home.social

#secconsult — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #secconsult, aggregated by home.social.

  1. After having been informed by @mathieui that #Exim is also affected, I compiled a list of what #SECConsult documented and what has been found out in the meantime. SEC Consult documented 11 mail systems (software and/or providers; many with millions of accounts) vulnerable to some form of #SMTPSmuggling. But they only informed 3. With #Exim also vulnerable (apparently presumed "clean" by SEC Consult), the list is now 12.
    netfuture.ch/2023/12/smtp-smug

  2. After having been informed by @mathieui that #Exim is also affected, I compiled a list of what #SECConsult documented and what has been found out in the meantime. SEC Consult documented 11 mail systems (software and/or providers; many with millions of accounts) vulnerable to some form of #SMTPSmuggling. But they only informed 3. With #Exim also vulnerable (apparently presumed "clean" by SEC Consult), the list is now 12.
    netfuture.ch/2023/12/smtp-smug

  3. After having been informed by @mathieui that #Exim is also affected, I compiled a list of what #SECConsult documented and what has been found out in the meantime. SEC Consult documented 11 mail systems (software and/or providers; many with millions of accounts) vulnerable to some form of #SMTPSmuggling. But they only informed 3. With #Exim also vulnerable (apparently presumed "clean" by SEC Consult), the list is now 12.
    netfuture.ch/2023/12/smtp-smug

  4. After having been informed by @mathieui that #Exim is also affected, I compiled a list of what #SECConsult documented and what has been found out in the meantime. SEC Consult documented 11 mail systems (software and/or providers; many with millions of accounts) vulnerable to some form of #SMTPSmuggling. But they only informed 3. With #Exim also vulnerable (apparently presumed "clean" by SEC Consult), the list is now 12.
    netfuture.ch/2023/12/smtp-smug

  5. After having been informed by @mathieui that #Exim is also affected, I compiled a list of what #SECConsult documented and what has been found out in the meantime. SEC Consult documented 11 mail systems (software and/or providers; many with millions of accounts) vulnerable to some form of #SMTPSmuggling. But they only informed 3. With #Exim also vulnerable (apparently presumed "clean" by SEC Consult), the list is now 12.
    netfuture.ch/2023/12/smtp-smug

  6. @moanos
    I can't remember a C3-Talk where #eggs or rotten #tomatoes were thrown at the presenter. That would be a first, IMHO.
    #37C3 #SMTPsmuggling #SECconsult

  7. @moanos
    I can't remember a C3-Talk where #eggs or rotten #tomatoes were thrown at the presenter. That would be a first, IMHO.
    #37C3 #SMTPsmuggling #SECconsult

  8. @moanos
    I can't remember a C3-Talk where #eggs or rotten #tomatoes were thrown at the presenter. That would be a first, IMHO.
    #37C3 #SMTPsmuggling #SECconsult

  9. @moanos
    I can't remember a C3-Talk where #eggs or rotten #tomatoes were thrown at the presenter. That would be a first, IMHO.
    #37C3 #SMTPsmuggling #SECconsult

  10. @moanos
    I can't remember a C3-Talk where #eggs or rotten #tomatoes were thrown at the presenter. That would be a first, IMHO.
    #37C3 #SMTPsmuggling #SECconsult

  11. E-Mails, die E-Mails schmuggeln und so Phishing-Mails ermöglichen!? Kein Spaß für Postmaster kurz vor den Weihnachtsferien. - Wir zeigen, worum es eigentlich geht und was Admins und Postmaster jetzt tun können.

    #SMTP #smuggling #Postfix #Mailserver #Postmaster #MTA #Spoofing #SMTPSmuggling #SECconsult

    heinlein-support.de/blog/smtp-

  12. E-Mails, die E-Mails schmuggeln und so Phishing-Mails ermöglichen!? Kein Spaß für Postmaster kurz vor den Weihnachtsferien. - Wir zeigen, worum es eigentlich geht und was Admins und Postmaster jetzt tun können.

