<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The HP Security Laboratory Blog - All Comments</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/default.aspx</link><description>HP Application Security Center blogs and forums covering all aspects of Web Application Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>re: Take your %00 and shove it</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/04/take-your-00-and-shove-it.aspx#108517</link><pubDate>Fri, 06 Nov 2009 21:46:04 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108517</guid><dc:creator>matt wood</dc:creator><description>&lt;p&gt;@Jericho. Absolutely, the results from google code are not guaranteed to be vulns. However its a pretty good way to find poor design decisions that use language API&amp;#39;s insecurely. &lt;/p&gt;
&lt;p&gt;So if your interested, as we were, about the most common ways developers fall prey to LFI, searching code is pretty helpful. Even if each specific search result isn&amp;#39;t a vuln, the usage pattern is probably repeated plenty of times.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108517" width="1" height="1"&gt;</description></item><item><title>Social comments and analytics for this post</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/05/hp-security-center-penetration-testing-job-posting.aspx#108508</link><pubDate>Fri, 06 Nov 2009 07:24:35 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108508</guid><dc:creator>uberVU - social comments</dc:creator><description>&lt;p&gt;This post was mentioned on Twitter by HP_AppSecurity: HP Security Center seeking to hire a Pen Tester...details and application information are available at &lt;a rel="nofollow" target="_new" href="http://bit.ly/1nSjoQ"&gt;http://bit.ly/1nSjoQ&lt;/a&gt; #jobs #security&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108508" width="1" height="1"&gt;</description></item><item><title>re: Take your %00 and shove it</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/04/take-your-00-and-shove-it.aspx#108498</link><pubDate>Wed, 04 Nov 2009 20:03:35 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108498</guid><dc:creator>Jericho</dc:creator><description>&lt;p&gt;Beware of the &amp;quot;grep and gripe&amp;quot; approach. This is why there are dozens of &amp;#39;myth/fake&amp;#39; entries in OSVDB.org. It&amp;#39;s easy to search for vulnerabilities with grep, but they are not always straight-forward. &lt;/p&gt;
&lt;p&gt;Searching GoogleCode for vulnerabilities when it came out a while back, showed that searches for &amp;quot;vulnerability&amp;quot; or &amp;quot;security&amp;quot; could find interesting things as developers would comment their code.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108498" width="1" height="1"&gt;</description></item><item><title>re: %3c has always been a friend of mine</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/3c-has-always-a-friend-of-mine.aspx#108494</link><pubDate>Tue, 03 Nov 2009 17:34:55 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108494</guid><dc:creator>Martin Hall</dc:creator><description>&lt;p&gt;%22 &lt;/p&gt;
&lt;p&gt;%2b&lt;/p&gt;
&lt;p&gt;(those two can help in bypassing the basic aspx bracket filters).&lt;/p&gt;
&lt;p&gt;Also some others of note &lt;/p&gt;
&lt;p&gt;%00 &lt;/p&gt;
&lt;p&gt;and anything else that html can&amp;#39;t usually render. &lt;/p&gt;
&lt;p&gt;for example XML will have issues attempting to render &lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Most DB&amp;#39;s can handle those but if the site takes the input from the DB unchecked it will fail at render time. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108494" width="1" height="1"&gt;</description></item><item><title>Social comments and analytics for this post</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/26/top-five-web-application-vulnerabilities-10-12-09-10-25-09.aspx#108468</link><pubDate>Tue, 27 Oct 2009 10:06:24 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108468</guid><dc:creator>uberVU - social comments</dc:creator><description>&lt;p&gt;This post was mentioned on Twitter by HP_AppSecurity: Top Five Web Application Vulnerabilities 10/12/09 - 10/25/09: &lt;a rel="nofollow" target="_new" href="http://bit.ly/2KWTyV"&gt;http://bit.ly/2KWTyV&lt;/a&gt; #security #web&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108468" width="1" height="1"&gt;</description></item><item><title>re: How to clean up a hacked WordPress installation</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/09/what-to-do-when-your-wordpress-is-hacked.aspx#108399</link><pubDate>Thu, 15 Oct 2009 04:12:46 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108399</guid><dc:creator>sd speicherkarten</dc:creator><description>&lt;p&gt;Very nice post bro, I hope you could have posted it lill before to help me out of this situation… lol&lt;/p&gt;
