<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Florian Bausch on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/florian-bausch/</link>
    <description>Recent content in Florian Bausch on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 21 May 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/florian-bausch/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Insights into Entra ID’s (Un)Conditional Access</title>
      <link>https://insinuator.net/2026/05/insights-into-entra-ids-unconditional-access/</link>
      <pubDate>Thu, 21 May 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/05/insights-into-entra-ids-unconditional-access/</guid>
      <description>&lt;p&gt;When looking at security measures in Microsoft Entra ID environments, a common&#xA;recommendation is to implement Conditional Access policies.&lt;/p&gt;&#xA;&lt;p&gt;Whether Conditional Access is implemented can be quickly checked, and you can&#xA;put a check mark next to it in your best-practice compliance form. However,&#xA;simply implementing conditional access will not provide much security. A&#xA;phishing attack that we recently analyzed highlights this very well.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Incident Response in GCP: Out of Scope – Out of Mind</title>
      <link>https://insinuator.net/2026/01/incident-response-in-gcp-out-of-scope-out-of-mind/</link>
      <pubDate>Tue, 27 Jan 2026 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2026/01/incident-response-in-gcp-out-of-scope-out-of-mind/</guid>
      <description>&lt;p&gt;We are regularly offering a&#xA;&lt;a href=&#34;https://hm-ts.de/seminare/courses/google-cloud-gcp-incident-response-analysis-2&#34;&gt;GCP Incident Response and Analysis&lt;/a&gt;&#xA;training. In this training, we analyze resources in GCP cloud together with our&#xA;trainees that were successfully compromised by attackers, e.g., GCE instances&#xA;and Cloud Build projects. Therefore, we need tooling that quickly detects&#xA;misconfiguration of resources that helped the attacker during the compromise.&#xA;During the analysis of different tools and different kinds of misconfiguration&#xA;we realized that GCE instance &lt;em&gt;access scopes&lt;/em&gt; are a blind spot of many (in fact&#xA;all that we tested) security audit tools. In this blog post, we want to&#xA;elaborate on the problems that arise from this behavior.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cookie Prefixes – The Lesser Known Cookie Security Feature</title>
      <link>https://insinuator.net/2025/04/cookie-prefixes-the-lesser-known-cookie-security-feature/</link>
      <pubDate>Tue, 08 Apr 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/04/cookie-prefixes-the-lesser-known-cookie-security-feature/</guid>
      <description>&lt;p&gt;When you’re analyzing web applications as a pentester or reading pentest reports&#xA;about web applications, you will often see findings regarding cookies missing&#xA;certain security flags. The &lt;em&gt;Set-Cookie&lt;/em&gt; HTTP header and the JavaScript&#xA;&lt;em&gt;document.cookie&lt;/em&gt; API allow to use, for example, the&#xA;flags &lt;em&gt;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#secure&#34;&gt;Secure&lt;/a&gt;&lt;/em&gt;, &lt;em&gt;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#pathpath-value&#34;&gt;Path&lt;/a&gt;&lt;/em&gt;, and &lt;em&gt;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/Headers/Set-Cookie#domaindomain-value&#34;&gt;Domain&lt;/a&gt;&lt;/em&gt;.&#xA;Common audit and pentest tools will tell you when your web application does not&#xA;or just insecurely implements these cookie flags.&lt;/p&gt;&#xA;&lt;p&gt;However, they do not provide optimal security even when using these flags&#xA;correctly. However, there are mitigations available that partly solve the&#xA;issues.&lt;/p&gt;</description>
    </item>
    <item>
      <title>When Your Edge Browser Syncs Private Data to Your Employer</title>
      <link>https://insinuator.net/2025/02/when-your-edge-browser-syncs-private-data-to-your-employer/</link>
      <pubDate>Fri, 07 Feb 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/02/when-your-edge-browser-syncs-private-data-to-your-employer/</guid>
      <description>&lt;p&gt;Recently, one of our customers contacted us to investigate the extent of some&#xA;unwanted and unexpected behavior regarding browsing data of employees.&lt;/p&gt;&#xA;&lt;p&gt;Employees started contacting IT support because private browser bookmarks,&#xA;private login credentials etc. showed up on their work machines. All affected&#xA;employees stated that they never created these bookmarks on work systems. And&#xA;interestingly, the data seemed to have been collected over quite some time.&lt;/p&gt;&#xA;&lt;p&gt;Our customer wanted to understand how private data ended up in their&#xA;environment. Obviously, private employee data in the enterprise landscape could&#xA;cause some data privacy trouble (GDPR).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking GLS Parcel Tracking</title>
      <link>https://insinuator.net/2024/04/breaking-gls-parcel-tracking/</link>
      <pubDate>Thu, 25 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/breaking-gls-parcel-tracking/</guid>
