<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt (info@mypapit.net)" -->
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>Dl21.org - News</title>
    <subtitle>Dl21.org Daily Security News</subtitle>
    <link rel="alternate" type="text/html" href="http://www.dl21.org/"/>
    <id>http://www.dl21.org/</id>
    <updated>2010-03-10T02:08:34+01:00</updated>
    <generator>FeedCreator 1.7.2-ppt (info@mypapit.net)</generator>
<link rel="self" type="application/atom+xml" href="http://www.dl21.org/" />
    <entry>
        <title>Now it's time for Twitter</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=15"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=15</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>As you may have noticed &lt;a href=&quot;http://www.xssed.com/news/88/17-year-old_promoted_his_website_on_Twitter_with_harmless_XSS_worm/&quot;&gt; here &lt;/a&gt; through our partner website news, a 17-years old promoted his own website (&lt;a href=&quot;http://www.stalkdaily.com&quot;&gt;StalkDaily&lt;/a&gt;) through a JS worm that infected several profiles in the &lt;a href=&quot;http://www.twitter.com&quot;&gt;Twitter&lt;/a&gt; network.&lt;br /&gt;
&lt;br /&gt;
The author released a short interview for &lt;a href=&quot;http://www.bnonews.com/news/242.html&quot;&gt;BNO News&lt;/a&gt; where he claims the responsability for the worm activity and explain few things.&lt;br /&gt;
&lt;br /&gt;
</summary>
    </entry>
    <entry>
        <title>Some updates</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=14"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=14</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>The XSS Cheats section has been just lightly updated with a couple of new features included you can now:&lt;br /&gt;
&amp;bull; Use the &amp;quot;export list&amp;quot; function which permits you to get the whole list of published XSS vectors submittes by the users, useful for fuzzing for example,&lt;br /&gt;
&amp;bull; You can now test with the &amp;quot;Test it!&amp;quot; link each vector in the page and check how it acts towards a real XSS vulnerability.
&lt;br /&gt;&lt;br /&gt;
Enjoy and have fun!&lt;br /&gt;
and Merry (late) Christmas and Happy new Year! ;-)</summary>
    </entry>
    <entry>
        <title>New Orkut Worm unleashed</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=13"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=13</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>Following the announcement by our partner &lt;a href=&quot;http://www.xssed.com&quot;&gt;XSSed&lt;/a&gt; you can find at this &lt;a href=&quot;http://www.xssed.com/news/77/New_Orkut_XSS_worm_by_Brazilian_web_security_group/&quot;&gt;URL&lt;/a&gt; we decided to upload the JS sources provided by the same XSSed website to our XSS Worms database and is now available for you at the relative page:&lt;br /&gt;
&lt;a href=&quot;http://www.dl21.org/index.php?x=6&quot;&gt;XSS Worms&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Keep up the good work!</summary>
    </entry>
    <entry>
        <title>Advisories Submissions</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=12"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=12</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>I wanted to remind everyone that submission of websites' vulnerabilities will be rejected since they are not in-line with our publishing policies: we &lt;u&gt;&lt;strong&gt;ONLY&lt;/strong&gt;&lt;/u&gt; accept advisories concerning Applications flaws such as &lt;strong&gt;CMS&lt;/strong&gt;, &lt;strong&gt;Forums&lt;/strong&gt;, &lt;strong&gt;Wikis&lt;/strong&gt; and every WebApp that is public and released.
&lt;p&gt;
If you want to notice a vulnerability in a specific website you can submit your discover to our partner's website: &lt;a href=&quot;http://www.dl21.org&quot;&gt;www.dl21.org&lt;/a&gt;.
&lt;/p&gt;
Thank you for your comprehension.
</summary>
    </entry>
    <entry>
        <title>Seride 0.2 out!</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=11"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=11</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>A new version of &lt;strong&gt;Seride&lt;/strong&gt; (&lt;em&gt;SEssion RIding DEfender&lt;/em&gt;), a PHP library for CSRF prevention, as been released and hit the &lt;strong&gt;0.2&lt;/strong&gt; status point.
