Vulnserver LTER - Extreme SEH Overwrite (Part 1)
https://ift.tt/2V3dsVg
Submitted March 29, 2019 at 02:58AM by doylersec
via reddit https://ift.tt/2CIk0Sa
https://ift.tt/2V3dsVg
Submitted March 29, 2019 at 02:58AM by doylersec
via reddit https://ift.tt/2CIk0Sa
doyler.net
Vulnserver LTER - Extreme SEH Overwrite (Part 1) | doyler.net
I know this one took a bit longer, but I've finally finished up my Vulnserver LTER write-up. Vulnserver LTER - Introduction If you have not been following along, I'm slowly writing all the exploits for vulnserver. This one will be … Continue reading →
N.S.A. Contractor Hal Martin, Arrested in Biggest Breach of U.S. Secrets, Pleads Guilty
https://ift.tt/2JQKqqG
Submitted March 29, 2019 at 02:27AM by dadoftwins71309
via reddit https://ift.tt/2YyW7FC
https://ift.tt/2JQKqqG
Submitted March 29, 2019 at 02:27AM by dadoftwins71309
via reddit https://ift.tt/2YyW7FC
NY Times
N.S.A. Contractor Arrested in Biggest Breach of U.S. Secrets Pleads Guilty
The contractor, Harold Martin, was arrested in 2016, but investigators never found evidence that he had shared stolen classified information with anyone.
Cisco RV320 Command Injection. Again.
https://ift.tt/2CHDczr
Submitted March 29, 2019 at 01:44AM by xaocuc
via reddit https://ift.tt/2HLUTBI
https://ift.tt/2CHDczr
Submitted March 29, 2019 at 01:44AM by xaocuc
via reddit https://ift.tt/2HLUTBI
www.redteam-pentesting.de
Cisco RV320 Command Injection
RedTeam Pentesting discovered a command injection vulnerability in the web-based certificate generator feature of the Cisco RV320 router which was inadequately patched by the vendor.
Magento 2.2.0 <= 2.3.0 Unauthenticated SQLi
https://ift.tt/2WuLhP7
Submitted March 29, 2019 at 04:09AM by cfambionics
via reddit https://ift.tt/2HJdFKd
https://ift.tt/2WuLhP7
Submitted March 29, 2019 at 04:09AM by cfambionics
via reddit https://ift.tt/2HJdFKd
Ambionics
Magento 2.2.0 <= 2.3.0 Unauthenticated SQLi
Several flaws have been identified in the latest version of Magento 2, allowing an attacker to obtain complete control over the server. We're now releasing the exploit for the unauthenticated SQL injection. We'll release the details for the RCE vulnerability…
Fireeye Introduces Commando VM: Windows Offensive VM
https://ift.tt/2V48eZ8
Submitted March 29, 2019 at 06:43AM by alnarra_1
via reddit https://ift.tt/2FClHBa
https://ift.tt/2V48eZ8
Submitted March 29, 2019 at 06:43AM by alnarra_1
via reddit https://ift.tt/2FClHBa
FireEye
Commando VM: The First of Its Kind Windows Offensive Distribution « Commando VM: The First of Its Kind Windows Offensive Distribution
We introduce Commando VM, a tool for penetration testers who use Windows.
Cisco bungled RV320/RV325 patches, routers still exposed to hacks
https://ift.tt/2OAfqtW
Submitted March 29, 2019 at 05:33AM by MatthewRS2
via reddit https://ift.tt/2V3HM1Q
https://ift.tt/2OAfqtW
Submitted March 29, 2019 at 05:33AM by MatthewRS2
via reddit https://ift.tt/2V3HM1Q
ZDNet
Cisco bungled RV320/RV325 patches, routers still exposed to hacks
Cisco blacklists curl instead of fixing vulnerable code. No new patches available, meaning devices still vulnerable to attacks.
