<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>N-Stalker Web Security Community</title>
	<atom:link href="http://community.nstalker.com/feed" rel="self" type="application/rss+xml" />
	<link>http://community.nstalker.com</link>
	<description>Serving Web Application security community since 2000</description>
	<lastBuildDate>Tue, 23 Feb 2010 16:00:41 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Joomla Vulnerabilities and multiple updates</title>
		<link>http://community.nstalker.com/23feb2010-joomla-vulnerabilities</link>
		<comments>http://community.nstalker.com/23feb2010-joomla-vulnerabilities#comments</comments>
		<pubDate>Tue, 23 Feb 2010 16:00:41 +0000</pubDate>
		<dc:creator>N-Stalker Team</dc:creator>
				<category><![CDATA[N-Stalker Latest Updates]]></category>
		<category><![CDATA[nstealth]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=801</guid>
		<description><![CDATA[N-Stalker has made available its latest &#8220;N-Stealth Web Attack Database&#8221; update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.
If you need to contact us for additional instructions, go to N-Stalker&#8217;s Customer Center.
Important Note:  N-Stalker 2006 Version has been discontinued since [...]]]></description>
			<content:encoded><![CDATA[<p>N-Stalker has made available its latest &#8220;N-Stealth Web Attack Database&#8221; update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.</p>
<p>If you need to contact us for additional instructions, go to <a href="https://customer.nstalker.com/cc/" target="_blank">N-Stalker&#8217;s Customer Center</a>.</p>
<p><strong>Important Note</strong>:  N-Stalker 2006 Version has been discontinued since March 31st, 2009. You must upgrade to N-Stalker 2009 to obtain our technical support.</p>
<p>This release includes patterns for the following vulnerabilities:</p>
<ul>
<li>Joomla! DigiStore Component Index.PHP SQL Injection Vulnerability</li>
<li>Joomla! com_schools Component Index.PHP SQL Injection Vulnerability</li>
<li>FlatPress 0.909 Login.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4461" target="_blank">CVE-2009-4461</a>]</li>
<li>FlatPress 0.909 Login.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4461" target="_blank">CVE-2009-4461</a>]</li>
<li>FlatPress 0.909 Contact.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4461" target="_blank">CVE-2009-4461</a>]</li>
<li>Sunbyte e-Flower Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4461" target="_blank">CVE-2009-4461</a>]</li>
<li>Joomla! com_calendario Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4461" target="_blank">CVE-2009-4461</a>]</li>
<li>MAXdev MD-Forum 2.07 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4577" target="_blank">CVE-2009-4577</a>]</li>
<li>Best Top List 2.11 Out.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4577" target="_blank">CVE-2009-4577</a>]</li>
<li>Joomla! iF Portfolio Nexus Index.PHP Local File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4577" target="_blank">CVE-2009-4577</a>]</li>
<li>IMG2ASCII 1.17 Ascii.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4577" target="_blank">CVE-2009-4577</a>]</li>
<li>phpPowerCards 2.0 Pagenumber.Inc.PHP ARCHIV Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4469" target="_blank">CVE-2009-4469</a>]</li>
<li>phpPowerCards 2.0 Pagenumber.Inc.PHP SUBCAT Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4469" target="_blank">CVE-2009-4469</a>]</li>
<li>phpPowerCards 2.0 Pagenumber.Inc.PHP PATH_INFO Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4469" target="_blank">CVE-2009-4469</a>]</li>
<li>freeForum 1.7 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4469" target="_blank">CVE-2009-4469</a>]</li>
<li>MyShoutPro 1.2 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4469" target="_blank">CVE-2009-4469</a>]</li>
<li>phpInstantGallery 1.1 Admin.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4446" target="_blank">CVE-2009-4446</a>]</li>
<li>Barbo91 Upload.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4446" target="_blank">CVE-2009-4446</a>]</li>
<li>APC Switched Rack PDU 3.7.0 Login1 Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4406" target="_blank">CVE-2009-4406</a>]</li>
<li>Woltlab Burning Board Kleinanzeigenmarkt Plugin Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4406" target="_blank">CVE-2009-4406</a>]</li>
<li>MyBB 1.4.10 Myps.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4406" target="_blank">CVE-2009-4406</a>]</li>
<li>Webformatique Car Manager Joomla! Component 2.1 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4406" target="_blank">CVE-2009-4406</a>]</li>
<li>Joomla! JEEMA Article Collection Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4406" target="_blank">CVE-2009-4406</a>]</li>
<li>4homepages 4images 1.7.1 Search.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4406" target="_blank">CVE-2009-4406</a>]</li>
<li>JBC Explorer 7.20 Arbre.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4406" target="_blank">CVE-2009-4406</a>]</li>
<li>Pre Projects E-Smart Cart Login.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4406" target="_blank">CVE-2009-4406</a>]</li>
<li>Pyrmont V2 2.0.7 WordPress Theme Results.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4424" target="_blank">CVE-2009-4424</a>]</li>
<li>F3Site 2009 New.PHP Local File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4435" target="_blank">CVE-2009-4435</a>]</li>
<li>F3Site 2009 Poll.PHP Local File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4435" target="_blank">CVE-2009-4435</a>]</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/23feb2010-joomla-vulnerabilities/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fim da era da serie 1.3 do Apache Server / End of Life for Apache 1.3 series</title>
		<link>http://community.nstalker.com/fim-da-era-da-serie-1-3-do-apache-server-end-of-life-for-apache-1-3-series</link>
		<comments>http://community.nstalker.com/fim-da-era-da-serie-1-3-do-apache-server-end-of-life-for-apache-1-3-series#comments</comments>
		<pubDate>Wed, 03 Feb 2010 17:50:25 +0000</pubDate>
		<dc:creator>Sp0oKeR</dc:creator>
				<category><![CDATA[N-Stalker's Team Blog]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=798</guid>
		<description><![CDATA[Portugues(pt_BR)
Certamente todo administrador linux ou de segurança já trabalhou com a serie 1.3 do Apache. Certamente ela deixara saudades para a velha guarda mais a evolução é necessária . Foi anunciado hoje (02/02/2010) a última versão da serie apache 1.3 . No release  1.3.42 informaram o fim da era da versão 1.3 e que o [...]]]></description>
			<content:encoded><![CDATA[<p><span style="text-decoration: underline;"><strong>Portugues(pt_BR)</strong></span></p>
<p>Certamente todo administrador linux ou de segurança já trabalhou com a serie 1.3 do Apache. Certamente ela deixara saudades para a velha guarda mais a evolução é necessária . Foi anunciado hoje (02/02/2010) a última versão da serie apache 1.3 . No release  1.3.42 informaram o fim da era da versão 1.3 e que o mesmo terá somente alguns updates críticos .</p>
<p>Parte do anúncio (Inglês)</p>
<p>&#8220;The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 1.3.42 of the Apache HTTP Server (&#8220;Apache&#8221;). This release is intended as the final release of version 1.3 of the Apache HTTP Server, which has reached end of life status.&#8221;</p>
<p>Anúncio completo:</p>
<p><a href="http://mail-archives.apache.org/mod_mbox/httpd-announce/201002.mbox/%3C20100203000334.GA19021@infiltrator.stdlib.net%3E">http://mail-archives.apache.org/mod_mbox/httpd-announce/201002.mbox/%3C20100203000334.GA19021@infiltrator.stdlib.net%3E</a></p>
<p>Visando a proteção de nossos clientes no futuro sugerimos que façam updates para versões correntes assim que possível visto que problemas de segurança podem surgir. Abaixo as melhores versões para uso:</p>
<p>Apache HTTP Server 2.2.14 is the best available version<br />
Apache 2.0.63 Released</p>
<p>Mais informações: <a href="http://httpd.apache.org/download.cgi">http://httpd.apache.org/download.cgi</a></p>
<p>N-Stalker Team</p>
<p><span style="text-decoration: underline;"><strong>English(en)</strong></span></p>
<p>Probably every linux administrator or security analyst have been worked with Apache 1.3 series . The old school guys will miss it but the evolution is necessary . Today was announced the lastest release for apache 1.3 series. In this release 1.3.42 they announced that apache 1.3 will only have critical updates.</p>
<p>Part of the announce:</p>
<p>&#8220;The Apache Software Foundation and the Apache HTTP Server Project are pleased to announce the release of version 1.3.42 of the Apache HTTP Server (&#8220;Apache&#8221;). This release is intended as the final release of version 1.3 of the Apache HTTP Server, which has reached end of life status.&#8221;</p>
<p>Full announce:</p>
<p><a href="http://mail-archives.apache.org/mod_mbox/httpd-announce/201002.mbox/%3C20100203000334.GA19021@infiltrator.stdlib.net%3E">http://mail-archives.apache.org/mod_mbox/httpd-announce/201002.mbox/%3C20100203000334.GA19021@infiltrator.stdlib.net%3E</a></p>
<p>Looking forward to protect and advise our costumer we really suggest you to update to current versions as listed bellow:</p>
<p>Apache HTTP Server 2.2.14 is the best available version<br />
Apache 2.0.63 Released</p>
<p>More information: <a href="http://httpd.apache.org/download.cgi">http://httpd.apache.org/download.cgi</a></p>
<p>N-Stalker Team</p>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/fim-da-era-da-serie-1-3-do-apache-server-end-of-life-for-apache-1-3-series/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>phpMyFAQ, UBB.threads vulnerabilities and multiple updates</title>
		<link>http://community.nstalker.com/phpmyfaq-ubb-threads-vulnerabilities-jan2010</link>
		<comments>http://community.nstalker.com/phpmyfaq-ubb-threads-vulnerabilities-jan2010#comments</comments>
		<pubDate>Tue, 19 Jan 2010 21:06:50 +0000</pubDate>
		<dc:creator>N-Stalker Team</dc:creator>
				<category><![CDATA[N-Stalker Latest Updates]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=795</guid>
		<description><![CDATA[N-Stalker has made available its latest &#8220;N-Stealth Web Attack Database&#8221; update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.
