<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>WASRC</title>
	<atom:link href="http://wasrc.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://wasrc.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Fri, 01 Jan 2010 16:06:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='wasrc.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>WASRC</title>
		<link>http://wasrc.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://wasrc.wordpress.com/osd.xml" title="WASRC" />
	<atom:link rel='hub' href='http://wasrc.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Disclosure policies &#8230; Leads to respons&#8230;</title>
		<link>http://wasrc.wordpress.com/2010/01/01/disclosure-policies-leads-to-respons/</link>
		<comments>http://wasrc.wordpress.com/2010/01/01/disclosure-policies-leads-to-respons/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 16:06:06 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[status]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/2010/01/01/disclosure-policies-leads-to-respons/</guid>
		<description><![CDATA[Disclosure policies &#8230; Leads to responsible disclosure? A post on http://securityretentive.blogspot.com/2009/12/security-disclosure-policies-that.html and http://securityretentive.blogspot.com/2007/11/some-comments-on-paypals-security.html caught my eyes, i read it a while and made me browse to another post(s): https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/ReportingSecurityIssues-outside http://shiflett.org/blog/2007/nov/paypal-groks-security http://jeremiahgrossman.blogspot.com/2007/11/paypals-vulnerability-disclosure-policy.html After taking a quick glance on the post(s), i have a question pop-up in my mind (i should have turn on the pop-up block [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=103&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Disclosure policies &#8230; Leads to responsible disclosure?</p>
<p>A post on <a href="http://securityretentive.blogspot.com/2009/12/security-disclosure-policies-that.html" rel="nofollow">http://securityretentive.blogspot.com/2009/12/security-disclosure-policies-that.html</a> and <a href="http://securityretentive.blogspot.com/2007/11/some-comments-on-paypals-security.html" rel="nofollow">http://securityretentive.blogspot.com/2007/11/some-comments-on-paypals-security.html</a> caught my eyes, i read it a while and made me browse to another post(s):</p>
<p><a href="https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/ReportingSecurityIssues-outside" rel="nofollow">https://www.paypal.com/us/cgi-bin/webscr?cmd=xpt/cps/securitycenter/general/ReportingSecurityIssues-outside</a></p>
<p><a href="http://shiflett.org/blog/2007/nov/paypal-groks-security" rel="nofollow">http://shiflett.org/blog/2007/nov/paypal-groks-security</a></p>
<p><a href="http://jeremiahgrossman.blogspot.com/2007/11/paypals-vulnerability-disclosure-policy.html" rel="nofollow">http://jeremiahgrossman.blogspot.com/2007/11/paypals-vulnerability-disclosure-policy.html</a></p>
<p>After taking a quick glance on the post(s), i have a question pop-up in my mind (i should have turn on the pop-up block feature on my head) about:<br />
&#8220;Do not engage in security research that involves:<br />
    * Use of an exploit to view data without authorization, or corruption of data.&#8221;</p>
<p>For example if i run sql injection test and i can login as admin or the first user on the database &#8230; that mean i can view the user data right? Will it cross the line on the policy guidelines? And the company can take a private action or refer a matter for public inquiry?</p>
<p>Well &#8230; we&#8217;ll never know until we try??? &#8230; or we&#8217;ll never know until we go to court or jail?</p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/103/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/103/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/103/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=103&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2010/01/01/disclosure-policies-leads-to-respons/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>
	</item>
		<item>
		<title>Certified ASS http://ha.ckers.org/blog/2&#8230;</title>
		<link>http://wasrc.wordpress.com/2010/01/01/certified-ass-httpha-ckers-orgblog2/</link>
		<comments>http://wasrc.wordpress.com/2010/01/01/certified-ass-httpha-ckers-orgblog2/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 14:46:52 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[status]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/2010/01/01/certified-ass-httpha-ckers-orgblog2/</guid>
		<description><![CDATA[Certified ASS http://ha.ckers.org/blog/20090401/certified-application-security-specialist/ I ROFL after reading the response on the post. This is the 3rd time i ROFL after reading posts on RSnake blog, the other two posts were http://ha.ckers.org/wallofshame.html and http://www.fthe.net/stuff/419.html<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=102&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Certified ASS</p>
