Burp Suite 2.0 beta now available
https://ift.tt/2o50OpS
Submitted August 23, 2018 at 07:52PM by IamJacksLackOf
via reddit https://ift.tt/2BFhDBr
https://ift.tt/2o50OpS
Submitted August 23, 2018 at 07:52PM by IamJacksLackOf
via reddit https://ift.tt/2BFhDBr
Web Security Blog | PortSwigger
Burp Suite 2.0 beta now available
Burp Suite 2.0 beta is now available to Professional users. This is a major upgrade, with a host of new features, including: A new crawler, able to automatically handle sessions, detect changes in app
DNS Rebinding Headless Browsers: Breaching the perimeter and attacking cloud environments
https://ift.tt/2oaIZpz
Submitted August 23, 2018 at 08:51PM by alexksak
via reddit https://ift.tt/2w7cD3c
https://ift.tt/2oaIZpz
Submitted August 23, 2018 at 08:51PM by alexksak
via reddit https://ift.tt/2w7cD3c
reddit
r/netsec - DNS Rebinding Headless Browsers: Breaching the perimeter and attacking cloud environments
1 vote and 0 comments so far on Reddit
The importance of being noisy [LWN.net]
https://ift.tt/2wtLebh
Submitted August 24, 2018 at 01:29AM by skeeto
via reddit https://ift.tt/2BHVbYq
https://ift.tt/2wtLebh
Submitted August 24, 2018 at 01:29AM by skeeto
via reddit https://ift.tt/2BHVbYq
lwn.net
The importance of being noisy
Hundreds (at least) of kernel bugs are fixed every month. Given the
kernel's privileged position within the system, a relatively large portion
of those bugs have security implications. Many bugs are relatively easily
noticed once they are triggered; that…
kernel's privileged position within the system, a relatively large portion
of those bugs have security implications. Many bugs are relatively easily
noticed once they are triggered; that…
CVE-2018-15685 - Electron WebPreferences RCE (yet another nodeIntegration bypass bug)
https://ift.tt/2BJkI3d
Submitted August 24, 2018 at 10:49PM by nibblesec
via reddit https://ift.tt/2Muknq4
https://ift.tt/2BJkI3d
Submitted August 24, 2018 at 10:49PM by nibblesec
via reddit https://ift.tt/2Muknq4
GitHub
matt-/CVE-2018-15685
POC for CVE-2018-15685
Learn about the Struts2 Remote Code Execution vulnerability CVE-2018-11776, how to exploit and how to create a Proof of Concept (POC) with docker.
https://ift.tt/2BK09DL
Submitted August 25, 2018 at 03:11AM by secjuice
via reddit https://ift.tt/2PCCckS
https://ift.tt/2BK09DL
Submitted August 25, 2018 at 03:11AM by secjuice
via reddit https://ift.tt/2PCCckS
Secjuice.com
Apache Struts2 CVE-2018-11776
Learn about the Struts2 Remote Code Execution vulnerability CVE-2018-11776, how to exploit and how to create a Proof of Concept (POC) with docker.
Fortnite Installer downloads are vulnerable to hijacking
https://ift.tt/2PBk1Mg
Submitted August 25, 2018 at 06:49AM by monarchmra
via reddit https://ift.tt/2Nc96qO
https://ift.tt/2PBk1Mg
Submitted August 25, 2018 at 06:49AM by monarchmra
via reddit https://ift.tt/2Nc96qO
reddit
r/netsec - Fortnite Installer downloads are vulnerable to hijacking
0 votes and 1 comment so far on Reddit
Replaying Trickbot's C&C traffic with imaginary C2
https://ift.tt/2LueELA
Submitted August 25, 2018 at 08:10PM by _toti
via reddit https://ift.tt/2Ni3viR
https://ift.tt/2LueELA
Submitted August 25, 2018 at 08:10PM by _toti
via reddit https://ift.tt/2Ni3viR
GitHub
felixweyne/imaginaryC2
imaginaryC2 - Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures HTTP requests towards selectively cho...
