The ROCA vulnerability has been discovered by researchers at Masaryk University (Brno, Czech Republic). As two of the researchers are also affiliated with Enigma Bridge we subsequently integrated a ROCA detection tool within this test suite. It allows users of affected products to verify security of their encryption keys.
cryptography  key  security  check  exploit  rsa 
3 days ago by plaxx
Check Infineon-generated RSA keys against ROCA attack
check your RSA keys in a text form, by uploading a keystore in one of the supported types, or by sending an email with a digital signature (S/MIME) or your PGP key to an email responder. 
security  exploit  public  key  cryptography 
4 days ago by dandv
Fairly un-documented static analysis / emulation / symbolik analysis framework for PE/Elf/Mach-O/Blob binary formats on various architectures.
binary  analysis  reverse-engineering  python  security  exploit  research 
9 days ago by plaxx
Thou Shalt Not Depend on Me: Analysing the Use of Outdated JavaScript Libraries on the Web (PDF)
Abstract—Web developers routinely rely on third-party Java-Script libraries such as jQuery to enhance the functionality of their sites. However, if not properly maintained, such dependen-cies can create attack vectors allowing a site to be compromised.
Javascript  exploit  article  academic  pdf 
15 days ago by aiefel
sensepost/ruler: A tool to abuse Exchange services
Using compromised exchange email credentials to achieve code execution and party
microsoft  exchange  remote  exploit  security  hacking  pentesting  software 
15 days ago by asteroza

