Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Pentagrid AG

@pentagrid@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Pentagrid performs technically solid IT security assessments.

152 Followers
2 Following
22 Posts
Joined November 10, 2022
Location:
Buchs SG, Switzerland
Web:
https://www.pentagrid.ch
Imprint:
https://www.pentagrid.ch/en/pages/imprint-and-contact/
Linkedin:
https://www.linkedin.com/company/pentagrid/
Github:
https://github.com/pentagridsec
Codeberg:
https://codeberg.org/pentagridsec
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 30mo ago

This is not a late April Fool's joke: After #37C3, we accidentally dumped the keypad codes of almost half of an IBIS hotel's rooms by entering some dashes into a check-in terminal: https://www.pentagrid.ch/en/blog/ibis-hotel-check-in-terminal-keypad-code-leakage/ #itsecurity #infosec #ibis #accor #terminal #hotel

IBIS hotel check-in terminal keypad-code leakage
Pentagrid AG

IBIS hotel check-in terminal keypad-code leakage

An IBIS hotel check-in terminal leaked room door key codes of almost half of the rooms.

182
7
144
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 4mo ago

Parsing modern ASP.NET Core Identity password hashes for password cracking with hashcat. https://www.pentagrid.ch/en/blog/parsing-modern-aspnet-core-identity-password-hashes-to-hashcat/ #itsecurity #infosec #hashcat #asp #dotnet

Pentagrid AG

Parsing modern ASP.NET Core Identity password hashes to Hashcat

Parsing modern (.NET 7.0+) and old ASP.NET Core Identity password hashes of v2 and v3 supporting PBKDF2+HMAC-SHA1, PBKDF2+HMAC-SHA256, and PBKDF2+HMAC-SHA512.

3
0
9
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 10mo ago

At Pentagrid, we occasionally review our clients' internal processes to identify IT security risks. When we discovered that large sums of money are transferred with just a few clicks and no transaction verification, we helped securing the process. At the same time, we developed a tool to support this improvement. #itsecurity #infosec #iso200222 #pain001 https://www.pentagrid.ch/en/blog/pain001-interfaces-and-payment-of-your-salary/

ISO 20022, Pain001 and payment of your salary
Pentagrid AG

ISO 20022, Pain001 and payment of your salary

Pain001 are a common way to instruct banks to send large amounts of money to different recipients, often sent via insecure channel and no interface for transactions reviews.

1
0
1
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 37mo ago

We analysed the security of a #WindRiver #VxWorks (the operating system running also on NASA's Curiosity mars rover) embedded device and found a critical vulnerability in the #tarExtract function: https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/ #itsecurity #infosec #pentesting #cisa #vxworks

pentagrid.ch
5
0
7
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 28mo ago

Today, our certificate transparency monitoring popped up with an InvalidSignature exception, because we didn't add the recent Let's Encrypt intermediate CAs as monitoring trust anchors. We updated the documentation accordingly, but it is good to see it working. If you want to monitor your certificates, you may run your own instance. https://github.com/pentagridsec/check-transparency-logs

GitHub

GitHub - pentagridsec/check-transparency-logs: Retrieve server certificate data from transparency logs or APIs and compare it to certs we know we have.

Retrieve server certificate data from transparency logs or APIs and compare it to certs we know we have. - pentagridsec/check-transparency-logs

3
0
3
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 33mo ago

Multiple vulnerabilities in Lantronix EDS-MD IoT gateway for medical devices: https://www.pentagrid.ch/en/blog/multiple-vulnerabilties-in-lantronix-eds-md-iot-gateway/ #itsecurity #infosec #pentesting #lantronix #iot #medical

Multiple vulnerabilities in Lantronix EDS-MD IoT gateway for medical d
Pentagrid AG

Multiple vulnerabilities in Lantronix EDS-MD IoT gateway for medical d

The Lantronix EDS-MS is an "IoT gateway for mission critical medical devices and equipment connectivity". It is affected by multiple vulnerabilities.

3
0
5
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 35mo ago

Summer is clearly over and silly season, too. We saw neither alligators in the swimming lake nor lions in town, but a a snake curling through the infrastructure. It was a #python. A few email-related Python libraries do not check server certificates. It is nothing new, but still a bit surprising in 2023 and not everyone got the memo.

https://www.pentagrid.ch/en/blog/python-mail-libraries-certificate-verification/
#itsecurity #infosec #pentesting #python #email #bugbounty

Nothing new, still broken, insecure by default since then: Python's e-
Pentagrid AG

Nothing new, still broken, insecure by default since then: Python's e-

Python’s e-mail libraries smtplib, imaplib, and poplib do not verify server certificates unless a proper SSL context is passed to the API. This leads to security problems.

3
0
2
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 28mo ago

Our colleague Michael will be speaking about #Unify #OpenScape and #OpenStage #VoIP phones at the #Area41 security conference in Zurich on June 6. If you use these VoIP systems, we recommend coming to the talk.

2
0
2
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 22mo ago

A story about looking at the effectiveness of web application firewalls and finding bypasses for the filter ruleset. https://www.pentagrid.ch/en/blog/airlock-web-application-firewall-ruleset-testing-and-waf-bypasses/ #WAF #OWASP #coreruleset #ergon #airlock

An excursion into Airlock WAF ruleset testing
Pentagrid AG

An excursion into Airlock WAF ruleset testing

A story about looking at the effectiveness of web application firewalls (WAFs) and finding bypasses for the filter ruleset.

