Open sourcing ClusterFuzz
http://bit.ly/2t9OKpF
Submitted February 07, 2019 at 11:17PM by halbface
via reddit http://bit.ly/2Djnwlm
http://bit.ly/2t9OKpF
Submitted February 07, 2019 at 11:17PM by halbface
via reddit http://bit.ly/2Djnwlm
Google Open Source Blog
Open sourcing ClusterFuzz
The latest news from Google on open source releases, major projects, events, and student outreach programs.
Write-up from a CTF with OSINT, social engineering, physical intrusion & hacking
http://bit.ly/2WGXlxI
Submitted February 07, 2019 at 11:35PM by navlys
via reddit http://bit.ly/2TDdNgq
http://bit.ly/2WGXlxI
Submitted February 07, 2019 at 11:35PM by navlys
via reddit http://bit.ly/2TDdNgq
ClusterFuzz: A scalable fuzzing infrastructure which finds security and stability issues in software
http://bit.ly/2WLFVjy
Submitted February 08, 2019 at 01:50AM by Titokhan
via reddit http://bit.ly/2GcwOnb
http://bit.ly/2WLFVjy
Submitted February 08, 2019 at 01:50AM by Titokhan
via reddit http://bit.ly/2GcwOnb
CipherSweet: Searchable Encryption Doesn't Have to be Bitter
http://bit.ly/2Ujaueg
Submitted February 08, 2019 at 02:07AM by sarciszewski
via reddit http://bit.ly/2tcQeiZ
http://bit.ly/2Ujaueg
Submitted February 08, 2019 at 02:07AM by sarciszewski
via reddit http://bit.ly/2tcQeiZ
Paragonie
CipherSweet: Searchable Encryption Doesn't Have to be Bitter - Paragon Initiative Enterprises Blog
CipherSweet is a PHP library that provides searchable encryption for the most common cases a web developer is likely to encounter.
WSC2 - Websockets C2 PoC
http://bit.ly/2yYhzuJ
Submitted February 08, 2019 at 02:04AM by Agadius
via reddit http://bit.ly/2tb4qcg
http://bit.ly/2yYhzuJ
Submitted February 08, 2019 at 02:04AM by Agadius
via reddit http://bit.ly/2tb4qcg
GitHub
Arno0x/WSC2
A WebSocket C2 Tool. Contribute to Arno0x/WSC2 development by creating an account on GitHub.
Providing Applications Secure Access to AWS S3 - a comparison of 4 approaches
http://bit.ly/2WP2Drd
Submitted February 08, 2019 at 02:38AM by jalamok
via reddit http://bit.ly/2I1BLki
http://bit.ly/2WP2Drd
Submitted February 08, 2019 at 02:38AM by jalamok
via reddit http://bit.ly/2I1BLki
Hedgehoglab
AWS S3 security best practices - Part 2
In the second part of his guide to AWS S3 security, hedgehog lab's Joe Keilty evaluates four methods for securely providing applications with access to your S3 resources.
Downgrade Attack on TLS 1.3 and Vulnerabilities in Major TLS Libraries
http://bit.ly/2UPuWUj
Submitted February 08, 2019 at 02:53PM by Moocha
via reddit http://bit.ly/2GAITl8
http://bit.ly/2UPuWUj
Submitted February 08, 2019 at 02:53PM by Moocha
via reddit http://bit.ly/2GAITl8
reddit
r/netsec - Downgrade Attack on TLS 1.3 and Vulnerabilities in Major TLS Libraries
0 votes and 0 comments so far on Reddit
Swiss Post on e-voting: Discloses sourcecode and conducts public intrusion test from 25 February to 24 March 2019
http://bit.ly/2RKYa4R
Submitted February 08, 2019 at 04:38PM by 418_beep_boop
via reddit http://bit.ly/2WQg2PB
http://bit.ly/2RKYa4R
Submitted February 08, 2019 at 04:38PM by 418_beep_boop
via reddit http://bit.ly/2WQg2PB
Swiss Post
E-voting: disclosure of source code
Swiss Post believes that only a transparent and politically neutral e-voting solution can be successful in the long term. It is therefore publishing the source code of its solution.