mkYARA – Writing YARA rules for the lazy analyst
https://ift.tt/2HXiMFZ
Submitted March 29, 2019 at 10:09AM by digicat
via reddit https://ift.tt/2YwRImO
https://ift.tt/2HXiMFZ
Submitted March 29, 2019 at 10:09AM by digicat
via reddit https://ift.tt/2YwRImO
Fox-IT International blog
mkYARA – Writing YARA rules for the lazy analyst
Writing YARA rules based on executable code within malware can be a tedious task. An analyst cannot simply copy and paste raw executable code into a YARA rule, because this code contains variable v…
privacytools.io is running a Mastodon instance now. Join us
https://ift.tt/2HMcklI
Submitted March 29, 2019 at 05:23PM by BurungHantu
via reddit https://ift.tt/2JOp9Oo
https://ift.tt/2HMcklI
Submitted March 29, 2019 at 05:23PM by BurungHantu
via reddit https://ift.tt/2JOp9Oo
Mastodon hosted on social.privacytools.io
Mastodon 🔐 privacytools.io
privacytools.io provides knowledge and tools to protect your privacy against global mass surveillance.
Website: privacytools.io
In cooperation with: OpenNIC.org
Website: privacytools.io
In cooperation with: OpenNIC.org
ShadowHammer MAC Address List
https://ift.tt/2TDRTsQ
Submitted March 29, 2019 at 04:48PM by ga-vu
via reddit https://ift.tt/2uE7X3v
https://ift.tt/2TDRTsQ
Submitted March 29, 2019 at 04:48PM by ga-vu
via reddit https://ift.tt/2uE7X3v
Skylightcyber
Skylight Cyber | Unleash The Hash
Get the [almost] full list of MAC addresses that were targeted in the ASUS breach, and share our pain in the short story of extracting them.
An in-depth analysis of Magecart skimming noscripts
https://ift.tt/2TJ1Fdg
Submitted March 29, 2019 at 06:54PM by ThisIsLibra
via reddit https://ift.tt/2WwVvyu
https://ift.tt/2TJ1Fdg
Submitted March 29, 2019 at 06:54PM by ThisIsLibra
via reddit https://ift.tt/2WwVvyu
reddit
r/netsec - An in-depth analysis of Magecart skimming noscripts
0 votes and 0 comments so far on Reddit
Intel VISA: Through the Rabbit Hole
https://ift.tt/2V4KJza
Submitted March 29, 2019 at 09:13PM by Pokaw0
via reddit https://ift.tt/2Ovt3KA
https://ift.tt/2V4KJza
Submitted March 29, 2019 at 09:13PM by Pokaw0
via reddit https://ift.tt/2Ovt3KA
Blackhat
Black Hat Asia 2019
Vulncode-DB - A vulnerable code database | Security Research
https://ift.tt/2FNVQGD
Submitted March 29, 2019 at 10:29PM by phisch90
via reddit https://ift.tt/2U2aDr3
https://ift.tt/2FNVQGD
Submitted March 29, 2019 at 10:29PM by phisch90
via reddit https://ift.tt/2U2aDr3
reddit
r/netsec - Vulncode-DB - A vulnerable code database | Security Research
0 votes and 0 comments so far on Reddit
8,000+ Cisco RV320/RV325 routers are leaking their entire configuration file, including admin credentials, to the public internet.
https://ift.tt/2U5yFl1
Submitted March 30, 2019 at 01:34AM by bad_packets
via reddit https://ift.tt/2YsQnNI
https://ift.tt/2U5yFl1
Submitted March 30, 2019 at 01:34AM by bad_packets
via reddit https://ift.tt/2YsQnNI
badpackets.net
Over 9,000 Cisco RV320/RV325 routers are vulnerable to CVE-2019-1653
On Friday, January 25, 2019, our honeypots detected opportunistic scanning activity from multiple hosts targeting Cisco Small Business RV320 and RV325 routers. A vulnerability exists in these routers that allow remote unauthenticated information disclosure…
New TLS Padding Oracle Scanner (padcheck)
https://ift.tt/2U32P8q
Submitted March 30, 2019 at 04:43AM by KernelJay
via reddit https://ift.tt/2OzAErz
https://ift.tt/2U32P8q
Submitted March 30, 2019 at 04:43AM by KernelJay
via reddit https://ift.tt/2OzAErz
GitHub
Tripwire/padcheck
TLS CBC Padding Oracle Checker. Contribute to Tripwire/padcheck development by creating an account on GitHub.
