Article: 3046310 - Improperly Issued Digital Certificates Could Allow Spoofing - Version: 2.0 - published almost 10 years ago. Content: Revision Note: V2.0 (March 19, 2015): Advisory rereleased to announce that the update for supported editions of Windows Server 2003 is now available. See Knowledge Base Article 3046310 for more information and download links.Summary: Microsoft is aware of an improperly issued SSL certificate for the domain “live.fi” that could be used in attempts to spoof co... https://technet.microsoft.com/en-us/library/security/3046310 Published: 2015 03 19 17:00:00 Received: 2022 04 14 18:03:37 Feed: Latest Security Advisories Source: Latest Security Advisories Category: Alerts Topic: Vulnerabilities |
Article: The OpenSSL project releases new versions of its software to squash 12 security vulnerabilities - published almost 10 years ago. Content: http://www.livehacking.com/2015/03/19/new-versions-openssl-to-squash-12-security-vulnerabilities/ Published: 2015 03 19 14:56:46 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Android Browser Kitkat Content Spoofing Vulnerability - published almost 10 years ago. Content: The following is a low risk vulnerability that was found few months ago while testing the latest Android Stock browser on Android Kitkat. The issue that was found is commonly referred as Content spoofing Vulnerability or dialog box spoofing vulnerability which could be used to fake an alert message on a legitimate website. In other words, i could d... http://www.rafayhackingarticles.net/2015/03/android-browser-kitkat-content-spoofing.html Published: 2015 03 12 05:41:00 Received: 2024 02 17 13:21:47 Feed: Ethical Hacking - Rafayhackingarticles Source: Ethical Hacking - Rafayhackingarticles Category: Cyber Security Topic: Cyber Security |
|
Article: 3033929 - Availability of SHA-2 Code Signing Support for Windows 7 and Windows Server 2008 R2 - Version: 1.0 - published almost 10 years ago. Content: Revision Note: V1.0 (March 10, 2015): Advisory published.Summary: Microsoft is announcing the reissuance of an update for all supported editions of Windows 7 and Windows Server 2008 R2 to add support for SHA-2 signing and verification functionality. This update supersedes the 2949927 update that was rescinded on October 17, 2014 to address issues that some c... https://technet.microsoft.com/en-us/library/security/3033929 Published: 2015 03 10 17:00:00 Received: 2022 04 14 18:03:38 Feed: Latest Security Advisories Source: Latest Security Advisories Category: Alerts Topic: Vulnerabilities |
Article: 3046015 - Vulnerability in Schannel Could Allow Security Feature Bypass - Version: 2.0 - published almost 10 years ago. Content: Severity Rating: ImportantRevision Note: V2.0 (March 10, 2015): Advisory updated to reflect publication of security bulletin.Summary: Microsoft has completed the investigation into a public report of a vulnerability. We have issued Microsoft Security Bulletin MS15-031 to address this issue. For more information about this issue, including download links for ... https://technet.microsoft.com/en-us/library/security/3046015 Published: 2015 03 10 17:00:00 Received: 2022 04 14 18:03:37 Feed: Latest Security Advisories Source: Latest Security Advisories Category: Alerts Topic: Vulnerabilities |
|
Article: Ask and you shall receive - published almost 10 years ago. Content: I get emails from readers asking for specific malware samples and thought I would make a mini post about it. Yes, I often obtain samples from various sources for my own research. I am sometimes too lazy/busy to post them but don't mind sharing. If you are looking for a particular sample, feel free to ask. I might have it. Send MD5 (several or few s... https://contagiodump.blogspot.com/2015/03/ask-and-you-shall-receive.html Published: 2015 03 09 01:08:00 Received: 2024 03 13 18:00:19 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: Thousand ways to backdoor a Windows domain (forest) - published almost 10 years ago. Content: When the Kerberos elevation of privilege (CVE-2014-6324 / MS14-068) vulnerability has been made public, the remediation paragraph of the following blog post made some waves: http://blogs.technet.com/b/srd/archive/2014/11/18/additional-information-about-cve-2014-6324.aspx "The only way a domain compromise can be remediated with a high level of certainty is... https://jumpespjump.blogspot.com/2015/03/thousand-ways-to-backdoor-windows.html Published: 2015 03 05 21:04:00 Received: 2023 03 31 10:02:48 Feed: Jump ESP, jump! Source: Jump ESP, jump! Category: Cyber Security Topic: Cyber Security |