<p><a href="http://ha.ckers.org/blog/20090401/certified-application-security-specialist/" rel="nofollow">http://ha.ckers.org/blog/20090401/certified-application-security-specialist/</a></p>
<p>I ROFL after reading the response on the post. This is the 3rd time i ROFL after reading posts on RSnake blog, the other two posts were <a href="http://ha.ckers.org/wallofshame.html" rel="nofollow">http://ha.ckers.org/wallofshame.html</a>  and <a href="http://www.fthe.net/stuff/419.html" rel="nofollow">http://www.fthe.net/stuff/419.html</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/102/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/102/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/102/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=102&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2010/01/01/certified-ass-httpha-ckers-orgblog2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>
	</item>
		<item>
		<title>OWASP 2010 Top 10 (RC1)</title>
		<link>http://wasrc.wordpress.com/2009/12/06/owasp-2010-top-10-rc1/</link>
		<comments>http://wasrc.wordpress.com/2009/12/06/owasp-2010-top-10-rc1/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 07:43:21 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[link]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/?p=81</guid>
		<description><![CDATA[OWASP 2010 Top 10 (RC1) The Open Web Application Security Project (OWASP) today released a new top 10 list at its conference in Washington, D.C., that focuses on Web application security risks rather than the way its previous lists highlighted the most common weaknesses found in Websites. OWASP member Georg Hess says the risk-based focus [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=81&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>OWASP 2010 Top 10 (RC1)</p>
<p><img src="http://www.cgisecurity.com/images/owasptoptentc1.JPG" alt="" width="80%" /></p>
<p>The Open Web Application Security Project (OWASP) today released a new top 10 list at its conference in Washington, D.C., that focuses on Web application security risks rather than the way its previous lists highlighted the most common weaknesses found in Websites.</p>
<p>OWASP member Georg Hess says the risk-based focus should broaden the OWASP list&#8217;s applicability to IT and higher-level executives, too. &#8220;This time, it&#8217;s not only about vulnerabilities, but really more about identifying the top 10 risks,&#8221; says Hess, CEO and founder of Art of Defence. &#8220;This should help raise the importance of this&#8230;and make it more likely [for organizations] to understand their risks.&#8221;</p>
<p>Injection attacks top the 2010 OWASP Top 10 list of Web application security threats, including SQL, OS, and LDAP injection, followed by cross-site scripting (XSS), broken authentication and session management, insecure direct object references, cross-site request forgery (CSRF), security misconfiguration, failure to restrict URL access, unvalidated redirects and forwards, insecure cryptographic storage, and insufficient transport layer protection.</p>
<p>The list is considered a &#8220;release candidate&#8221; that will be published in its final form in 2010.</p>
<p>New to the list are security misconfiguration and unvalidated redirects and forwards. Security misconfiguration is prevalent today, as is unvalidated redirects and forwards. &#8220;The evidence shows that this relatively unknown issue is widespread and can cause significant damage,&#8221; says the OWASP report. Web redirects typically steer users to other pages and sites, and when the data for the destination pages isn&#8217;t properly validated, users can be redirected to phishing or malware sites by attackers.</p>
<p>Malicious file execution and information leakage/improper error-handling are no longer on the top 10 list. OWASP says that while malicious file execution is still a big problem in many environments and was especially high in 2007 with PHP vulnerabilities, now that PHP ships with default security, it&#8217;s less of a problem. While information leakage/improper error-handling are rampant vulnerabilities, the impact of them isn&#8217;t usually as critical.</p>
<p>The OWASP report also includes how to assess the possibility that your Web application would be at risk of these types of Web attacks, as well as mitigation tips. OWASP used its risk-rating methodology to come up with its new list.</p>
<p>The top 10 comes on the heels of WhiteHat Security&#8217;s report yesterday of the most common vulnerabilities discovered in its clients&#8217; Websites. In that list, XSS was No. 1 and SQL injection No 5. But Jeremiah Grossman, founder and CTO of WhiteHat, says SQL injection flaw finds were likely underreported. SQL injection flaws can be difficult to detect in scans because developers who disable verbose error messages as a way to protect against SQL injection attack can also inadvertently make it difficult to find SQL injection flaws, according to Grossman.</p>
