Sponsored White Papers, Webcasts, and Downloads
ZDNet Resources
- Wi-Fi routers vulnerable to UPnP attack from hackers
- A couple of weeks ago we discovered that it's possible for viruses to quickly spread among unsecured or WEP-encrypted Wi-Fi routers in densely populated urban areas. The solution seemed to be simple: Use WPA encryption and strong passwords. Now, based on an article Gnucitizen, there's another way for hackers to...
- Tags: Router, Article, Wi-Fi Router, Wi-Fi, Hacker, UPnP, Attack, Gnucitizen, Routers & Switches, Network Technology, Networking, Rik Fairlie
- Blog posts 2008-01-15
- Researchers outline Wi-Fi router hijacking via browser
- Two security researchers have outlined how hackers can use a Web browser and a little Shockwave file to exploit most Wi-Fi routers. Ryan Naraine interviewed two researchers, Adrian Pastor and Petko D. Petkov, at the GNUCITIZEN think tank. Their big conclusion: It's trivial to construct "a massive...
- Tags: Router, Wi-Fi Router, Wi-Fi, Web Browser, UPnP, GNUCITIZEN, Routers & Switches, Network Technology, Networking, Larry Dignan
- Blog posts 2008-01-15
Additional Resources
- On GIFARs
- Ever since Rob McMillan of IDG published a story giving a preview of our coming Black Hat talk, specifically a preview of the portion of our talk related to GIFARs, media coverage of the research has swirled a bit out of control and there's been some misconceptions. My co-presenter John...
- Tags: Black Hat, Vector, Applet, Image, Attack, Heasman, Nathan McFeters
- Blog posts 2008-08-02
- Apple releases patches for dangerous QuickTime flaws in Apple TV 2.1 product
- Apple released patches for its Apple TV 2.1 product yesterday. Some of you might be saying, why do I care, I don't use Apple TV. Well, if you do use Apple TV, you obviously should care as some of these are very serious flaws, but if you don't,...
- Tags: Apple QuickTime, Movie, Patch Management, Apple Inc., Issue, Apple TV, Arbitrary Code Execution, Flaw, IMPACT, CVE-ID, Application Termination, Nathan McFeters
- Blog posts 2008-07-11
- House of Hackers social community opens up
- PDP, the leader of the Gnucitizen White Hat Hacker outfit announced the opening of the House of Hackers social community yesterday. The House of Hackers is intended to enable its members to exchange ideas with each other, communicate, form groups, elite circles and tiger/red teams, conglomerate around projects, and participate in...
- Tags: Community, Network, Member, Hacker, Gnucitizen White Hat Hacker, House, Hacking, Social Networking, Networking, Security, Online Communications, Marketing, Advertising & Promotion, Nathan McFeters
- Blog posts 2008-05-06
- More URI handler issues to come
- Rob Carter, Billy Rios, and I have been blogging about and speaking at conferences like Black Hat and ToorCon all year on the subject of URI handler abuse. One might think these types of flaws are soon to go away, but one look at SecurityFocus and FullDisclosure today and you can see...
- Tags: Flaw, Security, Nathan McFeters
- Blog posts 2008-04-25
- Researcher discovers QuickTime zero-day
- White hat hacker Petko D. Petkov has discovered a zero-day vulnerability in a patched version of Apple's QuickTime player for XP and Vista and has the video to prove it. Ryan Naraine has the video from Petkov, founder of the GNUCitizen think tank. In...
- Tags: Apple QuickTime, Video, Corporate Communications, Digital Music, Digital Media, Marketing, Personal Technology, Consumer Electronics, Larry Dignan
- Blog posts 2008-04-22
- Black Hat Europe, Day 2: The day that wasn't and Black Hat Europe, Day 3: Begin the presentations
- If you haven't seen it yet, you can check out Day 1 of my coverage of Black Hat Europe 2008 here. So, for those of you looking forward to a Black Hat Day 2 update with some more from the training sessions... I'm afraid it didn't happen. I had...
- Tags: Black Hat, Antivirus, Buffer-overflow, Attack, Breese, Security, Viruses And Worms, Nathan McFeters
- Blog posts 2008-03-29
- Are Routers the Next Big Target for Hackers?
- I've recently seen a great Black Hat presentation by Felix FX Lindner (see pic 2) and a blog posting by Petko D. Petkov PDP (see pic 1) on the subject of hacking routers. What seems to be clear is that they are becoming a bigger target. PDP, of the gnucitizen group, recently...
- Tags: Nathan McFeters
- Blog posts 2008-03-04
- Snom VoIP phone vulnerability enables phone history theft, addy book poisoning, and more
- Fellow VoIP blogger and multi-skilled polymath Tom Keating picks up on security consultancy GNUCitizen.org's description of a security vulnerability in snom Technology's model 320 VoIP phone. GNUCitizen, in turn, found this via what they term a "side result" of a router hacking challenge...
- Tags: VoIP, Phone, Vulnerability, XSS, VoIP Phone, Snom, Telecom & Utilities, Russell Shaw
- Blog posts 2008-02-12
- eEye spies new code-exection Windows hole
- eEye spies new code-exection Windows holeYOWB - Year of Windows Bugs?NTRyan, don't forget theseHow comes you managed to miss these high risk vulnerabilities?[url=http://www.securityfocus.com/archive/1/464719/30/0/threaded]Mozilla Firefox Insecure Element Stealth Injection Vulnerability[/url]and [url=http://www.securityfocus.com/archive/1/464740/30/0/threaded]Firefox extensions go Evil - Critical Vulnerabilities in Firefox/Firebug[/url]and[url=http://www.securityfocus.com/archive/1/464724/30/0/threaded]High Risk Vulnerability in OpenOffice[/url]I'm sure it was just an oversight...Silent fixes --...
- Tags: Web browsers, OpenOffice, SECURITY, Web browser, Firefox/Firebug, vulnerability, Firebug, chrome, flaw, eEye Digital Security, Microsoft Windows
- Discussion threads 2007-04-05
- Mozilla mulls Windows cursor flaw fix of its own
- Mozilla mulls Windows cursor flaw fix of its ownThe patch doesn't work for meits windoze based!Firefox extensions go Evil - Critical VulnerabilitiesFirefox extensions go Evil - Critical Vulnerabilitieswww.gnucitizen.org/blog/firebug-goes-evilThere is critical vulnerability in Firefox/Firebug which allowsattackers to inject code inside the browser chrome. This can lead to alot of problems. Theoretically...
- Tags: Web browsers, Operating systems, Mozilla Corp., MS Updates, Mozilla Firefox, POC, Firebug, Firefox Users, Microsoft Internet Explorer, Microsoft Corp., Linux, Microsoft Windows
- Discussion threads 2007-04-05
- Mozilla to ship Firefox 'workaround' for .ANI exploit
- Mozilla to ship Firefox 'workaround' for .ANI exploitWhy not just patch?What's the point? Why not just apply the patch, something you should do anyuway?Firefox / Firebug critical vulnerability!! (
- Tags: Web browsers, Mozilla Firefox, Firebug, Mozilla Corp., vulnerability
- Discussion threads 2007-04-04
- << Previous
- page 1 of 1
- Next >>
White Papers and Webcasts