A Deeper Look into XSS Payloads
http://bit.ly/2W0g8nq
Submitted January 17, 2019 at 06:36PM by digitalinterruption
via reddit http://bit.ly/2FwHEE4
http://bit.ly/2W0g8nq
Submitted January 17, 2019 at 06:36PM by digitalinterruption
via reddit http://bit.ly/2FwHEE4
Digitalinterruption
A Deeper Look into XSS Payloads | Digital Interruption Research
Over time, the type of vulnerabilities seen in the web app landscape changes. One that has persisted year in, year out, is cross-site noscripting. It’s been a ...
Google Play Apps Drop Anubis Banking Malware, Use Motion-based Evasion Tactics
http://bit.ly/2CqKp5O
Submitted January 17, 2019 at 11:00PM by EvanConover
via reddit http://bit.ly/2QSrdDn
http://bit.ly/2CqKp5O
Submitted January 17, 2019 at 11:00PM by EvanConover
via reddit http://bit.ly/2QSrdDn
Trendmicro
Google Play Apps Drop Anubis Banking Malware, Use Motion-based Evasion Tactics - TrendLabs Security Intelligence Blog
Malicious apps on Google Play were trying to drop the Anubis banking malware on unsuspecting users. They were also using an innovative new evasion tactic.
Taking a page from the kernel's book: A TLB issue in mremap()
http://bit.ly/2FDqDam
Submitted January 17, 2019 at 10:58PM by Vonter
via reddit http://bit.ly/2VYBstk
http://bit.ly/2FDqDam
Submitted January 17, 2019 at 10:58PM by Vonter
via reddit http://bit.ly/2VYBstk
reddit
r/netsec - Taking a page from the kernel's book: A TLB issue in mremap()
1 vote and 0 comments so far on Reddit
Buffer Overflow Practical Examples , Shellcode Injection and Local Privilege Escalation
http://bit.ly/2QWTwAi
Submitted January 18, 2019 at 01:35AM by Ahm3d_H3sham
via reddit http://bit.ly/2FxV96i
http://bit.ly/2QWTwAi
Submitted January 18, 2019 at 01:35AM by Ahm3d_H3sham
via reddit http://bit.ly/2FxV96i
0xRick Owned Root !
Buffer Overflow Practical Examples , Shellcode Injection and Local Privilege Escalation - protostar stack5
Introduction Hey I’m back with another Buffer Overflow article and today we are going to do a really interesting exploit , Today we will finally escalate privileges using a vulnerable suid binary (you can know more about that by reading the first buffer overflow…
A tale of private key reuse
http://bit.ly/2HuWaOD
Submitted January 18, 2019 at 01:34AM by koenrh
via reddit http://bit.ly/2RBDDEI
http://bit.ly/2HuWaOD
Submitted January 18, 2019 at 01:34AM by koenrh
via reddit http://bit.ly/2RBDDEI
Koen Rouwhorst
A tale of private key reuse
In 2017, while attempting to get some DRM-enabled video player to work on my Mac, I stumbled upon a hard-coded private key. The corresponding public key was used in a valid and publicly trusted Cis…
Developers Are Not Idiots
http://bit.ly/2FxDMCH
Submitted January 18, 2019 at 07:00AM by davidw_-
via reddit http://bit.ly/2CpDsC2
http://bit.ly/2FxDMCH
Submitted January 18, 2019 at 07:00AM by davidw_-
via reddit http://bit.ly/2CpDsC2
www.cryptologie.net
Developers Are Not Idiots
After spending many years working in information security, as a consultant, I've had the chance to audit a multitude of different systems invented and developed by many different people. While there is a lot to say about that, the focus of this article is…
FREE Webinar: The 1-Year Roadmap To Master Malware Analysis, Triple Your Salary Or Be The Star Of Your Response Team
http://bit.ly/2sxd84k
