VTSCAN - scan a malicious file from terminal using VirusTotal API
https://ift.tt/3bKX2JE
Submitted February 17, 2020 at 03:13AM by _____WINTERMUTE_____
via reddit https://ift.tt/2SNDtYB
https://ift.tt/3bKX2JE
Submitted February 17, 2020 at 03:13AM by _____WINTERMUTE_____
via reddit https://ift.tt/2SNDtYB
A friend recently got hit with Dever ransomware. The attacker appears to have been active for 14 minutes, dropping tools such as Mimikatz and Lazagne and then launching Dever ransomware which included SMB scanning, persistence mechanisms and lateral movement. See the timeline, summary and IOCs below
https://ift.tt/38ufdBs
Submitted February 17, 2020 at 04:47AM by InfoSecJim
via reddit https://ift.tt/2uOQ3ig
https://ift.tt/38ufdBs
Submitted February 17, 2020 at 04:47AM by InfoSecJim
via reddit https://ift.tt/2uOQ3ig
Wilbur Security
The Dever Ransomware Experience
My friend recently got hit with Dever ransomware. This blog post will talk about the network architecture of the environment, live incident response, an interesting prefetch, timeline of the attack, info on Dever ransomware, summary and IOCs.
CVE-2019-18683: Exploiting a Linux kernel vulnerability in the V4L2 subsystem
https://ift.tt/39Nk2X1
Submitted February 17, 2020 at 11:48AM by digicat
via reddit https://ift.tt/2SLauVq
https://ift.tt/39Nk2X1
Submitted February 17, 2020 at 11:48AM by digicat
via reddit https://ift.tt/2SLauVq
Alexander Popov
CVE-2019-18683: Exploiting a Linux kernel vulnerability in the V4L2 subsystem
Intro
Themegrill vulnerability allowed unauthenticated database wipe and auth bypass. Update asap as 200k+ sites affected!
https://ift.tt/2UVUzGA
Submitted February 17, 2020 at 03:25PM by ded1cated
via reddit https://ift.tt/3bToqWe
https://ift.tt/2UVUzGA
Submitted February 17, 2020 at 03:25PM by ded1cated
via reddit https://ift.tt/3bToqWe
WebARX
Critical Issue In ThemeGrill Demo Importer - WebARX Security
There is a critical vulnerability in ThemeGrill Demo Importer that leads to database wipe and auth bypass. In the versions 1.3.4 and above.
Top 10 web hacking techniques of 2019
https://ift.tt/39Kg6X0
Submitted February 17, 2020 at 09:07PM by 0xdea
via reddit https://ift.tt/2HICxQp
https://ift.tt/39Kg6X0
Submitted February 17, 2020 at 09:07PM by 0xdea
via reddit https://ift.tt/2HICxQp
PortSwigger Research
Top 10 web hacking techniques of 2019
The results are in! After 51 nominations whittled down to 15 finalists by a community vote, an expert panel consisting of Nicolas Grégoire, Soroush Dalili, Filedescriptor, and myself have conferred, v
How does Kerberos delegation work?
https://ift.tt/2wpI2ku
Submitted February 17, 2020 at 05:51PM by Zer1t0
via reddit https://ift.tt/2SWfUge
https://ift.tt/2wpI2ku
Submitted February 17, 2020 at 05:51PM by Zer1t0
via reddit https://ift.tt/2SWfUge
Tarlogic Security - Cyber Security and Ethical hacking
Kerberos (III): How does delegation work?
Introduction There are several kinds of delegation implemented by using the Kerberos protocol. Basically, delegation allows a service to impersonate the client user to interact with a second service, with the privileges and permissions of the client itself.…
Writing or Receiving your first pentest report
https://ift.tt/2V1hgcb
Submitted February 17, 2020 at 11:55PM by ZephrX112
via reddit https://ift.tt/2vGhVp7
https://ift.tt/2V1hgcb
Submitted February 17, 2020 at 11:55PM by ZephrX112
via reddit https://ift.tt/2vGhVp7
ZeroSec - Adventures In Information Security
LTR101: Writing or Receiving Your First Pentest Report
A penetration test report is more often tailored to multiple reading groups and as a result needs to be broken down into multiple sections for easier digestion by the business.
