A RiskIQ researcher is catching some flak on social media for showing how some people using the dark web are misconfiguring their Tor servers enabling them to be identified.Bleeping Computer first reported how Yonathan Klijnsma, a RiskIQ threat researcher explained how by using one of his company’s tools that crawls the web searching for SSL certificates and then matching them to its hosted IP address. So Klijnsma used these to find a misconfigured hidden Tor server by using that public IP address.Klijnsma told Bleeping Computer the primary mistake being made by those configuring the server “is they have their local Apache or Nginx server listening on any (* or 0.0.0.0) IP address” instead of the safe 127.0.0.1. He then uses the RiskIQ database to search for .onion certificates and checks them against the public IP they are mapped to, Bleeping Computer wrote.Klijnsma’s efforts to help educate those possibly leaving themselves open to being identified incurred the researcher enough wrath for him to tweet:
There are many ways to do DevSecOps, and each organization — each security team, even — uses a different approach. Questions such as how many environments you have and the frequency of deployment of those environments are important in understanding how to integrate a security scanner into your DevSecOps machinery. The ultimate goal is speed […]
It’s Cybersecurity Awareness Month, but security awareness is about much more than just dedicating a month to a few activities. Security awareness is a journey, requiring motivation along the way. And culture. Especially culture.That’s the point Proofpoint Cybersecurity Evangelist Brian Reed drove home in a recent appearance on Business Security Weekly.“If your security awareness program […]
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news