Submitted January 18, 2019 at 06:00AM by AmrThabet
via reddit http://bit.ly/2T0iRvj
http://bit.ly/2sxd84k
Submitted January 18, 2019 at 06:00AM by AmrThabet
via reddit http://bit.ly/2T0iRvj
Maltrak
Free Webinar: The 1-Year Roadmap To Master Malware Analysis
This the Webinar: "The 1-Year Roadmap To Master Malware Analysis, Triple Your Salary Or Be The Star Of Your Response Team, Without Getting a New Certificate or Programming Skills"
Automatic string formatting deobfuscation in a malicious Powershell sample
http://bit.ly/2szSHnl
Submitted January 18, 2019 at 04:25PM by ThisIsLibra
via reddit http://bit.ly/2TTjHty
http://bit.ly/2szSHnl
Submitted January 18, 2019 at 04:25PM by ThisIsLibra
via reddit http://bit.ly/2TTjHty
reddit
r/netsec - Automatic string formatting deobfuscation in a malicious Powershell sample
1 vote and 0 comments so far on Reddit
BYOB (Build Your Own Botnet) in action | Perception Point
http://bit.ly/2Rx7TAv
Submitted January 18, 2019 at 05:23PM by shleimeleh
via reddit http://bit.ly/2RUrJVQ
http://bit.ly/2Rx7TAv
Submitted January 18, 2019 at 05:23PM by shleimeleh
via reddit http://bit.ly/2RUrJVQ
Perception Point
BYOB (Build Your Own Botnet) in action | Perception Point
Perception Point’s platform recently intercepted an attack leveraging the BYOB framework. This is the first time the BYOB framework is seen being used for fraudulent activity in the wild.
Sicksploit - Finding and (possibly) exploiting exposed SickChill instances.
http://bit.ly/2RTHdt7
Submitted January 18, 2019 at 06:29PM by Sudneo
via reddit http://bit.ly/2FN2AGn
http://bit.ly/2RTHdt7
Submitted January 18, 2019 at 06:29PM by Sudneo
via reddit http://bit.ly/2FN2AGn
Coolbyte
SickSploit - Finding and exploiting open SickChill instances. | Cool|Byte
Finding and exploiting open instances of SickRage/SickChill.
Positive Hack Days 9 Security Conference CFP is now open
http://bit.ly/2Cpv3hO
Submitted January 18, 2019 at 07:36PM by alexlash
via reddit http://bit.ly/2T1g9pb
http://bit.ly/2Cpv3hO
Submitted January 18, 2019 at 07:36PM by alexlash
via reddit http://bit.ly/2T1g9pb
Phdays
Become a speaker at PHDays 9!
Positive Hack Days is a unique global event. It is the only event which brings together the elite of the hackers' world, leaders of the information security industry and representatives of the Internet community to cooperate in addressing burning information…
The Chrome Extension That Steals Credit Card Numbers
http://bit.ly/2FyXEoZ
Submitted January 19, 2019 at 12:14AM by Fantastic_Fix
via reddit http://bit.ly/2FJxm2z
http://bit.ly/2FyXEoZ
Submitted January 19, 2019 at 12:14AM by Fantastic_Fix
via reddit http://bit.ly/2FJxm2z
InfoSec-IT
The Chrome Extension That Steals Credit Card Numbers | InfoSec-IT
A Chrome extension is stealing your credit card details with you knowing, do you have it installed on your device?
Backchannel Leaks on Strict Content-Security Policy
http://bit.ly/2RQeo0T
Submitted January 19, 2019 at 12:43AM by mazen160
via reddit http://bit.ly/2HmQwhd
http://bit.ly/2RQeo0T
Submitted January 19, 2019 at 12:43AM by mazen160
via reddit http://bit.ly/2HmQwhd
blog.mazinahmed.net
Backchannel Leaks on Strict Content-Security Policy
Abstract Content-Security Policy (CSP) is one of the most vital protection layers in client-side web security. A strict policy should n...
