Category: passwords

Ubiquiti breach, and other IoT security problems
Networking equipment manufacturer Ubiquiti sent out an email to warn users about a possible data breach. The email stated there had been unauthorized [...]
![S3 Ep14: Money scams, HTTPS by default, and hardcoded passwords [Podcast] S3 Ep14: Money scams, HTTPS by default, and hardcoded passwords [Podcast]](https://modernnetsec.io/wp-content/uploads/2021/01/s3-ep14-money-scams-https-by-default-and-hardcoded-passwords-podcast.png)
S3 Ep14: Money scams, HTTPS by default, and hardcoded passwords [Podcast]
by Paul Ducklin We advise you how to react when a friend suddenly asks for money, explain why Chromium is finally aiming for HTTPS by default, and [...]

Depix – Recovers Passwords From Pixelized Screenshots
Depix is a tool for recovering passwords from pixelized screenshots. This implementation works on pixelized images that were created with a lin [...]

Announcement: Availability of AWS Recommendations for the management of AWS root account credentials
When AWS customers open their first account, they assume the responsibility for securely managing access to their root account credentials, under the [...]

Zracker – Zip File Password BruteForcing Utility Tool based on CPU-Power
Zracker is a Zip File Password BruteForcing Utility Tool based on CPU-Power. Yet available for Linux only ... Supports WordList Mode only but w [...]

Lil-Pwny – Auditing Active Directory Passwords Using Multiprocessing In Python
A multiprocessing approach to auditing Active Directory passwords using Python. About Lil PwnyLil Pwny is a Python application to perform an of [...]

PwnedPasswordsChecker – Search (Offline) If Your Password (NTLM Or SHA1 Format) Has Been Leaked (HIBP Passwords List V5)
PwnedPasswordsChecker is a tool that checks if the hash of a known password (in SHA1 or NTLM format) is present in the list of I Have Been Pwne [...]

IIS-Raid – A Native Backdoor Module For Microsoft IIS (Internet Information Services)
IS Raid is a native IIS module that abuses the extendibility of IIS to backdoor the web server and carry out custom actions defined by an attacker. [...]

iOS 14 flags TikTok, 53 other apps spying on iPhone clipboards
by Lisa Vaas
In March, researchers Talal Haj Bakry and Tommy Mysk revealed that Android and iOS apps – including the mind-bogglingly popular, China- [...]

A week in security (June 22 – 28)
Last week on Malwarebytes Labs, we provided a zero-day guide for 2020 featuring recent attacks and advanced preventive techniques, and we learned how [...]