Browser Sessions Trick Can Hack Encrypted Webservers

BlackHat¹ videos are up now… Specifically HEIST video²  – Http Encrypted Information can be Stolen through TCP windows By Tom Van Goethem & Mathy Vanhoef Belgian researchers The technical video about how a browser session can attack a server which attempts to prevent an attack using a token. The aspects of the encryption defense (CSRF token) … Read more

Zmodo camera Has hardcoded Security Flaw

Here is the “moneyquote”: Once it is scanned, you assign a name and connect to the camera.  A very simple and elegant setup solution to get up and running quickly.   Unfortunately for Zmodo and the purchasers of this camera this came out today(was 05/2016– then updated 08/2016): CERT² – Computer Emergency Response Team Vulnerability Note … Read more

Modern Hackers Good-Bad-Both

I have explained some of the description and history of a hacker on Fixvirus.com post¹: I want to refocus on the 3 types of hackers: White, Gray, and Black hat. The White hat hacker is the good guy, the black hat is the bad evil guy, and the grey hat does both good and bad. This  … Read more

Hackers Please Attack Us

What does this Headline mean to you?  From the Talos Intelligence website¹. The text may be a bit hard to read, so here it is: Intel HD Graphics Windows Kernel Driver (igdkmd64) Code Execution Vulnerability Vulnerability: CVE-2016-5647 Summary: A vulnerability exists in the communication functionality of Intel Graphics Kernel Mode Driver. A specially crafted message can cause … Read more

IoT Botnet Can DDoS Your Webserver

Ok it happened as some predicted last year: A botnet was found¹ (a collection of computers or in this case devices that are controlled by another computer) controlling a number of IoT (Internet of Things). These IoT devices were then told to attack a website thus causing a DDoS (Dynamic Denial of Service).  The website … Read more