Cable modem jailbreaks
https://ift.tt/3bXBV78
Submitted February 25, 2020 at 01:40AM by Soulw4xer
via reddit https://ift.tt/390lqW4
https://ift.tt/3bXBV78
Submitted February 25, 2020 at 01:40AM by Soulw4xer
via reddit https://ift.tt/390lqW4
Medium
Cable Modem Jailbreaks
First off all the goal off this blog is not to steal internet or clone modems !!! We are working on a way where cert’s will only be used…
Call For Papers: OWAP's Global AppSec 2020 Dublin
https://ift.tt/37ZHmiB
Submitted February 25, 2020 at 01:25AM by kerberosmansour
via reddit https://ift.tt/3c5je1u
https://ift.tt/37ZHmiB
Submitted February 25, 2020 at 01:25AM by kerberosmansour
via reddit https://ift.tt/3c5je1u
Submittable
OWASP Foundation
OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving…
Parent PID Spoofing - Three Process Injection Techniques that implement PPID Spoofing
https://www.youtube.com/watch?v=Fz3d5bFBKJ0
Submitted February 24, 2020 at 10:50PM by netbiosX
via reddit https://ift.tt/3bXUSXk
https://www.youtube.com/watch?v=Fz3d5bFBKJ0
Submitted February 24, 2020 at 10:50PM by netbiosX
via reddit https://ift.tt/3bXUSXk
YouTube
Parent PID Spoofing
Parent PID Spoofing is often used by red teams to evade detection from EDR (Endpoint Detection and Response) solutions that are capable to discover anomalies in the relationship of parent/child processes in order to identify malicious processes.
The video…
The video…
Defeating a Laptop's BIOS Password
https://ift.tt/2vcETEl
Submitted February 25, 2020 at 12:23PM by xxkcd
via reddit https://ift.tt/37Q0mQM
https://ift.tt/2vcETEl
Submitted February 25, 2020 at 12:23PM by xxkcd
via reddit https://ift.tt/37Q0mQM
GitHub
skysafe/reblog
SkySafe Miscellaneous Reverse Engineering Blog. Contribute to skysafe/reblog development by creating an account on GitHub.
Linux Kernel Stack Smashing by Dr Silvio Cesare
https://ift.tt/2VgHvM7
Submitted February 25, 2020 at 11:38AM by Gallus
via reddit https://ift.tt/2PkCs9w
https://ift.tt/2VgHvM7
Submitted February 25, 2020 at 11:38AM by Gallus
via reddit https://ift.tt/2PkCs9w
blog.infosectcbr.com.au
Linux Kernel Stack Smashing
Dr Silvio Cesare @silviocesare Summary In this blog post I’ll discuss how to exploit the Linux kernel via a stack smashin...
[Malware] Lazarus group's Brambul worm of the former Wannacry - 1.md
https://ift.tt/2HSQmvw
Submitted February 25, 2020 at 12:47PM by hanwint
via reddit https://ift.tt/37X3ZnO
https://ift.tt/2HSQmvw
Submitted February 25, 2020 at 12:47PM by hanwint
via reddit https://ift.tt/37X3ZnO
reddit
[Malware] Lazarus group's Brambul worm of the former Wannacry - 1.md
Posted in r/netsec by u/hanwint • 5 points and 0 comments
Running-up and organizing CTF events — Nginx & Docker
https://ift.tt/391fBaM
Submitted February 25, 2020 at 02:58PM by xkarezma
via reddit https://ift.tt/2PhMA2X
https://ift.tt/391fBaM
Submitted February 25, 2020 at 02:58PM by xkarezma
via reddit https://ift.tt/2PhMA2X
Medium
Running-up and organizing CTF events — Nginx & Docker
Introduction
In the Wild Evidence of VBA Purging Found in Malicious Documents
https://ift.tt/2v5Ng4J
Submitted February 25, 2020 at 03:52PM by 0xThiebaut
via reddit https://ift.tt/3c5EynB
https://ift.tt/2v5Ng4J
Submitted February 25, 2020 at 03:52PM by 0xThiebaut
via reddit https://ift.tt/3c5EynB
NVISO Labs
Evidence of VBA Purging Found in Malicious Documents
TL;DR We have found malicious Office documents containing VBA source code only, and no compiled code. Documents like these are more likely to evade anti-virus detection due to a technique we dubbed…
GWTUpload - vulnerability allowing to abuse the upload process and cause a total denial-of-service of a web server.
https://ift.tt/2PoeA58
Submitted February 25, 2020 at 06:11PM by logicaltrust-net
via reddit https://ift.tt/37Tyvit
https://ift.tt/2PoeA58
Submitted February 25, 2020 at 06:11PM by logicaltrust-net
via reddit https://ift.tt/37Tyvit
Security Audits, Penetration Tests - LogicalTrust
LogicalTrust - Blog - [EN] A-Z: GWTUpload - DoS
GWT is a Java web framework and GWTUpload is a library extending it with easier file upload.
We found a vulnerability allowing to abuse the upload process and cause a denial-of-service of a web application.
We found a vulnerability allowing to abuse the upload process and cause a denial-of-service of a web application.
How to write & share platform/SIEM agnostic detection content.
https://ift.tt/2lU7ln4
Submitted February 26, 2020 at 02:05AM by acalarch
via reddit https://ift.tt/32r5bPd
https://ift.tt/2lU7ln4
Submitted February 26, 2020 at 02:05AM by acalarch
via reddit https://ift.tt/32r5bPd
GitHub
Neo23x0/sigma
Generic Signature Format for SIEM Systems. Contribute to Neo23x0/sigma development by creating an account on GitHub.
