You won't believe you don't need to see those horrible ads on the web
Published:
This #1 trick ad companies don't want you to know!
Published:
This #1 trick ad companies don't want you to know!
Published:
I was reading the WebSub specification (formerly PubSubHubbub) when I found that there was a risk of reflected browser-side code injection (reflected cross site scripting, reflected XSS) in the WebSub intent verification exchange.
Friends don't let friends use $http_host
Published:
Two related authority-ambiguity vulnerabilities in NGINX and Debian's proxy_params configuration snippet.
Published:
Keycloak's UMA implementation seems tricky to me.
Published:
In a previous post, I described a pass-the-permission-ticket vulnerability in UMA 2.0 in which a malicious UMA resource server could kindly ask a UMA client to give it access tokens actually intended for another UMA resource server. In this post, I am describing a similar attack when the authorization server is malicious.
Published:
In the User-Managed Access (UMA) 2.0 protocol, a malicious resource server (or a malicious server acting as a resource server) can obtain a requesting party (access) token (RPT) intended for another UMA resource server from a UMA client by passing a permission ticket obtained from the target resource server to the UMA client. This can compromise the privacy (confidentiality) and integrity of UMA protected resources.
Published:
A sequence diagram for WebSub (formerly PubSubHubbub).
Trust no one
Published:
An interesting note from the FBI.
Published:
Some diagrams (mostly sequence diagrams) about UMA 2.0.
Published:
An interesting spoofing attack resulting from the interaction between Firefox (or Thunderbird) MIME types handling and file managers.
Page 1 of 3 | Previous page | Next page | JSON Feed | Atom Feed | RSS Feed