Malicious JavaScript in image metadata used to steal data; then, images are used again to exfiltrate data:

– Malware uses Exif metadata to inject JavaScript that steals data.
– Afterward, the data is exfiltrated as an image via GET/POST to another server.
– As a server admin, frequently update the server software, and monitor file integrity + network traffic. Moreover, set a strict Content Security Policy.

OWASP Chapters All Day (June 2020):
In case you missed it, there is a collection of recent OWASP talks. The topics include security-relevant HTTP response headers, lessons learned for incident response teams (CSIRT/PSIRT), and hardening code/systems.

This is a great example of why open source is the only thing that's really worth investing your time into long term.

"Because Synthing is free and doesn’t depend on server-side storage, they don’t need to put weird or unnatural restrictions on you."

"UtahFS is an encrypted storage system that provides a user-friendly FUSE drive backed by cloud storage."


The upcoming "Feature Policy" is now called "Permissions Policy":

We already updated the relevant part of our Web server security series:

Keep in mind that the Permissions Policy isn't supported by most web browsers, so you don't need to set it at the moment. Clients ignore it.

