Websec.ca - Information Security Solutions
https://www.websec.ca/rss
es-ESA Comparison Between the Real User ID and the Effective User ID is not Enough to Prevent Privilege Escalation
http://www.websec.ca/publication/Blog/comparison-between-real-user-id-and-effective-user-id-is-not-enough-to-prevent-privilege-escalation
Tue, 03 Oct 2023 19:39:50 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/comparison-between-real-user-id-and-effective-user-id-is-not-enough-to-prevent-privilege-escalationCVE-2022-21404: Another story of developers fixing vulnerabilities unknowingly because of CodeQL
http://www.websec.ca/publication/Blog/CVE-2022-21404-Another-story-of-developers-fixing-vulnerabilities-unknowingly-because-of-CodeQL
Thu, 19 May 2022 18:18:09 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/CVE-2022-21404-Another-story-of-developers-fixing-vulnerabilities-unknowingly-because-of-CodeQLCybersecurity in Web Applications - Where to start? Where to improve? Where to learn more?
http://www.websec.ca/publication/Blog/Appsec-Resources-For-Developers-Where-To-Start
Thu, 02 Sep 2021 17:46:16 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/Appsec-Resources-For-Developers-Where-To-StartHardening guide for JBoss EAP 7.0
http://www.websec.ca/publication/Blog/Hardening-guide-for-JBoss-EAP-7-0
Fri, 14 Dec 2018 22:39:19 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/Hardening-guide-for-JBoss-EAP-7-0Nmap scripts for Trane Tracer SC HVAC
http://www.websec.ca/publication/Blog/Nmap-scripts-for-Trane-Tracer-SC-HVAC
Fri, 14 Dec 2018 22:38:29 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/Nmap-scripts-for-Trane-Tracer-SC-HVACNcrack and Nmap NSE development for offense and defense - DEFCON CHINA
http://www.websec.ca/publication/Blog/Ncrack-and-Nmap-NSE-development-for-offense-and-defense-DEFCON-CHINA
Fri, 14 Dec 2018 22:31:13 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/Ncrack-and-Nmap-NSE-development-for-offense-and-defense-DEFCON-CHINALaunching replay attacks against the Wells Fargo Wallet service
http://www.websec.ca/publication/Blog/launching-replay-attacks-wells-fargo-wallet-service
Tue, 20 Nov 2018 19:28:28 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/launching-replay-attacks-wells-fargo-wallet-serviceThree Non Web-based XSS Injections
http://www.websec.ca/publication/Blog/Three-Non-Web-based-XSS-Injections
Tue, 19 Dec 2017 00:00:00 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/Three-Non-Web-based-XSS-InjectionsBelkin Wemo Switch NMap Scripts
http://www.websec.ca/publication/Blog/Belkin-Wemo-Switch-NMap-Scripts
Fri, 23 Jun 2017 00:00:00 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/Belkin-Wemo-Switch-NMap-ScriptsNew publication: Mastering the Nmap Scripting Engine
http://www.websec.ca/publication/Blog/mastering-the-nmap-scripting-engine
Tue, 29 Nov 2016 05:41:58 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/mastering-the-nmap-scripting-engineDownloading an Application's Entire Source Code Through an Exposed GIT Directory
http://www.websec.ca/publication/Blog/downloading-entire-source-code-through-exposed-GIT-directory
Fri, 19 Feb 2016 23:45:19 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/downloading-entire-source-code-through-exposed-GIT-directoryBackdoors in Zhone GPON 2520 and Alcatel Lucent I240Q
http://www.websec.ca/publication/Blog/backdoors-in-Zhone-GPON-2520-and-Alcatel-Lucent-I240Q
Thu, 08 Jan 2015 00:00:00 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/backdoors-in-Zhone-GPON-2520-and-Alcatel-Lucent-I240QDrive By ONT Botnet with IRC C&C
http://www.websec.ca/publication/Blog/drive-by-ONT-botnet-with-IRC-CC
Thu, 19 Dec 2013 18:21:40 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/drive-by-ONT-botnet-with-IRC-CC(IN)secure session data in CodeIgniter
http://www.websec.ca/publication/Blog/insecure-session-data-CodeIgniter
Thu, 04 Jul 2013 08:05:18 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/insecure-session-data-CodeIgniterPanoptic - A tool to exploit path traversal vulnerabilities
http://www.websec.ca/publication/Blog/panoptic
Sun, 14 Apr 2013 14:08:56 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/panopticSpecial discount code for "Nmap 6: Network Exploration and Security Auditing Cookbook"
http://www.websec.ca/publication/Blog/hackerhalted-discount-code-for-nmap-6-network-exploration-and-security-auditing-cookbook
Fri, 14 Dec 2012 21:39:20 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/hackerhalted-discount-code-for-nmap-6-network-exploration-and-security-auditing-cookbookBackdoor In Optical Fiber Device Alcatel-Lucent
http://www.websec.ca/publication/Blog/backdoor-in-Alcatel-Lucent
Sun, 02 Dec 2012 15:06:54 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/backdoor-in-Alcatel-LucentMac2WepKey HHG5xx for iPhone
http://www.websec.ca/publication/Blog/Mac2WepKey-HHG5xx-for-iPhone
Thu, 06 Sep 2012 14:34:52 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/Mac2WepKey-HHG5xx-for-iPhoneSolutions for challenge 2B
http://www.websec.ca/publication/Blog/solutions-challenge-2B
Wed, 22 Aug 2012 12:45:32 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/solutions-challenge-2BSolutions for challenge 2A
http://www.websec.ca/publication/Blog/solutions-challenge-2A
Sat, 14 Jul 2012 14:10:13 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/solutions-challenge-2AA series of SQL Injection challenges
http://www.websec.ca/publication/Blog/sql-injection-challenges
Sat, 07 Jul 2012 20:07:55 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/sql-injection-challengesUsing Burp to exploit a Blind SQL Injection
http://www.websec.ca/publication/Blog/using-burp-to-exploit-blind-sql-injection
Mon, 11 Jun 2012 13:02:03 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/using-burp-to-exploit-blind-sql-injectionCookie Stealing By Router Pharming (2Wire)
http://www.websec.ca/publication/Blog/Cookie_Stealing_By_Router_Pharming_2Wire
Wed, 30 May 2012 14:38:27 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/Cookie_Stealing_By_Router_Pharming_2WireRemote credential and configuration disclosure of Huawei HG5XX devices using Nmap.
http://www.websec.ca/publication/Blog/information-disclosure-huawei-hg5xx-nmap
Sun, 27 May 2012 14:40:03 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/information-disclosure-huawei-hg5xx-nmapDetecting and exploiting vulnerable PHP-CGI applications
http://www.websec.ca/publication/Blog/detecting-and-exploiting-php-cgi
Thu, 24 May 2012 20:31:18 +0000[email protected] (Websec)http://www.websec.ca/publication/Blog/detecting-and-exploiting-php-cgi