WordPress Pingback Vulnerability

Recently somebody posted on Reddit about a WordPress scanner that is taking advantage of a new WordPress vulnerability. The vulnerability is abusing the Pingback system, which is a well-known feature that’s used by a lot of bloggers. What is a Pingback? Quoting Wikipedia: A pingback…

Read more

Finding Web Flaws is not Point and Click

Successful web security testing is not as simple as point and click. Unfortunately, many people treat it as such. The thought process goes something like this: 1.    Load web vulnerability scanner. 2.    Enter URL to scan. 3.    Click Go. 4.    Generate report for the auditors….

Read more

The Email that Hacks You

Update: Seems to be working on TP-Link Routers as well (tested on TL-WR841N). Update2: Arcor EasyBox A600 also seems vulnerable. Opening a legitimate looking email on an iPhone, iPad or Mac while using an Asus router with a default or guessable password could compromise the security of…

Read more

It’s No Picnic: NBC Websites Hacked

On November 4th, Steven J. Vaughan-Nichols of ZDNet, who covers security, posted on his blog that NBC had suffered a hack on a number of its websites during the early morning of Sunday, November 4th. According to Vaughn-Nichols, as of noon Eastern Standard Time the…

Read more