Security

Hacking everything, by Chris Evans / scarybeasts

Thursday, March 18, 2010

vsftpd HTTP lunacy!

›
Ok, so I was bored and I added very very basic HTTP support to vsftpd. vsftpd is now perhaps the only FTP server to have an option ftp_enab...
14 comments:
Thursday, January 28, 2010

Encouraging More Chromium Security Research

›
I don't usually post non-original content here, but in this case I'll make an exception :) Here's one of the things I've bee...
Sunday, January 10, 2010

Posting raw XML cross-domain

›
I was recently stealing anti-XSRF tokens using the CSS design error I found . In the (unnamed for now) app I was exploiting, all the fun hap...
6 comments:
Saturday, January 9, 2010

"Logout XSRF" - significant web app bug?

›
[Or "Logout CSRF" for search indexes; I seem to be addicted to the less common acronym ;-)] Significant? No, of course not. It is ...
5 comments:
Monday, December 28, 2009

Generic cross-browser cross-domain theft

›
Well, here's a nice little gem for the festive season. I like it for a few distinct reasons: It's one of those cases where if you lo...
20 comments:
Tuesday, December 22, 2009

Bypassing the intent of blocking "third-party" cookies

›
[Aside: I'm not sure anyone cares, particularly because the "block third party cookies" option tends to break legitimate web s...
5 comments:
Friday, December 11, 2009

Cross-domain search timing

›
I've been meaning to fiddle around with timing attacks for a while. I've had various discussions in the past about the significance ...
9 comments:
‹
›
Home
View web version
Powered by Blogger.