Labeless Part 3: How to Dump and Auto-Resolve WinAPI Calls in LockPos Point-of-Sale Malware
https://ift.tt/2w6u2Ju
Submitted August 27, 2018 at 02:07AM by PeterG45
via reddit https://ift.tt/2PFwZsA
https://ift.tt/2w6u2Ju
Submitted August 27, 2018 at 02:07AM by PeterG45
via reddit https://ift.tt/2PFwZsA
Check Point Research
Labeless Part 3: How to Dump and Auto-Resolve WinAPI Calls in LockPos Point-of-Sale Malware - Check Point Research
In this part we show how to automatically resolve all WinAPI calls in malicious code dump of LockPoS Point-of-Sale malware. Instead of manually reconstructing a corrupted Import Address Table we simply extract a target portion of code in the research database…
ATT&CK-Tools - Utilities for MITRE ATT&CK (Updated 25 Aug)
https://ift.tt/2MAqSrC
Submitted August 27, 2018 at 02:05AM by PeterG45
via reddit https://ift.tt/2oj8EMR
https://ift.tt/2MAqSrC
Submitted August 27, 2018 at 02:05AM by PeterG45
via reddit https://ift.tt/2oj8EMR
GitHub
nshalabi/ATTACK-Tools
Utilities for MITRE™ ATT&CK. Contribute to nshalabi/ATTACK-Tools development by creating an account on GitHub.
Crack authKey from SNMPv3 packet
https://ift.tt/2obC5jB
Submitted August 27, 2018 at 02:02AM by Ch3mFl0
via reddit https://ift.tt/2BQ8FS1
https://ift.tt/2obC5jB
Submitted August 27, 2018 at 02:02AM by Ch3mFl0
via reddit https://ift.tt/2BQ8FS1
nmap-parse-output: A tool for analyzing Nmap scans
https://ift.tt/2BLrkOH
Submitted August 27, 2018 at 02:26AM by RuckelBob
via reddit https://ift.tt/2wfC2Yr
https://ift.tt/2BLrkOH
Submitted August 27, 2018 at 02:26AM by RuckelBob
via reddit https://ift.tt/2wfC2Yr
Insinuator.net
nmap-parse-output: A tool for analyzing Nmap scans
tl;dr: With the tool nmap-parse-output you can convert, manipulate or extract data from a Nmap/masscan scan output. This allows you to get the information you're looking for by just entering a straightforward command.
Preamble
A while ago, we had to scan…
Preamble
A while ago, we had to scan…
CVE-2018-11776 (Struts) Exploit with Detailed Explanation
https://ift.tt/2Mq9WUu
Submitted August 27, 2018 at 02:51AM by Prav123
via reddit https://ift.tt/2Nj5ByQ
https://ift.tt/2Mq9WUu
Submitted August 27, 2018 at 02:51AM by Prav123
via reddit https://ift.tt/2Nj5ByQ
GitHub
jas502n/St2-057
St2-057 Poc Example. Contribute to jas502n/St2-057 development by creating an account on GitHub.
I created a youtube video stream (with chat) for users of r/netsec.
https://ift.tt/2MUEhKk
Submitted August 27, 2018 at 05:04PM by ivonodi
via reddit https://ift.tt/2LtWCJF
https://ift.tt/2MUEhKk
Submitted August 27, 2018 at 05:04PM by ivonodi
via reddit https://ift.tt/2LtWCJF
vidstreams.tv
netsec
Currently playing: NetSec I - 04. WiFi basics and security
Reverse Engineering iOS Apps - iOS 11 Edition (Part 2)
https://ift.tt/2Lt6brW
Submitted August 27, 2018 at 03:17PM by Prav123
via reddit https://ift.tt/2NmVw3Z
https://ift.tt/2Lt6brW
Submitted August 27, 2018 at 03:17PM by Prav123
via reddit https://ift.tt/2NmVw3Z
Ivan R Blog
Reverse Engineering iOS Apps - iOS 11 Edition (Part 2)
This is the second part of the "Reverse Engineering iOS Apps - iOS 11 Edition" series. In the first part of the series we learned how to setup your phone on iOS 11 and how to decrypt an iOS app. In this second and final part we'll learn how to:
Apache Struts2 CVE-2018-11776 POC
https://ift.tt/2BK09DL
Submitted August 27, 2018 at 08:23PM by theMiddleBlue
via reddit https://ift.tt/2BS2Y5O
https://ift.tt/2BK09DL
Submitted August 27, 2018 at 08:23PM by theMiddleBlue
via reddit https://ift.tt/2BS2Y5O
Secjuice.com
Apache Struts2 CVE-2018-11776
Learn about the Struts2 Remote Code Execution vulnerability CVE-2018-11776, how to exploit and how to create a Proof of Concept (POC) with docker.
