Neat solution for storing fingerprints in biometric scanners for grocery stores
https://ift.tt/38bKVE0
Submitted December 06, 2019 at 02:30PM by Diddern
via reddit https://ift.tt/2OUJSAz
https://ift.tt/38bKVE0
Submitted December 06, 2019 at 02:30PM by Diddern
via reddit https://ift.tt/2OUJSAz
security.christmas
Here, have my biometric data, I don´t care.
Some grocery stores in Norway use fingerprints for verifying the users age when buying an item that has age-restrictions. The security of this solution gets a thumb up 👍
Cesanta Mongoose 6.16 - Integer overflow
https://ift.tt/2OWS6YM
Submitted December 06, 2019 at 03:05PM by everping
via reddit https://ift.tt/2sLLJ1W
https://ift.tt/2OWS6YM
Submitted December 06, 2019 at 03:05PM by everping
via reddit https://ift.tt/2sLLJ1W
CyStack Security Blog
Cesanta Mongoose 6.16 - Integer overflow
CyStack Advisory IDCSA-2019-04CVE IDs CVE-2019-19307
[https://nvd.nist.gov/vuln/detail/CVE-2019-19307]SeverityCriticalCVSS v3 Base9.8
Synopsis
CyStack Security discovered an integer overflow vulnerability in the
implementation of MQTT protocol in the Cesanta…
[https://nvd.nist.gov/vuln/detail/CVE-2019-19307]SeverityCriticalCVSS v3 Base9.8
Synopsis
CyStack Security discovered an integer overflow vulnerability in the
implementation of MQTT protocol in the Cesanta…
The “Great Cannon” has been deployed again
https://ift.tt/365DdJF
Submitted December 06, 2019 at 04:50PM by ram132
via reddit https://ift.tt/2YxlxUR
https://ift.tt/365DdJF
Submitted December 06, 2019 at 04:50PM by ram132
via reddit https://ift.tt/2YxlxUR
Att
The “Great Cannon” has been deployed again
Summary
The Great Cannon is a distributed denial of service tool (“DDoS”) that operates by injecting malicious Javascript into pages served from behind the Great Firewall. These scripts, potentially served to millions of users across the internet, hijack…
The Great Cannon is a distributed denial of service tool (“DDoS”) that operates by injecting malicious Javascript into pages served from behind the Great Firewall. These scripts, potentially served to millions of users across the internet, hijack…
Bigger security issue in OpenBSD
https://ift.tt/34RxdE5
Submitted December 06, 2019 at 06:13PM by seclurkern
via reddit https://ift.tt/2DTWfXq
https://ift.tt/34RxdE5
Submitted December 06, 2019 at 06:13PM by seclurkern
via reddit https://ift.tt/2DTWfXq
reddit
Bigger security issue in OpenBSD
Posted in r/netsec by u/seclurkern • 3 points and 0 comments
Webinar: How to Detect Sophisticated Attackers with Tactical Analytics (Intrusion detection examples included)
https://ift.tt/2OV8jhd
Submitted December 06, 2019 at 06:41PM by dimitrios_eLS
via reddit https://ift.tt/33SATUU
https://ift.tt/2OV8jhd
Submitted December 06, 2019 at 06:41PM by dimitrios_eLS
via reddit https://ift.tt/33SATUU
Medium
Blue Team Diary, Entry #2: Defeating Advanced Adversaries with Tactical Analytics
How to Effectively Transition to SOC 3.0 Operations
HTTP Request Smuggling + IDOR
https://ift.tt/2RjZsYd
Submitted December 06, 2019 at 07:50PM by DieBlackfisk
via reddit https://ift.tt/34Z5UYG
https://ift.tt/2RjZsYd
Submitted December 06, 2019 at 07:50PM by DieBlackfisk
via reddit https://ift.tt/34Z5UYG
hipotermia.pw
hipotermia - HTTP Request Smuggling + IDOR
A bug chain of HTTP Request Smuggling and an IDOR which allows to retrieve user sensitive data
crt.sh wrapper with golang
https://ift.tt/3679aBe
Submitted December 06, 2019 at 08:52PM by oil_sardine
via reddit https://ift.tt/34X3rh9
https://ift.tt/3679aBe
Submitted December 06, 2019 at 08:52PM by oil_sardine
via reddit https://ift.tt/34X3rh9
GitHub
famasoon/crtsh
This tool shows the result of crt.sh. Contribute to famasoon/crtsh development by creating an account on GitHub.
