Sponsored White Papers, Webcasts, and Downloads
ZDNet Dictionary Definition
- Exploit
- In computer security, an unethical or illegal attack that takes advantage of some vulnerability. See zero-day exploit and PoC exploit.
- Full Exploit Definition >>
ZDNet Resources
- Cybercriminals release Christmas themed web malware exploitation kit
- "Committing cybercrime around the Christmas tree" has always been a tradition for malicious attackers introducing new ways to scam the millions of online shoppers during the holidays. This Christmas isn't going to be an exception, but what has changed compared last couple of years is the tone of the Xmas...
- Tags: Web, Infection, Malware, Exploit, Christmas, Web Malware Exploitation Kit, Exploitation Kit, Security, Dancho Danchev
- Blog posts 2008-11-24
- Black market for zero day vulnerabilities still thriving
- Black market for zero day vulnerabilities still thrivingWhy shouldn't everyone want to make illegal...... the writing and publication of exploits? For any expressed purpose.How long will the idea of goading the software companies prevent people from realizing that the difference between a malign and supposedly useful exploit is the...
- Tags: Black Market, day vulnerability, Canadian Law, exploit
- Discussion threads 2008-11-03
- Black market for zero day vulnerabilities still thriving
- One would assume that popular sources for zero day vulnerabilities+Poc's such as Full-Disclosure, Bugtraq or Milw0rm are the primary sources for obtaining responsibly or irresponsibly released flaws. They'd be wrong. The black market for zero day vulnerabilities and the concept of over-the-counter OTC trade of zero day flaws, has been...
- Tags: Web, Vulnerability, Web Application, SQL Injection, Exploit, Day Vulnerability, E-shop, Security, Dancho Danchev
- Blog posts 2008-11-02
- Exploit published for Windows worm hole
- Exploit published for Windows worm holeThis is no big deal, right?This was patched for OSs that are 7 years old before the exploit was released and the exploit does not work on the latest version that was released nearly 2 years ago. The equivalent would be a worm targeting Panther...
- Tags: exploit, worm hole, Microsoft Windows
- Discussion threads 2008-10-28
- Secunia: popular security suites failing to block exploits
- Secunia: popular security suites failing to block exploitsPatch your applications...And don't run your browser with administrative rights (in case you forget to patch those applications, e.g., WinAmp, QuickTime, etc).If you're on Windows XP/2000 or Vista and you've foolishly turned off UAC, you can use this tool:http://www.download.com/RemoveAdmin/3000-2381_4-10824971.html?tag=lst-1&cdlPid=10835515Thing is, RemoveAdmin is a...
- Tags: Microsoft Windows, Secunia, popular security suite, exploit, security suite, Kaspersky, security
- Discussion threads 2008-10-14
- Secunia: popular security suites failing to block exploits
- In a recently conducted comparative review, Danish security company Secunia, tested the detection rate of 12 different Internet Security Suites against 300 exploits (144 malicious files and 156 malicious web pages) affecting popular end user applications, to find that even the top performer in the test is in fact performing...
- Tags: Web, Malware, Exploit, Secunia, Spyware, Adware & Malware, Cyberthreats, Security, Viruses And Worms, Dancho Danchev
- Blog posts 2008-10-14
- Clickjacking: Researchers raise alert for scary new cross-browser exploit
- Clickjacking: Researchers raise alert for scary new cross-browser exploitText or graphicremember there use to be a link on web pages if you wanted text only or graphics.that should be put back in placein the wild?"Zero-day" means that the exploit was being used in the wild before a patch was released...
- Tags: Web site development, Web browsers, exploit writer, Clickjacking, exploit
- Discussion threads 2008-09-25
- Researchers discover PDF exploit packs
- If you still need a reason to patch that installation of Adobe Reader, pay close attention to this discovery by Secure Computing's anti-malware research labs. The group has stumbled upon an exploit pack that exclusively targets PDF vulnerabilities, exposing millions of Windows desktops to malicious hacker attacks....
- Tags: Adobe PDF, Malware, Exploit, Spyware, Adware & Malware, Cyberthreats, Security, Ryan Naraine
- Blog posts 2008-09-24
- Who's Dumber: Bad Guys … Or Good Guys?
- Who's Dumber: Bad Guys … Or Good Guys?Bad guys don't need applauseJust money. So they'll modestly attempt to avoid receiving their due when they compromise systems. I wouldn't assume that not hearing about a success means the success has not occurred.Also, this statement is confusing:Now, we have the...
- Tags: SECURITY, flaw, exploit code, Bad Guys, exploit
- Discussion threads 2008-08-27
- HD Moore pwned with his own DNS exploit, vulnerable AT
- HD Moore pwned with his own DNS exploit, vulnerable ATOn top of thisIt wasn't HD who was hacked, as Dancho points out. I just want to reiterate that point, as Austin TX was what was hacked. The AT&T DNS servers there were what was hijacked, and unfortunately, HD...