If you need to contact us for additional instructions, go to N-Stalker&#8217;s Customer Center.
Important Note:  N-Stalker 2006 Version has been discontinued since [...]]]></description>
			<content:encoded><![CDATA[<p>N-Stalker has made available its latest &#8220;N-Stealth Web Attack Database&#8221; update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.</p>
<p>If you need to contact us for additional instructions, go to <a href="https://customer.nstalker.com/cc/" target="_blank">N-Stalker&#8217;s Customer Center</a>.</p>
<p><strong>Important Note</strong>:  N-Stalker 2006 Version has been discontinued since March 31st, 2009. You must upgrade to N-Stalker 2009 to obtain our technical support.</p>
<p>This release includes patterns for the following vulnerabilities:</p>
<ul>
<li>eWebquiz 8.0 Questions.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4436" target="_blank">CVE-2009-4436</a>]</li>
<li>eWebquiz 8.0 Importquestions.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4436" target="_blank">CVE-2009-4436</a>]</li>
<li>eWebquiz 8.0 Quiztakers.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4436" target="_blank">CVE-2009-4436</a>]</li>
<li>Active Auction House 3.6 Wishlist.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4437" target="_blank">CVE-2009-4437</a>]</li>
<li>Active Auction House 3.6 Links.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4437" target="_blank">CVE-2009-4437</a>]</li>
<li>cPanel 11.24.7 Dofileop.HTML Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4437" target="_blank">CVE-2009-4437</a>]</li>
<li>cPanel 11.24.7 Fileop.HTML Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4437" target="_blank">CVE-2009-4437</a>]</li>
<li>QuiXplorer 2.3.1 Index.PHP Local File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4437" target="_blank">CVE-2009-4437</a>]</li>
<li>Joomla! Com_Joomportfolio Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4428" target="_blank">CVE-2009-4428</a>]</li>
<li>Joomla! Com_Personel Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4428" target="_blank">CVE-2009-4428</a>]</li>
<li>Pluxml-Blog 4.2 Auth.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4428" target="_blank">CVE-2009-4428</a>]</li>
<li>WP-Forum WordPress Plugin 2.3 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3703" target="_blank">CVE-2009-3703</a>]</li>
<li>phpFaber CMS 1.3.36 Module.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4382" target="_blank">CVE-2009-4382</a>]</li>
<li>Zeeways ZeeLyrics 3.0 Searchresults_Main.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4316" target="_blank">CVE-2009-4316</a>]</li>
<li>VirtueMart 1.0 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4430" target="_blank">CVE-2009-4430</a>]</li>
<li>Million Pixel Script 3.0 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4381" target="_blank">CVE-2009-4381</a>]</li>
<li>iDevSpot iSupport 1.8 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3731" target="_blank">CVE-2009-3731</a>]</li>
<li>iDevSpot iSupport 1.8 Function.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3731" target="_blank">CVE-2009-3731</a>]</li>
<li>Ez Cart Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4317" target="_blank">CVE-2009-4317</a>]</li>
<li>Digital Scribe 1.4.1 Stuworkdisplay.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4317" target="_blank">CVE-2009-4317</a>]</li>
<li>Zeeways ZeeJobsite 3.0 Basic_Search_Result.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4317" target="_blank">CVE-2009-4317</a>]</li>
<li>Zen Cart 1.3.8 Curltest.PHP Information Disclosure Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4321" target="_blank">CVE-2009-4321</a>]</li>
<li>Joomla! JS Jobs Component 1.0.5.6 Index.PHP MD Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4321" target="_blank">CVE-2009-4321</a>]</li>
<li>Joomla! JS Jobs Component 1.0.5.6 Index.PHP OI Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4321" target="_blank">CVE-2009-4321</a>]</li>
<li>Joomla! com_jphoto Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4321" target="_blank">CVE-2009-4321</a>]</li>
<li>TestLink 1.8.4 Eventviewer.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4238" target="_blank">CVE-2009-4238</a>]</li>
<li>TestLink 1.8.4 NavBar.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4238" target="_blank">CVE-2009-4238</a>]</li>
<li>TestLink 1.8.4 Login.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4237" target="_blank">CVE-2009-4237</a>]</li>
<li>TestLink 1.8.4 ResultsMoreBuilds_BuildReport.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4237" target="_blank">CVE-2009-4237</a>]</li>
<li>TestLink 1.8.4 Eventviewer.PHP LOGLEVEL Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4237" target="_blank">CVE-2009-4237</a>]</li>
<li>TestLink 1.8.4 Eventviewer.PHP ENDDATE Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4237" target="_blank">CVE-2009-4237</a>]</li>
<li>TestLink 1.8.4 Eventviewer.PHP STARTDATE Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4237" target="_blank">CVE-2009-4237</a>]</li>
<li>TestLink 1.8.4 Attachmentupload.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4237" target="_blank">CVE-2009-4237</a>]</li>
<li>TestLink 1.8.4 StaticPage.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4237" target="_blank">CVE-2009-4237</a>]</li>
<li>Joomla! You!Hostit! Template 1.0.1 Index.PHP Cross-Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4255" target="_blank">CVE-2009-4255</a>]</li>
<li>Joomla! Com_Job Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4255" target="_blank">CVE-2009-4255</a>]</li>
<li>YOOtheme Warp5 Joomla! Component Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4255" target="_blank">CVE-2009-4255</a>]</li>
<li>Chipmunk Newsletter 2.0 Addlist.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4255" target="_blank">CVE-2009-4255</a>]</li>
<li>GCalendar Joomla! Component 2.1.4 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP ORDER_ID Parameter Cross-Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP CATEGORY Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP TAX_RATE_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP PAYMENT_METHOD_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP USER_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP VENDOR_CATEGORY_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP USER_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP MODULE_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP VENDOR_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP PRODUCT_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>PhpShop 0.8.1 Index.PHP MODULE_ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>Sisplet CMS 2008-01-24 New.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>AROUNDMe 1.1 Connect.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4264" target="_blank">CVE-2009-4264</a>]</li>
<li>YABSoft Advanced Image Hosting Script 2.2 Search.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>UBB.threads 7.5.4.2 Smarty_Compiler.Class.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>UBB.threads 7.5.4.2 Html.Inc.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>UBB.threads 7.5.4.2 Ubbthreads.PHP Local File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>Elkagroup Image Gallery 1.0 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>427BB 2.3.2 Showpost.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP LANG Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP QUESTION Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP CAT Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP CAT Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP ID Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP SRCLANG Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP ID Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP CAT Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP ARTLANG Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP NEWSLANG Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP TAGGING_ID Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP CAT Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP LANG Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP LETTER Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP LANG Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP ARTLANG Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
<li>phpMyFAQ 2.5.4 Index.PHP HIGHLIGHT Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4266" target="_blank">CVE-2009-4266</a>]</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/phpmyfaq-ubb-threads-vulnerabilities-jan2010/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>N-Stalker is 2009&#8217;s winning web application security software, says security-database!</title>
		<link>http://community.nstalker.com/n-stalker-is-2009s-winning-web-application-security-software-says-security-database</link>
		<comments>http://community.nstalker.com/n-stalker-is-2009s-winning-web-application-security-software-says-security-database#comments</comments>
		<pubDate>Wed, 13 Jan 2010 16:46:20 +0000</pubDate>
		<dc:creator>N-Stalker Team</dc:creator>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[N-Stalker's Team Blog]]></category>
		<category><![CDATA[ameaças]]></category>
		<category><![CDATA[aplicativos]]></category>
		<category><![CDATA[avaliação de segurança]]></category>
		<category><![CDATA[consultores de segurança]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[IT professionals]]></category>
		<category><![CDATA[n-stalker]]></category>
		<category><![CDATA[profissionais de TI]]></category>
		<category><![CDATA[scanner de segurança]]></category>
		<category><![CDATA[security assessment]]></category>
		<category><![CDATA[security award]]></category>
		<category><![CDATA[security consultants]]></category>
		<category><![CDATA[security scanner]]></category>
		<category><![CDATA[threats]]></category>
		<category><![CDATA[TI]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=782</guid>
		<description><![CDATA[SECURITY-DATABASE, one of world&#8217;s most accredited entities dedicated to identify and assess web security threats (as well as the best tools available on the market to combat them) has nominated N-STALKER as 2009&#8217;s winner in web application security assessment tools.
