Microsoft Anti-Cross Site Scripting Library V3.0 Beta More about

Posted on Monday, December 15, 2008 @ 14:23:44 CST in Tool and Utilities
by Raven

NB1 writes:  
The Microsoft Anti-Cross Site Scripting Library V3.0 (Anti-XSS V3.0) is an encoding library designed to help developers protect their ASP.NET web-based applications from XSS attacks.

It differs from most encoding libraries in that it uses the white-listing technique -- sometimes referred to as the principle of inclusions -- to provide protection against XSS attacks. This approach works by first defining a valid or allowable set of characters, and encodes anything outside this set (invalid characters or potential attacks). The white-listing approach provides several advantages over other encoding schemes. New features in this version of the Microsoft Anti-Cross Site Scripting Library include: - An expanded white list that supports more languages - Performance improvements - Performance data sheets (in the online help) - Support for Shift_JIS encoding for mobile browsers - A sample application - Security Runtime Engine (SRE) HTTP module


Download  Microsoft Anti-Cross Site Scripting Library V3.0 Beta
 

 

RoundCube Webmail *bin/html2text.php* PHP Code Execution More about Read More...

Posted on Monday, December 15, 2008 @ 11:40:01 CST in Security
by Raven

SECUNIA ADVISORY ID: SA33169
VERIFY ADVISORY: http://secunia.com/advisories/33169/
CRITICAL: Highly critical
IMPACT: System access
SOFTWARE: RoundCube Webmail 0.x - http://secunia.com/advisories/product/19066/
DESCRIPTION: A vulnerability has been discovered in RoundCube Webmail, which can be exploited by malicious people to compromise a vulnerable system. The vulnerability is confirmed in version 0.2-beta.
 Read More...
 

 

Many modules for you: see the many mods and get more code now! More about

Posted on Sunday, December 14, 2008 @ 15:32:00 CST in Add-Ons
by Raven

nukeevangelist writes:  
 

 

Backup_Restore Utility More about

Posted on Friday, December 12, 2008 @ 09:54:11 CST in MySQL
by Raven

papamike writes:  
Some of you may know me for the themes I build but my career went way further than that. I'm a retired Network Engineer who for 33 years worked in just about every area of a computer center that you can thnk of. But I'm not here to talk about me, I'm here to pass along to you the information I gathered while I conducted a test of the Backup_Restore utility that I released just for RavenNuke(tm) that's used to backup and if needed to restore your sql tables and data information.

This week started out just like every other one. I'm an invalid suffering from a variety of medical conditions so I sit in my chair everyday and create things on my computer. I got this crazy idea that I wanted to test the Backup_Restore utility that I had worked on and released a couple of weeks back. So to satisfy my craving I decided to conduct a realtime intrusion/forced entry attack on my root account which has 7 SQL databases. The reason I did this was to test my Backup_Restore utility under actual conditions where the entire SQL is compromised and deleted.

Before I started I backed up all of the databases just the same way I do everyday using the Backup_Restore utility that I designed and modified for RavenNuke(tm). Next I entered my root account (simulated hack attack) and deleted the entire SQL installation. This effectively wiped out all of my databases.

I started to recover right away.
- I changed the root username and password
- Reinstalled MySQL.
- Used phpMyAdmin to recreate the databases, usernames and passwords
- Edited the Backup_Restore config file for each site by adding the new Db info I created earlier and uploaded them to each domain directory using FTP.
- Uploaded and installed the database tables and data.

Everything went smoothly and I was back online with no errors in just a few minutes. This was the ultimate method I could think of to fully test my Backup_Restore.utility and it passed with flying colors.

I am now working on a new release which will work even better than this first release.

I did discover an error a couple of days later that I will need to address in the next stable release. When you install your database using Backup_Restore you must make sure that all tables in your database are dropped. This is easy to do using phpMyAdmin. If you don't drop the tables and data the BigDump restore utility will render an error message and stop.

I think that everyone should get a copy of my utility and use it to backup your databases daily. It only takes a few seconds to run the backup utility and have the data e-mailed to you. Visit me at http://www.papamikecreations.net to get your copy today.

Thanks and Happy Holidays to everyone
 

 

Windows Services Optimizer More about

Posted on Thursday, December 11, 2008 @ 23:03:55 CST in Downloads
by Raven

Southern writes:  
Disabling unnecessary Windows services can result in significant performance gains for production machines and virtual machines. This script helps you manage and share templates for services optimization.

read more and d/l: DesktopEngineer
 

 

Microsoft Internet Explorer Multiple Vulnerabilities More about Read More...

Posted on Wednesday, December 10, 2008 @ 22:17:10 CST in Security
by Raven

SECUNIA ADVISORY ID: SA33035
VERIFY ADVISORY: http://secunia.com/advisories/33035/
CRITICAL: Highly critical
IMPACT: System access
SOFTWARE:
Microsoft Internet Explorer 5.01 - http://secunia.com/advisories/product/9/
Microsoft Internet Explorer 6.x - http://secunia.com/advisories/product/11/
Microsoft Internet Explorer 7.x - http://secunia.com/advisories/product/12366/

DESCRIPTION: Some vulnerabilities have been reported in Microsoft Internet Explorer, which can be exploited by malicious people to compromise a user's system. Successful exploitation of the vulnerabilities may allow execution of arbitrary code.
 Read More...
 



Page 96 of 659 (3950 total stories) [ << | < | 91 | 92 | 93 | 94 | 95 | 96 | 97 | 98 | 99 | 100 | 101 | > | >> ]  

News ©

Site Info

Last SeenLast Seen
  • vashd1
  • neralex
Server TrafficServer Traffic
  • Total: 513,431,921
  • Today: 24,753
Server InfoServer Info
  • Apr 25, 2025
  • 03:44 am CDT