Dissecting Java Server Faces For Penetration Testing
Whitepaper called Dissecting Java Server Faces for Penetration Testing. This paper is divided into two parts. In the first part, they discuss the internals of JSF, a Java based web application...
View ArticleDigging Inside VxWorks OS And Firmware - Holistic Security
Whitepaper called Digging Inside VxWorks OS and Firmware - Holistic Security. VxWorks is one of the most widely accepted embedded OSes. In this paper, they have conducted a detailed study of the...
View ArticleOracle I-Recruitment Cross Site Scripting
A persistent cross site scripting vulnerability exists in the Oracle I-Recruitment portal. The account information page allows the user to upload his resume in Microsoft Word document. An attacker can...
View ArticleNoScript Cross Site Scripting Via SQL Injection
NoScript versions prior to 2.0.5.1 suffer from a reflective cross site scripting vulnerability via SQL injection.
View ArticleOracle I-Recruitment Redirection
An open redirect vulnerability exists in Oracle I-Recruitment versions 11.5.10.2, 12.0.6 and 12.1.3.
View ArticleMicrosoft Word 2003 MSO Null Pointer Dereference
A null pointer dereference vulnerability has been noticed in Microsoft Word. The exception results in the MSO.dll library failing to handle the specially crafted buffer in a file. The issue can be...
View ArticleWhitepaper Called Reverse Honey Trap
Whitepaper called Reverse Honey Trap - Striking Deep Inside Online Web Antivirus Engines and Analyzers.
View ArticleGoogle Docs PDF Repurposing
This document discusses cookie hijacking in Google Docs through PDF repurposing attacks. This has since been fixed by Google.
View ArticlePDF JavaScript Attacks
Whitepaper called PDF Silent HTTP Form Repurposing Attacks.This paper sheds light on the modified approach to trigger web attacks through JavaScript protocol handler in the context of browser when a...
View ArticleGoogle Chrome 1.0.154.53 Denial Of Service
Google Chrome version 1.0.154.53 "throw exception" remote crash and denial of service exploit.
View ArticleMozilla Firefox 3.0.8 Zero Buffer Check Memory Exhaustion / Leaking
Mozilla Firefox version 3.0.8 zero buffer check memory exhaustion and leaking proof of concept exploit.
View ArticleEvading Web XSS Filters Through Word
Whitepaper called Evading Web XSS Filters through Word (Microsoft Office and Open Office in Enterprise Web Applications.
View ArticleGoogle Chrome 1.0.154.48 Denial Of Service
Google Chrome version 1.0.154.48 single thread alert out of bounds memory access exploit.
View ArticleGoogle Chrome Click Jacking
The Google Chrome browser versions 1.0.154.43 and below suffer from a clickjacking vulnerability.
View ArticleOracle E-Business Suite Information Disclosure
Oracle E-Business Suite Release 12, version 12.0.6 and Oracle E-Business Suite Release 11i, version 11.5.10.2 both suffer from a sensitive information disclosure vulnerability.
View Articlegooglechrome-obfuscate.tgz
Google Chrome versions 0.2.149.30, 0.2.149.29, and 0.2.149.27 all suffer from a metacharacter URI obfuscation vulnerability. Proof of concept html included.
View Articleoperasuppress-dos.txt
Opera version 9.52 suffers from a window object suppression denial of service vulnerability.
View Articlefirefoxderef-dos.txt
The user interface in Mozilla Firefox version 3.0.3 suffers from a null pointer dereference crash.
View Articlegooglesuppress-dos.txt
Google Chrome version 0.2.149.30 suffers from a window object suppression denial of service vulnerability.
View Articlegoogle-exhaust.txt
Google Chrome versions 0.2.149.30 and 0.2.149.29 carriage return NULL object memory exhaustion denial of service proof of concept exploit.
View Article