Swrort PowerShell Stager Analysis [Malware]
https://ift.tt/2YIhyoo
Submitted December 16, 2019 at 11:05PM by kindredsec
via reddit https://ift.tt/36yqe3o
https://ift.tt/2YIhyoo
Submitted December 16, 2019 at 11:05PM by kindredsec
via reddit https://ift.tt/36yqe3o
GitHub
itsKindred/malware-analysis-writeups
A repository of my completed writeups, along with the samples themselves. - itsKindred/malware-analysis-writeups
Ring Account Breaches and why UX Over Security is Dangerous
https://ift.tt/2M0zoOe
Submitted December 17, 2019 at 12:47AM by kissmypiss2
via reddit https://ift.tt/2rTC21h
https://ift.tt/2M0zoOe
Submitted December 17, 2019 at 12:47AM by kissmypiss2
via reddit https://ift.tt/2rTC21h
Techwagyu
Ring and why UX Over Security is Dangerous - Tech Wagyu
Parents of three Tennessee children learned today that a hacker had remotely broke into there Ring smart camera. The hacker spoke to the children and monitored them just four days after the purchase of the device. This sets a dangerous precedent when so many…
Hacking GitHub with Unicode's dotless 'i'.
https://ift.tt/2EpkZXI
Submitted December 17, 2019 at 09:42AM by Gallus
via reddit https://ift.tt/2PV27VF
https://ift.tt/2EpkZXI
Submitted December 17, 2019 at 09:42AM by Gallus
via reddit https://ift.tt/2PV27VF
Wisdom Engineering
Hacking GitHub with Unicode's dotless 'i'.
From combining emoji marks and astral planes, Unicode is under appreciated and poorly understood. One lesser known attack vector is Unicode Case Mapping Collisions— an edge case that many of the best devs don't understand— even at Github.
The problem with IoT and random
https://ift.tt/35vp5cC
Submitted December 17, 2019 at 01:40PM by Diddern
via reddit https://ift.tt/36HrvFh
https://ift.tt/35vp5cC
Submitted December 17, 2019 at 01:40PM by Diddern
via reddit https://ift.tt/36HrvFh
security.christmas
The problem with IoT and random
“The s in IoT stands for security” is a joke as old as the shared code base used in your IoT web-camera. Usually we mock IoT for having little or bad security, but the real issue is perhaps that IoT can't have good security.
#include </etc/shadow>
https://ift.tt/2YZiC7p
Submitted December 17, 2019 at 03:12PM by pimterry
via reddit https://ift.tt/2POi8gg
https://ift.tt/2YZiC7p
Submitted December 17, 2019 at 03:12PM by pimterry
via reddit https://ift.tt/2POi8gg
reddit
#include </etc/shadow>
Posted in r/netsec by u/pimterry • 1 point and 0 comments
BreakingApp – WhatsApp Crash & Data Loss Bug
https://ift.tt/34qonMt
Submitted December 17, 2019 at 05:16PM by hacktvist
via reddit https://ift.tt/36PoZgt
https://ift.tt/34qonMt
Submitted December 17, 2019 at 05:16PM by hacktvist
via reddit https://ift.tt/36PoZgt
Check Point Research
BreakingApp – WhatsApp Crash & Data Loss Bug - Check Point Research
The bug will crash the app and it will continue to crash even after we reopen WhatsApp, resulting in a crash loop. Moreover, the user will not be able to return to thegroup and all the data that was written and shared in the group is now gone for good. The…
Hacking Live stream | Solving pwn, rev questions
https://ift.tt/35vRnnu
Submitted December 17, 2019 at 06:29PM by ISeeFacesInClouds
via reddit https://ift.tt/2sBIeuO
https://ift.tt/35vRnnu
Submitted December 17, 2019 at 06:29PM by ISeeFacesInClouds
via reddit https://ift.tt/2sBIeuO
Twitch
lionaneesh - Twitch
Hacking Live Stream | Playing CTFs for fun!
CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Telerik UI
https://ift.tt/2PMBfam
Submitted December 17, 2019 at 06:55PM by albinowax
via reddit https://ift.tt/2M3arBS
https://ift.tt/2PMBfam
Submitted December 17, 2019 at 06:55PM by albinowax
via reddit https://ift.tt/2M3arBS
Bishopfox
CVE-2019-18935: Remote Code Execution via Insecure Deserialization in Telerik UI
Telerik UI for ASP.NET AJAX insecurely deserializes JSON objects resulting in arbitrary RCE. Learn how to patch and securely configure this software.
(English) CCNA Day-11 :Enhanced Interior Gateway Routing Protocol (EIGRP)
https://ift.tt/2sErSSw
Submitted December 17, 2019 at 10:08PM by ashish016
via reddit https://ift.tt/35wzRQ0
https://ift.tt/2sErSSw
Submitted December 17, 2019 at 10:08PM by ashish016
via reddit https://ift.tt/35wzRQ0
AP Networking Services
AP Networking Services: (English) CCNA Day-11 :Enhanced Interior Gateway Routing Protocol (EIGRP)
CanaryTail — a proposed warrant canary standard for automated canary validation
https://ift.tt/2S0BOjN
Submitted December 18, 2019 at 03:22PM by carrotcypher
via reddit https://ift.tt/38Ki1Lr
https://ift.tt/2S0BOjN
Submitted December 18, 2019 at 03:22PM by carrotcypher
via reddit https://ift.tt/38Ki1Lr
GitHub
canarytail/standard
Contribute to canarytail/standard development by creating an account on GitHub.
Crypto poses billion-dollar risk for banks, cybersecurity firm claims
https://ift.tt/35A83do
Submitted December 18, 2019 at 03:00PM by Tennis3765
via reddit https://ift.tt/35BeA7U
https://ift.tt/35A83do
Submitted December 18, 2019 at 03:00PM by Tennis3765
via reddit https://ift.tt/35BeA7U
Decrypt
Crypto poses billion-dollar risk for banks, cybersecurity firm claims - Decrypt
Blockchain intelligence firm CipherTrace claims banks unknowingly process $2 billion in crypto funds every year, opening themselves up to potential risks.
BlueKeep Vulnerability Can Now Be Detected Easily With This New Scanning Tool
https://ift.tt/38QHPWd
Submitted December 18, 2019 at 05:19PM by harshsharma9619
via reddit https://ift.tt/2M8ZnDj
https://ift.tt/38QHPWd
Submitted December 18, 2019 at 05:19PM by harshsharma9619
via reddit https://ift.tt/2M8ZnDj
TechDator
BlueKeep Vulnerability Can Now Be Detected Easily With This New Scanning Tool
To check if they're vulnerable or not. Here's a new tool that scans the RDP of your system to explore BlueKeep's vulnerability.
Global Payments MITM Vulnerability
https://ift.tt/34DOVdv
Submitted December 18, 2019 at 06:58PM by thegeekbin
via reddit https://ift.tt/2YZ4URS
https://ift.tt/34DOVdv
Submitted December 18, 2019 at 06:58PM by thegeekbin
via reddit https://ift.tt/2YZ4URS
reddit
Global Payments MITM Vulnerability
Posted in r/netsec by u/thegeekbin • 29 points and 2 comments
4 Google Cloud Shell vulns explained
https://ift.tt/2EsfPdA
Submitted December 18, 2019 at 10:09PM by albinowax
via reddit https://ift.tt/35yYQC5
https://ift.tt/2EsfPdA
Submitted December 18, 2019 at 10:09PM by albinowax
via reddit https://ift.tt/35yYQC5
Offensi
4 Google Cloud Shell bugs explained
Quick navigation Introduction (this page)Bug #1 – The Python language serverBug #2 – A custom Cloud Shell imageBug #3 – Git cloneBug #4 – Go and get pwned Note: The vulnerab…
Frida 12.8 is out with massively enhanced support for in-process fuzzing use-cases, including Objective-C and Java calls
https://ift.tt/2sHMLvO
Submitted December 19, 2019 at 01:22AM by oleavr
via reddit https://ift.tt/34x2fjK
https://ift.tt/2sHMLvO
Submitted December 19, 2019 at 01:22AM by oleavr
via reddit https://ift.tt/34x2fjK
reddit
Frida 12.8 is out with massively enhanced support for in-process...
