<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Web App Security</title>
    <link>http://seclists.org/#webappsec</link>
    <atom:link href="http://seclists.org/rss/webappsec.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Provides insights on the unique challenges which make web applications notoriously hard to secure, as well as attack methods including SQL injection, cross-site scripting (XSS), cross-site request forgery, and more.</description>
    <pubDate>Thu, 26 Nov 2009 22:15:26 GMT</pubDate>
    <lastBuildDate>Thu, 26 Nov 2009 22:15:26 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: out of box scanner</title>
    <link>http://seclists.org/webappsec/2009/q4/11</link>
    <description>&lt;p&gt;Posted by Brian Shura on Nov 26&lt;/p&gt;The Web Application Security Scanner Evaluation Criteria provides &lt;br&gt;
guidance on features that should be considered when evaluating scanners &lt;br&gt;
and advice on conducting an evaluation.  I agree with Jon that obtaining &lt;br&gt;
evaluation licenses for these scanners and running them against a sample &lt;br&gt;
of your actual web applications will give you the best idea of which &lt;br&gt;
product best meets your needs....&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 22:07:31 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/11</guid>
  </item>
  <item>
    <title>Re: out of box scanner</title>
    <link>http://seclists.org/webappsec/2009/q4/10</link>
    <description>&lt;p&gt;Posted by Jon Kibler on Nov 26&lt;/p&gt;John Bennett wrote:&lt;br&gt;
&lt;br&gt;
Do a fly-off in your environment. Each will give you 15-day demos. Run the demos&lt;br&gt;
concurrently so that you can compare and contrast results. If a scanner vastly&lt;br&gt;
under-preforms one of the competitors, contact their tech reps because you most&lt;br&gt;
likely have something misconfigured.&lt;br&gt;
&lt;br&gt;
Pick the scanner that finds the most non-false positives that the other scanners&lt;br&gt;
miss, has the least false negatives, best fits your working...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 09:45:16 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/10</guid>
  </item>
  <item>
    <title>out of box scanner</title>
    <link>http://seclists.org/webappsec/2009/q4/9</link>
    <description>&lt;p&gt;Posted by John Bennett on Nov 25&lt;/p&gt;I'm currently evaluating some commercial scanners and wanted to get a &lt;br&gt;
feel for others experiences with appscan/cenzic/webinspect.  Any &lt;br&gt;
gotcha's with any of these products and can anybody recommend one over &lt;br&gt;
the other? &lt;br&gt;
&lt;br&gt;
thanks,&lt;br&gt;
John&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It's Finally Here - The Cenzic Website HealthCheck. FREE.&lt;br&gt;
Request Yours Now!...&lt;br&gt;</description>
    <pubDate>Thu, 26 Nov 2009 06:42:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/9</guid>
  </item>


  <item>
    <title>Replicating the Gonzalez Cyber Attacks through Penetration Testing</title>
    <link>http://seclists.org/webappsec/2009/q4/8</link>
    <description>&lt;p&gt;Posted by Core Security on Nov 20&lt;/p&gt;--------------------------------------------------------------------------------&lt;br&gt;
YOU'RE INVITED: IT SECURITY ON DEMAND WEBCAST&lt;br&gt;
 &lt;br&gt;
&amp;quot;Replicating the Gonzalez Cyber Attacks through Penetration Testing&amp;quot;&lt;br&gt;
Register: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&quot;&gt;http://www.coresecurity.com/Form/generic/campaign/SecurityFocusGonzalez&lt;/a&gt;&lt;br&gt;
---------------------------------------------------------------------------------&lt;br&gt;
 &lt;br&gt;
