Tag Archives: Drive by download attack

Android malware said to be targeting Indian politicians

am

Android as of now has gain popularity much more than desired by its creator! Anything that has popularity and relays on internet for major function, becomes an easy target for cyber crooks. Though security loopholes have been updated and brought … Continue reading

Tagged , , , , , , , , , , | Leave a comment

XSS in Dell

XSS alert

Dell is a leading name in the Information Technology industry, especially the hardware segment of the industry. From servers to work stations, desktops, laptops, mobiles, Dell has got its name and a good hold on leading forms of IT gadgets. … Continue reading

Tagged , , , , , , , | 1 Comment

XSS threats on leading Indian mobile operators websites

While passing by common websites, we had came across various security issues in them in the past. Be it a bug on Facebook, Flipkart or Indian Shopping sites, we have brought up many issues in the past and have responsibly … Continue reading

Tagged , , , , , , , , | Leave a comment

You can be a victim of malicious download!

Drive-by-cache, drive-by-download, we have seen many vulnerabilities in the past that affect modern browsers and can create havoc for the users. According Mr Michal Zalewski, a security researcher working at Google,a serious vulnerability were found in browser giants Firefox, IE … Continue reading

Tagged , , , , , , , | Leave a comment

XSS in official Adobe site

Cross-site scripting aka XSS has been a common threat faced by web applications these days. That’s why its on the top 10 chart of OWASP! :) Many times while browsing websites, we had came across  this vulnerability (like the FlipKart.com and … Continue reading

Tagged , , , , , | Leave a comment

ASP mass infection takes down 300,000 websites

Internet security research firm Armorize has spotted a search engine poisoning attack that has infected more than 300,000 websites. The websites relied on ASP or ASP.NET web application frameworks came under the attack vectors. A malicious script that points to … Continue reading

Tagged , , , , , | Leave a comment

Hacked mysql.com infects visitors with malware

MySQL is one of the most widely used RDBMS. Every 2 of 6 websites can be found using MySQL. Mysql.com was also hacked earlier due to SQL injection vulnerability in the website. According to a blog post at Armorize, Mysql.com … Continue reading

Tagged , , , | Leave a comment

Malvertising found on Google’s DoubleClick

Cyber criminals and malicious users have been using Google and its services actively to spread malwares and drive by download attacks. In a latest post, security researchers from Armorize have spotted malicious ads on Google’s DoubleClick network that lead to drive-by … Continue reading

Tagged , , , | Leave a comment

Attackers using DWORD formatted IP addresses in web attacks

Security researcher from Zscaler have detected web attacks in which links to drive-by exploits are obfuscated by converting IP addresses to DWORD. DWORD is 32-bit integer representation of a string. Browsers can automatically parse DWORD values if encountered in an URL … Continue reading

Tagged , , , | Leave a comment

An approach to Drive-by-cache attack

Few months ago, we had saw a new variant of drive-by-download attack, i.e. drive-by-cache attack. We had posted about it. Today, we will look into nuts and bolts of drive-by-cache through the following paper by Mr. Vinay Katoch, who is … Continue reading

Tagged , , , , | Leave a comment