<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>David Sopas</title>
	<atom:link href="http://www.davidsopas.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.davidsopas.com</link>
	<description>testing</description>
	<lastBuildDate>Tue, 11 Aug 2009 19:22:36 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Wordpress 2.8.3 admin exploit</title>
		<link>http://www.davidsopas.com/2009/08/11/wordpress-2-8-3-admin-exploit/</link>
		<comments>http://www.davidsopas.com/2009/08/11/wordpress-2-8-3-admin-exploit/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 19:22:36 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=290</guid>
		<description><![CDATA[It&#8217;s possible for a malicious user reset admin password on latest version Wordpress 2.8.3. Check out explanation here, patch here and exploit here.
]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s possible for a malicious user reset admin password on latest version Wordpress 2.8.3. Check out explanation <a href="http://blogs.zdnet.com/security/?p=4002" target="_blank">here</a>, patch <a href="http://core.trac.wordpress.org/changeset/11798" target="_blank">here</a> and exploit <a href="http://www.milw0rm.com/exploits/9410" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/08/11/wordpress-2-8-3-admin-exploit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8.3 is out</title>
		<link>http://www.davidsopas.com/2009/08/04/wordpress-2-8-3-is-out/</link>
		<comments>http://www.davidsopas.com/2009/08/04/wordpress-2-8-3-is-out/#comments</comments>
		<pubDate>Tue, 04 Aug 2009 20:57:46 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[security updates]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=288</guid>
		<description><![CDATA[Wordpress fixes latest security problems, download it now.
]]></description>
			<content:encoded><![CDATA[<p>Wordpress fixes latest security problems, <a href="http://wordpress.org/download/" target="_blank">download it now</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/08/04/wordpress-2-8-3-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IXXO Cart! Standalone and Joomla Component SQL Injection</title>
		<link>http://www.davidsopas.com/2009/07/25/ixxo-cart-standalone-and-joomla-component-sql-injection/</link>
		<comments>http://www.davidsopas.com/2009/07/25/ixxo-cart-standalone-and-joomla-component-sql-injection/#comments</comments>
		<pubDate>Sat, 25 Jul 2009 09:23:36 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[ixxo cart]]></category>
		<category><![CDATA[joomla]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=285</guid>
		<description><![CDATA[Ref. [DSF-03-2009] – IXXO Cart! Standalone and Joomla Component SQL Injection
Vendor: IXXO Internet Solutions
Status: Patched by vendor
IXXO Cart!
IXXO Cart is an extremely powerful php shopping cart and web site builder application. Designed from a marketing perspective, this ecommerce application is feature-packed, robust, scalable and easy to use. IXXO Cart Plus is the clear choice for [...]]]></description>
			<content:encoded><![CDATA[<p>Ref. [DSF-03-2009] – IXXO Cart! Standalone and Joomla Component SQL Injection<br />
Vendor: <a href="http://www.php-shop-system.com/" target="_blank">IXXO Internet Solutions</a><br />
Status: Patched by vendor</p>
<p><strong>IXXO Cart!</strong><br />
<em>IXXO Cart is an extremely powerful php shopping cart and web site builder application. Designed from a marketing perspective, this ecommerce application is feature-packed, robust, scalable and easy to use. IXXO Cart Plus is the clear choice for serious merchants focused on rapidly and cost effectively deploying, managing and growing a successful web-based business.<br />
New users appreciate the easy-to-use tools designed to help set up their store quickly and effectively while experienced users love the ability to customize and manage our software to meet the needs of their growing business.</em></p>
<p><strong>Description</strong><br />
This very known PHP store is vulnerable to SQL Injection on &#8220;parent&#8221; variable.<br />
Injecting a specific combination of SQL commands will execute the new SQL query and even provide sensitive database information that could help a malicious user to complete and enter a valid SQL injection query.</p>
<p><strong>Proof of concept</strong><br />
parent=1%27)%20order%20by%203/*</p>
<p><strong>Impact</strong><br />
A malicious user could manipulate SQL queries by injecting arbitrary SQL code and return private information.</p>
<p><strong>Time-line</strong><br />
June 2, 2009 &#8211; First contact by contact form<br />
June 17, 2009 &#8211; Second contact by email<br />
June 17, 2009 &#8211; Reply from vendor<br />
June 18, 2009 &#8211; Vendor reported that only standalone version and Joomla 1.0.x component are vulnerable<br />
June 24, 2009 &#8211; Vendor asked for more time to patch and warn their clients about this vulnerability<br />
June 25, 2009 – Vendor released 3.9.6.1 and and updated demo versions on their site<br />
July 20, 2009 – Third contact to check the status<br />
July 25, 2009 – Advisory goes public</p>
<p><strong>Disclosed</strong><br />
Not yet published in any database</p>
<p><a href="http://www.davidsopas.com/wp-content/uploads/2009/07/Imagem-1.png"><img class="aligncenter size-medium wp-image-286" title="Imagem 1" src="http://www.davidsopas.com/wp-content/uploads/2009/07/Imagem-1-300x300.png" alt="Imagem 1" width="300" height="300" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/07/25/ixxo-cart-standalone-and-joomla-component-sql-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking CSRF Tokens</title>
		<link>http://www.davidsopas.com/2009/07/20/hacking-csrf-tokens/</link>
		<comments>http://www.davidsopas.com/2009/07/20/hacking-csrf-tokens/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 19:38:24 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[csrf tokens]]></category>
		<category><![CDATA[css history]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=282</guid>
		<description><![CDATA[Great combination of techinques published by SecureThoughts.
