Security
Hacking everything, by Chris Evans / scarybeasts
Thursday, February 24, 2011
I got accidental code execution via glibc?!
›
The story of Chromium security bug 48733 , with guest Cris Neckar, part I It has been a long time now, but the story of Chromium security bu...
5 comments:
Wednesday, February 16, 2011
Some less obvious benefits of HSTS
›
HSTS , standing for HTTP Strict Transport Security, is a relatively new standard that aims to bolster the strength of HTTPS connections. Hop...
5 comments:
Wednesday, January 19, 2011
A harmless SVG + XSLT curiousity
›
How do you execute code in a turing complete language via the <img> tag? Why, by combining an XSL transform into an SVG image of cour...
2 comments:
Thursday, October 21, 2010
Minor leak, major headache
›
I find this bug interesting, because at first it looks like a relatively minor cross-origin leak. But with a bit of investigation, it has ma...
3 comments:
Wednesday, September 29, 2010
IE8 CSS-based forced tweeting
›
A few weeks back, I published a demo that uses a serious Internet Explorer cross-origin violation to permit a malicious web page to force th...
3 comments:
Wednesday, August 4, 2010
Internet Explorer considered harmful
›
Now that this paper is officially public, the full story of CSS-based cross-origin theft can come out. (As an aside I'd like to note th...
3 comments:
Thursday, July 22, 2010
Firefox fixes CSS-based cross-origin theft issue
›
Firefox just released version 3.6.7 of their excellent browser, and it fixes this: http://www.mozilla.org/security/announce/2010/mfsa2010-46...
1 comment:
‹
›
Home
View web version