Under Construction

Web Security

28 sites


Sort by: Random | A-Z | Newest | Oldest
Killing the Evercookie - Part2 MobileSafari - Dominic White
https://singe.za.net/blog/archives/1016-Killing-the-Evercookie-Part2-MobileSafari.html
Dominic White's technical blog dives into browser privacy and tracking vulnerabilities, with this post investigating how the Evercookie persistent tracking mechanism operates on iOS MobileSafari and embedded WebKit apps. The research reveals significant privacy gaps in Apple's mobile platform and offers practical steps for jailbroken iPhone users to defend against supercookies.
Blog 2026-03-13
Page Hijack Exploit: 302, redirects and Google (clsc.net)
https://clsc.net/articles/google-302-page-hijack.php
Written by Claus Schmidt in 2005, this technical article exposes the '302 page hijack' exploit, a method by which malicious webmasters could use server redirects to displace competitors' pages from search engine results. It covers how the attack works, which search engines were vulnerable, and practical precautions both victims and potential hijackers can take.
Resource 2026-03-13
Dig Deeper
https://digdeeper.club/
Dig Deeper is a privacy and security-focused resource site covering browser selection, spyware testing, email providers, VPNs, darknet setup, and critiques of major software like Mozilla and various search engines. The site goes deep into practical guides and opinion pieces on digital autonomy, making it a substantial destination for anyone serious about escaping surveillance and corporate tech.
Personal Page 2026-03-12
cleberg.net
https://cleberg.net/
Christian Cleberg is a Technology Assurance Manager at KPMG who publishes technical guides, AWS security auditing posts, and personal projects through this minimalist personal site. Recent posts focus on auditing AWS IAM users, passwords, and S3 buckets, making it a useful stop for cloud security and IT assurance content.
Personal Page 2026-03-12
https://sqlninja.sourceforge.net/
Sqlninja is an open-source penetration testing tool designed to exploit SQL Injection vulnerabilities in web applications backed by Microsoft SQL Server, automating the process of gaining remote access to vulnerable database servers. Created by 'icesurfer', it includes attack modules, a Metasploit wrapper, DNS tunneling for data extraction, and even a hidden Easter Egg that streams music.
Resource 2026-03-13
Hacking The Interwebs
https://gnucitizen.org/blog/hacking-the-interwebs
GNUCITIZEN is a security research blog by pdp and collaborators, focused on exposing web vulnerabilities including UPnP exploitation, XSS attacks, and router reconfiguration weaknesses. This 2008 post details a serious design-level flaw allowing UPnP to be abused across the web without XSS, making it a compelling read for anyone interested in network security research.
Blog 2026-03-15
https://mfzx.net/
Maxwell S. Fritz's personal site covers their work and interests in cybersecurity, software engineering, telecommunications, and amateur radio, with a strong emphasis on privacy as a fundamental human right. Visitors will find links to projects, a directory, updates, and connections to webrings like The Hacker Webring and IndieWeb Webring.
Personal Page 2026-03-13
The Art of ARP Spoofing/Flooding/Poisoning | www.SecurityXploded.com
https://securityxploded.com/art-of-arp-spoofing.php
SecurityXploded is an information security research organization offering in-depth technical articles on topics like ARP spoofing, flooding, and poisoning alongside over 200 free security and password recovery tools. This particular article dives into network-layer attack techniques including MITM attacks and ARP cache manipulation, making it a valuable reference for security professionals and enthusiasts alike.
Resource 2026-03-15
HOWTO bypass Internet Censorship, a tutorial on getting around filters and blocked ports
http://zensur.freerk.com/
Created by Freerk, this comprehensive tutorial covers dozens of techniques for bypassing internet censorship, including proxies, shell accounts, JAP, and circumventing blocked ports in schools, workplaces, and countries with restrictive filtering. It documents specific censorware products like NetNanny, WebSense, and DansGuardian, making it a rare and detailed reference for anyone facing restricted internet access.
Resource 2026-03-13
bad.download
https://bad.download/
The personal site of bad.download, a tech-industry professional who writes about cybersecurity, privacy, digital preservation, and generative AI models. Minimal but thoughtful in scope, it features links to personal projects like a Discord bot using GPT-4 Vision alongside old-school web nostalgia banners for Firefox, AIM, and WinRAR.
Personal Page 2026-03-17