Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Where Cybercriminals Go To Buy Your Stolen Data
Newest First  |  Oldest First  |  Threaded View
sasa23
50%
50%
sasa23,
User Rank: Apprentice
10/10/2017 | 9:46:04 PM
Re: Offensive Security by the Private Citizen
its so interesting, thanks
amirshk
100%
0%
amirshk,
User Rank: Author
12/16/2016 | 10:44:39 AM
Very interesting
Very interesting review of the marketplace
rayray2016
50%
50%
rayray2016,
User Rank: Apprentice
12/13/2016 | 12:55:28 PM
Twenty Motion
Awesome articles
lorraine89
50%
50%
lorraine89,
User Rank: Ninja
12/7/2016 | 8:05:06 AM
Identity theft
Well this just goes on to show how much of our data be it stored in our systems or browsing online is vulnerable and susceptible to being hacked or mistreated by malicious hands. Therefore it is always important to secure online footprints and privacy and what best way to do that than deploying secure vpn server like PureVPN which provides online encrypted connections. They have some deals going from what I read on my last visit to their website

www.purevpn.com/order
.osiris
50%
50%
.osiris,
User Rank: Apprentice
12/6/2016 | 1:27:29 AM
Re: .osiris
You can also add Armada board. A feaw years ago Crutop forum was very popular amonth the underground webmasters, until theor owner RedEye got prisoned.
RetiredUser
50%
50%
RetiredUser,
User Rank: Ninja
12/4/2016 | 11:30:34 PM
Offensive Security by the Private Citizen
I'm curious after reading this about whether a private citizen can do anything at all to investigate potential stolen data and illegal activities associated with their finances or business.  In the past I'd had the opportunity to build a honeypot which I was excited about since I always wanted to test out some ideas, build a custom Tor, etc.  But then I got lots of feedback from techs that know about these things to not even touch the project.  Once you attach yourself to something that can be used for illegal activities you risk being implicated, especially due to (as noted in the article) the possibility of law enforcement monitoring various networks, websites and file access points.  I'm surprised, in fact, this article doesn't unequivocally state private citizens not associated with law enforcement should not even consider researching these places.  What's the real rule of thumb in this case?


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/13/2020
Omdia Research Launches Page on Dark Reading
Tim Wilson, Editor in Chief, Dark Reading 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-14300
PUBLISHED: 2020-07-13
The docker packages version docker-1.13.1-108.git4ef4b30.el7 as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 (https://access.redhat.com/errata/RHBA-2020:0053) included an incorrect version of runc that was missing multiple bug and security fixes. One of the fixes regressed in th...
CVE-2020-14298
PUBLISHED: 2020-07-13
The version of docker as released for Red Hat Enterprise Linux 7 Extras via RHBA-2020:0053 advisory included an incorrect version of runc missing the fix for CVE-2019-5736, which was previously fixed via RHSA-2019:0304. This issue could allow a malicious or compromised container to compromise the co...
CVE-2020-15050
PUBLISHED: 2020-07-13
An issue was discovered in the Video Extension in Suprema BioStar 2 before 2.8.2. Remote attackers can read arbitrary files from the server via Directory Traversal.
CVE-2020-10987
PUBLISHED: 2020-07-13
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
CVE-2020-10988
PUBLISHED: 2020-07-13
A hard-coded telnet credential in the tenda_login binary of Tenda AC15 AC1900 version 15.03.05.19 allows unauthenticated remote attackers to start a telnetd service on the device.