Recently, we saw the indictment of cybercrime kingpin Albert Gonzalez, one...&lt;br&gt;</description>
    <pubDate>Sat, 21 Nov 2009 00:27:10 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/8</guid>
  </item>


  <item>
    <title>winAUTOPWN 2.0 - Introducing winAUTOPWN GUI - Now you can sleep</title>
    <link>http://seclists.org/webappsec/2009/q4/7</link>
    <description>&lt;p&gt;Posted by QUAKER DOOMER on Nov 03&lt;/p&gt;Dear all,&lt;br&gt;
&lt;br&gt;
After a long break and a lot of Unpolished SITA releases of the previous version,&lt;br&gt;
I am finally releasing winAUTOPWN version 2.0&lt;br&gt;
&lt;br&gt;
winAUTOPWN or WINDOWS AUTOPWN version 2.0 now has a GUI (winAUTOPWN_GUI.exe) to initiate the main &lt;br&gt;
console winAUTOPWN.exe&lt;br&gt;
winAUTOPWN now supports all console arguments which can also be fed interactively.&lt;br&gt;
This version covers almost all remote exploits from 2009 start uptill October 2009. Though a few are...&lt;br&gt;</description>
    <pubDate>Tue, 03 Nov 2009 22:27:05 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/7</guid>
  </item>


  <item>
    <title>[AntiSnatchOr] Eclipse BIRT &lt;= 2.2.1 Reflected XSS</title>
    <link>http://seclists.org/webappsec/2009/q4/6</link>
    <description>&lt;p&gt;Posted by Michele Orru on Oct 16&lt;/p&gt;Eclipse BIRT &amp;lt;= 2.2.1 Reflected XSS&lt;br&gt;
&lt;br&gt;
Vendor: Eclipse&lt;br&gt;
Advisory: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://antisnatchor.com/2008/12/18/eclipse-birt-reflected-xss/&quot;&gt;http://antisnatchor.com/2008/12/18/eclipse-birt-reflected-xss/&lt;/a&gt;&lt;br&gt;
Author:  Michele &amp;quot;euronymous&amp;quot; Orrù (euronymous AT antisnatchor DOT com)&lt;br&gt;
&lt;br&gt;
Quite a common problem in a lot of Java based applications: reflected&lt;br&gt;
XSS in Java stack trace.&lt;br&gt;
&lt;br&gt;
A Reflected XSS is present in the _report parameter: here below the modified&lt;br&gt;
request (that is the BIRT 2.2.1 version included in Konakart...&lt;br&gt;</description>
    <pubDate>Fri, 16 Oct 2009 23:45:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/6</guid>
  </item>
  <item>
    <title>Snitz Forums 2000 Multiple Cross-Site Scripting Vulnerabilities</title>
    <link>http://seclists.org/webappsec/2009/q4/5</link>
    <description>&lt;p&gt;Posted by Andrea Fabrizi on Oct 16&lt;/p&gt;**************************************************************&lt;br&gt;
Application: Snitz Forums 2000&lt;br&gt;
Version affected:  3.4.07&lt;br&gt;
Website: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://forum.snitz.com/&quot;&gt;http://forum.snitz.com/&lt;/a&gt;&lt;br&gt;
Discovered By: Andrea Fabrizi&lt;br&gt;
Email: andrea.fabrizi () gmail com&lt;br&gt;
Web: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.andreafabrizi.it&quot;&gt;http://www.andreafabrizi.it&lt;/a&gt;&lt;br&gt;
Vuln: Multiple Cross-Site Scripting&lt;br&gt;
**************************************************************&lt;br&gt;
&lt;br&gt;
###### PERMANENT XSS&lt;br&gt;
If [sound] tag is allowed:&lt;br&gt;
&lt;br&gt;
[sound]...&lt;br&gt;</description>
    <pubDate>Fri, 16 Oct 2009 22:53:04 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/5</guid>
  </item>
  <item>
    <title>[BONSAI] XSS in Achievo - Customized XSS payload included</title>
    <link>http://seclists.org/webappsec/2009/q4/4</link>
    <description>&lt;p&gt;Posted by Bonsai - Information Security on Oct 16&lt;/p&gt;           Bonsai Information Security - Advisory&lt;br&gt;
             &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.bonsai-sec.com/research/&quot;&gt;http://www.bonsai-sec.com/research/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
