<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt (info@mypapit.net)" -->
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>XSSing.com - News</title>
    <subtitle>XSSing.com Daily Security News</subtitle>
    <link rel="alternate" type="text/html" href="http://www.xssing.com/"/>
    <id>http://www.xssing.com/</id>
    <updated>2009-07-03T01:38:08+01:00</updated>
    <generator>FeedCreator 1.7.2-ppt (info@mypapit.net)</generator>
<link rel="self" type="application/atom+xml" href="http://www.xssing.com/" />
    <entry>
        <title>Now it's time for Twitter</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=15"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=15</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>As you may have noticed &lt;a href=&quot;http://www.xssed.com/news/88/17-year-old_promoted_his_website_on_Twitter_with_harmless_XSS_worm/&quot;&gt; here &lt;/a&gt; through our partner website news, a 17-years old promoted his own website (&lt;a href=&quot;http://www.stalkdaily.com&quot;&gt;StalkDaily&lt;/a&gt;) through a JS worm that infected several profiles in the &lt;a href=&quot;http://www.twitter.com&quot;&gt;Twitter&lt;/a&gt; network.&lt;br /&gt;
&lt;br /&gt;
The author released a short interview for &lt;a href=&quot;http://www.bnonews.com/news/242.html&quot;&gt;BNO News&lt;/a&gt; where he claims the responsability for the worm activity and explain few things.&lt;br /&gt;
&lt;br /&gt;
You can now find the Worm source code in our &lt;a href=&quot;http://www.xssing.com/index.php?x=6&quot;&gt;Worms Database&lt;/a&gt; to view and analize it.</summary>
    </entry>
    <entry>
        <title>Some updates</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=14"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=14</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>The XSS Cheats section has been just lightly updated with a couple of new features included you can now:&lt;br /&gt;
&amp;bull; Use the &amp;quot;export list&amp;quot; function which permits you to get the whole list of published XSS vectors submittes by the users, useful for fuzzing for example,&lt;br /&gt;
&amp;bull; You can now test with the &amp;quot;Test it!&amp;quot; link each vector in the page and check how it acts towards a real XSS vulnerability.
&lt;br /&gt;&lt;br /&gt;
Enjoy and have fun!&lt;br /&gt;
and Merry (late) Christmas and Happy new Year! ;-)</summary>
    </entry>
    <entry>
        <title>New Orkut Worm unleashed</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=13"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=13</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>Following the announcement by our partner &lt;a href=&quot;http://www.xssed.com&quot;&gt;XSSed&lt;/a&gt; you can find at this &lt;a href=&quot;http://www.xssed.com/news/77/New_Orkut_XSS_worm_by_Brazilian_web_security_group/&quot;&gt;URL&lt;/a&gt; we decided to upload the JS sources provided by the same XSSed website to our XSS Worms database and is now available for you at the relative page:&lt;br /&gt;
&lt;a href=&quot;http://www.xssing.com/index.php?x=6&quot;&gt;XSS Worms&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Keep up the good work!</summary>
    </entry>
    <entry>
        <title>Advisories Submissions</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=12"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=12</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>I wanted to remind everyone that submission of websites' vulnerabilities will be rejected since they are not in-line with our publishing policies: we &lt;u&gt;&lt;strong&gt;ONLY&lt;/strong&gt;&lt;/u&gt; accept advisories concerning Applications flaws such as &lt;strong&gt;CMS&lt;/strong&gt;, &lt;strong&gt;Forums&lt;/strong&gt;, &lt;strong&gt;Wikis&lt;/strong&gt; and every WebApp that is public and released.
&lt;p&gt;
If you want to notice a vulnerability in a specific website you can submit your discover to our partner's website: &lt;a href=&quot;http://www.xssed.com&quot;&gt;www.xssed.com&lt;/a&gt;.
&lt;/p&gt;
Thank you for your comprehension.
</summary>
    </entry>
    <entry>
        <title>Seride 0.2 out!</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=11"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=11</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>A new version of &lt;strong&gt;Seride&lt;/strong&gt; (&lt;em&gt;SEssion RIding DEfender&lt;/em&gt;), a PHP library for CSRF prevention, as been released and hit the &lt;strong&gt;0.2&lt;/strong&gt; status point.
