Improving Security with URL Rewriting

Thursday, April 9th, 2009

Most web application security experts frown on the practice of passing session or authentication tokens in a URL through the use of URL rewriting. Usually these tokens are passed between the server and the browser through HTTP cookies, but in cases where users configure their browsers to not accept cookies, ...

Browser plugin blocks ad-tracking cookies

Tuesday, March 17th, 2009

A researcher has developed a browser extension that stops advertising networks from tracking a person's surfing habits, such as search queries and content they view on the web. The extension, called Targeted Advertising Cookie Opt-Out (TACO), enables its users to opt out of 27 advertising networks that are employing behavioural advertising ...

GMail Service CSRF Vulnerability

Tuesday, March 3rd, 2009

Gmail is Google's "free webmail service. It comes with built-in Google search technology and over 2,600 megabytes of storage (and growing every day). You can keep all your important messages, files and pictures forever, use search to quickly and easily find anything you're looking for, and make sense of it ...

Koobface Variant Hits Facebook

Tuesday, March 3rd, 2009

Researchers at Trend Micro are reporting that a new variant of the Koobface worm is spreading on Facebook. Koobface first appeared in 2008, with separate variants striking members of Facebook and MySpace.com. Now the Koobface worm is back again, with an eye toward stealing cookies for other social networking sites. According to ...

Facebook Beacon Blocker

Monday, January 26th, 2009

Facebook Beacon is part of Facebook’s advertising efforts. It is basically a cooperation with 44 partner sites who execute JavaScript code on their website sending specific user information to Facebook. Examples would be the popular gaming portal Kongegrate which send information about played games to Facebook, movie reviews published at ...