                   Multiple XSS in Achievo&lt;br&gt;
&lt;br&gt;
1. *Advisory Information*&lt;br&gt;
&lt;br&gt;
Title: Multiple XSS in Achievo&lt;br&gt;
Advisory ID: BONSAI-2009-0101&lt;br&gt;
Advisory URL: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.bonsai-sec.com/research/vulnerabilities/achievo-multiple-xss-0101.txt&quot;&gt;http://www.bonsai-sec.com/research/vulnerabilities/achievo-multiple-xss-0101.txt&lt;/a&gt;&lt;br&gt;
Date published: 2009-10-13&lt;br&gt;
Vendors contacted: Achievo&lt;br&gt;
Release mode: Coordinated release&lt;br&gt;
&lt;br&gt;
2. *Vulnerability Information*...&lt;br&gt;</description>
    <pubDate>Fri, 16 Oct 2009 22:17:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/4</guid>
  </item>
  <item>
    <title>WASC Announcement: 2008 Web Application Security Statistics Published</title>
    <link>http://seclists.org/webappsec/2009/q4/3</link>
    <description>&lt;p&gt;Posted by announcements on Oct 16&lt;/p&gt;The Web Application Security Consortium (WASC) is pleased to announce&lt;br&gt;
the WASC Web Application Security Statistics Project 2008. This&lt;br&gt;
initiative is a collaborative industry wide effort to pool together&lt;br&gt;
sanitized website vulnerability data and to gain a better understanding&lt;br&gt;
about the web application vulnerability landscape.&lt;br&gt;
&lt;br&gt;
The statistics was compiled from web application security assessment&lt;br&gt;
projects which were made by the following companies in...&lt;br&gt;</description>
    <pubDate>Fri, 16 Oct 2009 22:16:06 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/3</guid>
  </item>
  <item>
    <title>[AntiSnatchOr] Pentaho Bi-server multiple vulnerabilities</title>
    <link>http://seclists.org/webappsec/2009/q4/2</link>
    <description>&lt;p&gt;Posted by Michele Orru on Oct 16&lt;/p&gt;Pentaho 1.7.0.1062 Multiple Vulnerabilities&lt;br&gt;
&lt;br&gt;
 Name Multiple Vulnerabilities in Pentaho&lt;br&gt;
 Systems Affected Pentaho &amp;lt;= 1.7.0.1062&lt;br&gt;
 Severity High&lt;br&gt;
 Impact (CVSSv2) High 7/10, vector: (AV:N/AC:L/Au:S/C:P/I:C/A:P)&lt;br&gt;
 Vendor &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.pentaho.com&quot;&gt;http://www.pentaho.com&lt;/a&gt;&lt;br&gt;
 Advisory &lt;a  rel=&quot;nofollow&quot; href=&quot;http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/&quot;&gt;http://antisnatchor.com/2009/06/20/pentaho-1701062-multiple-vulnerabilities/&lt;/a&gt;&lt;br&gt;
 Authors Michele &amp;quot;euronymous&amp;quot; Orrù (euronymous AT antisnatchor DOT com)&lt;br&gt;
&lt;br&gt;
 Date 20081224&lt;br&gt;
&lt;br&gt;
I. BACKGROUND...&lt;br&gt;</description>
    <pubDate>Fri, 16 Oct 2009 22:12:01 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/2</guid>
  </item>
  <item>
    <title>[BONSAI] SQL Injection in Achievo</title>
    <link>http://seclists.org/webappsec/2009/q4/1</link>
    <description>&lt;p&gt;Posted by Bonsai - Information Security on Oct 16&lt;/p&gt;           Bonsai Information Security - Advisory&lt;br&gt;
             &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.bonsai-sec.com/research/&quot;&gt;http://www.bonsai-sec.com/research/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
                 SQL Injection in Achievo&lt;br&gt;
&lt;br&gt;
1. *Advisory Information*&lt;br&gt;
&lt;br&gt;
Title: SQL Injection in Achievo&lt;br&gt;
Advisory ID: BONSAI-2009-0102&lt;br&gt;
Advisory URL: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt&quot;&gt;http://www.bonsai-sec.com/research/vulnerabilities/achievo-sql-injection-0102.txt&lt;/a&gt;&lt;br&gt;
Date published: 2009-10-13&lt;br&gt;
Vendors contacted: Achievo&lt;br&gt;
