CVE-2018-8471 | Microsoft RemoteFX Virtual GPU miniport driver Elevation of Privilege Vulnerability
https://ift.tt/2qMsDVo
Submitted November 14, 2018 at 11:01PM by jdrch
via reddit https://ift.tt/2PxnZJK
https://ift.tt/2qMsDVo
Submitted November 14, 2018 at 11:01PM by jdrch
via reddit https://ift.tt/2PxnZJK
Security updates available for Flash Player | APSB18-39
https://ift.tt/2FmYXZ4
Submitted November 14, 2018 at 11:00PM by jdrch
via reddit https://ift.tt/2FmU6XO
https://ift.tt/2FmYXZ4
Submitted November 14, 2018 at 11:00PM by jdrch
via reddit https://ift.tt/2FmU6XO
Adobe
Adobe Security Bulletin
Security updates available for Flash Player
msf-autoshell: Give it a .nessus file and watch Metasploit shells rain upon ye
https://ift.tt/2PYOl6H
Submitted November 14, 2018 at 10:50PM by FlyingTriangle
via reddit https://ift.tt/2DkfHgW
https://ift.tt/2PYOl6H
Submitted November 14, 2018 at 10:50PM by FlyingTriangle
via reddit https://ift.tt/2DkfHgW
GitHub
DanMcInerney/msf-autoshell
Feed the tool a .nessus file and it will automatically get you MSF shell - DanMcInerney/msf-autoshell
CVE-2018-8544 | Windows VBScript Engine Remote Code Execution Vulnerability
https://ift.tt/2DmmWVm
Submitted November 14, 2018 at 11:40PM by jdrch
via reddit https://ift.tt/2Q0Fj92
https://ift.tt/2DmmWVm
Submitted November 14, 2018 at 11:40PM by jdrch
via reddit https://ift.tt/2Q0Fj92
reddit
r/netsec - CVE-2018-8544 | Windows VBScript Engine Remote Code Execution Vulnerability
0 votes and 0 comments so far on Reddit
Adventures in Fuzzing - NYU Talk 2018
https://www.youtube.com/watch?v=SngK4W4tVc0
Submitted November 14, 2018 at 04:56PM by gamozolabs
via reddit https://ift.tt/2B7QJjh
https://www.youtube.com/watch?v=SngK4W4tVc0
Submitted November 14, 2018 at 04:56PM by gamozolabs
via reddit https://ift.tt/2B7QJjh
YouTube
Adventures in Fuzzing - NYU Talk 2018
Get the slides and audio here: https://github.com/gamozolabs/adventures_in_fuzzing
Follow me on Twitter: https://twitter.com/gamozolabs
I gave a talk at NYU about some of the major tools I've worked on over the years and why they came to be.
Follow me on Twitter: https://twitter.com/gamozolabs
I gave a talk at NYU about some of the major tools I've worked on over the years and why they came to be.
CVE-2018-8553 | Microsoft Graphics Components Remote Code Execution Vulnerability
https://ift.tt/2PrTbtG
Submitted November 15, 2018 at 01:42AM by jdrch
via reddit https://ift.tt/2K4tx8k
https://ift.tt/2PrTbtG
Submitted November 15, 2018 at 01:42AM by jdrch
via reddit https://ift.tt/2K4tx8k
reddit
r/netsec - CVE-2018-8553 | Microsoft Graphics Components Remote Code Execution Vulnerability
0 votes and 6 comments so far on Reddit
CVE-2018-8553 | Microsoft Graphics Components Remote Code Execution Vulnerability
https://ift.tt/2PrTbtG
Submitted November 15, 2018 at 01:42AM by jdrch
via reddit https://ift.tt/2K4tx8k
https://ift.tt/2PrTbtG
Submitted November 15, 2018 at 01:42AM by jdrch
via reddit https://ift.tt/2K4tx8k
reddit
r/netsec - CVE-2018-8553 | Microsoft Graphics Components Remote Code Execution Vulnerability
0 votes and 6 comments so far on Reddit
Privilege Escalation in gVisor, Google's Container Sandbox
https://ift.tt/2FmcWOx
Submitted November 15, 2018 at 03:34AM by justicz
via reddit https://ift.tt/2OK1uvQ
https://ift.tt/2FmcWOx
Submitted November 15, 2018 at 03:34AM by justicz
via reddit https://ift.tt/2OK1uvQ
justi.cz
Privilege Escalation in gVisor, Google's Container Sandbox
tl;dr gVisor is Google’s sandboxing technology for containers running less-than-fully-trusted code. It’s a Golang reimplementation of the Linux kernel that r...
