attacks
07-02-2008 12:58
telecharger.vnunet.fr XSS

ironzorg has discovered a vulnerability in telecharger.vnunet.fr, which could be exploited by malicious people to conduct XSS
attacks.
>>
Kompletan tekst: XSSed
07-02-2008 17:40
PCI-DSS references the outdated OWASP Top Ten

I’m sure other people have noticed this, at least I hope so, but never mentioned it publicly. If you read PCI-DSS 1.1 section 6.5, the part that covers “Cover prevention of common coding vulnerabilities in software development processes”, you’ll notice the list is identical to that of the OWASP Top Ten 2004 while the latest version is 2007:
6.5.1 Unvalidated input
6.5.2 Broken access control (for example, malicious use of user IDs)
6.5.3 Broken authentication and s
>>
Kompletan tekst: Jeremiah Grossman
07-02-2008 18:36
Anti-malware blocker, cross-site scripting protections coming in IE 8

When Microsoft’s Internet Explorer 8 hits the Beta 2 milestone in August, the browser makeover will feature a full-fledged anti-malware blocker and new protections against some forms of cross-site scripting
attacks.
The existing phishing filter IE 7 has been renamed SmartScreen Filter and will include blacklist-based blocking of known exploit sites.
The SmartScreen anti-malware feature is URL-reputation-based, [...]
>>
Kompletan tekst: Feedburner
07-02-2008 18:36
Anti-malware blocker, cross-site scripting protections coming in IE 8

When Microsoft’s Internet Explorer 8 hits the Beta 2 milestone in August, the browser makeover will feature a full-fledged anti-malware blocker and new protections against some forms of cross-site scripting
attacks.
The existing phishing filter IE 7 has been renamed SmartScreen Filter and will include blacklist-based blocking of known exploit sites.
The SmartScreen anti-malware feature is URL-reputation-based, [...]
>>
Kompletan tekst: Feedburner
07-02-2008 17:37
PCI-DSS references the outdated OWASP Top Ten

I’m sure other people have noticed this, at least I hope so, but never mentioned it publicly. If you read PCI-DSS 1.1 section 6.5, the part that covers “Cover prevention of common coding vulnerabilities in software development processes”, you’ll notice the list is identical to that of the OWASP Top Ten 2004 while the latest version is 2007:
6.5.1 Unvalidated input
6.5.2 Broken access control (for example, malicious use of user IDs)
6.5.3 Broken authentication and session m
>>
Kompletan tekst: Jeremiah Grossman
07-02-2008 21:13
www.ministers.sa.gov.au XSS

sl4xUz has discovered a vulnerability in www.ministers.sa.gov.au, which could be exploited by malicious people to conduct XSS
attacks.
>>
Kompletan tekst: XSSed
07-02-2008 21:14
shop.carphonewarehouse.com XSS

Uber0n has discovered a vulnerability in shop.carphonewarehouse.com, which could be exploited by malicious people to conduct XSS
attacks.
>>
Kompletan tekst: XSSed