‏إظهار الرسائل ذات التسميات Cross-site request forgery. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Cross-site request forgery. إظهار كافة الرسائل

الاثنين، 4 أبريل 2016

Microsoft Pays $13,000 to Hacker for Finding Authentication Flaw





A security researcher has won $13,000 bounty from Microsoft for finding a critical flaw in its main authentication system that could allow hackers to gain access to a user's Outlook, Azure and Office accounts.



The vulnerability has been uncovered by UK-based security consultant Jack Whitton and is similar to Microsoft's OAuth CSRF (Cross-Site Request Forgery) in Live.com discovered by

الخميس، 2 أبريل 2015

How Hackers Could Delete Any YouTube Video With Just One Click

A security researcher has discovered a simple but critical vulnerability in Google-owned YouTube that could be exploited by anyone to knock down the whole business of the popular video sharing website.
Kamil Hismatullin, a Russian security bod, found a simple logical vulnerability that allowed him to delete any video from YouTube in one shot.
While looking for Cross-Site Scripting (XSS) or

الأربعاء، 11 مارس 2015

Hacking Facebook Account with 'Reconnect' Tool





"Signup or Login with Facebook" ?? You might think twice before doing that next time. A security researcher has discovered a critical flaw that allows hackers take over Facebook accounts on websites that leverage 'Login with Facebook' feature.



The vulnerability doesn't grant hackers access to your actual Facebook password, but it does allow them to access your accounts using Facebook