Showing posts with label vuln. Show all posts
Showing posts with label vuln. Show all posts

2017/11/10

This is frightening

http://www.aviationtoday.com/2017/11/08/boeing-757-testing-shows-airplanes-vulnerable-hacking-dhs-says/

"""
The cost to change one line of code on a piece of avionics equipment is $1 million, and it takes a year to implement. For Southwest Airlines, whose fleet is based on Boeing’s 737, it would “bankrupt” them if a cyber vulnerability was specific to systems on board 737s, he said, adding that other airlines that fly 737s would also see their earnings hurt. Hickey said newer models of 737s and other aircraft, like Boeing’s 787 and the Airbus Group A350, have been designed with security in mind, but that legacy aircraft, which make up more than 90% of the commercial planes in the sky, don’t have these protections.
"""

Pretty strong argument for security early in the SDLC

2016/10/14

No surprise here

http://thehackernews.com/2016/10/sshowdown-iot-security.html?utm_source=feedburner&utm_medium=feed&utm_campaign=Feed:+TheHackersNews+(The+Hackers+News+-+Security+Blog)&_m=3n.009a.1344.av0aof6ngw.sdi&m=1

2016/06/17

Don't trust scores

http://www.zdnet.com/article/cvss-scores-are-not-enough-for-modern-security/

I remember a talk like this given at black hat, quite a few years ago. This is just now getting to the wider public?

2016/04/06

Another coffin nail

http://thehackernews.com/2016/04/adobe-flash-update.html

2016/03/30

7 ransomware tips

http://www.thinkadvisor.com/2016/03/28/7-ways-ransomware-could-invade-your-firm

Apple FBI war grows

http://www.fastcompany.com/3058424/fbi-is-unlikely-to-tell-apple-how-it-broke-into-that-iphone

2015/08/21

web.com breached

https://threatpost.com/web-com-loses-93000-credit-card-numbers-in-breach/114349

2015/07/30

More car hacks

"Researcher says can hack GM's OnStar app, open vehicle, start engine" - http://www.reuters.com/article/idUSKCN0Q42FI20150730

2015/07/22

In case you loose the garage door opener

http://samy.pl/opensesame/

Wireless car hacking

http://www.wsj.com/articles/hackers-show-they-can-take-control-of-moving-jeep-cherokee-1437522078?mod=trending_now_3

2015/07/16

Flight hackers get miles

United hackers given million free flight miles - http://www.bbc.co.uk/news/technology-33552195

This could be big

http://arstechnica.com/security/2015/07/once-theoretical-crypto-attack-against-https-now-verges-on-practicality/

RC4 is pretty widely used.

2015/07/14

Java 0day

http://www.infosecurity-magazine.com/news/first-java-zero-day-two-years-pawn/

2015/07/09

New Buf in Flash Found

Adobe tackles new Flash threat http://www.bbc.co.uk/news/technology-33442789

2011/08/25

Your Router is out to Get You.....!!!

So I have seen people playing with this for some time, but it looks as if the stakes have been raised a little bit now. 


So for those who don't know:
"UPnP, or universal plug and play, is a handy feature that lets devices on your network self-configure on a network, but it’s also a security hazard. A Trojan horse or virus on a computer inside your network could use UPnP to open a hole in your router’s firewall to let outsiders in."
Home Router Security Tips


Andy Garcia has written up a little tool that can demonstrate this problem. Attackers can redirect your traffic, reconfigure your router, and scan your internal network. .....And this is because the WAN port accepts UPnP commands? WTF! Why can't vendors turn stuff like this off on default, since most people don't use it or really even know what it does.


Ugggh!









Killer Apache Perl Script

almost sounds like a monster movie, and for some of us it could be a real monster soon....

Apache Killer

For any who might be worried, there has been a functional workaround published on the Full Disclosure website.