The FBI recommends using ad blockers
Published:
An interesting note from the FBI.
Published:
An interesting note from the FBI.
Published:
Some diagrams (mostly sequence diagrams) about UMA 2.0.
Published:
An interesting spoofing attack resulting from the interaction between Firefox (or Thunderbird) MIME types handling and file managers.
Published:
A dangerous file type association in Debian which could be used to trigger arbitrary code execution.
Published:
Some sequence diagrams about OAuth 2.x and OpenID Connect.
Published:
Some context and analysis about attacks on in WebDriver implementations.
Published:
Some notes about how TLS v1.3 works. This is a follow-up of the previous episode about TLS v1.2. As before, the goal is to have a high-level overview about how the protocol works, what is the role of the different messages and be able to understand (and debug) a network traffic dump.
Published:
Vulnerabilities in found on the WebDriver endpoints of Selenium Server (Grid).
Published:
A DNS rebinding vulnerability I found in GeckoDriver which could be used to execute arbitrary shell commands. This is bug #1652612 and CVE-2021-4138.
Published:
Some notes about how TLS v1.2 (Transport Layer Security) works. The goal explain what is going on in a network traffic dump, the role of the different TLS extensions, the impact of the different cipher suites on security, etc. It includes several diagrams and many references.
Page 1 of 2 | Previous page | Next page | JSON Feed | Atom Feed