<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Web App Security</title>
    <link>http://seclists.org/#webappsec</link>
    <atom:link href="http://seclists.org/rss/webappsec.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Provides insights on the unique challenges which make web applications notoriously hard to secure, as well as attack methods including SQL injection, cross-site scripting (XSS), cross-site request forgery, and more.</description>
    <pubDate>Wed, 23 May 2012 12:45:10 GMT</pubDate>
    <lastBuildDate>Wed, 23 May 2012 12:45:10 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>hydra and HTTP NTLM</title>
    <link>http://seclists.org/webappsec/2012/q2/9</link>
    <description>&lt;p&gt;Posted by Robin Wood on May 23&lt;/p&gt;Anyone know how to use the new HTTP NTLM feature in Hydra? I&amp;apos;m trying&lt;br&gt;
to brute force a MS Front Page login which only asks for&lt;br&gt;
authentication when the OPTIONS method is used as far as I can tell.&lt;br&gt;
&lt;br&gt;
Robin&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It&amp;apos;s Finally Here - The Cenzic Website HealthCheck. FREE.&lt;br&gt;
Request Yours Now! &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Wed, 23 May 2012 12:36:51 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/9</guid>
  </item>


  <item>
    <title>t2&apos;12: Call for Papers 2012 (Helsinki / Finland)</title>
    <link>http://seclists.org/webappsec/2012/q2/8</link>
    <description>&lt;p&gt;Posted by Tomi Tuominen on May 14&lt;/p&gt;                  # t2&amp;apos;12 - Call For Papers #&lt;br&gt;
                      Helsinki, Finland&lt;br&gt;
                    October 25 - 26, 2012&lt;br&gt;
&lt;br&gt;
We are pleased to announce the annual t2&amp;apos;12 infosec conference, which&lt;br&gt;
will take place in Helsinki, Finland, from October 25 to 26, 2012.&lt;br&gt;
&lt;br&gt;
We are looking for original, preferably technical presentations in the&lt;br&gt;
fields of information security. Presentations should last a minimum of&lt;br&gt;
60 minutes and a maximum of two...&lt;br&gt;</description>
    <pubDate>Mon, 14 May 2012 22:17:25 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/8</guid>
  </item>
  <item>
    <title>A survey on web application attacks</title>
    <link>http://seclists.org/webappsec/2012/q2/7</link>
    <description>&lt;p&gt;Posted by Hannes Holm on May 14&lt;/p&gt;Hi webappsec subscribers,&lt;br&gt;
&lt;br&gt;
I am researching the domain consensus regarding the effectiveness of different web application firewalls (WAF)s and &lt;br&gt;
would be glad if you could spare a few minutes of your time to answer a survey on the topic. &lt;br&gt;
&lt;br&gt;
By completing this survey you will:&lt;br&gt;
&lt;br&gt;
  * Help build valuable domain consensus on the topic of WAF effectiveness.&lt;br&gt;
  * Be able to compare your answers to the answers of others.&lt;br&gt;
  * Have the chance to win a 100 USD...&lt;br&gt;</description>
    <pubDate>Mon, 14 May 2012 19:20:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/7</guid>
  </item>


  <item>
    <title>Abusing Password Managers with XSS</title>
    <link>http://seclists.org/webappsec/2012/q2/6</link>
    <description>&lt;p&gt;Posted by mastah yeti on Apr 25&lt;/p&gt;New post on abusing password managers through xss.&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://labs.neohapsis.com/2012/04/25/abusing-password-managers-with-xss/&quot;&gt;http://labs.neohapsis.com/2012/04/25/abusing-password-managers-with-xss/&lt;/a&gt;&lt;br&gt;</description>
    <pubDate>Thu, 26 Apr 2012 01:51:05 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/6</guid>
  </item>


  <item>
    <title>[HITB-Announce] HITB Magazine Issue 008 (now with print edition!)</title>
    <link>http://seclists.org/webappsec/2012/q2/5</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Apr 23&lt;/p&gt;The 8th issue of the HITB Quarterly Magazine is now available for download!&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://magazine.hitb.org/&quot;&gt;http://magazine.hitb.org/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
This edition is a little bit &amp;apos;lighter&amp;apos; than previous issues as the&lt;br&gt;
editorial team is busy working on an extra special release for our 10th&lt;br&gt;
year anniversary conference in October, HITBSecConf2012 - Malaysia.&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://conference.hitb.org/hitbsecconf2012kul/&quot;&gt;http://conference.hitb.org/hitbsecconf2012kul/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
For the first time ever though, we&amp;apos;re making print editions of the&lt;br&gt;
magazine...&lt;br&gt;</description>
    <pubDate>Mon, 23 Apr 2012 23:14:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/5</guid>
  </item>


