Netgear Signed TLS Cert Private Key Disclosure
π£homothebrave
Netgear left in its router firmware key ingredients needed to intercept and tamper with secure connections to its equipment's web-based admin interfaces.
Specifically, valid, signed TLS certificates with private keys were embedded in the software, which was available to download for free by anyone, and also shipped with Netgear devices. This data can be used to create HTTPS certs that browsers trust, and can be used in miscreant-in-the-middle attacks to eavesdrop on and alter encrypted connections to the routers' built-in web-based control panel.
In other words, the data can be used to potentially hijack people's routers. It's partly an embarrassing leak, and partly indicative of manufacturers trading off security, user friendliness, cost, and effort.
π€homothebrave
π@malwr
π£homothebrave
Netgear left in its router firmware key ingredients needed to intercept and tamper with secure connections to its equipment's web-based admin interfaces.
Specifically, valid, signed TLS certificates with private keys were embedded in the software, which was available to download for free by anyone, and also shipped with Netgear devices. This data can be used to create HTTPS certs that browsers trust, and can be used in miscreant-in-the-middle attacks to eavesdrop on and alter encrypted connections to the routers' built-in web-based control panel.
In other words, the data can be used to potentially hijack people's routers. It's partly an embarrassing leak, and partly indicative of manufacturers trading off security, user friendliness, cost, and effort.
π€homothebrave
π@malwr
Gist
Netgear TLS Private Key Disclosure through Device Firmware Images
Netgear TLS Private Key Disclosure through Device Firmware Images - netgear-private-key-disclosure.md
Hiding Your Tracks: Bash History
π£bad3r_
Nice! I would add another one, kill the console to quit bash without saving history:
kill -9 $$
π€ReigningShells
π@malwr
π£bad3r_
Nice! I would add another one, kill the console to quit bash without saving history:
kill -9 $$
π€ReigningShells
π@malwr
What do you use for IP Reputation?
We are currently using IBM X-force, but o don't find it that reliable there is a lot if false positives in there.
Any suggestions? Especially for one were we can get a feed from (API or something)
π£Mo7Robot
https://www.abuseipdb.com/register
https://talosintelligence.com/reputation\_center
https://www.apivoid.com/api/ip-reputation/
π€chrisknight1985
If you are looking for malicious domains the Fortinet threat feed is pretty good. It's part of their Fortinet Developer's Network Site License. It's an API feed that supports csv and stix formats.
π€Defiant_Success
π@malwr
We are currently using IBM X-force, but o don't find it that reliable there is a lot if false positives in there.
Any suggestions? Especially for one were we can get a feed from (API or something)
π£Mo7Robot
https://www.abuseipdb.com/register
https://talosintelligence.com/reputation\_center
https://www.apivoid.com/api/ip-reputation/
π€chrisknight1985
If you are looking for malicious domains the Fortinet threat feed is pretty good. It's part of their Fortinet Developer's Network Site License. It's an API feed that supports csv and stix formats.
π€Defiant_Success
π@malwr
Reddit
From the cybersecurity community on Reddit
Explore this post and more from the cybersecurity community
OP Glowing Symphony β How US military claims to have disrupted ISIS βs propaganda
π£quellaman
π@malwr
π£quellaman
π@malwr
Security Affairs
OP Glowing Symphony - How US military claims to have disrupted ISIS 's propaganda
US military claims to have disrupted the online propaganda activity of the Islamic State (ISIS) in a hacking operation dating back at least to 2016.
sLoad malware gang returns: Microsoft detects quickly revamped 2.0 version
π£BhaswatiGuha19
π@malwr
π£BhaswatiGuha19
π@malwr
International Business Times
sLoad malware gang returns: Microsoft detects quickly revamped 2.0 version
sLoad malware has been around for years but after the detection, in December it again returned with 2.0 version named as Starslord earlier this month
Local Privilege Escalation in many Ricoh Printer Drivers for Windows (CVE-2019-19363) + Exploit
π£aunga
π@malwr
π£aunga
π@malwr
Pentagrid AG
Local Privilege Escalation in many Ricoh Printer Drivers for Windows (
A local privilege escalation in Ricoh Windows printer drivers is affecting many Ricoh printer models.
Israeli security pros using βCybernetβ social network for threat intelligence
π£tds_404
π@malwr
π£tds_404
π@malwr
The Daily Swig | Cybersecurity news and views
Israeli security pros using βCybernetβ social network for threat intelligence
Infosec platform is free to join, but members are subject to approval process