Credential Stealer - MEGA Chrome Extension version 3.39.4
https://ift.tt/2oEKs7J
Submitted September 05, 2018 at 01:34AM by Roflnor
via reddit https://ift.tt/2MQ3OW5
https://ift.tt/2oEKs7J
Submitted September 05, 2018 at 01:34AM by Roflnor
via reddit https://ift.tt/2MQ3OW5
reddit
r/Monero - Don't use MEGA Chrome Extension version 3.39.4
94 votes and 29 comments so far on Reddit
Create a Hypervisor From Scratch (Parts 1 &2)
https://ift.tt/2NOJD70
Submitted September 05, 2018 at 03:12AM by PeterG45
via reddit https://ift.tt/2MKBGTX
https://ift.tt/2NOJD70
Submitted September 05, 2018 at 03:12AM by PeterG45
via reddit https://ift.tt/2MKBGTX
Sina & Shahriar's Blog
Hypervisor From Scratch – Part 2: Entering VMX Operation - Sina & Shahriar's Blog
In this section, we will learn about Detect Hypervisor Support for our processor, then we simply config the basic stuff to Enable VMX and Loading our VMCS in the last of this, we look at Interacting with our VMM from User-Mode.
x64 Inline Assembly in Windows Driver Kit
https://ift.tt/2NOTQ3z
Submitted September 05, 2018 at 03:10AM by PeterG45
via reddit https://ift.tt/2NndBlX
https://ift.tt/2NOTQ3z
Submitted September 05, 2018 at 03:10AM by PeterG45
via reddit https://ift.tt/2NndBlX
Sina & Shahriar's Blog
x64 Inline Assembly in Windows Driver Kit - Sina & Shahriar's Blog
In this post, you will learn how to create an x64 inline assembly project in Windows Driver Kit. As you know Microsoft remove _asm from its compilers.
Hacking the RPi Cam Web Interface
https://ift.tt/2LWQyJK
Submitted September 05, 2018 at 07:55AM by Inter4567
via reddit https://ift.tt/2M096bU
https://ift.tt/2LWQyJK
Submitted September 05, 2018 at 07:55AM by Inter4567
via reddit https://ift.tt/2M096bU
Reigningshells
Hacking The RPi Cam Web Interface
In my spare time, I like to poke around on different open and closed source projects and look for vulnerabilities. Recently, I turned m...
Which Vulnerabilities Are Being Exploited by Attackers
https://ift.tt/2LIbm7C
Submitted September 05, 2018 at 12:41PM by CyberBullets
via reddit https://ift.tt/2wJTh3F
https://ift.tt/2LIbm7C
Submitted September 05, 2018 at 12:41PM by CyberBullets
via reddit https://ift.tt/2wJTh3F
Rapid7 Blog
Common Vulnerabilities Exploited in Attacks and Penetration Tests
Software vulnerabilities are at the core of pen testing—and our "Under the Hoodie" report provides insights and advice one can only get in the trenches.
Company claim "New" way to access home routers and home networks
https://ift.tt/2NiGmzR
Submitted September 05, 2018 at 01:39PM by le-quack
via reddit https://ift.tt/2oEWDBc
https://ift.tt/2NiGmzR
Submitted September 05, 2018 at 01:39PM by le-quack
via reddit https://ift.tt/2oEWDBc
SureCloud
Wi-Jacking: Accessing your neighbour’s WiFi without cracking
During a recent engagement we found an interesting interaction of browser behaviour and an accepted weakness in almost every home router that could be Abusing ‘by design’ behaviour to gain the ability to hijack millions of WiFi networks through saved credentials…
Passwordless Authentication Wallet (PAW)
https://ift.tt/2M5zDVC
Submitted September 05, 2018 at 09:36PM by jrjr17
via reddit https://ift.tt/2NiUw4g
https://ift.tt/2M5zDVC
Submitted September 05, 2018 at 09:36PM by jrjr17
via reddit https://ift.tt/2NiUw4g
GitHub
jrjr/paw.js
Passwordless Authentication Wallet (PAW) is key-based authentication for the web. The library helps manage identities, their associated public/private keypairs, and signing operations in the browse...
