use nginx auth_request module and Lasso to protect all of your private applications with Google Auth
https://ift.tt/2O73oWU
Submitted October 27, 2018 at 12:50AM by bnfinet
via reddit https://ift.tt/2z51HDT
https://ift.tt/2O73oWU
Submitted October 27, 2018 at 12:50AM by bnfinet
via reddit https://ift.tt/2z51HDT
Medium
Enforce Google Authentication for Any Application with nginx and Lasso
By using the nginx auth_request module and Lasso you can protect any application running behind your nginx reverse proxy with OAuth. Lasso…
Trivial local privilege escalation to root in X11 - CVE-2018-14665
https://ift.tt/2CHyr9S
Submitted October 27, 2018 at 05:42PM by picklednull
via reddit https://ift.tt/2Au0HLn
https://ift.tt/2CHyr9S
Submitted October 27, 2018 at 05:42PM by picklednull
via reddit https://ift.tt/2Au0HLn
reddit
r/netsec - Trivial local privilege escalation to root in X11 - CVE-2018-14665
4 votes and 0 comments so far on Reddit
Rocket Shot: Backwards program slice stitching for automatic CTF problem solving.
https://ift.tt/2EMtP4F
Submitted October 27, 2018 at 05:51PM by Arrilius
via reddit https://ift.tt/2PnjBfs
https://ift.tt/2EMtP4F
Submitted October 27, 2018 at 05:51PM by Arrilius
via reddit https://ift.tt/2PnjBfs
GitHub
ChrisTheCoolHut/Rocket-Shot
Backwards program slice stitching for automatic CTF problem solving. - ChrisTheCoolHut/Rocket-Shot
BlackEye Phishing Kit In Python w/ Automatic Serveo Forwarding. Allows you to use custom subdomains.
https://ift.tt/2OQ1EGN
Submitted October 27, 2018 at 07:20PM by thecoderkiller
via reddit https://ift.tt/2Sokm6r
https://ift.tt/2OQ1EGN
Submitted October 27, 2018 at 07:20PM by thecoderkiller
via reddit https://ift.tt/2Sokm6r
GitHub
M4cs/BlackEye-Python
BlackEye Phishing Kit in Python w Serveo Subdomain Creation - M4cs/BlackEye-Python
Hack The Box – Bounty Walkthrough
https://ift.tt/2AvrtTJ
Submitted October 27, 2018 at 08:31PM by m4v3r1ck-
via reddit https://ift.tt/2PZKRh5
https://ift.tt/2AvrtTJ
Submitted October 27, 2018 at 08:31PM by m4v3r1ck-
via reddit https://ift.tt/2PZKRh5
VeteranSec
Hack The Box – Bounty Walkthrough
Video Walkthrough: Introduction: This week’s retiring machine is Bounty, which is a beginner-friendly box that can still teach a few new tricks. Bounty is rated 4.8/10, which I feel is prett…
PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls.
https://ift.tt/2D6M6bq
Submitted October 28, 2018 at 03:15AM by ustayready
via reddit https://ift.tt/2OaxRmN
https://ift.tt/2D6M6bq
Submitted October 28, 2018 at 03:15AM by ustayready
via reddit https://ift.tt/2OaxRmN
GitHub
ustayready/CasperStager
PoC for persisting .NET payloads in Windows Notification Facility (WNF) state names using low-level Windows Kernel API calls. - ustayready/CasperStager
Blocking Internet Ads Using DNS Sinkhole
https://ift.tt/2Smo40q
Submitted October 28, 2018 at 11:41AM by shreyasonline
via reddit https://ift.tt/2z9MVfd
https://ift.tt/2Smo40q
Submitted October 28, 2018 at 11:41AM by shreyasonline
via reddit https://ift.tt/2z9MVfd
Technitium
Blocking Internet Ads Using DNS Sinkhole
Technitium DNS Server is an open source software that can be effectively used to block Internet Advertisements (Ads), adware and, malware o...
SSLLabs.com can't connect to browser's with enforced TLS 1.3
https://ift.tt/2z8ViYi
Submitted October 28, 2018 at 04:06PM by rediii123
via reddit https://ift.tt/2JjRfNq
https://ift.tt/2z8ViYi
Submitted October 28, 2018 at 04:06PM by rediii123
via reddit https://ift.tt/2JjRfNq
Filtering NSFW Content While Running a Wall of Sheep in the Wild
https://ift.tt/2qaWnLa
Submitted October 28, 2018 at 06:01PM by xenexfor
via reddit https://ift.tt/2qeOioP
https://ift.tt/2qaWnLa
Submitted October 28, 2018 at 06:01PM by xenexfor
via reddit https://ift.tt/2qeOioP
/dev/random
Post-BruCON Experience - Running a Wall of Sheep in the Wild | /dev/random
The use of a Wall of Sheep is nice to raise the security awareness of your audience. A Wall of Sheep is a tool used to demonstrate what can happen when users connect to a wild network without a minimum level of security. The non-encrypted traffic is analyzed…
IBM Acquiring RedHat.
https://ift.tt/2ObUSWA
Submitted October 29, 2018 at 02:24AM by sastdast
via reddit https://ift.tt/2Q3rrry
https://ift.tt/2ObUSWA
Submitted October 29, 2018 at 02:24AM by sastdast
via reddit https://ift.tt/2Q3rrry
CNBC
IBM to acquire Red Hat in deal valued at $34 billion
The acquisition is by far IBM's largest deal ever, and third-biggest in the history of U.S. tech.
