Archive for February, 2007
Tuesday, February 27th, 2007
It seems that debate over the automatic tools vs. manual penetration tools raises serious questions within the government agencies.South Carolina and Delaware already use Core Impact, other might follow:
Leave Comment » | Posted in Articles, Penetration Testing
Monday, February 26th, 2007
Nick Baskett wrote an interesting article in it-observer about best practices when hiring an external penetration testing consultant. I hope that more and more business decision makers will apply his advices :
Leave Comment » | Posted in Articles, Penetration Testing
Friday, February 23rd, 2007
If there is any mention of XSS, there is a big chance RSnake’s name or its cheat sheet is mentioned along with it. His contribution in the web application security awareness is legendary.
Leave Comment » | Posted in Articles, Web Applications
Wednesday, February 21st, 2007
It seems that Esser’s initiative to disclose one PHP vulnerability each day during March 2007 is unpopular among core PHP developers, especially for Zeev Suraski, co-creator of PHP and chief technology officer of Zend, which manages PHP development.
Leave Comment » | Posted in Month Of PHP Bugs, Open Mike, Web Applications
Tuesday, February 20th, 2007
ABC News reports on a new attack vector targeted at broadband routers / acces points : Drive-By Pharming.
Leave Comment » | Posted in Articles, Web Applications
Monday, February 19th, 2007
I stumbled upon yet another blind SQl injection tool called sqlmap written by Bernardo Damele and Daniele Bellucci. I didn’t have time to test it, but the tool’s description is quite ambitious
Leave Comment » | Posted in Sql Injection, Tools
Saturday, February 17th, 2007
Tenable puts a cool Antivirus deployment Audit checks into it’s ground breaking Nessus tool. Compliance is the universal security obsession and I think Nessus will move more and more into this area. Quote:
2 Comments » | Posted in Tools, Vuln. Scanner
Saturday, February 17th, 2007
The other day I attended a meeting where I got hit by a new concept .It is the unfortunate brainchild of the new age of risk management and compliance obsession. So it goes like this : Compliance = Vulnerability.
2 Comments » | Posted in Open Mike
Thursday, February 15th, 2007
The February 2007 10th issue of (IN)SECURE Magazine is out ! The topics which are covered include : Microsoft Windows Vista: significant security improvement? Review: GFI Endpoint Security
Leave Comment » | Posted in Articles
Monday, February 12th, 2007
The (in) famous Adobe Acrobat Reader Plugin Universal PDF XSS is the scariest vulnerability discovered this year because it can turn any pdf into an XSS attack vector.
Leave Comment » | Posted in Articles, Web Applications
Pages (2): [1] 2 »