sqlninja 0.2.2 Released – SQL Injection Tool

Tuesday, April 15th, 2008

Sqlninja is a tool targeted to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end.  Its main goal is to provide a remote shell on the vulnerable DB server, even in a very hostile environment. It should be used by penetration testers to ...

CEOs targetted by sneaky phishing scam

Tuesday, April 15th, 2008

Panos Anastassiadis didn't click on the fake subpoena that popped into his inbox on Monday morning, but he runs a computer security company. Others were not so lucky. In fact, security researchers say that thousands have fallen victim to an email scam in which senior managers such as Anastassiadis are told ...

Tracking down Firefox plug-ins

Monday, April 14th, 2008

My last posting was about upgrading the Adobe Flash Player, a Web browser plug-in. Adobe Systems just released a new version that fixes critical bugs in older versions, so everyone should update to the latest version. Adobe's Flash tester page displays the version of the Flash Player being used by your ...

Google Comes Knocking In Search Of Hidden Data

Monday, April 14th, 2008

Google on Friday said that it has been testing ways to index data that is normally hidden to search engine crawlers, a change that should improve the breadth of information available through Google. The so-called "hidden Web" that Google has begun indexing refers to data beyond static Web pages, such as Web ...

Bot breaks Hotmail’s CAPTCHA in 6 seconds

Monday, April 14th, 2008

A new bot can crack defenses erected by Microsoft to keep spammers from creating large numbers of accounts on its Live Hotmail service within seconds, a security researcher said Friday. Dan Hubbard, vice president of security research at Websense, said the bot broke Live Hotmail's CAPTCHA (Completely Automated Public Turing Test ...