&lt;p&gt;
This new version introduces several new features and fixes stated in the &lt;em&gt;CHANGELOG&lt;/em&gt; file as following:&lt;br /&gt;
&lt;em&gt;* Fixed the creation of the log file avoiding not setted variables and generalizing the Session Username to an no-specified var.&lt;br /&gt;
 * Added the possibility to choose the method of error reporting (standard/custom message/custom file).&lt;br /&gt;
 * Changed the standard error output's look.&lt;br /&gt;
 * Added the possibility to choose if page generation and the request should be aborted or not.&lt;br /&gt;
 * Added the possibility to choose to print or not the error message.&lt;br /&gt;
 * The log file now saves the HTTP Referer and the HTTP User Agent too.&lt;/em&gt;
&lt;/p&gt;
&lt;p&gt;
You can find additional infos on the project and the download link at the following address:&lt;br /&gt;
&lt;a href=&quot;http://projects.playhack.net/project.php?id=3&quot; target=&quot;_blank&quot;&gt;http://projects.playhack.net/project.php?id=3&lt;/a&gt;
&lt;/p&gt;
&lt;a href=&quot;http://www.dl21.org&quot;&gt;Dl21&lt;/a&gt; uses Seride for his own hijacking protection too.</summary>
    </entry>
    <entry>
        <title>Justin.TV affected by XSS Worm</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=10"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=10</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>&lt;a href=&quot;http://www.thedefaced.org&quot; target=&quot;_blank&quot;&gt;TheDefaced.org&lt;/a&gt; team contacted our partner &lt;a href=&quot;http://www.xssed.com&quot; target=&quot;_blank&quot;&gt;XSSed.com&lt;/a&gt; to communicate their last discovered vulnerability in the well-known &lt;a href=&quot;http://www.justin.tv&quot;&gt;Justin.TV&lt;/a&gt; broadcasting website and have released a&lt;strong&gt; JavaScript Worm&lt;/strong&gt; that is presented by&amp;nbsp; &lt;a href=&quot;http://www.dl21.org&quot; target=&quot;_blank&quot;&gt;DL21&lt;/a&gt; in our &lt;a href=&quot;http://www.dl21.org/index.php?x=3&quot; target=&quot;_blank&quot;&gt;XSS Worms&lt;/a&gt; section.
&lt;p&gt;
Here's a statement from XSSed news about the discovery:&lt;br /&gt;
&lt;em&gt;&amp;quot;As of 'Sat, 28 Jun 2008 21:52:33 GMT' - An XSS worm was released on this website, this was and is meant only for research purposes. It was successfully executed and lasted roughly around 24 hours.&lt;br /&gt;
We have recorded such records making it possible for us to create graphical images &lt;a href=&quot;http://thedefaced.org/jtv/jtvworm-graph.png&quot;&gt;graphing the progress of this XSS worm&lt;/a&gt; as it infected each profile upon the last being viewed.&lt;br /&gt;
The XSS Vulnerability was discovered and fixed during 'Sun, 29 Jun 2008 21:12:21 GMT', with an after mass of 2525 profiles.&amp;quot;&lt;/em&gt; 
&lt;/p&gt;
&lt;p&gt;
You can find the Worm source code at this address:&lt;br /&gt;
&lt;a href=&quot;http://worms.xssing.com/sources/justintv.txt&quot; target=&quot;_blank&quot;&gt;http://worms.xssing.com/sources/justintv.txt&lt;/a&gt;
&lt;/p&gt;
And all the details on XSSed.com news item:&lt;br /&gt;
&lt;a href=&quot;http://www.xssed.com/news/75/Justin.tv_non-malicious_cross-site_scripting_worm/&quot; target=&quot;_blank&quot;&gt;http://www.xssed.com/news/75/Justin.tv_non-malicious_cross-site_scripting_worm/&lt;/a&gt;</summary>
    </entry>
    <entry>
        <title>PunBB Security Update</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=8"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=8</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>Today a new vulnerability advisorie on &lt;a href=&quot;http://secunia.com/advisories/29043/&quot; target=&quot;_blank&quot;&gt;PunBB Password Change and Cross Site Scripting&lt;/a&gt; has been published.