Just got this Humble Bundle - Help me prioritize them
/r/cybersecurity/comments/f9h9ov/just_got_this_humble_bundle_help_me_prioritize/
Submitted February 26, 2020 at 02:43AM by mrmeeseeks2014
via reddit https://ift.tt/39bCbNW
/r/cybersecurity/comments/f9h9ov/just_got_this_humble_bundle_help_me_prioritize/
Submitted February 26, 2020 at 02:43AM by mrmeeseeks2014
via reddit https://ift.tt/39bCbNW
reddit
Just got this Humble Bundle - Help me prioritize them
Posted in r/netsec by u/mrmeeseeks2014 • 0 points and 0 comments
CVE-2017-11176: A step-by-step Linux Kernel exploitation (4 parts)
https://ift.tt/2Tk2bQy
Submitted February 26, 2020 at 05:20AM by Gallus
via reddit https://ift.tt/2SWEK0S
https://ift.tt/2Tk2bQy
Submitted February 26, 2020 at 05:20AM by Gallus
via reddit https://ift.tt/2SWEK0S
[Malware] Lazarus group's Brambul worm of the former Wannacry - 2
https://ift.tt/2TfIc5F
Submitted February 26, 2020 at 07:44AM by hanwint
via reddit https://ift.tt/2Tkf2lM
https://ift.tt/2TfIc5F
Submitted February 26, 2020 at 07:44AM by hanwint
via reddit https://ift.tt/2Tkf2lM
Forgot2kEyXCHANGE - CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
https://ift.tt/391rXjh
Submitted February 26, 2020 at 09:34AM by Gallus
via reddit https://ift.tt/2HXUZEI
https://ift.tt/391rXjh
Submitted February 26, 2020 at 09:34AM by Gallus
via reddit https://ift.tt/2HXUZEI
Zero Day Initiative
Zero Day Initiative — CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
This most recent Patch Tuesday, Microsoft released an Important-rated patch to address a remote code execution bug in Microsoft Exchange Server. This vulnerability was reported to us by an anonymous researcher and affects all supported versions of Microsoft…
BlueGate vulnerability internals (CVE-2020-0609 & CVE-2020-0610)
https://ift.tt/3a4fTxS
Submitted February 26, 2020 at 01:42PM by gid0rah
via reddit https://ift.tt/2v97kTM
https://ift.tt/3a4fTxS
Submitted February 26, 2020 at 01:42PM by gid0rah
via reddit https://ift.tt/2v97kTM
blog.rop.la
BlueGate Internals
Reversing, exploiting, pentesting, ctf writeups... && ++hacking
Silver & Golden Tickets Explained
https://ift.tt/2TkACa5
Submitted February 26, 2020 at 04:06PM by hackndo
via reddit https://ift.tt/3948pLk
https://ift.tt/2TkACa5
Submitted February 26, 2020 at 04:06PM by hackndo
via reddit https://ift.tt/3948pLk
hackndo
Silver & Golden Tickets
This post focuses on silver ticket and golden ticket. What are they, how are they used, what can be done with them, we will uncover everything there is to know.
Different Approaches To Finding Pwned Passwords in Active Directory
https://ift.tt/2PpUiIp
Submitted February 26, 2020 at 05:18PM by thatstevelord
via reddit https://ift.tt/2vkhctH
https://ift.tt/2PpUiIp
Submitted February 26, 2020 at 05:18PM by thatstevelord
via reddit https://ift.tt/2vkhctH
Torture-Proof Authentication
https://ift.tt/3cdPuiT
Submitted February 26, 2020 at 11:10PM by utku1337
via reddit https://ift.tt/2HX8lkn
https://ift.tt/3cdPuiT
Submitted February 26, 2020 at 11:10PM by utku1337
via reddit https://ift.tt/2HX8lkn
Utkusen
Torture-Proof Authentication
Authentication is one of the biggest problems of security since the beginning of the internet. In most cases, we are using passwords for authentication. But it usually causes problems since people are using weak passwords, reusing the same passwords on different…
Classical cipher cryptanalysis cheatsheet :: Notes from Overthewire Krypton
https://ift.tt/2vit7IA
Submitted February 26, 2020 at 11:01PM by SkullTech101
via reddit https://ift.tt/2T4X73X
https://ift.tt/2vit7IA
Submitted February 26, 2020 at 11:01PM by SkullTech101
via reddit https://ift.tt/2T4X73X
Musings of Sumit Ghosh
Cryptanalysis Cheatsheet :: Notes from Overthewire Krypton
I’ve been on a wargame streak! After doing Leviathan, I jumped into Krypton and completed it; and this post is in a way a write-up of Krypton. Krypton, Leviathan, in case these words sound alien to you: well they’re wargames—or Ctfs—hosted by Overthewire.org.…
A serious vulnerability deep inside Wi-Fi encryption
https://ift.tt/2waSzQw
Submitted February 26, 2020 at 11:46PM by oherrala
via reddit https://ift.tt/2VrsqY2
https://ift.tt/2waSzQw
Submitted February 26, 2020 at 11:46PM by oherrala
via reddit https://ift.tt/2VrsqY2
reddit
A serious vulnerability deep inside Wi-Fi encryption
Posted in r/netsec by u/oherrala • 4 points and 0 comments
Other Security Features of Content Security Policy
https://ift.tt/2TcP3Ne
Submitted February 27, 2020 at 12:08AM by xc0nradx
via reddit https://ift.tt/37Yql8B
https://ift.tt/2TcP3Ne
Submitted February 27, 2020 at 12:08AM by xc0nradx
via reddit https://ift.tt/37Yql8B
Csper
Other Security Features of Content Security Policy
Some of the other security features of content security policy including upgrade-insecure-requests, block-all-mixed-content, frame-ancestors, sandbox, form-actions, and more.