█████╗ ██████╗ ██████╗ ███████╗███████╗ ██████╗ ███████╗███████╗██╗███╗ ██╗███████╗ ██╔══██╗██╔══██╗██╔══██╗██╔════╝██╔════╝██╔════╝ ██╔════╝╚══███╔╝██║████╗ ██║██╔════╝ ███████║██████╔╝██████╔╝███████╗█████╗ ██║ █████╗ ███╔╝ ██║██╔██╗ ██║█████╗ ██╔══██║██╔═══╝ ██╔═══╝ ╚════██║██╔══╝ ██║ ██╔══╝ ███╔╝ ██║██║╚██╗██║██╔══╝ ██║ ██║██║ ██║ ███████║███████╗╚██████╗ ███████╗███████╗██║██║ ╚████║███████╗ ╚═╝ ╚═╝╚═╝ ╚═╝ ╚══════╝╚══════╝ ╚═════╝ ╚══════╝╚══════╝╚═╝╚═╝ ╚═══╝╚══════╝ ### Week: 10 | Month: March | Year: 2017 | Release Date: 10/03/2017 | Edition: #160 ### ' ╔╦╗┬ ┬┌─┐┌┬┐ ╔═╗┌─┐┌─┐ ' ║║║│ │└─┐ │ ╚═╗├┤ ├┤ ' ╩ ╩└─┘└─┘ ┴ ╚═╝└─┘└─┘ ' Something that's really worth your time! URL: https://klikki.fi/adv/bttv.html Description: BetterTTV Chrome extension stored XSS. URL: https://goo.gl/0GUXQJ (+) Description: Hacking Slack using postMessage and WebSocket-reconnect. URL: https://goo.gl/7yUj5d (+) Description: Ok Google, Give Me All Your Internal DNS Information! ' ╦ ╦┌─┐┌─┐┬┌─ ' ╠═╣├─┤│ ├┴┐ ' ╩ ╩┴ ┴└─┘┴ ┴ ' Some Kung Fu Techniques. URL: https://github.com/antire-book/dont_panic Book: https://leanpub.com/anti-reverse-engineering-linux Description: Linux bind shell with anti-reverse engineering techniques. URL: https://github.com/michael-myers/MacOS-WPA-PSK Description: Script to get wireless key from MacOS NVRAM. URL: https://github.com/nettitude/xss_payloads Description: Payloads for practical exploitation of cross site scripting. URL: https://github.com/sirusdv/EdgeHTTP2Fuzzer Description: HTTP/2 Peach Pit for Microsoft Edge. URL: https://goo.gl/YrxqHQ (+) Description: Bypassing Next-Gen AV For Fun and Profit URL: https://github.com/Rurik/Noriben Description: Noriben - Portable, Simple, Malware Analysis Sandbox. URL: https://github.com/securifera/cowcron Blog: http://research.aurainfosec.io/hunting-for-bugs-101/ Description: Cronbased Dirty Cow Exploit. URL: https://github.com/subTee/AllTheThings Description: Dump of known application WL/control bypasses in one file. URL: https://www.redteam-pentesting.de/advisories/rt-sa-2016-001.txt Description: Padding Oracle in Apache (2.3 to 2.5) mod_session_crypto. URL: https://github.com/Arno0x/DNSDelivery Description: DNSDelivery use DNS requests as a delivery channel. URL: https://github.com/dekimir/RamFuzz Description: A fuzzer for individual method parameters. ' ╔═╗┌─┐┌─┐┬ ┬┬─┐┬┌┬┐┬ ┬ ' ╚═╗├┤ │ │ │├┬┘│ │ └┬┘ ' ╚═╝└─┘└─┘└─┘┴└─┴ ┴ ┴ ' All about security issues. URL: https://www.exploitee.rs/index.php/Western_Digital_MyCloud Blog: https://blog.exploitee.rs/2017/hacking_wd_mycloud/ More: http://gulftech.org/advisories/WDMyCloud%20Multiple%20Vulnerabilities/125 Description: Hacking the Western Digital MyCloud NAS. URL: https://www.myhackerhouse.com/naenara-browser-3-5-exploit-jackrabbit/ Description: Naenara Browser 3.5 exploit (JACKRABBIT). URL: https://squeal.net/bypassing-twitter-account-protection/ Description: Bypassing Twitter's account lockout protection. URL: https://alephsecurity.com/2017/03/08/nexus9-fiq-debugger/ Description: Attacking Nexus 9 with Malicious Headphones. URL: https://pierrekim.github.io/blog/2017-03-08-camera-goahead-0day.html Description: Multiple vulns found in Wireless IP Camera (P2P) WIFICAM cameras. URL: https://pages.nist.gov/mobile-threat-catalogue/ Description: Mobile Threat Catalogue. URL: https://goo.gl/iVOK1o (+) Description: Hijacking Broken Nameservers to Compromise Your Target. URL: https://goo.gl/1Iml0J (+) Description: Siklu EtherHaul Unauthenticated RCE Vulnerability (<7.4.0). URL: https://goo.gl/6t10EZ (+) Description: Privilege Escalation in Amazon Web Services. URL: https://rftap.github.io/blog/2016/09/01/rftap-wifi.html Description: Using RFtap to Detect MAC Spoofing. URL: https://www.toshellandback.com/2017/02/11/psexec/ Description: *Puff* *Puff* PSExec. ' ╔═╗┬ ┬┌┐┌ ' ╠╣ │ ││││ ' ╚ └─┘┘└┘ ' Spare time? URL: http://jamesbvaughan.com/python-twilio-scraping/ Description: Finding Free Food with Python. URL: https://goo.gl/ObQkkZ (+) Description: The selinux-coloring-book. URL: https://thehftguy.com/2017/02/23/docker-in-production-an-update/ Description: Docker in Production - An Update. ' ╔═╗┬─┐┌─┐┌┬┐┬┌┬┐┌─┐ ' ║ ├┬┘├┤ │││ │ └─┐ ' ╚═╝┴└─└─┘─┴┘┴ ┴ └─┘ ' Content Helpers (0x) 52656e61746f20526f64726967756573202d204073696d7073306e202d20687474703a2f2f706174686f6e70726f6a6563742e636f6d http://pathonproject.com/zb/?744541c02fb89360#wsfD19ul8qX6lpO7QLFqR0vxX+Cw09qjBcqR1L1nRWk=