Azeria-labs: ARM heap exploitation series
https://ift.tt/2HfI3L7
Submitted March 06, 2019 at 12:02PM by xchg_ax_ax
via reddit https://ift.tt/2TvRNHL
https://ift.tt/2HfI3L7
Submitted March 06, 2019 at 12:02PM by xchg_ax_ax
via reddit https://ift.tt/2TvRNHL
Azeria-Labs
Heap Exploitation Part 1: Understanding the Glibc Heap Implementation
How to Assess and Breach the Physical Environment for a Red Team
https://ift.tt/2HfA5BG
Submitted March 06, 2019 at 10:44PM by pentest4life
via reddit https://ift.tt/2tQsEZM
https://ift.tt/2HfA5BG
Submitted March 06, 2019 at 10:44PM by pentest4life
via reddit https://ift.tt/2tQsEZM
Medium
Top 5 Ways The Red Team breached and assessed the Physical Environment
We tailgate, skim and clone. Social engineer and deceived to employee and CISO alike, to get onsite and hit our “Breach” Physical, or…
[CVE-2019-5786] Chrome / Chromium severe bug
https://ift.tt/2EpHv2l
Submitted March 07, 2019 at 12:16AM by cowreth
via reddit https://ift.tt/2NMq1RK
https://ift.tt/2EpHv2l
Submitted March 07, 2019 at 12:16AM by cowreth
via reddit https://ift.tt/2NMq1RK
Chrome Releases
Stable Channel Update for Desktop
The stable channel has been updated to 72.0.3626.121 for Windows, Mac, and Linux, which will roll out over the coming days/weeks. Secur...
Tails on steroids: Vagabond Workstation
https://ift.tt/2XJiCY0
Submitted March 07, 2019 at 03:15AM by 1337shill
via reddit https://ift.tt/2SPytAO
https://ift.tt/2XJiCY0
Submitted March 07, 2019 at 03:15AM by 1337shill
via reddit https://ift.tt/2SPytAO
reddit
r/netsec - Tails on steroids: Vagabond Workstation
0 votes and 0 comments so far on Reddit
An Hour With Ghidra : The Good and The Ugly
https://ift.tt/2ESbLEc
Submitted March 07, 2019 at 08:53AM by fady_othman
via reddit https://ift.tt/2UrnPlm
https://ift.tt/2ESbLEc
Submitted March 07, 2019 at 08:53AM by fady_othman
via reddit https://ift.tt/2UrnPlm
My last submission wasn't "technical" enough
https://ift.tt/2VE67Lz
Submitted March 07, 2019 at 08:52AM by 1337shill
via reddit https://ift.tt/2Cc8b6h
https://ift.tt/2VE67Lz
Submitted March 07, 2019 at 08:52AM by 1337shill
via reddit https://ift.tt/2Cc8b6h
GitHub
vagabondworkstation/hedron
Mirror for http://a3dninefan3vhkhkw36cgesk4hlfzwkbj3done4iscp3na7jckrcypid.onion - vagabondworkstation/hedron
An Exercise in Practical Container Escapology [Exploit]
https://ift.tt/2EGp1dZ
Submitted March 07, 2019 at 07:11PM by elon2020
via reddit https://ift.tt/2tTV2dv
https://ift.tt/2EGp1dZ
Submitted March 07, 2019 at 07:11PM by elon2020
via reddit https://ift.tt/2tTV2dv
Capsule8
Container Escape: You Think That's Air You're Breathing? • Capsule8
Container escape exercise tutorial from C8 Labs with working exploit leveraging vulnerabilities CVE-2017-18344 and CVE-2017-1000112.
