Jeremiah Grossman: Top Ten Web Hacks of 2007 (Official)
Web Hacks of 2007:
Top Ten
XSS Vulnerabilities in Common Shockwave Flash Files
Universal XSS in Adobe’s Acrobat Reader Plugin
Firefox’s JAR: Protocol issues
Cross-Site Printing (Printer Spamming)
Hiding JS in Valid Images
Firefoxurl URI Handler Flaw
Anti-DNS Pinning ( DNS Rebinding )
Google GMail E-mail Hijack Technique
PDF XSS Can Compromise Your Machine
Port Scan without JavaScript
Honorable Mention:
Microsoft ASP.NET Request Validation Bypass Vulnerability (POC)
The rest of the top web hacks:
Cross-Site Printing (Printer Spamming)Stealing Pictures with PicasaHScan ReduxISO-8895-1 Vulnerable in Firefox to Null InjectionMITM attack to overwrite addons in FirefoxMicrosoft ASP.NET Request Validation Bypass Vulnerability (POC)Non-Alpha-Non-Digit 3Steal History without JavaScriptPure Java™, Pure Evil™ PopupsGoogle Adsense CSRF holeThere’s an OAK TREE in my blog!?!?!BK for Mayor of Oak Tree ViewGoogle Docs puts Google Users at RiskAll Your Google Docs are Belong To US…Java Applets and DNS RebindingScanning internal Lan with PHP remote file opening.Firefox File Handling WoesFirefoxurl URI Handler FlawBugs in the Browser: Firefox’s DATA URL Scheme VulnerabilityMultiviews Apache, Accept Requests and free listingOptimizing the number of requests in blind SQL injectionBursting Performances in Blind SQL Injection - Take 2 (Bandwidth)Port Scan without JavaScriptFavorites Gone WildCross-Browser Proxy UnmaskingSpoofing Firefox protected objectsInjecting the script tag into XMLLogin Detection without JavaScriptAnti-DNS Pinning ( DNS Rebinding ) : Online Demonstration Username Enumeration Timing Attacks (Sensepost)Google GMail E-mail Hijack TechniqueRecursive Request DoSExaggerating Timing Attack Results Via GET FloodingInitiating Probes Against Servers Via Other ServersEffects of DNS Rebinding On IE’s Trust ZonesPaper on Hacking Intranets Using Websites (Not Web Browsers)More Port Scanning - This Time in FlashHTTP Response Splitting and Data: URI scheme in FirefoxRes:// Protocol Local File EnumerationRes Timing AttackIE6.0 Protocol GuessingIE 7 and Firefox Browsers Digest Authentication Request SplittingHacking Intranets Via Brute ForceHiding JS in Valid ImagesInternet Archiver Port ScannerNoisy Decloaking MethodsCode Execution Through Filenames in UploadsCross Domain Basic Auth Phishing TacticsAdditional Image Bypass on WindowsDetecting users via Authenticated RedirectsPassing Malicious PHP Through getimagesize()Turn Any Page Into A Greasemonkey PopupEnumerate Windows Users In JSAnti-DNS Pinning ( DNS Rebinding ) + Socket in FLASHIframe HTTP PingRead Firefox Settings (PoC)Stealing Mouse Clicks for Banner Fraud(Non-Persistent) Untraceable XSS AttacksInter Protocol ExploitationDetecting Default Browser in IEBypass port blocking in Firefox, Opera and Konqueror.LocalRodeo DetectionImage Names Gone BadIE Sends Local Addresses in Referer HeaderPDF XSS Can Compromise Your MachineUniversal XSS in Adobe’s Acrobat Reader PluginFirefox Popup Blocker Allows Reading Arbitrary Local FilesIE7.0 Detectoroverwriting cookies on other people’s domains in Firefox. Embeding SVG That Contains XSS Using Base64 Encoding in FirefoxFirefox Header Redirection JavaScript ExecutionMore URI Stuff… (IE’s Resouce URI)Hacking without 0days: Drive-by JavaGoogle Urchin password theft madnessUsername Enumeration VulnerabilitiesClient-side SQL Injection AttacksContent-Disposition HackingFlash Cookie Object TrackingJava JAR Attacks and FeaturesSevere XSS in Google and Others due to the JAR protocol issuesWeb Mayhem: Firefox’s JAR: Protocol issues (bugzilla)0DAY: QuickTime pwns FirefoxExploiting Second Life
United Arab Emirate's site for security news, latest security blog posts, security podcasts, hardware hacks and security related links.
