I recommend you to check if the 0x0804b795 address is writable for the printf segmentation fault. You can see the different regions of a running process in /proc/PID/maps. For example: $ sleep 10 & [1] 1438 $ cat /proc/$(pgrep -f 'sleep 10')/maps 08048000-0804d000 r-xp 00000000 08:01 399565 /bin/sleep…
SQL Server
Answered Jan 12, 2022
·
620 Views
Read answer →
My opinion is that it is not dangerous to disable the IPv6 firewall. But still, it is a bit unwise. I have had since 2014 (if I recall right) directly connected IPv6 without any firewall at all, but there have never been any attempts using IPv6, even if the primary devices sit in the addresses ::1 and ::10. With IPv4…
SQL Server
Answered Jan 12, 2022
·
523 Views
Read answer →
Contrary to a common misconception, the network key is not the encryption key. The WiFi communication is encrypted on its own using a key exchange protocol. This makes it impossible for anyone without abnormally huge processing power to decrypt anything that goes through. That said, the answer to your question - Can…
SQL Server
Answered Jan 11, 2022
·
594 Views
Read answer →
The "all odds in attackers favor" scenario Attacker is in the same network as the victim, can monitor the network and can not only eavesdrop on the connection, but interfere with it. This is the case when the attacker can execute an ARP Spoofing attack against the victim. In this case, the attack is possible, and…
SQL Server
Answered Jan 11, 2022
·
373 Views
Read answer →
There's a concept in threat modelling called spheres of control which can be used if you want to password protect internal hard drive. A sphere of control is effectively the things in a system that a particular actor has control over. Actors are usually people with different roles, such as unauthenticated users,…
SQL Server
Answered Jan 11, 2022
·
511 Views
Read answer →
The MySQL AES_ENCRYPT function is insecure by default, as it uses ECB mode unless configured otherwise. The documentation provides an example of how to use CBC mode with a 256 bit key (though their example of a key is terrible): mysql> SET block_encryption_mode = 'aes-256-cbc'; mysql> SET @key_str = SHA2('My secret…
SQL Server
Answered Jan 4, 2022
·
2.1K Views
Read answer →
Your verdict shows the website which triggered it - quickprivacycheck.com. Please see http://www.avgthreatlabs.com/us-en/virus-and-malware-information/info/rogue-scanner/ - note that quickprivacycheck.com website is reported as being the #1 site triggering this exploit in the last 7 days. If you don't visit this…
SQL Server
Answered Jan 3, 2022
·
461 Views
Read answer →
To answer the original question - most people never type https://example.com directly. They rely either on links (click here to access our secure login server) or on redirects (type "gmail.com" in the browser, and you will be automatically redirected to a secure site).This is where SSLStrip comes in: it intercepts the…
SQL Server
Answered Jan 3, 2022
·
1.3K Views
Read answer →
The Answer to the question - Can we view directory of website is No. There is no way to browse a directory of any website. For example, let's say you have a website with the url http://example.com/documents/document.doc I can check out http://example.com/documents/ to see if this can return the file index. If they…
SQL Server
Answered Dec 31, 2021
·
408 Views
Read answer →
To see how to detect keyloggers on Android, you can Stop android to send keyboard keystrokes: A scenario for preventing the keyboard on sending would be by using a firewall. For NON-Rooted phones this ones should do the trick: NoRoot Firewall >> www.play.google.com/store/apps/details?id=app.greyshirts.firewall Mobiwol…
SQL Server
Answered Dec 31, 2021
·
1.3K Views
Read answer →
Why is UPnP safe Or unsafe anyway? UPnP's bad name comes from implementation issues found in 2011-2013. It's like saying email is insecure and should be disabled because someone found a common issue in multiple email clients some years ago. I always disabled UPnP because everyone said so. Now that I looked into it, it…
SQL Server
Answered Dec 31, 2021
·
476 Views
Read answer →
"Role based authentication" isn't an industry term. Perhaps you confused it with Role-based access control, which is a method of controlling access to functions based on a users "role", rather than his identity. For example, a blog system might define an "Author" role and an "Editor" role. An "Author" might have…
SQL Server
Answered Dec 30, 2021
·
839 Views
Read answer →