Jonkman Microblog
  • Login
Show Navigation
  • Public

    • Public
    • Network
    • Groups
    • Popular
    • People

Notices by infosec-handbook.eu (infosechandbook@mastodon.at), page 2

  1. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Sunday, 21-Apr-2019 00:32:56 EDT infosec-handbook.eu infosec-handbook.eu

    HTML5 ping tracking – Firefox :firefox: will enable it by default:

    https://www.bleepingcomputer.com/news/software/mozilla-firefox-to-enable-hyperlink-ping-tracking-by-default/

    – HTML5 ping attributes can be used to track people if they click a link (<a href=… ping=…>) by sending POST requests to an arbitrary amount of hosts
    – tracking is possible without any JavaScript, or Cookies
    – Steve Gibson talked about it in Security Now 709: https://mastodon.at/@infosechandbook/101899819296611698
    – ping is enabled in Chrome, Opera, Edge, Safari by default

    #html5 #ping #tracking #firefox #mozilla

    In conversation Sunday, 21-Apr-2019 00:32:56 EDT from mastodon.at permalink

    Attachments

    1. File without filename could not get a thumbnail source.
      New status by infosechandbook
      By infosec-handbook.eu from mastodon.at
  2. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Sunday, 14-Apr-2019 00:55:21 EDT infosec-handbook.eu infosec-handbook.eu

    Microsoft–compromised MS support agent account used to access e-mail accounts of customers:

    https://techcrunch.com/2019/04/13/microsoft-support-agent-email-hack/

    – Microsoft confirmed that "a limited number of people" had their accounts compromised
    – affected are @msn.com and @hotmail.com accounts; no enterprise customers are affected
    – the breach occurred between January 1 and March 28

    #microsoft #databreach #breach #dataleak #leak #infosec #cybersecurity #security

    In conversation Sunday, 14-Apr-2019 00:55:21 EDT from mastodon.at permalink
  3. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Thursday, 11-Apr-2019 23:46:01 EDT infosec-handbook.eu infosec-handbook.eu

    Matrix.org publishes timeline after security breach:

    https://matrix.org/blog/2019/04/11/security-incident/

    – the attacker exploited vulnerabilities in Jenkins
    – the attacker had full database access, including access to unencrypted content like private messages, passwords hashes, access tokens
    – Matrix.org recommends changing your password (including NickServ password)

    #matrix #breach #infosec #cybersecurity #security

    In conversation Thursday, 11-Apr-2019 23:46:01 EDT from mastodon.at permalink
  4. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Thursday, 04-Apr-2019 23:44:19 EDT infosec-handbook.eu infosec-handbook.eu

    Thousands of D-Link routers have been hacked to redirect their DNS traffic:

    https://www.zdnet.com/article/hacker-group-has-been-hijacking-dns-traffic-on-d-link-routers-for-three-months/

    – nearly 15,000 D-Link routers are affected, mostly DSL-2640B
    – other affected manufacturers are TOTOLINK, and Secutech
    – hacked routers modify the DNS settings of connected devices to redirect victims to malicious websites

    #dlink #totolink #secutech #router #vulnerability #dsl2640b #infosec #cybersecurity #security #dns #dnschanger

    In conversation Thursday, 04-Apr-2019 23:44:19 EDT from mastodon.at permalink
  5. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Friday, 29-Mar-2019 00:52:32 EDT infosec-handbook.eu infosec-handbook.eu
    in reply to

    It seems that ASUS employees uploaded some of their passwords to GitHub:

    https://techcrunch.com/2019/03/27/asus-hacking-risk/

    If true, this may have led to the compromise of their update servers, now known as Operation ShadowHammer:

    https://mastodon.at/@infosechandbook/101815258103125982

    In conversation Friday, 29-Mar-2019 00:52:32 EDT from mastodon.at permalink
  6. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Friday, 29-Mar-2019 00:36:43 EDT infosec-handbook.eu infosec-handbook.eu

    Newly disclosed SQL injection in widespread e-commerce platform Magento:

    https://www.ambionics.io/blog/magento-sqli

    – according to the article, Magento 2.2.x/2.3.x is affected
    – attackers can read anything from the database, including password hashes
    – fixed in Magento 2.3.1 (along with many other vulnerabilities)
    – besides, Magento 2.2.8 and 2.1.17 were released

    #magento #ecommerce #cms #infosec #cybersecurity #security

    In conversation Friday, 29-Mar-2019 00:36:43 EDT from mastodon.at permalink
  7. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 26-Mar-2019 01:19:06 EDT infosec-handbook.eu infosec-handbook.eu

