Author: Farica

eye surveillance watching

Paranoid or Prepared? The spies on your desk

I usually receive questions about why I have a sticker on ambient light sensors my laptops and phone. Some think I don't know the difference between a light sensor and a camera and try to explain to me that this is not a camera. Na ka era sega ni kila oya ni ambient light sensors e rawa ni…
Wilika eso tale na ka

The ancient world's biggest security failure: Security lessons from the Valley of the Kings

Thanks to Mastercard’s long annual leave (we have 25 days!) I took a two week trip to Egypt earlier this month to visit a place I have always wanted to see: the burial tombs of the ancient pharaohs in the Valley of the Kings. As a security engineer, I could not help looking at these
Wilika eso tale na ka

Cybersecurity jobs

How to land an entry level cybersecurity job

This post is a response to a friend who is seeking a cybersecurity role in an extremely challenging market. Given that this is a widespread issue these days, I decided to write a post rather than simply leaving a comment. Various statistics from multiple sources suggest that there is a wide gap in cybersecurity roles,…
Wilika eso tale na ka

WaterHole attack

Watering hole attacks: how APT and cyber criminals infiltrate secure infrastructures

My first encounter with the world of cyber-criminals happened through a watering hole attack campaign many years ago. I visited a Persian website and found that it was downloading malware into visitors’ browsers. I immediately contacted the site administrator, who told me that they had no technical knowledge of the issue. It became obvious that…
Wilika eso tale na ka

credential stuffing

Credential stuffing is no DDoS!

Au sa rogoca tiko oqo vakalevu ena loma ni yabaki sa oti: e dua e sotava tiko e dua na vakavulewa levu ni DDoS ena nodrau website. Ni'u tarogi koya na kena leqa ni vakawati vakaevei na kena sotavi, na isau e dau vakamacalataki ni na vakayacori vei ira na ca e vakauta vei ira e vaqa na liba se milioni ni POST requests. Ni'u…
Wilika eso tale na ka

vakavakarau ni DDoS ni porokaramu

Vakavakarau ni DDoS ni porokaramu ni lvayala, kei na kena rawa ni vakayacori kina na tosoi

DDoS (distributed denial of service) kei na DoS (denial of service) na vakavakarau e rawa ni vakaduri vakataki ira e tolu me salavata kei na layers ni OSI model era dikeva: network layer (Layer 3), transport layer (Layer 4), kei na application layer (Layer 7). Layer 3 kei na Layer 4 na vakavakarau e dau sega ni dredre cake–ena gauna e rawa ni…
Wilika eso tale na ka

Web Application Firewall (WAF)

Na WAF e mate oti, rai ni bula na WAF!

Na vula ni web application firewall (WAF) is a security tool used to protect from unwanted access to web applications. It is often a security device that sits on top of a web server and guards against threats from the internet or from beyond the network perimeter. Unlike Layer 3 (Network) kei na Layer 4 (Transport) firewalls, which…
Wilika eso tale na ka

Cookies o Kila Kilai Oqai

iWalewale ni kena walii na iwalewale vou ni kena vakadikevi; Cookies ni Veikauqaqa kei na iYagavulu ni Yavaqaso

iYqaqa ni yava ivakatakata, E ka vou na dausaro cookies kei na Kadrala; ia, era sa torocake na iwalewale oqo ka sa yaco me mana sara vakalevu ena veigauna. Wale tikoga oqo, e dua na vakanananu e vakamacalataka ni dua mai na va na tamata 10,000 na ivavakoso e vakayagataki vakalevu ena initaneti e vakayagataka na canvas fingerprinting me vakamatei ira na lewe i visiter ena rawarawa ni kena tuuta oqo 99.9% i vakamacala dina. Na yalo ni vakamatei me taura…
Wilika eso tale na ka

PHP Suhosin

Na icavacava kei Suhosin; na cava e tarava?

Ena vuqa na yabaki, Au sa dau vakayagataki Suhosin ena dua na ivakavakaravutaki ni PHP5 ena Apache2 se PHP-FPM Nix webservers me ra taqomaka mai na icula ni SQL kei na veicacati tale eso ni veilawa. E dina ga, PHP5 e a cala vakalevu, sega ga ena nona qaravi ni veivakadei vou, kei na nona ituvatuva kei na iyaya ka’u a sega ni guilecava me’u dau vakayagataka…
Wilika eso tale na ka

Voroki ni iLati