  <item>
    <title>Ruxcon 2012 Call For Papers</title>
    <link>http://seclists.org/webappsec/2012/q2/4</link>
    <description>&lt;p&gt;Posted by cfp on Apr 20&lt;/p&gt;Ruxcon 2012 Call For Papers&lt;br&gt;
&lt;br&gt;
The Ruxcon team is pleased to announce the call for papers for the 2012 annual Ruxcon conference.&lt;br&gt;
&lt;br&gt;
This year the conference will take place over the weekend of 20th and 21st of October at the CQ Function Centre, &lt;br&gt;
Melbourne, Australia.&lt;br&gt;
&lt;br&gt;
The deadline for submissions is the 15th of July.&lt;br&gt;
&lt;br&gt;
* What is Ruxcon?&lt;br&gt;
&lt;br&gt;
Ruxcon is the premier technical computer security conference in the Australia. The conference aims to bring...&lt;br&gt;</description>
    <pubDate>Sat, 21 Apr 2012 06:17:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/4</guid>
  </item>


  <item>
    <title>Passwords^12 : Call for Presentations</title>
    <link>http://seclists.org/webappsec/2012/q2/3</link>
    <description>&lt;p&gt;Posted by Per Thorsheim on Apr 18&lt;/p&gt;For the third time I am happy to announce a Call for Presentations for&lt;br&gt;
Passwords^12.&lt;br&gt;
&lt;br&gt;
Passwords^12 will be held at the University of Oslo (Norway) on December&lt;br&gt;
3-4, 2012. The 2-day conference will be free and open for anyone to&lt;br&gt;
attend. Please do note that our primary audience will be academics and&lt;br&gt;
security professionals with deep technical knowledge. This is a&lt;br&gt;
conference with international speakers and participants, presenting&lt;br&gt;
fresh ideas and...&lt;br&gt;</description>
    <pubDate>Wed, 18 Apr 2012 11:10:02 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/3</guid>
  </item>
  <item>
    <title>winAUTOPWN v3.0 Released</title>
    <link>http://seclists.org/webappsec/2012/q2/2</link>
    <description>&lt;p&gt;Posted by QUAKER DOOMER on Apr 18&lt;/p&gt;Dear all,&lt;br&gt;
&lt;br&gt;
 This is to announce release of winAUTOPWN version 3.0&lt;br&gt;
&lt;br&gt;
 The improved GUI extension - WINAUTOPWN ACTIVE SYSTEMS TRANSGRESSOR GUI [ C4 - WAST ] is a&lt;br&gt;
 Systems and Network Exploitation Framework built on the famous winAUTOPWN as a backend.&lt;br&gt;
 C4 - WAST gives users the freedom to select individual exploits and use them.&lt;br&gt;
 &lt;br&gt;
 A complete list of all Exploits in winAUTOPWN is available inside MISC\CHANGELOG.TXT &lt;br&gt;
 A complete list of User Interface...&lt;br&gt;</description>
    <pubDate>Wed, 18 Apr 2012 11:07:24 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/2</guid>
  </item>
  <item>
    <title>SEC Consult whitepaper :: The Source Is A Lie</title>
    <link>http://seclists.org/webappsec/2012/q2/1</link>
    <description>&lt;p&gt;Posted by SEC Consult Vulnerability Lab on Apr 18&lt;/p&gt;SEC Consult Vulnerability Lab released a new whitepaper titled:&lt;br&gt;
&amp;quot;The Source Is A Lie&amp;quot;&lt;br&gt;
&lt;br&gt;
Abstract:&lt;br&gt;
---------&lt;br&gt;
Backdoors have always been a concern of the security community. In&lt;br&gt;
recent years the idea of not trusting the developer has gained momentum&lt;br&gt;
and manifested itself in various forms of source code review. For Java,&lt;br&gt;
being one of the most popular programming languages, numerous tools and&lt;br&gt;
papers have been written to help during reviews....&lt;br&gt;</description>
    <pubDate>Wed, 18 Apr 2012 11:03:32 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/1</guid>
  </item>