This is the result of 10 years fully dedicated to the creation, design and development of [...]]]></description>
			<content:encoded><![CDATA[<p>SECURITY-DATABASE, one of world&#8217;s most accredited entities dedicated to identify and assess web security threats (as well as the best tools available on the market to combat them) has nominated N-STALKER as 2009&#8217;s winner in web application security assessment tools.</p>
<p>This is the result of 10 years fully dedicated to the creation, design and development of state-of-the-art, outstanding security scanner software solutions now adoptedby governmental, public and legal entities as well as IT professionals and security consultants worldwide.</p>
<p>Another jewel in our crown and a challenge to keep up the good work!</p>
<hr /><a name="#PT"></a></p>
<h2>N-Stalker escolhido como melhor scanner de segurança em 2009!</h2>
<p>O site SECURITY-DATABASE, uma das mais conceituadas entidades dedicadas à identificação e avaliação de ameaças à segurança na Web (como também na indicação das melhores ferramentas disponíveis no mercado para combatê-las) declarou N-STALKER o software vencedor em 2009 na categoria de ferramentas de avaliação de segurança em aplicativos da Web.</p>
<p>Este nada mais é que o resultado de 10 anos plenamente dedicados à criação, projeto e desenvolvimento de soluções de software de segurança na Web no estado-da-arte, hoje adotadas por governos, empresas públicas e privadas, profissionais de TI e consultores de segurança na Web, por todo o mundo.</p>
<p>Mais uma jóia em nossa coroa e mais um desafio para nos mantermos no topo em 2010!</p>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/n-stalker-is-2009s-winning-web-application-security-software-says-security-database/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Joomla and Wordpress attacks and multiple updates</title>
		<link>http://community.nstalker.com/joomla-wp-vulnerabilities-dec2009</link>
		<comments>http://community.nstalker.com/joomla-wp-vulnerabilities-dec2009#comments</comments>
		<pubDate>Thu, 24 Dec 2009 14:37:31 +0000</pubDate>
		<dc:creator>N-Stalker Team</dc:creator>
				<category><![CDATA[N-Stalker Latest Updates]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=780</guid>
		<description><![CDATA[N-Stalker has made available its latest &#8220;N-Stealth Web Attack Database&#8221; update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.
If you need to contact us for additional instructions, go to N-Stalker&#8217;s Customer Center.
Important Note:  N-Stalker 2006 Version has been discontinued since March [...]]]></description>
			<content:encoded><![CDATA[<p>N-Stalker has made available its latest &#8220;N-Stealth Web Attack Database&#8221; update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.</p>
<p>If you need to contact us for additional instructions, go to <a href="https://customer.nstalker.com/cc/" target="_blank">N-Stalker&#8217;s Customer Center</a>.</p>
<p><strong>Important Note</strong>:  N-Stalker 2006 Version has been discontinued since March 31st, 2009. You must upgrade to N-Stalker 2009 to obtain our technical support.</p>
<p>This release includes patterns for the following vulnerabilities:</p>
<ul>
<li>Yoast Google Analytics for WordPress Plugin 3.2.4 404 Error Page Cross Site Scripting Vulnerability</li>
<li>Invision Power Board 3.0.4 Index.PHP SQL Injection Vulnerability</li>
<li>Invision Power Board 3.0.4 Index.PHP Local File Include Vulnerability</li>
<li>Invision Power Board 3.0.4 Index.PHP SQL Injection Vulnerability</li>
<li>Thatware 0.5.3 Thatfile.PHP Remote File Include Vulnerability</li>
<li>Thatware 0.5.3 Artlist.PHP Remote File Include Vulnerability</li>
<li>Thatware 0.5.3 Config.PHP Remote File Include Vulnerability</li>
<li>Ciamos 0.9.5 Index.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4156" target="_blank">CVE-2009-4156</a>]</li>
<li>Joomla! mojoBlog Component RC0.15 Wp-Comments-Post.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4156" target="_blank">CVE-2009-4156</a>]</li>
<li>Joomla! mojoBlog Component RC0.15 Wp-Trackback.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4156" target="_blank">CVE-2009-4156</a>]</li>
<li>Joomla! Joaktree Component 1.0 &#8216;treeId&#8217; Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4156" target="_blank">CVE-2009-4156</a>]</li>
<li>Elxis Feedcreator.Class.PHP Directory Traversal Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4154" target="_blank">CVE-2009-4154</a>]</li>
<li>SmartMedia Module for XOOPS 0.85 Folder.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4359" target="_blank">CVE-2009-4359</a>]</li>
<li>Joomla! Quick News Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4359" target="_blank">CVE-2009-4359</a>]</li>
<li>Content Module for XOOPS 0.5 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4360" target="_blank">CVE-2009-4360</a>]</li>
<li>Power Phlogger 2.2.5 DspStats.PHP Cross-site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4253" target="_blank">CVE-2009-4253</a>]</li>
<li>Joomla! 1.5.11 404 Error Page Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4253" target="_blank">CVE-2009-4253</a>]</li>
<li>MusicGallery Joomla! Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4217" target="_blank">CVE-2009-4217</a>]</li>
<li>Joomla! ProofReader Component 1.0 Index.PHP Cross-Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4157" target="_blank">CVE-2009-4157</a>]</li>
<li>LyftenBloggie Joomla! Component 1.0.4 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4104" target="_blank">CVE-2009-4104</a>]</li>
<li>phpBazar 2.1.1 Classified.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4221" target="_blank">CVE-2009-4221</a>]</li>
<li>Joomla! Google Calendar Component 1.1.2 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4099" target="_blank">CVE-2009-4099</a>]</li>
<li>Quick.Cart 2.4 and Quick.CMS 3.4 Delete Function Cross Site Request Forgery Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4120" target="_blank">CVE-2009-4120</a>]</li>
<li>klinza professional cms 5.0.1 Menulast.PHP Local File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4216" target="_blank">CVE-2009-4216</a>]</li>
<li>WordPress WP-Cumulus Plugin 1.22 Tagcloud.SWF Cross-Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4168" target="_blank">CVE-2009-4168</a>]</li>
<li>PHP Live! 3.1 Help.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4168" target="_blank">CVE-2009-4168</a>]</li>
<li>WordPress Trashbin Plugin 0.1 Edit.PHP Cross-Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4168" target="_blank">CVE-2009-4168</a>]</li>
<li>WordPress WP-PHPList Plugin 2.10.2 Wp-Phplist.PHP Cross-Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4168" target="_blank">CVE-2009-4168</a>]</li>
<li>Outreach Project Tool 1.2.7 Index.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4082" target="_blank">CVE-2009-4082</a>]</li>
<li>CubeCart 4.3.6 ViewProd.Inc.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4060" target="_blank">CVE-2009-4060</a>]</li>
<li>Joomla! iF Portfolio Nexus Component Index.PHP ID Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4057" target="_blank">CVE-2009-4057</a>]</li>
<li>Joomla! iF Portfolio Nexus Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4057" target="_blank">CVE-2009-4057</a>]</li>
<li>ActiveWebSoftwares Active Bids Default.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4057" target="_blank">CVE-2009-4057</a>]</li>
<li>Joomla! JoomClip Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4059" target="_blank">CVE-2009-4059</a>]</li>
<li>Multiple JiRo&#8217;s Products Login.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4218" target="_blank">CVE-2009-4218</a>]</li>
<li>Joomla! eZine Component 2.1 D4m_Ajax_Pagenav.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4094" target="_blank">CVE-2009-4094</a>]</li>
<li>eNdonesia 8.4 Mod.PHP Local File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4094" target="_blank">CVE-2009-4094</a>]</li>
<li>TFTgallery 0.13 Index.PHP Directory Traversal Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3912" target="_blank">CVE-2009-3912</a>]</li>
<li>TFTgallery 0.13 Settings.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3911" target="_blank">CVE-2009-3911</a>]</li>