Nearby Threats: Reversing, Analyzing, and Attacking Google’s ‘Nearby Connections’ on Android
https://ift.tt/2EUgSE2
Submitted March 07, 2019 at 09:24PM by franconezappa
via reddit https://ift.tt/2VLzxHV
https://ift.tt/2EUgSE2
Submitted March 07, 2019 at 09:24PM by franconezappa
via reddit https://ift.tt/2VLzxHV
Daniele Antonioli
Nearby Threats: Reversing, Analyzing, and Attacking Google’s ‘Nearby Connections’ on Android | Daniele Antonioli
Google’s Nearby Connections API enables any Android (and Android Things) application to provide proximity-based services to its users, regardless of their network connectivity. The API uses Bluetooth BR/EDR, Bluetooth LE and Wi-Fi to let “nearby” …
Security Researchers Discover 6 More Polyglot Malware Exploits Inside of Ad Networks
https://ift.tt/2EIJmQ1
Submitted March 07, 2019 at 09:03PM by ascetik
via reddit https://ift.tt/2XH8kro
https://ift.tt/2EIJmQ1
Submitted March 07, 2019 at 09:03PM by ascetik
via reddit https://ift.tt/2XH8kro
Adweek
Cybersecurity Firm Finds Increasingly Complex and Common Malware Inside of Ad Networks
Devcon says it’s found several polyglots.
Facebook Messenger server random memory exposure through corrupted GIF image
https://ift.tt/2IVtezW
Submitted March 07, 2019 at 10:27PM by albinowax
via reddit https://ift.tt/2TAWXCj
https://ift.tt/2IVtezW
Submitted March 07, 2019 at 10:27PM by albinowax
via reddit https://ift.tt/2TAWXCj
Vulnano
Facebook Messenger server random memory exposure through corrupted GIF image
Notepad++ drops code signing [xpost /r/programming]
https://ift.tt/2H3cIMo
Submitted March 08, 2019 at 06:54AM by CodeBlock
via reddit https://ift.tt/2EWLlkT
https://ift.tt/2H3cIMo
Submitted March 08, 2019 at 06:54AM by CodeBlock
via reddit https://ift.tt/2EWLlkT
reddit
r/netsec - Notepad++ drops code signing [xpost /r/programming]
0 votes and 0 comments so far on Reddit
Tomcat exploit variant : host-manager
https://ift.tt/2Hm7WZV
Submitted March 08, 2019 at 02:52PM by __SamBeckS__
via reddit https://ift.tt/2Ce8k9j
https://ift.tt/2Hm7WZV
Submitted March 08, 2019 at 02:52PM by __SamBeckS__
via reddit https://ift.tt/2Ce8k9j
3 million vehicles can be unlocked remotely via trivially discovered web API vulnerability
https://ift.tt/2VEGMB6
Submitted March 08, 2019 at 04:55PM by cybergibbons
via reddit https://ift.tt/2UrY3xs
https://ift.tt/2VEGMB6
Submitted March 08, 2019 at 04:55PM by cybergibbons
via reddit https://ift.tt/2UrY3xs
Pentestpartners
Gone in six seconds? Exploiting car alarms | Pen Test Partners
Key relay attacks against keyless entry vehicles are well known. Many 3rd party car alarm vendors market themselves as solutions to this. We have shown that
WebTech, identify technologies used on websites
https://ift.tt/2TDS3Vc
Submitted March 08, 2019 at 07:21PM by smaury
via reddit https://ift.tt/2HlUzZt
https://ift.tt/2TDS3Vc
Submitted March 08, 2019 at 07:21PM by smaury
via reddit https://ift.tt/2HlUzZt
Shielder
WebTech, identify technologies used on websites - Shielder
WebTech is a tool and a Burp extension capable of analyzing web pages and report used web technologies, frameworks and versions.
Mapping the state of the .gov.uk domain space
https://ift.tt/2SU02ca
Submitted March 09, 2019 at 01:33AM by Quick_Stick
via reddit https://ift.tt/2TplNFV
https://ift.tt/2SU02ca
Submitted March 09, 2019 at 01:33AM by Quick_Stick
via reddit https://ift.tt/2TplNFV
GitHub
tg12/MappingGovUKDomains
A look into the "state" of the .gov.uk namespace. Contribute to tg12/MappingGovUKDomains development by creating an account on GitHub.
