WordPress Privilege Escalation through Post Types
https://ift.tt/2CjoSNO
Submitted December 18, 2018 at 01:26AM by zit-hb
via reddit https://ift.tt/2A4IqE2
https://ift.tt/2CjoSNO
Submitted December 18, 2018 at 01:26AM by zit-hb
via reddit https://ift.tt/2A4IqE2
reddit
r/netsec - WordPress Privilege Escalation through Post Types
7 votes and 0 comments so far on Reddit
SharpPack: The Insider Threat Toolkit
https://ift.tt/2LjZU3s
Submitted December 18, 2018 at 04:21AM by dmchell
via reddit https://ift.tt/2PMkjPz
https://ift.tt/2LjZU3s
Submitted December 18, 2018 at 04:21AM by dmchell
via reddit https://ift.tt/2PMkjPz
www.mdsec.co.uk
SharpPack: The Insider Threat Toolkit – MDSec
Interactive Beginner's Guide to ROP
https://ift.tt/2EyuK7Z
Submitted December 18, 2018 at 01:12PM by pgombos
via reddit https://ift.tt/2GmAHGH
https://ift.tt/2EyuK7Z
Submitted December 18, 2018 at 01:12PM by pgombos
via reddit https://ift.tt/2GmAHGH
reddit
r/netsec - Interactive Beginner's Guide to ROP
7 votes and 3 comments so far on Reddit
Guide to finding and exploiting hidden web directories and files
https://ift.tt/2BAdGe7
Submitted December 18, 2018 at 02:53PM by albinowax
via reddit https://ift.tt/2rJpAO6
https://ift.tt/2BAdGe7
Submitted December 18, 2018 at 02:53PM by albinowax
via reddit https://ift.tt/2rJpAO6
Medium
Hidden directories and files as a source of sensitive information about web application
Hidden directories and files left accidentally on the web server might be a very valuable source of sensitive information. There can be a…
Reading ASP secrets for $17,000
https://ift.tt/2QC8EYz
Submitted December 18, 2018 at 02:48PM by albinowax
via reddit https://ift.tt/2LsiWoA
https://ift.tt/2QC8EYz
Submitted December 18, 2018 at 02:48PM by albinowax
via reddit https://ift.tt/2LsiWoA
samcurry.net
Reading ASP secrets for $17,000 | Sam Curry
One of the more common vulnerabilities on ASP.NET applications is local file disclosure. If you've never developed or worked with this technology, exploiting LFD can be confusing and often unfruitful. In the following write up I describe approaching an application…
Hackthebox - Waldo Walkthrough
https://ift.tt/2SXcgRU
Submitted December 18, 2018 at 06:48PM by p4wsec
via reddit https://ift.tt/2LoeKWN
https://ift.tt/2SXcgRU
Submitted December 18, 2018 at 06:48PM by p4wsec
via reddit https://ift.tt/2LoeKWN
GitHub
p4wsec/hackthebox
Contribute to p4wsec/hackthebox development by creating an account on GitHub.
Everything you should know about certificates and PKI but are too afraid to ask
https://ift.tt/2Bdcjl7
Submitted December 18, 2018 at 06:31PM by mariuz
via reddit https://ift.tt/2QEqQB1
https://ift.tt/2Bdcjl7
Submitted December 18, 2018 at 06:31PM by mariuz
via reddit https://ift.tt/2QEqQB1
Smallstep
Everything you should know about certificates and PKI but are too afraid to ask
Everything you should know about certificates and public key infrastructure (PKI) but are too afraid to ask.
krf: A kernelspace randomized fault injector
https://ift.tt/2S8SJOa
Submitted December 18, 2018 at 06:58PM by yossarian_flew_away
via reddit https://ift.tt/2QDTulT
https://ift.tt/2S8SJOa
Submitted December 18, 2018 at 06:58PM by yossarian_flew_away
via reddit https://ift.tt/2QDTulT
GitHub
trailofbits/krf
A kernelspace syscall interceptor and randomized faulter - trailofbits/krf
Multiple vulnerabilities in AspNetSaml
https://ift.tt/2QDVpH8
Submitted December 18, 2018 at 11:25PM by holyvier
via reddit https://ift.tt/2GsCdr8
https://ift.tt/2QDVpH8
Submitted December 18, 2018 at 11:25PM by holyvier
via reddit https://ift.tt/2GsCdr8
etticblog
Multiple vulnerabilities in AspNetSaml
Introduction
The 2018 SANS holiday hack challenge - KringleCon
https://ift.tt/2Lrrj3q
Submitted December 18, 2018 at 11:54PM by dr_netsec
via reddit https://ift.tt/2ECEVbU
https://ift.tt/2Lrrj3q
Submitted December 18, 2018 at 11:54PM by dr_netsec
via reddit https://ift.tt/2ECEVbU
Kringlecon
KringleCon 2018 – Register Today!
KringleCon is a virtual conference for security-minded people and hackers from around the world, hosted by Santa and his team at the North Pole mid-December, 2018. Santa's goal for KringleCon is to help improve the state of cyber security world-wide, protecting…
6.8 Million Users Private Photos Exposed in Facebook Flaw
https://ift.tt/2EsbUi6
Submitted December 19, 2018 at 12:40AM by Fantastic_Fix
via reddit https://ift.tt/2A2ZoCM
https://ift.tt/2EsbUi6
Submitted December 19, 2018 at 12:40AM by Fantastic_Fix
via reddit https://ift.tt/2A2ZoCM
InfoSec-IT
6.8 Million Users Private Photos Exposed in Facebook Flaw | InfoSec-IT
Facebook is having to yet again apologise for another flaw which affects millions of their users - this time exposing unpublished, private photos...