<p>OWASP 2010 RC1: <a href="http://www.owasp.org/index.php/File:OWASP_T10_-_2010_rc1.pdf" rel="nofollow">http://www.owasp.org/index.php/File:OWASP_T10_-_2010_rc1.pdf</a><br />
Source: </p>
<p><a href="http://darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221700095&#038;cid=ref-true" rel="nofollow">http://darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=221700095&#038;cid=ref-true</a></p>
<p><a href="http://www.cgisecurity.com/2009/11/owasp-issues-2010-top-10-rc1.html" rel="nofollow">http://www.cgisecurity.com/2009/11/owasp-issues-2010-top-10-rc1.html</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/81/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/81/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/81/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=81&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2009/12/06/owasp-2010-top-10-rc1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>

		<media:content url="http://www.cgisecurity.com/images/owasptoptentc1.JPG" medium="image" />
	</item>
		<item>
		<title>Moth</title>
		<link>http://wasrc.wordpress.com/2009/12/06/moth-is-a-vmware-image-with-a-set-of/</link>
		<comments>http://wasrc.wordpress.com/2009/12/06/moth-is-a-vmware-image-with-a-set-of/#comments</comments>
		<pubDate>Sun, 06 Dec 2009 07:34:34 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[status]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/2009/12/06/moth-moth-is-a-vmware-image-with-a-set-o/</guid>
		<description><![CDATA[Moth Moth is a VMware image with a set of vulnerable Web Applications and scripts, that you may use for: 1. Testing Web Application Security Scanners 2. Testing Static Code Analysis tools (SCA) 3. Giving an introductory course to Web Application Security The main objective of this tool is to give the community a ready [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=83&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Moth</p>
<p>Moth is a VMware image with a set of vulnerable Web Applications and scripts, that you may use for:</p>
<p>   1. Testing Web Application Security Scanners<br />
   2. Testing Static Code Analysis tools (SCA)<br />
   3. Giving an introductory course to Web Application Security</p>
<p>The main objective of this tool is to give the community a ready to use testbed for web application security tools. For almost every web application vulnerability that exists in the wild, there is a test script available in moth.</p>
<p>There are three different ways to access the web applications and vulnerable scripts included in moth:</p>
<p>   1. Directly<br />
   2. Through mod_security<br />
   3. Through PHP-IDS (only if the web application is written in PHP)</p>
<p>Both mod_security and PHP-IDS have their default configurations and they show a log of the offending request when one is found. This is very useful for testing web application scanners, and teaching students how web application firewalls work. The beauty is that a user may access the same vulnerable script using the three methods; which helps a lot in the learning process.</p>
<p>Moth image: <a href="http://sourceforge.net/projects/w3af/files/moth/moth/moth-v0.6.7z/download" rel="nofollow">http://sourceforge.net/projects/w3af/files/moth/moth/moth-v0.6.7z/download</a></p>
<p>Source: </p>
<p><a href="http://www.bonsai-sec.com/en/research/moth.php" rel="nofollow">http://www.bonsai-sec.com/en/research/moth.php</a></p>
<p><a href="http://www.bonsai-sec.com/blog/index.php/moth-vulnerable-vmware-image/" rel="nofollow">http://www.bonsai-sec.com/blog/index.php/moth-vulnerable-vmware-image/</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/83/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/83/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/83/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=83&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2009/12/06/moth-is-a-vmware-image-with-a-set-of/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>
	</item>
		<item>
		<title>Samurai – Web Testing Framework part 2</title>
		<link>http://wasrc.wordpress.com/2009/12/05/samurai-web-testing-framework-2/</link>
		<comments>http://wasrc.wordpress.com/2009/12/05/samurai-web-testing-framework-2/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 07:59:44 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[link]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/?p=72</guid>
