Citrix Got Hacked
https://ift.tt/2TLjEnv
Submitted March 15, 2019 at 11:59PM by chexss
via reddit https://ift.tt/2XTLFZ4
https://ift.tt/2TLjEnv
Submitted March 15, 2019 at 11:59PM by chexss
via reddit https://ift.tt/2XTLFZ4
LinkedIn Hank
https://ift.tt/1sxqmMI
Submitted March 16, 2019 at 12:43AM by Xidium426
via reddit https://ift.tt/2Ob6Otu
https://ift.tt/1sxqmMI
Submitted March 16, 2019 at 12:43AM by Xidium426
via reddit https://ift.tt/2Ob6Otu
Motherboard
Another Day, Another Hack: 117 Million LinkedIn Emails And Passwords
Four years later, the 2012 LinkedIn breach just got way worse.
One-Way Shellcode for firewall evasion using Out Of Band data
https://ift.tt/2Y1f1ol
Submitted March 16, 2019 at 12:27AM by bmerino
via reddit https://ift.tt/2W0DJDB
https://ift.tt/2Y1f1ol
Submitted March 16, 2019 at 12:27AM by bmerino
via reddit https://ift.tt/2W0DJDB
Shelliscoming
One-Way Shellcode for firewall evasion using Out Of Band data
In a recent post I was talking about a shellcode technique to bypass firewalls based on the socket's lifetime which could be useful for ve...
RCE on Steam Client via buffer overflow in Server Info
https://ift.tt/2u9U2lB
Submitted March 16, 2019 at 07:01AM by eexiled
via reddit https://ift.tt/2UDhV0v
https://ift.tt/2u9U2lB
Submitted March 16, 2019 at 07:01AM by eexiled
via reddit https://ift.tt/2UDhV0v
HackerOne
Valve disclosed on HackerOne: RCE on Steam Client via buffer...
## Introduction
In Steam and other valve games (CSGO, Half-Life, TF2) there is a functionality to find game servers called the server browser. In order to retrieve the information about these...
In Steam and other valve games (CSGO, Half-Life, TF2) there is a functionality to find game servers called the server browser. In order to retrieve the information about these...
TIL: Beto O' Rourke not only was a founding member of the cDc but he also came up with the name
https://ift.tt/2F664l3
Submitted March 16, 2019 at 02:54PM by snatchington
via reddit https://ift.tt/2TFLIJr
https://ift.tt/2F664l3
Submitted March 16, 2019 at 02:54PM by snatchington
via reddit https://ift.tt/2TFLIJr
Hack The Box - Carrier write-up by 0xRick
https://ift.tt/2CoLhsr
Submitted March 16, 2019 at 07:54PM by Ahm3d_H3sham
via reddit https://ift.tt/2UF9qSK
https://ift.tt/2CoLhsr
Submitted March 16, 2019 at 07:54PM by Ahm3d_H3sham
via reddit https://ift.tt/2UF9qSK
0xRick Owned Root !
Hack The Box - Carrier
Quick Summary Hey guys today Carrier retired and here is my write-up about it. User on this box wasn’t hard to get , but for root it’s a different thing because we will go through some networking tricks and we will perform an attack called bgp hijacking.…
PowerHub: Transfer PowerShell modules and binaries and execute them in-memory while bypassing endpoint protection and application whitelisting
https://ift.tt/2Y4ZKDl
Submitted March 16, 2019 at 09:05PM by 0xfffffg
via reddit https://ift.tt/2u9GZAH
https://ift.tt/2Y4ZKDl
Submitted March 16, 2019 at 09:05PM by 0xfffffg
via reddit https://ift.tt/2u9GZAH
GitHub
AdrianVollmer/PowerHub
A web application to transfer PowerShell modules, executables, snippets and files - AdrianVollmer/PowerHub
Analysis of some Metasploit network payloads (Linux/x64)
https://ift.tt/2TTjuui
Submitted March 16, 2019 at 11:11PM by h41zum
via reddit https://ift.tt/2TTpNhj
https://ift.tt/2TTjuui
Submitted March 16, 2019 at 11:11PM by h41zum
via reddit https://ift.tt/2TTpNhj
Medium
Analysis of some Metasploit network payloads (Linux/x64)
3 msfvenom payloads under the microscope
Know Your [roots]#
https://ift.tt/2W5DzuS
Submitted March 16, 2019 at 11:05PM by Bowserjklol
via reddit https://ift.tt/2Hqk4db
https://ift.tt/2W5DzuS
Submitted March 16, 2019 at 11:05PM by Bowserjklol
via reddit https://ift.tt/2Hqk4db
Codecatoctin
Know Your [roots]#
After recently wrapping up Forshaw's awesome Attacking Network Protocols , it felt like a good time to take a break from the purely technic...
Electronic tools used by car thieves
https://ift.tt/2J5sDeZ
Submitted March 16, 2019 at 10:24PM by mycall
via reddit https://ift.tt/2Y3kET2
https://ift.tt/2J5sDeZ
Submitted March 16, 2019 at 10:24PM by mycall
via reddit https://ift.tt/2Y3kET2
Punch Newspapers
Electronic tools used by car thieves
Kunle Shonaike Developments in vehicle security over recent years have made it increasingly difficult for thieves to steal vehicles by conventional means and this has led to thieves using burglary...
