Archive for April, 2007

ClipperZ - JavaScript Crypto library

ClipperZ is a JavaScript cryptographic library that lets web developers use extensive and efficient set of cryptographic functions. The library aims to obtain maximum execution speed while preserving modularity and re-usability. The library presently includes: SRP authentication protocol, SHA2 hash functions, AES symmetric encryption and Fortuna PRNG. The developers plan to add support for elliptic [...]

PwdHash, from the Security Lab at Stanford University, is a browser extension - available for Internet Explorer, Firefox and Opera - that converts a user’s password into a domain-specific password. PwdHash reads any password fields in a web form and dynamically replaces them with unique strong passwords.
The unique password is auto-generated by combining the user-specified [...]

aircrack-ptw - WEP Cracking tool

WEP, or Wired Equivalent Privacy, is the default protocol used for securing wireless LANs. It uses the RC4 stream to encrypt data which is transmitted over the air, using usually a single secret key - the WEP key - of a length of 40 or 104 bit.
aircrack-ptw is a WEP key cracking tool that utilizes [...]

SafePasswd - Generate secure passwords online

SafePasswd is a free online web site that helps users generate memorable, secure passwords for use on web sites, business systems, or any other place that may need a password. You can choose various characteristics of a good password and visually see how effective a password is.

Vista: Run CMD as Administrator

In Windows Vista, even though you have administrator privileges, the programs you run have “Standard User” permissions, unless they ask you for permission through the User Account Control mechanism - “Windows needs your permission to continue”.
If you are comfortable with command line utilities, a possible option is to run a command line with Administrator [...]

WirelessKeyView - Recover WEP and WPA keys

WirelessKeyView is a free utility to recover all wireless keys (WEP and WPA) stored on your computer. It allows you to easily save all keys to text/html/xml file, or copy a single key to the clipboard. WirelessKeyView supports both Windows XP Wireless Zero Configuration service and Windows Vista WLAN AutoConfig service.

Download the latest version of [...]

Manage Vista Integrity Levels with CHML

Windows Vista includes a security mechanism that labels objects with an integrity level. Files and folders have integrity levels, as do users and processes. Vista has six integrity levels, from highest trustworthiness to lowest: Trusted Installer, System, High, Medium, Low and Untrusted.
So, what are integrity levels? Well, they act as a kind of second [...]

How to test your firewall

The firewall is our gateway to the Internet. It is a piece of software or hardware that manages Internet connections to and from your computer. It monitors the applications that try to initiate connection with your computer from the Internet, and it controls which programs are allowed to use the Internet.
Nowadays, Internet users are exposed [...]

FG-Injector is a free open source framework designed to help find SQL injection vulnerabilities in web applications. It includes a proxy feature for intercepting and modifying HTTP requests, and an interface for automating SQL injection exploitation.
It’s a common thought among web developers that by disabling error messages in their code, SQL injection vulnerabilities stop being [...]

Vista: Install authorized removable devices only

The ability of users to add new hardware devices to their computers creates a significant security issues for system administrators. A malicious user can potentially use a removable device with malicious software configured on it that includes an auto-run script to install malicious software on computers and steal company’s sensitive data.
Windows Vista enables system administrators [...]




Security-Hacks is a web site that covers tips and tricks for security. Updated several times daily, Security-Hacks points out tools downloads, how-to's and tutorials.

Contact


Have a hot hack? want to request a hack? let us know - editor [at] security-hacks.com

subscribe

Enter your Email

Archives

Add to Technorati Favorites

Categories