<rss version="2.0"><channel><title>Web App Security (webappsec) Mailing List</title>
<link>http://seclists.org/#webappsec</link>
<description>Provides insights on the unique challenges which make web applications notoriously hard to secure.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>[White Paper] Abusing HTML 5 Structured Client-side Storage</title><description>Posted by Alberto Trivero on Jul 21&lt;p&gt;


&lt;p&gt;
The aim of this white paper is to analyze security implications of the  
&lt;br /&gt;
new HTML 5 client-side storage technology, showing how different  
&lt;br /&gt;
attacks can be conduct in order to steal storage data in the client&#146;s  
&lt;br /&gt;
machine.
&lt;br /&gt;
Download at: http://trivero.secdiscover.com/html5whitepaper.pdf
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/webappsec/2008/q3/0040.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0040.html</guid>
<pubDate>Mon, 21 Jul 2008 02:57:01 +0200</pubDate></item>
<item><title>Re: RE: Web Pen Test Honeypot</title><description>Posted by mike_at_cenzic.com on Jul 16&lt;p&gt;


 (&#39;binary&#39; encoding is not supported, stored as-is)
To add one more to the fray...
&lt;br /&gt;
&lt;p&gt;Cenzic has one available off their web site.
&lt;br /&gt;
&lt;p&gt;http://crackme.cenzic.com/
&lt;br /&gt;
&lt;p&gt;Login: mary
&lt;br /&gt;
Password: mary123
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;mikekaz
&lt;br /&gt;
&lt;p&gt;-------------------------------------------------------------------------
&lt;br /&gt;
Sponsored by: Watchfire...</description>
<link>http://seclists.org/webappsec/2008/q3/0039.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0039.html</guid>
<pubDate>16 Jul 2008 21:08:21 -0000</pubDate></item>
<item><title>RE: [Webappsec] Corsaire whitepaper: Breaking the Bank (Vulnerabilities in Numeric Processing within Financial Applications)</title><description>Posted by Martin ONeal on Jul 16&lt;p&gt;


&lt;p&gt;
&amp;gt; Yes I did; but it doesn&#39;t 
&lt;br /&gt;
&amp;gt; change the fact that your 
&lt;br /&gt;
&amp;gt; comments under &amp;quot;Testing&amp;quot; 
&lt;br /&gt;
&amp;gt; in that section (page 16) 
&lt;br /&gt;
&amp;gt; are still not applicable to 
&lt;br /&gt;
&amp;gt; c#. Nor is the &amp;quot;Recommendation&amp;quot; 
&lt;br /&gt;
&amp;gt; about ==. As I said.
&lt;br /&gt;
&lt;p&gt;LOL; you would like a testing and...</description>
<link>http://seclists.org/webappsec/2008/q3/0038.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0038.html</guid>
<pubDate>Wed, 16 Jul 2008 11:51:37 +0100</pubDate></item>
<item><title>Re: Auditing mailing scripts for web app pentesters</title><description>Posted by Adrian Pastor on Jul 16&lt;p&gt;


&lt;p&gt;
&lt;p&gt;Hi Brett,
&lt;br /&gt;
&lt;p&gt;I came across this paper a while ago but had forgotten about it! Will
&lt;br /&gt;
definitely keep it in mind for future assessments.
&lt;br /&gt;
&lt;p&gt;What percentage of ASP.NET/MS SQL environments would you say you find
&lt;br /&gt;
vulnerable to this attack against &amp;quot;forgotten password&amp;quot; facilities?
&lt;br /&gt;
&lt;p&gt;Also, have you...</description>
<link>http://seclists.org/webappsec/2008/q3/0037.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0037.html</guid>
<pubDate>Wed, 16 Jul 2008 11:31:15 +0100</pubDate></item>
<item><title>Re: [Webappsec] Corsaire whitepaper: Breaking the Bank (Vulnerabilities in Numeric Processing within Financial Applications)</title><description>Posted by silky on Jul 16&lt;p&gt;


