Monday, May 11, 2009
Gmail/Google Doc PDF Repurposing Integrated Attacks - Cookie Hijacking / Stealing
Google docs network was vulnerable to PDF repurposing attacks. The vulnerability was disclosed to Google responsibly. This was done to mitigate the risk. Google had worked over it and patched it with in a period of 5 days.
The Google doc has been refined now and the integrated support for adobe plugin is removed. The user security was the prime issue because millions of user were at risk if this attack persisted in the open environment. Integrated accounts were more susceptible as certain stolen credentials could be used to access accounts.
The advisory is released here:
http://secniche.org/gmd_hijack/gc_hijack.xhtml
http://secniche.org/gmd_hijack/advisory_gmail_google_docs_pdf_repurposing_attack.pdf
Enjoy !
Saturday, May 02, 2009
Troopers 09 Security Conference
The troopers security conference is the one of the finest conference I have been to. Its very nice to have such conference in the heart of Germany. a great technical content and nice crew to discuss things and hang around :). I gave a talk on "Browser Design Flaws". There were some good talks around rootkits , malware for business purposes and web application firewall stuff. All talks were good and it was a great learning environment. Visit :Troopers09
Personally I liked the Packet Wars Hacking Competition by Bryan. It was nicely organized. You can look at the stuff at : Packet Wars Good hacking games to enjoy.
If you miss the fun you can have a look at the snaps here : Troopers09 fun
Regards
Personally I liked the Packet Wars Hacking Competition by Bryan. It was nicely organized. You can look at the stuff at : Packet Wars Good hacking games to enjoy.
If you miss the fun you can have a look at the snaps here : Troopers09 fun
Regards