The anatomy of a .NET malware dropper - a detailed blog post about reverse engineering .NET malware
https://ift.tt/2NzqYPG
Submitted September 11, 2018 at 08:10PM by 0xAmit
via reddit https://ift.tt/2MkGOcr
https://ift.tt/2NzqYPG
Submitted September 11, 2018 at 08:10PM by 0xAmit
via reddit https://ift.tt/2MkGOcr
Cybereason
The anatomy of a .NET malware dropper
Attackers don't need sophisticated tools to create effective malware. Basic tools work just fine. Case in point: Cybereason researchers discovered a .NET dropper/crypter. Here's how they reverse engineered it.
Gamifiying Binary Exploitation Through Next Generation Wargames
https://ift.tt/2Qmxlo5
Submitted September 11, 2018 at 09:37PM by gaasedelen
via reddit https://ift.tt/2O9Dwuo
https://ift.tt/2Qmxlo5
Submitted September 11, 2018 at 09:37PM by gaasedelen
via reddit https://ift.tt/2O9Dwuo
Ret2 Systems Blog
Scaling up Binary Exploitation Education
The shortage of proficient cyber operators in a world now dependent on connectivity and information has left nations scrambling to build capabilities in a vo...
OATmeal on the Universal Cereal Bus: Exploiting Android phones over USB
https://ift.tt/2x3FJzY
Submitted September 11, 2018 at 12:51PM by UnrealQuester
via reddit https://ift.tt/2CKQD3T
https://ift.tt/2x3FJzY
Submitted September 11, 2018 at 12:51PM by UnrealQuester
via reddit https://ift.tt/2CKQD3T
Blogspot
OATmeal on the Universal Cereal Bus: Exploiting Android phones over USB
Posted by Jann Horn, Google Project Zero Recently, there has been some attention around the topic of physical attacks on smartphones, wh...
Comparing Our Micropatch With Microsoft's Official Patch For CVE-2018-8440
https://ift.tt/2QnPqSL
Submitted September 12, 2018 at 03:09AM by dielel
via reddit https://ift.tt/2xa577A
https://ift.tt/2QnPqSL
Submitted September 12, 2018 at 03:09AM by dielel
via reddit https://ift.tt/2xa577A
0Patch
Comparing Our Micropatch With Microsoft's Official Patch For CVE-2018-8440
by Mitja Kolsek, the 0patch Team As expected, Windows Update has just brought the official patch for CVE-2018-8440 today, a patch that w...
Frida 12.2 is out with brand new iOS kernel introspection APIs
https://ift.tt/2QjJD0N
Submitted September 12, 2018 at 06:50AM by oleavr
via reddit https://ift.tt/2Mn0wnL
https://ift.tt/2QjJD0N
Submitted September 12, 2018 at 06:50AM by oleavr
via reddit https://ift.tt/2Mn0wnL
Frida • A world-class dynamic instrumentation framework
Frida 12.2 Released
Inject JavaScript to explore native apps on Windows, macOS, GNU/Linux, iOS, Android, and QNX
September 11, 2018—KB4457128 (OS Build 17134.285)
https://ift.tt/2NAnkW1
Submitted September 12, 2018 at 09:03AM by jdrch
via reddit https://ift.tt/2xf3zcv
https://ift.tt/2NAnkW1
Submitted September 12, 2018 at 09:03AM by jdrch
via reddit https://ift.tt/2xf3zcv
Microsoft
September 11, 2018—KB4457128 (OS Build 17134.285)
Learn more about update KB4457128, including improvements and fixes, any known issues, and how to get the update.
.NET Framework September 2018 Security and Quality Rollup
https://ift.tt/2oYSng8
Submitted September 12, 2018 at 09:01AM by jdrch
via reddit https://ift.tt/2p1iFi2
https://ift.tt/2oYSng8
Submitted September 12, 2018 at 09:01AM by jdrch
via reddit https://ift.tt/2p1iFi2
Microsoft
.NET Framework September 2018 Security and Quality Rollup
A first-hand look from the .NET engineering teams
Keybase browser extension is flawed
https://ift.tt/2wPOGNg
Submitted September 12, 2018 at 01:54PM by CyberBullets
via reddit https://ift.tt/2NE7Dgm
https://ift.tt/2wPOGNg
Submitted September 12, 2018 at 01:54PM by CyberBullets
via reddit https://ift.tt/2NE7Dgm
Wladimir Palant's notes
Keybase: "Our browser extension subverts our encryption, but why should we care?"
