Episode 4-Enumerating DNS: Public by Intent… Public by Intent!?!
https://ift.tt/38NB7Q8
Submitted February 18, 2020 at 05:04AM by iamtherealmod
via reddit https://ift.tt/2HtGmZz
https://ift.tt/38NB7Q8
Submitted February 18, 2020 at 05:04AM by iamtherealmod
via reddit https://ift.tt/2HtGmZz
Obsecurity
Episode 4-Enumerating DNS: Public by Intent… Public by Intent!?!
Got another anecdotal one this week! In a short summary, here, I will walk through the role that DNS, and DNS servers play in an enterprise network. Then, I’ll demonstrate how we can glean ba…
SonicWall SRA and SMA vulnerabilties
https://ift.tt/39AnWSS
Submitted February 18, 2020 at 08:52AM by Mempodipper
via reddit https://ift.tt/2SSl0u1
https://ift.tt/39AnWSS
Submitted February 18, 2020 at 08:52AM by Mempodipper
via reddit https://ift.tt/2SSl0u1
Simple online tools to provide a fast SSL report
https://ift.tt/37AsxTF
Submitted February 18, 2020 at 04:33PM by KeyDutch
via reddit https://ift.tt/324WOJ2
https://ift.tt/37AsxTF
Submitted February 18, 2020 at 04:33PM by KeyDutch
via reddit https://ift.tt/324WOJ2
Sucuri Blog
SSL Testing Methods
Not all SSL configurations on websites are equal, and a growing number push for HTTPS everywhere. There is an increasing demand to check and quantify that little padlock in your browser. Some simple online tools provide
Hidden in PEB Sight: Hiding Windows API Imports With a Custom Loader
https://ift.tt/39UCPQf
Submitted February 18, 2020 at 05:30PM by thorn42
via reddit https://ift.tt/2VcCTGX
https://ift.tt/39UCPQf
Submitted February 18, 2020 at 05:30PM by thorn42
via reddit https://ift.tt/2VcCTGX
Christophe Tafani-Dereeper
Hidden in PEB Sight: Hiding Windows API Imports With a Custom Loader
In this post, we look at different techniques to hide Windows API imports in a program in order to fly under the radar of static analysis tools.
GadgetProbe (Burp extension/Library): Java Deserialization - identify classes, libraries, and library versions on remote classpaths
https://ift.tt/37zhYQR
Submitted February 18, 2020 at 06:50PM by theBumbleSec
via reddit https://ift.tt/2HBnebS
https://ift.tt/37zhYQR
Submitted February 18, 2020 at 06:50PM by theBumbleSec
via reddit https://ift.tt/2HBnebS
GitHub
BishopFox/GadgetProbe
Probe endpoints consuming Java serialized objects to identify classes, libraries, and library versions on remote Java classpaths. - BishopFox/GadgetProbe
Windows, Linux Devices at Risk Due to Unsigned Peripheral Firmware
https://ift.tt/2V7KTsJ
Submitted February 18, 2020 at 06:34PM by PowerOfLove1985
via reddit https://ift.tt/2VcMb5N
https://ift.tt/2V7KTsJ
Submitted February 18, 2020 at 06:34PM by PowerOfLove1985
via reddit https://ift.tt/2VcMb5N
BleepingComputer
Windows, Linux Devices at Risk Due to Unsigned Peripheral Firmware
Researchers have discovered multiple instances of unsigned firmware in computer peripherals that can be used by malicious actors to attack laptops and servers running Windows and Linux.
