Generated by All in One SEO v4.9.4.1, this is an llms.txt file, used by LLMs to index the site. # Ruptura InfoSecurity Securing Your Critical Assets ## Sitemaps - [XML Sitemap](https://ruptura-infosec.com/sitemap.xml): Contains all public & indexable URLs for this website. ## Posts - [SAML Shenanigans](https://ruptura-infosec.com/hack-of-the-month/saml-shenanigans/) - March 2023 - With single sign-on becoming more common during our assessments, we cover one of the vulnerabilities we discovered during an engagement that let us forge SAML responses to escalate privileges in a web application. - [SyncFusion: CVE-2023-26563/4/5](https://ruptura-infosec.com/ownage/syncfusion-cve-2023-26563-4-5/) - We discovered multiple high severity CVEs in Syncfusion's software and discuss the advantages and disadvantages of utilising third-party solutions in your software. This blog goes into detail about the issues themselves and the corresponding risks that they pose to businesses. - [PrInT-NiGhTmArE?](https://ruptura-infosec.com/hack-of-the-month/print-nightmare/) - In April 2023, we completed an internal infrastructure security assessment for a client in the financial sector. What we didnt realise, is that this would become our first 'Fail of the Month' blog post... Read below to understand what happened and the technical reasons behind it. - [Navigating Cyber Essentials - An Assessors Perspective](https://ruptura-infosec.com/cyber-essentials/navigating-cyber-essentials-an-assessors-perspective/) - Read about how our assessors can help your organisation understand the common pitfalls when going through a Cyber Essentials assessment. - [How Can Random Be Real When Random Isn't Real?](https://ruptura-infosec.com/hack-of-the-month/how-can-random-be-real-when-random-isnt-real/) - In this post, we’ll shed some light on insecure PRNG vulnerabilities and walk through a real-world example of how such a vulnerability could be (theoretically) exploited without access to the vulnerable web application's source code, highlighting both the risks and the nuances involved. - [Cookie Security Flags](https://ruptura-infosec.com/security-advice/cookie-security-flags/) - Learn about HTTP cookies, how they are used and how they can be used to secure web traffic. This blog will go into technical details as well as the practical applications for various types of cookies and the "flags" that can be set. - [HTTP Strict Transport Security (HSTS)](https://ruptura-infosec.com/security-advice/http-strict-transport-security-hsts/) - Learn about how HSTS protects users against a variety of threats. We will discuss the use cases for HSTS, how it affects user experience and how it works under the hood. - [Why Does Ransomware Affect All Businesses?](https://ruptura-infosec.com/ransomware/why-does-ransomware-affect-all-businesses/) - Ransomware is a growing threat. It's undeniable and indiscriminate, looming over businesses of all sizes and industries. We take a look at the ins and outs of why Ransomware affects all businesses. - [What is Double Extortion?](https://ruptura-infosec.com/ransomware/what-is-double-extortion/) - Ransomware, a multifaceted cyber threat, is more complex and damaging than many realise. With diverse attack vectors and multiple profit mechanisms, it represents an escalating danger. This guide delves into the intricacies of double extortion in Ransomware, offering comprehensive insights into its operations, impact, and why it's a significant concern. - [The Major Ransomware Groups](https://ruptura-infosec.com/ransomware/the-major-ransomware-groups/) - Conti, Ryuk, and REvil are three of the most well-known and notorious ransomware groups that have caused significant damage and financial loss to organisations worldwide. Each of these groups has their own unique tactics and techniques, but they all share a common goal of extorting money from their victims through the use of ransomware attacks. - [From Previewing Files to Cracking Hashes](https://ruptura-infosec.com/hack-of-the-month/from-previewing-files-to-cracking-hashes/) - In August 2022, we completed a web application penetration test for a relatively new client. The scope was a pre-existing web application that allowed users to manage their calendars, plan events, upload documents and manage their accounts. The application had been tested by a previous penetration testing supplier and received a clean bill of health, but that all changed once we had our hands on it… - [Compromising 5,000 Servers CTF-Style](https://ruptura-infosec.com/hack-of-the-month/compromising-5000-servers-ctf-style/) - In