<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Florian Grunow on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/authors/florian-grunow/</link>
    <description>Recent content in Florian Grunow on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 02 Sep 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/authors/florian-grunow/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Vulnerability Disclosure: Stealing Emails via Prompt Injections</title>
      <link>https://insinuator.net/2025/09/vulnerability-disclosure-stealing-emails-via-prompt-injections/</link>
      <pubDate>Tue, 02 Sep 2025 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2025/09/vulnerability-disclosure-stealing-emails-via-prompt-injections/</guid>
      <description>&lt;p&gt;With the rise of AI assistance features in an increasing number of products, we&#xA;have begun to focus some of our research efforts on refining our internal&#xA;detection and testing guidelines for LLMs by taking a brief look at the new AI&#xA;integrations we discover.&lt;/p&gt;&#xA;&lt;p&gt;Alongside the rise of applications with LLM integrations, an increasing number&#xA;of customers come to ERNW to specifically assess AI applications. Our colleagues&#xA;&lt;a href=&#34;https://www.linkedin.com/in/fgrunow&#34;&gt;Florian Grunow&lt;/a&gt; and&#xA;&lt;a href=&#34;https://www.linkedin.com/in/hannesmohr/&#34;&gt;Hannes Mohr&lt;/a&gt; analyzed the novel attack&#xA;vectors that emerged and presented the results at&#xA;&lt;a href=&#34;https://troopers.de/troopers24/talks/vnwhm8/&#34;&gt;TROOPERS24&lt;/a&gt; already.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Announcement: Progress / Kemp LoadMaster CVE-2024-7591</title>
      <link>https://insinuator.net/2024/09/announcement-progress-/-kemp-loadmaster-cve-2024-7591/</link>
      <pubDate>Mon, 09 Sep 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/09/announcement-progress-/-kemp-loadmaster-cve-2024-7591/</guid>
      <description>&lt;p&gt;Hey everybody,&lt;/p&gt;&#xA;&lt;p&gt;during a recent Red Teaming engagement Marius Walter from &lt;a href=&#34;https://ernw.de/&#34;&gt;ERNW&lt;/a&gt; found a command injection issue in Progress (Kemp) LoadMaster. It was registered as &lt;a href=&#34;https://www.cve.org/CVERecord?id=CVE-2024-7591&#34;&gt;CVE-2024-7591&lt;/a&gt; and scores a CVSS of 10.0.&lt;/p&gt;&#xA;&lt;p&gt;The vendor already has patches out, make sure to apply them as this is a high severe issue. You can find the official announcement and the patch references on the &lt;a href=&#34;https://support.kemptechnologies.com/hc/en-us/articles/29196371689613-LoadMaster-Security-Vulnerability-CVE-2024-7591&#34;&gt;official support page&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Marius will follow up with a technical blog post on this issue once we think everybody had a realistic chance of applying the patches.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Considerations on AI-Security – Part I: Introduction and Nondeterminism</title>
      <link>https://insinuator.net/2024/02/considerations-on-ai-security-part-i-introduction-and-nondeterminism/</link>
      <pubDate>Tue, 06 Feb 2024 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2024/02/considerations-on-ai-security-part-i-introduction-and-nondeterminism/</guid>
      <description>&lt;p&gt;Hey there!&lt;/p&gt;&#xA;&lt;p&gt;This is the first blog post in a series about issues we think are currently relevant in the field of AI-Security. The intention is not to get full coverage of the topic, but to point out things that seem practical and relevant. We will base some of our statements on lab setups and real-life examples. The technology that we will focus on is chat bots based on generative AI, mainly OpenAI’s ChatGPT. Right now, this specific application of AI in the wild seems to be the best way to demonstrate issues and pitfalls when it comes to IT security.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Student Project - Audit Framework</title>
      <link>https://insinuator.net/2023/10/student-project-audit-framework/</link>
