Archive for the ‘ Web Security ’ Category
Analysis of .jar attack from blackhole exploit pack.
Yesterday, one of my friend received a legitimate looking email from Internal Revenue Service with subject: Your Federal Tax Payment with a link to tax report.pdf file. He reported it to me and I got a chance to analyze it. Below are some of my findings from the analysis. The link had below obfuscated javascript in [...]
Outburst of HDFC and IDBI bank phishing emails
For past few days, I was getting fraud emails impersonating HDFC and IDBI banks. Emails looked pretty legitimate unless you looked into the email headers or actually visited the link provided in them. Below are some screen shots of the emails that I received. You may also see some superficial investigation I underwent to make [...]
Yet another information disclosure vulnerability in Internet explorer.
IE Aurora‘s dust was not even settled in our minds and yet another critical vulnerability in IE has emerged with a bang !! A Security Consultant from CORE Security Technologies, Mr.Jorge Luis Alvarez Medina discussed a vulnerability in BlackHat DC 10 conference. His presentation demonstrated a Proof of Concept code which exploits this vulnerability and allows [...]
URL shortening: Social engineering attack vector
URL shortening is a technique in the World Wide Web wherein a provider makes a web page available under a very short URL in addition to the original address. For example, the page http://blog.chackraview.net/2010/01/19/operation-aurora/ can be shortened to http://bit.ly/5RJICq As web clients tends to pass more and more data in the URL to communicate with [...]
Decode: eval_gzinflate_base64_decode
If you follow my posts….sometime back i wrote about the my encounter with web attacks which was amazing experience. I am lazy kinda person and with all this IPL fever these days, I don’t even think of blogging or doing personal research. So what made me sit and write today? The answer is, my same [...]
My Encounter with Live Web Attack
It will not be an average day, I knew from the dawn, as EOD I will be on my way to Pune. You might think whats so special about visiting pune? Let me tell you, people who have spent at least a year or two in city like Pune or Bangalore will hate to stay [...]
