Archive for 2009

Cross Site Scripting (XSS) no User-Agent

September 7, 2009

Acompanhando o projeto de Honeypot do WASC (WASC Distributed Open Proxy Honeypot) deparamos com um post do Ryan Barnett comentando sobre o uso de tags de cross site scripting (XSS) no cabeçalho de User-Agent (WASC Distributed Open Proxy Honeypot Update – XSS in User-Agent Field – http://tacticalwebappsec.blogspot.com/2009/08/wasc-distributed-open-proxy-honeypot.html ) Ficamos curiosos em saber o que poderiamos […]

Null Prefix attack – More tips to defeating use of SSL

August 12, 2009

After some days in Vegas attending Defcon 17 here we are to comment on the conference in what refers to subjects related to the web. In this first post I will comment on what I think it was the best lecture and how they mentioned he literally “broke internet’s security”. The lecture in question was […]

Null prefix attack – Mais dicas para frustar o uso de SSL

August 7, 2009

Após alguns dias em Vegas para Defcon 17 aqui estamos para comentar sobre a conferência nos assuntos relacionados a web. Nesse primeiro post comentarei a que considero a melhor palestra e como citaram ele literalmente “quebrou a segurança da internet” . A palestra foi “More Tricks for defeating SSL” https://www.defcon.org/html/defcon-17/dc-17-speakers.html#Marlinspike . Para quem não conhece […]

« Older Entries   Newer Entries »