September 2022, we completed an internal security assessment for a large client in the tech industry. The scope was enormous – about 20,000 hosts in scope split over eight different countries. Of these 20,000 hosts, there were approximately 50 Windows machines in a single domain. Our scenario assumed a stolen laptop of the lowest privileged user. This user had a standard account on AD with no access to the Linux infrastructure. - [Accessing the Keys to The Kingdom](https://ruptura-infosec.com/hack-of-the-month/accessing-the-keys-to-the-kingdom/) - In October 2022, we completed an internal security assessment for a large tech organisation with clients in the legal industry, focused around the handling of sensitive documents for other companies. The scope was focused on their “user network” – which hosted their active directory domain which all of their workstations and laptops were all connected to. Our scenario assumed access to their office – while this may seem like a fairly extreme position to start with, our first day we arrived at their office, we were able to walk in and someone helpfully held the door open for us without asking who we were… - [Facts and Fallacies of Multi Factor Authentication](https://ruptura-infosec.com/security-advice/facts-and-fallacies-of-multi-factor-authentication/) - Multi-Factor Authentication (MFA) has been widely adopted over the years as a means to enhance the security of authentication processes for all sorts of systems. It has somewhat become a must-have security control in order for organisations to claim that their systems have a withstanding security posture. This is especially true for organisations willing to be compliant with information security specifications, such as ISO 27001 and Cyber Essentials. However, it has been demonstrated time and again that even when MFA is put in place, it can be circumvented. The recent attack on Uber is a rather convincing example of this. The attack itself is not the topic of this post, but it serves as an incentive to remind ourselves that an authentication process that mandates MFA from its’ users is not impenetrable. In this blog post, we will be comparing the most common and prominent MFA methods with a focus on their usage within organisations’ internal infrastructure, as that is where the impact can be menacing. - [Writing Tiny, Stealthy & Reliable Malware](https://ruptura-infosec.com/ownage/writing-tiny-stealthy-reliable-malware/) - When it comes to writing custom tooling for engagements, the motivations associated with it often vary. At a high level, as a consultancy, having the capabilities to produce allows us to offer a niche but more realistic engagement. We can emulate the adversaries who target similar businesses in the same industry – ultimately giving the client a better assessment of their overall security posture through a profound offence against their various defensive capabilities. - [NoSQL? No Problem.](https://ruptura-infosec.com/hack-of-the-month/nosql-no-problem/) - In November 2022, we completed a web application security assessment for a new client within the health / wellbeing sector. We were told through previous discussions, that the web application had both standard user accounts for everyday use and administrator accounts for backend administration. As is fairly standard with these engagements, we were given credentials for a standard user account and were tasked to see what could be achieved from this position… - [You Are The Weakest Link, GoodLFI](https://ruptura-infosec.com/hack-of-the-month/you-are-the-weakest-link-goodlfi/) - In February 2023, we completed a web application security assessment for a new client within the legal field. What followed was a series of hurdles, followed by jumps and yet more hurdles, to eventually end up with a full working attack chain and LFI. - [Subdomain Takeovers](https://ruptura-infosec.com/security-advice/subdomain-takeovers/) - Subdomain takeovers are where an attacker is able to abuse dangling DNS aliases for cloud services to host their own content on an organisation’s subdomain. This content could consist of phishing pages, malware or anything else to compromise sensitive data. - [Hidden in Plain Sight](https://ruptura-infosec.com/hack-of-the-month/hidden-in-plain-sight/) - May 2023 - In this edition, we highlight how a decommissioned application was not fully removed as expected, allowing us to abuse legacy functionality to compromise an enormous amount of client and PII data. - [Password