101010.pl is one of the many independent Mastodon servers you can use to participate in the fediverse.
101010.pl czyli najstarszy polski serwer Mastodon. Posiadamy wpisy do 2048 znaków.

Server stats:

517
active users

#IDOR

0 posts0 participants0 posts today
sekurak News<p>Jak można było czytać listę połączeń klientów sieci Verizon</p><p>Evan Connelly zaprezentował odkrytą przez siebie podatność w aplikacji&nbsp; Verizon Call Filter na urządzenia z systemem iOS. Co prawda problem dotyczy klientów tej amerykańskiej sieci GSM, jednak postanowiliśmy opisać błąd leżący u podstaw tej podatności, ponieważ z doświadczenia wiemy, że luki klasy IDOR (ang. Insecure Direct Object Reference) pojawiają się...</p><p><a href="https://mastodon.com.pl/tags/WBiegu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WBiegu</span></a> <a href="https://mastodon.com.pl/tags/Billing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Billing</span></a> <a href="https://mastodon.com.pl/tags/IDOR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IDOR</span></a> <a href="https://mastodon.com.pl/tags/Podatno%C5%9B%C4%87" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Podatność</span></a> <a href="https://mastodon.com.pl/tags/Verizon" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Verizon</span></a> <a href="https://mastodon.com.pl/tags/Websec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Websec</span></a></p><p><a href="https://sekurak.pl/jak-mozna-bylo-czytac-liste-polaczen-klientow-sieci-verizon/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">sekurak.pl/jak-mozna-bylo-czyt</span><span class="invisible">ac-liste-polaczen-klientow-sieci-verizon/</span></a></p>
sekurak News<p>Jak można było mieć dostęp do dziesiątek tysięcy raportów z wypadków, w których brały udział samochody wypożyczone z Hertz? Zmieniając identyfikator w tym adresie: /accident-report/12345</p><p>Uff, w zasadzie cała treść znaleziska zmieściła się w tytule ;-) co w pewien sposób świadczy o poziomie bezpieczeństwa aplikacji webowych w 2024 roku… Dla jasności cała historia wyglądała tak: najpierw badacz otrzymał maila z Hertz z informacją o swoim raporcie. W tym przypadku adres w aplikacji webowej wyglądał mniej...</p><p><a href="https://mastodon.com.pl/tags/WBiegu" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WBiegu</span></a> <a href="https://mastodon.com.pl/tags/IDOR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IDOR</span></a> <a href="https://mastodon.com.pl/tags/Websec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Websec</span></a></p><p><a href="https://sekurak.pl/jak-mozna-bylo-miec-dostep-do-dziesiatek-tysiecy-raportow-z-wypadkow-w-ktorych-braly-udzial-samochody-wypozyczone-z-hertz-zmieniajac-identyfikator-w-tym-adresie-accident-report-12345/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">sekurak.pl/jak-mozna-bylo-miec</span><span class="invisible">-dostep-do-dziesiatek-tysiecy-raportow-z-wypadkow-w-ktorych-braly-udzial-samochody-wypozyczone-z-hertz-zmieniajac-identyfikator-w-tym-adresie-accident-report-12345/</span></a></p>
Shai Almog<p>🚨 Discover how simple teenage curiosity with phone numbers parallels today's digital exploits. <a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://mastodon.social/tags/IDOR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IDOR</span></a> <a href="https://mastodon.social/tags/TechInsights" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TechInsights</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a><br><a href="https://debugagent.com/understanding-security-vulnerabilities-a-first-step-in-preventing-attacks" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">debugagent.com/understanding-s</span><span class="invisible">ecurity-vulnerabilities-a-first-step-in-preventing-attacks</span></a></p>
Xavier «X» Santolaria :verified_paw: :donor:<p>📨 Latest issue of my curated <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> and <a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosec</span></a> list of resources for week #30/2023 is out! It includes the following and much more:</p><p>➝ 🇷🇺 🇪🇺 <a href="https://infosec.exchange/tags/BlueBravo" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BlueBravo</span></a> Deploys GraphicalProton Backdoor Against European Diplomatic Entities<br>➝ 🇰🇵 💸 <a href="https://infosec.exchange/tags/CoinsPaid" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CoinsPaid</span></a> Blames North Korean Hackers for $37 Million Cryptocurrency Heist<br>➝ 👥 💸 <a href="https://infosec.exchange/tags/BreachForums" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BreachForums</span></a> database and private chats for sale in hacker data breach<br>➝ 🇺🇸 🔓 Up to 11 Million People Hit by <a href="https://infosec.exchange/tags/MOVEit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MOVEit</span></a> Hack at Government Services Firm Maximus<br>➝ 🇦🇺 🇺🇸 Cybersecurity Agencies Warn Against <a href="https://infosec.exchange/tags/IDOR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IDOR</span></a> Bugs Exploited for Data Breaches<br>➝ 🔓 🐧 