Service to tell you about expired names which have history/juice
expired  DNS  domain  name  list  service  security  hacking  pentesting  phishing  SEO 
9 days ago by asteroza
The Register on Twitter: ""Spectre? Psst. Who cares. You need local code execution." *record skip*… "
NetSpectre is a thing now, but slow as hell and needs a very stable network to pull off (15 bits per hour right now...)
spectre  remote  network  memory  read  security  hacking  pentesting  research 
23 days ago by asteroza
AlienVault - Open Threat Exchange
Will it remain open after the AT&T deathstar consumes them?
open  threat  exchange  infosec  IoC  security  hacking  pentesting  intelligence  analysis 
5 weeks ago by asteroza
Port Forwarding in Windows | Windows OS Hub
Using native netsh for port forwarding so you can live off the land
windows  port  forwarding  networking  sysadmin  tips  tricks  security  hacking  pentesting 
9 weeks ago by asteroza
New Attack Vector: Serverless Crypto-Mining
If your lambdas aren't tight, you will probably be mining monero shortly...
serveless  security  hacking  pentesting  cryptomining 
10 weeks ago by asteroza
Release 2.1.0 20180527 - Terminal Server Multi RDP · gentilkiwi/mimikatz
So Mimikatz can now patch desktop OS to allow multiple simultaneous concurrent user RDP, Works in Windows 10 1803 too...
mimikatz  multiuser  concurrent  RDP  patch  windows  security  hacking  pentesting 
11 weeks ago by asteroza
Living off the land, some binaries have unusual capabilities. You can exfil with whois, for example...
reference  information  hacking  pentesting  security  exfiltration  shell  tools  utilities  linux 
11 weeks ago by asteroza
[1805.04101] Adding Salt to Pepper: A Structured Security Assessment over a Humanoid Robot
only remote user is nao, but you can brute force the SSH login, and root password is fixed as root. Also unauthenticated command channel over an open TCP port via published API. I guess the only real barrier then is accessing the wifi Pepper runs on then...
Softbank  pepper  robot  security  hacking  pentesting 
11 weeks ago by asteroza
Firefox Send
One time file send service. File lives on server for 24hrs or one download, whichever comes first. Uses clientside encryption so network DLP with SSL stripping won't easily catch it.
mozilla  firefox  selfdestruct  link  file  upload  sharing  service  encryption  DLP  bypass  security  hacking  pentesting 
11 weeks ago by asteroza
9b/chirp: Interface to manage and centralize Google Alert information
Using google alert as an infiltration mechanism, by using the google alert system to delivery shady links directly to your targets...
google  alert  recon  OSINT  security  hacking  pentesting 
12 weeks ago by asteroza
Booby trap a shortcut with a backdoor
fancy pants compression/encoding directly in a shortcut LNK file
security  hacking  pentesting  compressed  payload  powershell  VBscript  C#  shortcut 
may 2018 by asteroza
