Microsoft Warns Of Security Vulnerability Arising From Apple’s Safari

Friday, May 30th, 2008

Microsoft on Friday said it is investigating reports of "a blended threat that allows remote code execution on all supported versions of Windows XP and Windows Vista when Apple's Safari Web browser has been installed."An attacker could exploit the vulnerability by tricking a user into visiting a maliciously crafted Web ...

Students crack Microsoft CardSpace

Friday, May 30th, 2008

Students at the Ruhr University of Bochum, Germany, say they have found a way to steal security tokens in Microsoft's new CardSpace authentication framework. Attackers can apparently get access to protected, encrypted user data – such as passwords, credit card numbers, and delivery addresses – when they are transmitted. ...

sqlninja 0.2.3 released – Advanced Automated SQL Injection Tool for MS-SQL

Friday, May 30th, 2008

We’ve been folowing the development of sqlninja since the early days, it’s growing into a well matured and more polished tool with advanced features. Sqlninja is a tool written in PERL to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main goal ...

PstPassword Recovers Lost Outlook Passwords

Friday, May 30th, 2008

Windows only: When you dig up that old Outlook PST (Personal Folders) file from years ago you cleverly secured with a hard-to-guess password—and now you can't guess it—you want PstPassword. Turns out that Outlook passwords aren't that difficult to figure out, because this handy utility detects the PST's on your ...

Comcast Hijackers Say They Warned the Company First

Friday, May 30th, 2008

The computer attackers who took down Comcast's homepage and webmail service for over five hours Thursday say they didn't know what they were getting themselves into. In an hour-long telephone conference call with Threat Level, the hackers known as "Defiant" and "EBK" expressed astonishment over the attention their DNS hijacking has ...