		<description><![CDATA[Enter Samurai As live CD’s have become more popular, specialized distributions have begun to emerge. One such specialty live CD is Samurai, a distribution squarely focused on web application penetration and vulnerability testing. Samurai is dubbed a “web testing framework” in much the same way that Metasploit is termed a framework. Samurai is sponsored by [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=72&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<h4>Enter Samurai</h4>
<p>As live CD’s have become more popular, specialized distributions have begun to emerge.  One such specialty live CD is <a href="http://samurai.intelguardians.com/">Samurai</a>, a distribution squarely focused on web application penetration and vulnerability testing. Samurai is dubbed a “web testing framework” in much the same way that <a href="http://www.metasploit.com/">Metasploit</a> is termed a framework.  Samurai is sponsored by <a href="http://www.intelguardians.com/">IntelGuardians Network Intelligence Inc</a> a for profit information security consulting firm based in Washington, DC.</p>
<p>Samurai focuses on tools needed by web application testers to look for common vulnerabilities, such as misconfigurations, cross site scripting (XSS), SQL injection, remote file inclusion and other common vulnerabilities. the CD includes several tools to reconnoiter web applications and servers, enumerate files and directories, and test scripts.</p>
<h4>Samurai – First Looks</h4>
<p>The bootable Samurai CD allows several options once started. It can be run as a live CD or you can install the framework as a complete operating system:</p>
<p><img src="http://www.madirish.net/assets/images/samurai_boot.jpg" alt="The Samurai live CD boot screen" /></p>
<p>The starting status screen is fairly clean:</p>
<p><img src="http://www.madirish.net/assets/images/samurai_status.jpg" alt="The Samurai live CD boot status" /></p>
<p>Once you boot Samurai to the login screen you enter the username ’samurai’ and the password ’samurai’ to log in. This information is a little obscure. It appears on the Samurai <a href="http://sourceforge.net/docman/display_doc.php?docid=129322&amp;group_id=235785">SourceForge.net project page</a>, and in the Readme.txt that is only available once you’re logged in to the distro:</p>
<p><strong><img src="http://www.madirish.net/images/samurai_login.jpg" alt="The Samurai live CD log in screen" /></strong></p>
<p>Once logged in it becomes obvious that Samurai is based on Ubuntu, which is a little unusual for a live CD distribution:</p>
<p><img src="http://www.madirish.net/assets/images/samurai.jpg" alt="The Samurai live CD" /></p>
<h4>Applications</h4>
<p>Samurai comes with a host of useful applications.  These include many of the regular Linux tools but also include:</p>
<ul>
<li><a href="http://portswigger.net/suite/">Burp Suite</a>, a web application attacking tool</li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_DirBuster_Project">DirBuster</a>, an application file and directory enumeration and brute forcing tool from <abbr title="Open Web Application Security Project">OWASP</abbr></li>
<li><a href="http://ha.ckers.org/fierce/">Fierce Domain Scanner</a> a target ennumeration utility</li>
<li><a href="http://johnny.ihackstuff.com/downloads/task,cat_view/gid,16/">Gooscan</a> an automated Google querying tool that is useful for finding CGI vulnerabilities without scanning the target directly, but rather querying Google’s caches</li>
<li><a href="http://grendel-scan.com/">Grendel-Scan</a>, just released, an open source web application vulnerability testing tool</li>
<li><a href="http://www.net-square.com/httprint/">HTTP_Print</a> a web server fingerprinting tool</li>
<li><a href="http://www.paterva.com/maltego/">Maltego CE</a>, an open source intelligence and forensics application that does data mining to find information from the internet and link it together (great for background research on a target).</li>
<li><a href="http://www.cirt.net/nikto2">Nikto</a>, an open source web server scanner</li>
<li><a href="http://www.parosproxy.org/download.shtml">Paros</a>, one of my favorite, Java based, cross platform, web application auditing and proxy tools</li>
<li><a href="http://code.google.com/p/ratproxy/">Rat Proxy</a>, a semi-automated, passive web application security audit tool.</li>
<li><a href="http://www.immunitysec.com/resources-freesoftware.shtml">Spike Proxy</a>, an extensible web application analyzer and vulnerability scanner.</li>
<li><a href="http://www.darknet.org.uk/2007/06/sqlbrute-sql-injection-brute-force-tool/">SQLBrute</a>, a SQL injection and brute forcing tool.</li>
<li><a href="http://w3af.sourceforge.net/">w3af</a> (and the GUI), a web application attack and audit framework.</li>
<li><a href="http://wapiti.sourceforge.net/">Wapiti</a>, a web application security auditor and vulnerability scanner</li>
<li><a href="http://www.owasp.org/index.php/Category:OWASP_WebScarab_Project">WebScarab</a>, an HTTP application auditing tool from <abbr title="Open Web Application Security Project">OWASP</abbr></li>
