All of the various findings, articles, videos, pictures, and other stuff I dig up on the web. Anything on this site was posted by me. Any opinion expressed here is only my own
Showing posts with label vuln. Show all posts
Showing posts with label vuln. Show all posts
2020/03/10
2017/11/10
This is frightening
http://www.aviationtoday.com/2017/11/08/boeing-757-testing-shows-airplanes-vulnerable-hacking-dhs-says/
"""
The cost to change one line of code on a piece of avionics equipment is $1 million, and it takes a year to implement. For Southwest Airlines, whose fleet is based on Boeing’s 737, it would “bankrupt” them if a cyber vulnerability was specific to systems on board 737s, he said, adding that other airlines that fly 737s would also see their earnings hurt. Hickey said newer models of 737s and other aircraft, like Boeing’s 787 and the Airbus Group A350, have been designed with security in mind, but that legacy aircraft, which make up more than 90% of the commercial planes in the sky, don’t have these protections.
"""
Pretty strong argument for security early in the SDLC
"""
The cost to change one line of code on a piece of avionics equipment is $1 million, and it takes a year to implement. For Southwest Airlines, whose fleet is based on Boeing’s 737, it would “bankrupt” them if a cyber vulnerability was specific to systems on board 737s, he said, adding that other airlines that fly 737s would also see their earnings hurt. Hickey said newer models of 737s and other aircraft, like Boeing’s 787 and the Airbus Group A350, have been designed with security in mind, but that legacy aircraft, which make up more than 90% of the commercial planes in the sky, don’t have these protections.
"""
Pretty strong argument for security early in the SDLC
2016/10/14
No surprise here
http://thehackernews.com/2016/10/sshowdown-iot-security.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed:+TheHackersNews+(The+Hackers+News+-+Security+Blog)&_m=3n.009a.1344.av0aof6ngw.sdi&m=1
2016/06/17
Don't trust scores
http://www.zdnet.com/article/cvss-scores-are-not-enough-for-modern-security/
I remember a talk like this given at black hat, quite a few years ago. This is just now getting to the wider public?
2016/04/06
2016/03/30
Apple FBI war grows
http://www.fastcompany.com/3058424/fbi-is-unlikely-to-tell-apple-how-it-broke-into-that-iphone
2015/08/21
2015/07/30
More car hacks
"Researcher says can hack GM's OnStar app, open vehicle, start engine" - http://www.reuters.com/article/idUSKCN0Q42FI20150730
2015/07/22
Wireless car hacking
http://www.wsj.com/articles/hackers-show-they-can-take-control-of-moving-jeep-cherokee-1437522078?mod=trending_now_3
2015/07/16
Flight hackers get miles
United hackers given million free flight miles - http://www.bbc.co.uk/news/technology-33552195
This could be big
http://arstechnica.com/security/2015/07/once-theoretical-crypto-attack-against-https-now-verges-on-practicality/
RC4 is pretty widely used.
RC4 is pretty widely used.
2015/07/14
2015/07/09
2011/09/01
2011/08/25
Your Router is out to Get You.....!!!
So I have seen people playing with this for some time, but it looks as if the stakes have been raised a little bit now.
So for those who don't know:
"UPnP, or universal plug and play, is a handy feature that lets devices on your network self-configure on a network, but it’s also a security hazard. A Trojan horse or virus on a computer inside your network could use UPnP to open a hole in your router’s firewall to let outsiders in."
Home Router Security Tips
Andy Garcia has written up a little tool that can demonstrate this problem. Attackers can redirect your traffic, reconfigure your router, and scan your internal network. .....And this is because the WAN port accepts UPnP commands? WTF! Why can't vendors turn stuff like this off on default, since most people don't use it or really even know what it does.
Ugggh!
So for those who don't know:
"UPnP, or universal plug and play, is a handy feature that lets devices on your network self-configure on a network, but it’s also a security hazard. A Trojan horse or virus on a computer inside your network could use UPnP to open a hole in your router’s firewall to let outsiders in."
Home Router Security Tips
Andy Garcia has written up a little tool that can demonstrate this problem. Attackers can redirect your traffic, reconfigure your router, and scan your internal network. .....And this is because the WAN port accepts UPnP commands? WTF! Why can't vendors turn stuff like this off on default, since most people don't use it or really even know what it does.
Ugggh!
Killer Apache Perl Script
almost sounds like a monster movie, and for some of us it could be a real monster soon....
Apache Killer
For any who might be worried, there has been a functional workaround published on the Full Disclosure website.
Apache Killer
For any who might be worried, there has been a functional workaround published on the Full Disclosure website.
Subscribe to:
Posts (Atom)