Unpacking ASIC firmware: AntMiner Exploited
http://bit.ly/2YNPMpi
Submitted May 26, 2019 at 04:55PM by serhack
via reddit http://bit.ly/30TZPuW
http://bit.ly/2YNPMpi
Submitted May 26, 2019 at 04:55PM by serhack
via reddit http://bit.ly/30TZPuW
serhack.me
Unpacking ASIC firmware: AntMiner Exploited - SerHack Security Engineer
Unpacking and reverse engineering of Bitmain AntMiner Z11 firmware.
PoC: Encrypting Shellcode Into Invisible Unicode Characters
http://bit.ly/2EC3eFc
Submitted May 26, 2019 at 09:04PM by sectronex
via reddit http://bit.ly/2HAvTfw
http://bit.ly/2EC3eFc
Submitted May 26, 2019 at 09:04PM by sectronex
via reddit http://bit.ly/2HAvTfw
www.vallejo.cc
PoC: Encrypting Shellcode Into Invisible Unicode Characters
Malware has been using unicode since time ago, to hide / obfuscate urls, filenames, noscripts, etc... Right-to-left Override character (e2 80 ...
RCE Without Native Code: Exploitation of a Write-What-Where in Internet Explorer
http://bit.ly/2Em1qzK
Submitted May 27, 2019 at 12:13AM by joshuajpearce
via reddit http://bit.ly/2Xbl5tK
http://bit.ly/2Em1qzK
Submitted May 27, 2019 at 12:13AM by joshuajpearce
via reddit http://bit.ly/2Xbl5tK
Zero Day Initiative
RCE Without Native Code: Exploitation of a Write-What-Where in Internet Explorer
On the last day of 2018, I discovered a type confusion vulnerability in Internet Explorer that yields a clean write-what-where primitive. It patched this April as CVE-2019-0752 . As an exercise, I wrote a full exploit for this vulnerability using an original…
Work Diary - SystemBack & Third Party Security Tools
http://bit.ly/2woMPzb
Submitted May 27, 2019 at 10:56AM by Eta-Meson
via reddit http://bit.ly/2JI6fYu
http://bit.ly/2woMPzb
Submitted May 27, 2019 at 10:56AM by Eta-Meson
via reddit http://bit.ly/2JI6fYu
Medium
Work Diary - SystemBack & Third Party Security Tools
I have recently joined a startup and have been a part of their InfoSec team. Recently this thought popped up in my mind that I should…
Endpoint Isolation with the Windows Firewall
http://bit.ly/2Hf6IiE
Submitted May 27, 2019 at 11:57AM by disclosure5
via reddit http://bit.ly/2WtDm8v
http://bit.ly/2Hf6IiE
Submitted May 27, 2019 at 11:57AM by disclosure5
via reddit http://bit.ly/2WtDm8v
Medium
Endpoint Isolation with the Windows Firewall
Over the last few weeks, I’ve had conversations with several individuals around mitigating lateral movement in a Windows environment. In…
Building a real-world web honeypot for CVE-2019–6340 (RCE in Drupal core)
http://bit.ly/2W2GXuV
Submitted May 27, 2019 at 01:24PM by _bend3r
via reddit http://bit.ly/2wpCCm4
http://bit.ly/2W2GXuV
Submitted May 27, 2019 at 01:24PM by _bend3r
via reddit http://bit.ly/2wpCCm4
Medium
Building a real-world web honeypot for CVE-2019–6340 (RCE in Drupal core)
A while ago I started a project for managing real-word web honeypots. I initially built it to manage some WordPress honeypots but after…
Tickey: extracting kerberos tickets from kernel keyring (post-explotation tool)
http://bit.ly/2WpsFnr
Submitted May 27, 2019 at 06:20PM by gid0rah
via reddit http://bit.ly/2McyfFW
http://bit.ly/2WpsFnr
Submitted May 27, 2019 at 06:20PM by gid0rah
via reddit http://bit.ly/2McyfFW
GitHub
TarlogicSecurity/tickey
Tool to extract Kerberos tickets from Linux kernel keys. - TarlogicSecurity/tickey
Update your Fortigates if you use SSLVPN. Major and minor vulnerabilities found
http://bit.ly/2wpKRyJ
Submitted May 27, 2019 at 09:17PM by Ungolive
via reddit http://bit.ly/2VOMQXH
http://bit.ly/2wpKRyJ
