FOCA – Find Metadata And Hidden Information In The Documents

  FOCA (Fingerprinting Organizations with Collected Archives)FOCA is a tool used mainly to find metadata and hidden information in the documents it scans. These documents may be on web pages, and can be downloaded and analysed with FOCA. It is capable of analysing a wide variety of documents, with the most common being Microsoft Office, […]

Google Photos Vulnerability that Lets Retrieve Image Metadata

A vulnerability that was detected in the web version of Google Photos could be used by hackers to retrieve image metadata. ZDNet reports, “Google has patched a bug in its Photos service that could have allowed a malicious threat actor to infer geo-location details about images a user was storing in their Google Photos account.” […]

NSA Collected 534 Million Call Records Metadata In 2017: 3 Times Increase From 2016

The new Annual Statistical Transparency report published by the Office of The Director of National Intelligence (ODNI) gives the highlights of NSA’s surveillance campaigns. In 2017, the agency sourced the metadata of over 530 million call records related to targets. That’s more than three times than the data collected in 2016, i.e., 151 million. The metadata […]

Metadata From IoT Traffic Exposes In-Home User Activity

Metadata from web traffic generated by smart devices installed in a home can reveal quite a lot of information about the owner’s habits and lifestyle. According to research published this month by experts from Princeton University, a determined attacker with “capabilities similar to those of an ISP” can use passive network monitoring techniques to collect […]

Abusing the AWS metadata service using SSRF vulnerabilities

I recently worked on a small toy project to execute untrusted Python code in Docker containers. This lead me to test several online code execution engines to see how they reacted to various attacks. While doing so, I found several interesting vulnerabilities in the code execution engine developed by Qualified, which is quite widely used including by […]

Boffins analyzed EXIF metadata in photos on principal blackmarkets

Two researchers have analyzed images Exif metadata included in the photos used by crooks to advertise their products on black marketplaces in the dark web. Darknets are a privileged environment for crooks that intend to develop a prolific business protecting their anonymity, anyway, there are several aspects that they need to consider in order to […]

Ricochet peer-to-peer messenger uses power of the dark web to escape metadata

Ricochet is the most secure encrypted anonymous messenger that sends no metadata. The security experts have approved a new internet messaging tool that bypasses the federal government’s metadata collection system to help human rights activists and journalists protect whistleblowers. Called the Ricochet, this software has been in development for around two years. However, following a […]

Your Password Manager 1Password Leaks Your Account’s Important Metadata

Short Bytes: 1Password, a password manager feature has been found to leak traces of the user account’s metadata which could be exploited by the attackers. However, only the older accounts using Agile Keychain format are vulnerable.  Storing all your passwords and sensitive information in a single vault appears to be a good option, but what […]