Must watch (IMHO) Securing Vendor Webapps - A Vulnerability Assessment on HELK
http://bit.ly/2IsjtIo
Submitted April 18, 2019 at 10:10PM by small-data-expert
via reddit http://bit.ly/2GlINMH
http://bit.ly/2IsjtIo
Submitted April 18, 2019 at 10:10PM by small-data-expert
via reddit http://bit.ly/2GlINMH
reddit
r/sysadmin - Must watch (IMHO) Securing Vendor Webapps - A Vulnerability Assessment on HELK
6 votes and 1 comment so far on Reddit
Simple Tool for Testing CVE Mitigation in Web Apps
http://bit.ly/2GtmTZ2
Submitted April 19, 2019 at 01:36AM by foospidy
via reddit http://bit.ly/2XqAZQO
http://bit.ly/2GtmTZ2
Submitted April 19, 2019 at 01:36AM by foospidy
via reddit http://bit.ly/2XqAZQO
Medium
Simple Tool for Testing CVE Mitigation in Web Apps
With Internet exposed web applications prompt mitigation of CVE (Common Vulnerabilities and Exposures) is critical. When a new CVE has…
Using Slack as a C2 Channel (Download Code)
http://bit.ly/2VaXJGQ
Submitted April 19, 2019 at 01:18AM by myover
via reddit http://bit.ly/2KM8MlS
http://bit.ly/2VaXJGQ
Submitted April 19, 2019 at 01:18AM by myover
via reddit http://bit.ly/2KM8MlS
Praetorian
Using Slack as a C2 Channel: MITRE ATT&CK – Web Service (T1102)
Our proof of concept (PoC) blends in with normal business activities such as user-to-user or user-to-group communications. Detecting this type of activity requires sophisticated network analysis capabilities, such as the ability to intercept and decrypt SSL…
BlueCommand: Dashboarding and Tooling front-end for PowerShell Empire using PowerShell Universal Dashboard
http://bit.ly/2Gv2AdV
Submitted April 19, 2019 at 09:18AM by l33t_d0nut
via reddit http://bit.ly/2KNWU2P
http://bit.ly/2Gv2AdV
Submitted April 19, 2019 at 09:18AM by l33t_d0nut
via reddit http://bit.ly/2KNWU2P
GitHub
leeberg/BlueCommand
Dashboarding and Tooling front-end for PowerShell Empire using PowerShell Universal Dashboard - leeberg/BlueCommand
How the Boeing 737 Max Disaster Looks to a Software Developer
http://bit.ly/2ZopI50
Submitted April 19, 2019 at 12:34PM by xaocuc
via reddit http://bit.ly/2IHEE8v
http://bit.ly/2ZopI50
Submitted April 19, 2019 at 12:34PM by xaocuc
via reddit http://bit.ly/2IHEE8v
IEEE Spectrum: Technology, Engineering, and Science News
How the Boeing 737 Max Disaster Looks to a Software Developer
Design shortcuts meant to make a new plane seem like an old, familiar one are to blame
Unmasked: An Analysis of 10 Million Passwords
http://bit.ly/1ELt5G1
Submitted April 19, 2019 at 01:25PM by NaiveMonitor
via reddit http://bit.ly/2GrO0T1
http://bit.ly/1ELt5G1
Submitted April 19, 2019 at 01:25PM by NaiveMonitor
via reddit http://bit.ly/2GrO0T1
Wpengine
Unmasked: An Analysis of 10 Million Passwords
How strong are your passwords? Here's an analysis of 10 million via @wpengine
Protected tweets leakage through URL detection #XSSearch #BugBounty
http://bit.ly/2PgLsLA
Submitted April 19, 2019 at 11:14PM by terjanq
via reddit http://bit.ly/2vfln6G
http://bit.ly/2PgLsLA
Submitted April 19, 2019 at 11:14PM by terjanq
via reddit http://bit.ly/2vfln6G
HackerOne
Twitter disclosed on HackerOne: Protected tweets exposure through...
## Summary
Leaking sensitive information from protected tweets via a prepared website. This vulnerability could lead to exposure of information such as **credit card numbers**, **bank account...
Leaking sensitive information from protected tweets via a prepared website. This vulnerability could lead to exposure of information such as **credit card numbers**, **bank account...