]]></description>
			<content:encoded><![CDATA[<p>Great combination of techinques published by <a href="http://securethoughts.com/2009/07/hacking-csrf-tokens-using-css-history-hack/" target="_blank">SecureThoughts</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/07/20/hacking-csrf-tokens/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8.2 update</title>
		<link>http://www.davidsopas.com/2009/07/20/wordpress-2-8-2-update/</link>
		<comments>http://www.davidsopas.com/2009/07/20/wordpress-2-8-2-update/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 19:18:26 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=279</guid>
		<description><![CDATA[Wordpress 2.8.2 is out and covers/patches some XSS problems in comments at admin section.
]]></description>
			<content:encoded><![CDATA[<p>Wordpress 2.8.2 is out and covers/patches some XSS problems in comments at admin section.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/07/20/wordpress-2-8-2-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Truth about pen-testing</title>
		<link>http://www.davidsopas.com/2009/07/20/truth-about-pen-testing/</link>
		<comments>http://www.davidsopas.com/2009/07/20/truth-about-pen-testing/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 19:16:45 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[pen-testing]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=277</guid>
		<description><![CDATA[A very good and self explanatory article that covers 10 points on the truth about pen-testing, written by Alberto Soliño. Check it out here.
]]></description>
			<content:encoded><![CDATA[<p>A very good and self explanatory article that covers 10 points on the truth about pen-testing, written by Alberto Soliño. Check it out <a href="http://blogs.zdnet.com/security/?p=3761" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/07/20/truth-about-pen-testing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ImageShack was hacked</title>
		<link>http://www.davidsopas.com/2009/07/14/imageshack-was-hacked/</link>
		<comments>http://www.davidsopas.com/2009/07/14/imageshack-was-hacked/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 23:18:54 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[anti-sec]]></category>
		<category><![CDATA[deface]]></category>
		<category><![CDATA[imageshack]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=275</guid>
		<description><![CDATA[anti-sec again is the group who everyone is talking. They hacked imageshack and promote their anti full-disclosure policy. Great discussion at Slashdot about this.
]]></description>
			<content:encoded><![CDATA[<p>anti-sec again is the group who everyone is talking. They hacked imageshack and promote their anti full-disclosure policy. Great discussion at <a href="http://it.slashdot.org/story/09/07/11/1430249/ImageShack-Hacked-Security-Groups-Threatened?from=rss">Slashdot</a> about this.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/07/14/imageshack-was-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Wordpress 2.8.1 is out</title>
		<link>http://www.davidsopas.com/2009/07/14/wordpress-2-8-1-is-out/</link>
		<comments>http://www.davidsopas.com/2009/07/14/wordpress-2-8-1-is-out/#comments</comments>
		<pubDate>Mon, 13 Jul 2009 23:05:37 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=273</guid>
		<description><![CDATA[Wordpress update is out, download here.
]]></description>
			<content:encoded><![CDATA[<p>Wordpress update is out, download <a href="http://wordpress.org/download/" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/07/14/wordpress-2-8-1-is-out/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Milw0rm is be closed?</title>
		<link>http://www.davidsopas.com/2009/07/09/milw0rm-is-be-closed/</link>
		<comments>http://www.davidsopas.com/2009/07/09/milw0rm-is-be-closed/#comments</comments>
		<pubDate>Thu, 09 Jul 2009 20:23:35 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[milw0rm]]></category>
		<category><![CDATA[str0ke]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=271</guid>
		<description><![CDATA[After str0ke announce that milw0rm will be closed, it seems that a couple of guys will continue his work. Hope they continue the great job str0ke made in the last years of milw0rm existence.
]]></description>
			<content:encoded><![CDATA[<p>After str0ke announce that milw0rm will be closed, it seems that a couple of guys will continue his work. Hope they continue the great job str0ke made in the last years of milw0rm existence.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/07/09/milw0rm-is-be-closed/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Michael Jackson death malware</title>
		<link>http://www.davidsopas.com/2009/06/26/michael-jackson-death-malware/</link>
		<comments>http://www.davidsopas.com/2009/06/26/michael-jackson-death-malware/#comments</comments>
		<pubDate>Fri, 26 Jun 2009 20:03:05 +0000</pubDate>
		<dc:creator>David</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[michael jackson death]]></category>

		<guid isPermaLink="false">http://www.davidsopas.com/?p=269</guid>
		<description><![CDATA[Michael Jackson death malware is already spreading according to the latest news.
]]></description>
			<content:encoded><![CDATA[<p>Michael Jackson death malware is already spreading according to the <a href="http://blogs.zdnet.com/security/?p=3682" target="_blank">latest news</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.davidsopas.com/2009/06/26/michael-jackson-death-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
