“The NSA discovered an error in the Microsoft code that verifies those signatures, potentially enabling a hacker to forge the signature”https://www.washingtonpost.com/national-security/nsa-found-a-dangerous-microsoft-software-flaw-and-alerted-the-firm--rather-than-weaponize-it/2020/01/14/f024c926-3679-11ea-bb7b-265f4554af6d_story.html …
-
-
can't talk rn, spinning up my AD test bench
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
Connected via TLS that is validated how exactly?
-
Are you saying this affects X.509 validation?
- Još 6 drugih odgovora
Novi razgovor -
-
-
For the longest time, win update used TLS with NULL NULL. Updates by design need to be delivered over any channel, many unreliable and insecure
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
Speaking from experience caching it: Windows Update uses HTTP, not HTTPS and packages are signed independently of the transport
-
WSUS can be configure to use HTTPS for the control/management/reporting channel but automatically uses -1 port for HTTP binary/data channel for updates. Defaults are 8531 and 8530 for this communication.
- Još 2 druga odgovora
Novi razgovor -
-
-
Anyway, I think that Windows Update is using TLS only for metadata. https://www.blackhat.com/docs/us-15/materials/us-15-Stone-WSUSpect-Compromising-Windows-Enterprise-Via-Windows-Update-wp.pdf …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
How on earth has everyone forgotten Flame? https://trailofbits.files.wordpress.com/2012/06/flame-md5.pdf …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.