S E C U R I T Y   P A P E R S   A N D   A D V I S O R I E S

New ENCODE Security Paper (ESP0204): Some more improvements on a fair non-repudiation protocol. Published also in the "Journal of Internet Technology. Vol. 4, No. 4"

ENCODE Security Advisory (ESA0104): In an attempt to target the clients of financial institutions, unknown attackers have compromised various Microsoft Web servers using a known vulnerability (Microsoft Patch 835732) and added code to the web servers to attack anyone browsing the web server with Internet Explorer. The exploit code uses both a known vulnerability in Internet Explorer (addressed by Microsoft Security Bulletin MS04-013) and an unknown vulnerability which can exploit even a fully patched version of Internet Explorer.

ENCODE Security Paper (ESP0104): Whitepaper on i-Mode security issues

ENCODE Security Paper (ESP0402): A framework for transaction non-repudiation & demonstrable log completeness.

 

ENCODE Security Paper (ESP0302): Obfuscated passwords in IBM WebSphere v4.0

Wireless Security & Drive-by Hacking:  ENCODE's presentation @ the Broadband & Mobility Conference 2002, 21-22 May, Athens, Greece

ENCODE Security Advisory (ESA0202): Weakness of "F-Secure Anti-virus" virus update method based on unauthenticated HTTP communication"

ENCODE Security Paper (ESP0202): An empirical analysis of the RVP-based Instant Messaging (MSN Messenger Service v3.6).

ENCODE Security Advisory (ESA0101): Weaknesses in Lotus Notes R5.0 Password Dialog Boxes.

ENCODE Security Paper (ESP0102): Improvements on a fair non-repudiation protocol.