Helping Nonprofits and Other Growing Businesses Understand Security Risks - Security Exploits & News
https://ift.tt/2LwTn3Q
Submitted August 27, 2018 at 08:36PM by bonniek4t
via reddit https://ift.tt/2PJkMmP
https://ift.tt/2LwTn3Q
Submitted August 27, 2018 at 08:36PM by bonniek4t
via reddit https://ift.tt/2PJkMmP
Security Exploits & News
Helping Nonprofits and Other Growing Businesses Understand Security Risks - Security Exploits & News
Raxis COO, Bonnie Smyre, wrote a guest blog post on "What Nonprofits Need to Know about Assessing Security Risk" for the NTEN Nonprofit Technology Network.
threatfeeds.io - free and open-source threat intelligence feeds and sources
https://threatfeeds.io
Submitted August 27, 2018 at 10:31PM by netbroom
via reddit https://ift.tt/2PaMwj4
https://threatfeeds.io
Submitted August 27, 2018 at 10:31PM by netbroom
via reddit https://ift.tt/2PaMwj4
threatfeeds.io
Free threat intelligence feeds - threatfeeds.io
Search and download free and open-source threat intelligence feeds with threatfeeds.io.
API interface for kali tools
https://ift.tt/2PCka22
Submitted August 28, 2018 at 01:35AM by knsankar
via reddit https://ift.tt/2LATdsA
https://ift.tt/2PCka22
Submitted August 28, 2018 at 01:35AM by knsankar
via reddit https://ift.tt/2LATdsA
reddit
r/Information_Security - API interface for kali tools
0 votes and 0 comments so far on Reddit
Microsoft.Workflow.Compiler.exe, Veil, and Cobalt Strike
https://ift.tt/2wn2s9S
Submitted August 28, 2018 at 01:25AM by SonOfFlynnn
via reddit https://ift.tt/2MZUcaw
https://ift.tt/2wn2s9S
Submitted August 28, 2018 at 01:25AM by SonOfFlynnn
via reddit https://ift.tt/2MZUcaw
FortyNorth Security
Microsoft.Workflow.Compiler.exe, Veil, and Cobalt Strike - FortyNorth Security
This blog post documents how to use Microsoft.Workflow.Compiler.exe and the Veil Framework's output to receive a Cobalt Strike beacon.
I made a push notification feed (desktop/mobile) for posts of r/netsec that have a minimum of 200 Karma.
https://ift.tt/2ofGv96
Submitted August 28, 2018 at 06:36AM by soeindohuwabohu
via reddit https://ift.tt/2BTzEvU
https://ift.tt/2ofGv96
Submitted August 28, 2018 at 06:36AM by soeindohuwabohu
via reddit https://ift.tt/2BTzEvU
Traversing the Path to RCE (Bug Bounty)
https://ift.tt/2wnfzYE
Submitted August 28, 2018 at 04:38AM by chocoluvin
via reddit https://ift.tt/2MAbU4P
https://ift.tt/2wnfzYE
Submitted August 28, 2018 at 04:38AM by chocoluvin
via reddit https://ift.tt/2MAbU4P
∞ Growing Web Security Blog
Traversing the Path to RCE
This post will detail the steps I took to find a path traversal vulnerability, and how I paired the vulnerability with the logic of the application to achieve Remote Code Execution through a shell …
Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the ALPC interface
https://ift.tt/2PJxVvN
Submitted August 28, 2018 at 11:38AM by 0xdea
via reddit https://ift.tt/2BOFqil
https://ift.tt/2PJxVvN
Submitted August 28, 2018 at 11:38AM by 0xdea
via reddit https://ift.tt/2BOFqil
www.kb.cert.org
Vulnerability Note VU#906424 - Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the ALPC…
Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the Advanced Local Procedure Call (ALPC) interface, which can allow a local user to obtain SYSTEM privileges.
