In real life, when you take two species, a horse and a donkey, and mix them up you
get a mule. In the
browsers world, when you take a horse (Firefox/IE) and a donkey (Safari) and mix them
up, you get...
Do you think that just following security best practices will keep you and your users
safe? Think again.
Recently, I've found 2 examples where following security best practices can...
Summary
The iPhone's Mail and Safari applications
are prone to a URL Spoofing vulnerability, which may allow attackers to conduct phishing
attacks against iPhone users.
By creating a specially...
Apple’s Safari for Windows is a nice browser. It really is. It has slick user interface,
some pretty cool features, and benchmarks show that it is really fast. But, saying
that it is “secured from...
I’ve just read Ryan's post about
the new VLC remote code execution vulnerability. He quoted Secunia’s workaround
recommendation for VLC users: “Do not open untrusted WAV files”. This...
[Updated - see below]
Yes, you've read it right. Apple Safari can be used to pwn users with Internet
Explorer installed. Well, basically this means that attackers can pwn Windows users
who browse...
During the past 2 weeks I got tons of questions regarding the 0day treasure hunt and
the vulnerability itself. In order to make things more clear and understandable, I've
compiled a list of answers...
Summary
Internet Explorer is prone to a Cross-Zone Scripting vulnerability in its “Print Table
of Links” feature. This feature allows users to add to a printed web page an appendix
which contains...
[And the winner is: George the Greek]
Today we are celebrating, here in Israel, 60
years of being an independent country. As part of the celebration, I’m releasing
a new 0day vulnerability.
One...
I hate when things like this happen. You are too eager to succeed in something, and
it eventually fails because of pure bad luck. This exactly what happened to me in CanSecWest's
PWN2OWN contest....