GWTUpload - vulnerability allowing to abuse the upload process and cause a total denial-of-service of a web server.
https://ift.tt/2PoeA58
Submitted February 25, 2020 at 06:11PM by logicaltrust-net
via reddit https://ift.tt/37Tyvit
https://ift.tt/2PoeA58
Submitted February 25, 2020 at 06:11PM by logicaltrust-net
via reddit https://ift.tt/37Tyvit
Security Audits, Penetration Tests - LogicalTrust
LogicalTrust - Blog - [EN] A-Z: GWTUpload - DoS
GWT is a Java web framework and GWTUpload is a library extending it with easier file upload.
We found a vulnerability allowing to abuse the upload process and cause a denial-of-service of a web application.
We found a vulnerability allowing to abuse the upload process and cause a denial-of-service of a web application.
How to write & share platform/SIEM agnostic detection content.
https://ift.tt/2lU7ln4
Submitted February 26, 2020 at 02:05AM by acalarch
via reddit https://ift.tt/32r5bPd
https://ift.tt/2lU7ln4
Submitted February 26, 2020 at 02:05AM by acalarch
via reddit https://ift.tt/32r5bPd
GitHub
Neo23x0/sigma
Generic Signature Format for SIEM Systems. Contribute to Neo23x0/sigma development by creating an account on GitHub.
Just got this Humble Bundle - Help me prioritize them
/r/cybersecurity/comments/f9h9ov/just_got_this_humble_bundle_help_me_prioritize/
Submitted February 26, 2020 at 02:43AM by mrmeeseeks2014
via reddit https://ift.tt/39bCbNW
/r/cybersecurity/comments/f9h9ov/just_got_this_humble_bundle_help_me_prioritize/
Submitted February 26, 2020 at 02:43AM by mrmeeseeks2014
via reddit https://ift.tt/39bCbNW
reddit
Just got this Humble Bundle - Help me prioritize them
Posted in r/netsec by u/mrmeeseeks2014 • 0 points and 0 comments
CVE-2017-11176: A step-by-step Linux Kernel exploitation (4 parts)
https://ift.tt/2Tk2bQy
Submitted February 26, 2020 at 05:20AM by Gallus
via reddit https://ift.tt/2SWEK0S
https://ift.tt/2Tk2bQy
Submitted February 26, 2020 at 05:20AM by Gallus
via reddit https://ift.tt/2SWEK0S
[Malware] Lazarus group's Brambul worm of the former Wannacry - 2
https://ift.tt/2TfIc5F
Submitted February 26, 2020 at 07:44AM by hanwint
via reddit https://ift.tt/2Tkf2lM
https://ift.tt/2TfIc5F
Submitted February 26, 2020 at 07:44AM by hanwint
via reddit https://ift.tt/2Tkf2lM
Forgot2kEyXCHANGE - CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
https://ift.tt/391rXjh
Submitted February 26, 2020 at 09:34AM by Gallus
via reddit https://ift.tt/2HXUZEI
https://ift.tt/391rXjh
Submitted February 26, 2020 at 09:34AM by Gallus
via reddit https://ift.tt/2HXUZEI
Zero Day Initiative
Zero Day Initiative — CVE-2020-0688: Remote Code Execution on Microsoft Exchange Server Through Fixed Cryptographic Keys
This most recent Patch Tuesday, Microsoft released an Important-rated patch to address a remote code execution bug in Microsoft Exchange Server. This vulnerability was reported to us by an anonymous researcher and affects all supported versions of Microsoft…
BlueGate vulnerability internals (CVE-2020-0609 & CVE-2020-0610)
https://ift.tt/3a4fTxS
Submitted February 26, 2020 at 01:42PM by gid0rah
via reddit https://ift.tt/2v97kTM
https://ift.tt/3a4fTxS
Submitted February 26, 2020 at 01:42PM by gid0rah
via reddit https://ift.tt/2v97kTM
blog.rop.la
BlueGate Internals
Reversing, exploiting, pentesting, ctf writeups... && ++hacking
Silver & Golden Tickets Explained
https://ift.tt/2TkACa5
Submitted February 26, 2020 at 04:06PM by hackndo
via reddit https://ift.tt/3948pLk
https://ift.tt/2TkACa5
Submitted February 26, 2020 at 04:06PM by hackndo
via reddit https://ift.tt/3948pLk
hackndo
Silver & Golden Tickets
This post focuses on silver ticket and golden ticket. What are they, how are they used, what can be done with them, we will uncover everything there is to know.
