Finding Domain frontable Azure domains
http://ift.tt/2eIbEjY
Submitted July 24, 2017 at 09:06PM by Gallus
via reddit http://ift.tt/2vBlvMD
http://ift.tt/2eIbEjY
Submitted July 24, 2017 at 09:06PM by Gallus
via reddit http://ift.tt/2vBlvMD
Theobsidiantower
Finding Domain frontable Azure domains
If you’re not familiar with domain fronting then the tl;dr is a number of large CDNs route based on the Host: header which means you can connect to google.co...
Introducing Web Sight - Enterprise Attack Surface Enumeration (BH Arsenal 2017)
http://ift.tt/2tv091O
Submitted July 24, 2017 at 09:39PM by but_im_made_of_lava
via reddit http://ift.tt/2tTZIxq
http://ift.tt/2tv091O
Submitted July 24, 2017 at 09:39PM by but_im_made_of_lava
via reddit http://ift.tt/2tTZIxq
l.avala.mp's place
Web Sight Community Edition – Enterprise Attack Surface Enumeration
Greetings and thanks for stopping by! It is with some seriously mixed emotions that I bring this blog post to you, as this post is the culmination of a failed business and nearly two years of heart…
Introducing Soft U2F, a software U2F authenticator for macOS (Made with <3 by GitHub)
http://ift.tt/2v0rP36
Submitted July 25, 2017 at 12:21AM by Fletch_to_99
via reddit http://ift.tt/2gXIq1A
http://ift.tt/2v0rP36
Submitted July 25, 2017 at 12:21AM by Fletch_to_99
via reddit http://ift.tt/2gXIq1A
GitHub Engineering
Soft U2F
In an effort to increase the adoption of FIDO U2F second factor authentication, we’re releasing Soft U2F: a software-based U2F authenticator for macOS.
Bright City: A Highly Insecure Police and Municipal Government App
http://ift.tt/2uQZv2L
Submitted July 25, 2017 at 01:55AM by rwestergren
via reddit http://ift.tt/2tvNyvn
http://ift.tt/2uQZv2L
Submitted July 25, 2017 at 01:55AM by rwestergren
via reddit http://ift.tt/2tvNyvn
Randy Westergren
Bright City: A Highly Insecure Police and Municipal Government App - Randy Westergren
Earlier this year I received a Nextdoor message from my County Police Department announcing a “Property LockBox App” they’d released (purchased) for citizens. There was no previous communication regarding this app that I could find, so I was interested in…
Full rewrite: Zydis v2.0 alpha released (X86-64 disassembler library) [X-Post /r/ReverseEngineering]
http://ift.tt/2tvEI0H
Submitted July 25, 2017 at 03:00AM by athre0z
via reddit http://ift.tt/2vCNlYS
http://ift.tt/2tvEI0H
Submitted July 25, 2017 at 03:00AM by athre0z
via reddit http://ift.tt/2vCNlYS
Flow Ambiguity: A Path Towards Classically Driven Blind Quantum Computation
http://ift.tt/2ueV0hD
Submitted July 25, 2017 at 04:46AM by Natanael_L
via reddit http://ift.tt/2eJ3U1k
http://ift.tt/2ueV0hD
Submitted July 25, 2017 at 04:46AM by Natanael_L
via reddit http://ift.tt/2eJ3U1k
Physical Review X
Flow Ambiguity: A Path Towards Classically Driven Blind Quantum Computation
Current protocols for securely delegating computation to remote quantum computers require some form of quantum communication, thus limiting secure access to future cloud-based quantum computing resources. A new analysis shows that it is possible to hide critical…
