<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security on blag</title><link>https://blog.beford.org/categories/security/</link><description>Recent content in Security on blag</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 13 Mar 2013 16:38:45 +0000</lastBuildDate><atom:link href="https://blog.beford.org/categories/security/index.xml" rel="self" type="application/rss+xml"/><item><title>iCloud Cross Site Scripting</title><link>https://blog.beford.org/2013/03/13/icloud-cross-site-scripting/</link><pubDate>Wed, 13 Mar 2013 16:38:33 +0000</pubDate><guid>https://blog.beford.org/2013/03/13/icloud-cross-site-scripting/</guid><description>&lt;p&gt;&lt;a href="https://blog.beford.org/wp-content/uploads/2013/03/icloud.png"&gt;&lt;img alt="icloud" loading="lazy" src="https://blog.beford.org/wp-content/uploads/2013/03/icloud.png"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;iCloud Cross Site in the subject of email messages fixed by apple and &lt;a href="http://support.apple.com/kb/HT1318"&gt;acknowledged here.&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Defcon 20 - CTF Prequals</title><link>https://blog.beford.org/2012/06/04/defcon-20-ctf-prequals/</link><pubDate>Mon, 04 Jun 2012 04:50:27 +0000</pubDate><guid>https://blog.beford.org/2012/06/04/defcon-20-ctf-prequals/</guid><description>&lt;p&gt;&lt;a href="http://null-life.com"&gt;Null Life&lt;/a&gt; 1800 puntos! Lugar 49 de 303 equipos.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://blog.beford.org/wp-content/uploads/2012/06/defcon20.png"&gt;&lt;img loading="lazy" src="https://blog.beford.org/wp-content/uploads/2012/06/defcon20.png" title="defcon20"&gt;&lt;/a&gt;&lt;/p&gt;</description></item><item><title>YUT Codegate 2012 CTF</title><link>https://blog.beford.org/2012/02/26/yut-codegate-2012-ctf/</link><pubDate>Sun, 26 Feb 2012 20:33:46 +0000</pubDate><guid>https://blog.beford.org/2012/02/26/yut-codegate-2012-ctf/</guid><description>&lt;p&gt;&lt;a href="https://blog.beford.org/wp-content/uploads/2012/02/codegate_banner.png"&gt;&lt;img loading="lazy" src="https://blog.beford.org/wp-content/uploads/2012/02/codegate_banner.png" title="codegate_banner"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Este viernes 24 de febrero empezó el Codegate 2012. Logramos terminar en el lugar número 38 de 182 equipos, como siempre ningún equipo de latinoamerica por encima de nosotros :). El equipo no estuvo completo, &lt;a href="http://sinfocol.org"&gt;Daniel&lt;/a&gt; solo participó un par de horas y yo tampoco hice gran cosa, la mayor parte del trabajo fue por &lt;a href="https://twitter.com/#!/marceloje"&gt;emyei&lt;/a&gt; y &lt;a href="https://twitter.com/#!/_g05u_"&gt;gosu&lt;/a&gt;. Nuestro scoreboard al final del evento fue:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://blog.beford.org/wp-content/uploads/2012/02/scoreboard.png"&gt;&lt;img loading="lazy" src="https://blog.beford.org/wp-content/uploads/2012/02/scoreboard.png" title="scoreboard"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Se nos escaparon un par de retos que ya teniamos &lt;em&gt;&lt;strong&gt;casi&lt;/strong&gt;&lt;/em&gt; resueltos pero bueno, para una proxima oportunidad será.  El rank final lo pueden ver a continuación:&lt;/p&gt;</description></item><item><title>CSAW 2011 - Reversing - Python 200</title><link>https://blog.beford.org/2011/09/26/csaw-2011-reversing-python-200/</link><pubDate>Mon, 26 Sep 2011 06:43:41 +0000</pubDate><guid>https://blog.beford.org/2011/09/26/csaw-2011-reversing-python-200/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Python - 200 Points&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;nc csawctf.poly.edu 53080&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When we connected to the port it was running a service Haderper:&lt;/p&gt;
