morph3us.org

Entries tagged as news

Quicksearch

Categories

Syndication

Blogroll

Tagged entries

Entries tagged as news

Serendipity 1.2

  (Sunday, August 26. 2007)
The Serendipity team released the final version of Serendipity 1.2 today. I just upgraded to 1.2 and everything went as smooth and easy as usual.

The Serendipity Team is proud to present the final release and immediate availability of Serendipity 1.2.

This release is a feature consolidation release and focuses on small usability improvements, a shiny new template (bulletproof) as well as backend templating and backend login mechanisms as well as some tighter security restrictions.

Some more changes in depth are:
[...]

Serendipity blog: Serendipity 1.2 released
Comments (0) | Trackbacks (0)

Blog and Website update

  (Tuesday, August 7. 2007)
As you may already noticed I published two new advisories (Winamp 5.35 (Infinite) M3U File Inclusion Stack Overflow Exception respectively DoS Vulnerability in Konqueror 3.5.7) and replaced Wordpress with a good[TM] weblog software named Serendipity.

Actually, I wanted to replace Wordpress since the beginning of this year (I'll explain the reasons for this decision in another blog posting) but I did not have enough time (and at least mind to) convert my customized Wordpress theme into a Serendipity theme until now.


Continue reading this entry..
Comments (2) | Trackbacks (0)

New advisories..

  (Wednesday, April 5. 2006)
Unfortunately, my last blog entry was almost three weeks ago so it's time for a new entry..

Presumably, I'm going to release several new advisories next week. Two advisories will cover multiple stack based overflows in W3C's browser Amaya, three advisories are about DoS vulnerabilities in the latest release of Internet Explorer 6 SP2 with all patches applied and another advisory will deal with multiple vulnerabilities in a rather unknown web application - but I'm not sure yet if I'll publish this advisory this time.

So stay tuned..
Comments (0) | Trackbacks (0)

BuHa ExploitMe Contest

  (Tuesday, March 7. 2006)
The BuHa ExploitMe Contest is organized in multiple levels with increasing difficulty. In each of this levels you'll find a exploitable ANSI C program and a small advice about the kind of shellcode which should be used. The first and the second level do not require the usage of any shellcode because people which are not familar with security related bugs in C programs should be able to complete them too.

The contest started almost a week ago and until now there are 19 different participants. I was surprised about three brazilian guys which also take part in the contest and found the contest site with Google.

Check it out: https://www.buha.info/projects/exploitme-contest/

Comment (1) | Trackbacks (0)

New design for site and blog

  (Tuesday, February 21. 2006)
The last week I created a new layout for my site and my blog. I used valid XHTML 1.1 Strict and CSS 2 to realize the design which is based on modern CSS layout techniques. The smart use of CSS and in general the separation between code and layout was very important for me.. The layout should look fine in all latest browsers like Firefox 1.x+, Opera 7.x+ and M$ IE 5.x+ which support the CSS 1 (and partly CSS2) standard.

I adapted (almost) the entire default template of Wordpress to my ideas and requirements. The CSS file of the default style sucks because it's pretty huge and I reduced its size by nearly 50 percent but my current stylesheet file is anything but perfect. There are still a lot of things to improve.. maybe I will provide a minimal Wordpress template for interested people in the near future.

Comments (10) | Trackbacks (0)

MS05-054 - 905915

  (Thursday, December 22. 2005)
M$ released Security Bulletin MS05-054 which resolves several newly-discovered vulnerabilities in M$ IE.
See File Download Dialog Box Manipulation Vulnerability (CAN-2005-2829), HTTPS Proxy Vulnerability (CAN-2005-2830), COM Object Instantiation Memory Corruption Vulnerability (CAN-2005-2831) and Mismatched Document Object Model Objects Memory Corruption Vulnerability (CAN-2005-1790) for details.

I updated the update pack for Windoze XP SP2..
Comments (0) | Trackbacks (0)

MS05-053 - 896424

  (Friday, November 11. 2005)
M$ released the Bulletin MS05-053 to resolve some latley discovered vulnerabilities in the rendering of Windows Metafile (WMF) and Windows Metafile (WMF) image format. See CAN-2005-2123, CAN-2005-2124 and EMF file DOS vulnerability for details.

Therefore I updated the update pack for Windoze XP SP2..
Comments (0) | Trackbacks (0)

Links about Web Application Security

  (Friday, November 11. 2005)
A while ago I uploaded a XHTML document containing several viable resources about Web Application Security from my bookmarks. I think most links will be usefull for people who are interested in web application security related topics.

Have a look..

http://morph3us.org/security/links/web-app-security.html
Comments (0) | Trackbacks (0)

Jetzt hat es mich auch erwischt ...

  (Wednesday, October 5. 2005)
Ich habe mich mittlerweile relativ kurzfristig dazu entschlossen einen eigenen Blog zu fuehren. Eigentlich halte ich ja nicht besonders viel vom sogenannten 'Blogging' aber andererseits kann es auch nicht schaden es einfach mal zu versuchen. Ausschlaggebend fuer meinen Entschluss damit anzufangen war uebrigens Dominik (siehe Blogroll) der kleine Rotzluemmel. (o: Jegliche Beschwerden bitte an ihn. *g

Eventuell kann ich cyrus-tc noch davon ueberzeugen hier auch den ein oder anderen Eintrag zu verfassen - auch wenn er sich derzeit noch etwas davor straeubt.

Comments (0) | Trackbacks (0)
(Page 1 of 1, totaling 9 entries)