Oracle interrupted: Stealing sessions and credentials
In this video from OWASP AppSec Research 2010, Wendel G. Henrique and Steve Ocepek from Trustwave look at Oracle sessions and credentials, take them apart and take them over.
FGET: Network-capable forensic data acquisition tool
FGET which is short for “Forensic Get” is a network-capable forensic data acquisition tool. It’s primary function is collecting sets of forensically …
New ICQ worm spreads like fire
A new worm is targeting ICQ users, but apart from spreading itself by taking control of the ICQ application of the victim to send out more of the same messages and a file …
Twitter app demonstrates spammers have nothing to worry about
A fun, seemingly innocuous Twitter application created by a scottish teenager became a good example of how easy is to trick even technologically savvy users into participating …
Resourceful attackers continue to make the web insecure
Attackers are staying one step ahead of the game and enterprises are struggling to keep up, according to a report by Zscaler. During the second quarter of 2010, attackers once …
Employees admit they would steal data when leaving a job
Employees openly admit they would take company data, including customer data and product plans, when leaving a job, according to Harris Interactive. The online survey probed …
DDoS threat spam targets domain owners
An interesting and not that often seen approach to make users part with their hard-earned cash has been spotted recently by Symantec. In the email in question, the spammer …
Facebook clickjacking scam tries to rip off users
If you happen to see a post on your friends’ Facebook pages about “Top 10 Funny T-Shirt Fails ROFL”, don’t fall for it. It’s just another scheme …
Over 200 websites use Justin Bieber as bait to distribute malware
PandaLabs detected more than 200 spoof Web addresses using the name of Justin Bieber as bait to lure users. By including the name of this popular singer in malicious links, …
WhatWeb: Fingerprint Web servers and applications
WhatWeb allows you to identify content management systems, blogging platforms, stats/analytics packages, javascript libraries, servers and more. When you visit a website in …
Millions of ColdFusion users still at serious risk
Millions of users of Adobe’s ColdFusion programming language are still at risk of losing control of their applications and websites. Out of the twenty two corporate …
Facebook Hacker: A dangerous tool
Phishing is known to be the weapon of choice for all cybercriminals that are after login credentials. However, a new attack tool – Facebook Hacker – has drawn …
Featured news
Resources
Don't miss
- Google fixes actively exploited Chrome zero-day vulnerability (CVE-2025-10585)
- LinkedIn now uses your data for AI by default, opt out now!
- Behind the scenes of cURL with its founder: Releases, updates, and security
- Product showcase: Exaforce – The full lifecycle AI SOC platform
- AI made crypto scams far more dangerous