#www

california@diaspora.permutationsofchaos.com

security.txt

A proposed #standard which allows websites to define #security #policies.

Take a look: https://securitytxt.org

“When security risks in web services are discovered by independent security researchers who understand the severity of the risk, they often lack the channels to disclose them properly. As a result, security issues may be left unreported. security.txt defines a standard to help organizations define the process for security researchers to disclose security vulnerabilities securely.”

#web #www #website #vulnerability #cybercrime #privacy #advice #instructions #communication #software #bug #research

anonymiss@despora.de

#WordPress installer #attack race

source: https://smitka.me/2022/07/01/wordpress-installer-attack-race/

The attacker uses the #Certificate Transparency Log to find new WordPress #installations. It works because you usually generate the #SSL certificate when you set up a hosting space. When the certificate is issued, the record appears in the public log.

...

It takes only 4 minutes from the certificate issue to abuse the installer (but in some cases, the attacker managed to do it in under 1 minute).

#internet #blog #security #backdoor #problem #www #web #software #install #news

anonymiss@despora.de
anonymiss@despora.de

Check out #Iceraven a #Mozilla based #browser for #Android ...

Github: https://github.com/fork-maintainers/iceraven-browser
Screenshots: https://iceraven-browser.en.uptodown.com/android

Our goal is to be a close fork of the new Firefox for Android that seeks to provide users with more options, more opportunities to customize (including a broad extension library), and more information about the pages they visit and how their browsers are interacting with those pages.

#software #internet #firefox #fork #www #web #opensource #mobile #smartPhone