[FD] DefenseCode Security Advisory: PureVPN Windows Privilege Escalation Vulnerability

2018-02-25 Thread Defense Code
DefenseCode Security Advisory PureVPN Windows Privilege Escalation Vulnerability Advisory ID:DC-2018-02-001 Advisory Title: PureVPN Windows Privilege Escalation Vulnerability Advisory URL: http://www.defensecode.com/advisories.php Software: PureVPN Version:5.19.4.0 and below (

[FD] BSides Denver 2018 CFP is open

2018-02-25 Thread Jeff Pettorino
Greetings! Security BSides in the mile high city, Denver CO, is accepting submissions for speakers and presentations for our 2018 event. Our CFP submission form is online at: https://goo.gl/forms/ZEIlX9qkZDUAYGuw1 We look forward to your submissions and hope you can participate in our community e

Re: [FD] Defense in depth -- the Microsoft way (part 51): Skype's home-grown updater allows escalation of privilege to SYSTEM

2018-02-25 Thread Kevin Beaumont
I did a fresh install of Win7 Home yesterday and can confirm impacted Skype version was offered by Windows Update for install. Kev On Tue, 20 Feb 2018 at 18:31, Stefan Kanthak wrote: > "Jeffrey Walton" wrote: > > > On Fri, Feb 9, 2018 at 1:01 PM, Stefan Kanthak > wrote: > > [ http://seclists.

[FD] [CVE-2018-1000088] Stored XSS vulnerability in Doorkeeper gem v2.1.0 - v4.2.5

2018-02-25 Thread Justin Bull
Hey everyone, A security bulletin for you. Software: - Doorkeeper (https://github.com/doorkeeper-gem/doorkeeper) Description: Doorkeeper is an OAuth 2 provider for Rails written in Ruby. Affected Versions: -- 2.1.0 - 4.2.5 Fixed Versions: --- 4.

Re: [FD] [CVE-2018-1000088] Stored XSS vulnerability in Doorkeeper gem v2.1.0 - v4.2.5

2018-02-25 Thread Justin Bull
On Wed, Feb 21, 2018 at 5:17 PM Justin Bull wrote: > > Solution: > - > Upgrade to Doorkeeper v4.2.6 or later > > Apologies. This fails to account for a non-trivial scenario. Any software using Doorkeeper that has generated its own custom views[0] requires manual work to verify there's no

[FD] Search engine of leaks

2018-02-25 Thread Gustavo Sánchez
I started working with a leaks search engine and although it has some other bug, it is very complete. This search engine works with such sources that it analyzes from: 1) - Github 2) - Pastebin 3) -Robtex 4) - Shodan 5) - Censys 6) - Email Sherlock 7) - Threatcrowd 8) Alienvault 9) - Netcraft 10