Who: Shakacon Crew
What: Shakacon VII
When: July 6-7 (Training) & July 8-9 (Conference) 2015
Where: Honolulu, HI – Hawaii Prince Hotel Waikiki
Why: World Class Speakers,…
yesterday Microsoft published the security advisory 3004375
<https://technet.microsoft.com/en-us/library/security/3004375>
announcing an update which enables Windows 7 and newer to log
the command lines used to start processes to the event log.
In my research I found out that the ‘x-frame-options’ solution doesn’t
protect against session hijacking via session cookie theft. It is very
important that you also need to add ‘HttpOnly’ flags on all cookies.
I’ve published an overview of my research, additional mitigations and
supporting evidence in a web log article:
Ticket opened: 2014-06-25
Affected Versions: ALL
Problem: No CSPRNG
Patch available, collecting dust because of negligent (and questionably
competent) WP maintainers
On June 25, 2014 I opened a ticked on WordPress’s issue tracker to expose a
cryptographically secure pseudorandom number generator, since none was
present (although it looks like others have tried to hack together a
band-aid solution to mitigate php_mt_seed until WordPress gets…