Nov 29
When I was searching for a ticket in nationalrail.co.uk website, I suddenly found an XSS and also a SQL Injection vulnerabilities in it.
I reported these two vulns. to its website just for having more security. And, I think these two vulnerabilities are fixed now.
However, I believe that still 70% of webistes are vulnerable against the OWASP TOP 10!
Also, I think you should read “Survey: Majority of Web sites vulnerable” as well.
Cheers,
Soroush
Nov 29
3 weeks ago, I sent an email about some small but effective vulnerabilities in Travian online game to its providers. By using these vulnerabilities a player can make several accounts by the same email address (because of a logical flaw), and also, he/she can login to other players’ accounts (by using an XSS vulnerability which is completely proved).
Now, I’m still waiting for their final response as I don’t want to be harmful for them!
Nov 21
In only 3 pages, I tried to explain Phishing attacks and prevention methods. Although there are some books about this topic, I tried to do my best in 3 pages only! :D
I hope you enjoy :)
Click here to download this mini-article!
Cheers,
Soroush
Jan 31
I found some XSS vulnerabilities in my blog’s template, so I reported them to its creator (Inanis).
Thanks from Inanis because of fast fix and also for this beautiful template.
You can see these in this link:
http://www.inanis.net/blog/index.php/downloads/inanis-glass-wordpress-theme/inanis-glass-readme/