Appsec Weekly Review: A vulnerability in e-ticket systems, malware targeting premium publishers, vulnerabilities in Gmail
http://bit.ly/2TCvsFe
Submitted February 08, 2019 at 05:55PM by KeyDutch
via reddit http://bit.ly/2HYH5Fe
http://bit.ly/2TCvsFe
Submitted February 08, 2019 at 05:55PM by KeyDutch
via reddit http://bit.ly/2HYH5Fe
Htbridge
Application Security Weekly Review, Week 6 2019
A vulnerability in e-ticketing systems used by major airlines, malvertising campaign targeting premium publishers, abuse of a long-standing feature in Google Gmail, and more.
Here’s the One Gmail Setting You Should Activate Now
http://bit.ly/2DlBy61
Submitted February 08, 2019 at 08:47PM by 7me9up
via reddit http://bit.ly/2TE3LMh
http://bit.ly/2DlBy61
Submitted February 08, 2019 at 08:47PM by 7me9up
via reddit http://bit.ly/2TE3LMh
LeakParser: A parser for last data dumps Collection #1 / Collection #2-5
http://bit.ly/2DpX1uG
Submitted February 08, 2019 at 09:32PM by peppermalware
via reddit http://bit.ly/2BqP1cp
http://bit.ly/2DpX1uG
Submitted February 08, 2019 at 09:32PM by peppermalware
via reddit http://bit.ly/2BqP1cp
GitHub
p3pperp0tts/leaks_parser
Parser for data dumps Collection #1 / Collection #2-5 - p3pperp0tts/leaks_parser
Public hacker test on Swiss Post’s e-voting system
http://bit.ly/2I36ddN
Submitted February 08, 2019 at 11:10PM by retrotronica
via reddit http://bit.ly/2SG4PSs
http://bit.ly/2I36ddN
Submitted February 08, 2019 at 11:10PM by retrotronica
via reddit http://bit.ly/2SG4PSs
www.evoting-blog.ch
Public hacker test on Swiss Post’s e-voting system
Swiss Post will be carrying out resilience testing, also known as a public intrusion test (PIT), on its e-voting system between 25 February and 24 March 2019. How does the intrusion test work and what happens if anything is found? The answers to the key questions.
Recently announced: Confidential Computing Challenge (C3)
http://bit.ly/2Sk7T7j
Submitted February 09, 2019 at 06:33AM by mrfitzy
via reddit http://bit.ly/2UQYuAX
http://bit.ly/2Sk7T7j
Submitted February 09, 2019 at 06:33AM by mrfitzy
via reddit http://bit.ly/2UQYuAX
Cloudplatformonline
Confidential Computing Challenge (C3)
In collaboration with Intel, Google Cloud is hosting a cybersecurity contest called the Confidential Computing Challenge. If you’re a developer, security researcher, or otherwise interested in developing safe apps, this is your chance to make an impact in…
Major Security Breach Found in Hospital and Supermarket Refrigeration Systems
http://bit.ly/2SjPuYA
Submitted February 09, 2019 at 05:59AM by westondeboer
via reddit http://bit.ly/2GxuJkX
http://bit.ly/2SjPuYA
Submitted February 09, 2019 at 05:59AM by westondeboer
via reddit http://bit.ly/2GxuJkX
Safety Detective
Major Security Breach Found in Hospital and Supermarket Refrigeration Systems
Major security breach uncovered in temperature control system of hospital and supermarket chains including Marks & Spencer, Ocado, Way-on, and others.