<li>Joomla! Com_Photoblog Component 3a Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3834" target="_blank">CVE-2009-3834</a>]</li>
<li>TFTgallery 0.13 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3833" target="_blank">CVE-2009-3833</a>]</li>
<li>TBmnetCMS 1.0 Tbmnet.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3747" target="_blank">CVE-2009-3747</a>]</li>
<li>Achievo 1.3.4 Debugger.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3705" target="_blank">CVE-2009-3705</a>]</li>
<li>RunCMS Post.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3705" target="_blank">CVE-2009-3705</a>]</li>
<li>Joomla! Com_Jshop Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3835" target="_blank">CVE-2009-3835</a>]</li>
<li>OpenDocMan 1.2.5 View_File.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 User.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 Search.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 Rejects.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 Add.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 Profile.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 Department.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 Category.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 Admin.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>OpenDocMan 1.2.5 ToBePublished.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3789" target="_blank">CVE-2009-3789</a>]</li>
<li>Joomla! com_booklibrary Component 1.0 Releasenote.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3817" target="_blank">CVE-2009-3817</a>]</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/joomla-wp-vulnerabilities-dec2009/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cross Site Scripting (XSS) Twitter / WafW00f release 0.24</title>
		<link>http://community.nstalker.com/cross-site-scripting-xss-twitter-wafw00f-release-0-24</link>
		<comments>http://community.nstalker.com/cross-site-scripting-xss-twitter-wafw00f-release-0-24#comments</comments>
		<pubDate>Mon, 21 Dec 2009 12:47:52 +0000</pubDate>
		<dc:creator>Sp0oKeR</dc:creator>
				<category><![CDATA[N-Stalker's Team Blog]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=776</guid>
		<description><![CDATA[Primeiramente comentarei de um XSS encontrado no twitter pelo time da N-Stalker junto com o time da iBliss (http://www.ibliss.com.br) . Fazendo alguns testes rotineiros encontramos uma situação aparentemente não muito fácil de explorar globalmente mas com possibilidades de roubo de sessão dentre outros fatores.
O twitter tem um campo de pesquisas http://www.twitter.com/timeline/search?q= .
Se digitassemos algo como [...]]]></description>
			<content:encoded><![CDATA[<p>Primeiramente comentarei de um XSS encontrado no twitter pelo time da N-Stalker junto com o time da iBliss (<a href="http://www.ibliss.com.br">http://www.ibliss.com.br</a>) . Fazendo alguns testes rotineiros encontramos uma situação aparentemente não muito fácil de explorar globalmente mas com possibilidades de roubo de sessão dentre outros fatores.</p>
<p>O twitter tem um campo de pesquisas <a href="http://www.twitter.com/timeline/search?q=">http://www.twitter.com/timeline/search?q=</a> .</p>
<p>Se digitassemos algo como <strong><em>&lt;script language=javascript&gt;alert(&#8216;XSS&#8217;)&lt;/script&gt;</em></strong> no search nada aconteceria. O problema seria quando você  salvasse o search e realizando o reload na página o código era carregado .</p>
<p>A falha foi reportada para o security do twitter</p>
<p><strong>Discovered                        29/11/2009<br />
Vendor Disclosure       02/12/2009<br />
Patched                              09/12/2009<br />
Disclosure                        09/12/2009</strong></p>
<p>A correção foi extremamente rápida e vale parabenizar a equipe de desenvolvedores/equipe de segurança do twitter.</p>
<p>Além do report do XSS testamos o release 0.24 do WafW00f escrito pelo Sandro Gauci e pelo nosso amigo Wendel aka Dumdum. Essa ferramenta visa detectar a presença de web application firewalls e com isso colaborar com uso de possíveis técnicas de evasion para bypassar e ter maior sucesso no pentest ou analise de vulnerabilidade web .</p>
<p>A ferramenta suporta a detecção dos seguintes WAF&#8217;s</p>
<p><em>spooker@notsecure:/LABS/waffit$ python wafw00f.py &#8211;list</em></p>
<p><em>WAFW00F &#8211; Web Application Firewall Detection Tool</em></p>
<p><em>By Sandro Gauci &amp;&amp; Wendel G. Henrique</em></p>
<p><em>Can test for these WAFs:</em></p>
<p><em>Profense<br />
NetContinuum<br />
Barracuda<br />
HyperGuard<br />
BinarySec<br />
Teros<br />
F5 Trafficshield<br />
F5 ASM<br />
Airlock<br />
Citrix NetScaler<br />
ModSecurity<br />
DenyALL<br />
dotDefender<br />
webApp.secure<br />
BIG-IP<br />
URLScan<br />
WebKnight<br />
SecureIIS<br />
BeeWare<br />
Imperva</em></p>
<p><em>spooker@notsecure:/LABS/waffit$ </em></p>
<p>A ferramenta basicamente envia algumas requisições consideradas maliciosas pela maioria dos web application firewalls e baseado nas respostas enumera o que está sendo utilizado . Fiz um teste em um hosting que conheço que utiliza Imperva e o resultado foi perfeito.</p>
<p>Algumas das requisições maliciosas enviadas pelo mesmo :</p>
<p><em><strong>send: &#8216;GET /../../../../etc/passwd HTTP/1.1\r\nHost: www.domain.com\r\nAccept-Encoding: identity\r\nAccept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\r\nAccept: */*\r\nUser-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.1b1) Gecko/20081007 Firefox/3.0\r\n\r\n&#8217;</strong></em></p>
<p><em><strong>send: &#8216;GET / HTTP/1.1\r\nHost: www.domain.com\r\nAccept-Encoding: identity\r\nTransfer-Encoding: zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz&lt;RECORTADO&gt;\r\nAccept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\r\nAccept: */*\r\nUser-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.1b1) Gecko/20081007 Firefox/3.0\r\n\r\n&#8217;</strong></em></p>
<p><em><strong>send: &#8216;GET /cmd.exe HTTP/1.1\r\nHost: www.domain.com\r\nAccept-Encoding: identity\r\nAccept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7\r\nAccept: */*\r\nUser-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.1b1) Gecko/20081007 Firefox/3.0\r\n\r\n&#8217;<br />
</strong></em></p>
<p>s<em>pooker@notsecure:/LABS/waffit$ python wafw00f.py http://www.domain.com</em></p>
<p><em>WAFW00F &#8211; Web Application Firewall Detection Tool</em></p>
<p><em>By Sandro Gauci &amp;&amp; Wendel G. Henrique</em></p>
<p><em>Checking http://www.domain.com<br />
<strong> The site http://www.domain.com is behind a Imperva</strong><br />
Number of requests: 8<br />
spooker@notsecure:/LABS/waffit$</em></p>
<p>A ferramenta é bem interessante para ajudar no uso ou não de técnicas de evasion e não sei se existem números ainda quanto a eficácia da mesma em todas os WAFs listados mas certamente a ferramenta continua em crescimento e vamos aguarda o release 0.25 .</p>
<p>Links:</p>
<p><a href="http://waffit.googlecode.com/">http://waffit.googlecode.com/</a><br />
<a href="http://pentestit.com/2009/12/13/update-wafw00f-revision-24/">http://pentestit.com/2009/12/13/update-wafw00f-revision-24/</a></p>
<p>Aproveitando a equipe da N-Stalker gostaria de desejar <strong><span style="color: #ff0000;">Feliz Natal e Ótimo Ano Novo </span></strong>a todos que nos acompanham.</p>
<p>N-Stalker Team</p>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/cross-site-scripting-xss-twitter-wafw00f-release-0-24/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rational RequisitePro and Joomla multiple vulnerabilities</title>
		<link>http://community.nstalker.com/rational-requisitepro-and-joomla-vulnerabilities</link>
		<comments>http://community.nstalker.com/rational-requisitepro-and-joomla-vulnerabilities#comments</comments>
		<pubDate>Thu, 19 Nov 2009 23:05:31 +0000</pubDate>
		<dc:creator>N-Stalker Team</dc:creator>
				<category><![CDATA[N-Stalker Latest Updates]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=773</guid>
		<description><![CDATA[N-Stalker has made available its latest &#8220;N-Stealth Web Attack Database&#8221; update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.
