Remove http referrer bookmarklet and Safari5 extension
Let's go through the creation of a bookmarklet that removes the http referrers from all links in a page. This has been tested in Safari and Firefox.
Bypassing Safari 5 XSS Auditor
Safari 5 was released today and following IE8's move they decided to implement what they call XSS Auditor.
DirBuster Dictionary Populator
Dirbuster and dirb are in the toolset of all web application security fans. Both tools are excellent (although I prefer dirb due to it being command line and not Java), but their results obviously depends on how good the wordlist you are using is.
Parliament.gr blocks search engines?
I sometimes surf while using the Googlebot user-agent and often forget to switch back to the default Firefox user-agent.
iPhone applications that transmit credentials using “unsafe” protocols
The iPhone SDK allowed for the creation of thousands of applications. However, some of these applications (probably more than I would like to admit), have not been coded with security in mind.
How to stop Google Analytics
Yes I know google owns us, yes I know we are using analytics as well.
What you need:
- a web server
- place the two files in this file in the root of the web server
- edit your hosts file and add this entry (where xxx.xxx.xxx.xxx is the IP of your web server):
xxx.xxx.xxx.xxx www.google-analytics.com ssl.google-analytics.com
Now every time you visit an analytics-enabled page, the two files from your web server will be included, and all javascript will be executed properly, but google will not track you.
Show hidden fields bookmarklet
Just a quick useful bookmarklet, that shows all the hidden fields in a page.
Just bookmark this:
Show hidden
Converting an exe file to vbs and back to exe
It is often useful to be able to convert an exe file to a string which will be able to reproduce the exe file. This can be used in a variety of ways (send by email, from an SQL injection, etc.).
Windows simple backdooring
I remember reading this ages ago, and a couple of weeks ago I decided to give it a try.
I was amazed to see not only that this works, but that it even works on Windows7. Granted you do need some extra steps to make this happen in the later.
MacOSX Sandboxes
MacOSX Snow Leopard implements a sandbox facility.
According to the sandbox manpage:
The sandbox facility allows applications to voluntarily restrict their access to operating system resources. This safety mechanism is intended to limit potential damage in the event that a vulnerability is exploited. It is not a replacement for other operating system access controls.