&lt;pre tabindex="0"&gt;&lt;code&gt;-----------------------------
| Welcome to Haderper! |
| Please enter your command |
-----------------------------
&amp;gt; help
Haderper v0.1-alpha
Command help:
help - this screen
exec - execute a command
derp - derp a string
underp - underp a string
logout/exit - disconnect
&amp;gt; derp hi
UydoaScKcDAKLg==
&amp;gt; underp UydoaScKcDAKLg==
hi
&amp;gt;
&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;If we decode the base64 string we can see that it looks like a Pickle dump file:&lt;/p&gt;</description></item><item><title>Hack.lu 2011 CTF - Scotty's last signal Solution</title><link>https://blog.beford.org/2011/09/21/hack-lu-2011-ctf-scottys-last-signal-solution/</link><pubDate>Wed, 21 Sep 2011 22:41:26 +0000</pubDate><guid>https://blog.beford.org/2011/09/21/hack-lu-2011-ctf-scottys-last-signal-solution/</guid><description>&lt;p&gt;Challenge summary:&lt;/p&gt;
&lt;blockquote&gt;
&lt;h1 id="scottys-last-signal"&gt;Scotty&amp;rsquo;s last signal&lt;/h1&gt;
&lt;p&gt;You might have heard about Montgomery Scott, the legendary chief engineer of the U.S.S. Enterprise. What you probably did not know is his passion for Video Games - especially really old classics. We recently lost contact with his transport shuttle and we think you should examine this old game file we recently recieved because he might have just put a message into there. This would make sense if he could not send a fully blown Space-Unicode message signal to avoid attracting any Borg ships in the sector&amp;hellip; (Borg usually are very bad at video games) His passion for Beaming and Warping might be of interest for your analysis. &lt;a href="https://ctf.hack.lu/files/mario"&gt;https://ctf.hack.lu/files/mario&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Campus Party Valencia 2011 - Premio ESET</title><link>https://blog.beford.org/2011/09/15/campus-party-valencia-2011-premio-eset/</link><pubDate>Thu, 15 Sep 2011 06:31:22 +0000</pubDate><guid>https://blog.beford.org/2011/09/15/campus-party-valencia-2011-premio-eset/</guid><description>&lt;p&gt;Esta publicación la tenia pendiente hace casi un mes, desde que recibí el premio entregado por ESET a nuestro equipo &lt;a href="http://null-life.com"&gt;NULL Life&lt;/a&gt; por haber logrado finalizar de primeros el &lt;a href="http://www.securitybydefault.com/2011/01/wargame-sbd-i.html"&gt;WGSBD2&lt;/a&gt; organizado para Campus Party España.  Ya se ha publicado una recopilación de las &lt;a href="http://www.securitybydefault.com/2011/08/recopilacion-de-soluciones-para-las.html"&gt;soluciones WGSBD2&lt;/a&gt; para los que esten interesados.&lt;/p&gt;
&lt;p&gt;Las categorias del wargame fueron las siguientes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Trivial&lt;/li&gt;
&lt;li&gt;Networking&lt;/li&gt;
&lt;li&gt;Binarios&lt;/li&gt;
&lt;li&gt;Crypto&lt;/li&gt;