Multiple Persistent XSS into RCE Walkthrough -- Cantemo Portal Version 3.8.4
https://ift.tt/2EQsFSO
Submitted March 09, 2019 at 02:54AM by SilentEcho
via reddit https://ift.tt/2TnMWcm
https://ift.tt/2EQsFSO
Submitted March 09, 2019 at 02:54AM by SilentEcho
via reddit https://ift.tt/2TnMWcm
Bishop Fox
Cantemo Portal Version 3.8.4 - Cross-Site Scripting - Bishop Fox
Product Vendor Cantemo AB Product Denoscription Cantemo AB is a software systems and technology vendor for major media outlets. The Cantemo Portal application is a high-performance media asset management tool. The latest version at the time of this research…
Russian hackers are eight times faster than North Korean groups
https://ift.tt/2Hqrf47
Submitted March 09, 2019 at 02:56PM by Akkeri
via reddit https://ift.tt/2VOs9ez
https://ift.tt/2Hqrf47
Submitted March 09, 2019 at 02:56PM by Akkeri
via reddit https://ift.tt/2VOs9ez
MIT Technology Review
Russian hackers are eight times faster than North Korean groups
Russian hackers are way ahead of the next-fastest state-sponsored hackers, North Korea, who themselves are nearly twice as fast as Chinese groups, according to a new report by US cybersecurity firm Crowdstrike.
Hack The Box - Ethereal write-up by 0xRick
https://ift.tt/2F08dQG
Submitted March 09, 2019 at 08:28PM by Ahm3d_H3sham
via reddit https://ift.tt/2UqHSjO
https://ift.tt/2F08dQG
Submitted March 09, 2019 at 08:28PM by Ahm3d_H3sham
via reddit https://ift.tt/2UqHSjO
0xRick Owned Root !
Hack The Box - Ethereal
Introduction Hey guys today Ethereal retired and here is my write-up about it. And as the difficulty says , It’s insane ! The most annoying part about this box is that it was very hard to enumerate because we only get a blind RCE and the firewall rules made…
NMAP 101 - RTFM
https://ift.tt/2H9q0XO
Submitted March 10, 2019 at 12:43AM by ZephrX112
via reddit https://ift.tt/2HnGT0i
https://ift.tt/2H9q0XO
Submitted March 10, 2019 at 12:43AM by ZephrX112
via reddit https://ift.tt/2HnGT0i
ZeroSec - Adventures In Information Security
NMAP Tips: RTFM?
NMAP TL;DR
It's a tool used for portscanning and this post will explore some of the common
and useful flags that can be used while scanning to pick up usful information
about targets.
What Is NMAP?
Nmap or Network mapper is an open source tool for network…
It's a tool used for portscanning and this post will explore some of the common
and useful flags that can be used while scanning to pick up usful information
about targets.
What Is NMAP?
Nmap or Network mapper is an open source tool for network…
Writing a Password Protected Reverse Shell (Linux/x64)
https://ift.tt/2TGuqLF
Submitted March 10, 2019 at 10:23PM by h41zum
via reddit https://ift.tt/2F0XyoP
https://ift.tt/2TGuqLF
Submitted March 10, 2019 at 10:23PM by h41zum
via reddit https://ift.tt/2F0XyoP
Medium
Writing a Password Protected Reverse Shell (Linux/x64)
Let’s write some shellcode, shall we?
SharPyShell - tiny and obfuscated ASP.NET webshell for C# web applications
https://ift.tt/2UqJCtf
Submitted March 11, 2019 at 04:10AM by splinter_code
via reddit https://ift.tt/2SVeP6r
https://ift.tt/2UqJCtf
Submitted March 11, 2019 at 04:10AM by splinter_code
via reddit https://ift.tt/2SVeP6r
GitHub
antonioCoco/SharPyShell
SharPyShell - tiny and obfuscated ASP.NET webshell for C# web applications - antonioCoco/SharPyShell