Practical TLS examples: TLS 1.3, automatic Let's Encrypt, and more
https://ift.tt/2Dzpmky
Submitted November 09, 2018 at 10:00PM by bswap
via reddit https://ift.tt/2JRKKBO
https://ift.tt/2Dzpmky
Submitted November 09, 2018 at 10:00PM by bswap
via reddit https://ift.tt/2JRKKBO
Probe.ly
How to deploy modern TLS in 2018?
Exciting things have been happening on TLS land lately. TLS 1.3 was finally released, bringing many security and performance improvements…
The impact of bad Certificate Management in Sennheiser Headsetup - Vulnerability Report
https://ift.tt/2FezLUs
Submitted November 09, 2018 at 10:34PM by harrie9191
via reddit https://ift.tt/2qB7mh0
https://ift.tt/2FezLUs
Submitted November 09, 2018 at 10:34PM by harrie9191
via reddit https://ift.tt/2qB7mh0
Deep Analysis of TrickBot New Module pwgrab
https://ift.tt/2zGXZAv
Submitted November 09, 2018 at 10:22PM by EvanConover
via reddit https://ift.tt/2RLfB5H
https://ift.tt/2zGXZAv
Submitted November 09, 2018 at 10:22PM by EvanConover
via reddit https://ift.tt/2RLfB5H
Fortinet Blog
Deep Analysis of TrickBot New Module pwgrab
FortiGuard Labs found a new TrickBot variant, with a new module pwgrab, which attempts to steal credentials, autofill data, history and so on. We did a deep analysis on this pwgrab module to explai…
Introducing the Android Ecosystem Security Transparency Report
https://ift.tt/2AWfPkU
Submitted November 10, 2018 at 07:03AM by jdrch
via reddit https://ift.tt/2T1KC6Q
https://ift.tt/2AWfPkU
Submitted November 10, 2018 at 07:03AM by jdrch
via reddit https://ift.tt/2T1KC6Q
Googleblog
Introducing the Android Ecosystem Security Transparency Report
Posted by Jason Woloz and Eugene Liderman, Android Security & Privacy Team Update: We identified a bug that affected how we calculated dat...
Countering SSH Brute Attackers
https://ift.tt/2qDBM2h
Submitted November 10, 2018 at 02:27PM by lawandordercandidate
via reddit https://ift.tt/2zEJ0Y0
https://ift.tt/2qDBM2h
Submitted November 10, 2018 at 02:27PM by lawandordercandidate
via reddit https://ift.tt/2zEJ0Y0
MUFASA.GQ
Countering SSH Brute Attackers
The amount of attacks a server gets when the SSH port is open is ridiculous.
Chinese version of Shodan
https://www.fofa.so/
Submitted November 10, 2018 at 09:05PM by digicat
via reddit https://ift.tt/2Fg5N2o
https://www.fofa.so/
Submitted November 10, 2018 at 09:05PM by digicat
via reddit https://ift.tt/2Fg5N2o
FOFA
FOFA Search Engine
FOFA is a Cyberspace search engine. By conducting Cyberspace mapping, it can help researchers or enterprises quickly match network assets, such as vulnerability impact range analysis, application distribution statistics, and application popularity ranking…
Exposed Sonos speakers Webinterface
https://ift.tt/2PUAoqe
Submitted November 12, 2018 at 01:58AM by Orlin82
via reddit https://ift.tt/2T4XAAP
https://ift.tt/2PUAoqe
Submitted November 12, 2018 at 01:58AM by Orlin82
via reddit https://ift.tt/2T4XAAP
reddit
r/netsec - Exposed Sonos speakers Webinterface
23 votes and 2 comments so far on Reddit
Malware discovered on Google Play with over 5,000 installs was available to download for almost a year
https://ift.tt/2QB5uQZ
Submitted November 12, 2018 at 01:41PM by lukasstefanko
via reddit https://ift.tt/2PRI9gx
https://ift.tt/2QB5uQZ
Submitted November 12, 2018 at 01:41PM by lukasstefanko
via reddit https://ift.tt/2PRI9gx
Lukas Stefanko
Malware discovered on Google Play with over 5,000 installs was available to download for almost a year - Lukas Stefanko
Trojan discovered on Googel Play was available for download almost for a year. Its malicious functionality was hidden inside “Simple Call Recorder” application with over 5,000 installs.