NeverLAN CTF Full Writeups
https://ift.tt/2SxmPxD
Submitted February 17, 2020 at 04:16AM by boshdajosh
via reddit https://ift.tt/2uRt9qw
https://ift.tt/2SxmPxD
Submitted February 17, 2020 at 04:16AM by boshdajosh
via reddit https://ift.tt/2uRt9qw
GitHub
joshdabosh/writeups
My write-ups to CTF challenges. Contribute to joshdabosh/writeups development by creating an account on GitHub.
Episode 4-Enumerating DNS: Public by Intent… Public by Intent!?!
https://ift.tt/38NB7Q8
Submitted February 18, 2020 at 05:04AM by iamtherealmod
via reddit https://ift.tt/2HtGmZz
https://ift.tt/38NB7Q8
Submitted February 18, 2020 at 05:04AM by iamtherealmod
via reddit https://ift.tt/2HtGmZz
Obsecurity
Episode 4-Enumerating DNS: Public by Intent… Public by Intent!?!
Got another anecdotal one this week! In a short summary, here, I will walk through the role that DNS, and DNS servers play in an enterprise network. Then, I’ll demonstrate how we can glean ba…
SonicWall SRA and SMA vulnerabilties
https://ift.tt/39AnWSS
Submitted February 18, 2020 at 08:52AM by Mempodipper
via reddit https://ift.tt/2SSl0u1
https://ift.tt/39AnWSS
Submitted February 18, 2020 at 08:52AM by Mempodipper
via reddit https://ift.tt/2SSl0u1
Simple online tools to provide a fast SSL report
https://ift.tt/37AsxTF
Submitted February 18, 2020 at 04:33PM by KeyDutch
via reddit https://ift.tt/324WOJ2
https://ift.tt/37AsxTF
Submitted February 18, 2020 at 04:33PM by KeyDutch
via reddit https://ift.tt/324WOJ2
Sucuri Blog
SSL Testing Methods
Not all SSL configurations on websites are equal, and a growing number push for HTTPS everywhere. There is an increasing demand to check and quantify that little padlock in your browser. Some simple online tools provide
Hidden in PEB Sight: Hiding Windows API Imports With a Custom Loader
https://ift.tt/39UCPQf
Submitted February 18, 2020 at 05:30PM by thorn42
via reddit https://ift.tt/2VcCTGX
https://ift.tt/39UCPQf
Submitted February 18, 2020 at 05:30PM by thorn42
via reddit https://ift.tt/2VcCTGX
Christophe Tafani-Dereeper
Hidden in PEB Sight: Hiding Windows API Imports With a Custom Loader
In this post, we look at different techniques to hide Windows API imports in a program in order to fly under the radar of static analysis tools.
GadgetProbe (Burp extension/Library): Java Deserialization - identify classes, libraries, and library versions on remote classpaths
https://ift.tt/37zhYQR
Submitted February 18, 2020 at 06:50PM by theBumbleSec
via reddit https://ift.tt/2HBnebS
https://ift.tt/37zhYQR
Submitted February 18, 2020 at 06:50PM by theBumbleSec
via reddit https://ift.tt/2HBnebS
GitHub
BishopFox/GadgetProbe
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths. - BishopFox/GadgetProbe
Windows, Linux Devices at Risk Due to Unsigned Peripheral Firmware
https://ift.tt/2V7KTsJ
Submitted February 18, 2020 at 06:34PM by PowerOfLove1985
via reddit https://ift.tt/2VcMb5N
https://ift.tt/2V7KTsJ
Submitted February 18, 2020 at 06:34PM by PowerOfLove1985
via reddit https://ift.tt/2VcMb5N
BleepingComputer
Windows, Linux Devices at Risk Due to Unsigned Peripheral Firmware
Researchers have discovered multiple instances of unsigned firmware in computer peripherals that can be used by malicious actors to attack laptops and servers running Windows and Linux.
