Testing Your Red Team Infrastructure
https://ift.tt/38tKRPv
Submitted February 22, 2020 at 12:45AM by dmchell
via reddit https://ift.tt/2PecAwe
https://ift.tt/38tKRPv
Submitted February 22, 2020 at 12:45AM by dmchell
via reddit https://ift.tt/2PecAwe
MDSec
Testing your RedTeam Infrastructure - MDSec
As RedTeaming has grown with the industry, so has our need to build dependable environments. In keeping with the cat-and-mouse game we find ourselves in, it’s essential to possess the...
IIS Raid – Backdooring IIS Using Native Modules
https://ift.tt/38IjEZp
Submitted February 22, 2020 at 12:45AM by dmchell
via reddit https://ift.tt/3c1lo2i
https://ift.tt/38IjEZp
Submitted February 22, 2020 at 12:45AM by dmchell
via reddit https://ift.tt/3c1lo2i
MDSec
IIS Raid – Backdooring IIS Using Native Modules - MDSec
Introduction Back in 2018, PaloAlto Unit42 publicly documented RGDoor, an IIS backdoor used by the APT34. The article highlighted some details which sparked my interest and inspired me to write...
Getting What You’re Entitled To: A Journey Into MacOS Stored Credentials
https://ift.tt/32eEz3R
Submitted February 22, 2020 at 12:45AM by dmchell
via reddit https://ift.tt/39XrXRB
https://ift.tt/32eEz3R
Submitted February 22, 2020 at 12:45AM by dmchell
via reddit https://ift.tt/39XrXRB
Open source Malboxes now deploys Windows desktop OS to AWS ready for malware detonation and analysis with many tools preinstalled
https://ift.tt/2Vd6vUk
Submitted February 22, 2020 at 01:33AM by obilodeau
via reddit https://ift.tt/2SOtwvg
https://ift.tt/2Vd6vUk
Submitted February 22, 2020 at 01:33AM by obilodeau
via reddit https://ift.tt/2SOtwvg
GoSecure
Cloudy With a Chance of Malware: Malboxes Now Deploys to AWS - GoSecure
The open-source tool Malboxes now makes malware analysis safer by deploying directly into the Amazon AWS cloud removing the requirement of operating a local dirty network.
How Microsoft 365 uses machine learning to stop data leaks & insider attacks
https://ift.tt/2SNXDTC
Submitted February 22, 2020 at 01:28AM by myinnerbanjo
via reddit https://ift.tt/32ei1QS
https://ift.tt/2SNXDTC
Submitted February 22, 2020 at 01:28AM by myinnerbanjo
via reddit https://ift.tt/32ei1QS
The AI Blog
How Microsoft 365 uses AI to stop data leaks & insider attacks
A new Insider Risk Management solution within Microsoft 365 uses machine learning to intelligently detect potentially risky behavior within a company.
Another Subdomain ENumeration Tool
https://ift.tt/2V70Pvc
Submitted February 22, 2020 at 01:26AM by cinerieus
via reddit https://ift.tt/2SNi17r
https://ift.tt/2V70Pvc
Submitted February 22, 2020 at 01:26AM by cinerieus
via reddit https://ift.tt/2SNi17r
GitHub
cinerieus/as3nt
Another Subdomain ENumeration Tool. Contribute to cinerieus/as3nt development by creating an account on GitHub.
I hacked SlickWraps. This is how.
https://ift.tt/39VQLJo
Submitted February 22, 2020 at 07:24AM by irckeyboardwarrior
via reddit https://ift.tt/2VdPbie
https://ift.tt/39VQLJo
Submitted February 22, 2020 at 07:24AM by irckeyboardwarrior
via reddit https://ift.tt/2VdPbie
reddit
I hacked SlickWraps. This is how.