&lt;p&gt;
This new version introduces several new features and fixes stated in the &lt;em&gt;CHANGELOG&lt;/em&gt; file as following:&lt;br /&gt;
&lt;em&gt;* Fixed the creation of the log file avoiding not setted variables and generalizing the Session Username to an no-specified var.&lt;br /&gt;
 * Added the possibility to choose the method of error reporting (standard/custom message/custom file).&lt;br /&gt;
 * Changed the standard error output's look.&lt;br /&gt;
 * Added the possibility to choose if page generation and the request should be aborted or not.&lt;br /&gt;
 * Added the possibility to choose to print or not the error message.&lt;br /&gt;
 * The log file now saves the HTTP Referer and the HTTP User Agent too.&lt;/em&gt;
&lt;/p&gt;
&lt;p&gt;
You can find additional infos on the project and the download link at the following address:&lt;br /&gt;
&lt;a href=&quot;http://projects.playhack.net/project.php?id=3&quot; target=&quot;_blank&quot;&gt;http://projects.playhack.net/project.php?id=3&lt;/a&gt;
&lt;/p&gt;
&lt;a href=&quot;http://www.xssing.com&quot;&gt;XSSing.com&lt;/a&gt; uses Seride for his own hijacking protection too.</summary>
    </entry>
    <entry>
        <title>Justin.TV affected by XSS Worm</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=10"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=10</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>&lt;a href=&quot;http://www.thedefaced.org&quot; target=&quot;_blank&quot;&gt;TheDefaced.org&lt;/a&gt; team contacted our partner &lt;a href=&quot;http://www.xssed.com&quot; target=&quot;_blank&quot;&gt;XSSed.com&lt;/a&gt; to communicate their last discovered vulnerability in the well-known &lt;a href=&quot;http://www.justin.tv&quot;&gt;Justin.TV&lt;/a&gt; broadcasting website and have released a&lt;strong&gt; JavaScript Worm&lt;/strong&gt; that is presented by&amp;nbsp; &lt;a href=&quot;http://www.xssing.com&quot; target=&quot;_blank&quot;&gt;XSSing.com&lt;/a&gt; in our &lt;a href=&quot;http://www.xssing.com/index.php?x=3&quot; target=&quot;_blank&quot;&gt;XSS Worms&lt;/a&gt; section.
&lt;p&gt;
Here's a statement from XSSed news about the discovery:&lt;br /&gt;
&lt;em&gt;&amp;quot;As of 'Sat, 28 Jun 2008 21:52:33 GMT' - An XSS worm was released on this website, this was and is meant only for research purposes. It was successfully executed and lasted roughly around 24 hours.&lt;br /&gt;
We have recorded such records making it possible for us to create graphical images &lt;a href=&quot;http://thedefaced.org/jtv/jtvworm-graph.png&quot;&gt;graphing the progress of this XSS worm&lt;/a&gt; as it infected each profile upon the last being viewed.&lt;br /&gt;
The XSS Vulnerability was discovered and fixed during 'Sun, 29 Jun 2008 21:12:21 GMT', with an after mass of 2525 profiles.&amp;quot;&lt;/em&gt; 
&lt;/p&gt;
&lt;p&gt;
You can find the Worm source code at this address:&lt;br /&gt;
&lt;a href=&quot;http://worms.xssing.com/sources/justintv.txt&quot; target=&quot;_blank&quot;&gt;http://worms.xssing.com/sources/justintv.txt&lt;/a&gt;
&lt;/p&gt;
And all the details on XSSed.com news item:&lt;br /&gt;
&lt;a href=&quot;http://www.xssed.com/news/75/Justin.tv_non-malicious_cross-site_scripting_worm/&quot; target=&quot;_blank&quot;&gt;http://www.xssed.com/news/75/Justin.tv_non-malicious_cross-site_scripting_worm/&lt;/a&gt;</summary>
    </entry>
    <entry>
        <title>XSSing Forums back to life</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=9"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=9</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>After an inactive period the &lt;strong&gt;forums are finally back&lt;/strong&gt; with some &lt;em&gt;fix&lt;/em&gt; and modifications in order to make it more useable from all the users that alwawys proved their support to &lt;a href=&quot;http://www.xssing.com&quot; target=&quot;_blank&quot;&gt;XSSing.com&lt;/a&gt; and its activities.&lt;br /&gt;
&lt;p&gt;The spam issue has always ruined the forum activity so now it's up with two new features that should help in this way:&lt;br /&gt;
- the registration form now have an &lt;strong&gt;image verificatio&lt;/strong&gt;n that should most likely avoid spambots to register to the forum&lt;br /&gt;
- the forums flow is now monitored by &lt;a href=&quot;http://www.akismet.com&quot; target=&quot;_blank&quot;&gt;Akismet&lt;/a&gt;, which is configured to disable spam posts and ban those users creating them.