Tracking Down Malware by Analyzing Beacon Traffic
https://ift.tt/2w7PxcU
Submitted August 28, 2018 at 02:15PM by CyberBullets
via reddit https://ift.tt/2oe4Fkq
https://ift.tt/2w7PxcU
Submitted August 28, 2018 at 02:15PM by CyberBullets
via reddit https://ift.tt/2oe4Fkq
Active Countermeasures
Beacon Analysis - The Key to Cyber Threat Hunting - Active Countermeasures
Beacon analysis is by far the most effective method of threat hunting your network. In fact, I would argue that if you are not checking your network for beacon activity, you have a huge gap in your defenses that attackers will happily leverage. In this two…
Gmail Android app insecure Network Security Configuration
https://ift.tt/2NqjhIw
Submitted August 28, 2018 at 03:50PM by clviper
via reddit https://ift.tt/2PIgMmh
https://ift.tt/2NqjhIw
Submitted August 28, 2018 at 03:50PM by clviper
via reddit https://ift.tt/2PIgMmh
From Compiler Optimization to Code Execution - VirtualBox VM Escape - CVE-2018-2844
https://ift.tt/2NnD6jr
Submitted August 28, 2018 at 03:45PM by tunnelshade
via reddit https://ift.tt/2LyZHb6
https://ift.tt/2NnD6jr
Submitted August 28, 2018 at 03:45PM by tunnelshade
via reddit https://ift.tt/2LyZHb6
www.voidsecurity.in
From Compiler Optimization to Code Execution - VirtualBox VM Escape - CVE-2018-2844
Oracle fixed some of the issues I reported in VirtualBox during the Oracle Critical Patch Update - April 2018. CVE-2018-2844 was an inter...
A walkthrough the AcridRain Stealer
https://ift.tt/2Nrb86s
Submitted August 28, 2018 at 05:06PM by _cacao
via reddit https://ift.tt/2ohRrmR
https://ift.tt/2Nrb86s
Submitted August 28, 2018 at 05:06PM by _cacao
via reddit https://ift.tt/2ohRrmR
This is Security :: by Stormshield
A walk through the AcridRain Stealer - This is Security :: by Stormshield
This blogpost will talk about the analysis of a new password stealer named AcridRain and its different updates during the last 2 months. Introduction AcridRain is a new password stealer written in C/C++ that showed up on forums around the 11th of July 2018.…
Uber Bug Bounty: 1000$ for two “high severity” issue
https://ift.tt/2NqXjVR
Submitted August 28, 2018 at 05:49PM by mrpeuch
via reddit https://ift.tt/2BWjYIg
https://ift.tt/2NqXjVR
Submitted August 28, 2018 at 05:49PM by mrpeuch
via reddit https://ift.tt/2BWjYIg
Medium
Uber Bug Bounty: 1000$ for two “high severity” issue
Despite the fact I am fairly active on the various bug bounty platforms, I usually don’t blog around my activities or promote myself for…
Unpatched ALPC Priv Esc Bug in Windows 10 x64 PoC
https://ift.tt/2BWEFUw
Submitted August 28, 2018 at 07:44PM by at_physicaltherapy
via reddit https://ift.tt/2Ly8Cti
https://ift.tt/2BWEFUw
Submitted August 28, 2018 at 07:44PM by at_physicaltherapy
via reddit https://ift.tt/2Ly8Cti
GitHub
SandboxEscaper/randomrepo
Repo for random stuff. Contribute to SandboxEscaper/randomrepo development by creating an account on GitHub.