Drive by download with iframes

does the definition of a drive by download include malicious execution of an unaccepted downloaded file or is the unaccepted download of a file the drive by download by itself. I didn’t find a good/clear definition.

Why is it possible to download files with a hidden iframe, so the user isn’t even asked if he wants to download it. Something like this:

<iframe src="" width="1" height="1" frameborder="0"></iframe> 

Isnt this way to risky?

Thank you for your answers.

My iframe on google drive folder is blocked

WordPress refuses to add this custom iframe markup:

<iframe src="" style="width:100%; height:600px; border:0;"></iframe> 

I have free plan and I’m not able to add plugins. Is it possible to add iframe that links to google drive folder with free plan and withou plugins? If yes – than how I can achieve this?

Veracrypt encrypted file – how to expand the Volume and what are Drive Letters?

can you help me understand some questions about Veracrypt:

  1. If you have created an encrypted file but the volume which you selected for it needs expansion, is it from security standpoint fine to just use the available option “expand volume” to adjust the file’s volume? Or is it for some reason better to create a totally new encrypted file with your desired larger volume?

  2. What is the meaning of all the different Drive Letters (A-Z)? Do you have to mount a file from a specific drive letter, or can you mount from any letter?


Printing document on usb drive with confidential information on multi user computer

I have a pdf file with confidential information on a usb flash drive. This document needs to be printed on a multi user Ubuntu system. I want to prevent other users from seeing the content of the document.

Assume the following procedure:

  • The usb drive is inserted to the computer and mounted.
  • The document is opened with okular or evince and printed directly from the program.
  • The usb drive is umounted and removed from the computer.

Question: What do I need to do to wipe any traces / copies of the document I printed?

First idea: I guess /tmp would be a good place to look out for – though I do not know if there will be any copies stored there or at other places. Do I have to do additional steps to remove all traces / copies?

Self encrypting drive without ATA password

Kind of new to this area so correct me if I am wrong.

Based on my reading self encrypting drive will encrypt and decrypt all data in your disk and this process is totally transparent to the user.

To make use of this feature user would need to set an ATA (HDD) password on the drive or otherwise the self encrypting feature is 100% useless. If a malicious user takes your hard drive and plug into another machine the drive will still be more than happy to decrypt the data for that malicious user. The only way to stop this would be to set an ATA password and lock it down so that the drive will not respond to any command including read/write until its unlocked by the password.

However to leverage this security feature the BIOS must support ATA password. Software based solution won’t work since you can’t even boot the system until the drive is unlocked. But the sad truth is that most mobos doesnt support ATA password which renders this feature completely redundant.

TL;DR: Is there a way to make use of this feature without BIOS ATA support? (My gaming mobo did not come with a TPM header either)

Can you set up 2FA with a USB drive?

I want to set up two factor authentication for some of my online accounts. I don’t want to install an app, and I don’t like using my phone as the physical medium anyway, because it’s more likely to get stolen and it’s also more vulnerable than a static object that I just carry around.

I’m attracted to the idea of Yubikey, but they’re a little pricey and I don’t see what they’re charging for. I don’t know exactly what is going on under the hood in 2FA, but I can’t see any reason that you couldn’t use any old USB (with the appropriate software around it).

So, my question is: can you use a USB flash drive to generate 2FA codes?

