Awesome Free Starter for Web App Pentesting: Their simulated labs include previously disclosed vulnerabilities on Hackerone
https://ift.tt/2NEQelu
Submitted March 01, 2019 at 07:13PM by payloadartist
via reddit https://ift.tt/2T5qAMF
https://ift.tt/2NEQelu
Submitted March 01, 2019 at 07:13PM by payloadartist
via reddit https://ift.tt/2T5qAMF
HackEDU
Interactive Cybersecurity Training | HackEDU
Interactive Cybersecurity Training. HackEDU offers comprehensive online Secure Development Training for your developers, engineers, and IT personnel to assist your organization in laying a foundation of security and application vulnerability prevention, assessment…
Eliminating opportunities for BGP accidents with traffic hijacking
https://ift.tt/2VnN9J8
Submitted March 01, 2019 at 06:55PM by atomlib_com
via reddit https://ift.tt/2H6gweW
https://ift.tt/2VnN9J8
Submitted March 01, 2019 at 06:55PM by atomlib_com
via reddit https://ift.tt/2H6gweW
Habr
Eliminating opportunities for traffic hijacking
Beatiful scheme for BGP connection to Qrator filtering network A little historical overview BGP hijacks — when an ISP originates an advertisement of address s...
Bypassing a restrictive JS sandox
https://ift.tt/2C1RD0E
Submitted March 02, 2019 at 04:49AM by EzequielTBH
via reddit https://ift.tt/2tMS6zg
https://ift.tt/2C1RD0E
Submitted March 02, 2019 at 04:49AM by EzequielTBH
via reddit https://ift.tt/2tMS6zg
Licencia para Hackear
Bypassing a restrictive JS sandbox
While participating in a bug bounty program, I found a site with a very
interesting functionality: it allowed me to filter some data based on a
user-controlled expression. I could put something like b
interesting functionality: it allowed me to filter some data based on a
user-controlled expression. I could put something like b
"Cheapest" sketchy hindi certs for sale
https://ift.tt/2VqLqmg
Submitted March 02, 2019 at 05:13AM by jonbonesjonesjohnson
via reddit https://ift.tt/2EtPStQ
https://ift.tt/2VqLqmg
Submitted March 02, 2019 at 05:13AM by jonbonesjonesjohnson
via reddit https://ift.tt/2EtPStQ
Inertia IT Solutions
512 Bit SSL Encryption- High Level of Encryption Technique
512 Bit SSL encryption integrates high-standard technology to ensure the security and safety of your website information.
Universal RCE with Ruby YAML.load
https://ift.tt/2EIAdIh
Submitted March 02, 2019 at 05:13PM by Gallus
via reddit https://ift.tt/2VuFIQj
https://ift.tt/2EIAdIh
Submitted March 02, 2019 at 05:13PM by Gallus
via reddit https://ift.tt/2VuFIQj
reddit
r/netsec - Universal RCE with Ruby YAML.load
0 votes and 0 comments so far on Reddit
Hack The Box - Access Write-up by 0xRick
https://ift.tt/2H89HJQ
Submitted March 02, 2019 at 08:06PM by Ahm3d_H3sham
via reddit https://ift.tt/2EIHDLO
https://ift.tt/2H89HJQ
Submitted March 02, 2019 at 08:06PM by Ahm3d_H3sham
via reddit https://ift.tt/2EIHDLO
0xRick Owned Root !
