Spam in combination with phishing and exploiting

Yesterday a reader of ours forwarded two phishing emails. The first email was a paypal phishing email, but the links in it were offline so we concentrated on the second one. This second email looked like it was from linked-in.

Pwning a paypal phishing site

Recently, a colleague sent us a link to a paypal phishing site. After we had a look at the website, we started a “counter-attack”.

Jochen Schweizer fixed security issues

Most people surly have heard about Jochen Schweitzer adventure trips. Like every other big company Jochen Schweizer has a homepage which also serves as an online shop for their products.

Zeit.de fixes some security issues

We were able to deternin a couple of XSS vulnerabilities on the website of a well known german newspaper (Die Zeit). The security issue would have allowed hackers to alter the the design of the webpage or manipulate the systeme routines.

TeleTrust sidesteps a local file inclusion

“TeleTrust” is an it-security association in germany, which describes itself as a network for people from the industry, management and science. We discovered there a very low-hanging security issue.

Heise fixes XSS vulnerabilities

Heise.de is one of the biggest technology-news-portals, which started back in 1996. Since then a lot of things have changed. For example heise.de now has different categories for every topic. In short terms: all nerds, geeks, technology-affine people cannot miss Heises’ news reports if they want to on top of newest technology news. However, a such a big portal can sometimes be vulnerable, too.

Handelsblatt fixes multiple security issues

The “Handelsblatt” is one of the biggest daily newspaper in germany. With over 20,000 prints every day it enjoys a broad popularity offline as well as online, whereat the internet is getting more important. That’s why we took a closer look at the website.

Greenpeace fixes SQL Injection

Since we think that the responsible usage of resources and the protection of nature are important facts, we sympathize with organizations like greenpeace. That’s why we had a look at greenpeace’s website.