    #SMTP #smuggling #Postfix #Mailserver #Postmaster #MTA #Spoofing #SMTPSmuggling #SECconsult

    heinlein-support.de/blog/smtp-

  13. E-Mails, die E-Mails schmuggeln und so Phishing-Mails ermöglichen!? Kein Spaß für Postmaster kurz vor den Weihnachtsferien. - Wir zeigen, worum es eigentlich geht und was Admins und Postmaster jetzt tun können.

    #SMTP #smuggling #Postfix #Mailserver #Postmaster #MTA #Spoofing #SMTPSmuggling #SECconsult

    heinlein-support.de/blog/smtp-

  14. E-Mails, die E-Mails schmuggeln und so Phishing-Mails ermöglichen!? Kein Spaß für Postmaster kurz vor den Weihnachtsferien. - Wir zeigen, worum es eigentlich geht und was Admins und Postmaster jetzt tun können.

    #SMTP #smuggling #Postfix #Mailserver #Postmaster #MTA #Spoofing #SMTPSmuggling #SECconsult

    heinlein-support.de/blog/smtp-

  15. E-Mails, die E-Mails schmuggeln und so Phishing-Mails ermöglichen!? Kein Spaß für Postmaster kurz vor den Weihnachtsferien. - Wir zeigen, worum es eigentlich geht und was Admins und Postmaster jetzt tun können.

    #SMTP #smuggling #Postfix #Mailserver #Postmaster #MTA #Spoofing #SMTPSmuggling #SECconsult

    heinlein-support.de/blog/smtp-

  16. Some additional links:

    The blog post describing the attack:
    sec-consult.com/blog/detail/sm

    Security advisory by #Postfix, clearly pissed:
    postfix.org/smtp-smuggling.htm

    Some reactions from across the fedi:
    zombofant.net/@jssfr/111618969
    gay-pirate-assassins.de/@moano
    waldvogel.family/@marcel/11162

    As Timo clearly likes getting recognition for his work, I for one will be remembering his name, and the name of #SECConsult, his employer, for giving us this Christmas present. 💝

    Thanks Timo. Now get off the fucking stage.

  17. Some additional links:

    The blog post describing the attack:
    sec-consult.com/blog/detail/sm

    Security advisory by #Postfix, clearly pissed:
    postfix.org/smtp-smuggling.htm

    Some reactions from across the fedi:
    zombofant.net/@jssfr/111618969
    gay-pirate-assassins.de/@moano
    waldvogel.family/@marcel/11162

    As Timo clearly likes getting recognition for his work, I for one will be remembering his name, and the name of #SECConsult, his employer, for giving us this Christmas present. 💝

    Thanks Timo. Now get off the fucking stage.

  18. Some additional links:

    The blog post describing the attack:
    sec-consult.com/blog/detail/sm

    Security advisory by #Postfix, clearly pissed:
    postfix.org/smtp-smuggling.htm

    Some reactions from across the fedi:
    zombofant.net/@jssfr/111618969
    gay-pirate-assassins.de/@moano
    waldvogel.family/@marcel/11162

    As Timo clearly likes getting recognition for his work, I for one will be remembering his name, and the name of #SECConsult, his employer, for giving us this Christmas present. 💝

    Thanks Timo. Now get off the fucking stage.

  19. Some additional links:

    The blog post describing the attack:
    sec-consult.com/blog/detail/sm

    Security advisory by #Postfix, clearly pissed:
    postfix.org/smtp-smuggling.htm

    Some reactions from across the fedi:
    zombofant.net/@jssfr/111618969
    gay-pirate-assassins.de/@moano
    waldvogel.family/@marcel/11162

    As Timo clearly likes getting recognition for his work, I for one will be remembering his name, and the name of #SECConsult, his employer, for giving us this Christmas present. 💝

    Thanks Timo. Now get off the fucking stage.