How to combine Pentesting with Automation to improve your security
https://ift.tt/2MdCfFv
Submitted November 15, 2018 at 06:01AM by nandodelgado
via reddit https://ift.tt/2QO8YQk
https://ift.tt/2MdCfFv
Submitted November 15, 2018 at 06:01AM by nandodelgado
via reddit https://ift.tt/2QO8YQk
Hackmetrix Blog
How to combine Pentesting with Automation to improve your security - Hackmetrix Blog
Combining manual penetration testing and automated security testing results in a comprehensive and effective approach to safety
Facebook employee morale is down after a turbulent year for the company, according to the reported findings of an internal survey.
https://ift.tt/2B5qvxU
Submitted November 15, 2018 at 10:49AM by biz_signity
via reddit https://ift.tt/2B8fU5f
https://ift.tt/2B5qvxU
Submitted November 15, 2018 at 10:49AM by biz_signity
via reddit https://ift.tt/2B8fU5f
Stock Market News Today
Facebook employee morale is down after a turbulent year for the company, according to the reported findings of an internal survey.
The darkening mood within the social-media giant is notable in part because its workforce has been resilient through other difficult patches in the past. That includes the period after the 2016 pre…
Using Google Bots as an Attack Vector
https://ift.tt/2RRVdQs
Submitted November 15, 2018 at 03:51PM by ziyahanalbeniz
via reddit https://ift.tt/2QHJaFd
https://ift.tt/2RRVdQs
Submitted November 15, 2018 at 03:51PM by ziyahanalbeniz
via reddit https://ift.tt/2QHJaFd
Netsparker
Using Google Bots as an Attack Vector
This article examines the latest attack vector to surface: using Google Bots. It examines how search engines sue bots to help index websites, explains how such attacks happen and how to counter them. Code samples are included.
The Powerful Resource of PHP Stream Wrappers
https://ift.tt/2z9xZhU
Submitted November 15, 2018 at 03:47PM by ziyahanalbeniz
via reddit https://ift.tt/2PujmQA
https://ift.tt/2z9xZhU
Submitted November 15, 2018 at 03:47PM by ziyahanalbeniz
via reddit https://ift.tt/2PujmQA
Netsparker
The Powerful Resource of PHP Stream Wrappers
This blog post examines how PHP stream wrappers can be used to bypass keyword based blacklists. It includes an examination of the generic functions that can be used to interact with streams, the concept of stream-context and steam filters. It also looks at…
Kickstarting an Integrated Risk Management Program
https://ift.tt/2PrIx6a
Submitted November 15, 2018 at 07:10PM by KeyDutch
via reddit https://ift.tt/2DpfxVD
https://ift.tt/2PrIx6a
Submitted November 15, 2018 at 07:10PM by KeyDutch
via reddit https://ift.tt/2DpfxVD
Htbridge
Kickstarting an Integrated Risk Management Program
Addressing Shadow IT, legacy and abandoned applications for a holistic risk management program.
