Ivan Fratric's Security Blog
Saturday, September 29, 2012
Of HTML5 security, cross-domain Math.random() prediction and Facebook JavaScript API
›
In an earlier post, I talked about a technique called Cross-domain Math.random() prediction . And while the technique is interesting it is ...
48 comments:
Sunday, August 26, 2012
My BlueHat Prize entry: ROPGuard - runtime prevention of return-oriented programming attacks
›
In my previous (brief) post I was very excited to announce that ROPGuard, a system for runtime prevention of return-oriented programming a...
9 comments:
Sunday, June 24, 2012
ROPGuard selected as one of the top three entries in Microsoft's BlueHat Prize contest
›
Earlier this year, I participated in Microsoft's BlueHat Prize contest - a contest to design a novel runtime mitigation technology des...
59 comments:
Thursday, June 14, 2012
Stored XSS in Google Sites
›
I was recently introduced to an interested project called Google Caja . Google Caja is basically a compiler/sandbox that makes user-supplie...
13 comments:
Thursday, May 31, 2012
Cross-domain Math.random() prediction
›
I recently descovered an interesting security issue in a web application that could be potentially exploited if an attacker could guess the...
535 comments:
Monday, March 12, 2012
Two Facebook vulnerabilities
›
A while ago I realized that it's been a long time since I wrote about the web application security here, so when Facebook announced thei...
14 comments:
Tuesday, February 28, 2012
Reliable Windows 7 Exploitation: A Case Study
›
Those of you that follow my blog know that I am not accustomed to publishing the exploit code for critical vulnerabilities. I'm only pub...
16 comments:
‹
›
Home
View web version