Interesting links – May 14th
Some potentially interesting links for May 14th:
- moth – vulnerable web app teaching tool – a VMware image with a set of vulnerable Web Applications and scripts helpful for testing web application security scanners, testing static code analysis tools, giving an introductory course to Web Application Security.
- PDF Most Common File Type in Targeted Attacks – According to F-Secure, 48% of targeted attacks use PDF documents as the vector, 29% are MS Word files, 7% are Excel. In 2008, Word was in the lead at 34%.
- Durzosploit XSS exploit framework – Framework to quickly and easily generate working exploits for cross-site scripting vulnerabilities in popular web applications or web sites. Written in Ruby.
Tags: javascript, Malware, pdf, statistics, targeted+attacks, training, web application security, web security, webappsec, word, xss