Bypass AppLocker as an Admin
http://bit.ly/2WBBlEk
Submitted February 01, 2019 at 11:23PM by oddvarmoe
via reddit http://bit.ly/2G4Mbhh
http://bit.ly/2WBBlEk
Submitted February 01, 2019 at 11:23PM by oddvarmoe
via reddit http://bit.ly/2G4Mbhh
Oddvar Moe's Blog
Bypassing AppLocker as an admin
I thought it would be useful to have a blog post about two different techniques you can use to bypass AppLocker if you are an admin on a host that has AppLocker enabled. The first technique that us…
Apple will issue Group FaceTime patch next week.
http://bit.ly/2S1ctY8
Submitted February 02, 2019 at 01:52AM by skoomski
via reddit http://bit.ly/2TyBuXa
http://bit.ly/2S1ctY8
Submitted February 02, 2019 at 01:52AM by skoomski
via reddit http://bit.ly/2TyBuXa
9to5Mac
Apple says iOS fix for Group FaceTime bug now coming next week, issues apology
Apple has today released an update on the FaceTime eavesdropping bug and offered an apology. The company says it has patched the flaw on its servers and will roll out an update to iOS users next we…
Vulnerabilities in Tightrope Media Systems Carousel digital signage platform (3 CVEs)
http://bit.ly/2sYoTRD
Submitted February 02, 2019 at 05:33AM by agreenbhm
via reddit http://bit.ly/2UBkXSO
http://bit.ly/2sYoTRD
Submitted February 02, 2019 at 05:33AM by agreenbhm
via reddit http://bit.ly/2UBkXSO
Drew Green's Tech Blog
Vulnerabilities in Tightrope Media Systems Carousel <=7.0.4.104 (and likely newer)
While on a recent penetration test, I discovered a digital signage system made by Tightrope Media Systems (TRMS). The client was using this software on an appliance provided by TRMS which was essen…
"A fresh look on reverse proxy related attacks" by @antyurin
http://bit.ly/2HL3vcP
Submitted February 02, 2019 at 05:26AM by HDKramer
via reddit http://bit.ly/2MPtJKg
http://bit.ly/2HL3vcP
Submitted February 02, 2019 at 05:26AM by HDKramer
via reddit http://bit.ly/2MPtJKg
Acunetix
A Fresh Look On Reverse Proxy Related Attacks | Acunetix
The goal of this research is to portray the bigger picture of potential attacks on a reverse proxy or the backend servers behind it. In the main part of the article, I will show some examples of vulnerable configurations and exploitation of attacks on various…
Various Google Play ‘Beauty Camera’ Apps Send Users Pornographic Content, Redirect Them to Phishing Websites and Collect Their Pictures
http://bit.ly/2sXempI
Submitted February 02, 2019 at 03:22PM by Titokhan
via reddit http://bit.ly/2BcUKm4
http://bit.ly/2sXempI
Submitted February 02, 2019 at 03:22PM by Titokhan
via reddit http://bit.ly/2BcUKm4
Trendmicro
Various Google Play 'Beauty Camera' Apps Send Users Pornographic Content, Redirect Them to Phishing Websites and Collect Their…
We discovered several beauty camera apps (detected as AndroidOS_BadCamera.HRX) on Google Play that are capable of accessing remote ad configuration servers that can be used for malicious purposes.
APT32/OceanLotus sample: d592b06f9d112c8650091166c19ea05a
http://bit.ly/2D8N4RU
Submitted February 02, 2019 at 07:28PM by m_edmondson
via reddit http://bit.ly/2D2QK80
http://bit.ly/2D8N4RU
Submitted February 02, 2019 at 07:28PM by m_edmondson
via reddit http://bit.ly/2D2QK80
Marcus Edmondson | Malware Analysis | Security Analytics
APT 32/OceanLotus – Sample:D592B06F9D112C8650091166C19EA05A
Today I wanted to do a post on a sample that I pulled down from 0xffff0800 website here. It is just a quick behavioral analysis in order to rip out some IOC’s for quick wins. A little backgro…
Hack The Box - Dab write-up by 0xRick
http://bit.ly/2RBJJjE
Submitted February 02, 2019 at 08:21PM by Ahm3d_H3sham
via reddit http://bit.ly/2TuKo8g
http://bit.ly/2RBJJjE
Submitted February 02, 2019 at 08:21PM by Ahm3d_H3sham
via reddit http://bit.ly/2TuKo8g
0xRick Owned Root !
