How to break PDF Signatures
https://ift.tt/2NrU4hH
Submitted February 25, 2019 at 01:20PM by hannob
via reddit https://ift.tt/2BQ1ZAW
https://ift.tt/2NrU4hH
Submitted February 25, 2019 at 01:20PM by hannob
via reddit https://ift.tt/2BQ1ZAW
reddit
r/netsec - How to break PDF Signatures
0 votes and 0 comments so far on Reddit
Manipulating top-sites rankings
https://ift.tt/2EwU79b
Submitted February 25, 2019 at 12:15PM by tomvangoethem
via reddit https://ift.tt/2TgyIcl
https://ift.tt/2EwU79b
Submitted February 25, 2019 at 12:15PM by tomvangoethem
via reddit https://ift.tt/2TgyIcl
Aaronlocker - a set of PowerShell noscripts that makes creating/maintaining AppLocker policies a breeze
https://ift.tt/2PGCmqh
Submitted February 25, 2019 at 06:24PM by snackoverflow
via reddit https://ift.tt/2XoYuuq
https://ift.tt/2PGCmqh
Submitted February 25, 2019 at 06:24PM by snackoverflow
via reddit https://ift.tt/2XoYuuq
GitHub
GitHub - microsoft/AaronLocker: Robust and practical application control for Windows
Robust and practical application control for Windows - GitHub - microsoft/AaronLocker: Robust and practical application control for Windows
CRXcavator a new free web tool to scan Chrome extensions and provide risk scores
https://ift.tt/2T4uCUO
Submitted February 25, 2019 at 08:12PM by lyoko37
via reddit https://ift.tt/2EefpHd
https://ift.tt/2T4uCUO
Submitted February 25, 2019 at 08:12PM by lyoko37
via reddit https://ift.tt/2EefpHd
Duo Security
CRXcavator: Democratizing Chrome Extension Security
To provide users and IT teams with actionable intelligence about Chrome extensions, Duo Labs is excited to announce the public beta of CRXcavator (rhymes with “excavator”), a free service that analyzes Chrome extensions and produces comprehensive security…
"Building Virtual Machine Labs" is now free!
https://ift.tt/2ICsxvj
Submitted February 25, 2019 at 11:33PM by BenjaminFlankin
via reddit https://ift.tt/2EvRWCL
https://ift.tt/2ICsxvj
Submitted February 25, 2019 at 11:33PM by BenjaminFlankin
via reddit https://ift.tt/2EvRWCL
Leanpub
Building Virtual Machine Labs
Learn everything there is to know about building and maintaining your own home or workplace virtual lab environment on the most popular hypervisors today!
Experiments, growth engineering, and the perils of not disguising your API routes: Part 1
https://ift.tt/2ICqU0F
Submitted February 25, 2019 at 11:27PM by JonLuca
via reddit https://ift.tt/2VjGQWO
https://ift.tt/2ICqU0F
Submitted February 25, 2019 at 11:27PM by JonLuca
via reddit https://ift.tt/2VjGQWO
JonLuca’s Blog
Experiments, growth engineering, and the perils of not disguising your API routes: Part 1
JonLuca’s Blog - A blog about tech, programming, and information
Investigating WinRAR Code Execution Vulnerability (CVE-2018-20250) at Internet Scale
https://ift.tt/2VjVy0g
Submitted February 26, 2019 at 03:13AM by ga-vu
via reddit https://ift.tt/2NuIUbV
https://ift.tt/2VjVy0g
Submitted February 26, 2019 at 03:13AM by ga-vu
via reddit https://ift.tt/2NuIUbV
reddit
r/netsec - Investigating WinRAR Code Execution Vulnerability (CVE-2018-20250) at Internet Scale
0 votes and 0 comments so far on Reddit
Digital extortionist offer high six figure salaries to accomplices | SC Media
https://ift.tt/2EwUDns
Submitted February 26, 2019 at 03:12AM by KeyDutch
via reddit https://ift.tt/2GJrJ63
https://ift.tt/2EwUDns
Submitted February 26, 2019 at 03:12AM by KeyDutch
via reddit https://ift.tt/2GJrJ63
SC Media
Digital extortionist offer high six figure salaries to accomplices | SC Media
Cybercriminals are promising salaries of up to $360,000 a year to accomplices who seek to extort high networth individuals such as C-Level executives, lawyers, and doctors.
