I keep forgetting this great link.
XSS from IronGeek
A great site. And a very useful XSS post.
Showing posts with label Exploits. Show all posts
Showing posts with label Exploits. Show all posts
Friday, January 15, 2010
Tuesday, June 9, 2009
U.S. Army servers breached
ZDNet has an article on U.S. Army servers being breached by hackers. I've written before about the project I last worked on; acquiring data in order to certify applications that are moving off an army base. The problem discussed in the article is pervasive, and I think we did a good job of helping the developers and admins find some of these potent vulnerabilities and get them on their road to recovery.
I hope to get up a post on our methodology for completing the task. Hopefully, I can get some positive and negative feedback.
I hope to get up a post on our methodology for completing the task. Hopefully, I can get some positive and negative feedback.
Tuesday, December 16, 2008
Microsoft IE and the out-of-bound-patch
By now, the news has made it's rounds that Microsoft is releasing an out-of-bound patch for the zero-day exploit regarding IE. What I find interesting is....with so many people/news outlets/blogs/etc suggesting to switch browsers AWAY from IE, it seems MS was forced into pushing a patch out early. If the exploit did not impact IE, would the patch come so quick?
Just musing....
Just musing....
Tuesday, December 2, 2008
MS08-067
In testing today, we found some servers that had some massive vulnerabilities on them. Severe enough that the organization would NOT get accreditation because of the vulnerabilities. One of the main vulnerabilities that we saw popping up were servers that were not patched for MS08-067. And just today I see a report on worms exploiting the patch. A link dump from SANS:
http://www.theregister.co.uk/2008/11/26/conficker_attacks_windows/s
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9121660&source=rss_topic17s
http://news.cnet.com/8301-1009_3-10109080-83.html?part=rss&subj=news&tag=2547-1009_3-0-20
http://www.securityfocus.com/brief/862
http://www.heise-online.co.uk/security/Windows-worm-infection-accelerates--/news/112077
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9121958&source=rss_topic17
http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspx
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspxs
http://www.theregister.co.uk/2008/11/26/conficker_attacks_windows/s
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9121660&source=rss_topic17s
http://news.cnet.com/8301-1009_3-10109080-83.html?part=rss&subj=news&tag=2547-1009_3-0-20
http://www.securityfocus.com/brief/862
http://www.heise-online.co.uk/security/Windows-worm-infection-accelerates--/news/112077
http://www.computerworld.com/action/article.do?command=viewArticleBasic&articleId=9121958&source=rss_topic17
http://blogs.technet.com/mmpc/archive/2008/11/25/more-ms08-067-exploits.aspx
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspxs
Subscribe to:
Posts (Atom)