WebSec
Just a quick post to draw attention to Ronald's excellent article at h [...]
Well, long time no post. Been in hospital. Been busy with college. L [...]
There's been a fair bit of discussion going on at slackers on the secu [...]
I know I haven't posted anything here for a good while, but that's bec [...]
Just thought I'd share the following script vector with you all that I [...]
There's such a wealth of new XSS vectors coming out of the work on php [...]
Whilst working on the next release of .NETIDS I came across some inter [...]
This is a well known trick that I just wanted to share as it is so cru [...]
Just a quick note to announce the release of .NETIDS v.0.1.1.0 - a sma [...]
I was interested to see in a XSS/CSRF exploit the following lines:
[...]
After much testing/tweaking the first release of .NETIDS is upon us!
[...]
Today I made some large commits to the .NETIDS project to enable detec [...]
Following on from a post on sla.ckers it emerges that Firefox has a vu [...]
Today there were 5 flaws for Firefox and IE6/7 unveiled - 2 for IE and [...]
Just a quick note to announce the start of dotnetids, a port of phpids [...]
This morning I knocked up some proof of concept code to illustrate the [...]
GNUCITIZEN has been going on about this for some time now, but the tru [...]
ha.ckers are reporting that their book on Cross Site Scripting has fin [...]
Stefano Di Paola presented an interesting paper on Flash security at O [...]
Purpose of this Month of Bugs is a demonstration of real state with s [...]
As the title says, heise Security have found a backdoor in the Artmedi [...]
kishord today presents a tool, called XSS in eXceSS and hosted by .mar [...]
Just a quick note to point out this invaluable resource for those inte [...]
For those who haven't yet seen this, .mario and christ1an over at sla. [...]
Here is a nice tool for encoding JavaScript into eval(String.fromCharC [...]
pdp has an interesting post from last month about amendments to the Br [...]
ASP.NET comes preloaded with some default XSS protection which is actu [...]
Admittedly of limited use, here is a JavaScript function I wrote to de [...]
A proposed extension to the currently supported set of ...Request obje [...]
Many sites use JavaScript methods to inject a hidden form field into 4 [...]
Today I wrote a simple tool to illustrate the binding of a Javascript [...]