New Ovidiy Stealer Password Stealing Malware Priced to Boost Sales
http://bit.ly/2tpRGP2
Submitted February 15, 2019 at 01:12AM by sdsfjrl123
via reddit http://bit.ly/2DGsJE0
http://bit.ly/2tpRGP2
Submitted February 15, 2019 at 01:12AM by sdsfjrl123
via reddit http://bit.ly/2DGsJE0
ArcTitan
New Ovidiy Stealer Password Stealing Malware Priced to Boost Sales - ArcTitan
The malware known as ‘Ovidiy Stealer’ is password stealing software that will capture login details and send the information to the hacker’s C2 server. As with most other password stealers, information is captured as it is entered into websites such as banking…
Actual high-level network security roles and skillsets
http://bit.ly/2TQV5SC
Submitted February 15, 2019 at 09:02AM by ahazred8vt
via reddit http://bit.ly/2GHPMkR
http://bit.ly/2TQV5SC
Submitted February 15, 2019 at 09:02AM by ahazred8vt
via reddit http://bit.ly/2GHPMkR
Innovative Phishing Campaign Uses Google Translate to Serve Phishing Webpage
http://bit.ly/2EcJQ1M
Submitted February 15, 2019 at 11:39AM by kotmana456
via reddit http://bit.ly/2V1xLC1
http://bit.ly/2EcJQ1M
Submitted February 15, 2019 at 11:39AM by kotmana456
via reddit http://bit.ly/2V1xLC1
WebTitan
Innovative Phishing Campaign Uses Google Translate to Serve Phishing Webpage - WebTitan
A new phishing campaign has been detected that uses Google Translate to mask the URL of the phishing web page on mobile devices. The tactic makes it appear that users are on an official Google website.
Facebook CSRF protection bypass which leads to Account Takeover.
http://bit.ly/2SxCizm
Submitted February 15, 2019 at 03:03PM by albinowax
via reddit http://bit.ly/2DLVpv8
http://bit.ly/2SxCizm
Submitted February 15, 2019 at 03:03PM by albinowax
via reddit http://bit.ly/2DLVpv8
Bug Bounty Write-ups
Facebook CSRF protection bypass which leads to Account Takeover.
Chashell, a Go reverse shell, cross-platform and communicating over DNS.
http://bit.ly/2Gt8hdC
Submitted February 15, 2019 at 08:58PM by phocean
via reddit http://bit.ly/2IcMSXL
http://bit.ly/2Gt8hdC
Submitted February 15, 2019 at 08:58PM by phocean
via reddit http://bit.ly/2IcMSXL
Sysdream
Sysdream, Chashell, a reverse shell over DNS
Sysdream, audits et formations en sécurité informatique Ethical Hacking PCI DSS Test d'intrusion
I just completed the Bandit wargame at Overthewire, here are my takeaways.