Web cache deception named top web hacking technique of 2019
https://ift.tt/38Dj8vH
Submitted February 18, 2020 at 09:29PM by sajjadium
via reddit https://ift.tt/2SGOool
https://ift.tt/38Dj8vH
Submitted February 18, 2020 at 09:29PM by sajjadium
via reddit https://ift.tt/2SGOool
The Daily Swig | Cybersecurity news and views
Web cache deception named top web hacking technique of 2019
This is no basic listicle
Bypass Windows 10 User Group Policy (and more) with this One Weird Trick
https://ift.tt/328pvVn
Submitted February 18, 2020 at 10:27PM by MalwareSeattle
via reddit https://ift.tt/2SE928l
https://ift.tt/328pvVn
Submitted February 18, 2020 at 10:27PM by MalwareSeattle
via reddit https://ift.tt/2SE928l
Medium
Bypass Windows 10 User Group Policy (and more) with this One Weird Trick
I‘m going to share an (ab)use of a Windows feature which can result in bypassing User Group Policy (as well as a few other interesting…
Introducing Updog, a replacement for Python's SimpleHTTPServer. It allows both uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use basic auth.
https://ift.tt/2HwpjG6
Submitted February 18, 2020 at 11:25PM by sc0tfree
via reddit https://ift.tt/2SW0PLS
https://ift.tt/2HwpjG6
Submitted February 18, 2020 at 11:25PM by sc0tfree
via reddit https://ift.tt/2SW0PLS
GitHub
sc0tfree/updog
Updog is a replacement for Python's SimpleHTTPServer. It allows uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use http basic auth. - sc0tfree/updog
AWS Automatic Remediation - Part I: Security Groups
https://ift.tt/2STNuDz
Submitted February 19, 2020 at 07:27PM by Default-G8way
via reddit https://ift.tt/2wy1vQ9
https://ift.tt/2STNuDz
Submitted February 19, 2020 at 07:27PM by Default-G8way
via reddit https://ift.tt/2wy1vQ9
getsec.github.io
AWS Automated Remediation - Part 1: Security Groups
Automatically remediating poorly implemented security groups
Resolving an Unfortunate STACKLEAK Interaction
https://ift.tt/2vLAkko
Submitted February 19, 2020 at 09:10PM by citypw
via reddit https://ift.tt/2HCaWA3
https://ift.tt/2vLAkko
Submitted February 19, 2020 at 09:10PM by citypw
via reddit https://ift.tt/2HCaWA3
grsecurity.net
grsecurity - Resolving an Unfortunate STACKLEAK Interaction
During a performance evaluation, an unfortunate interaction of the STACKLEAK plugin with the RAP plugin was noticed that lead to unnecessary bloat. This blog post highlights the steps that have been taken to resolve the source of the problem.
Pen Testing Ships. A year in review
https://ift.tt/2vGQQls
Submitted February 19, 2020 at 10:42PM by QuirkySpiceBush
via reddit https://ift.tt/2P7pyM2
https://ift.tt/2vGQQls
Submitted February 19, 2020 at 10:42PM by QuirkySpiceBush
via reddit https://ift.tt/2P7pyM2
Pentestpartners
Pen Testing Ships. A year in review | Pen Test Partners
Partially driven by the upcoming inclusion of Cyber Security by the IMO (International Maritime Organisation), 2019 was a really busy year for maritime security
Learn how Chinese hackers compromised Equifax
https://ift.tt/32fxEaL
Submitted February 19, 2020 at 11:40PM by DebugDucky
via reddit https://ift.tt/329btTy
https://ift.tt/32fxEaL
Submitted February 19, 2020 at 11:40PM by DebugDucky
via reddit https://ift.tt/329btTy
Cybrary
Learn how Chinese hackers compromised Equifax