&lt;li&gt;Web&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Agradecimientos a &lt;a href="http://www.securitybydefault.com/"&gt;Security By Default&lt;/a&gt; por un excelente Wargame, a &lt;a href="http://www.campus-party.es/"&gt;Campus Party España&lt;/a&gt;, y por ultimo, pero no menos importante, &lt;a href="http://www.eset.es"&gt;ESET&lt;/a&gt; por patrocinar este tipo de eventos. Sin más preambulo el unboxing del premio, una Macbook Pro 15&amp;quot; (con ESET Cybersecurity) otorgada por ESET.&lt;/p&gt;</description></item><item><title>WGSBD2 - Campus Party Valencia 2011</title><link>https://blog.beford.org/2011/07/17/wgsbd2-campus-party-valencia-2011/</link><pubDate>Sun, 17 Jul 2011 07:48:10 +0000</pubDate><guid>https://blog.beford.org/2011/07/17/wgsbd2-campus-party-valencia-2011/</guid><description>&lt;p&gt;Nuestro equipo NULL Life participó en el CTF de &lt;a href="http://securitybydefault.com/"&gt;SecurityByDefault.com&lt;/a&gt; y logró finalizar de primero todos los retos, ademas de obtener el primer lugar por puntos al finalizar el evento :D&lt;/p&gt;
&lt;p&gt;Los miembros del equipo que participaron &lt;a href="http://sinfocol.org" title="Seguridad Informatica"&gt;Daniel&lt;/a&gt; (Colombia), &lt;a href="http://g30rg3x.com/"&gt;g30rg3_x&lt;/a&gt; (Mexico), g05u (Perú), emyei (Argentina), Perverths0 (Perú) y snr33 (Perú). Brillo por su ausencia nuestro CISSP, CEH fataku por motivos de su trabajo, o eso dice el xD&lt;/p&gt;
&lt;p&gt;Por cierto, esta entrada va desde el iPad obtenida en el CTF de Campus Party Colombia, me la entregaron el dia de ayer, y ya le estamos dando un buen uso. Este ha sido un buen año para NULL Life :D&lt;/p&gt;</description></item><item><title>CTF Campus Party 2011 Colombia</title><link>https://blog.beford.org/2011/07/08/ctf-campus-party-2011-colombia/</link><pubDate>Fri, 08 Jul 2011 21:44:47 +0000</pubDate><guid>https://blog.beford.org/2011/07/08/ctf-campus-party-2011-colombia/</guid><description>&lt;p&gt;Este año representé a &lt;a href="http://null-life.com" title="null-life team"&gt;NULL-Life&lt;/a&gt; en el CTF de Campus Party Colombia, logré obtener el primer lugar, el premio fue un magico iPad 2 :D (que aún no me han entregado, pero la paciencia es la virtud de todo pentester). Les dejo el &lt;a href="http://beford.net/stuff/WriteUpCampusPartyCo2011.pdf"&gt;writeup&lt;/a&gt; para que vean la dificultad y solucion de todos los retos.&lt;/p&gt;
&lt;p&gt;La próxima semana viene el CTF de Campus Party Valencia, en el cual podremos participar como equipo :D&lt;/p&gt;</description></item><item><title>PlaidCTF 2011 - Division is HARD!!</title><link>https://blog.beford.org/2011/04/28/plaidctf-2011-division-is-hard/</link><pubDate>Thu, 28 Apr 2011 18:04:33 +0000</pubDate><guid>https://blog.beford.org/2011/04/28/plaidctf-2011-division-is-hard/</guid><description>&lt;p&gt;Esta vez participamos en el PlaidCTF, organizado por el Plaid Parlament of Pwning. Muchos retos, casi 40 para resolverlos en 2 dias, y con una dificultad considerable.&lt;/p&gt;
&lt;p&gt;Obtuvimos la posicion numero 42 con NULL Life, aunque nos faltaba un miembro importante del equipo. Nos ubicamos por encima de los otros equipos Colombianos, el ultimo dia del ctf el equipo RICTeam nos logro empatar, pero teniamos un As bajo la manga y los pudimos dejar abajo faltando 5 minutos para terminar el CTF cuando ya poco podian hacer. Pueden ver la &lt;a href="http://www.plaidctf.com/scoreboard"&gt;tabla de posiciones&lt;/a&gt; completa en el &lt;a href="http://www.plaidctf.com/"&gt;sitio de plaidctf&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Firefox 3.6.19 Remote Code Execution</title><link>https://blog.beford.org/2011/04/15/firefox-3-6-19-remote-code-execution/</link><pubDate>Fri, 15 Apr 2011 06:32:08 +0000</pubDate><guid>https://blog.beford.org/2011/04/15/firefox-3-6-19-remote-code-execution/</guid><description>&lt;p&gt;&lt;a href="https://blog.beford.org/wp-content/uploads/2011/04/minefield-icon.png"&gt;&lt;img loading="lazy" src="https://blog.beford.org/wp-content/uploads/2011/04/minefield-icon.png" title="minefield-icon"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;To be disclosed soon.