• 0 Votes
    1 Posts
    18k Views
    No one has replied
  • Passwords, identities and data breaches

    3
    1 Votes
    3 Posts
    2k Views
    T

    Thank you for your feedback.

    I agree, the "solution" I suggest, may not suit everybody. I did test out Lastpass at some point, one or two years ago, I didn't really like it, despite all the plugins to support my browsers (or perhaps, that was the very reason I didn't get comfortably with it, I like to keep the password manager far away from my browser).

    But I guess more users would find Lastpass easier to deal with, compared to the KeePass solution.

    I just noticed that Troy Hunt posted about his new collaboration with 1password, which allows checking if your credentials has been breached. A similar thing can be achieved with a plugin for KeePass, but again, the KeePass approach is less user friendly.

    In either case, a password manager will be a great step-up, for most of us. Choosing the right one is a matter of taste and preferences, and trust.

    I agree, there could be some perspective to Webauthn, though I always get a rash, when we all start relying on the same technology. Nonetheless, I will test it, once one of my favorite sites / services, offer Webauthn authentication.

  • GDPR / Privacy Policy & System upgrade & Status

    4
    0 Votes
    4 Posts
    3k Views
    V

    Todays change to the database required a small addition to our Privacy Policy, stating the fact, that MongoDB Cloud Services are managing the backend. Your data is still at the same facility, in Europe.

  • IPv6 added for vulndetect.com (testing)

    6
    0 Votes
    6 Posts
    20k Views
    V

    While troubleshooting my private IPv6 connectivity, I decided to enable an IPv6 and IPv4 specific access to the forum, so you and everybody else can test it:

    https://ipv4.vulndetect.org/
    https://ipv6.vulndetect.org/

    https://vulndetect.org/ is naturally dual-stack and most of us need not worry, once you have IPv6, you will use it automatically (if your ISP set it up correctly).

    It appears that my ISP currently has a routing issue, but then I could use my cellphone (just needed to enable dual-stack support in the APN under Mobile network).

    We also expect to enable dual-stack access to the VulnDetect backend, at some point during the tech preview stage.

  • Vulnerability and Patch Information

    2
    1 Votes
    2 Posts
    3k Views
    OLLI_SO

    @Tom I am not sure if this topic should be in Suggestions?
    If yes, then add it to the category "Application detection" in the suggestions summary.

  • Secunia PSI Forum

    3
    3 Votes
    3 Posts
    46k Views
    A

    Tom, that's just cold seeing as how they discontinued our beloved psi anyway. I'm really pleased to hear that someone cares enough to try and build something similar. I like many other's used psi for years to help me keep vulnerable programs safe. Please forgive any typo's my vision isn't all that good anymore, lol. I hope you guys have a nice day. šŸ™‚

  • Merchandise

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Feedback for the User-Interface

    2
    0 Votes
    2 Posts
    1k Views
    OLLI_SO

    Right now KeePass showed me that a new version is available:

    0_1537198130694_KeePass_Update_Check.png

    This Update Check window is simple, but shows all important information:

    Component (the name of the application) Status Installed Version Available Version (see Show Available Version)

    This should be an inspiration of VulnDetect.

  • Manual?

    3
    0 Votes
    3 Posts
    2k Views
    OLLI_SO

    VulnDetect is installed as service and is running silently in the background.
    If you go to https://personal.vulndetect.com/#/applications and click on Configuration then you can set up when the automatic scan should start.
    The scan results you see at https://personal.vulndetect.com/#/applications.

    I am programming a small tool that offers a graphical UI and allows to start an immediate scan.
    The tool is called Toolbox for VulnDetect and can be found here: https://1drv.ms/f/s!AsiLVok82IpQg_pe63xK8K01XuPIAw (in the folder "Toolbox Beta).
    But I am a normal user, not an official of SecTeer (the programmers of VulnDetect) so use the tool at your own risk!

  • What Version Number to display

    7
    0 Votes
    7 Posts
    2k Views
    OLLI_SO

    Today an update for ToDoList was released.
    The old version was 7.2.7.0 and VulnDetect displayed 7.2.7 (VulnDetect left away the last digit for the last versions of ToDoList).

    But today the version 7.2.8.1 was released and here you should show the last digit!
    In Help -> About I see also the following information: ToDoList 7.2.8.1 (Stable Version).

  • Apps that support Auto-Update (via VulnDetect)

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Ofiicial Chocolatey Packages

    1
    0 Votes
    1 Posts
    357 Views
    No one has replied
  • Is VulnDetect dead?

    16
    0 Votes
    16 Posts
    3k Views
    A

    I am surprised (and very disappointed) that the feature "Additional Status for Update Available" (https://vulndetect.org/topic/492/additional-status-for-update-available) is not yet implemented or has at least the status "Work in progress".
    Seems like the guys at VulnDetect are busy with other stuff that has not such a great benefit than that feature.
    This is very very sad!

  • 0 Votes
    3 Posts
    3k Views
    T

    Microsoft has issued official fixes for the 0-day CVE-2022-30190 / Follina:
    https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-30190

    As expected, Microsoft has classified it as a Windows vulnerability.

    You can see affected systems here:
    https://corporate.vulndetect.com/#/applications/versions?channelTag=microsoft.windows.endrule&status=insecure&title=Microsoft Windows

    Note that it requires a recent inspection, hosts that haven't inspected since 14-06-2022 20:00 CET will not report the missing KB update.

  • Things I would look for in a new vulnerability detection program

    8
    6 Votes
    8 Posts
    5k Views
    T

    @WacoJohn My apologies for this.

    Please see this response:
    https://vulndetect.org/post/6673

  • vulndetect newcomer

    4
    1 Votes
    4 Posts
    578 Views
    H

    @WacoJohn

    Welcome! This is the first time I've posted. I've been using VulDetect since it was announced after the demise of Secunia PSI. This is the first time I've felt I had a constructive comment to make.

    When I finally realized all my accounts were showing just the profile for the first machine I installed on, I combed through and found that each installation needed a separate email address. Since Apple, Comcast and others want to give me unique email addresses, I had enough to make separate accounts for each installation.

    I do like the idea of a corporate style account and hope I can change over to that once everything is worked out.

  • [Corporate] Why do Ignore Rules expire?

    3
    0 Votes
    3 Posts
    6k Views
    OLLI_SO

    @Tom The first feedback you have now
    šŸ˜‰

  • 0 Votes
    1 Posts
    242 Views
    No one has replied