The Keybase browser extension subverts the app's end-to-end encryption. Keybase considers that "an acceptable risk" and not worth fixing.
Passing-the-Hash to NTLM Authenticated Web Applications
https://ift.tt/2uYsgsh
Submitted September 12, 2018 at 05:40PM by ericnyamu
via reddit https://ift.tt/2Odx0Tx
https://ift.tt/2uYsgsh
Submitted September 12, 2018 at 05:40PM by ericnyamu
via reddit https://ift.tt/2Odx0Tx
BIOS Boots What? Finding Evil in Boot Code at Scale!
https://ift.tt/2vrR6lE
Submitted September 12, 2018 at 05:38PM by ericnyamu
via reddit https://ift.tt/2QlGb5E
https://ift.tt/2vrR6lE
Submitted September 12, 2018 at 05:38PM by ericnyamu
via reddit https://ift.tt/2QlGb5E
FireEye
BIOS Boots What? Finding Evil in Boot Code at Scale! « BIOS Boots What? Finding Evil in Boot Code at Scale!
This post details the challenges FireEye faced examining boot records at scale and our solution to find evil boot records in large enterprise networks.
Hash Function Attacks Illustrated
https://ift.tt/2QmfXzT
Submitted September 12, 2018 at 05:36PM by ericnyamu
via reddit https://ift.tt/2OcWDDN
https://ift.tt/2QmfXzT
Submitted September 12, 2018 at 05:36PM by ericnyamu
via reddit https://ift.tt/2OcWDDN
McCormick Tech
Hash Function Attacks Illustrated
Here are some illustrated explanations of the main ways in which cryptographic hash functions can be attacked, and be resistant to those...
Bypassing CSP using polyglot JPEGs
https://ift.tt/2nlYKJO
Submitted September 12, 2018 at 05:35PM by ericnyamu
via reddit https://ift.tt/2OcWG2r
https://ift.tt/2nlYKJO
Submitted September 12, 2018 at 05:35PM by ericnyamu
via reddit https://ift.tt/2OcWG2r
Web Security Blog | PortSwigger
Bypassing CSP using polyglot JPEGs
James challenged me to see if it was possible to create a polyglot JavaScript/JPEG. Doing so would allow me to bypass CSP on almost any website that hosts user-uploaded images on the same domain. I gl
Windows Privilege Escalation Guide
https://ift.tt/2EVH96s
Submitted September 12, 2018 at 05:33PM by ericnyamu
via reddit https://ift.tt/2QlX9kp
https://ift.tt/2EVH96s
Submitted September 12, 2018 at 05:33PM by ericnyamu
via reddit https://ift.tt/2QlX9kp
Researcher finds vulnerability enabling disclosure of Intel ME encryption keys
https://ift.tt/2QjGiyy
Submitted September 12, 2018 at 06:46PM by alexlash
via reddit https://ift.tt/2Nabkes
https://ift.tt/2QjGiyy
Submitted September 12, 2018 at 06:46PM by alexlash
via reddit https://ift.tt/2Nabkes
Ptsecurity
Positive Technologies researcher finds vulnerability enabling disclosure of Intel ME encryption keys
Image credit: Unsplash Intel has issued a patch in response to a serious vulnerability in Intel ME firmware discovered by Positive Tec...
CVE-2018-5240: Symantec Management Agent (Altiris) Privilege Escalation
https://ift.tt/2x6Qe5F
Submitted September 12, 2018 at 10:34PM by eth_
via reddit https://ift.tt/2COK0xA
https://ift.tt/2x6Qe5F
Submitted September 12, 2018 at 10:34PM by eth_
via reddit https://ift.tt/2COK0xA
Nettitude Labs
CVE-2018-5240: Symantec Management Agent (Altiris) Privilege Escalation
During a recent red team exercise, we discovered a vulnerability within the latest versions of the Symantec Management Agent (Altiris), that allowed us to escalate our privileges. Overview When the…
DFLabs’ No-Script Automation Tool (NAT) is a new free tool that helps incident responders collect live forensic data.