1
0
4
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 22mo ago

Pentagrid published two #Hackvertor tags for #EAN13 (also Swiss AHV numbers) and #TOTP for #2FA. These tags are available via the Hackvertor Tag Store by @garethheyes@bird.makeup. Our blog post explains what these tags do and how they can be used. https://www.pentagrid.ch/en/blog/hackervertor-ean13-and-totp-tags-for-web-application-penetration-testing-with-burp/ #pentest #OWASP

Hackvertor EAN-13 and TOTP tags for web-application penetration testin
Pentagrid AG

Hackvertor EAN-13 and TOTP tags for web-application penetration testin

Using Hackvertor tags for Swiss social security number and EAN-13 generation and for second factor authentication with TOTP in web pentests.

1
1
3
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 36mo ago
Replying to
I think a 9.0 for CVS-2023-42629 is a bit overrated, because of PR:L, but anyway Liferay publishes an advisory for this: https://liferay.dev/portal/security/known-vulnerabilities/-/asset_publisher/jekt/content/cve-2023-42629
Liferay

CVE-2023-42629 Stored XSS vulnerability with vocabulary description - Liferay

2
0
0
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 31mo ago

#SQLinjection in login dialog of web-based #YABOOK harbour administration allows authentication bypass
https://www.pentagrid.ch/en/blog/sql-injection-in-port-administration-software-yabook/
#pentest #sailing #hafenverwaltung #imonaboat

SQL injection in YABOOK port administration allows authentication bypa
Pentagrid AG

SQL injection in YABOOK port administration allows authentication bypa

An SQL injection on the login page of the YABOOK port administration allows authentication to be bypassed and disclosure of all data.

1
0
3
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 34mo ago
Replying to
♫ Ground control to Major Tom, take the patch and put secure mode on. ♫ https://github.com/pentagridsec/openstage-exploit-chain #openstage #openscape #unify
GitHub

GitHub - pentagridsec/openstage-exploit-chain: Multiple vulnerabilities in Mitel Unify OpenStage and OpenScape phones allow a remote compromise in the unhardened default configuration and an elevation of privileges to become the root user.

Multiple vulnerabilities in Mitel Unify OpenStage and OpenScape phones allow a remote compromise in the unhardened default configuration and an elevation of privileges to become the root user. - pe...

1
2
2
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 36mo ago

Wir haben ein Werkzeug in Python geschrieben, dass Dateiarchive wie zip, tar und cpio generiert welche Path Traversal Angriffe beinhalten: https://www.pentagrid.ch/de/blog/archive-pwn-tool-release/ #itsicherheit #informationssicherheit #pentesting

Archive Pwn tool released
Pentagrid AG

Archive Pwn tool released

Archive Pwn is a Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes

1
0
2
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 36mo ago

We wrote a tool in Python to create file archives such as zip, tar and cpio that include path traversal attacks: https://www.pentagrid.ch/en/blog/archive-pwn-tool-release/ #itsecurity #infosec #pentesting

Archive Pwn tool released
Pentagrid AG

Archive Pwn tool released

Archive Pwn is a Python-based tool to create zip, tar and cpio archives to exploit common archive library issues and developer mistakes

1
0
3
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 24mo ago

Pentagrid is looking for an IT security analyst (d/f/m) in Buchs SG, Switzerland. https://www.pentagrid.ch/en/pages/career/ #FediHire #infosec

Career
Pentagrid AG

Career

Open job postings for IT-Security Analysts, Penetration testers and Red Teamer

0
0
4
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 28mo ago

If you want to protect your IT #infrastructure against #MITM attacks where an attacker bypasses domain verification to obtain valid certificates, you may want to use #CAA and #accountURI binding, which is easy to set up. https://www.pentagrid.ch/en/blog/domain-verification-bypass-prevention-caa-accounturi/ #hardening

How to prevent domain verification bypasses of your server certificate
Pentagrid AG

How to prevent domain verification bypasses of your server certificate

Description of the CAA accounturi binding to mitigate or prevent domain verification bypasses and monitoring approaches like certificate transparency log analysis.

0
0
4
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 28mo ago

It happened again. We accidentally broke another #hotel check-in #terminal. This time Mr O'Yolo triggered a problem, crashed the #Ariane Allegro Scenario Player and escaped the #kiosk mode, which enabled access to the Windows Desktop: https://www.pentagrid.ch/en/blog/ariane-allegro-hotel-check-in-terminal-kios-escape/ #itsecurity #infosec

Kiosk mode bypass for an Ariane Allegro Scenario Player based hotel ch
Pentagrid AG

Kiosk mode bypass for an Ariane Allegro Scenario Player based hotel ch

A hotel check-in kiosk application crashed when entering a single quote into the guest search, which enabled access to the Windows Desktop. The terminal uses the Ariane Allegro Scenario Player.

0
0
2
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 34mo ago

Multiple vulnerabilities affecting #Atos #Unify IP Devices - the vendor published OBSO-2312-01: https://networks.unify.com/security/advisories/OBSO-2312-01.pdf

networks.unify.com
0
0
1
0
Open post
Pentagrid AG @pentagrid@infosec.exchange
· 3mo ago

A missing config setting for the document root on an IKEA DIRIGERA smart hub web server exposed large parts of the file system: https://www.pentagrid.ch/en/blog/ikea-dirigera-security-misconfiguration-web-server-exposes-root-filesystem/ #itsecurity #infosec #ikea #owasp

Security misconfiguration in IKEA DIRIGERA smart hub web server expose
Pentagrid AG

Security misconfiguration in IKEA DIRIGERA smart hub web server expose

An unauthenticated attacker on the network can download large parts of the DIRIGERA hub root filesystem that the service user 'license-server' can read.

0
0
2
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 06:39:57 UTC