usd Herolab Navigation
  • Our Services
  • About us
    • The Way We Work
    • Our Experts
    • Our Platforms and Tools
  • Security Research
    • Our Commitment
    • Security Advisories
    • Responsible Disclosure Policy
  • LabNews
  • Meet The Team
  • usd AG
  • Deutsch
  • Search
  • Our Services
  • About us
    • The Way We Work
    • Our Experts
    • Our Platforms and Tools
  • Security Research
    • Our Commitment
    • Security Advisories
    • Responsible Disclosure Policy
  • LabNews
  • Meet The Team
  • usd AG
  • Deutsch
  • Search

News

Below you'll find a list of all posts that have been categorized as “News”

Security Advisory 01/2021

usd AG 29. January 2021 News, Security Advisories

usd HeroLab penetration testers have identified a path traversal vulnerability during security analyses. This vulnerability affects the product Mailoptimizer. In accordance with usd HeroLabs Responsible Disclosure Policy, the vendor has been notified of the existence of this vulnerability. In the …

Read more
Security Researchzero-day vulnerabilities

Security Advisories 10/2020

usd AG 27. October 2020 News, Security Advisories

usd HeroLab penetration testers have identified several security vulnerabilities during security analyses. These vulnerabilities affect the products OScommerce Phoenix CE, NeoPost Mail Accounting Software und SQL Server Management Studio. The following vulnerability classes were identified: Authenticated Remote Code Execution Cross …

Read more
Security Researchzero-day vulnerabilities

Security Advisory 09/2020

usd AG 29. September 2020 News, Security Advisories

usd HeroLab penetration testers have identified several security vulnerabilities during security analyses. These vulnerabilities affect the products Gophish and Net-SNMP. The following vulnerability classes were identified: Stored Cross-Site Scripting Non-persistent Self Cross-Site Scripting Clickjacking CSV Injection Insufficient Session Expiration Elevation …

Read more
Security Researchzero-day vulnerabilities

Hack The Box: Fatty Writeup

usd AG 8. August 2020 News

A full walkthrough of the Hack The Box “Fatty” machine, written by the machine maker (qtc).

Hack The Box: Oouch Writeup

usd AG 1. August 2020 News

A full walkthrough of the Hack The Box “Oouch” machine, written by the machine maker (qtc).

Security Advisory 07/2020

usd AG 15. July 2020 News, Security Advisories

usd HeroLab penetration testers have identified several security vulnerabilities during security analyses. These vulnerabilities affect the products Bitbucket Server and Concrete5 CMS. The following vulnerability classes were identified: Server-Side Request Forgery Unencrypted Service Code Injection In accordance with usd HeroLabs …

Read more
PentestSecurity Researchzero-day vulnerabilities

Security Advisory 06/2020

usd AG 18. June 2020 News, Security Advisories

usd HeroLab penetration testers have identified several security vulnerabilities during security analyses. These vulnerabilities affect the products Symantec Endpoint Protection (Broadcom), Gambio GX and NCP Secure Enterprise Client. The following vulnerability classes were identified: Privileged File Write Cross-Site-Request-Forgery (CSRF) Blind …

Read more
PentestSecurity Researchzero-day vulnerabilities

Catching the phishes

usd AG 6. May 2020 News

Florian Haag, dual student in computer science at usd HeroLab, developed a tool chain to automatically detect cloned websites related to phishing attacks during his practical semester at the University of Applied Sciences Darmstadt. Here he gives us an introduction …

Read more
Cloned WebsitesPhishingphishing websites

Security Advisory 04/2020

usd AG 29. April 2020 News, Security Advisories

usd HeroLab penetration testers have identified several security vulnerabilities during security analyses. These vulnerabilities affect the products Control-M/Agent, Chocolatey, Zencart, Starface UCC Client and Userlike Chat. The following vulnerability classes were identified: Cross-Site Scripting (XSS) Insufficient Filtering OS Command Injection …

Read more
PentestSecurity Researchzero-day vulnerabilities

Pentest Scope: How to Determine the Testing Scope?

usd AG 8. April 2020 News

Pentests are one of the most effective security analysis methods to check the IT security level of a company and identify opportunities for sustainable improvements. In addition, proof of conducting a pentest is an important component of many compliance requirements, …

Read more
Pentestpentest preparatory steps
  • Page 1 of 4
  • 1
  • 2
  • 3
  • ...
  • 4
  • →

Categories

  • News
  • Security Advisories

usd AG

  • Contact
  • Imprint
  • Privacy Protection
  • General Terms and Conditions

© 2020 usd AG

  • Report a vulnerability or bug
  • Code of Ethics

Follow us: Bild Bild Bild Bild Bild Bild Bild

LabNews

Security Advisory 01/2021

29. January 2021

Security Advisories 10/2020

27. October 2020

Security Advisory 09/2020

29. September 2020

  • Contact
  • Imprint
  • Privacy Protection
  • General Terms and Conditions