<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Infosec on Dave Hall Consulting</title><link>https://www.davehall.com.au/tags/infosec/</link><description>Recent content in Infosec on Dave Hall Consulting</description><generator>Hugo</generator><language>en-au</language><lastBuildDate>Fri, 10 Dec 2021 00:00:00 +0000</lastBuildDate><atom:link href="https://www.davehall.com.au/tags/infosec/index.xml" rel="self" type="application/rss+xml"/><item><title>Does GitHub Enterprise Cloud Make Your Organisation Less Secure?</title><link>https://www.davehall.com.au/blog/2021/12/10/does-github-enterprise-cloud-make-your-organisation-less-secure/</link><pubDate>Fri, 10 Dec 2021 00:00:00 +0000</pubDate><guid>https://www.davehall.com.au/blog/2021/12/10/does-github-enterprise-cloud-make-your-organisation-less-secure/</guid><description>GitHub&amp;rsquo;s oAuth scopes could leave organisations vulnerable.</description></item><item><title>A Lost Parcel Results in a New Website</title><link>https://www.davehall.com.au/blog/2021/02/12/lost-parcel-results-new-website/</link><pubDate>Fri, 12 Feb 2021 00:00:00 +0000</pubDate><guid>https://www.davehall.com.au/blog/2021/02/12/lost-parcel-results-new-website/</guid><description>When Australia Post lost a parcel, we found a lot of problems with one of their websites.</description></item><item><title>Zoom's Make or Break Moment</title><link>https://www.davehall.com.au/blog/2020/04/01/zooms-make-or-break-moment/</link><pubDate>Wed, 01 Apr 2020 00:00:00 +0000</pubDate><guid>https://www.davehall.com.au/blog/2020/04/01/zooms-make-or-break-moment/</guid><description>Covid-19 has fuelled massive growth for Zoom. Will this motivate them to fix their security problems?</description></item><item><title>Leaking Information in Drupal URLs</title><link>https://www.davehall.com.au/blog/2015/05/15/leaking-information-drupal-urls/</link><pubDate>Fri, 15 May 2015 00:00:00 +0000</pubDate><guid>https://www.davehall.com.au/blog/2015/05/15/leaking-information-drupal-urls/</guid><description>Update: It turns out the DA was trolling. We all now know that DrupalCon North America 2016 will be in New Orleans. I&amp;rsquo;ve kept this post up as I believe the information about handling unpublished nodes is relevant. I have also learned that m4032404 is enabled by default in govCMS.
When a user doesn&amp;rsquo;t have access to content in Drupal a 403 forbidden response is returned. This is the case out of the box for unpublished content.</description></item></channel></rss>