Serious Netmask vulnerability found to affect three Perl IP modules

"A trio of Perl modules are potentially vulnerable to a serious upstream security flaw in Net::Netmask, a Perl distribution used to parse, manipulate, and lookup IP network blocks. The affected CPAN modules include Net-CIDR-Lite, used to merge IPv4 or IPv6 CIDR addresses; Net-IPAddress-Util, a version-agnostic IP address representation; and Data-Validate-IP, an IPv4 and IPv6 validator..." Full article: https://portswigger.net/daily-swig/serious-netmask-vulnerability-found-to-affect-three-perl-ip-modules

H2C smuggling proves effective against Azure, Cloudflare Access, and more

"Security researchers have harnessed the novel ‘H2C smuggling’ technique to achieve authentication, routing, and WAF bypasses on a number of leading cloud platforms. The attack’s first in-the-wild scalps included routing and WAF bypasses in Microsoft Azure, and an authentication bypass in Cloudflare Access, although Google Cloud Platform emerged unscathed. The technique’s architects, from security firm... Continue Reading →

Isn’t it ironic: Exploiting GDPR laws to gain access to personal data

"A security researcher has detailed how they were able to exploit GDPR laws to leak sensitive personal information from the systems put in place to protect it. Full-time bug bounty hunter Hx01 detailed how they were able to gain access to personally identifiable information (PII) stored by various organizations including Fortune 500 companies. The General Data Protection Regulation (GDPR) was introduced... Continue Reading →

Advanced Automation for Space Missions (1980) – NASA Conference Publication 2255

This publication describes a group of studies aimed at exploring the feasibility of using machine intelligence, including automation and robotics, in future space missions. TABLE OF CONTENTS INTRODUCTION ………………………………………………………….1 TERRESTRIAL APPLICATIONS: AN INTELLIGENT EARTH-SENSING INFORMATION SYSTEM ……..11 SPACE EXPLORATION: THE INTERSTELLAR GOAL AND TITAN DEMONSTRATION …………..39 NONTERRESTRIAL UTILIZATION OF MATERIALS: AUTOMATED SPACE MANUFACTURING FACILITY……………………………………………………………..77 REPLICATING... Continue Reading →

Facebook awards $55k bug bounty for third-party vulnerabilities that could compromise its internal network

"A security researcher has been awarded a $55,000 bug bounty after they chained a pair of vulnerabilities in an unnamed third-party application to achieve server-side request forgery (SSRF) and compromise Facebook’s internal network." Full article: https://portswigger.net/daily-swig/facebook-awards-55k-bug-bounty-for-third-party-vulnerabilities-that-could-compromise-its-internal-network

Blog at WordPress.com.

Up ↑

Design a site like this with WordPress.com
Get started