r00tin.blogspot.com
Farfromr00tin: April 2008
http://r00tin.blogspot.com/2008_04_01_archive.html
View my complete profile. Aut disce, aut discede. IE 7 and 8 Intranet Zones. Amaya 11 Stack Overflow Exploits. Back In The Saddle Again. Black Hat Vegas 2008 Recap. Google Gears Origin Spoofing. Were In @ Black Hat Vegas. Wednesday, April 30, 2008. Azureus Web UI XSS ]. Like I said in my uTorrent CSRF post. More torrent pwnage to come soon". Here it is. The web UI plugin for Azureus. I won't take the time to explain what all this means since I've done that at length. Search=") ;alert('xss');/. Posted by ...
r00tin.blogspot.com
Farfromr00tin: Pwnie Nomination
http://r00tin.blogspot.com/2008/07/pwnie-nomination.html
View my complete profile. Google Gears Origin Spoofing. Were In @ Black Hat Vegas. Blue Hat Day 2. Vista OS Version Trick. Blue Hat Day 1. Azureus Web UI XSS. Eclipse Local Web Server Exploitation. Toorcon Seattle was Awesome. Monday, July 21, 2008. I just learned that Nate McFeters. And I have been nominated for pwnies for the best client-side attack. I think protocol handlers are still quite viable for exploitation. URI Use and Abuse. Posted by Rob @ 9:45 AM. Links to this post. Links to this post:.
r00tin.blogspot.com
Farfromr00tin: August 2008
http://r00tin.blogspot.com/2008_08_01_archive.html
View my complete profile. Aut disce, aut discede. IE 7 and 8 Intranet Zones. Amaya 11 Stack Overflow Exploits. Back In The Saddle Again. Black Hat Vegas 2008 Recap. Google Gears Origin Spoofing. Were In @ Black Hat Vegas. Sunday, August 10, 2008. Black Hat Vegas 2008 Recap ]. First of all, I want to say thank you to all the people who came out and supported Nate. And I for our talk. Right after the talk which you can find here. On top of all this, Nate, Billy Rios. And I won the Pwnie Award.
r00tin.blogspot.com
Farfromr00tin: January 2009
http://r00tin.blogspot.com/2009_01_01_archive.html
View my complete profile. Aut disce, aut discede. IE 7 and 8 Intranet Zones. Amaya 11 Stack Overflow Exploits. Back In The Saddle Again. Black Hat Vegas 2008 Recap. Google Gears Origin Spoofing. Were In @ Black Hat Vegas. Saturday, January 03, 2009. Back In The Saddle Again ]. Posted by Rob @ 9:10 PM. Links to this post.
securitycoin.blogspot.com
Security Coin: Can I get your Username and Password ?
http://securitycoin.blogspot.com/2008/03/hewitt.html
Different Issues. Two Sides. One Coin. Your Information. Mar 24, 2008. Can I get your Username and Password? A while back, I got a call from someone claiming to be from a major benefits provider and said ". Hello Sir. We noticed that you have a security flag on your account. Could you please give us your username and password to reset the flag. I almost yelled in excitement ". A real live telephone scammer! It was the same number. Posted by Random InfoSec Guy. Subscribe to: Post Comments (Atom). Can I ge...
securitycoin.blogspot.com
Security Coin: September 2008
http://securitycoin.blogspot.com/2008_09_01_archive.html
Different Issues. Two Sides. One Coin. Your Information. Sep 24, 2008. Insecurities in Privacy Protection Software. I recently wrote an article for INSECURE Magazine. On the lack of protection given to one's sensitive information, ironically, by the very software that claims to protect it in the first place! Or read it online at http:/ issuu.com/insecure/docs/insecure-18/44? Also - Jeremiah Grossman's nice article. On the bitter reality of Web Browser security. I have no idea if a project like that even ...
securitycoin.blogspot.com
Security Coin: March 2008
http://securitycoin.blogspot.com/2008_03_01_archive.html
Different Issues. Two Sides. One Coin. Your Information. Mar 29, 2008. Chris Hoofnagle published a report. That attempts to measure ID thefts at major financial institutions. It is no surprise that BoA is the leader of the pack here, but that is mainly due to the fact that it is also the largest institution in the list. To address that, he created another list - this time with number of incidents per billion in deposits. Posted by Random InfoSec Guy. Links to this post. Mar 24, 2008. I quickly looked up ...
securitycoin.blogspot.com
Security Coin: Secure Email from Voltage
http://securitycoin.blogspot.com/2008/04/secure-email-from-voltage.html
Different Issues. Two Sides. One Coin. Your Information. Apr 1, 2008. Secure Email from Voltage. Offers one of the many alternatives present in the industry for secure encrypted email communication. It is supposed to have incorporated strong anti-phishing. Technology within it. Could very well be, but there is a huge problem with the whole concept. You see, the way it is. 1 I type an email - and then choose to encrypt via voltage and send. Posted by Random InfoSec Guy. Http:/ vsn.voltage.com. Double clic...
r00tin.blogspot.com
Farfromr00tin: May 2008
http://r00tin.blogspot.com/2008_05_01_archive.html
View my complete profile. Aut disce, aut discede. IE 7 and 8 Intranet Zones. Amaya 11 Stack Overflow Exploits. Back In The Saddle Again. Black Hat Vegas 2008 Recap. Google Gears Origin Spoofing. Were In @ Black Hat Vegas. Thursday, May 22, 2008. Miscellaneous Security Musings ]. There's not going to be anything too technical or groundbreaking in this post. I'm waiting on a flaw to get fixed by Google right now so I figured I'd post this in the interim. How do you combat this? It's human nature to get com...