    Compromissed ASUS update servers delivered signed malware to hundreds of thousands of customers in 2018:

    https://motherboard.vice.com/en_us/article/pan9wn/hackers-hijacked-asus-software-updates-to-install-backdoors-on-thousands-of-computers

    – it is a targeted attack since the malware is only active if your device has certain MAC addresses
    – most victims are in Russia, Germany, and France
    – technical details, and affected MAC addresses: https://securelist.com/operation-shadowhammer/89992/

    #asus #supplychain #attack #malware #update #security #infosec #cybersecurity #shadowhammer

    In conversation Tuesday, 26-Mar-2019 01:19:06 EDT from mastodon.at permalink

    Attachments

    1. Operation ShadowHammer
      By GReAT from Securelist - English - Global - securelist.com
      Operation ShadowHammer
  8. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Friday, 22-Mar-2019 01:37:24 EDT infosec-handbook.eu infosec-handbook.eu

    Repos hosted on GitHub and similar platforms often leak crypto secrets and API keys:

    https://www.ndss-symposium.org/wp-content/uploads/2019/02/ndss2019_04B-3_Meli_paper.pdf (PDF file)

    – researchers scanned 13% of public GitHub repos
    – 100,000 repos contained secrets; thousands of new secrets are leaked every day
    – GitHub develops "token scanning" to help removing secrets, however, dedicated scanners like TruffleHog are ineffective according to the paper

    #github #gitlab #token #key #leak #infosec #cybersecurity #security #development #trufflehog

    In conversation Friday, 22-Mar-2019 01:37:24 EDT from mastodon.at permalink
  9. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Wednesday, 13-Mar-2019 00:38:06 EDT infosec-handbook.eu infosec-handbook.eu

    Automatic Certificate Management Environment (ACME) is officially RFC 8555 now:

    https://tools.ietf.org/html/rfc8555

    "This document describes a protocol that a CA and an applicant can use to automate the process of verification and certificate issuance. The protocol also provides facilities for other certificate management functions, such as certificate revocation."

    #acme #certificate #ca #letsencrypt #infosec #cybersecurity #security #https #rfc8555

    In conversation Wednesday, 13-Mar-2019 00:38:06 EDT from mastodon.at permalink
  10. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Thursday, 28-Feb-2019 23:51:33 EST infosec-handbook.eu infosec-handbook.eu

    Wireshark 3.0.0 available:

    https://www.wireshark.org/docs/relnotes/wireshark-3.0.0.html

    – supports about 40 new protocols
    – supports 4 new capture file formats

    #wireshark #pcap #pcapng #packetinspection #pentest #network #infosec #cybersecurity #security

    In conversation Thursday, 28-Feb-2019 23:51:33 EST from mastodon.at permalink
  11. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Saturday, 23-Feb-2019 01:34:59 EST infosec-handbook.eu infosec-handbook.eu

    Popular mobile apps send sensitive personal data to Facebook by using Facebook's SDK to collect this data:

    https://www.cnet.com/news/facebook-receives-personal-info-like-your-heart-rate-from-popular-apps/

    – at least 11 out of 70 popular apps are affected
    – sensitive data includes blood pressure, pregnancy status, menstrual cycles, heartbeat rates, viewed real estate postings etc.
    – some of these apps are "Instant Heart Rate", "Flo Period & Ovulation Tracker", "Realtor.com"
    – also affects users without Facebook accounts

    #facebook #privacy #pii #gdpr

    In conversation Saturday, 23-Feb-2019 01:34:59 EST from mastodon.at permalink
  12. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 19-Feb-2019 13:53:36 EST infosec-handbook.eu infosec-handbook.eu

    WordPress vulnerabilities–path traversal + local file inclusion = remote code execution:

    https://blog.ripstech.com/2019/wordpress-image-remote-code-execution/

    – the vulnerability was there for 6 years
    – fixed in WordPress 4.9.9 and 5.0.1, however, path traversal is still possible under certain circumstances

    #wordpress #vulnerability #cms #infosec #security #cybersecurity #rce

    In conversation Tuesday, 19-Feb-2019 13:53:36 EST from mastodon.at permalink
  13. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Thursday, 07-Feb-2019 22:10:46 EST infosec-handbook.eu infosec-handbook.eu

    Some popular iPhone apps are secretly recording your screen:

    https://www.extremetech.com/mobile/285342-some-popular-iphone-apps-are-secretly-recording-your-screen

    – apps include Air Canada, Hollister, Expedia, Hotels.com
    – these and other apps use a "session replay" feature of Glassbox
    – Glassbox session replays are essentially real-time videos of how you interact with the app

