Security
Hacking everything, by Chris Evans / scarybeasts
Saturday, January 28, 2012
The dirty secret of browser security #1
›
Here's a curiousity that's developing in modern browser security: The security of a given browser is dominated by how much effort it...
3 comments:
Sunday, July 3, 2011
Alert: vsftpd download backdoored
›
[With thanks to Mathias Kresin for being the first to notice] An incident, what fun! Earlier today, I was alerted that a vsftpd download fro...
34 comments:
Friday, May 27, 2011
libxml vulnerability and interesting integer issues
›
A while ago, I was playing with grammar-based XPath fuzzing and I found and fixed an interesting libxml bug. The commit, for the curious, is...
Wednesday, May 25, 2011
Bug bounties vs. black (& grey) markets
›
I'm just back from the fun that was HiTB Amsterdam 2011. (Plug: you should check out one of the HiTB series if you haven't yet; Dhil...
3 comments:
Wednesday, April 27, 2011
Fiddling with Chromium's new certificate pinning
›
Over the past few years, there have been various high-profile incidents and concerns with the Certificate Authority-based infrastructure tha...
3 comments:
Wednesday, March 9, 2011
Multi-browser heap address leak in XSLT
›
It's not often that I find a bug that affects multiple different codebases in the same way, but here is an interesting info-leak bug tha...
9 comments:
Tuesday, March 8, 2011
Busy Chrome day...
›
I did a bunch of fairly interesting things with my corporate hat on today (not to be confused with any of my personal research ;-) Firstly, ...
1 comment:
‹
›
Home
View web version