Systemd has a remotely exploitable bug in its DHCPv6 client
https://ift.tt/2CMl9bQ
Submitted October 29, 2018 at 03:47AM by xrna
via reddit https://ift.tt/2qfN1xT
https://ift.tt/2CMl9bQ
Submitted October 29, 2018 at 03:47AM by xrna
via reddit https://ift.tt/2qfN1xT
Erratasec
Systemd is bad parsing and should feel bad
Systemd has a remotely exploitable bug in it's DHCPv6 client. That means anybody on the local network can send you a packet and take control...
Three C-Words of Web App Security: Part 2 – CSRF
https://ift.tt/2PuKBtg
Submitted October 29, 2018 at 01:55PM by CyberBullets
via reddit https://ift.tt/2PZgLu1
https://ift.tt/2PuKBtg
Submitted October 29, 2018 at 01:55PM by CyberBullets
via reddit https://ift.tt/2PZgLu1
Fuxploider - File upload vulnerability scanner and exploitation tool
https://ift.tt/2uIkxkx
Submitted October 29, 2018 at 05:19PM by n1ghtw1sh
via reddit https://ift.tt/2SqeMQZ
https://ift.tt/2uIkxkx
Submitted October 29, 2018 at 05:19PM by n1ghtw1sh
via reddit https://ift.tt/2SqeMQZ
GitHub
almandin/fuxploider
File upload vulnerability scanner and exploitation tool. - almandin/fuxploider
New Android banking family found on Google Play with over 10,000 installs
https://ift.tt/2zeBzGE
Submitted October 29, 2018 at 06:38PM by lukasstefanko
via reddit https://ift.tt/2SsLqBu
https://ift.tt/2zeBzGE
Submitted October 29, 2018 at 06:38PM by lukasstefanko
via reddit https://ift.tt/2SsLqBu
Lukas Stefanko
Android banking malware found on Google Play with over 10,000 installs targets Brazil - Lukas Stefanko
New Android malware banking family was recently found targeting users from Brazil. Trojans are distributed not only through Google Play store but also on Facebook through promoted ads.
Malware sample library
https://ift.tt/2EHUEXR
Submitted October 29, 2018 at 09:03PM by mstfknn
via reddit https://ift.tt/2qiZAbG
https://ift.tt/2EHUEXR
Submitted October 29, 2018 at 09:03PM by mstfknn
via reddit https://ift.tt/2qiZAbG
GitHub
mstfknn/malware-sample-library
Malware sample library. Contribute to mstfknn/malware-sample-library development by creating an account on GitHub.
Attacking Google Authenticator
https://ift.tt/2CL3KjQ
Submitted October 29, 2018 at 09:00PM by westondeboer
via reddit https://ift.tt/2CNLRRG
https://ift.tt/2CL3KjQ
Submitted October 29, 2018 at 09:00PM by westondeboer
via reddit https://ift.tt/2CNLRRG
reddit
r/netsec - Attacking Google Authenticator
3 votes and 0 comments so far on Reddit
Same Old yet Brand-new: New File Types Emerge in Malware Spam Attachments
https://ift.tt/2SrDdxq
Submitted October 29, 2018 at 08:58PM by EvanConover
via reddit https://ift.tt/2qibWk4
https://ift.tt/2SrDdxq
Submitted October 29, 2018 at 08:58PM by EvanConover
via reddit https://ift.tt/2qibWk4
Trendmicro
Same Old yet Brand-new: New File Types Emerge in Malware Spam Attachments - TrendLabs Security Intelligence Blog
Cybercriminals make use of old file types in brand-new ways in spam attachments, proving that they are regularly experimenting to evade spam filters.
Attacking Google Authenticator
https://ift.tt/2CL3KjQ
Submitted October 29, 2018 at 09:38PM by Chris911
via reddit https://ift.tt/2SwcZKv
https://ift.tt/2CL3KjQ
Submitted October 29, 2018 at 09:38PM by Chris911
via reddit https://ift.tt/2SwcZKv
reddit
r/netsec - Attacking Google Authenticator
1 vote and 0 comments so far on Reddit
Windows Defender Antivirus can now run in a sandbox
https://ift.tt/2z7kq1B
Submitted October 30, 2018 at 01:15AM by picklednull
via reddit https://ift.tt/2zf31E6
https://ift.tt/2z7kq1B
Submitted October 30, 2018 at 01:15AM by picklednull
via reddit https://ift.tt/2zf31E6
Microsoft Security Blog
Windows Defender Antivirus can now run in a sandbox | Microsoft Security Blog
Windows Defender Antivirus has hit a new milestone: the built-in antivirus capabilities on Windows can now run within a sandbox.
Mac cryptocurrency ticker app installs backdoors
https://ift.tt/2OiLrVC
Submitted October 30, 2018 at 01:23AM by EvanConover
via reddit https://ift.tt/2ObKj5T
https://ift.tt/2OiLrVC
Submitted October 30, 2018 at 01:23AM by EvanConover
via reddit https://ift.tt/2ObKj5T
Malwarebytes
Mac cryptocurrency ticker app installs backdoors
A Mac application named CoinTicker has been found installing two different backdoors, capable of keylogging, data theft, execution of arbitrary commands, and more.
Facebook's New ID Verification System Is Intrusive
https://ift.tt/2OelmXt
Submitted October 30, 2018 at 06:02AM by lawandordercandidate
via reddit https://ift.tt/2Q5kFBB
https://ift.tt/2OelmXt
Submitted October 30, 2018 at 06:02AM by lawandordercandidate
via reddit https://ift.tt/2Q5kFBB
1000 Days of Code
Facebook's New ID Verification System Is Intrusive
I run social media for a small company that represents unions in the local area. Before, creating posts and Facebook ads have been easy. With [...]