RedTram News Search Engine
Русский  English Українська  Français  Polski  Deutsch  Italiano  Español  中文   
21 December 2009 year (time zone GMT 00:00)  Number of sources in English: 4957
cgisecurity.com RSS 2.0

Experimenting With WASC Threat Classification Views: Vulnerability Root Cause Mapping

14.12.2009 04:41    cgisecurity.com
I currently lead the WASC Threat Classification Project and we're expecting to publish our latest version next month. One of the biggest changes between the TCv2 and TCv1 is that we're doing away with single ways to represent the data.
Experimenting With WASC Threat Classification Views: Vulnerability Root Cause Mapping



132,000+ sites Compromised Via SQL Injection

11.12.2009 01:44    cgisecurity.com
Net-Security has posted an article on the discovery of 132k+ sites that have been SQL Injected. From the article "A large scale SQL injection attack has injected a malicious iframe on tens of thousands of susceptible websites. ScanSafe reports that
132,000+ sites Compromised Via SQL Injection

Potential risks of using Google's free DNS service

05.12.2009 11:28    cgisecurity.com
Google has announced that they are offering a free DNS service to anyone wanting to use it. Unfortunately the privacy concerns aren't being discussed in as much detail as I'd like, and people aren't asking why google would offer such
Potential risks of using Google's free DNS service

Preventing Security Development Errors: Lessons Learned at Windows Live by Using ASP.NET MVC

04.12.2009 15:06    cgisecurity.com
Microsoft has published a paper on its ASP.NET MVC framework, how to use it, and how utilization of an SDL eliminates the potential to introduce vulnerabilities such as XSRF. From the paper "On the Microsoft platform, most Web applications are
Preventing Security Development Errors: Lessons Learned at Windows Live by Using ASP.NET MVC

Clientless SSL VPN products break web browser domain-based security models

02.12.2009 18:31    cgisecurity.com
A new CERT advisory has been published outlining a weakness in the way web based SSL clients operate, resulting in a Same Origin Policy breakage. Here's the meaty details. "As the web VPN retrieves web pages, it rewrites hyperlinks so
Clientless SSL VPN products break web browser domain-based security models


Nozzle: A Defense Against Heap-spraying Code Injection Attacks

25.11.2009 02:17    cgisecurity.com
Microsoft has been working on a tool called 'Nozzle' to prevent the exploitation of heap spraying attacks and released a whitepaper describing the process. From the whitepaper. "Heap spraying is a new security attack that significantly increases the exploitability of
Nozzle: A Defense Against Heap-spraying Code Injection Attacks

Symantec SQL Injected, Seeks Counseling

24.11.2009 02:23    cgisecurity.com
The Romanian hacker who successfully broke into a web site owned by security vendor Kaspersky Lab has struck again, this time exposing shortcomings in a Symantec web server. The hacker, known only as Unu, said in a blog post today
Symantec SQL Injected, Seeks Counseling

Firefox 3.6 locks out rogue add-ons

19.11.2009 07:39    cgisecurity.com
From computerworld "Mozilla will add a new lockdown feature to Firefox 3.6 that will prevent developers from sneaking add-ons into the program, the company said. The new feature, which Mozilla dubbed "component directory lockdown," will bar access to Firefox's "components"
Firefox 3.6 locks out rogue add-ons

Article: Securely deploying cross-domain policy files

18.11.2009 07:01    cgisecurity.com
Peleus from Adobe's security team has published a blog entry on how to securely deploy flash crossdomain.xml files. If you're considering using flash on your site, or already are be sure to check out this article. Article:
Article: Securely deploying cross-domain policy files

Metasploit Framework 3.3 Released

18.11.2009 07:01    cgisecurity.com
The latest version of metasploit has been released. From the announcement "We are excited to announce the immediate availability of version 3.3 of the Metasploit Framework. This release includes 446 exploits, 216 auxiliary modules, and hundreds of payloads, including an

OWASP Issues 2010 Top 10 (RC1)

16.11.2009 20:56    cgisecurity.com
At AppsecDC OWASP published the latest version of its top ten list. From the Top Ten "OWASP plans to release the final public release of the OWASP Top 10 -2010during the first quarter of 2010 after a final, one-month public
OWASP Issues 2010 Top 10 (RC1)

Heading out to AppsecDC

11.11.2009 13:42    cgisecurity.com
to present Transparent Proxy Abuse on Thursday, so if you're attending and want to chat about appsec I'll be available after my talk. Here's a teaser of my presentation I'll be presenting a video demonstrating this abuse case against Squid
Heading out to AppsecDC

TLS negotiation flaw published

10.11.2009 10:59    cgisecurity.com
Steve Dispensa and Marsh Ray have published a paper describing a weakness in the TLS negotiation process. This is the same attack discussed on the IETF TLS list. From the whitepaper "Transport Layer Security (TLS, RFC 5246 and previous, including
TLS negotiation flaw published

Amazon EC2 cloud computing for password/crypto cracking

05.11.2009 15:05    cgisecurity.com
There is a rather lengthy set of posts on using cloud based computing services as ideal venues for crypto and password cracking. Link: Link:
Amazon EC2 cloud computing for password/crypto cracking

Microsoft's Enhanced Mitigation Evaluation Toolkit adds protection to processes

29.10.2009 13:59    cgisecurity.com
Microsoft has published the Enhanced Mitigation Evaluation Toolkit. This toolkit allows you to specify a process to add the following forms of protection (without recompiling). SEHOP This mitigation performs Structured Exception Handling (SEH) chain validation and breaks SEH overwrite exploitation
Microsoft's Enhanced Mitigation Evaluation Toolkit adds protection to processes

Attacking Magstripe Gift Cards

27.10.2009 16:01    cgisecurity.com
Corsaire has published a rather lengthy paper on attacking gift card systems. While this is a little off topic it's a good read. "This paper is based on research conducted on a large number of UK gift cards. It has
Attacking Magstripe Gift Cards

Metasploit sold to Rapid7

22.10.2009 23:17    cgisecurity.com
It was announced this morning that Rapid7 has purchased metasploit, and hdmoore! That is all. Rapid7 Announcement: http://www.rapid7.com/metasploit-announcement.jsp Metasploit Blog: http://blog.metasploit.com/2009/10/metasploit-rising.html Metasploit Blog: http://blog.metasploit.com/2009/10/joining-team.html More Coverage http://www.andrewhay.ca/archives/1085
Metasploit sold to Rapid7

OWASP Publishes Transport Layer Protection Cheat Sheet

22.10.2009 23:17    cgisecurity.com
This article provides a simple model to follow when implementing transport layer protection for an application. Although the concept of SSL is known to many, the actual details and security specific decisions of implementation are often poorly understood and frequently
OWASP Publishes Transport Layer Protection Cheat Sheet

WASC Announcement: 2008 Web Application Security Statistics Published

18.10.2009 19:02    cgisecurity.com
The Web Application Security Consortium (WASC) is pleased to announce the WASC Web Application Security Statistics Project 2008. This initiative is a collaborative industry wide effort to pool together sanitized website vulnerability data and to gain a better understanding about
WASC Announcement: 2008 Web Application Security Statistics Published

One character mistake knocks .se TLD offline

15.10.2009 20:40    cgisecurity.com
What was essentially a typo last night resulted in the temporary disappearance from the Internet of almost a million Web sites in Sweden -- every address with a .se top-level down name. According to Web monitoring company Pingdom, which happens

1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 | 11 ... 24 »