7 new "Spectre Like" attacks using transient execution
https://ift.tt/2FmvSwB
Submitted November 15, 2018 at 07:59PM by alnarra_1
via reddit https://ift.tt/2PZBO2V
https://ift.tt/2FmvSwB
Submitted November 15, 2018 at 07:59PM by alnarra_1
via reddit https://ift.tt/2PZBO2V
reddit
r/netsec - 7 new "Spectre Like" attacks using transient execution
0 votes and 1 comment so far on Reddit
Fun analysis of how the “Nemucod” ransomware works by preforming a security assessment on it.
https://ift.tt/2K567zH
Submitted November 15, 2018 at 10:51PM by goopcat
via reddit https://ift.tt/2K6Ai9Q
https://ift.tt/2K567zH
Submitted November 15, 2018 at 10:51PM by goopcat
via reddit https://ift.tt/2K6Ai9Q
Independent Security Evaluators
Outsmarting Ransomware
Recovering Supposedly-Encrypted Files Without the Key
New variant in wp-gdpr-compliance vulnerability and fixing it with virtual patching
https://ift.tt/2Ps7Sgp
Submitted November 15, 2018 at 10:37PM by csalazars
via reddit https://ift.tt/2QFrx94
https://ift.tt/2Ps7Sgp
Submitted November 15, 2018 at 10:37PM by csalazars
via reddit https://ift.tt/2QFrx94
Medium
New variant in wp-gdpr-compliance vulnerability and fixing it with virtual patching
On Tuesday, I wrote about a serialization vulnerability fixed in the last version of wp-gdpr-compliance plugin.
Bettercap Using in Penetration Tests
https://ift.tt/2KaSGOZ
Submitted November 15, 2018 at 11:55PM by mstfknn
via reddit https://ift.tt/2QJh9gD
https://ift.tt/2KaSGOZ
Submitted November 15, 2018 at 11:55PM by mstfknn
via reddit https://ift.tt/2QJh9gD
PRISMA CSI
Bettercap Using in Penetration Tests • PRISMA CSI
Bettercap is a man-in-the-middle (MITM) attack tool developed to for users who are likely to be penetration testers to test and improve the security of networks or some devices connected to these networks.
A Tale of Three CVEs -- Multiple vulnerabilities in the SUSE linux Subnoscription Management Tool leads to an interesting case of RCE
https://ift.tt/2B9MdAA
Submitted November 15, 2018 at 11:44PM by ebx
via reddit https://ift.tt/2K570YX
https://ift.tt/2B9MdAA
Submitted November 15, 2018 at 11:44PM by ebx
via reddit https://ift.tt/2K570YX
netsequitur
~/netsequitur/research/reports/SUSE
I discovered multiple vulnerabilities in the RegistrationSharing module of the Subnoscription Management Tool provided by SUSE for enterprise customers that leads to unauthenticated RCE
A shellcoding tutorial I wrote.
https://ift.tt/2qQOZ7T
Submitted November 16, 2018 at 12:26AM by RayofLight-z
via reddit https://ift.tt/2OLJBwx
https://ift.tt/2qQOZ7T
Submitted November 16, 2018 at 12:26AM by RayofLight-z
via reddit https://ift.tt/2OLJBwx
wolfshirtz
Basic shellcoding for linux on x86
Beginning Writing shellcode is an excellent way to learn more about assembly language and how a program communicates with the underlying OS. Put simply shellcode is code that is injected into a running program to make it do something it was not made to do.…
ADBHoney - Low interaction honeypot designed for Android Debug Bridge over TCP/IP
https://ift.tt/2DoQW31
Submitted November 16, 2018 at 03:18PM by CosmoTheParrot
via reddit https://ift.tt/2qOolg1
https://ift.tt/2DoQW31
Submitted November 16, 2018 at 03:18PM by CosmoTheParrot
via reddit https://ift.tt/2qOolg1
GitHub
huuck/ADBHoney
Low interaction honeypot designed for Android Debug Bridge over TCP/IP - huuck/ADBHoney
Hacking Connected Home Alarm Systems – The Expensive [part 2]
https://ift.tt/2K5CCOa
Submitted November 16, 2018 at 03:46PM by daanraman
via reddit https://ift.tt/2TbXbwJ
https://ift.tt/2K5CCOa
Submitted November 16, 2018 at 03:46PM by daanraman
via reddit https://ift.tt/2TbXbwJ
NVISO Labs
Hacking Connected Home Alarm Systems – The Expensive [part 2]
TL;DR: We were wondering whether price affects the security of IoT appliances. So we verified the security of two differently priced connected home alarm systems. Both IoT alarms are marketed as an…