Ongoing DNS hijacking campaign targeting consumer routers
https://ift.tt/2Id7gGI
Submitted April 05, 2019 at 05:19AM by bad_packets
via reddit https://ift.tt/2Unk5Wg
https://ift.tt/2Id7gGI
Submitted April 05, 2019 at 05:19AM by bad_packets
via reddit https://ift.tt/2Unk5Wg
badpackets.net
Ongoing DNS hijacking campaign targeting consumer routers
Over the last three months, our honeypots have detected DNS hijacking attacks targeting various types of consumer routers. All exploit attempts have originated from hosts on the network of Google Cloud Platform (AS15169). In this campaign, we've identified…
What is penetration testing and how does it differ from vulnerability scanning? It's an important distinction that those in most need of these tests don't know and sometimes get mislead about.
http://bit.ly/2D09MMX
Submitted April 05, 2019 at 05:29PM by travishat
via reddit http://bit.ly/2Vk6Emd
http://bit.ly/2D09MMX
Submitted April 05, 2019 at 05:29PM by travishat
via reddit http://bit.ly/2Vk6Emd
spriteCloud
What is penetration testing?
There is a considerable amount of confusion in the security testing industry regarding the differences between penetration testing and vulnerability scanning.
Handlebars template injection and RCE in a Shopify app
http://bit.ly/2D0LjHh
Submitted April 05, 2019 at 05:41AM by ml33t3r
via reddit http://bit.ly/2Igv4tk
http://bit.ly/2D0LjHh
Submitted April 05, 2019 at 05:41AM by ml33t3r
via reddit http://bit.ly/2Igv4tk
Blogspot
Handlebars template injection and RCE in a Shopify app
TL;DR We found a zero-day within a JavaScript template library called handlebars and used it to get Remote Code Execution in the Sh...
Our take on social engineering
http://bit.ly/2UhdLiY
Submitted April 05, 2019 at 08:29PM by dn3t
via reddit http://bit.ly/2G25LJJ
http://bit.ly/2UhdLiY
Submitted April 05, 2019 at 08:29PM by dn3t
via reddit http://bit.ly/2G25LJJ
Giggity: cli tool/python module to scrape useful information from a github user/org
http://bit.ly/2DbD1gr
Submitted April 05, 2019 at 08:21PM by amusciano
via reddit http://bit.ly/2UD1jZY
http://bit.ly/2DbD1gr
Submitted April 05, 2019 at 08:21PM by amusciano
via reddit http://bit.ly/2UD1jZY
GitHub
needmorecowbell/giggity
Wraps github api for openly available information about an organization, user, or repo - needmorecowbell/giggity
IResponse to IEncrypt - a Detailed Incident Response to an IEncrypt Ransomware Attack
http://bit.ly/2CY0vVN
Submitted April 06, 2019 at 12:05AM by ophirharpaz
via reddit http://bit.ly/2D08xx4
http://bit.ly/2CY0vVN
Submitted April 06, 2019 at 12:05AM by ophirharpaz
via reddit http://bit.ly/2D08xx4
Guardicore - Data Center and Cloud Security
IResponse to IEncrypt | Guardicore Labs
A detailed investigation into an IEncrypt ransomware attack, analysis of the decryption process and the decryptor. Also providing a safe to use version of Guardicore’s IEncrypt decryptor
OSINT for Windows
http://bit.ly/2HYKiUc
Submitted April 06, 2019 at 02:29AM by endless
via reddit http://bit.ly/2WJBXXK
http://bit.ly/2HYKiUc
Submitted April 06, 2019 at 02:29AM by endless
via reddit http://bit.ly/2WJBXXK
GitHub
visualbasic6/chatter
internet monitoring osint tool for windows. Contribute to visualbasic6/chatter development by creating an account on GitHub.
