Showing posts fromSegurança
Connecting LinkSys WRT54G using WDS and make a kid happy.
- 13 Mar, 2011
Today I solved a problem with my wireless home network. My kid have a PS3 and wants to play online.
The signal strength was not too bad (52%) but the PS3 got some network errors and the kid loses the game.
My solution was to buy another router TP-Link WR941 and link the Linksys WRT54G using WDS.
The problem was that WRT54G doesn't have support to WDS. To solve this problem go and change the bios of the WRT54G from the LinkSys to
DD-WRT http://www.dd-wrt.com/site/index. Look up for your WRT54G version and follow the instructions.
The WDS setup was easy, just setup the WR941 as usual (basic setup), like next, next and finish. The WR941 was the primary router (gateway to in
End of public updates for JAVA SE6 and SE5
- 11 Dec, 2012
The last publicly available release of Oracle JDK 6 is to be released in February, 2013.This means that after February 19, 2013, all new security updates, patches and fixes for Java SE 6 and Java SE 5 will only be available through My Oracle Support and will thus require a commercial license with Oracle. It's important for developers and systems administrators to either make the transition over to Java SE 7 or to work with Oracle to get updates via the Java SE Support program(http://www.oracle.com/us/technologies/java/standard-edition/support/overview/index.html) .
Link
Every API Authentication Method Explained (Don’t Choose the Wrong One)
- 25 Mar, 2026
Você já passou horas desenvolvendo uma API incrível, só para travar completamente na hora de decidir como protegê-la? É um dilema comum. Se você escolhe um método simples demais, como o Basic Auth, p
Every API Authentication Method Explained (Don’t Choose the Wrong One)Read MoreHow Hackers Steal Passwords: 5 Attack Methods Explained
- 15 Jun, 2026
Você já parou para pensar em quantas senhas usa diariamente? Provavelmente, você acha que aquela sua senha antiga, com apenas uma letra maiúscula e um número, está totalmente segura, certo? O problem
How Hackers Steal Passwords: 5 Attack Methods ExplainedRead MoreHow to test your PC for the New "Superfish" Security Vulnerability
- 19 Feb, 2015
Security researchers have discovered a vulnerability in a piece of adware called Superfish(http://gizmodo.com/lenovo-installs-adware-on-new-computers-that-could-stea-1686721226) that makes your computer vulnerable to all kinds of attacks. Superfish ships preloaded on many Lenovo computers, but can also be installed on any machine. Here's what's going on and how to test if you're infected. See the full article here(http://lifehacker.com/how-to-test-your-pc-for-the-new-superfish-security-vu-1686788663)
How to test your PC for the New "Superfish" Security VulnerabilityRead MoreHTTP response splitting attack in WebSphere Application Server
- 05 Nov, 2015
There is a vulnerability in IBM WebSphere Application Server that could allow an HTTP response splitting attack in Channel. More information on this link(http://www-01.ibm.com/support/docview.wss?uid=swg21966837)
HTTP response splitting attack in WebSphere Application ServerRead MoreIBM ICS - Product Information for General Data Protection Regulation (GDPR)
- 25 May, 2018
IBM publised a TechNote listing links and pdf files about GDPR for ICS products See the TechNote here(http://www-01.ibm.com/support/docview.wss?uid=swg27051100) Thanks to Robert Ingran for sharing this.
IBM ICS - Product Information for General Data Protection Regulation (GDPR)Read Moremkcert: valid HTTPS certificates for localhost
- 14 Jan, 2019
I found it today when googling for some solution for my mac and it works! The web is moving to HTTPS, preventing network attackers from observing or injecting page contents. But HTTPS needs TLS certificates, and while deployment is increasingly a solved issue thanks to the ACME protocol and Let's Encrypt, development still mostly ends up happening over HTTP because no one can get an universally valid certificate for localhost(https://letsencrypt.org/docs/certificates-for-localhost/). This is a problem because more and more browser features are being made available only to secure origins, and testing with HTTP hides any mixed content issues that can break a production HTTPS website. Develop
mkcert: valid HTTPS certificates for localhostRead More’Not Access Server’ field is not prevent Web users from accessing server by default
- 23 Jun, 2011
From TN 1182264 This behavior can occur if you have not set the "Enforce server access setting" field to Yes. The default value is No, which does not apply the "Not Access Server" information to Web (HTTP) traffic. You must set this field to Yes to have the HTTP task honor the settings on the Security tab. The "Enforce server access setting" field is in the Server document on the Ports -> Internet Ports -> Web tab. After changing the value to Yes, restart the HTTP task to apply the changes. In one particular case, the changes did not take effect with restarting the HTTP task, so the customer restarted the server.
’Not Access Server’ field is not prevent Web users from accessing server by defaultRead MoreQuad9 free anycast DNS from IBM
- 18 Nov, 2017
Quad9 is a free, recursive, anycast DNS platform that provides end users robust security protections, high-performance, and privacy. Security: Quad9 blocks against known malicious domains, preventing your computers and IoT devices from connecting malware or phishing sites. Whenever a Quad9 user clicks on a website link or types in an address into a web browser, Quad9 will check the site against the IBM X-Force threat intelligence database of over 40 billion analyzed web pages and images. Quad9 also taps feeds from 18 additional threat intelligence partners to block a large portion of the threats that present risk to end users and businesses alike. Performance: Quad9 systems are distributed w
Quad9 free anycast DNS from IBMRead MoreSecurity Vulnerability in IBM WebSphere Portal
- 23 Oct, 2015
Several versions of WebSphere Portar are vulnerable. BM WebSphere Portal could allow a remote attacker to obtain sensitive information, caused by the failure to restrict access to resources located within web applications. An attacker could exploit this vulnerability to obtain configuration data and other sensitive information. How to fix this vulnerability ? Go to this link(http://www-01.ibm.com/support/docview.wss?uid=swg21963226&myns=swgws&mynp=OCSSHRKX&mync=E&cmsp=swgws--OCSSHRKX--E) from IBM
Security Vulnerability in IBM WebSphere PortalRead MoreSegurança de Grupos Domino
- 19 May, 2009
Em alguns casos é desejado ou necessário que algumas pessoas possam administrar os grupos no diretório Domino. Aparentemente é suficiente colocar o usuário ou grupo de usuários com acesso de editor/autor na ACL do names.nsf e marcar a role GroupModifier. O problema é que se for dado este direito o usuário pode alterar qualquer grupo do Diretório, inclusive se colocar como LocalDomainAdmins ou Administrator ou outro grupo de segurança.
Para solucionar o problema com segurança o TN 1370433(http://www-01.ibm.com/support/docview.wss?rs=463&context=SSKTMJ&dcÛ560&dcÛ520&uid=swg21370433&loc=enUS&cs=UTF-8&lang=en&rss=ct463lotus) explica uma alternativa onde não é necessário alter

