UAC bypass via elevated .NET applications
https://offsec.provadys.com/UAC-bypass-dotnet.html
https://offsec.provadys.com/UAC-bypass-dotnet.html
Advanced Flash Vulnerabilities in Youtube. Serie de posts explicando las vulnerabilidades presentes en el reproductor flash de Youtube
https://opnsec.com/2017/08/advanced-flash-vulnerabilities-in-youtube/
https://opnsec.com/2017/08/advanced-flash-vulnerabilities-in-youtube/
OpnSec
Advanced Flash Vulnerabilities in Youtube – Part 1 | OpnSec
Why Flash Security still matters? Flash is still an active threat. In 2017, I reported Flash vulnerabilities to Facebook, Youtube, Wordpress, Yahoo, Paypal and Stripe. Over the last 3 years, I reporte
Forwarded from AntonioJ
eldiario.es
Tu cara es tu contraseña, ¿qué podría salir mal?
El sistema de reconocimiento facial de Apple es polémico, pero no es el primero ni el único: Android lo usa desde 2012 y el nuevo Galaxy S8 también lo incorporaEl problema es el mismo en todos los casos: puedes cambiar de nombre y de casa pero no de cara…
Forwarded from AntonioJ
https://www.redeszone.net/2017/09/14/los-ciberdelincuentes-hecho-agosto-espana-no-se-ha-librado/amp/
RedesZone
Los ciberdelincuentes han hecho su agosto y España no se ha librado
Agosto ha sido un gran mes para los ciberdelincuentes. Numerosos ataques, aumento de software malicioso y otros métodos. España no se ha librado.
Forwarded from SysAdmin 24x7
Burplay - A Burp Extension for Detection Privilege Escalations https://t.co/k2LrVaF4Lg https://t.co/ITYsRXvkgb
Trustwave
Introducing Burplay, A Burp Extension for Detection Privilege Escalations
The seventh entry on the most recent OWASP Top 10 release (from 2013, due to the 2017 release candidate being rejected!) is "Missing Function Level Access Control", which is essentially what leads to Privilege Escalation issues. This common vulnerability…
Forwarded from canyoupwn.me
Burp Suite 1.7.27 Remote Code Execution
https://www.youtube.com/watch?v=zcj1j69-6p4
https://www.youtube.com/watch?v=zcj1j69-6p4
Forwarded from Deleted Account
Linux Container Security | Twistlock
https://www.twistlock.com/resources/type/linux-container-security/
https://www.twistlock.com/resources/type/linux-container-security/
Twistlock
Linux Container Security | Twistlock
Learn more about Linux Container Security from Twistlock. Dev-to-Production Docker and container security for enterprises.
Forwarded from Deleted Account
Welcome | Anchore Navigator
https://anchore.io/
https://anchore.io/
Anchore
Software supply chain security solutions • Anchore
Protect your software supply chain with policy-based container security solutions.
Forwarded from Deleted Account
Container Troubleshooting and Linux Visibility | Sysdig
https://www.sysdig.org/
https://www.sysdig.org/
Sysdig
Security Tools for Containers, Kubernetes, and Cloud (Vulnerability Management)
From runtime to development, gain real-time visibility into your cloud with Sysdig. Prioritize critical risks, detect threats instantly, and respond with confidence.
Forwarded from Deleted Account
Docker Security Scanning | Docker Documentation
https://docs.docker.com/docker-cloud/builds/image-scan/
https://docs.docker.com/docker-cloud/builds/image-scan/
Forwarded from Deleted Account
Dagda: The Docker Security Suite! - PenTestIT
https://www.google.es/amp/pentestit.com/dagda-docker-security-suite/amp/
https://www.google.es/amp/pentestit.com/dagda-docker-security-suite/amp/
PenTestIT
Dagda: The Docker Security Suite! - PenTestIT
Dagda is an open source tool, coded in Python to perform static analysis of known vulnerabilities in Docker images/containers.