Archive | Security RSS feed for this section

Security in October: Google Wave, Facebook, XSS

30. October 2009

7 Comments

Security in October: Google Wave, Facebook, XSS

Further support of what I mentioned in my presentation In my Cross-site scripting presentation at #heweb09, I mentioned that a North Carolina State University report from September 2008 showed that users clicked the “ok” button on message alerts 61% of the time, regardless of whether the message alert was legitimate or not.  From that I concluded [...]

Continue reading...

New Utility Allows You to Control Facebook Accounts Without the Password

21. October 2009

5 Comments

New Utility Allows You to Control Facebook Accounts Without the Password

FBConTroller v2.0 was released late yesterday.  As the author clearly states, FBController does not, nor can it, hack into a Facebook account.  What it CAN do though is to control a Facebook account (write on one’s own wall, others wall, retrieve profile page, retrieve friends list and even attempts to retrieve inbox and send messages) [...]

Continue reading...

How Serious are XSS Threats for .edu’s?

16. June 2009

10 Comments

How Serious are XSS Threats for .edu’s?

Well, thanks to the keen eyes of fellow higher ed tweeter @gilzow for spotting the article, plenty of these guys could tell you just how frustrating XSS attacks can be.  There’s simply no avoiding the fact that the more dynamic and complex our higher ed sites get, the more prone we are to these exploits.  [...]

Continue reading...