&lt;/p&gt;</description></item><item><title>Nuit Du Hack 2011 Prequals</title><link>https://blog.beford.org/2011/04/11/nuit-du-hack-2011-prequals/</link><pubDate>Mon, 11 Apr 2011 04:32:22 +0000</pubDate><guid>https://blog.beford.org/2011/04/11/nuit-du-hack-2011-prequals/</guid><description>&lt;p&gt;Nuestro equipo NULL Life participó hace un par de semanas en los prequal de CTF Nuit Du Hack. Logramos finalizar en la posición número 12. Este es el ranking final de los prequals:&lt;/p&gt;
&lt;p&gt;&lt;a href="https://blog.beford.org/wp-content/uploads/2011/04/Screenshot.png"&gt;&lt;img alt="Nuit du Hack Prequals 2011" loading="lazy" src="https://blog.beford.org/wp-content/uploads/2011/04/Screenshot.png" title="Nuit du Hack "&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Entre los equipos que conozco de este top, esta el equipo fail0verflow, es el grupo que encontró la falla de criptografía en el PS3 :D! holy cactus son los mismos de int3pids, Leet More, smoked chicken y Rdot.Org equipos rusos con bastante potencial.&lt;/p&gt;</description></item><item><title>Codegate 2011 CTF</title><link>https://blog.beford.org/2011/03/06/codegate-2011-ctf/</link><pubDate>Sun, 06 Mar 2011 21:33:26 +0000</pubDate><guid>https://blog.beford.org/2011/03/06/codegate-2011-ctf/</guid><description>&lt;p&gt;Este año lo inauguramos con el CTF de Codegate,  retos que nos pusieron a trasnochar dos dias seguidos, pero el resultado no estuvo mal :D  nuestro equipo NULL-Life logro quedar en la posicion 30 de 178 equipos. Observando el resto del ranking, fuimos el primer equipo de latinos, seguidos por un equipo Argentino, KchoTeam en el lugar 69, y otro equipo Colombiano, RICTeam en el lugar 92.&lt;/p&gt;
&lt;p&gt;Estos fueron los retos que logramos pasar:&lt;/p&gt;</description></item><item><title>padocon ctf 2011</title><link>https://blog.beford.org/2011/01/20/padocon-ctf-2011/</link><pubDate>Thu, 20 Jan 2011 17:44:59 +0000</pubDate><guid>https://blog.beford.org/2011/01/20/padocon-ctf-2011/</guid><description>&lt;p&gt;Esta vez nuestro equipo *NULL Labs logro la posicion 19 de un total de 351 equipos registrados. Todavia nos falta bastante :) Daniel publicara los writeups pronto.&lt;/p&gt;
&lt;p&gt;Me parecio extrano no ver a int3pids en el top pero creo que ellos se enfocaron mas en el ctf de secbydefault.&lt;/p&gt;
&lt;p&gt;No pudimos hacer nada para el ctf de securitybydefault por falta de tiempo, pero bueno a quien se le ocurre hacer dos ctf el mismo fin de semana :P&lt;/p&gt;</description></item><item><title>Cosas que pasan</title><link>https://blog.beford.org/2008/11/02/cosas-que-pasan/</link><pubDate>Sun, 02 Nov 2008 06:56:25 +0000</pubDate><guid>https://blog.beford.org/2008/11/02/cosas-que-pasan/</guid><description>&lt;p&gt;El mmg de Hades publico esto antes que yo, un XSS en live mail, estaba almacenado en /stuff hace tiempo ya, es un simple poc, que muestra los contactos.  Fue reportado a Microsoft hace casi 1 mes, recibi un correo diciendo que ya habrian creado un reporte interno, donde se encargarian del asunto.&lt;/p&gt;
