Coinbase User Enumeration

Posted by stephen () averagesecurityguy info on Dec 08

Coinbase User Enumeration
=========================
The Coinbase web site allows user enumeration, which would normally not be a big deal, but in this case, we are able to
enumerate a users username, “real name”, and an MD5 hash of the user’s email address. Using a large list of email
addresses and a tool like hashcat it is possible to determine the email address for many of these users. Keep in mind
that the real name is user…

CVE-2014-3616

nginx 0.5.6 through 1.7.4, when using the same shared ssl_session_cache or ssl_session_ticket_key for multiple servers, can reuse a cached SSL session for an unrelated context, which allows remote attackers with certain privileges to conduct “virtual host confusion” attacks. (CVSS:4.3) (Last Update:2014-12-08)