Archive for January, 2007

The Cross-site Request Forgery FAQ

The Cross-site Request Forgery FAQ has been released to address some of the common questions and misconceptions regarding this commonly misunderstood web flaw.

iWar – The first war dialer with VoIP functionality

One of the best War Dialers I came across . Current Features: Full and Normal logging: Full logging records all possible events during dialing (busy signals, no answers, carriers, etc). By default it only records things that we might find interesting (carriers, possible telco equipment). ASCII flat file and MySQL logging: You can log to [...]

New GUI for OVAL scanner

SSA is a GUI that relies on OVAL Framework (see oval.mitre.org) http://www.security-database.com/

NetBIOS NULL Sessions Explained

Here is a good resource on the good, the bad and the ugly of using NetBIOS NULL Sessions as attack target

Page 4 of 6« First...23456