Это статья о клиентских уязвимостях, которые мне показались интересными.Целью статьи является показать, что иногда из, казалось бы, скучных уязвимостей с низким импактом, можно выжимать больше, чем кажется. Читать далее
Встраиваемый холодильник Side-by-Side (HANSEL GRETEL)Общие данные:Размеры:высота: 177 смширина: 110 см (55 каждый)глубина: 54.5 смОбщий объем/ Полезный объем: Холодильника (л): 524/497 Холодильной камеры (л): 303/300 Морозильной камеры (л): 221/197Тип управления: электронныйКласс энергопотребления: A/AКлиматический класс: SN-T (от 10С до 43С)Количество компрессоров: 2...Read more
Fresenius Kabi Vigilant Software Suite (Mastermed Dashboard) version 2.0.1.3 allows user input to be validated on the client side without authentication by the server. The server should not rely on the correctness of the data because users might not support or block JavaScript or intentionally bypass the client-side checks. An attacker with knowledge of the service user could circumvent the client-side control and login with service privileges.
The Diffie-Hellman Key Agreement Protocol allows remote attackers (from the client side) to send arbitrary numbers that are actually not public keys, and trigger expensive server-side DHE modular-exponentiation calculations, aka a D(HE)ater attack. The client needs very little CPU resources and network bandwidth. The attack may be more disruptive in cases where a client can require a server to select its largest supported key size. The basic attack scenario is that the client must claim that it can only…