PandorFMS remote code execution vulnerability (with an authenticated user)
https://ift.tt/34AEib7
Submitted December 20, 2019 at 02:27AM by spudball
via reddit https://ift.tt/2PF4NIo
https://ift.tt/34AEib7
Submitted December 20, 2019 at 02:27AM by spudball
via reddit https://ift.tt/2PF4NIo
Medium
Remote Code Execution Vulnerability in PandoraFMS 7.x
I found a security vulnerability in PandoraFMS 7 Monitoring System. As an authenticated user it is possible to modify or configure alerts…
Wawa Breached: Payment Processing Servers Hit with Malware, Undetected Since March 4, 2019
https://ift.tt/2s3KefC
Submitted December 20, 2019 at 04:56AM by blueperception
via reddit https://ift.tt/35Hn90G
https://ift.tt/2s3KefC
Submitted December 20, 2019 at 04:56AM by blueperception
via reddit https://ift.tt/35Hn90G
Apple Security Bounty
https://ift.tt/2Q2cTtA
Submitted December 20, 2019 at 07:47AM by ttocslliw
via reddit https://ift.tt/35GyWfW
https://ift.tt/2Q2cTtA
Submitted December 20, 2019 at 07:47AM by ttocslliw
via reddit https://ift.tt/35GyWfW
Apple Developer
Apple Security Bounty - Apple Developer
As part of Apple’s commitment to security, we reward researchers who share with us critical issues and the techniques used to exploit them.
I discovered a new technique to bypass null byte POPPOPRET's during local SEH exploitation
https://ift.tt/2PDPcZA
Submitted December 20, 2019 at 08:46AM by Signal-Education
via reddit https://ift.tt/2S9WhCP
https://ift.tt/2PDPcZA
Submitted December 20, 2019 at 08:46AM by Signal-Education
via reddit https://ift.tt/2S9WhCP
GitHub
FULLSHADE/POPPOPRET-nullbyte-DLL-bypass
A method to bypass a null byte in a POP-POP-RETN address for exploiting local SEH overflows via DLL injection - FULLSHADE/POPPOPRET-nullbyte-DLL-bypass
Whoopsie-daisy: Chaining accidental features of Ubuntu’s crash reporter to get LPE
https://ift.tt/2rg0hqm
Submitted December 20, 2019 at 12:45PM by 0xdea
via reddit https://ift.tt/2PIkwGG
https://ift.tt/2rg0hqm
Submitted December 20, 2019 at 12:45PM by 0xdea
via reddit https://ift.tt/2PIkwGG
Github
Whoopsie-daisy: Chaining accidental features of Ubuntu’s crash reporter to get LPE - GitHub Security Lab
Securing the world's software, together.
Flipper Zero: Under Development Multi-tool Device for Pen-Testers
https://ift.tt/2SaPsAT
Submitted December 20, 2019 at 03:12PM by dukeofmola
via reddit https://ift.tt/2Smhcmn
https://ift.tt/2SaPsAT
Submitted December 20, 2019 at 03:12PM by dukeofmola
via reddit https://ift.tt/2Smhcmn
flipperzero.one
Flipper Zero — Multi-tool Device for Hackers. Lite version based on STM32
Based on ultra low power STM32 MCU for daily hacking of access control systems, radio protocols. Compatible with Arduino IDE and PlatformIO.
The Hacker Who Took Down a Country
https://ift.tt/2sPujkU
Submitted December 20, 2019 at 05:50PM by Fugitif
via reddit https://ift.tt/35HiH2h
https://ift.tt/2sPujkU
Submitted December 20, 2019 at 05:50PM by Fugitif
via reddit https://ift.tt/35HiH2h
Bloomberg.com
The Hacker Who Took Down a Country
Daniel Kaye, also known as Spdrman, found regular jobs tough but corporate espionage easy. He’s about to get out of prison.
On Linux's Random Number Generation
https://ift.tt/34HRsDj
Submitted December 20, 2019 at 07:26PM by digicat
via reddit https://ift.tt/38SA8il
https://ift.tt/34HRsDj
Submitted December 20, 2019 at 07:26PM by digicat
via reddit https://ift.tt/38SA8il
NCC Group Research
On Linux's Random Number Generation
I have been asked about the usefulness of security monitoring of entropy levels in the Linux kernel. This calls for some explanation of how random generation works in Linux systems. So, randomness …
How to use your Ledger crypto wallet to secure Gmail, Facebook accounts
https://ift.tt/2EG4YNk
Submitted December 20, 2019 at 08:19PM by Tennis3765
via reddit https://ift.tt/34KrDT4
https://ift.tt/2EG4YNk
Submitted December 20, 2019 at 08:19PM by Tennis3765
via reddit https://ift.tt/34KrDT4
Decrypt
How to use your Ledger crypto wallet to secure Gmail, Facebook accounts - Decrypt
Crypto security and hardware developer Ledger has a new 2FA system that, while designed for crypto, can now protect your Google, Facebook or GitHub accounts
Using WebRTC ICE Servers for Port Scanning in Chrome
https://ift.tt/35Dx4EF
Submitted December 20, 2019 at 08:57PM by chicksdigthelongrun
via reddit https://ift.tt/2sMjMHl
https://ift.tt/35Dx4EF
Submitted December 20, 2019 at 08:57PM by chicksdigthelongrun
via reddit https://ift.tt/2sMjMHl
Medium
Using WebRTC ICE Servers for Port Scanning in Chrome
To everything (TURN! TURN! TURN!)