      <pubDate>Fri, 20 Oct 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/10/student-project-audit-framework/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;In 2021, &lt;a href=&#34;https://www.ernw.de&#34;&gt;ERNW&lt;/a&gt; collaborated with&#xA;&lt;a href=&#34;https://www.hs-mannheim.de&#34;&gt;Hochschule Mannheim&lt;/a&gt; for their CEP (Cyber Security&#xA;Entwicklungsprojekt) to build an auditing framework for testing operating system&#xA;configurations against security procedures. This project is part of the&#xA;education program of the university to give the students the chance to utilize&#xA;the knowledge gained throughout the first semesters in a real world project.&#xA;ERNW posed as the fictitious customer, providing a requirements document and&#xA;regular meetings with all project groups for feedback. We planned to process and&#xA;adapt the results for an open source auditing framework. Unfortunately, we were&#xA;not able to finish this project yet, but we think the students should get some&#xA;attention for their work independent from our side. So here is a short summary&#xA;of what the students created and the corresponding repositories.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hilarious Buffer Overflow  Mitigation and TCL Injection in CheckPoint Gaia Portal</title>
      <link>https://insinuator.net/2022/12/hilarious-buffer-overflow-mitigation-and-tcl-injection-in-checkpoint-gaia-portal/</link>
      <pubDate>Fri, 16 Dec 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/12/hilarious-buffer-overflow-mitigation-and-tcl-injection-in-checkpoint-gaia-portal/</guid>
      <description>&lt;p&gt;Hey there,&lt;/p&gt;&#xA;&lt;p&gt;I am going to disclose two bug classes I found a while ago in CheckPoint R77.30:&#xA;Two buffer overflows in the username (no shit) and HTTP method of a request to&#xA;the administrative UI pre-auth and some interesting injections into the TCL web&#xA;interface.&lt;/p&gt;&#xA;&lt;p&gt;Let’s start with the TCL part. The web interface reacted pretty weird when a&#xA;payload contained a colon. Diving deeper into this it became clear that a colon&#xA;would actually cause an error from the TCL interpreter. By going down this&#xA;rabbit hole and learning some TCL (:D) you could see that injecting a colon&#xA;breaks some part of the application code, probably because colons are control&#xA;characters in TCL e.g. preceding a global variable in TCL (::MyVar) or&#xA;separating namespaces.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Plume Twitter Client URL Spoofing</title>
      <link>https://insinuator.net/2018/11/plume-twitter-client-url-spoofing/</link>
      <pubDate>Fri, 23 Nov 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/11/plume-twitter-client-url-spoofing/</guid>
      <description>&lt;p&gt;It is possible to spoof the URLs that Plume will open to arbitrary locations because of how Plume parses URLs. The preview of an URL in a tweet will show the complete (at least the host name and the first few chars of the URL) but shortened URL. However, if the URL contains a semicolon (;) the URL that will be opened is the part after the semicolon.&lt;/p&gt;&#xA;&lt;p&gt;An attacker can make use of this behavior by specifying a URL like the following in a Tweet or direct message:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Security of Busch-Jaeger IP Gateway</title>
      <link>https://insinuator.net/2018/05/security-of-busch-jaeger-ip-gateway/</link>
      <pubDate>Wed, 16 May 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/05/security-of-busch-jaeger-ip-gateway/</guid>
      <description>&lt;p&gt;IoT is everywhere right now and there are a lot of products out there. I have been looking at an IP Gateway lately and found some serious issues. The &lt;a href=&#34;https://www.busch-jaeger.de/en/products/systems/door-communication/abb-welcome-ip-gateway-app-and-myabb-livingspace/&#34;&gt;Busch-Welcome IP-Gateway from Busch-Jaeger&lt;/a&gt; is one of the devices that bridges the gap between sensors and actors in your smart home and the network/Internet. It enables the communication to a door control system that implements various smart home functions. The device itself is offering an HTTP service to configure it, which is protected by a username and password. Some folks even actually expose the device and its login to the Internet. I tried to configure one of these lately and stumbled upon some security issues that I would like to discuss in this blog post.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Squirrelmail Full Disclosure – TROOPERS18</title>