A public database exposed medical records of 150k rehab patients
http://bit.ly/2XsQzLs
Submitted April 20, 2019 at 01:35AM by xxdesmus
via reddit http://bit.ly/2XqJEmb
http://bit.ly/2XsQzLs
Submitted April 20, 2019 at 01:35AM by xxdesmus
via reddit http://bit.ly/2XqJEmb
Rainbowtabl.es
Steps To Recovery Addiction Treatment Center Leaking PII
An improperly secured ElasticSearch database leaked 1.5 years of PII related to individuals who had received medical treatment at an addiction treatment center. Steps to Recovery has yet to reply to any inquiries, and has not notified their patients regarding…
miniprint - A medium interaction printer honeypot 🍯
http://bit.ly/2DoeynL
Submitted April 20, 2019 at 02:59AM by GoGoGadgetSalmon
via reddit http://bit.ly/2KMOUin
http://bit.ly/2DoeynL
Submitted April 20, 2019 at 02:59AM by GoGoGadgetSalmon
via reddit http://bit.ly/2KMOUin
GitHub
sa7mon/miniprint
A medium interaction printer honeypot 🍯. Contribute to sa7mon/miniprint development by creating an account on GitHub.
The Future of Vulnerabilities Equities Processes Around the World
http://bit.ly/2FbEzZg
Submitted April 20, 2019 at 05:48PM by xaocuc
via reddit http://bit.ly/2DsuBB0
http://bit.ly/2FbEzZg
Submitted April 20, 2019 at 05:48PM by xaocuc
via reddit http://bit.ly/2DsuBB0
Lawfare
The Future of Vulnerabilities Equities Processes Around the World
Recent actions by the U.K. and Germany set a new bar for how nations can and should use a vulnerabilities equities process.
(Thai) In-depth Analysis of "SUDO_INJECT" Privilege Escalation Vulnerability
http://bit.ly/2KO9S0l
Submitted April 20, 2019 at 05:17PM by pe3zx
via reddit http://bit.ly/2GBQ1fR
http://bit.ly/2KO9S0l
Submitted April 20, 2019 at 05:17PM by pe3zx
via reddit http://bit.ly/2GBQ1fR
i-secure Co, Ltd.
อธิบายเจาะลึกเทคนิคยกระดับสิทธิ์ใหม่บนลินุกซ์ "SUDO_INJECT" - Bangkok, Thailand | i-secure Co, Ltd.
เมื่อช่วงสงกรานต์ที่ผ่านมา นักวิจัยด้านความปลอดภัย chaignc จากทีม HexpressoCTF ได้มีเปิดเผยเทคนิคใหม่ในการโจมตี sudo ในระบบปฏิบัติการลินุกซ์เพื่อช่วยยกระดับสิทธิ์ของบัญชีผู้ใช้งานปัจจุบันให้มีสิทธิ์สูงขึ้นภายใต้ชื่อการโจมตีว่า SUDO_INJECT ในบล็อกนี้ ทีมต…
Hack The Box - Teacher Write-up by 0xRick
http://bit.ly/2ULYR4x
Submitted April 20, 2019 at 08:37PM by Ahm3d_H3sham
via reddit http://bit.ly/2KS58qM
http://bit.ly/2ULYR4x
Submitted April 20, 2019 at 08:37PM by Ahm3d_H3sham
via reddit http://bit.ly/2KS58qM
0xRick Owned Root !