&lt;p&gt;
On Wed, Jul 16, 2008 at 8:02 PM, Martin O&#39;Neal
&lt;br /&gt;
&amp;lt;martin.oneal_at_corsaire&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; &amp;gt; this is fairly stupid.
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; LOL; more stupid than vacuous name calling, or less?
&lt;br /&gt;
&lt;p&gt;I&#39;d say it&#39;s on par with it :)
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&amp;gt; &amp;gt; what financial institutions are
&lt;br /&gt;
&amp;gt; &amp;gt; using...</description>
<link>http://seclists.org/webappsec/2008/q3/0036.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0036.html</guid>
<pubDate>Wed, 16 Jul 2008 20:07:35 +1000</pubDate></item>
<item><title>RE: [Webappsec] Corsaire whitepaper: Breaking the Bank (Vulnerabilities in Numeric Processing within Financial Applications)</title><description>Posted by Martin ONeal on Jul 16&lt;p&gt;


&lt;p&gt;
&amp;gt; this is fairly stupid.
&lt;br /&gt;
&lt;p&gt;LOL; more stupid than vacuous name calling, or less?
&lt;br /&gt;
&lt;p&gt;&amp;gt; what financial institutions are 
&lt;br /&gt;
&amp;gt; using floating point and not decimal
&lt;br /&gt;
&amp;gt; variables to represent their money? 
&lt;br /&gt;
&amp;gt; very few i&#39;d guess. it hardly needs 
&lt;br /&gt;
&amp;gt; to be said that anyone using FP 
&lt;br /&gt;
&amp;gt;...</description>
<link>http://seclists.org/webappsec/2008/q3/0035.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0035.html</guid>
<pubDate>Wed, 16 Jul 2008 11:02:43 +0100</pubDate></item>
<item><title>RE: [Webappsec] Corsaire whitepaper: Breaking the Bank (Vulnerabilities in Numeric Processing within Financial Applications)</title><description>Posted by Martin ONeal on Jul 16&lt;p&gt;


&lt;p&gt;
&amp;gt; you don&#39;t ever need to round, and 
&lt;br /&gt;
&amp;gt; can use relatively simple fixed-
&lt;br /&gt;
&amp;gt; precision for this sort of thing.
&lt;br /&gt;
&lt;p&gt;Sometimes.  Some financial calculations, such as exchange rates etc, are
&lt;br /&gt;
inherently floats.
&lt;br /&gt;
&lt;p&gt;Martin...
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&lt;p&gt;...</description>
<link>http://seclists.org/webappsec/2008/q3/0034.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0034.html</guid>
<pubDate>Wed, 16 Jul 2008 10:46:05 +0100</pubDate></item>
<item><title>RE: [Webappsec] Corsaire whitepaper: Breaking the Bank (Vulnerabilities in Numeric Processing within Financial Applications)</title><description>Posted by Martin ONeal on Jul 16&lt;p&gt;


&lt;p&gt;
&amp;gt; Have you reported these issues to Sun/Microsoft?
&lt;br /&gt;
&lt;p&gt;These are all by-design issues, that have side-effects for the unwary.
&lt;br /&gt;
&lt;p&gt;Martin...
&lt;br /&gt;
&lt;p&gt;-------------------------------------------------------------------------
&lt;br /&gt;
Sponsored by: Watchfire 
&lt;br /&gt;
Methodologies &amp;amp; Tools for Web Application Security...</description>
<link>http://seclists.org/webappsec/2008/q3/0033.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0033.html</guid>
<pubDate>Wed, 16 Jul 2008 10:42:59 +0100</pubDate></item>
<item><title>Re: Paper draft: Enough With Default Allow in Web Applications!</title><description>Posted by Adrian Pastor on Jul 16&lt;p&gt;


&lt;p&gt;
&lt;p&gt;Ivan, I agree with you 100% but as you said it&#39;s easier said than done.
&lt;br /&gt;
I think that a lot of insecure configuration settings are forgotten to
&lt;br /&gt;
be fixed when moving from a UAT to a production environment.
&lt;br /&gt;
&lt;p&gt;You might want to take a look at the following:
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/webappsec/2008/q3/0032.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0032.html</guid>
<pubDate>Wed, 16 Jul 2008 10:09:15 +0100</pubDate></item>
<item><title>RE: Auditing mailing scripts for web app pentesters</title><description>Posted by Brett Moore on Jul 16&lt;p&gt;


&lt;p&gt;
Hi.
&lt;br /&gt;
&lt;p&gt;While not directly related to your papers topic. I think it would
&lt;br /&gt;
be beneficial to raise awareness of the issue illustrated in this
&lt;br /&gt;
paper by Gary O&#39;Leary-Steele.
&lt;br /&gt;
&lt;p&gt;http://www.sec-1labs.co.uk/advisories/BTA_Full.pdf
&lt;br /&gt;
&lt;p&gt;Surprising how many forgotten password mail out features are vulnerable
&lt;br /&gt;
to...</description>
<link>http://seclists.org/webappsec/2008/q3/0031.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0031.html</guid>
<pubDate>Wed, 16 Jul 2008 15:08:29 +1200</pubDate></item>
<item><title>Re: Recommended training course?</title><description>Posted by Johannes B. Ullrich on Jul 16&lt;p&gt;


