Windows Userland Application Attack Surface Enumeration
http://bit.ly/2suuM8J
Submitted January 16, 2019 at 03:01AM by marketingversprite
via reddit http://bit.ly/2ComHqO
http://bit.ly/2suuM8J
Submitted January 16, 2019 at 03:01AM by marketingversprite
via reddit http://bit.ly/2ComHqO
VerSprite | Integrated Security Services and Consulting
Windows Userland Application Attack Surface Enumeration | VerSprite
This blog provides information on how to enumerate the attack surface of userland applications that are deployed on the Windows operating system.
Giggity - Scrapes github for openly available information about an organization or user OSINT
http://bit.ly/2DbD1gr
Submitted January 16, 2019 at 07:05AM by amusciano
via reddit http://bit.ly/2TTSfw0
http://bit.ly/2DbD1gr
Submitted January 16, 2019 at 07:05AM by amusciano
via reddit http://bit.ly/2TTSfw0
GitHub
needmorecowbell/giggity
Wraps github api for openly available information about an organization, user, or repo - needmorecowbell/giggity
DerbyCon 9.0 – Every Beginning Has an End
http://bit.ly/2FuUamN
Submitted January 16, 2019 at 02:16PM by Reetpeteet
via reddit http://bit.ly/2AMKmRW
http://bit.ly/2FuUamN
Submitted January 16, 2019 at 02:16PM by Reetpeteet
via reddit http://bit.ly/2AMKmRW
reddit
r/netsec - DerbyCon 9.0 – Every Beginning Has an End
1 vote and 1 comment so far on Reddit
Multiple vulnerabilities in ntpsec 1.1.2 and earlier (proof-of-concept exploits available)
http://bit.ly/2Hd6dHW
Submitted January 16, 2019 at 02:56PM by magnusstubman
via reddit http://bit.ly/2TZmJwL
http://bit.ly/2Hd6dHW
Submitted January 16, 2019 at 02:56PM by magnusstubman
via reddit http://bit.ly/2TZmJwL
reddit
r/netsec - Multiple vulnerabilities in ntpsec 1.1.2 and earlier (proof-of-concept exploits available)
1 vote and 0 comments so far on Reddit
Researcher shows how popular app ES File Explorer exposes Android device data
http://bit.ly/2VRfV61
Submitted January 16, 2019 at 04:18PM by NewCaramel
via reddit http://bit.ly/2FBAe1s
http://bit.ly/2VRfV61
Submitted January 16, 2019 at 04:18PM by NewCaramel
via reddit http://bit.ly/2FBAe1s
threader.app
A thread written by @fs0c131y
With more than 100,000,000 downloads ES File Explorer is one of the most famous #Android file manager.The surprise is: if you opened the app at least once, anyone connected to the same local network can remotely get a file from your phone https://t.co/Uv2ttQpUcN
ES File Explorer Open Port Vulnerability
http://bit.ly/2FCwL2B
Submitted January 16, 2019 at 04:35PM by 0v3rl04d
via reddit http://bit.ly/2QUxoXs
http://bit.ly/2FCwL2B
Submitted January 16, 2019 at 04:35PM by 0v3rl04d
via reddit http://bit.ly/2QUxoXs
GitHub
fs0c131y/ESFileExplorerOpenPortVuln
ES File Explorer Open Port Vulnerability. Contribute to fs0c131y/ESFileExplorerOpenPortVuln development by creating an account on GitHub.
