The 9 Lives of Bleichenbacher's CAT: New Cache ATtacks on TLS Implementations
https://ift.tt/2zCaZbL
Submitted December 01, 2018 at 06:24PM by digicat
via reddit https://ift.tt/2KP8l6U
https://ift.tt/2zCaZbL
Submitted December 01, 2018 at 06:24PM by digicat
via reddit https://ift.tt/2KP8l6U
Using google translator as a proxy to a reverse shell.
https://ift.tt/2Pg1BPM
Submitted December 02, 2018 at 05:39AM by mthbernardes
via reddit https://ift.tt/2zAwoSG
https://ift.tt/2Pg1BPM
Submitted December 02, 2018 at 05:39AM by mthbernardes
via reddit https://ift.tt/2zAwoSG
GitHub
mthbernardes/GTRS
GTRS - Google Translator Reverse Shell. Contribute to mthbernardes/GTRS development by creating an account on GitHub.
Burp Extension: Virtual Host Payload Generator
https://ift.tt/2QuUebY
Submitted December 02, 2018 at 11:31AM by payloadartist
via reddit https://ift.tt/2BJNs9Z
https://ift.tt/2QuUebY
Submitted December 02, 2018 at 11:31AM by payloadartist
via reddit https://ift.tt/2BJNs9Z
GitHub
righettod/virtualhost-payload-generator
BURP extension providing a set of values for the HTTP request "Host" header for the "BURP Intruder" in order to abuse virtual host resolution. - righettod/virtualhost-payload-ge...
Extending Fuzzing with Burp by Fast
https://ift.tt/2EbaTf9
Submitted December 02, 2018 at 01:22PM by payloadartist
via reddit https://ift.tt/2zFb2mS
https://ift.tt/2EbaTf9
Submitted December 02, 2018 at 01:22PM by payloadartist
via reddit https://ift.tt/2zFb2mS
Wallarm
Extending fuzzing with Burp by FAST
I love Burp Suite, like really. It’s the most convenient tool to visualize what’s happening with apps, how requests look like and to test…
$9400 bounty for XS-Searching Google’s bug tracker to find vulnerable source code
https://ift.tt/2ORtGwL
Submitted December 02, 2018 at 09:24PM by s14ve
via reddit https://ift.tt/2PgvwaG
https://ift.tt/2ORtGwL
Submitted December 02, 2018 at 09:24PM by s14ve
via reddit https://ift.tt/2PgvwaG
Medium
XS-Searching Google’s bug tracker to find out vulnerable source code
Or how side-channel timing attacks aren’t that impractical
The PewDiePie printer hack
https://ift.tt/2FUrPrE
Submitted December 02, 2018 at 08:45PM by yesnoornext
via reddit https://ift.tt/2AG4C6Q
https://ift.tt/2FUrPrE
Submitted December 02, 2018 at 08:45PM by yesnoornext
via reddit https://ift.tt/2AG4C6Q
threader.app
A thread written by @HackerGiraffe
Here is how the entire #pewdiepie printer hack went down:
1. I was bored after playing Destiny 2 for a continous 4 hours, and decided I wanted to hack something. So I thought of any vulnerable protocols I could find on shodan
(1/)
1. I was bored after playing Destiny 2 for a continous 4 hours, and decided I wanted to hack something. So I thought of any vulnerable protocols I could find on shodan
(1/)
IDN Homograph Attack on Facebook Messenger and Whatsapp
https://ift.tt/2P4VZIi
Submitted December 03, 2018 at 08:03AM by payloadartist
via reddit https://ift.tt/2zDmyiA
https://ift.tt/2P4VZIi
Submitted December 03, 2018 at 08:03AM by payloadartist
via reddit https://ift.tt/2zDmyiA
Medium
Homograph attack on Facebook Messenger and WhatsApp
Hello,
Top Five Ways The Red Team breached the External Perimeter
https://ift.tt/2pBRVoT
Submitted December 03, 2018 at 07:54AM by payloadartist
via reddit https://ift.tt/2rjm2lv
https://ift.tt/2pBRVoT
Submitted December 03, 2018 at 07:54AM by payloadartist
via reddit https://ift.tt/2rjm2lv
Medium
Top Five Ways the Red Team breached the External Perimeter
I have been performing “red team” breach assessments for many years. Often the goal is penetrating an external network, and gaining access…
Intro to NFC Payment Relay Attacks
https://ift.tt/2Rr9x2z
Submitted December 03, 2018 at 01:22PM by digicat
via reddit https://ift.tt/2FSAMld
https://ift.tt/2Rr9x2z
Submitted December 03, 2018 at 01:22PM by digicat
via reddit https://ift.tt/2FSAMld
Salvador Mendoza
Intro to NFC Payment Relay Attacks
DisclaimerThis is a simple intro to relay attacks using NFC payment data. I will add different types of relays during next year.IntroA NFC payment relay is an attack that could be described as extr…
Abuse MITM possible regardless of HTTPS
https://ift.tt/2TYhT3y
Submitted December 03, 2018 at 01:21PM by digicat
via reddit https://ift.tt/2rkfOS9
https://ift.tt/2TYhT3y
Submitted December 03, 2018 at 01:21PM by digicat
via reddit https://ift.tt/2rkfOS9
Detectify Labs
Abuse MITM possible regardless of HTTPS
Almost ten years ago Firesheep made the news. Security people had known for years the danger of public WiFi-networks, but it was not until someone made a user-friendly Firefox extension out of the idea until it really got people’s attention. Since then a…
Jailbreaks Demystified
https://ift.tt/2ytRkcH
Submitted December 03, 2018 at 04:24PM by payloadartist
via reddit https://ift.tt/2Rv4uOR
https://ift.tt/2ytRkcH
Submitted December 03, 2018 at 04:24PM by payloadartist
via reddit https://ift.tt/2Rv4uOR
geosn0w.github.io
Jailbreaks Demystified
The Jailbreaking process has long been a mysterious process where the iOS system suddenly gets unlocked out of Apple’s shackles after running an application for a few seconds. For a very long time, exactly what happened during the runtime of that application…
Remotely Hijacking Zoom Clients
https://ift.tt/2KPQj4h
Submitted December 03, 2018 at 07:13PM by chicksdigthelongrun
via reddit https://ift.tt/2rhYJIF
https://ift.tt/2KPQj4h
Submitted December 03, 2018 at 07:13PM by chicksdigthelongrun
via reddit https://ift.tt/2rhYJIF
Medium
Remotely Hijacking Zoom Clients
Hello Everyone,
PhpSpreadsheet library Versions<=1.5.0 - XXE injection (CVE-2018-19277)
https://ift.tt/2SsOVr4
Submitted December 04, 2018 at 12:40AM by acidwinter
via reddit https://ift.tt/2AOVsoH
https://ift.tt/2SsOVr4
Submitted December 04, 2018 at 12:40AM by acidwinter
via reddit https://ift.tt/2AOVsoH
Bishop Fox
PhpSpreadsheet Versions
PhpSpreadsheet is a library written in pure PHP that provides a set of classes allowing users to read from and write to different spreadsheet file formats, such as Excel and LibreOffice Calc.