Crack WPA/WPA2 Wi-Fi Routers with Aircrack-ng and Hashcat
http://ift.tt/2uO2ZD0
Submitted July 25, 2017 at 07:01AM by brannondorsey
via reddit http://ift.tt/2uTMHZ5
http://ift.tt/2uO2ZD0
Submitted July 25, 2017 at 07:01AM by brannondorsey
via reddit http://ift.tt/2uTMHZ5
GitHub
brannondorsey/wifi-cracking
wifi-cracking - Crack WPA/WPA2 Wi-Fi Routers with Airodump-ng and Aircrack-ng/Hashcat 🖧
How We Made Daily Malware And Vulnerability Scanning Free For All Websites
http://ift.tt/2tylcRc
Submitted July 25, 2017 at 10:46AM by wt1j
via reddit http://ift.tt/2tUYe6q
http://ift.tt/2tylcRc
Submitted July 25, 2017 at 10:46AM by wt1j
via reddit http://ift.tt/2tUYe6q
Gravityscan
How We Made Daily Malware And Vulnerability Scanning Free For All Websites - Gravityscan
As I start two write this, it is 6pm in Seattle and getting close to the end of launch day for the Gravityscan badge program. And I am really happy. We already have over 541 websites that have installed the Gravityscan badge and are getting free daily monitoring…
Dump LAPS passwords with ldapsearch
http://ift.tt/2uUOUmT
Submitted July 25, 2017 at 12:44PM by FireFart
via reddit http://ift.tt/2eK0viI
http://ift.tt/2uUOUmT
Submitted July 25, 2017 at 12:44PM by FireFart
via reddit http://ift.tt/2eK0viI
Room362
Dump LAPS passwords with ldapsearch · Rob 'mubix' Fuller
If you’ve ever been pentesting an organization that had LAPS, you know that it is the best solution for randomizing local administrator passwords on the planet. (You should just be leaving them disabled).
LAPS stores it’s information in Active Directory:…
LAPS stores it’s information in Active Directory:…
Universal Android SSL Pinning bypass with Frida
http://ift.tt/2tG2paK
Submitted July 25, 2017 at 02:08PM by 0xdea
via reddit http://ift.tt/2uT6J6x
http://ift.tt/2tG2paK
Submitted July 25, 2017 at 02:08PM by 0xdea
via reddit http://ift.tt/2uT6J6x
reddit
Universal Android SSL Pinning bypass with Frida • r/netsec
2 points and 0 comments so far on reddit
Deauthentication attack and other wifi hacks using an ESP8266 module.
http://ift.tt/2uSR8Ud
Submitted July 25, 2017 at 05:09PM by xenexfor
via reddit http://ift.tt/2utW7d9
http://ift.tt/2uSR8Ud
Submitted July 25, 2017 at 05:09PM by xenexfor
via reddit http://ift.tt/2utW7d9
Medium
Deauthentication attack and other ‘wifi hacks’ using an ESP8266 module.
As famed wifi hacker Samy Kamkar recently said we should move towards low-cost hacking/exploitation tools. NodeMCU is one of such tools, a…
8 Valuable Security Certifications For 2017
http://ift.tt/2eInc6Z
Submitted July 25, 2017 at 08:06PM by katebrownwell
via reddit http://ift.tt/2v4IVNB
http://ift.tt/2eInc6Z
Submitted July 25, 2017 at 08:06PM by katebrownwell
via reddit http://ift.tt/2v4IVNB
websecurity
8 Valuable Security Certifications For 2017 - Gotowebsecurity
How you can save your valuable data from getting stolen? Well, there are some security certification courses are available for everyone.
Open Sourcing JA3, SSL Client Fingerprinting, makes detecting malware easy. Really easy.
