A story about looking at the effectiveness of web application firewalls and finding bypasses for the filter ruleset. www.pentagrid.ch/en/blog/airl... #WAF #OWASP #coreruleset #ergon #airlock
A story about looking at the effectiveness of web application firewalls and finding bypasses for the filter ruleset. www.pentagrid.ch/en/blog/airl... #WAF #OWASP #coreruleset #ergon #airlock
Pentagrid published two #Hackvertor tags for #EAN13 (also Swiss AHV numbers) and #TOTP for #2FA. These tags are available via the Hackvertor Tag Store by @garethheyes.co.uk. Our blog post explains what these tags do and how they can be used. www.pentagrid.ch/en/blog/hack... #pentest #OWASP #Burp
Pentagrid is looking for an IT security analyst (d/f/m) in Buchs SG, Switzerland. www.pentagrid.ch/en/pages/car... #hiring #infosec #pentesting #infosecjob
If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. www.pentagrid.ch/en/blog/doma... #hardening
It happened again. We accidentally broke another #hotel check-in #terminal. This time Mr O'Yolo triggered a problem, crashed the #Ariane Allegro Scenario Player and escaped the #kiosk mode, which enabled access to the Windows Desktop: www.pentagrid.ch/en/blog/aria... #itsecurity #infosec
This is not a late April Fool's joke: After #37C3, we accidentally dumped the keypad codes of almost half of an IBIS hotel's rooms by entering some dashes into a check-in terminal: www.pentagrid.ch/en/blog/ibis... #itsecurity #infosec #ibis #accor #terminal #hotel
#SQLinjection in login dialog of web-based #YABOOK harbour administration allows authentication bypass
www.pentagrid.ch/en/blog/sql-...
#pentest #sailing #hafenverwaltung #imonaboat
Multiple vulnerabilities in Lantronix EDS-MD IoT gateway for medical devices: www.pentagrid.ch/en/blog/mult... #itsecurity #infosec #pentesting #lantronix #iot #medical
โซ Ground control to Major Tom, take the patch and put secure mode on. โซ github.com/pentagridsec... #openstage #openscape #unify
RCE and LPE in a wide range of Mitel Unify #OpenStage and #OpenScape VoIP phones with default config: www.pentagrid.ch/en/blog/rce-... #itsecurity #infosec #pentesting #voip #unify
A few email-related Python libraries do not check server certificates. It is nothing new, but a bit surprisingly in 2023 and not everyone got the memo. www.pentagrid.ch/en/blog/pyth... #itsecurity #infosec #pentesting #python #email #bugbounty
The #Liferay Portal software < 7.4.3.88 respectively < 7.4.3.92 is affected by persistent cross-site-scripting vulnerabilities. www.pentagrid.ch/en/blog/stor... #itsecurity #infosec #pentesting
Hello World!