I was honoured to have been asked by @SamanthaNiblet4 to share my expertise in cyber security at an All-Party Parliamentary Group (APPG) for Cyber Innovation in the Houses of Parliament yesterday.
https://t.co/YNoZP8T0rj
#Cybersecurity#E2EE#ADP
Introducing HTTP/2 Bomb: a remote DoS in nginx, Apache httpd, Microsoft IIS, Envoy, and Cloudflare Pingora. A single client pins 32GB of server memory in 10s. Found by Codex.
Blog post: https://t.co/WO9MeExoun
PoCs: https://t.co/NpVgEHBHPl
You might think it's just a game, but it's so much more!
Minesweeper was included to teach users how to right-click.
Solitaire was included to get people familiar with drag and drop.
Cardfile was included to familiarize people with MDI applications.
Paint was included for mouse dexterity, range selection, and more advanced mouse use.
Pinball was included just because it was cool.
Credit to @dsobeski for pointing it out!
The number of attacks targeting web applications and APIs has increased significantly and shows no sign of slowing 📈
See what Barracuda CPO Neal Bradbury has to say regarding the reasons why web applications are attractive targets for attackers. https://t.co/UB3pdMZqOQ #AppSec
I wrote this Format dialog back on a rainy Thursday morning at Microsoft in late 1994, I think it was.
We were porting the bajillion lines of code from the Windows95 user interface over to NT, and Format was just one of those areas where WindowsNT was different enough from Windows95 that we had to come up with some custom UI.
I got out a piece of paper and wrote down all the options and choices you could make with respect to formatting a disk, like filesystem, label, cluster size, compression, encryption, and so on.
Then I busted out VC++2.0 and used the Resource Editor to lay out a simple vertical stack of all the choices you had to make, in the approximate order you had to make. It wasn't elegant, but it would do until the elegant UI arrived.
That was some 30 years ago, and the dialog is still my temporary one from that Thursday morning, so be careful about checking in "temporary" solutions!
I also had to decide how much "cluster slack" would be too much, and that wound up constraining the format size of a FAT volume to 32GB. That limit was also an arbitrary choice that morning, and one that has stuck with us as a permanent side effect.
So remember... there are no "temporary" checkins :)
Follow me for more random code musings!
Did you know that denial of service, social engineering, and credential theft were the most prevalent attack vectors in 2023?
Stay informed by reading our new Cybernomics 101 report https://t.co/x8WMQPwS5d #cybercrime
@SeanWrightSec I personally hate the term AI... Why? Because there is no intelligence there, artificial or otherwise... It's all just machine learning at this point.
I have registered for Infosecurity Europe 2023. First time in a few years. Looking forward to catching up with friends and former colleagues l've not seen in person since the pandemic https://t.co/vTqgb0jOPJ
@MentorWebDev I would suggest replacing chapter 10 with "@OWASP Top 10 and Web Application Security" before moving on to "Job"... Although l would hope these things are already being introduced and discussed in the proceeding chapters?
How are you protecting against API security vulnerabilities? https://t.co/mHIByW4FGC Join Barracuda for a look at the state of API security #APISecurity
The recent WhatsApp accounts takeover is simple and genius.
This is how it works:
You're sleeping.
A "hacker" tries to login to your account via WhatsApp.
You get a text message with a pincode that says "Do not share this".
You don't share it, yet you still get hacked.
How?