Andrea Fortuna
AboutSearch
Tools
DFIR Toolkit OSINT Toolkit
  • Apr 9, 2020

    i3: how to make a pretty lock screen with a small bash script

    My regular readers already knows that my favorite desktop environment on Linux is i3.However, let's face it, the UI of the default theme of lockscreen tool (i3lock) is hawful. Luckily, i3lock provides some command line options, such us the -i… read more »
  • Apr 8, 2020

    Weekly Privacy Roundup #2

    Privacy is implied. Privacy is not up for discussion - Mikko Hypponen… read more »
  • Apr 7, 2020

    Security analysis of WhatsApp calls

    Today i'd like to share a interesting research by Marvin Schirrmacher, focused on WhatsApp calls.… read more »
  • Apr 6, 2020

    Weekly Cybersecurity Roundup #2

    Remote work, 5th week!… read more »
  • Apr 3, 2020

    Weekly Tech Roundup #1

    It's Friday! Let's talk about Minecraft, Books, Space Movies AI and Robots!… read more »
  • Apr 2, 2020

    TLDR #3: Zero Trust Security

    "Zero trust" is a phrase first coined by John Kindervag, in a research for Forrester Research Inc., in 2010… read more »
  • Apr 1, 2020

    Be careful! A Windows flaw lets Zoom leak network credentials and run code remotely

    Researcher have found a security issue in the Windows client of the popular video conferencing service that can be used for limited remote code execution and, worse, to capture and replay security tokens to access network resources… read more »
  • Mar 31, 2020

    Some security thoughts about videocalls

    Recently in Norway a school had to stop using the Whereby video conference service because during a video lesson a man broke into the group video conference and ​showed himself naked.… read more »
  • Mar 30, 2020

    Weekly Cybersecurity Roundup #1

    So, let's start with the new "Weekly Cybersecurity Roundup"!… read more »
  • Mar 27, 2020

    Amethyst: an 8-bit home computer based on ATmega1284

    Amethyst, by Matt Sarnoff, it's a great project for a classic home computer… read more »
  • Mar 26, 2020

    A brand-new attack hijack routers’ DNS to push malicious COVID-19 apps

    A recently discovered campaign that targets home and small-office routers is redirecting users to fake COVID-19 informational sites that attempt to install password stealing malware… read more »
  • Mar 25, 2020

    Windows Service Accounts enumeration using Powershell

    Windows Service Accounts are the elephant in the room in the corporate environment: things that nobody ever talks about or considers to be a problem. Often, these service accounts are in the Domain Admins group, with passwords like "Service123", "Password123",… read more »
  • Mar 24, 2020

    ADV200006: critical Windows RCE exploited in the wild

    Microsoft has released a security advisory about a remote code execution vulnerabilities affecting all currently supported versions of Windows and Windows Server operating systems. … read more »
  • Mar 20, 2020

    Pypykatz: a Mimikatz Python implementation

    Mimikatz is famous post-exploitation tool written in C by Benjamin Delpy: it allows a local attacker to dump secrets from memory exploiting Windows single sign-on functionality. … read more »
  • Mar 19, 2020

    Hacking Android Smart TVs using the IR remote control

    Valerio Mulas published an interesting analysis about the security of Android-based Smart TVs. The analysis points out the default configuration of most Android-based TVs, which allows you to enable the ADB, install unsigned applications and theoretically gain full control of… read more »
  • Mar 18, 2020

    What do browsers say when they phone home?

    Professor Douglas Leith from Trinity College in Ireland, tested six web browsers to determine what data they were sharing.… read more »
  • Mar 17, 2020

    Some thoughts about the Signal Messaging Protocol

    Some years ago, a team of researchers realized a security analysis of Signal protocol, still relevant and useful… read more »
  • Mar 13, 2020

    How to block Windows 10 telemetry using "hosts" file

    Since Windows 8, Microsoft has moved to a new commercial strategy: in addition with traditional selling of OS licenses, started got revenues from searches, apps and games. But to do this, MS has started the collection of “telemetry” data, considered… read more »
  • Mar 11, 2020

    SMBGhost (CVE-2020-0796): a new wormable Windows SMBv3 vulnerability

    Security firms inadvertently leaked info about a 0-Day 'wormable' vulnerability found in the SMBv3 protocol. How to detect and moderate it?… read more »
  • Mar 11, 2020

    Load Value Injection (CVE-2020-0551): a new Side-Channel attack affects Intel's CPUs

    Many processors made by Intel are vulnerable to a new type of attack named Load Value Injection.… read more »
« Previous page Next page »

Andrea Fortuna

  • Andrea Fortuna
  • andrea@andreafortuna.org
  • andreafortuna
  • andreafortunaig
  • andrea-fortuna

Cybersecurity expert, software developer, experienced digital forensic analyst, musician