-
Recent Posts
Recent Comments
- MediaMarkt in The Wall gaat te slordig om met persoonsgegevens - Leidsche-Rijn on Password database of MediaMarkt leaks again
- Cine se afla in spatele protestelor #REZIST & Chilotareala on Massive child porn site is hiding in plain sight, and the owners behind it
- Photos d'enfants sur les réseaux sociaux | Cmic Blog on Massive child porn site is hiding in plain sight, and the owners behind it
- Pierre Dekan (via Twitter) on Massive child porn site is hiding in plain sight, and the owners behind it
- avocatnet.ro (via Twitter) on Massive child porn site is hiding in plain sight, and the owners behind it
Archives
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- April 2020
- February 2020
- December 2019
- October 2019
- August 2019
- July 2019
- June 2019
- May 2019
- April 2019
- March 2019
- February 2019
- January 2019
- December 2018
- November 2018
- October 2018
- September 2018
- July 2018
- June 2018
- May 2018
- April 2018
- March 2018
- February 2018
- January 2018
- December 2017
- November 2017
- October 2017
- September 2017
- August 2017
- July 2017
- June 2017
- May 2017
- April 2017
- March 2017
- February 2017
- January 2017
- December 2016
- October 2016
- July 2016
- June 2016
- May 2016
- March 2016
- February 2016
- January 2016
- December 2015
- November 2015
- October 2015
- July 2015
- March 2015
- February 2015
- November 2014
- September 2014
- July 2012
- March 2012
- May 2011
- April 2010
- July 2004
- January 1970
Categories
- advertising
- analysis
- anti-virus
- article
- automation
- backup
- banking
- biometrics
- bluetooth
- bnr nieuwsradio
- browser security
- bug
- camera
- chat-app
- child porn
- computer worm
- copyright
- critical infrastructure
- cross site scripting
- cryptography
- cyber crime
- cyber security
- cyber terrorisme
- cyber warfare
- data leakage
- ddos
- deanonymization
- demonstration
- discussion
- drive-by
- e-voting
- election hacking
- espionage
- fake profiles
- hacking
- hart van nederland
- identity theft
- internet of things
- interview
- javascript
- law enforcement
- magazine
- media
- menu
- mobile phone
- multi-factor authentication
- nos
- online banking
- online dating
- osint
- password
- pentesting
- phishing
- PHP
- PHP security
- podcast
- presentation
- privacy
- radio
- ransomware
- responsible disclosure
- russia
- SAP
- scam
- scoping
- search engine optimization
- security
- security advice
- security assessment
- security audit
- security awareness
- security management
- security monitoring
- security vulnerability
- seo
- smart devices
- software development
- telecom
- tv
- Uncategorized
- vulnerability management
- website
- website security
- WiFi
- wiretapping
- zero day
Meta
Category Archives: website security
Kassa: Het raadsel van de digitale inbraak bij Ticketmaster
Ticketmaster heeft alle wachtwoorden van klanten gereset, maar wil niet ingaan op wat er precies aan de hand is. Kassa nam daarom contact op met IT-deskundige Danny Mekić en mij en vroeg ons wat er aan de hand zou kunnen … Continue reading
Posted in cyber crime, data leakage, identity theft, password, security advice, security vulnerability, tv, website security
Comments Off on Kassa: Het raadsel van de digitale inbraak bij Ticketmaster
Twinkle Magazine: Zes tips om je webshop tegen hackers te beschermen
Hoe kun je als online retailer je shop en klanten het best beschermen tegen digitale aanvallen? E-commerce magazine Twinkle stelde me deze vraag en schreef het volgende:
Posted in interview, magazine, security advice, website security
Comments Off on Twinkle Magazine: Zes tips om je webshop tegen hackers te beschermen
Security assessment of Dutch election software
Last month I started an independent security assessment on the software that totalizes votes in the upcoming Dutch elections on March 21, 2018. The software is called OSV (Ondersteunende Software Verkiezingen) and made by German company IVU Traffic Technologies AG. … Continue reading
Posted in critical infrastructure, cyber warfare, e-voting, hacking, responsible disclosure, security assessment, tv, website security
Comments Off on Security assessment of Dutch election software
Websites Nederlandse politieke partijen onvoldoende beveiligd
In de recente hack bij de Democratische Partij in de VS (toen Hillary Clinton presidentskandidate was), werden Clinton en haar partij in diskrediet gebracht doordat bijna twintig duizend interne mails van de partijtop op internet zijn geplaatst door WikiLeaks. Eerder publiceerde WikiLeaks meer … Continue reading
Hoe hackbaar zijn onze politieke partijen?
NOS’ Nieuws & Co vroeg mij hoe hackbaar onze politieke partijen zijn. In opdracht van de NOS deed ik een snelle steekproef en keek in naar hun websitebeveiliging. Luister het complete Radio 1 fragment terug op: Update 13 januari 2017 … Continue reading
Posted in interview, radio, website security
Comments Off on Hoe hackbaar zijn onze politieke partijen?
Access to 250,000+ event tickets and personal details
In today’s episode of the insecure internet I present you the company Ticketscript. This event ticketing company provides tools and features to make selling tickets for events easier. According to their website: “[..] Ticket buyers are your biggest asset. Why … Continue reading
Hack demonstration at the WatchGuard symposium
Last week I demonstrated on the WatchGuard symposium how you can break into a website and into WiFi connections from mobile phones. It’s always very awesome to see the disbelief first on one side and then the enthusiasm from attendees … Continue reading
Posted in presentation, security awareness, website security, WiFi
Comments Off on Hack demonstration at the WatchGuard symposium
Interviewed by Lock Me Down podcast
Max McCarty from Lock Me Down podcast interviewed me for an hour (view the show notes) and we talked about web security and how software developers can improve it:
How I could hack internet bank accounts of Danish largest bank in a few minutes
In August I visited the Chaos Communication Camp near Berlin. Once every four years this great and world’s greatest hacker festival is organized. I spoke with a couple of cool Danish hackers there and we talked about internet security and … Continue reading
Posted in responsible disclosure, website security
183 Comments
Lukt het om in te breken in de website van Massa Media?
Die vraag stelde een TV-ploeg van RTV Utrecht mij:
Posted in hacking, website, website security
Comments Off on Lukt het om in te breken in de website van Massa Media?
Mitigations against critical universal cross-site scripting vulnerability in fully patched Internet Explorer 10 and 11
This week David Leo disclosed a critical universal cross-site scripting vulnerability in fully patched Microsoft Internet Explorer 10 and 11 (from now on called the UXSS leak). He notified Microsoft on October 13 last year, but Microsoft didn’t publish a … Continue reading
2.364 Nederlandse bedrijfswebsites met ernstige beveiligingslekken
Toen ik in oktober 2012 op internet op zoek was naar een nieuwe auto, kwam ik een autobedrijf tegen waar ik een auto wou gaan kopen: (bovenstaande website is van een willekeurig bedrijf uit de lijst die ik later beschrijf) … Continue reading