Retaining beacon source IPs with HAproxy relays
https://ift.tt/2Ef4xsp
Submitted February 26, 2019 at 12:37PM by _d3vzer0
via reddit https://ift.tt/2T4BUZz
https://ift.tt/2Ef4xsp
Submitted February 26, 2019 at 12:37PM by _d3vzer0
via reddit https://ift.tt/2T4BUZz
d3vzer0
Retaining beacon source IPs with HAProxy relays
During a red team exercise it's common to set up a relaying infrastructure to separate your external facing footprint from the actual command and control backend. Some of the popular light-weight options are to set up either HAProxy or NGINX on disposable…
New Malspam Campaign Targets WinRAR ACE Flaw to Deliver Malware
https://ift.tt/2GQpspN
Submitted February 26, 2019 at 02:19PM by ashique789
via reddit https://ift.tt/2tE4SjN
https://ift.tt/2GQpspN
Submitted February 26, 2019 at 02:19PM by ashique789
via reddit https://ift.tt/2tE4SjN
SecureReading
New Malspam Campaign Targets WinRAR ACE Flaw to Deliver Malware | SecureReading
Security researchers have discovered a new Malspam campaign exploiting the recently discovered WinRAR ACE flaw to install malware on the computer
Metasploit is adding a browser exploit for iOS 10
https://ift.tt/2EobuI3
Submitted February 26, 2019 at 03:21PM by strongheadwu
via reddit https://ift.tt/2EceAP7
https://ift.tt/2EobuI3
Submitted February 26, 2019 at 03:21PM by strongheadwu
via reddit https://ift.tt/2EceAP7
GitHub
Initial commit of CVE-2018-4233 for iOS 10 by timwr · Pull Request #11477 · rapid7/metasploit-framework
The demonstrates CVE-2018-4233 on iOS. This should work on all 64bit iOS 10 devices but currently the kernel exploit has kernel offsets hardcoded for an iPod7,1 10.1.1 until I manage to add liboffs...
Critical Remote Execution Flaw Discovered in WinRAR Impacting all Versions
https://ift.tt/2U000B3
Submitted February 26, 2019 at 07:10PM by ashique789
via reddit https://ift.tt/2H1zcfX
https://ift.tt/2U000B3
Submitted February 26, 2019 at 07:10PM by ashique789
via reddit https://ift.tt/2H1zcfX
SecureReading
Critical Remote Execution Flaw Discovered in WinRAR Impacting all Versions | SecureReading
Security researchers have discovered a critical remote execution vulnerability in WinRAR software affecting all versions.
Identifying Cobalt Strike team servers in the wild
https://ift.tt/2H4ff8c
Submitted February 26, 2019 at 09:11PM by Taqu
via reddit https://ift.tt/2Eh6CnK
https://ift.tt/2H4ff8c
Submitted February 26, 2019 at 09:11PM by Taqu
via reddit https://ift.tt/2Eh6CnK
Fox-IT International blog
Identifying Cobalt Strike team servers in the wild
How an anomalous space led to fingerprinting Summary On the 2nd of January 2019 Cobalt Strike version 3.13 was released, which contained a fix for an “extraneous space”. This uncommon w…
Alternatives for Google Search System
https://ift.tt/2EypCiY
Submitted February 26, 2019 at 09:06PM by Ullage34
via reddit https://ift.tt/2BXxQ2t
https://ift.tt/2EypCiY
Submitted February 26, 2019 at 09:06PM by Ullage34
via reddit https://ift.tt/2BXxQ2t
Surfshark
Is Google Spying on You? How to Manage Without Google Search - Surfshark
Google is by far the best search engine, with the most developed algorithms and the largest database of sites. Unfortunately, it is also well known for monitoring its users and using your search history to target ads.
