Pwn a network by calling their fax machine
fax  badtech  security  exploit 
20 minutes ago by nelson
Rotten Potato | Penetration Testing Lab
However there is a technique which can be used that tries to trick the “NT Authority\System” account to negotiate and authenticate via NTLM locally so the token for the “NT Authority\System” account would become available and therefore privilege escalation possible. This technique is called Rotten Potato and it was introduced in DerbyCon 2016 by Stephen Breen and Chris Mallz.
windows  privesc  privilegeescalation  pentest  security 
1 hour ago by whip_lash
GitHub - quentinhardy/odat: ODAT: Oracle Database Attacking Tool
ODAT (Oracle Database Attacking Tool) is an open source penetration testing tool that tests the security of Oracle Databases remotely.
oracle  database  pentest  security  tool 
2 hours ago by whip_lash
An 11-year-old changed election results on a replica Florida state website in under 10 minutes | PBS NewsHour
Great demonstration of just how insecure voting machines are: this conference had KIDS go ahead and hack the machines.
security  voting  via:Techdirt 
2 hours ago by mcherm
Who Left Open The Cookie Jar?
Complexity of the attack surface makes for exploitable bugs.
Good reading of what kinds of things can happen.
browser  security  tracking  cookies  xss 
4 hours ago by drmeme
NSA Cracked Open Encrypted Networks of Russian Airlines, Al Jazeera, and Other “High Potential” Targets
The NSA’s ability to crack into sensitive VPNs belonging to large organizations, all the way back in 2006, raises broader questions about the security of such networks. Many consumers pay for access to VPNs in order to mask the origin of their internet traffic from the sites they visit, hide their surfing habits from their internet service providers, and to protect against eavesdroppers on public Wi-Fi networks.
security  nsa  vpn 
4 hours ago by whip_lash
The Security of Cellular Connections - The New York Times
"On a typical 4G LTE network connection, your data is encrypted and your identity is authenticated and protected."
security  wifi  cellular  nyt 
5 hours ago by outkast

