Ivan Fratric's Security Blog

Saturday, September 29, 2012

Of HTML5 security, cross-domain Math.random() prediction and Facebook JavaScript API

›
In an earlier post, I talked about a technique called Cross-domain Math.random() prediction . And while the technique is interesting it is ...
48 comments:
Sunday, August 26, 2012

My BlueHat Prize entry: ROPGuard - runtime prevention of return-oriented programming attacks

›
In my previous (brief) post  I was very excited to announce that ROPGuard, a system for runtime prevention of return-oriented programming a...
9 comments:
Sunday, June 24, 2012

ROPGuard selected as one of the top three entries in Microsoft's BlueHat Prize contest

›
Earlier this year, I participated in Microsoft's BlueHat Prize contest - a contest to design a novel runtime mitigation technology des...
59 comments:
Thursday, June 14, 2012

Stored XSS in Google Sites

›
I was recently introduced to an interested project called Google Caja . Google Caja is basically a compiler/sandbox that makes user-supplie...
13 comments:
Thursday, May 31, 2012

Cross-domain Math.random() prediction

›
I recently descovered an interesting security issue in a web application that could be potentially exploited if an attacker could guess the...
535 comments:
Monday, March 12, 2012

Two Facebook vulnerabilities

›
A while ago I realized that it's been a long time since I wrote about the web application security here, so when Facebook announced thei...
14 comments:
Tuesday, February 28, 2012

Reliable Windows 7 Exploitation: A Case Study

›
Those of you that follow my blog know that I am not accustomed to publishing the exploit code for critical vulnerabilities. I'm only pub...
16 comments:
‹
›
Home
View web version
Powered by Blogger.