Hack The Box - Dab
Quick Summary Hey guys today dab retired and this is my write-up. Dab was a nice box ,A hard one but it had some funny stuff too , getting user was really annoying because it had a lot of rabbit holes. Root was much better. It’s a linux box and it’s ip is…
Confusing the data miners is important.
http://bit.ly/2HOPOK1
Submitted February 02, 2019 at 11:40PM by wavetranscender
via reddit http://bit.ly/2t3JqnU
http://bit.ly/2HOPOK1
Submitted February 02, 2019 at 11:40PM by wavetranscender
via reddit http://bit.ly/2t3JqnU
reddit
r/Rat_Race_Exit - Confusing the data miners is important.
1 vote and 1 comment so far on Reddit
Docker and Visual Studio Code on a Chromebook
http://bit.ly/2G88yCv
Submitted February 03, 2019 at 06:37PM by kev-thehermit
via reddit http://bit.ly/2D50MFu
http://bit.ly/2G88yCv
Submitted February 03, 2019 at 06:37PM by kev-thehermit
via reddit http://bit.ly/2D50MFu
techanarchy.net
Dev Tools on a Chromebook | TechAnarchy
Just another DFIR Blog
Interlace: Easily Automate and Multithread Your Pentesting + Bounty Hunting Workflow Without Any Coding
http://bit.ly/2SoA4Bn
Submitted February 03, 2019 at 07:07PM by hakluke
via reddit http://bit.ly/2GqI3Yv
http://bit.ly/2SoA4Bn
Submitted February 03, 2019 at 07:07PM by hakluke
via reddit http://bit.ly/2GqI3Yv
Medium
Interlace: A Tool to Easily Automate and Multithread Your Pentesting & Bug Bounty Workflow Without Any Coding
Before we start, I need to get something off my chest. I’m an efficiency junkie. I’m one of those people who spends 4 hours configuring…
The strange case of the Jekyll and Hyde PDF
http://bit.ly/2G8TfcP
Submitted February 03, 2019 at 11:01PM by alech_de
via reddit http://bit.ly/2D2CQ5E
http://bit.ly/2G8TfcP
Submitted February 03, 2019 at 11:01PM by alech_de
via reddit http://bit.ly/2D2CQ5E
reddit
r/netsec - The strange case of the Jekyll and Hyde PDF
3 votes and 0 comments so far on Reddit
Scams, American Express, and obfuscated Javanoscript
http://bit.ly/2Tu9Pab
Submitted February 04, 2019 at 01:20AM by JonLuca
via reddit http://bit.ly/2BhY2o1
http://bit.ly/2Tu9Pab
Submitted February 04, 2019 at 01:20AM by JonLuca
via reddit http://bit.ly/2BhY2o1
JonLuca’s Blog
Scams, American Express, and obfuscated Javanoscript
Whenever I get a scam email that manages to circumvent both my and gmail’s email filters, I like to take a closer look at how it did it and what it’s trying to accomplish.
Obfuscated javanoscript, scam emails, and American Express
http://bit.ly/2Tu9Pab
Submitted February 04, 2019 at 09:04AM by JonLuca
via reddit http://bit.ly/2WFf0G0
http://bit.ly/2Tu9Pab
Submitted February 04, 2019 at 09:04AM by JonLuca
via reddit http://bit.ly/2WFf0G0
JonLuca’s Blog
Scams, American Express, and obfuscated Javanoscript
Whenever I get a scam email that manages to circumvent both my and gmail’s email filters, I like to take a closer look at how it did it and what it’s trying to accomplish.
