Liability in an Assume Breach World F5 Labs 7 years 4 months ago The safest way to run a network is to assume it’s going to breached, but that also means minimizing your liability and ensuring the executive team is fully aware of what is going on.
灯塔资讯中心Beta版本发布 灯塔实验室 7 years 4 months ago 我们实验室于近期推出了一个工控安全资讯搜集与分享工具(https://cert.plcscan.org),长久… Z-0ne
BrickerBot: Do “Good Intentions” Justify the Means—or Deliver Meaningful Results? F5 Labs 7 years 4 months ago Most security researchers have good intentions, but ethics must play a central role in the decisions they make.
Bleichenbacher Rears Its Head Again with the ROBOT Attack F5 Labs 7 years 4 months ago Bleichenbacher attacks will likely continue to pop up until TLS 1.3 is fully adopted, which could take years.
Drupal V7.3.1 框架处理不当导致SQL注入 - magic_zero Magic_Zero 7 years 4 months ago 这个漏洞本是2014年时候被人发现的,本着学习的目的,我来做个详细的分析。漏洞虽然很早了,新版的Drupal甚至已经改变了框架的组织方式。但是丝毫不影响对于漏洞的分析。这是一个经典的使用PDO,但是处理不当,导致SQL语句拼接从而导致注入的问题。从这个问题,以及以往我见过的很多的漏洞来看,我不得不说 magic_zero
Achieving Multi-Dimensional Security Through Information Modeling—Modeling Inversion Part 5 F5 Labs 7 years 4 months ago In Part 5 of this blog series, we use inversion modeling techniques to develop a high-level protection strategy.