&lt;/p&gt;
&lt;p&gt;
It will probably get some false positive and disable legitimate posts and ban unguilty users: if this happens to you just contact us and clarify the problem and we'll restore your account.
&lt;/p&gt;
Hope you enjoy and strike back to the forum!&lt;br /&gt;
Stay tuned. </summary>
    </entry>
    <entry>
        <title>PunBB Security Update</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=8"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=8</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>Today a new vulnerability advisorie on &lt;a href=&quot;http://secunia.com/advisories/29043/&quot; target=&quot;_blank&quot;&gt;PunBB Password Change and Cross Site Scripting&lt;/a&gt; has been published.
&lt;p&gt;
As you may know our &lt;a href=&quot;http://forum.xssing.com&quot; target=&quot;_blank&quot;&gt;Forum&lt;/a&gt; is using that &lt;strong&gt;Bulletin Board&lt;/strong&gt; and in order to keep the data safe we already updated the software to the latest patched version &lt;em&gt;1.2.17&lt;/em&gt;, which solved this and other security issues affecting the previous versions.
&lt;/p&gt;
The Cascading Style Sheet files will be restored within today, but if you notice any malfunctioning feel free to contact us.</summary>
    </entry>
    <entry>
        <title>XSSing got RSS!</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=7"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=7</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>With the new update of the website a new important feature has been added: RSS Feeds for the most important sections.&lt;br /&gt;
It was already planned from the beginning of the development but has been introduced only now for timing problems; the sections are:&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/news.php&quot; target=&quot;_blank&quot;&gt;News&lt;/a&gt;&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/cheats.php&quot; target=&quot;_blank&quot;&gt;XSS Cheats&lt;/a&gt;&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/worms.php&quot; target=&quot;_blank&quot;&gt;XSS Worms&lt;/a&gt;&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/docs.php&quot; target=&quot;_blank&quot;&gt;Docs&lt;/a&gt;&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/vulns.php&quot; target=&quot;_blank&quot;&gt;Vulns&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
You can find an &amp;quot;RSS&amp;quot; link on the top-right corner of each page featuring it.&lt;br /&gt;
Enjoy!</summary>
    </entry>
    <entry>
        <title>Routers Hacking Challenge</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=6"/>
        <published>2009-07-03T01:38:08+01:00</published>
        <updated>2009-07-03T01:38:08+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=6</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>&lt;a href=&quot;http://www.gnicitizen.org&quot; target=&quot;_blank&quot;&gt;Gnuciticen&lt;/a&gt; is organizing a Routers Hacking Challenge open to everyone interested in joining it!
&lt;p&gt;
It simply consists in a very flexible challenge where anyone can submit their discoveries about their own home Routers security flaws: Buffer overflow, XSS, CSRF.. everything is allowed!&lt;br /&gt;
Stress up your own home device and find as much vulnerabilities as you can, write them down and submit everything to the project page at this address: &lt;a href=&quot;http://www.gnucitizen.org/projects/router-hacking-challenge&quot; target=&quot;_blank&quot;&gt;visit&lt;/a&gt;.&lt;br /&gt;
The most interesting and effective ones will be involved in media coverage and several researches about it.
&lt;/p&gt;
Have fun!</summary>
    </entry>
</feed>
