Developers Are Not Idiots
http://bit.ly/2FxDMCH
Submitted January 18, 2019 at 07:00AM by davidw_-
via reddit http://bit.ly/2CpDsC2
http://bit.ly/2FxDMCH
Submitted January 18, 2019 at 07:00AM by davidw_-
via reddit http://bit.ly/2CpDsC2
www.cryptologie.net
Developers Are Not Idiots
After spending many years working in information security, as a consultant, I've had the chance to audit a multitude of different systems invented and developed by many different people. While there is a lot to say about that, the focus of this article is…
FREE Webinar: The 1-Year Roadmap To Master Malware Analysis, Triple Your Salary Or Be The Star Of Your Response Team
http://bit.ly/2sxd84k
Submitted January 18, 2019 at 06:00AM by AmrThabet
via reddit http://bit.ly/2T0iRvj
http://bit.ly/2sxd84k
Submitted January 18, 2019 at 06:00AM by AmrThabet
via reddit http://bit.ly/2T0iRvj
Maltrak
Free Webinar: The 1-Year Roadmap To Master Malware Analysis
This the Webinar: "The 1-Year Roadmap To Master Malware Analysis, Triple Your Salary Or Be The Star Of Your Response Team, Without Getting a New Certificate or Programming Skills"
Automatic string formatting deobfuscation in a malicious Powershell sample
http://bit.ly/2szSHnl
Submitted January 18, 2019 at 04:25PM by ThisIsLibra
via reddit http://bit.ly/2TTjHty
http://bit.ly/2szSHnl
Submitted January 18, 2019 at 04:25PM by ThisIsLibra
via reddit http://bit.ly/2TTjHty
reddit
r/netsec - Automatic string formatting deobfuscation in a malicious Powershell sample
1 vote and 0 comments so far on Reddit
BYOB (Build Your Own Botnet) in action | Perception Point
http://bit.ly/2Rx7TAv
Submitted January 18, 2019 at 05:23PM by shleimeleh
via reddit http://bit.ly/2RUrJVQ
http://bit.ly/2Rx7TAv
Submitted January 18, 2019 at 05:23PM by shleimeleh
via reddit http://bit.ly/2RUrJVQ
Perception Point
BYOB (Build Your Own Botnet) in action | Perception Point
Perception Point’s platform recently intercepted an attack leveraging the BYOB framework. This is the first time the BYOB framework is seen being used for fraudulent activity in the wild.
Sicksploit - Finding and (possibly) exploiting exposed SickChill instances.
http://bit.ly/2RTHdt7
Submitted January 18, 2019 at 06:29PM by Sudneo
via reddit http://bit.ly/2FN2AGn
http://bit.ly/2RTHdt7
Submitted January 18, 2019 at 06:29PM by Sudneo
via reddit http://bit.ly/2FN2AGn
Coolbyte
SickSploit - Finding and exploiting open SickChill instances. | Cool|Byte
Finding and exploiting open instances of SickRage/SickChill.
Positive Hack Days 9 Security Conference CFP is now open
http://bit.ly/2Cpv3hO
Submitted January 18, 2019 at 07:36PM by alexlash
via reddit http://bit.ly/2T1g9pb
http://bit.ly/2Cpv3hO
Submitted January 18, 2019 at 07:36PM by alexlash
via reddit http://bit.ly/2T1g9pb
Phdays
Become a speaker at PHDays 9!
Positive Hack Days is a unique global event. It is the only event which brings together the elite of the hackers' world, leaders of the information security industry and representatives of the Internet community to cooperate in addressing burning information…
The Chrome Extension That Steals Credit Card Numbers
http://bit.ly/2FyXEoZ
Submitted January 19, 2019 at 12:14AM by Fantastic_Fix
via reddit http://bit.ly/2FJxm2z
http://bit.ly/2FyXEoZ
Submitted January 19, 2019 at 12:14AM by Fantastic_Fix
via reddit http://bit.ly/2FJxm2z
InfoSec-IT
The Chrome Extension That Steals Credit Card Numbers | InfoSec-IT
A Chrome extension is stealing your credit card details with you knowing, do you have it installed on your device?