Fake Movie File Infects PC to Steal Cryptocurrency, Poison Google Results
http://bit.ly/2SRmkvQ
Submitted January 16, 2019 at 05:41PM by ga-vu
via reddit http://bit.ly/2McYVmi
http://bit.ly/2SRmkvQ
Submitted January 16, 2019 at 05:41PM by ga-vu
via reddit http://bit.ly/2McYVmi
BleepingComputer
Fake Movie File Infects PC to Steal Cryptocurrency, Poison Google Results
A malicious Windows shortcut file posing as a movie via The Pirate Bay torrent tracker can trigger a chain of mischievous activities on your computer, like injecting content from the attacker into high-profile web sites such as Wikipedia, Google and Yandex Search or…
Fake Movie File Infects PC to Steal Cryptocurrency, Poison Google Results
http://bit.ly/2SRmkvQ
Submitted January 16, 2019 at 05:41PM by ga-vu
via reddit http://bit.ly/2McYVmi
http://bit.ly/2SRmkvQ
Submitted January 16, 2019 at 05:41PM by ga-vu
via reddit http://bit.ly/2McYVmi
BleepingComputer
Fake Movie File Infects PC to Steal Cryptocurrency, Poison Google Results
A malicious Windows shortcut file posing as a movie via The Pirate Bay torrent tracker can trigger a chain of mischievous activities on your computer, like injecting content from the attacker into high-profile web sites such as Wikipedia, Google and Yandex Search or…
Hacking Fortnite
http://bit.ly/2FwjHNd
Submitted January 16, 2019 at 05:31PM by albinowax
via reddit http://bit.ly/2HfJ0Vq
http://bit.ly/2FwjHNd
Submitted January 16, 2019 at 05:31PM by albinowax
via reddit http://bit.ly/2HfJ0Vq
Check Point Research
Hacking Fortnite - Check Point Research
Research by: Alon Boxiner, Eran Vaknin and Oded Vanunu, January 16th, 2018 Played in a virtual world, players of ‘Fortnite’, the massively popular game from game developer Epic Games, are tasked with testing their endurance as they battle for tools and weapons…
Hacking Jenkins Part 1 - Play with Dynamic Routing
http://bit.ly/2su9UyL
Submitted January 16, 2019 at 06:46PM by albinowax
via reddit http://bit.ly/2Dd3lGN
http://bit.ly/2su9UyL
Submitted January 16, 2019 at 06:46PM by albinowax
via reddit http://bit.ly/2Dd3lGN
Orange
Hacking Jenkins Part 1 - Play with Dynamic Routing
This is 🍊 speaking
Distribution of malicious JAR appended to MSI files signed by third parties
http://bit.ly/2DbsYb0
Submitted January 16, 2019 at 07:31PM by TheLantean
via reddit http://bit.ly/2FAaNgW
http://bit.ly/2DbsYb0
Submitted January 16, 2019 at 07:31PM by TheLantean
via reddit http://bit.ly/2FAaNgW
Virustotal
Distribution of malicious JAR appended to MSI files signed by third parties
Microsoft Windows keeps the Authenticode signature valid after appending any content to the end of Windows Installer (.MSI) files signed by ...
Virtuailor: An IDAPython plugin to automate and ease the reversing of C++ code.
http://bit.ly/2HomjOG
Submitted January 16, 2019 at 06:23PM by rvngr12
via reddit http://bit.ly/2VWsehj
http://bit.ly/2HomjOG
Submitted January 16, 2019 at 06:23PM by rvngr12
via reddit http://bit.ly/2VWsehj
GitHub
0xgalz/Virtuailor
IDAPython tool for creating automatic C++ virtual tables in IDA Pro - 0xgalz/Virtuailor
What We Found in the SANS Holiday Hack: A 0day in rssh
http://bit.ly/2VU2K4l
Submitted January 16, 2019 at 11:11PM by grigorescu
via reddit http://bit.ly/2MfyXyC
http://bit.ly/2VU2K4l
Submitted January 16, 2019 at 11:11PM by grigorescu
via reddit http://bit.ly/2MfyXyC
esnet-security.github.io
Command Execution Vulnerability in rssh with allowscp
ESnet Security’s github.io Site
Securely Connecting an Arduino MKR WiFi 1010 to AWS IoT Core
http://bit.ly/2swWpyi
Submitted January 16, 2019 at 11:02PM by gvarisco
via reddit http://bit.ly/2Fuxcgk
http://bit.ly/2swWpyi
Submitted January 16, 2019 at 11:02PM by gvarisco
via reddit http://bit.ly/2Fuxcgk
Arduino Project Hub
Securely connecting an Arduino MKR WiFi 1010 to AWS IoT Core
In this tutorial, you'll learn how to connect your Arduino MKR WiFi 1010 (or MKR 1000) board securely to AWS IoT Core.