<li><a href="http://www.scrt.ch/pages_en/outils.html">WebShag</a>, a web server auditing tool</li>
<li><a href="http://nmap.org/zenmap/">ZenMap</a>, a NMAP graphical front end</li>
</ul>
<p>Additionally Samurai includes several utilities that aren’t available from the GUI menu.  These include:</p>
<ul>
<li><a href="http://freshmeat.net/projects/corkscrew/%3Ecorkscrew%3C/a%3E,%20a%20tool%20that%20allows%20you%20to%20tunnel%20SSH%20through%20HTTP%3C/li%3E%3Cli%3E%3Ca%20href=">dnswalk</a>, a DNS query and zone transfer tool</li>
<li><a href="http://www.vanheusden.com/httping/">httping</a>, a ping like utility for HTTP requests</li>
<li><a href="http://www.httrack.com/">httrack</a>, a website copying utility.</li>
<li><a href="http://www.openwall.com/john/">john the ripper</a>, a password cracking program</li>
<li><a href="http://netcat.sourceforge.net/">netcat</a>, a TCIP/IP swiss army knife</li>
<li><a href="http://www.nmap.org/">nmap</a>, a port scanner and OS detection tool</li>
<li><a>siege</a>, an HTTP stress tester and benchmarking tool.</li>
<li><a href="http://www.xach.com/snarf/">snarf</a>, a lightweight URL fetching utility</li>
</ul>
<p>and many others. Of course, all of these tools could easily be installed on your own Linux based machine, but having a live CD with the tools installed and pre configured is quite nice. Samurai also comes with <a href="http://www.winehq.org/">Wine</a> installed, which is handy if you want to run some windows based tools off of the distribution.</p>
<p>Source: <a rel="nofollow" href="http://www.madirish.net/?article=218">http://www.madirish.net/?article=218</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/72/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/72/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/72/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=72&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2009/12/05/samurai-web-testing-framework-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>

		<media:content url="http://www.madirish.net/assets/images/samurai_boot.jpg" medium="image">
			<media:title type="html">The Samurai live CD boot screen</media:title>
		</media:content>

		<media:content url="http://www.madirish.net/assets/images/samurai_status.jpg" medium="image">
			<media:title type="html">The Samurai live CD boot status</media:title>
		</media:content>

		<media:content url="http://www.madirish.net/images/samurai_login.jpg" medium="image">
			<media:title type="html">The Samurai live CD log in screen</media:title>
		</media:content>

		<media:content url="http://www.madirish.net/assets/images/samurai.jpg" medium="image">
			<media:title type="html">The Samurai live CD</media:title>
		</media:content>
	</item>
		<item>
		<title>w3af &#8211; Web Application Attack and Audit &#8230;</title>
		<link>http://wasrc.wordpress.com/2009/12/05/w3af-web-application-attack-and-audit-framework/</link>
		<comments>http://wasrc.wordpress.com/2009/12/05/w3af-web-application-attack-and-audit-framework/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 04:12:24 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[status]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/?p=50</guid>
		<description><![CDATA[w3af &#8211; Web Application Attack and Audit Framework w3af, is a Web Application Attack and Audit Framework. The w3af core and it&#8217;s plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross site scripting (xss), local and remote file inclusion and much. Download: http://sourceforge.net/projects/w3af/files/ FAQ: http://w3af.sourceforge.net/faq.php [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=50&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>w3af &#8211; Web Application Attack and Audit Framework</p>
<p><a href="http://wasrc.files.wordpress.com/2009/12/w3af.png"><img class="alignleft size-medium wp-image-51" title="w3af" src="http://wasrc.files.wordpress.com/2009/12/w3af.png?w=300&#038;h=91" alt="" width="300" height="91" /></a>w3af, is a Web Application Attack and Audit Framework. The w3af core and it&#8217;s plugins are fully written in python. The project has more than 130 plugins, which check for SQL injection, cross site scripting (xss), local and remote file inclusion and much.</p>
<p>Download: <a href="http://sourceforge.net/projects/w3af/files/" rel="nofollow">http://sourceforge.net/projects/w3af/files/</a><br />
FAQ: <a href="http://w3af.sourceforge.net/faq.php" rel="nofollow">http://w3af.sourceforge.net/faq.php</a><br />
User Guide: <a href="http://w3af.svn.sourceforge.net/viewvc/w3af/trunk/readme/EN/w3afUsersGuide.pdf" rel="nofollow">http://w3af.svn.sourceforge.net/viewvc/w3af/trunk/readme/EN/w3afUsersGuide.pdf</a><br />
Video: <a href="http://www.youtube.com/watch?v=YABMASGv4A8" rel="nofollow">http://www.youtube.com/watch?v=YABMASGv4A8</a> &amp; <a href="http://www.youtube.com/watch?v=3UwQO3-Unt8" rel="nofollow">http://www.youtube.com/watch?v=3UwQO3-Unt8</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=50&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2009/12/05/w3af-web-application-attack-and-audit-framework/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>

