neonprimetime security , just trying to help
Monday, March 5, 2018
Infosec quotes - joomla plain text
“... Simple flaw exposes plaintext password for Database, FTP, SMTP servers' of thousands of #Joomla websites...”
https://twitter.com/thehackersnews/status/970720943403356160?s=21
Infosec quotes - bucket to full compromise
Cloud buckets are scarey, do you know what your users are putting out there ?
“... Identified open S3 bucket -> backup files -> credential file -> partial compromise of AWS -> pivot to other cloud instances -> credential file -> full compromise ...”
https://twitter.com/vysecurity/status/970769553016815616?s=21
Infosec quotes - kali is a Windows app
Do control what apps your users can download from the App Store?
“... Kali Linux is now an App in the Windows Store. Have Kali run natively in Windows...”
https://twitter.com/tinkersec/status/970774059452633093?s=21
Infosec quotes - domain admin outside AD
Gaining Domain Admin from Outside Active Directory
“... mitigations such as using LAPS to manage local administrator passwords and setting FilterAdministratorToken to prevent SMB logins using the local RID 500 account...”
https://twitter.com/x0rz/status/970656354544254976?s=21
Infosec quotes - cameras shodan
“... More than 110 thousand cameras exposed in the shodan can be explored ...”
https://twitter.com/6ix7ine/status/970640054451359744?s=21
Sunday, March 4, 2018
Infosec quotes - defender blocks flash player HTA
Windows defender has blocked of 1 million malicious HTA files this year already , mostly fake flash player updates delivering Kovter
https://twitter.com/wdsecurity/status/969026958804836352?s=21
Infosec quotes - fake chrome updates
Fake updates to Chrome and Flash lead to Ramnit Trojan.
https://twitter.com/broadanalysis/status/969875302838128640?s=21
Newer Posts
Older Posts
Home
Subscribe to:
Posts (Atom)