Key Managers and Key Stores
https://ift.tt/2x0F0ja
Submitted September 10, 2018 at 10:22PM by amazedballer
via reddit https://ift.tt/2oYjyrj
https://ift.tt/2x0F0ja
Submitted September 10, 2018 at 10:22PM by amazedballer
via reddit https://ift.tt/2oYjyrj
reddit
r/netsec - Key Managers and Key Stores
1 vote and 0 comments so far on Reddit
Analysis of Unpatched Advantech Webaccess RCE
https://ift.tt/2wYQTHl
Submitted September 10, 2018 at 10:16PM by chicksdigthelongrun
via reddit https://ift.tt/2Mhk2SI
https://ift.tt/2wYQTHl
Submitted September 10, 2018 at 10:16PM by chicksdigthelongrun
via reddit https://ift.tt/2Mhk2SI
Medium
Advantech WebAccess Unpatched RCE
Author: Chris Lyne
Exposing Private Domains via Certificate Transparency Logs [tool release]
https://ift.tt/2CxETBy
Submitted September 10, 2018 at 11:27PM by mpeg4codec
via reddit https://ift.tt/2Qkj0J0
https://ift.tt/2CxETBy
Submitted September 10, 2018 at 11:27PM by mpeg4codec
via reddit https://ift.tt/2Qkj0J0
Chris408
Certificate Transparency logs and how they are a gold mine to Bug Hunters
What is CT? Certificate Transparency (CT) is an experimental IETF standard. The goal of CT is to allow the public to audit which certificates were created by Certificate Authorities (CA). TLS has a weakness that comes from the large list of CAs that your…
local host discovery in browser
https://ift.tt/2x1VVSC
Submitted September 11, 2018 at 03:04AM by rain5
via reddit https://ift.tt/2Nqm7AD
https://ift.tt/2x1VVSC
Submitted September 11, 2018 at 03:04AM by rain5
via reddit https://ift.tt/2Nqm7AD
reddit
r/netsec - local host discovery in browser
3 votes and 2 comments so far on Reddit
Slides & presentation of "Unpacking the non-unpackable" (anti-static analytic new ELF packer) in R2CON2018
https://ift.tt/2MgZr0U
Submitted September 11, 2018 at 03:02AM by mmd0xFF
via reddit https://ift.tt/2NwAkfm
https://ift.tt/2MgZr0U
Submitted September 11, 2018 at 03:02AM by mmd0xFF
via reddit https://ift.tt/2NwAkfm
reddit
r/LinuxMalware - About my presentation of: "Unpacking the non-unpackable" (an ELF new packer) in R2CON2018
1 vote and 0 comments so far on Reddit
Spoofing DNS with fragments
https://ift.tt/2CP0Ooi
Submitted September 11, 2018 at 04:42AM by nykzhang
via reddit https://ift.tt/2O2cuVE
https://ift.tt/2CP0Ooi
Submitted September 11, 2018 at 04:42AM by nykzhang
via reddit https://ift.tt/2O2cuVE
PowerDNS Blog
Spoofing DNS with fragments
With some care, it turns out to be possible to spoof fake DNS responses using fragmented datagrams. While preparing a presentation for XS4ALL back in 2009, I found out how this could be done, but I…
India’s citizen biometric registry Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
https://ift.tt/2CFbyoQ
Submitted September 11, 2018 at 10:54AM by lordatlas
via reddit https://ift.tt/2NA8RsU
https://ift.tt/2CFbyoQ
Submitted September 11, 2018 at 10:54AM by lordatlas
via reddit https://ift.tt/2NA8RsU
HuffPost India
UIDAI’s Aadhaar Software Hacked, ID Database Compromised, Experts Confirm
Skilled hackers disabled security features of Aadhaar enrolment software, circulated hack on Whatsapp
Sploitus.com - Exploits & Tools Search Engine
https://sploitus.com
Submitted September 11, 2018 at 02:43PM by i_bo0om
via reddit https://ift.tt/2MjgijM
https://sploitus.com
Submitted September 11, 2018 at 02:43PM by i_bo0om
via reddit https://ift.tt/2MjgijM
Sploitus
💀 Sploitus | Exploits & Tools Search Engine
Sploitus is a convenient central place for identifying the newest exploits and finding attacks that exploit known vulnerabilities. The search engine is also a good resource for finding security and vulnerability discovery tools.
