Tag: 35c3

Blog

Solution to 35C3 Junior CTF Challenge "Entrance"

Tag: authentication

Blog

Vulnerability Disclosure: Authentication Bypass in Auth0

Blog

Vulnerability Disclosure: Session Fixation in Auth0

Blog

Mobile Authenticator Apps Algorithm Support Review - 2023 Edition

Blog

Many Common Mobile Authenticator Apps Accept QR Codes for Modes They Don't Support

Tag: ccc

Blog

Solution to 35C3 Junior CTF Challenge "Entrance"

Tag: cdn

Blog

The Akamai Origin Disclosure Non-vulnerability

Tag: certificates

Blog

PKI Is Hard - How Yubico Trusted OpenSSL And Got It Wrong

Tag: coordinated-disclosure

Blog

Wardriving 2024: Using Electricity Meter Readers to Get In

Blog

The Akamai Origin Disclosure Non-vulnerability

Blog

Vulnerability Disclosure: Authentication Bypass in Auth0

Blog

Vulnerability Disclosure: Session Fixation in Auth0

Blog

Man-in-The-Middle Session Fixation in Securitas Direct My Pages

Blog

The Devise Extension That Peeled off One Layer of the Security Onion (CVE-2021-28680)

Blog

CSN Follow-Up: Another CAPTCHA Problem Hidden In Plain Sight

Blog

Brute-Forcing Borrowers' PINs at the Swedish Board of Student Finance (CSN)

Tag: ctf

Blog

Solution to 35C3 Junior CTF Challenge "Entrance"

Tag: cve

Blog

The Devise Extension That Peeled off One Layer of the Security Onion (CVE-2021-28680)

Tag: iot

Blog

Wardriving 2024: Using Electricity Meter Readers to Get In

Tag: pki

Blog

PKI Is Hard - How Yubico Trusted OpenSSL And Got It Wrong

Tag: sentor-blog-posts

Blog

The Akamai Origin Disclosure Non-vulnerability

Blog

Vulnerability Disclosure: Authentication Bypass in Auth0

Blog

Vulnerability Disclosure: Session Fixation in Auth0

Tag: totp

Blog

Mobile Authenticator Apps Algorithm Support Review - 2023 Edition

Blog

Many Common Mobile Authenticator Apps Accept QR Codes for Modes They Don't Support

Tag: waf

Blog

The Akamai Origin Disclosure Non-vulnerability

Tag: web-vulnerabilities

Blog

Wardriving 2024: Using Electricity Meter Readers to Get In

Blog

The Akamai Origin Disclosure Non-vulnerability

Blog

Vulnerability Disclosure: Authentication Bypass in Auth0

Blog

Vulnerability Disclosure: Session Fixation in Auth0

Blog

Man-in-The-Middle Session Fixation in Securitas Direct My Pages

Blog

The Devise Extension That Peeled off One Layer of the Security Onion (CVE-2021-28680)

Blog

CSN Follow-Up: Another CAPTCHA Problem Hidden In Plain Sight

Blog

Brute-Forcing Borrowers' PINs at the Swedish Board of Student Finance (CSN)