Managers](https://ruptura-infosec.com/security-advice/password-managers/) - Password managers are an essential tool for everyone in the modern world, but are they really safe or are we making a bigger mistake by not using them? - [Bypassing Threatlocker With Powershell](https://ruptura-infosec.com/hack-of-the-month/bypassing-threatlocker-with-powershell/) - June 2023 - We discuss and highlight how we bypassed one of the most heavily used 'zero trust' application whitelisting platforms. Their homepage ironically states that they block execution of anything not explicitly whitelisted 'including ransomware' but as we will show that wasn't entirely accurate... - [RCE - Really Crap Encryption](https://ruptura-infosec.com/hack-of-the-month/rce-really-crap-encryption/) - In December 2022, we completed a web application security assessment for a client who wanted assurance that their newly developed application was ready for production. The application allowed users to upload documents, rename files, create directories – basically acting as a web based file explorer. As a penetration tester, file upload functionality always raises alarm bells in our head as it’s deceivingly difficult to implement securely. - [Developers Hate This One Simple (Image) Magick Trick](https://ruptura-infosec.com/hack-of-the-month/developers-hate-this-one-simple-image-magick-trick/) - ImageMagick is one of those really powerful libraries that always gets mentioned in regards to anything to do with image processing. Sure enough, it’s a case of doing “apt install” and installing the relevant library in whatever programming language is being used. And away you go, you now have support for dozens of image formats and the ability to resize, convert between them, add text, and so on. This is exactly what one of our clients had implemented into their web application, that we assessed in late January. - [The Real Risks of TLS / SSL Issues](https://ruptura-infosec.com/security-advice/the-real-risks-of-tls-ssl-issues/) - Within almost 99% of web application penetration tests, there is usually at least one TLS / SSL related issue. Typically these are either reported as a Low CVSS score, or sometimes creeping into a Medium, depending on the application and its uses. We wanted to provide an informative article highlighting the real risks of these issues and how they can negatively impact the security of organisations. - [Why Should An MSSP Use A Pentesting Partner?](https://ruptura-infosec.com/security-advice/why-should-an-mssp-use-a-pentesting-partner/) - A good MSSP (Managed Security Service Provider) should be able to service all their clients cyber security needs to a very high standard. With the sheer size of the cyber security field, this may not be possible with niche services such as penetration testing and targeted security assessments. Here we discuss why it is beneficial for MSSP's to work with a penetration testing partner, rather than developing their own capabilities. ## Pages - [Secure Your Critical Assets Through Approved Penetration Testing Today](https://ruptura-infosec.com/) - Ruptura InfoSecurity are a CREST and CHECK accredited Penetration Testing provider. We are also an NCSC approved Cyber Essentials certification body. - [Request a Pentest](https://ruptura-infosec.com/request-a-pentest/) - Request A Pentest Our form allows you to submit information about your penetration testing requirements. We can then use this information to provide you with an accurate quote. Take Me There Request A Pentest Please use the below form to provide us with as much information as possible about your penetration testing requirements. We will - [CHECK Penetration Testing](https://ruptura-infosec.com/check-penetration-testing/) - CHECK Penetration Testing Government Penetration Testing & IT Health Checks (ITHC) I Need an ITHC What is CHECK Penetration Testing? CHECK is the terminology used to describe UK National Cyber Security Centre (NCSC) approved penetration testing.CHECK companies are subject to stringent auditing, must employ experienced and qualified staff and must hold UK approved security clearances.The - [Web Application Penetration Testing](https://ruptura-infosec.com/web-application-pentesting/) - Web Application Penetration Testing Identifying security vulnerabilities within your critical web applications. I Need a Pentest What is Web Application Penetration Testing? Web application penetration testing is the security assessment of a web application, website or web API by a trusted and experienced security consultant.A