The No-Script Automation Tool (NAT) was designed to solve the complexity and management issues surrounding noscripting multiple tools via batch files or other noscripting languages for Windows systems. NAT allows users to run sets of pre-defined and pre-verified tools based on user specified input, pre-defined commands and system properties such as architecture and Windows version.Downloadhttps://github.com/dflabs/NAT
Submitted September 12, 2018 at 07:48PM by GeekSikhSecurity
via reddit https://ift.tt/2NB0sFP
The No-Script Automation Tool (NAT) was designed to solve the complexity and management issues surrounding noscripting multiple tools via batch files or other noscripting languages for Windows systems. NAT allows users to run sets of pre-defined and pre-verified tools based on user specified input, pre-defined commands and system properties such as architecture and Windows version.Downloadhttps://github.com/dflabs/NAT
Submitted September 12, 2018 at 07:48PM by GeekSikhSecurity
via reddit https://ift.tt/2NB0sFP
GitHub
dflabs/NAT
No-Script Automation Tool. Contribute to dflabs/NAT development by creating an account on GitHub.
How long to crack this PW given the info provided
https://ift.tt/2CQrK6Y
Submitted September 13, 2018 at 03:49AM by gregtwelve
via reddit https://ift.tt/2p365Pl
https://ift.tt/2CQrK6Y
Submitted September 13, 2018 at 03:49AM by gregtwelve
via reddit https://ift.tt/2p365Pl
reddit
r/privacy - ISP wants me to keep my default password on my router/modem. Are default router/modem passwords good enough?
3 votes and 6 comments so far on Reddit
NSD DNS Server Tutorial: alternative to BIND for zone hosting and slaving
https://ift.tt/1NwDQMm
Submitted September 13, 2018 at 03:22AM by unquietwiki
via reddit https://ift.tt/2MpwPTk
https://ift.tt/1NwDQMm
Submitted September 13, 2018 at 03:22AM by unquietwiki
via reddit https://ift.tt/2MpwPTk
Feedify Compromised. Magecart noscript potentially on over 4000 websites.
https://ift.tt/2N83P7V
Submitted September 13, 2018 at 11:17AM by le-quack
via reddit https://ift.tt/2x8VlmL
https://ift.tt/2N83P7V
Submitted September 13, 2018 at 11:17AM by le-quack
via reddit https://ift.tt/2x8VlmL
BleepingComputer
Feedify Hacked with Magecart Information Stealing Script
A noscript used by the customer engagement service Feedify has been hacked to include the malicious MageCart noscript. MageCart is malicious code used by attackers to steal credit card details and other information from e-commerce sites when a user submits a…
Low-cost USB Rubber Ducky pen-test tool for $3 using Digispark and Duck2Spark
https://ift.tt/2p5jlmc
Submitted September 13, 2018 at 02:24PM by vasiliborodin
via reddit https://ift.tt/2N8d4VE
https://ift.tt/2p5jlmc
Submitted September 13, 2018 at 02:24PM by vasiliborodin
via reddit https://ift.tt/2N8d4VE
Medium
Low-cost USB Rubber Ducky pen-test tool for $3 using Digispark and Duck2Spark
It’s a story as old as time: some hacker sees nice hardware pen-testing tool, hacker recoils in horror at the price of said tool, hacker…
Vulmon - Vulnerability / Exploit Search Engine with Vulnerability Intelligence
https://vulmon.com
Submitted September 13, 2018 at 04:07PM by drodrouw
via reddit https://ift.tt/2p5vxU0
https://vulmon.com
Submitted September 13, 2018 at 04:07PM by drodrouw
via reddit https://ift.tt/2p5vxU0
Vulmon
Vulmon - Vulnerability Intelligence Search Engine
Vulmon is a vulnerability and exploit search engine with vulnerability intelligence features.