&lt;p&gt;
/* disclaimer: I work for SANS */
&lt;br /&gt;
&lt;p&gt;Take a look at http://www.sans.org. Plenty of courses to choose from. I will not comment on quality as I work for them. Essentially all of them include hands on exercises and can be taken live or online. I will gladly provide more information off-list.
&lt;br /&gt;
&lt;p&gt;Most...</description>
<link>http://seclists.org/webappsec/2008/q3/0030.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0030.html</guid>
<pubDate>Wed, 16 Jul 2008 02:48:51 +0000 (UTC)</pubDate></item>
<item><title>Re: usabilty vs sescurity - return urls by parameter</title><description>Posted by Gleb Paharenko on Jul 16&lt;p&gt;


&lt;p&gt;
Hi.
&lt;br /&gt;
&lt;p&gt;That seems to be a part of &amp;quot;open redirects problem&amp;quot; which was
&lt;br /&gt;
discussed a lot on this list.
&lt;br /&gt;
&lt;p&gt;2008/7/15 MC Iglo &amp;lt;mc.iglo_at_googlemail&amp;#46;com&amp;gt;:
&lt;br /&gt;
&amp;gt; Hi all,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; lately, I see more and more pages using get-parameters to store a
&lt;br /&gt;
&amp;gt; return url after login.
&lt;br /&gt;
&amp;gt; two...</description>
<link>http://seclists.org/webappsec/2008/q3/0029.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0029.html</guid>
<pubDate>Wed, 16 Jul 2008 15:12:59 +0300</pubDate></item>
<item><title>CFP now open for ClubHack2008 - India</title><description>Posted by ClubHack on Jul 15&lt;p&gt;


&lt;p&gt;
Dear all
&lt;br /&gt;
We are pleased to announce the opening of CFP for ClubHack2008.
&lt;br /&gt;
ClubHack is India&#39;s own international hackers&#39; convention started in 2007.
&lt;br /&gt;
&lt;p&gt;We are expecting good deep knowledge technical
&lt;br /&gt;
presentations/demonstrations on topics from the world of Information
&lt;br /&gt;
Security.
&lt;br /&gt;
&lt;p&gt;These...</description>
<link>http://seclists.org/webappsec/2008/q3/0028.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0028.html</guid>
<pubDate>Tue, 15 Jul 2008 15:46:20 +0530</pubDate></item>
<item><title>Re: Recommended training course?</title><description>Posted by Kevin Johnson on Jul 15&lt;p&gt;


&lt;p&gt;
On Jul 13, 2008, at 1:18 AM, Jimmy Liang wrote:
&lt;br /&gt;
&amp;gt; Hello,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I&#146;m looking at expanding my security knowledge and am looking for  
&lt;br /&gt;
&amp;gt; recommendations on training courses. I&#146;ve had a few years of Windows  
&lt;br /&gt;
&amp;gt; and Solaris admin experience managing 30 or so 24/7 systems, and  
&lt;br /&gt;
&amp;gt;...</description>
<link>http://seclists.org/webappsec/2008/q3/0027.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0027.html</guid>
<pubDate>Tue, 15 Jul 2008 22:48:05 -0400</pubDate></item>
<item><title>Re: [Webappsec] Corsaire whitepaper: Breaking the Bank (Vulnerabilities in Numeric Processing within Financial Applications)</title><description>Posted by silky on Jul 16&lt;p&gt;


&lt;p&gt;
On Tue, Jul 15, 2008 at 11:02 PM, Martin O&#39;Neal
&lt;br /&gt;
&amp;lt;martin.oneal_at_corsaire&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Breaking the Bank
&lt;br /&gt;
&amp;gt; (Vulnerabilities in Numeric Processing within Financial Applications)
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; By Adam Boulton, Stephen De Vries, Kevin O&#39;Reilly, July 15, 2008
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; This...</description>
<link>http://seclists.org/webappsec/2008/q3/0026.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q3/0026.html</guid>
<pubDate>Wed, 16 Jul 2008 10:08:03 +1000</pubDate></item>
</channel></rss>