web

Zoetis to Host Webcast and Conference Call on Fourth Quarter and Full Year 2015 Financial Results




web

500,000 Zoom IDs, Passwords Being Sold At 15 Paisa On Dark Web; This Bank Has Banned Zoom!

With the extended lockdown in the Coronavirus pandemic has pushed people to work from home and conduct meetings via video conferencing.  During this time, it’s no surprise that apps like Zoom witnessed a massive surge in usage. What About The Security? But, along with popularity, Zoom has been the target of controversies over security issues. […]

The post 500,000 Zoom IDs, Passwords Being Sold At 15 Paisa On Dark Web; This Bank Has Banned Zoom! first appeared on Trak.in . Trak.in Mobile Apps: Android | iOS.




web

Marquette adds Gardner-Webb transfer Perez

Marquette has added Gardner-Webb transfer Jose Perez, who scored at least 15 points per game for his former team each of the past two seasons.






web

Advantech WebAccess dvs.ocx GetColor Buffer Overflow

This Metasploit module exploits a buffer overflow vulnerability in Advantec WebAccess. The vulnerability exists in the dvs.ocx ActiveX control, where a dangerous call to sprintf can be reached with user controlled data through the GetColor function. This Metasploit module has been tested successfully on Windows XP SP3 with IE6 and Windows 7 SP1 with IE8 and IE 9.




web

Advantech WebAccess 7.2 Stack-Based Buffer Overflow

Core Security Technologies Advisory - Advantech WebAccess version 7.2 is vulnerable to a stack-based buffer overflow attack, which can be exploited by remote attackers to execute arbitrary code, by providing a malicious html file with specific parameters for an ActiveX component.




web

Advantech WebAccess 8.0 / 3.4.3 Code Execution

Using Advantech WebAccess SCADA Software and attacker can remotely manage industrial control systems devices like RTU's, generators, motors, etc. Attackers can execute code remotely by passing a maliciously crafted string to ConvToSafeArray API in ASPVCOBJLib.AspDataDriven ActiveX.





web

Soca Website Attack: Norway Arrests Two Youths




web

KeeWeb 1.14.0 HTML Injection

KeeWeb version 1.14.0 suffers from an html injection vulnerability.





web

Web Tools Create XSS Headaches




web

Scripting Bugs Blight Security Giants' Websites




web

Attention Symantec - There Is A Bug Crawling On Your Website




web

MoD Website Outflanked By XSS Flaws




web

Anti-Virus Vendor Trio Plug Website Flaws





web

Hackers Shut Down NDDC Website Over Presidential Inauguration








web

Hacking ASP/ASPX Websites Manually

This is a whitepaper that goes into detail on hacking ASP/ASPX websites manually.




web

ASP Webshell For IIS 8

ASP webshell backdoor designed specifically for IIS 8.




web

AfterLogic WebMail Pro ASP.NET Account Takeover / XXE Injection

AfterLogic WebMail Pro ASP.NET versions prior to 6.2.7 suffer from an administrator account takeover via an XXE injection vulnerability.




web

Defending Islam, Hacker Defaces Thousands Of Dutch Websites







web

Microsoft Warns Of Hacking Group Targeting Vulnerable Web Servers




web

webTareas 2.0.p8 Arbitrary File Deletion

webTareas version 2.0.p8 suffers from an arbitrary file deletion vulnerability.





web

Wapiti Web Application Vulnerability Scanner 3.0.2

Wapiti is a web application vulnerability scanner. It will scan the web pages of a deployed web application and will fuzz the URL parameters and forms to find common web vulnerabilities.




web

WebSploit Framework 4.0.1

WebSploit is an advanced man-in-the-middle framework.




web

Wapiti Web Application Vulnerability Scanner 3.0.3

Wapiti is a web application vulnerability scanner. It will scan the web pages of a deployed web application and will fuzz the URL parameters and forms to find common web vulnerabilities.




web

Apache2 Web Server Hardening Article

This is an article discussing Apache2 Web Server hardening. Written in Turkish.




web

Google Launches Coronavirus Website In The United States





web

Memorial Web Site Script Password Reset / Insecure Cookie

Memorial Web Site Script suffers from password reset and insecure cookie handling vulnerabilities.




web

xWeblog 2.2 Insecure Cookie Handling

xWeblog version 2.2 suffers from an insecure cookie handling vulnerability.




web

WikiWebHelp 0.3.3 Insecure Cookie Handling

WikiWebHelp version 0.3.3 suffers from an insecure cookie handling vulnerability.




web

web.go Insecure Cookie

web.go suffers from an insecure cookie vulnerability. Their cookie is modeled after Tornado which had the same issue reported on in 2010.









web

Webmin 1.920 password_change.cgi Backdoor

This Metasploit module exploits a backdoor in Webmin versions 1.890 through 1.920. Only the SourceForge downloads were backdoored, but they are listed as official downloads on the project's site. Unknown attacker(s) inserted Perl qx statements into the build server's source code on two separate occasions: once in April 2018, introducing the backdoor in the 1.890 release, and in July 2018, reintroducing the backdoor in releases 1.900 through 1.920. Only version 1.890 is exploitable in the default install. Later affected versions require the expired password changing feature to be enabled.