Tag Archives: web protection

Beware! RBI lottery scam on the way

s2

One fine morning while doing routine work to analyze malicious mails and samples, I came across one such mail hailing from RBI offering lottery. Obviously this ain’t gonna be legitimate! :) But this kind of mail landing in inbox is … Continue reading

Tagged , , , , , , , | Leave a comment

XSS in Dell

XSS alert

Dell is a leading name in the Information Technology industry, especially the hardware segment of the industry. From servers to work stations, desktops, laptops, mobiles, Dell has got its name and a good hold on leading forms of IT gadgets. … Continue reading

Tagged , , , , , , , | 1 Comment

No, not a Java Zero Day again!

Java_Bullet

For all netizens, I have a simple advice: either disable Java or uninstall it! A brand new Java Zero Day has been identified by security firm FireEye. The constant targets are browsers that have Java v1.6 Update 41 and Java … Continue reading

Tagged , , , , , , , | Leave a comment

HealthKart.com XSS

XSS alert

Many a times passing by few websites, we have responsibly disclosed security related issues especially XSS and SQL injection threats. This is one of the findings of our. HealthKart.com is an e-commerce website dealing in health care products, providing online … Continue reading

Tagged , , , , , | 1 Comment

PCWorld.com XSS

pc1

PCWorld is a leading magazine in the field of Information Technology updating its reader with the modern trends in technology, computers, gadgets etc. The magazine is available in paper back format and has a website as well. A month back … Continue reading

Tagged , , , , , , | Leave a comment

XSS threats on leading Indian mobile operators websites

While passing by common websites, we had came across various security issues in them in the past. Be it a bug on Facebook, Flipkart or Indian Shopping sites, we have brought up many issues in the past and have responsibly … Continue reading

Tagged , , , , , , , , | Leave a comment

Passive Information Gathering using open source tools

Information gathering, often termed as reconnaissance is a very basic and important steps during penetration testing. A well detailed and proper information gathering gives you the overall review of the architecture of the target, hence making it easy on what … Continue reading

Tagged , , , , , | 1 Comment

Exploiting the hidden LFI

Many a times during a web application penetration testing, we get to test for various security threats and bugs. This short article will narrate one such experience while penetration testing where we have noticed that many security professionals are not … Continue reading

Tagged , , , , , | Leave a comment

XSS flaws reported on NASA’s websites

Many a times while browsing many sites, we have came across severe vulnerabilities in them. Be it Facebook or any other website, we have reported our finding to make sure that site gets a safe from the reported vulnerabilities. XSS … Continue reading

Tagged , , , , , , , | 1 Comment

3 million bank accounts hacked in Iran

The security of payment process online has always been a big concern for the financial houses present around. Even after implementing top security features, a small flaw in the applications makes it damn vulnerable and easy to exploit by cyber … Continue reading

Tagged , , , , , , , | Leave a comment