Now it’s time for the final phase where our panel of security experts vote on the list (same position point system) to determine the Top Ten Web Hacking Techniques of 2010. All those on the panel have substantial industry technical experience, domain knowledge in application security, and do not have entries on the list.
This year we’re very pleased to have:
Ed Skoudis (InGuardians Founder & Senior Security Consultant)
Giorgio Maone (Author of NoScript)
Caleb Sima (CEO, Armorize)
Chris Wysopal (Veracode Co-Founder & CTO)
Jeff Willams (OWASP Chairman & CEO, Aspect Security)
Charlie Miller (Consultant, Independent Security Evaluators)
Dan Kaminsky (Director of Pen-Testing, IOActive)
Steven Christey (Mitre)
Arian Evans (VP of Operations, WhiteHat Security)
Final Fifteen
- A Twitter DomXss, a wrong fix and something more
- Attacking HTTPS with Cache Injection
- Breaking into a WPA network with a webpage
- Bypassing CSRF protections with ClickJacking and HTTP Parameter Pollution
- CSS History Hack In Firefox Without JavaScript for Intranet Portscanning
- Cross Site URL Hijacking by using Error Object in Mozilla Firefox
- Evercookie
- HTTP POST DoS
- Hacking Auto-Complete (Safari v1, Safari v2 TabHack, Firefox, Internet Explorer)
- Java Applet DNS Rebinding
- JavaSnoop
- NAT Pinning: Penetrating routers and firewalls from a web page
- Next Generation Clickjacking
- 'Padding Oracle' Crypto Attack (poet, Padbuster, demo, ASP.NET)
- Universal XSS in IE8 (CVE, White Paper)
6 comments:
Link to Universal XSS in IE8 is broken
@anonymous it was working yesterday, for some reason they removed the files with no pointer. tried contacting the authors, but they haven't responded. any other working references would be much appreciated.
Jeremiah, here is the CVE link for universal XSS in IE.
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-1489
Nice work, I enjoyed this post and research.
Here is a better link for the Universal XSS ie8 technique: the google cache version of the original research.
I had to shorten it since blogger was rejecting some of the characters in the original URL.
http://bit.ly/fmSNzA
@Jim, thanks for the help!
The link for 'Universal XSS in IE8' is back in action!
Post a Comment