      <link>https://insinuator.net/2018/03/squirrelmail-full-disclosure-troopers18/</link>
      <pubDate>Thu, 15 Mar 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/03/squirrelmail-full-disclosure-troopers18/</guid>
      <description>&lt;p&gt;Birk an me basically fully disclosed a 0day in &lt;a href=&#34;http://squirrelmail.org/&#34;&gt;Squirrelmail&lt;/a&gt; yesterday. This is a short Q&amp;amp;A to answer the most common questions about the issue to calm you all down a little bit. 😉&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;What is the punchline, what do I need to know?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;An attacker able to exploit this vulnerability can extract files of the server the application is running on. This may include configuration files, log files and additionally all files that are readable for all users on the system. This issue is post-authentication. That means an attacker would need valid credentials for the application to log in or needs to exploit an additional vulnerability of which we are not aware of at this point of time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>HITCON CMT 2017</title>
      <link>https://insinuator.net/2017/09/hitcon-cmt-2017/</link>
      <pubDate>Thu, 28 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/hitcon-cmt-2017/</guid>
      <description>&lt;p&gt;Some of our Troopers had the chance to visit HITCON conference in Taiwan this year. There are two main events: HITCON Pacific, which is aimed more at corporate attendees and HITCON CMT, the community edition, which aims at students and the general Infosec community. HITCON is the biggest security conference in Taiwan.&lt;/p&gt;&#xA;&lt;p&gt;The venue for the event is the Academia Sinica, one of the most important academic institution in the Republic of China and was founded in 1928 to promote and undertake scholarly research in sciences and humanities. The conference had three usual tracks and one special track that was free to use for the public for demos, presentations and discussions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Woolim – Lifting the Fog on DPRK’s Latest Tablet PC</title>
      <link>https://insinuator.net/2016/12/woolim-lifting-the-fog-on-dprks-latest-tablet-pc/</link>
      <pubDate>Wed, 28 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/woolim-lifting-the-fog-on-dprks-latest-tablet-pc/</guid>
      <description>&lt;p&gt;Niklaus, Manuel and me had a great time speaking about one of the latest Tablet PCs from DPRK at &lt;a href=&#34;https://fahrplan.events.ccc.de/congress/2016/Fahrplan/events/8143.html&#34;&gt;33C3 this year&lt;/a&gt;. Our work on &lt;a href=&#34;https://insinuator.net/2015/07/redstar-os-watermarking/&#34;&gt;RedStar OS from last year&lt;/a&gt; revealed a nasty watermarking mechanism that can be used to track the origin and distribution path of media files in North Korea. We have seen some interesting dead code in some of RedStar’s binaries that indicated a more sophisticated mechanism to control the distribution of media files. We got hands on a Tablet PC called “Ul-lim” that implemented this advanced control mechanism.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MRMCD16 – diagnosis:critical</title>
      <link>https://insinuator.net/2016/09/mrmcd16-diagnosiscritical/</link>
      <pubDate>Sat, 03 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/mrmcd16-diagnosiscritical/</guid>
