CGISecurity Logo
  • New Silicon Valley security conference – BayThreat

    A handful of people from silicon valley (myself included) have been discussing the lack of good hacker conference in the bay area (RSA does not count) for some time and decided to meet up during defcon to see what  we could do about this.  It was concluded that the only logical thing to do, was…

  • Phrack #67 is out for 25th anniversary!

    To celebrate 25 years the phrack team has published issue #67. Introduction    The Phrack Staff Phrack Prophile on Punk    The Phrack Staff Phrack World News    EL ZILCHO Loopback (is back)    The Phrack Staff How to make it in Prison    TAp Kernel instrumentation using kprobes    ElfMaster ProFTPD with mod_sql pre-authentication, remote root    FelineMenace The House Of…

  • Interesting IE leak via window.onerror

    Chris Evans has posted an interesting bug in IE involving using JavaScript's window.onerror to leak cross domain data. From his blog "The bug is pretty simple: IE supports a window.onerror callback which fires whenever a Javascript parse or runtime error occurs. Trouble is, it fires even if www.evil.com registers its own window.onerror handler and then…

  • Palin e-mail snoop sentenced to a year in custody

    "Former college student David Kernell, whose criminal prying into Sarah Palin's personal e-mail account caused an uproar two months before the 2008 presidential election, was today sentenced to a year and a day in federal custody by a judge who recommended that the time be served in a Knoxville, Tenn. halfway house. Corrections officials could…