Application Security this Week for August 19

by Bill Sempf 19. August 2018 09:24

Trend Micro found a really interesting use-after-free vulnerability in the VBScript engine in IE.  Now, before you giggle, think of all of the companies that have standardized on IE. They are out there. Either way, the finding is cool.


Username enumeration bug discovered in OpenSSH of all things.


Ever seen a scanner point out that a site is vulnerable to DNS Rebinding, and wonder what the heck it was talking about?  Yeah me too.  These folks wrote up a framework for it.


Here is a password list sorted by probability. Remember that training course when I said you should check your new passwords against a list of known bad values, because NIST said to? Here ya go. The esteemed Jim Fenton recommends checking against the first 100,000. Neat project.


Comments are closed

Husband. Father. Pentester. Secure software composer. Brewer. Lockpicker. Ninja. Insurrectionist. Lumberjack. All words that have been used to describe me recently. I help people write more secure software.

Find me on Mastodon

profile for Bill Sempf on Stack Exchange, a network of free, community-driven Q&A sites