New URL Shortener Hijacks Browsers for DDoS

Tuesday, December 21st, 2010

In order to outline the dangers of implicitly trusting shortened URLs, a student has launched a service which generates links that take users to their destination, but also hijack their browsers for DDoS.  Called d0z.me, the service is the creation of Ben Schmidt (@supernothing307), a computer science major at University ...

evercookie

Friday, October 22nd, 2010

evercookie is a javascript API available that produces extremely persistent cookies in a browser. Its goal is to identify a client even after they've removed standard cookies, Flash cookies (Local Shared Objects or LSOs), and others. evercookie accomplishes this by storing the cookie data in several types of storage mechanisms ...

Update your browsers!

Tuesday, October 19th, 2010

Today, Firefox moved up to 3.6.11 and Google Chrome (stable release) moved up to 7.0.517.41. Lots of security fixes in these new versions.

Private browsing: it’s not so private

Friday, August 13th, 2010

Research by Stanford University to investigate the privacy of the "private browsing" feature of many Web browsers suggests that the tools aren't all that private after all, and that many kinds of information can be leaked by browsers when using the mode. The paper is due to be presented next week ...

Most SSL Sites Poorly Configured

Saturday, July 31st, 2010

The good news about SSL-based websites: Most are running strong encryption. The bad news: More than 60 percent aren't properly configured.Researcher Ivan Ristic, who is director of engineering, Web application firewall, and SSL at Qualys, revealed findings here yesterday from a study he conducted of some 120 million registered domain ...