-
Recent Posts
- BNR radio-interview: Hackbare gemeenteraadsverkiezingen en intransparantie daarvan
- De fraudegevoeligheid van Nederlandse verkiezingen
- Security assessment of Dutch election software
- 3FM radio interview: Gehackte sauna camerabeelden
- De verborgen wereld van Nederlandse nepdatingsites met nepprofielen en teams van chatoperators
Recent Comments
- MediaMarkt in The Wall gaat te slordig om met persoonsgegevens - Leidsche-Rijn on Password database of MediaMarkt leaks again
- Cine se afla in spatele protestelor #REZIST & Chilotareala on Massive child porn site is hiding in plain sight, and the owners behind it
- Photos d'enfants sur les réseaux sociaux | Cmic Blog on Massive child porn site is hiding in plain sight, and the owners behind it
- Pierre Dekan (via Twitter) on Massive child porn site is hiding in plain sight, and the owners behind it
- avocatnet.ro (via Twitter) on Massive child porn site is hiding in plain sight, and the owners behind it
Archives
- March 2018
- February 2018
- January 2018
- December 2017
- November 2017
- October 2017
- September 2017
- August 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- October 2016
- July 2016
- June 2016
- May 2016
- March 2016
- February 2016
- January 2016
- December 2015
- November 2015
- October 2015
- July 2015
- March 2015
- February 2015
- November 2014
- September 2014
- September 2012
- July 2012
- May 2012
- March 2012
- October 2011
- September 2011
- August 2011
- July 2011
- June 2011
- May 2011
- February 2011
- January 2011
- December 2010
- September 2010
- June 2010
- April 2010
- March 2010
- August 2006
- January 2005
- July 2004
- January 1970
Categories
- advertising
- analysis
- Apple
- article
- backup
- banking
- browser security
- bug
- camera
- child porn
- computer worm
- copyright
- credit card
- critical infrastructure
- cross site scripting
- cyber crime
- cyber terrorisme
- cyber warfare
- data leakage
- ddos
- deanonymization
- discussion
- drive-by
- e-voting
- election hacking
- hacking
- ICT
- interview
- jargon
- javascript
- legal
- magazine
- media
- menu
- online banking
- online dating
- osint
- password
- pentesting
- phishing
- PHP
- PHP security
- podcast
- presentation
- privacy
- process improvement
- radio
- ransomware
- responsible disclosure
- russia
- SAP
- scam
- scoping
- search engine optimization
- security
- security assessment
- security audit
- security awareness
- security vulnerability
- seo
- SNS Bank
- software development
- test
- tv
- Uncategorized
- vulnerability management
- w3c
- website
- website security
- WiFi
- wiretapping
- workshop
- zero day
Meta
Category Archives: security assessment
Security assessment of Dutch election software
Last month I started an independent security assessment on the software that totalizes votes in the upcoming Dutch elections on March 21, 2018. The software is called OSV (Ondersteunende Software Verkiezingen) and made by German company IVU Traffic Technologies AG. … Continue reading
Posted in critical infrastructure, cyber warfare, e-voting, hacking, responsible disclosure, security assessment, tv, website security
Comments Off on Security assessment of Dutch election software
‘Een patchkast hacken? Fluitje van een cent’
Cobouw heeft me geïnterviewd over de digitale dreigingen die de bouwsector loopt tegenwoordig:
Posted in cyber crime, hacking, interview, magazine, phishing, security assessment, security awareness
Comments Off on ‘Een patchkast hacken? Fluitje van een cent’
Security awareness sessie voor ambtenaren tijdens Zaakgericht Werken congres
Vandaag heb ik op het Zaakgericht Werken in de Overheid congres een presentatie mogen geven over wat er mis is gegaan in het digitaliseringsproces van onze verkiezingen, en wat we hier van hebben kunnen leren. Met de opkomst van Zaakgericht … Continue reading
Posted in e-voting, hacking, presentation, security assessment, security awareness, software development
Comments Off on Security awareness sessie voor ambtenaren tijdens Zaakgericht Werken congres
NOS: “Zeker 15 van de 25 ziekenhuizen geïnfecteerd met ransomware”
De NOS bericht vandaag: Zeker 15 van de 25 ziekenhuizen geïnfecteerd met ransomware Nederlandse ziekenhuizen zijn kwetsbaar voor aanvallen met een gijzelvirus. Zeker vijftien Nederlandse ziekenhuizen hebben de afgelopen drie jaar te maken gehad met zulke ransomware-aanvallen. In één ziekenhuis … Continue reading
Posted in cyber crime, cyber terrorisme, data leakage, drive-by, interview, radio, ransomware, security assessment, security awareness, tv
Comments Off on NOS: “Zeker 15 van de 25 ziekenhuizen geïnfecteerd met ransomware”
Cqure Quick Question: over (non)scoping bij pentests
Cqure nodigde me uit om te komen praten over de scoping van pentesten: Cqure: “Sijmen Ruwhof van Secundity vertelt deze week in de Cqure Quick Question over (non) scoping bij pentests. Sijmen vertelt in deze video dat veel pentesten in … Continue reading
Posted in hacking, interview, pentesting, scoping, security assessment
Comments Off on Cqure Quick Question: over (non)scoping bij pentests
Websites Nederlandse politieke partijen onvoldoende beveiligd
In de recente hack bij de Democratische Partij in de VS (toen Hillary Clinton presidentskandidate was), werden Clinton en haar partij in diskrediet gebracht doordat bijna twintig duizend interne mails van de partijtop op internet zijn geplaatst door WikiLeaks. Eerder publiceerde WikiLeaks meer … Continue reading
How to hack the upcoming Dutch elections – and how hackers could have hacked all Dutch elections since 2009
As everybody has read in the newspapers, the recent American elections involved multiple and severe hacking attacks. Tens of thousands of confidential and private emails from Hillary Clinton and the Democratic National Committee (DNC) were leaked via WikiLeaks. It is thought … Continue reading
How I accidentally found a huge data leak during a college lecture
A few weeks ago I gave a guest lecture at the Windesheim University of Applied Sciences in The Netherlands. Being a Windesheim graduate myself I’ve always kept in touch with my former teachers. One of them told me recently that … Continue reading
Posted in responsible disclosure, security assessment
44 Comments
Epic failure of Phone House & Dutch telecom providers to protect personal data: How I could access 12+ million records #phonehousegate
On September 11, 2015 I visited MediaMarkt in Utrecht Hoog Catherijne, a well-known electronics shop in The Netherlands. Since summer 2014, the biggest independent Dutch phone retail company Phone House also operates (white labeled) from within MediaMarkt locations as a … Continue reading
Full disclosure: multiple critical security vulnerabilities (including a backdoor!) in PHP File Manager
In July 2010 I was looking for a web based file manager that I could use on my own web server. After some research I found the PHP File Manager from Revived Wire Media. A basic, but good looking web … Continue reading
Veiligheidsanalyse iDEAL Lite bijgewerkt
Naar aanleiding van het overleg met Rabobank Nederland is het rapport over de iDEAL Lite voorbeeldcode bijgewerkt met nieuwe informatie.
Posted in responsible disclosure, security assessment
Comments Off on Veiligheidsanalyse iDEAL Lite bijgewerkt