Defeating a Laptop's BIOS Password
https://ift.tt/2vcETEl
Submitted February 25, 2020 at 12:23PM by xxkcd
via reddit https://ift.tt/37Q0mQM
https://ift.tt/2vcETEl
Submitted February 25, 2020 at 12:23PM by xxkcd
via reddit https://ift.tt/37Q0mQM
GitHub
skysafe/reblog
SkySafe Miscellaneous Reverse Engineering Blog. Contribute to skysafe/reblog development by creating an account on GitHub.
Linux Kernel Stack Smashing by Dr Silvio Cesare
https://ift.tt/2VgHvM7
Submitted February 25, 2020 at 11:38AM by Gallus
via reddit https://ift.tt/2PkCs9w
https://ift.tt/2VgHvM7
Submitted February 25, 2020 at 11:38AM by Gallus
via reddit https://ift.tt/2PkCs9w
blog.infosectcbr.com.au
Linux Kernel Stack Smashing
Dr Silvio Cesare @silviocesare Summary In this blog post I’ll discuss how to exploit the Linux kernel via a stack smashin...
[Malware] Lazarus group's Brambul worm of the former Wannacry - 1.md
https://ift.tt/2HSQmvw
Submitted February 25, 2020 at 12:47PM by hanwint
via reddit https://ift.tt/37X3ZnO
https://ift.tt/2HSQmvw
Submitted February 25, 2020 at 12:47PM by hanwint
via reddit https://ift.tt/37X3ZnO
reddit
[Malware] Lazarus group's Brambul worm of the former Wannacry - 1.md
Posted in r/netsec by u/hanwint • 5 points and 0 comments
Running-up and organizing CTF events — Nginx & Docker
https://ift.tt/391fBaM
Submitted February 25, 2020 at 02:58PM by xkarezma
via reddit https://ift.tt/2PhMA2X
https://ift.tt/391fBaM
Submitted February 25, 2020 at 02:58PM by xkarezma
via reddit https://ift.tt/2PhMA2X
Medium
Running-up and organizing CTF events — Nginx & Docker
Introduction
In the Wild Evidence of VBA Purging Found in Malicious Documents
https://ift.tt/2v5Ng4J
Submitted February 25, 2020 at 03:52PM by 0xThiebaut
via reddit https://ift.tt/3c5EynB
https://ift.tt/2v5Ng4J
Submitted February 25, 2020 at 03:52PM by 0xThiebaut
via reddit https://ift.tt/3c5EynB
NVISO Labs
Evidence of VBA Purging Found in Malicious Documents
TL;DR We have found malicious Office documents containing VBA source code only, and no compiled code. Documents like these are more likely to evade anti-virus detection due to a technique we dubbed…
GWTUpload - vulnerability allowing to abuse the upload process and cause a total denial-of-service of a web server.
https://ift.tt/2PoeA58
Submitted February 25, 2020 at 06:11PM by logicaltrust-net
via reddit https://ift.tt/37Tyvit
https://ift.tt/2PoeA58
Submitted February 25, 2020 at 06:11PM by logicaltrust-net
via reddit https://ift.tt/37Tyvit
Security Audits, Penetration Tests - LogicalTrust
LogicalTrust - Blog - [EN] A-Z: GWTUpload - DoS
GWT is a Java web framework and GWTUpload is a library extending it with easier file upload.
We found a vulnerability allowing to abuse the upload process and cause a denial-of-service of a web application.
We found a vulnerability allowing to abuse the upload process and cause a denial-of-service of a web application.
How to write & share platform/SIEM agnostic detection content.
https://ift.tt/2lU7ln4
Submitted February 26, 2020 at 02:05AM by acalarch
via reddit https://ift.tt/32r5bPd
https://ift.tt/2lU7ln4
Submitted February 26, 2020 at 02:05AM by acalarch
via reddit https://ift.tt/32r5bPd
GitHub
Neo23x0/sigma
Generic Signature Format for SIEM Systems. Contribute to Neo23x0/sigma development by creating an account on GitHub.
Just got this Humble Bundle - Help me prioritize them
/r/cybersecurity/comments/f9h9ov/just_got_this_humble_bundle_help_me_prioritize/
Submitted February 26, 2020 at 02:43AM by mrmeeseeks2014
via reddit https://ift.tt/39bCbNW
/r/cybersecurity/comments/f9h9ov/just_got_this_humble_bundle_help_me_prioritize/
Submitted February 26, 2020 at 02:43AM by mrmeeseeks2014
via reddit https://ift.tt/39bCbNW
reddit
Just got this Humble Bundle - Help me prioritize them
Posted in r/netsec by u/mrmeeseeks2014 • 0 points and 0 comments
CVE-2017-11176: A step-by-step Linux Kernel exploitation (4 parts)
https://ift.tt/2Tk2bQy
Submitted February 26, 2020 at 05:20AM by Gallus
via reddit https://ift.tt/2SWEK0S
https://ift.tt/2Tk2bQy
Submitted February 26, 2020 at 05:20AM by Gallus
via reddit https://ift.tt/2SWEK0S
[Malware] Lazarus group's Brambul worm of the former Wannacry - 2
https://ift.tt/2TfIc5F
Submitted February 26, 2020 at 07:44AM by hanwint
via reddit https://ift.tt/2Tkf2lM
https://ift.tt/2TfIc5F
Submitted February 26, 2020 at 07:44AM by hanwint
via reddit https://ift.tt/2Tkf2lM
Forgot2kEyXCHANGE - CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
https://ift.tt/391rXjh
Submitted February 26, 2020 at 09:34AM by Gallus
via reddit https://ift.tt/2HXUZEI
https://ift.tt/391rXjh
Submitted February 26, 2020 at 09:34AM by Gallus
via reddit https://ift.tt/2HXUZEI
Zero Day Initiative
Zero Day Initiative — CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
This most recent Patch Tuesday, Microsoft released an Important-rated patch to address a remote code execution bug in Microsoft Exchange Server. This vulnerability was reported to us by an anonymous researcher and affects all supported versions of Microsoft…
BlueGate vulnerability internals (CVE-2020-0609 & CVE-2020-0610)
https://ift.tt/3a4fTxS
Submitted February 26, 2020 at 01:42PM by gid0rah
via reddit https://ift.tt/2v97kTM
https://ift.tt/3a4fTxS
Submitted February 26, 2020 at 01:42PM by gid0rah
via reddit https://ift.tt/2v97kTM
blog.rop.la
BlueGate Internals
Reversing, exploiting, pentesting, ctf writeups... && ++hacking
Silver & Golden Tickets Explained
https://ift.tt/2TkACa5
Submitted February 26, 2020 at 04:06PM by hackndo
via reddit https://ift.tt/3948pLk
https://ift.tt/2TkACa5
Submitted February 26, 2020 at 04:06PM by hackndo
via reddit https://ift.tt/3948pLk
hackndo
Silver & Golden Tickets
This post focuses on silver ticket and golden ticket. What are they, how are they used, what can be done with them, we will uncover everything there is to know.