Web cache deception named top web hacking technique of 2019
https://ift.tt/38Dj8vH
Submitted February 18, 2020 at 09:29PM by sajjadium
via reddit https://ift.tt/2SGOool
https://ift.tt/38Dj8vH
Submitted February 18, 2020 at 09:29PM by sajjadium
via reddit https://ift.tt/2SGOool
The Daily Swig | Cybersecurity news and views
Web cache deception named top web hacking technique of 2019
This is no basic listicle
Bypass Windows 10 User Group Policy (and more) with this One Weird Trick
https://ift.tt/328pvVn
Submitted February 18, 2020 at 10:27PM by MalwareSeattle
via reddit https://ift.tt/2SE928l
https://ift.tt/328pvVn
Submitted February 18, 2020 at 10:27PM by MalwareSeattle
via reddit https://ift.tt/2SE928l
Medium
Bypass Windows 10 User Group Policy (and more) with this One Weird Trick
I‘m going to share an (ab)use of a Windows feature which can result in bypassing User Group Policy (as well as a few other interesting…
Introducing Updog, a replacement for Python's SimpleHTTPServer. It allows both uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use basic auth.
https://ift.tt/2HwpjG6
Submitted February 18, 2020 at 11:25PM by sc0tfree
via reddit https://ift.tt/2SW0PLS
https://ift.tt/2HwpjG6
Submitted February 18, 2020 at 11:25PM by sc0tfree
via reddit https://ift.tt/2SW0PLS
GitHub
sc0tfree/updog
Updog is a replacement for Python's SimpleHTTPServer. It allows uploading and downloading via HTTP/S, can set ad hoc SSL certificates and use http basic auth. - sc0tfree/updog
AWS Automatic Remediation - Part I: Security Groups
https://ift.tt/2STNuDz
Submitted February 19, 2020 at 07:27PM by Default-G8way
via reddit https://ift.tt/2wy1vQ9
https://ift.tt/2STNuDz
Submitted February 19, 2020 at 07:27PM by Default-G8way
via reddit https://ift.tt/2wy1vQ9
getsec.github.io
AWS Automated Remediation - Part 1: Security Groups
Automatically remediating poorly implemented security groups
Resolving an Unfortunate STACKLEAK Interaction
https://ift.tt/2vLAkko
Submitted February 19, 2020 at 09:10PM by citypw
via reddit https://ift.tt/2HCaWA3
https://ift.tt/2vLAkko
Submitted February 19, 2020 at 09:10PM by citypw
via reddit https://ift.tt/2HCaWA3
grsecurity.net
grsecurity - Resolving an Unfortunate STACKLEAK Interaction
During a performance evaluation, an unfortunate interaction of the STACKLEAK plugin with the RAP plugin was noticed that lead to unnecessary bloat. This blog post highlights the steps that have been taken to resolve the source of the problem.
Pen Testing Ships. A year in review
https://ift.tt/2vGQQls
Submitted February 19, 2020 at 10:42PM by QuirkySpiceBush
via reddit https://ift.tt/2P7pyM2
https://ift.tt/2vGQQls
Submitted February 19, 2020 at 10:42PM by QuirkySpiceBush
via reddit https://ift.tt/2P7pyM2
Pentestpartners
Pen Testing Ships. A year in review | Pen Test Partners
Partially driven by the upcoming inclusion of Cyber Security by the IMO (International Maritime Organisation), 2019 was a really busy year for maritime security
Learn how Chinese hackers compromised Equifax
https://ift.tt/32fxEaL
Submitted February 19, 2020 at 11:40PM by DebugDucky
via reddit https://ift.tt/329btTy
https://ift.tt/32fxEaL
Submitted February 19, 2020 at 11:40PM by DebugDucky
via reddit https://ift.tt/329btTy
Cybrary
Learn how Chinese hackers compromised Equifax
Well, Terahash $1.4 Million configuration of 448 x RTX 2080 GPUs can't even crack 1 character long hashed password generated with "Multi One Password" tool!
/r/WindowsPortableApps/comments/f6ckmu/well_terahash_14_million_configuration_of_448_x/
Submitted February 20, 2020 at 12:44AM by RedditGeneralUser
via reddit https://ift.tt/38Hpdrl
/r/WindowsPortableApps/comments/f6ckmu/well_terahash_14_million_configuration_of_448_x/
Submitted February 20, 2020 at 12:44AM by RedditGeneralUser
via reddit https://ift.tt/38Hpdrl
reddit
Well, Terahash $1.4 Million configuration of 448 x RTX 2080 GPUs...