Bypass MaxScales DB Firewall for MySQL/MariaDB
https://ift.tt/2OaXPIz
Submitted March 17, 2019 at 12:09AM by TarqDirtyToMe
via reddit https://ift.tt/2HCZe9y
https://ift.tt/2OaXPIz
Submitted March 17, 2019 at 12:09AM by TarqDirtyToMe
via reddit https://ift.tt/2HCZe9y
Christopher Tarquini's Blog
Bypassing MaxScale's Firewall and Masking Rules
Learn how to bypass MaxScale's Firewall and Masking filters using SQL comments
Nemesida WAF Free for DEB/RHEL, good signature database and minimum of False Positives
https://ift.tt/2FgAbru
Submitted March 17, 2019 at 03:32AM by romanovroman
via reddit https://ift.tt/2F7bxrS
https://ift.tt/2FgAbru
Submitted March 17, 2019 at 03:32AM by romanovroman
via reddit https://ift.tt/2F7bxrS
Nemesida WAF - complex site protection system with machine learning
Nemesida WAF Free
«Nemesida WAF» Free provides the base security level of web-applications and API. «Nemesida WAF» Free has simple installation and exploitation, doesn’t have high requirements to hardware resources.
Fileless UAC Bypass in Windows Store Binary
https://ift.tt/2FdOk7k
Submitted March 17, 2019 at 05:34AM by IUsedToBeACave
via reddit https://ift.tt/2CndsYE
https://ift.tt/2FdOk7k
Submitted March 17, 2019 at 05:34AM by IUsedToBeACave
via reddit https://ift.tt/2CndsYE
Active Cyber
Fileless UAC Bypass in Windows Store Binary
Based on the increased interest in User Account Control (UAC) bypass research as of late, we've decided to read more on the subject and attempt to identify some sort of a pattern which ultimately led...
Subdomain Bruteforce for Windows
https://ift.tt/2TF7rBi
Submitted March 17, 2019 at 07:12AM by endless
via reddit https://ift.tt/2O8AiYN
https://ift.tt/2TF7rBi
Submitted March 17, 2019 at 07:12AM by endless
via reddit https://ift.tt/2O8AiYN
GitHub
visualbasic6/subdomain-bruteforce
a subdomain brute forcing tool for windows. Contribute to visualbasic6/subdomain-bruteforce development by creating an account on GitHub.
APK Utilities - a collection of noscript to modify Android APK files
https://ift.tt/2FinhZS
Submitted March 17, 2019 at 07:39PM by virb3
via reddit https://ift.tt/2FhZ85M
https://ift.tt/2FinhZS
Submitted March 17, 2019 at 07:39PM by virb3
via reddit https://ift.tt/2FhZ85M
GitHub
GitHub - ViRb3/apk-utilities: 🛠 Tools and noscripts to manipulate Android APKs
🛠 Tools and noscripts to manipulate Android APKs. Contribute to ViRb3/apk-utilities development by creating an account on GitHub.
Common Web Application Threats
https://ift.tt/2NTYEp5
Submitted March 17, 2019 at 08:49PM by lokendra15
via reddit https://ift.tt/2ubkBH0
https://ift.tt/2NTYEp5
Submitted March 17, 2019 at 08:49PM by lokendra15
via reddit https://ift.tt/2ubkBH0
TechnoLush
Common Web Application Threats
Lists the most common web application threats
Python for Reverse Engineering #1: ELF Binaries
https://ift.tt/2Y4xpN7
Submitted March 17, 2019 at 09:29PM by Icyphox
via reddit https://ift.tt/2Y2c2Mx
https://ift.tt/2Y4xpN7
Submitted March 17, 2019 at 09:29PM by Icyphox
via reddit https://ift.tt/2Y2c2Mx
Medium
Python for Reverse Engineering #1: ELF Binaries
Building your own disassembly tooling for — that’s right — fun and profit
Secure Registration Flow
https://ift.tt/2JkaLNJ
Submitted March 17, 2019 at 10:34PM by lokendra15
via reddit https://ift.tt/2F8FYxS
https://ift.tt/2JkaLNJ
Submitted March 17, 2019 at 10:34PM by lokendra15
via reddit https://ift.tt/2F8FYxS
TechnoLush
Secure Registration Flow
A flowchart explaining the implementation of secure registration using the combination of username, email, and mobile number.
RCE in Slanger 0.6.0, a Ruby implementation of Pusher
https://ift.tt/2Jmnu2c
Submitted March 18, 2019 at 12:18PM by honoki
via reddit https://ift.tt/2JlfrCL
https://ift.tt/2Jmnu2c
Submitted March 18, 2019 at 12:18PM by honoki
via reddit https://ift.tt/2JlfrCL
Honoki
RCE in Slanger, a Ruby implementation of Pusher
While researching a web application last February, I learned about Slanger, an open source server implementation of Pusher. In this post I describe the discovery of a critical RCE vulnerability in …
Exploiting OGNL Injection in Apache Struts
https://ift.tt/2Y1t1OU
Submitted March 18, 2019 at 02:44PM by nytrorst
via reddit https://ift.tt/2Fk2g15
https://ift.tt/2Y1t1OU
Submitted March 18, 2019 at 02:44PM by nytrorst
via reddit https://ift.tt/2Fk2g15
Pentest-Tools.com Blog
Exploiting OGNL Injection in Apache Struts
OGNL Injection attack explained. Learn to exploit OGNL Injection in Apache Struts
Top three tips for safeguarding your network when deploying IoT
https://ift.tt/2Oasshi
Submitted March 18, 2019 at 06:56PM by TheJCOEco
via reddit https://ift.tt/2O9GXSH
https://ift.tt/2Oasshi
Submitted March 18, 2019 at 06:56PM by TheJCOEco
via reddit https://ift.tt/2O9GXSH
Techerati
Top three tips for safeguarding your network when deploying IoT - Techerati
Many of the security vulnerabilities inherent to deploying IoT can be mitigated by utilising a SDP, parallel networks and encouraging collaboration.