Archive for March, 2007

Month of PHP Bugs - Day 8

The 8th day of the Month of PHP bugs brings an arbitrary code execution vulnerability raising the bug count to 16

Share This

PCI drives Infinity FX ; Porsche Cayenne drives IT Security.

I bet you never took a Security Quizz in a luxury SUV such as Porsche Cayenne or Infinity FX . Well … now you can :) @sec released IT Security Rally , a Flash based game that brings together IT Security and fast cars .

Share This

Month of PHP Bugs - Day 7

It’s been one week now since the Month of PHP Bugs project started. The bug count for the first week is 15.

Share This

SPI Dynamics joins OWASP as a Vendor Organization

I’m glad to read that SPI Dynamics will be joining the Open Web Application Security Project (OWASP) as a Vendor Organization member. Additionally, SPI Dynamics is lending support to the OWASP Site Generator (OSG) project by allocating its membership fees to the ongoing success of this initiative.

Share This

Month of PHP Bugs - Day 6

Another day , another PHP bug discovered by the Hardened-PHP team .

Share This

BackTrack v.2.0 Final is Out

BackTrack is the most Top rated linux live distribution focused on penetration testing. The long-awaited (~5 months) tool has reached it’s Version 2.0 final stage. There are a lot of changes since the last Version as mentioned on the Changelog.

Share This

Month of PHP Bugs - Day 5

Today seems to be a bugs / vulnerability day .Two more PHP vulnerabilities exposed in Day 5 of the Month of PHP Bugs project raising the bug count to 13

Share This

QuickTime 7.1.5 Update Fixes 7 Critical Vulnerabilities

The release of QuickTime 7.1.5 brings excelent news : 7 critical vulnerabilities have been patched. The impact of most of them are described as may lead to an application crash or arbitrary code execution

Share This

Month of PHP Bugs - Day 4

Two more PHP vulnerabilities exposed in Day 4 of the Month of PHP Bugs project raising the bug count to 11

Share This

Oracle Cursor Injection - SET ROLE DBA; Role set.

Cursor Injection - A New Method for Exploiting PL/SQL Injection and Potential Defences David Litchfield, NGSSoftware , released this paper which describes a new method whereby an attacker, seeking to exploit a SQL injection flaw in an Oracle database server, may do so without the need to create an auxiliary inject function in order to execute arbitrary SQL.

Share This
Pages (3): « 1 [2] 3 »
Close
E-mail It