January 2007 - Posts

How Prevalent Are XSS Vulnerabilities?
How Prevalent Are Cross Site Scripting (XSS) Vulnerabilities? Based on a recent experiment, I wasn't surprised to see that they're everywhere and finding dozens at a time doesn't present much of a challenge. Back in September, 2006 I sought Read More...
Posted 31 January 07 01:27 by Erik | 4 Comments   
Filed under ,
Evaluating Security Tools
All companies face the challenge of evaluating security tools that they will procure, but knowing where to start can be a daunting task. While there's no perfect way to ensure that a product meets your needs a little due diligence is essential. Fortunately, Read More...
Posted 26 January 07 03:50 by Erik | 2 Comments   
Decoding the Google Blacklist
After publishing last week's blog entitled ‘A Tour of the Google Blacklist' , I received a few queries about Google's encoded/hashed blacklist (enchash). This blacklist is separate from the unencoded blacklist that was the focus of the Read More...
Posted 10 January 07 04:07 by Erik | 3 Comments   
Filed under
Microsoft Black Tuesday - January 2007
This month's bulletins leave us with two major headlines. First, ‘What happened to half of the bulletins?' and secondly, Internet Explorer 7.0 isn't apparently quite as bullet proof as advertised. Even before Black Tuesday arrived this Read More...
Posted 09 January 07 02:13 by Erik | 7 Comments   
A Tour of the Google Blacklist
[Update 01.10.07: In response to some of the queries that I've been receiving, I've published a follow up blog to discuss the structure/decryption algorithm of Google's Encoded/Hashed Blacklist .] I recently decided to devote a day to walking Read More...
Posted 04 January 07 12:48 by Erik | 52 Comments   
Filed under , ,