Password strength estimation in nonwestern languages - iacr eprint
https://ift.tt/2QvI936
Submitted December 13, 2018 at 12:31AM by ahazred8vt
via reddit https://ift.tt/2C9vVs9
https://ift.tt/2QvI936
Submitted December 13, 2018 at 12:31AM by ahazred8vt
via reddit https://ift.tt/2C9vVs9
reddit
r/netsec - Password strength estimation in nonwestern languages - iacr eprint
2 votes and 0 comments so far on Reddit
Troubleshooting Obscure OpenSSH Failures
https://ift.tt/2RV6Kim
Submitted December 13, 2018 at 06:21AM by CameronNemo
via reddit https://ift.tt/2zTICG8
https://ift.tt/2RV6Kim
Submitted December 13, 2018 at 06:21AM by CameronNemo
via reddit https://ift.tt/2zTICG8
Pivotal Engineering Journal
Troubleshooting Obscure OpenSSH Failures
How an elusive CI (Continuous Integration) error led us to uncover a hidden man-in-the-middle ssh proxy.
Locality Sensitive Fuzzy Hashing (in Golang)
https://ift.tt/2PA9Nui
Submitted December 13, 2018 at 02:08PM by glaslos
via reddit https://ift.tt/2G9PN2i
https://ift.tt/2PA9Nui
Submitted December 13, 2018 at 02:08PM by glaslos
via reddit https://ift.tt/2G9PN2i
Medium
Locality Sensitive Fuzzy Hashing
Using hashes maximized for collision probability (in Golang)
Pentesting with InSecure Chrome
https://ift.tt/2C9FO9p
Submitted December 13, 2018 at 07:30PM by sastdast
via reddit https://ift.tt/2LdG0Hw
https://ift.tt/2C9FO9p
Submitted December 13, 2018 at 07:30PM by sastdast
via reddit https://ift.tt/2LdG0Hw
jabbari.io
InSecure Chrome
This site is design to share my work with programming enthusists like me. My main focus is on software development and security
Logitech Keyboard opens WebSocket server with no authentication - Google Project Zero
https://ift.tt/2BaMPoA
Submitted December 13, 2018 at 07:00PM by rcmaehl
via reddit https://ift.tt/2PBPzjS
https://ift.tt/2BaMPoA
Submitted December 13, 2018 at 07:00PM by rcmaehl
via reddit https://ift.tt/2PBPzjS
reddit
r/netsec - Logitech Keyboard opens WebSocket server with no authentication - Google Project Zero
34 votes and 10 comments so far on Reddit
Just Launched - Security Innovation Blockchain CTF V2
https://ift.tt/2rBQ2Je
Submitted December 13, 2018 at 09:04PM by mickayz
via reddit https://ift.tt/2Esywjf
https://ift.tt/2rBQ2Je
Submitted December 13, 2018 at 09:04PM by mickayz
via reddit https://ift.tt/2Esywjf
Securityinnovation
Just Launched - Security Innovation Blockchain CTF V.2
Since we launched the Security Innovation Blockchain CTF, we have seen the demand for educational resources in the field of smart contract security increase. SI has recently launched V2 of our Blockchain CTF. We also formed a partnership with ConsenSys Diligence…
Samsung Bug Allowed Full Takeover of User Accounts
https://ift.tt/2ryrAbZ
Submitted December 13, 2018 at 11:23PM by Fantastic_Fix
via reddit https://ift.tt/2UB3p9Y
https://ift.tt/2ryrAbZ
Submitted December 13, 2018 at 11:23PM by Fantastic_Fix
via reddit https://ift.tt/2UB3p9Y
InfoSec-IT
Samsung Bug Allowed Full Takeover of User Accounts | InfoSec-IT
Malicious users could have seized control over any Samsung account due to a recent vulnerability. By tricking users into a clicking on a malicious link.