MEGA Chrome Extension Hacked - Detailed Timeline of Events - SerHack security engineer
https://ift.tt/2NkWlgV
Submitted September 05, 2018 at 10:40PM by serhack
via reddit https://ift.tt/2wKfHlg
https://ift.tt/2NkWlgV
Submitted September 05, 2018 at 10:40PM by serhack
via reddit https://ift.tt/2wKfHlg
serhack.me
MEGA Chrome Extension Hacked - Detailed Timeline of Events - SerHack security engineer
On 4 September at 14:30 UTC, an unknown attacker managed to hack into MEGA's Google Chrome web store account and upload a malicious version 3.39.4 of an extension to the web store, according to a blog post published by the company.
Hack the Struts 2 RCE Vulnerability (CVE-2018-11776) in a live sandbox
https://ift.tt/2LLN2Sj
Submitted September 06, 2018 at 12:57AM by jrkjared3
via reddit https://ift.tt/2Q58dSJ
https://ift.tt/2LLN2Sj
Submitted September 06, 2018 at 12:57AM by jrkjared3
via reddit https://ift.tt/2Q58dSJ
HackEDU
Interactive Cybersecurity Training | HackEDU
Interactive Cybersecurity Training. HackEDU offers comprehensive online Secure Development Training for your developers, engineers, and IT personnel to assist your organization in laying a foundation of security and application vulnerability prevention, assessment…
Cisco has addressed vulnerabilities in its products
https://ift.tt/2LXgUeJ
Submitted September 06, 2018 at 02:37PM by sirpedrotavares
via reddit https://ift.tt/2NjdI1E
https://ift.tt/2LXgUeJ
Submitted September 06, 2018 at 02:37PM by sirpedrotavares
via reddit https://ift.tt/2NjdI1E
Segurança Informática
Cisco has addressed vulnerabilities in its products
Cisco addressed a dozen and high severity vulnerabilities affecting the company's RV series, SD-WAN, Umbrella, and other products.
Fallout Exploit Kit Used in Malvertising Campaign to Deliver GandCrab Ransomware
https://ift.tt/2NUoAzY
Submitted September 07, 2018 at 01:26AM by EvanConover
via reddit https://ift.tt/2CmPcZc
https://ift.tt/2NUoAzY
Submitted September 07, 2018 at 01:26AM by EvanConover
via reddit https://ift.tt/2CmPcZc
FireEye
Fallout Exploit Kit Used in Malvertising Campaign to Deliver GandCrab Ransomware « Fallout Exploit Kit Used in Malvertising Campaign…
FireEye identified a new exploit kit that was being served up as part of a malvertising campaign affecting users in Japan, Korea, the Middle East, Southern Europe, and other countries in the Asia Pacific region.
XSS using quirky implementations of ACME http-01
https://ift.tt/2M3WUXU
Submitted September 05, 2018 at 01:40PM by zulln
via reddit https://ift.tt/2NlIl6O
https://ift.tt/2M3WUXU
Submitted September 05, 2018 at 01:40PM by zulln
via reddit https://ift.tt/2NlIl6O
Detectify Labs
XSS using quirky implementations of ACME http-01
Some hosting providers implemented http-01 having one part of the challenge key reflected in the response. This resulted in a huge amount of websites being vulnerable to XSS just because of their quirky implementation of the http-01 ACME-challenge.
