MikroTik Firewall & NAT Bypass
https://ift.tt/2EmRztZ
Submitted February 21, 2019 at 07:19PM by chicksdigthelongrun
via reddit https://ift.tt/2V95p91
https://ift.tt/2EmRztZ
Submitted February 21, 2019 at 07:19PM by chicksdigthelongrun
via reddit https://ift.tt/2V95p91
Medium
MikroTik Firewall & NAT Bypass
Exploitation from WAN to LAN
IDS/IPS malware download evasion | GitHub
https://ift.tt/2NjgIbP
Submitted February 21, 2019 at 07:10PM by Eplox
via reddit https://ift.tt/2GA1P4x
https://ift.tt/2NjgIbP
Submitted February 21, 2019 at 07:10PM by Eplox
via reddit https://ift.tt/2GA1P4x
GitHub
Eplox/evador
IDS/IPS malware download evasion. Contribute to Eplox/evador development by creating an account on GitHub.
Breaking out of Docker via runC - Explaining CVE-2019-5736
https://ift.tt/2IC84Xw
Submitted February 21, 2019 at 09:06PM by reddit_read_today
via reddit https://ift.tt/2SRJsyk
https://ift.tt/2IC84Xw
Submitted February 21, 2019 at 09:06PM by reddit_read_today
via reddit https://ift.tt/2SRJsyk
Twistlock
Breaking out of Docker via runC - Explaining CVE-2019-5736 | Twistlock
Last week (2019-02-11) a new vulnerability in runC was reported by its maintainers, originally found by Adam Iwaniuk and Borys Poplawski. Dubbed CVE-2019-5736, it affects Docker containers running in default settings and can be used by an attacker to gain…
Cloud Based fully Automated Reconnaissance Tool
https://ift.tt/2V7IVVO
Submitted February 21, 2019 at 10:15PM by SwordSec
via reddit https://ift.tt/2TawLhB
https://ift.tt/2V7IVVO
Submitted February 21, 2019 at 10:15PM by SwordSec
via reddit https://ift.tt/2TawLhB
Swordeye
SwordEye Recon Private Beta
Cloud Based Fully Automated Reconnaissance Tool
Venom - A Multi-hop Proxy for Penetration Testers Written in Go
https://ift.tt/2Nk6iJh
Submitted February 21, 2019 at 07:19PM by D1ive
via reddit https://ift.tt/2ICnISK
https://ift.tt/2Nk6iJh
Submitted February 21, 2019 at 07:19PM by D1ive
via reddit https://ift.tt/2ICnISK
GitHub
Dliv3/Venom
Venom - A Multi-hop Proxy for Penetration Testers Written in Go - Dliv3/Venom
Sensitive Information Disclosure in Android Banking App
https://ift.tt/2GDH0VV
Submitted February 22, 2019 at 03:15AM by plasticbag_spaceman
via reddit https://ift.tt/2IGWn1N
https://ift.tt/2GDH0VV
Submitted February 22, 2019 at 03:15AM by plasticbag_spaceman
via reddit https://ift.tt/2IGWn1N
Bishop Fox
Simple – Better Banking (Android) v. 2.45.0 – 2.45.3 - Sensitive Information Disclosure - Bishop Fox
The Simple – Better Banking Android application was affected by an information disclosure vulnerability that leaked user passwords to the keyboard autocomplete functionality. If exploited, this vulnerability could be leveraged to gain unauthorized access…
144 Million MyFitnessPal accounts now out there from the breach one year ago
https://ift.tt/1l33Xi1
Submitted February 22, 2019 at 03:05AM by PlannedObsolescence_
via reddit https://ift.tt/2Nju4F6
https://ift.tt/1l33Xi1
Submitted February 22, 2019 at 03:05AM by PlannedObsolescence_
via reddit https://ift.tt/2Nju4F6
Haveibeenpwned
Have I Been Pwned: Check if your email has been compromised in a data breach
Have I Been Pwned allows you to search across multiple data breaches to see if your email address or phone number has been compromised.
