Information Security Weekly Newsletter
Information Security Weekly Newsletter

Top new questions this week:

What to do when I found a spyware that my spouse has installed?

Today I was trying to uninstall some application and I was very surprised to see this entry in my applications list Then I try to find what is this and I finally found it in "Program Files". After …

forensics incident-response spyware  
asked by Green Fly 33 votes
answered by Rob Church 36 votes

Why should one avoid chains of SSH sessions?

In this document on Security on NSC computing resources, there are several obvious pieces of advice (use a strong password, don't repeat passwords, etc.). One piece of advice I have not seen before, …

authentication ssh  
asked by gerrit 11 votes
answered by Olivier Dulac 8 votes

Is it a good practice to show 403 unauthorized access error to user?

Whenever we see a 403 forbidden access error page we think we have got to a place where some secret or private data is present. Now at this point bad guys know that this might be of interest and start …

http data-leakage  
asked by ThankYouSRT 8 votes
answered by Adnan 4 votes

Site preventing user from closing tab/closing browser

I've come across the following website hxxp://politie.nl.id169787298-7128265115.e2418.com/ [Possible malware] Whenever I open it in Firefox it prevents me from closing it, I can't even close the …

web-browser  
asked by user2180680 8 votes
answered by Bob 10 votes

Suspicious activity on contact form, what are their intentions?

I've just started receiving several emails per second and I think it's likely someone is trying to exploit my contact form. I've taken steps to protect my site, I'm just curious what it is they're …

exploit hacking  
asked by Scott Helme 5 votes
answered by Abe Miessler 5 votes

How to destroy VOIP phone in a proper way?

Are there standards which consider safe destroying of VOIP phones? I would like to prevent eventual data leakage after devices will left the company. Thanks in advance for help!

physical data-leakage voip  
asked by boleslaw.smialy 4 votes
answered by Lucas Kauffman 4 votes

Browsers silently adding trusted root certificates in Windows

When accessing https://internetbanking.caixa.gov.br (site of a well known bank in Brazil), the server returns a certificate signed by "Autoridade Certificadora Raiz Brasileira" (Brazilian Root …

windows web-browser certificate-authority  
asked by BoppreH 3 votes
answered by mcgyver5 2 votes

Greatest hits from previous weeks:

How to block some websites and torrent usage in a small office?

In my office there are approaximately 25 systems are connected through network and all having internet accessibility.but some people are missusing this facilities like downloading films from torrent …

network  
asked by shibinlal 3 votes
answered by AbsoluteĈµERØ 7 votes

What is certificate pinning?

I'm superficially familiar with SSL and what certs do. Recently I saw some discussion on cert pinning but there wasn't a definition. A DDG search didn't turn up anything useful. What is certificate …

ssl certificates public-key-infrastructure  
asked by Avery Chan 22 votes
answered by tylerl 21 votes

Can you answer these?

Suggestions on easy distribution/installation of self signed certificates & roots to mobile devices

Suggestions on easy distribution/installation of self signed certificates & roots to mobile devices I am a developer at a government agency in a developing country that has a web application with …

public-key-infrastructure  
asked by darz 2 votes

Can a mismatched server encoding on HTTP POST or GET result in a security issue?

It is possible for a server to parse HTTP POST and GET data with a fixed encoding or one that is dynamic with the client's response. Consider the situation where a client uses UTF7,32 or any other …

web-application appsec asp.net encoding asp.net-mvc  
asked by makerofthings7 1 vote

A crash/mini dump concern

I just experienced a crash on my laptop. I was surfing the internet and all of a sudden everything crashed and a small blue screen (centred on the screen) popped up and was counting down. I didn't …

windows  
asked by Reanimation 1 vote
Subscribe to more Stack Exchange newsletters


Unsubscribe from this newsletter or change your email preferences by visiting your subscriptions page on stackexchange.com.

Questions? Comments? Let us know on our feedback site. If you no longer want to receive mail from Stack Exchange, unsubscribe from all stackexchange.com emails.

Stack Exchange, Inc. 110 William St, 28th Floor, NY NY 10038 <3