3 weeks ago
3 weeks ago
3 weeks ago
Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.
We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

By Exploiting This Office 365 Flaw, Attackers Can Send You Malicious Emails Every windows user is also using Office 365 to maintain his business records and daily work. A major security vulnerability in Office 365 has been discovered by a Turkish security researcher, which is allowing attackers to send spoofed malicious emails from a fake “Microsoft.com” address. The name of this Turkish security researcher is “Utku Sen”. He is a cyber-se

Microsoft Make Security changes in Latest Version of Skype! Microsoft has updated latest version of skype and make some security changes in it. Now Company will hide the IP address of it's users to protect them from cyber attacks and Cyber Trolls. Skype has activated this functionality by default in it's latest version. First it was very easy to find the IP address of Skype users. It was very easy for the attackers to target the skype users, just by knowing their skype names. So many

Cylance Researchers have discovered a major vulnerability in Windows Operating System. A new technique has been found for stealing login credentials from any Windows System, tablet or even Server. All Major versions of the OS are affected including the yet to release Windows 10. The software products from 31 companies are said to be affected by this vulnerability, which marks Adobe, Apple, Box, Microsoft, Oracle and Symantec on the line. The Vulnerability Redirect to SMB vulnerability allows a

Securify, a dutch security firm, have revealed a serious vulnerability in Pinterest and Yammer iOS apps, which can lead bad actors to perform Man-in-the-Middle attacks. In an official tweet, Securify showed how burpsuite disclosed the passwords sent over the network within apps and are clearly visible. The vulnerability in the application is caused due to failure of server certificates validation, allowing bad actors to eavesdrop in users' talks. But the issue has been fixed in the latest v

Have been thinking from years that DLL Hijacking is just restricted to Windows only? Then let us make it clear, NO! It's nothing like that. Windows were found vulnerable to DLL Hijacking attacks years ago, but a latest research by a Security Firm research director, Patrick Wardle at Synack, revealed OS X are also similarly vulnerable to DLL Hijacking attacks. Mac OS X Dll Hijacking Patrick is going to show off this concept similar to Windows DLL Hijacking at CanSecWest Applied Security C

Samba Server, used popularly for Linux is found to be critically vulnerable to Remote Code Execution vulnerability. Samba is the most commonly used Windows interoperability suite of programs, used by Linux and Unix systems. The vulnerability is recently disclosed on Samba's official website mentioning the vulnerability with CVE id as CVE-2015-0240. The affected versions are found to be Samba 3.5.0 to 4.2.0rc4. According to Trend Micro researchers this Samba Server Vulnerability is said to be

In an official Security Advisory, Microsoft has revealed that it's Windows operating Systems are vulnerable to a FREAK SSL/TLS Flaw. The FREAK flaw is a loophole that allows hackers to initiate man-in-the-middle attacks on connections like Sockets Layer(SSL) and Transport Layer Security(TLS). These two security layers use outdated encryption to cipher. " Microsoft is aware of a security feature bypass vulnerability in Secure Channel (Schannel) that affects all supported releases of M

The once popular mail service Microsoft Outlook is the latest one to get caught in the nets of Phishing scam. The users of the service are receiving email as "Microsoft Account Team" with subject as to terminate your account. The emails contains an attached file in the form of a PDF. The mail states that the account team has received a request to terminate your account but if you had not made any such claim then view the attached file. The scam is a typical phishing technique whe

After back to back revelation of highly critical vulnerabilities in Microsoft products, its time now that Google has targeted Apple to take down the security aspect people look for in Apple products. Google's Project Zero Initiative have exposed 3 Zero-Day vulnerabilities in Apple's OS X operating system, in mere 2 days of time. The alleged reports contain detailed information including the proof-of-concept, whose code is written by Ian Beer, a member of Google's Project Zero Team

Chinese version of "WikiLeaks" - GreatFire reported on Monday, about latest news of Microsoft's Outlook email system being hacked on 17th of January. According to the report, Microsoft's Outlook (which was merged with Hotmail in 2013), was targeted using Man-In-the-Middle (MITM) attack in China. The follwoing snapshots shows what happens when a Chinese user accesses Outlook via an email client (in this case, Ice-dove): GreatFire says, We have tested Outlook to verify the at