HackDig : Dig high-quality web security articles

Breaking DPD Parcel Tracking

This blog post is the continuation of our parcel research. We already reported about how we broke parcel tracking at DHL and the disclosure process of the identified problems. As DHL is not the only parcel service in Germany, we also investigated the other available parcel services. In this blog post, we want to talk about DPD, also called Geopost, which bel
Publish At:2023-09-12 16:08 | Read:77432 | Comments:0 | Tags:Misc disclosure DPD Parcels talk

Public companies must now disclose breaches within 4 days

Public organisations in the US impacted by a cyberattack will now have to disclose it within four days…with some caveats attached. On Wednesday, new rules were approved by the US Securities and Exchange Commission (SEC). These rules mean that publicly traded companies will need to reveal said attack details in cases where it had a “material impa
Publish At:2023-08-01 22:05 | Read:352860 | Comments:0 | Tags:Business SEC filing file breach breaches US cyber attack dis

Meta subsidiaries must pay $14m over misleading data collection disclosure

Meta has run into yet another bout of court related issues—two subsidiaries have been ordered to pay $14 million regarding undisclosed data collection. The Australian case, which has rumbled on for the best part of two and a half years, has focused on claims related to a now discontinued Virtual Private Network (VPN). The subsidiary Onavo, acquired in
Publish At:2023-07-31 22:05 | Read:347254 | Comments:0 | Tags:Business VPN meta Facebook data disclosure australia austral

HackerOne insider fired for trying to claim other people’s bounties

The vulnerability disclosure platform HackerOne has revealed that one of their staff members had improperly accessed security reports for personal gain. The—now former—staff member approached HackerOne customers with vulnerabilities that belonged to users of the platform. HackerOne HackerOne acts as a mediator between white hat hackers that find sof
Publish At:2022-07-04 20:00 | Read:881854 | Comments:0 | Tags:Reports bug bounty disclosure HackerOne insider threat rzlr

ManiMed: Ypsomed AG – mylife YpsoPump System Vulnerabilities

Manipulating Medical Devices The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
Publish At:2021-07-29 04:56 | Read:490934 | Comments:0 | Tags:Breaking disclosure medical pentest

ManiMed: Hamilton Medical AG – HAMILTON-T1 Ventilator Vulnerabilities

Manipulating Medical Devices The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
Publish At:2021-02-22 09:04 | Read:555809 | Comments:0 | Tags:Breaking disclosure medical pentest

ManiMed: B. Braun Melsungen AG – Space System Vulnerabilities

Manipulating Medical Devices The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
Publish At:2021-02-15 05:28 | Read:761998 | Comments:0 | Tags:Breaking disclosure medical pentest

ManiMed: Innokas Yhtymä Oy – VC150 Patient Monitor Vulnerabilities

Manipulating Medical Devices The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
Publish At:2021-02-01 03:12 | Read:639187 | Comments:0 | Tags:Breaking disclosure medical pentest

ManiMed: Philips Medizin Systeme Böblingen GmbH – IntelliVue System Vulnerabilities

Manipulating Medical Devices The Federal Office for Information Security (BSI) aims to sensitize manufacturers and the public regarding security risks of networked medical devices in Germany. In response to the often fatal security reports and press releases of networked medical devices, the BSI initiated the project Manipulation of Medical Devices (ManiMed)
Publish At:2021-01-25 06:22 | Read:520160 | Comments:0 | Tags:Breaking disclosure medical pentest

Root Cause Analysis of a Heap-Based Buffer Overflow in GNU Readline

In the last blog post, we discussed how fuzzers determine the uniqueness of a crash. In this blog post, we discuss how we can manually triage a crash and determine the root cause. As an example, we use a heap-based buffer overflow I found in GNU readline 8.1 rc2, which has been fixed in the newest release. We use GDB and rr for time-travel debugging to deter
Publish At:2020-12-17 06:22 | Read:461573 | Comments:0 | Tags:Breaking Misc disclosure fuzzing

VMware NSX-T MITM Vulnerability (CVE-2020-3993)

NSX-T is a Software-Defined-Networking (SDN) solution of VMware which, as its basic functionality, supports spanning logical networks across VMs on distributed ESXi and KVM hypervisors. The central controller of the SDN is the NSX-T Manager Cluster which is responsible for deploying the network configurations to the hypervisor hosts. This summer, I looked in
Publish At:2020-11-26 07:16 | Read:550400 | Comments:0 | Tags:Breaking CVE-2020-3993 disclosure NSX-T VMware vulnerability

Vulnerabilities in GNU Readline Fixed

Recently I discovered some vulnerabilities in GNU Readline. These bugs have been fixed in GNU Readline version 8.1. The case of identifying the vulnerabilities was rather interesting. I wanted to fuzz another program and wrote a quick harness to test if my setup works. This test harness used GNU Readline to read input from stdin and passed the data along to
Publish At:2020-10-07 06:27 | Read:543884 | Comments:0 | Tags:Breaking disclosure fuzzing

Unauthenticated File upload Vulnerability on Synology Sub-domain

In this post, you will learn about how I could find the unauthenticated file upload vulnerability in Synology and, according to Synology’s highest amount for website security bounty. Start Point to be noted, before I found this bug, I had also found a bug in their hardware device, which I’ll release soon. During performing the hardware devi
Publish At:2020-09-30 11:15 | Read:527284 | Comments:0 | Tags:Disclosure Synology Security Synology vulneerability Unauthe

ERNW White Paper 69 – Safety Impact of Vulnerabilities in Insulin Pumps

With this blog post I am pleased to announce the publication of a new ERNW White Paper [1]. The paper is about severe vulnerabilities in an insulin pump we assessed during project ManiMed and we are proud to publish this subset of the results today. Manipulating Medical Devices The German Federal Office for Information Security (BSI), in its role as the Fed
Publish At:2020-09-11 09:06 | Read:491689 | Comments:0 | Tags:Breaking disclosure ERNW white paper medical

Medical Device Security: HL7v2 Injections in Patient Monitors

Digital networking is already widespread in many areas of life. In the healthcare industry, a clear trend towards networked devices is noticeable, so that the number of high-tech medical devices in hospitals is steadily increasing. In this blog post, we want to elucidate a vulnerability we identified during the security assessment of a patient monitor. The d
Publish At:2020-05-03 08:57 | Read:523706 | Comments:0 | Tags:Breaking disclosure medical

Announce

Share high-quality web security related articles with you:)
Tell me why you support me <3

Tag Cloud