<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Appliance on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/appliance/</link>
    <description>Recent content in Appliance on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Fri, 01 Apr 2022 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/appliance/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Solving client-side controls once and for all</title>
      <link>https://insinuator.net/2022/04/solving-client-side-controls-once-and-for-all/</link>
      <pubDate>Fri, 01 Apr 2022 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2022/04/solving-client-side-controls-once-and-for-all/</guid>
      <description>&lt;p&gt;Missing server-side validation consistently scores a place in the&#xA;&lt;a href=&#34;https://owasp.org/www-project-top-ten/&#34;&gt;OWASP Top 10&lt;/a&gt;. Browsers nowadays offer&#xA;a lot of ways to easily implement client-side controls, increasing the usability&#xA;by a lot. They automatically detect missing fields or invalid characters in your&#xA;input fields and may even validate user input against a regular expressions.&lt;/p&gt;&#xA;&lt;p&gt;However, these controls should only be considered as usability features. When&#xA;sending data to a back-end system the application must always ensure data&#xA;integrity by implementing encodings, validations and filters. Even for small&#xA;applications this is a painful and tedious process. For each possible input,&#xA;developers together with security experts have to carefully identify the context&#xA;of each field, how the input is going to be used and what data requirements are&#xA;present.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FireEye Security Bug: Connection to physical host and adjacent network possible during analysis in Live-Mode</title>
      <link>https://insinuator.net/2017/09/fireeye-security-bug-connection-to-physical-host-and-adjacent-network-possible-during-analysis-in-live-mode/</link>
      <pubDate>Wed, 13 Sep 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/09/fireeye-security-bug-connection-to-physical-host-and-adjacent-network-possible-during-analysis-in-live-mode/</guid>
      <description>&lt;p&gt;We recently identified a security issue in FireEye AX 5400, that also affected other products. We responsibly disclosed the bug to FireEye and a fix that addresses the issue has been released with version 7.7.7. The fix was also merged into the common core and is available as 8.0.1 for other products (i.e. FireEye EX).&lt;/p&gt;&#xA;&lt;p&gt;The related release notes can be found here:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.fireeye.com/docs/docs_en/AX/sw/7.7.7/RN/AX_RN_7.7.7_en.pdf&#34;&gt;https://docs.fireeye.com/docs/docs_en/AX/sw/7.7.7/RN/AX_RN_7.7.7_en.pdf&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://docs.fireeye.com/docs/docs_en/EX/sw/8.0.1/RN/EX_RN_8.0.1_en.pdf&#34;&gt;https://docs.fireeye.com/docs/docs_en/EX/sw/8.0.1/RN/EX_RN_8.0.1_en.pdf&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;FireEye announced to post a 2017 Q3 notice with credit to us, too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Defending Democracy</title>
      <link>https://insinuator.net/2016/11/defending-democracy/</link>
      <pubDate>Thu, 24 Nov 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/11/defending-democracy/</guid>
      <description>&lt;p&gt;I recently had the pleasure to attend two events organized by the &lt;a href=&#34;https://www.esmt.org/faculty-research/centers-chairs-and-institutes/digital-society-institute-dsi&#34;&gt;Digital Society Institute&lt;/a&gt;, one was a &lt;a href=&#34;https://www.esmt.org/node/26449&#34;&gt;workshop on software vulnerabilities&lt;/a&gt; and one was their annual &lt;a href=&#34;https://www.esmt.org/faculty-research/events/conferences-and-workshops/digital-society-conference-2016-defending&#34;&gt;conference&lt;/a&gt;. For both events I delivered input on the security of security products and their evaluation (slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_CritivalViewOnSecProducts_mluft.pdf&#34;&gt;here&lt;/a&gt;). The DSI did a great job of assembling people from various areas (e.g. industry, academia, politics, and research) so there was a lot of input which is not covered by conferences I usually attend. The workshop I attended also resulted in a short policy recommendation when it comes to the security of security products which can be found &lt;a href=&#34;https://www.esmt.org/sites/default/files/2016_dsi_ipr_vulnerabilities-in-it-security-products.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How ‘security’ black boxes might corrupt your investment</title>
      <link>https://insinuator.net/2016/04/how-security-black-boxes-might-corrupt-your-investment/</link>
      <pubDate>Fri, 29 Apr 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/04/how-security-black-boxes-might-corrupt-your-investment/</guid>
      <description>&lt;p&gt;Usually I’m not the kind of guy who talks about such economic topics. Because I’m an engineer / security researcher who is exclusively concerned with understanding technical problems and if possible, solving them accordingly. My whole education is based on this and contains predominantly technical aspects of information security. This sometimes makes it difficult to understand what the market cares about (and why some products are being developed / exist on the market 😉 ). Nevertheless, a current engagement for one of our customers made me stumble upon such a product.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Bug Hunting for the Man on the Street</title>
      <link>https://insinuator.net/2015/03/bug-hunting-for-the-man-on-the-street/</link>
      <pubDate>Tue, 03 Mar 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/03/bug-hunting-for-the-man-on-the-street/</guid>
      <description>&lt;p&gt;This is a guest post from Vladimir Wolstencroft, to provide some details of his upcoming &lt;a href=&#34;https://www.troopers.de/events/troopers15/499_bug_hunting_for_the_man_on_the_street/&#34;&gt;#TR15 talk&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;What do you get when you combine a security appliance vendor, a bug bounty program, readily available virtualised machines, a lack of understanding of best security practices and broken crypto?&lt;br&gt;&#xA;Ownage, a good story and maybe even that bounty…&lt;/p&gt;&#xA;&lt;p&gt;Focusing on Barracuda’s numerous security appliances, this talk will detail bug hunting methods and the principles used to examine these machines:&lt;br&gt;&#xA;Starting with a black box test and the challenges that this approach poses, to decrypting the firmware, getting system root, bricking the box, fighting the (de)activation methods, getting system root again, DOS’ing the VM host and finally using Barracuda’s own source code to find those vulnerabilities that otherwise would be invisible or impossible to find! There were also some unexpected outcomes that followed…&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