If you need to contact us for additional instructions, go to N-Stalker&#8217;s Customer Center.
Important Note:  N-Stalker 2006 Version has been discontinued since March [...]]]></description>
			<content:encoded><![CDATA[<p>N-Stalker has made available its latest &#8220;N-Stealth Web Attack Database&#8221; update for all products, including N-Stalker 2009 and 2006 version.You should be able to automatically download it next time you execute N-Stalker Scanner.</p>
<p>If you need to contact us for additional instructions, go to <a href="https://customer.nstalker.com/cc/" target="_blank">N-Stalker&#8217;s Customer Center</a>.</p>
<p><strong>Important Note</strong>:  N-Stalker 2006 Version has been discontinued since March 31st, 2009. You must upgrade to N-Stalker 2009 to obtain our technical support.</p>
<p>This release includes patterns for the following vulnerabilities:</p>
<ul>
<li>Joomla! Ajax Chat Component 1.0 Ajcuser.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3822" target="_blank">CVE-2009-3822</a>]</li>
<li>Joomla! JD-WordPress Component 2.0 Wp-Feed.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4992" target="_blank">CVE-2006-4992</a>]</li>
<li>IBM Rational RequisitePro ReqWebHelp 7.10 SearchView.JSP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3730" target="_blank">CVE-2009-3730</a>]</li>
<li>IBM Rational RequisitePro ReqWebHelp 7.10 WorkingSet.JSP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3730" target="_blank">CVE-2009-3730</a>]</li>
<li>Snitz Forums 2000 3.4.7 Pop_Send_To_Friend.ASP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3730" target="_blank">CVE-2009-3730</a>]</li>
<li>Zainu 1.0 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3730" target="_blank">CVE-2009-3730</a>]</li>
<li>bloofoxCMS 0.3.5 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3730" target="_blank">CVE-2009-3730</a>]</li>
<li>Achievo 1.3.4 Dispatch.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2734" target="_blank">CVE-2009-2734</a>]</li>
<li>Achievo 1.3.4 Dispatch.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2733" target="_blank">CVE-2009-2733</a>]</li>
<li>Dream Poll 3.1 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2733" target="_blank">CVE-2009-2733</a>]</li>
<li>Dream Poll 3.1 Index.PHP Cross-Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2733" target="_blank">CVE-2009-2733</a>]</li>
<li>Docebo 3.6.3 Index.PHP WORD Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2733" target="_blank">CVE-2009-2733</a>]</li>
<li>Docebo 3.6.3 Index.PHP ID_CERTIFICATE Parameter SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2733" target="_blank">CVE-2009-2733</a>]</li>
<li>Joomla! Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2733" target="_blank">CVE-2009-2733</a>]</li>
<li>AIOCP 1.4.1 Cp_Html2xhtmlbasic.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3220" target="_blank">CVE-2009-3220</a>]</li>
<li>AfterLogic WebMail Pro 4.7.10 History-Storage.ASPX Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3220" target="_blank">CVE-2009-3220</a>]</li>
<li>Joomla! Soundset Component 1.0 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3644" target="_blank">CVE-2009-3644</a>]</li>
<li>X-Cart Email Subscription Home.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3592" target="_blank">CVE-2009-3592</a>]</li>
<li>Joomla! CB Resume Builder Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3645" target="_blank">CVE-2009-3645</a>]</li>
<li>Interspire Knowledge Manager 5.0 File_Manager.PHP Directory Traversal Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3645" target="_blank">CVE-2009-3645</a>]</li>
<li>Juniper Networks JUNOS J-Web 9.0R1.1 PATH_INFO Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3485" target="_blank">CVE-2009-3485</a>]</li>
<li>Juniper Networks JUNOS J-Web 9.0R1.1 Scripter.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3487" target="_blank">CVE-2009-3487</a>]</li>
<li>Juniper Networks JUNOS J-Web 9.0R1.1 JEXEC Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3487" target="_blank">CVE-2009-3487</a>]</li>
<li>Juniper Networks JUNOS J-Web 9.0R1.1 CONFIGURATION Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3487" target="_blank">CVE-2009-3487</a>]</li>
<li>Juniper Networks JUNOS J-Web 9.0R1.1 CONFIGURATION Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3486" target="_blank">CVE-2009-3486</a>]</li>
<li>Juniper Networks JUNOS J-Web 9.0R1.1 TRACEROUTE Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3486" target="_blank">CVE-2009-3486</a>]</li>
<li>Juniper Networks JUNOS J-Web 9.0R1.1 PINGHOST Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3486" target="_blank">CVE-2009-3486</a>]</li>
<li>e107 0.7.16 Search.PHP IN Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3486" target="_blank">CVE-2009-3486</a>]</li>
<li>e107 0.7.16 Search.PHP BE Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3486" target="_blank">CVE-2009-3486</a>]</li>
<li>e107 0.7.16 Search.PHP EP Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3486" target="_blank">CVE-2009-3486</a>]</li>
<li>e107 0.7.16 Search.PHP EX Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3486" target="_blank">CVE-2009-3486</a>]</li>
<li>Joomla! Fastball Component 1.2 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3443" target="_blank">CVE-2009-3443</a>]</li>
<li>OSSIM 2.1.1 Repository_Document.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3439  " target="_blank">CVE-2009-3439 </a>]</li>
<li>OSSIM 2.1.1 Repository_Links.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3439  " target="_blank">CVE-2009-3439 </a>]</li>
<li>OSSIM 2.1.1 Repository_Editdocument.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3439  " target="_blank">CVE-2009-3439 </a>]</li>
<li>OSSIM 2.1.1 Getpolicy.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3439  " target="_blank">CVE-2009-3439 </a>]</li>
<li>OSSIM 2.1.1 Newhostgroupform.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3439  " target="_blank">CVE-2009-3439 </a>]</li>
<li>OSSIM 2.1.1 Modifynetform.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3439  " target="_blank">CVE-2009-3439 </a>]</li>
<li>OSSIM 2.1.1 Index.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3440" target="_blank">CVE-2009-3440</a>]</li>
<li>Joomla!/Mambo Tupinambis Component 1.0 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3434" target="_blank">CVE-2009-3434</a>]</li>
<li>IBM Lotus Connections 2.0.1 SimpleSearch.Do Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3469" target="_blank">CVE-2009-3469</a>]</li>
<li>Vastal I-Tech Agent Zone View_Listing.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3497" target="_blank">CVE-2009-3497</a>]</li>
<li>Vastal I-Tech DVD Zone View_Mag.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3495" target="_blank">CVE-2009-3495</a>]</li>
<li>Vastal I-Tech DVD Zone View_Mag.PHP Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3496" target="_blank">CVE-2009-3496</a>]</li>
<li>Vastal I-Tech Cosmetics Zone View_Products.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3496" target="_blank">CVE-2009-3496</a>]</li>
<li>Vastal I-Tech MMORPG View_News.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3505" target="_blank">CVE-2009-3505</a>]</li>
<li>Joomla! JoomlaFacebook Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3438" target="_blank">CVE-2009-3438</a>]</li>
<li>Joomla! SportFusion Component 0.2.3 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3491" target="_blank">CVE-2009-3491</a>]</li>
<li>MaxWebPortal 1.365 Forum.ASP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3436" target="_blank">CVE-2009-3436</a>]</li>
<li>Joomla! Com_Jinc Component 0.2 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3334" target="_blank">CVE-2009-3334</a>]</li>
<li>Joomla! MyRemote Video Gallery 1.0 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3446" target="_blank">CVE-2009-3446</a>]</li>
<li>Joomla! Survey Manager Component 1.5 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3325" target="_blank">CVE-2009-3325</a>]</li>
<li>Joomla! JBudgetsMagic 0.4 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3332" target="_blank">CVE-2009-3332</a>]</li>
<li>eFront 3.5.4 Database.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3332" target="_blank">CVE-2009-3332</a>]</li>
<li>Xerver Administration Interface 4.32 CURRENTPATH Parameter Cross Site Scripting Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3562" target="_blank">CVE-2009-3562</a>]</li>
<li>Zainu 1.0 Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3310" target="_blank">CVE-2009-3310</a>]</li>
<li>Com_Koesubmit Mambo/Joomla! Component 1.0 Koesubmit.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3333" target="_blank">CVE-2009-3333</a>]</li>
<li>JForJoomla JReservation Joomla! Component Index.PHP SQL Injection Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3316" target="_blank">CVE-2009-3316</a>]</li>
<li>OpenSiteAdmin 0.9.7 PageHeader.PHP Remote File Include Vulnerability &#8211; [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3317" target="_blank">CVE-2009-3317</a>]</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/rational-requisitepro-and-joomla-vulnerabilities/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Brazilian Blackout – Our comments on &#8220;The true about blackout post&#8221;</title>
		<link>http://community.nstalker.com/brazilian-blackout-%e2%80%93-our-comments-on-the-true-about-blackout-post</link>
		<comments>http://community.nstalker.com/brazilian-blackout-%e2%80%93-our-comments-on-the-true-about-blackout-post#comments</comments>
		<pubDate>Thu, 19 Nov 2009 13:41:57 +0000</pubDate>
		<dc:creator>Sp0oKeR</dc:creator>
				<category><![CDATA[N-Stalker's Team Blog]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=770</guid>
		<description><![CDATA[Much has been spoken last week about reasons for the great blackout occurred on November 10th, 2009. The Brazilian government has reported atmospheric problems as its main cause but it was quite a coincidence that a CBS 60-minute report had been broadcasted, informing that the Brazilian power grid system was vulnerable to hacker attacks.