Keyless CryptoTrading - a use case for open source tech that automates cryptography without having access to the private key
https://ift.tt/36Yo5yi
Submitted December 20, 2019 at 10:20PM by tidefoundation
via reddit https://ift.tt/35OHtO4
https://ift.tt/36Yo5yi
Submitted December 20, 2019 at 10:20PM by tidefoundation
via reddit https://ift.tt/35OHtO4
Tide Keyless Trading explainer
Learn how Tide groundbreaking technology allows others to access your crypto-funds and trade on your behalf without giving away your keys.
Hacking live on twitch | Solving pwn, rev
https://ift.tt/35vRnnu
Submitted December 20, 2019 at 11:00PM by ISeeFacesInClouds
via reddit https://ift.tt/34JgamN
https://ift.tt/35vRnnu
Submitted December 20, 2019 at 11:00PM by ISeeFacesInClouds
via reddit https://ift.tt/34JgamN
Twitch
lionaneesh - Twitch
Hacking Live Stream | Playing CTFs for fun!
WordPress: tale of the 4-month old zero-day
https://ift.tt/391uyKk
Submitted December 20, 2019 at 11:19PM by Alabatross
via reddit https://ift.tt/2Q5AvgP
https://ift.tt/391uyKk
Submitted December 20, 2019 at 11:19PM by Alabatross
via reddit https://ift.tt/2Q5AvgP
reddit
WordPress: tale of the 4-month old zero-day
Posted in r/netsec by u/Alabatross • 3 points and 0 comments
Massive leak leaves 267 million Facebook users' data exposed
https://ift.tt/2sOwtBj
Submitted December 21, 2019 at 12:44AM by MayonaiseRemover
via reddit https://ift.tt/2sMYgSP
https://ift.tt/2sOwtBj
Submitted December 21, 2019 at 12:44AM by MayonaiseRemover
via reddit https://ift.tt/2sMYgSP
Android Central
Massive leak leaves 267 million Facebook users' data exposed
Security researchers found an online database containing the private information of over 267 million Facebook users exposed on the internet. It contained the Facebook IDs, phone numbers, and real names of the users.
Source Code Analysis - SQL Injection
https://ift.tt/2sE5Te8
Submitted December 21, 2019 at 07:36AM by ghostlulz
via reddit https://ift.tt/36ZWcWC
https://ift.tt/2sE5Te8
Submitted December 21, 2019 at 07:36AM by ghostlulz
via reddit https://ift.tt/36ZWcWC
Ghostlulz Hacks
Source Code Analysis SQL Injection - Ghostlulz Hacks
Learn how to find SQL injection while doing source code analysis .
Privilege Escalation in AWS
https://ift.tt/2s6U5RU
Submitted December 21, 2019 at 04:34PM by digicat
via reddit https://ift.tt/2PL1aAy
https://ift.tt/2s6U5RU
Submitted December 21, 2019 at 04:34PM by digicat
via reddit https://ift.tt/2PL1aAy
Bishopfox
Well, That Escalated Quickly
Guide for security professionals performing AWS cloud security reviews or pen tests. These methods can be used in practice and explained clearly to clients.
Drupal 8 File Upload Vulnerability
https://ift.tt/2Q7fdiL
Submitted December 21, 2019 at 04:33PM by digicat
via reddit https://ift.tt/2EI3v9a
https://ift.tt/2Q7fdiL
Submitted December 21, 2019 at 04:33PM by digicat
via reddit https://ift.tt/2EI3v9a
Aon
Drupal 8 File Upload Vulnerability | Aon's Cyber Labs
Aon’s Cyber Solutions recently discovered a security vulnerability in all versions of Drupal 8 below 8.7.11 / 8.8.1.
Safe travels for the road warrior
https://ift.tt/38WZXOl
Submitted December 21, 2019 at 03:59PM by Diddern
via reddit https://ift.tt/2Q47Dpc
https://ift.tt/38WZXOl
Submitted December 21, 2019 at 03:59PM by Diddern
via reddit https://ift.tt/2Q47Dpc
Live stream - Hacking Android application using Frida (hooking, bypassing integrity checks and tcp pinning)
https://ift.tt/35vRnnu
Submitted December 22, 2019 at 02:17AM by ISeeFacesInClouds
via reddit https://ift.tt/2Mjk1AN
https://ift.tt/35vRnnu
Submitted December 22, 2019 at 02:17AM by ISeeFacesInClouds
via reddit https://ift.tt/2Mjk1AN
Twitch
lionaneesh - Twitch
Hacking Live Stream | Playing CTFs for fun!
Exploiting Null Byte Buffer Overflow for a $40,000 bounty
https://ift.tt/35A74dh
Submitted December 22, 2019 at 01:43AM by albinowax
via reddit https://ift.tt/36VICmW
https://ift.tt/35A74dh
Submitted December 22, 2019 at 01:43AM by albinowax
via reddit https://ift.tt/36VICmW
samcurry.net
Exploiting Null Byte Buffer Overflow for a $40,000 bounty | Sam Curry
As a preface, when I originally found this bug I was unfamiliar the class of "null byte buffer overflow" even existed. I was simply fuzzing a standard web application's input field and ran into a very interesting behavior that turned out to be a cool bug.
Out-of-band Attacks
https://ift.tt/2ZdSUfp
Submitted December 22, 2019 at 06:17AM by om3rcitak
via reddit https://ift.tt/2EKpP22
https://ift.tt/2ZdSUfp
Submitted December 22, 2019 at 06:17AM by om3rcitak
via reddit https://ift.tt/2EKpP22
Out-of-band Attacks [EN] | Omer Citak's Blog | Om3rCitak
ömer çıtak, omer citak, om3rcitak, security, development, php, vulnerability, ethical hacking