Tag Archives: Vulnerabilities

XSS in Dell

XSS alert

Dell is a leading name in the Information Technology industry, especially the hardware segment of the industry. From servers to work stations, desktops, laptops, mobiles, Dell has got its name and a good hold on leading forms of IT gadgets. … Continue reading

Tagged , , , , , , , | 1 Comment

No, not a Java Zero Day again!

Java_Bullet

For all netizens, I have a simple advice: either disable Java or uninstall it! A brand new Java Zero Day has been identified by security firm FireEye. The constant targets are browsers that have Java v1.6 Update 41 and Java … Continue reading

Tagged , , , , , , , | Leave a comment

Exploit Diary: Ruby on Rails and Java back with exploits

Java_Bullet

The New Year welcomed Ruby on Rails and Java with exploits and zero days! Talking about Ruby on Rails first, an SQL injection vulnerability was identified on the active record in all versions. Due to the way dynamic finders in … Continue reading

Tagged , , , , , , , | Leave a comment

Exploit Diary: Firefox memory leak exploit

We at Secfence keep analyzing day to day threats and exploits to provide better solutions to our customers. Our vulnerability research specialist Mr Vinay Katoch came across one such exploit where he was able to create PoC for the exploit. … Continue reading

Tagged , , , , , | Leave a comment

Cover Story : Internet Explorer zero day used in CFR cyber espionage

First of all, Happy New Year to our all readers! The past year witnessed major cyber attacks, that later turned out to be some state sponsored cyber attacks. An example of one such state sponsored attack was the Russians attacking … Continue reading

Tagged , , , , , , , , , , , | Leave a comment

Inside story: Firefox 16 eploit code revealed

  Mozzila firefox, one of the most popular browser on planet had two think on its security and withdrew the release of its version 16 after a security researcher had discovered a vulnerability in the release. The new version 16 … Continue reading

Tagged , , , , , , | Leave a comment

And again we have an IE zero day being exploited in the wild!

  The java zero day exploit had already came under spotlight and was found to be exploited in the wild. It seems as if the java zero day authors have something more in there bags. In latest happening, a security … Continue reading

Tagged , , , , , , | Leave a comment

BlackHole Exploit kit back with new version 2.0

BlackHole is a famous and widely used exploit kit. Previously we have seen how BlackHole was being used in few malicious campaigns. Few latest exploits and modules give cyber criminal an edge over the victim and hence make them successful … Continue reading

Tagged , , , , , , , | Leave a comment

Java zero day exploitation analysis

Few days back Java zero day was in news. It made it place into metasploit as well as into exploit kits like Blackhole. Here’s a quick analysis of how the attack surfaced and came into action. As seen in earlier … Continue reading

Tagged , , , , , , | Leave a comment

X-Fuzzer: A Dynamic browser fuzzer

Usually fuzzers are used to test the parameters of an application. It compromises of various techniques like providing invalid, unexpected, or random data to the inputs of an application. Generally fuzzing is used for security assessments. In short, its like … Continue reading

Tagged , , , , | 1 Comment