Hack The Box - Access
Quick Summary Hey guys today Access retired and this is my write-up. I don’t have too much to say about this box , It was a nice easy windows box and a good example of using runas in windows , Which is like sudo in linux and doas in openbsd (we used doas…
Introducing Reactive Password Hashing
https://ift.tt/2Heemdl
Submitted March 02, 2019 at 10:12PM by neverforgetdream
via reddit https://ift.tt/2EpizId
https://ift.tt/2Heemdl
Submitted March 02, 2019 at 10:12PM by neverforgetdream
via reddit https://ift.tt/2EpizId
reddit
r/netsec - Introducing Reactive Password Hashing
0 votes and 0 comments so far on Reddit
The Windows Sandbox Paradox: Slides by James Forshaw @ Nullcon
https://ift.tt/2VwHEb4
Submitted March 02, 2019 at 09:55PM by payloadartist
via reddit https://ift.tt/2C0XyTT
https://ift.tt/2VwHEb4
Submitted March 02, 2019 at 09:55PM by payloadartist
via reddit https://ift.tt/2C0XyTT
From HackerOne: The 2019 Hacker Report (survey results & statistics)
https://ift.tt/2NDpiCt
Submitted March 03, 2019 at 04:30AM by clairegiordano
via reddit https://ift.tt/2T9Y7W4
https://ift.tt/2NDpiCt
Submitted March 03, 2019 at 04:30AM by clairegiordano
via reddit https://ift.tt/2T9Y7W4
HackerOne
The 2019 Hacker Report
The 2019 Hacker Report brings the HackerOne community to life with statistics, interviews, insights, from the individuals working to make the internet a safer place.
In the report, you’ll learn how hackers earned over $19 million in bounties last year, how…
In the report, you’ll learn how hackers earned over $19 million in bounties last year, how…
If you’re not peppering your passwords, you are irresponsible.
https://ift.tt/2NFow7X
Submitted March 03, 2019 at 01:44PM by neverforgetdream
via reddit https://ift.tt/2UkfkbK
https://ift.tt/2NFow7X
Submitted March 03, 2019 at 01:44PM by neverforgetdream
via reddit https://ift.tt/2UkfkbK
reddit
r/netsec - If you’re not peppering your passwords, you are irresponsible.
0 votes and 3 comments so far on Reddit
Windows Exploit Suggester - Next Generation
https://ift.tt/2H8qa0R
Submitted March 04, 2019 at 03:32AM by fuckup1337
via reddit https://ift.tt/2SFVmGA
https://ift.tt/2H8qa0R
Submitted March 04, 2019 at 03:32AM by fuckup1337
via reddit https://ift.tt/2SFVmGA
GitHub
bitsadmin/wesng
Windows Exploit Suggester - Next Generation. Contribute to bitsadmin/wesng development by creating an account on GitHub.
What online radicalisation can teach us about cybersecurity
https://ift.tt/2NHxEsE
Submitted March 04, 2019 at 05:00PM by WhoopDeFreakinDo
via reddit https://ift.tt/2NFqGo8
https://ift.tt/2NHxEsE
Submitted March 04, 2019 at 05:00PM by WhoopDeFreakinDo
via reddit https://ift.tt/2NFqGo8
Digit
What online radicalisation can teach us about cybersecurity
Lisa Forte of Red Goat Cyber Security discusses the similarity between social engineering tactics employed by Islamic State recruiters and cybercriminals.
Hacking a BLE smartlock using bettercap and a kudu knife
https://ift.tt/2VAyb2u
Submitted March 04, 2019 at 10:19PM by s0pas
via reddit https://ift.tt/2IRg3A0
https://ift.tt/2VAyb2u
Submitted March 04, 2019 at 10:19PM by s0pas
via reddit https://ift.tt/2IRg3A0
Eye Oh Tee .cheap
Don't worry about being locked with Loccess
Loccess smart lock is promoted has being a lock to be used in luggage, bicycles and lockers. Besides opening with a keypad on the bottom of the device, this smart lock is able to be opened with your smart phone using BLE. I was able to get this smart lock
ITAG device tracks your keys and let others track and beep you.
https://ift.tt/2IU71lI
Submitted March 04, 2019 at 10:37PM by s0pas
via reddit https://ift.tt/2C3HeS2
https://ift.tt/2IU71lI
Submitted March 04, 2019 at 10:37PM by s0pas
via reddit https://ift.tt/2C3HeS2
Eye Oh Tee .cheap
ITAG - it tracks your keys and let others track you
This device sells for about $2 to $4 on AliExpress and is basically for tracking your keys, phone and comes with a special feature which is a button that when pressed, takes a selfie or record audio using your phone.It arrived like this:The seller announces…
Don't use Bcrypt
https://ift.tt/2Tgw7QF
Submitted March 05, 2019 at 02:53AM by neverforgetdream
via reddit https://ift.tt/2Ul31vU
https://ift.tt/2Tgw7QF
Submitted March 05, 2019 at 02:53AM by neverforgetdream
via reddit https://ift.tt/2Ul31vU
Unlimitednovelty
Don't use bcrypt
(Edit: Some numbers for you people who like numbers) If you're already using bcrypt, relax, you're fine, probably. However, if you're ...