Article: FREAK vulnerability weakens secure Web sites - published almost 10 years ago. Content: http://www.livehacking.com/2015/03/04/freak/ Published: 2015 03 04 09:24:02 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: WP-Slimstat vulnerability exposes WordPress websites to SQL injection attacks - published almost 10 years ago. Content: http://www.livehacking.com/2015/02/25/wp-slimstat-vulnerability/ Published: 2015 02 25 11:37:19 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: Collection of Pcap files from malware analysis - published almost 10 years ago. Content: Update: Feb 19. 2015 We have been adding pcaps to the collection so remember to check out the folder ( Pcap collection) for the recent pcaps. I had a project to test some malicious and exploit pcaps and collected a lot of them (almost 1000) from various public sources. You can see them in the PUBLIC folder. The credits go to the authors of the pcaps lis... https://contagiodump.blogspot.com/2013/04/collection-of-pcap-files-from-malware.html Published: 2015 02 20 04:39:00 Received: 2023 03 31 08:41:26 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: iOS Masque Attack Revived: Bypassing Prompt for Trust and App URL Scheme Hijacking - published almost 10 years ago. Content: In November of last year, we uncovered a major flaw in iOS we dubbed “Masque Attack” that allowed for malicious apps to replace existing, legitimate ones on an iOS device via SMS, email, or web browsing. In total, we have notified Apple of five security issues related to four kinds of Masque Attacks. Today, we are sharing Masque Attack II in the ... https://www.fireeye.com/blog/threat-research/2015/02/ios_masque_attackre.html Published: 2015 02 19 19:00:00 Received: 2022 05 23 16:06:47 Feed: FireEye Blog Source: FireEye Blog Category: Cyber Security Topic: Cyber Security |
|
Article: Equation samples - from the Kaspersky Report and additional - published almost 10 years ago. Content: Here are a few samples from the report by Kaspersky Lab "Equation: The Death Star of Malware Galaxy" and additional samples of the same family. The full list is belowDownload all the samples listed below. Email me if you need the password (New link)List of filesFiles from the report:File NameMD5Size_SD_IP_CF.dll_03718676311DE33DD0B8F4F18CFFD48803718676311de3... http://contagiodump.blogspot.com/2015/02/equation-samples-from-kaspersky-report.html Published: 2015 02 17 06:22:00 Received: 2021 06 06 09:04:40 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
Article: Google backpedals on its arbitrary vulnerability disclosure policy - published almost 10 years ago. Content: http://www.livehacking.com/2015/02/14/google-backpedals-on-its-arbitrary-vulnerability-disclosure-policy/ Published: 2015 02 14 10:58:46 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: 3004375 - Update for Windows Command Line Auditing - Version: 1.0 - published almost 10 years ago. Content: Revision Note: V1.0 (February 10, 2015): Advisory published.Summary: Microsoft is announcing the availability of an update for supported editions of Windows 7, Windows 8, Windows Server 2008R2 and Windows Server 2012 that expands the Audit Process Creation policy to include the command information passed to every process. This is a new feature that provides ... https://technet.microsoft.com/en-us/library/security/3004375 Published: 2015 02 10 18:00:00 Received: 2022 04 14 18:03:38 Feed: Latest Security Advisories Source: Latest Security Advisories Category: Alerts Topic: Vulnerabilities |
|
Article: Oracle Security Alert for CVE-2016-0603 - 5 February 2016
- published almost 10 years ago. Content: http://www.oracle.com/technetwork/topics/security/alert-cve-2016-0603-2874360.html Published: 2015 02 05 19:30:54 Received: 2021 06 06 09:03:27 Feed: Oracle Security Alerts Source: Oracle Security Alerts Category: Alerts Topic: Vulnerabilities |
Article: Cross Site Scripting vulnerability found in IE 11 - published almost 10 years ago. Content: http://www.livehacking.com/2015/02/04/cross-site-scripting-vulnerability-found-in-ie-11/ Published: 2015 02 04 09:46:59 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Blind Return Oriented Programming (BROP) Attack - published almost 10 years ago. Content: submitted by /u/turnersr [link] [comments] https://www.reddit.com/r/vrd/comments/2u7wxo/blind_return_oriented_programming_brop_attack/ Published: 2015 01 30 18:06:05 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
|
Article: Apple updates iOS, OS X and Apple TV in monster patch release - published almost 10 years ago. Content: http://www.livehacking.com/2015/01/28/apple-updates-ios-os-x-and-apple-tv/ Published: 2015 01 28 12:56:01 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: Google discloses three more zero-day vulnerabilities, this time for OS X - published almost 10 years ago. Content: http://www.livehacking.com/2015/01/23/google-discloses-three-more-zero-day-vulnerabilities-this-time-for-os-x/ Published: 2015 01 23 07:45:27 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Oracle Critical Patch Update Advisory - January 2015
