20 February 2018

Be kind to your local security researcher

As big fans of open source, we feel the urge to support the community and contribute to the projects we like. And because our code is ugly as hell, we try to do it at least by reporting bugs and security vulnerabilities.

20 February 2018

Report from 30C3: Forget privacy online!

Chaos Communication Congress is the oldest hacker conference in the world and the largest of its kind in Europe. It brings current research in the field of security, networking and increasingly also politics and other topics related to “hacking".

8 February 2018

How to Order a Penetration Test – A Quick Guide

Although people working in the IT security industry may consider this question to be as trivial as "How to order a phone charger", for many, writing a purchase order for a penetration test can be like designing a nuclear power plant.

28 January 2018

Unofficial Patch Tuesday – MSMQ Privilege Escalation Vulnerability Hotfix

Microsoft won’t patch this one — so we did. CVE-2014-4971 is a known privilege escalation vulnerability in the MSMQ service on Windows XP. Citadelo’s unofficial hotfix helps secure legacy systems against this active exploit.

28 January 2018

WebsiteBaker CMS 2.10.0 – Multiple SQL Injection Vulnerabilities

The vulnerability exists due to insufficient filtration of user-supplied data. By exploiting this vulnerability, an attacker gains access to all records stored in the database with the privileges of the WebsiteBaker database user

28 January 2018

Considerations before using keybase.io

Keybase.io is a service that according to their website “maps your identity to your public keys, and vice versa.”. It is also doing other optional things such as an encrypted filesystem and synchronized key management.