      <description>&lt;p&gt;This year’s &lt;a href=&#34;https://2016.mrmcd.net/en/&#34;&gt;MRMCD16&lt;/a&gt; had a topic that immediately let me submit a talk about medical device security: “diagnosis:critical”. Or to quote the official website:&lt;/p&gt;&#xA;&lt;p&gt;Security issues in soft- and hardware have a low chance of healing, especially in medical IT.&lt;/p&gt;&#xA;&lt;p&gt;Despite years of therapy using code reviews and programming guidelines, we still face huge amounts of vulnerable software that probably is in need of palliative treatment.&lt;/p&gt;&#xA;&lt;p&gt;Security vulnerabilities caused by the invasion of IT in the medical sector are becoming real threats. From insulin pumps over analgesic pumps through to pace makers, more and more medical devices have been hacked already. This year&amp;rsquo;s motto &amp;ldquo;mrmcd2016 - diagnosis:critical&amp;rdquo; stands summarizing for the current state of the whole IT sector.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DPRK’s RedStar OS on 32c3</title>
      <link>https://insinuator.net/2015/12/dprks-redstar-os-on-32c3/</link>
      <pubDate>Wed, 30 Dec 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/12/dprks-redstar-os-on-32c3/</guid>
      <description>&lt;p&gt;Niklaus and me had the chance to talk about our research on RedStar OS on the 32nd Chaos Communication Congress in Hamburg this year. You can see the talk online at &lt;a href=&#34;https://media.ccc.de/v/32c3-7174-lifting_the_fog_on_red_star_os#video&#34;&gt;media.ccc.de&lt;/a&gt; or on &lt;a href=&#34;https://www.youtube.com/watch?v=KTBemKiSgWI&#34;&gt;Youtube&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;We talked about the details of the watermarking mechanism that &lt;a href=&#34;https://www.insinuator.net/2015/07/redstar-os-watermarking/&#34;&gt;we found in July&lt;/a&gt; and additional features of RedStar OS like it’s “Virus Scanner” and the system architecture. During the days after our talk we were able to find watermarks applied by RedStar OS in the wild on some sites on the Internet. We can confirm at least 7 different instances of RedStar OS that have applied watermarks to JPGs. Cleaning up the data is work in progress and we will get back to you with the results! Niklaus has put our presentation and additional resources in the &lt;a href=&#34;https://github.com/takeshixx/redstar-tools&#34;&gt;git&lt;/a&gt;. Feel free to join us in our research and make the world a safer place!&lt;/p&gt;</description>
    </item>
    <item>
      <title>“We have a Code Blue right here!”</title>
      <link>https://insinuator.net/2015/11/we-have-a-code-blue-right-here/</link>
      <pubDate>Wed, 04 Nov 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/11/we-have-a-code-blue-right-here/</guid>
      <description>&lt;p&gt;That was the opener for my presentation on the Security in Medical Devices at &lt;a href=&#34;http://codeblue.jp/2015/en/&#34;&gt;CodeBlue 2015&lt;/a&gt; last week in Tokyo, Japan. A &lt;a href=&#34;https://en.wikipedia.org/wiki/Hospital_emergency_codes#Code_Blue&#34;&gt;Code Blue&lt;/a&gt; often describes a patient in a critical condition, mostly needing resuscitation. That just seemed to be a perfect match, also in the sense that the condition of some medical devices out there are still pretty critical concerning security. If you follow our current research on this you know what I am talking about. I hope that we are not talking about this topic anymore three years from now. That would mean that we have made the world a safer place, although it took some time … 😉&lt;/p&gt;</description>
    </item>
    <item>
      <title>RedStar OS Watermarking</title>
      <link>https://insinuator.net/2015/07/redstar-os-watermarking/</link>
      <pubDate>Thu, 16 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/redstar-os-watermarking/</guid>
      <description>&lt;p&gt;During the last few months information about one of North Koreas operating systems was leaked. It is a Linux based OS that tries to simulate the look and feel of a Mac. Some of it’s features have already been discussed on &lt;a href=&#34;https://www.northkoreatech.org/2014/12/30/red-star-3-0-desktop-finally-becomes-public/&#34; title=&#34;rs desktop&#34;&gt;various&lt;/a&gt; &lt;a href=&#34;https://www.northkoreatech.org/2014/01/31/north-koreas-red-star-os-goes-mac/&#34; title=&#34;rs mac&#34;&gt;blog&lt;/a&gt; &lt;a href=&#34;http://www.openingupnorthkorea.com/downloads-2&#34; title=&#34;rs download&#34;&gt;posts&lt;/a&gt; and news &lt;a href=&#34;http://www.golem.de/news/red-star-ausprobiert-das-linux-aus-nordkorea-1501-111443-3.html&#34; title=&#34;golem rs&#34;&gt;articles&lt;/a&gt;. We thought we would take a short look at the OS. This blog post contains some of the results.