HN user

jonaslejon

649 karma

Web and cyber security geek.

[ my public key: https://keybase.io/jonaslejon; my proof: https://keybase.io/jonaslejon/sigs/CWrMd2vYkWkMYf7XVDm0kpGGtm1-yXbhmqenTcQdCDM ]

Posts51
Comments16
View on HN
blog.wpsec.com 1y ago

The Full Story of CVE-2024-6386: Remote Code Execution in WPML

jonaslejon
1pts0
www.netresec.com 1y ago

How to Inspect TLS Encrypted Traffic

jonaslejon
2pts0
blog.wpsec.com 3y ago

Critical Security Flaw in the WooCommerce Payments Plugin

jonaslejon
2pts0
hub.docker.com 3y ago

Wpsec.com Docker WordPress Vulnerability Scanner Command Line Client

jonaslejon
1pts0
github.com 3y ago

Wpsec.com Python Command-Line Client

jonaslejon
1pts0
blog.wpsec.com 3y ago

Eight-Year Study Shows the Dark Side of WordPress Plugins

jonaslejon
4pts0
blog.wpsec.com 4y ago

Security in WordPress Plugin Development

jonaslejon
2pts0
blog.wpsec.com 4y ago

Discovering Vulnerabilities in WordPress Plugins at Scale

jonaslejon
1pts0
blog.wpsec.com 4y ago

Backdooring WordPress Using PyShell

jonaslejon
6pts0
blog.wpsec.com 4y ago

Security Features We Wish Were Included in WordPress

jonaslejon
1pts0
blog.wpsec.com 4y ago

WordPress and the new vulnerability Trojan Source

jonaslejon
1pts0
github.com 4y ago

Malicious PDF Generator

jonaslejon
2pts0
blog.wpsec.com 5y ago

WooCommerce Unauthenticated SQL Injection Vulnerability

jonaslejon
1pts0
blog.wpsec.com 5y ago

WordPress PHPMailer Vulnerability Analysis

jonaslejon
2pts0
blog.wpsec.com 5y ago

WordPress XXE Vulnerability in Media Library – CVE-2021-29447

jonaslejon
2pts0
blog.wpsec.com 5y ago

Are WordPress Websites That Vulnerable? – WPSec

jonaslejon
2pts0
blog.wpsec.com 5y ago

What You Need to Know About WordPress 5.7 and One-Click HTTPS Migration

jonaslejon
1pts0
blog.wpsec.com 5y ago

Write-up about the WordPress Contact Form 7 plugin vulnerability

jonaslejon
1pts0
blog.wpsec.com 5y ago

WordPress 5.5.2 Security Release

jonaslejon
1pts0
www.hakanlidbo.com 6y ago

The Corona Hat helps you keeping the distance to your fellow citizens

jonaslejon
1pts1
blog.wpsec.com 6y ago

Backdooring WordPress with Phpsploit

jonaslejon
1pts0
blog.wpsec.com 6y ago

Dozens of File Upload Vulnerabilities Found in Web Apps

jonaslejon
2pts0
blog.wpsec.com 6y ago

CVE-2020-9334: Stored XSS Vulnerability in Popular Gallery Plugin for WordPress

jonaslejon
1pts0
blog.wpsec.com 6y ago

100k WordPress Sites Vulnerable Due to Events Manager Plugin

jonaslejon
2pts0
blog.hostdns.com 6y ago

Troubleshooting DNS Problems with Dig

jonaslejon
1pts0
blog.wpsec.com 6y ago

From CSRF to RCE and WordPress-Site Takeover: CVE-2020-8417

jonaslejon
1pts0
www.exploit-db.com 6y ago

Citrix XenMobile Server 10.8 – XML External Entity Injection

jonaslejon
1pts0
blog.wpsec.com 6y ago

What is xmlrpc.php file and why you should care about it

jonaslejon
2pts0
blog.wpsec.com 6y ago

Cracking WordPress Passwords with Hashcat

jonaslejon
1pts0
gist.github.com 7y ago

Episerver XML External Entity (XXE) Vulnerability

jonaslejon
1pts0

I personally use OSSEC for File Integrity Monitoring. And it has also actually caught an intruder that modified some PHP-code on a webserver. The attacker forgot to use the prefix @ in the PHP-code so a new error message was sent to the logfile and reported by OSSEC.