Menu

Skip to content
  • Home
    • Surviving The Week
    • About
      • Contact
  • Podcasts (AppSec)
    • Hands On Series
    • Infosec Place
    • Podcast Setup
  • Web Hacking Survival Kit
    • Free SQL Injection Tool
    • SQL Injection Cheat Sheet
    • Injection Cheat Sheet
    • Pentesting Tools
    • Browser Extensions
    • News Sources
  • PodPress
    • podPress Donors
    • Donor Club
    • PodPress Tutorial
    • PodPress ChangeLog
  • Dev
    • PodPress
    • phpGroupware
    • INNRevival Installer
  • NT OBJECTives
    • NTOSpider
    • NTOEnterprise
    • NTO On-Demand
    • NTODefend
Surviving the Week 2/1/13 – Ruby on Rails – JSON Parser Vulnerability

Surviving the Week 2/1/13 – Ruby on Rails – JSON Parser Vulnerability

Ruby on Rails – JSON Parser Vulnerability The JSON parser which converts JSON into YAML and in turn hands over to the YAML parser is buggy. The fix delivered replaces the YAML backend (yaml.rb) which…

Full Article →

Posted by: NTO Research Team // Attack Types, JSON, Surviving The Week, XSS // February 7, 2013 // Comment
Tweet that, Twitter Hack: Potentially 250,000 users compromised

Tweet that, Twitter Hack: Potentially 250,000 users compromised

Last week, hackers gained access to Twitter’s internal systems and stole information, compromising 250,000 accounts. In a blog post, on Friday, Twitter announced that they had recorded some unusual access patterns that was identified as…

Full Article →

Posted by: Nauman Ashraf // Misc // February 5, 2013 // Comment
PayPal plugs SQL Injection Hole

PayPal plugs SQL Injection Hole

An Indian researcher, Prakhar Prasad found a Blind SQL Injection vulnerability in the Paypal Notifications (https://www.paypal-notify.com) application as part of a bug bounty program. The bug enabled him to access the Paypal Notifications system database. The Paypal team patched…

Full Article →

Posted by: Kim Dinerman // Misc // February 5, 2013 // Comment
Did Twitter set users up for future phishing attacks?

Did Twitter set users up for future phishing attacks?

On the morning of the Twitter attack, I received this email: On one hand, I appreciate that Twitter was up front with their users, but it also bothers me when companies make use of bad…

Full Article →

Posted by: Dan Kuykendall // Misc, Security, Web App Sec // February 4, 2013 // Comment
Techniques for creating secure passwords

Techniques for creating secure passwords

Most people are starting to realize that they need to start using more complex passwords, but generally believe: complex password = hard to remember This is not true. The solution I have been using for…

Full Article →

Posted by: Dan Kuykendall // Misc, Security // February 4, 2013 // Comment
Mobile App Security – Application Security’s “Where’s Waldo”

Mobile App Security – Application Security’s “Where’s Waldo”

As I have discussed in previous posts and at conferences, like OWASP AppSecUSA, while the number of attacks continue to increase, the attack techniques aren’t new at all. They are actually the same old attacks…

Full Article →

Posted by: Dan Kuykendall // Misc, Mobile, NT OBJECTives, Security, Web App Sec // February 1, 2013 // 2 Comments
Security B-Sides SF 2013: The Pineapple Express: Live mobile application hacking demo…

Security B-Sides SF 2013: The Pineapple Express: Live mobile application hacking demo…

All aboard the Pineapple Express, its a speeding bullet to the mobile backend! I’m looking forward to speaking at the upcoming B-Sides San Francisco. Most of the mobile security research has been focused on the apps…

Full Article →

Posted by: Dan Kuykendall // Hands On Series, Misc, Mobile // January 28, 2013 // Comment
Anonymous Strikes Again in the Name of Aaron Swartz & Hacks US Sentencing Commission

Anonymous Strikes Again in the Name of Aaron Swartz & Hacks US Sentencing Commission