A practical guide to testing the security of Amazon Web Services (Part 1: AWS S3)
https://ift.tt/2N1EbS5
Submitted September 11, 2018 at 08:12PM by albinowax
via reddit https://ift.tt/2MmvzQE
https://ift.tt/2N1EbS5
Submitted September 11, 2018 at 08:12PM by albinowax
via reddit https://ift.tt/2MmvzQE
Mindedsecurity
A practical guide to testing the security of Amazon Web Services (Part 1: AWS S3)
Back in the days, the word Amazon used to refer to over half of earth's rainforests. While this is still true, it isn't what most people ...
The anatomy of a .NET malware dropper - a detailed blog post about reverse engineering .NET malware
https://ift.tt/2NzqYPG
Submitted September 11, 2018 at 08:10PM by 0xAmit
via reddit https://ift.tt/2MkGOcr
https://ift.tt/2NzqYPG
Submitted September 11, 2018 at 08:10PM by 0xAmit
via reddit https://ift.tt/2MkGOcr
Cybereason
The anatomy of a .NET malware dropper
Attackers don't need sophisticated tools to create effective malware. Basic tools work just fine. Case in point: Cybereason researchers discovered a .NET dropper/crypter. Here's how they reverse engineered it.
Gamifiying Binary Exploitation Through Next Generation Wargames
https://ift.tt/2Qmxlo5
Submitted September 11, 2018 at 09:37PM by gaasedelen
via reddit https://ift.tt/2O9Dwuo
https://ift.tt/2Qmxlo5
Submitted September 11, 2018 at 09:37PM by gaasedelen
via reddit https://ift.tt/2O9Dwuo
Ret2 Systems Blog
Scaling up Binary Exploitation Education
The shortage of proficient cyber operators in a world now dependent on connectivity and information has left nations scrambling to build capabilities in a vo...
OATmeal on the Universal Cereal Bus: Exploiting Android phones over USB
https://ift.tt/2x3FJzY
Submitted September 11, 2018 at 12:51PM by UnrealQuester
via reddit https://ift.tt/2CKQD3T
https://ift.tt/2x3FJzY
Submitted September 11, 2018 at 12:51PM by UnrealQuester
via reddit https://ift.tt/2CKQD3T
Blogspot
OATmeal on the Universal Cereal Bus: Exploiting Android phones over USB
Posted by Jann Horn, Google Project Zero Recently, there has been some attention around the topic of physical attacks on smartphones, wh...
Comparing Our Micropatch With Microsoft's Official Patch For CVE-2018-8440
https://ift.tt/2QnPqSL
Submitted September 12, 2018 at 03:09AM by dielel
via reddit https://ift.tt/2xa577A
https://ift.tt/2QnPqSL
Submitted September 12, 2018 at 03:09AM by dielel
via reddit https://ift.tt/2xa577A
0Patch
Comparing Our Micropatch With Microsoft's Official Patch For CVE-2018-8440
by Mitja Kolsek, the 0patch Team As expected, Windows Update has just brought the official patch for CVE-2018-8440 today, a patch that w...