    #ios #glassbox #session #replay #leak #aircanada #hollister #expedia #hotelscom

    In conversation Thursday, 07-Feb-2019 22:10:46 EST from mastodon.at permalink
  14. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Thursday, 07-Feb-2019 00:06:40 EST infosec-handbook.eu infosec-handbook.eu

    Project Fission–Firefox :firefox: will get a "site isolation" feature, similar to Chrome/Chromium:

    https://mystor.github.io/fission-news-1.html

    – no ETA for Project Fission
    – Currently, Firefox comes with one process for the browser's user interface, and a few processes for the Firefox code that renders the websites

    #mozilla #firefox #site #isolation #fission #infosec #webbrowser #cybersecurity #security

    In conversation Thursday, 07-Feb-2019 00:06:40 EST from mastodon.at permalink
  15. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 20-Nov-2018 23:45:44 EST infosec-handbook.eu infosec-handbook.eu

    Do you own a website/blog? There are several online tools to assess security features of it:

    https://infosec-handbook.eu/blog/online-assessment-tools/

    Keep in mind that most security features need client-side support and external scanning covers only a small fraction of web server security:

    https://infosec-handbook.eu/blog/web-security-myths/#m1

    We also provide a web server security series:

    https://infosec-handbook.eu/as-wss/

    (Part 4 coming soon.)

    #websecurity #webserver #server #security #infosec #cybersecurity

    In conversation Tuesday, 20-Nov-2018 23:45:44 EST from mastodon.at permalink
  16. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Sunday, 04-Nov-2018 12:30:04 EST infosec-handbook.eu infosec-handbook.eu

    dank-selfhosted: playbook for self-hosting your own email, web hosting, XMPP chat, and DNS records using OpenBSD

    https://github.com/cullum/dank-selfhosted

    – automated solution for hosting email, web, DNS, XMPP, and ZNC on OpenBSD

    #openbsd #xmpp #dns #email #webhosting #selfhosting #privacy

    In conversation Sunday, 04-Nov-2018 12:30:04 EST from mastodon.at permalink
  17. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Wednesday, 31-Oct-2018 02:39:41 EDT infosec-handbook.eu infosec-handbook.eu

    An opinion on the future of OMEMO:

    http://blogs.fsfe.org/vanitasvitae/2018/09/07/future-of-omemo/

    – some users/developers consider forward secrecy needless
    – OMEMO's trust management sucks
    – OMEMO only protects the message body
    – OMEMO isn't a standard and further development came to a standstill
    – Messaging Layer Security (MLS) is an upcoming attempt to create a new encryption standard

    #omemo #xmpp #mls #infosec #cybersecurity #security

    In conversation Wednesday, 31-Oct-2018 02:39:41 EDT from mastodon.at permalink
  18. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Sunday, 14-Oct-2018 13:26:19 EDT infosec-handbook.eu infosec-handbook.eu

    The Illustrated TLS Connection: Every byte of a TLS 1.2 connection explained and reproduced.

    https://tls.ulfheim.net/

    #tls #https #security #cybersecurity #infosec

    In conversation Sunday, 14-Oct-2018 13:26:19 EDT from mastodon.at permalink
  19. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Sunday, 07-Oct-2018 04:05:59 EDT infosec-handbook.eu infosec-handbook.eu

    Upcoming DNSSEC key rollover – how to check your Turris Omnia's knot resolver:

    – connect to your Turris Omnia using SSH
    – enter '# cat /etc/root.keys | grep "KeyTag:20326"'

    If you see the key, no further action is required. All modern resolvers follow the process defined in RFC 5011 to update their root keys automatically.

    See also:

    https://www.icann.org/dns-resolvers-updating-latest-trust-anchor

    #turris #omnia #knot #dnssec #key #rollover #dns #security #infosec #cybersecurity

    In conversation Sunday, 07-Oct-2018 04:05:59 EDT from mastodon.at permalink
  20. infosec-handbook.eu (infosechandbook@mastodon.at)'s status on Tuesday, 25-Sep-2018 12:43:32 EDT infosec-handbook.eu infosec-handbook.eu

    Ad-blocker uBlock Origin got per-site JavaScript master switch:

    https://github.com/gorhill/uBlock/releases/tag/1.17.0

    #ublockorigin #ublock #adblock #adblocker #javascript #js #privacy

    In conversation Tuesday, 25-Sep-2018 12:43:32 EDT from mastodon.at permalink
  • After
  • Before
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

Jonkman Microblog is a social network, courtesy of SOBAC Microcomputer Services. It runs on GNU social, version 1.2.0-beta5, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All Jonkman Microblog content and data are available under the Creative Commons Attribution 3.0 license.

Switch to desktop site layout.