Different Approaches To Finding Pwned Passwords in Active Directory
https://ift.tt/2PpUiIp
Submitted February 26, 2020 at 05:18PM by thatstevelord
via reddit https://ift.tt/2vkhctH
https://ift.tt/2PpUiIp
Submitted February 26, 2020 at 05:18PM by thatstevelord
via reddit https://ift.tt/2vkhctH
Torture-Proof Authentication
https://ift.tt/3cdPuiT
Submitted February 26, 2020 at 11:10PM by utku1337
via reddit https://ift.tt/2HX8lkn
https://ift.tt/3cdPuiT
Submitted February 26, 2020 at 11:10PM by utku1337
via reddit https://ift.tt/2HX8lkn
Utkusen
Torture-Proof Authentication
Authentication is one of the biggest problems of security since the beginning of the internet. In most cases, we are using passwords for authentication. But it usually causes problems since people are using weak passwords, reusing the same passwords on different…
Classical cipher cryptanalysis cheatsheet :: Notes from Overthewire Krypton
https://ift.tt/2vit7IA
Submitted February 26, 2020 at 11:01PM by SkullTech101
via reddit https://ift.tt/2T4X73X
https://ift.tt/2vit7IA
Submitted February 26, 2020 at 11:01PM by SkullTech101
via reddit https://ift.tt/2T4X73X
Musings of Sumit Ghosh
Cryptanalysis Cheatsheet :: Notes from Overthewire Krypton
I’ve been on a wargame streak! After doing Leviathan, I jumped into Krypton and completed it; and this post is in a way a write-up of Krypton. Krypton, Leviathan, in case these words sound alien to you: well they’re wargames—or Ctfs—hosted by Overthewire.org.…
A serious vulnerability deep inside Wi-Fi encryption
https://ift.tt/2waSzQw
Submitted February 26, 2020 at 11:46PM by oherrala
via reddit https://ift.tt/2VrsqY2
https://ift.tt/2waSzQw
Submitted February 26, 2020 at 11:46PM by oherrala
via reddit https://ift.tt/2VrsqY2
reddit
A serious vulnerability deep inside Wi-Fi encryption
Posted in r/netsec by u/oherrala • 4 points and 0 comments
Other Security Features of Content Security Policy
https://ift.tt/2TcP3Ne
Submitted February 27, 2020 at 12:08AM by xc0nradx
via reddit https://ift.tt/37Yql8B
https://ift.tt/2TcP3Ne
Submitted February 27, 2020 at 12:08AM by xc0nradx
via reddit https://ift.tt/37Yql8B
Csper
Other Security Features of Content Security Policy
Some of the other security features of content security policy including upgrade-insecure-requests, block-all-mixed-content, frame-ancestors, sandbox, form-actions, and more.
PyRDP on Autopilot – Unattended Credential Harvesting and Client-Side File Stealing
https://ift.tt/3a8ToI9
Submitted February 27, 2020 at 01:28AM by Pourliver
via reddit https://ift.tt/3cc075W
https://ift.tt/3a8ToI9
Submitted February 27, 2020 at 01:28AM by Pourliver
via reddit https://ift.tt/3cc075W
‘Cloud Snooper’ Attack Bypasses Firewall Security Measures
https://ift.tt/37Yirwb
Submitted February 27, 2020 at 03:04AM by GadgetryTech
via reddit https://ift.tt/397x1Ti
https://ift.tt/37Yirwb
Submitted February 27, 2020 at 03:04AM by GadgetryTech
via reddit https://ift.tt/397x1Ti
reddit
‘Cloud Snooper’ Attack Bypasses Firewall Security Measures
Posted in r/netsec by u/GadgetryTech • 39 points and 3 comments
What Is The Dark Web? | How To Access The Dark Web Safely and Securely
https://ift.tt/395CsCb
Submitted February 27, 2020 at 03:38AM by stewofkc
via reddit https://ift.tt/32sciak
https://ift.tt/395CsCb
Submitted February 27, 2020 at 03:38AM by stewofkc
via reddit https://ift.tt/32sciak
Medium
What Is The Dark Web?
How To Access The Dark Web Safely and Securely
Windows Persistence via Application Shims - T1138
https://ift.tt/3a7ih70
Submitted February 27, 2020 at 04:27PM by _creosote
via reddit https://ift.tt/2PrRxWM
https://ift.tt/3a7ih70
Submitted February 27, 2020 at 04:27PM by _creosote
via reddit https://ift.tt/2PrRxWM
liberty shell
Persistence via Shims | liberty shell
A-Z guide on setting up Graylog Part 3: Making our first dashboards and alerts from domain controllers
/r/sysadmin/comments/fabu7q/az_guide_on_setting_up_graylog_part_3_making_our/
Submitted February 27, 2020 at 06:43PM by HanSolo71
via reddit https://ift.tt/2wSvYbI
/r/sysadmin/comments/fabu7q/az_guide_on_setting_up_graylog_part_3_making_our/
Submitted February 27, 2020 at 06:43PM by HanSolo71
via reddit https://ift.tt/2wSvYbI
reddit
A-Z guide on setting up Graylog Part 3: Making our first...
Posted in r/netsec by u/HanSolo71 • 1 point and 0 comments
[How-To Tutorial] - Turn Android ProtonVPN into an Application-Based Firewall
/r/ProtonVPN/comments/facqjb/howto_tutorial_turn_android_protonvpn_into_an/
Submitted February 27, 2020 at 08:14PM by BackgroundSet9
via reddit https://ift.tt/395qmJl
/r/ProtonVPN/comments/facqjb/howto_tutorial_turn_android_protonvpn_into_an/
Submitted February 27, 2020 at 08:14PM by BackgroundSet9
via reddit https://ift.tt/395qmJl
reddit
[How-To Tutorial] - Turn Android ProtonVPN into an...
Posted in r/netsec by u/BackgroundSet9 • 1 point and 0 comments
Checking Flask template files that aren’t autoescaped by default
https://ift.tt/2TkU7iv
Submitted February 27, 2020 at 10:27PM by pabloest
via reddit https://ift.tt/3abDfBL
https://ift.tt/2TkU7iv
Submitted February 27, 2020 at 10:27PM by pabloest
via reddit https://ift.tt/3abDfBL
Using BPF to Transform SSH Sessions into Structured Events
https://ift.tt/2T3hbna
Submitted February 28, 2020 at 01:05AM by benarent
via reddit https://ift.tt/32vDaWO
https://ift.tt/2T3hbna
Submitted February 28, 2020 at 01:05AM by benarent
via reddit https://ift.tt/32vDaWO