To make [...]]]></description>
			<content:encoded><![CDATA[<p>Much has been spoken last week about reasons for the great blackout occurred on November 10th, 2009. The Brazilian government has reported atmospheric problems as its main cause but it was quite a coincidence that a CBS 60-minute report had been broadcasted, informing that the Brazilian power grid system was vulnerable to hacker attacks.</p>
<p>To make reasons for blackout even more confused, Maycon Vitali, security researcher and professor at UVV in Vila Velha, Espirito Santo State, Brazil, has issued a post without blog  (pt_BR <a href="http://blog.hacknroll.com/2009/11/12/a-verdade-sobre-o-apagao/">http://blog.hacknroll.com/2009/11/12/a-verdade-sobre-o-apagao/</a>) demonstrating flaws in web security in the ONS site (Brazil’s National Operating System)  through which he received thousands of accesses to post which has been heavily commented in the web community, posted in big media vehicles like infoexame, G1, e Band among others, with many referenced made to such post on personal blogs and twitter.</p>
<p>We believe that many people have wrongly analyzed the contents of such post as well as a great (and unnecessary) hullabaloo has been made about this matter.</p>
<p>Below we will comment on such post and some erroneous interpretations.</p>
<p>Firstly, it has been comment about robots.txt in the ONS site:</p>
<p><strong><em><br />
What’s robots.txt?</em></strong></p>
<p>As the name says, it is a file in txt format that works as a filter for crawlers, enabling webmasters to control access permissions to specific points in the sites. The robots.txt controls which information item from a site should (or should not) be indexed by the browsing sites. File syntax is very simple and should be placed by the webmaster responsible for the site in the roots of hosting.</p>
<p>In the case of the mentioned robots.txt, it blocks any user-agent that is performing crawler action and in two directories:</p>
<p><strong><em>User-agent: *<br />
Disallow: /agentes/agentes.aspx<br />
Disallow: /download/agentes/</em></strong></p>
<p>By accessing the site in the directories that should not be indexed in the browsers we noticed in the links (for some applications like citrix) a web system where the post in the blog was originated.</p>
<p>Based on the post it reports he says that he tried to access an application in the presented list and in the login he tried to use simple inverted commas, thus causing the result below:<br />
<em><strong><br />
&#8220;[IfxException: ERROR [HY000] [Informix .NET provider]General error.] IBM.Data.Informix.IfxConnection.HandleError(IntPtr hHandle, SQL_HANDLE hType, RETCODE retcode) +27 IBM.Data.Informix.IfxCommand.ExecuteReaderObject(CommandBehavior behavior, String method) +739 IBM.Data.Informix.IfxCommand.ExecuteReader(CommandBehavior behavior) +104 IBM.Data.Informix.IfxCommand.ExecuteReader() +48 OnsClasses.OnsData.OnsCommand.ExecuteReader() IntUnica.Menu.btnOk_Click(Object sender, ImageClickEventArgs e) System.Web.UI.WebControls.ImageButton.OnClick(ImageClickEventArgs e) +109 System.Web.UI.WebControls.ImageButton.System.Web.UI.IPostBackEventHandler.RaisePostBackEvent(String eventArgument) +69 System.Web.UI.Page.RaisePostBackEvent(IPostBackEventHandler sourceControl, String eventArgument) +18 System.Web.UI.Page.RaisePostBackEvent(NameValueCollection postData) +33 System.Web.UI.Page.ProcessRequestMain() +1292&#8243;</strong></em></p>
<p>As I mentioned in mailling lists and in comments with friends that based on post and error message showed WE CANNOT STATE that there is a SQL injection in the application as it was only an exception (stack) that had been printed on the screen and it would thus be an “A6- Information Leakage and Improper Error Handling” failure. Logically, if we analyze statistics about this type of error, the majority will lead us to find the SQL Injection itself as being an Informix error. Logically, if we check statistics on this type of error, the majority will lead us to find the SQL injection itself as being an Informix error. To find the truth it would be necessary to accomplish tests, what would be illegal as we do not have authorization for such..</p>
<p><em><strong>What would be an A6-  Information Leakage and Improper Error Handling failure?</strong></em></p>
<p>Several applications may, unintentionally, leak information about their configurations, internal functioning or violate privacy through several problems. Applications can leak their internal functioning via response time to execute specific process or different responses for diverse entries, like displaying same error message but with different error codes. Web Applications will frequently leak information about their internal functioning through detailed error messages or debug. Frequently, these information items can be the path to launch attacks or even more powerful tools.</p>
<p><em><strong>Conclusions:</strong></em></p>
<p>-Access to agents cannot be regarded as a failure since robots.txt are globally used so that information cannot be indexed in the searchs as google, yahoo  but, when dealing with applications, it would be a best practice to place an access password in the directory /agents/.</p>
<p>- A stack error or inadequate error handling does not mean that the site has some SQL Injection vulnerability in the application, however, one may notice that data input sanitization has not been accomplished.</p>
<p>- We do not know what can be found inside the applications, what gives no reason for such hullabaloo in case a SQL Injection is confirmed to have some relation with the big blackout.</p>
<p>-Internally there they must have perimeter defense tools, stronger authentication engines, but, as informed, such information is based only on assumptions.</p>
<p>-The Brazilian Government should invest more in web security in its environments and logically make use of Web Vulnerability Analysis tools as well as use Web Application Firewall (WAF) and also develop internally a Secure Development LifeCycle (SDLC).</p>
<p>N-Stalker Team</p>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/brazilian-blackout-%e2%80%93-our-comments-on-the-true-about-blackout-post/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apagão &#8211; Relato sobre possível falha web gerou mídia</title>
		<link>http://community.nstalker.com/apagao-relato-sobre-possivel-falha-web-gerou-midia</link>
		<comments>http://community.nstalker.com/apagao-relato-sobre-possivel-falha-web-gerou-midia#comments</comments>
		<pubDate>Mon, 16 Nov 2009 11:30:50 +0000</pubDate>
		<dc:creator>Sp0oKeR</dc:creator>
				<category><![CDATA[N-Stalker's Team Blog]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=762</guid>
		<description><![CDATA[
Muito se falou nessa semana sobre os motivos do apagão ocorrido no dia 10 de novembro de 2009. O governo comentou sobre problemas atmosféricos, mas foi muita coincidência o apagão e a matéria do programa 60 minutes da CBS falando que o sistema elétrico brasileiro estaria vulnerável a ataques de hackers.