      <description>&lt;p&gt;Recently, we held a talk at the Winterkongress&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt; of the &lt;em&gt;Digitale Gesellschaft Schweiz&lt;/em&gt; in Winterthur, Switzerland, about our research project on breaking German parcel tracking sites. We could not name all the parcel services for which we identified vulnerabilities respecting disclosure timelines. Today, we describe our findings at GLS, another player in the German parcel market, and the disclosure process of corresponding vulnerabilities.&lt;/p&gt;&#xA;&lt;h1 id=&#34;findings&#34;&gt;Findings&lt;/h1&gt;&#xA;&lt;p&gt;Similar to the vulnerabilities previously disclosed for DHL&lt;sup id=&#34;fnref:2&#34;&gt;&lt;a href=&#34;#fn:2&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;2&lt;/a&gt;&lt;/sup&gt; and DPD&lt;sup id=&#34;fnref:3&#34;&gt;&lt;a href=&#34;#fn:3&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;3&lt;/a&gt;&lt;/sup&gt;, and UPS&lt;sup id=&#34;fnref:4&#34;&gt;&lt;a href=&#34;#fn:4&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;4&lt;/a&gt;&lt;/sup&gt;, we identified that the GLS parcel tracking website discloses the recipient’s geographic area by showing the name of the destination parcel center. Furthermore, the recipient’s ZIP code was used to unlock personal information (including the exact coordinates of the address) and features that influence the parcel delivery process. The website did not implement rate-limiting or other techniques to prevent brute-forcing ZIP codes using the API.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking UPS Parcel Tracking</title>
      <link>https://insinuator.net/2024/04/breaking-ups-parcel-tracking/</link>
      <pubDate>Wed, 10 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/breaking-ups-parcel-tracking/</guid>
      <description>&lt;p&gt;Today, we describe our findings at United Parcel Service of America, Inc. (UPS), another German parcel market player, and the corresponding vulnerabilities’ disclosure process.&lt;/p&gt;&#xA;&lt;h1 id=&#34;findings&#34;&gt;Findings&lt;/h1&gt;&#xA;&lt;p&gt;Only a valid tracking number is needed to get the personal information of a parcel’s receiver, including the sender’s location, the recipient’s name, and the recipient’s location (city and country). It was possible to enumerate numerous tracking numbers during testing by iterating from known ones. Since the last digit of a tracking number is a checksum, it can be calculated. Also, certain businesses have a predefined prefix in their tracking numbers. This schema allows the enumeration of every parcel sent from a particular business.&lt;/p&gt;</description>
    </item>
    <item>
      <title>I know what you ordered last summer @ Winterkongress 2024</title>
      <link>https://insinuator.net/2024/04/i-know-what-you-ordered-last-summer-@-winterkongress-2024/</link>
      <pubDate>Wed, 03 Apr 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/04/i-know-what-you-ordered-last-summer-@-winterkongress-2024/</guid>
      <description>&lt;p&gt;Dennis and I already published blog posts about our research project dealing with vulnerabilities in parcel tracking implementations at &lt;a href=&#34;https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/&#34;&gt;DHL&lt;/a&gt; and &lt;a href=&#34;https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/&#34;&gt;DPD&lt;/a&gt;. At the &lt;a href=&#34;https://cfp.winterkongress.ch/wk24/schedule/&#34;&gt;&lt;em&gt;Winterkongress&lt;/em&gt;&lt;/a&gt; (winter congress) in Winterthur, Switzerland, we had the great opportunity to give a talk about the matter. The talk was recorded and can be watched &lt;a href=&#34;https://media.ccc.de/v/dgwk2024-56194-ich-wei-was-du-letzten-so&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://digitale-gesellschaft.ch&#34;&gt;&lt;em&gt;DigiGes&lt;/em&gt;&lt;/a&gt; held the Winterkongress, which took place in Winterthur on 01.03. till 02.03.2024. The main topics are ethics, threats, and opportunities of IT. This year, many talks looked at AI in some way.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Breaking DPD Parcel Tracking</title>
      <link>https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/</link>
      <pubDate>Tue, 12 Sep 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/</guid>
      <description>&lt;p&gt;This blog post is the continuation of our parcel research. We already reported&#xA;about how we broke parcel tracking at&#xA;&lt;a href=&#34;https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/&#34;&gt;DHL&lt;/a&gt;&#xA;and the disclosure process of the identified problems. As DHL is not the only&#xA;parcel service in Germany, we also investigated the other available parcel&#xA;services. In this blog post, we want to talk about DPD, also called Geopost,&#xA;which belongs to the French Post Office.&lt;/p&gt;&#xA;&lt;h2 id=&#34;efficient-guessing-of-tracking-numbers&#34;&gt;Efficient Guessing of Tracking Numbers&lt;/h2&gt;&#xA;&lt;p&gt;DPD uses the recipient’s ZIP code to unlock detailed shipment information and&#xA;additional options. After trying some ZIP codes manually, we received CAPTCHA&#xA;prompts in the web interface (more on this later).&lt;/p&gt;</description>
    </item>
    <item>
      <title>All your parcel are belong to us – Talk at Troopers 2023</title>