GCP Bucket Enumeration and Privilege Escalation
https://ift.tt/2IDeqpq
Submitted February 26, 2019 at 09:38PM by hackers_and_builders
via reddit https://ift.tt/2GJfO8l
https://ift.tt/2IDeqpq
Submitted February 26, 2019 at 09:38PM by hackers_and_builders
via reddit https://ift.tt/2GJfO8l
Rhino Security Labs
Google Cloud Platform (GCP) Bucket Enumeration & Privilege Escalation
Google Storage is a GCP service that hosts files within GCP "buckets”. Enumerating vulnerable GCP buckets can identify potential cloud weaknesses.
Thunderclap: Modern computers are vulnerable to malicious peripheral devices
http://thunderclap.io/
Submitted February 26, 2019 at 10:24PM by zxombie
via reddit https://ift.tt/2To1Kag
http://thunderclap.io/
Submitted February 26, 2019 at 10:24PM by zxombie
via reddit https://ift.tt/2To1Kag
reddit
r/netsec - Thunderclap: Modern computers are vulnerable to malicious peripheral devices
0 votes and 0 comments so far on Reddit
Reversing challenge: Hack this smart contract, extract the 0.05 Ether and win a 200 Dai (USD) bounty.
https://ift.tt/2Vlk8h1
Submitted February 26, 2019 at 10:44PM by berndtzl
via reddit https://ift.tt/2XsKvDw
https://ift.tt/2Vlk8h1
Submitted February 26, 2019 at 10:44PM by berndtzl
via reddit https://ift.tt/2XsKvDw
Medium
ConsenSys Diligence Ethereum Hacking Challenge
ConsenSys Diligence is deploying vulnerable contracts on purpose.
New padding oracle attacks against TLS with CBC
https://ift.tt/2GMMCx9
Submitted February 27, 2019 at 01:39AM by xaocuc
via reddit https://ift.tt/2Vm6s5n
https://ift.tt/2GMMCx9
Submitted February 27, 2019 at 01:39AM by xaocuc
via reddit https://ift.tt/2Vm6s5n
GitHub
RUB-NDS/TLS-Padding-Oracles
New TLS Padding Oracles. Contribute to RUB-NDS/TLS-Padding-Oracles development by creating an account on GitHub.
Truly hidden Tor VPS hosting
https://ift.tt/2SueDe1
Submitted February 27, 2019 at 08:36AM by 1337shill
via reddit https://ift.tt/2Xskoww
https://ift.tt/2SueDe1
Submitted February 27, 2019 at 08:36AM by 1337shill
via reddit https://ift.tt/2Xskoww
reddit
r/netsec - Truly hidden Tor VPS hosting
0 votes and 0 comments so far on Reddit
Firewall vs Hacker
https://ift.tt/2H5tDgs
Submitted February 27, 2019 at 11:56AM by william-harvey-07
via reddit https://ift.tt/2tFAgOU
https://ift.tt/2H5tDgs
Submitted February 27, 2019 at 11:56AM by william-harvey-07
via reddit https://ift.tt/2tFAgOU
reddit
r/netsec - Firewall vs Hacker
0 votes and 2 comments so far on Reddit
Startup created remotely customisable application layer WAF engine that runs on any PHP site.
https://ift.tt/2H6Lkw3
Submitted February 27, 2019 at 01:28PM by ded1cated
via reddit https://ift.tt/2BUyMEC
https://ift.tt/2H6Lkw3
Submitted February 27, 2019 at 01:28PM by ded1cated
via reddit https://ift.tt/2BUyMEC
WebARX
New Web Application Firewall Engine - WebARX Security
WebARX web application firewall engine now allows you to make your own firewall rules. Plans starting from $4.99/month - start your free trial now.
