A few email-related Python libraries do not check server certificates. It is nothing new, but a bit surprisingly in 2023 and not everyone got the memo. https://t.co/MUpVKknaTl #itsecurity#infosec#pentesting#python#email#bugbounty
@Abraxus7331 don't know if you saw it, but as we mentioned your research specifically, I thought I'll give you a quick heads up: https://t.co/5y5JsZuT6a
We wrote a tool in Python to create file archives such as zip, tar and cpio that include path traversal attacks: https://t.co/SjLoCzdjoB #itsecurity#infosec#pentesting
We had a look at Liechtenstein's electronic health files and the underlying #Liferay portal software and found some weaknesses in the portal software as well as risks in the IT setup. Full article (in German only): https://t.co/FkJ3XFuSvZ #itsecurity#infosec#eHealth#eGD
For some #Icinga#monitoring, we wrote a small plugin in Python that sends mail via SMTP and checks on another mail server via IMAP if the mail was received. Here is the code: https://t.co/gcgAxYJLVI
Our advisory for Busybox cpio. When extracting cpio archives with BusyBox cpio, the cpio archiving tools may write files outside the destination directory and there is no option to prevent this.
Full advisory: https://t.co/X8quvoJE7C
#itsecurity#infosec#pentesting#Busybox
As they are not responding to emails, we are looking for security contacts at Atos/Unify for #coordinatedDisclosure#responsibledisclosure purposes. Please help finding someone, the 2 week initial response deadline is ticking fast... #vulnerability
@Cocoatech hey cocoatech, I'd like to send a security issue in path finder towards you, unfortunately there is no https://t.co/v0BLDvXfGJ could you please tell me where to send it to?
Our advisory for @ATENconnect's Power Distribution Unit PE8108 is public now. We found multiple vulnerabilities regarding authn and authz. Aten failed to provide a FW update within a 90 days after initial contact.
https://t.co/Kz5BV4HAA2
#itsecurity#infosec#pentesting
@ant0inet@adfichter@MarcelWaldvogel Das ist ok, das kann man schwierig finden wenn man möchte. Man kann auch schwierig finden jeden Shop mit PCI DSS zu regulieren aber als Herausgeber das nicht gebacken zu kriegen. Wir reden hier ja nicht von einem Kühlschrankhersteller der das erste mal lernt was ein Pentest ist.