Archives

Archive for December, 2006

MX Injection Testing Available

In reference to the previous post, our partner Syhunt has added MX injection testing capabilities to their Sandcat product. Of course, this is in addition to the thousands of other tests already being performed by the tool. Sandcat is an excellent tool for performing checks of web servers, web applications and such for potential and [...]

Injection Attacks – Not Just for SQL Anymore!

Over the last several months security researchers have been identifying more and more scenarios for performing injection style attacks against various applications. What is interesting about this is that many of the new injection issues have little to do with SQL. In fact, protocols like LDAP and SSI along with various forms of command injections, [...]

Bugs

Last month over two dozen kernel bugs were published on a security researcher’s blog. Most of them were found using a file system fuzzer, which would create malformed file systems to try to crash each kernel. Not all of the MOKB bugs were file system related though. Some problems were found with Apple Airport drivers, [...]

Making Passwords Manageable

Recently, with the passing of the Thanksgiving holiday, many of us have paid closer attention to those things for which we are thankful. I, too, have just taken an assessment and realize I have a plethora of things for which I’m grateful, at home as well as at work. I know this might sound trite, [...]