web application penetration test will highlight vulnerabilities within your web - [Cyber Essentials Plus](https://ruptura-infosec.com/cyber-essentials-plus/) - Cyber Essentials Plus Show your clients that your business is secured against the most prevalent cyber threats. I Need Cyber Essentials Plus What is Cyber Essentials Plus? Cyber Essentials Plus is a technical assessment of your organisation by an approved third party. It can only take place alongside, or after a successful Cyber Essentials Basic - [Cyber Essentials Basic](https://ruptura-infosec.com/cyber-essentials-basic/) - Cyber Essentials Basic Certifying your organisation with a UK Government approved cyber security accreditation. I Need Cyber Essentials Basic What is Cyber Essentials Basic? Cyber Essentials is a simple but effective, Government backed scheme that will help you to protect your organisation, whatever its size, against a range of the most common cyber attacks.Cyber Essentials - [Red Teaming](https://ruptura-infosec.com/red-teaming/) - Red Teaming Goal based engagements targeting your critical assets. I Need a Red Team What is Red Teaming? Our red teaming service aims to emulate highly skilled (and potentially state-funded) adversaries attacking your business.In our red team penetration testing service, we will utilise cutting edge tools and techniques in an attempt to compromise your organisation’s - [Mobile Application Penetration Testing](https://ruptura-infosec.com/mobile-application-penetration-testing/) - Mobile Application Penetration Testing Identifying security vulnerabilities within your critical mobile applications. I Need a Pentest What is Mobile Application Penetration Testing? A mobile application pentest assesses your mobile applications to identify security vulnerabilities and weaknesses. We can perform this service against: Android and iOS applications.Mobile application security testing aims to identify vulnerabilities that could - [Internal Infrastructure Penetration Testing](https://ruptura-infosec.com/internal-infrastructure-penetration-testing/) - Internal Infrastructure Penetration Testing Identifying security vulnerabilities within your most sensitive internal networks. I Need a Pentest What is Internal Infrastructure Penetration Testing? An internal infrastructure penetration test will assess your critical internal networks to identify security vulnerabilities and weaknesses.These are the environments that may be used on a daily basis to: transmit sensitive data, - [External Infrastructure Penetration Testing](https://ruptura-infosec.com/external-infrastructure-penetration-testing/) - External Infrastructure Penetration Testing Identifying security vulnerabilities within your critical external networks. I Need a Pentest What is External Infrastructure Penetration Testing? An external infrastructure penetration test will assess your externally facing networks to identify any security vulnerabilities and weaknesses.As these networks are publicly exposed to the internet, malicious attackers from around the world are - [Blog](https://ruptura-infosec.com/blog/) - Ruptura InfoSecurity Blog — Read the latest cyber security news, views and perspectives from Ruptura's cyber security experts. - [Payment Terms](https://ruptura-infosec.com/payment-terms/) - Payment Related Terms and Conditions Refund and Dispute PolicyEffective Date: 01/12/2024Company Name: Ruptura InfoSecurity LimitedRuptura InfoSecurity Limited (“we,” “us,” or “our”) is committed to ensuring a fair and transparent process for handling refunds and disputes related to our Cyber Essentials assessment services. By purchasing our services, you acknowledge and agree to the terms outlined in - [Modern Slavery Policy](https://ruptura-infosec.com/modern-slavery-policy/) - Modern Slavery Policy for Ruptura InfoSecurity Ltd. We take this topic very seriously, and update our modern slavery policy regularly - [Privacy Policy](https://ruptura-infosec.com/privacy-policy/) - Privacy Policy Last updated December 1, 2024.This privacy notice for Ruptura InfoSecurity Ltd (‘Company‘, ‘we‘, ‘us‘, or ‘our‘,), describes how and why we might collect, store, use, and/or share (‘process‘) your information when you use our services (‘Services‘), such as when you: Visit our website at https://ruptura-infosec.com, or any website of ours that links to this privacy - [Cookie Policy](https://ruptura-infosec.com/cookie-policy/) - Cookie Policy This Cookie Policy was last updated on December 1, 2024 and applies to citizens and legal permanent residents of the