Microsoft discovers Huawei's PC drivers are using an unnecessary watchdog, apparently structured to provide privilege escalations.
http://bit.ly/2HZFVIy
Submitted April 06, 2019 at 10:35AM by alirobe
via reddit http://bit.ly/2G25arq
http://bit.ly/2HZFVIy
Submitted April 06, 2019 at 10:35AM by alirobe
via reddit http://bit.ly/2G25arq
Microsoft Security
From alert to driver vulnerability: Microsoft Defender ATP investigation unearths privilege escalation flaw - Microsoft Security
Our discovery of two privilege escalation vulnerabilities in a driver highlights the strength of Microsoft Defender ATP’s sensors. These sensors expose anomalous behavior and give SecOps personnel the intelligence and tools to investigate threats, as we did.
From alert to driver vulnerability: Microsoft Defender ATP investigation unearths privilege escalation flaw - Microsoft Security
http://bit.ly/2HZFVIy
Submitted April 06, 2019 at 02:46PM by alirobe
via reddit http://bit.ly/2WJsNuq
http://bit.ly/2HZFVIy
Submitted April 06, 2019 at 02:46PM by alirobe
via reddit http://bit.ly/2WJsNuq
Microsoft Security
From alert to driver vulnerability: Microsoft Defender ATP investigation unearths privilege escalation flaw - Microsoft Security
Our discovery of two privilege escalation vulnerabilities in a driver highlights the strength of Microsoft Defender ATP’s sensors. These sensors expose anomalous behavior and give SecOps personnel the intelligence and tools to investigate threats, as we did.
Fracker – PHP function tracker
http://bit.ly/2D0QNSu
Submitted April 06, 2019 at 06:16PM by cyrus-and
via reddit http://bit.ly/2ImhTGW
http://bit.ly/2D0QNSu
Submitted April 06, 2019 at 06:16PM by cyrus-and
via reddit http://bit.ly/2ImhTGW
GitHub
cyrus-and/fracker
PHP function tracker. Contribute to cyrus-and/fracker development by creating an account on GitHub.
Hack The Box - Vault Write-up by 0xRick
http://bit.ly/2OV3Yca
Submitted April 06, 2019 at 08:34PM by Ahm3d_H3sham
via reddit http://bit.ly/2YVywzp
http://bit.ly/2OV3Yca
Submitted April 06, 2019 at 08:34PM by Ahm3d_H3sham
via reddit http://bit.ly/2YVywzp
0xRick Owned Root !
Hack The Box - Vault
Quick Summary Hey guys today Vault retired and here is my write-up about it. Vault was a fun box and it’s absolutely one of my favorites. Starting with an insecure file upload functionality to escaping from a host to another and getting a reverse shell with…
Multi-threaded Port Scanner Implemented in Python
http://bit.ly/2BBa2RO
Submitted April 06, 2019 at 07:48PM by woahdotcom
via reddit http://bit.ly/2VrD2n3
http://bit.ly/2BBa2RO
Submitted April 06, 2019 at 07:48PM by woahdotcom
via reddit http://bit.ly/2VrD2n3
zeroequalsfalse.press
How to Optimise Port-Scanning with a Multi-threaded approach
System Admins, here is a way to optimise your port scanning.
SharpExec - Lateral Movement With Your Favorite .NET Bling
http://bit.ly/2UwDeEk
Submitted April 07, 2019 at 10:33AM by fuckup1337
via reddit http://bit.ly/2KilUPs
http://bit.ly/2UwDeEk
Submitted April 07, 2019 at 10:33AM by fuckup1337
via reddit http://bit.ly/2KilUPs
Redxorblue
SharpExec - Lateral Movement With Your Favorite .NET Bling
TL;DR: SharpExec is an offensive security C# tool designed to aid with lateral movement. While the techniques used are not groundbreaking ...
Linux Sockets and Python
http://bit.ly/2G3Oobs
Submitted April 07, 2019 at 08:30AM by lawandordercandidate
via reddit http://bit.ly/2UnqFfa
http://bit.ly/2G3Oobs
Submitted April 07, 2019 at 08:30AM by lawandordercandidate
via reddit http://bit.ly/2UnqFfa
menz-o-matic.com
Linux Sockets and Python
Discovering New And Open-Source Software.