&lt;/p&gt;&#xA;&lt;p&gt;As you can imagine, most interesting for us was to investigate features that impact the privacy of the users. There are some &lt;a href=&#34;http://www.openwall.com/lists/oss-security/2015/01/09/1&#34; title=&#34;sec vuln rs&#34;&gt;publications concerning the security&lt;/a&gt; of the OS, this is an aspect that we will not cover in this post. We will stick to a privacy issue that we identified in this post. As ERNW has a long history of “Making the World a Safer Place”, we consider this topic an important one. The privacy of potential users (especially from North Korea) may be impacted and therefore we think that the results must be made available for the public. So, here we go …&lt;/p&gt;</description>
    </item>
    <item>
      <title>The patient’s last words: I am not a target!</title>
      <link>https://insinuator.net/2015/07/the-patients-last-words-i-am-not-a-target/</link>
      <pubDate>Wed, 01 Jul 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/07/the-patients-last-words-i-am-not-a-target/</guid>
      <description>&lt;p&gt;Last week I gave a short interview for Süddeutsche Zeitung on the security of medical devices. You can find it &lt;a href=&#34;http://www.sueddeutsche.de/wirtschaft/medizintechnik-naechtliches-desaster-1.2534424&#34;&gt;here&lt;/a&gt;. Unfortunately it is in German so I decided to sum up some of my key points that made it into the article and some that didn’t in this blog post.&lt;/p&gt;&#xA;&lt;p&gt;The medical devices that we have been looking into include patient monitors, syringe pumps, EEGs, home monitoring devices and an MRI. All of these devices had major flaws that look like they came straight out of the 90s. Sometimes, we were able to crash the machines by simply doing a port scan, sometimes we could get around access controls protecting PIN codes of devices, and in most cases we were able to render the machine unusable. All these attacks were performed over the network and no physical access to the device was needed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Scal(e)ing down Privacy</title>
      <link>https://insinuator.net/2014/11/scaleing-down-privacy/</link>
      <pubDate>Sat, 22 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/scaleing-down-privacy/</guid>
      <description>&lt;p&gt;As you might know we are continuously doing &lt;a href=&#34;http://www.insinuator.net/2013/11/medical-device-security/&#34; title=&#34;Medical Devices&#34;&gt;research on medical devices&lt;/a&gt;. I presented some of the new results at &lt;a href=&#34;http://www.powerofcommunity.net/index.html&#34; title=&#34;Power of Community 2014&#34;&gt;Power of Community 2014&lt;/a&gt; last week and we thought we would share some of the details with you here. The focus of the previous work was testing medical devices that are used in hospitals like patient monitors, syringe pumps or even MRIs. This time we looked at a device that every user can use at home and which is available to anyone on the market: A smart scale.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Power of Community 2014</title>
      <link>https://insinuator.net/2014/11/power-of-community-2014/</link>
      <pubDate>Thu, 13 Nov 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/11/power-of-community-2014/</guid>
      <description>&lt;p&gt;I had the pleasure to participate in this year’s &lt;a href=&#34;http://www.powerofcommunity.net/index.html&#34; title=&#34;Power of Community 2014&#34;&gt;Power of Community&lt;/a&gt; and was invited to talk about the insecurity of medical devices. The conference is based in Seoul, Korea and started in 2006. It has a strong technical focus and it is a community driven event. For me it was great to participate as mostly hackers from Asia were there and I got the chance to talk to a lot of nice folks that I wouldn’t be able to meet otherwise. This is especially true for the host, vangelis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>XSS in SAP Netweaver</title>
      <link>https://insinuator.net/2014/01/xss-in-sap-netweaver/</link>
