At Pentagrid, we occasionally review our clients' internal processes to identify IT security risks. When we discovered that large sums of money are transferred with just a few clicks and no transaction verification, we helped securing the process. At the same time, we developed a tool to support this improvement. #itsecurity #infosec #iso200222 #pain001 https://www.pentagrid.ch/en/blog/pain001-interfaces-and-payment-of-your-salary/
Pentagrid AG
Pentagrid performs technically solid IT security assessments.
Posts
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
A story about looking at the effectiveness of web application firewalls and finding bypasses for the filter ruleset. https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/ #WAF #OWASP #coreruleset #ergon #airlock
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Pentagrid published two #Hackvertor tags for #EAN13 (also Swiss AHV numbers) and #TOTP for #2FA. These tags are available via the Hackvertor Tag Store by @garethheyes@bird.makeup. Our blog post explains what these tags do and how they can be used. https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/ #pentest #OWASP
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Pentagrid is looking for an IT security analyst (d/f/m) in Buchs SG, Switzerland. https://www.pentagrid.ch/en/pages/career/ #FediHire #infosec
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Today, our certificate transparency monitoring popped up with an InvalidSignature exception, because we didn't add the recent Let's Encrypt intermediate CAs as monitoring trust anchors. We updated the documentation accordingly, but it is good to see it working. If you want to monitor your certificates, you may run your own instance. https://github.com/pentagridsec/check-transparency-logs
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. https://www.pentagrid.ch/en/blog/domain-verification-bypass-prevention-caa-accounturi/ #hardening
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Our colleague Michael will be speaking about #Unify #OpenScape and #OpenStage #VoIP phones at the #Area41 security conference in Zurich on June 6. If you use these VoIP systems, we recommend coming to the talk.
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
It happened again. We accidentally broke another #hotel check-in #terminal. This time Mr O'Yolo triggered a problem, crashed the #Ariane Allegro Scenario Player and escaped the #kiosk mode, which enabled access to the Windows Desktop: https://www.pentagrid.ch/en/blog/ariane-allegro-hotel-check-in-terminal-kios-escape/ #itsecurity #infosec
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
This is not a late April Fool's joke: After #37C3, we accidentally dumped the keypad codes of almost half of an IBIS hotel's rooms by entering some dashes into a check-in terminal: https://www.pentagrid.ch/en/blog/ibis-hotel-check-in-terminal-keypad-code-leakage/ #itsecurity #infosec #ibis #accor #terminal #hotel
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
#SQLinjection in login dialog of web-based #YABOOK harbour administration allows authentication bypass
https://www.pentagrid.ch/en/blog/sql-injection-in-port-administration-software-yabook/
#pentest #sailing #hafenverwaltung #imonaboat
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Multiple vulnerabilities in Lantronix EDS-MD IoT gateway for medical devices: https://www.pentagrid.ch/en/blog/multiple-vulnerabilties-in-lantronix-eds-md-iot-gateway/ #itsecurity #infosec #pentesting #lantronix #iot #medical
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Multiple vulnerabilities affecting #Atos #Unify IP Devices - the vendor published OBSO-2312-01: https://networks.unify.com/security/advisories/OBSO-2312-01.pdf
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
RCE and LPE in a wide range of Mitel Unify #OpenStage and #OpenScape VoIP phones with default config: https://www.pentagrid.ch/en/blog/rce-and-local-root-in-openstage-and-openscape-phones/ #itsecurity #infosec #pentesting #voip #unify
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Summer is clearly over and silly season, too. We saw neither alligators in the swimming lake nor lions in town, but a a snake curling through the infrastructure. It was a #python. A few email-related Python libraries do not check server certificates. It is nothing new, but still a bit surprising in 2023 and not everyone got the memo.
https://www.pentagrid.ch/en/blog/python-mail-libraries-certificate-verification/
#itsecurity #infosec #pentesting #python #email #bugbounty
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
The #Liferay Portal software < 7.4.3.88 respectively < 7.4.3.92 is affected by persistent cross-site-scripting vulnerabilities. https://www.pentagrid.ch/en/blog/stored-cross-site-scripting-vulnerabilities-in-liferay-portal/ #itsecurity #infosec #pentesting
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
Wir haben ein Werkzeug in Python geschrieben, dass Dateiarchive wie zip, tar und cpio generiert welche Path Traversal Angriffe beinhalten: https://www.pentagrid.ch/de/blog/archive-pwn-tool-release/ #itsicherheit #informationssicherheit #pentesting
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
We wrote a tool in Python to create file archives such as zip, tar and cpio that include path traversal attacks: https://www.pentagrid.ch/en/blog/archive-pwn-tool-release/ #itsecurity #infosec #pentesting
Pentagrid performs technically solid IT security assessments.
Pentagrid performs technically solid IT security assessments.
We analysed the security of a #WindRiver #VxWorks (the operating system running also on NASA's Curiosity mars rover) embedded device and found a critical vulnerability in the #tarExtract function: https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/ #itsecurity #infosec #pentesting #cisa #vxworks