Drupal core - Highly critical - Remote Code Execution - CVE-2019-6340
https://ift.tt/2GUyuBh
Submitted February 22, 2019 at 08:44AM by sluglord14
via reddit https://ift.tt/2U2jghc
https://ift.tt/2GUyuBh
Submitted February 22, 2019 at 08:44AM by sluglord14
via reddit https://ift.tt/2U2jghc
reddit
r/netsec - Drupal core - Highly critical - Remote Code Execution - CVE-2019-6340
0 votes and 0 comments so far on Reddit
Vulnerabilities in Swiss E-Voting Code (Public Intrusion Test)
https://ift.tt/2SUoqPF
Submitted February 22, 2019 at 07:48PM by xorkiwi
via reddit https://ift.tt/2SVEn8u
https://ift.tt/2SUoqPF
Submitted February 22, 2019 at 07:48PM by xorkiwi
via reddit https://ift.tt/2SVEn8u
GitHub
setuid0-sec/Swiss_E-Voting_Publications
Our publications of the Swiss E-Voting Public Intrusion Test (PIT) - setuid0-sec/Swiss_E-Voting_Publications
Linux Kernel Through 4.20.10 Found Vulnerable to Arbitrary Code Execution
https://ift.tt/2txU9ay
Submitted February 22, 2019 at 10:04PM by jp8100lt
via reddit https://ift.tt/2E4OE85
https://ift.tt/2txU9ay
Submitted February 22, 2019 at 10:04PM by jp8100lt
via reddit https://ift.tt/2E4OE85
Coocoor
CVE-2019-8912
Exploiting Drupal8's REST RCE (SA-CORE-2019-003, CVE-2019-6340)
https://ift.tt/2BN4EeD
Submitted February 22, 2019 at 11:15PM by cfambionics
via reddit https://ift.tt/2U3pBZC
https://ift.tt/2BN4EeD
Submitted February 22, 2019 at 11:15PM by cfambionics
via reddit https://ift.tt/2U3pBZC
Ambionics
Exploiting Drupal8's REST RCE
Exploitation and mitigation bypasses for the new Drupal 8 RCE (SA-CORE-2019-003, CVE-2019-6340), targeting the REST module.
Drupalgeddon 2019: Code Injection, Langsec
https://ift.tt/2IvYiGi
Submitted February 23, 2019 at 12:18AM by rain5
via reddit https://ift.tt/2GGljEJ
https://ift.tt/2IvYiGi
Submitted February 23, 2019 at 12:18AM by rain5
via reddit https://ift.tt/2GGljEJ
reddit
r/netsec - Drupalgeddon 2019: Code Injection, Langsec
0 votes and 0 comments so far on Reddit
Hack The Box - Zipper Write-up by 0xRick
https://ift.tt/2U4GNxS
Submitted February 23, 2019 at 08:20PM by Ahm3d_H3sham
via reddit https://ift.tt/2U4mZee
https://ift.tt/2U4GNxS
Submitted February 23, 2019 at 08:20PM by Ahm3d_H3sham
via reddit https://ift.tt/2U4mZee
0xRick Owned Root !
Hack The Box - Zipper
Quick Sumarry Hey guys today Zipper retired and here’s my write-up. Owning user on this box was challenging because we have to exploit an RCE vulnerability which is not really easy and then we have to get a stable shell to be able to enumerate, for the privilege…
Video Downloader and Video Downloader Plus Chrome Extension Hijack Exploit - UXSS via CSP Bypass (~15.5 Million Affected)
https://ift.tt/2U9hcnO
Submitted February 24, 2019 at 06:10AM by mandatoryprogrammer
via reddit https://ift.tt/2BLUwCI
https://ift.tt/2U9hcnO
Submitted February 24, 2019 at 06:10AM by mandatoryprogrammer
via reddit https://ift.tt/2BLUwCI
The Hacker Blog
Video Downloader and Video Downloader Plus Chrome Extension Hijack Exploit - UXSS via CSP Bypass (~15.5 Million Affected)
A Hacker's Blog of Unintended Use and Insomnia.
