<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://www.communities.hp.com/securitysoftware/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The HP Security Laboratory Blog - All Comments</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/default.aspx</link><description>HP Application Security Center blogs and forums covering all aspects of Web Application Security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><item><title>re: SSLv3/TLS Renegotiation Stream Injection</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/16/ssl-tls-renegotiation-content-injection.aspx#108541</link><pubDate>Mon, 16 Nov 2009 16:44:54 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108541</guid><dc:creator>chris sullo</dc:creator><description>&lt;p&gt;Twitter usernames &amp;amp; passwords were gathered via this bug in a real-world exploit.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.securityfocus.com/news/11564?ref=rss"&gt;www.securityfocus.com/.../11564&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108541" width="1" height="1"&gt;</description></item><item><title>re: Take your %00 and shove it</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/04/take-your-00-and-shove-it.aspx#108533</link><pubDate>Wed, 11 Nov 2009 18:32:24 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108533</guid><dc:creator>Jeff Williams</dc:creator><description>&lt;p&gt;For Java, you can try the SafeFile class available in the ESAPI library, which prevents null-byte injection.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108533" width="1" height="1"&gt;</description></item><item><title>re: WebInspect Tips: Changing settings to improve scans</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/28/webinspect-tips-changing-settings-to-improve-scans.aspx#108527</link><pubDate>Mon, 09 Nov 2009 21:33:27 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108527</guid><dc:creator>todd.densmore</dc:creator><description>&lt;p&gt;@Varun&lt;/p&gt;
&lt;p&gt;Can you give me more details about your problem? Does your IT department require a connection through a proxy? Step 4 of the Scan Wizard allows the configuration of a web proxy, which might be needed in your case. If you need more general WebInspect support, please feel free to call our support hotline:&lt;/p&gt;
&lt;p&gt;1. Call 1-800-633-3600. &lt;/p&gt;
&lt;p&gt;2. Select option #2 for Software. &lt;/p&gt;
&lt;p&gt;3. Enter your SAID (Service Agreement ID) followed by #. &lt;/p&gt;
&lt;p&gt;4. Select option #1 for Enterprise Application Software. &lt;/p&gt;
&lt;p&gt;5. Select option #5 for Application Security Center&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108527" width="1" height="1"&gt;</description></item><item><title>re: WebInspect Tips: Changing settings to improve scans</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/28/webinspect-tips-changing-settings-to-improve-scans.aspx#108521</link><pubDate>Mon, 09 Nov 2009 01:22:57 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108521</guid><dc:creator>whips04r</dc:creator><description>&lt;p&gt;Man Farsi ra sohbet khardoom ;)&lt;/p&gt;
&lt;p&gt;Always wise to ommitt the Form/Field that changes an Account&amp;#39;s password from the FormValues File. Using the default FormValues is always a risky thing to do, I never do it on Production. And keep in mind the &amp;#39;Default&amp;#39; value will be used for any field that isn&amp;#39;t specified within the file!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108521" width="1" height="1"&gt;</description></item><item><title>re: HP Application Security Center at OWASP DC 11/11-13</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/03/hp-application-security-center-at-owasp-dc-11-11-13.aspx#108518</link><pubDate>Sat, 07 Nov 2009 06:59:48 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108518</guid><dc:creator>E-Learning in Information Security</dc:creator><description>&lt;p&gt;Thanks for the great information.&lt;/p&gt;
&lt;p&gt;I really enjoy reading your blog, it is very useful for us.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108518" width="1" height="1"&gt;</description></item><item><title>re: Take your %00 and shove it</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/04/take-your-00-and-shove-it.aspx#108517</link><pubDate>Fri, 06 Nov 2009 21:46:04 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108517</guid><dc:creator>matt wood</dc:creator><description>&lt;p&gt;@Jericho. Absolutely, the results from google code are not guaranteed to be vulns. However its a pretty good way to find poor design decisions that use language API&amp;#39;s insecurely. &lt;/p&gt;
&lt;p&gt;So if your interested, as we were, about the most common ways developers fall prey to LFI, searching code is pretty helpful. Even if each specific search result isn&amp;#39;t a vuln, the usage pattern is probably repeated plenty of times.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108517" width="1" height="1"&gt;</description></item><item><title>re: WebInspect Tips: Changing settings to improve scans</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/28/webinspect-tips-changing-settings-to-improve-scans.aspx#108510</link><pubDate>Fri, 06 Nov 2009 09:37:36 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108510</guid><dc:creator>varun.asok@oracle.com</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;i&amp;#39;m getting an error while using this web inspect. its an intranet site ssl based. the error which i&amp;#39;m getting is &amp;quot;The request was canceled by Web Proxy&amp;quot;. Wat is the proxy should i set. ?