Archive for April, 2007
ClipperZ is a JavaScript cryptographic library that lets web developers use extensive and efficient set of cryptographic functions. The library aims to obtain maximum execution speed while preserving modularity and re-usability. The library presently includes: SRP authentication protocol, SHA2 hash functions, AES symmetric encryption and Fortuna PRNG. The developers plan to add support for elliptic [...]
PwdHash, from the Security Lab at Stanford University, is a browser extension - available for Internet Explorer, Firefox and Opera - that converts a user’s password into a domain-specific password. PwdHash reads any password fields in a web form and dynamically replaces them with unique strong passwords.
The unique password is auto-generated by combining the user-specified [...]
WEP, or Wired Equivalent Privacy, is the default protocol used for securing wireless LANs. It uses the RC4 stream to encrypt data which is transmitted over the air, using usually a single secret key - the WEP key - of a length of 40 or 104 bit.
aircrack-ptw is a WEP key cracking tool that utilizes [...]
SafePasswd is a free online web site that helps users generate memorable, secure passwords for use on web sites, business systems, or any other place that may need a password. You can choose various characteristics of a good password and visually see how effective a password is.
In Windows Vista, even though you have administrator privileges, the programs you run have “Standard User” permissions, unless they ask you for permission through the User Account Control mechanism - “Windows needs your permission to continue”.
If you are comfortable with command line utilities, a possible option is to run a command line with Administrator [...]
WirelessKeyView is a free utility to recover all wireless keys (WEP and WPA) stored on your computer. It allows you to easily save all keys to text/html/xml file, or copy a single key to the clipboard. WirelessKeyView supports both Windows XP Wireless Zero Configuration service and Windows Vista WLAN AutoConfig service.
Download the latest version of [...]
Windows Vista includes a security mechanism that labels objects with an integrity level. Files and folders have integrity levels, as do users and processes. Vista has six integrity levels, from highest trustworthiness to lowest: Trusted Installer, System, High, Medium, Low and Untrusted.
So, what are integrity levels? Well, they act as a kind of second [...]
The firewall is our gateway to the Internet. It is a piece of software or hardware that manages Internet connections to and from your computer. It monitors the applications that try to initiate connection with your computer from the Internet, and it controls which programs are allowed to use the Internet.
Nowadays, Internet users are exposed [...]
FG-Injector is a free open source framework designed to help find SQL injection vulnerabilities in web applications. It includes a proxy feature for intercepting and modifying HTTP requests, and an interface for automating SQL injection exploitation.
It’s a common thought among web developers that by disabling error messages in their code, SQL injection vulnerabilities stop being [...]
The ability of users to add new hardware devices to their computers creates a significant security issues for system administrators. A malicious user can potentially use a removable device with malicious software configured on it that includes an auto-run script to install malicious software on computers and steal company’s sensitive data.
Windows Vista enables system administrators [...]
Contact
Have a hot hack? want to request a hack? let us know - editor [at] security-hacks.com
subscribe
Search
Latest Entries
- msramdmp: Dump RAM from a USB stick
- SWFIntruder: Are your Flash applications secure?
- Untidy: Python-based XML fuzzer
- Jailbreaking iPhone software v1.1.1
- Secure browsing with Squid and SSH
- Combat spam with Gmail aliases
- 5 Essential laptop security tips
- Email encryption with GPG and Mail.app
- Firefox: Disable suspicious JavaScript features
- aSSL: Add SSL to your Ajax application
Archives
Categories
- Data Recovery (2)
- Encryption (16)
- Firefox (5)
- Hacks (36)
- In the news (1)
- Internet Explorer (1)
- iPhone (1)
- Linux (9)
- Mac OS X (2)
- Mobile devices (2)
- Network (7)
- Privacy (28)
- Tools (29)
- Vista (14)
- Web Security (28)
- Windows (25)
- wireless (4)