Submitted May 27, 2019 at 09:17PM by Ungolive
via reddit http://bit.ly/2VOMQXH
reddit
r/fortinet - Update your Fortigates if you use SSLVPN. Major and minor vulnerabilities found
0 votes and 1 comment so far on Reddit
Introduction to analysing full disk encryption solutions
http://bit.ly/2VYco4M
Submitted May 27, 2019 at 09:06PM by DiabloHorn
via reddit http://bit.ly/2WumFK5
http://bit.ly/2VYco4M
Submitted May 27, 2019 at 09:06PM by DiabloHorn
via reddit http://bit.ly/2WumFK5
DiabloHorn
Introduction to analysing full disk encryption solutions
I’ve written a couple of times on the subject of boot loaders and full disk encryption, but I haven’t really explored it in more detail. With this blog post I hope to dive a bit deeper …
h8mail v2: Password Breach Hunting locally or using premium services. Supports chasing down related email
http://bit.ly/2AE2yNq
Submitted May 28, 2019 at 05:31AM by khast3x
via reddit http://bit.ly/2JHMqAQ
http://bit.ly/2AE2yNq
Submitted May 28, 2019 at 05:31AM by khast3x
via reddit http://bit.ly/2JHMqAQ
GitHub
khast3x/h8mail
Password Breach Hunting and Email OSINT locally or using premium services. Supports chasing down related email - khast3x/h8mail
Frida 12.6 is out with major stability improvements on all platforms
http://bit.ly/2HFe3rW
Submitted May 28, 2019 at 06:19AM by oleavr
via reddit http://bit.ly/2YOEhhi
http://bit.ly/2HFe3rW
Submitted May 28, 2019 at 06:19AM by oleavr
via reddit http://bit.ly/2YOEhhi
Frida • A world-class dynamic instrumentation framework
Frida 12.6 Released
Inject JavaScript to explore native apps on Windows, macOS, GNU/Linux, iOS, Android, and QNX
Sample Pentest Report
http://bit.ly/30Ot564
Submitted May 28, 2019 at 12:09PM by DorkNowitzki41
via reddit http://bit.ly/2VWwHzg
http://bit.ly/30Ot564
Submitted May 28, 2019 at 12:09PM by DorkNowitzki41
via reddit http://bit.ly/2VWwHzg
GitHub
hmaverickadams/TCM-Security-Sample-Pentest-Report
Sample pentest report provided by TCM Security. Contribute to hmaverickadams/TCM-Security-Sample-Pentest-Report development by creating an account on GitHub.
investmentweek.co.uk left 330k user records exposed
http://bit.ly/2HGfXZj
Submitted May 28, 2019 at 03:22PM by drew-o
via reddit http://bit.ly/2JL031R
http://bit.ly/2HGfXZj
Submitted May 28, 2019 at 03:22PM by drew-o
via reddit http://bit.ly/2JL031R
reddit
r/privacy - investmentweek.co.uk left 330k user records exposed
0 votes and 0 comments so far on Reddit
Throwing 160 CPUs at OpenSSL 1 year CPU target.
http://bit.ly/2HG7x43
Submitted May 28, 2019 at 05:31PM by jekapats
via reddit http://bit.ly/2YRlp1e
http://bit.ly/2HG7x43
Submitted May 28, 2019 at 05:31PM by jekapats
via reddit http://bit.ly/2YRlp1e
Fuzzit
Throwing 160 CPUs at 1 Year Fuzzing Target - Fuzzit
In this blog post we will walk through how throwing 160 distributed CPUs at a fuzzing target that takes initially one year of CPU time can shorten the fuzzing time substantially. Also we will share test-cases where throwing more CPUs … Read More
Shift Left on Cloud Security, Part II - Phases of the SDLC
http://bit.ly/2K4fEcq
Submitted May 28, 2019 at 06:49PM by OnlyInstruction
via reddit http://bit.ly/2JIC03W
http://bit.ly/2K4fEcq
Submitted May 28, 2019 at 06:49PM by OnlyInstruction
via reddit http://bit.ly/2JIC03W
www.fugue.co
Shift Left on Cloud Security, Part II - Phases of the SDLC
By extending cloud infrastructure security left to development and testing phases, we can have a high degree of certainty that the production environment meets policy when deployed.