Security hole leaves passenger information available to anyone
http://bit.ly/2Rv1khR
Submitted January 16, 2019 at 11:00PM by le-quack
via reddit http://bit.ly/2HsQiW7
http://bit.ly/2Rv1khR
Submitted January 16, 2019 at 11:00PM by le-quack
via reddit http://bit.ly/2HsQiW7
Safety Detective
Major Security Breach Discovered Affecting Nearly Half of All Airline Travelers Worldwide | Safety Detective
New Magecart Attack Delivered Through Compromised Advertising Supply Chain
http://bit.ly/2AKoTsz
Submitted January 16, 2019 at 10:49PM by EvanConover
via reddit http://bit.ly/2FwxLGC
http://bit.ly/2AKoTsz
Submitted January 16, 2019 at 10:49PM by EvanConover
via reddit http://bit.ly/2FwxLGC
Trendmicro
New Magecart Attack Delivered Through Compromised Advertising Supply Chain - TrendLabs Security Intelligence Blog
We looked into Magecart's latest online skimming activity: injecting malicious code to the JavaScript library of a third-party advertising network.
Troy Hunt: The 773 Million Record "Collection #1" Data Breach
http://bit.ly/2QR5qfa
Submitted January 17, 2019 at 05:42AM by raincan
via reddit http://bit.ly/2RuSEIu
http://bit.ly/2QR5qfa
Submitted January 17, 2019 at 05:42AM by raincan
via reddit http://bit.ly/2RuSEIu
Troy Hunt
The 773 Million Record "Collection #1" Data Breach
Many people will land on this page after learning that their email address has appeared in a data breach I've called "Collection #1". Most of them won't have a tech background or be familiar with the concept of credential stuffing so I'm going to write this…
hardened-alpine : hardened alpine Docker image
http://bit.ly/2HglvLP
Submitted January 17, 2019 at 04:24PM by nindustries
via reddit http://bit.ly/2HgnjV3
http://bit.ly/2HglvLP
Submitted January 17, 2019 at 04:24PM by nindustries
via reddit http://bit.ly/2HgnjV3
GitHub
HazCod/hardened-alpine
Hardened alpine linux baseimage for Docker. Contribute to HazCod/hardened-alpine development by creating an account on GitHub.
An Introduction to the WebAuthn API
http://bit.ly/2FAClm7
Submitted January 17, 2019 at 04:57PM by kerberosmansour
via reddit http://bit.ly/2RC8zVD
http://bit.ly/2FAClm7
Submitted January 17, 2019 at 04:57PM by kerberosmansour
via reddit http://bit.ly/2RC8zVD
Medium
Introduction to WebAuthn API
…or Level 1 Credential Management API extension for Public Key Credentials, and the untold stories of managing credentials in the browser…
The curious case of the Raspberry Pi in the network closet
http://bit.ly/2MdLWkd
Submitted January 17, 2019 at 07:37PM by albinowax
via reddit http://bit.ly/2RW9S0A
http://bit.ly/2MdLWkd
Submitted January 17, 2019 at 07:37PM by albinowax
via reddit http://bit.ly/2RW9S0A
The curious case of the Raspberry Pi in the network closet
Personal blog of Christian Haschek
Exposed JIRA server leaks NASA staff and project data!
http://bit.ly/2CkF8N9
Submitted January 17, 2019 at 08:31PM by logic_bomb_1
via reddit http://bit.ly/2RUC7gj
http://bit.ly/2CkF8N9
Submitted January 17, 2019 at 08:31PM by logic_bomb_1
via reddit http://bit.ly/2RUC7gj
Medium
Exposed JIRA server leaks NASA staff and project data!
Here, I’ll be talking about an interesting vulnerability that I have found in NASA Jira (An Atlassian task tracking systems/project management software etc.).