&lt;p&gt;Anyhow, I am sure it will be very helpful to some else who is stucked in such situation. Thanks for the useful post&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108399" width="1" height="1"&gt;</description></item><item><title>re: 24 Hour Live Hacking Challenge</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/02/24-hour-live-hacking-challenge.aspx#108373</link><pubDate>Mon, 12 Oct 2009 04:22:05 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108373</guid><dc:creator>whips04r</dc:creator><description>&lt;p&gt;Gah! I swear I did try debug as a GET parameter name, guess I forgot to check the HTML source :( Went so far as to install FirePHP ontop of FireBug with the hope that&amp;#39;d turn debug mode on. I hate you guys for making such a secure challenge :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108373" width="1" height="1"&gt;</description></item><item><title>re: 24 Hour Live Hacking Challenge</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/02/24-hour-live-hacking-challenge.aspx#108363</link><pubDate>Fri, 09 Oct 2009 19:53:19 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108363</guid><dc:creator>matt wood</dc:creator><description>&lt;p&gt;In order to pass the 8th level, you had a view the source code and read the HTML comments. The comments suggested there was a debug mode, the intuition here would have been to try requesting the page with some kind of debug mode enabled. This turned out to be enabled by just requesting the page with a query parameter named debug.&lt;/p&gt;
&lt;p&gt;Unfortunately for your attempts to exploit the email system... the email address was only recorded once, the other times it was just kinda ignored :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108363" width="1" height="1"&gt;</description></item><item><title>re: 24 Hour Live Hacking Challenge</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/02/24-hour-live-hacking-challenge.aspx#108358</link><pubDate>Fri, 09 Oct 2009 00:06:38 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108358</guid><dc:creator>whips04r</dc:creator><description>&lt;p&gt;Am really interested to know how one would pass level 8! I saw a few peeps got it but all my attempts were in vain :( I had to resort to exploiting (seemingly existent) logic flaws in the scoring functionality whereby I hopefully overwrote the email address of some winners - am still waiting to receive my prize :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108358" width="1" height="1"&gt;</description></item><item><title>re: Microsoft's ClickOnce Firefox add-on</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/22/the-sneaky-ms-clickonce-firefox-add-on.aspx#108328</link><pubDate>Sun, 04 Oct 2009 09:56:47 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108328</guid><dc:creator>Roberto</dc:creator><description>&lt;p&gt;cool blog&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108328" width="1" height="1"&gt;</description></item><item><title>re: %3c has always been a friend of mine</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/3c-has-always-a-friend-of-mine.aspx#108221</link><pubDate>Fri, 02 Oct 2009 08:58:31 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108221</guid><dc:creator>MichaelSchratt</dc:creator><description>&lt;p&gt;Do not forget %25 :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108221" width="1" height="1"&gt;</description></item><item><title>re: How to clean up a hacked WordPress installation</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/09/what-to-do-when-your-wordpress-is-hacked.aspx#107984</link><pubDate>Thu, 01 Oct 2009 09:32:11 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:107984</guid><dc:creator>lilikindsli</dc:creator><description>&lt;p&gt;dzbXi0 I want to say - thank you for this!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=107984" width="1" height="1"&gt;</description></item><item><title>re: HTML 5 Form Tags a Risk?</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/html-5-form-tags-a-risk.aspx#107965</link><pubDate>Thu, 01 Oct 2009 07:26:37 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:107965</guid><dc:creator>lilikindsli</dc:creator><description>&lt;p&gt;V3gbAY I want to say - thank you for this!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=107965" width="1" height="1"&gt;</description></item><item><title>re: Is your .svn showing (like 3300 other sites)?</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/24/is-your-svn-showing-like-3320-other-sites.aspx#107841</link><pubDate>Wed, 30 Sep 2009 14:20:04 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:107841</guid><dc:creator>lilikindsli</dc:creator><description>&lt;p&gt;aYHkm4 I want to say - thank you for this!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=107841" width="1" height="1"&gt;</description></item><item><title>re: Two Emerging Trends in Web Application Security</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2006/04/27/33.aspx#107816</link><pubDate>Wed, 30 Sep 2009 10:49:26 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:107816</guid><dc:creator>software developers</dc:creator><description>&lt;p&gt;Humm... interesting,&lt;/p&gt;
&lt;p&gt;It is great that new technologies, exist on both client and server sides. &lt;/p&gt;
&lt;p&gt;Thanks for writing about it&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=107816" width="1" height="1"&gt;</description></item></channel></rss>