		<media:content url="http://wasrc.files.wordpress.com/2009/12/w3af.png?w=300" medium="image">
			<media:title type="html">w3af</media:title>
		</media:content>
	</item>
		<item>
		<title>Samurai &#8211; Web Testing Framework</title>
		<link>http://wasrc.wordpress.com/2009/12/05/samurai-web-testing-framework-the-samu/</link>
		<comments>http://wasrc.wordpress.com/2009/12/05/samurai-web-testing-framework-the-samu/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 02:24:41 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[status]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/2009/12/05/samurai-web-testing-framework-the-samu/</guid>
		<description><![CDATA[Samurai &#8211; Web Testing Framework The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. The CD contains the best of the open source and free tools that focus on testing and attacking websites. In developing this environment, we have based our tool selection [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=26&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Samurai &#8211; Web Testing Framework</p>
<p><a href="http://wasrc.files.wordpress.com/2009/12/samurai1.jpg"><img class="alignleft size-medium wp-image-30" title="Samurai" src="http://wasrc.files.wordpress.com/2009/12/samurai1.jpg?w=300&#038;h=225" alt="" width="300" height="225" /></a>The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. The CD contains the best of the open source and free tools that focus on testing and attacking websites. In developing this environment, we have based our tool selection on the tools we use in our security practice. We have included the tools used in all four steps of a web pen-test.</p>
<p>Starting with reconnaissance, we have included tools such as the Fierce domain scanner and Maltego. For mapping, we have included tools such WebScarab and ratproxy. We then chose tools for discovery. These would include w3af and burp. For exploitation, the final stage, we included BeEF, AJAXShell and much more. This CD also includes a pre-configured wiki, set up to be the central information store during your pen-test.</p>
<p>Website: <a href="http://samurai.inguardians.com/" rel="nofollow">http://samurai.inguardians.com/</a><br />
Video: <a href="http://www.vimeo.com/1790680" rel="nofollow">http://www.vimeo.com/1790680</a><br />
Live CD: <a href="http://sourceforge.net/projects/samurai/files/" rel="nofollow">http://sourceforge.net/projects/samurai/files/</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/26/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/26/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/26/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=26&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2009/12/05/samurai-web-testing-framework-the-samu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>

		<media:content url="http://wasrc.files.wordpress.com/2009/12/samurai1.jpg?w=300" medium="image">
			<media:title type="html">Samurai</media:title>
		</media:content>
	</item>
		<item>
		<title>Pangolin and your data</title>
		<link>http://wasrc.wordpress.com/2009/12/02/pangolin-and-your-data-remember-pangolin/</link>
		<comments>http://wasrc.wordpress.com/2009/12/02/pangolin-and-your-data-remember-pangolin/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 16:27:09 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[status]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/2009/12/02/pangolin-and-your-data-remember-pangolin/</guid>
		<description><![CDATA[Pangolin and your data Remember Pangolin? It&#8217;s an automatic tools for SQL Injection Tool developed by nosec (http://www.nosec.org/download/) that used by Unu when &#8220;walking&#8221; on symantec server (http://unu123456.baywords.com/2009/11/23/symantec-exposed-passwordsserials-sql-injection-full-database-access/). Laramies (Christian Martorella Etiquetas) run some test that revealed pangolin dubious behavior! Laramies said that: &#8220;&#8230; the results of the injection is sent to a nosec.org web [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=25&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Pangolin and your data</p>
<p>Remember Pangolin? It&#8217;s an automatic tools for SQL Injection Tool developed by nosec (<a href="http://www.nosec.org/download/" rel="nofollow">http://www.nosec.org/download/</a>) that used by Unu when &#8220;walking&#8221; on symantec server (<a href="http://unu123456.baywords.com/2009/11/23/symantec-exposed-passwordsserials-sql-injection-full-database-access/" rel="nofollow">http://unu123456.baywords.com/2009/11/23/symantec-exposed-passwordsserials-sql-injection-full-database-access/</a>). Laramies (Christian Martorella Etiquetas) run some test that revealed pangolin dubious behavior! Laramies said that: &#8220;&#8230; the results of the injection is sent to a nosec.org web server, and then Pangolin perform a GET to retrieve the data&#8221;! At least don&#8217;t use it when you audit a client network, otherwise the data will goes to 3rd party?!</p>