[Vuln. Report] Omron Denial-of-Service as a Feature
https://ift.tt/389DRYx
Submitted December 06, 2019 at 10:48PM by Ox6e3062306479
via reddit https://ift.tt/33Z75FY
https://ift.tt/389DRYx
Submitted December 06, 2019 at 10:48PM by Ox6e3062306479
via reddit https://ift.tt/33Z75FY
reddit
[Vuln. Report] Omron Denial-of-Service as a Feature
[https://ics.i3xplore.com/2019/12/06/omron-plc-denial-of-service-as-a-feature/](https://ics.i3xplore.com/2019/12/06/omron-plc-denial-of-service-as-...
Google Chrome portal element fuzzing
https://ift.tt/33VDEVi
Submitted December 07, 2019 at 01:17AM by h0wlu
via reddit https://ift.tt/2LufZVH
https://ift.tt/33VDEVi
Submitted December 07, 2019 at 01:17AM by h0wlu
via reddit https://ift.tt/2LufZVH
blog.redteam.pl
Google Chrome portal element fuzzing
red team, blue team, penetration testing, red teaming, threat hunting, digital forensics, incident response, cyber security, IT security
We thought they were potatoes but they were beans (from Service Account to SYSTEM again)
https://ift.tt/33QeZ4A
Submitted December 07, 2019 at 01:46AM by splinter_code
via reddit https://ift.tt/2YuDV0n
https://ift.tt/33QeZ4A
Submitted December 07, 2019 at 01:46AM by splinter_code
via reddit https://ift.tt/2YuDV0n
Decoder's Blog
We thought they were potatoes but they were beans (from Service Account to SYSTEM again)
This post has been written by me and two friends: @splinter_code and 0xea31 This is the “unintended” result of a research we did on Juicypotato exploit in order to find a possibl…
Hack The Box - Wall Write-up by 0xRick
https://ift.tt/36febrk
Submitted December 07, 2019 at 08:37PM by Ahm3d_H3sham
via reddit https://ift.tt/2P2MWuF
https://ift.tt/36febrk
Submitted December 07, 2019 at 08:37PM by Ahm3d_H3sham
via reddit https://ift.tt/2P2MWuF
0xRick
Hack The Box - Wall
My write-up / walkthrough for Wall from Hack The Box.
HackTheBox: Wall -Writeup by Khaotic
https://ift.tt/2YpOeTo
Submitted December 07, 2019 at 08:29PM by Khaoticdude
via reddit https://ift.tt/2DZ5dCs
https://ift.tt/2YpOeTo
Submitted December 07, 2019 at 08:29PM by Khaoticdude
via reddit https://ift.tt/2DZ5dCs
Khaotic Developments
Hack The Box: Wall
Jump Ahead: Enum – Getting a Rev. Shell – Root – Resources – Shoutout TL;DR; To solve this machine we enumerate open ports – finding ports 80 and 22 open. Enumerating …
[threat hunting] badsec.io - An online domain permutation, certificate transparency lookup utility
https://ift.tt/38ky3LU
Submitted December 08, 2019 at 12:38AM by evo4ce
via reddit https://ift.tt/2Pmff61
https://ift.tt/38ky3LU
Submitted December 08, 2019 at 12:38AM by evo4ce
via reddit https://ift.tt/2Pmff61
Reddit
From the netsec community on Reddit: [threat hunting] badsec.io - An online domain permutation, certificate transparency lookup…
Posted by evo4ce - 50 votes and 2 comments
Tunneling traffic through MySQL service (or your mysqld is my new SOCKS5)
https://ift.tt/2YqveEi
Submitted December 08, 2019 at 03:24AM by gid0rah
via reddit https://ift.tt/2PlLaUc
https://ift.tt/2YqveEi
Submitted December 08, 2019 at 03:24AM by gid0rah
via reddit https://ift.tt/2PlLaUc
x-c3ll.github.io
Tunneling traffic through MySQL service (or your mysqld is my new SOCKS5) ::
DoomsDay Vault
DoomsDay Vault
Description of how to pivot though the MySQL service. Turning MySQL into a SOCKS5 that can be used by proxychains.