Kubernetes privilege escalation, its patch day!
https://ift.tt/2riwmdi
Submitted December 04, 2018 at 04:06AM by CMDR_Shazbot
via reddit https://ift.tt/2zEDdCm
https://ift.tt/2riwmdi
Submitted December 04, 2018 at 04:06AM by CMDR_Shazbot
via reddit https://ift.tt/2zEDdCm
Google
Google Groups
Google Groups allows you to create and participate in online forums and email-based groups with a rich experience for community conversations.
Quora users' data compromised
https://ift.tt/2QBLwZq
Submitted December 04, 2018 at 06:52AM by modelop
via reddit https://ift.tt/2SrEkMR
https://ift.tt/2QBLwZq
Submitted December 04, 2018 at 06:52AM by modelop
via reddit https://ift.tt/2SrEkMR
Quora Help Center
Quora Security Update - FAQ
What happened?
We recently became aware that some user data was compromised due to unauthorized access to our systems by a malicious third party. We have engaged leading digital forensic and securi...
We recently became aware that some user data was compromised due to unauthorized access to our systems by a malicious third party. We have engaged leading digital forensic and securi...
Undefined Behavior Is Really Undefined
https://ift.tt/2re74Nq
Submitted December 04, 2018 at 06:47AM by davidw_-
via reddit https://ift.tt/2EeLZeg
https://ift.tt/2re74Nq
Submitted December 04, 2018 at 06:47AM by davidw_-
via reddit https://ift.tt/2EeLZeg
cryptoservices.github.io
Undefined Behavior Is Really Undefined
Cryptography Services is a dedicated team of consultants from iSEC Partners, Matasano, Intrepidus Group, and NCC Group focused on cryptographic security assessments, protocol and design reviews, and tracking impactful developments in the space of academia…
Unlimited Google Drive Storage by splitting binary files into base64
https://ift.tt/2MmHjnf
Submitted December 04, 2018 at 07:31AM by getsobah
via reddit https://ift.tt/2KPKbsE
https://ift.tt/2MmHjnf
Submitted December 04, 2018 at 07:31AM by getsobah
via reddit https://ift.tt/2KPKbsE
GitHub
stewartmcgown/uds
Unlimited Drive Storage by splitting binary files into base64 - stewartmcgown/uds
TR Modsecurity with Web Application Security Installing, Usage and Rules
https://ift.tt/2EevTS9
Submitted December 04, 2018 at 05:50PM by berkdusunurx
via reddit https://ift.tt/2ri80jQ
https://ift.tt/2EevTS9
Submitted December 04, 2018 at 05:50PM by berkdusunurx
via reddit https://ift.tt/2ri80jQ
www.berkdusunur.net
ModSecurity ile Web Uygulama Güvenliği - Kurulum, Kullanım ve Kurallar
Herkese Selamlar, Bu yazı açık kaynak bir güvenlik duvarının kurulum, kullanım ve kuralları hakkında olacak. Mod Security WAF Web...
No Sql Injection Experiment Guide part-1.
https://ift.tt/2Sre3y7
Submitted December 04, 2018 at 05:27PM by beyonderdabas
via reddit https://ift.tt/2EcWhf0
https://ift.tt/2Sre3y7
Submitted December 04, 2018 at 05:27PM by beyonderdabas
via reddit https://ift.tt/2EcWhf0
Mohit Dabas's Blog
No Sql Injection Experiment Guide part-1.
So I started some little experiments on MongoDB to find out how can I execute few my own crafted queries in MongoDB query statements. It is not a how to do a manual to do NoSQL injection instead wh…
Hacking with a Heads Up Display
https://ift.tt/2Q9lHAw
Submitted December 04, 2018 at 07:21PM by psiinon
via reddit https://ift.tt/2E1Ku2r
https://ift.tt/2Q9lHAw
Submitted December 04, 2018 at 07:21PM by psiinon
via reddit https://ift.tt/2E1Ku2r
Segment
Hacking with a Heads Up Display
Kickstart your code obfuscation skills: obfuscation 10**2+(2*a+3)%2
https://ift.tt/2PlhF33
Submitted December 04, 2018 at 08:22PM by mabote
via reddit https://ift.tt/2zGagGi
https://ift.tt/2PlhF33
Submitted December 04, 2018 at 08:22PM by mabote
via reddit https://ift.tt/2zGagGi