- published almost 10 years ago. Content: http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html Published: 2015 01 20 19:30:54 Received: 2021 06 06 09:03:27 Feed: Oracle Security Alerts Source: Oracle Security Alerts Category: Alerts Topic: Vulnerabilities |
|
Article: The Devil is in the Constants: Bypassing Defenses in Browser JIT Engines by Michalis Athanasakis, Elias Athanasopoulos, Michalis Polychronakis, Georgios Portokalidis, and Sotiris Ioannidis [PDF] - published almost 10 years ago. Content: submitted by /u/turnersr [link] [comments] https://www.reddit.com/r/vrd/comments/2sppvi/the_devil_is_in_the_constants_bypassing_defenses/ Published: 2015 01 17 06:44:33 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
Article: Preventing Use-after-free with Dangling Pointers Nullification by Byoungyoung Lee, Chengyu Song, Yeongjin Jang, and Tielei Wang [PDF] - published almost 10 years ago. Content: submitted by /u/turnersr [link] [comments] https://www.reddit.com/r/vrd/comments/2sppt4/preventing_useafterfree_with_dangling_pointers/ Published: 2015 01 17 06:43:25 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
|
Article: Hacking freemium games - the evolution of PC game cheating - published almost 10 years ago. Content: This post is going to be a rather strange post compared to previous ones. But bear with me, in the middle of the post you will see why this post fits the IT security topic. I'm also terribly sorry for not posting recently, but I was busy with my SPSE and SLAE certification. Both are recommended for Python and Assembly noobs like me. But back to this post... https://jumpespjump.blogspot.com/2015/01/hacking-freemium-games-evolution-of-pc.html Published: 2015 01 14 19:47:00 Received: 2024 03 12 23:22:34 Feed: Jump ESP, jump! Source: Jump ESP, jump! Category: Cyber Security Topic: Cyber Security |
|
Article: Microsoft to fix Windows vulnerability that Google publicly disclosed last week - published almost 10 years ago. Content: http://www.livehacking.com/2015/01/13/microsoft-to-fix-windows-vulnerability-that-google-publicly-disclosed-last-week/ Published: 2015 01 13 07:43:54 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: How I Evolved your Fuzzer: Techniques for Black-Box Evolutionary Fuzzing by Fabien Duchene [PDF] - published almost 10 years ago. Content: submitted by /u/turnersr [link] [comments]... https://www.reddit.com/r/vrd/comments/2s812x/how_i_evolved_your_fuzzer_techniques_for_blackbox/ Published: 2015 01 12 23:55:46 Received: 2021 06 06 11:29:11 Feed: Vulnerability Research and Development Source: Vulnerability Research and Development Category: Alerts Topic: Vulnerabilities |
Article: Video archives of security conferences and workshops - published about 10 years ago. Content: Just some links for your enjoyment List of security conferences in 2014 Video archives: AIDE (Appalachian Institute of Digital Evidence) 2013 2012 2011 Blackhat 2012 or 2012 torrent Botconf 2013 Bsides BSides DC 2014 BSides Chicago 2014 BSides Nashville 2014 BSides Augusta 2014 BSides Huntsville 2014 BSides Las Vegas 2014 BSidesDE 2013 BSid... https://contagiodump.blogspot.com/2015/01/video-archives-of-security-conferences.html Published: 2015 01 05 04:11:00 Received: 2024 03 13 18:00:19 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: Episode #180: Open for the Holidays! - published about 10 years ago. Content: Not-so-Tiny Tim checks in with the ghost of Christmas present: I know many of you have been sitting on Santa's lap wishing for more Command Line Kung Fu. Well, we've heard your pleas and are pushing one last Episode out before the New Year! We come bearing a solution for a problem we've all encountered. Ever try to delete or modify a file and receive an e... http://blog.commandlinekungfu.com/2014/12/episode-180-open-for-holidays.html Published: 2014 12 31 12:00:00 Received: 2023 03 31 08:44:32 Feed: Command Line Kung Fu Source: Command Line Kung Fu Category: News Topic: Security Tooling |
|
Article: Android Browser Cross Scheme Data Exposure + Intent Scheme Attack - published about 10 years ago. Content: tl;dr This exploit is an issue present in Android browser < 4.4 and several other android browsers which allows an attacker to read sqlite cookie database file and hence exposing all cookies. Along with it we also talk about a Cross Scheme Data exposure attack in Android < 4.4. Introduction During my research on ASOP (Stock Browser) I found out th... http://www.rafayhackingarticles.net/2014/12/android-browser-cross-scheme-data.html Published: 2014 12 29 10:00:00 Received: 2024 02 17 13:21:47 Feed: Ethical Hacking - Rafayhackingarticles Source: Ethical Hacking - Rafayhackingarticles Category: Cyber Security Topic: Cyber Security |