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108510" width="1" height="1"&gt;</description></item><item><title>Social comments and analytics for this post</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/05/hp-security-center-penetration-testing-job-posting.aspx#108508</link><pubDate>Fri, 06 Nov 2009 07:24:35 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108508</guid><dc:creator>uberVU - social comments</dc:creator><description>&lt;p&gt;This post was mentioned on Twitter by HP_AppSecurity: HP Security Center seeking to hire a Pen Tester...details and application information are available at &lt;a rel="nofollow" target="_new" href="http://bit.ly/1nSjoQ"&gt;http://bit.ly/1nSjoQ&lt;/a&gt; #jobs #security&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108508" width="1" height="1"&gt;</description></item><item><title>re: Take your %00 and shove it</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/11/04/take-your-00-and-shove-it.aspx#108498</link><pubDate>Wed, 04 Nov 2009 20:03:35 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108498</guid><dc:creator>Jericho</dc:creator><description>&lt;p&gt;Beware of the &amp;quot;grep and gripe&amp;quot; approach. This is why there are dozens of &amp;#39;myth/fake&amp;#39; entries in OSVDB.org. It&amp;#39;s easy to search for vulnerabilities with grep, but they are not always straight-forward. &lt;/p&gt;
&lt;p&gt;Searching GoogleCode for vulnerabilities when it came out a while back, showed that searches for &amp;quot;vulnerability&amp;quot; or &amp;quot;security&amp;quot; could find interesting things as developers would comment their code.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108498" width="1" height="1"&gt;</description></item><item><title>re: %3c has always been a friend of mine</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/17/3c-has-always-a-friend-of-mine.aspx#108494</link><pubDate>Tue, 03 Nov 2009 17:34:55 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108494</guid><dc:creator>Martin Hall</dc:creator><description>&lt;p&gt;%22 &lt;/p&gt;
&lt;p&gt;%2b&lt;/p&gt;
&lt;p&gt;(those two can help in bypassing the basic aspx bracket filters).&lt;/p&gt;
&lt;p&gt;Also some others of note &lt;/p&gt;
&lt;p&gt;%00 &lt;/p&gt;
&lt;p&gt;and anything else that html can&amp;#39;t usually render. &lt;/p&gt;
&lt;p&gt;for example XML will have issues attempting to render &lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;Most DB&amp;#39;s can handle those but if the site takes the input from the DB unchecked it will fail at render time. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108494" width="1" height="1"&gt;</description></item><item><title>Social comments and analytics for this post</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/10/26/top-five-web-application-vulnerabilities-10-12-09-10-25-09.aspx#108468</link><pubDate>Tue, 27 Oct 2009 10:06:24 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108468</guid><dc:creator>uberVU - social comments</dc:creator><description>&lt;p&gt;This post was mentioned on Twitter by HP_AppSecurity: Top Five Web Application Vulnerabilities 10/12/09 - 10/25/09: &lt;a rel="nofollow" target="_new" href="http://bit.ly/2KWTyV"&gt;http://bit.ly/2KWTyV&lt;/a&gt; #security #web&lt;/p&gt;
&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108468" width="1" height="1"&gt;</description></item><item><title>re: How to clean up a hacked WordPress installation</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/09/what-to-do-when-your-wordpress-is-hacked.aspx#108399</link><pubDate>Thu, 15 Oct 2009 04:12:46 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108399</guid><dc:creator>sd speicherkarten</dc:creator><description>&lt;p&gt;Very nice post bro, I hope you could have posted it lill before to help me out of this situation… lol&lt;/p&gt;
&lt;p&gt;Anyhow, I am sure it will be very helpful to some else who is stucked in such situation. Thanks for the useful post&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108399" width="1" height="1"&gt;</description></item><item><title>re: 24 Hour Live Hacking Challenge</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/02/24-hour-live-hacking-challenge.aspx#108373</link><pubDate>Mon, 12 Oct 2009 04:22:05 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108373</guid><dc:creator>whips04r</dc:creator><description>&lt;p&gt;Gah! I swear I did try debug as a GET parameter name, guess I forgot to check the HTML source :( Went so far as to install FirePHP ontop of FireBug with the hope that&amp;#39;d turn debug mode on. I hate you guys for making such a secure challenge :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108373" width="1" height="1"&gt;</description></item><item><title>re: 24 Hour Live Hacking Challenge</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/02/24-hour-live-hacking-challenge.aspx#108363</link><pubDate>Fri, 09 Oct 2009 19:53:19 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108363</guid><dc:creator>matt wood</dc:creator><description>&lt;p&gt;In order to pass the 8th level, you had a view the source code and read the HTML comments. The comments suggested there was a debug mode, the intuition here would have been to try requesting the page with some kind of debug mode enabled. This turned out to be enabled by just requesting the page with a query parameter named debug.&lt;/p&gt;
&lt;p&gt;Unfortunately for your attempts to exploit the email system... the email address was only recorded once, the other times it was just kinda ignored :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108363" width="1" height="1"&gt;</description></item><item><title>re: 24 Hour Live Hacking Challenge</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/09/02/24-hour-live-hacking-challenge.aspx#108358</link><pubDate>Fri, 09 Oct 2009 00:06:38 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:108358</guid><dc:creator>whips04r</dc:creator><description>&lt;p&gt;Am really interested to know how one would pass level 8! I saw a few peeps got it but all my attempts were in vain :( I had to resort to exploiting (seemingly existent) logic flaws in the scoring functionality whereby I hopefully overwrote the email address of some winners - am still waiting to receive my prize :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=108358" width="1" height="1"&gt;</description></item></channel></rss>