No Country For Old Vulnerabilities

Leveraging LFI To Get Full Compromise On WordPress Sites

In this post I will discuss how a serious but mostly ignored vulnerability can lead to a full ...

Read More

8 Common Pitfalls of Heartbleed Identification and Remediation (CVE-2014-0160)

Unfortunately, one of the biggest vulnerabilities disclosed this year, Heartbleed, has been ...

Read More

Detecting A Surveillance State - Part 2 Radio Frequency Exfiltration

In the last post we reviewed a few hardware implants that may have been used by surveillance states ...

Read More

Exploiting Serialized XSS in Joomla! (return of the undead CVE)

While reviewing Joomla! Vulnerabilities I felt a glitch in the matrix. Deja vu had set in and I was ...

Read More

Jamming With WordPress Sessions

Let's talk about some targeted attacks where session management can be targeted to side step multi ...

Read More

Breaking the Authentication Chain

This little post is going to talk about how authentication goes beyond just usernames and passwords.

Read More