Alternative job board dedicated to InfoSec jobs
http://bit.ly/2Tom4VJ
Submitted February 04, 2019 at 01:39PM by infosec-jobs
via reddit http://bit.ly/2tcTqeN
http://bit.ly/2Tom4VJ
Submitted February 04, 2019 at 01:39PM by infosec-jobs
via reddit http://bit.ly/2tcTqeN
infosec-jobs.com
Your prime source of cyber security jobs | infosec-jobs.com
infosec-jobs.com is the prime InfoSec job board serving the cyber security community with fresh career opportunities and a platform to attract great talent
My Forensic and Incident Response Note Taking Methodology
http://bit.ly/2DRz5Bw
Submitted February 04, 2019 at 01:35PM by skygrip
via reddit http://bit.ly/2HQ42dF
http://bit.ly/2DRz5Bw
Submitted February 04, 2019 at 01:35PM by skygrip
via reddit http://bit.ly/2HQ42dF
IronMoon
My Forensic and Incident Response Note Taking Methodology
Why You Should Take Good Notes During Forensic and Incident Response
Even if you use HTTPS, your browsing habits can still be tracked by observing your DNS queries.
http://bit.ly/2GnhG5m
Submitted February 04, 2019 at 03:39PM by judit_k
via reddit http://bit.ly/2DSz54m
http://bit.ly/2GnhG5m
Submitted February 04, 2019 at 03:39PM by judit_k
via reddit http://bit.ly/2DSz54m
Avatao
How to avoid issues with DNS security and privacy - Avatao
DNS security & DNS privacy: problems that can arise from the lack of these attributes & tips on how to remedy them.
Exploiting SSRF in AWS Elastic Beanstalk - NotSoSecure
http://bit.ly/2MNwefU
Submitted February 04, 2019 at 05:49PM by anantshri
via reddit http://bit.ly/2WOcduq
http://bit.ly/2MNwefU
Submitted February 04, 2019 at 05:49PM by anantshri
via reddit http://bit.ly/2WOcduq
NotSoSecure
Exploiting SSRF in AWS Elastic Beanstalk - NotSoSecure
Checkout how an ssrf vulnerability can lead to a complete compromise of your aws infrastructure hosted using the elastic beanstalk service
Multiple Vulnerabilities Found in Mobile Device Management Software
http://bit.ly/2RyrD21
Submitted February 04, 2019 at 04:09PM by digitalinterruption
via reddit http://bit.ly/2t29rnw
http://bit.ly/2RyrD21
Submitted February 04, 2019 at 04:09PM by digitalinterruption
via reddit http://bit.ly/2t29rnw
Digitalinterruption
Multiple Vulnerabilities Found in Mobile Device Management Software | Digital Interruption Research
A few months ago during a penetration test, we stumbled upon a Windows based mobile device management [MDM] system named SureMDM. MDM systems aim to provide ...
GDPR Compliance: How Continuous Vulnerability Scanning is Key
http://bit.ly/2FX9UQv
Submitted February 04, 2019 at 07:48PM by nandodelgado
via reddit http://bit.ly/2Bi5gbS
http://bit.ly/2FX9UQv
Submitted February 04, 2019 at 07:48PM by nandodelgado
via reddit http://bit.ly/2Bi5gbS
Hackmetrix Blog
GDPR Compliance: How Continuous Vulnerability Scanning is Key - Hackmetrix Blog
Even months after interest in GDPR compliance peaked, some companies are struggling to make sure they comply with this new set of regulations aimed at protecting the privacy and security of European citizens. The regulation applies to businesses anywhere…
A crypto exchange can't repay $190 million it owes customers because its CEO died with the only password
http://bit.ly/2SbaAbu
Submitted February 04, 2019 at 10:53PM by wavetranscender
via reddit http://bit.ly/2UDspMY
http://bit.ly/2SbaAbu
Submitted February 04, 2019 at 10:53PM by wavetranscender
via reddit http://bit.ly/2UDspMY
Business Insider Nederland
A crypto exchange can't repay $190 million it owes customers because its CEO died with the only password
QuadrigaCX's founder and CEO, Gerald Cotten, who reportedly died in December, is believed to have had the sole ability to access the crypto exchange.
TEMPEST - We see your secrets
http://bit.ly/2GbbsGJ
Submitted February 04, 2019 at 11:35PM by digitalinterruption
via reddit http://bit.ly/2UDVB6E
http://bit.ly/2GbbsGJ
Submitted February 04, 2019 at 11:35PM by digitalinterruption
via reddit http://bit.ly/2UDVB6E
Digital Interruption
TEMPEST - We see your secrets | Digital Interruption
In this post we discuss how practical TEMPEST attacks are whether it's something most companies should worry about when considering cyber security.