May, 2011

article thumbnail

libxml vulnerability and interesting integer issues

Scary Beasts Security

A while ago, I was playing with grammar-based XPath fuzzing and I found and fixed an interesting libxml bug. The commit, for the curious, is here: [link] The trigger for this bug was the XPath expression: //@*/preceding::node()/ancestor::node()/ancestor::foo['foo'] which for some reason I haven't yet analyzed leads to a pathologically large collection of nodes within libxml.

50
article thumbnail

New European “Cookie Law” Guidance Published

Privacy and Cybersecurity Law

On 26 May 2011, new rules on the use of website cookies will come into force and threatens to drastically […].

article thumbnail

Bug bounties vs. black (& grey) markets

Scary Beasts Security

I'm just back from the fun that was HiTB Amsterdam 2011. (Plug: you should check out one of the HiTB series if you haven't yet; Dhillon and crew invariably put a good, intimate conf together). I sat on the day 2 keynote panel on "The economics of vulnerabilities". As usual, talking about this topic was great fun and the audience asked some great questions.