Last 50 'Demo' Tagged Posts

NIST publishes 50kish vulnerable code samples in Java/C/C++, is officially krad

NIST has published a fantastic project (its been out since late December, but I only just became aware of it) where they've created vulnerable code test cases for much of MITRE's CWE project in Java and c/c++. From the README "This archive contains test cases intended for use by organizations and individuals...

There is no Data, there is only XUL: Using XUL to spoof a web browser and next generation UIML phishing attacks

The following outlines how to utilize XUL applications to 'spoof' an entire firefox/mozilla window. This allows one to phish people across all domains simply by visiting any webpage where popups and JavaScript is allowed to execute. This is merely a demonstration on how to fool people with UIML's. I started poking around...