Vulnerability in MHTML Could Allow Information Disclosure

Saturday, January 29th, 2011

Microsoft is investigating new public reports of a vulnerability in all supported editions of Microsoft Windows. The vulnerability could allow an attacker to cause a victim to run malicious scripts when visiting various Web sites, resulting in information disclosure. This impact is similar to server-side cross-site scripting (XSS) vulnerabilities. Microsoft ...

Security tool uncovers multiple bugs in every browser

Tuesday, January 4th, 2011

Browser security specialist Michal Zalewski believes that Chinese hackers have long been aware of a security vulnerability in Internet Explorer which has only recently come to public attention. It is believed that this vulnerability could be exploited to infect computers, though current efforts have succeeded only in provoking crashes. The ...

Armitage – graphical cyber attack management tool for Metasploit

Sunday, November 28th, 2010

Armitage is a graphical cyber attack management tool for Metasploit that visualizes your targets, recommends exploits, and exposes the advanced capabilities of the framework. Armitage aims to make Metasploit usable for security practitioners who understand hacking but don't use Metasploit every day. If you want to learn Metasploit and grow ...

Windows Kernel Bug May Bypass User Account Control

Saturday, November 27th, 2010

Another 0-day bug on the Windows platform is affecting win32k.sys (a critical component of the Windows kernel), and this time, the approach seems to pose a major challenge to the security world. This vulnerability is triggered by a buffer overflow in the kernel file, which allows code to bypass UAC ...

Most SSL Sites Poorly Configured

Saturday, July 31st, 2010

The good news about SSL-based websites: Most are running strong encryption. The bad news: More than 60 percent aren't properly configured.Researcher Ivan Ristic, who is director of engineering, Web application firewall, and SSL at Qualys, revealed findings here yesterday from a study he conducted of some 120 million registered domain ...