<p>Source:</p>
<p><a href="http://laramies.blogspot.com/2009/05/pangolin-and-your-data.html" rel="nofollow">http://laramies.blogspot.com/2009/05/pangolin-and-your-data.html</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=25&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2009/12/02/pangolin-and-your-data-remember-pangolin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>
	</item>
		<item>
		<title>F-Secure gets hacked (likewise)</title>
		<link>http://wasrc.wordpress.com/2009/12/02/f-secure-gets-hacked-likewise-the-roma/</link>
		<comments>http://wasrc.wordpress.com/2009/12/02/f-secure-gets-hacked-likewise-the-roma/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 16:17:03 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[status]]></category>
		<category><![CDATA[SQL injection]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/2009/12/02/f-secure-gets-hacked-likewise-the-roma/</guid>
		<description><![CDATA[F-Secure gets hacked (likewise) The Romanian hacker that made the news this week by blowing the whistle on an SQL injection affecting two of the best known security software developers, Kaspersky and BitDefender, is not resting on his laurels and is now putting the Finish experts from F-Secure to the test. According to Unu, the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=24&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>F-Secure gets hacked (likewise)</p>
<p>The Romanian hacker that made the news this week by blowing the whistle on an SQL injection affecting two of the best known security software developers, Kaspersky and BitDefender, is not resting on his laurels and is now putting the Finish experts from F-Secure to the test. According to Unu, the alias used by the hacker in question, the web page of F-secure is vulnerable to SQL injection and XSS (cross site scripting); the good thing is that no confidential or sensitive data has been leaked. The only info that Unu managed to access is related to past virus activity and some statistics.</p>
<p>“During the last few days a Romanian group has been doing SQL injection attacks on several security vendor&#8217;s websites and early this morning they hit us,” replied F-Secure. “One of our servers used in gathering malware statistics had a page that didn&#8217;t properly sanitize input and was therefore vulnerable to attack. Fortunately we utilize defense-in-depth strategies so the attack was only partly successful. Although the attackers were able to read information from the database they couldn&#8217;t write or manipulate it. And they couldn&#8217;t access any other data on that server because the SQL user only had access to its own database, which only contains public information that is shown on our statistics pages. So while the attack is something we must learn from and points at things we need to improve, it&#8217;s not the end of the world.”</p>
<p>It may not be “the end of the world” but it is properly embarrassing when a company that specializes in security solutions is vulnerable to some sort of exploit or attack.</p>
<p>While Unu’s success may have been a limited, some other hacker has been successful in compromising the official web page of Germany’s Interior Minister, Wolfgang Schäuble. The attacker exploited a security vulnerability in the Typo3 content management system and placed the “Visit: Vorratsdatenspeicherung” message on the site. The attack seems to have been spurred by the minister’s support for biometric passports and logging all email, internet, landline and mobile phone communications.</p>
<p>Source:</p>
<p><a href="http://www.findmysoft.com/news/SQL-Injection-Attack-on-F-Secure-Site-of-Germany-Ministry-of-Interior-Successfully-Hacked/" rel="nofollow">http://www.findmysoft.com/news/SQL-Injection-Attack-on-F-Secure-Site-of-Germany-Ministry-of-Interior-Successfully-Hacked/</a></p>
<p><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1347639,00.html" rel="nofollow">http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1347639,00.html</a></p>
<p><a href="http://www.hackersblog.org/2009/02/11/f-securecom-sql-injection-cross-site-scripting/" rel="nofollow">http://www.hackersblog.org/2009/02/11/f-securecom-sql-injection-cross-site-scripting/</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/24/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/24/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/24/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=24&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2009/12/02/f-secure-gets-hacked-likewise-the-roma/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>
