Security

Hacking everything, by Chris Evans / scarybeasts

Monday, November 24, 2008

Cookie forcing

›
It's time to write some coherent details about "cookie forcing", which is the name I've given for a new way to attempt to ...
3 comments:
Friday, November 21, 2008

Owning the paranoid: browser background traffic

›
When I talk to a lot of security researchers or paranoid types, it's very common to hear them describe how they very carefully access th...
1 comment:
Tuesday, November 18, 2008

E4X and a Firefox XML injection bug

›
Up-front credit to my colleagues Filipe Almeida and Michal Zalewski who led the way in E4X security research. If you haven't heard of E4...
Monday, November 17, 2008

Firefox cross-domain image theft... and the "302 redirect trick"

›
Here's the first bug with full details from my PacSec presentation. It's fixed in the recent Firefox 2.0.0.18 update. Firefox 3 was ...
3 comments:
Sunday, November 16, 2008

PacSec presentation

›
My recent PacSec presentation (with Billy Rios), entitled "Cross-domain leakiness", is now online. You can view it via this link ....
Monday, October 20, 2008

Some Python bugs

›
A little late on this report, but here are some Python runtime bugs I found back in May 2007: http://scary.beasts.org/security/CESA-2008-008...
1 comment:
Saturday, August 30, 2008

Cross-domain leaks of site logins

›
Browsers suck. We're building our fortified web apps on foundations of sand. A little while back, I was talking with Jeremiah about an i...
1 comment:
‹
›
Home
View web version
Powered by Blogger.