Wells Fargo Passwords Are Not Case-Sensitive!

Friday, September 5th, 2008

I just heard on the Security Now podcast a listener mention that his Wells Fargo password was not case-sensitive.  I'm not a Wells Fargo user but several users who are that I asked this morning actually confirmed this.  You will be logged in no matter what case you enter into ...

New attack against multiple encryption functions

Saturday, August 23rd, 2008

Unless you're a dyed in the wool cryptographic geek you probably didn't know that there was a Crypto conference, or even a chain of worldwide crypto conferences that take place each year. Fortunately, for the most of us that aren't crypto geeks there are a handful of very highly skilled ...

Adobe: Beware of fake Flash downloads

Tuesday, August 5th, 2008

Amidst confirmed reports that malicious hackers are starting to use fake Flash Player downloads as social engineering lures for malware, Adobe has issued a call-to-arms for users to validate installers before downloading software updates.The company’s notice comes on the heels of malware attacks on Facebook, MySpace and Twitter that attempt ...

Opera Arioso!

Tuesday, July 8th, 2008

I'm pretty excited by Opera's Userscripts that allow you to write Javascript files that are far richer than greasemonkey Userscripts -which is also supported by Opera- I've written a security plugin for Opera last night, that attempts to mitigate various Javascript attack vectors. But, one problem for writing a security ...

Crawling AJAX

Saturday, July 5th, 2008

Traditionally, a web spider system is tasked with connecting to a server, pulling down the HTML document, scanning the document for anchor links to other HTTP URLs and repeating the same process on all of the discovered URLs. Each URL represents a different state of the traditional web site. In ...