Microsoft Patch Tuesday, July 2013 - CRITICAL

July 09, 2013 | Space Rogue

This is probably one of the most important Patch Tuesday's we have seen in ...

ModSecurity Advanced Topic of the Week: Detecting Banking Trojan Page Modifications

July 09, 2013 | Admin

The following blog post is taken from Recipe 10-5: Detecting Banking Trojan ...

SpiderLabs Radio July 5, 2013 w/ Space Rogue

July 06, 2013 | Admin

This week's episode of SpiderLabs Radio hosted by Space Rogue is brought to you ...

Custom Native Library Loader for Android

July 05, 2013 | Mike Park

If you read my co-worker Neal Hindocha's recent post "Debugging Android ...

Microsoft Advance Notification for July 2013 – BOOM!

July 05, 2013 | Space Rogue

While you were stuffing your face with hotdogs and potato salad and then ...

Look What I Found: It's a Pony!

July 01, 2013 | Anat (Fox) Davidi

Every once in a while we get to peek into the lion's den, this time we'll be ...

Corporate Passwords Part 1

June 28, 2013 | Admin

With the vast amount of research and content that was done by SpiderLabs for ...

A Friday Afternoon Troubleshooting Ruby OpenSSL... it's a trap!

June 28, 2013 | Jonathan Claudius

Last Friday I was trying out some new code that one of my colleagues wrote to ...

Fake Qantas Spam Campaign Leads to Andromeda Bot Infection

June 26, 2013 | Admin

If you have booked a flight from Qantas recently, you might be expecting a ...

Digging Into the New Apache Injection Module

June 26, 2013 | Josh Grunzweig

I recently got a chance to dig into a couple variants of the new Apache ...

Exploiting Serialized XSS in Joomla! (return of the undead CVE)

June 26, 2013 | Robert Rowley

While reviewing Joomla! Vulnerabilities I felt a glitch in the matrix. Deja vu ...

Old Exploits Still Do the Trick

June 24, 2013 | Daniel Chechik

We are all aware that patching is very important. Many websites, however, take ...

Welcome to the Spider’s Lair

June 24, 2013 | Admin

"Will you step into my parlor?" said the spider to the fly; "'Tis the prettiest ...

Debugging Android Libraries using IDA

June 22, 2013 | Neal Hindocha

During a recent test, I encountered a native JNI library used by an Android ...

SpiderLabs Radio June 21, 2013 w/ Space Rogue

June 21, 2013 | Admin

This weeks episode of SpiderLabs Radio hosted by Space Rogue is brought to you ...

Wendel's Small Hacking Tricks - Microsoft SQL Server Edition

June 20, 2013 | Wendel Guglielmetti Henrique

Since 2003 a large part of my workday has been devoted solely to hacking ...

CBC-R: It's not just for padding oracles!

June 20, 2013 | Admin

This is the short, technical version of a technique that I'll be writing more ...

[Honeypot Alert] Inside the Attacker's Toolbox: Webshell Usage Logging

June 19, 2013 | Ryan Barnett

In a previous blog post, we discussed the common lifecycle of web server botnet ...

Discovering BMW Car Systems: Getting Started

June 17, 2013 | Bruno Oliveira

Since I love both (in)security and cars, it is not uncommon for me to mix those ...

Sometimes, The PenTest Gods Shine On You

June 14, 2013 | Nathan Drier

Settling down for a hacking session usually means lots of hard work and a long ...

SpiderLabs Radio June 14, 2013 w/ Space Rogue

June 14, 2013 | Admin

This week's episode of SpiderLabs Radio hosted by Space Rogue is brought to you ...

TWSL2013-006: Cross-Site Scripting Vulnerability in Coldbox

June 11, 2013 | Robert Foggia

Trustwave SpiderLabs has published a new advisory yesterday fora reflective ...

TWSL2013-007: Multiple Vulnerabilities in VLC Media Player - Web Interface

June 11, 2013 | Admin

Yesterday, Trustwave SpiderLabs has published an advisory for multiple ...

Microsoft Patch Tuesday, June 2013

June 11, 2013 | Admin

Finally, patch Tuesday has arrived and fortunately this one will be a real ...

Behind the Phish: Romance Perhaps?

June 10, 2013 | Phil Hay

When I look at the masses of spam we receive on a daily basis, I often wonder ...

[Honeypot Alert] Active Exploits Attempts for Plesk Vulnerability

June 10, 2013 | Ryan Barnett

Last week, hacker "kingcope" provided PoC expliot code for a Plesk 0-day on the ...

SpiderLabs Radio June 7, 2013 w/ Space Rogue

June 07, 2013 | Admin

This week's episode of SpiderLabs Radio hosted by Space Rogue is brought to you ...

ModSecurity Updates: Nginx Stable Release and Google Summer of Code Participation

June 06, 2013 | Ryan Barnett

Availability of ModSecurity 2.7.4: Nginx Stable Release The ModSecurity ...