Statistics from 10,000 leaked Hotmail passwords

An anonymous user posted usernames and passwords for over 10,000 Windows Live Hotmail accounts to web site PasteBin. PasteBin is currently down for maintenance but I managed to get a copy of the list and quickly generated some statistics from these passwords. First, my impression…

Read more

Every website is a target; hacktivism

As stated in previous blog posts, hackers don’t just hack websites to steal online databases and credit card details.  Hacktivism, where innocent websites are defaced from malicious users to transmit their political view or opinion, is on the increase.  In many major world political events,…

Read more

New Invicti WVS 6.5 sets new standards in web vulnerability scanning

Unique Invicti WVS vulnerability checks save businesses time, money and embarrassment London 20th May 2009 – Invicti (www.acunetix.com), a pioneer in web application security scanning technology, has announced new ‘file upload forms vulnerability checks’ in version 6.5, an industry first and only Web Vulnerability Scanner…

Read more

Drupal Local File Inclusion Vulnerability

I was testing our scanner (with AcuSensor enabled) on Drupal (http://www.drupal.org) and the scanner found a possible File Inclusion vulnerability. As you can see from the screenshot above, the GET variable q was set to start/../../xxx….end and it got partially sanitized. It reached the include…

Read more