GameOver(lay): Two Severe <a href="https://infosec.exchange/tags/Linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Linux</span></a> Vulnerabilities Impact 40% of Ubuntu Users<br>➝ 🦠 🗣️ <a href="https://infosec.exchange/tags/Deloitte" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Deloitte</span></a> denies <a href="https://infosec.exchange/tags/Cl0p" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cl0p</span></a> data breach impacted client data in wake of MOVEit attack<br>➝ 🇺🇸 🇨🇳 US Senator Wyden Accuses <a href="https://infosec.exchange/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> of ‘Cybersecurity Negligence’<br>➝ 🇨🇦 🫀 <a href="https://infosec.exchange/tags/CardioComm" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CardioComm</span></a>, a provider of <a href="https://infosec.exchange/tags/ECG" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ECG</span></a> monitoring devices, confirms cyberattack downed its services<br>➝ 🇲🇽 💸 Fenix <a href="https://infosec.exchange/tags/Cybercrime" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybercrime</span></a> Group Poses as Tax Authorities to Target Latin American Users<br>➝ 🇺🇸 💰 <a href="https://infosec.exchange/tags/SEC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SEC</span></a> now requires companies to disclose cyberattacks in 4 days<br>➝ ✨ 👀 <a href="https://infosec.exchange/tags/NATO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NATO</span></a> investigates alleged data theft by <a href="https://infosec.exchange/tags/SiegedSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SiegedSec</span></a> hackers<br>➝ 🇷🇺 ⚖️ Russian Cybersecurity Firm Founder Jailed for 14 Years<br>➝ 🇳🇱 ⚓️ Maritime Cyberattack Database Launched by Dutch University<br>➝ 🦠 🍏 Realst Mac <a href="https://infosec.exchange/tags/malware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>malware</span></a> targets macOS <a href="https://infosec.exchange/tags/Sonoma" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Sonoma</span></a><br>➝ 🔐 📝 <a href="https://infosec.exchange/tags/IBM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IBM</span></a> Report: Half of Breached Organizations Unwilling to Increase Security Spend Despite Soaring Breach Costs<br>➝ 🇳🇱 🚔 Researchers find deliberate <a href="https://infosec.exchange/tags/backdoor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>backdoor</span></a> in police radio <a href="https://infosec.exchange/tags/encryption" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>encryption</span></a> algorithm<br>➝ 🇰🇵 🥷🏻 <a href="https://infosec.exchange/tags/JumpCloud" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JumpCloud</span></a> hack linked to <a href="https://infosec.exchange/tags/NorthKorea" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NorthKorea</span></a> after <a href="https://infosec.exchange/tags/OPSEC" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OPSEC</span></a> mistake<br>➝ 🩹 <a href="https://infosec.exchange/tags/Ivanti" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Ivanti</span></a> patches MobileIron zero-day bug exploited in attacks<br>➝ 🇳🇴 🥷🏻 <a href="https://infosec.exchange/tags/Norway" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Norway</span></a> government ministries hit by cyber attack<br>➝ 🧘🏻 🩸 <a href="https://infosec.exchange/tags/Zenbleed" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Zenbleed</span></a> attack leaks sensitive data from <a href="https://infosec.exchange/tags/AMD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AMD</span></a> Zen2 processors<br>➝ 🩹 🍏 <a href="https://infosec.exchange/tags/Apple" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Apple</span></a> fixes new zero-day used in attacks against iPhones, Macs<br>➝ 🦠 🏦 <a href="https://infosec.exchange/tags/Banking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Banking</span></a> Sector Targeted in Open-Source Software Supply Chain Attacks</p><p><a href="https://infosec.exchange/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a> <a href="https://infosec.exchange/tags/TETRA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>TETRA</span></a> <a href="https://infosec.exchange/tags/IoT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IoT</span></a> <a href="https://infosec.exchange/tags/MIoT" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MIoT</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> </p> <p>📚 This week's recommended reading is: "Evading EDR: A Comprehensive Guide to Defeating Endpoint Detection Systems" by Matt Hand</p> <p>Subscribe to the <a href="https://infosec.exchange/tags/infosecMASHUP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>infosecMASHUP</span></a> newsletter to have it piping hot in your inbox every week-end ⬇️</p><p><a href="https://infosec-mashup.santolaria.net/p/infosec-mashup-week-302023" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">infosec-mashup.santolaria.net/</span><span class="invisible">p/infosec-mashup-week-302023</span></a></p>
