ADB, Docker, And GHIDRA
https://ift.tt/2HTopG0
Submitted April 02, 2019 at 02:47PM by lawandordercandidate
via reddit https://ift.tt/2TS9Wvf
https://ift.tt/2HTopG0
Submitted April 02, 2019 at 02:47PM by lawandordercandidate
via reddit https://ift.tt/2TS9Wvf
menz-o-matic.com
ADB, Docker, And GHIDRA
Running GHIDRA inside a Docker container with Hearthstone APK file loaded.
Circumventing SSL Pinning in obfuscated apps with OkHttp
https://ift.tt/2uCKhgd
Submitted April 02, 2019 at 04:49PM by daanraman
via reddit https://ift.tt/2WIieYF
https://ift.tt/2uCKhgd
Submitted April 02, 2019 at 04:49PM by daanraman
via reddit https://ift.tt/2WIieYF
NVISO Labs
Circumventing SSL Pinning in obfuscated apps with OkHttp
TL;DR – There are many Android SSL pinning bypass noscripts available for Frida. However, those don’t always work on obfuscated applications. If the application uses OkHttp, there’s…
FileZilla 'fzsftp' Untrusted Search Path - Write-Up and Video PoC
https://ift.tt/2K02HC4
Submitted April 02, 2019 at 07:20PM by lynerc
via reddit https://ift.tt/2UszyDr
https://ift.tt/2K02HC4
Submitted April 02, 2019 at 07:20PM by lynerc
via reddit https://ift.tt/2UszyDr
Medium
FileZilla Untrusted Search Path
Targeting the user with a rogue binary
clong/DetectionLab: Vagrant & Packer noscripts to build a lab environment complete with security tooling and logging best practices
https://ift.tt/2yhynYw
Submitted April 02, 2019 at 08:41PM by digicat
via reddit https://ift.tt/2TOTts2
https://ift.tt/2yhynYw
Submitted April 02, 2019 at 08:41PM by digicat
via reddit https://ift.tt/2TOTts2
GitHub
GitHub - clong/DetectionLab: Automate the creation of a lab environment complete with security tooling and logging best practices
Automate the creation of a lab environment complete with security tooling and logging best practices - clong/DetectionLab
Apache HTTP Server privilege escalation from modules' noscripts (CVE-2019-0211)
https://ift.tt/2YRtyDM
Submitted April 02, 2019 at 10:19PM by 0xdea
via reddit https://ift.tt/2Veh46I
https://ift.tt/2YRtyDM
Submitted April 02, 2019 at 10:19PM by 0xdea
via reddit https://ift.tt/2Veh46I
httpd.apache.org
httpd 2.4 vulnerabilities - The Apache HTTP Server Project
Web Security Academy — Free Online Training by Portswigger
https://ift.tt/2UuGpMw
Submitted April 02, 2019 at 10:17PM by 0xdea
via reddit https://ift.tt/2CQlHN4
https://ift.tt/2UuGpMw
Submitted April 02, 2019 at 10:17PM by 0xdea
via reddit https://ift.tt/2CQlHN4
portswigger.net
Web Security Academy: Free Online Training from PortSwigger
The Web Security Academy is a free online training center for web application security, brought to you by PortSwigger. Create an account to get started.