Posted in r/netsec by u/irckeyboardwarrior • 3 points and 7 comments
Simple malware de obfuscation using Chepy
/r/Malware/comments/f7lgk9/simple_malware_de_obfuscation_using_chepy/
Submitted February 22, 2020 at 07:13AM by securisec
via reddit https://ift.tt/2HMazDe
/r/Malware/comments/f7lgk9/simple_malware_de_obfuscation_using_chepy/
Submitted February 22, 2020 at 07:13AM by securisec
via reddit https://ift.tt/2HMazDe
reddit
Simple malware de obfuscation using Chepy
Posted in r/netsec by u/securisec • 1 point and 0 comments
Hunting Tesla Model Y Secrets in the Parts Catalog
https://ift.tt/37RLmSm
Submitted February 22, 2020 at 08:57AM by techdash
via reddit https://ift.tt/3bXchPP
https://ift.tt/37RLmSm
Submitted February 22, 2020 at 08:57AM by techdash
via reddit https://ift.tt/3bXchPP
Medium
Hunting Tesla Model Y Secrets in the Parts Catalog
After buying a Model 3 in June of 2019, I began deep diving into understanding how my new car works. My interest largely being the…
Opposition Research (OSINT): Twitter
https://ift.tt/2PdNFsA
Submitted February 22, 2020 at 10:22AM by NattyFried1
via reddit https://ift.tt/32fSRkZ
https://ift.tt/2PdNFsA
Submitted February 22, 2020 at 10:22AM by NattyFried1
via reddit https://ift.tt/32fSRkZ
TurgenSec Community
Opposition Research (OSINT): Twitter
This article is part of a broader series on opposition research and OSINT. If you would like to contribute or want to suggest an amendment or work with me on my upcoming articles on Facebook,
Radare2/Cutter were accepted in Google Summer of Code 2020 - Call for Students
https://ift.tt/2SNHTjk
Submitted February 22, 2020 at 10:13AM by XVilka
via reddit https://ift.tt/2vQmKw1
https://ift.tt/2SNHTjk
Submitted February 22, 2020 at 10:13AM by XVilka
via reddit https://ift.tt/2vQmKw1
reddit
Radare2/Cutter were accepted in Google Summer of Code 2020 - Call...
Posted in r/netsec by u/XVilka • 5 points and 1 comment
Slickwraps Data breach
/r/technology/comments/f7r0yy/slickwraps_data_breach/
Submitted February 22, 2020 at 04:26PM by PickleeeeeRick
via reddit https://ift.tt/39SwAMD
/r/technology/comments/f7r0yy/slickwraps_data_breach/
Submitted February 22, 2020 at 04:26PM by PickleeeeeRick
via reddit https://ift.tt/39SwAMD
reddit
Slickwraps Data breach
Posted in r/netsec by u/PickleeeeeRick • 3 points and 0 comments
HackTheBox: Zetta - writeup by t3chnocat
https://t3chnocat.com/htb-zetta/
Submitted February 22, 2020 at 09:33PM by t3chnocat_
via reddit https://ift.tt/2ukzqLa
https://t3chnocat.com/htb-zetta/
Submitted February 22, 2020 at 09:33PM by t3chnocat_
via reddit https://ift.tt/2ukzqLa
t3chnocat.com
HackTheBox Writeup: Zetta
Zetta was a hard rated box that had some interesting vulnerabilities. An unfinished dual-stack implementation was used to leak the IPv6 address of the server which exposed a rsync service. Write access to rsync was used to write to an authorized_keys file…
AngularJs Client Side Template Injection (XSS)
https://ift.tt/3c119le
Submitted February 22, 2020 at 09:45PM by ghostlulz
via reddit https://ift.tt/2Vg5ZF8
https://ift.tt/3c119le
Submitted February 22, 2020 at 09:45PM by ghostlulz
via reddit https://ift.tt/2Vg5ZF8
Ghostlulz Hacks
AngularJS Client Side Template Injection (XSS) - Ghostlulz Hacks
Slack Group Before we get started I have started a slack group dedicated to hacking. We welcome everyone from beginner…
Working POC for CVE-2020-0668 local priv esc on all windows versions
https://github.com/RedCursorSecurityConsulting/CVE-2020-0668
Submitted February 21, 2020 at 05:14AM by gmad
via reddit https://ift.tt/2vT2RV8
https://github.com/RedCursorSecurityConsulting/CVE-2020-0668
Submitted February 21, 2020 at 05:14AM by gmad
via reddit https://ift.tt/2vT2RV8
reddit
Working POC for CVE-2020-0668 local priv esc on all windows versions
[https://github.com/RedCursorSecurityConsulting/CVE-2020-0668](https://www.google.com/url?q=https://github.com/RedCursorSecurityConsulting/CVE-2020...