Para tumultuar ainda mais o [...]]]></description>
			<content:encoded><![CDATA[<p><!-- 		@page { margin: 2cm } 		P { margin-bottom: 0.21cm } --></p>
<p style="margin-bottom: 0.49cm;">Muito se falou nessa semana sobre os motivos do apagão ocorrido no dia 10 de novembro de 2009. O governo comentou sobre problemas atmosféricos, mas foi muita coincidência o apagão e a matéria do programa <em>60 minutes</em> da CBS falando que o sistema elétrico brasileiro estaria vulnerável a ataques de <em>hackers</em>.</p>
<p><!-- 		@page { margin: 2cm } 		P { margin-bottom: 0.21cm } 		A:link { color: #0000ff } --></p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">Para tumultuar ainda mais o assunto, Maycon Vitali, pesquisador de segurança e professor na UVV em Vilha Velha no Espírito Santo, fez um <em>post</em> em seu <em>blog</em> (<span style="color: #0000ff;"><span style="text-decoration: underline;"><a href="http://blog.hacknroll.com/2009/11/12/a-verdade-sobre-o-apagao/">http://blog.hacknroll.com/2009/11/12/a-verdade-sobre-o-apagao/</a></span></span>) demonstrando falhas de segurança <em>web</em> no <em>site</em> do ONS &#8211; Operador Nacional do Sistema.</p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">O <em>post </em>obteve dezena de milhares de acessos, sendo muito comentado pela comunidade, postado em grandes mídias como InfoExame, G1, eBand e diversas referências ao <em>post</em> em <em>blogs</em> pessoais e perfis do twitter .</p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">Acreditamos que muitos fizeram análise errada do <em>post</em> bem como um alarde muito grande e desnecessário. Abaixo faremos os comentários sobre o <em>post</em> e sobre algumas interpretações errôneas.</p>
<p>Primeiramente foi comentado do robots.txt no site da ONS.</p>
<p><strong>O que é o robots.txt ?</strong></p>
<p>Como o próprio nome já diz, é um arquivo no formato txt que funciona como um filtro para os Crawlers, fazendo com que webmasters possam controlar permissões de acesso a determinados pontos dos sites. O robots.txt controla qual informação de um site deve ou não deve ser indexado pelos sites de busca. A sintaxe do arquivo é bem simples, e deve ser colocada pelo webmaster responsável pelo site na raíz da hospedagem.</p>
<p>No caso do robots.txt citado ele bloqueia qualquer user-agent que façam crawlers e em dois diretórios</p>
<p><em>User-agent: *<br />
Disallow: /agentes/agentes.aspx<br />
Disallow: /download/agentes/</em></p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">Acessando esses diretórios que não deveriam ser indexados pelos buscadores, reparamos nos <em>links</em> para algumas aplicações, tais como Citrix.</p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">Baseado no <em>post</em> o autor diz que tentou acessar uma das aplicações listadas e digitou nos campos de usuário e senha o caractere de aspas simples (‘) que resultou no seguinte:</p>
<p><em>&#8220;[IfxException: ERROR [HY000] [Informix .NET provider]General error.] IBM.Data.Informix.IfxConnection.HandleError(IntPtr hHandle, SQL_HANDLE hType, RETCODE retcode) +27 IBM.Data.Informix.IfxCommand.ExecuteReaderObject(CommandBehavior behavior, String method) +739 IBM.Data.Informix.IfxCommand.ExecuteReader(CommandBehavior behavior) +104 IBM.Data.Informix.IfxCommand.ExecuteReader() +48 OnsClasses.OnsData.OnsCommand.ExecuteReader() IntUnica.Menu.btnOk_Click(Object sender, ImageClickEventArgs e) System.Web.UI.WebControls.ImageButton.OnClick(ImageClickEventArgs e) +109 System.Web.UI.WebControls.ImageButton.System.Web.UI.IPostBackEventHandler.RaisePostBackEvent(String eventArgument) +69 System.Web.UI.Page.RaisePostBackEvent(IPostBackEventHandler sourceControl, String eventArgument) +18 System.Web.UI.Page.RaisePostBackEvent(NameValueCollection postData) +33 System.Web.UI.Page.ProcessRequestMain() +1292&#8243;</em></p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">Conforme citei em listas de distribuição e em comentários com amigos; baseado no <em>post</em> e na mensagem de erro NÃO se pode afirmar que existe um <em>SQL Injection</em> na aplicação visto que foi somente um <em>exception</em> que foi impressa na tela, o que caracteriza a seguinte vulnerabilidade de acordo com o Guia TOP 10 do OWASP: A6 – Vazamento de Informações e Tratamento de erros inapropriado. Logicamente se pegarmos estatísticas desse tipo de erro a maioria leva a encontrar <em>SQL Injection</em>, levando em conta que o problema se manifestou num banco de dados Informix. Para descobrir a vulnerabilidade de <em>SQL Injection</em> teriam que ser feitos testes, o que é ilegal visto que não temos autorização para isso.</p>
<p><strong>O que seria uma falha &#8220;A6 – Vazamento de Informações e Tratamento de erros inapropriado&#8221; ?</strong></p>
<p>Diversas aplicações podem sem intenção vazar informações sobre suas configurações, funcionamento interno, ou violar privacidade através de diversos problemas. Aplicações podem vazar o funcionamento interno via tempo de resposta para executar determinados processos ou respostas diferentes para entradas diversas, como exibindo mesma mensagem de erro mas com código de erros diferentes. Aplicações Web freqüentemente vazarão informações sobre seu duncionamento interno através de mensagens de erros detalhadas ou debug. Freqüentemente, essa informação pode ser o caminho para lançar ataques ou ferramentas automáticas mais poderosas.</p>
<p><strong>Conclusões:</strong></p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">- O acesso ao diretório escondido /agentes não pode ser considerado uma falha, pois o arquivo robots.txt é globalmente utilizado para informações não serem indexadas nos buscadores. Porém, como se trata de aplicações <em>web</em> críticas seria uma melhor prática colocar senha de acesso ao diretório /agentes, e qualquer outro diretório que contenha <em>links </em>para aplicações críticas.</p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">- Um erro de <em>stack</em> ou manipulação inapropriada de erro não quer dizer que o <em>site</em> possui alguma vulnerabilidade de <em>SQL Injection</em> na aplicação, porém nota-se que a mesma não faz sanitização de entrada e saída de dados.</p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">- Não sabemos exatamente o que se encontra dentro das aplicações ou o que ela executa, portanto mesmo se um <em>SQL Injection</em> fosse confirmado, não teríamos certeza qual a relação desse ataque com o apagão.</p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">- Internamente deve existir segmentação, ferramentas de defesa de perímetro, mecanismos mais fortes de autenticação, mas como citado essas informações são baseadas em deduções.</p>
<p style="margin-top: 0.49cm; margin-bottom: 0.49cm;">- O governo brasileiro deveria investir mais em segurança <em>web</em> em seus ambientes e logicamente, além de utilizar ferramentas de análise de vulnerabilidades <em>web,</em> também fazer uso de <em>WAF</em> &#8211; <em>Web Application Firewall</em> e desenvolver internamente um SDLC – <em>Software Development Life Cycle</em>, com elementos de segurança que envolvam todo o ciclo.</p>
<p><strong>Referências</strong></p>
<p><a href="http://www.seomarketing.com.br/robots.txt.html">http://www.seomarketing.com.br/robots.txt.html</a><br />
<a href="http://info.abril.com.br/noticias/seguranca/hacker-aponta-falhas-no-sistema-de-energia-13112009-6.shl"> http://info.abril.com.br/noticias/seguranca/hacker-aponta-falhas-no-sistema-de-energia-13112009-6.shl</a><br />
<a href="http://www.owasp.org/images/4/42/OWASP_TOP_10_2007_PT-BR.pdf"> http://www.owasp.org/images/4/42/OWASP_TOP_10_2007_PT-BR.pdf</a><br />
<a href="http://blog.hacknroll.com/2009/11/12/a-verdade-sobre-o-apagao/"> http://blog.hacknroll.com/2009/11/12/a-verdade-sobre-o-apagao/</a></p>
<p>N-Stalker Team</p>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/apagao-relato-sobre-possivel-falha-web-gerou-midia/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Relato sobre AppSec Brasil 2009</title>
		<link>http://community.nstalker.com/relato-sobre-appsec-brasil-2009</link>
		<comments>http://community.nstalker.com/relato-sobre-appsec-brasil-2009#comments</comments>
		<pubDate>Thu, 05 Nov 2009 17:04:25 +0000</pubDate>
		<dc:creator>Sp0oKeR</dc:creator>
				<category><![CDATA[N-Stalker's Team Blog]]></category>

		<guid isPermaLink="false">http://community.nstalker.com/?p=759</guid>
		<description><![CDATA[Aqui estamos após AppSec2009 que aconteceu em Brasília nos dias 27 a 30.
