how2itsec
Pages
(Move to ...)
Home
▼
(Move to ...)
Startseite
▼
Showing posts with label
Vulnerability
.
Show all posts
Showing posts with label
Vulnerability
.
Show all posts
Almost perfect protection for websites and other services - Mutual TLS
›
Its hard to secure your IT services and applications. The list of possible attacks is long, as shown in the Mitre Att&ck framework , the...
Mini/Reverse/Web-Shells explained
›
The website explainshell.com explains Mini/Reverse/ Web-Shells (T1505.003): Example 1: https://explainshell.com/explain?cmd=file%3D%24%2...
FortiGate admin interface authentication bypass
›
There are rumors about a vulnerability in Fortinets FortiGate firewalls where you may bypass authentication on their admin interfaces. Affec...
Paessler PRTG fixes OpenSSL vulnerability CVE-2022-1292
›
Paesslers PRTG version 22.3.79 will update its internal OpenSSL libraries to 1.0.2ze in order to address and fix CVE-2022-1292 . CVE-2022-...
Citrix ICA SSO saved credentials in XOR obfuscated readable storage
›
The Citrix ICA application stores user credentials for its SingleSignOn SSO functionality in readable form using XOR obfuscation with the ke...
Myths of IT Security
›
I recently saw Linus Neumann from the Chaos Computer Club in a video talking about IT security myths which I try to explain all time, howev...
IT-Security newsletter recommendations
›
There are many newsletters, a few of them I can recommend: SANS NewsBites I'd compare it to reading international newspapers, narrowed ...
PRTG Hardening Security CSRF
›
PRTG version 22.1.74 introduces protection from Cross Site Request Forgery (CSRF) attacks to harden the products security. In CSRF the atta...
New log4j 1.x vulnerabilities
›
Apache.org is warning about new log4j vulnerabilities: CVE-2022-23302 CVE-2022-23302 is a high severity deserialization vulnerability in JM...
Detect "log4shell" log4j RCE - CVE-2021-44228
›
The very critical CVE-2021-44228 can be detected by the following methods as Florian Roth has posted them on GitHub: https://gist.github.co...
Apache Shiro Vulnerability RCE CVE-2016-4437 - not detected by Qualys and Tenable
›
Vulnerability-scanning and management is one of the most important topics in IT-security and unfortunately most companies forget or even don...
Zenmap show SSHv2 algorithms/cipher suite
›
Discover the used SSHv2 algorithms/cipher suite using nmap or zenmap can be done using the follwing nse-script and steps: URL: https://nmap....
Windows CVE-2021-34527 PrintNightmare - Useful flowchart
›
@wdormann posted a very useful flowchart regarding Windows CVE-2021-34527 PrintNightmare: https://www.kb.cert.org/vuls/id/383432 Further...
API security - How to start securing APIs
›
APIs are great, they are everywhere and they grow. When thinking about API security very often very basic security mechanisms are missing. T...
How to increase IT security of a company using quick wins
›
How to increase my companys IT security? Of course there are many, many, many topics, processes, systems, parameters, awareness and a lot mo...
FortiOS XSS in DHCP-Monitor
›
Fortinet has released PSIRT FG-IR-19-184 ( CVE-2019-6697 ) about a vulnerability in FortiOS of the FortiGate firewall. A DHCP packet may c...
›
Home
View web version