Rafael Ortiz is a user on infosec.exchange. You can follow them or interact with them if you have an account anywhere in the fediverse. If you don't, you can sign up here.

So many [recent] examples of no validation/verification/authentication. Pathetic. Negligence, pure and simple. Not like SQLi is ~20 years old...

¯\_(ツ)_/¯ 💩 🔥

Pacemakers, TrendMicro AV, automated email, SQLi for years,

t.co/wDI39Kzi6Y

blog.whitescope.io/2017/05/und

coresecurity.com/advisories/tr

@sten0_SE security adds no marginal sales value.

Rafael Ortiz @Senicar

@jerry @sten0_SE

I happened across an IoT device once that validated new firmware in-browser with javascript. You could trivially bypass the verification and upload a firmware with a backdoor. Also default hardcoded credentials to access the firmware upload page. It's like they're not even trying. Contact the vendor? "We no longer support that model, you should upgrade to the newest and shiniest hardware."

· Web · 8 · 3

@Senicar @sten0_SE the newest model, which likely has the same problem. But yeah, this is the major issue with iot

@jerry @sten0_SE extracting the latest and greatest firmware and briefly inspecting the contents seems to support this hypothesis...