Yesterday a reader of ours forwarded two phishing emails. The first email was a paypal phishing email, but the links in it were offline so we concentrated on the second one. This second email looked like it was from linked-in.
Pwning a paypal phishing site
Recently, a colleague sent us a link to a paypal phishing site. After we had a look at the website, we started a “counter-attack”.
Jochen Schweizer fixed security issues
Most people surly have heard about Jochen Schweitzer adventure trips. Like every other big company Jochen Schweizer has a homepage which also serves as an online shop for their products.
Zeit.de fixes some security issues
We were able to deternin a couple of XSS vulnerabilities on the website of a well known german newspaper (Die Zeit). The security issue would have allowed hackers to alter the the design of the webpage or manipulate the systeme routines.
Multiple XSS vulnerabilites fixed in a City-CMS
The STERNBERG Software-Technik GmbH from Bielefeld (Germany) is producing Content Managment Systems for cities and alike.
TeleTrust sidesteps a local file inclusion
“TeleTrust” is an it-security association in germany, which describes itself as a network for people from the industry, management and science. We discovered there a very low-hanging security issue.
Heise fixes XSS vulnerabilities
Heise.de is one of the biggest technology-news-portals, which started back in 1996. Since then a lot of things have changed. For example heise.de now has different categories for every topic. In short terms: all nerds, geeks, technology-affine people cannot miss Heises’ news reports if they want to on top of newest technology news. However, a such a big portal can sometimes be vulnerable, too.
Handelsblatt fixes multiple security issues
The “Handelsblatt” is one of the biggest daily newspaper in germany. With over 20,000 prints every day it enjoys a broad popularity offline as well as online, whereat the internet is getting more important. That’s why we took a closer look at the website.
Greenpeace fixes SQL Injection
Since we think that the responsible usage of resources and the protection of nature are important facts, we sympathize with organizations like greenpeace. That’s why we had a look at greenpeace’s website.
Focus fixes a SQL Injection vulnerability
Our very first case (06.06.2012) was about a vulnerability on the website of the german magazine “Focus”.