Hack The Box - Teacher
Quick Summary Hey guys , today Teacher retired and here is my write-up about it. I don’t have too much to say about this box. It was an easy regular machine , We will exploit an authenticated remote code execution in a vulnerable version of a web application…
Inaugural issue of CyberBites Newsletter/ezine for InfoSec pros [PDF]
http://bit.ly/2XAn6j7
Submitted April 21, 2019 at 12:14AM by IAintShootinMister
via reddit http://bit.ly/2IL7WDg
http://bit.ly/2XAn6j7
Submitted April 21, 2019 at 12:14AM by IAintShootinMister
via reddit http://bit.ly/2IL7WDg
HackTheBox: Teacher write-up by Khaotic
http://bit.ly/2Zm5vgk
Submitted April 21, 2019 at 02:12AM by Khaoticdude
via reddit http://bit.ly/2Dpvx8W
http://bit.ly/2Zm5vgk
Submitted April 21, 2019 at 02:12AM by Khaoticdude
via reddit http://bit.ly/2Dpvx8W
reddit
r/netsec - HackTheBox: Teacher write-up by Khaotic
0 votes and 0 comments so far on Reddit
Writeup for Teacher machine on HackTheBox
http://bit.ly/2PlAKDu
Submitted April 21, 2019 at 01:25AM by mzfr98
via reddit http://bit.ly/2VTYLUF
http://bit.ly/2PlAKDu
Submitted April 21, 2019 at 01:25AM by mzfr98
via reddit http://bit.ly/2VTYLUF
WebRTC Adxploits Over DTLS-UDP: The Latest In A Series of Elegant Exploits
http://bit.ly/2GnnNFt
Submitted April 21, 2019 at 05:48AM by DEVCON3PJS
via reddit http://bit.ly/2W0Pla8
http://bit.ly/2GnnNFt
Submitted April 21, 2019 at 05:48AM by DEVCON3PJS
via reddit http://bit.ly/2W0Pla8
DEVCON | Ad Fraud Security®
WebRTC Adxploits Over DTLS-UDP: The Latest In A Series of Elegant Exploits
DEVCON researchers have observed a massive surge in a series of attacks that could cost digital publishers hundreds of millions of dollars in intercepted programmatic revenue.
pe3zx/huawei-block-list: Captured DNS requests from Huawei P30 Pro to a block list
http://bit.ly/2PiYpoa
Submitted April 21, 2019 at 11:57AM by pe3zx
via reddit http://bit.ly/2ItGXwE
http://bit.ly/2PiYpoa
Submitted April 21, 2019 at 11:57AM by pe3zx
via reddit http://bit.ly/2ItGXwE
GitHub
pe3zx/huawei-block-list
Captured DNS requests from Huawei P30 Pro to a block list - pe3zx/huawei-block-list
Questionnaire about Information Security Awareness (Working adults +20)
http://bit.ly/2DklpP1
Submitted April 21, 2019 at 04:46PM by DrNixon
via reddit http://bit.ly/2Xz9ftf
http://bit.ly/2DklpP1
Submitted April 21, 2019 at 04:46PM by DrNixon
via reddit http://bit.ly/2Xz9ftf
Qualtrics
Online Survey | Built with Qualtrics Experience Management™
Qualtrics makes sophisticated research simple and empowers users to capture customer, product, brand & employee experience insights in one place.
pyEmbed - Small noscript for Embedding Malicious Python Code into Inconspicuous Python Code
http://bit.ly/2KR3V2M
Submitted April 21, 2019 at 09:00PM by kindredsec
via reddit http://bit.ly/2GycefE
http://bit.ly/2KR3V2M
Submitted April 21, 2019 at 09:00PM by kindredsec
via reddit http://bit.ly/2GycefE
GitHub
itsKindred/pyEmbed
Elementary bash noscript that embeds malicious python code within another piece of inconspicuous python code. - itsKindred/pyEmbed
Banking-Grade Credential Stuffing: The Futility of Partial Password Validation
http://bit.ly/2EHZzY8
Submitted April 21, 2019 at 09:57PM by civicode
via reddit http://bit.ly/2vha25O
http://bit.ly/2EHZzY8
Submitted April 21, 2019 at 09:57PM by civicode
via reddit http://bit.ly/2vha25O
The Cloudflare Blog
Banking-Grade Credential Stuffing: The Futility of Partial Password Validation
Recently when logging into one of my credit card providers, I was greeted by a familiar screen. After entering in my username, the service asked me to supply 3 random characters from my password to validate ownership of my account.
Modern Vulnerability Research Techniques on Embedded Systems
http://bit.ly/2Zsltps
Submitted April 21, 2019 at 11:50PM by Arrilius
via reddit http://bit.ly/2IMqenC
http://bit.ly/2Zsltps
Submitted April 21, 2019 at 11:50PM by Arrilius
via reddit http://bit.ly/2IMqenC
breaking-bits.gitbook.io
Modern Vulnerability Research Techniques on Embedded Systems