Backchannel Leaks on Strict Content-Security Policy
http://bit.ly/2RQeo0T
Submitted January 19, 2019 at 12:43AM by mazen160
via reddit http://bit.ly/2HmQwhd
http://bit.ly/2RQeo0T
Submitted January 19, 2019 at 12:43AM by mazen160
via reddit http://bit.ly/2HmQwhd
blog.mazinahmed.net
Backchannel Leaks on Strict Content-Security Policy
Abstract Content-Security Policy (CSP) is one of the most vital protection layers in client-side web security. A strict policy should n...
CFP - OWASP Global AppSec - Tel Aviv
http://bit.ly/2FB8lro
Submitted January 19, 2019 at 01:39AM by kerberosmansour
via reddit http://bit.ly/2HljyOp
http://bit.ly/2FB8lro
Submitted January 19, 2019 at 01:39AM by kerberosmansour
via reddit http://bit.ly/2HljyOp
reddit
r/netsec - CFP - OWASP Global AppSec - Tel Aviv
2 votes and 0 comments so far on Reddit
Linux PrivEsc Revisited - /etc/sudoers common issues & package managers - Neat and (mostly) undocumented tricks you need to be aware of before setting NOPASSWD & Bonus POCs for pentesters! (Part 2 at bottom)
http://bit.ly/2TYPae7
Submitted January 19, 2019 at 07:53AM by prodlsd
via reddit http://bit.ly/2MnsYb6
http://bit.ly/2TYPae7
Submitted January 19, 2019 at 07:53AM by prodlsd
via reddit http://bit.ly/2MnsYb6
reddit
r/netsec - Linux PrivEsc Revisited - /etc/sudoers common issues & package managers - Neat and (mostly) undocumented tricks you…
7 votes and 0 comments so far on Reddit
PortPush - A Bash Utility for Pivoting into Internal Networks via a Compromised Linux Host
http://bit.ly/2RyRg7R
Submitted January 19, 2019 at 06:05AM by kindredsec
via reddit http://bit.ly/2CxscUb
http://bit.ly/2RyRg7R
Submitted January 19, 2019 at 06:05AM by kindredsec
via reddit http://bit.ly/2CxscUb
GitHub
itsKindred/PortPush
A small Bash utility used for pivoting into internal networks upon compromising a public-facing host. - itsKindred/PortPush
CypherCon - April in Milwaukee
http://bit.ly/2FJo0E7
Submitted January 19, 2019 at 04:27AM by bitcoins
via reddit http://bit.ly/2FGDetD
http://bit.ly/2FJo0E7
Submitted January 19, 2019 at 04:27AM by bitcoins
via reddit http://bit.ly/2FGDetD
CypherCon
Cyphercon 4.0 - CypherCon
Welcome to CypherCon 4.0 (2019), Wisconsin’s Hacker Conference! Our conference provides hackers with an outlet to openly demonstrate and experience creativity and ingenuity through hands-on enlightening activities and thought provoking presentations and technical…
VLC is refuses to use HTTPS, relies on HTTP instead
http://bit.ly/2T2iVul
Submitted January 19, 2019 at 09:05AM by ExternalUserError
via reddit http://bit.ly/2R0MScm
http://bit.ly/2T2iVul
Submitted January 19, 2019 at 09:05AM by ExternalUserError
via reddit http://bit.ly/2R0MScm
Hack The Box - SecNotes write-up by 0xRick
http://bit.ly/2CxCyna
Submitted January 19, 2019 at 08:40PM by Ahm3d_H3sham
via reddit http://bit.ly/2HmCZ9z
http://bit.ly/2CxCyna
Submitted January 19, 2019 at 08:40PM by Ahm3d_H3sham
via reddit http://bit.ly/2HmCZ9z
0xRick Owned Root !
