Home

Search results

"tag:webappsec"


Title and summary Date/time
1
More intranet hacks with applets
We've already looked at one of the two big problems posed by anti DNS pinning on Java applets; because there's rebinding on the applet and not the browser you can open a channel from an Internet host to an internal system (this is also true of Flash, o...
16-Aug-2007
23:02:00
2
Intranet port forwarding
It has been known for a month or so now that proxy bypass is an effective way of breaking DNS pinning on Java applets. It's been known since forever that Java applets can interact with scripts on the parent page (same origin restrictions apply, IIRC)....
10-Aug-2007
00:29:00
3
Does Firefox implement DNS Pinning?
I've been playing around with DNS pinning over the past few weeks; mainly on how the presence of proxies affects the story, which Rsnake and Portswigger beat me to (nice work guys), but also on various other bits. Something that's caught my attent...
19-Jul-2007
19:27:00
4
Browser based DDOS
Everybody is saying that JavaScript is the new malware. There's an interesting application of this idea that probably hasn't occurred to many people; we've all heard about standard CSRF and using this type of technique to perform sophisticated operatio...
17-May-2007
20:49:00
5
Integrated Windows Authentication
On the face of it Integrated Windows Authentication for your intranet applications (formerly known as NTLM) seems like a good deal; you can protect your users' credentials without needing to set up SSL (so your credentials are safer than with basic au...
16-Apr-2007
20:54:00