CERT

Recently in Web Category

Reported Vulnerability in CERT Secure Coding Standards Website

Hi, it's Will. Recently, a blog author reported that the CERT® Secure Coding Standards website, which runs on Atlassian Confluence, contained a SQL injection vulnerability. After analyzing the report and discussing it with the Confluence vendor, we have concluded that the behavior described is not a vulnerability.


Continue reading Reported Vulnerability in CERT Secure Coding Standards Website

Carpet Bombing and Directory Poisoning

Hey, it's Will. Earlier this year, details about "carpet bombing" attacks were released. Apple addressed the issue by prompting users before downloading files, but recent news indicates that Google Chrome, which is based on Apple's WebKit code, is also vulnerable to the same type of attack. However, some people seem to be missing an aspect of the attack that affects all web browsers.


Continue reading Carpet Bombing and Directory Poisoning

ActiveX Vulnerability Discovery at the CERT/CC

Hi, it's Will. Anybody who has been keeping an eye on the US-CERT Vulnerability Notes has probably noticed that I've published a lot of ActiveX vulnerabilities. So it should be no surprise to learn that we have been testing ActiveX controls and discovering vulnerabilities in the process.


Continue reading ActiveX Vulnerability Discovery at the CERT/CC

Signed Java Applet Security: Worse than ActiveX?

Hi, it's Will again. ActiveX vulnerabilities seem to be getting a lot of attention lately. However, Java applets are also a concern.


Continue reading Signed Java Applet Security: Worse than ActiveX?

Is Your Adobe Flash Player Updated?

Hey, it's Will. As you may already be aware, there is active exploitation of a vulnerability in Adobe Flash. So, it's a good idea to make sure that you have the latest version of Flash Player, which, at the time of this writing, is 9.0.124.0. Even if you think that you are up to date, can you be sure?


Continue reading Is Your Adobe Flash Player Updated?

Who has my cookies?

Hi, Ryan Giobbi from the Vulnerability Analysis team making this post. The CERT/CC has been tracking cross-site scripting vulnerabilities for a long time, and the actual vulnerabilities haven't changed much over the years. However, some technology that was developed to make life easier can actually be exploited to expand the impact of a cross-site scripting attack.


Continue reading Who has my cookies?