Get valid HTTPS certificates for dev & pre-prod using step
https://ift.tt/2XpM71c
Submitted February 26, 2019 at 06:15AM by sourishkrout
via reddit https://ift.tt/2BV1ZiO
https://ift.tt/2XpM71c
Submitted February 26, 2019 at 06:15AM by sourishkrout
via reddit https://ift.tt/2BV1ZiO
Smallstep
Almost 80% of web page loads now use TLS. But almost no one uses TLS in development and pre-production. Why? Because it's hard. That sucks. When dev and staging don't match prod, bad things happen. Today's step release, version 0.8.6, makes using TLS in dev…
Malvertisers using polyglot BMP images to avoid detection and spread malicious redirects on mobile devices.
https://ift.tt/2SYpmCX
Submitted February 26, 2019 at 11:03AM by ascetik
via reddit https://ift.tt/2E77NGc
https://ift.tt/2SYpmCX
Submitted February 26, 2019 at 11:03AM by ascetik
via reddit https://ift.tt/2E77NGc
DEVCON | Ad Fraud Security®
Hacking group using Polyglot images to hide malvertsing attacks
What happens when an image is also javanoscript? And when that Image does not even need a payload to extract the malware from the image.. Well then you have a polyglot!
Retaining beacon source IPs with HAproxy relays
https://ift.tt/2Ef4xsp
Submitted February 26, 2019 at 12:37PM by _d3vzer0
via reddit https://ift.tt/2T4BUZz
https://ift.tt/2Ef4xsp
Submitted February 26, 2019 at 12:37PM by _d3vzer0
via reddit https://ift.tt/2T4BUZz
d3vzer0
Retaining beacon source IPs with HAProxy relays
During a red team exercise it's common to set up a relaying infrastructure to separate your external facing footprint from the actual command and control backend. Some of the popular light-weight options are to set up either HAProxy or NGINX on disposable…
New Malspam Campaign Targets WinRAR ACE Flaw to Deliver Malware
https://ift.tt/2GQpspN
Submitted February 26, 2019 at 02:19PM by ashique789
via reddit https://ift.tt/2tE4SjN
https://ift.tt/2GQpspN
Submitted February 26, 2019 at 02:19PM by ashique789
via reddit https://ift.tt/2tE4SjN
SecureReading
New Malspam Campaign Targets WinRAR ACE Flaw to Deliver Malware | SecureReading
Security researchers have discovered a new Malspam campaign exploiting the recently discovered WinRAR ACE flaw to install malware on the computer
Metasploit is adding a browser exploit for iOS 10
https://ift.tt/2EobuI3
Submitted February 26, 2019 at 03:21PM by strongheadwu
via reddit https://ift.tt/2EceAP7
https://ift.tt/2EobuI3
Submitted February 26, 2019 at 03:21PM by strongheadwu
via reddit https://ift.tt/2EceAP7
GitHub
Initial commit of CVE-2018-4233 for iOS 10 by timwr · Pull Request #11477 · rapid7/metasploit-framework
The demonstrates CVE-2018-4233 on iOS. This should work on all 64bit iOS 10 devices but currently the kernel exploit has kernel offsets hardcoded for an iPod7,1 10.1.1 until I manage to add liboffs...
Critical Remote Execution Flaw Discovered in WinRAR Impacting all Versions
https://ift.tt/2U000B3
Submitted February 26, 2019 at 07:10PM by ashique789
via reddit https://ift.tt/2H1zcfX
https://ift.tt/2U000B3
Submitted February 26, 2019 at 07:10PM by ashique789
via reddit https://ift.tt/2H1zcfX
SecureReading
Critical Remote Execution Flaw Discovered in WinRAR Impacting all Versions | SecureReading
Security researchers have discovered a critical remote execution vulnerability in WinRAR software affecting all versions.
