Frida 12.8 is out with massively enhanced support for in-process fuzzing use-cases, including Objective-C and Java calls
https://ift.tt/2sHMLvO
Submitted December 19, 2019 at 01:22AM by oleavr
via reddit https://ift.tt/34x2fjK
https://ift.tt/2sHMLvO
Submitted December 19, 2019 at 01:22AM by oleavr
via reddit https://ift.tt/34x2fjK
reddit
Frida 12.8 is out with massively enhanced support for in-process...
Posted in r/netsec by u/oleavr • 63 points and 6 comments
Most Worst Passwords Of 2019 Are Here, Check If Your Password is in the List
https://ift.tt/2M6ASqo
Submitted December 19, 2019 at 02:05AM by harshsharma9619
via reddit https://ift.tt/2EySAP8
https://ift.tt/2M6ASqo
Submitted December 19, 2019 at 02:05AM by harshsharma9619
via reddit https://ift.tt/2EySAP8
TechDator
Most Worst Passwords Of 2019 Are Here, Check If Your Password is in the List
List of worst passwords of the 2019 list. You can check out the list and see if your password is on the list or not.
TIL Facebook had a Tor gateway.
https://ift.tt/2S3qLX3
Submitted December 19, 2019 at 09:21AM by 8309312feaa9aa4f4628
via reddit https://ift.tt/35x2kVP
https://ift.tt/2S3qLX3
Submitted December 19, 2019 at 09:21AM by 8309312feaa9aa4f4628
via reddit https://ift.tt/35x2kVP
SC Media
Facebook Tor gateway down while TLS certificate renewed | SC Media
Facebook’s Tor gateway will be out of commission for a week or two after a TLS certificate expired. “Our onion service, facebookcorewwwi.onion, is
Operation Wocao: Shining a light on one of China’s hidden hacking groups (APT20)
https://ift.tt/2tAfYJT
Submitted December 19, 2019 at 12:08PM by digicat
via reddit https://ift.tt/2PDNRSC
https://ift.tt/2tAfYJT
Submitted December 19, 2019 at 12:08PM by digicat
via reddit https://ift.tt/2PDNRSC
Demystifying AWS' AssumeRole and sts:ExternalId
https://ift.tt/35ChGbH
Submitted December 19, 2019 at 12:54PM by digicat
via reddit https://ift.tt/2EvFZfh
https://ift.tt/35ChGbH
Submitted December 19, 2019 at 12:54PM by digicat
via reddit https://ift.tt/2EvFZfh
NCC Group Research
Demystifying AWS' AssumeRole and sts:ExternalId
Amazon Web Services’ AssumeRole operation accepts an optional parameter called “sts:ExternalId” which is intended to mitigate certain types of attacks. However, both the attacks t…
From dropbox(updater) to NT AUTHORITY\SYSTEM (another eop via hardlink)
https://ift.tt/2Z63wNp
Submitted December 19, 2019 at 02:54PM by decoder-ap
via reddit https://ift.tt/2r3ToIq
https://ift.tt/2Z63wNp
Submitted December 19, 2019 at 02:54PM by decoder-ap
via reddit https://ift.tt/2r3ToIq
Decoder's Blog
From dropbox(updater) to NT AUTHORITY\SYSTEM
Hardlinks again! Yes, there are plenty of opportunities to raise your privileges due to incorrect permissions settings when combined with hardlinks in many softwares (MS included) ;-) In this post…
Broken Links Repair By Hexometer – WordPress plugin
https://ift.tt/38Sudtx
Submitted December 19, 2019 at 04:08PM by Drileyll
via reddit https://ift.tt/38VIsOk
https://ift.tt/38Sudtx
Submitted December 19, 2019 at 04:08PM by Drileyll
via reddit https://ift.tt/38VIsOk
WordPress.org
Broken Links Repair By Hexometer
Broken Links Repair Plugin disables the bad links in your content immediately upon detection by Hexometer.com scanner.