Public IP Addresses of Tor Sites Exposed via SSL Certificates
https://ift.tt/2PFnUiL
Submitted September 07, 2018 at 01:24PM by CyberBullets
via reddit https://ift.tt/2oMuGHZ
https://ift.tt/2PFnUiL
Submitted September 07, 2018 at 01:24PM by CyberBullets
via reddit https://ift.tt/2oMuGHZ
BleepingComputer
Public IP Addresses of Tor Sites Exposed via SSL Certificates
A security researcher has found a method that can be used to easily identify the public IP addresses of misconfigured dark web servers. While some feel that this researcher is attacking Tor or other similar networks, in reality he is exposing the pitfalls…
New persistence technique using Appx debugger - Not discovered by Autoruns
https://ift.tt/2wSIhSr
Submitted September 07, 2018 at 02:14PM by oddvarmoe
via reddit https://ift.tt/2Cqv0Wg
https://ift.tt/2wSIhSr
Submitted September 07, 2018 at 02:14PM by oddvarmoe
via reddit https://ift.tt/2Cqv0Wg
Oddvar Moe's Blog
Persistence using Universal Windows Platform apps (APPX)
TL;DR Persistence can be achieved with Appx/UWP apps using the debugger options. This technique will not be visible by Autoruns. Two different approaches exists (registry keys). Listed below are th…
Bypassing Hotstar Premium with DOM manipulation and some JavaScript
https://ift.tt/2NnqZX0
Submitted September 07, 2018 at 03:36PM by ajinabraham
via reddit https://ift.tt/2CvnVDV
https://ift.tt/2NnqZX0
Submitted September 07, 2018 at 03:36PM by ajinabraham
via reddit https://ift.tt/2CvnVDV
OpSecX
Bypassing Hotstar Premium with DOM manipulation and some JavaScript
Hotstar is a premium streaming platform like Netflix and Amazon Prime Videos. The security controls for restricting premium content were implemented at client side as frontend React JS logic. We were able to bypass these access controls and view paid premium…
Why Chrome and Firefox will soon block sites with certain SSL certificates
https://ift.tt/2wRpxCD
Submitted September 07, 2018 at 11:36PM by iamcoolc
via reddit https://ift.tt/2QaopCi
https://ift.tt/2wRpxCD
Submitted September 07, 2018 at 11:36PM by iamcoolc
via reddit https://ift.tt/2QaopCi
Templarbit Inc.
The story of why Chrome and Firefox will soon block sites with certain SSL certificates
In the near future, Google Chrome and Mozilla Firefox will...
Open Source Intelligence Gathering 201
https://ift.tt/2QbMdpr
Submitted September 08, 2018 at 06:38AM by diaanasxsw
via reddit https://ift.tt/2NsbeOr
https://ift.tt/2QbMdpr
Submitted September 08, 2018 at 06:38AM by diaanasxsw
via reddit https://ift.tt/2NsbeOr
Appsecco
Open Source Intelligence Gathering 201 (Covering 12 additional techniques)
This post is the second in a series of technical posts we are writing about Open Source Intelligence(OSINT) gathering.
British Airways hacked as data belonging up to 400,000 customers is stolen
https://ift.tt/2oLjD1t
Submitted September 08, 2018 at 11:15AM by Arnox
via reddit https://ift.tt/2wSM0PK
https://ift.tt/2oLjD1t
Submitted September 08, 2018 at 11:15AM by Arnox
via reddit https://ift.tt/2wSM0PK
#BugBounty — How Naaptol (India’s popular home shopping company) Kept their Millions of User Data at Risk!
https://ift.tt/2M9nte8
Submitted September 08, 2018 at 09:28AM by security_blogs
via reddit https://ift.tt/2oWFZNX
https://ift.tt/2M9nte8
Submitted September 08, 2018 at 09:28AM by security_blogs
via reddit https://ift.tt/2oWFZNX
Medium
#BugBounty — How Naaptol (India’s popular home shopping company) Kept their Millions of User Data at Risk!
Hi Guys,
CyStack - A web security platform that can scan vulnerabilities/malwares, monitor availability and serve as a firewall
https://app.cystack.net
Submitted September 08, 2018 at 04:49PM by everping
via reddit https://ift.tt/2QcXcil
https://app.cystack.net
Submitted September 08, 2018 at 04:49PM by everping
via reddit https://ift.tt/2QcXcil
Wi-Fi Gets More Secure: Everything You Need to Know About WPA3
https://ift.tt/2M9uHPy
Submitted September 08, 2018 at 08:37PM by yo91
via reddit https://ift.tt/2NrVivS
https://ift.tt/2M9uHPy
Submitted September 08, 2018 at 08:37PM by yo91
via reddit https://ift.tt/2NrVivS
IEEE Spectrum: Technology, Engineering, and Science News
Wi-Fi Gets More Secure: Everything You Need to Know About WPA3
WPA3, Enhanced Open, Easy Connect: The Wi-Fi Alliance's trio of new protocols explained