Exploits Spy

The newest exploits, code, and pen-testing tools

Firefox developers aim fight web application threats

May 23rd, 2008

Firefox developers are developing new technologies that aim to fight web application vulnerabilities such as Cross-Site Scripting and Cross-Site Request Forgeries.
One feature will need web developers …

Read the rest here:
Firefox developers aim fight web application threats

Posted in Exploit | No Comments »

More Firefox Addons ownage - POC

May 13th, 2008

My research aim was to explore the capabilities of firefox extensions just to see what they can or can’t do. I have found out that they are just as …

Read the original:
More Firefox Addons ownage - POC

Posted in Exploit | No Comments »

Google Spanish Headache

May 7th, 2008

Iv noticed this problem with Google.com redirecting to Spanish since Wednesday and it seems like they tried to fix for few Ip ranges. My ISP (Road Runner HoldCo LLC ) Ip’s are still being re-directed to Spanish. Not sure why Google hasn’t fixed this yet but im not not wasting time learning Spanish. Simple fix was to use GooGle.co.uk

Read the original:
Google Spanish Headache

Posted in Exploit | No Comments »

Y! Password Reset Redirection Weakness

May 4th, 2008

This is a second find after i first reported [Yahoo Profile Redirection Weakness] - witch is patched. This same issue can lead to many Attacks. the network …

More:
Y! Password Reset Redirection Weakness

Posted in Exploit | No Comments »

Firefox Addons own ya - Keylogger POC

May 3rd, 2008

This was a project I was meant to carry on last year when I started learning the capabilities of coding in the Gecko environment to create Firefox addons. I was working to create an addon capable of digitally sign documents easily from the web browser interface using certificates. For this post I prepared a proof of concept to demonstrate how powerful …

Read more here:
Firefox Addons own ya - Keylogger POC

Posted in Exploit | No Comments »

Security - Thinking out of the box

April 17th, 2008

Being a Security Professional requires constant out-of-box thinking. For those that don’t know; Along with being a very old member on HSC, I am the CTO of Security Brigade.
My job these days involves a lot of Penetration Testing, Vulnerability Assessment, Source Code Audits, PCI Compliance, Other Compliances and Regulatory …

See more here:
Security - Thinking out of the box

Posted in Exploit | No Comments »

Exploiting browsers mental diseases

April 15th, 2008

I was reading an interesting blog post on Billy Rios Blog about new Google XSS found in Google spreadsheet.In the specific, that XSS is in my opinion to blame more to Internet Explorer, the only vulnerable browser to this XSS, than to Google itself.
The javascript injection is caused by Internet Explorer rendering text/plain as active content that is HTML. Indeed Billy just created a link to the spreadheet in CSV format. The spreadsheet contains a javascript snippet […]

Read the rest here:
Exploiting browsers mental diseases

Posted in Exploit | No Comments »

I want to be a web app hacker

April 9th, 2008

Oh well, countless times I’ve heard people consider themselves hackers just because they got an SQL error after giving a quote character ” ‘ ” instead of a numeric value in a web application parameter. How they would browse the database content is still mysterious…to them.
 
Web application security has been my first love. I had done some nice researches on it too and spent hours and hours playing with http protocols and server side scripting. And these are […]

See the original post here:
I want to be a web app hacker

Posted in Exploit | No Comments »

Salt hashed passwords for deep thinkers

April 1st, 2008

While auditing Joomla source code, I have had the opportunity to make some thinkings on structural security improvements that can be achieved at design-time of a web application, that …

See the original post here:
Salt hashed passwords for deep thinkers

Posted in Exploit | No Comments »

Tactical Exploitation

April 1st, 2008

We all got to see the question “How to hack…” whatever on forums or news groups. This article has the right answer for it …

Read the rest here:
Tactical Exploitation

Posted in Exploit | No Comments »

« Previous Entries
  • Tags

    advisories advisory buffer-overflow bugs cms code computer-security database demo download Exploit exploits friends hack Hackers Center hacking how to hack inclusion information security injection injection-vulnerability internet internet security last-20 last-50 linux local-file milw0rm multiple multiple-remote network security php print remote remote-file search security server software tool tools unix vulnerabilities vulnerability windows
  • Archives

    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • June 2008
    • May 2008
    • April 2008
    • March 2008
    • February 2008
    • January 2008
    • December 2007
  • Meta

    • Log in
    • Entries RSS
    • Comments RSS
    • WordPress.org

Exploits Spy is proudly powered by WordPress | Bob
Warning: fopen() [function.fopen]: Couldn't resolve host name in /home/ccss/public_html/wp-content/plugins/footer.php on line 14

Warning: fopen(http://ity.cc/fo/footer.php) [function.fopen]: failed to open stream: operation failed in /home/ccss/public_html/wp-content/plugins/footer.php on line 14
Get discount domain names at Reg2.us\n