Security Checklist
http://bit.ly/2Rrgkxw
Submitted January 15, 2019 at 08:16PM by PRIVACYx05i4shUl
via reddit http://bit.ly/2VTuuWu
http://bit.ly/2Rrgkxw
Submitted January 15, 2019 at 08:16PM by PRIVACYx05i4shUl
via reddit http://bit.ly/2VTuuWu
Security Checklist
A checklist for staying safe on the internet
SANS Christmas Challenge 2018: Write-ups thread
Hi all! I thought that instead of everyone creating a post to submit their write-up for the 2018 SANS Christmas Challenge, we could create a thread where everyone could post their write-up in the comments.Hope this respects this subreddit's post guidelines. I look forward to reading other write-ups!
Submitted January 15, 2019 at 02:08PM by the-useless-one
via reddit http://bit.ly/2Dc1YYM
Hi all! I thought that instead of everyone creating a post to submit their write-up for the 2018 SANS Christmas Challenge, we could create a thread where everyone could post their write-up in the comments.Hope this respects this subreddit's post guidelines. I look forward to reading other write-ups!
Submitted January 15, 2019 at 02:08PM by the-useless-one
via reddit http://bit.ly/2Dc1YYM
reddit
r/netsec - SANS Christmas Challenge 2018: Write-ups thread
3 votes and 1 comment so far on Reddit
Thirty-five-year-old vulnerability found in SCP
http://bit.ly/2QLstbh
Submitted January 15, 2019 at 10:23PM by turtleflax
via reddit http://bit.ly/2AOV8XU
http://bit.ly/2QLstbh
Submitted January 15, 2019 at 10:23PM by turtleflax
via reddit http://bit.ly/2AOV8XU
reddit
r/netsec - Thirty-five-year-old vulnerability found in SCP
8 votes and 0 comments so far on Reddit
Ransomware Incorporates Paypal Phishing
http://bit.ly/2DccKhW
Submitted January 15, 2019 at 11:50PM by Fantastic_Fix
via reddit http://bit.ly/2TVlsGZ
http://bit.ly/2DccKhW
Submitted January 15, 2019 at 11:50PM by Fantastic_Fix
via reddit http://bit.ly/2TVlsGZ
InfoSec-IT
Ransomware Incorporates Paypal Phishing | InfoSec-IT
Ransomware is known to encrypt all the files on your device, however this variant also attempts to steal your PayPal credentials!
DerbyCon has shut down due to outrage mob demands.
http://bit.ly/2De1lOz
Submitted January 16, 2019 at 01:12AM by redis_help
via reddit http://bit.ly/2FApUXu
http://bit.ly/2De1lOz
Submitted January 16, 2019 at 01:12AM by redis_help
via reddit http://bit.ly/2FApUXu
Computer Business Review
DerbyCon Shut Down Blamed on Attendee Behaviour
DerbyCon shut down blamed on fractious attendees, the need for behaviour-policing and verbal abuse. The Kentucky-based event, a "baby DEFCON" will...
JA3/S TLS Client+Server Fingerprinting makes detecting pen testers easy. Really easy.
https://sforce.co/2FzxwcQ
Submitted January 16, 2019 at 01:44AM by darkfiber-
via reddit http://bit.ly/2sukWEc
https://sforce.co/2FzxwcQ
Submitted January 16, 2019 at 01:44AM by darkfiber-
via reddit http://bit.ly/2sukWEc
Salesforce Engineering
TLS Fingerprinting with JA3 and JA3S
Utilize JA3 with JA3S as a method to fingerprint the TLS negotiation between client and server
Silverpeas 5.15 To 6.0.2: Path Traversal
http://bit.ly/2QNPOsZ
Submitted January 16, 2019 at 05:01AM by Bishopfox
via reddit http://bit.ly/2DcLtf2
http://bit.ly/2QNPOsZ
Submitted January 16, 2019 at 05:01AM by Bishopfox
via reddit http://bit.ly/2DcLtf2
Bishop Fox
Silverpeas 5.15 To 6.0.2: Path Traversal - Bishop Fox
A Bishop Fox researcher discovered a critical vulnerability in the popular Silverpeas application, a popular open source WEB platform that services multiple high-profile French organizations.