Hack The Box - SecNotes
Quick Summary Hey guys Today SecNotes retired. SecNotes was a very nice box and I really liked that it mixed between windows and linux , and that’s because it was a windows box and it had windows subsystem for linux (WSL) installed.It was relatively easy.…
Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi: from zero knowledge to zero-click RCE
http://bit.ly/2DiZ8Bu
Submitted January 19, 2019 at 09:28PM by campuscodi
via reddit http://bit.ly/2W0Qxed
http://bit.ly/2DiZ8Bu
Submitted January 19, 2019 at 09:28PM by campuscodi
via reddit http://bit.ly/2W0Qxed
Embedi
Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi: from zero knowledge to zero-click RCE
Remotely compromise devices by using bugs in Marvell Avastar Wi-Fi: from zero knowledge to zero-click RCE Introduction and motivation How wireless device works and starts up Interaction between Wi-Fi SoC and driver Firmware analysis Static firmware file analysis…
HAMMERTHROW: Rotate my domain
http://bit.ly/2W3w3kR
Submitted January 20, 2019 at 12:27AM by vysec
via reddit http://bit.ly/2Mi5Sm7
http://bit.ly/2W3w3kR
Submitted January 20, 2019 at 12:27AM by vysec
via reddit http://bit.ly/2Mi5Sm7
vincentyiu.co.uk
HAMMERTHROW: Rotate my domain - Vincent Yiu
Speed and Cryptography
http://bit.ly/2MonUmQ
Submitted January 20, 2019 at 01:49AM by davidw_-
via reddit http://bit.ly/2R06JZ7
http://bit.ly/2MonUmQ
Submitted January 20, 2019 at 01:49AM by davidw_-
via reddit http://bit.ly/2R06JZ7
www.cryptologie.net
Speed and Cryptography
At Real World Crypto 2019, Mihir Bellare won the Levchin Prize (along with Eric Rescorla) and gave a short and inspiring speech. You can watch it here. In it, he briefly mentioned what I'll call the speed issue:
when I started it was a question of being…
when I started it was a question of being…
Three Byte Overwrite to Exploit Vulnserver TRUN
http://bit.ly/2U47z9n
Submitted January 20, 2019 at 07:33AM by doylersec
via reddit http://bit.ly/2FNAx9p
http://bit.ly/2U47z9n
Submitted January 20, 2019 at 07:33AM by doylersec
via reddit http://bit.ly/2FNAx9p
doyler.net
Three Byte Overwrite to Exploit Vulnserver TRUN | doyler.net
For my vulnserver TRUN exploit, I decided to use a three byte overwrite to jump to EAX. Three Byte Overwrite (Vulnserver TRUN) - Introduction As I mentioned in my earlier post, I am going through vulnserver for OSCE/binary exploitation practice. … Continue…
Digital Safety: Using security keys to secure accounts against phishing
http://bit.ly/2MfDota
Submitted January 20, 2019 at 09:34AM by Privatrics
via reddit http://bit.ly/2FC3ENI
http://bit.ly/2MfDota
Submitted January 20, 2019 at 09:34AM by Privatrics
via reddit http://bit.ly/2FC3ENI
cpj.org
Digital Safety: Using security keys to secure accounts against phishing
Hackers are using more sophisticated methods to target journalists, including those who use two-step authentication (2FA)....
0xgalz/Virtuailor - IDAPython tool for creating automatic C++ virtual tables in IDA Pro
http://bit.ly/2HomjOG
Submitted January 20, 2019 at 05:21PM by GelosSnake
via reddit http://bit.ly/2FDh2RR
http://bit.ly/2HomjOG
Submitted January 20, 2019 at 05:21PM by GelosSnake
via reddit http://bit.ly/2FDh2RR
GitHub
0xgalz/Virtuailor
IDAPython tool for creating automatic C++ virtual tables in IDA Pro - 0xgalz/Virtuailor
GitHub - fs0c131y/CVE-2018-20555: Social Network Tabs Wordpress Plugin Vulnerability - Leaks tokens
http://bit.ly/2Mlp2HB
Submitted January 20, 2019 at 05:41PM by thms00
via reddit http://bit.ly/2szz0fB
http://bit.ly/2Mlp2HB
Submitted January 20, 2019 at 05:41PM by thms00
via reddit http://bit.ly/2szz0fB
GitHub
fs0c131y/CVE-2018-20555
Social Network Tabs Wordpress Plugin Vulnerability - CVE-2018-20555 - fs0c131y/CVE-2018-20555