Sniffing Browser History with NO Javascript!

Monday, June 15th, 2009

This is a method of sniffing your browsing history without using Javascript. If you haven't cleaned your browsing history recently, just click "Start Scan" and the system will get to work. If this doesn't shock you, it should: websites are not supposed to see this information. It has potential for anyone, ...

Firefox 3.0.11 Released

Thursday, June 11th, 2009

Firefox 3.0.11 fixes several security issues found in Firefox 3.0.10: JavaScript chrome privilege escalation XUL scripts bypass content-policy checks Incorrect principal set for file: resources loaded via location bar Arbitrary code execution using event listeners attached to an element whose owner document is null Race condition while accessing the private data of a NPObject JS wrapper ...

The First Few Milliseconds of an HTTPS Connection

Thursday, June 11th, 2009

Here is a great post from Jeff Moser over at Moserware that gives you a detailed walk-through of what exactly happens when you make an https connection to a server (in this example: amazon.com). So much more happens than just the URL changing from http to https and a padlock ...

Attacks on SHA-1 made even easier

Thursday, June 11th, 2009

Australian researchers have described a new and faster way of provoking collisions of the SHA-1 hash algorithm. With their method, a collision can be found using only 252 attempts. This makes practical attacks feasible and could have an impact on the medium-term use of the algorithm in digital signatures. SHA-1 is ...

Beware of Repackaged HijackThis Downloads

Wednesday, June 10th, 2009

HijackThis is one of the well-known free utilities of Trend Micro that quickly scans a user’s Windows computer to find settings that may have been changed by spyware, malware, or other unwanted programs. By itself, it does not determine what is good or bad but it lists registry keys and ...