Saturday, January 26, 2008
Subscribe to:
Post Comments (Atom)
MySecured.com
- CNET Compares T-Mobile G1 vs. iPhone 3G - Nov 18, 2008
- Android T-Mobile G1 - The Rap Song (G1 Love) - Nov 18, 2008
- Flash Player 10 Demonstrated on Android - Nov 18, 2008
- Android Guides and Wiki - Nov 18, 2008
- AccessData Offers to Acquire Guidance Software - Nov 18, 2008
Fatma Bazargan:
- Hackers penetrate the IMF Computer Systems - Nov 16, 2008
- Rogue Anti-Virus Programs - Win32/FakeSecSen - Nov 13, 2008
- SecureDubai presented by (ISC)2 on 4 Dec 2008 - Nov 13, 2008
- Getting Ready for MEITSEC 08? - Oct 25, 2008
- GITEX Technology Week Highlights - Oct 24, 2008
DAILY INFO SEC
- Blogs - Schneier On Security: Skein and SHA-3 News - Nov 19, 2008
- Blogs - Darknet: Dshocker AKA Aush0k Hacker Pleads Guilty to Computer Felonies - Nov 19, 2008
- Podcasts - Blue Box: FYI - "Security Bloggers Network" in transition... stay tuned... - Nov 19, 2008
- Blogs - The Dark Visitor: Chinese hackers and the Kappa Girl video - Nov 19, 2008
- Blogs - The Dark Visitor: Chinese nationalism by the Ogilvy Group - Nov 19, 2008
DARKNET
- Dshocker AKA Aush0k Hacker Pleads Guilty to Computer Felonies - Nov 19, 2008
- Microsoft Security Assessment Tool - Free for Windows - Nov 18, 2008
- Spam ISP McColo Cut Off From the Internet - Nov 17, 2008
- Maltego - Forensics and Intelligence Application & Information Gathering Tool - Nov 14, 2008
- Express Scripts Offers $1million Reward for Cyber Extortionists - Nov 13, 2008
CGISecurity
WEB SEC
ArsTechnica:
- US court orders keylogger CyberSpy to halt software sales - Nov 19, 2008
- Microsoft to kill off Windows Live OneCare next year (Updated) - Nov 19, 2008
- Quick Take: Eikon fingerprint reader - Nov 19, 2008
- DDoS attacks, DNS cache poisoning keeping ISPs up at night - Nov 18, 2008
- Equifax's new age-verification tool cumbersome, limited - Nov 14, 2008
HACK A DAY
- Alarm clock automated blinds - Nov 19, 2008
- Hacking at Random 2009 dates announced - Nov 19, 2008
- Reversing Google’s iPhone voice search - Nov 19, 2008
- Guardian Hack Day - Nov 19, 2008
- Animated LED keyboard - Nov 19, 2008
Help Net Sec
- Security World: McAfee completes acquisition of Secure Computing - Nov 19, 2008
- Security World: Winners of (ISC)2 Annual Cyber Security Awareness Contest - Nov 19, 2008
- Security World: New firewall matrix analysis technology - Nov 19, 2008
- Security World: New book: "Ubuntu Kung Fu" - Nov 19, 2008
- Off the wire: Organizations fail to educate employees about online shopping risks - Nov 19, 2008
The Spanner
- Javascript vbscript challenge - Nov 9, 2008
- Hackvertor and clickjacking - Nov 3, 2008
- Wordpress plugin security - Oct 22, 2008
- Bluehat - Oct 21, 2008
- To infinity and beyond! - Oct 2, 2008
USB Hacks:
- Sensitive Government Gateway Information on Lost Flash Drive - Nov 3, 2008
- Hacking Amazon Kindle’s DRM - Oct 27, 2008
- GadgetTrak Mobile Security - Ultimate Anti Theft For Blackberry & Windows Mobile - Oct 14, 2008
- McCain “Let’s put medical records online”. Bad idea. - Oct 8, 2008
- 60K mobile phones left in London taxis in the last six months - Sep 18, 2008
UAE TECH NEWS
Dubai News & Current Affairs in Arabic
- نكون أو لا نكون.. - Nov 19, 2008
- ايقاف صحيفة الإمارات اليوم..!! - Nov 19, 2008
- استبدال ساعة دبي - Nov 19, 2008
- استقالة جيري يانج مدير “ياهو” - Nov 18, 2008
- نجل ملك البحرين يقاضي مايكل جاكسون - Nov 18, 2008
Middle East Technology News
- Intel launches world's fastest processor - Nov 19, 2008
- TechnoPark inks deal with South Korean firm - Nov 19, 2008
- Sun layoffs not expected in ME - Nov 18, 2008
- HP signs training deal with Egyptian government - Nov 17, 2008
- Qatar's Hukoomi on display - Nov 17, 2008
CRIME
HACKING IN THE NEWS
- Atos Worldline selected by GEK to implement and manage electronic health cards
- Fortasys joins SkyRecon Partner Program to reduce data leakage
- Tufin SecureTrack 4.4 provides support and interoperability with Fortinet UTM systems
- Symantec completes acquisition of MessageLabs
- Clearswift helps organisations apply consistent data loss prevention policies across internal email
The Certified Geek
- Cisco Quickie: Promoting a switch into a master in switch stack - Oct 13, 2008
- How to brick a Cisco Wireless (AP1131AG) A.K.A Downgrading from lightweight mode to autonomous mode - Jun 24, 2008
- Hackvertor - Nov 2, 2007
- Free Cisco Webcasts - Oct 31, 2007
- Remote Desktop support without the hassle - Oct 30, 2007
hackerati
- RFID on the cheap - hacking tikitag - Oct 31, 2008
- Fabrication d'une lampe triode - Oct 7, 2008
- Elvis Presley - alive in Schiphol - Oct 2, 2008
- The 25¢ I2C Adapter - Sep 24, 2008
- Hacking the Esquire E-Ink Cover: A How-To | Popular Science - Sep 23, 2008
Taking Network Security to the Streets
- Better Risk Management for Banking Industry - Aug 18, 2008
- How to hack a Bank part 1? - Aug 18, 2008
- Yet Another SQL injection - May 12, 2008
- Scanless PCI, Hurray - Apr 3, 2008
- PIX/ASA Finesse 7.1 & 7.2 Privilege Escalation - Jan 30, 2008

0 comments:
Post a Comment