OWASP Vulnerable Web Applications Directory Project/Pages/VMs
https://ift.tt/2xuxDBC
Submitted September 23, 2018 at 10:57PM by fireh7nter
via reddit https://ift.tt/2zoSGXM
https://ift.tt/2xuxDBC
Submitted September 23, 2018 at 10:57PM by fireh7nter
via reddit https://ift.tt/2zoSGXM
reddit
r/netsec - OWASP Vulnerable Web Applications Directory Project/Pages/VMs
0 votes and 1 comment so far on Reddit
Browser Reaper has been released so you can kill your browser.
https://reaperbugs.com
Submitted September 24, 2018 at 02:16AM by pwnsdxpw
via reddit https://ift.tt/2Doq3hl
https://reaperbugs.com
Submitted September 24, 2018 at 02:16AM by pwnsdxpw
via reddit https://ift.tt/2Doq3hl
Reaperbugs
Browser Reaper
From VNC to reverse shell
https://ift.tt/2O64HJy
Submitted September 24, 2018 at 03:53AM by Benjojo
via reddit https://ift.tt/2NzkgKv
https://ift.tt/2O64HJy
Submitted September 24, 2018 at 03:53AM by Benjojo
via reddit https://ift.tt/2NzkgKv
reddit
r/netsec - From VNC to reverse shell
21 votes and 0 comments so far on Reddit
Abusing SUDO (Linux Privilege Escalation)
https://ift.tt/2JVAxUw
Submitted September 24, 2018 at 06:46PM by xenexfor
via reddit https://ift.tt/2IbWbDs
https://ift.tt/2JVAxUw
Submitted September 24, 2018 at 06:46PM by xenexfor
via reddit https://ift.tt/2IbWbDs
Touhid M.Shaikh
Abusing SUDO (Linux Privilege Escalation) - Touhid M.Shaikh
The SUDO(Substitute User and Do) command , allows users to delegate privileges resources proceeding activity logging. In other words users can execute command under root ( or other users) using their own passwords instead of root’s one or without password…
Encrypting SNI: Fixing One of the Core Internet Bugs
https://ift.tt/2OM18Wg
Submitted September 24, 2018 at 07:53PM by protecz
via reddit https://ift.tt/2IcaWGm
https://ift.tt/2OM18Wg
Submitted September 24, 2018 at 07:53PM by protecz
via reddit https://ift.tt/2IcaWGm
The Cloudflare Blog
Encrypting SNI: Fixing One of the Core Internet Bugs
Cloudflare launched on September 27, 2010. Since then, we've considered September 27th our birthday. This Thursday we'll be turning 8 years old.
Ever since our first birthday, we've used the occasion to launch new products or services.
Ever since our first birthday, we've used the occasion to launch new products or services.
Outrunning Attackers On The Jet Database Engine 0day
https://ift.tt/2QTvAPw
Submitted September 24, 2018 at 10:41PM by dielel
via reddit https://ift.tt/2PXTNDd
https://ift.tt/2QTvAPw
Submitted September 24, 2018 at 10:41PM by dielel
via reddit https://ift.tt/2PXTNDd
0Patch
Outrunning Attackers On The Jet Database Engine 0day (CVE-2018-8423)
Micropatching Makes It Possible To Create And Apply Patches Before Attackers Write a Reliable Exploit by Mitja Kolsek, the 0patch Team ...
Mobile Menace Monday: SMS phishing attacks target the job market - Malwarebytes Labs
https://ift.tt/2OcB75y
Submitted September 25, 2018 at 12:18AM by glimpsed
via reddit https://ift.tt/2O8x0ao
https://ift.tt/2OcB75y
Submitted September 25, 2018 at 12:18AM by glimpsed
via reddit https://ift.tt/2O8x0ao
Malwarebytes
Mobile Menace Monday: SMS phishing attacks target the job market
Could it be that our dream job awaits via a random SMS message? On the contrary, this SMS phishing attack could cause nightmares for unsuspecting job hunters.
