http://blogs.360.cn/post/PoisonNeedles_CVE-2018-15982_EN
Detailed breakdown of the PoC MS-Office file targeting Russia.
Detailed breakdown of the PoC MS-Office file targeting Russia.
#Tool: #Evilginx2 v2.2.0 - Standalone Man-In-The-Middle Attack Framework
https://www.kitploit.com/2018/12/evilginx2-v220-standalone-man-in-middle.html
https://www.kitploit.com/2018/12/evilginx2-v220-standalone-man-in-middle.html
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
#GoodRead: Blind #SQL injection
https://medium.com/@tomnomnom/making-a-blind-sql-injection-a-little-less-blind-428dcb614ba8
https://medium.com/@tomnomnom/making-a-blind-sql-injection-a-little-less-blind-428dcb614ba8
Medium
Making a Blind SQL Injection a Little Less Blind
Someone told me the other day that “no-one does SQL Injection by hand any more”. I want to tell you about a SQL Injection bug that I found…
#News: #Google #Android
https://arstechnica.com/information-technology/2018/12/google-play-ejects-22-backdoored-apps-with-2-million-downloads
https://arstechnica.com/information-technology/2018/12/google-play-ejects-22-backdoored-apps-with-2-million-downloads
Ars Technica
22 apps with 2 million+ Google Play downloads had a malicious backdoor
Device-draining downloader used for ad fraud could have recovered other malicious files.
https://www.presseportal.de/blaulicht/pm/amp/108748/4134607
Security agencies are gaining access with decent pace to encrypted systems.
Security agencies are gaining access with decent pace to encrypted systems.
Forwarded from Bug Bounty Channel
HackerOne
X / xAI disclosed on HackerOne: CORS misconfig | Account Takeover
**Summary:**
CORS misconfig is found on niche.co as Access-Control-Allow-Origin is dynamically fetched from client Origin header with **credential true** and **different methods are enabled** as...
CORS misconfig is found on niche.co as Access-Control-Allow-Origin is dynamically fetched from client Origin header with **credential true** and **different methods are enabled** as...