Posted in r/netsec by u/oleavr • 63 points and 6 comments
Most Worst Passwords Of 2019 Are Here, Check If Your Password is in the List
https://ift.tt/2M6ASqo
Submitted December 19, 2019 at 02:05AM by harshsharma9619
via reddit https://ift.tt/2EySAP8
https://ift.tt/2M6ASqo
Submitted December 19, 2019 at 02:05AM by harshsharma9619
via reddit https://ift.tt/2EySAP8
TechDator
Most Worst Passwords Of 2019 Are Here, Check If Your Password is in the List
List of worst passwords of the 2019 list. You can check out the list and see if your password is on the list or not.
TIL Facebook had a Tor gateway.
https://ift.tt/2S3qLX3
Submitted December 19, 2019 at 09:21AM by 8309312feaa9aa4f4628
via reddit https://ift.tt/35x2kVP
https://ift.tt/2S3qLX3
Submitted December 19, 2019 at 09:21AM by 8309312feaa9aa4f4628
via reddit https://ift.tt/35x2kVP
SC Media
Facebook Tor gateway down while TLS certificate renewed | SC Media
Facebook’s Tor gateway will be out of commission for a week or two after a TLS certificate expired. “Our onion service, facebookcorewwwi.onion, is
Operation Wocao: Shining a light on one of China’s hidden hacking groups (APT20)
https://ift.tt/2tAfYJT
Submitted December 19, 2019 at 12:08PM by digicat
via reddit https://ift.tt/2PDNRSC
https://ift.tt/2tAfYJT
Submitted December 19, 2019 at 12:08PM by digicat
via reddit https://ift.tt/2PDNRSC
Demystifying AWS' AssumeRole and sts:ExternalId
https://ift.tt/35ChGbH
Submitted December 19, 2019 at 12:54PM by digicat
via reddit https://ift.tt/2EvFZfh
https://ift.tt/35ChGbH
Submitted December 19, 2019 at 12:54PM by digicat
via reddit https://ift.tt/2EvFZfh
NCC Group Research
Demystifying AWS' AssumeRole and sts:ExternalId
Amazon Web Services’ AssumeRole operation accepts an optional parameter called “sts:ExternalId” which is intended to mitigate certain types of attacks. However, both the attacks t…
From dropbox(updater) to NT AUTHORITY\SYSTEM (another eop via hardlink)
https://ift.tt/2Z63wNp
Submitted December 19, 2019 at 02:54PM by decoder-ap
via reddit https://ift.tt/2r3ToIq
https://ift.tt/2Z63wNp
Submitted December 19, 2019 at 02:54PM by decoder-ap
via reddit https://ift.tt/2r3ToIq
Decoder's Blog
From dropbox(updater) to NT AUTHORITY\SYSTEM
Hardlinks again! Yes, there are plenty of opportunities to raise your privileges due to incorrect permissions settings when combined with hardlinks in many softwares (MS included) ;-) In this post…
Broken Links Repair By Hexometer – WordPress plugin
https://ift.tt/38Sudtx
Submitted December 19, 2019 at 04:08PM by Drileyll
via reddit https://ift.tt/38VIsOk
https://ift.tt/38Sudtx
Submitted December 19, 2019 at 04:08PM by Drileyll
via reddit https://ift.tt/38VIsOk
WordPress.org
Broken Links Repair By Hexometer
Broken Links Repair Plugin disables the bad links in your content immediately upon detection by Hexometer.com scanner.