	</item>
		<item>
		<title>BitDefender gets hacked (also)</title>
		<link>http://wasrc.wordpress.com/2009/12/02/bitdefender-gets-hacked-also-unu-the/</link>
		<comments>http://wasrc.wordpress.com/2009/12/02/bitdefender-gets-hacked-also-unu-the/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 16:05:40 +0000</pubDate>
		<dc:creator>--</dc:creator>
				<category><![CDATA[status]]></category>
		<category><![CDATA[SQL injection]]></category>

		<guid isPermaLink="false">http://wasrc.wordpress.com/2009/12/02/bitdefender-gets-hacked-also-unu-the/</guid>
		<description><![CDATA[BitDefender gets hacked (also) Unu, the Romanian hacker that blew the whistle on the SQL injection vulnerability affecting the Kaspersky USA web page has done it again: this time he has discovered a vulnerability affecting the BitDefender Portugal site. By means of SQL injection he managed to gain access to loads of confidential data such [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=23&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>BitDefender gets hacked (also)</p>
<p>Unu, the Romanian hacker that blew the whistle on the SQL injection vulnerability affecting the Kaspersky USA web page has done it again: this time he has discovered a vulnerability affecting the BitDefender Portugal site. By means of SQL injection he managed to gain access to loads of confidential data such as admin usernames, passwords, sales tables, customer details and email addresses, and so on.</p>
<p>Just as in the case of the Kaspersky SQL injection, Unu has posted several pictures depicting his accomplishments: “It seems Kaspersky aren’t the only ones who need to secure their database. BitDefender has the same problems. The images speak for themselves. First we see the version, user and name of the Data Base. Now let’s see the Admin userName, userPass, sessionID and lastlog. Here’s an injection that returns thousands of lines where we see personal details of the customers, tabel vendas (sales table),” he says.</p>
<p>The list of customer email addresses alone makes is worth it for spammers to take advantage of the poorly programmed database – with a simple SQL injection they have access to a whole list of verified and authentic addresses which can be later on exploited. The least worrisome situation would be bombarding the inboxes of these people with “Genuric Viagr@” messages; but what is stopping someone with malicious intent to launch a phishing attempt? We can only take comfort on the fact that Unu will not disclose details about the vulnerability, just as he did in the Kaspersky situation. The other consolation is that since BitDefender is based in Romania, the communication process between Unu and the aforementioned security software developer will go smoothly.</p>
<p>In related security news, it must be said that Microsoft will release a patch tomorrow, the 10th of February 2009. With this month’s Patch Tuesday the Redmond software developer will address two critical vulnerabilities in Internet Explorer and Microsoft Exchange Software and two important vulnerabilities in Microsoft Office and Microsoft SQL.</p>
<p>Source:</p>
<p><a href="http://www.findmysoft.com/news/Unu-Strikes-Again-Hacks-BitDefender/" rel="nofollow">http://www.findmysoft.com/news/Unu-Strikes-Again-Hacks-BitDefender/</a></p>
<p><a href="http://hackersblog.org/2009/02/09/hackedbitdefender-portugal-exposes-sensitive-customer-data/" rel="nofollow">http://hackersblog.org/2009/02/09/hackedbitdefender-portugal-exposes-sensitive-customer-data/</a></p><br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/wasrc.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/wasrc.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/wasrc.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/wasrc.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/wasrc.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/wasrc.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/wasrc.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/wasrc.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/wasrc.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/wasrc.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/wasrc.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/wasrc.wordpress.com/23/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/wasrc.wordpress.com/23/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/wasrc.wordpress.com/23/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=wasrc.wordpress.com&amp;blog=10250583&amp;post=23&amp;subd=wasrc&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://wasrc.wordpress.com/2009/12/02/bitdefender-gets-hacked-also-unu-the/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/07b7c662730ca46978df5ead46621fb8?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">--</media:title>
		</media:content>
	</item>
	</channel>
</rss>