Hack The Box - Curling Write-up by 0xRick
https://ift.tt/2V1iHol
Submitted March 30, 2019 at 08:36PM by Ahm3d_H3sham
via reddit https://ift.tt/2CJiA9W
https://ift.tt/2V1iHol
Submitted March 30, 2019 at 08:36PM by Ahm3d_H3sham
via reddit https://ift.tt/2CJiA9W
0xRick Owned Root !
Hack The Box - Curling
Quick Summary Hey guys today Curling retired and here is my write-up about it. I had a lot of fun doing this box as it was easy and simple. Also it was straightforward , no rabbit holes and such things. It’s a linux box and its ip is 10.10.10.150 I added…
Vulnserver LTER SEH Continued (Part 2)
https://ift.tt/2UcPKJ5
Submitted March 30, 2019 at 09:05PM by doylersec
via reddit https://ift.tt/2HP9JaV
https://ift.tt/2UcPKJ5
Submitted March 30, 2019 at 09:05PM by doylersec
via reddit https://ift.tt/2HP9JaV
doyler.net
Vulnserver LTER SEH Continued (Part 2) | doyler.net
This post will conclude my Vulnserver LTER SEH exploit. Vulnserver LTER SEH - Part 2 If you haven't read Part 1 yet, then I recommend you start there. That said, I last left off with a newly generated reverse shell … Continue reading →
PoC || GTFO 0x19 (Github Mirror)
https://ift.tt/2WBMjZT
Submitted March 30, 2019 at 11:32PM by netsecfriends
via reddit https://ift.tt/2HOq1Rc
https://ift.tt/2WBMjZT
Submitted March 30, 2019 at 11:32PM by netsecfriends
via reddit https://ift.tt/2HOq1Rc
GitHub
pocorgtfo/README.md at master · angea/pocorgtfo
a "Proof of Concept or GTFO" mirror with extra article index, direct links and clean PDFs. - pocorgtfo/README.md at master · angea/pocorgtfo
Exodus: New Android Spyware Made in Italy
https://ift.tt/2U5VdSz
Submitted March 31, 2019 at 01:40PM by fo0
via reddit https://ift.tt/2OAoLlf
https://ift.tt/2U5VdSz
Submitted March 31, 2019 at 01:40PM by fo0
via reddit https://ift.tt/2OAoLlf
Kubernetes (kubectl) directory traversal vulnerability due to insufficient fix - CVE-2019-1002101
https://ift.tt/2I7WJMC
Submitted March 31, 2019 at 02:02PM by reddit_read_today
via reddit https://ift.tt/2U5rlpy
https://ift.tt/2I7WJMC
Submitted March 31, 2019 at 02:02PM by reddit_read_today
via reddit https://ift.tt/2U5rlpy
Twistlock
Disclosing a directory traversal vulnerability in Kubernetes copy - CVE-2019-1002101 | Twistlock
Preface On March 4, I reported a security vulnerability in kubectl to the Kubernetes and OpenShift security teams, which was assigned CVE-2019-1002101. This post explains the discovery process, the vulnerability details and its impact and exploitation methods.…
CommandoVM - a fully customized, Windows-based security distribution for penetration testing and red teaming
https://ift.tt/2YyHHpe
Submitted March 31, 2019 at 02:49PM by Titokhan
via reddit https://ift.tt/2WCggsz
https://ift.tt/2YyHHpe
Submitted March 31, 2019 at 02:49PM by Titokhan
via reddit https://ift.tt/2WCggsz
GitHub
fireeye/commando-vm
Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com - fireeye/commando-vm
The Journey to Try Harder: TJNull’s Preparation Guide for PWK/OSCP
https://ift.tt/2CLZkZf
Submitted March 31, 2019 at 08:44PM by xaocuc
via reddit https://ift.tt/2uzq1vO
https://ift.tt/2CLZkZf
Submitted March 31, 2019 at 08:44PM by xaocuc
via reddit https://ift.tt/2uzq1vO
NetSec Focus
The Journey to Try Harder: TJNull’s Preparation Guide for PWK/OSCP
Table of Contents: Overview Dedication A Word of Warning! Section 1: Getting Comfortable with Kali Linux Section 2: Essential Tools in Kali Section 3: Passive Reconnaissance Section 4: Active Reconnaissance Section 5: Vulnerability Scanning Section 6: Buffer…