csrf


Bank & Mobile Network Security: For want of a nail...
banking

Bank & Mobile Network Security: For want of a nail...

Ever since publishing a "two factor authentication vs two step verification" article in 2014, I've been waiting for an opportunity to irrefutably demonstrate the difference. Note: This article is very much a "work in progress" as until both exploits are patched, I can't provide any technical information. A quick recap... If you haven't yet read the above article, let's quickly recap on the differences between two-factor authentication & two-step verification. A "factor" falls into o
PwnPhone: Default passwords allow covert surveillance.
snom

PwnPhone: Default passwords allow covert surveillance.

A few weeks ago, I was asked to observe an installation of several wireless access points & VoIP phones, with a view to making recommendations on how best to improve security while maintaining ease of deployment. It didn't take long for several trends to appear; chief amongst which was the use of We'll just use defaults, for now. That password will do, for now. Of course, as soon as the device burst into life, it's on to the next one. At which point, "now" becomes a distant memory, alo
Identity theft & payment fraud?  That's ASDA price.
csrf

Identity theft & payment fraud? That's ASDA price.

Back in March 2014, I contacted ASDA to report several security vulnerabilities and despite a fix promised "in the next few weeks", little appears to have changed. @Stuho1mez All of our sites are secure, I would advise using Chrome. Thanks, Beth — Asda Service Team (@AsdaServiceTeam) January 14, 2016 After 677 days and several tweets along a similar vein, my patience has finally run out. What's the problem? Two of the simplest and most prevalent exploits allow an attacker to quickly &
companies house

Corporate Identity Theft - Perhaps the biggest risk is where you least expect it...

Update(s): 18/Dec/2012 - One SSL bug now fixed (might want to put security testing out to tender next time!) - but still a few to go.  Directory traversal still possible... hint encode/escape or strip, don't add slashes!  Significant improvements have been made to the SSL implementation - now scoring a healthy Grade A @ Qualys SSL Labs.  At least progress is being made...  can't fault them for that. 17/Dec/2012 - WebCheck now uses cookies - but still not secure!  At this point, I'm not sure w