CVE-2019-0539 Exploitation
https://ift.tt/2TyeYRy
Submitted March 05, 2019 at 03:52AM by v0yAgEr
via reddit https://ift.tt/2SJ6lzk
https://ift.tt/2TyeYRy
Submitted March 05, 2019 at 03:52AM by v0yAgEr
via reddit https://ift.tt/2SJ6lzk
Perception Point
CVE-2019-0539 Exploitation | Perception Point
Achieving full R\W primitive with CVE-2019-0539
Tracking 20,000 skiers and listening to their walkie talkie chats!
https://ift.tt/2Ev1IUl
Submitted March 05, 2019 at 03:48AM by almonie
via reddit https://ift.tt/2XDm6vh
https://ift.tt/2Ev1IUl
Submitted March 05, 2019 at 03:48AM by almonie
via reddit https://ift.tt/2XDm6vh
Pentestpartners
Hacking ski helmet audio | Pen Test Partners
I love snow sports, and I also like my tunes, so purchasing the Outdoor Tech CHIPS smart headphones was a no-brainer. They fit into audio-equipped helmets and
MouseJack: From Mouse to Shell - Part 1 - This blog post describes what is MouseJack, what to do if you are affected, and how to get a reverse shell using JackIt and Unicorn
https://ift.tt/2UjWzVZ
Submitted March 05, 2019 at 03:41AM by InfoSecJim
via reddit https://ift.tt/2SEec12
https://ift.tt/2UjWzVZ
Submitted March 05, 2019 at 03:41AM by InfoSecJim
via reddit https://ift.tt/2SEec12
Jim Wilbur's Blog
MouseJack: From Mouse to Shell - Part 1
MouseJack was publicly disclosed February 23rd 2016 and in 2017 an exploit for this vulnerability was released named JackIt.
Combining NTLM Relaying and Kerberos delegation
https://ift.tt/2H0lhaC
Submitted March 05, 2019 at 08:14AM by got_nations
via reddit https://ift.tt/2EAxBuy
https://ift.tt/2H0lhaC
Submitted March 05, 2019 at 08:14AM by got_nations
via reddit https://ift.tt/2EAxBuy
dirkjanm.io
The worst of both worlds: Combining NTLM Relaying and Kerberos delegation
After my in-depth post last month about unconstrained delegation, this post will discuss a different type of Kerberos delegation: resource-based constrained delegation. The content in this post is based on Elad Shamir’s Kerberos research and combined with…
Automated/declarative "pen testing as code"
https://ift.tt/2Tsi75H
Submitted March 05, 2019 at 12:47PM by DeviantJuiceBox
via reddit https://ift.tt/2XFDejR
https://ift.tt/2Tsi75H
Submitted March 05, 2019 at 12:47PM by DeviantJuiceBox
via reddit https://ift.tt/2XFDejR
reddit
r/blackhat - Automated/declarative "pen testing as code"
24 votes and 6 comments so far on Reddit
Facebook exploit – Confirm website visitor identities
https://ift.tt/2XDsh2z
Submitted March 05, 2019 at 02:38PM by TomAnthony
via reddit https://ift.tt/2HeL3Yc
https://ift.tt/2XDsh2z
Submitted March 05, 2019 at 02:38PM by TomAnthony
via reddit https://ift.tt/2HeL3Yc
www.tomanthony.co.uk
Facebook Information Leak - Webpages can confirm a user's ID
I discovered a Facebook bug which allows me to identify whether a visitor is logged in to a specific Facebook account. It can check hundreds of identities per second.