<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Hell - Spy . De &#187; Sec</title>
	<atom:link href="http://www.hell-spy.de/category/sec/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hell-spy.de</link>
	<description>Anyone who has never made a mistake has never tried anything new. - Albert Einstein</description>
	<lastBuildDate>Sat, 29 Oct 2011 10:23:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Wie &#8220;hackt&#8221; man nen Koffer?</title>
		<link>http://www.hell-spy.de/2011/08/wie-hackt-man-nen-koffer/</link>
		<comments>http://www.hell-spy.de/2011/08/wie-hackt-man-nen-koffer/#comments</comments>
		<pubDate>Wed, 03 Aug 2011 18:30:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sec]]></category>

		<guid isPermaLink="false">http://www.hell-spy.de/?p=112</guid>
		<description><![CDATA[So machen die Sec-Leute am Flughafen deinen Koffer auf:]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.hell-spy.de%2F2011%2F08%2Fwie-hackt-man-nen-koffer%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.hell-spy.de%2F2011%2F08%2Fwie-hackt-man-nen-koffer%2F&amp;source=cavka&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>So machen die Sec-Leute am Flughafen deinen Koffer auf:</p>
<p><iframe src="http://blip.tv/play/hr9MgraLSAI.html" width="470" height="290" frameborder="0" allowfullscreen></iframe><embed type="application/x-shockwave-flash" src="http://a.blip.tv/api.swf#hr9MgraLSAI" style="display:none"></embed></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hell-spy.de/2011/08/wie-hackt-man-nen-koffer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHP Web Stat XSS</title>
		<link>http://www.hell-spy.de/2009/05/php-web-stat-xss/</link>
		<comments>http://www.hell-spy.de/2009/05/php-web-stat-xss/#comments</comments>
		<pubDate>Sat, 16 May 2009 09:19:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sec]]></category>

		<guid isPermaLink="false">http://www.hell-spy.de/?p=51</guid>
		<description><![CDATA[The newest version of PHP Web Stat (3.6.28) is vulnerable to a Cross Site Scripting attack, allowing code injection by malicious users. You can find my Proof of Concept here.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.hell-spy.de%2F2009%2F05%2Fphp-web-stat-xss%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.hell-spy.de%2F2009%2F05%2Fphp-web-stat-xss%2F&amp;source=cavka&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>The newest version of PHP Web Stat (3.6.28) is vulnerable to a Cross Site Scripting attack, allowing code injection by malicious users. You can find my Proof of Concept <a href="http://www.hell-spy.de/sec/CAV-2009-02.txt">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hell-spy.de/2009/05/php-web-stat-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lansuite / phgstats XSS</title>
		<link>http://www.hell-spy.de/2009/05/lansuite-xss/</link>
		<comments>http://www.hell-spy.de/2009/05/lansuite-xss/#comments</comments>
		<pubDate>Sun, 03 May 2009 19:32:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Sec]]></category>

		<guid isPermaLink="false">http://www.hell-spy.de/?p=43</guid>
		<description><![CDATA[Looks like it&#8217;s blogging time. For unknown reasons (unknown my ass &#8211; boredom and lack of beer), I took a deeper look at Lansuite. The last version (v3.someting CVS) was full of XSS and SQL injection bugs but after reporting it they fixed many, but not all of them. There are still 3 XSS bugs. [...]]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.hell-spy.de%2F2009%2F05%2Flansuite-xss%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.hell-spy.de%2F2009%2F05%2Flansuite-xss%2F&amp;source=cavka&amp;style=normal&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
<p>Looks like it&#8217;s blogging time. For unknown reasons (unknown my ass &#8211; boredom and lack of beer), I took a deeper look at Lansuite. The last version (v3.someting CVS) was full of XSS and SQL injection bugs but after reporting it they fixed many, but not all of them. There are still 3 XSS bugs. Well they don&#8217;t directly affect Lansuite but phgstats. You can find a few details about it <a href="http://www.hell-spy.de/sec/CAV-2009-01.txt">here</a>. Have fun.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hell-spy.de/2009/05/lansuite-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