Frida 12.2 is out with brand new iOS kernel introspection APIs
https://ift.tt/2QjJD0N
Submitted September 12, 2018 at 06:50AM by oleavr
via reddit https://ift.tt/2Mn0wnL
https://ift.tt/2QjJD0N
Submitted September 12, 2018 at 06:50AM by oleavr
via reddit https://ift.tt/2Mn0wnL
Frida • A world-class dynamic instrumentation framework
Frida 12.2 Released
Inject JavaScript to explore native apps on Windows, macOS, GNU/Linux, iOS, Android, and QNX
September 11, 2018—KB4457128 (OS Build 17134.285)
https://ift.tt/2NAnkW1
Submitted September 12, 2018 at 09:03AM by jdrch
via reddit https://ift.tt/2xf3zcv
https://ift.tt/2NAnkW1
Submitted September 12, 2018 at 09:03AM by jdrch
via reddit https://ift.tt/2xf3zcv
Microsoft
September 11, 2018—KB4457128 (OS Build 17134.285)
Learn more about update KB4457128, including improvements and fixes, any known issues, and how to get the update.
.NET Framework September 2018 Security and Quality Rollup
https://ift.tt/2oYSng8
Submitted September 12, 2018 at 09:01AM by jdrch
via reddit https://ift.tt/2p1iFi2
https://ift.tt/2oYSng8
Submitted September 12, 2018 at 09:01AM by jdrch
via reddit https://ift.tt/2p1iFi2
Microsoft
.NET Framework September 2018 Security and Quality Rollup
A first-hand look from the .NET engineering teams
Keybase browser extension is flawed
https://ift.tt/2wPOGNg
Submitted September 12, 2018 at 01:54PM by CyberBullets
via reddit https://ift.tt/2NE7Dgm
https://ift.tt/2wPOGNg
Submitted September 12, 2018 at 01:54PM by CyberBullets
via reddit https://ift.tt/2NE7Dgm
Wladimir Palant's notes
Keybase: "Our browser extension subverts our encryption, but why should we care?"
The Keybase browser extension subverts the app's end-to-end encryption. Keybase considers that "an acceptable risk" and not worth fixing.
Passing-the-Hash to NTLM Authenticated Web Applications
https://ift.tt/2uYsgsh
Submitted September 12, 2018 at 05:40PM by ericnyamu
via reddit https://ift.tt/2Odx0Tx
https://ift.tt/2uYsgsh
Submitted September 12, 2018 at 05:40PM by ericnyamu
via reddit https://ift.tt/2Odx0Tx
BIOS Boots What? Finding Evil in Boot Code at Scale!
https://ift.tt/2vrR6lE
Submitted September 12, 2018 at 05:38PM by ericnyamu
via reddit https://ift.tt/2QlGb5E
https://ift.tt/2vrR6lE
Submitted September 12, 2018 at 05:38PM by ericnyamu
via reddit https://ift.tt/2QlGb5E
FireEye
BIOS Boots What? Finding Evil in Boot Code at Scale! « BIOS Boots What? Finding Evil in Boot Code at Scale!
This post details the challenges FireEye faced examining boot records at scale and our solution to find evil boot records in large enterprise networks.
Hash Function Attacks Illustrated
https://ift.tt/2QmfXzT
Submitted September 12, 2018 at 05:36PM by ericnyamu
via reddit https://ift.tt/2OcWDDN
https://ift.tt/2QmfXzT
Submitted September 12, 2018 at 05:36PM by ericnyamu
via reddit https://ift.tt/2OcWDDN
McCormick Tech
Hash Function Attacks Illustrated
Here are some illustrated explanations of the main ways in which cryptographic hash functions can be attacked, and be resistant to those...
Bypassing CSP using polyglot JPEGs
https://ift.tt/2nlYKJO
Submitted September 12, 2018 at 05:35PM by ericnyamu
via reddit https://ift.tt/2OcWG2r
https://ift.tt/2nlYKJO
Submitted September 12, 2018 at 05:35PM by ericnyamu
via reddit https://ift.tt/2OcWG2r
Web Security Blog | PortSwigger
Bypassing CSP using polyglot JPEGs
James challenged me to see if it was possible to create a polyglot JavaScript/JPEG. Doing so would allow me to bypass CSP on almost any website that hosts user-uploaded images on the same domain. I gl