      <link>https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/</link>
      <pubDate>Tue, 11 Jul 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/</guid>
      <description>&lt;p&gt;At Troopers 2023, we gave a talk on how to attack DHL parcel tracking&#xA;information based on OSINT. Since we previously had an exemplary disclosure&#xA;process about this attack with DHL, Mr. Kiehne (from DHL) joined us to provide&#xA;interesting background information and insights on how they addressed our&#xA;findings.&lt;/p&gt;&#xA;&lt;p&gt;We want to thank DHL and especially Mr. Kiehne for sharing those insights with&#xA;us at Troopers 2023. It is the ideal case, but still not common that&#xA;organizations talk openly about their actions and views on a disclosure process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IMF Conference 2023 in Munich</title>
      <link>https://insinuator.net/2023/05/imf-conference-2023-in-munich/</link>
      <pubDate>Thu, 25 May 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/05/imf-conference-2023-in-munich/</guid>
      <description>&lt;p&gt;The IMF Conference is the &lt;em&gt;International Conference on IT Security Incident&#xA;Management &amp;amp; IT Forensics&lt;/em&gt;. This year it took place from May 23 to 24 in Munich.&#xA;The schedule lists&#xA;&lt;a href=&#34;https://imf-conference.org/imf2023/program.html&#34;&gt;a lot of interesting talks&lt;/a&gt;.&#xA;One of the talks was my presentation on a paper about Ceph forensics, based on&#xA;my Master Thesis:&lt;/p&gt;&#xA;&lt;p&gt;The concept of Software Defined Storage (SDS) has become very popular over the&#xA;last few years.  It is used in public, private, and hybrid clouds to store&#xA;enterprise, private, and other kinds of data. &lt;a href=&#34;https://ceph.io/&#34;&gt;Ceph&lt;/a&gt; is an&#xA;open-source software that implements an SDS stack.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analysis of HSTS Caches of Different Browsers</title>
      <link>https://insinuator.net/2021/05/analysis-of-hsts-caches-of-different-browsers/</link>
      <pubDate>Thu, 06 May 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/05/analysis-of-hsts-caches-of-different-browsers/</guid>
      <description>&lt;p&gt;I recently stumbled upon a strange behavior in my Firefox: I visited an&#xA;HTTPS-enabled website that I had visited before and saw that my Firefox&#xA;connected insecurely via HTTP. I found that strange because nowadays, most&#xA;websites set the&#xA;&lt;a href=&#34;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Strict-Transport-Security&#34;&gt;HSTS&lt;/a&gt;&#xA;header, which is supposed to force the browser to connect via HTTPS. I checked&#xA;whether this website set the HSTS header – and it did. This means my Firefox was&#xA;ignoring/forgetting about the HSTS header right after my visit.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Of Corona, Buggy Audio Drivers and Industrial Espionage</title>
      <link>https://insinuator.net/2021/04/of-corona-buggy-audio-drivers-and-industrial-espionage/</link>
      <pubDate>Fri, 23 Apr 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/04/of-corona-buggy-audio-drivers-and-industrial-espionage/</guid>
      <description>&lt;h2 id=&#34;the-situation&#34;&gt;The Situation&lt;/h2&gt;&#xA;&lt;p&gt;Last year, the CISO of a customer sent me a laptop for analysis. The reason was&#xA;that he feared the company could have been victim of industrial espionage.&#xA;Starting in spring 2020, the IT help desk got several employee laptops with full&#xA;hard drives, caused by a huge amount of audio recordings. The audio files&#xA;contained recordings even of highly sensitive telephone conferences. An&#xA;automated scan on all employee computers for such audio recordings showed that&#xA;about 300 devices were affected.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW Whitepaper 71: Analysis of Anti-Virus Software Quarantine Files</title>
      <link>https://insinuator.net/2021/01/ernw-whitepaper-71-analysis-of-anti-virus-software-quarantine-files/</link>
      <pubDate>Wed, 27 Jan 2021 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2021/01/ernw-whitepaper-71-analysis-of-anti-virus-software-quarantine-files/</guid>
      <description>&lt;p&gt;I am glad to announce the release of the ERNW whitepaper 71 containing&#xA;information about quarantine file formats of different AV software vendors. It&#xA;is available&#xA;&lt;a href=&#34;https://static.ernw.de/whitepaper/ERNW-Whitepaper-71_AV_Quarantine_signed.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;h2 id=&#34;anti-virus-software&#34;&gt;Anti-Virus Software&lt;/h2&gt;&#xA;&lt;p&gt;I took quarantine files from real-life incidents and created some in a lab&#xA;environment. Afterwards I tried to identify metadata, like timestamps, path&#xA;names, malware names, and the actual malicious file in the quarantine files. One&#xA;goal was to use this information to support our incident analyses: Using the&#xA;results, we can now easily create timelines showing information about&#xA;quarantined files, extract the detected malware, and sometimes even find&#xA;information about processes that created the malicious files.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