Exploit | YARA Internals II: Bytecode
https://ift.tt/2QShSzp
Submitted December 13, 2018 at 10:23PM by bnbdr
via reddit https://ift.tt/2SMF7bo
https://ift.tt/2QShSzp
Submitted December 13, 2018 at 10:23PM by bnbdr
via reddit https://ift.tt/2SMF7bo
https://bnbdr.github.io/
YARA Internals II: Bytecode
and how it can still be used to run arbitrary code
IDORs (Insecure Direct Object Reference) over Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10 (CVE-2018–7690, CVE-2018–7691)
https://ift.tt/2El0RqJ
Submitted December 13, 2018 at 12:40AM by alt3kx
via reddit https://ift.tt/2Etx6oF
https://ift.tt/2El0RqJ
Submitted December 13, 2018 at 12:40AM by alt3kx
via reddit https://ift.tt/2Etx6oF
Medium
IDORs (Insecure Direct Object Reference) over Fortify Software Security Center (SSC) 17.10, 17.20 & 18.10 (CVE-2018–7690, CVE-2018–7691)
Hello everyone, we continue disclosure some CVEs/exploits (0days) with specific software/hardware products. Few months ago during my…
Hackers are Modern Witches
https://ift.tt/2A7JbfF
Submitted December 14, 2018 at 12:25PM by neverforgetdream
via reddit https://ift.tt/2Pxklup
https://ift.tt/2A7JbfF
Submitted December 14, 2018 at 12:25PM by neverforgetdream
via reddit https://ift.tt/2Pxklup
reddit
r/netsec - Hackers are Modern Witches
0 votes and 4 comments so far on Reddit
BSides Columbus 2019 (01Mar2019) CFP (and general registration) is open
https://ift.tt/2BgpguI
Submitted December 14, 2018 at 10:39AM by SnarkyMoo
via reddit https://ift.tt/2QtjPCW
https://ift.tt/2BgpguI
Submitted December 14, 2018 at 10:39AM by SnarkyMoo
via reddit https://ift.tt/2QtjPCW
reddit
r/netsec - BSides Columbus 2019 (01Mar2019) CFP (and general registration) is open
1 vote and 0 comments so far on Reddit
Exploiting XXE with local DTD files. Get output from your blind XXE.
https://ift.tt/2QUJwf2
Submitted December 14, 2018 at 03:06PM by kavmax
via reddit https://ift.tt/2UJzvk7
https://ift.tt/2QUJwf2
Submitted December 14, 2018 at 03:06PM by kavmax
via reddit https://ift.tt/2UJzvk7
Mohemiv
Exploiting XXE with local DTD files
This little technique can force your blind XXE to output anything you want!
Binder transactions in the bowels of the Linux Kernel
https://ift.tt/2CdFXZr
Submitted December 14, 2018 at 02:50PM by mabote
via reddit https://ift.tt/2Elz21v
https://ift.tt/2CdFXZr
Submitted December 14, 2018 at 02:50PM by mabote
via reddit https://ift.tt/2Elz21v
reddit
r/netsec - Binder transactions in the bowels of the Linux Kernel
3 votes and 1 comment so far on Reddit
How I got a $3k bug bounty from Twitter
https://ift.tt/2Gft3ht
Submitted December 14, 2018 at 05:58PM by edent
via reddit https://ift.tt/2ULjdXG
https://ift.tt/2Gft3ht
Submitted December 14, 2018 at 05:58PM by edent
via reddit https://ift.tt/2ULjdXG
Terence Eden's Blog
$3k Bug Bounty - Twitter's OAuth Mistakes
Imagine the scenario. You’re trying out some cool new Twitter app. It asks you to sign in via OAuth as per usual. You look through the permissions – phew – it doesn’t want t…
Bypassing Firebase client-side authorization to create custom app.goo.gl subdomains
https://ift.tt/2PVOMv0
Submitted December 14, 2018 at 06:48PM by ThomasCZ
via reddit https://ift.tt/2zXErcq
https://ift.tt/2PVOMv0
Submitted December 14, 2018 at 06:48PM by ThomasCZ
via reddit https://ift.tt/2zXErcq
Thomas Orlita's blog
Bypassing Firebase authorization to create custom goo.gl subdomains - Thomas Orlita's blog
Since the support of goo.gl has already ended, I’ve been looking for ways to shorten URLs using Google services. Some time ago I’ve found a bug that allowed me to shorten links using Google’s official g.co shortener. This time I took a look at Firebase Dynamic…
Cylance Narrows The Cybersecurity Skills Gap With Virtual CISO.
