Cyberis is an innovative information security consultancy which was formed in 2011. Cyberis' founders have 30 years of experience between them working in the information security industry and are able to call upon a wide range of skills and abilities.
Another week, another ransomware outbreak. On Tuesday, we saw another variant of ransomware spreading, worm-style, across unsecured networks within large organisations. As with the WannaCry outbreak in May, large global corporations have been affected, and infections have spread from their initially-compromised hosts across internal networks. NotPetya hasn't received as much press as WannaCry did, but from a security perspective it does, at the moment, look far more interesting.
Sanitisation of user input is essential for preventing SQL injection, regardless of the format of the supplied data. Today I'm going to look at SQL injection through a more obscure injection point: serialized PHP arrays. Taking inspiration from a finding in a recent test, I've created a small app which allows the user to upload a CSV file. This file is then converted to a PHP array, serialized and returned to the user as a hidden form field. Finally, this is posted back to the application where the supplied data is inserted into the MySQL database.
Cyberis is an innovative cyber security consultancy based in Tewkesbury. We deliver industry-leading technical assurance and cyber security advice, including penetration testing and simulated attacks, to our customers across a wide range of verticals.
We are hiring highly motivated and enthusiastic candidates to join our team of cyber security consultants providing high-quality targeted assurance, advice and guidance to our customers. Our vision is to build the most respected team in the information security industry.
Another ransomware attack hits, this time on a scale never seen before. The spread has gone viral across a large and crucial network – the network underpinning the UK's National Health Service.
There are three main differences between this attack and previous ransomware incidents.
Cyberis is hunting for an excellent candidate to fulfil the role of Consultant within our expanding consultancy team. The role will entail delivering high quality penetration testing and other security consultancy work for our clients. Our team is dynamic, innovative and hard working. Career development is a priority for our company and this is reflected in the opportunities presented to our staff.
Ever wondered if you're prepared for a cyber security incident? This week, one of our Directors, Gemma Moore, is guiding you through incident preparation and handling.
Follow us on Twitter for the mini-how-to series, and view the previous blogs here:
There is some confusion surrounding Cyber Essentials; what it is, why people need it and often there is a misinterpretation that Certifying Bodies are responsible for the schemes rules. Cyber Essentials is a relatively new certification. It has been mandated since October 2014 for UK government suppliers, although it is not limited to them, non-government organisations are encouraged to seek to obtain the certification.
NetAlerts is Cyberis’ new service which provides a concise, consistent overview of changes to your internet exposure. Understanding your exposure is a key factor in understanding the risk to your network; by detecting changes in TCP/IP port states and highlighting dangerous ports, NetAlerts can aid in the identification of insecure or misconfigured services as well as potentially malicious software.