Different Approaches To Finding Pwned Passwords in Active Directory
https://ift.tt/2PpUiIp
Submitted February 26, 2020 at 05:18PM by thatstevelord
via reddit https://ift.tt/2vkhctH
https://ift.tt/2PpUiIp
Submitted February 26, 2020 at 05:18PM by thatstevelord
via reddit https://ift.tt/2vkhctH
Torture-Proof Authentication
https://ift.tt/3cdPuiT
Submitted February 26, 2020 at 11:10PM by utku1337
via reddit https://ift.tt/2HX8lkn
https://ift.tt/3cdPuiT
Submitted February 26, 2020 at 11:10PM by utku1337
via reddit https://ift.tt/2HX8lkn
Utkusen
Torture-Proof Authentication
Authentication is one of the biggest problems of security since the beginning of the internet. In most cases, we are using passwords for authentication. But it usually causes problems since people are using weak passwords, reusing the same passwords on different…
Classical cipher cryptanalysis cheatsheet :: Notes from Overthewire Krypton
https://ift.tt/2vit7IA
Submitted February 26, 2020 at 11:01PM by SkullTech101
via reddit https://ift.tt/2T4X73X
https://ift.tt/2vit7IA
Submitted February 26, 2020 at 11:01PM by SkullTech101
via reddit https://ift.tt/2T4X73X
Musings of Sumit Ghosh
Cryptanalysis Cheatsheet :: Notes from Overthewire Krypton
I’ve been on a wargame streak! After doing Leviathan, I jumped into Krypton and completed it; and this post is in a way a write-up of Krypton. Krypton, Leviathan, in case these words sound alien to you: well they’re wargames—or Ctfs—hosted by Overthewire.org.…
A serious vulnerability deep inside Wi-Fi encryption
https://ift.tt/2waSzQw
Submitted February 26, 2020 at 11:46PM by oherrala
via reddit https://ift.tt/2VrsqY2
https://ift.tt/2waSzQw
Submitted February 26, 2020 at 11:46PM by oherrala
via reddit https://ift.tt/2VrsqY2
reddit
A serious vulnerability deep inside Wi-Fi encryption
Posted in r/netsec by u/oherrala • 4 points and 0 comments
Other Security Features of Content Security Policy
https://ift.tt/2TcP3Ne
Submitted February 27, 2020 at 12:08AM by xc0nradx
via reddit https://ift.tt/37Yql8B
https://ift.tt/2TcP3Ne
Submitted February 27, 2020 at 12:08AM by xc0nradx
via reddit https://ift.tt/37Yql8B
Csper
Other Security Features of Content Security Policy
Some of the other security features of content security policy including upgrade-insecure-requests, block-all-mixed-content, frame-ancestors, sandbox, form-actions, and more.
PyRDP on Autopilot – Unattended Credential Harvesting and Client-Side File Stealing
https://ift.tt/3a8ToI9
Submitted February 27, 2020 at 01:28AM by Pourliver
via reddit https://ift.tt/3cc075W
https://ift.tt/3a8ToI9
Submitted February 27, 2020 at 01:28AM by Pourliver
via reddit https://ift.tt/3cc075W
‘Cloud Snooper’ Attack Bypasses Firewall Security Measures
https://ift.tt/37Yirwb
Submitted February 27, 2020 at 03:04AM by GadgetryTech
via reddit https://ift.tt/397x1Ti
https://ift.tt/37Yirwb
Submitted February 27, 2020 at 03:04AM by GadgetryTech
via reddit https://ift.tt/397x1Ti
reddit
‘Cloud Snooper’ Attack Bypasses Firewall Security Measures
Posted in r/netsec by u/GadgetryTech • 39 points and 3 comments
What Is The Dark Web? | How To Access The Dark Web Safely and Securely
https://ift.tt/395CsCb
Submitted February 27, 2020 at 03:38AM by stewofkc
via reddit https://ift.tt/32sciak
https://ift.tt/395CsCb
Submitted February 27, 2020 at 03:38AM by stewofkc
via reddit https://ift.tt/32sciak
Medium
What Is The Dark Web?
How To Access The Dark Web Safely and Securely