RCE Via Arbitrary File Upload at Open eClass

RCE Via Arbitrary File Upload at Open eClass

Introduction The Open eClass platform (http://www.openeclass.org) is an integrated Learning Management System (LMS). It follows the philosophy of open source software and supports a multitude of e-learning scenarios without restrictions and constraints. The service...
BoFs Are Not Dead

BoFs Are Not Dead

Abstract Buffer overflow vulnerabilities remain highly relevant in embedded systems, where the absence of operating system abstractions and modern memory protection mechanisms creates conditions fundamentally different from traditional software exploitation. Unlike...
Is user training a good thing?

Is user training a good thing?

In the past years, there has been a major focus on end-user training as it is considered (and rightly so) the weakest link in the cybersecurity chain. I keep hearing more and more experts (and self-proclaimed ones) emphasize that we should train our users constantly....