Inception, a tool written in go lang that detects configuration files and more on web server.
http://bit.ly/2De60yK
Submitted February 06, 2019 at 10:06PM by Abiral111
via reddit http://bit.ly/2Spu4sj
http://bit.ly/2De60yK
Submitted February 06, 2019 at 10:06PM by Abiral111
via reddit http://bit.ly/2Spu4sj
GitHub
proabiral/inception
A highly configurable tool to check for whatever you like against any number of hosts. - proabiral/inception
JellyHive - Set up Let's Encrypt certificate solution on Azure (xpost /r/dotnet)
http://bit.ly/2TzWGw5
Submitted February 06, 2019 at 11:26PM by smatsson
via reddit http://bit.ly/2BlWKbI
http://bit.ly/2TzWGw5
Submitted February 06, 2019 at 11:26PM by smatsson
via reddit http://bit.ly/2BlWKbI
JellyHive
Set up Let's Encrypt certificate solution on Azure
IntroductionIt’s 2019 and your site needs a SLL/TLS certificate. These can be quite expensiv, but fear not, there are solutions that are free!Enter Let’s Encrypt. Scenario and prerequisiteThe scenari
Open source hardware vs next generation hacking
http://bit.ly/2Add91v
Submitted February 07, 2019 at 01:19AM by edsonarantes2
via reddit http://bit.ly/2Gctqsk
http://bit.ly/2Add91v
Submitted February 07, 2019 at 01:19AM by edsonarantes2
via reddit http://bit.ly/2Gctqsk
PONDERWALL
Open Source Hardware Could Defend Against Next Generation Hacking
Making open-source hardware systems more available increases regular people’s security by giving them verifiable secure options.
Researcher Assaulted By A Vendor After Disclosing A Vulnerability
http://bit.ly/2UKfEjT
Submitted February 07, 2019 at 01:08AM by Titokhan
via reddit http://bit.ly/2TEvRHm
http://bit.ly/2UKfEjT
Submitted February 07, 2019 at 01:08AM by Titokhan
via reddit http://bit.ly/2TEvRHm
Secjuice.com
Researcher Assaulted After Disclosure
Following a serious vulnerability disclosure to Atrient, the security researcher who disclosed the vulnerability was assaulted by their COO at ICE.
Red team hackers crack DOD's MHS Genesis electronic heath records system -- FCW
http://bit.ly/2Shr95u
Submitted February 07, 2019 at 04:18AM by mc_security
via reddit http://bit.ly/2UECXLQ
http://bit.ly/2Shr95u
Submitted February 07, 2019 at 04:18AM by mc_security
via reddit http://bit.ly/2UECXLQ
FCW
Red team hackers crack DOD's MHS Genesis electronic heath records system -- FCW
The $5.5 billion commercial health record system is 'not survivable in a cyber-contested environment,' according to an internal Pentagon report.
OSCP Write-up Leaked By “Cyb3rsick “
http://bit.ly/2DhUYIG
Submitted February 07, 2019 at 10:56AM by icssindia
via reddit http://bit.ly/2UJY7ID
http://bit.ly/2DhUYIG
Submitted February 07, 2019 at 10:56AM by icssindia
via reddit http://bit.ly/2UJY7ID
reddit
r/netsec - OSCP Write-up Leaked By “Cyb3rsick “
1 vote and 0 comments so far on Reddit
Cache Deception at Medium (reported and fixed)
http://bit.ly/2Diuozv
Submitted February 07, 2019 at 11:05AM by HUCK45
via reddit http://bit.ly/2GrHXjg
http://bit.ly/2Diuozv
Submitted February 07, 2019 at 11:05AM by HUCK45
via reddit http://bit.ly/2GrHXjg
freeCodeCamp.org
Cache Deception: How I discovered a vulnerability in Medium and helped them fix it
In my previous post, I tried to demonstrate how powerful and cool reverse engineering Android apps can be. I did this by showing how to…
Yet another plea against using public WiFi
http://bit.ly/2SCa71e
Submitted February 07, 2019 at 03:37PM by atomlib_com
via reddit http://bit.ly/2Si1vh8
http://bit.ly/2SCa71e
Submitted February 07, 2019 at 03:37PM by atomlib_com
via reddit http://bit.ly/2Si1vh8
Habr
Yet another plea against using public WiFi
The thoughts I’m going to relate in this post may seem obvious and even trivial to some of you, but my experience with water cooler chats with my workmates s...
LOLbins and trojans: How the Ramnit Trojan spreads via sLoad in a cyberattack
http://bit.ly/2C2Ywye
Submitted February 07, 2019 at 10:34PM by Eliad-Cybereason
via reddit http://bit.ly/2GfXvHE
http://bit.ly/2C2Ywye
Submitted February 07, 2019 at 10:34PM by Eliad-Cybereason
via reddit http://bit.ly/2GfXvHE
Cybereason
LOLbins and trojans: How the Ramnit Trojan spreads via sLoad in a cyberattack
Cybereason detected an evasive infection technique used to spread a variant of the Ramnit banking Trojan as part of an Italian spam campaign. We investigate this attack, its use of sLoad, and its adoption of LOLbins to minimize discovery.
Open sourcing ClusterFuzz
http://bit.ly/2t9OKpF
Submitted February 07, 2019 at 11:17PM by halbface
via reddit http://bit.ly/2Djnwlm
http://bit.ly/2t9OKpF
Submitted February 07, 2019 at 11:17PM by halbface
via reddit http://bit.ly/2Djnwlm
Google Open Source Blog
Open sourcing ClusterFuzz
The latest news from Google on open source releases, major projects, events, and student outreach programs.
