Skip to content

Kalypto (in)Security

Research, demonstrations, and popcorn

  • Home
  • About
  • Disclosure Record
Research

Vault 7: An attack on The United States of America

On Tuesday March 7th, 2016, WikiLeaks posted a trove of stolen files and data sourced from inside the Central Intelligence Agency.  This information was posted to the WikiLeaks website with a press release claiming the need for transparency…

Continue reading Vault 7: An attack on The United States of America
KalyptoMarch 8, 2017
Research

Arris Modem Vulnerability – Updated 3/14

Arris is one of the single largest providers of cable internet modems in the United States and around the world.  I was playing around with this a bit tonight while bored and came up with a simple way to cause…

Continue reading Arris Modem Vulnerability – Updated 3/14
KalyptoFebruary 13, 2017September 18, 2026
Personal

Let’s get some self-respect back

I see a lot of arguments between people who have no clue about the truth behind the topics and points being argued. I miss the old days of the internet being solely for cat videos and pictures of…

Continue reading Let’s get some self-respect back
KalyptoJanuary 30, 2017
Research

How to enable Authentication on your MongoDB instance

This is a quick post on enabling authentication on your MongoDB instance, but the first thing you should do is bring the MongoDB inside your network if possible.  If it is not exposed externally, there is a far lower…

Continue reading How to enable Authentication on your MongoDB instance
KalyptoJanuary 24, 2017
Research

MRIT – MongoDB Ransom Investigation Tool released on GitHub

I have written a simple multithreaded application used to Shodan exports for open MongoDB instances and report on ransom demands.  This tool is on GitHub and is released for free use.  The only caveat is that you may…

Continue reading MRIT – MongoDB Ransom Investigation Tool released on GitHub
KalyptoJanuary 18, 2017September 18, 2026
Research

STOP AND GO SECURE YOUR DATA… NOW!

After doing some research into MongoDB for the company I currently work for, I started looking around at some servers online.  What I found was amazing.  Database servers almost never need to be exposed on the perimeter of a network, but…

Continue reading STOP AND GO SECURE YOUR DATA… NOW!
KalyptoJanuary 15, 2017September 18, 2026
Research

Do your MongoDB admins know what they are doing?

Note:  This was originally posted to LinkedIn, but I have moved it over here to go along with the update I posted about the explosion of malicious ransom demands. MongoDB by default does not have very good security…

Continue reading Do your MongoDB admins know what they are doing?
KalyptoJanuary 9, 2017
Research Site News

MongoDB Ransomware Explosion

Recently I posted an article on LinkedIn about MongoDB security… well, it turns out that this has exploded into a big issue.  Over the last two weeks malicious hackers have been going crazy with extortion schemes.  Hackers are…

Continue reading MongoDB Ransomware Explosion
KalyptoJanuary 9, 2017
Personal

Have a Happy New Year and Don’t Drive Drunk

I would like to wish everyone a happy and safe New Year’s Eve.  I hope you all get to go out and spend time with family and friends to ring in the new year with cheer.  After the year…

Continue reading Have a Happy New Year and Don’t Drive Drunk
KalyptoDecember 31, 2016
Research

Bricking the Apple Message App

There are three reasons an exploit may exist in code:  poorly written code, logic failure on the part of the developer, or in the case of this exploit, using something in a way that was never intended or tested.  Arguably,…

Continue reading Bricking the Apple Message App
KalyptoDecember 31, 2016

Posts navigation

← Previous 1 2 3 4 5 … 7 Next →

Copyright © 2026 Kalypto (in)Security