Gmail Security Flaw Proof of Concept

Monday, November 24th, 2008

Is it possible for someone to create a malicious filter without having access to your Gmail username and password? No, however, they can force you to create the filter without your knowledge. The blogosphere is buzzing about a Gmail Security Flaw that has caused some people to lose their domain names ...

Android flaw executed typed text

Monday, November 10th, 2008

With the news that Google's Android shipped with an embarrassing security hole being followed by a simple two-step method to 'jailbreak' the OS, you'd think that the company had ironed out most of the remaining bugs – but you'd be wrong. According to ZDnet's Ed Burnette, the open-source Linux-based smartphone platform ...

Fake WordPress steals data

Thursday, November 6th, 2008

Yesterday evening amid the researching the Barack related malware our friends at The Register pointed out an interesting article on Craig Murphy’s blog. Craig talks about how when he logged in to his admin account in WordPress he received a “High Risk Vulnerability Warning” from a spoofed WordPress domain. (The last ...

Ruby On Rails Security Guide published as free ebook

Tuesday, November 4th, 2008

The Ruby on Rails Security Project have published a Ruby on Rails Security Guide as a free e-book and also made it available as HTML. The guide covers how to secure Ruby on Rails applications, looking at, sessions and how to manage them securely, cross site forgery, redirection and other ...

Adobe fixes clickjacking flaw

Thursday, October 16th, 2008

Adobe Systems has released a new version of its Flash Player software, fixing a critical security bug that could make the Internet a dangerous place for Web surfers. The new Flash Player 10 software, released Wednesday, fixes security flaws in Adobe's multimedia software including bugs that could allow hackers to pull ...