Write-up from a CTF with OSINT, social engineering, physical intrusion & hacking
http://bit.ly/2WGXlxI
Submitted February 07, 2019 at 11:35PM by navlys
via reddit http://bit.ly/2TDdNgq
http://bit.ly/2WGXlxI
Submitted February 07, 2019 at 11:35PM by navlys
via reddit http://bit.ly/2TDdNgq
ClusterFuzz: A scalable fuzzing infrastructure which finds security and stability issues in software
http://bit.ly/2WLFVjy
Submitted February 08, 2019 at 01:50AM by Titokhan
via reddit http://bit.ly/2GcwOnb
http://bit.ly/2WLFVjy
Submitted February 08, 2019 at 01:50AM by Titokhan
via reddit http://bit.ly/2GcwOnb
CipherSweet: Searchable Encryption Doesn't Have to be Bitter
http://bit.ly/2Ujaueg
Submitted February 08, 2019 at 02:07AM by sarciszewski
via reddit http://bit.ly/2tcQeiZ
http://bit.ly/2Ujaueg
Submitted February 08, 2019 at 02:07AM by sarciszewski
via reddit http://bit.ly/2tcQeiZ
Paragonie
CipherSweet: Searchable Encryption Doesn't Have to be Bitter - Paragon Initiative Enterprises Blog
CipherSweet is a PHP library that provides searchable encryption for the most common cases a web developer is likely to encounter.
WSC2 - Websockets C2 PoC
http://bit.ly/2yYhzuJ
Submitted February 08, 2019 at 02:04AM by Agadius
via reddit http://bit.ly/2tb4qcg
http://bit.ly/2yYhzuJ
Submitted February 08, 2019 at 02:04AM by Agadius
via reddit http://bit.ly/2tb4qcg
GitHub
Arno0x/WSC2
A WebSocket C2 Tool. Contribute to Arno0x/WSC2 development by creating an account on GitHub.
Providing Applications Secure Access to AWS S3 - a comparison of 4 approaches
http://bit.ly/2WP2Drd
Submitted February 08, 2019 at 02:38AM by jalamok
via reddit http://bit.ly/2I1BLki
http://bit.ly/2WP2Drd
Submitted February 08, 2019 at 02:38AM by jalamok
via reddit http://bit.ly/2I1BLki
Hedgehoglab
AWS S3 security best practices - Part 2
In the second part of his guide to AWS S3 security, hedgehog lab's Joe Keilty evaluates four methods for securely providing applications with access to your S3 resources.
Downgrade Attack on TLS 1.3 and Vulnerabilities in Major TLS Libraries
http://bit.ly/2UPuWUj
Submitted February 08, 2019 at 02:53PM by Moocha
via reddit http://bit.ly/2GAITl8
http://bit.ly/2UPuWUj
Submitted February 08, 2019 at 02:53PM by Moocha
via reddit http://bit.ly/2GAITl8
reddit
r/netsec - Downgrade Attack on TLS 1.3 and Vulnerabilities in Major TLS Libraries
0 votes and 0 comments so far on Reddit
Swiss Post on e-voting: Discloses sourcecode and conducts public intrusion test from 25 February to 24 March 2019
http://bit.ly/2RKYa4R
Submitted February 08, 2019 at 04:38PM by 418_beep_boop
via reddit http://bit.ly/2WQg2PB
http://bit.ly/2RKYa4R
Submitted February 08, 2019 at 04:38PM by 418_beep_boop
via reddit http://bit.ly/2WQg2PB
Swiss Post
E-voting: disclosure of source code
Swiss Post believes that only a transparent and politically neutral e-voting solution can be successful in the long term. It is therefore publishing the source code of its solution.
Appsec Weekly Review: A vulnerability in e-ticket systems, malware targeting premium publishers, vulnerabilities in Gmail
http://bit.ly/2TCvsFe
Submitted February 08, 2019 at 05:55PM by KeyDutch
via reddit http://bit.ly/2HYH5Fe
http://bit.ly/2TCvsFe
Submitted February 08, 2019 at 05:55PM by KeyDutch
via reddit http://bit.ly/2HYH5Fe
Htbridge
Application Security Weekly Review, Week 6 2019
A vulnerability in e-ticketing systems used by major airlines, malvertising campaign targeting premium publishers, abuse of a long-standing feature in Google Gmail, and more.
Here’s the One Gmail Setting You Should Activate Now
http://bit.ly/2DlBy61
Submitted February 08, 2019 at 08:47PM by 7me9up
via reddit http://bit.ly/2TE3LMh
http://bit.ly/2DlBy61
Submitted February 08, 2019 at 08:47PM by 7me9up
via reddit http://bit.ly/2TE3LMh
LeakParser: A parser for last data dumps Collection #1 / Collection #2-5
http://bit.ly/2DpX1uG
Submitted February 08, 2019 at 09:32PM by peppermalware
via reddit http://bit.ly/2BqP1cp
http://bit.ly/2DpX1uG
Submitted February 08, 2019 at 09:32PM by peppermalware
via reddit http://bit.ly/2BqP1cp
GitHub
p3pperp0tts/leaks_parser
Parser for data dumps Collection #1 / Collection #2-5 - p3pperp0tts/leaks_parser
Public hacker test on Swiss Post’s e-voting system
http://bit.ly/2I36ddN
Submitted February 08, 2019 at 11:10PM by retrotronica
via reddit http://bit.ly/2SG4PSs
http://bit.ly/2I36ddN
Submitted February 08, 2019 at 11:10PM by retrotronica
via reddit http://bit.ly/2SG4PSs
www.evoting-blog.ch
Public hacker test on Swiss Post’s e-voting system
Swiss Post will be carrying out resilience testing, also known as a public intrusion test (PIT), on its e-voting system between 25 February and 24 March 2019. How does the intrusion test work and what happens if anything is found? The answers to the key questions.