5iTD
Submitted August 22, 2018 at 09:51PM by CodeColorist
via reddit https://ift.tt/2OY7gKO
https://ift.tt/2Pt5iTD
Submitted August 22, 2018 at 09:51PM by CodeColorist
via reddit https://ift.tt/2OY7gKO
Medium
CVE-2018–8412: MS Office 2016 for Mac Privilege Escalation via a Legacy Package
The patch has been released, please upgrade your MAU to 18081201
CVE-2018-11776: How to find 5 RCEs in Apache Struts with Semmle QL
https://ift.tt/2PwHNZN
Submitted August 22, 2018 at 10:31PM by sheepfiend
via reddit https://ift.tt/2BBf96Z
https://ift.tt/2PwHNZN
Submitted August 22, 2018 at 10:31PM by sheepfiend
via reddit https://ift.tt/2BBf96Z
Lgtm
CVE-2018-11776: How to find 5 RCEs in Apache Struts with Semmle QL
Semmle security researcher Man Yue Mo explains how he used Semmle QL's Data Flow library to discover multiple RCE vulnerabilities (CVE-2018-11776) in Apache Struts.
vulnerability affects all openssh versions released in the past twodecades
https://ift.tt/2BCSgQE
Submitted August 22, 2018 at 11:41PM by sai_ismyname
via reddit https://ift.tt/2NcCzRH
https://ift.tt/2BCSgQE
Submitted August 22, 2018 at 11:41PM by sai_ismyname
via reddit https://ift.tt/2NcCzRH
BleepingComputer
Vulnerability Affects All OpenSSH Versions Released in the Past Two Decades
A vulnerability affects all versions of the OpenSSH client released in the past two decades, ever since the application was released in 1999.