  20. Some additional links:

    The blog post describing the attack:
    sec-consult.com/blog/detail/sm

    Security advisory by #Postfix, clearly pissed:
    postfix.org/smtp-smuggling.htm

    Some reactions from across the fedi:
    zombofant.net/@jssfr/111618969
    gay-pirate-assassins.de/@moano
    waldvogel.family/@marcel/11162

    As Timo clearly likes getting recognition for his work, I for one will be remembering his name, and the name of #SECConsult, his employer, for giving us this Christmas present. 💝

    Thanks Timo. Now get off the fucking stage.

  21. Wenige Tage bevor alle Systemadministratoren sich zu ihren Familien in die verdienten Weihnachtsferien zurückziehen, lässt SEC Consult die Bombe platzen: Die Antispam-Massnahmen der weitverbreitesten Mailserver können ausgehebelt werden, sogar die Vortragsreise dazu ist schon geplant. Nur: Der weitverbreiteste Mailserver weiss davon nichts, seine User sind ungeschützt.
    #SMTP #SMTPSmuggling #Postfix #SECconsult #disclosure
    dnip.ch/2023/12/22/nicht-wirkl

  22. Wenige Tage bevor alle Systemadministratoren sich zu ihren Familien in die verdienten Weihnachtsferien zurückziehen, lässt SEC Consult die Bombe platzen: Die Antispam-Massnahmen der weitverbreitesten Mailserver können ausgehebelt werden, sogar die Vortragsreise dazu ist schon geplant. Nur: Der weitverbreiteste Mailserver weiss davon nichts, seine User sind ungeschützt.
    #SMTP #SMTPSmuggling #Postfix #SECconsult #disclosure
    dnip.ch/2023/12/22/nicht-wirkl

  23. Wenige Tage bevor alle Systemadministratoren sich zu ihren Familien in die verdienten Weihnachtsferien zurückziehen, lässt SEC Consult die Bombe platzen: Die Antispam-Massnahmen der weitverbreitesten Mailserver können ausgehebelt werden, sogar die Vortragsreise dazu ist schon geplant. Nur: Der weitverbreiteste Mailserver weiss davon nichts, seine User sind ungeschützt.
    #SMTP #SMTPSmuggling #Postfix #SECconsult #disclosure
    dnip.ch/2023/12/22/nicht-wirkl

  24. Wenige Tage bevor alle Systemadministratoren sich zu ihren Familien in die verdienten Weihnachtsferien zurückziehen, lässt SEC Consult die Bombe platzen: Die Antispam-Massnahmen der weitverbreitesten Mailserver können ausgehebelt werden, sogar die Vortragsreise dazu ist schon geplant. Nur: Der weitverbreiteste Mailserver weiss davon nichts, seine User sind ungeschützt.
    #SMTP #SMTPSmuggling #Postfix #SECconsult #disclosure
    dnip.ch/2023/12/22/nicht-wirkl

  25. Wenige Tage bevor alle Systemadministratoren sich zu ihren Familien in die verdienten Weihnachtsferien zurückziehen, lässt SEC Consult die Bombe platzen: Die Antispam-Massnahmen der weitverbreitesten Mailserver können ausgehebelt werden, sogar die Vortragsreise dazu ist schon geplant. Nur: Der weitverbreiteste Mailserver weiss davon nichts, seine User sind ungeschützt.
    #SMTP #SMTPSmuggling #Postfix #SECconsult #disclosure
    dnip.ch/2023/12/22/nicht-wirkl

  26. "🚨 Multiple Vulnerabilities Unveiled in SAP® Enable Now Manager 🚨"

    SEC Consult has disclosed multiple vulnerabilities in SAP® Enable Now Manager, which could potentially allow a remote, unauthenticated attacker to create new administrative user accounts by exploiting a chain of vulnerabilities. The vulnerabilities include Open Redirect, Reflected Cross Site Scripting (XSS), and Insufficient Cross-Site Request Forgery (CSRF) Protection. The vendor has pushed a fix in the May 2023 Release for the Cloud Edition.