Best 2019 Christmas gift ideas that no one ever thought of
https://ift.tt/2PB7xXc
Submitted December 19, 2019 at 06:29PM by swampman74
via reddit https://ift.tt/35DpvxP
https://ift.tt/2PB7xXc
Submitted December 19, 2019 at 06:29PM by swampman74
via reddit https://ift.tt/35DpvxP
Medium
Best 2019 Christmas gift ideas that no one ever thought of. Password managers and Antivirus software
Christmas is basically in one week, and if you are like me, which means you are not keen on the idea of going into actual shops and…
Make HID great again - from an old Wireless adaptor to a reverse shell in a Digispark
https://ift.tt/36Sw1Rv
Submitted December 19, 2019 at 08:53PM by s0pas
via reddit https://ift.tt/2Z6p1xR
https://ift.tt/36Sw1Rv
Submitted December 19, 2019 at 08:53PM by s0pas
via reddit https://ift.tt/2Z6p1xR
Davidsopas
Make HID great again | David Sopas - Web Security Researcher
Since ever I've been using HID devices on red-team assessments at Char49 - specially using Rubber Ducky and latelly with Cactus WHID. I wanted to play a little
An experience with Daimler’s vulnerability reporting program
https://ift.tt/2sN8TFq
Submitted December 20, 2019 at 01:16AM by EatonZ
via reddit https://ift.tt/2M7cFAb
https://ift.tt/2sN8TFq
Submitted December 20, 2019 at 01:16AM by EatonZ
via reddit https://ift.tt/2M7cFAb
reddit
An experience with Daimler’s vulnerability reporting program
Posted in r/netsec by u/EatonZ • 40 points and 9 comments
A Data Leak Exposed The Personal Information Of Over 3,000 Ring Users
https://ift.tt/2Sa4qqI
Submitted December 20, 2019 at 01:36AM by DefinitelyNotTheNSA-
via reddit https://ift.tt/2SbwZEe
https://ift.tt/2Sa4qqI
Submitted December 20, 2019 at 01:36AM by DefinitelyNotTheNSA-
via reddit https://ift.tt/2SbwZEe
BuzzFeed News
A Data Leak Exposed The Personal Information Of Over 3,000 Ring Users
“This gives a potential attacker access to view cameras in somebody’s home — that’s a real serious potential invasion of privacy right there.”
PandorFMS remote code execution vulnerability (with an authenticated user)
https://ift.tt/34AEib7
Submitted December 20, 2019 at 02:27AM by spudball
via reddit https://ift.tt/2PF4NIo
https://ift.tt/34AEib7
Submitted December 20, 2019 at 02:27AM by spudball
via reddit https://ift.tt/2PF4NIo
Medium
Remote Code Execution Vulnerability in PandoraFMS 7.x
I found a security vulnerability in PandoraFMS 7 Monitoring System. As an authenticated user it is possible to modify or configure alerts…
Wawa Breached: Payment Processing Servers Hit with Malware, Undetected Since March 4, 2019
https://ift.tt/2s3KefC
Submitted December 20, 2019 at 04:56AM by blueperception
via reddit https://ift.tt/35Hn90G
https://ift.tt/2s3KefC
Submitted December 20, 2019 at 04:56AM by blueperception
via reddit https://ift.tt/35Hn90G
Apple Security Bounty
https://ift.tt/2Q2cTtA
Submitted December 20, 2019 at 07:47AM by ttocslliw
via reddit https://ift.tt/35GyWfW
https://ift.tt/2Q2cTtA
Submitted December 20, 2019 at 07:47AM by ttocslliw
via reddit https://ift.tt/35GyWfW
Apple Developer
Apple Security Bounty - Apple Developer
As part of Apple’s commitment to security, we reward researchers who share with us critical issues and the techniques used to exploit them.