http://bit.ly/2SZnJno
Submitted February 15, 2019 at 09:19PM by SkullTech101
via reddit http://bit.ly/2GqALon
http://bit.ly/2SZnJno
Submitted February 15, 2019 at 09:19PM by SkullTech101
via reddit http://bit.ly/2GqALon
Musings of Sumit Ghosh
Notes from Overthewire Bandit
I solved the Bandit wargame by Overthewire over the last few days, and noted down anything new // interesting I learned. This is not a writeup in any way, you’re not likely to find solutions to specific questions here. This is more like study notes, mostly…
Nigerian election 2019: how to access social media and blocked websites during the election day
http://bit.ly/2DEsfOC
Submitted February 15, 2019 at 09:05PM by CaptainVictoorr
via reddit http://bit.ly/2tnXnNu
http://bit.ly/2DEsfOC
Submitted February 15, 2019 at 09:05PM by CaptainVictoorr
via reddit http://bit.ly/2tnXnNu
Medium
Nigerian election 2019: how to access social media and blocked websites during the election day
Nigeria’s presidential election approaches and will be held on 16th of February. According to recent calculations, about 84 million people…
Electrohunt Part 1: Hunting for the phishing campaigns on the Electrum network
http://bit.ly/2STyxDE
Submitted February 15, 2019 at 10:54PM by iphelix
via reddit http://bit.ly/2EcGgEP
http://bit.ly/2STyxDE
Submitted February 15, 2019 at 10:54PM by iphelix
via reddit http://bit.ly/2EcGgEP
Medium
Electrohunt Part 1: Hunting for the phishing campaigns on the Electrum network
Users of the Electrum Wallet, a popular desktop Bitcoin client, have been under a persistent attack since December of 2018. According to…
Pwning yet another insecure IP camera
http://bit.ly/2N4984W
Submitted February 15, 2019 at 08:05PM by mvanaltvorst
via reddit http://bit.ly/2S1jpja
http://bit.ly/2N4984W
Submitted February 15, 2019 at 08:05PM by mvanaltvorst
via reddit http://bit.ly/2S1jpja
Mauritsvanaltvorst
Achieving remote code execution on a Chinese IP camera
Background Cheap Chinese Internet of Things devices are on the rise. Unfortunately, security on these devices is often an afterthought. I recently got my hands…
Docker Container Escape PoC (CVE-2019-5736)
http://bit.ly/2N8CTBE
Submitted February 16, 2019 at 02:27AM by RedTerminalSession
via reddit http://bit.ly/2DGhStD
http://bit.ly/2N8CTBE
Submitted February 16, 2019 at 02:27AM by RedTerminalSession
via reddit http://bit.ly/2DGhStD
GitHub
Frichetten/CVE-2019-5736-PoC
PoC for CVE-2019-5736. Contribute to Frichetten/CVE-2019-5736-PoC development by creating an account on GitHub.
Medical Exploitation: You Are Now Diabetic
http://bit.ly/2GLKq88
Submitted February 16, 2019 at 02:48AM by faisalt
via reddit http://bit.ly/2tnh9IW
http://bit.ly/2GLKq88
Submitted February 16, 2019 at 02:48AM by faisalt
via reddit http://bit.ly/2tnh9IW
Depthsecurity
Medical Exploitation: You Are Now Diabetic
A few months ago, our CTO and hacker-in-chief, Jake Reynolds, bought a glucometer online along with all the necessary stuff to make it work. He thought it would make for an interesting project, as res
EngelKey - TOTP Hardware Token
http://bit.ly/2STurLM
Submitted February 16, 2019 at 06:17AM by Sid_Engel
via reddit http://bit.ly/2X5CBjy
http://bit.ly/2STurLM
Submitted February 16, 2019 at 06:17AM by Sid_Engel
via reddit http://bit.ly/2X5CBjy
reddit
r/2fa - EngelKey - TOTP Hardware Token
2 votes and 4 comments so far on Reddit
BitMitigate: A Rather Pleasant Alternative to Cloudflare
http://bit.ly/2N6jm4J
Submitted February 16, 2019 at 06:12AM by smartertechMS
via reddit http://bit.ly/2IcauM2
http://bit.ly/2N6jm4J
Submitted February 16, 2019 at 06:12AM by smartertechMS
via reddit http://bit.ly/2IcauM2
Epik Blog
Epik announces acquisition of BitMitigate.com
Epik.com is pleased to announce the completion of the acquisition of BitMitigate.com, a fast-growing innovator in the area of Content Delivery, Denial of Service protection, DNS resiliency and Virtual Private Networking.
