Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
davedd
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
15 ms
·
1.
▲
ChangeIP (dynamic DNS) being abused by malware
(labs.sucuri.net)
5 points
by
davedd
14y ago
|
0 comments
2.
▲
by
davedd
14y ago
Glad you liked :)
3.
▲
SFTP/FTP Password Exposure via sftp-config.json
(blog.sucuri.net)
2 points
by
davedd
14y ago
|
0 comments
4.
▲
More Fake jQuery sites
(labs.sucuri.net)
31 points
by
davedd
14y ago
|
12 comments
5.
▲
by
davedd
14y ago
Nope, we work with hosts that do exactly that. Patch and update if it is outdated, fix if it is broken and even remove any malware if it is infected. Again, what you guys are doing is great, and I don't want to take that way. My only point
6.
▲
by
davedd
14y ago
That's a good approach, but not novel and not the first host doing that. Many hosts automatically scan and fix their clients sites and have been doing that for a while. Specially when you are talking about popular CMSs like WorPress, Joomla
7.
▲
Out-of-date Software Affects Websites Big and Small
(blog.sucuri.net)
1 points
by
davedd
14y ago
|
0 comments
8.
▲
by
davedd
14y ago
Another issue we identified is that you can find those "hidden" admin panel or URLs that shouldn't be known to the outside, by just refreshing the page a few times and checking all requests. It is not a best practice, but some companies do
9.
▲
by
davedd
14y ago
Site is back up.
10.
▲
Popular sites with Apache server-status enabled (leaking internal details)
(blog.sucuri.net)
95 points
by
davedd
14y ago
|
46 comments
11.
▲
by
davedd
14y ago
Valid link: https://gudado.com/tools/freeemail.php It also has a simple/open API that anyone can use (being using that on our own sites). thanks,
12.
▲
Ask HN: Review quick tool to check if an email is disposable (one time)
5 points
by
davedd
14y ago
|
3 comments
13.
▲
Linode Newark datacenter down
(status.linode.com)
6 points
by
davedd
14y ago
|
0 comments
14.
▲
Crypto for Pentesters Video - Tom Ptacek - Spring 2012
(vimeo.com)
1 points
by
davedd
14y ago
|
0 comments
15.
▲
by
davedd
14y ago
Remote, Anywhere, anywhere PHP Developer: http://sucuri.net/company/employment " Sucuri is looking for a Senior PHP Developer with JavaScript & AJAX chops to join our team, and help us continue building the most polished and reliable
16.
▲
by
davedd
14y ago
A quick tool for end users to check if their emails were compromised: http://labs.sucuri.net/?yahooleak
17.
▲
Yahoo Leak - Check if your email was compromised
(labs.sucuri.net)
2 points
by
davedd
14y ago
|
0 comments
18.
▲
by
davedd
14y ago
We did an analysis of the dump: http://blog.sucuri.net/2012/07/analysis-of-yahoo-voice-passw... Interesting is the lack of "yahoo" as part of the passwords... I would expect a much higher % from a yahoo leak.
19.
▲
Analysis of Yahoo Voice Password Leak – 453,441 Passwords exposed
(blog.sucuri.net)
1 points
by
davedd
14y ago
|
0 comments
20.
▲
Plesk 0Day For Sale As Thousands of Sites Hacked
(krebsonsecurity.com)
3 points
by
davedd
14y ago
|
0 comments
21.
▲
Uploadify, Uploadify and Uploadify – The New TimThumb?
(blog.sucuri.net)
2 points
by
davedd
14y ago
|
0 comments
22.
▲
Google.com and malware (what attackers are doing to difficult detection)
(labs.sucuri.net)
1 points
by
davedd
14y ago
|
0 comments
23.
▲
.htaccess malware to MSN.com
(labs.sucuri.net)
1 points
by
davedd
14y ago
|
0 comments
24.
▲
by
davedd
14y ago
Remote. This position is remote and affords a semi-flexible working schedule. Job Position: Senior Security Support “Ninja” Analyst Description: As a Senior Analyst you will be responsible for: -Handling our most complex security cases (hac
25.
▲
List of domains hosting webshells for Timthumb attacks
(labs.sucuri.net)
1 points
by
davedd
14y ago
|
0 comments
26.
▲
by
davedd
14y ago
In terms of countries (based on the IP address of the spammer): #1 USA (30%) #2 China (20%) #3 Russia (6%) #4 Brazil (4%)
27.
▲
Blog Comments – Analysing 100,000 Comments and Spammers
(blog.sucuri.net)
7 points
by
davedd
14y ago
|
4 comments
28.
▲
by
davedd
14y ago
You would be surprised: http://www.shodanhq.com/search?q=PHP-CGI
29.
▲
by
davedd
14y ago
It prevents a user visiting those sites from getting compromised. However, the spread if this is via SQL injection, so as long as those sites are insecure, it will keep going..
30.
▲
Nikjju Mass SQL injection campaign (180k+ sites compromised)
(blog.sucuri.net)
7 points
by
davedd
14y ago
|
3 comments
More ›