Trusted Platform Module (TPM) 2.0 flaws could impact billions of devices

Two vulnerabilities affecting the Trusted Platform Module (TPM) 2.0 library could potentially lead to information disclosure or privilege escalation. The Trusted Computing Group (TCG) is warning of two vulnerabilities affecting the implementations of the Trusted Platform Module (TPM) 2.0 that could potentially lead to information disclosure or privilege escalation. The Trusted Platform Module (TPM) technology […]

The post Trusted Platform Module (TPM) 2.0 flaws could impact billions of devices appeared first on Security Affairs.

WebGoat 2023.4 Hijack a session

I was wondering has anyone play around with WebGoat and solve thier “Hijack a session”?

I’m using latest version which you can find at https://github.com/WebGoat/WebGoat/releases/tag/v2023.4

Download the jar file, and run it with java -jar webgoat-2023.4.jar to bring up the lab

I sent the session to repeater and noticed that “hijack_cookie” is predictable. The 1st part is easy where it is incremented by one from 90 to 95, and so on

However, the second part is little bit tricky. I’ve been looking at this for hours and I can’t figure it out yet

Set-Cookie: hijack_cookie=5183292529236277390-1677844963222; Set-Cookie: hijack_cookie=5183292529236277391-1677844963782; Set-Cookie: hijack_cookie=5183292529236277392-1677844966110; Set-Cookie: hijack_cookie=5183292529236277393-1677845094872; Set-Cookie: hijack_cookie=5183292529236277394-1677845115207; Set-Cookie: hijack_cookie=5183292529236277395-1677845755408; 

Not really sure if it’s feasible to brute force the 2nd part.

Checked the hint and found this, nothing useful as I already know the pattern is predictable, but don’t know how

Hint: Check the ‘hijack_cookie’ cookie value and think about its format.

If any of you have solved this, feel free to share your knowledge on how to solve this. Thank you

submitted by /u/w0lfcat
[link] [comments]

False positives when cracking shadow files

Does anyone else get frequent false positives when cracking shadow files using John and rockyou? Can anyone offer any tips on how to avoid them? submitted by /u/No-Manner3916 [link] [comments]

The U.S. CISA and FBI warn of Royal ransomware operation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of the capabilities of the recently emerged Royal ransomware. The human-operated Royal ransomware first appeared on the threat landscape in September 2022, it has demanded ransoms up to millions of dollars. Unlike other ransomware operations, Royal doesn’t offer Ransomware-as-a-Service, it appears to be a private group without […]

The post The U.S. CISA and FBI warn of Royal ransomware operation appeared first on Security Affairs.

Retailer WH Smith discloses data breach after a cyberattack

Retailer WH Smith disclosed a data breach following a cyber attack, threat actors had access to access company data. Retailer WH Smith revealed that threat actors have breached its infrastructure and had access to the data of about 12,500 current and former employees. The company immediately launched an investigation into the incident with the help […]

The post Retailer WH Smith discloses data breach after a cyberattack appeared first on Security Affairs.