• security

    OWASP AppSec Conf Delhi – Day 2; and more

    by  • September 4, 2008 • education, hackers, life, news, security, webappsec • 4 Comments

    The pictures of Day 2 are here. The second day consisted of 6 workshops – 3 before lunch and 3 after. I was confused on choosing between Sheeraj Shah and Mano Paul’s workshops during the first half; and Jason Li’s talk on “Web 2.0  Security” and “Secure Code Review” workshop (originally by Dinis Cruz, but [...]

    Read more →

    A Phish floating in Google Survey!

    by  • January 29, 2008 • demo, education, google, hackers, life, news, phishing, script, security, webappsec • 4 Comments

    Demo 1. Phizy-Phizy-Phizy I have always loved making this phizy-phizy-phizy sound purposelessly, which I once heard in a Rob Schneider movie (which, if I remember correctly, was a pathetic movie). Anyhoo! I, now, have a set of very strong reasons to move around repeating the same lines. First, we received a request to be involved [...]

    Read more →

    What a new year Gift! :)

    by  • January 5, 2008 • news, review, security, w3af, webappsec • 0 Comments

    It brings me immense pleasure to inform you that w3af (web application attack and audit framework) has been named the Best Application Scanner in BEST IT Security and Auditing Softwares 2007 list prepared by Security Database. I had mentioned in a few previous articles that I see immense potential in w3af. I must, however, also [...]

    Read more →

    AdSense exploited by malware (Trojan.Qhost.WU)

    by  • December 22, 2007 • bug, education, google, irony, life, loophole, news, security, webappsec • 5 Comments

    1. Life & Code (The title of this section is taken from Johnny’s blog of the same name, Life and Code. Although my implementation of the phrase isn’t in terms with Johnny’s, yet I could resist using it. ) Life: Three days ago I found that there are some strange entries in my local Apache [...]

    Read more →

    Orkut Latest XSS Worm; and what it means for Indian Orkuteers

    by  • December 20, 2007 • cyberlaw, defacement, education, google, guide, irony, life, news, review, security, webappsec, xss • 16 Comments

    Update: Kishor reports a flaw in the implementation of “private” videos feature on Orkut. Although I am at office and I haven’t checked it yet myself, I believe I can trust him, based on his posts at Slackers. Nice one Kishor. 1. YAWN [Yet Another Worm, Nanny] Orkut (Google’s MySpace and Facebook for Indian, Pakistan [...]

    Read more →

    Drive-by Download: Where Network Security Meets WebAppSec

    by  • November 2, 2007 • demo, education, hack, loophole, security, webappsec • 5 Comments

    DEMO This post was due since the Bank of India hack incident, and was fueled by PDP’s Drive-by Java post, which is a very simple, yet a well thought of extension (sort of) to the Drive-by Download attack. This post is aimed to provide a clearer understanding of the Drive-by Download attack (via a demo). [...]

    Read more →

    The Web is Broken

    by  • October 12, 2007 • csrf, defacement, google, hack, hackers, humour, life, review, script, security, webappsec, xss • 0 Comments

    Update: I somehow managed to make a blunder. A part of slide no. 12 was taken from David Kierznowski’s (of GNUCitizen and Blogsecurity group) presentation for OWASP Belgium Conf. I missed out on mentioning David’s name is the credits. Apologies David. I’ve updated and re-uploaded it. Yesterday, I presented my first Webinar (Seminar on Web). [...]

    Read more →