[Github] Fast Multi-threaded FTP Scanner
http://bit.ly/2D3Pdz4
Submitted April 07, 2019 at 03:30PM by Quick_Stick
via reddit http://bit.ly/2VoXVzi
http://bit.ly/2D3Pdz4
Submitted April 07, 2019 at 03:30PM by Quick_Stick
via reddit http://bit.ly/2VoXVzi
Gist
Fast Multi-threaded FTP Scanner
Fast Multi-threaded FTP Scanner. GitHub Gist: instantly share code, notes, and snippets.
Tricks used in Anubis Malware
http://bit.ly/2KfNEEu
Submitted April 07, 2019 at 08:13PM by eybisi_
via reddit http://bit.ly/2UEXmnG
http://bit.ly/2KfNEEu
Submitted April 07, 2019 at 08:13PM by eybisi_
via reddit http://bit.ly/2UEXmnG
Ahmet Bilal Can
Mobile Malware Analysis : Tricks used in Anubis
Anubis Anubis is my first case of complicated android malware and taught me so much about android malware. I want to share these learnings in this post. Anubis is almost one year old but its impact is
On Eggs and Egg-hunters (Linux/x64) - @syscall59
http://bit.ly/2I5Q5Hy
Submitted April 07, 2019 at 09:16PM by h41zum
via reddit http://bit.ly/2D1YyaV
http://bit.ly/2I5Q5Hy
Submitted April 07, 2019 at 09:16PM by h41zum
via reddit http://bit.ly/2D1YyaV
Medium
On Eggs and Egg-hunters (Linux/x64)
Writing and testing of an egg-hunter shellcode for Linux/x64
GitHub - PowerShell based Active Directory Honey User Account Management with Universal Dashboards
http://bit.ly/2G2pR5E
Submitted April 07, 2019 at 09:52PM by l33t_d0nut
via reddit http://bit.ly/2UnH6rK
http://bit.ly/2G2pR5E
Submitted April 07, 2019 at 09:52PM by l33t_d0nut
via reddit http://bit.ly/2UnH6rK
GitHub
leeberg/BlueHive
PowerShell based Active Directory Honey User Account Management with Universal Dashboards - leeberg/BlueHive
My first POC: Gaining root access to a kubernetes node with a "bad" container. Comments welcome
http://bit.ly/2VnvDFb
Submitted April 07, 2019 at 09:49PM by audscias
via reddit http://bit.ly/2G5F07g
http://bit.ly/2VnvDFb
Submitted April 07, 2019 at 09:49PM by audscias
via reddit http://bit.ly/2G5F07g
GitHub
jmg87/redteam-gkpown
Reverse shell container for k8s deployments. Contribute to jmg87/redteam-gkpown development by creating an account on GitHub.
Funnel: a lightweight yara-based feed scraper
http://bit.ly/2IhZUlh
Submitted April 08, 2019 at 11:34AM by amusciano
via reddit http://bit.ly/2CX8bYj
http://bit.ly/2IhZUlh
Submitted April 08, 2019 at 11:34AM by amusciano
via reddit http://bit.ly/2CX8bYj
GitHub
needmorecowbell/Funnel
Funnel is a lightweight yara-based feed scraper. Contribute to needmorecowbell/Funnel development by creating an account on GitHub.
Computer Security Materials
http://bit.ly/2X1VCDc
Submitted April 08, 2019 at 09:28AM by gabrielfelippe90
via reddit http://bit.ly/2Im24QH
http://bit.ly/2X1VCDc
Submitted April 08, 2019 at 09:28AM by gabrielfelippe90
via reddit http://bit.ly/2Im24QH
GitHub
the-akira/Computer_Science_Web_Resources
A curated list of important computer science multi-languages resources found on the Web. - the-akira/Computer_Science_Web_Resources