Sentrant | Bedep Ad-Fraud Botnet Analysis – Exposing the Mechanics Behind 1
Windows 10^H^H Symbolic Link Mitigations
Posted by James Forshaw, abusing symbolic links like it’s 1999. For the past couple of years I’ve been researching Windows elevation of ...
https://gist.github.com/subTee/28b7439d3dfa07053b61
Navigation menu
Views
http://subt0x10.blogspot.ru/
Introducing bstrings, a Better Strings utility!
Do you like strings? Do you like to find strings? How about in binary data? What about via regular expressions? ME TOO! bstrings works l...
10 Places to Stick Your UNC Path
Doing an assessment and want to capture some hashes? Here's 10 methods you can try to get a user to authenticate to you over SMB.
http://goo.gl/w6NUay
Compromised by Endpoint Protection
In a recent research project, Markus Wulftange of Code White discovered several critical vulnerabilities in the Symantec Endpoint Protection...
Bypassing Malware Scanning in Sophos UTM Web Protection - Again
Intro
https://www.fox-it.com/en/files/2015/08/FoxIT-Whitepaper_Blackhat-web.pdf
OpenSSH 6.9p1 Authentication Bypass / Use-After-Free
Blue Frost has realised a new security note OpenSSH 6.9p1 Authentication Bypass / Use-After-Free
http://www.bishopfox.com/download/5439/
https://goo.gl/gg0S8p
xoreaxeaxeax/sinkhole
sinkhole - Architectural privilege escalation on x86
The Art of Transforming Network into Networking -
NetFormation helps businesses navigate digital transformation via Level 3’s unique network with a focus on growth, efficiency, innovation and connections
Firefox < 39.03 - pdf.js Same Origin Policy Exploit
In Ming Loh has realised a new security note Firefox < 39.03 - pdf.js Same Origin Policy Exploit
https://goo.gl/1rcfqj
Ongoing analysis of unknown exploit targeting Office 2007-2013 UTAI MS15-022
NB: This blog post will be updated in the upcoming days with more information Introduction A few days before the publishing of this blog post I came across an unknown RTF exploit sample which I cou…
Abusing Chrome's XSS auditor to steal tokens
Detecting XSS auditor James pointed out to me that XSS auditor in Chrome has a block mode and I thought it might be interesting to see if this could be exploited in some way. When the http header is s
Predicting Vulnerability Exploits With Twitter Analytics - Tudor Dumitras
More and more software vulnerabilities are discovered each year, and hundreds of public disclosures may occur on the same day. For example, the CVE …
Exploiting the Mercury Browser for Android
Remote Code Execution in Dolphin Browser for Android
Unicode Characters in URLs · cure53/H5SC Wiki · GitHub
H5SC - HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors
UAC Bypass Vulnerability in the Windows Script Host.
IPSwitch MoveIt Stored Cross Site Scripting (XSS)
CrowdShield | Create your bug bounty disclosure program and leverage ethical hackers from around the world!
Multiple Vulnerabilities in Pocket
Issues - project-zero - Project Zero - Monorail
Underhanded Javascript - How to be a Complete Arsehole with Bad Javascript
Three bypasses and a fix for one of Flash's Vector.<*> mitigations
Posted by Chris Evans, Cookie Monster With the release of Flash 18.0.0.209 , two mitigations were introduced to combat abuse of Vector ...