Release mode: Coordinated release&lt;br&gt;
&lt;br&gt;
2. *Vulnerability Information*...&lt;br&gt;</description>
    <pubDate>Fri, 16 Oct 2009 22:07:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/1</guid>
  </item>


  <item>
    <title>WASC Announcement: Announcing the Web Application Security Scanner Evaluation Criteria v1</title>
    <link>http://seclists.org/webappsec/2009/q4/0</link>
    <description>&lt;p&gt;Posted by announcements on Oct 08&lt;/p&gt;The Web Application Security Consortium is pleased to announce the release&lt;br&gt;
of version 1 of the Web Application Security Scanner Evaluation Criteria&lt;br&gt;
(WASSEC).  The goal of the WASSEC project is to create a vendor-neutral&lt;br&gt;
document to help guide information security professionals during web&lt;br&gt;
application scanner evaluations.  The document provides a comprehensive list&lt;br&gt;
of features that should be considered when conducting an evaluation.  The&lt;br&gt;
WASSEC...&lt;br&gt;</description>
    <pubDate>Thu, 08 Oct 2009 23:47:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q4/0</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>FBController - (Facebook Control Utility) version 2.0</title>
    <link>http://seclists.org/webappsec/2009/q3/51</link>
    <description>&lt;p&gt;Posted by QUAKER DOOMER on Sep 15&lt;/p&gt;FBController - The Ultimate Utility to Control Facebook accounts without the &lt;br&gt;
Password.&lt;br&gt;
&lt;br&gt;
Let me clear this again like last time that this utility WON'T hack/crack Facebook accounts.&lt;br&gt;
The utility will need biscuits/cookies instead of the password.&lt;br&gt;
&lt;br&gt;
Get the target's cookie by sniffing, XSS, social engineering, ARP Poison-Sniffing, &lt;br&gt;
scroogle search, anyhow !&lt;br&gt;
Once you have the cookies you can use FBController and have Full control over the &lt;br&gt;
target's...&lt;br&gt;</description>
    <pubDate>Wed, 16 Sep 2009 04:23:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q3/51</guid>
  </item>
  <item>
    <title>Re: How to enable LDAP signing on client side</title>
    <link>http://seclists.org/webappsec/2009/q3/50</link>
    <description>&lt;p&gt;Posted by Peter M. Jansson on Sep 15&lt;/p&gt;The goal of having the server sign LDAP results would be to give  &lt;br&gt;
confidence in the integrity if the answers. I don't understand what  &lt;br&gt;
the goal of having clients sign queries would be. If you use SSL, the  &lt;br&gt;
client-server exchange is kept confidential (subject to some  &lt;br&gt;
assumptions) and client-side certificates can be used by the server to  &lt;br&gt;
provide access control so rogue clients can't make requests. &lt;br&gt;</description>
    <pubDate>Wed, 16 Sep 2009 04:20:31 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q3/50</guid>
  </item>


  <item>
    <title>How to enable LDAP signing on client side</title>
    <link>http://seclists.org/webappsec/2009/q3/49</link>
    <description>&lt;p&gt;Posted by Jianrong Yu on Sep 15&lt;/p&gt;Hi All,&lt;br&gt;
&lt;br&gt;
The link &amp;lt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://support.microsoft.com/kb/935834&quot;&gt;http://support.microsoft.com/kb/935834&lt;/a&gt;&amp;gt; is the step the How to &lt;br&gt;
enable LDAP signing in Windows Server 2008.&lt;br&gt;
&lt;br&gt;
How to enable LDAP signing on client side?&lt;br&gt;
&lt;br&gt;
Thanks,&lt;br&gt;
&lt;br&gt;
Jianrong Yu&lt;br&gt;
Systems Operation&lt;br&gt;
Office of Information technology&lt;br&gt;
Ohio University&lt;br&gt;</description>
    <pubDate>Tue, 15 Sep 2009 11:11:59 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2009/q3/49</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