Unlock any car - HackRF and Universal Hacker Radio
https://ift.tt/2Q3829B
Submitted September 25, 2018 at 07:23AM by nullze
via reddit https://ift.tt/2xQ3BaM
https://ift.tt/2Q3829B
Submitted September 25, 2018 at 07:23AM by nullze
via reddit https://ift.tt/2xQ3BaM
reddit
r/netsec - Unlock any car - HackRF and Universal Hacker Radio
0 votes and 7 comments so far on Reddit
Tencent security engineer fined 5000 SGD for Singapore hotel hack
https://ift.tt/2O2VbHs
Submitted September 25, 2018 at 09:29AM by Dessem
via reddit https://ift.tt/2NBQdBL
https://ift.tt/2O2VbHs
Submitted September 25, 2018 at 09:29AM by Dessem
via reddit https://ift.tt/2NBQdBL
Yahoo
Tencent engineer attending cybersecurity event fined for Fragrance hotel hacking
While attending a cybersecurity conference in Singapore, a Chinese national decided to hack into the WiFi of the hotel he was staying in. Zheng Dutao, a 23-year-old security engineer with Chinese internet giant Tencent Holdings, was curious to find any vulnerabilities…
Threat intelligence analysis on onion websites
https://ift.tt/2xAdDxE
Submitted September 25, 2018 at 01:26PM by ragupal
via reddit https://ift.tt/2QZekZx
https://ift.tt/2xAdDxE
Submitted September 25, 2018 at 01:26PM by ragupal
via reddit https://ift.tt/2QZekZx
Deep Dot Web
Using keywords and links to perform threat intelligence analysis on onion websites - Deep Dot Web
With rapid advancement of technologies on the dark web, cybercrimes are skyrocketing. Onion websites represent the main source of illegal activities across the dark web. Cyber threat intelligence (CTI) aims at pinpointing onion websites that represent the…
From Kekeo to Rubeus
https://ift.tt/2MZK9hp
Submitted September 25, 2018 at 01:58PM by FireFart
via reddit https://ift.tt/2xBHs0G
https://ift.tt/2MZK9hp
Submitted September 25, 2018 at 01:58PM by FireFart
via reddit https://ift.tt/2xBHs0G
Posts By SpecterOps Team Members
From Kekeo to Rubeus
Kekeo, the other big project from Benjamin Delpy after Mimikatz, is an awesome code base with a set of great features. As Benjamin states, it’s external to the Mimikatz codebase because, “I hate to…
Juicy Potato: new Windows local privilege escalation tool
https://ift.tt/2QX5QC4
Submitted September 25, 2018 at 03:06PM by 0xdea
via reddit https://ift.tt/2xOZcoJ
https://ift.tt/2QX5QC4
Submitted September 25, 2018 at 03:06PM by 0xdea
via reddit https://ift.tt/2xOZcoJ
juicy-potato
Juicy Potato (abusing the golden privileges)
A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM.
