Archive

Archive

1481 bookmarks
Custom sorting
New Scam Holds YouTube Channels for Ransom
New Scam Holds YouTube Channels for Ransom
Scammers are abusing the YouTube policy violation system by filing fake copyright infringements against content creators until their channel is close to being suspended. These scammers then hold the c…
·bleepingcomputer.com·
New Scam Holds YouTube Channels for Ransom
KJCracks/Clutch
KJCracks/Clutch
Fast iOS executable dumper. Contribute to KJCracks/Clutch development by creating an account on GitHub.
·github.com·
KJCracks/Clutch
nabla-c0d3/ssl-kill-switch2
nabla-c0d3/ssl-kill-switch2
Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps - nabla-c0d3/ssl-kill-switch2
·github.com·
nabla-c0d3/ssl-kill-switch2
CSRF in Periscope Producer API
CSRF in Periscope Producer API
My last blog post was like 1 year old so I thought I would quickly write something interesting with a bug I found recently on Twitter (Periscope). The bug (CSRF) itself is not particuarly impressive b…
·blog.innerht.ml·
CSRF in Periscope Producer API
Поиск дающих шопов
Поиск дающих шопов
Доброго времени суток, коллеги. Сегодня немного отойдем от тематики ebay и попиздим о шопах.Как найти дающие шопы и сэкономить своё время и нервы.
·telegra.ph·
Поиск дающих шопов
Угоняем телегу
Угоняем телегу
Всем привет, друзья) Тема безопасности и анонимности телеграма до сих пор постоянно обсуждается. И сегодня я хочу рассказать вам о том, каким образом можно украть доступ к телеграмму другого человека.…
·telegra.ph·
Угоняем телегу
LeakLooker: Find Open Databases in Seconds
LeakLooker: Find Open Databases in Seconds
TL;DR With LeakLooker you can find publicly open MongoDB, CouchDB and Elasticsearch database, it also includes Kibana instances. Script…
·hackernoon.com·
LeakLooker: Find Open Databases in Seconds
Spoofing Google Search results
Spoofing Google Search results
TL;DR - By adding two parameters to any Google Search URL, you can replace search results with a Knowledge Graph card of your choice. A malicious user can use this to generate false information or ‘fa…
·wietzebeukema.nl·
Spoofing Google Search results
How to write a rootkit without really trying
How to write a rootkit without really trying
We open-sourced a fault injection tool, KRF, that uses kernel-space syscall interception. You can use it today to find faulty assumptions (and resultant bugs) in your programs. Check it out! This post…
·blog.trailofbits.com·
How to write a rootkit without really trying
m1ghtym0/browser-pwn
m1ghtym0/browser-pwn
An updated collection of resources targeting browser-exploitation. - m1ghtym0/browser-pwn
·github.com·
m1ghtym0/browser-pwn
sharkdp/hexyl
sharkdp/hexyl
A command-line hex viewer. Contribute to sharkdp/hexyl development by creating an account on GitHub.
·github.com·
sharkdp/hexyl
xss in Steam Chat client
xss in Steam Chat client
# 1. Background The Steam Chat client is a particularly interesting system to attack because it's built using a modern set of technologies with strong security characteristics. It's built on...
·hackerone.com·
xss in Steam Chat client
christian-korneck/get_win8key
christian-korneck/get_win8key
script to read the Windows 8.x OEM license key from PC firmware - christian-korneck/get_win8key
·github.com·
christian-korneck/get_win8key
good ol’ Run key, another persistence location
good ol’ Run key, another persistence location
Scanning the Windows files for possible persistence mechanisms I came across a few interesting strings inside the Natural Language Development Platform 6 library (NaturalLanguage6.dll): StemmerDLLPath…
·hexacorn.com·
good ol’ Run key, another persistence location
Facebook’s ImageTragick story
Facebook’s ImageTragick story
I want to believe that all of you know about ImageMagick and its Tragick. This issue was found in the end of the April, 2016 and due to many processing plugins depends on the ImageMagick library this …
·4lemon.ru·
Facebook’s ImageTragick story
radareorg/cutter
radareorg/cutter
A Qt and C++ GUI for radare2 reverse engineering framework - radareorg/cutter
·github.com·
radareorg/cutter
XSSing Google Code-in thanks to improperly escaped JSON data
XSSing Google Code-in thanks to improperly escaped JSON data
Google Code-in is an online programming competition for students hosted by Google that takes place every year. When I was signing up for a second time, I put a payload into all the text fields. I didn…
·blog.thomasorlita.cz·
XSSing Google Code-in thanks to improperly escaped JSON data
Logically Bypassing Browser Security Boundaries
Logically Bypassing Browser Security Boundaries
This talk was presented at bugSWAT. Video of the talk is at https://youtu.be/B5ZyYTKp4gc Talk features: Password manager issue with iframe/CSP sandbox https://crbug.com/825258, https://bugzilla.mozill…
·speakerdeck.com·
Logically Bypassing Browser Security Boundaries
Microsoft Account Takeover Vulnerability Affecting 400 Million Users
Microsoft Account Takeover Vulnerability Affecting 400 Million Users
During our first security investigation for critical vulnerabilities affecting Microsoft, we came across multiple vulnerabilities that, when chained together, allow an attacker to take over any Micros…
·safetydetective.com·
Microsoft Account Takeover Vulnerability Affecting 400 Million Users
50 CVEs in 50 Days: Fuzzing Adobe Reader
50 CVEs in 50 Days: Fuzzing Adobe Reader
A Fuzzing Drill Hits the Motherlode Research By: Yoav Alon, Netanel Ben-Simon Introduction The year 2017 was an inflection point in the vulnerability landscape. The number of new vulnerabilities repor…
·research.checkpoint.com·
50 CVEs in 50 Days: Fuzzing Adobe Reader