High performance WordPress login bruteforcer
https://ift.tt/38gINe6
Submitted December 08, 2019 at 08:05AM by lle-bout
via reddit https://ift.tt/38j5MFe
https://ift.tt/38gINe6
Submitted December 08, 2019 at 08:05AM by lle-bout
via reddit https://ift.tt/38j5MFe
GitHub
GitHub - llebout/wpbrute-rs: High performance WordPress login bruteforcer with automatic concurrency for maximum amount of tries…
High performance WordPress login bruteforcer with automatic concurrency for maximum amount of tries per second. - llebout/wpbrute-rs
Global Offshore Corporate Networks Exposed in Massive Data Leak - UNICORN RIOT
https://ift.tt/37Wh8yO
Submitted December 08, 2019 at 04:04PM by MayonaiseRemover
via reddit https://ift.tt/2s6ylFk
https://ift.tt/37Wh8yO
Submitted December 08, 2019 at 04:04PM by MayonaiseRemover
via reddit https://ift.tt/2s6ylFk
UNICORN RIOT
Global Offshore Corporate Networks Exposed in Massive Data Leak - UNICORN RIOT
LONDON, UK – Hundreds of thousands of documents from inside Formations House, a posh British finance firm located in central London, have been released online tonight. Formations House created thousands of companies for ultra-wealthy business-people for offshore…
Report: Millions of Americans at Risk After Huge Data and SMS Leak
https://ift.tt/34AlpWF
Submitted December 08, 2019 at 07:42PM by KoViPe
via reddit https://ift.tt/2sYldTd
https://ift.tt/34AlpWF
Submitted December 08, 2019 at 07:42PM by KoViPe
via reddit https://ift.tt/2sYldTd
vpnMentor
Report: Millions of Americans at Risk After Huge Data and SMS Leak
Introduction
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a breached database belonging to the American communications company, TrueDialog.
TrueDialog
Led by Noam Rotem and Ran Locar, vpnMentor’s research team discovered a breached database belonging to the American communications company, TrueDialog.
TrueDialog
A cookbook for hackers, forensic analyst, pentester, and security engineer
https://ift.tt/2rhLJXl
Submitted December 09, 2019 at 12:29AM by xcorshinex
via reddit https://ift.tt/36gJpyC
https://ift.tt/2rhLJXl
Submitted December 09, 2019 at 12:29AM by xcorshinex
via reddit https://ift.tt/36gJpyC
reddit
A cookbook for hackers, forensic analyst, pentester, and security...
[https://drive.google.com/file/d/0B-OpLAp8EyTfbEVfTm5OdkVXT2s/view?usp=sharing](https://drive.google.com/file/d/0B-OpLAp8EyTfbEVfTm5OdkVXT2s/view?u...
Pentesting Training Website Challenges Authentication Best Practices
https://ift.tt/352Lmyv
Submitted December 09, 2019 at 05:27AM by arrayleads
via reddit https://ift.tt/2E0iScI
https://ift.tt/352Lmyv
Submitted December 09, 2019 at 05:27AM by arrayleads
via reddit https://ift.tt/2E0iScI
Techwagyu
Pentesting Training Website Challenges Authentication Best Practices - Tech Wagyu
The penetration testing company Practical Pentest Labs has recently come under fire for how they handle user passwords. The passwords for user accounts were sent via email to users upon sign up in clear text. The argument was made that these could be intercepted…
Configuring MTA-STS and SMTP TLS-RPT
https://ift.tt/2LDHe0a
Submitted December 09, 2019 at 05:16AM by fmisle
via reddit https://ift.tt/36h1a0B
https://ift.tt/2LDHe0a
Submitted December 09, 2019 at 05:16AM by fmisle
via reddit https://ift.tt/36h1a0B
Faisalmisle
Configuring MTA-STS and SMTP TLS-RPT | Faisal Misle
Faisal's Blog
MalwinX: A framework for learning Malware and win32 functions
https://ift.tt/2RzlV3q
Submitted December 09, 2019 at 07:08AM by beyonderdabas
via reddit https://ift.tt/2DVg00L
https://ift.tt/2RzlV3q
Submitted December 09, 2019 at 07:08AM by beyonderdabas
via reddit https://ift.tt/2DVg00L
securityviacode.in
MalwinX: A framework for learning Malware and win32 functions
Just a normal flask web app to understand win32api with code snippets and references.