Two More Cases of Third-Party Facebook App Data Exposure
https://ift.tt/2UexbVI
Submitted April 04, 2019 at 06:43PM by pgl
via reddit https://ift.tt/2G1woi1
https://ift.tt/2UexbVI
Submitted April 04, 2019 at 06:43PM by pgl
via reddit https://ift.tt/2G1woi1
Upguard
Losing Face: Two More Cases of Third-Party Facebook App Data Exposure
Third-party Facebook apps gather Facebook data about the people who use them. While Facebook struggles to contain these exposures, insecure third-party data practices & misconfigured cloud systems continue to leak Facebook data to the internet. See how UpGuard…
Ghidra source code officially released!
https://ift.tt/2EQelLi
Submitted April 04, 2019 at 07:24PM by frrossty
via reddit https://ift.tt/2FRIglf
https://ift.tt/2EQelLi
Submitted April 04, 2019 at 07:24PM by frrossty
via reddit https://ift.tt/2FRIglf
GitHub
GitHub - NationalSecurityAgency/ghidra: Ghidra is a software reverse engineering (SRE) framework
Ghidra is a software reverse engineering (SRE) framework - GitHub - NationalSecurityAgency/ghidra: Ghidra is a software reverse engineering (SRE) framework
Huawei and Security Analysis | grsecurity
https://ift.tt/2TWRlOW
Submitted April 04, 2019 at 10:05PM by shawn_webb
via reddit https://ift.tt/2YMve1a
https://ift.tt/2TWRlOW
Submitted April 04, 2019 at 10:05PM by shawn_webb
via reddit https://ift.tt/2YMve1a
grsecurity.net
grsecurity - Huawei and Security Analysis
grsecurity is an extensive security enhancement to the Linux kernel that defends against a wide range of security threats through intelligent access control, memory corruption-based exploit prevention, and a host of other system hardening that generally require…
Apache HTTPD: Apache HTTP Server privilege escalation from modules' noscripts (CVE-2019-0211)
https://ift.tt/2K3Esmf
Submitted April 05, 2019 at 12:12AM by BruteIPTV
via reddit https://ift.tt/2Uv3PBr
https://ift.tt/2K3Esmf
Submitted April 05, 2019 at 12:12AM by BruteIPTV
via reddit https://ift.tt/2Uv3PBr
reddit
r/netsec - Apache HTTPD: Apache HTTP Server privilege escalation from modules' noscripts (CVE-2019-0211)
0 votes and 0 comments so far on Reddit
Apache Server Bug Gives Root Level Access to Any Level Account
https://ift.tt/2VmQLeH
Submitted April 05, 2019 at 03:05AM by threaltwizzla
via reddit https://ift.tt/2Uvna5v
https://ift.tt/2VmQLeH
Submitted April 05, 2019 at 03:05AM by threaltwizzla
via reddit https://ift.tt/2Uvna5v
Secure Intelligence
Cybersecurity Threat Advisory 0014-19: Apache Server Bug Gives Root Level Access to Any Level Account
Check Out Our New Cybersecurity Threat Advisory! SkOUT Specializes in helping SMBs and MSPs stay secure and safe from Cybersecurity Threats.
Subverting Electron Apps via Insecure Preload. Wire App and Discord XSS to RCE bugs.
https://ift.tt/2TZe78O
Submitted April 04, 2019 at 02:29AM by nibblesec
via reddit https://ift.tt/2YPBzsQ
https://ift.tt/2TZe78O
Submitted April 04, 2019 at 02:29AM by nibblesec
via reddit https://ift.tt/2YPBzsQ
Doyensec
Subverting Electron Apps via Insecure Preload · Doyensec's Blog
Doyensec's Blog :: Doyensec is an independent security research and development company focused on vulnerability discovery and remediation.
