Hanz Ostmaster’s revenge: An SSL Validation issue SpiderLabs Blog February 10, 2017 Chaim Sanders Why would I title a blog post with the name 'Hanz Ostmaster'? Don't worry, it's not some new named vulnerability, but it turns out this name has some significance. Do you see it? It requires a bit of imagination -... Read More
Unauthenticated Backdoor Access in Unanet SpiderLabs Blog February 8, 2017 Chaim Sanders The default configuration of the Unanet web application has a backdoor that can allow unauthenticated users to login and manipulate the user accounts and the roles they maintain. This vulnerability is due to a code branch that exists within the... Read More
Database Security Knowledgebase Update 5.11 SpiderLabs Blog February 3, 2017 Lolita Chandra This month's update for Database Security Knowledgebase is now available. Knowledgebase version 5.11 includes new checks for MySQL, SQL Server and Oracle as well as updated checks for SQL Server and MySQL. New Vulnerability and Configuration Check Highlights MySQL Critical... Read More
Underground Scams: Cutting the Head Off a Snake SpiderLabs Blog February 2, 2017 Simon Kenin Shortly after publishing our post about Terror EK, "King Cobra" (a Twitter account that we mentioned at the end of that blog post), tweeted a note to us: Figure 1: King Cobra's tweet to Trustwave This, along with other feedback... Read More
CVE-2017-5521: Bypassing Authentication on NETGEAR Routers SpiderLabs Blog January 30, 2017 Simon Kenin Home routers are the first and sometimes last line of defense for a network. Despite this fact, many manufacturers of home routers fail to properly audit their devices for security issues before releasing them to the market. As security researchers,... Read More