New Pluralsight Play by Play: What You Need to Know About HTTPS Today

Presently sponsored by: Matchlight by Terbium Labs: Know when your exact data appears on the dark web. Contact us for a demo today.

As many followers know, I run a workshop titled Hack Yourself First where I spend a couple of days with folks running through all sorts of common security issues and, of course, how to fix them. I must have run it 50 times by now so it’s a pretty well-known…

Continue reading New Pluralsight Play by Play: What You Need to Know About HTTPS Today

Encryption is a Double-Edged Sword for the Healthcare Industry

The healthcare industry must take security and privacy seriously.  They collect and retain personal health information (PHI) and financial information while providing life-saving medical care.  The protection of this information and the netw… Continue reading Encryption is a Double-Edged Sword for the Healthcare Industry

Bypassing Browser Security Warnings with Pseudo Password Fields

Presently sponsored by: Worried your social media accounts got hacked? ZeroFOX can teach you how to protect yourself. Learn how.

It seems that there is no limit to human ingenuity when it comes to working around limitations within one’s environment. For example, imagine you genuinely wanted to run a device requiring mains power in the centre of your inflatable pool – you’re flat out of luck, right? Wrong!

Powerboard Floating in Pool

Or imagine…

Continue reading Bypassing Browser Security Warnings with Pseudo Password Fields

The 6-Step “Happy Path” to HTTPS

Presently sponsored by: Build your own mock malware and test your stack. Stackhackr will tell you if your company is vulnerable. Built by Barkly.

It’s finally time: it’s time the pendulum swings further towards the “secure by default” end of the scale than what it ever has before. At least insofar as securing web traffic goes because as of this week’s Chrome 62’s launch, any website with an input box is now…

Continue reading The 6-Step “Happy Path” to HTTPS

A2SV – Auto Scanning SSL Vulnerability Tool For Poodle & Heartbleed

A2SV – Auto Scanning SSL Vulnerability Tool For Poodle & Heartbleed

A2SV is a Python-based SSL Vulnerability focused tool that allows for auto-scanning and detection of the common and well-known SSL Vulnerabilities.

SSL Vulnerabilities Detected by A2SV

  • [CVE-2007-1858] Anonymous Cipher
  • [CVE-2012-4929] CRIME(SPDY)
  • [CVE-2014-0160] CCS Injection
  • [CVE-2014-0224] HeartBleed
  • [CVE-2014-3566] SSLv3 POODLE
  • [CVE-2015-0204] FREAK Attack
  • [CVE-2015-4000] LOGJAM Attack
  • [CVE-2016-0800] SSLv2 DROWN

Planned for future:

  • [PLAN] SSL ACCF
  • [PLAN] SSL Information Analysis

Installation & Requirements for A2SV

A.

Read the rest of A2SV – Auto Scanning SSL Vulnerability Tool For Poodle & Heartbleed now! Only available at Darknet.

Continue reading A2SV – Auto Scanning SSL Vulnerability Tool For Poodle & Heartbleed

2017’s 5 Most Dangerous DDoS Attacks & How to Mitigate Them (Part 1)

Throughout the history of mankind, whether in warfare or crime, the advantage has swung between offense and defense, with new technologies and innovative tactics displacing old doctrines and plans. For example, the defensive advantage of the Greek phalanx was eventually outmaneuvered by the Roman legion. Later, improvements in fortifications and armor led to castles and […]

The post 2017’s 5 Most Dangerous DDoS Attacks & How to Mitigate Them (Part 1) appeared first on Radware Blog.

Continue reading 2017’s 5 Most Dangerous DDoS Attacks & How to Mitigate Them (Part 1)