Samsung freaks out smartphone owners with mysterious β1β notification
Samsung explained:
π@malwr
Samsung explained:
This notification was confirmed as a message sent unintentionally during internal testing and there is no effect on your device. Samsung apologises for any inconvenience this may have caused to our customers and will work to prevent similar cases from occurring in the future
π@malwr
Graham Cluley
Samsung freaks out smartphone owners with mysterious β1β notification
Samsung has apologised after it accidentally sent a bizarre notification to smartphone owners' devices.
Exclusive: Pakistan and India to armaments: Operation Transparent Tribe is back 4 years later
π£quellaman
π@malwr
π£quellaman
π@malwr
Security Affairs
Pakistan and India to armaments:Operation Transparent Tribe 4 years later
Exclusive: Pakistan and India to armaments. Researchers from Cybaze-Yoroi ZLab gathered intelligence on the return of Operation Transparent Tribe, 4 years later
Forwarded from CVE Notify
π¨ CVE-2020-9320
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK.
π@cveNotify
Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform Anti-malware SDK.
π@cveNotify
blog.zoller.lu
[TZO-19-2020] - AVIRA Generic AV Bypass (ISO Container)
Musings on Information Security and Privacy Risk Management - Thierry Zoller.
Forwarded from CVE Notify
π¨ CVE-2019-14688
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.
π@cveNotify
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.
π@cveNotify
Mobile networks - Do they have a text message spam filter?
Someone is using my phone number when making online enquires. They've been doing it for about 2 months now. So I'm getting unsolicited texts and calls.
I've decided to attempt to contact the person to persuade them to stop. In my country, I predict I'll need to send 100 text messages to find them...if they respond to the text. It feels like they're changing a digit of their own phone number.
The content of the text will be exactly the same, it'll be using a newly registered sim, and I'll be using a GSM module connected to my computer.
If this were emails, I imagine Google and Microsoft would probably mark the emails as spam. And so I'm curious if mobile networks would treat text messages in the same manner?
I ask in this sub because I imagine someone in this community has played with mass text messages and I can't think of a better sub.
π£reddit_user33
Mobile networks do have some spam protections, depending on the service provider. The problem is that many of these networks allow phone number spoofing, meaning you can call from a number you donβt own. This bypasses a lot of the anti-spam protections in place. Itβs a huge problem world wide and thereβs not much anyone can do about it because networks donβt want to spend the money to fix it, and government agencies wonβt force them to fix it. (Often because these government agencies get lobbied by the networks)
Thereβs really just not much you can do. Even if you call the original number, thereβs probably not a person on the other side, just a computer.
π€NullOfUndefined
π@malwr
Someone is using my phone number when making online enquires. They've been doing it for about 2 months now. So I'm getting unsolicited texts and calls.
I've decided to attempt to contact the person to persuade them to stop. In my country, I predict I'll need to send 100 text messages to find them...if they respond to the text. It feels like they're changing a digit of their own phone number.
The content of the text will be exactly the same, it'll be using a newly registered sim, and I'll be using a GSM module connected to my computer.
If this were emails, I imagine Google and Microsoft would probably mark the emails as spam. And so I'm curious if mobile networks would treat text messages in the same manner?
I ask in this sub because I imagine someone in this community has played with mass text messages and I can't think of a better sub.
π£reddit_user33
Mobile networks do have some spam protections, depending on the service provider. The problem is that many of these networks allow phone number spoofing, meaning you can call from a number you donβt own. This bypasses a lot of the anti-spam protections in place. Itβs a huge problem world wide and thereβs not much anyone can do about it because networks donβt want to spend the money to fix it, and government agencies wonβt force them to fix it. (Often because these government agencies get lobbied by the networks)
Thereβs really just not much you can do. Even if you call the original number, thereβs probably not a person on the other side, just a computer.
