Bit Discovery Blog https://blog.bitdiscovery.com/ Mon, 11 Jul 2022 18:10:27 +0000 en-US hourly 1 https://wordpress.org/?v=5.9.3 Google Analytics May Not be GDPR Compliant https://blog.bitdiscovery.com/2022/01/google-analytics-may-not-be-gdpr-compliant/ https://blog.bitdiscovery.com/2022/01/google-analytics-may-not-be-gdpr-compliant/#respond Thu, 20 Jan 2022 22:49:02 +0000 https://blog.bitdiscovery.com/?p=543
Robert Hansen
Google Analytics May Not be GDPR Compliant
I got a notice from a marketing friend of mine that may point to the fact that GDPR forbids the use of Google Analytics. Google Analytics is one of the most widely used ways to identify traffic on websites, and the implications of its non-compliance are wide-reaching as not many ...

Read More
]]>
0
Python NaN Injection https://blog.bitdiscovery.com/2021/12/python-nan-injection/ https://blog.bitdiscovery.com/2021/12/python-nan-injection/#respond Wed, 29 Dec 2021 19:03:10 +0000 https://blog.bitdiscovery.com/?p=531
Robert Hansen
Python NaN Injection
Python is often called “type safe” by people who aren’t aware of the fact that it is actually “duck typed” in the sense that if the variable ‘walks like a duck and talks like a duck, it must be a duck’. A variable can be injected with a string called NaN (which stands ...

Read More
]]>
0
An Introduction to “Scan Everything” https://blog.bitdiscovery.com/2021/09/an-introduction-to-scan-everything/ https://blog.bitdiscovery.com/2021/09/an-introduction-to-scan-everything/#respond Tue, 14 Sep 2021 08:16:16 +0000 http://blog.bitdiscovery.com/?p=513
Robert Hansen
An Introduction to “Scan Everything”
At Bit Discovery, we often must walk both clients and potential clients through the rational objection to the idea of adding everything to their inventory and then testing everything that they find.  The concern is understandable – it’s expensive, creates duplicate workload, potentials for false positives grow, and any additional ...

Read More
]]>
0
Bit Discovery Raises $4 Million Series B as Attack Surface Management Gains Momentum https://blog.bitdiscovery.com/2021/06/series-b-funding/ https://blog.bitdiscovery.com/2021/06/series-b-funding/#respond Fri, 25 Jun 2021 07:51:31 +0000 http://blog.bitdiscovery.com/?p=504
Jeremiah Grossman
Bit Discovery Raises $4 Million Series B as Attack Surface Management Gains Momentum
Bit Discovery Raises $4 Million Series B as Attack Surface Management Gains Momentum
]]>
0
10 Reasons Why Websites STILL Get Hacked https://blog.bitdiscovery.com/2021/06/10-reasons-why-websites-still-get-hacked/ https://blog.bitdiscovery.com/2021/06/10-reasons-why-websites-still-get-hacked/#respond Thu, 24 Jun 2021 06:32:18 +0000 http://blog.bitdiscovery.com/?p=501
Jeremiah Grossman
10 Reasons Why Websites STILL Get Hacked
1. Over 2 billion Internet-connected assets are listening on ports 80 and 443, each most likely containing some number of vulnerabilities. Do the math. 2. Most companies remain unaware of the websites they own, what they do, or who is responsible for them. Obviously, you can only scan and secure what ...

Read More
]]>
0
False Negatives in Attack Surface Mapping https://blog.bitdiscovery.com/2021/06/false-negatives-in-attack-surface-mapping/ https://blog.bitdiscovery.com/2021/06/false-negatives-in-attack-surface-mapping/#respond Thu, 10 Jun 2021 06:49:56 +0000 http://blog.bitdiscovery.com/?p=497
Robert Hansen
False Negatives in Attack Surface Mapping
On occasion, there will be an asset that slips through the cracks, and there is a wide variety of reasons for it. Not all assets are made equal, so while an asset may be missed, the ones that are missed are often the least important in terms of risk, but ...

Read More
]]>
0
HTML Search https://blog.bitdiscovery.com/2021/06/html-search/ https://blog.bitdiscovery.com/2021/06/html-search/#respond Mon, 07 Jun 2021 07:49:32 +0000 http://blog.bitdiscovery.com/?p=494
Robert Hansen
HTML Search
One of the most powerful features within Bit Discovery is an often overlooked one – the HTML search. It is so simple, yet so powerful. It gives you the unique ability to “see” what is on each homepage within your environment without having to look at each page.  Think of ...

Read More
]]>
0
0days Do not Wait for CVEs https://blog.bitdiscovery.com/2021/06/0days-do-not-wait-for-cves/ https://blog.bitdiscovery.com/2021/06/0days-do-not-wait-for-cves/#respond Thu, 03 Jun 2021 06:35:31 +0000 http://blog.bitdiscovery.com/?p=490
Robert Hansen
0days Do not Wait for CVEs
What if I were to tell you that an attack surface map can be more effective at finding critical vulnerabilities in some cases than a traditional network vulnerability scan? Crazy to think about, I know.  To understand why it is crucial, you must first understand that CVEs do not matter ...

Read More
]]>
0
IT Audit Use Case https://blog.bitdiscovery.com/2021/05/it-audit-use-case/ https://blog.bitdiscovery.com/2021/05/it-audit-use-case/#respond Thu, 27 May 2021 05:35:13 +0000 http://blog.bitdiscovery.com/?p=481
Robert Hansen
IT Audit Use Case
I had the pleasure of talking to an IT Audit organization that had been using Bit Discovery extensively to protect themselves and audit external IT. When they mean external, they really mean companies they have either acquired or are about to acquire.  We usually don’t get a lot of insight ...

Read More
]]>
0
The Right Way to do Attack Surface Mapping https://blog.bitdiscovery.com/2021/05/the-right-way-to-do-attack-surface-mapping/ https://blog.bitdiscovery.com/2021/05/the-right-way-to-do-attack-surface-mapping/#respond Mon, 17 May 2021 14:10:24 +0000 http://blog.bitdiscovery.com/?p=476
Robert Hansen
The Right Way to do Attack Surface Mapping
This post is the eighth and last of a short series of posts that we have dubbed “Attack Surface Mapping the Wrong Way,” showing the wrong ways that people/companies/vendors attempt to do attack surface mapping. In this final post, I will show the right way. The answer: Start with Everything So now ...

Read More
]]>
0