CIA secretly owned world's top encryption supplier, read enemy and ally messages for decades
https://ift.tt/38jRm7B
Submitted February 23, 2020 at 12:09AM by MayonaiseRemover
via reddit https://ift.tt/2T5NmkL
https://ift.tt/38jRm7B
Submitted February 23, 2020 at 12:09AM by MayonaiseRemover
via reddit https://ift.tt/2T5NmkL
Boing Boing
CIA secretly owned world's top encryption supplier, read enemy and ally messages for decades
For more than half a century, governments all over the world trusted a single company to keep the communications of their spies, soldiers and diplomats secret. That company was secretly run by the …
Our First Weeks of Securing Windows 7 and Windows Server 2008 R2
https://ift.tt/38NhU16
Submitted February 23, 2020 at 05:58AM by dielel
via reddit https://ift.tt/38SKEFF
https://ift.tt/38NhU16
Submitted February 23, 2020 at 05:58AM by dielel
via reddit https://ift.tt/38SKEFF
0Patch
Our First Weeks of Securing Windows 7 and Windows Server 2008 R2
A quick status update by Mitja Kolsek, the 0patch Team [Update 2/22/2020: More details on the exploit code for CVE-2020-0674 were publis...
Zero Networks Access Orchestrator: Autonomous, airtight network access security at scale - Help Net Security
https://ift.tt/2PcQbiK
Submitted February 23, 2020 at 06:36PM by ZeroNetworks
via reddit https://ift.tt/2wGYFIv
https://ift.tt/2PcQbiK
Submitted February 23, 2020 at 06:36PM by ZeroNetworks
via reddit https://ift.tt/2wGYFIv
Help Net Security
Zero Networks Access Orchestrator: Autonomous, airtight network access security at scale - Help Net Security
Zero Networks Access Orchestrator is a network security platform that defines, enforces and adapts user- and machine-level network access policies.
Writing a GHIDRA Loader: STM32 Edition.
https://ift.tt/2VhK7Jp
Submitted February 23, 2020 at 08:20PM by wrongbaud
via reddit https://ift.tt/3c0lxCN
https://ift.tt/2VhK7Jp
Submitted February 23, 2020 at 08:20PM by wrongbaud
via reddit https://ift.tt/3c0lxCN
Reddit
From the netsec community on Reddit: Writing a GHIDRA Loader: STM32 Edition.
Posted by wrongbaud - 78 votes and no comments
OSWE/AWAE Preparation compiled reference Links
https://ift.tt/2T70Oou
Submitted February 23, 2020 at 10:02PM by 0crypt
via reddit https://ift.tt/3c0OQ8u
https://ift.tt/2T70Oou
Submitted February 23, 2020 at 10:02PM by 0crypt
via reddit https://ift.tt/3c0OQ8u
z-r0crypt.github.io
OSWE/AWAE Preparation · Z-r0crypt
Security Research Blog for learning and sharing
I just open-sourced sweetie data, a repo of multiple honeypot logs.
https://ift.tt/38TfduX
Submitted February 23, 2020 at 11:15PM by 0xsha
via reddit https://ift.tt/37Ofzlr
https://ift.tt/38TfduX
Submitted February 23, 2020 at 11:15PM by 0xsha
via reddit https://ift.tt/37Ofzlr
GitHub
GitHub - 0xsha/sweetie-data: This repo contains logstash of various honeypots
This repo contains logstash of various honeypots. Contribute to 0xsha/sweetie-data development by creating an account on GitHub.