Splitting atoms in XNU
https://ift.tt/2uDuOfN
Submitted April 02, 2019 at 07:22AM by QuirkySpiceBush
via reddit https://ift.tt/2Ic4xgJ
https://ift.tt/2uDuOfN
Submitted April 02, 2019 at 07:22AM by QuirkySpiceBush
via reddit https://ift.tt/2Ic4xgJ
reddit
Splitting atoms in XNU
Posted in r/netsec by u/QuirkySpiceBush • 9 points and 0 comments
GitHub - GoMet: Multi-platform implant written in Golang. TCP forwarding, socks5, tunneling, shell, download, exec
https://ift.tt/2YDDKjb
Submitted April 02, 2019 at 01:22AM by mimah35
via reddit https://ift.tt/2uEOAHI
https://ift.tt/2YDDKjb
Submitted April 02, 2019 at 01:22AM by mimah35
via reddit https://ift.tt/2uEOAHI
BSides Houston 2019 Call For Paper is Open
https://ift.tt/2FIjfsQ
Submitted April 02, 2019 at 11:17PM by Extremite
via reddit https://ift.tt/2I6IBU4
https://ift.tt/2FIjfsQ
Submitted April 02, 2019 at 11:17PM by Extremite
via reddit https://ift.tt/2I6IBU4
Introducing: KatzKatz a python tool to parse text files containing output from Mimikatz
https://ift.tt/2CPOvWa
Submitted April 03, 2019 at 12:24AM by GelosSnake
via reddit https://ift.tt/2OKojBa
https://ift.tt/2CPOvWa
Submitted April 03, 2019 at 12:24AM by GelosSnake
via reddit https://ift.tt/2OKojBa
GitHub
GitHub - xFreed0m/KatzKatz: Python3 noscript to parse txt files containing Mimikatz output
Python3 noscript to parse txt files containing Mimikatz output - GitHub - xFreed0m/KatzKatz: Python3 noscript to parse txt files containing Mimikatz output
Wizard Labs - Devlife Write-up by 0xRick
https://ift.tt/2VdQhrl
Submitted April 03, 2019 at 12:17AM by Ahm3d_H3sham
via reddit https://ift.tt/2FTqxv9
https://ift.tt/2VdQhrl
Submitted April 03, 2019 at 12:17AM by Ahm3d_H3sham
via reddit https://ift.tt/2FTqxv9
0xRick Owned Root !
Wizard Labs - Devlife
Quick Summary Hey guys this is my write-up about Devlife from Wizard Labs which is their second box to retire. Just like dummy it’s another easy box (Difficulty : 2/10) , It’s a linux box and its ip is 10.1.1.20 so let’s jump right in ! Nmap We will start…
A One-two Punch of Emotet, TrickBot, and Ryuk Stealing and Ransoming Data
https://ift.tt/2TOPPyd
Submitted April 03, 2019 at 01:26AM by hackerxbella
via reddit https://ift.tt/2WNAO1J
https://ift.tt/2TOPPyd
Submitted April 03, 2019 at 01:26AM by hackerxbella
via reddit https://ift.tt/2WNAO1J
Cybereason
A One-two Punch of Emotet, TrickBot, & Ryuk Stealing & Ransoming Data
The Cybereason team has identified a campaign that incorporates Emotet, TrickBot, and the Ryuk ransomware. This malware adapts Emotet to drop TrickBot, and adapts TrickBot to not only steal data but also download the Ryuk ransomware.
DiffAIv3: diffai can now provably protect extremely deep residual neural networks against adversarial attack
https://ift.tt/2FSVRtP
Submitted April 03, 2019 at 02:13AM by mmirman
via reddit https://ift.tt/2UbPvOV
https://ift.tt/2FSVRtP
Submitted April 03, 2019 at 02:13AM by mmirman
via reddit https://ift.tt/2UbPvOV
GitHub
Release DiffAI Version 3 · eth-sri/diffai
Version from the Arxiv paper https://arxiv.org/abs/1903.12519
Updates
Added DSL to specify complex objectives and complex training scheduling.
Added abstract layers for increasing precision in dee...
Updates
Added DSL to specify complex objectives and complex training scheduling.
Added abstract layers for increasing precision in dee...