&lt;p&gt;POC: &lt;a href="http://beford.org/stuff/live.htm"&gt;http://beford.org/stuff/live.htm&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Y otra cosa interesante que encontre, es algo en la &lt;a href="http://m.google.com"&gt;interface movil de google&lt;/a&gt;, en la seccion para configurar el idioma, el parametro continue, recibe la ruta donde se encontraba el usuario, para poder retornarlo alli una vez seleccione el idioma. Aparentemente no estan haciendo una concatenacion de &amp;rsquo;m.google.com/&amp;rsquo; + continue sino de &amp;rsquo;m.google.com&amp;rsquo; + continue. Pasandole a continue un valor de &amp;lsquo;.otrodominio.com&amp;rsquo; hariamos que todos los enlaces apunten a un sitio externo fuera de google.&lt;/p&gt;</description></item><item><title>Gmail Cross Site Scripting</title><link>https://blog.beford.org/2008/05/04/gmail-cross-site-scripting/</link><pubDate>Sun, 04 May 2008 01:40:13 +0000</pubDate><guid>https://blog.beford.org/2008/05/04/gmail-cross-site-scripting/</guid><description>&lt;p&gt;El dia de hoy les traigo un pequeño descubrimiento, una vulnerabilidad en el sistema de Presentaciones (para los burros, powerpoint) en linea de Google Mail. El problema es sencillo, y no le tomara mucho tiempo arreglar a los de Mountain View, pero hay algo que me preocupa más. Describire el problema de Gmail rapidamente para poder pasar al detalle del plugin de flash.&lt;/p&gt;
&lt;p&gt;Google Slideshows no esta filtrando los hipervinculos de las presentaciones cuyo destino es una URI javascript:, con solo crear un simple enlace, colocarle como destino &lt;em&gt;javascript:alert(1)&lt;/em&gt; e insertarlo en la presentacion, es posible ejecutar javascript en el contexto de mail.google.com. Para los que quieran verlo en funcionamiento he preparado un sencillo poc que envia las cookies a un sitio remoto (que no existe), tendrian que enviarse &lt;a href="http://beford.org/stuff/mozilla.ppt"&gt;este archivo&lt;/a&gt; por correo, y luego verlo en modo de Presentacion desde Gmail.&lt;/p&gt;</description></item><item><title>Security Bookmarklets</title><link>https://blog.beford.org/2008/01/28/security-bookmarklets/</link><pubDate>Mon, 28 Jan 2008 23:47:57 +0000</pubDate><guid>https://blog.beford.org/2008/01/28/security-bookmarklets/</guid><description>&lt;p&gt;I took a couple of days from my school vacation to write 3 bookmarklets that will help me when auditing web sites, I&amp;rsquo;d like to share them here because I know that they&amp;rsquo;ll help some of my friends, and probably one of the two readers of this blog.&lt;/p&gt;
&lt;p&gt;[Text2SQLChar](javascript:(function(){ x=prompt(&amp;lsquo;Input text:&amp;rsquo;,&amp;rsquo;&amp;rsquo;);l=x.length;t=x.charCodeAt(0);for (i = 1;i&amp;lt;l;i++) t = t +&amp;rsquo;,&amp;rsquo;+x.charCodeAt(i);prompt(&amp;lsquo;Output: &amp;lsquo;, &amp;lsquo;Char(&amp;rsquo;+t+&amp;rsquo;)&amp;rsquo;); })();) Converts an string into a CHAR() mysql, usefull when magic_quotes is on.&lt;br&gt;
[SQLIncrement](javascript:(function(){url=decodeURI(location);if (url.indexOf(&amp;lsquo;select 1&amp;rsquo;)==-1) { alert(&amp;lsquo;Inject a simple 'union select 1' first.&amp;rsquo;);return; }max=url.substring(url.indexOf(&amp;lsquo;select 1&amp;rsquo;)).split(&amp;rsquo;,&amp;rsquo;).length;if (max&amp;gt;1) zx = (max-1)+&amp;rsquo;,&amp;rsquo;+max; else zx = &amp;lsquo;select 1&amp;rsquo;;tmp=url.indexOf(zx);location=encodeURI(url.substring(0, tmp+zx.length)+&amp;rsquo;,&amp;rsquo;+(max+1)+url.substring(tmp+zx.length));})()) Increments automatically the number of columns of the injected select query.&lt;br&gt;
