Archive: November 2009

  • Shockwave Vulnerability Directs Users to Malicious Websites

    Researchers at VUPEN have discovered four major vulnerabilities and one minor in the Adobe Shockwave Player. The vulnerabilities are present in version 11.5.1.601 and those predating it. Adobe Shockwave is installed on over 450 million client systems world-wide. The most problematic of the vulnerabilities can be exploited to execute arbitrary commands when a visitor views [...]

  • New Security Issues come to light with SSL 3.0

    New SSL Security Issues: A vulnerability allowing hijacking of an already connected SSL 3.0 (TLS 1.0) sessions has been disclosed. SSL technology provides an end-to-end secure communications tunnel used most commonly by the HTTPS protocol. This, most recent, vulnerability allows an attacker to insert text of their choice into the data-stream, even after the secure [...]

  • HTTP and HTTPS

    A lot of times, people confuse HTTP and HTTPS. This is primarily because of the lack of understanding of a simple encryption based security mechanism that nearly all browsers can work with. HTTP is the protocol according to which your web browser transfers data to and from any web server, a computer that throws web [...]