Recovering the Master Password from a Locked Password Manager (1Password 4)
https://ift.tt/2tt83e1
Submitted February 24, 2019 at 08:20AM by dare_dick
via reddit https://ift.tt/2SUbdq4
https://ift.tt/2tt83e1
Submitted February 24, 2019 at 08:20AM by dare_dick
via reddit https://ift.tt/2SUbdq4
Independent Security Evaluators
Recovering the Master Password from a Locked Password Manager (1Password 4)
New tools, old methods. Down the RE’ing rabbit hole to exploit a fatal flaw in an otherwise great password manager (1Password 4).
Failure to Encrypt ePHI Costs Cancer Treatment and Research Center $4.34 Million - NetSec.News
https://ift.tt/2VdwJ5M
Submitted February 24, 2019 at 03:30PM by chincuntry12
via reddit https://ift.tt/2EsX4Hu
https://ift.tt/2VdwJ5M
Submitted February 24, 2019 at 03:30PM by chincuntry12
via reddit https://ift.tt/2EsX4Hu
NetSec.News
Failure to Encrypt ePHI Costs Cancer Treatment and Research Center $4.34 Million - NetSec.News
The HHS’ Office for Civil Rights has announced its third HIPAA financial penalty of 2018 - The 4th largest HIPAA penalty ever issued.
Novel Phishing Scam Uses Custom Web Fonts to Evade Detection
https://ift.tt/2BQpjOZ
Submitted February 24, 2019 at 06:59PM by mamavapa
via reddit https://ift.tt/2Eut3Ya
https://ift.tt/2BQpjOZ
Submitted February 24, 2019 at 06:59PM by mamavapa
via reddit https://ift.tt/2Eut3Ya
SpamTitan
Novel Phishing Scam Uses Custom Web Fonts to Evade Detection - SpamTitan
A new technique is being used by scammers to hide their phishing websites. This novel phishing attack uses a custom web font to render ciphertext as plaintext. The tactic is being used in phishing scams impersonating major U.S. banks.
Bug Allows Bypass of Face ID and Touch ID Authentication of WhatsApp iOS version
https://ift.tt/2BZC3Tx
Submitted February 24, 2019 at 06:47PM by ashique789
via reddit https://ift.tt/2VapBXY
https://ift.tt/2BZC3Tx
Submitted February 24, 2019 at 06:47PM by ashique789
via reddit https://ift.tt/2VapBXY
SecureReading
Bug Allows Bypass of Face ID and Touch ID Authentication of WhatsApp iOS version | SecureReading
A Reddit user has discovered a method to bypass recently introduced Face ID and Touch ID authentication for WhatsApp iOS version
"How a chain of multiple hacks leads me to database compromise"
https://ift.tt/2GHBxNY
Submitted February 24, 2019 at 11:57PM by logic_bomb_1
via reddit https://ift.tt/2Xmtg75
https://ift.tt/2GHBxNY
Submitted February 24, 2019 at 11:57PM by logic_bomb_1
via reddit https://ift.tt/2Xmtg75
Medium
Chain of hacks leading to Database Compromise!
Hi Guys, This is yet another a security vulnerability writeup about a chain of security vulnerabilities that linked up to compromise one…
New flaws in 4G, 5G allow attackers to intercept calls and track phone locations
https://ift.tt/2XuRFYe
Submitted February 25, 2019 at 01:10AM by lightlimegreen
via reddit https://ift.tt/2NpIoMh
https://ift.tt/2XuRFYe
Submitted February 25, 2019 at 01:10AM by lightlimegreen
via reddit https://ift.tt/2NpIoMh
TechCrunch
New flaws in 4G, 5G allow attackers to intercept calls and track phone locations
A group of academics have found three new security flaws in 4G and 5G, which they say can be used to intercept phone calls and track the locations of cell phone users. The findings are said to be the first time vulnerabilities have affected both 4G and the…
The Stoic Approach To conducting dedicated OSINT engagements
https://ift.tt/2GZJkpE
Submitted February 25, 2019 at 06:08AM by hp777us
via reddit https://ift.tt/2H5dGal
https://ift.tt/2GZJkpE
Submitted February 25, 2019 at 06:08AM by hp777us
via reddit https://ift.tt/2H5dGal
Infosec Writers Club
The Stoic Approach To OSINT
The deep thinkers approach to OSINT. What if all you had was a search engine? A complete and total focus on observable evidence linked by inferences.