admin

HTTP request smuggling bug patched in HAProxy

Exploitation of this bug can allow attackers to gain access to backend servers. HAProxy, a widely used open source load balancer and reverse proxy, has addressed a critical vulnerability that permitted attackers to execute HTTP request smuggling attacks. Through the submission of specially crafted HTTP requests, an attacker could potentially sidestep HAProxy’s protective filters, allowing…

Read More

HTTP request smuggling bug patched in HAProxy

Exploitation of this vulnerability could allow attackers to gain access to backend servers. HAProxy, a widely used open-source load balancer and reverse proxy, has released a fix for a vulnerability that could potentially allow attackers to carry out HTTP request smuggling attacks. By sending a carefully crafted HTTP request, attackers could circumvent HAProxy’s filters and…

Read More

‘Most web API flaws are missed by standard security tests’ – Corey J Ball on securing a neglected attack vector

API security presents a valuable entry point into a career in penetration testing, according to an expert in the field. INTERVIEW Securing web APIs requires a specialized approach rather than relying on traditional web application security, as standard tests often overlook prevalent vulnerabilities. This perspective is shared by API security specialist Corey J Ball, who…

Read More

Cisco ClamAV anti-malware scanner vulnerable to serious security flaw

John Leyden 22 February 2023 at 14:23 UTC A patch has been released addressing a significant vulnerability that could endanger several technologies. A security vulnerability in a bundled anti-malware scanning product has created a serious risk for various Cisco products. Specifically, a vulnerability in the ClamAV scanning library (identified as CVE-2023-20032) poses a significant security…

Read More

Chromium bug allowed SameSite cookie bypass on Android devices

Ben Dickson27 February 2023 at 11:50 UTC Recent vulnerabilities have exposed flaws in protections against cross-site request forgery (CSRF). An alarming issue in the Chromium project has been identified, allowing unauthorized users to bypass critical security features designed to protect sensitive cookies on Android devices. The SameSite attribute allows developers to restrict cookie access, thus…

Read More

Deserialized web security roundup: Twitter 2FA backlash, GoDaddy suffers years-long attack campaign, and XSS Hunter adds e2e encryption

Jessica Haworth-Elsayed 24 February 2023 at 13:09 UTC Updated: 27 February 2023 at 15:32 UTC In this bi-weekly summary, we delve into recent vulnerabilities in application security, innovative hacking methodologies, and significant updates from the cybersecurity landscape. Recently, Twitter encountered backlash as its CEO Elon Musk declared that SMS-based two-factor authentication (2FA) will now be…

Read More

Chromium bug allowed SameSite cookie bypass on Android devices

Ben Dickson 27 February 2023 at 11:50 UTC Recent findings reveal vulnerabilities in protections against cross-site request forgery (CSRF), which may be exploited by malicious entities. A critical vulnerability in the Chromium platform might allow attackers to sidestep a vital security feature designed to protect sensitive cookies in Android browsers. The SameSite attribute is implemented…

Read More

Password managers: A rough guide to enterprise secret platforms

The second installment of our series on password managers delves into enterprise-level solutions designed to manage API tokens, login credentials, and much more. Today’s enterprises manage numerous servers, applications, services, APIs, and containers. To protect these assets, they require robust tools to handle sensitive information, including passwords, encryption keys, SSH keys, API tokens, and certificates….

Read More

Indian transport ministry flaws potentially allowed creation of counterfeit driving licenses

Charlie Osborne28 February 2023 at 14:15 UTC Updated: 28 February 2023 at 14:51 UTC A researcher has shown alarming vulnerabilities that allowed access to the personal identifiable information (PII) of approximately 185 million Indian citizens, enabling the creation of counterfeit driving licenses. An important revelation came from student and cybersecurity researcher Robin Justin, who disclosed…

Read More
Back To Top