Ustream.tv Show Pwn

Hey look everyone, yet another demonstration of how cross-site scripting (XSS) can be used for evil. This time we find ourselves at ustream.tv and yet ... Continue Reading

CloudKick Takeover

This video demonstrates a flaw found in a large number of sites. It still makes me chuckle that the cloud is supposed to be this ... Continue Reading

Kayako SupportSuite

Here is a quick video demonstrating a fun cross-site scripting I found in Kayako SupportSuite. It shows an interesting side of XSS that scanners rarely ... Continue Reading

Rackspace Cloud

This video is a follow-on to the previous Rackspace cloud video on stealing Rackspace API keys using XSS.

In the Rackspace cloud when you ... Continue Reading

Rackspace

Ever wanted to know what somebody is hiding in their Rackspace cloud files account? The vulnerability that is demonstrated here is cross-site scripting (xss) due ... Continue Reading

Basecamp 0wn3d

So it's possible to compromise a Basecamp account when the victim, with a valid session, clicks on a link. I think this is a bad ... Continue Reading

Open-Realty Takeover

Open-Realty combined with a misconfigured web server provides for a really bad day if an agent goes rogue or if an agents account is compromised. ... Continue Reading

Does your web app need a security audit? YES. Get your security assessment here.

evilpacket is an awesome public service of nGenuity Information Services. Note: not actually evil.

Site by &yet Web Design