Finding Python ReDoS bugs at scale using Dlint and r2c (CVE-2020-8492)
π£Schwag
This reminds me of a similar project done for Javascript a while back, looking for ReDoS vulns at scale live on websites: https://www.usenix.org/conference/usenixsecurity18/presentation/staicu
π€wargame-mods
π@malwr
π£Schwag
This reminds me of a similar project done for Javascript a while back, looking for ReDoS vulns at scale live on websites: https://www.usenix.org/conference/usenixsecurity18/presentation/staicu
π€wargame-mods
π@malwr
How to proxy and tamper with Mobile Applications
If you've ever wondered how to intercept and tamper with Mobile Applications, here's two videos explaining how to setup a proxy on your device and do just that.
Android: https://youtu.be/cRN0WEzadsE
iOS: https://youtu.be/AWsvdiVN4PA
π£mrturvey
π@malwr
If you've ever wondered how to intercept and tamper with Mobile Applications, here's two videos explaining how to setup a proxy on your device and do just that.
Android: https://youtu.be/cRN0WEzadsE
iOS: https://youtu.be/AWsvdiVN4PA
π£mrturvey
π@malwr
YouTube
How to proxy Android applications
Don't forget to subscribe and like the video for continued Cyber Security viewing!
In this video you will learn how to proxy Android applications with Burp Suite and intercept web and mobile applications. This will then allow you to tamper with the HTTPSβ¦
In this video you will learn how to proxy Android applications with Burp Suite and intercept web and mobile applications. This will then allow you to tamper with the HTTPSβ¦
FIDO2 security key company publishes results of internal security audit
π£qznc_bot2
There is a discussion on Hacker News
π€qznc_bot2
π@malwr
π£qznc_bot2
There is a discussion on Hacker News
π€qznc_bot2
π@malwr
Doyensec
Security Analysis of the Solo Firmware
We engaged Doyensec to perform a security assessment of our firmware, v3.0.1 at the time of testing. During a 10 person/days project, Doyensec discovered and reported 3 vulnerabilities in our firmware. While two of the issues are considered informationalβ¦
Threat Analysis: Active C2 Discovery Using Protocol Emulation Part2 (Winnti 4.0)
π£digicat
Part 1: https://www.carbonblack.com/2019/09/04/cb-tau-threat-intelligence-notification-winnti-malware-4-0/
π@malwr
π£digicat
Part 1: https://www.carbonblack.com/2019/09/04/cb-tau-threat-intelligence-notification-winnti-malware-4-0/
π@malwr
Broadcom
Why Carbon Black? | Carbon Black
The right decisions require the right data. That's why Carbon Black is here to help you see targeted threats and prevent repeated attacks.