CFP - OWASP Global AppSec - Tel Aviv
http://bit.ly/2FB8lro
Submitted January 19, 2019 at 01:39AM by kerberosmansour
via reddit http://bit.ly/2HljyOp
http://bit.ly/2FB8lro
Submitted January 19, 2019 at 01:39AM by kerberosmansour
via reddit http://bit.ly/2HljyOp
reddit
r/netsec - CFP - OWASP Global AppSec - Tel Aviv
2 votes and 0 comments so far on Reddit
Linux PrivEsc Revisited - /etc/sudoers common issues & package managers - Neat and (mostly) undocumented tricks you need to be aware of before setting NOPASSWD & Bonus POCs for pentesters! (Part 2 at bottom)
http://bit.ly/2TYPae7
Submitted January 19, 2019 at 07:53AM by prodlsd
via reddit http://bit.ly/2MnsYb6
http://bit.ly/2TYPae7
Submitted January 19, 2019 at 07:53AM by prodlsd
via reddit http://bit.ly/2MnsYb6
reddit
r/netsec - Linux PrivEsc Revisited - /etc/sudoers common issues & package managers - Neat and (mostly) undocumented tricks you…
7 votes and 0 comments so far on Reddit
PortPush - A Bash Utility for Pivoting into Internal Networks via a Compromised Linux Host
http://bit.ly/2RyRg7R
Submitted January 19, 2019 at 06:05AM by kindredsec
via reddit http://bit.ly/2CxscUb
http://bit.ly/2RyRg7R
Submitted January 19, 2019 at 06:05AM by kindredsec
via reddit http://bit.ly/2CxscUb
GitHub
itsKindred/PortPush
A small Bash utility used for pivoting into internal networks upon compromising a public-facing host. - itsKindred/PortPush
CypherCon - April in Milwaukee
http://bit.ly/2FJo0E7
Submitted January 19, 2019 at 04:27AM by bitcoins
via reddit http://bit.ly/2FGDetD
http://bit.ly/2FJo0E7
Submitted January 19, 2019 at 04:27AM by bitcoins
via reddit http://bit.ly/2FGDetD
CypherCon
Cyphercon 4.0 - CypherCon
Welcome to CypherCon 4.0 (2019), Wisconsin’s Hacker Conference! Our conference provides hackers with an outlet to openly demonstrate and experience creativity and ingenuity through hands-on enlightening activities and thought provoking presentations and technical…
VLC is refuses to use HTTPS, relies on HTTP instead
http://bit.ly/2T2iVul
Submitted January 19, 2019 at 09:05AM by ExternalUserError
via reddit http://bit.ly/2R0MScm
http://bit.ly/2T2iVul
Submitted January 19, 2019 at 09:05AM by ExternalUserError
via reddit http://bit.ly/2R0MScm
Hack The Box - SecNotes write-up by 0xRick
http://bit.ly/2CxCyna
Submitted January 19, 2019 at 08:40PM by Ahm3d_H3sham
via reddit http://bit.ly/2HmCZ9z
http://bit.ly/2CxCyna
Submitted January 19, 2019 at 08:40PM by Ahm3d_H3sham
via reddit http://bit.ly/2HmCZ9z
0xRick Owned Root !
Hack The Box - SecNotes
Quick Summary Hey guys Today SecNotes retired. SecNotes was a very nice box and I really liked that it mixed between windows and linux , and that’s because it was a windows box and it had windows subsystem for linux (WSL) installed.It was relatively easy.…
Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi: from zero knowledge to zero-click RCE
http://bit.ly/2DiZ8Bu
Submitted January 19, 2019 at 09:28PM by campuscodi
via reddit http://bit.ly/2W0Qxed
http://bit.ly/2DiZ8Bu
Submitted January 19, 2019 at 09:28PM by campuscodi
via reddit http://bit.ly/2W0Qxed
Embedi
Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi: from zero knowledge to zero-click RCE
Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi: from zero knowledge to zero-click RCE Introduction and motivation How wireless device works and starts up Interaction between Wi-Fi SoC and driver Firmware analysis Static firmware file analysis…
HAMMERTHROW: Rotate my domain
http://bit.ly/2W3w3kR
Submitted January 20, 2019 at 12:27AM by vysec
via reddit http://bit.ly/2Mi5Sm7
http://bit.ly/2W3w3kR
Submitted January 20, 2019 at 12:27AM by vysec
via reddit http://bit.ly/2Mi5Sm7
vincentyiu.co.uk
HAMMERTHROW: Rotate my domain - Vincent Yiu