Week: 17 | Month: April | Year: 2014 | Release Date: 28/04/2014 | Edition: 13º

Must See

Something that really worth your time!

URL: https://community.rapid7.com/community/metasploit/blog/2014/04/15/exploiting-csrf-without-javascript
Description: Exploiting CSRF under NoScript Conditions.

URL: http://breaktoprotect.blogspot.in/2014/04/feedly-android-application-zero-day.html
Description: Feedly Android Application Zero-day Vulnerability - JavaScript Code Injection.

URL: https://github.com/apenwarr/sshuttle
Description: Transparent proxy server that works as a poor man's VPN.

Hack

Some Kung Fu Techniques.

URL: https://github.com/yarrick/iodine
Description: Tunnel IPv4 data through a DNS server.

URL: https://github.com/DiabloHorn/rdps2rdp
Description: Decrypt MITM SSL RDP and save to pcap.

URL: http://pyrasite.readthedocs.org/en/latest/CLI.html
Description: Inject arbitrary code into a running Python process.

URL: https://code.google.com/p/pdf-grapher/
Description: pdf-grapher graphs PDF objects and references to help aid in malicious PDF analysis.

Security

All about security issues/problems.

URL: http://phrack.org/papers/revisiting-mac-os-x-kernel-rootkits.html
Description: Revisiting Mac OS X Kernel Rootkits.

URL: http://www.mehmetince.net/codeigniter-object-injection-vulnerability-via-encryption-key/
Description: Codeigniter Object Injection Vulnerability via Encryption Key.

URL: http://www.sodnpoo.com/posts.xml/spoofing_the_samsung_smart_tv_internet_check.xml
Description: Spoofing the samsung smart tv internet check.

URL: http://www.debasish.in/2014/04/attacking-audio-recaptcha-using-googles.html
Description: Attacking Audio reCaptcha using Google's Web Speech API.

URL: http://2014.hackitoergosum.org/slides/
Description: Hackito Ergo Sum 2014 Slides.

Fun

Spare time ?

URL http://smutefy.inacho.es/ | https://gist.github.com/pcworld/3198763
Description: Spotify Ad Mute (MacOS and Linux).

URL: https://www.youtube.com/watch?v=whEWE6WC1Ew
Description: I'm a C I Double S P (CISSP Parody).

URL: http://annasagrera.com/on-ascii-youtube-and-letting-go/
Description: On ascii, youtube and letting go.

Credits

Content Helpers (0x)

52656e61746f20526f64726967756573202d204073696d7073306e202d20687474703a2f2f706174686f6e70726f6a6563742e636f6d
5065746b6f205065746b6f76202d2040706470202d2068747470733a2f2f61626f75742e6d652f706470