Subscribe via feed.

[webapps] – glFusion 1.2.2 – Multiple XSS Vulnerabilities

Posted by deepcore under exploit, m$, XSS (No Respond)

glFusion 1.2.2 – Multiple XSS Vulnerabilities

Tags: , , ,

iOS Application (In)Security

Posted by deepcore under Apple, exploit, iphone, OSX security tools, Security (No Respond)

This whitepaper details some of the vulnerabilities observed over the past year while performing regular security assessments of iPhone and iPad applications. MDSec documents some of the vulnerabilities identified as well as the methods to exploit them, and recommendations that developers can adopt to protect their iOS applications. It covers not only the security features of the platform, but provides in depth information on how to perform both black box and white box iOS penetration tests, along with suggested methodologies and compliance.

Tags: , , ,

Vega Web Security Scanner 1.0 Beta Mac OS X 64 Bit

Posted by deepcore under Apple, OSX security tools, Security, XSS (No Respond)

Vega is a GUI-based, multi-platform, free and open source web security scanner that can be used to find instances of SQL injection, cross-site scripting (XSS), and other vulnerabilities in your web applications. Vega also includes an intercepting proxy for interactive web application debugging. Vega attack modules are written in Javascript, users can easily modify them or write their own

Tags: , , , ,

Vega Web Security Scanner 1.0 Beta Mac OS X 32 Bit

Posted by deepcore under Apple, OSX security tools, Security, XSS (No Respond)

Vega is a GUI-based, multi-platform, free and open source web security scanner that can be used to find instances of SQL injection, cross-site scripting (XSS), and other vulnerabilities in your web applications. Vega also includes an intercepting proxy for interactive web application debugging. Vega attack modules are written in Javascript, users can easily modify them or write their own.

Tags: , , ,

Apple Security Advisory 2011-10-12-4

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-10-12-4 – Safari version 5.1.1 is now available and addresses a directory traversal issue, a policy issue, various arbitrary code execution issues, and 40+ other vulnerabilities.

Tags: , ,

Apple Security Advisory 2011-10-12-2

Posted by deepcore under Apple, OSX security tools, Security, software (No Respond)

Apple Security Advisory 2011-10-12-2 – An Apple TV software update is now available and addresses credential interception, spoofing, information disclosure, and various other vulnerabilities.

Tags: , , ,

Apple Security Advisory 2011-10-11-1

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-10-11-1 – iTunes 10.5 has been released and addresses CoreFoundation, ColorSync, CoreAudio, CoreMedia, ImageIO, WebKit, and various other vulnerabilities.

Tags: , ,

Apple Security Advisory 2011-08-03-1

Posted by deepcore under Apple, OSX security tools, Security (No Respond)

Apple Security Advisory 2011-08-03-1 – QuickTime version 7.7 has been made available to address multiple code execution, cross-origin, integer overflow, memory corruption, and other vulnerabilities.

Tags: , , ,

Source code leaked for pricey ZeuS crimeware kit

Posted by deepquest under Security, tools (No Respond)

Source code for the latest version of the ZeuS crimeware kit has been leaked on the internet, giving anyone who knows where to look free access to a potent set of malware-generation tools that normally sell for as much as $10,000.

Tags: , , , , , ,