Anonymous Hackers hacked and defaced United States Sentencing Commission under the operation called “#opLastResort”. And also threatened the US government to release sensitive information. Hacked Site: http://www.ussc.gov   Cached Deface Page on Google: The website…

Full Article →

Posted by: Nauman Ashraf // Misc // January 28, 2013 // Comment
Surviving the Week 1/25/13 – The Widening Web App Security Scanner Coverage Gap

Surviving the Week 1/25/13 – The Widening Web App Security Scanner Coverage Gap

New White Paper: The Widening Web Application Security Scanner Coverage Gap in RIA, Mobile and Web Services – Is Your Scanner Like the Emperor’s New Clothes? The research detailed in this white paper explains the…

Full Article →

Posted by: Dan Kuykendall // Misc // January 25, 2013 // Comment
DNS Attack Takes Down Google Morocco

DNS Attack Takes Down Google Morocco

Google Morocco was the latest victim of a Domain Name System or DNS attack. A notorious Pakistani leet hacker group named, “PAKbugs”, hijacked Google Morocco’s official website (www.google.co.ma). Defaced Page: This is not the first…

Full Article →

Posted by: Nauman Ashraf // Misc // January 25, 2013 // Comment
Page 2 of 20‹ Previous1234567Next ›Last »

Search

Follow Us

 Facebook Google+ Twitter LinkedIn YouTube RSS E-mail
http://paydayloansuk.uk.com/

NTOSpider - FREE TRIAL
Is Your Scanner Like the Emperor’s New Clothes? - White Paper
Free SQL Injection Tool - NTO SQL Invader

Archives

Categories

  • 2013 B-Sides San Francisco (4)
  • AMF – Flash Remoting (1)
  • Application Security Strategies (2)
  • Attack Types (1)
  • CSRF/XSRF Tokens (1)
  • Gartner (1)
  • Google Web Toolkit (GWT) (1)
  • Hands On Series (3)
  • HTML5 (1)
  • Infosec Place (14)
  • Interactive Application Security Testing (IAST) (2)
  • JSON (2)
  • Misc (60)
  • Mobile (7)
  • Network (4)
  • NT OBJECTives (20)
  • Physical (1)
  • Podcasting (11)
  • Podcasts (AppSec) (33)
  • podPress (10)
  • REST (1)
  • RSA (2)
  • Securing Mobile Applications (1)
  • Securing Web Services (1)
  • Security (59)
  • Security Conference Presentation Summaries (2)
  • Side channel attacks (1)
  • Surviving The Week (52)
  • Tales from the Web Scanning Front (4)
  • Watch Your SaaS (1)
  • Web App Sec (81)
  • XSS (1)

Recent Comments

  • Dan Kuykendall on Mobile App Security – Application Security’s “Where’s Waldo”
  • Mobile hacker on Mobile App Security – Application Security’s “Where’s Waldo”
  • NT Obejctives on Web Application Security Scanning – The Art of Automation
  • Kim Dinerman on Payback on Web Attackers: Web Honeypots (OWASP AppSecUSA Presentation Review)
  • Simon Roses Femerling on Payback on Web Attackers: Web Honeypots (OWASP AppSecUSA Presentation Review)

Tags

2013 San Francisco B-Sides @jimio Application Security Application Security Program Tips & Tricks Application security re-scans Application security reporting B-Sides Botnets BSidesLV Cert-Pinning CRIME and BEAST SSL/TLS Attacks Defcon Dynamic Application Security Testing Gartner Ghost in the Wires HTML5 intrustion prevention system IPS Iran drone hack Kevin Mitnick Magic Quadrant Metasploit Mobile NT OBJECTives NTODefend NTOSpider OWASP AppSecUSA Reducing scan times RSA RSA 2012 securing mobile applications Securing web services Security Conference Presentation Summaries SQL Injection SQL Server SSL Surviving The Week Tales from the Web Scanning Front Transport layer security at Twitter Twitter WAF Watch Your SaaS Web Appplication Firewall Web App Sec Wine
© 2013 Man Vs WebApp