Understanding Certificate Pinning
https://littlemaninmyhead.wordpress.com/2020/06/08/understanding-certificate-pinning/
https://littlemaninmyhead.wordpress.com/2020/06/08/understanding-certificate-pinning/
Little Man In My Head
Understanding Certificate Pinning
Certificate pinning (“cert pinning” for short) is a technique used for mobile applications to add an extra layer of protection to secure communications. Some people additionally use the…
A nice diff-view webpage between WinNT structs, quite useful https://ntdiff.github.io
Announcing Connected Papers — a visual tool for researchers to find and explore academic papers https://medium.com/connectedpapers/announcing-connected-papers-a-visual-tool-for-researchers-to-find-and-explore-academic-papers-89146a54c7d4
Medium
Announcing Connected Papers — a visual tool for researchers to find and explore academic papers
We release Connected papers to the public! Enter a paper of interest and we will generate a graph that shows that section of paper-space…
Fuzzing sockets, part 1: FTP servers https://securitylab.github.com/research/fuzzing-sockets-FTP
GitHub Security Lab
Fuzzing sockets, part 1: FTP servers
Antonio shares findings and tips from his research on socket-based fuzzing. Let’s start with the audit of three widely-used FTP servers, with details on interesting CVEs found along the way.
CVE-2020-6110 Zoom Client Application Chat Code Snippet Remote Code Execution Vulnerability https://talosintelligence.com/vulnerability_reports/TALOS-2020-1056
Reversing DexGuard https://www.pnfsoftware.com/blog/reversing-dexguard/
Looking at Big Threats Using Code Similarity. Part 1 https://securelist.com/big-threats-using-code-similarity-part-1/97239/
Securelist
Looking at Big Threats Using Code Similarity – part 1
Big Threats Using Code Similarity. Part 1 Today, we are announcing the release of KTAE, the Kaspersky Threat Attribution Engine. This code attribution technology, developed initially for internal use by the Kaspersky Global Research and Analysis Team,
Attacking FreeIPA — Part IV: CVE-2020–10747 https://posts.specterops.io/attacking-freeipa-part-iv-cve-2020-10747-7c373a1bf66b
Medium
Attacking FreeIPA — Part IV: CVE-2020–10747
This post is the final part in a series about my experiences attacking FreeIPA. In Part I of this series, we reviewed some of the…
Bahrain, Kuwait and Norway contact tracing apps among most dangerous for privacy https://www.amnesty.org/en/latest/news/2020/06/bahrain-kuwait-norway-contact-tracing-apps-danger-for-privacy/
Amnesty International
Bahrain, Kuwait and Norway contact tracing apps a danger for privacy
Amnesty investigation of contact tracing apps from Europe, Middle East and North Africa finds several are dangerous for human rights.
A Click from the Backyard | Analysis of CVE-2020-9332, a Vulnerable USB Redirection Software https://labs.sentinelone.com/click-from-the-backyard-cve-2020-9332/