Windows Userland Application Attack Surface Enumeration
http://bit.ly/2suuM8J
Submitted January 16, 2019 at 03:01AM by marketingversprite
via reddit http://bit.ly/2ComHqO
http://bit.ly/2suuM8J
Submitted January 16, 2019 at 03:01AM by marketingversprite
via reddit http://bit.ly/2ComHqO
VerSprite | Integrated Security Services and Consulting
Windows Userland Application Attack Surface Enumeration | VerSprite
This blog provides information on how to enumerate the attack surface of userland applications that are deployed on the Windows operating system.
Giggity - Scrapes github for openly available information about an organization or user OSINT
http://bit.ly/2DbD1gr
Submitted January 16, 2019 at 07:05AM by amusciano
via reddit http://bit.ly/2TTSfw0
http://bit.ly/2DbD1gr
Submitted January 16, 2019 at 07:05AM by amusciano
via reddit http://bit.ly/2TTSfw0
GitHub
needmorecowbell/giggity
Wraps github api for openly available information about an organization, user, or repo - needmorecowbell/giggity
DerbyCon 9.0 – Every Beginning Has an End
http://bit.ly/2FuUamN
Submitted January 16, 2019 at 02:16PM by Reetpeteet
via reddit http://bit.ly/2AMKmRW
http://bit.ly/2FuUamN
Submitted January 16, 2019 at 02:16PM by Reetpeteet
via reddit http://bit.ly/2AMKmRW
reddit
r/netsec - DerbyCon 9.0 – Every Beginning Has an End
1 vote and 1 comment so far on Reddit
Multiple vulnerabilities in ntpsec 1.1.2 and earlier (proof-of-concept exploits available)
http://bit.ly/2Hd6dHW
Submitted January 16, 2019 at 02:56PM by magnusstubman
via reddit http://bit.ly/2TZmJwL
http://bit.ly/2Hd6dHW
Submitted January 16, 2019 at 02:56PM by magnusstubman
via reddit http://bit.ly/2TZmJwL
reddit
r/netsec - Multiple vulnerabilities in ntpsec 1.1.2 and earlier (proof-of-concept exploits available)
1 vote and 0 comments so far on Reddit
Researcher shows how popular app ES File Explorer exposes Android device data
http://bit.ly/2VRfV61
Submitted January 16, 2019 at 04:18PM by NewCaramel
via reddit http://bit.ly/2FBAe1s
http://bit.ly/2VRfV61
Submitted January 16, 2019 at 04:18PM by NewCaramel
via reddit http://bit.ly/2FBAe1s
threader.app
A thread written by @fs0c131y
With more than 100,000,000 downloads ES File Explorer is one of the most famous #Android file manager.The surprise is: if you opened the app at least once, anyone connected to the same local network can remotely get a file from your phone https://t.co/Uv2ttQpUcN
ES File Explorer Open Port Vulnerability
http://bit.ly/2FCwL2B
Submitted January 16, 2019 at 04:35PM by 0v3rl04d
via reddit http://bit.ly/2QUxoXs
http://bit.ly/2FCwL2B
Submitted January 16, 2019 at 04:35PM by 0v3rl04d
via reddit http://bit.ly/2QUxoXs
GitHub
fs0c131y/ESFileExplorerOpenPortVuln
ES File Explorer Open Port Vulnerability. Contribute to fs0c131y/ESFileExplorerOpenPortVuln development by creating an account on GitHub.
