Archive

Archive

1481 bookmarks
Custom sorting
A Guide To Subdomain Takeovers
A Guide To Subdomain Takeovers
HackerOne's Hacktivity feed — a curated feed of publicly-disclosed reports — has seen its fair share of subdomain takeover reports. Since Detectify's fantastic series on subdomain takeovers, the bug b…
·hackerone.com·
A Guide To Subdomain Takeovers
Using PoolTags to Fingerprint Hosts
Using PoolTags to Fingerprint Hosts
Commonly, malware will fingerprint the host it executes on, in an attempt to discover more about its environment and act accordingly. Part of this process is quite often dedicated to analyzing spec…
·labs.nettitude.com·
Using PoolTags to Fingerprint Hosts
Why so Spurious? (BlackHat 2018) - Final
Why so Spurious? (BlackHat 2018) - Final
Error-Prone x86/x64 CPU "Feature" can be Abused to Achieve Local Privilege Escalation on Many Operating Systems
·docs.google.com·
Why so Spurious? (BlackHat 2018) - Final
CS:GO RCE 0-day - Real World CTF Qualifiers 2018
CS:GO RCE 0-day - Real World CTF Qualifiers 2018
This was the P90_Rush_B challenge from Real World CTF Qualifiers - 2018, in which we participated as perfect blue This challenge was solved by @j0nathanj and @VoidMercy_pb. Unfortunately we did not ma…
·blog.perfect.blue·
CS:GO RCE 0-day - Real World CTF Qualifiers 2018
Светлые паттерны Амазона
Светлые паттерны Амазона
1 августа 2018 года была опубликована статья "Тёмные паттерны Amazon", мало того, что переводная, так и кроме этого содержащая крайне мало фактических данных,...
·habr.com·
Светлые паттерны Амазона
downloaded are being scanned by the antivirus program
downloaded are being scanned by the antivirus program
When IOfficeAntiVirus::Scan method is called by the programs (or internally via IAttachmentExecute) the system enumerates the Registry, collects info about all components implementing IOfficeAntiVirus, and stores them inside the following location
·hexacorn.com·
downloaded are being scanned by the antivirus program
LFI and SSRF via XXE in emblem editor
LFI and SSRF via XXE in emblem editor
This summary is provided by the researcher who submitted this report, @alexbirsan ....
·hackerone.com·
LFI and SSRF via XXE in emblem editor
UWP Localhost Network Isolation and Edge
UWP Localhost Network Isolation and Edge
“feature” added to Windows to support Edge accessing the loopback network interface. For referenc...
·tyranidslair.blogspot.com·
UWP Localhost Network Isolation and Edge
RFID Thief v2.0
RFID Thief v2.0
Building and using the RFID Thief v2.0 for long range RFID cloning
·scund00r.com·
RFID Thief v2.0
Новая техника атак на основе Meltdown. Использование спекулятивных инструкций для детектирования виртуализации
Новая техника атак на основе Meltdown. Использование спекулятивных инструкций для детектирования виртуализации
Атака Meltdown открыла новый класс атак на процессоры, использующий архитектурные состояния для передачи информации. Но спекулятивное исполнение, которое было...
·habr.com·
Новая техника атак на основе Meltdown. Использование спекулятивных инструкций для детектирования виртуализации
x0rz/tweets_analyzer
x0rz/tweets_analyzer
Tweets metadata scraper & activity analyzer
·github.com·
x0rz/tweets_analyzer
EagleEye
EagleEye
Stalk your Friends. Find their Instagram, FB and Twitter Profiles using Image Recognition and Reverse Image Search.
·github.com·
EagleEye
Exploiting MS15-076 (CVE-2015-2370)
Exploiting MS15-076 (CVE-2015-2370)
A few weeks ago (July 14, 2015), Microsoft had a busy patch Tuesday fixing quite a few privilege escalation vulnerabilities. Among these was a bug in DCOM/RPC which allows for an...
·silentbreaksecurity.com·
Exploiting MS15-076 (CVE-2015-2370)
minimaxir/big-list-of-naughty-strings
minimaxir/big-list-of-naughty-strings
big-list-of-naughty-strings - The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data.
·github.com·
minimaxir/big-list-of-naughty-strings
Research Spotlight: Detecting Algorithmically Generated Domains
Research Spotlight: Detecting Algorithmically Generated Domains
This post was authored by Mahdi Namazifar and Yuxi Pan Once a piece of malware has been successfully installed on a vulnerable system one of the first orders of business is for the malware to reach out to the remote command-and-control (C&C) servers in order to receive further instructions, u
·tinyurl.com·
Research Spotlight: Detecting Algorithmically Generated Domains
cure53/H5SC
cure53/H5SC
H5SC - HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors
·github.com·
cure53/H5SC