      <pubDate>Fri, 24 Jan 2014 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2014/01/xss-in-sap-netweaver/</guid>
      <description>&lt;p&gt;We just got &lt;a href=&#34;http://scn.sap.com/docs/DOC-8218&#34; title=&#34;Acknowledgments to Security Researchers&#34;&gt;credits&lt;/a&gt; for a flaw we found in SAP Netweaver. The issue is a reflected &lt;a href=&#34;https://www.owasp.org/index.php/Top_10_2013-A3-Cross-Site_Scripting_%28XSS%29&#34; title=&#34;OWASP Top 10 - XSS&#34;&gt;Cross-Site Scripting&lt;/a&gt; (XSS). It can be triggered in the administrative interface for the Internet Communication Manager (ICM) and Web Dispatcher. This means that the targets for this XSS will definitely be users with administrative privileges. This makes it especially juicy for an attacker.&lt;/p&gt;&#xA;&lt;p&gt;SAP rated the vulnerability with CVSS and a Base Score of 4.3 having a Base Vector of &lt;code&gt;AV:N/AC:M/AU:N/C:N/I:P/A:N&lt;/code&gt;. Which again opens the discussion on how to rate the impact of XSS by using CVSS. CVSS &lt;a href=&#34;http://www.first.org/cvss/cvss-guide#i3.1.1&#34; title=&#34;CVSS rating XSS&#34;&gt;states&lt;/a&gt; that XSS “&lt;em&gt;should be scored with no impact to confidentiality or availability, and partial impact to integrity&lt;/em&gt;“, which is clearly arguable. Especially when thinking of the impact on confidentiality. As you might know by now, we tried to tackle the problem of rating vulnerabilities ourselves with the &lt;a href=&#34;http://www.insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/&#34; title=&#34;ERRS&#34;&gt;ERNW Rapid Rating System&lt;/a&gt; (ERRS) and it was not an easy task. 😉 However, SAP states that this is a correction with high priority, so you should apply the patches as soon as possible.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Medical Device Security</title>
      <link>https://insinuator.net/2013/11/medical-device-security/</link>
      <pubDate>Thu, 21 Nov 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/11/medical-device-security/</guid>
      <description>&lt;p&gt;One of our guiding principles at ERNW is “Make the World a Safer Place”. There could not be a topic that matches this principle more than the security or insecurity of medical devices. This is why we started a research project that is looking at how vulnerable those devices are that might be deployed in hospitals around the world. Recently the U.S. Food and Drug Administration (FDA) has put out a &lt;a href=&#34;http://www.fda.gov/medicaldevices/safety/alertsandnotices/ucm356423.htm&#34; title=&#34;FDA recommendation&#34;&gt;recommendation&lt;/a&gt; concerning the security of medical devices. It recommends that “manufacturers and health care facilities take steps to assure that appropriate safeguards are in place to reduce the risk of failure due to cyberattack, which could be initiated by the introduction of malware into the medical equipment or unauthorized access to configuration settings in medical devices and hospital networks”. We thought that we should take a look at how manufacturers deal with security for these devices.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ISSE 2013 – ERNW Rapid Rating System</title>
      <link>https://insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/</link>
      <pubDate>Mon, 28 Oct 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/10/isse-2013-ernw-rapid-rating-system/</guid>
      <description>&lt;p&gt;Michael Thumann and me had the chance to give a talk at this year’s &lt;a href=&#34;http://www.isse.eu.com/&#34; title=&#34;ISSE&#34;&gt;ISSE&lt;/a&gt; conference in Brussels, Belgium. ISSE was founded in 1999 as an initiative of the European Commission Directorate General Information Society. The con had a focus on eGovernment, electronic business processes and the corresponding security issues.&lt;/p&gt;&#xA;&lt;p&gt;We talked about the ERRS, the &lt;a href=&#34;https://www.troopers.de/archives/troopers13/agenda13/troopers13-presentations/&#34; title=&#34;here&#34;&gt;ERNW Rapid Rating System&lt;/a&gt;, that can be used to perform a vulnerability rating for findings that result from different kinds of sources. Audits and Pentests will find a vast amount of vulnerabilities in the infrastructure. To deal with these vulnerabilities, you have to use some kind of prioritization in order to use resources effectively. We tried to adopt the strengths from metrics like CVSS and developed our own set of parameters to calculate the metric, focussing on the relevant customer questions concerning vulnerabilities from all kinds of sources.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DayCon VII</title>