Posted in r/netsec by u/RedditGeneralUser • 0 points and 0 comments
Finding Python ReDoS bugs at scale using Dlint and r2c (CVE-2020-8492)
https://ift.tt/2HzZdC6
Submitted February 20, 2020 at 02:13AM by Schwag
via reddit https://ift.tt/2SWyIME
https://ift.tt/2HzZdC6
Submitted February 20, 2020 at 02:13AM by Schwag
via reddit https://ift.tt/2SWyIME
r2c eng log
Finding Python ReDoS bugs at scale using Dlint and r2c
Automating regular expression denial-of-service detection
Security Analysis of the SoloKeys Firmware
https://ift.tt/3bOldqJ
Submitted February 20, 2020 at 03:36AM by nibblesec
via reddit https://ift.tt/2V7lMWI
https://ift.tt/3bOldqJ
Submitted February 20, 2020 at 03:36AM by nibblesec
via reddit https://ift.tt/2V7lMWI
SoloKeys
Security Analysis of the Solo Firmware
We engaged Doyensec to perform a security assessment of our firmware, v3.0.1 at the time of testing. During a 10 person/days project, Doyensec discovered and reported 3 vulnerabilities in our firmware. While two of the issues are considered informational…
2020 Wisconsin Hacker Conference Speakers
https://ift.tt/2SK9WAl
Submitted February 20, 2020 at 08:48AM by kamic
via reddit https://ift.tt/39SQwPh
https://ift.tt/2SK9WAl
Submitted February 20, 2020 at 08:48AM by kamic
via reddit https://ift.tt/39SQwPh
reddit
2020 Wisconsin Hacker Conference Speakers
Posted in r/netsec by u/kamic • 2 points and 0 comments
MGM Resorts Says Data Breach Exposed Some Guests’ Personal Information
https://ift.tt/2vRic8t
Submitted February 20, 2020 at 09:35AM by 0xb800
via reddit https://ift.tt/2SZ9nBB
https://ift.tt/2vRic8t
Submitted February 20, 2020 at 09:35AM by 0xb800
via reddit https://ift.tt/2SZ9nBB
NY Times
MGM Resorts Says Data Breach Exposed Some Guests’ Personal Information
The casino and hotel giant said “it was confident that no financial, payment card or password data was involved in this matter.”
Stop Using Encrypted Email
https://ift.tt/2HJniX3
Submitted February 20, 2020 at 03:08PM by ajsharp
via reddit https://ift.tt/39QkhAt
https://ift.tt/2HJniX3
Submitted February 20, 2020 at 03:08PM by ajsharp
via reddit https://ift.tt/39QkhAt
latacora.micro.blog
Latacora - Stop Using Encrypted Email
Email is unsafe and cannot be made safe. The tools we have today to encrypt email are badly flawed. Even if those flaws were fixed, email would remain unsafe. Its problems cannot plausibly be mitigated. Avoid encrypted email.
Technologists hate this argument.…
Technologists hate this argument.…
SentinelOne Announces $200M Series E
https://ift.tt/2v26o3d
Submitted February 20, 2020 at 03:47PM by Cyberthere
via reddit https://ift.tt/2uZe2eI
https://ift.tt/2v26o3d
Submitted February 20, 2020 at 03:47PM by Cyberthere
via reddit https://ift.tt/2uZe2eI
SentinelOne
SentinelOne Announces $200M Series E
Cybersecurity’s Fastest Growing Platform Now Valued at Over $1 Billion
Exploiting Jira for Host Discovery
https://ift.tt/38Ih45W
Submitted February 20, 2020 at 08:06PM by chicksdigthelongrun
via reddit https://ift.tt/2vQYb1Q
https://ift.tt/38Ih45W
Submitted February 20, 2020 at 08:06PM by chicksdigthelongrun
via reddit https://ift.tt/2vQYb1Q
Medium
Exploiting Jira for Host Discovery
Last October I dived into the world of Jira Software (version 8.4.1) in the hope of discovering new vulnerabilities. Initially, I came…