- Tags: Internet service providers (ISPs), Games, Domain names, Pwned, game, DNS
- Discussion threads 2008-07-30
- Oracle ships emergency workaround for zero-day flaw
- Oracle ships emergency workaround for zero-day flawDoes anybody know?Where the exploit runs? On the Apache web tier where mod_wl sits OR on the app server WebLogic tier? Does mod_wl just package up the exploit and let WL run it? Or does this just allow for RCE with...
- Tags: Application servers, Middleware, emergency workaround, zero-day bug, Oracle Corp., exploit, Apache Software Foundation
- Discussion threads 2008-07-30
- Evolution is punctuated equilibria
- Guest editorial by Dino Dai Zovi In evolutionary biology, the theory of punctuated equilibiria states that evolution is not a gradual process but instead consists of long periods of stasis interrupted by rapid, catastrophic change. Â This is supported by fossil evidence that shows...
- Tags: Vulnerability, Exploit, Internet Security, Internet Security Community, Internet, Security, Ryan Naraine
- Blog posts 2008-07-30
- |)ruid and HD Moore release part 2 of DNS exploit
- |)ruid and HD Moore release part 2 of DNS exploitSo, Linux's BIND the first to be exploited...So, Linux's BIND the first to be exploited...Nice work!CoolNate, nice post and analysis!Wasn't the replacing the ns.victim.com cache entry part of the Halvar Flake speculation? I thought first part of the exploit was to...
- Tags: Domain names, NETWORKING, Operating systems, Alecco, DNS, ruid, exploit, HD Moore, Linux
- Discussion threads 2008-07-24
- Code Diffs for DNS Exploit Code
- Diffs between revisions of the exploit code released by HDM and |)ruid. Generated by Billy Rios. by Nathan McFeters
- Tags: Revision, DNS, Exploit Code, Domain Names, Networking, Internet, Nathan McFeters, diffs, code, Exploit, HDM, |)ruid, Billy, Rios, McFeters, Nate, Nathan, screenshots
- Image galleries 2008-07-23
- |)ruid and HD Moore release part 2 of DNS exploit
- [Updated 07/24/2008: Gallery images of diffs of code revisions has been included and will be updated as things change, see here.] Earlier today, noted researchers |)ruid and HD Moore released exploit code for the Metasploit tool for attacking the DNS flaw that was originally reported by Dan...
- Tags: DNS, Domain, Server, Entry, Exploit, NS, NS Record, Domain Names, Networking, Internet, Nathan McFeters
- Blog posts 2008-07-23
- Attack code published for DNS flaw
- Attack code published for DNS flawIrresponsible and evil"In an IM exchange, Moore told me his exploit takes about a minute or two to poison a DNS cache but said he is working to improve it in version 2.0."As far as i am concerened he is just an evil person to...
- Tags: Domain names, Halvar, exploit, DNS
- Discussion threads 2008-07-23
- Storm Worm's Independence Day campaign
- A Storm Worm's Independence Day campaign is circulating online using email as propagation vector, attempting to trick users into visiting a Storm Worm infected host, where a multitude of what looks like over five different exploits attempt to automatically infect the visitors next to the malware binary fireworks.exe. Historically, Storm...
- Tags: Software, Malware, Worm, Exploit, Storm Worm, Day Vulnerability, Cyberthreats, Spyware, Adware & Malware, Viruses And Worms, Security, Dancho Danchev
- Blog posts 2008-07-04
- Local root escalation vulnerability in Mac OS X 10.4 and 10.5 discovered
- Local root escalation vulnerability in Mac OS X 10.4 and 10.5 discoveredSurprise surpriseSo many of these, they are dime a dozen for all the operating system out there. Just do a little digging on the IRC channels if you want to see for yourself.RE: Local root escalation vulnerability in Mac...
- Tags: Desktops, Operating systems, UNIX, System 9, Apple Macintosh, X-WINDOWS, Apple Mac OS X, Apple Mac OS, Apple Mac OS X 10.4
- Discussion threads 2008-06-19
- What's wrong with an exploit being sexy?
- What's wrong with an exploit being sexy?Ignore the fanboisActiveX gave us global computing. If we were stuck with *nix we'd still be back in the 70s with only the IT high priests and obsessive hobbyists playing with computers. Sure some people make mistakes in coding, but the benefits...
- Tags: Microsoft Windows, Operating systems, Cyberthreats, computer code, Zkiwi, exploit, Unix, global computing, computing, operating system
- Discussion threads 2008-06-10
- What's wrong with an exploit being sexy?
- First off, let me start by saying _dietrich has been following our blog for quite some time and is a consistent poster, providing good advice on how to use Linux securely, sometimes as an alternative to Windows technologies. I wouldn't have commented about this in a blog posting, except that...
- Tags: Exploit, ActiveX, Flaw, Dietrich, openSUSE, Microsoft Windows, ActiveX/COM/COM+/DCOM, Operating Systems, Middleware, Software, Software Development, Software/Web Development, Enterprise Software, Nathan McFeters
- Blog posts 2008-06-10
White Papers and Webcasts