    🔗 Source: Full Disclosure Mailing List

    🔗 Advisory URL: SEC Consult

    Tags: #SAP #Vulnerability #CyberSecurity #InfoSec #XSS #CSRF #OpenRedirect #SECConsult #CyberAttack #PatchUpdate 🌐🔐🔍

    👥 Researchers: Paul Serban, Fabian Hagg from SEC Consult Vulnerability Lab (SEC Consult)

  27. "🚨 Multiple Vulnerabilities Unveiled in SAP® Enable Now Manager 🚨"

    SEC Consult has disclosed multiple vulnerabilities in SAP® Enable Now Manager, which could potentially allow a remote, unauthenticated attacker to create new administrative user accounts by exploiting a chain of vulnerabilities. The vulnerabilities include Open Redirect, Reflected Cross Site Scripting (XSS), and Insufficient Cross-Site Request Forgery (CSRF) Protection. The vendor has pushed a fix in the May 2023 Release for the Cloud Edition.

    🔗 Source: Full Disclosure Mailing List

    🔗 Advisory URL: SEC Consult

    Tags: #SAP #Vulnerability #CyberSecurity #InfoSec #XSS #CSRF #OpenRedirect #SECConsult #CyberAttack #PatchUpdate 🌐🔐🔍

    👥 Researchers: Paul Serban, Fabian Hagg from SEC Consult Vulnerability Lab (SEC Consult)

  28. "🚨 Multiple Vulnerabilities Unveiled in SAP® Enable Now Manager 🚨"

    SEC Consult has disclosed multiple vulnerabilities in SAP® Enable Now Manager, which could potentially allow a remote, unauthenticated attacker to create new administrative user accounts by exploiting a chain of vulnerabilities. The vulnerabilities include Open Redirect, Reflected Cross Site Scripting (XSS), and Insufficient Cross-Site Request Forgery (CSRF) Protection. The vendor has pushed a fix in the May 2023 Release for the Cloud Edition.

    🔗 Source: Full Disclosure Mailing List

    🔗 Advisory URL: SEC Consult

    Tags: #SAP #Vulnerability #CyberSecurity #InfoSec #XSS #CSRF #OpenRedirect #SECConsult #CyberAttack #PatchUpdate 🌐🔐🔍

    👥 Researchers: Paul Serban, Fabian Hagg from SEC Consult Vulnerability Lab (SEC Consult)

  29. "🚨 Multiple Vulnerabilities Unveiled in SAP® Enable Now Manager 🚨"

    SEC Consult has disclosed multiple vulnerabilities in SAP® Enable Now Manager, which could potentially allow a remote, unauthenticated attacker to create new administrative user accounts by exploiting a chain of vulnerabilities. The vulnerabilities include Open Redirect, Reflected Cross Site Scripting (XSS), and Insufficient Cross-Site Request Forgery (CSRF) Protection. The vendor has pushed a fix in the May 2023 Release for the Cloud Edition.

    🔗 Source: Full Disclosure Mailing List

    🔗 Advisory URL: SEC Consult

    Tags: #SAP #Vulnerability #CyberSecurity #InfoSec #XSS #CSRF #OpenRedirect #SECConsult #CyberAttack #PatchUpdate 🌐🔐🔍

    👥 Researchers: Paul Serban, Fabian Hagg from SEC Consult Vulnerability Lab (SEC Consult)

  30. "🚨 Multiple Vulnerabilities Unveiled in SAP® Enable Now Manager 🚨"

    SEC Consult has disclosed multiple vulnerabilities in SAP® Enable Now Manager, which could potentially allow a remote, unauthenticated attacker to create new administrative user accounts by exploiting a chain of vulnerabilities. The vulnerabilities include Open Redirect, Reflected Cross Site Scripting (XSS), and Insufficient Cross-Site Request Forgery (CSRF) Protection. The vendor has pushed a fix in the May 2023 Release for the Cloud Edition.

    🔗 Source: Full Disclosure Mailing List

    🔗 Advisory URL: SEC Consult

    Tags: #SAP #Vulnerability #CyberSecurity #InfoSec #XSS #CSRF #OpenRedirect #SECConsult #CyberAttack #PatchUpdate 🌐🔐🔍

    👥 Researchers: Paul Serban, Fabian Hagg from SEC Consult Vulnerability Lab (SEC Consult)