Too XXE For My Shirt
Until tonight, I'd never gotten a chance to try an xml external entity (XXE) attack. Earlier, I was ...
Read MoreUntil tonight, I'd never gotten a chance to try an xml external entity (XXE) attack. Earlier, I was ...
Read MoreThis is the fourth part in a series of blogs. The prior blogs describe the technical details of the ...
Read MoreIn the next series of blogs we will describe in detail an attack from one of the most sophisticated ...
Read MoreBananaStand learned from last time (to see last time, go here ). Systems were patched, ACL's were ...
Read MoreAbout two weeks ago, a Brazilian security researcher by the name of Gabriel Menezes Nunes released ...
Read MoreThis may sound a bit odd but "nosteve" who usually gives his take on the patch Tuesday release is ...
Read MoreThis year's instantiation of the THOTCON hacking conference issued a unique challenge:
Read MoreThe SpiderLabs team at Trustwave published a new advisory yesterday, which details multiple ...
Read MoreLate last week, a vulnerability in PHP-CGI was disclosed, which allows all sorts of bad for folks ...
Read MoreUPDATE - we have received more exploit attempt details from web hosting provider DreamHost. Thanks ...
Read MoreDuring our research we have recently encountered a new private exploit kit. The developers behind ...
Read MoreBefore I jump into this blog post, I'd like to point out some interesting developments with the ...
Read MoreThere have been a number of mass SQL Injection campaigns targeting ASP/ASP.Net/MS-SQL sites over ...
Read MoreIt was a hectic week in London. In case you hadn't heard its was InfoSec Europe week, but we were ...
Read MoreI recently got wind of an interesting little sample that I believe originated as part of a ...
Read MoreWe Won! :-) Thanks to all the hard work of the Trustwave's Engineering teams, IT, SpiderLabs, and ...
Read MoreBack in January we released a security advisory for WordPress, which included four vulnerabilities ...
Read MoreRecently, while scrounging around our spam traps, I spotted this ordinary piece of malicious spam. ...
Read MoreIn the past few months, a certain cybercrime group operates a large stable malware infrastructure, ...
Read MoreThis week we will be presenting and speaking at InfoSecurity, Europe's No.1 Information Security ...
Read MoreTrustwave SpiderLabs has published a new advisory today for a reflective Cross-Site Scripting ...
Read MorePenTest Manager, the cutting edge penetration test management and reporting platform used by ...
Read MoreOur web honeypots picked up some increased scanning for the following Exploit-DB vulnerability:
Read MoreRecently, we came across a phishing attack targeting Australian Apple Store customers. The phishing ...
Read MoreMuch has been made of the recent attacks against a Puerto Rican utility's smart metering system, ...
Read MoreTrustwave SpiderLabs has published a new advisory yesterday for multiple vulnerabilities found in ...
Read MoreOur web honeypots recently identified attacks for CVE-2009-4834 which is a vulnerability within ...
Read MoreWhile perusing the change log for the release of SAMBA that was pushed out today a member of the ...
Read More