Hacking Android: Attack Surfaces
http://bit.ly/2V758nS
Submitted January 29, 2019 at 02:37AM by marketingversprite
via reddit http://bit.ly/2TlgGSY
http://bit.ly/2V758nS
Submitted January 29, 2019 at 02:37AM by marketingversprite
via reddit http://bit.ly/2TlgGSY
VerSprite | Integrated Security Services and Consulting
Hacking Android: Attack Surfaces | VerSprite TVM
Many users with older versions of Android are prime targets with less hardend security. We will briefly look at the attack surface of an Android device.
52 Actionable Ways to Hack Your Productivity (satire)
http://bit.ly/2Rk4HmR
Submitted January 29, 2019 at 02:25AM by small-data-expert
via reddit http://bit.ly/2UhRooW
http://bit.ly/2Rk4HmR
Submitted January 29, 2019 at 02:25AM by small-data-expert
via reddit http://bit.ly/2UhRooW
Medium
52 Actionable Ways to Hack Your Productivity
Techniques I used when starting a startup and keeping my job as a day trader
Restoring a SQL Server Database during a pentest using AWS
http://bit.ly/2FUMUle
Submitted January 29, 2019 at 04:33AM by 312sec
via reddit http://bit.ly/2B5qyt2
http://bit.ly/2FUMUle
Submitted January 29, 2019 at 04:33AM by 312sec
via reddit http://bit.ly/2B5qyt2
Dolos Group
Restore a SQL Server Database to AWS
It happens to all testers eventually. You come across a file share hosting dozens of database backups. Giddiness ensues as you realize you have full read access and can copy any of them down to your dropbox, until you notice the database backups are tens…
iPhone bug lets you hear the audio of the person you are calling before they pick up
http://bit.ly/2HCWkU7
Submitted January 29, 2019 at 08:30AM by the-silent-guardian
via reddit http://bit.ly/2RSVHue
http://bit.ly/2HCWkU7
Submitted January 29, 2019 at 08:30AM by the-silent-guardian
via reddit http://bit.ly/2RSVHue
9to5Mac
Major iPhone FaceTime bug lets you hear the audio of the person you are calling … before they pick up
A significant bug has been discovered in FaceTime and is currently spreading virally over social media. The bug lets you call anyone with FaceTime, and immediately hear the audio coming from their …
TLS beaconing detection using ee-outliers and Elasticsearch
http://bit.ly/2G8f635
Submitted January 29, 2019 at 03:06PM by digicat
via reddit http://bit.ly/2Sf35iT
http://bit.ly/2G8f635
Submitted January 29, 2019 at 03:06PM by digicat
via reddit http://bit.ly/2Sf35iT
NVISO Labs
TLS beaconing detection using ee-outliers and Elasticsearch
Earlier today, we open-source ee-outliers, our in-house developed framework to detect outliers in events stored in Elasticsearch. This blog post is the first of several in which we want to dive a b…
7z AES encryption contains several vulnerabilities
http://bit.ly/2MrgFug
Submitted January 29, 2019 at 06:34PM by Titokhan
via reddit http://bit.ly/2sVhene
http://bit.ly/2MrgFug
Submitted January 29, 2019 at 06:34PM by Titokhan
via reddit http://bit.ly/2sVhene
Threadreaderapp
Thread by @3lbios: "So I wanted to encrypt some files. Thought about using 7z+password. Stackexchange folks said "Didn't review…