http://ift.tt/2tzyc9r
Submitted July 25, 2017 at 10:50PM by darkfiber-
via reddit http://ift.tt/2tGUMB9
http://ift.tt/2tzyc9r
Submitted July 25, 2017 at 10:50PM by darkfiber-
via reddit http://ift.tt/2tGUMB9
Salesforce Engineering
Open Sourcing JA3
SSL/TLS Client Fingerprinting for Malware Detection
Get notified when a CVE change has been detected in your Docker image
https://beta.anchore.io
Submitted July 25, 2017 at 11:21PM by weighanchore
via reddit http://ift.tt/2h0BpNf
https://beta.anchore.io
Submitted July 25, 2017 at 11:21PM by weighanchore
via reddit http://ift.tt/2h0BpNf
reddit
Get notified when a CVE change has been detected in... • r/netsec
6 points and 0 comments so far on reddit
Exploring voice-based authentication systems to inject commands
https://www.youtube.com/playlist?list=PLl6DAJhNeWAmOcGC38tLlFGdevLniiUmG
Submitted July 25, 2017 at 01:54PM by hemorro
via reddit http://ift.tt/2v5gChT
https://www.youtube.com/playlist?list=PLl6DAJhNeWAmOcGC38tLlFGdevLniiUmG
Submitted July 25, 2017 at 01:54PM by hemorro
via reddit http://ift.tt/2v5gChT
YouTube
EMHacktivity - YouTube
Trust Issues: Exploiting TrustZone TEEs
http://ift.tt/2uWFx6w
Submitted July 25, 2017 at 07:37AM by numberbuzy
via reddit http://ift.tt/2vXLGwq
http://ift.tt/2uWFx6w
Submitted July 25, 2017 at 07:37AM by numberbuzy
via reddit http://ift.tt/2vXLGwq
googleprojectzero.blogspot.co.uk
Trust Issues: Exploiting TrustZone TEEs
Posted by Gal Beniamini, Project Zero Mobile devices are becoming an increasingly privacy-sensitive platform. Nowadays, devices process ...
BSidesLV Livestreams 🔴
http://ift.tt/2tzOC1n
Submitted July 26, 2017 at 12:16AM by Maijin
via reddit http://ift.tt/2v5TD6d
http://ift.tt/2tzOC1n
Submitted July 26, 2017 at 12:16AM by Maijin
via reddit http://ift.tt/2v5TD6d
Peerlyst
Top "bsideslv" experts and posts
Read about "bsideslv" wiki, training, posts, blogs, discussions, overview, Q&A, vendors, products, and events.
"Bypassing" Microsoft's Patch for CVE-2017-0199
http://ift.tt/2tA0Wib
Submitted July 25, 2017 at 09:21PM by vipzen
via reddit http://ift.tt/2vXOFoo
http://ift.tt/2tA0Wib
Submitted July 25, 2017 at 09:21PM by vipzen
via reddit http://ift.tt/2vXOFoo
justhaifei1.blogspot.co.uk
"Bypassing" Microsoft's Patch for CVE-2017-0199
Background If you have followed my research on the infamous CVE-2017-0199 zero-day attack, you may know we (w/ my colleague Bing) did a p...
SOURCE CODE FOR INTEGER FACTORIZATION. This program can factor integers of any arbitrary precision. So public key encryption is null and void as it attacks the basic premise that very large integers cannot be factored in reasonable amounts of time
http://ift.tt/2uWtMwS
Submitted July 26, 2017 at 12:16AM by subhendrabasu
via reddit http://ift.tt/2v5sPD1
http://ift.tt/2uWtMwS
Submitted July 26, 2017 at 12:16AM by subhendrabasu
via reddit http://ift.tt/2v5sPD1
Dropbox
SourceCode-AlgorithmIntfact.pdf
Shared with Dropbox
Metadata: a hacker's best friend
http://ift.tt/2tXagfq
Submitted July 26, 2017 at 12:56AM by intense_feel
via reddit http://ift.tt/2vGwxQy
http://ift.tt/2tXagfq
Submitted July 26, 2017 at 12:56AM by intense_feel
via reddit http://ift.tt/2vGwxQy
Sweepatic Blog
Metadata: a hacker's best friend
Summary In this blog post, we are going to explore what the metadata of a document are and why it's such a juicy source of information for advanced attackers. A document's metadata allows to collect various high-sensitive data such as usernames, software…