Shared Security Podcast :verified:<p>🤔​Should you use Meta's new app called Threads? Why are airline reservation scams happening so frequently? What are IDOR (Insecure Direct Object Reference) vulnerabilities and why are they so dangerous?</p><p>Join us on the latest episode of Shared Security as we discuss three compelling stories that will leave you questioning the boundaries of privacy, the tricks of scammers, and the vulnerabilities in our digital world.</p><p>📖 Threads Unleashed - We unravel the rise of Threads, Meta's social media app challenging Twitter. With over 10 million users in just seven hours, we explore its data collection practices and the implications for your personal information.</p><p>🚫 Beware of Flight Scams - Discover the dark side of airline reservations as we discuss a crafty scam that dupes unsuspecting travelers. Learn how to protect yourself from falling victim to these ticket scams that can cost you more than just money.</p><p>🔒 Security Alarm Breach - Listen to our discussiobn about the alarming IDOR vulnerability found in Eaton's SecureConnect system. We discuss the risks of weak access controls and the potential implications for remote access to thousands of smart security alarm systems.</p><p>Join us these topics and more this week on Shared Security!💻🌍</p><p><a href="https://infosec.exchange/tags/technology" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>technology</span></a> <a href="https://infosec.exchange/tags/privacy" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>privacy</span></a> <a href="https://infosec.exchange/tags/scams" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>scams</span></a> <a href="https://infosec.exchange/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://infosec.exchange/tags/idor" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>idor</span></a> <a href="https://infosec.exchange/tags/podcast" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>podcast</span></a></p><p>Subscribe on Apple Podcasts, Spotify, or your favorite podcast platform:<br><a href="https://sharedsecurity.net/subscribe" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">sharedsecurity.net/subscribe</span><span class="invisible"></span></a></p><p>Watch on YouTube:<br><a href="https://youtu.be/nZCZk9myDcA" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">youtu.be/nZCZk9myDcA</span><span class="invisible"></span></a></p><p>Listen on our website:<br><a href="https://sharedsecurity.net/2023/07/10/metas-threads-and-your-privacy-airline-reservation-scams-idor-srikes-back/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">sharedsecurity.net/2023/07/10/</span><span class="invisible">metas-threads-and-your-privacy-airline-reservation-scams-idor-srikes-back/</span></a></p>
👁️à̸̖̜͖͖͇̐͘͠z̸̡̧̈́̌̏̔̌̈z̴̼̥̻̰͉͙̥̟̤͂̽̈͒͊ͅy̴̗̍͐̈́̃͘̚͝👁️<p>I wondered due to recently remembering when I was able to pull the PDFs off teacher's section. On the textbook manufacturer's just from fking around the URL.</p><p>This is a while ago, but I did mention to the professor but he did the idk what you talking about. (2+ years ago)</p><p>So I did email the contact email for the manufacturer. They asked for student ID, school code and classroom name. I told in response You can get the school name and thats it. But the following response was how I need to disciplinary actions against me for attempting to cheat. Thus they need the student ID. I ain't gonna get expelled for absolute dumb shit. So I didn't give it and cut off all communications.</p><p>In cases this it's now like a double sided thing. I want to report an issue so someone could fix it. But if I'm going to be punished too, why report the issue at all? </p><p><a href="https://infosec.exchange/tags/teaching" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>teaching</span></a> <a href="https://infosec.exchange/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://infosec.exchange/tags/IDOR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IDOR</span></a> <a href="https://infosec.exchange/tags/url" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>url</span></a> <a href="https://infosec.exchange/tags/exploit" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>exploit</span></a></p>
Sam Stepanyan :verified: 🐘<p>"Hacking on a plane: Leaking data of millions of users of in-flight <a href="https://infosec.exchange/tags/WiFi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WiFi</span></a> and taking over any account" - a blog post by @rez0__@twitter.com :</p><p><a href="https://infosec.exchange/tags/AirplaneWifi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AirplaneWifi</span></a><br><a href="https://infosec.exchange/tags/AppSec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AppSec</span></a><br><a href="https://infosec.exchange/tags/IDOR" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>IDOR</span></a></p><p><a href="https://rez0.blog/hacking/2022/12/02/hacking-on-a-plane.html" rel="nofollow noopener" target="_blank"><span class="invisible">https://</span><span class="ellipsis">rez0.blog/hacking/2022/12/02/h</span><span class="invisible">acking-on-a-plane.html</span></a></p>