Fake Movie File Infects PC to Steal Cryptocurrency, Poison Google Results
http://bit.ly/2SRmkvQ
Submitted January 16, 2019 at 05:41PM by ga-vu
via reddit http://bit.ly/2McYVmi
http://bit.ly/2SRmkvQ
Submitted January 16, 2019 at 05:41PM by ga-vu
via reddit http://bit.ly/2McYVmi
BleepingComputer
Fake Movie File Infects PC to Steal Cryptocurrency, Poison Google Results
A malicious Windows shortcut file posing as a movie via The Pirate Bay torrent tracker can trigger a chain of mischievous activities on your computer, like injecting content from the attacker into high-profile web sites such as Wikipedia, Google and Yandex Search or…
Fake Movie File Infects PC to Steal Cryptocurrency, Poison Google Results
http://bit.ly/2SRmkvQ
Submitted January 16, 2019 at 05:41PM by ga-vu
via reddit http://bit.ly/2McYVmi
http://bit.ly/2SRmkvQ
Submitted January 16, 2019 at 05:41PM by ga-vu
via reddit http://bit.ly/2McYVmi
BleepingComputer
Fake Movie File Infects PC to Steal Cryptocurrency, Poison Google Results
A malicious Windows shortcut file posing as a movie via The Pirate Bay torrent tracker can trigger a chain of mischievous activities on your computer, like injecting content from the attacker into high-profile web sites such as Wikipedia, Google and Yandex Search or…
Hacking Fortnite
http://bit.ly/2FwjHNd
Submitted January 16, 2019 at 05:31PM by albinowax
via reddit http://bit.ly/2HfJ0Vq
http://bit.ly/2FwjHNd
Submitted January 16, 2019 at 05:31PM by albinowax
via reddit http://bit.ly/2HfJ0Vq
Check Point Research
Hacking Fortnite - Check Point Research
Research by: Alon Boxiner, Eran Vaknin and Oded Vanunu, January 16th, 2018 Played in a virtual world, players of ‘Fortnite’, the massively popular game from game developer Epic Games, are tasked with testing their endurance as they battle for tools and weapons…
Hacking Jenkins Part 1 - Play with Dynamic Routing
http://bit.ly/2su9UyL
Submitted January 16, 2019 at 06:46PM by albinowax
via reddit http://bit.ly/2Dd3lGN
http://bit.ly/2su9UyL
Submitted January 16, 2019 at 06:46PM by albinowax
via reddit http://bit.ly/2Dd3lGN
Orange
Hacking Jenkins Part 1 - Play with Dynamic Routing
This is 🍊 speaking
Distribution of malicious JAR appended to MSI files signed by third parties
http://bit.ly/2DbsYb0
Submitted January 16, 2019 at 07:31PM by TheLantean
via reddit http://bit.ly/2FAaNgW
http://bit.ly/2DbsYb0
Submitted January 16, 2019 at 07:31PM by TheLantean
via reddit http://bit.ly/2FAaNgW
Virustotal
Distribution of malicious JAR appended to MSI files signed by third parties
Microsoft Windows keeps the Authenticode signature valid after appending any content to the end of Windows Installer (.MSI) files signed by ...
Virtuailor: An IDAPython plugin to automate and ease the reversing of C++ code.
http://bit.ly/2HomjOG
Submitted January 16, 2019 at 06:23PM by rvngr12
via reddit http://bit.ly/2VWsehj
http://bit.ly/2HomjOG
Submitted January 16, 2019 at 06:23PM by rvngr12
via reddit http://bit.ly/2VWsehj
GitHub
0xgalz/Virtuailor
IDAPython tool for creating automatic C++ virtual tables in IDA Pro - 0xgalz/Virtuailor
What We Found in the SANS Holiday Hack: A 0day in rssh
http://bit.ly/2VU2K4l
Submitted January 16, 2019 at 11:11PM by grigorescu
via reddit http://bit.ly/2MfyXyC
http://bit.ly/2VU2K4l
Submitted January 16, 2019 at 11:11PM by grigorescu
via reddit http://bit.ly/2MfyXyC
esnet-security.github.io
Command Execution Vulnerability in rssh with allowscp
ESnet Security’s github.io Site
Securely Connecting an Arduino MKR WiFi 1010 to AWS IoT Core
http://bit.ly/2swWpyi
Submitted January 16, 2019 at 11:02PM by gvarisco
via reddit http://bit.ly/2Fuxcgk
http://bit.ly/2swWpyi
Submitted January 16, 2019 at 11:02PM by gvarisco
via reddit http://bit.ly/2Fuxcgk
Arduino Project Hub
Securely connecting an Arduino MKR WiFi 1010 to AWS IoT Core
In this tutorial, you'll learn how to connect your Arduino MKR WiFi 1010 (or MKR 1000) board securely to AWS IoT Core.