Is it necessary to encrypt an eMMC that’s soldered to the board?

Say you have a machine where the disk (eMMC) is non-removable like the Surface Go. If the UEFI configuration is protected with a long password, USB + network boot is disabled, and your user has a long password: How’d you gain access to the… Continue reading Is it necessary to encrypt an eMMC that’s soldered to the board?

Rsync vulnerabilities allow remote code execution on servers, patch quickly!

Six vulnerabilities have been fixed in the newest versions of Rsync (v3.4.0), two of which could be exploited by a malicious client to achieve arbitrary code execution on a machine with a running Rsync server. “The client requires only anonymous … Continue reading Rsync vulnerabilities allow remote code execution on servers, patch quickly!

Are libc security vulnerabilities in a Python web application actually exploitable in a private cloud environment?

We use a Python web framework and gunicornlibrary on top of Docker to power a web application with a frontend in a private cloud that can be accessed by a private network. Our security tools report many libc vulnerabilities for the Debian-… Continue reading Are libc security vulnerabilities in a Python web application actually exploitable in a private cloud environment?

Is there any software needed to install from Parrot OS for TP-Link UB500 Nano USB bluetooth 5.0?

I am performing experiment on trying to capture Bluetooth traffic from the fitness device to the Mobile App installed on the Phone.
I am using commands like gatttool, hciconfig, hcitool lescan to scan the Bluetooth device.
I am using Parro… Continue reading Is there any software needed to install from Parrot OS for TP-Link UB500 Nano USB bluetooth 5.0?