  <item>
    <title>OWASP ZAP 1.4.0 released</title>
    <link>http://seclists.org/webappsec/2012/q2/0</link>
    <description>&lt;p&gt;Posted by psiinon on Apr 08&lt;/p&gt;Hi folks,&lt;br&gt;
&lt;br&gt;
I&amp;apos;m very pleased to announce that version 1.4.0 of the OWASP Zed&lt;br&gt;
Attack Proxy (ZAP) has now been released.&lt;br&gt;
&lt;br&gt;
This release adds the following main features:&lt;br&gt;
* Syntax highlighting&lt;br&gt;
* fuzzdb integration&lt;br&gt;
* Parameter analysis&lt;br&gt;
* Enhanced XSS scanner&lt;br&gt;
* A port of some of the Watcher checks&lt;br&gt;
* Plugable extensions&lt;br&gt;
&lt;br&gt;
And a load of bugfixes!&lt;br&gt;
&lt;br&gt;
For more information and to download this release please visit the ZAP&lt;br&gt;
homepage:...&lt;br&gt;</description>
    <pubDate>Mon, 09 Apr 2012 01:25:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q2/0</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Time based Blind SQL injection</title>
    <link>http://seclists.org/webappsec/2012/q1/37</link>
    <description>&lt;p&gt;Posted by martin . mngoma on Mar 30&lt;/p&gt;Hi guys&lt;br&gt;
&lt;br&gt;
Just off the topic, can any of you help me.&lt;br&gt;
&lt;br&gt;
I need a vulnerability scanner that can scan WCF web services (silver light technologies )as acunetix does not support &lt;br&gt;
wcf yet.&lt;br&gt;
&lt;br&gt;
All help will be appreciated &lt;br&gt;
&lt;br&gt;
Thanks&lt;br&gt;
Martin&lt;br&gt;
Sent from my BlackBerry® wireless device&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
From: Yiannis Koukouras &amp;lt;ikoukouras () gmail com&amp;gt;&lt;br&gt;
Sender: listbounce () securityfocus com&lt;br&gt;
Date: Thu, 29 Mar 2012 21:04:00 &lt;br&gt;
To: Danux&amp;lt;danuxx ()...&lt;br&gt;</description>
    <pubDate>Fri, 30 Mar 2012 22:29:05 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q1/37</guid>
  </item>
  <item>
    <title>Re: Time based Blind SQL injection</title>
    <link>http://seclists.org/webappsec/2012/q1/36</link>
    <description>&lt;p&gt;Posted by Yiannis Koukouras on Mar 29&lt;/p&gt;So, the only difference, from other tools out there, is the support of TAB(%09)?&lt;br&gt;
&lt;br&gt;
Am I missing something?&lt;br&gt;
&lt;br&gt;
Thanks for sharing! :)&lt;br&gt;
&lt;br&gt;
Cheers,&lt;br&gt;
Ioannis (Yiannis) Koukouras&lt;br&gt;
CISSP, CISA, CISM, OSCP&lt;br&gt;
MSc in Computer Systems Security&lt;br&gt;
BEng in Electronic Engineering&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.linkedin.com/in/ikoukouras&quot;&gt;http://www.linkedin.com/in/ikoukouras&lt;/a&gt;&lt;br&gt;
---&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It&amp;apos;s Finally Here - The Cenzic Website...&lt;br&gt;</description>
    <pubDate>Fri, 30 Mar 2012 00:47:51 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q1/36</guid>
  </item>
  <item>
    <title>Re: Time based Blind SQL injection</title>
    <link>http://seclists.org/webappsec/2012/q1/35</link>
    <description>&lt;p&gt;Posted by Yiannis Koukouras on Mar 29&lt;/p&gt;Cool, I just wanted to be sure I didn&amp;apos;t miss anything else...&lt;br&gt;
&lt;br&gt;
Again thanx for sharing! :)&lt;br&gt;
&lt;br&gt;
Ioannis (Yiannis) Koukouras&lt;br&gt;
CISSP, CISA, CISM, OSCP&lt;br&gt;
MSc in Computer Systems Security&lt;br&gt;
BEng in Electronic Engineering&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.linkedin.com/in/ikoukouras&quot;&gt;http://www.linkedin.com/in/ikoukouras&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It&amp;apos;s Finally Here - The Cenzic Website HealthCheck. FREE.&lt;br&gt;
Request Yours Now!...&lt;br&gt;</description>
    <pubDate>Fri, 30 Mar 2012 00:44:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q1/35</guid>
  </item>


  <item>
    <title>winAUTOPWN v2.9 - As [ C4 - WAST ]</title>
    <link>http://seclists.org/webappsec/2012/q1/34</link>
    <description>&lt;p&gt;Posted by QUAKER DOOMER on Mar 21&lt;/p&gt;Dear all, &lt;br&gt;
&lt;br&gt;
It has been more than 3 YEARS since the first version of winAUTOPWN.&lt;br&gt;
This is to announce release of winAUTOPWN version 2.9&lt;br&gt;
&lt;br&gt;
This version introduces an improved GUI extension - WINAUTOPWN ACTIVE SYSTEMS &lt;br&gt;
TRANSGRESSOR GUI [ C4 - WAST ]&lt;br&gt;
C4 - WAST gives the user the freedom to select individual exploits and use them.&lt;br&gt;
Note that the legacy winAUTOPWN feature to fire all exploits available for open ports &lt;br&gt;
discovered is still present and has...&lt;br&gt;</description>
    <pubDate>Wed, 21 Mar 2012 11:16:36 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q1/34</guid>
  </item>


  <item>
    <title>Re: FBController - (Facebook Control Utility) version 4.0 { With 0-DAY Features }</title>
    <link>http://seclists.org/webappsec/2012/q1/33</link>
    <description>&lt;p&gt;Posted by Alex on Mar 15&lt;/p&gt;You probably should purchase an ad if you&amp;apos;re going to try to sell&lt;br&gt;
something. Just some friendly guidence. Good luck!&lt;br&gt;
&lt;br&gt;
Alex Fernandez-Gatti&lt;br&gt;
&amp;quot;Laws control the lesser man.  Right conduct controls the greater&lt;br&gt;
one.&amp;quot; - Chinese Proverb&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It&amp;apos;s Finally Here - The Cenzic Website HealthCheck. FREE.&lt;br&gt;
Request Yours Now!...&lt;br&gt;</description>
    <pubDate>Thu, 15 Mar 2012 21:00:26 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2012/q1/33</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>