[SQLDecrement](javascript:(function(){url=decodeURI(location);if (url.indexOf(&amp;lsquo;select 1&amp;rsquo;)==-1) { alert(&amp;lsquo;Inject a simple 'union select 1' first.&amp;rsquo;);return; }max=url.substring(url.indexOf(&amp;lsquo;select 1&amp;rsquo;)).split(&amp;rsquo;,&amp;rsquo;).length;if (max&amp;gt;2) zx = (max-2)+&amp;rsquo;,&amp;rsquo;+(max-1); else { if (max==2) zx=&amp;lsquo;select 1&amp;rsquo;; else return; } tmp=url.indexOf(zx);dx = &amp;lsquo;,&amp;rsquo;+max;location=encodeURI(url.substring(0, tmp+zx.length)+url.substring(tmp+zx.length+dx.length));})()) Decrements automatically the number of columns of the injected select query.&lt;br&gt;
[Increment](javascript:(function(){ var e,s; IB=1; function isDigit(c) { return (&amp;lsquo;0&amp;rsquo; &amp;lt;= c &amp;amp;&amp;amp; c &amp;lt;= &amp;lsquo;9&amp;rsquo;) } L = decodeURI(location.href); LL = L.length; for (e=LL-1; e&amp;gt;=0; &amp;ndash;e) if (isDigit(L.charAt(e))) { for(s=e-1; s&amp;gt;=0; &amp;ndash;s) if (!isDigit(L.charAt(s))) break; break; } ++s; if (e&amp;lt;0) return; oldNum = L.substring(s,e+1); newNum = &amp;rsquo;&amp;rsquo; + (parseInt(oldNum,10) + IB); while (newNum.length &amp;lt; oldNum.length) newNum = &amp;lsquo;0&amp;rsquo; + newNum; location.href = L.substring(0,s) + newNum + L.slice(e+1); })();) Allows you to navigate up html files or images that have a number in them.&lt;br&gt;
[Decrement](javascript:(function(){ var e,s; IB=-1; function isDigit(c) { return (&amp;lsquo;0&amp;rsquo; &amp;lt;= c &amp;amp;&amp;amp; c &amp;lt;= &amp;lsquo;9&amp;rsquo;) } L = decodeURI(location.href); LL = L.length; for (e=LL-1; e&amp;gt;=0; &amp;ndash;e) if (isDigit(L.charAt(e))) { for(s=e-1; s&amp;gt;=0; &amp;ndash;s) if (!isDigit(L.charAt(s))) break; break; } ++s; if (e&amp;lt;0) return; oldNum = L.substring(s,e+1); newNum = &amp;rsquo;&amp;rsquo; + (parseInt(oldNum,10) + IB); while (newNum.length &amp;lt; oldNum.length) newNum = &amp;lsquo;0&amp;rsquo; + newNum; location.href = L.substring(0,s) + newNum + L.slice(e+1); })();) Allows you to navigate down html files or images that have a number in them.&lt;br&gt;
&lt;a href="javascript:(function()%7Bx=prompt('Text:','');l=x.length%3;if(l)for(i=1;i%3C7-l;i++)x=x+'%20';;prompt('Output:',window.btoa(x));%7D)();"&gt;base64&lt;/a&gt; Firefox only, base64 with no padding&lt;/p&gt;</description></item><item><title>Firefox 2.0.0.10 released</title><link>https://blog.beford.org/2007/11/27/firefox-20010-released/</link><pubDate>Tue, 27 Nov 2007 05:40:52 +0000</pubDate><guid>https://blog.beford.org/2007/11/27/firefox-20010-released/</guid><description>&lt;p&gt;Mozilla Corporation just released &lt;a href="http://www.mozilla-europe.org/es/products/firefox/2.0.0.10/releasenotes/"&gt;Firefox 2.0.0.10&lt;/a&gt; which includes fixes against &lt;a href="https://blog.beford.org/2007/11/10/firefox-jar-protocol-vulnerability/"&gt;JAR uri attacks&lt;/a&gt;. This issue affected browsers that used Gecko engine, a quick check showed me that only &lt;a href="http://kmeleon.sourceforge.net/"&gt;K-meleon&lt;/a&gt; browser was also updated, however there are several Gecko based web browsers that need to get fixed: &lt;a href="http://en.wikipedia.org/wiki/List_of_web_browsers#Gecko-based_browsers"&gt;Gecko-based browsers.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Update:&lt;/strong&gt; Let&amp;rsquo;s make that, Firefox 2.0.0.11, which also fixes some regressions.