The story behind a feature in Windows called ASLR (Address Space Layout Randomization)
http://bit.ly/2RLoewZ
Submitted February 09, 2019 at 09:47AM by Titokhan
via reddit http://bit.ly/2tgOXr6
http://bit.ly/2RLoewZ
Submitted February 09, 2019 at 09:47AM by Titokhan
via reddit http://bit.ly/2tgOXr6
Threadreaderapp
Thread by @JohnLaTwC: "Story time. This one is about a feature in Windows called ASLR. It was 2005. We were working on Windows…
Thread by @JohnLaTwC: "Story time. This one is about a feature in Windows called ASLR. It was 2005. We were working on Windows Vista. Most re the release with the maligned User Account Control feature. For us in Trustworthy Computing it was the first […]"
Article: Best practices to consider before deploying a network virtual appliance on Azure
http://bit.ly/2E0KjDX
Submitted February 09, 2019 at 01:44PM by shehackspurple
via reddit http://bit.ly/2SCHBwr
http://bit.ly/2E0KjDX
Submitted February 09, 2019 at 01:44PM by shehackspurple
via reddit http://bit.ly/2SCHBwr
Microsoft
Best practices to consider before deploying a network virtual appli…
A network virtual appliance (NVA) is a virtual appliance primarily focused on network functions virtualization. A typical network virtual appliance involves various layers of four to seven function…
Hack The Box - Ypuffy write-up by 0xRick
http://bit.ly/2N16mxm
Submitted February 09, 2019 at 08:22PM by Ahm3d_H3sham
via reddit http://bit.ly/2TDhWB6
http://bit.ly/2N16mxm
Submitted February 09, 2019 at 08:22PM by Ahm3d_H3sham
via reddit http://bit.ly/2TDhWB6
0xRick Owned Root !
Hack The Box - Ypuffy
Quick Summary Hey guys today Ypuffy retired and this is my write-up. This box is a little different from the other boxes. It’s not windows or linux , it’s running openbsd which is a unix-like system. I really liked the privilege escalation in this box because…
Gorsair, a tool to remotely access exposed the Docker API of vulnerable Docker containers
http://bit.ly/2Snckyf
Submitted February 09, 2019 at 11:46PM by Ullaakut
via reddit http://bit.ly/2GvKAR4
http://bit.ly/2Snckyf
Submitted February 09, 2019 at 11:46PM by Ullaakut
via reddit http://bit.ly/2GvKAR4
GitHub
Ullaakut/Gorsair
Gorsair hacks its way into remote docker containers that expose their APIs. - Ullaakut/Gorsair
I scanned the whole country of Austria and this is what I've found
http://bit.ly/2RO53m5
Submitted February 10, 2019 at 01:42AM by _vavkamil_
via reddit http://bit.ly/2BtdnCu
http://bit.ly/2RO53m5
Submitted February 10, 2019 at 01:42AM by _vavkamil_
via reddit http://bit.ly/2BtdnCu
I scanned the whole country of Austria and this is what I've found
Personal blog of Christian Haschek
Evil Twin Attack - The Definitive Guide (Updated 2019)
http://bit.ly/2MWWCnJ
Submitted February 10, 2019 at 03:28AM by i_rsX
via reddit http://bit.ly/2RPTcE3
http://bit.ly/2MWWCnJ
Submitted February 10, 2019 at 03:28AM by i_rsX
via reddit http://bit.ly/2RPTcE3
rootsh3ll
Evil Twin Attack [The Definitive Guide] (Updated 2019)
A step-by-step guide to learn how to hack WiFi passwords (WEP/ WPA2/ WPS) in plain-text using the Evil Twin attack method
Guide for IR policies, plans, and more
http://bit.ly/2WLATDE
Submitted February 10, 2019 at 08:10AM by AllUrRootRBelong2Me
via reddit http://bit.ly/2SlYZ9n
http://bit.ly/2WLATDE
Submitted February 10, 2019 at 08:10AM by AllUrRootRBelong2Me
via reddit http://bit.ly/2SlYZ9n
Google Docs
SecKC - IR Manual (Draft).pdf