Archive

Archive

1481 bookmarks
Custom sorting
Hot Potato – Windows Privilege Escalation
Hot Potato – Windows Privilege Escalation
By @breenmachine Privilege Escalation on Windows 7,8,10, Server 2008, Server 2012 … and a new network attack How it works Hot Potato (aka: Potato) takes advantage of known issues in Windows t…
·foxglovesecurity.com·
Hot Potato – Windows Privilege Escalation
CVE-2015-2545 ITW EMET Evasion
CVE-2015-2545 ITW EMET Evasion
Sometime back, FireEye discovered a 0day attack using docx file format Two for One: Microsoft Office Encapsulated PostScript and Wind...
·casual-scrutiny.blogspot.ru·
CVE-2015-2545 ITW EMET Evasion
GreenDog's blog: Remote detection of a user's AV using Flash
GreenDog's blog: Remote detection of a user's AV using Flash
Attention, the method works not as well as it should There is a possibility to find out a vendor of AV installed on a user's PC. Remotely and without detection from the user. This information could be useful for us if we want to attack the user. The method is based on two main features. The first feature. The most of modern AVs can detect malware analyzing network traffic. Usually, http and smtp/pop3/imap protocols are analyzed. However, as TLS is used more and more often, then an AV actually has to perform a man in the middle attack against a user application and a remote server. To byp...
·agrrrdog.blogspot.ru·
GreenDog's blog: Remote detection of a user's AV using Flash
Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Da
Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Da
We recently discovered two zero-day vulnerabilities in Adobe Reader. Adobe has since released a patch (on October 6, 2016) to fix these vulnerabilities, which are named CVE-2016-6957 and CVE-2016-6958. These vulnerabilities could allow an attacker to compromise Adobe Reader by bypassing restrictions on JavaScript API execution (CVE-2016-6957) and security provisions that prevent arbitrary execution of scripts such as those written in Python (CVE-2016-6957). In this blog post, I will provide a technical walkthrough of these vulnerabilities, how they can be exploited, and how Palo Alto Networ...
·researchcenter.paloaltonetworks.com·
Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Da
Jurczyk windows metafile_pacsec_v2
Jurczyk windows metafile_pacsec_v2
Windows Metafiles An Analysis of the EMF A1ack Surface & Recent Vulnerabili;es Mateusz “j00ru” Jurczyk PacSec, Tokyo 2016
·slideshare.net·
Jurczyk windows metafile_pacsec_v2
Detecting headless browsers
Detecting headless browsers
This presentation by Sergey Shekyan and Bei Zhang discusses offensive use of headless browsers tools, and how to counteract them in practice.
·slideshare.net·
Detecting headless browsers
Опасное видео: как я нашёл уязвимость в видеохостингах и не умер через 7 дн
Опасное видео: как я нашёл уязвимость в видеохостингах и не умер через 7 дн
Всем привет! Я Максим Андреев, программист бэкенда Облака Mail.Ru. В свободное время я люблю искать баги. В сегодняшнем посте я хочу рассказать об одной...
·habrahabr.ru·
Опасное видео: как я нашёл уязвимость в видеохостингах и не умер через 7 дн
https://goo.gl/oaM7Mu
https://goo.gl/oaM7Mu
HTML Compiler - Remote Code Execution. CVE-2014-6332. Remote exploit for Windows platform
·t.co·
https://goo.gl/oaM7Mu
Motivation
Motivation
A look at how the Snifflab test environment works to collect packets and man-in-the-middle HTTPS communications for easy security research.
·bit.ly·
Motivation