fatt /fingerprintAllTheThings - a pyshark based noscript for extracting network metadata and fingerprints from pcap files and live network traffic
http://bit.ly/2HGDXf1
Submitted May 28, 2019 at 07:33PM by fo0
via reddit http://bit.ly/2QwhtQl
http://bit.ly/2HGDXf1
Submitted May 28, 2019 at 07:33PM by fo0
via reddit http://bit.ly/2QwhtQl
GitHub
0x4D31/fatt
fatt /fingerprintAllTheThings - a pyshark based noscript for extracting network metadata and fingerprints from pcap files and live network traffic - 0x4D31/fatt
Ad Fraud Makes it's way to Twitter's Promoted Content (Social engineering, Ad fraud, Fake News)
http://bit.ly/2whrMPe
Submitted May 28, 2019 at 09:37PM by DEVCON3PJS
via reddit http://bit.ly/2YMSUlc
http://bit.ly/2whrMPe
Submitted May 28, 2019 at 09:37PM by DEVCON3PJS
via reddit http://bit.ly/2YMSUlc
BuzzFeed News
Twitter Is Showing More Ads, And People Are Seeing Lots Of Weird Crap As A Result
One malicious campaign used false articles about Drake and the Weeknd to promote casinos.
Almost One Million Vulnerable to BlueKeep Vuln (CVE-2019-0708)
http://bit.ly/2wprAgQ
Submitted May 28, 2019 at 10:04PM by zexterio
via reddit http://bit.ly/2VRqpkt
http://bit.ly/2wprAgQ
Submitted May 28, 2019 at 10:04PM by zexterio
via reddit http://bit.ly/2VRqpkt
Erratasec
Almost One Million Vulnerable to BlueKeep Vuln (CVE-2019-0708)
Microsoft announced a vulnerability in it's "Remote Desktop" product that can lead to robust, wormable exploits. I scanned the Internet to a...
Post-Exploitation with Leprechaun (finding interesting systems and connections)
http://bit.ly/2X9oqJK
Submitted May 28, 2019 at 10:00PM by altjx
via reddit http://bit.ly/2HGyWCS
http://bit.ly/2X9oqJK
Submitted May 28, 2019 at 10:00PM by altjx
via reddit http://bit.ly/2HGyWCS
Vonahi Security's Blog
Post-Exploitation with Leprechaun
Finding valuable data during post-exploitation can be a challenge. Leprechaun helps solve this problem.
Analysis of a 1day (cve-2019-0547) and discovery of a forgotten condition in the patch (cve-2019-0726) 1/2
http://bit.ly/2JEmXs1
Submitted May 29, 2019 at 03:53AM by h3ku
via reddit http://bit.ly/2WsbIJ3
http://bit.ly/2JEmXs1
Submitted May 29, 2019 at 03:53AM by h3ku
via reddit http://bit.ly/2WsbIJ3
Sensepost
SensePost | Analysis of a 1day (cve-2019-0547) and discovery of a forgotten condition in the patch (cve-2019-0726) – part 1 of…
Leaders in Information Security
Check End of Life of php, python, ubuntu, alpine, laravel etc at one place. Verify whether your application needs an update, or if you need to upgrade your device.
https://endoflife.date/
Submitted May 29, 2019 at 07:13AM by Gallus
via reddit http://bit.ly/2MenQJW
https://endoflife.date/
Submitted May 29, 2019 at 07:13AM by Gallus
via reddit http://bit.ly/2MenQJW
reddit
r/netsec - Check End of Life of php, python, ubuntu, alpine, laravel etc at one place. Verify whether your application needs an…
0 votes and 0 comments so far on Reddit