Building C&Cs with DNS communication in few minutes
https://ift.tt/2DhED8Q
Submitted November 12, 2018 at 01:33PM by gid0rah
via reddit https://ift.tt/2qFRGcD
https://ift.tt/2DhED8Q
Submitted November 12, 2018 at 01:33PM by gid0rah
via reddit https://ift.tt/2qFRGcD
x-c3ll.github.io
Building simple DNS endpoints for exfiltration or C&C ::
DoomsDay Vault
DoomsDay Vault
Brief tutorial of how to use backend pipes in PowerDNS for exfiltration
Want to Middlebox TLS 1.3, don't worry the ETSI has you covered.
https://ift.tt/2B2N2LJ
Submitted November 12, 2018 at 07:16PM by alnarra_1
via reddit https://ift.tt/2JWyfFf
https://ift.tt/2B2N2LJ
Submitted November 12, 2018 at 07:16PM by alnarra_1
via reddit https://ift.tt/2JWyfFf
ETSI
ETSI releases standards for enterprise security and data centre management
Press release, ETSI releases standards for enterprise security and data centre management
How secure is the Ciphersweet library for searchable encryption, and why is a duplicate entry leak not a problem?
https://ift.tt/2Fdirz9
Submitted November 12, 2018 at 08:27PM by sarciszewski
via reddit https://ift.tt/2JWtmMk
https://ift.tt/2Fdirz9
Submitted November 12, 2018 at 08:27PM by sarciszewski
via reddit https://ift.tt/2JWtmMk
Information Security Stack Exchange
How secure is the Ciphersweet library for searchable encryption, and why is a duplicate entry leak not a problem?
I'm currently managing a code base in which we've got a mysql database with all records encrypted using the php-encryption library. This works well for our current setup. We now got a new business
Trends Emerging Following Vulnerability In WP GDPR Compliance Plugin
https://ift.tt/2zHcUe9
Submitted November 12, 2018 at 10:56PM by EvanConover
via reddit https://ift.tt/2B1a1GR
https://ift.tt/2zHcUe9
Submitted November 12, 2018 at 10:56PM by EvanConover
via reddit https://ift.tt/2B1a1GR
Wordfence
Trends Emerging Following Vulnerability In WP GDPR Compliance Plugin
Earlier this week the WP GDPR Compliance plugin was briefly removed from the WordPress.org repository after the discovery of critical security issues impacting its users. In yesterday’s post, we provided some details regarding these issues and illustrated…
Sacara VM Vs Antivirus Industry
https://ift.tt/2RVkbyH
Submitted November 12, 2018 at 02:48PM by aparata_s4tan
via reddit https://ift.tt/2PXN5AA
https://ift.tt/2RVkbyH
Submitted November 12, 2018 at 02:48PM by aparata_s4tan
via reddit https://ift.tt/2PXN5AA
Blogspot
Sacara VM Vs Antivirus Industry
Twitter: @s4tan Sacara VM GitHub project: https://github.com/enkomio/sacara In this blog post I want to describe a bit my latest side pro...
XSStrike - Advanced XSS Detection Suite v3.0 released
https://ift.tt/2Dg6pSX
Submitted November 12, 2018 at 11:41AM by _vavkamil_
via reddit https://ift.tt/2OFBZf4
https://ift.tt/2Dg6pSX
Submitted November 12, 2018 at 11:41AM by _vavkamil_
via reddit https://ift.tt/2OFBZf4
GitHub
s0md3v/XSStrike
Most advanced XSS detection suite. Contribute to s0md3v/XSStrike development by creating an account on GitHub.