https://ift.tt/2UHZ9Wd
Submitted December 14, 2018 at 07:13PM by xaocuc
via reddit https://ift.tt/2rzYVDg
https://ift.tt/2UHZ9Wd
Submitted December 14, 2018 at 07:13PM by xaocuc
via reddit https://ift.tt/2rzYVDg
IT Security Guru
Cylance Narrows The Cybersecurity Skills Gap With Virtual CISO. - IT Security Guru
Cylance Inc., the leading provider of AI-driven, prevention-first security solutions, today announced the availability of its virtual chief information sec
NoNameCon 2019 Call for Talks and Workshops
https://ift.tt/2Lj2jLU
Submitted December 14, 2018 at 07:30PM by xaocuc
via reddit https://ift.tt/2LnYpS9
https://ift.tt/2Lj2jLU
Submitted December 14, 2018 at 07:30PM by xaocuc
via reddit https://ift.tt/2LnYpS9
cfp.nonamecon.org
NoNameCon 2019
Schedule, talks and talk submissions for NoNameCon 2019
phpMyAdmin (AllowArbitraryServer) Arbitrary File Read Vulnerability
https://ift.tt/2Cd91jr
Submitted December 14, 2018 at 10:46PM by Ambulong
via reddit https://ift.tt/2Ljov8G
https://ift.tt/2Cd91jr
Submitted December 14, 2018 at 10:46PM by Ambulong
via reddit https://ift.tt/2Ljov8G
Vulnspy
phpMyAdmin (AllowArbitraryServer) Arbitrary File Read Vulnerability | VULNSPY
Many posts have pointed out that a malicious MySQL server can use the LOAD DATA LOCAL command to read arbitrary files from MYSQL clients. According to this article (chinese) phpMyAdmin开启远程登陆导致本地文件读取, We can read arbitrary file on phpMyAdmin server if $cf…
SQLite and Chromium RCE
https://ift.tt/2A29rYB
Submitted December 15, 2018 at 04:07AM by 3553x
via reddit https://ift.tt/2GgjJKf
https://ift.tt/2A29rYB
Submitted December 15, 2018 at 04:07AM by 3553x
via reddit https://ift.tt/2GgjJKf
Tencent
Magellan - Tencent Blade Team
Magellan is a remote code execution vulnerability that exists in SQLite. As a well-known database, SQLite is widely used in all modern mainstream operating systems and software, so this vulnerability has a wide range of influence. After testing Chromium was…
Magellan - SQLite Remote Code Execution Vulnerability
https://ift.tt/2A29rYB
Submitted December 15, 2018 at 05:26AM by Pandry
via reddit https://ift.tt/2A0Goom
https://ift.tt/2A29rYB
Submitted December 15, 2018 at 05:26AM by Pandry
via reddit https://ift.tt/2A0Goom
Tencent
Magellan - Tencent Blade Team
Magellan is a remote code execution vulnerability that exists in SQLite. As a well-known database, SQLite is widely used in all modern mainstream operating systems and software, so this vulnerability has a wide range of influence. After testing Chromium was…
Hosting malicious payloads on Youtube
https://ift.tt/2CeNhUI
Submitted December 15, 2018 at 06:32AM by mthbernardes
via reddit https://ift.tt/2Qzqdss
https://ift.tt/2CeNhUI
Submitted December 15, 2018 at 06:32AM by mthbernardes
via reddit https://ift.tt/2Qzqdss
mthbernardes.github.io
Gambler - Hacking and other stuffs
Posts about hacking, coding and other stuffs