Welcome to KnowledgeCave - Network Security News
Search
_TOPICS
Home Your Account FAQ Topics Content Submit News Top 10
  Login/Create an Account    

KC Menu
· Home
· Downloads
· Forums
· KC Archive
· KC Disclaimer
· KC Members List
· KC Search
· KC Sorted Articles
· KC Staff
· KC Surveys
· KC Top 10
· KC Video archive
· KC Web Links
· Your Account
· Your Private Messages

KC OnLine Tools
· KCPenTrix 1.0
· KCPenTrix 2.0
· Speed test
· Whois
· Network Utils
· Ports List

Google Search
Google

Related links

KnowledgeCave - Network Security News: Security Tutorials

Search on This Topic:   
[ Go to Home | Select a New Topic ]

Security Tutorials: 2 Java Web Security WhitePapers
Security Tutorials
SecNiche Security released two whitepapers regarding Java Web Security Technologies

JNLP Security Convergence : Here

Hack Annotations in JWIG : Here

Posted by traxx on Thursday, July 26 @ 18:52:05 MST (3580 reads)
(Read More... | 772 comments | Security Tutorials | Score: 0)

Security Tutorials: BIND 9 DNS Cache Poisoning paper
Security Tutorials
New Amit Klein paper:

"The paper shows that BIND 9 DNS queries are predictable
A predictability algorithm is described that, in optimal conditions,
provides very few guesses for the "next" query (10 in the basic attack,
and 1 in the advanced attack), thereby overcoming whatever protection
offered by the transaction ID mechanism. This enables a much more
effective DNS cache poisoning than the currently known attacks against BIND 9..."

Read: Here

Posted by traxx on Thursday, July 26 @ 18:47:14 MST (1449 reads)
(Read More... | 128 comments | Security Tutorials | Score: 0)

Security Tutorials: XSS Tunneling White Paper and Tool
Security Tutorials
"XSS Tunneling is the tunneling of HTTP traffic through an opened XSS
Channel. Thus any application with HTTP proxy support can tunnel its
traffic through an XSS Channel (a channel opened by a tool like XSS
Shell).
White paper is explaining XSS Tunneling, benefits, real worlds examples
and basic usage of XSS Tunnel (a local HTTP proxy for tunneling) tool."

Homepage: Here

Posted by traxx on Wednesday, July 11 @ 16:34:09 MST (3685 reads)
(Read More... | 788 comments | Security Tutorials | Score: 5)

Security Tutorials: DNS pinning and web proxies paper
Security Tutorials
"DNS-based attacks against browsers have been known about for years. These
attacks have received increased attention recently, following the discovery
of defects within browser-based DNS pinning defences.
So far, discussion has focused on browser issues. However, the same attacks
can also be performed against web proxies. Browser-based DNS pinning does
not apply when a web proxy is being used, because the DNS look-ups occur on
the proxy, not the browser. Hence, even if DNS-based attacks are completely
addressed within browsers, the problem is not going to go away altogether."

Homepage: Here

Posted by traxx on Wednesday, July 11 @ 16:31:08 MST (3858 reads)
(Read More... | 777 comments | Security Tutorials | Score: 0)

Security Tutorials: Analysis of Ajax Based Load Tab Modules paper
Security Tutorials
"This analysis compose of the active module checking derived from AJAX
based applications.This vulnerability or bad programming practise
makes the web application vulnerable to XSS scripting and other
Javascript injections. "

Read: Here

Posted by traxx on Wednesday, June 13 @ 19:09:20 MST (857 reads)
(Read More... | 155 comments | Security Tutorials | Score: 0)

KC Categories
· All Categories
· Other
· Security News
· Security Tools
· Security Tutorials
· Weblinks

KC Video Archive
DNS Spoofing

By: traxx
On: 08th May 2007
Views: 1103
Rating: 0.00 Votes: 0

XP SP2 Buffer overflows exploitation

By: traxx
On: 08th May 2007
Views: 952
Rating: 0.00 Votes: 0

PHP backdoor + local root exploit

By: traxx
On: 08th May 2007
Views: 910
Rating: 0.00 Votes: 0

ActiveX bug in IE

By: traxx
On: 08th May 2007
Views: 774
Rating: 0.00 Votes: 0

MSF exploit builder

By: traxx
On: 08th May 2007
Views: 825
Rating: 0.00 Votes: 0

JPortal SQL injection

By: traxx
On: 08th May 2007
Views: 760
Rating: 0.00 Votes: 0

JSP Injection fast demo

By: traxx
On: 17th Jan 2007
Views: 880
Rating: 0.00 Votes: 0

Bluetooth Hack

By: traxx
On: 17th Jan 2007
Views: 990
Rating: 0.00 Votes: 0

PHP remote file inclusion

By: traxx
On: 17th Jan 2007
Views: 849
Rating: 0.00 Votes: 0

CRLF Injection

By: traxx
On: 17th Jan 2007
Views: 834
Rating: 0.00 Votes: 0

Privilege escalation with metasploit

By: traxx
On: 10th Nov 2006
Views: 816
Rating: 0.00 Votes: 0

Another MSF usage of RPC_DCOM

By: traxx
On: 10th Nov 2006
Views: 741
Rating: 0.00 Votes: 0

DeAUTH all WIFI station

By: traxx
On: 10th Nov 2006
Views: 759
Rating: 0.00 Votes: 0

Cracking WEP in 10 minutes

By: traxx
On: 10th Nov 2006
Views: 829
Rating: 0.00 Votes: 0

Tunelling Exploit thru ssh-dcom

By: traxx
On: 10th Nov 2006
Views: 672
Rating: 0.00 Votes: 0


KC Total Hits
We received
1316249
page views since February 2005

Security News
·News: Change in Focus
·News: Twitter attacker had proper credentials
·News: PhotoDNA scans images for child abuse
·News: Conficker data highlights infected networks
·Brief: Google offers bounty on browser bugs
·Brief: Cyberattacks from U.S. "greatest concern"
·Brief: Microsoft patches as fraudsters target IE flaw
·Brief: Attack on IE 0-day refined by researchers
·News: Monster botnet held 800,000 people's details
·News: Google: 'no timetable' on China talks

read more...

TheRegister Security Headlines
·MS probes mystery IE bug
·Symantec finally secures HackIsWack
·iPad scammers hack Kirstie Allsopp's Twitter
·Browser security warning lookalike pushes malware
·USB stick with anti-terror training found outside police station
·Google pays $8.5m to settle Buzz privacy invasion suit
·Nigerian man gets 12 years for $1.3m 419 scam
·Spammers latch onto Ping to pump iPhone survey scams
·Symantec Snoop Dogg rap contest site rickrolled
·Phone bugging scandal reignited as <em>NotW</em> suspends reporter

read more...

Tech News
·addict3d.org

read more...

Latest Downloads
1:Kcpentrix 2.0 submitted by fred
2:Wi-Fi Security: What Hackers Know That You Don't submitted by air defense
3:The whitepaper gives a detailed view of the current wireless threats and the working countermeasures submitted by Uniskill
4:One-way Web Hacking submitted by iNPUt-
5:wnikto submitted by iNPUt-

Donations

Support knowledgecave & KCPentrix Via Paypal



All logos and trademarks in this site are property of their respective owner. The comments are property of their posters, all the rest © 2005 by KnowledgeCave Crew.
Creation and development by Fredericofrazao.com
PHP-Nuke Copyright © 2004 by Francisco Burzi. This is free software, and you may redistribute it under the GPL. PHP-Nuke comes with absolutely no warranty, for details, see the license.
Page Generation: 0.72 Seconds