Quantcast
Channel: Context Information Security Blog
Browsing index pages (262 articles)

Image may be NSFW.
Clik here to view.

Part I: An Overview of Firmware Storage Options

The security of a device’s firmware, as the first or an early part of a trusted chain, can have implications for the security of the whole system. At Context we often obtain the firmware for a device...

View Article


Image may be NSFW.
Clik here to view.

Testing Multi-Step Forms

In this two-part blog, we will be discussing multi-step forms. In part 1, we will see how multi-step forms affect scoping a test; while in part two we will go through techniques involved in testing...

View Article


Image may be NSFW.
Clik here to view.

Über die Schwierigkeiten von Antragsstrecken

In diesem zweiteiligen Blogpost werden wir Antragsstrecken diskutieren. In Teil 1 befassen wir uns damit, wie Antragsstrecken die Aufwandsabschätzung („Scoping“) beeinflusst. In Teil 2 (Englisch)...

View Article

Image may be NSFW.
Clik here to view.

What's a Security Operations Centre (SOC) and why should I care?

My previous blog post talked about cyber security risk management. This post explains the relevance and importance of a SOC and how this capability can reduce the risk to your network. As we have been...

View Article

Image may be NSFW.
Clik here to view.

The Neglected Dangers of Email Functionality

A great deal of web applications utilise email to implement functionalities such as user self-registration, password reset or a simple 'contact us' form. What we know is that email is sent using one of...

View Article


Petya: What you need to know

Context has become aware of a new self-propagating variant of the “Petya” ransomware which spreads using the EternalBlue SMB exploit made famous by WannaCry.Like WannaCry, this malware variant contains...

View Article

Image may be NSFW.
Clik here to view.

Hacking the Virgin Media Super Hub

IntroductionContext’s Research team have looked a large number of off-the-shelf home routers in the past and found them to be almost universally dreadful in terms of security posture. However, flagship...

View Article

What is effective cyber security risk management?

Cyber services are currently going through an evolution, moving from the reactive to the proactive, as businesses wake up to the impact a cyber-attack can have on their operational output or...

View Article


Lessons learned from WannaCry

In the wake of the WannaCry ransomware cyber-attack, which had such a significant impact on the UK’s NHS, amongst many other organisations worldwide, I am mindful of my simple mantra:  Know your...

View Article


Image may be NSFW.
Clik here to view.

Applocker Bypass via Registry Key Manipulation

AppLocker is the de-facto standard to locking down Windows machines. It is new to Windows 7 and Windows Server 2008 R2 and is the successor to Software Restriction Policies (SRP). Applocker is used by...

View Article

WannaCry: What you need to know

Following the “WannaCry” cyber-attacks last Friday, we have put together a short briefing note with some essential information about the attack, what it is and how it works, and some immediate actions...

View Article

Image may be NSFW.
Clik here to view.

Exploiting Vulnerable Pandas

There’s been some debate recently (see the work of Tavis Ormandy, Project Zero) around whether security applications such as Anti-Virus make devices more secure, or whether their greater attack surface...

View Article

The Resilient Road to Recovery

“It’s not a matter of if your network is compromised but when”. This phrase may be one of the tired clichés of cyber security, but it is true nonetheless. All organisations will be attacked and some...

View Article


Making an NTFS Volume Mountable by Tinkering with the VBR

We recently had to do disk forensics of 10 disks, each of which had a BitLocker encrypted C volume. We were working with E01s, but no real problem, the organisation's IT department provided us with...

View Article

Forensic Imaging. So this should now boot... right?

Often within forensics an investigation can benefit from analysing the machine as the user would see it. This can lead to artefacts being found that may not be obvious when using our analytical...

View Article


Hacking Unicorns with Web Bluetooth

Some news broke yesterday about the CloudPets toy we've been looking at over the last few months. Researchers discovered an unsecured MongoDB server that exposed sensitive CloudPets customer data. My...

View Article

Phwning the boardroom: hacking an Android conference phone

At Context we’re always on the lookout for interesting devices to play with. Sat in a meeting room one day, we noticed that the menus on the conference phone, a Mitel MiVoice Conference/Video Phone,...

View Article


User Awareness: An Important Tool in Protecting Your Organisation from Cyber...

Making your employees aware of the cyber threats they might face, both at work and at home, is an invaluable exercise. On its own, this activity is certainly not going to make your organisation...

View Article

WAP just happened to my Samsung Galaxy?

This is the third in a series of blogs about how, even in 2017, SMS-based attacks on Android phones are still viable. In part one, Al described how to set up infrastructure to launch potential attacks....

View Article

Manipulating client-side variables in Java applications

Penetration testing of thick client applications is a common service performed at Context. For those unfamiliar with the term, in the context of application penetration testing, thick clients are any...

View Article
Browsing index pages (262 articles)


Latest Images