&lt;/p&gt;</description></item><item><title>Google Gadgets XSS (IE6/Opera)</title><link>https://blog.beford.org/2007/11/25/google-gadgets-xss-ie6/</link><pubDate>Sun, 25 Nov 2007 09:58:23 +0000</pubDate><guid>https://blog.beford.org/2007/11/25/google-gadgets-xss-ie6/</guid><description>&lt;p&gt;There is a recent discussion on &lt;a href="http://ha.ckers.org/blog/20071119/google-gadgets-gaffe/"&gt;ha.ckers.org&lt;/a&gt; regarding a possible CSRF that could allow an attacker to inject an evil gadget on someobdy else&amp;rsquo;s iGoogle page. After checking the format of the &lt;a href="http://ha.ckers.org/asdf2.xml"&gt;xml file&lt;/a&gt; used to define the gadgets properties, I noticed a couple of attributes that could be used as point of injections to active content, the &lt;strong&gt;thumbnail&lt;/strong&gt; and &lt;strong&gt;screenshot&lt;/strong&gt; attribute. Only one of them is vulnerable, the screenshot attribute, by using a javascript URI as value you can execute active content on certain browsers such as IE6. This is a poc that shows an alert with the current document.domain value:&lt;/p&gt;</description></item><item><title>Firefox jar: Protocol Vulnerability</title><link>https://blog.beford.org/2007/11/10/firefox-jar-protocol-vulnerability/</link><pubDate>Sat, 10 Nov 2007 10:47:45 +0000</pubDate><guid>https://blog.beford.org/2007/11/10/firefox-jar-protocol-vulnerability/</guid><description>&lt;p&gt;I just came across pdp&amp;rsquo;s finding &lt;a href="http://www.gnucitizen.org/blog/web-mayhem-firefoxs-jar-protocol-issues"&gt;jar protocol vulnerability&lt;/a&gt; on Mozilla Firefox, I think its a big issue, and the fact that it has been on &lt;a href="https://bugzilla.mozilla.org/show_bug.cgi?id=369814"&gt;bugzilla (#369814)&lt;/a&gt; for way more than &lt;a href="http://ha.ckers.org/blog/20070803/mozilla-says-ten-fucking-days/"&gt;ten fuck*ng days&lt;/a&gt; is not a good thing.&lt;/p&gt;
&lt;p&gt;According to pdp, this issue makes vulnerable to Cross-site scripting applications that allow users uploading compressed ZIP, and JAR files. After a couple of minutes messing around the poc&amp;rsquo;s, I figured out that sites with open redirect issues are vulnerable too. I&amp;rsquo;ve created this poc that attacks Gmail, it&amp;rsquo;s based on my previous post and it will only show your contacts list, it&amp;rsquo;s not being logged server side or anything (as some people thought that my previous poc did. Credit to &lt;a href="http://lowtechlive.com/"&gt;tx&lt;/a&gt; for discovering the &lt;a href="http://sla.ckers.org/forum/read.php?3,505,10958#msg-10958"&gt;open redirect issue&lt;/a&gt; used to exploit Google / Firefox):&lt;/p&gt;</description></item><item><title>Google Vulnerability</title><link>https://blog.beford.org/2007/09/24/googlecom-cross-site-scripting-vulnerability/</link><pubDate>Mon, 24 Sep 2007 03:29:26 +0000</pubDate><guid>https://blog.beford.org/2007/09/24/googlecom-cross-site-scripting-vulnerability/</guid><description>&lt;p&gt;Yesterday, I found a new Google.com XSS vulnerability that can be abused to steal information from Gmail accounts, I&amp;rsquo;ve done responsible disclosure of at least 3 vulns to Google, but since I haven&amp;rsquo;t got enough &amp;lsquo;motivation&amp;rsquo;, I&amp;rsquo;ll go full disclosure now.&lt;/p&gt;
&lt;p&gt;The vulnerability exists in Blogspot polls feature, I had already disclosed a vulnerability on this system. The &amp;lsquo;font&amp;rsquo; parameter was not being sanitized before being used inside an STYLE tag, so you could inject IE&amp;rsquo;s expression() and Mozilla&amp;rsquo;s -moz-binding. They fixed it, however they didn&amp;rsquo;t check enough the rest of the code, the new XSS is:&lt;/p&gt;</description></item></channel></rss>