Unveiling Amazon S3 bucket names
http://bit.ly/2DIPirv
Submitted February 16, 2019 at 05:51AM by localh0t
via reddit http://bit.ly/2IfJLOB
http://bit.ly/2DIPirv
Submitted February 16, 2019 at 05:51AM by localh0t
via reddit http://bit.ly/2IfJLOB
Medium
Unveiling Amazon S3 bucket names
Introduction
Hack The Box - Giddy Write-up by 0xRick
http://bit.ly/2SYo7Te
Submitted February 16, 2019 at 08:10PM by Ahm3d_H3sham
via reddit http://bit.ly/2N8HZ0E
http://bit.ly/2SYo7Te
Submitted February 16, 2019 at 08:10PM by Ahm3d_H3sham
via reddit http://bit.ly/2N8HZ0E
0xRick Owned Root !
Hack The Box - Giddy
Quick Summary Hey guys today Giddy retired and this is my write-up. Giddy was a nice windows box , This box had a nice sqli vulnerability which we will use to steal ntlm hashes and login , Then the privilege escalation was a Local Privilege Escalation vulnerability…
BlueHatIL 2019 Slides/Videos
http://bit.ly/2EdgEaG
Submitted February 16, 2019 at 08:07PM by campuscodi
via reddit http://bit.ly/2N7W1zw
http://bit.ly/2EdgEaG
Submitted February 16, 2019 at 08:07PM by campuscodi
via reddit http://bit.ly/2N7W1zw
reddit
r/netsec - BlueHatIL 2019 Slides/Videos
1 vote and 0 comments so far on Reddit
REST-ler: Automatic Intelligent REST API Fuzzing
http://bit.ly/2N8Wx0g
Submitted February 16, 2019 at 11:26PM by sudo-chmod-777
via reddit http://bit.ly/2GtRZkA
http://bit.ly/2N8Wx0g
Submitted February 16, 2019 at 11:26PM by sudo-chmod-777
via reddit http://bit.ly/2GtRZkA
Illegal streams, decrypting m3u8's, and building a better stream experience
http://bit.ly/2SXjw3N
Submitted February 17, 2019 at 07:32AM by JonLuca
via reddit http://bit.ly/2NhoWl3
http://bit.ly/2SXjw3N
Submitted February 17, 2019 at 07:32AM by JonLuca
via reddit http://bit.ly/2NhoWl3
JonLuca’s Blog
Illegal streams, decrypting m3u8’s, and building a better stream experience
Having not lived in the US for the majority of my life, I often needed to rely on illegal streams to watch America sports games. The experience on these streams is, to say the least, extremely poor. Most have some sort of crypto miner running in the background…
Latest Ursnif Trojan Campaign Highlights Need to Improve Anti-Phishing Defenses
http://bit.ly/2IwrOf9
Submitted February 17, 2019 at 11:51AM by kotmana456
via reddit http://bit.ly/2Gtpaol
http://bit.ly/2IwrOf9
Submitted February 17, 2019 at 11:51AM by kotmana456
via reddit http://bit.ly/2Gtpaol
SpamTitan
Latest Ursnif Trojan Campaign Highlights Need to Improve Anti-Phishing Defenses - SpamTitan
A new Ursnif Trojan campaign has been detected that uses a new variant of the malware which uses fileless techniques to avoid detection. In addition to the banking Trojan, GandCrab ransomware is also downloaded.
Tracking the trackers. Draw connections between noscripts and domains on website.
http://bit.ly/2GIMXA9
Submitted February 17, 2019 at 07:08PM by Mysterii8
via reddit http://bit.ly/2EdqklN
http://bit.ly/2GIMXA9
Submitted February 17, 2019 at 07:08PM by Mysterii8
via reddit http://bit.ly/2EdqklN
Medium
Tracking the trackers. Draw connections between noscripts and domains on website.
TL;DR
Build JA3 fingerprint mappings with Bro-Sysmon
https://sforce.co/2I82Imm
Submitted February 17, 2019 at 09:17PM by neslog
via reddit http://bit.ly/2BE132r
https://sforce.co/2I82Imm
Submitted February 17, 2019 at 09:17PM by neslog
via reddit http://bit.ly/2BE132r
Salesforce Engineering
How to Test Bro-Sysmon
How to stand up an environment to test Bro-Sysmon