United Kingdom.1. IntroductionOur website, https://ruptura-infosec.com (hereinafter: "the website") uses cookies and other related technologies (for convenience all technologies are referred to as "cookies"). Cookies are also placed by third parties we have engaged. - [UAE Penetration Testing](https://ruptura-infosec.com/uae-penetration-testing/) - "We have been very impressed with the quality to the work, from initial scoping, through the delivery, as well as the final reporting & recommendations to our customers. Ruptura have been a delight to work with, the feedback from our customers is uniformly excellent, and we look forward to working with them on future projects." ## My Templates - [Elementor Loop Item #9681](https://ruptura-infosec.com/?elementor_library=elementor-loop-item-5) - February 7, 2025 Elementor Loop Item #9681 Read More - [Blog Template](https://ruptura-infosec.com/?elementor_library=blog-template) - Blog Template June 2, 2023 Introduction About Ruptura InfoSecurity​ Ruptura InfoSecurity are a fully accredited and trusted UK based cyber security provider. You can rest assured that our technical cyber security expertise and level of service is second to none. Linkedin Twitter Globe-americas Introduction to PRNGs When it comes to vulnerabilities in web applications, there’s - [404 Template](https://ruptura-infosec.com/?elementor_library=404-template) - 404 Oops! That page can't be found - [Elementor Loop Item #9426](https://ruptura-infosec.com/?elementor_library=elementor-loop-item-4) - NEW Elementor Loop Item #9426 Read More - [Archive Templtae](https://ruptura-infosec.com/?elementor_library=archive-templtae) - Template: Archive Templtae Hack of the Month How Can Random Be Real When Random Isn’t Real? In this post, we’ll shed some light on insecure PRNG vulnerabilities and walk through a real-world example of how such a vulnerability could be (theoretically) exploited without access to the Read More » February 10, 2025 Security Advice Cookie - [Elementor Loop Item #5774](https://ruptura-infosec.com/?elementor_library=elementor-loop-item-2) - Elementor Loop Item #5774 Read More - [Default Kit](https://ruptura-infosec.com/?elementor_library=default-kit-2) - [CE Basic Payments](https://ruptura-infosec.com/?elementor_library=ce-basic-payments) - Book Your Cyber Essentials Assessment Working with Ruptura is easy, simply select your company size, click on the link and pay, then we'll handle the rest!Want an invoice instead?Email us at ________________ Please enable JavaScript in your browser to complete this form.Please enable JavaScript in your browser to complete this form.Company Size1-9 Employees10-49 Employees50-249 Employees250+ - [About Us Dubai](https://ruptura-infosec.com/?elementor_library=about-us-dubai) - About Us Penetration Testing Middle East were established in mid 2023 to fully explore and develop the UAE’s existing cyber security strategy. We identified a gap in the market for a highly technical, in-depth and proven cyber security company – primarily focused around penetration testing as a service. Using our teams experience from our successes - [Elementor Loop Item #5767](https://ruptura-infosec.com/?elementor_library=elementor-loop-item) - [Elementor Loop Item #6210](https://ruptura-infosec.com/?elementor_library=elementor-loop-item-3) - Elementor Loop Item #6210 - [Default Kit](https://ruptura-infosec.com/?elementor_library=default-kit) ## Elementor Header & Footer Builder - [Footer Template](https://ruptura-infosec.com/elementor-hf/elementor-5535/) - Providing Real Insights Our team of technical consultants are some of the most highly skilled individuals in the industry. Their technical ability allows them to go above and beyond to identify vulnerabilities within your organisation.In the summer of 2024 we placed 9th globally in the HackTheBox Business capture the flag event and 1st in the UK, highlighting - [Test Header](https://ruptura-infosec.com/elementor-hf/test-header/) - Menu Home Penetration Testing Web Application External Infrastructure Internal Infrastructure Mobile Application Red Teaming CHECK Cyber Essentials Cyber Essentials Basic Cyber Essentials Plus Blog Request a Pentest ## Categories - [Hack of the Month](https://ruptura-infosec.com/category/hack-of-the-month/) - [Security Advice](https://ruptura-infosec.com/category/security-advice/) - [Ownage](https://ruptura-infosec.com/category/ownage/) - [Ransomware](https://ruptura-infosec.com/category/ransomware/) - [Cyber Essentials](https://ruptura-infosec.com/category/cyber-essentials/)