Recently Patched Drupal RCE Flaw Discovered Actively Exploited in the Wild
https://ift.tt/2Vp6Akz
Submitted February 27, 2019 at 02:59PM by ashique789
via reddit https://ift.tt/2ViW6mM
https://ift.tt/2Vp6Akz
Submitted February 27, 2019 at 02:59PM by ashique789
via reddit https://ift.tt/2ViW6mM
SecureReading
Recently Patched Drupal RCE Flaw Discovered Actively Exploited in the Wild | SecureReading
Threat actors have already started exploiting recently patched Drupal RCE flaw (CVE-2019-6340) to deliver cryptocurrency miners
SHAREit Multiple Vulnerabilities Enable Unrestricted Access to Adjacent Devices’ Files
https://ift.tt/2H7QBDJ
Submitted February 27, 2019 at 06:27PM by Titokhan
via reddit https://ift.tt/2Nv71r2
https://ift.tt/2H7QBDJ
Submitted February 27, 2019 at 06:27PM by Titokhan
via reddit https://ift.tt/2Nv71r2
Redforce
SHAREit Multiple Vulnerabilities Enable Unrestricted Access to Adjacent Devices’ Files
Two recently discovered vulnerabilities affecting SHAREit Android application
Recently Patched Drupal RCE Flaw Discovered Actively Exploited in the Wild
https://ift.tt/2Vp6Akz
Submitted February 27, 2019 at 07:23PM by ashique789
via reddit https://ift.tt/2EB2ws2
https://ift.tt/2Vp6Akz
Submitted February 27, 2019 at 07:23PM by ashique789
via reddit https://ift.tt/2EB2ws2
SecureReading
Recently Patched Drupal RCE Flaw Discovered Actively Exploited in the Wild | SecureReading
Threat actors have already started exploiting recently patched Drupal RCE flaw (CVE-2019-6340) to deliver cryptocurrency miners
CVE-2019-6977: imagecolormatch() OOB Heap Write Exploit
https://ift.tt/2TidyKP
Submitted February 27, 2019 at 07:18PM by cfambionics
via reddit https://ift.tt/2TePokF
https://ift.tt/2TidyKP
Submitted February 27, 2019 at 07:18PM by cfambionics
via reddit https://ift.tt/2TePokF
GitHub
cfreal/exploits
Some of my exploits. Contribute to cfreal/exploits development by creating an account on GitHub.
Leaking company secrets through your testing infrastructure
https://ift.tt/2BX4yAY
Submitted February 27, 2019 at 09:25PM by JonLuca
via reddit https://ift.tt/2tEQiIu
https://ift.tt/2BX4yAY
Submitted February 27, 2019 at 09:25PM by JonLuca
via reddit https://ift.tt/2tEQiIu
JonLuca’s Blog
Experiments, growth engineering, and exposing company secrets through your API: Part 1
JonLuca’s Blog - A blog about tech, programming, and information
Top 10 web hacking techniques of 2018: The Final Verdict
https://portswigger.net/blog/top-10-web-hacking-techniques-of-2018
Submitted February 27, 2019 at 09:20PM by Fugitif
via reddit https://ift.tt/2H5aBH9
https://portswigger.net/blog/top-10-web-hacking-techniques-of-2018
Submitted February 27, 2019 at 09:20PM by Fugitif
via reddit https://ift.tt/2H5aBH9
PortSwigger Research
Top 10 web hacking techniques of 2018
The results are in! After an impressive 59 nominations followed by a community vote to pick 15 finalists, a panel consisting of myself and noted researchers Nicolas Grégoire, Soroush Dalili and Filede
A Minimal Drupal Honeypot
https://ift.tt/2UbANnd
Submitted February 28, 2019 at 10:16AM by d1str0
via reddit https://ift.tt/2Ny3gB7
https://ift.tt/2UbANnd
Submitted February 28, 2019 at 10:16AM by d1str0
via reddit https://ift.tt/2Ny3gB7
GitHub
d1str0/Drupot
Drupal Honeypot. Contribute to d1str0/Drupot development by creating an account on GitHub.
Some issues with google data security
https://www.dashdevs.com/blog/how-google-сan-help-you-to-steal-somebodies-personal-data/
Submitted February 28, 2019 at 12:01PM by dashdevs
via reddit https://ift.tt/2SxzblY
https://www.dashdevs.com/blog/how-google-сan-help-you-to-steal-somebodies-personal-data/
Submitted February 28, 2019 at 12:01PM by dashdevs
via reddit https://ift.tt/2SxzblY
How Google Can Help You to Steal Somebody's Personal Data
A real-life story from our experience of configuring the G-Suit for the company and how it ended in us unintentionally stealing personal data.