π€NullOfUndefined
π@malwr
Reddit
Mobile networks - Do they have a text message spam filter? : r/hacking
2.7M subscribers in the hacking community. A subreddit dedicated to hacking and hackers. Constructive collaboration and learning about exploitsβ¦
MASSIVE Slickwraps Data breach!
https://preview.redd.it/glle8vcgpbi41.png?width=1892&format=png&auto=webp&s=f51a26272b2fb64b01fe2b25b22bef1b1a95ae4e
Whole story at https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
https://www.droid-life.com/2020/02/21/slickwraps-appears-to-have-suffered-a-massive-data-breach/
https://www.androidcentral.com/slickwraps-website-full-vulnerabilities-and-they-dont-seem-care
https://www.androidpolice.com/2020/02/21/slickwraps-has-been-hacked-customer-data-is-compromised/
π£projeto56
Whole story at https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb(Includes PDF of the pentest report)
https://www.androidpolice.com/2020/02/21/slickwraps-has-been-hacked-customer-data-is-compromised/
π€projeto56
π@malwr
https://preview.redd.it/glle8vcgpbi41.png?width=1892&format=png&auto=webp&s=f51a26272b2fb64b01fe2b25b22bef1b1a95ae4e
Whole story at https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb
https://www.droid-life.com/2020/02/21/slickwraps-appears-to-have-suffered-a-massive-data-breach/
https://www.androidcentral.com/slickwraps-website-full-vulnerabilities-and-they-dont-seem-care
https://www.androidpolice.com/2020/02/21/slickwraps-has-been-hacked-customer-data-is-compromised/
π£projeto56
Whole story at https://medium.com/@lynx0x00/i-hacked-slickwraps-this-is-how-8b0806358fbb(Includes PDF of the pentest report)
https://www.androidpolice.com/2020/02/21/slickwraps-has-been-hacked-customer-data-is-compromised/
π€projeto56
π@malwr
A new malware sample format called UMSE (Universal Malware Sample Encryption) which improves user confidentiality and reverse engineering process is now available here: https://github.com/dalvarezperez/umse/
βΉοΈ Sent from one of our subscribers
π@malwr
βΉοΈ Sent from one of our subscribers
π@malwr
GitHub
dalvarezperez/umse
Universal Malware Sample Encryption. Contribute to dalvarezperez/umse development by creating an account on GitHub.
Chinese Bitcoin investor loses $45 million to a SIM-Swapping attack.
π£nilehighclub
SIM Swapping is stupid easy too, thatβs why this is a rampant issue - all it takes is someone inside the carrier (and not even a high ranking person)
π€mc2memes
These sort of attacks are just stunning.
I still have not really worked out how they manage to steal a persons phone number.
I guess they gain a lot of information about a person so they can answer any question an ISP may ask. Or is it simply the fact that ISP's have basically no security built into their processes?
π€VestigialHead
You keep 45 million on something protected by an sms on a phone.... youβre an idiot
π€EAP007
π@malwr
π£nilehighclub
SIM Swapping is stupid easy too, thatβs why this is a rampant issue - all it takes is someone inside the carrier (and not even a high ranking person)
π€mc2memes
These sort of attacks are just stunning.
I still have not really worked out how they manage to steal a persons phone number.
I guess they gain a lot of information about a person so they can answer any question an ISP may ask. Or is it simply the fact that ISP's have basically no security built into their processes?
π€VestigialHead
You keep 45 million on something protected by an sms on a phone.... youβre an idiot
π€EAP007
π@malwr
X (formerly Twitter)
X
Cacti v1.2.8 authenticated Remote Code Execution (CVE-2020-8813) - Shells.Systems
π£cyberg0100
π@malwr
π£cyberg0100
π@malwr
Shells.Systems
Cacti v1.2.8 authenticated Remote Code Execution (CVE-2020-8813) - Shells.Systems
Estimated Reading Time: 8 minutesSummary about Cacti Cacti is a complete network graphing solution designed to harness the power of RRDToolβs data storage and graphing functionality, Cacti provides a fast poller, advanced graph templating, multiple dataβ¦