|
Article: Bad Meets evil - PHP meets Regular Expressions - published about 10 years ago. Content: twi This article would briefly discuss the reason why Regular Expressions might not be suitable for filtersand how things could turn miserably bad when PHP comes is used with Regular Expressions. The post would then continue with the write-up of a relevant scenario based challenge, and finally will conclude with the author’s opinion on the topic. Common... http://www.rafayhackingarticles.net/2014/12/bad-meets-evil-php-meets-regular.html Published: 2014 12 25 11:33:00 Received: 2024 02 17 13:21:47 Feed: Ethical Hacking - Rafayhackingarticles Source: Ethical Hacking - Rafayhackingarticles Category: Cyber Security Topic: Cyber Security |
|
Article: Apple updates OS X’s NTP server to address recently disclosed NTP vulnerabilities - published about 10 years ago. Content: http://www.livehacking.com/2014/12/23/apple-updates-os-xs-to-address-ntp-vulnerabilities/ Published: 2014 12 23 08:39:04 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: Common Attacks Against Modems - published about 10 years ago. Content: 0x01: Introduction to Modems The term DSL modem is technically used to describe "a modem which connects to a single computer, through a USB port or is installed in a computer PCI slot". The more common DSL router which combines the function of a DSL modem and a home router is a standalone device which could be connected to multiple computers through m... http://www.rafayhackingarticles.net/2014/12/common-attacks-against-modems.html Published: 2014 12 14 19:40:00 Received: 2024 02 17 13:21:47 Feed: Ethical Hacking - Rafayhackingarticles Source: Ethical Hacking - Rafayhackingarticles Category: Cyber Security Topic: Cyber Security |
|
Article: Microsoft fixes 24 security vulnerabilities in December’s Patch Tuesday - published about 10 years ago. Content: http://www.livehacking.com/2014/12/10/microsoft-fixes-24-security-vulnerabilities-in-decembers-patch-tuesday/ Published: 2014 12 10 07:34:11 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: OphionLocker. New ransomware on the scene - published about 10 years ago. Content: This malware was discovered by a honeypot triggered during a malvertising campaign. The campaign used the RIG exploit kit. Interesting features of this ransomware: Uses elliptic curve cryptography for the encryption of files. (I believe this is the first ransomware to use such methods) Spread using an EK all variants were FUD at time ... http://trojan7malware.blogspot.com/2014/12/ophionlocker-new-ransomware-on-scene.html Published: 2014 12 09 19:46:00 Received: 2023 03 31 23:02:32 Feed: Trojan7Malware Source: Trojan7Malware Category: Cyber Security Topic: Cyber Security |
Article: Sony hack shows that the company kept passwords stored in a folder called “Password” - published about 10 years ago. Content: http://www.livehacking.com/2014/12/05/sony-hacks-shows-that-the-company-kept-passwords-stored-in-a-folder-called-password/ Published: 2014 12 05 10:48:59 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
|
Article: Apple patches security flaws in iOS 8, OS X 10.10 and Apple TV 7 - published about 10 years ago. Content: http://www.livehacking.com/2014/11/18/apple-patches-security-flaws-in-ios-8-os-x-10-10-and-apple-tv-7/ Published: 2014 11 18 07:15:30 Received: 2021 06 06 09:04:45 Feed: LIVE HACKING Source: LIVE HACKING Category: Cyber Security Topic: Cyber Security |
Article: AlienSpy Java RAT samples and traffic information - published about 10 years ago. Content: AlienSpy Java based cross platform RAT is another reincarnation of ever popular Unrecom/Adwind and Frutas RATs that have been circulating through 2014. It appears to be used in the same campaigns as was Unrccom/Adwind - see the references. If C2 responds, the java RAT downloads Jar files containing Windows Pony/Ponik loader. The RAT is crossplatform and ... https://contagiodump.blogspot.com/2014/11/alienspy-java-rat-samples-and-traffic.html Published: 2014 11 17 21:16:00 Received: 2024 03 13 18:00:19 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Article: OnionDuke samples - published about 10 years ago. Content: Research: F-Secure: OnionDuke: APT Attacks Via the Tor Network Download Download. Email me if you need the password (new link) File attributes Size: 219136 MD5: 28F96A57FA5FF663926E9BAD51A1D0CB Size: 126464 MD5: C8EB6040FD02D77660D19057A38FF769 Size: 316928 MD5: D1CE79089578DA2D41F1AD901F7B1014 Vir... https://contagiodump.blogspot.com/2014/11/onionduke-samples.html Published: 2014 11 16 03:58:00 Received: 2024 03 13 18:00:20 Feed: contagio Source: contagio Category: Cyber Security Topic: Cyber Security |
|
Click to Open Code Editor