      <link>https://insinuator.net/2013/09/daycon-vii/</link>
      <pubDate>Thu, 26 Sep 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/09/daycon-vii/</guid>
      <description>&lt;p&gt;Some of us had the pleasure to participate in this year’s &lt;a href=&#34;http://www.day-con.org&#34;&gt;Daycon VII&lt;/a&gt;, three days of Real Hacking and Relevant Content, in Dayton, OH. The event began on September 16th with the Packetwars bootcamp. We had the chance to teach some really promising young students and to prepare them for the Packetwars battle that was scheduled four days later. The students had to go through topics like Windows security, network security and web application security both practical and in theory.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SLES 11 Hardening Guide</title>
      <link>https://insinuator.net/2013/08/sles-11-hardening-guide/</link>
      <pubDate>Thu, 15 Aug 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/08/sles-11-hardening-guide/</guid>
      <description>&lt;p&gt;SUSE Linux Enterprise Server (SLES) has been around since 2000. As it is designed to be used in an enterprise environment the security of these systems must be kept at a high level. SLES implements a lot of basic security measures that are common in most Linux systems, but are these enough to protect your business? We think that with a little effort you can raise the security of your SLES installation a lot.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of Talks Held at HITB 2013 – Day 1</title>
      <link>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-1/</link>
      <pubDate>Wed, 17 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-1/</guid>
      <description>&lt;p&gt;This is a short summary of some selected talks from the first day of this year’s &lt;a href=&#34;http://conference.hackinthebox.org/hitbsecconf2013ams/&#34; title=&#34;Hack In The Box&#34;&gt;Hack in the Box&lt;/a&gt; conference in Amsterdam.&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Abusing Twitter’s API and OAuth Implementation by Nicolas Seriot&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Nicolas Seriot (&lt;a href=&#34;https://twitter.com/nst021&#34;&gt;https://twitter.com/nst021&lt;/a&gt;) is an iOS Cocoa developer with an interest in privacy and security. He is currently a mobile applications developer and project manager in Switzerland. Nicolas focused his talk on the extraction of consumer tokens that are needed for OAuth to authenticate a consumer to a service provider. These tokens can then be used by rogue applications to gain access to a victims twitter account.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Summary of Talks Held at HITB 2013 – Day 2</title>
      <link>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-2/</link>
      <pubDate>Wed, 17 Apr 2013 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2013/04/summary-of-talks-held-at-hitb-2013-day-2/</guid>
      <description>&lt;p&gt;This is a short summary of some selected talks from the second day of this year’s Hack in the Box conference in Amsterdam.&lt;/p&gt;&#xA;&lt;p&gt; &lt;br&gt;&#xA;&lt;strong&gt;Rethinking the Front Lines by Bob Lord&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Bob Lord is currently the Director of Information Security at Twitter. He has worked at numerous companies in the area of security and software engineering.&lt;/p&gt;&#xA;&lt;p&gt;In his keynote for the second day of HITB13AMS he tackled a topic that has raised a lot of discussions in the past months. His talk was a summary of what twitter does internally to ensure the security of the company and a plea to implement so called security awareness trainings for employees in a sustainable way.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