Vba2Graph - Generate call graphs from VBA code for easier analysis of malicious documents
https://ift.tt/2wd9sHg
Submitted August 26, 2018 at 01:24AM by TechLord2
via reddit https://ift.tt/2My82S1
https://ift.tt/2wd9sHg
Submitted August 26, 2018 at 01:24AM by TechLord2
via reddit https://ift.tt/2My82S1
GitHub
MalwareCantFly/Vba2Graph
Vba2Graph - Generate call graphs from VBA code, for easier analysis of malicious documents.
Phishing for Files with Airmail 3 for Mac
https://ift.tt/2BAplN3
Submitted August 26, 2018 at 01:22AM by Natanael_L
via reddit https://ift.tt/2o92NcH
https://ift.tt/2BAplN3
Submitted August 26, 2018 at 01:22AM by Natanael_L
via reddit https://ift.tt/2o92NcH
VerSprite | Integrated Security Services and Consulting
Phishing for Files with Airmail 3 for Mac | VerSprite
We chose Airmail 3 as a target for reverse engineering to gain a better understanding of how MacOS applications work on a low-level.
Frida 12.1 is out with a brand new Chrome Inspector-compatible debugger integration for V8-powered noscripts
https://ift.tt/2BMg6JB
Submitted August 26, 2018 at 03:10AM by oleavr
via reddit https://ift.tt/2o9KPqr
https://ift.tt/2BMg6JB
Submitted August 26, 2018 at 03:10AM by oleavr
via reddit https://ift.tt/2o9KPqr
Frida • A world-class dynamic instrumentation framework
Frida 12.1 Released
Inject JavaScript to explore native apps on Windows, macOS, GNU/Linux, iOS, Android, and QNX
A reliable exploit for CVE-2018-11776 (Struts st2-057) is released
https://ift.tt/2BNtspc
Submitted August 26, 2018 at 08:15AM by mazen160
via reddit https://ift.tt/2o7ChAi
https://ift.tt/2BNtspc
Submitted August 26, 2018 at 08:15AM by mazen160
via reddit https://ift.tt/2o7ChAi
GitHub
mazen160/struts-pwn_CVE-2018-11776
struts-pwn_CVE-2018-11776 - An exploit for Apache Struts CVE-2018-11776
Why and How Use a Password Manager
https://ift.tt/2wpafEh
Submitted August 26, 2018 at 06:05PM by Icognito289
via reddit https://ift.tt/2P6jSPM
https://ift.tt/2wpafEh
Submitted August 26, 2018 at 06:05PM by Icognito289
via reddit https://ift.tt/2P6jSPM
Minute Cyber
Why and How Use a Password Manager
Even though nothing is foolproof, password managers are still by far the most reliable method of safe keeping your passwords but, that is only when you use them properly. We are going to tell you w…
CVE-2018-11776 Exploit and explanation
https://ift.tt/2BNtspc
Submitted August 26, 2018 at 10:14PM by digicat
via reddit https://ift.tt/2PFV0PY
https://ift.tt/2BNtspc
Submitted August 26, 2018 at 10:14PM by digicat
via reddit https://ift.tt/2PFV0PY
GitHub
mazen160/struts-pwn_CVE-2018-11776
struts-pwn_CVE-2018-11776 - An exploit for Apache Struts CVE-2018-11776
A Universal Windows Bootkit
https://ift.tt/1YHhMVx
Submitted August 27, 2018 at 02:11AM by PeterG45
via reddit https://ift.tt/2odD5E0
https://ift.tt/1YHhMVx
Submitted August 27, 2018 at 02:11AM by PeterG45
via reddit https://ift.tt/2odD5E0
William Showalter
A Universal Windows Bootkit
An analysis of the MBR bootkit referred to as “HDRoot”
CVE-2018-0953: A particularly elegant type confusion bug in Microsoft Chakra.