URSNIF, EMOTET, DRIDEX and BitPaymer Gangs Linked by a Similar Loader
https://ift.tt/2BpZRPg
Submitted December 19, 2018 at 01:41AM by EvanConover
via reddit https://ift.tt/2Sb3C24
https://ift.tt/2BpZRPg
Submitted December 19, 2018 at 01:41AM by EvanConover
via reddit https://ift.tt/2Sb3C24
Trendmicro
URSNIF, EMOTET, DRIDEX and BitPaymer Gangs Linked by a Similar Loader - TrendLabs Security Intelligence Blog
We analyzed samples of EMOTET, URSNIF, DRIDEX and BitPaymer and found similar payload loaders and internal data structures, possibly implying that these different groups are familiar with and are working closely together.
Happy 16shop hunting
https://ift.tt/2PM5Umc
Submitted December 19, 2018 at 07:41AM by ninoseki
via reddit https://ift.tt/2A5NDex
https://ift.tt/2PM5Umc
Submitted December 19, 2018 at 07:41AM by ninoseki
via reddit https://ift.tt/2A5NDex
HackMD
Happy 16shop hunting - HackMD
# Happy 16shop hunting ## What is 16shop? 16shop is an infamous phishing kit targets Apple users.
Pure In-Memory ShellCode Injection In Linux Userland
https://ift.tt/2Gq3sCJ
Submitted December 19, 2018 at 08:06AM by 0xInfection
via reddit https://ift.tt/2QH5MtG
https://ift.tt/2Gq3sCJ
Submitted December 19, 2018 at 08:06AM by 0xInfection
via reddit https://ift.tt/2QH5MtG
Windows Sandbox
https://ift.tt/2EvJZxO
Submitted December 19, 2018 at 08:22AM by dudeimawizard
via reddit https://ift.tt/2A5e1p7
https://ift.tt/2EvJZxO
Submitted December 19, 2018 at 08:22AM by dudeimawizard
via reddit https://ift.tt/2A5e1p7
TECHCOMMUNITY.MICROSOFT.COM
Windows Sandbox
Windows Sandbox is a new lightweight desktop environment tailored for safely running applications in isolation. How many times have you downloaded an executable file, but were afraid to run it? Have you ever been in a situation which required a clean installation…
Intel Visualization of Internal Signals Architecture (VISA): Through the Rabbit Hole
https://ift.tt/2S9Nqy3
Submitted December 19, 2018 at 11:54AM by osztyapenko
via reddit https://ift.tt/2GuH0In
https://ift.tt/2S9Nqy3
Submitted December 19, 2018 at 11:54AM by osztyapenko
via reddit https://ift.tt/2GuH0In
Blackhat
Black Hat Asia 2019
PyRDP: a new open-source RDP MITM that records screens and collects files, credentials, and clipboard data. Bonus: Office Christmas Prank
https://ift.tt/2POfIw0
Submitted December 19, 2018 at 10:34PM by obilodeau
via reddit https://ift.tt/2QDnoGE
https://ift.tt/2POfIw0
Submitted December 19, 2018 at 10:34PM by obilodeau
via reddit https://ift.tt/2QDnoGE
GoSecure
RDP Man-in-the-Middle - Smile! You're on Camera - GoSecure
Discover our new RDP man-in-the-middle tool. It features clipboard and file stealing, as well as the ability to see connections live or after the fact.
Security Controls at DoD Facilities for Protecting Ballistic Missile Defense System - Technical Information
https://ift.tt/2A0JGrH
Submitted December 19, 2018 at 11:30PM by midael
via reddit https://ift.tt/2R0LFWP
https://ift.tt/2A0JGrH
Submitted December 19, 2018 at 11:30PM by midael
via reddit https://ift.tt/2R0LFWP
Details on Golang mutual TLS authentication vulnerability CVE-2018-16875
https://ift.tt/2ECGGWv
Submitted December 20, 2018 at 12:04AM by DSotnikov
via reddit https://ift.tt/2RbpBbO
https://ift.tt/2ECGGWv
Submitted December 20, 2018 at 12:04AM by DSotnikov
via reddit https://ift.tt/2RbpBbO
API Security News
Understanding Golang TLS mutual authentication DoS - CVE-2018-16875 - API Security News
Microservices written in Golang versions earlier than 1.10.6 and 1.11.3 using mutual TLS authentication are vulnerable to CPU denial of service (DoS) attack
Linux privilege escalation via trusted $PATH in keybase-redirector
https://ift.tt/2QE1cwe
Submitted December 19, 2018 at 11:48PM by d4nk1st
via reddit https://ift.tt/2GvvP26
https://ift.tt/2QE1cwe
Submitted December 19, 2018 at 11:48PM by d4nk1st
via reddit https://ift.tt/2GvvP26
HackerOne
Keybase disclosed on HackerOne: Linux privilege escalation via...
keybase-redirector is a setuid root binary. keybase-redirector calls the fusermount binary using a relative path and the application trusts the value of $PATH. This allows a local, unprivileged...
Binary Exploitation - Buffer Overflow Explained in Detail by 0xRick
https://ift.tt/2R6qylH
Submitted December 20, 2018 at 01:08AM by Ahm3d_H3sham
via reddit https://ift.tt/2GwpnrT
https://ift.tt/2R6qylH
Submitted December 20, 2018 at 01:08AM by Ahm3d_H3sham
via reddit https://ift.tt/2GwpnrT
0xRick Owned Root !
Binary Exploitation - Buffer Overflow Explained in Detail
Introduction So first of all I know that there are many tutorials published about buffer overflow and binary exploitation but I decided to write this article because most of these tutorials and articles don’t really talk about the basic fundmentals needed…