• Home
  • Disclosure Policy
  • About:Me
  • Imprint
Inshell.net
Security News | Inshell.net

Category Archives: Security News

Plesk <= 10.4.4 0day Exploit for sale

July 10, 2012 11:02 pm / Leave a Comment / MrTuxracer

According to a quite interesting blog post from Brian Krebs, there is currently a Plesk exploit sold (for around 8000$) on underground forums, with the capabilities of: Printing the Admin Password Remote Code Execution Read files from Server Be aware.

Posted in: Security News / Tagged: 0day, Remote Code Execution

The University of Salzburg refuses security reports

June 27, 2012 4:45 pm / 2 Comments / MrTuxracer
uni-salzburg

Have you read one of my last articles regarding webmasters ? The university of Salzburg didn’t or at least didn’t want to. In April I tried to contact the internal university IT staff about a possible Cross-Site Scripting security flaw on their main website, but got no answer (beside the auto-response from their helpdesk system). After … Read More →

Posted in: Security News, Vulnerabilities / Tagged: fail, Gulli, ignorance, XSS

China Software Developer Network (CSDN) leaked 6 Million user data

December 21, 2011 8:00 pm / Leave a Comment / MrTuxracer

CSDN, One of the biggest programming communities in China, leaked 6M user data. A text file with 6M CSDN user info: user name, password, emails, all in clear text, is hot on internet. You could easily get the download link (use xunlei to download the file) on google plus or twitter. NowChinese programmers are busy … Read More →

Posted in: Security News / Tagged: leak

Follow Me!

Follow Me on TwitterFollow Me on LinkedInFollow Me on Exploit-DBFollow Me on RSSFollow Me on E-mail

Links

Latest Tweets

RT @OSVDB: Dear $VENDOR, pro tip: vague legal threats to make us update an entry with inaccurate information don't play well. Sincerely, OSVDB
9 hours ago
RT @ndouba: Me: You have XSS vulnerabilities. $client: Fixed! Me: how? $client: we turned off XSS Me: ... #facepalm
13 hours ago
@tekwizz123 maybe...it's a feature: They've already cracked your pwd, and would like to tell you that...indirectly...;-)
20 hours ago
Why should I give #security vulnerability details to multi-million-$ vendors FOR FREE? Most of the times, I don't even get a "thank you".
20 hours ago
@tekwizz123 wtf?
20 hours ago

Blogroll

  • 1337core
  • carnal0wnage
  • cd1zz
  • Crilogs
  • FuzzySecurity
  • Gehaxelt
  • Internetwache
  • KrebsOnSecurity
  • Sicherheit-Online
  • TacticalCode
  • Will

Categories

  • Exploits (4)
  • Papers (2)
  • Playground (21)
  • Security News (3)
  • Site News (5)
  • Tools (1)
  • Tutorials (5)
  • Videos (1)
  • Vulnerabilities (36)

Archive

  • May 2013 (2)
  • April 2013 (1)
  • March 2013 (4)
  • February 2013 (3)
  • January 2013 (3)
  • December 2012 (1)
  • November 2012 (6)
  • October 2012 (1)
  • September 2012 (4)
  • August 2012 (2)
  • July 2012 (3)
  • June 2012 (5)
  • May 2012 (1)
  • April 2012 (4)
  • March 2012 (3)
  • February 2012 (4)
  • January 2012 (4)
  • December 2011 (7)
  • November 2011 (3)

Tag Cloud

0-day advisory buffer overflow bug bounty bypass call cloud DoS eip esp exam exploit hacking hackme IDA ignorance injection inshell lighttpd local Metasploit nmap nop NoSQL Off-Topic opcode PoC pop privileges escalation push python remote reporting ret SafeSEH shellcode SQLi sqlmap stack tool trunk vlan WinALL WPScan XSS
© Copyright 2012 - Inshell.net
Infinity Theme by DesignCoral / WordPress