Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Ahead With Linux Security News

Filter Icon Refine news
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security news

We found 1 articles for you...
74

Billy Hoffman on AJAX Security: Insights into JavaScript Attacks

As more and more computing moves to the Web, Web application security has become a high priority -- at least for users. In this interview, Executive Editor Dennis Fisher talks to Billy Hoffman, manager of Hewlett-Packard Co.'s Web Security Research Group, about the security features in Google Chrome, the lack of security training for Web developers and how JavaScript has become the favored tool of attackers. This article is an interview with Billy Hoffman, manager of Hewlett-Packard Co.'s Web Security Research Group. Which he talks about how JavaScript has become the favored tool of attackers.. The link for this article located at is no longer available. . Uncovering AJAX security reveals critical vulnerabilities in async web applications. While JavaScript enhances user experience, it also invites potential exploits.. Web Application Security, JavaScript Attacks, AJAX Trends. . Bill Locke

Calendar 2 Oct 10, 2008 User Avatar Bill Locke Network Security
83

Adobe Flex 3: DOM-Based XSS Risk Due To JavaScript Manipulation

We recently researched an interesting DOM-based XSS vulnerability in Adobe Flex 3 applications that exploits a scenario in which two frames (parent & son) interact with each other, without properly validating their execution environment. In our research, we have seen that in some cases, it is possible to manipulate JavaScript code flow, by controlling the environment in which it runs. Specifically, we managed to return hacker-controlled boolean values to conditional statements, and by that force the application to be vulnerable to an existing DOM-based XSS, which was otherwise unexploitable. . The link for this article located at wfblog is no longer available. . Investigations into a significant DOM-related XSS flaw in Adobe Flex 3 software indicate techniques for altering JavaScript.. JavaScript Vulnerability, Adobe Flex 3, DOM-Based Attack. . LinuxSecurity.com Team

Calendar 2 Jun 24, 2008 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Evolving JavaScript Obfuscation Techniques Making Defense Harder

As JavaScript becomes an increasingly key component of online attacks, attackers are investing more energy in obfuscation and other techniques to make defenders' attempts at reverse engineering more difficult, a security researcher told attendees at the annual CanSecWest conference on Wednesday. . Attackers have adopted the same techniques used to hide the purpose of other types of malicious code, such as splitting up the code into many components and the use of custom encoders, to obfuscate JavaScript, said Jose Nazario, senior security engineer at network-protection firm Arbor Networks. Other advances include the addition of functions aimed at detecting any attempts at debugging or running the program in a virtual machine, he said. The link for this article located at SecurityFocus is no longer available. . Advancements in code encryption methods complicate the decryption of JavaScript scripts for security experts.. JavaScript Obfuscation,Cyberattack Strategies,Security Techniques. . LinuxSecurity.com Team

Calendar 2 Apr 19, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
83

Emerging JavaScript Tool Poses Significant Threat to Browser Security

A new tool too dangerous to give away can turn any PC. After silently inserting itself to run inside any browser The link for this article located at eWeek is no longer available. . An application surfaces that can stealthily transform any web browser with JavaScript support into a harmful agent, presenting considerable dangers.. JavaScript Threat, Malware Tool, Browser Security Issue, Cyber Attack Software. . LinuxSecurity.com Team

Calendar 2 Mar 28, 2007 User Avatar LinuxSecurity.com Team Hacks/Cracks
74

Home Routers: Remote Attacks Through Malicious JavaScript Exploit

They have demonstrated that users could open up their router's traffic as a result of visiting a web page loaded with malicious javascript. The researchers said, "Settings on the router can be changed, including the DNS servers used by members of small, quickly erected internal networks. The attacks do not exploit any vulnerabilities in the user's browser. Instead, all they require is that the browser run JavaScript and Java Applets." While the threat to home routers is real, said the researchers, no actual attacks have so far taken place. Users would also first have to be persuaded to visit a malicious website for any attack to take place. . . Individuals face dangers since residential networking devices can be exploited remotely through harmful codes embedded in websites.. home routers security, remote attack prevention, javascript risks. . Benjamin D. Thomas

Calendar 2 Feb 20, 2007 User Avatar Benjamin D. Thomas Network Security
81

Exploiting XSS: Capturing User Search Queries with JavaScript

SPI Labs has discovered a practical method of using JavaScript to detect the search queries a user has entered into arbitrary search engines. All the code needed to steal a user's search queries is written in JavaScript and uses Cascading Style Sheets (CSS). This code could be embedded into any website either by the website owner or by a malicious third party through a Cross-site Scripting (XSS) attack. There it would harvest information about every visitor to that site. . . Innovative Security Team uncovers a technique utilizing Python to hijack user browsing histories via CSRF exploitation.. JavaScript Attacks, Cross Site Scripting, Data Harvesting Techniques, Web Security Analysis, Security Threats. . LinuxSecurity.com Team

Calendar 2 Oct 03, 2006 User Avatar LinuxSecurity.com Team Privacy
News Add Esm H340

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here