Archive for the 'Web Security' Category

The KeyScrambler Personal Firefox extension, scrambles your keystrokes at the kernel level to protect your login credentials from keyboard sniffers.
For users, that means your keystrokes will be encrypted at the keyboard driver, deep within the operating system. When the encrypted keystrokes reach the browser, KeyScrambler will decrypt them on-the-fly and let you see the keys [...]

Mozilla Firefox web browser provides a built-in password manager, which stores access credentials for visited web sites. The credentials are encrypted and stored in Firefox special database files: key3.db and signons.txt.
The key3.db file contains the master password and the key to encrypt and decrypt the passwords. The signons.txt file stores saved user names and passwords [...]

ClipperZ - JavaScript Crypto library

ClipperZ is a JavaScript cryptographic library that lets web developers use extensive and efficient set of cryptographic functions. The library aims to obtain maximum execution speed while preserving modularity and re-usability. The library presently includes: SRP authentication protocol, SHA2 hash functions, AES symmetric encryption and Fortuna PRNG. The developers plan to add support for elliptic [...]

PwdHash, from the Security Lab at Stanford University, is a browser extension - available for Internet Explorer, Firefox and Opera - that converts a user’s password into a domain-specific password. PwdHash reads any password fields in a web form and dynamically replaces them with unique strong passwords.
The unique password is auto-generated by combining the user-specified [...]

How to test your firewall

The firewall is our gateway to the Internet. It is a piece of software or hardware that manages Internet connections to and from your computer. It monitors the applications that try to initiate connection with your computer from the Internet, and it controls which programs are allowed to use the Internet.
Nowadays, Internet users are exposed [...]

FG-Injector is a free open source framework designed to help find SQL injection vulnerabilities in web applications. It includes a proxy feature for intercepting and modifying HTTP requests, and an interface for automating SQL injection exploitation.
It’s a common thought among web developers that by disabling error messages in their code, SQL injection vulnerabilities stop being [...]

Enforce Vista IE 7 Protected Mode

By default, Internet Explorer 7 in Windows Vista runs in Protected-Mode, which adds additional defenses to help enable a safer browsing experience for users. In Protected-Mode, Internet Explorer runs with reduced permissions to mitigate software vulnerabilities exploitation by eliminating the possibility to alter user or system files without user’s explicit permission.
While Protected-Mode is enabled by [...]

JavaScript malware protection for Firefox

JavaScript has recently turned from a web development tool into a hackers’ gateway to your home or corporate network. JavaScript malware is the common term used to summarize the new brand of JavaScript attacks that allow hackers to map your network and launch sophisticated phishing attacks. The malicious JavaScript code can be embedded in any [...]




Security-Hacks is a web site that covers tips and tricks for security. Updated several times daily, Security-Hacks points out tools downloads, how-to's and tutorials.

Contact


Have a hot hack? want to request a hack? let us know - editor [at] security-hacks.com

subscribe

Enter your Email

Archives

Add to Technorati Favorites

Categories