Node.js HTTP Response Splitting
Node.js suffers from an HTTP response splitting vulnerability. Node.js versions 5.6.0, 4.3.0, 0.12.10, and 0.10.42 contain a fix for this vulnerability.
View ArticleVM Detection Via Browsers
In three browser families researched (Edge, Internet Explorer and Firefox - all on Windows 7 or above), it is possible to extract the frequency of the Windows performance counter, using standard HTML...
View ArticleMicrosoft IE9 Math.random Vulnerability
The IE9 (platform preview) Javascript Math.random implementation is vulnerable to seed reconstruction. The seed reveals the computer's boot time (and on Windows 7 - also CPU clock speed). These can be...
View ArticleCross-Domain Information Leakage / Temporary User Tracking In Safari
Apple Safari versions 4.02 through 4.05 and Windows versions 5.0 through 5.0.2 suffer from cross-domain information leakage and temporary user tracking vulnerabilities.
View ArticleCross-Domain Information Leakage In Firefox
Firefox versions 3.6.4 through 3.6.8, 3.5.10 through 3.5.11 and 4.0 Beta1 suffer from a cross-domain information leakage vulnerability.
View ArticleGoogle Chrome 3.0 Beta Math.random Vulnerability
The revised Google Chrome Math.random algorithm (included in version 3.0 of Google Chrome) is predictable. This paper describes how Google Chrome 3.0 Math.random's internal state can be reconstructed,...
View ArticleTemporary User Tracking
Whitepaper called Temporary user tracking in major browsers and Cross-domain information leakage and attacks.
View Articleaddress-spoof.txt
Address Bar Spoofing Attacks Against Microsoft Internet Explorer 6. Due to formatting issues when sent , additional notes regarding the attacks are appended.
View Articlemsswi-blog.txt
It appears that Microsoft may have incorrectly stated a few things regarding MS08-020 on their blog and are reluctant to fix it.
View ArticleMicrosoft_Windows_resolver_DNS_cache_poisoning.pdf
This paper shows that Windows DNS stub resolver queries are predictable - i.e. that the source UDP port and DNS transaction ID can be effectively predicted. A predictability algorithm is described...
View ArticlePowerDNS_recursor_DNS_Cache_Poisoning.pdf
PowerDNS Recursor versions 3.0 through 3.1.4 suffer form a DNS cache poisoning vulnerability.
View ArticleOpenBSD_DNS_Cache_Poisoning_and_Multiple_OS_Predictable_IP_ID_Vulnerability.pdf
The paper describes a weakness in the pseudo random number generator (PRNG) in use by OpenBSD, Mac OS X, Mac OS X Server, Darwin, NetBSD, FreeBSD and DragonFlyBSD to produce random DNS transaction IDs...
View ArticleWindows DNS Cache Poisoning Whitepaper
The paper shows that Microsoft Windows DNS Server outgoing queries are predictable, allowing for cache poisoning attacks.
View ArticleBIND 8 DNS Cache Poisoning Whitepaper
The paper shows that BIND 8 DNS queries are predictable, allowing for cache poisoning attacks.
View Articlebind9forgery.txt
A new weakness has been discovered in the BIND 9 DNS server that allows for DNS forgery pharming.
View ArticleHeaderFlash.txt
Formal write up discussing how arbitrary HTTP requests can be crafted using Flash 7/8 with Internet Explorer.
View ArticleflashTheft.txt
By forging HTTP request headers with flash, virtual hosted systems can be susceptible to cookie theft using IE.
View ArticlehttpResponseSmuggle.txt
Whitepaper entitled "HTTP Response Smuggling". It discusses evasion techniques to bypass anti-HTTP response splitting strategies.
View ArticlexmlhttpRequestpaper.txt
Whitepaper entitled "Exploiting the XmlHttpRequest object in IE - Referrer spoofing, and a lot more."
View Article