sirdarckcat

Monday, May 12, 2008

Ghosts for IE8 and IE7.5730

›
Here's a new version of the last post code for hijacking IE6 and IE7 iframes. Aparently some versions of IE where fixed, (the code didnt...
Sunday, May 11, 2008

Browser's Ghost Busters

›
Due to the news that there are a few ghost busters on the wild, and no one is willing to tell us exactly what's the ghost about, I...
Thursday, January 03, 2008

Exploiting XSS vulnerabilities on cookies

›
Well, after talking with David Ross about the last post (bypassing content-disposition), I found out that it's exploitation wasn't a...
Sunday, December 30, 2007

Bypassing Content-Disposition: attachment for XSS on IE

›
Well first of all I want to congrats my friend kuza55 because of his talk "Unusual Web Bugs" at 24c3, was a success. I watched it ...
Monday, December 24, 2007

Making a Social Network XSS Worm (hi5.com)

›
Well, the last couple of days I've been playing with hi5. It's pretty cool, and I found a couple of XSS vulnerabilities. I reported ...
Wednesday, November 21, 2007

CSK2 and CSS Applications

›
This week, I've sort of improoved the CSK of Gareth Heyes , with a few more event handlers, and interoperability with Opera (and menus!...
Thursday, November 08, 2007

Inside History of hacking rsnake for fun and pagerank.

›
Well the research made for the exploit for the joke for rsnake is sort of interesting, so I'll try to explain what was needed (even do i...
Saturday, October 13, 2007

Vulns of Google that where, and are not?

›
Well, this are the bugs at Google services that even do are fixed now, where around for a while. First I have to say that the Google Securit...
Sunday, September 30, 2007

Universal youtube mods XSS explained in 7 steps

›
Well, I want to explain first, this was not my idea, someone at irc.irchighway.net/#slackers discussed about this a while ago, but he wasn...
Friday, September 28, 2007

Google Mashups Vulnerability

›
yay, I wanted to be part of this hell of a week (Google's Dark Week). Here is the vulnerability I reported to google, and it appears ...
Thursday, September 06, 2007

Allowing debug in a javascript library

›
Hi, some days ago I watched John Resig Tech Talk, about building a JavaScript library , where he pointed out some "good habits", w...
Saturday, September 01, 2007

7 minutes to kill a monster.

›
Well, a response time of 1 week, is said to be good, Mozilla has 10 f***ing days , Google depending on the complexity of the vulnerability t...
Thursday, August 23, 2007

SHA-1 Collision Search Graz XSS and CSRF

›
A couple of days ago, at elhacker.net , they showed a project, for finding SHA-1 collisions. After I registered, I found out that there was ...
Monday, August 06, 2007

JavaScript is just evil (for you) [ Part I ]

›
This is the first of 3 parts of the document entitled: " JavaScript is just evil ". Here are the first 2 chapters. 1.- DoSing the ...

Morfi! the Human readable+HTML+JavaScript file all in one..

›
Here I present a file that will appear different depending on which application you open it. As plain text, it will describe how it works, a...
Saturday, August 04, 2007

Google teachs security basics

›
It's rather simple.. and it deals with vulns at the "server level" (no sqli, rfi, xss, etc..) anyway.. http://code.google.com/...
Sunday, July 29, 2007

DoSing Firefox with Error Consoles

›
3 days ago, I found out that there was a way of Popping up the Firefox JavaScript Error Console, by doing: <iframe src="javascript:...
Friday, July 27, 2007

Temporal Cache Poisoning (IExplorer and Firefox) = Feature?

›
While making estigma 's function EditHTML() (a WYSIWYG editor), I realized that the code modified, will stay on cache, until you close t...
Thursday, July 26, 2007

Playing with Google Wireless Transcoder

›
Last Week, I found Google Wireless Transcoder , and I started playing with it trying to find a XSS bug in the HTML "transcoder", a...
Saturday, July 07, 2007

Passing Variables by Reference in JavaScript

›
Long time ago, when I was learning C, and I understood the use of pointers, I started thinking if there was a way to pass the JavaScript var...
‹
Home
View web version
Powered by Blogger.