Category: General Security

10/20/09

Permalink 09:04:30 am, by Zach Brewer, 368 words
Categories: General Security, Pen Testing

An Intro to Cross-Site Scripting (XSS)

A recent conversation with a customer revealed the fact that many auditors and web server admins do not understand the basics of Cross Site Scripting attacks. Cross Site scripting attacks (commonly represented with XSS as CSS = Cascading Style Sheets) a… more »

09/25/09

Permalink 09:54:40 am, by Zach Brewer, 706 words
Categories: General Security

ASA 8.2 Dynamic Botnet Filtering

ASA 8.2 includes several new features including Dynamic Filtering. Dynamic Filtering detects outbound traffic from the internal network to known malicious destinations. The feature uses the Cisco SIO (Security Intelligence Operations) threat data also… more »

09/22/09

Permalink 08:53:16 am, by Zach Brewer, 176 words
Categories: General Security, Pen Testing

Hijacking Software Updates with EvilUpgrade

Infobyte has released a tool called EvilUpgrade which can hijack legitimate software updates when used in conjunction with ARP spoofing, DNS Cache poisoning, DHCP spoofing, or other attacks. From the victim's system, the process looks and feels like a… more »

09/15/09

Permalink 08:39:22 am, by Zach Brewer, 136 words
Categories: Security Advisories, General Security

Compromised nGinx Servers Used to Distribute Malware

As discussed in previous blog entries, nGinx is a favorite web server for malware authors including Conficker and Storm. H-Online is reporting that nGinx servers have been compromised and used along with a dynamic DNS service to distribute malware. T… more »

08/20/09

Permalink 10:37:12 am, by Zach Brewer, 38 words
Categories: General Security, Pen Testing

Shodan Computer Search Engine

This is an interesting concept - a search engine that will find computers/routers. Search criteria includes geographic location, specific software (Apache, ProFTP), and more. Registration and use is currently limited and requires approval. http://… more »

<< 1 2 3 4 5 6 7 8 9 10 11 12 ... 19 >>

Priveon, Inc.

Today's complex security and networking solutions require a great deal of knowledge to successfully support and operate. Priveon uses the field experience of its expert staff to develop and maintain a positive reinforcement loop between business practices and to provide the latest information to our customers. The information posted here is supported by Priveon subject-matter experts.

Search

XML Feeds

Archives

©2010 by Priveon, Inc.