https://ift.tt/2MLwiz2
Submitted August 27, 2018 at 02:10AM by PeterG45
via reddit https://ift.tt/2PFwY80
https://ift.tt/2MLwiz2
Submitted August 27, 2018 at 02:10AM by PeterG45
via reddit https://ift.tt/2PFwY80
Zero Day Initiative
Floating-Poison Math in Chakra
This post is an installment in my series of posts on security in Chakra, Microsoft’s JavaScript engine. In this installment, I present a particularly elegant type confusion bug in Chakra. This vulnerability was discovered by multiple researchers, including…
Labeless Part 3: How to Dump and Auto-Resolve WinAPI Calls in LockPos Point-of-Sale Malware
https://ift.tt/2w6u2Ju
Submitted August 27, 2018 at 02:07AM by PeterG45
via reddit https://ift.tt/2PFwZsA
https://ift.tt/2w6u2Ju
Submitted August 27, 2018 at 02:07AM by PeterG45
via reddit https://ift.tt/2PFwZsA
Check Point Research
Labeless Part 3: How to Dump and Auto-Resolve WinAPI Calls in LockPos Point-of-Sale Malware - Check Point Research
In this part we show how to automatically resolve all WinAPI calls in malicious code dump of LockPoS Point-of-Sale malware. Instead of manually reconstructing a corrupted Import Address Table we simply extract a target portion of code in the research database…
ATT&CK-Tools - Utilities for MITRE ATT&CK (Updated 25 Aug)
https://ift.tt/2MAqSrC
Submitted August 27, 2018 at 02:05AM by PeterG45
via reddit https://ift.tt/2oj8EMR
https://ift.tt/2MAqSrC
Submitted August 27, 2018 at 02:05AM by PeterG45
via reddit https://ift.tt/2oj8EMR
GitHub
nshalabi/ATTACK-Tools
Utilities for MITRE™ ATT&CK. Contribute to nshalabi/ATTACK-Tools development by creating an account on GitHub.
Crack authKey from SNMPv3 packet
https://ift.tt/2obC5jB
Submitted August 27, 2018 at 02:02AM by Ch3mFl0
via reddit https://ift.tt/2BQ8FS1
https://ift.tt/2obC5jB
Submitted August 27, 2018 at 02:02AM by Ch3mFl0
via reddit https://ift.tt/2BQ8FS1
nmap-parse-output: A tool for analyzing Nmap scans
https://ift.tt/2BLrkOH
Submitted August 27, 2018 at 02:26AM by RuckelBob
via reddit https://ift.tt/2wfC2Yr
https://ift.tt/2BLrkOH
Submitted August 27, 2018 at 02:26AM by RuckelBob
via reddit https://ift.tt/2wfC2Yr
Insinuator.net
nmap-parse-output: A tool for analyzing Nmap scans
tl;dr: With the tool nmap-parse-output you can convert, manipulate or extract data from a Nmap/masscan scan output. This allows you to get the information you're looking for by just entering a straightforward command.
Preamble
A while ago, we had to scan…
Preamble
A while ago, we had to scan…
CVE-2018-11776 (Struts) Exploit with Detailed Explanation
https://ift.tt/2Mq9WUu
Submitted August 27, 2018 at 02:51AM by Prav123
via reddit https://ift.tt/2Nj5ByQ
https://ift.tt/2Mq9WUu
Submitted August 27, 2018 at 02:51AM by Prav123
via reddit https://ift.tt/2Nj5ByQ
GitHub
jas502n/St2-057
St2-057 Poc Example. Contribute to jas502n/St2-057 development by creating an account on GitHub.
I created a youtube video stream (with chat) for users of r/netsec.
https://ift.tt/2MUEhKk
Submitted August 27, 2018 at 05:04PM by ivonodi
via reddit https://ift.tt/2LtWCJF
https://ift.tt/2MUEhKk
Submitted August 27, 2018 at 05:04PM by ivonodi
via reddit https://ift.tt/2LtWCJF
vidstreams.tv
netsec
Currently playing: NetSec I - 04. WiFi basics and security