Thread by @3lbios: "So I wanted to encrypt some files. Thought about using 7z+password. Stackexchange folks said "Didn't review it but it sho I did. After a few mins I noticed they use 8byte "random" IV. Yes, h […]" #7zip #encryption #facepalm #randomness
Abusing Exchange: One API call away from Domain Admin
http://bit.ly/2DqEhMH
Submitted January 29, 2019 at 06:27PM by Reddfish
via reddit http://bit.ly/2G4XAgl
http://bit.ly/2DqEhMH
Submitted January 29, 2019 at 06:27PM by Reddfish
via reddit http://bit.ly/2G4XAgl
dirkjanm.io
Abusing Exchange: One API call away from Domain Admin
In most organisations using Active Directory and Exchange, Exchange servers have such high privileges that being an Administrator on an Exchange server is enough to escalate to Domain Admin. Recently I came across a blog from the ZDI, in which they detail…
sn0int - Semi-automatic OSINT framework and package manager
http://bit.ly/2Wv0LUr
Submitted January 29, 2019 at 07:51PM by kpcyrd
via reddit http://bit.ly/2G8bFcI
http://bit.ly/2Wv0LUr
Submitted January 29, 2019 at 07:51PM by kpcyrd
via reddit http://bit.ly/2G8bFcI
GitHub
kpcyrd/sn0int
Semi-automatic OSINT framework and package manager - kpcyrd/sn0int
Learning about Universal Links and Fuzzing URL Schemes on iOS with Frida
http://bit.ly/2HE6SSX
Submitted January 29, 2019 at 08:04PM by cbolat
via reddit http://bit.ly/2MKxsc1
http://bit.ly/2HE6SSX
Submitted January 29, 2019 at 08:04PM by cbolat
via reddit http://bit.ly/2MKxsc1
Htcrawl - a nodejs module for the recursive crawling of single page applications using Puppeteer
https://htcrawl.org/
Submitted January 29, 2019 at 09:23PM by filippo_cavallarin
via reddit http://bit.ly/2SiqsIe
https://htcrawl.org/
Submitted January 29, 2019 at 09:23PM by filippo_cavallarin
via reddit http://bit.ly/2SiqsIe
reddit
r/netsec - Htcrawl - a nodejs module for the recursive crawling of single page applications using Puppeteer
1 vote and 0 comments so far on Reddit
Drupal POP Chain via Cache Poisoning
http://bit.ly/2sPubim
Submitted January 29, 2019 at 10:07PM by websecdev
via reddit http://bit.ly/2CUwMw3
http://bit.ly/2sPubim
Submitted January 29, 2019 at 10:07PM by websecdev
via reddit http://bit.ly/2CUwMw3
reddit
r/netsec - Drupal POP Chain via Cache Poisoning
3 votes and 0 comments so far on Reddit
Pompa - another open-source phishing toolkit for those who value flexibility and control
http://bit.ly/2G6awlU
Submitted January 29, 2019 at 01:03AM by m1nl
via reddit http://bit.ly/2FVHEOf
http://bit.ly/2G6awlU
Submitted January 29, 2019 at 01:03AM by m1nl
via reddit http://bit.ly/2FVHEOf
GitHub
m1nl/pompa
Fully-featured spear-phishing toolkit - web front-end - m1nl/pompa
Apple Was Apparently Notified About Major FaceTime Eavesdropping Bug Over a Week Ago
http://bit.ly/2t22qTX
Submitted January 30, 2019 at 01:46AM by notchplusone
via reddit http://bit.ly/2Wuo1BC
http://bit.ly/2t22qTX
Submitted January 30, 2019 at 01:46AM by notchplusone
via reddit http://bit.ly/2Wuo1BC
Macrumors
Apple Was Apparently Notified About Major FaceTime Eavesdropping Bug Over a Week Ago [Updated]
While it only made the news yesterday, it appears Apple was alerted to a major FaceTime privacy bug over a week ago. Twitter user MGT7500...
