Archive

Archive

1481 bookmarks
Custom sorting
Jackin tor
Jackin tor
·packetstorm.foofus.com·
Jackin tor
Own a printer, own a network with point and print drive-by
Own a printer, own a network with point and print drive-by
Printers present an interesting IoT example because they are far more powerful than other IoT devices, yet are not always considered real computers by most network administrators.
·blog.vectranetworks.com·
Own a printer, own a network with point and print drive-by
Inside SafetyNet - part 3 · John Kozyrakis ~ blog
Inside SafetyNet - part 3 · John Kozyrakis ~ blog
This post is part of a series: Inside SafetyNet part 1 (Oct 2015) Inside SafetyNet part 2 (Feb 2016) Inside SafetyNet part 3 (Nov 2016) How to implement Attestation securely using server-side checks (my blog, Cigital blog) SafetyNet Playground (POC server-side implementation) Play Store - Android source - PHP source It’s been more than 8 months since my last blog post on Android’s SafetyNet. In that post I was describing an end-of-2015 version of the system (version code 2495818).
·koz.io·
Inside SafetyNet - part 3 · John Kozyrakis ~ blog
How To Build A Password Cracking Rig
How To Build A Password Cracking Rig
Why????? Why build a cracking rig? Because it's fun! This article will explain every step in building what I call a
·netmux.com·
How To Build A Password Cracking Rig
Simple domain fronting PoC with GAE C2 server - Security Art Work
Simple domain fronting PoC with GAE C2 server - Security Art Work
In this entry we continue with domain fronting; on this occasion we will explore how to implement a simple PoC of a command and control and exfiltration server on Google App Engine (GAE), and we will see how to do the domain fronting from Windows, with a VBS or PowerShell script, to hide interactions with […]
·securityartwork.es·
Simple domain fronting PoC with GAE C2 server - Security Art Work
Pwnani: Use After Free in Google Hangouts ActiveX
Pwnani: Use After Free in Google Hangouts ActiveX
Summary In 2015 I found a use-after free vulnerability in the "Google Talk ActiveX Plugin" that is used by Google Hangouts. The activeX is sitelocked, meaning it can only be invoked from certain whitelisted Google domains. To exploit this, an attacker would need an XSS bug on one of these domains. The bug was reported to Google and has since been fixed.  ActiveX Details When installing Google Hangouts on IE, the control "Google Talk ActiveX Plugin" is installed. This control can be invoked from the browser and exports 5 methods. dispinterface GTalkPluginInterface {     properties:     met...
·pwnanisec.blogspot.ru·
Pwnani: Use After Free in Google Hangouts ActiveX
Fortinet Blog
Fortinet Blog
Google patched some Android security vulnerabilities in early August. One of them was a remote code execution vulnerability in Mediaserver (CVE-2016-3820), which was discovered by me. This vulnerab…
·blog.fortinet.com·
Fortinet Blog
Windows 10 Sharpens Browser Security With Microsoft Edge
Windows 10 Sharpens Browser Security With Microsoft Edge
Internet Explorer is possibly the most popular target for vulnerabilities around today. In 2014 alone, a total of 243 memory corruption vulnerabilities in Internet Explorer were disclosed and patched. Every Microsoft Patch Tuesday cycle contains one bulletin that covers multiple IE vulnerabilities – the monthly “Cumulative Security Update for Internet Explorer”, as it is called...
·blog.trendmicro.com·
Windows 10 Sharpens Browser Security With Microsoft Edge
Places of Interest in Stealing NetNTLM Hashes | ?Blog of Osanda
Places of Interest in Stealing NetNTLM Hashes | ?Blog of Osanda
One day me and @m3g9tr0n was discussing different places where we can use responder in stealing NetNTLM hashes. After experimenting I thought of writing this post along with some cool findings in t…
·osandamalith.com·
Places of Interest in Stealing NetNTLM Hashes | ?Blog of Osanda
Disarming EMET 5.52: Controlling it all with a single write action | blog.r
Disarming EMET 5.52: Controlling it all with a single write action | blog.r
The Enhanced Mitigation Experience Toolkit (EMET) is a software solution from Microsoft that aims at preventing the exploitation of – legacy – software. It is designed to “help prevent …
·blog.ropchain.com·
Disarming EMET 5.52: Controlling it all with a single write action | blog.r