Part I: An Overview of Firmware Storage Options
The security of a device’s firmware, as the first or an early part of a trusted chain, can have implications for the security of the whole system. At Context we often obtain the firmware for a device...
View ArticleTesting Multi-Step Forms
In this two-part blog, we will be discussing multi-step forms. In part 1, we will see how multi-step forms affect scoping a test; while in part two we will go through techniques involved in testing...
View ArticleÜber die Schwierigkeiten von Antragsstrecken
In diesem zweiteiligen Blogpost werden wir Antragsstrecken diskutieren. In Teil 1 befassen wir uns damit, wie Antragsstrecken die Aufwandsabschätzung („Scoping“) beeinflusst. In Teil 2 (Englisch)...
View ArticleWhat's a Security Operations Centre (SOC) and why should I care?
My previous blog post talked about cyber security risk management. This post explains the relevance and importance of a SOC and how this capability can reduce the risk to your network. As we have been...
View ArticleThe Neglected Dangers of Email Functionality
A great deal of web applications utilise email to implement functionalities such as user self-registration, password reset or a simple 'contact us' form. What we know is that email is sent using one of...
View ArticlePetya: What you need to know
Context has become aware of a new self-propagating variant of the “Petya” ransomware which spreads using the EternalBlue SMB exploit made famous by WannaCry.Like WannaCry, this malware variant contains...
View ArticleHacking the Virgin Media Super Hub
IntroductionContext’s Research team have looked a large number of off-the-shelf home routers in the past and found them to be almost universally dreadful in terms of security posture. However, flagship...
View ArticleWhat is effective cyber security risk management?
Cyber services are currently going through an evolution, moving from the reactive to the proactive, as businesses wake up to the impact a cyber-attack can have on their operational output or...
View ArticleLessons learned from WannaCry
In the wake of the WannaCry ransomware cyber-attack, which had such a significant impact on the UK’s NHS, amongst many other organisations worldwide, I am mindful of my simple mantra: Know your...
View ArticleApplocker Bypass via Registry Key Manipulation
AppLocker is the de-facto standard to locking down Windows machines. It is new to Windows 7 and Windows Server 2008 R2 and is the successor to Software Restriction Policies (SRP). Applocker is used by...
View ArticleWannaCry: What you need to know
Following the “WannaCry” cyber-attacks last Friday, we have put together a short briefing note with some essential information about the attack, what it is and how it works, and some immediate actions...
View ArticleExploiting Vulnerable Pandas
There’s been some debate recently (see the work of Tavis Ormandy, Project Zero) around whether security applications such as Anti-Virus make devices more secure, or whether their greater attack surface...
View ArticleThe Resilient Road to Recovery
“It’s not a matter of if your network is compromised but when”. This phrase may be one of the tired clichés of cyber security, but it is true nonetheless. All organisations will be attacked and some...
View ArticleMaking an NTFS Volume Mountable by Tinkering with the VBR
We recently had to do disk forensics of 10 disks, each of which had a BitLocker encrypted C volume. We were working with E01s, but no real problem, the organisation's IT department provided us with...
View ArticleForensic Imaging. So this should now boot... right?
Often within forensics an investigation can benefit from analysing the machine as the user would see it. This can lead to artefacts being found that may not be obvious when using our analytical...
View ArticleHacking Unicorns with Web Bluetooth
Some news broke yesterday about the CloudPets toy we've been looking at over the last few months. Researchers discovered an unsecured MongoDB server that exposed sensitive CloudPets customer data. My...
View ArticlePhwning the boardroom: hacking an Android conference phone
At Context we’re always on the lookout for interesting devices to play with. Sat in a meeting room one day, we noticed that the menus on the conference phone, a Mitel MiVoice Conference/Video Phone,...
View ArticleUser Awareness: An Important Tool in Protecting Your Organisation from Cyber...
Making your employees aware of the cyber threats they might face, both at work and at home, is an invaluable exercise. On its own, this activity is certainly not going to make your organisation...
View ArticleWAP just happened to my Samsung Galaxy?
This is the third in a series of blogs about how, even in 2017, SMS-based attacks on Android phones are still viable. In part one, Al described how to set up infrastructure to launch potential attacks....
View ArticleManipulating client-side variables in Java applications
Penetration testing of thick client applications is a common service performed at Context. For those unfamiliar with the term, in the context of application penetration testing, thick clients are any...
View Article