Deep Analysis of a Driver-Based MITM Malware: iTranslator
https://ift.tt/2Nv0xM0
Submitted September 25, 2018 at 05:34PM by glimpsed
via reddit https://ift.tt/2xBr8x5
https://ift.tt/2Nv0xM0
Submitted September 25, 2018 at 05:34PM by glimpsed
via reddit https://ift.tt/2xBr8x5
Fortinet Blog
Deep Analysis of a Driver-Based MITM Malware: iTranslator
The FortiGuard Labs research team recently captured a malware sample, an EXE file, which was signed by an invalid certificate. Once a victim opens the exe file, it installs two drivers to control t…
New Twist to Doing Cold Boot Attacks
https://ift.tt/2MqBfJJ
Submitted September 25, 2018 at 07:11PM by CyberBullets
via reddit https://ift.tt/2QWf69q
https://ift.tt/2MqBfJJ
Submitted September 25, 2018 at 07:11PM by CyberBullets
via reddit https://ift.tt/2QWf69q
F-Secure Blog
The Chilling Reality of Cold Boot Attacks - F-Secure Blog
What do you do when you finish working with your laptop? Do you turn it off? Put it to sleep? Just close the lid and walk away? Many people might not realize that what they do when leaving their laptop unattended, even a laptop with full disk encryption,…
Disarm a Home Security System (No rolling encryption)
https://ift.tt/2ztCynO
Submitted September 26, 2018 at 09:04AM by nullze
via reddit https://ift.tt/2ONTJWw
https://ift.tt/2ztCynO
Submitted September 26, 2018 at 09:04AM by nullze
via reddit https://ift.tt/2ONTJWw
Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges
https://ift.tt/2D6qEEh
Submitted September 26, 2018 at 02:40PM by CyberBullets
via reddit https://ift.tt/2QaBrPv
https://ift.tt/2D6qEEh
Submitted September 26, 2018 at 02:40PM by CyberBullets
via reddit https://ift.tt/2QaBrPv
www.securify.nl
Authentication bypass vulnerability in Western Digital My Cloud allows escalation to admin privileges
Securify provides reality checks to lower security risks and build up resilience against threats. Agile Security, Pentesting (scenario-based) and Red Teaming.
Linux kernel universal heap spray userfaultfd+setxattr
https://ift.tt/2IjABNA
Submitted September 26, 2018 at 04:06PM by vnik5287
via reddit https://ift.tt/2DxZ96M
https://ift.tt/2IjABNA
Submitted September 26, 2018 at 04:06PM by vnik5287
via reddit https://ift.tt/2DxZ96M
Cyseclabs
Linux Kernel universal heap spray - Vitaly Nikolenko
Universal Linux kernel heap spray
Effortless security feature detection with Winchecksec
https://ift.tt/2N1BcEh
Submitted September 26, 2018 at 05:48PM by yossarian_flew_away
via reddit https://ift.tt/2xG2jzZ
https://ift.tt/2N1BcEh
Submitted September 26, 2018 at 05:48PM by yossarian_flew_away
via reddit https://ift.tt/2xG2jzZ
Trail of Bits Blog
Effortless security feature detection with Winchecksec
We’re proud to announce the release of Winchecksec, a new open-source tool that detects security features in Windows binaries. Developed to satisfy our analysis and research needs, Wincheckse…
cspparse: A tool to evaluate Content Security Policies.
https://ift.tt/2R1SOTD
Submitted September 26, 2018 at 09:58PM by sxcurity
via reddit https://ift.tt/2IhUvZo
https://ift.tt/2R1SOTD
Submitted September 26, 2018 at 09:58PM by sxcurity
via reddit https://ift.tt/2IhUvZo
GitHub
GitHub - lc/cspparse: A tool to evaluate Content Security Policies.
A tool to evaluate Content Security Policies. Contribute to lc/cspparse development by creating an account on GitHub.
BYOB (Build Your Own Botnet)
https://ift.tt/2o2lJKj
Submitted September 26, 2018 at 09:35PM by PoonSafari
via reddit https://ift.tt/2zw9H21
https://ift.tt/2o2lJKj
Submitted September 26, 2018 at 09:35PM by PoonSafari
via reddit https://ift.tt/2zw9H21
GitHub
GitHub - malwaredllc/byob: An open-source post-exploitation framework for students, researchers and developers.
An open-source post-exploitation framework for students, researchers and developers. - GitHub - malwaredllc/byob: An open-source post-exploitation framework for students, researchers and developers.
windows-ntfs-tricks-collection/
https://ift.tt/2LNNfoB
Submitted September 26, 2018 at 10:26PM by ericnyamu
via reddit https://ift.tt/2Dz9Ohp
https://ift.tt/2LNNfoB
Submitted September 26, 2018 at 10:26PM by ericnyamu
via reddit https://ift.tt/2Dz9Ohp