Archive for the ‘Coding’ Category

Major security sites hit by XSS bugs

Thursday, June 12th, 2008

The websites of three of the security industry's best-known companies include security flaws that could be used to launch scams against customers, according to a new report. The report, from security watchdog site XSSed, verified 30 cross-site scripting (XSS) vulnerabilities across the sites of McAfee, Symantec and VeriSign. The flaws could ...

SIPVicious v0.2.3 - VoIP/SIP Auditing Toolkit

Wednesday, June 11th, 2008

SIPVicious suite is a set of tools that can be used to audit SIP based VoIP systems. It currently consists of four tools: svmap - this is a sip scanner. Lists SIP devices found on an IP range svwar - identifies active extensions on a PBX svcrack - an online password cracker for ...

Safari ‘carpet Bomb’ Attack Code Released

Wednesday, June 11th, 2008

A hacker has posted attack code that exploits critical flaws in the Safari and Internet Explorer Web browsers. The source code, along with a demo of the attack, was posted Sunday on a computer security blog. It can be used to run unauthorized software on a victim's machine, and could be ...

Nessus 3 Tutorial

Tuesday, June 10th, 2008

If you're looking for a vulnerability scanner, chances are you've come across a number of expensive commercial products and tools with long lists of features and benefits. Unfortunately, if you're in the same situation as most of us, you simply don't have the budget to implement fancy high-priced systems. You ...

Verisign, McAfee and Symantec sites can be used for phishing due to XSS

Monday, June 9th, 2008

Should they all be trusted at first sight by unsuspecting online users? Yes, unfortunately this is the case with the websites of renowned and respected IT security companies. However, now that are all vulnerable to cross-site scripting, the possibilities to get phished and infected with malware and crimeware are dramatically ...