Sqreen launches ASM platform to bridge the gap between security and developers
https://ift.tt/2HRjhC7
Submitted April 03, 2019 at 03:46AM by paulble83
via reddit https://ift.tt/2K1DJCk
https://ift.tt/2HRjhC7
Submitted April 03, 2019 at 03:46AM by paulble83
via reddit https://ift.tt/2K1DJCk
TechCrunch
Sqreen raises $14 million for its application security management service
Sqreen has raised a Series A round of $14 million. Greylock Partners is leading the round, existing investors Y Combinator, Alven and Point Nine are also participating. The startup wants to improve security when it comes to web applications and cloud infrastructure.…
Most likely an attempted USB Drop Attack at the highest level. Chinese woman carrying ‘malware’ arrested at Mar-a-Lago heading to a Cindy Yang event
https://ift.tt/2HRKVik
Submitted April 03, 2019 at 06:47AM by LinearFluid
via reddit https://ift.tt/2I9AlTs
https://ift.tt/2HRKVik
Submitted April 03, 2019 at 06:47AM by LinearFluid
via reddit https://ift.tt/2I9AlTs
Miami Herald
Chinese woman carrying ‘malware’ arrested at Mar-a-Lago heading to a Cindy Yang event
A Chinese woman carrying a thumb drive loaded with malware was detained at Mar-a-Lago Saturday after trying to gain access to events advertised on Chinese-language social media by Li “Cindy” Yang, the South Florida massage parlor entrepreneur who also ran…
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
https://ift.tt/2Ew4ewf
Submitted April 03, 2019 at 06:39AM by androshka
via reddit https://ift.tt/2WJCpW5
https://ift.tt/2Ew4ewf
Submitted April 03, 2019 at 06:39AM by androshka
via reddit https://ift.tt/2WJCpW5
GitHub
GitHub - trimstray/the-book-of-secret-knowledge: A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners…
A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. - GitHub - trimstray/the-book-of-secret-knowledge: A collection of inspiring lists, manuals,...
Rethinking the inotify API as an offensive helper
https://ift.tt/2UuZhLx
Submitted April 03, 2019 at 12:05PM by gid0rah
via reddit https://ift.tt/2KbTmH8
https://ift.tt/2UuZhLx
Submitted April 03, 2019 at 12:05PM by gid0rah
via reddit https://ift.tt/2KbTmH8
x-c3ll.github.io
Rethinking the inotify API as an offensive helper ::
DoomsDay Vault
DoomsDay Vault
Examples of how the inotify API can be useful for the Red Team
Magento e-commerce sites urged to apply security update
https://ift.tt/2Oy4I6T
Submitted April 03, 2019 at 02:06PM by KeyDutch
via reddit https://ift.tt/2Ub3Xa6
https://ift.tt/2Oy4I6T
Submitted April 03, 2019 at 02:06PM by KeyDutch
via reddit https://ift.tt/2Ub3Xa6
ComputerWeekly.com
Magento e-commerce sites urged to apply security update
Security experts are urging companies using the Magento ecommerce site to apply security updates without delay to avoid a disastrous hacking campaign
CARPE (DIEM): CVE-2019-0211 Apache Root Privilege Escalation
https://ift.tt/2WD9RNO
Submitted April 03, 2019 at 02:31PM by cfambionics
via reddit https://ift.tt/2VlwHtr
https://ift.tt/2WD9RNO
Submitted April 03, 2019 at 02:31PM by cfambionics
via reddit https://ift.tt/2VlwHtr
Post Exploitation with KOADIC
https://ift.tt/2YL11Qb
Submitted April 03, 2019 at 03:01PM by mstfknn
via reddit https://ift.tt/2VaPk2Z
https://ift.tt/2YL11Qb
Submitted April 03, 2019 at 03:01PM by mstfknn
via reddit https://ift.tt/2VaPk2Z
PRISMA CSI
Post Exploitation with KOADIC • PRISMA CSI
Koadic as a tool can be used in any of the last two stages, an added advantage to the user. It is a Windows post-exploitation rootkit.
APC Injection with Parent Process Spoofing
https://ift.tt/2CU4oL8
Submitted April 03, 2019 at 05:18PM by hlldz
via reddit https://ift.tt/2VdRQFC
https://ift.tt/2CU4oL8
Submitted April 03, 2019 at 05:18PM by hlldz
via reddit https://ift.tt/2VdRQFC
GitHub
hlldz/APC-PPID
Adds a user-mode asynchronous procedure call (APC) object to the APC queue of the specified thread and spoof the Parent Process. - hlldz/APC-PPID