Ongoing DNS hijacking campaign targeting consumer routers
https://ift.tt/2Id7gGI
Submitted April 05, 2019 at 05:19AM by bad_packets
via reddit https://ift.tt/2Unk5Wg
https://ift.tt/2Id7gGI
Submitted April 05, 2019 at 05:19AM by bad_packets
via reddit https://ift.tt/2Unk5Wg
badpackets.net
Ongoing DNS hijacking campaign targeting consumer routers
Over the last three months, our honeypots have detected DNS hijacking attacks targeting various types of consumer routers. All exploit attempts have originated from hosts on the network of Google Cloud Platform (AS15169). In this campaign, we've identified…
What is penetration testing and how does it differ from vulnerability scanning? It's an important distinction that those in most need of these tests don't know and sometimes get mislead about.
http://bit.ly/2D09MMX
Submitted April 05, 2019 at 05:29PM by travishat
via reddit http://bit.ly/2Vk6Emd
http://bit.ly/2D09MMX
Submitted April 05, 2019 at 05:29PM by travishat
via reddit http://bit.ly/2Vk6Emd
spriteCloud
What is penetration testing?
There is a considerable amount of confusion in the security testing industry regarding the differences between penetration testing and vulnerability scanning.
Handlebars template injection and RCE in a Shopify app
http://bit.ly/2D0LjHh
Submitted April 05, 2019 at 05:41AM by ml33t3r
via reddit http://bit.ly/2Igv4tk
http://bit.ly/2D0LjHh
Submitted April 05, 2019 at 05:41AM by ml33t3r
via reddit http://bit.ly/2Igv4tk
Blogspot
Handlebars template injection and RCE in a Shopify app
TL;DR We found a zero-day within a JavaScript template library called handlebars and used it to get Remote Code Execution in the Sh...
Our take on social engineering
http://bit.ly/2UhdLiY
Submitted April 05, 2019 at 08:29PM by dn3t
via reddit http://bit.ly/2G25LJJ
http://bit.ly/2UhdLiY
Submitted April 05, 2019 at 08:29PM by dn3t
via reddit http://bit.ly/2G25LJJ
Giggity: cli tool/python module to scrape useful information from a github user/org
http://bit.ly/2DbD1gr
Submitted April 05, 2019 at 08:21PM by amusciano
via reddit http://bit.ly/2UD1jZY
http://bit.ly/2DbD1gr
Submitted April 05, 2019 at 08:21PM by amusciano
via reddit http://bit.ly/2UD1jZY
GitHub
needmorecowbell/giggity
Wraps github api for openly available information about an organization, user, or repo - needmorecowbell/giggity
IResponse to IEncrypt - a Detailed Incident Response to an IEncrypt Ransomware Attack
http://bit.ly/2CY0vVN
Submitted April 06, 2019 at 12:05AM by ophirharpaz
via reddit http://bit.ly/2D08xx4
http://bit.ly/2CY0vVN
Submitted April 06, 2019 at 12:05AM by ophirharpaz
via reddit http://bit.ly/2D08xx4
Guardicore - Data Center and Cloud Security
IResponse to IEncrypt | Guardicore Labs
A detailed investigation into an IEncrypt ransomware attack, analysis of the decryption process and the decryptor. Also providing a safe to use version of Guardicore’s IEncrypt decryptor
OSINT for Windows
http://bit.ly/2HYKiUc
Submitted April 06, 2019 at 02:29AM by endless
via reddit http://bit.ly/2WJBXXK
http://bit.ly/2HYKiUc
Submitted April 06, 2019 at 02:29AM by endless
via reddit http://bit.ly/2WJBXXK
GitHub
visualbasic6/chatter
internet monitoring osint tool for windows. Contribute to visualbasic6/chatter development by creating an account on GitHub.
Microsoft discovers Huawei's PC drivers are using an unnecessary watchdog, apparently structured to provide privilege escalations.
http://bit.ly/2HZFVIy
Submitted April 06, 2019 at 10:35AM by alirobe
via reddit http://bit.ly/2G25arq
http://bit.ly/2HZFVIy
Submitted April 06, 2019 at 10:35AM by alirobe
via reddit http://bit.ly/2G25arq
Microsoft Security
From alert to driver vulnerability: Microsoft Defender ATP investigation unearths privilege escalation flaw - Microsoft Security
Our discovery of two privilege escalation vulnerabilities in a driver highlights the strength of Microsoft Defender ATP’s sensors. These sensors expose anomalous behavior and give SecOps personnel the intelligence and tools to investigate threats, as we did.
