Learning from previous mistakes – pulling historical vulnerability information from various plugins

If you keep a watch on software security newsletters or blogs like the Wordfence blog, you’ll know there are a good number of new detected defects and vulnerabilities on a regular basis, even on well known plugins and software. It’s worth looking into the details of how this happens especially if you work on PHP software from time to time. Thankfully there are public records which let you compare to look at how these are fixed:

Continue reading “Learning from previous mistakes – pulling historical vulnerability information from various plugins”

de Bruijn sequence, security, and the surprising reason your phone requires pressing enter on the lock screen

de Bruijn sequences (also known as Ouroborean rings in Professor Stewart’s Cabinet of Mathematical Curiosities, p. 44) are an interesting topic that have a surprising connection to moving across a square, and the security of most phone unlock screens. These sequences make a compact listing of all the possible values, in a repeating (cyclical) string of values.

Continue reading “de Bruijn sequence, security, and the surprising reason your phone requires pressing enter on the lock screen”

Analyzing a Zoom(link) hack:

Once in awhile a service may get compromised script or item in it – in a recent case, a Zoom link will actually take you to some random site as part of some sort of adware campaign??? However a closer look shows it is very important to test your links on email or sites:

The link I saw recently actually had a very odd looking script – script in a production service is generally minified sometimes, but won’t be oddly obfuscated or base64-encoded. The suspicious part of this script starts out in the <body> with an odd looking launchBase64:

Continue reading “Analyzing a Zoom(link) hack:”

Back to School and watch out for security and your preinstalled sofware!

This may be a back-to-school like no other in recent history. Kyle Rankin, chief security officer of Purism, has an interesting article about privacy as schools start online this year. While many schools use Google docs or Chromebooks, it is important to use your school account which is legally not allowed to be tracking as much.

(If you do use Google docs for education please also check out Autocorrect remover which makes writing much better for English learners!)

Continue reading “Back to School and watch out for security and your preinstalled sofware!”