January 2004 - Posts

0
Comments

Cross Site scripting on ebay selling auctions by preishuber

Some news papers and televison stations in germany showed today how to fake the seller information which are shown on the article description page. The trick is to include a jscript in the article description which overwrites the outputed HTML. This is...
9
Comments

the end of my blog? by preishuber

I have posted two security exploits about web application leaks. You cant see it because they are deleted. The owner of the exploits was not intressed that others know how easy it is to hack their web pages. i understand this! I am shure that other guys...
12
Comments

Another Web Hack by preishuber

During my writing a PPT doc for my new security speech i try severaly varaints of well known issues. My todays topic is cross site scripting and effects nobody have in mind. It is based on the community starter kit and also in other community websites...
0
Comments

Datagrid & HTTP harvesting by preishuber

Every one trys to protect their data. Do not use sa user, use stored procedures and so on. But many websites create their own public usable TSQL like query language. Think about a list with ASP.NET datagrid including a link to details page. Look like...
4
Comments

Free visual tool for administration of sql based servers by preishuber

After we have supported the asp.net community with the free asp.net based web log analyzer we proudly announce another helpfull tool for the web developer. On problem of the free "SQL Server light" MSDE is the missing management interface. Now you can...
3
Comments

2 ASP.NET Security speeches by preishuber

On of my hobbys is to login into webpages with username % and password %. This works in 50 % of all ASP pages! Dont ask me which- you wouldnt believe it! On invitation of microsoft sitzerland i will make two talks about ASP .NET Security in german www...
More Posts