[FD] Syhunt Advisory: CGILua session.lua Predictable Session ID Vulnerability

2014-04-30 Thread Felipe Daragon
ith additional comments in a separate email. * April 30, 2014 - No response received to emails sent on April 4 & 13. * April 30, 2014 - Public disclosure. ---- Credit: Felipe Daragon Syhunt Security Research Team, www.syhunt.com We thank

[FD] Lua Web Application Security Vulnerabilities

2014-05-26 Thread Felipe Daragon
LUA WEB APPLICATION SECURITY VULNERABILITIES Auditing and Defending Lua-Based Web Applications By Felipe Daragon - May 26, 2014 This paper intends to highlight the risk of unvalidated input in Lua-based web applications. Some time ago I wrote about how to detect NoSQL and server-side