I discovered a new technique to bypass null byte POPPOPRET's during local SEH exploitation
https://ift.tt/2PDPcZA
Submitted December 20, 2019 at 08:46AM by Signal-Education
via reddit https://ift.tt/2S9WhCP
https://ift.tt/2PDPcZA
Submitted December 20, 2019 at 08:46AM by Signal-Education
via reddit https://ift.tt/2S9WhCP
GitHub
FULLSHADE/POPPOPRET-nullbyte-DLL-bypass
A method to bypass a null byte in a POP-POP-RETN address for exploiting local SEH overflows via DLL injection - FULLSHADE/POPPOPRET-nullbyte-DLL-bypass
Whoopsie-daisy: Chaining accidental features of Ubuntu’s crash reporter to get LPE
https://ift.tt/2rg0hqm
Submitted December 20, 2019 at 12:45PM by 0xdea
via reddit https://ift.tt/2PIkwGG
https://ift.tt/2rg0hqm
Submitted December 20, 2019 at 12:45PM by 0xdea
via reddit https://ift.tt/2PIkwGG
Github
Whoopsie-daisy: Chaining accidental features of Ubuntu’s crash reporter to get LPE - GitHub Security Lab
Securing the world's software, together.
Flipper Zero: Under Development Multi-tool Device for Pen-Testers
https://ift.tt/2SaPsAT
Submitted December 20, 2019 at 03:12PM by dukeofmola
via reddit https://ift.tt/2Smhcmn
https://ift.tt/2SaPsAT
Submitted December 20, 2019 at 03:12PM by dukeofmola
via reddit https://ift.tt/2Smhcmn
flipperzero.one
Flipper Zero — Multi-tool Device for Hackers. Lite version based on STM32
Based on ultra low power STM32 MCU for daily hacking of access control systems, radio protocols. Compatible with Arduino IDE and PlatformIO.
The Hacker Who Took Down a Country
https://ift.tt/2sPujkU
Submitted December 20, 2019 at 05:50PM by Fugitif
via reddit https://ift.tt/35HiH2h
https://ift.tt/2sPujkU
Submitted December 20, 2019 at 05:50PM by Fugitif
via reddit https://ift.tt/35HiH2h
Bloomberg.com
The Hacker Who Took Down a Country
Daniel Kaye, also known as Spdrman, found regular jobs tough but corporate espionage easy. He’s about to get out of prison.
On Linux's Random Number Generation
https://ift.tt/34HRsDj
Submitted December 20, 2019 at 07:26PM by digicat
via reddit https://ift.tt/38SA8il
https://ift.tt/34HRsDj
Submitted December 20, 2019 at 07:26PM by digicat
via reddit https://ift.tt/38SA8il
NCC Group Research
On Linux's Random Number Generation
I have been asked about the usefulness of security monitoring of entropy levels in the Linux kernel. This calls for some explanation of how random generation works in Linux systems. So, randomness …
How to use your Ledger crypto wallet to secure Gmail, Facebook accounts
https://ift.tt/2EG4YNk
Submitted December 20, 2019 at 08:19PM by Tennis3765
via reddit https://ift.tt/34KrDT4
https://ift.tt/2EG4YNk
Submitted December 20, 2019 at 08:19PM by Tennis3765
via reddit https://ift.tt/34KrDT4
Decrypt
How to use your Ledger crypto wallet to secure Gmail, Facebook accounts - Decrypt
Crypto security and hardware developer Ledger has a new 2FA system that, while designed for crypto, can now protect your Google, Facebook or GitHub accounts
Using WebRTC ICE Servers for Port Scanning in Chrome
https://ift.tt/35Dx4EF
Submitted December 20, 2019 at 08:57PM by chicksdigthelongrun
via reddit https://ift.tt/2sMjMHl
https://ift.tt/35Dx4EF
Submitted December 20, 2019 at 08:57PM by chicksdigthelongrun
via reddit https://ift.tt/2sMjMHl
Medium
Using WebRTC ICE Servers for Port Scanning in Chrome
To everything (TURN! TURN! TURN!)