Scrawlr – Tool for finding SQL Injection

Wednesday, October 28th, 2009

Scrawlr, developed by the HP Web Security Research Group in coordination with the MSRC, is short for SQL Injector and Crawler. Scrawlr will crawl a website while simultaneously analyzing the parameters of each individual web page for SQL Injection vulnerabilities. Scrawlr is lightning fast and uses our intelligent engine technology ...

Mozilla fixes 16 flaws with Firefox 3.5.4

Wednesday, October 28th, 2009

Mozilla today patched 16 vulnerabilities in Firefox, 11 of them critical, as it updated the open-source browser to version 3.5.4.The 11 critical Firefox 3.5 vulnerabilities were located in a variety of components, including Web worker calls, the GIF color map parser, the string-to-number converter, a trio of third-party media libraries, ...

Cain & Abel v4.9.35 released

Monday, October 26th, 2009

New in 4.9.35: - Added support for Windows 2008 Terminal Server in APR-RDP sniffer filter. - Added Abel64.exe and Abel64.dll to support hashes extraction on x64 operating systems. - Added x64 operating systems support in NTLM hashes Dumper, MS-CACHE hashes Dumper, LSA Secrets Dumper, Wireless Password Decoder, Credential Manager Password Decoder, DialUp Password ...

Cain & Abel v4.9.34 released

Sunday, October 18th, 2009

New in 4.9.34: Added support for Windows 2008 Terminal Server in APR-RDP sniffer filter. Added Abel64.exe and Abel64.dll to support hashes extraction on x64 operating systems. Added x64 operating systems support in NTLM hashes Dumper, MS-CACHE hashes Dumper, LSA Secrets Dumper, Wireless Password Decoder, Credential Manager Password Decoder, DialUp Password Decoder. Added Windows Live ...

Evil Maid goes after TrueCrypt!

Friday, October 16th, 2009

Let’s quickly recap the Evil Maid Attack. The scenario we consider is when somebody left an encrypted laptop e.g. in a hotel room. Let’s assume the laptop uses full disk encryption like e.g. this provided by TrueCrypt or PGP Whole Disk Encryption. Many people believe, including some well known security experts, ...