gialloporpora 's Library tagged → View Popular
RUBotted - Trend Micro USA
Malicious software called Bots can secretly take control of computers and make them participate in networks called “Botnets.” These networks can harness massive computing power and Internet bandwidth to relay spam, attack web servers, infect more computers, and perform other illicit activities.
BitDefender QuickScan - The quickest way to find out if your PC is infected
QuickScan is very lightweight, requiring only a very small browser plugin for client-side tasks. Unlike other online virus scanners the engines don't need to be downloaded to your system and updated. Scanning of suspicious items is done remotely, at the push of a button, using the BitDefender Antivirus technologies.
JSONP: JSON With Padding come usarlo, significato,implementazione,callback → SoulBit.org
Buona spiegazione dell'utilizzo di Ajax, dei problemi di sicurezza ad esso legati (XSS Cross Site Scripting).
-
La cosiddetta same domain policy è una restrizione presente nei recenti browser che impedisce a script scaricati dalla rete di accedere, tramite qualsiasi tipo di richiesta HTTP, a risorse che si trovano su server diversi rispetto a quello iniziale che ha inviato lo script. Questa inibizione non riguarda solo host diversi tra di loro, ma anche processi in ascolto su porte diverse della stessa macchina, il motivo principale, per il quale si è iniziato a chiudere l’accesso a siti esterni è stato quello di evitare il cross-site scripting (XSS).
-
Attacco non persistente: Bob espone un servizio web che richiede autenticazione, e i suoi utenti registrano nel loro profilo dei dati sensibili. Alice si iscrive e diventa uno dei tanti utenti di Bob. Mallory, scopre una vulnerabilità in una pagina del sito di Bob. Visto che è un esperto di XSS, costruisce una url che sfrutta questa falla e la invia via mail ad Alice, facendosi passare per Bob (email spoofing). Alice è distratta e non si accorge che la mail non proviene dal sito di Bob, e clicca sul link in essa contenuto. Se in quel momento Alice era contemporaneamente collegata, con un’altra finestra del suo browser, al sito di Bob, Mallory può farsi inviare dallo script i dati sensibili di Alice (contenuti ad esempio in cookies non criptati).
Configurable Security Policies (CAPS)
Mozilla's configurable security policies allow users to set up security policies for the browser, and also have different security policies for different Internet sites. The ideas for configurable security policies come from a number of sources. Bell Labs researchers Vinod Anupam and Alain Mayer have written papers and contributed code to Mozilla. The infamous bug 858 serves as a wish list for this sort of functionality. The code for this is called CAPS (capabilities). Finally, IE's zones employ some of this idea.
MS08-067 exploited by Worm.KernelBot
Here at Prevx Research Lab we were expecting this. It was just a matter of time before seeing a worm that makes use of MS08-067 vulnerability.
During these hours we have isolated a new malware, called KernelBot. We have seen this malware for the first time on 28th October and it most likely comes from China.
Bandwidth monitor, bandwidth speed test, bandwidth and traffic monitoring tool for Windows
NetWorxNetWorx is a simple and free, yet powerful tool that helps you objectively evaluate your bandwidth situation. You can use it to collect bandwidth usage data and measure the speed of your Internet or any other network connection. NetWorx can help you identify possible sources of network problems, ensure that you do not exceed the bandwidth limits specified by your ISP, or track down suspicious network activity characteristic of Trojan horses and hacker attacks.
Adblock Plus and (a little) more: Blocking malicious sites with Adblock Plus
So now Adblock Plus users can add a subscription with slightly over 40000 filters that will block access to the known malicious domains. It is the first time I tried Adblock Plus with so many filters, and the good news is: the slowdown during browsing is in the area of single-digit millisecond numbers, that’s not noticeable. The bad news: loading/saving the list still takes a while (noticeable as browser startup/shutdown delay). In Firefox 2 this took around 20 seconds which is why I recommend against using this subscription there. The big surprise was Firefox 3, there the delay is only 3-4 seconds. Congratulations to everybody who helped optimizing JavaScript, the results are really incredible!
0x000000 # The Hacker Webzine
While working on my new ActiveX fuzzer I needed a break and wrote another html/css fuzzer called fuzzy overdrive. It's a basic concept tool born out of boredom that generates all sorts of HTML and CSS intended to trigger a crashed browser in order to locate vulnerabilities or just bugs in markup parsing. I know that fuzzing is like playing the slots, but it is still fun to write and use it. Anyway, I thought maybe you like to play with this toy too. I had it running a couple of times, and at some point Firefox crashed while viewing the source window that became very unstable. The joy of fuzzing.
0x000000 # The Hacker Webzine
Arioso, script per Opera per verificare la presenza di eventuali link malefici nella pagina.
More built-in Windows commands for system analysis
This command tells tasklist to show which services are running inside of each process. Many Windows users don't understand the relationship between services and processes, having at best a murky idea that they are different but related entities. In reality, each service on a Windows box must run inside of a process, and some processes have multiple services living inside of them. Thus, there is a one-to-many relationship between processes and services, which the tasklist command can reveal.
Alta Gradazione°: Antivir a riga di comando e adspy
Antivir PersonalEdition Classic (la versione free) ha una limitazione, ovvero non rileva gli adspy, per volontà del produttore stesso ma possiamo aggirare parzialmente la cosa con questo piccolo trucco.
Wordpress Security Tips and Hacks
Raccolta di trucchi per tenere il proprio blog Wordpress al sicuro :-)
Online malware scans - Comparison - CastleCopsWiki
Lista completa degli scanner online. Per ognuno viene indicata la presenza o meno di un tool freeware per lo scan locale e altri parametri comparativi.
Opera 9.x - Vulnerability Report - Secunia
bug di sicurezza presenti in Opera 9 riportate da Secunia
Microsoft Internet Explorer 7.x - Vulnerability Report - Secunia
Falle di sicurezza di Internet Explorer 7 rilevate da Secunia
Mozilla Firefox 2.0.x - Vulnerability Report - Secunia
Vulnerabilità riscontrate in Mozilla Firefox da Secunia
Surf SSL » Surfing securely with Open SSH and Firefox
I would like to demonstrate how to setup a socks proxy that enables anonymity and privacy while surfing the web. Before you start reading I think it will be helpful to take some time to get familiar with a few key definitions. I realize that some of the t
Exploit - XSS Warning - Estensione di Sicurezza per Firefox
Chi usa Firefox ha una chance in più: NoScript, una eccellente estensione ideata da Giorgio Maone che ci consente di gestire i permessi degli script per ogni singola pagina visitata. Tuttavia, applicazioni web e pagine web fanno largo uso di JavaScript p
MegaLab.it - Come rimuovere Instant Access e Obfuscated
Guida alla rimozione di Instant Access e Obfuscated, un'accoppiata di malware dagli effetti distruttivi.
Selected Tags
Related Tags
Sponsored Links
Top Contributors
Diigo is about better ways to research, share and collaborate on information. Learn more »
Join Diigo