Identifying Cobalt Strike team servers in the wild
https://ift.tt/2H4ff8c
Submitted February 26, 2019 at 09:11PM by Taqu
via reddit https://ift.tt/2Eh6CnK
https://ift.tt/2H4ff8c
Submitted February 26, 2019 at 09:11PM by Taqu
via reddit https://ift.tt/2Eh6CnK
Fox-IT International blog
Identifying Cobalt Strike team servers in the wild
How an anomalous space led to fingerprinting Summary On the 2nd of January 2019 Cobalt Strike version 3.13 was released, which contained a fix for an “extraneous space”. This uncommon w…
Alternatives for Google Search System
https://ift.tt/2EypCiY
Submitted February 26, 2019 at 09:06PM by Ullage34
via reddit https://ift.tt/2BXxQ2t
https://ift.tt/2EypCiY
Submitted February 26, 2019 at 09:06PM by Ullage34
via reddit https://ift.tt/2BXxQ2t
Surfshark
Is Google Spying on You? How to Manage Without Google Search - Surfshark
Google is by far the best search engine, with the most developed algorithms and the largest database of sites. Unfortunately, it is also well known for monitoring its users and using your search history to target ads.
GCP Bucket Enumeration and Privilege Escalation
https://ift.tt/2IDeqpq
Submitted February 26, 2019 at 09:38PM by hackers_and_builders
via reddit https://ift.tt/2GJfO8l
https://ift.tt/2IDeqpq
Submitted February 26, 2019 at 09:38PM by hackers_and_builders
via reddit https://ift.tt/2GJfO8l
Rhino Security Labs
Google Cloud Platform (GCP) Bucket Enumeration & Privilege Escalation
Google Storage is a GCP service that hosts files within GCP "buckets”. Enumerating vulnerable GCP buckets can identify potential cloud weaknesses.
Thunderclap: Modern computers are vulnerable to malicious peripheral devices
http://thunderclap.io/
Submitted February 26, 2019 at 10:24PM by zxombie
via reddit https://ift.tt/2To1Kag
http://thunderclap.io/
Submitted February 26, 2019 at 10:24PM by zxombie
via reddit https://ift.tt/2To1Kag
reddit
r/netsec - Thunderclap: Modern computers are vulnerable to malicious peripheral devices
0 votes and 0 comments so far on Reddit
Reversing challenge: Hack this smart contract, extract the 0.05 Ether and win a 200 Dai (USD) bounty.
https://ift.tt/2Vlk8h1
Submitted February 26, 2019 at 10:44PM by berndtzl
via reddit https://ift.tt/2XsKvDw
https://ift.tt/2Vlk8h1
Submitted February 26, 2019 at 10:44PM by berndtzl
via reddit https://ift.tt/2XsKvDw
Medium
ConsenSys Diligence Ethereum Hacking Challenge
ConsenSys Diligence is deploying vulnerable contracts on purpose.
New padding oracle attacks against TLS with CBC
https://ift.tt/2GMMCx9
Submitted February 27, 2019 at 01:39AM by xaocuc
via reddit https://ift.tt/2Vm6s5n
https://ift.tt/2GMMCx9
Submitted February 27, 2019 at 01:39AM by xaocuc
via reddit https://ift.tt/2Vm6s5n
GitHub
RUB-NDS/TLS-Padding-Oracles
New TLS Padding Oracles. Contribute to RUB-NDS/TLS-Padding-Oracles development by creating an account on GitHub.
Truly hidden Tor VPS hosting
https://ift.tt/2SueDe1
Submitted February 27, 2019 at 08:36AM by 1337shill
via reddit https://ift.tt/2Xskoww
https://ift.tt/2SueDe1
Submitted February 27, 2019 at 08:36AM by 1337shill
via reddit https://ift.tt/2Xskoww
reddit
r/netsec - Truly hidden Tor VPS hosting
0 votes and 0 comments so far on Reddit