Pentagrid AG(@pentagridsec) 's Twitter Profileg
Pentagrid AG

@pentagridsec

Pentagrid performs technically solid IT security assessments.
Mastodon: @[email protected]

ID:1126200162232217605

linkhttps://pentagrid.ch calendar_today08-05-2019 19:00:17

48 Tweets

292 Followers

2 Following

Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

This is not a late April Fool's joke: After , we accidentally dumped the keypad codes of almost half of an IBIS hotel's rooms by entering some dashes into a check-in terminal: pentagrid.ch/en/blog/ibis-h…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

A few email-related Python libraries do not check server certificates. It is nothing new, but a bit surprisingly in 2023 and not everyone got the memo. pentagrid.ch/en/blog/python…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

The Portal software < 7.4.3.88 respectively < 7.4.3.92 is affected by persistent cross-site-scripting vulnerabilities. pentagrid.ch/en/blog/stored…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

Wir haben ein Werkzeug in Python geschrieben, dass Dateiarchive wie zip, tar und cpio generiert welche Path Traversal Angriffe beinhalten: pentagrid.ch/de/blog/archiv…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

We wrote a tool in Python to create file archives such as zip, tar and cpio that include path traversal attacks: pentagrid.ch/en/blog/archiv…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

We analysed the security of a (the operating system running also on NASA's Curiosity mars rover) embedded device and found a critical vulnerability in the function: pentagrid.ch/en/blog/wind-r…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

Wir haben uns das Liechtensteiner und die zugrunde liegende Portal-Software angeschaut. Im Ergebnis haben wir Verwundbarkeiten in Liferay gefunden und Schwächen im IT-Setup: pentagrid.ch/de/blog/it-sic…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

We had a look at Liechtenstein's electronic health files and the underlying portal software and found some weaknesses in the portal software as well as risks in the IT setup. Full article (in German only): pentagrid.ch/de/blog/it-sic…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

For some , we wrote a small plugin in Python that sends mail via SMTP and checks on another mail server via IMAP if the mail was received. Here is the code: github.com/pentagridsec/i…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

Our advisory for Busybox cpio. When extracting cpio archives with BusyBox cpio, the cpio archiving tools may write files outside the destination directory and there is no option to prevent this.

Full advisory: pentagrid.ch/en/blog/busybo…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

Published advisory for Viseca, one of the larger credit card issuers in CH/FL. Vulnerability to download credit card statements (other business customers) -> coordinated disclosure
Advisory: pentagrid.ch/en/blog/viseca…
Republik (German): republik.ch/2023/03/20/kre…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

Today is tool day. We are releasing our Gateway tool. Attach your or your old from the grab box, insert SIM cards and forward to your e-mail box. And why not using it for Icinga SMS alerts?
pentagrid.ch/en/blog/open-s…

account_circle
Pentagrid AG(@pentagridsec) 's Twitter Profile Photo

We conducted a security analysis of the secure e-mail software SEPPmail – Deutschland GmbH 11.1.10 and found multiple vulnerabilities that have been fixed (and hopefully widely applied) by now pentagrid.ch/en/blog/multip…

account_circle