O evento teve algumas mudanças na grade visto 3 casos de gripe suina que impossibilitaram os palestrantes virem para o Brasil mas os mesmo foram substituidos por palestrantes de altissimo nivel.
O congresso foi bem interessante , revi amigos, conheci novos profissionais, coffee break [...]]]></description>
			<content:encoded><![CDATA[<p>Aqui estamos após AppSec2009 que aconteceu em Brasília nos dias 27 a 30.</p>
<p>O evento teve algumas mudanças na grade visto 3 casos de gripe suina que impossibilitaram os palestrantes virem para o Brasil mas os mesmo foram substituidos por palestrantes de altissimo nivel.</p>
<p>O congresso foi bem interessante , revi amigos, conheci novos profissionais, coffee break excelente, o auditório muito bom e confortável. Acredito que os únicos problemas que tiveram e até já foram discutidos previamente a conferência foram: entrada sem custos o que faz muitos se inscreverem e na hora poucos realmente vão e por ser em Brasilia dificulta um pouco a viagem para a maioria dos profissionais que está em São Paulo . Foi o primeiro evento, realmente muito bom e os próximos certamente serão melhores , como diz o ditado, &#8220;a prática leva a perfeição&#8221; . Tivemos em média 150 participantes por dia o que é um excelente número para uma primeira edição .</p>
<p>Abaixo relatarei algumas palestras :</p>
<p><strong>- Abertura </strong></p>
<p>A abertura foi bem a moda governo, bem formal, presença de Deputados, Membros OWASP, professores da UNB. A conversa inicial foi interessante, deputado, professores da UNB pareceram estar interessado no OWASP e segurança web.</p>
<p>Um comentário legal do Diniz foi que pela primeira vez o OWASP estava tão próximo ao governo e achava que isso no futuro poderia dar bons frutos .</p>
<p>- Sobre o OWASP (Diniz Cruz)</p>
<p>Ele comentou alguns números bem interessantes do OWASP que teve inicio em 2001, instituição sem fins lucrativos e que atualmente conta com 6464 usuários, 21 milhões de page view mes, 10 mil inscritos nas listas de e-mail.</p>
<p>Algo que ele sempre salienta é que embora seja patrocinado por varias empresas da area o OWASP não é influenciado por fabricantes.</p>
<p>Atualmente possuem um podcast que já tem 45 edições e videos da conferencia no owasp.tv</p>
<p><strong>- Gary McGraw Keynote Speaker</strong></p>
<p>Inicialmente uma palavra pra definir ele SHOWMAN . Simplesmente ele deu uma palestra de quase 2 horas onde você nem percebe o tempo, totalmente descontraido, engraçado , simplesmente otima escolha de Keynote.</p>
<p>Na sua palestra ele comentou sobre seu recente projeto no OWASP chamado BSIMM.  O projeto nasceu de amostra/metricas coletadas de 9 grandes desenvolvedores de softwares no mercado como google, microsoft, adobe. A idéia é criar um Software Security Framework nos quais atualmente temos MS SDL, OWASP CLASP, OpenSAMM .</p>
<p>Ele valorizou muito o projeto falando que as metricas foram geradas a partir de um mundo real (observações) , de grandes empresas de sucesso e que não tinha falsas estatisticas. Algo que ele comentou foi que para pequenas empresas não saberia se funcionaria ainda visto que o inicio foi baseada em grandes players.</p>
<p>Mais info:<a href="http://bsi-mm.com"> http://bsi-mm.com</a></p>
<p><strong>- Brian Contos</strong></p>
<p>A palestra dele foi interessante pois comentou de profiling de websites, monitoramento de banco de dados porque uso de blacklist é falho. Muitos criticam o WAF pois ele não resolve o problema do codigo mas muitas vezes o codigo é um legado antigo, code freezing no final de ano, virtual patching até corrigirem entre tantos outras ocasiões .</p>
<p><strong>- Optimizing Security Spending using OWASP (Matt)</strong></p>
<p>Nessa apresentação ele ilustrou exemplos de um banco no qual o mesmo gastava uma boa quantia anual com testes de aplicações web, code review entre outros fatores. Nela ele comentou de projetos legais que podem mitigar gastos das empresas, automatizar processos e especialmente cortar gastos.</p>
<p>Sinceramente achei alguns pontos BEM interessantes mas os numeros mostrados acho que não condizem muito com uma realidade visto que em 1 ano eles mudaram da terceirizacao para testes internos  . Mas realmente as ideias, projetos apresentados sao de grande valia.</p>
<p>Comentou sobre os projetos que ele considera ser os melhores como WebGoat, WebScarab, Testing Guide v3 , OWASP LiveCD (do qual ele é o leader do projeto). Algo que achei legal que o mesmo apresentou foi sobre uma extensão para HTTP chamada OpenPGP Extension. Pesquisarei e testarei mais sobre ela no futuro .</p>
<p><strong>- SQL Injection (Ulysses)</strong></p>
<p>O The Bug apresentou tecnicas e metodos de SQL Injections no MySQL com demos bem interessantes. A palestra foi legal pois saiu um pouco do teorico e caiu 100% mão na massa .</p>
<p><strong>- Exploiting Online Games (McGraw)</strong></p>
<p>Devido os problemas de alguns palestrantes internacionais com a gripe suina o McGraw entrou em cena novamente falando de Exploiting Online Games no qual acredito ser um mercado mais americano (eu desconheço o mundo de games nacional) mas ele citou numeros expressivos o que torna a exploração de games online bem interessante no ponto de vista malicioso. Alguns números citados por ele:</p>
<p>- Cliente de Game com 2 gb de tamanho (opa, certamente temos falhas ai)<br />
- 10 milhoes de games inscritos no site WoW .</p>
<p>Algo que ele salientou e é bem interessante são que explorando games  a maioria dos usuário são leigos em segurança, sao pessoas normais o que aumenta mais ainda quem fornece os jogos online.</p>
<p>E pra finalizar ele sempre fazendo showtime =)</p>
<p>Tivemos outras palestras interessantes, algumas não assiste por conversas de corredor que sempre são bem produtivas.</p>
<p>Para quem se interessou o material do evento pode ser acessado no link <a href="http://www.owasp.org/index.php/AppSec_Brasil_2009_(pt-br)#tab=Arquivos_das_Apresenta.C3.A7.C3.B5es">http://www.owasp.org/index.php/AppSec_Brasil_2009_(pt-br)#tab=Arquivos_das_Apresenta.C3.A7.C3.B5es</a></p>
<p>No final do evento foi comunicado que o próximo AppSec Brasil será realizado no CPqD em campinas e os preparativos já começarão em breve.</p>
<p>AppSec Brasil é um grande avanço no Brasil pois segurança web é algo muito novo para maioria das empresas e ações como essas certamente ajudarão muito o amadurecimento do mercado nacional .</p>
<p>Nós vemos por ai!</p>
<p>N-Stalker Team</p>
]]></content:encoded>
			<wfw:commentRss>http://community.nstalker.com/relato-sobre-appsec-brasil-2009/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
