Security

Hanno's Blog

Friday, January 17. 2025

Private Keys in the Fortigate Leak

Monday, February 5. 2024

How to create a Secure, Random Password with JavaScript

Wednesday, October 21. 2020

File Exfiltration via Libreoffice in BigBlueButton and JODConverter

Monday, April 13. 2020

Generating CRIME safe CSRF Tokens

Monday, April 6. 2020

Userdir URLs like https://example.org/~username/ are dangerous

Monday, December 16. 2019

#include </etc/shadow>

Friday, September 13. 2019

Security Issues with PGP Signatures and Linux Package Management

Monday, November 12. 2018

How my personal Bug Bounty Program turned into a Free Security Audit for the Serendipity Blog

Wednesday, April 11. 2018

Introducing Snallygaster - a Tool to Scan for Secrets on Web Servers

Thursday, November 16. 2017

Some minor Security Quirks in Firefox

Thursday, September 7. 2017

In Search of a Secure Time Source

Tuesday, September 5. 2017

Abandoned Domain Takeover as a Web Security Risk

Thursday, July 20. 2017

How I tricked Symantec with a Fake Private Key

Thursday, June 15. 2017

Don't leave Coredumps on Web Servers

Friday, May 19. 2017

The Problem with OCSP Stapling and Must Staple and why Certificate Revocation is still broken

(Page 1 of 8, totaling 112 entries) » next page

About

This blog is written by Hanno Böck. Unless noted otherwise, its content is licensed as CC0.

You can find my web page with links to my work as a journalist here.

I am also publishing a newsletter about climate change and decarbonization technologies.

The blog uses the free software Serendipity and is hosted at schokokeks.org.

Hanno on Mastodon | Contact / Imprint | Privacy / Datenschutz