browserrecon - Passive Browser Fingerprinting

Wednesday, May 14th, 2008

Most of todays tools for fingerprinting are focusing on server-side services. Well-known and widely-accepted implementations of such utilities are available for http web services, smtp mail server, ftp servers and even telnet daemons. Of course, many attack scenarios are focusing on server-side attacks. Client-based attacks, especially targeting web clients, are becoming ...

‘Long-Term’ Phishing Attack Underway

Monday, April 28th, 2008

The notorious Rock Phish gang has added a new twist to its phishing exploits that doesn’t require its victim to visit a malicious Website -- instead, it just loads a malicious keylogging Trojan onto the victim’s machine that steals information or credentials. Both Trend Microand F-Secure over the past few days ...

sqlninja 0.2.2 Released - SQL Injection Tool

Tuesday, April 15th, 2008

Sqlninja is a tool targeted to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end.  Its main goal is to provide a remote shell on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to ...

New Crimeware-as-a-Service Market Thriving

Sunday, April 13th, 2008

First it was do-it-yourself malware and phishing toolkits, then it was specialized sites selling stolen FTP credentials and credit card accounts, and now it’s the next phase in cybercrime: crimeware as a service. Researchers at Finjan, MarkMonitor, and Trend Micro are among those seeing a new cybercrime business model, where ...

FTP Bug Leaves IE Users Vulnerable

Wednesday, March 12th, 2008

A flaw in the way Microsoft's Internet Explorer browser processes FTP commands could let attackers steal or erase data from a victim's FTP site. The bug, which affects users of IE 6 and the unsupported IE 5 browser, gives an attacker a way of hijacking the victim's FTP sessions. But a ...

Problems updating AVG?

Saturday, March 8th, 2008

Navigate to your AVG install directory and rename your existing url.ini file to url.iniold.Copy the following and paste into notepad and save it as url.ini. Put this new file into your AVG install directory. You'll now have 3 options to select from with www.grisoft.com being the default.[SERVER_NAME] 1=free.grisoft.cz 2=ftp.grisoft.com 3=www.grisoft.com [SERVER_URL] 1=http://free.grisoft.cz/softw/60/fe 2=ftp.grisoft.com/pub/softw/60/fe/ 3=http://www.grisoft.com/softw/60/fe/ Actual URL=3