Another Heartbleed-like vulnerability has been discovered in the decade old but still widely used Secure Sockets Layer (SSL) 3.0 cryptographic protocol that could allow an attacker to decrypt contents of encrypted connections to websites.
Google's Security Team revealed on Tuesday that the most widely used web encryption standard SSL 3.0 has a major security vulnerability that could be exploited
إظهار الرسائل ذات التسميات website security. إظهار كافة الرسائل
إظهار الرسائل ذات التسميات website security. إظهار كافة الرسائل
الأربعاء، 15 أكتوبر 2014
POODLE SSL 3.0 Attack Exploits Widely-used Web Encryption Standard
التسميات:
digital Certificate,
encryption,
hacking news,
Heartbleed bug,
man-in-the-middle attack,
POODLE,
Shellshock,
ssl security,
SSL vulnerability,
Vulnerability,
web browser,
website security
الخميس، 9 أكتوبر 2014
SQL Injection Vulnerability in 'Yahoo! Contributors Network'
Yahoo! Contributors Network (contributor.yahoo.com), the network of authors that generated the contents such as photographs, videos, articles and their knowledge to more than 600 million monthly visitors, was vulnerable to a Time based Blind SQL Injection vulnerability.
Behrouz Sadeghipour, a security researcher reported the Blind SQLi vulnerability in Yahoo!’s website that could be
التسميات:
data breach,
database hacking,
sql injection,
Vulnerability,
Web Application Vulnerability,
Web Author Network,
website security,
Yahoo,
Yahoo Security
الأربعاء، 24 سبتمبر 2014
jQuery Official Website Compromised To Serve Malware
The official website of the popular cross-platform JavaScript library jQuery (jquery.com) has been compromised and redirecting its visitors to a third-party website hosting the RIG exploit kit, in order to distribute information-stealing malware.
JQuery is a free and open source JavaScript library designed to simplify the client-side scripting of HTML. It is used to build AJAX applications
التسميات:
Ajax Security,
drive-by download,
hacking website,
html injection,
JavaScript library,
JQuery,
jquery cdn,
jquery ui cdn,
Malware,
RIG Exploit Kit,
Risk management,
user experience design,
website security
السبت، 9 أغسطس 2014
Researcher Uncovers Vulnerability Oracle Data Redaction Security Feature
Oracle’s newly launched Data Redaction security feature in Oracle Database 12c can be easily disrupted by an attacker without any need to use exploit code, a security researcher long known as a thorn in Oracle's side said at Defcon.
Data Redaction is one of the new Advanced Security features introduced in Oracle Database 12c. The service is designed to allow administrators to automatically
الاشتراك في:
الرسائل (Atom)
