YEHG .Inc | Public Secuiry Advisories Weakness Holes Vulnerabilities

Advisories | What security breaches we've found

We don't intentionally hunt for vulnerabilities. The following ones are some of what we came across. [more...]Surely enough, we are not the only ones who found such holes. Many security professionals may have found the same holes at the same time or so. According to hacker code of ethics, we never do any harm or damage to our tested target (Yes, to do damage is one further step that exploits found weakenesses). and make disclosure only after vendor has been reported. But some vendors don't even response;hence we assume that they ignore our reports. There is no patch for ignorance.

We always find it difficult to explain security-knowlege-lack-and-stubborn-to-fix developers about security risks, threats and vulnerabilities. There are always many common myths of security which provoke Today secure and Tomorrow hacked. That's why we can't tell you something like “ Hey, guy  This is a protection code - Use this and your life will be forever secure! ”
Since July '09, we've now believed in FD (=full disclosure) after reporting numerous vulnerabilities to various vendors.Only a few ones take interest in fixing their security holes. Only FD will be a better force towards them to fix. It is the only way to harden or worsen the world.



False Assumption:“XSS Can't 0wn Web Applications”
A number of Bad Guys have owned web application only with XSS!
Attackers are more imaginative and smarter than you are!