Firefox 3.0.9 Released

Tuesday, April 21st, 2009

Firefox 3.0.9 fixes several security issues found in Firefox 3.0.8: Firefox allows Refresh header to redirect to javascript: URIs POST data sent to wrong site when saving web page with embedded frame Malicious search plugins can inject code into arbitrary sites Same-origin violations in XMLHttpRequest and XPCNativeWrapper.toString XSS hazard using third-party stylesheets and XBL bindings Same-origin violations ...

Zero-Day PowerPoint Attacks Under Way

Saturday, April 4th, 2009

Microsoft's PowerPoint application is being used in a new attack that exploits an unpatched vulnerability in the popular Office app. The software giant yesterday issued a security alert confirming "limited and targeted attacks" were under way using malicious PowerPoint files that exploit the flaw. The exploits carry a Trojan, according to ...

Windows AUTOPWN (winAUTOPWN)

Wednesday, April 1st, 2009

Autohack your targets with least possible interaction. Features : - Contains already custom-compiled executables of famous and effective exploits alongwith a few original exploits. - No need to debug, script or compile the source codes. - Scans all ports 1 - 65535 after taking the IP address and tries all possible exploits according to ...

Mozilla Firefox XSL Parsing ‘root’ XML Tag Remote Memory Corruption Vulnerability

Thursday, March 26th, 2009

Mozilla Firefox is prone to a remote memory-corruption vulnerability. An attacker can exploit this issue to execute arbitrary code within the context of the affected browser. Failed exploit attempt will result in a denial-of-service condition. The following proof of concept is available: http://www.securityfocus.com/data/vulnerabilities/exploits/2009-ffox-poc.tar.gz

No User Action Required In Newly Discovered PDF Attack

Tuesday, March 10th, 2009

Merely storing -- without opening -- a malicious PDF file can trigger an attack that exploits the new, unpatched zero-day flaw in Adobe Reader, a researcher has discovered. Didier Stevens, a researcher and IT security consultant with Contrast Europe NV, today released a proof-of-concept demonstration that shows how a file ...