Information Security Stack Exchange Community Digest

Top new questions this week:

How to receive large files guaranteeing authenticity, integrity and sending time

I need to receive some important documents from another person. It may be important to be able to prove (in justice) which files exactly I received from that person at a specific moment. My first ...

authentication integrity data-transfer  
user avatar asked by alex Score of 8
user avatar answered by Ja1024 Score of 32

What sort of security does Docusign provide?

In the last days I have seen two apparent "breaches" of Docusign's security. Neither are good evidence, but they illustrate the point: Wall Street Millennial's youtube review of Joonko's ...

digital-signature documents  
user avatar asked by User65535 Score of 8
user avatar answered by Ja1024 Score of 13

How safe are my app's keys inside the TPM against other apps trying to impersonate mine?

This is a follow-up of these two questions about using the TPM to store application's keys. While both have great answers, there is a specific aspect I am missing: How safe are the keys inside the TPM ...

encryption windows key-management tpm  
user avatar asked by mist Score of 4
user avatar answered by Ja1024 Score of 2

Can someone with access to the infrastructure of the VPN provider access my or other devices in my local network?

The network of a customer/company/VPN provider is compromised while using VPN Clients, like for example Check Point Endpoint VPN or (Palo Alto Networks) Global Protect and so on. Would it be possible ...

vpn  
user avatar asked by mab Score of 4

What are the risks of disabling issuer URL validation?

According to the OIDC specification: The issuer value returned MUST be identical to the Issuer URL that was used as the prefix to /.well-known/openid-configuration to retrieve the configuration ...

jwt validation kubernetes oidc  
user avatar asked by iamsecb Score of 3
user avatar answered by Ja1024 Score of 3

PCI DSS SAQ A qualification - what counts as a 'found' vulnerability?

This Q pertains to PCI DSS v4.0 SAQ A - previous Q&A only touched on previous versions of PCI. Since 4.0, merchants that accept credit card payment, even if they only iframe or link to their ...

pci-dss cve  
user avatar asked by bukwyrm Score of 3
user avatar answered by Gh0stFish Score of 3

Difference between PS Remoting and Winrs from a detection standpoint

From a detection standpoint, when pivoting inside a network what difference (if any) is there between establishing a remote connection between using Enter-PSSession -ComputerName PC1 vs winrs -r:PC1 ...

detection powershell  
user avatar asked by user2334659 Score of 2
user avatar answered by security_paranoid Score of 0

Greatest hits from previous weeks:

How difficult to crack keepass master password?

How easily could someone crack my keepass .kdbx file if that person steals the file but never obtains the Master Password? Is this a serious threat, or would a brute force attack require massive ...

passwords password-management  
user avatar asked by steampowered Score of 122
user avatar answered by Tom Leek Score of 154

Wordlists on Kali Linux?

I notice that in /usr/share/wordlists in Kali Linux (former Backtrack) there are some lists. Are they used to bruteforce something? Is there specific list for specific kind of attacks?

passwords brute-force kali-linux dictionary  
user avatar asked by Stephenloky Score of 20
user avatar answered by GdD Score of 29

How do I run proper HTTPS on an Internal Network?

This question has been asked several times, I'll link a few: https://superuser.com/questions/791015/https-over-private-network https://stackoverflow.com/questions/616055/https-certificate-for-...

tls dns  
user avatar asked by alficles Score of 168
user avatar answered by Steffen Ullrich Score of 49

Phone Call from weird number

I just got a call from a very weird number. On my phone it displays as "+1 (1) (5 )" and "USA" below. I answered the call and there was 100% silence. Then about 2 seconds later the call ended. Next ...

phone iphone  
user avatar asked by KaareZ Score of 3

How to get rid of ad.doubleclick.net malware?

I can't get rid of ad.doubleclick.net malware from my PC. I am using Firefox and it seems that all links that lead to www.googleadservices.com are redirected to https://ad.doubleclick.net/ddm/*** ...

malware  
user avatar asked by Adam Score of 2
user avatar answered by John Deters Score of 6

Unknown automatically generated email in sent folder

I just noticed a strange email in my sent folder that I did not send. Here is the header information: To: [email protected] From: ********@gmail.com Date: Mon, 10 Jun 2019 06:54:17 ...

phishing gmail  
user avatar asked by connorp Score of 11

How do I test for SQL injection vulnerabilities on a site with input fields?

What methods are available for testing SQL injection vulnerabilities?

sql-injection  
user avatar asked by John S Score of 52

Can you answer these questions?

ARP Spoof: Will it work on public wifi networks as compared to a home network?

I have recently successfully demonstrated a simple ARP spoofing attack on my home network. The setup in my home network, described to the best of my abilities is as follows: Optical network router (...

man-in-the-middle arp-spoofing  
user avatar asked by Jarrett GXZ Score of 1
user avatar answered by Ljm Dullaart Score of 0

How to launch XSS code from an INPUT tag?

I have a website with the following code: <input class="Header--search--form-input" name="search" value="&quot; onfocus=&quot;alert(1)&quot; autofocus=&quot;...

xss javascript html  
user avatar asked by Уканис Алексей Score of 1

Why is presence of SPN on an account causing Kerberos "failed to decrypt" error (KRB_AP_ERR_MODIFIED)

I am in a corporate environment with on-premises AD on the company.com domain. We have an AWS VPC hosting some .Net APIs in IIS - the domain these are in is companycloud.com. These APIs are all on the ...

aws active-directory iis kerberos  
user avatar asked by El Ronnoco Score of 2
You're receiving this message because you subscribed to the Information Security community digest.
Unsubscribe from this community digest       Edit email settings       Leave feedback       Privacy
Stack Overflow

Stack Overflow, 14 Wall Street, 20th Floor, New York, NY 10005

<3