Sec-T presentation on BankID Hijacking and other mis-configuration in Cross-Device protocols

My Sec-T Presentation Hi there! This year I had the pleasure to attend and present at Sec-T for the very first time! It was overall a great conference with lots of cool hackers and presentations. I got to show off my research and findings in Swedish BankID along with some other insights in research I’ve been doing in other Cross-Device Authentication protocols. Here I attach the full sides: As well as the recording from Sec-T official’s YouTube channel:...

September 15, 2024 · 1 min · 111 words · Me

Hijacking accounts via BankID Session Fixation attack

The Swedish BankID is a form of digital identification used by most if not all Swedish residents to authenticate to multiple services such as: internet providers, online banking services, betting websites and especially governmental websites. Living in Sweden myself, and with the hacker mentality always buzzing in my brain, I decided that it would be a very interesting field to do some security research in. In this post I will be presenting a new vulnerability I found present in most Swedish service providers due to an insecure implementation of BankID’s authentication protocol....

March 21, 2024 · 12 min · 2393 words · Me

TensorFlow Remote Code Execution with Malicious Model

The purpose of this article is to show how to get RCE when a crafted malicious Tensorflow model is loaded. Remember all of this is for educational purposes only! Don’t be mean! Tensorflow Models are Programs This article is in no way reporting a vulnerability in the Tensorflow python module. As it can be read in the SECURITY section of the project, Tensorflow models should be treated as programs and thus from a security you should not load (run) untrusted models in your application....

September 29, 2022 · 7 min · 1332 words · Me