From alert to driver vulnerability: Microsoft Defender ATP investigation unearths privilege escalation flaw - Microsoft Security
http://bit.ly/2HZFVIy
Submitted April 06, 2019 at 02:46PM by alirobe
via reddit http://bit.ly/2WJsNuq
http://bit.ly/2HZFVIy
Submitted April 06, 2019 at 02:46PM by alirobe
via reddit http://bit.ly/2WJsNuq
Microsoft Security
From alert to driver vulnerability: Microsoft Defender ATP investigation unearths privilege escalation flaw - Microsoft Security
Our discovery of two privilege escalation vulnerabilities in a driver highlights the strength of Microsoft Defender ATP’s sensors. These sensors expose anomalous behavior and give SecOps personnel the intelligence and tools to investigate threats, as we did.
Fracker – PHP function tracker
http://bit.ly/2D0QNSu
Submitted April 06, 2019 at 06:16PM by cyrus-and
via reddit http://bit.ly/2ImhTGW
http://bit.ly/2D0QNSu
Submitted April 06, 2019 at 06:16PM by cyrus-and
via reddit http://bit.ly/2ImhTGW
GitHub
cyrus-and/fracker
PHP function tracker. Contribute to cyrus-and/fracker development by creating an account on GitHub.
Hack The Box - Vault Write-up by 0xRick
http://bit.ly/2OV3Yca
Submitted April 06, 2019 at 08:34PM by Ahm3d_H3sham
via reddit http://bit.ly/2YVywzp
http://bit.ly/2OV3Yca
Submitted April 06, 2019 at 08:34PM by Ahm3d_H3sham
via reddit http://bit.ly/2YVywzp
0xRick Owned Root !
Hack The Box - Vault
Quick Summary Hey guys today Vault retired and here is my write-up about it. Vault was a fun box and it’s absolutely one of my favorites. Starting with an insecure file upload functionality to escaping from a host to another and getting a reverse shell with…
Multi-threaded Port Scanner Implemented in Python
http://bit.ly/2BBa2RO
Submitted April 06, 2019 at 07:48PM by woahdotcom
via reddit http://bit.ly/2VrD2n3
http://bit.ly/2BBa2RO
Submitted April 06, 2019 at 07:48PM by woahdotcom
via reddit http://bit.ly/2VrD2n3
zeroequalsfalse.press
How to Optimise Port-Scanning with a Multi-threaded approach
System Admins, here is a way to optimise your port scanning.
SharpExec - Lateral Movement With Your Favorite .NET Bling
http://bit.ly/2UwDeEk
Submitted April 07, 2019 at 10:33AM by fuckup1337
via reddit http://bit.ly/2KilUPs
http://bit.ly/2UwDeEk
Submitted April 07, 2019 at 10:33AM by fuckup1337
via reddit http://bit.ly/2KilUPs
Redxorblue
SharpExec - Lateral Movement With Your Favorite .NET Bling
TL;DR: SharpExec is an offensive security C# tool designed to aid with lateral movement. While the techniques used are not groundbreaking ...
Linux Sockets and Python
http://bit.ly/2G3Oobs
Submitted April 07, 2019 at 08:30AM by lawandordercandidate
via reddit http://bit.ly/2UnqFfa
http://bit.ly/2G3Oobs
Submitted April 07, 2019 at 08:30AM by lawandordercandidate
via reddit http://bit.ly/2UnqFfa
menz-o-matic.com
Linux Sockets and Python
Discovering New And Open-Source Software.
[Github] Fast Multi-threaded FTP Scanner
http://bit.ly/2D3Pdz4
Submitted April 07, 2019 at 03:30PM by Quick_Stick
via reddit http://bit.ly/2VoXVzi
http://bit.ly/2D3Pdz4
Submitted April 07, 2019 at 03:30PM by Quick_Stick
via reddit http://bit.ly/2VoXVzi
Gist
Fast Multi-threaded FTP Scanner
Fast Multi-threaded FTP Scanner. GitHub Gist: instantly share code, notes, and snippets.