Security

Hacking everything, by Chris Evans / scarybeasts

Wednesday, March 9, 2011

Multi-browser heap address leak in XSLT

›
It's not often that I find a bug that affects multiple different codebases in the same way, but here is an interesting info-leak bug tha...
9 comments:
Tuesday, March 8, 2011

Busy Chrome day...

›
I did a bunch of fairly interesting things with my corporate hat on today (not to be confused with any of my personal research ;-) Firstly, ...
1 comment:
Saturday, March 5, 2011

Dangerous file write bug in Foxit PDF Reader

›
This is fixed in the recently released Foxit PDF Reader v4.3.1.0218. That release is marked as an important security update , although this ...
2 comments:
Thursday, February 24, 2011

I got accidental code execution via glibc?!

›
The story of Chromium security bug 48733 , with guest Cris Neckar, part I It has been a long time now, but the story of Chromium security bu...
5 comments:
Wednesday, February 16, 2011

Some less obvious benefits of HSTS

›
HSTS , standing for HTTP Strict Transport Security, is a relatively new standard that aims to bolster the strength of HTTPS connections. Hop...
5 comments:
Wednesday, January 19, 2011

A harmless SVG + XSLT curiousity

›
How do you execute code in a turing complete language via the <img> tag? Why, by combining an XSL transform into an SVG image of cour...
2 comments:
Thursday, October 21, 2010

Minor leak, major headache

›
I find this bug interesting, because at first it looks like a relatively minor cross-origin leak. But with a bit of investigation, it has ma...
3 comments:
‹
›
Home
View web version
Powered by Blogger.