Unsecured access to personal data of a million Leo Express users
http://bit.ly/2Shi5g8
Submitted January 30, 2019 at 03:50AM by ThomasCZ
via reddit http://bit.ly/2sSd4wp
http://bit.ly/2Shi5g8
Submitted January 30, 2019 at 03:50AM by ThomasCZ
via reddit http://bit.ly/2sSd4wp
Thomas Orlita's blog
Unsecured access to personal data of a million Leo Express users - Thomas Orlita's blog
Leo Express is a Czech company operating train and bus lines in Central Europe. When I signed up, I noticed that on every page load a GraphQL request is sent to the server, which returns my account information in JSON. GraphQL is a query language for APIs…
Reversing the Rachio3 Smart Sprinkler Controller
http://bit.ly/2Gdi9ax
Submitted January 30, 2019 at 02:25AM by chicksdigthelongrun
via reddit http://bit.ly/2DHPaKc
http://bit.ly/2Gdi9ax
Submitted January 30, 2019 at 02:25AM by chicksdigthelongrun
via reddit http://bit.ly/2DHPaKc
Medium
Reversing the Rachio Smart Sprinkler Controller
A new smart device that “takes the guesswork out of watering.” An IoT device that extends the boundaries of your smart home into the yard…
Facebook Paying People $20/Month to Install Data Harvesting VPN App on iPhones
http://bit.ly/2DGXiKO
Submitted January 30, 2019 at 07:08AM by detroitguy16
via reddit http://bit.ly/2sVBJ34
http://bit.ly/2DGXiKO
Submitted January 30, 2019 at 07:08AM by detroitguy16
via reddit http://bit.ly/2sVBJ34
Macrumors
Facebook Paying Teens $20/Month to Install Data Harvesting VPN App on iPhones
Apple in August 2018 forced Facebook to remove its Onavo VPN app from the App Store, because Facebook was using it to track user activity and data...
PKI federation: how to use certificates & mTLS to connect across clouds and stuff
http://bit.ly/2B96h63
Submitted January 30, 2019 at 06:45AM by sourishkrout
via reddit http://bit.ly/2TqYt6R
http://bit.ly/2B96h63
Submitted January 30, 2019 at 06:45AM by sourishkrout
via reddit http://bit.ly/2TqYt6R
Smallstep
We are excited to start the New Year off with a new release (v0.8.3) of step certificates, the powerful open source certificate management solution. Amongst regular bug fixes, we’ve included some exciting new features!
Black Hats & White Collars: SEC EDGAR Database Hackers Revealed
https://splk.it/2Wmdngi
Submitted January 30, 2019 at 04:53AM by orygunian
via reddit http://bit.ly/2G71ntk
https://splk.it/2Wmdngi
Submitted January 30, 2019 at 04:53AM by orygunian
via reddit http://bit.ly/2G71ntk
Splunk-Blogs
Black Hats & White Collars: SEC EDGAR Database Hackers Revealed
One of the most critical aspects of crime is to understand intent so we can further understand the increasingly cozy relationship between black hat hackers and white collar criminals
24 million loan records found on open Amazon S3 bucket
http://bit.ly/2Bbr4pv
Submitted January 30, 2019 at 11:24AM by sidcool1234
via reddit http://bit.ly/2TlDZw9
http://bit.ly/2Bbr4pv
Submitted January 30, 2019 at 11:24AM by sidcool1234
via reddit http://bit.ly/2TlDZw9
SC Media
24 million loan records found on open Amazon S3 bucket| SC Media
The original mortgage and credit documents involved in the 24 million Elasticsearch data breach also have been found residing in an open Amazon S3 bucket.
BEEMKA: Basic Electron Framework Exploitation Tool (Red Team Persistence / Data Egress)
http://bit.ly/2B4PdxZ
Submitted January 30, 2019 at 02:27PM by h0wlett
via reddit http://bit.ly/2Tm5m9t
http://bit.ly/2B4PdxZ
Submitted January 30, 2019 at 02:27PM by h0wlett
via reddit http://bit.ly/2Tm5m9t
GitHub
ctxis/beemka
Basic Electron Exploitation. Contribute to ctxis/beemka development by creating an account on GitHub.
Samsung Galaxy Apps Store RCE via MITM (Writeup)
http://bit.ly/2GappUv
Submitted January 30, 2019 at 06:38PM by cbolat
via reddit http://bit.ly/2To0y35
http://bit.ly/2GappUv
Submitted January 30, 2019 at 06:38PM by cbolat
via reddit http://bit.ly/2To0y35
Adyta
Writeup – Samsung Galaxy Apps Store RCE via MITM