pentagridsec Profile Banner
Pentagrid AG Profile
Pentagrid AG

@pentagridsec

Followers
285
Following
7
Statuses
53

Pentagrid performs technically solid IT security assessments. Mastodon: @[email protected]

Buchs SG, Switzerland
Joined May 2019
Don't wanna be here? Send us removal request.
@pentagridsec
Pentagrid AG
2 years
We are also on #Mastodon: @pentagrid@infosec.exchange See you there!
0
2
2
@pentagridsec
Pentagrid AG
2 months
A story about looking at the effectiveness of web application firewalls and finding bypasses for the filter ruleset. #WAF #OWASP #coreruleset #ergon #airlock
0
1
1
@pentagridsec
Pentagrid AG
2 months
Pentagrid published two @hackvertor tags for #EAN13 (also Swiss AHV numbers) and #TOTP for #2FA. These tags are available via the Hackvertor Tag Store by @garethheyes . Our blog post explains what these tags do and how they can be used. #pentest #OWASP
0
6
6
@pentagridsec
Pentagrid AG
4 months
Pentagrid is looking for an IT security analyst (d/f/m) in Buchs SG, Switzerland.
1
1
6
@pentagridsec
Pentagrid AG
8 months
If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. #hardening
0
1
0
@pentagridsec
Pentagrid AG
8 months
It happened again. We accidentally broke another #hotel check-in #terminal. This time Mr O'Yolo triggered a problem, crashed the #Ariane Allegro Scenario Player and escaped the #kiosk mode, which enabled access to the Windows Desktop: #itsecurity #infosec
0
1
3
@pentagridsec
Pentagrid AG
10 months
This is not a late April Fool's joke: After #37C3, we accidentally dumped the keypad codes of almost half of an IBIS hotel's rooms by entering some dashes into a check-in terminal: #itsecurity #infosec #ibis #accor #terminal #hotel
0
3
2
@pentagridsec
Pentagrid AG
11 months
#SQLinjection in login dialog of web-based #YABOOK harbour administration allows authentication bypass #pentest #sailing #hafenverwaltung #imonaboat
0
1
1
@pentagridsec
Pentagrid AG
1 year
Multiple vulnerabilities in Lantronix EDS-MD IoT gateway for medical devices: #itsecurity #infosec #pentesting #lantronix #iot #medical
0
4
4
@pentagridsec
Pentagrid AG
1 year
♫ Ground control to Major Tom, take the patch and put secure mode on. ♫ #openstage #openscape #unify
0
2
1
@pentagridsec
Pentagrid AG
1 year
A few email-related Python libraries do not check server certificates. It is nothing new, but a bit surprisingly in 2023 and not everyone got the memo. #itsecurity #infosec #pentesting #python #email #bugbounty
0
3
2
@pentagridsec
Pentagrid AG
1 year
The #Liferay Portal software < 7.4.3.88 respectively < 7.4.3.92 is affected by persistent cross-site-scripting vulnerabilities. #itsecurity #infosec #pentesting
0
6
0
@pentagridsec
Pentagrid AG
1 year
Wir haben ein Werkzeug in Python geschrieben, dass Dateiarchive wie zip, tar und cpio generiert welche Path Traversal Angriffe beinhalten: #itsicherheit #informationssicherheit #pentesting
0
0
0
@pentagridsec
Pentagrid AG
1 year
We wrote a tool in Python to create file archives such as zip, tar and cpio that include path traversal attacks: #itsecurity #infosec #pentesting
0
4
2
@pentagridsec
Pentagrid AG
1 year
We analysed the security of a #WindRiver #VxWorks (the operating system running also on NASA's Curiosity mars rover) embedded device and found a critical vulnerability in the #tarExtract function: #itsecurity #infosec #pentesting #cisa #vxworks
0
3
3
@pentagridsec
Pentagrid AG
1 year
Wir haben uns das Liechtensteiner #Gesundheitsdossier und die zugrunde liegende Portal-Software #Liferay angeschaut. Im Ergebnis haben wir Verwundbarkeiten in Liferay gefunden und Schwächen im IT-Setup: #itsicherheit #informationssicherheit #eHealth #eGD
0
2
4
@pentagridsec
Pentagrid AG
1 year
We had a look at Liechtenstein's electronic health files and the underlying #Liferay portal software and found some weaknesses in the portal software as well as risks in the IT setup. Full article (in German only): #itsecurity #infosec #eHealth #eGD
0
2
4
@pentagridsec
Pentagrid AG
1 year
For some #Icinga #monitoring, we wrote a small plugin in Python that sends mail via SMTP and checks on another mail server via IMAP if the mail was received. Here is the code:
0
2
4
@pentagridsec
Pentagrid AG
1 year
Our advisory for Busybox cpio. When extracting cpio archives with BusyBox cpio, the cpio archiving tools may write files outside the destination directory and there is no option to prevent this. Full advisory: #itsecurity #infosec #pentesting #Busybox
0
3
4
@pentagridsec
Pentagrid AG
2 years
Do not put the PDU's management interface on the Internet. Otherwise, the Internet turns off the light. #aten #pdu #Vulnerability
0
5
7