What's new in TrickBot? Deobfuscating elements
https://ift.tt/2zJpYzI
Submitted November 13, 2018 at 01:26AM by EvanConover
via reddit https://ift.tt/2z5cheS
https://ift.tt/2zJpYzI
Submitted November 13, 2018 at 01:26AM by EvanConover
via reddit https://ift.tt/2z5cheS
Malwarebytes Labs
What's new in TrickBot? Deobfuscating elements - Malwarebytes Labs
Trojan.TrickBot has been present in the threat landscape from quite a while. We wrote about its first version in October 2016. From the beginning, it was a well organized modular malware, written by developers with mature skills. It is often called a banker…
Trinity - P2P Malware Over Android Debug Bridge
https://ift.tt/2POyBjd
Submitted November 13, 2018 at 03:41AM by CosmoTheParrot
via reddit https://ift.tt/2FgjCxW
https://ift.tt/2POyBjd
Submitted November 13, 2018 at 03:41AM by CosmoTheParrot
via reddit https://ift.tt/2FgjCxW
Ixiacom
Trinity - P2P Malware Over ADB | Ixia
ADB - Trinity in Words
The Android Debug Bridge (ADB) is a protocol designed to keep track of both emulated and real phones/TVs/DVRs connected to a given host. It implements various commands designed to assist the developer (adb shell, adb push, and so on)…
The Android Debug Bridge (ADB) is a protocol designed to keep track of both emulated and real phones/TVs/DVRs connected to a given host. It implements various commands designed to assist the developer (adb shell, adb push, and so on)…
USN-3815-1: gettext vulnerability
https://ift.tt/2OH4Uzk
Submitted November 13, 2018 at 07:02AM by jdrch
via reddit https://ift.tt/2zLHAer
https://ift.tt/2OH4Uzk
Submitted November 13, 2018 at 07:02AM by jdrch
via reddit https://ift.tt/2zLHAer
Ubuntu
USN-3815-1: gettext vulnerability | Ubuntu security notices
It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute arbitrary code.
USN-3815-2: gettext vulnerability
https://ift.tt/2OBqGEt
Submitted November 13, 2018 at 07:02AM by jdrch
via reddit https://ift.tt/2zR3NaH
https://ift.tt/2OBqGEt
Submitted November 13, 2018 at 07:02AM by jdrch
via reddit https://ift.tt/2zR3NaH
Ubuntu
USN-3815-2: gettext vulnerability | Ubuntu security notices
USN-3815-1 fixed a vulnerability in gettext. This update provides the corresponding update for Ubuntu 12.04 ESM.
Original advisory details:
It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute…
Original advisory details:
It was discovered that gettext incorrectly handled certain messages. An attacker could possibly use this issue to execute…
Vulnerability in BGP takes down Google
https://ift.tt/2DCeySy
Submitted November 13, 2018 at 02:41PM by It_Is1-24PM
via reddit https://ift.tt/2PVTY5B
https://ift.tt/2DCeySy
Submitted November 13, 2018 at 02:41PM by It_Is1-24PM
via reddit https://ift.tt/2PVTY5B
Network Intelligence Blog | ThousandEyes
Internet Vulnerability Takes Down Google
BGP route leak interrupts access to Google’s services throughout the world. Traffic rerouted via Russia and China and slammed into the great firewall.
The rise of multivector DDoS attacks
https://ift.tt/2B1dhCo
Submitted November 13, 2018 at 04:18PM by pimterry
via reddit https://ift.tt/2B3UBSl
https://ift.tt/2B1dhCo
Submitted November 13, 2018 at 04:18PM by pimterry
via reddit https://ift.tt/2B3UBSl
The Cloudflare Blog
The rise of multivector DDoS attacks
It's been a while since we last wrote about Layer 3/4 DDoS attacks on this blog. This is a good news - we've been quietly handling the daily onslaught of DDoS attacks. Since our last write-up, a handful of interesting L3/4 attacks have happened. Let's review…
#FCL (Fileless Command Lines) - Known command lines of fileless malicious executions
https://ift.tt/2FefoXo
Submitted November 13, 2018 at 06:05PM by chenerlich
via reddit https://ift.tt/2OJ70ia
https://ift.tt/2FefoXo
Submitted November 13, 2018 at 06:05PM by chenerlich
via reddit https://ift.tt/2OJ70ia
GitHub
chenerlich/FCL
FCL (Fileless Command Lines) - Known command lines of fileless malicious executions - chenerlich/FCL