[FD] "VirusTotal Windows Uploader" poor design of privacy

2017-09-04 Thread Eitan Caspi via Fulldisclosure
Somethingto share with you, which I am not sure is known enough:   Recently,while I was tweaking a network monitoring systems, I noticed an upload of afile that its name included a full local Windows file path, ending with a nameof a file I uploaded to VirusTotal, using their Windows applicati

[FD] Microsoft account site using old cert

2018-04-13 Thread Eitan Caspi via Fulldisclosure
Hi,   On21-February-2018 I send the following email to sec...@microsoft.com. Onthe same day I received back a (probably automated) response email that a casewas opened, with a case number.   Today,13-Apri-2018 it happened again, so I share it. Seeit also at a SSL Labs test report at https:

[FD] It is not a vulnerability. It is a feature. A Zendesk customer? Act now!

2018-11-27 Thread Eitan Caspi via Fulldisclosure
Original, as HTML with images, was posted at LinkedIn - https://www.linkedin.com/pulse/vulnerability-feature-zendesk-customer-act-now-eitan-caspi/And also at my security blog - https://fudie.net/it-is-not-a-vulnerability-it-is-a-feature-a-zendesk-customer-act-now/ I am not a Zendesk expert but