Archive | Exploits/Vulnerabilities


02 November 2011 | 9,045 views

13 Out Of 15 Popular CAPTCHA Schemes Vulnerable To Automated Attacks

This is not a real shock to be if I’m perfectly honestly, I only use reCAPTCHA whenever I need a CAPTCHA implementation for anything. And well even then, it’s not totally safe as apparently you can farm out your CAPTCHA cracking (those the fail the automated attempts) to India for a few dollars. It does [...]

Continue Reading


27 October 2011 | 11,110 views

Facebook Attachment Uploader Owned By A Space

Oh look – another vulnerability in Facebook! It wasn’t long ago we reported New Research Shows Facebook’s URL Scanner Is Vulnerable To Cloaking. Well this time the private messaging function has been compromised, you can attach an executable and send it to anyone as long as you put a space after the filename. It’s not [...]

Continue Reading


24 October 2011 | 24,948 views

THC SSL DoS/DDoS Tool Released For Download

THC-SSL-DOS is a tool to verify the performance of SSL. Establishing a secure SSL connection requires 15x more processing power on the server than on the client. THC-SSL-DOS exploits this asymmetric property by overloading the server and knocking it off the Internet. This problem affects all SSL implementations today. The vendors are aware of this [...]

Continue Reading


18 October 2011 | 21,053 views

winAUTOPWN v2.8 Released For Download – Windows Auto-Hacking Toolkit

I wanted to post this a while back, but the site (and thus the download) was down again – it seems to be a common occurrence. Someone get this guy some proper hosting! winAUTOPWN and bsdAUTOPWN are minimal Interactive Frameworks which act as a frontend for quick systems vulnerability exploitation. It takes inputs like IP [...]

Continue Reading


10 October 2011 | 16,914 views

New Research Shows Facebook’s URL Scanner Is Vulnerable To Cloaking

Oh look, Facebook security (or insecurity) is in the news again – not that this technique is anything revolutionary or ground-breaking. It’s basically a HTTP referer detection system for the Facebook URL scanner (the thing that generates the preview/thumbnail etc for links posted to Facebook). By detecting it, you can feed it something benign – [...]

Continue Reading


27 September 2011 | 8,523 views

MySQL.com Compromised & Spreading Malware

The latest story doing the rounds is that MySQL.com got hacked and was serving malware which put it on the Google malware block list. It appears to be in the clear now though and it’s accessible again via Google. It seems to be a similar case with that of the recent Linux.com and Kernel.org hacks [...]

Continue Reading


19 September 2011 | 7,725 views

Google Patches 32 Chrome Browser Bugs & Releases Version 14

Google and their Chrome browser have really been stepping things up lately when it comes to security and browsing, we reported not along ago on Google Chrome To Protect Users Against Malicious Executables. Also since we reported on the Chrome bug bounty program back in February 2010 – Google Willing To Pay Bounty For Chrome [...]

Continue Reading


13 September 2011 | 9,344 views

Script Kiddies Lay Claim To NBC News Twitter Account Hack

There was a bit of a buzz on the 10th anniversary of 9/11 when the NBC News Twitter account was hacking and started posting updates regarding a repeated terrorist attack against ground zero. It only lasted a few minutes but as the account has 120,000 followers – it caused quite a stir. It’s not known [...]

Continue Reading


06 September 2011 | 19,594 views

winAUTOPWN v2.7 Released – Windows Autohacking Tool

I’ve always been skeptical about this tool, especially seen as though the first version was released on April Fools day in 2009, anyway it’s 2 years later now and it still seems to be around so I think it’s worth publishing an update. If any of you have actually tested this tool out, do drop [...]

Continue Reading


30 August 2011 | 16,497 views

Hackers Get Hold Of Wildcard Google SSL Certificate – Could Hijack Gmail Accounts

One of the big discussions points this week is about a wildcard cert for Google that has leaked out from a Dutch company called DigiNotar. The certificate is good for all Google domains – it’s a *.google.com cert. This is bad news and apparently has been in the wild for a while, some people are [...]

Continue Reading