December 10, 2010

PayPal Send Money Cross-Site Scripting Vulnerability







1. Summary:

PayPal's send money feature is affected by an XSS (cross-site scripting) vulnerability.


Trustwave WebDefend Static Database Password Vulnerability








1. Summary:

A static database username and password has been identified in Trustwave's Security's WebDefend Enterprise Console product.  The information could potentially allow a remote attacker access to the database located on the WebDefend appliance.



Trustwave WebDefend Static Console Password Vulnerability



1. Summary:

A static console username and password has been identified in Trustwave's WebDefend Enterprise Console product.  The information could potentially allow a remote attacker access to the data in the database located on the WebDefend appliance.


December 8, 2010

Presenting @ OISF










This month at Ohio Information Security Forum,  I'm going to be demonstrating a new security advisory Microsoft chooses to ignore.

More information on the advisory can be found @ www.exploitdevelopment.com