&lt;p&gt;
As you may know our &lt;a href=&quot;http://forum.dl21.org&quot; target=&quot;_blank&quot;&gt;Forum&lt;/a&gt; is using that &lt;strong&gt;Bulletin Board&lt;/strong&gt; and in order to keep the data safe we already updated the software to the latest patched version &lt;em&gt;1.2.17&lt;/em&gt;, which solved this and other security issues affecting the previous versions.
&lt;/p&gt;
The Cascading Style Sheet files will be restored within today, but if you notice any malfunctioning feel free to contact us.</summary>
    </entry>
    <entry>
        <title>Routers Hacking Challenge</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=6"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=6</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>&lt;a href=&quot;http://www.gnicitizen.org&quot; target=&quot;_blank&quot;&gt;Gnuciticen&lt;/a&gt; is organizing a Routers Hacking Challenge open to everyone interested in joining it!
&lt;p&gt;
It simply consists in a very flexible challenge where anyone can submit their discoveries about their own home Routers security flaws: Buffer overflow, XSS, CSRF.. everything is allowed!&lt;br /&gt;
Stress up your own home device and find as much vulnerabilities as you can, write them down and submit everything to the project page at this address: &lt;a href=&quot;http://www.gnucitizen.org/projects/router-hacking-challenge&quot; target=&quot;_blank&quot;&gt;visit&lt;/a&gt;.&lt;br /&gt;
The most interesting and effective ones will be involved in media coverage and several researches about it.
&lt;/p&gt;
Have fun!</summary>
    </entry>
    <entry>
        <title>PHP Bypass Testing Page</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=5"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=5</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>For your interest i made a simple page that you can disfrut in order to try if your own vectors are able to bypass the most common PHP html encoding functions such as &lt;em&gt;htmlspecialchars&lt;/em&gt;, &lt;em&gt;htmlentities&lt;/em&gt; and &lt;em&gt;strip_tags&lt;/em&gt;: the input will be parsed through this function and printed on the page as it is.&lt;br /&gt;
&lt;br /&gt;
You can reach the page at this address: &lt;a href=&quot;http://bypass.dl21.org&quot; target=&quot;_blank&quot;&gt;bypass.dl21.org&lt;/a&gt;.&lt;br /&gt;
You can discuss your results on the &lt;a href=&quot;http://forum.dl21.org/viewforum.php?id=8&quot; target=&quot;_blank&quot;&gt;forum&lt;/a&gt;, enjoy!</summary>
    </entry>
    <entry>
        <title>New Seride major release</title>
        <link rel="alternate" type="text/html" href="http://www.dl21.org/index.php?x=8&amp;y=3"/>
        <published>2010-03-10T09:08:34+01:00</published>
        <updated>2010-03-10T09:08:34+01:00</updated>
        <id>http://www.dl21.org/index.php?x=8&amp;y=3</id>
        <author>
            <name>admin@IHATEJUNK.dl21.org</name>
        </author>
        <summary>&lt;a href=&quot;http://www.dl21.org/index.php?x=9&amp;amp;y=1\&quot; target=\&quot;_blank\&quot;&gt;Nexus&lt;/a&gt; released the new version of &lt;a href=&quot;http://projects.playhack.net/project.php?id=3&quot; target=\&quot;_blank\&quot;&gt;Seride PHP Library&lt;/a&gt; (updated to 0.1.1).&lt;br /&gt;
It's available for the download at this link: &lt;a href=&quot;http://files.playhack.net/projects/seride/seride_0.1.1-beta.tar.gz&quot;&gt;download&lt;/a&gt;.&lt;br /&gt;
With the new features addition, Seride reached a stable release that provide a more professional and complete solution for CSRF preventing needs.</summary>
    </entry>
</feed>
