<?xml version="1.0" encoding="utf-8"?>
<!-- generator="FeedCreator 1.7.2-ppt (info@mypapit.net)" -->
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>XSSing.com - News</title>
    <subtitle>XSSing.com Daily Security News</subtitle>
    <link rel="alternate" type="text/html" href="http://www.xssing.com/"/>
    <id>http://www.xssing.com/</id>
    <updated>2008-08-21T11:38:14+01:00</updated>
    <generator>FeedCreator 1.7.2-ppt (info@mypapit.net)</generator>
<link rel="self" type="application/atom+xml" href="http://www.xssing.com/" />
    <entry>
        <title>Seride 0.2 out!</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=11"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=11</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>A new version of &lt;strong&gt;Seride&lt;/strong&gt; (&lt;em&gt;SEssion RIding DEfender&lt;/em&gt;), a PHP library for CSRF prevention, as been released and hit the &lt;strong&gt;0.2&lt;/strong&gt; status point.
&lt;p&gt;
This new version introduces several new features and fixes stated in the &lt;em&gt;CHANGELOG&lt;/em&gt; file as following:&lt;br /&gt;
&lt;em&gt;* Fixed the creation of the log file avoiding not setted variables and generalizing the Session Username to an no-specified var.&lt;br /&gt;
 * Added the possibility to choose the method of error reporting (standard/custom message/custom file).&lt;br /&gt;
 * Changed the standard error output's look.&lt;br /&gt;
 * Added the possibility to choose if page generation and the request should be aborted or not.&lt;br /&gt;
 * Added the possibility to choose to print or not the error message.&lt;br /&gt;
 * The log file now saves the HTTP Referer and the HTTP User Agent too.&lt;/em&gt;
&lt;/p&gt;
&lt;p&gt;
You can find additional infos on the project and the download link at the following address:&lt;br /&gt;
&lt;a href=&quot;http://projects.playhack.net/project.php?id=3&quot; target=&quot;_blank&quot;&gt;http://projects.playhack.net/project.php?id=3&lt;/a&gt;
&lt;/p&gt;
&lt;a href=&quot;http://www.xssing.com&quot;&gt;XSSing.com&lt;/a&gt; uses Seride for his own hijacking protection too.</summary>
    </entry>
    <entry>
        <title>Justin.TV affected by XSS Worm</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=10"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=10</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>&lt;a href=&quot;http://www.thedefaced.org&quot; target=&quot;_blank&quot;&gt;TheDefaced.org&lt;/a&gt; team contacted our partner &lt;a href=&quot;http://www.xssed.com&quot; target=&quot;_blank&quot;&gt;XSSed.com&lt;/a&gt; to communicate their last discovered vulnerability in the well-known &lt;a href=&quot;http://www.justin.tv&quot;&gt;Justin.TV&lt;/a&gt; broadcasting website and have released a&lt;strong&gt; JavaScript Worm&lt;/strong&gt; that is presented by&amp;nbsp; &lt;a href=&quot;http://www.xssing.com&quot; target=&quot;_blank&quot;&gt;XSSing.com&lt;/a&gt; in our &lt;a href=&quot;http://www.xssing.com/index.php?x=3&quot; target=&quot;_blank&quot;&gt;XSS Worms&lt;/a&gt; section.
&lt;p&gt;
Here's a statement from XSSed news about the discovery:&lt;br /&gt;
&lt;em&gt;&amp;quot;As of 'Sat, 28 Jun 2008 21:52:33 GMT' - An XSS worm was released on this website, this was and is meant only for research purposes. It was successfully executed and lasted roughly around 24 hours.&lt;br /&gt;
We have recorded such records making it possible for us to create graphical images &lt;a href=&quot;http://thedefaced.org/jtv/jtvworm-graph.png&quot;&gt;graphing the progress of this XSS worm&lt;/a&gt; as it infected each profile upon the last being viewed.&lt;br /&gt;
The XSS Vulnerability was discovered and fixed during 'Sun, 29 Jun 2008 21:12:21 GMT', with an after mass of 2525 profiles.&amp;quot;&lt;/em&gt; 
&lt;/p&gt;
&lt;p&gt;
You can find the Worm source code at this address:&lt;br /&gt;
&lt;a href=&quot;http://worms.xssing.com/sources/justintv.txt&quot; target=&quot;_blank&quot;&gt;http://worms.xssing.com/sources/justintv.txt&lt;/a&gt;
&lt;/p&gt;
And all the details on XSSed.com news item:&lt;br /&gt;
&lt;a href=&quot;http://www.xssed.com/news/75/Justin.tv_non-malicious_cross-site_scripting_worm/&quot; target=&quot;_blank&quot;&gt;http://www.xssed.com/news/75/Justin.tv_non-malicious_cross-site_scripting_worm/&lt;/a&gt;</summary>
    </entry>
    <entry>
        <title>XSSing Forums back to life</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=9"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=9</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>After an inactive period the &lt;strong&gt;forums are finally back&lt;/strong&gt; with some &lt;em&gt;fix&lt;/em&gt; and modifications in order to make it more useable from all the users that alwawys proved their support to &lt;a href=&quot;http://www.xssing.com&quot; target=&quot;_blank&quot;&gt;XSSing.com&lt;/a&gt; and its activities.&lt;br /&gt;
&lt;p&gt;The spam issue has always ruined the forum activity so now it's up with two new features that should help in this way:&lt;br /&gt;
- the registration form now have an &lt;strong&gt;image verificatio&lt;/strong&gt;n that should most likely avoid spambots to register to the forum&lt;br /&gt;
- the forums flow is now monitored by &lt;a href=&quot;http://www.akismet.com&quot; target=&quot;_blank&quot;&gt;Akismet&lt;/a&gt;, which is configured to disable spam posts and ban those users creating them.
&lt;/p&gt;
&lt;p&gt;
It will probably get some false positive and disable legitimate posts and ban unguilty users: if this happens to you just contact us and clarify the problem and we'll restore your account.
&lt;/p&gt;
Hope you enjoy and strike back to the forum!&lt;br /&gt;
Stay tuned. </summary>
    </entry>
    <entry>
        <title>PunBB Security Update</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=8"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=8</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>Today a new vulnerability advisorie on &lt;a href=&quot;http://secunia.com/advisories/29043/&quot; target=&quot;_blank&quot;&gt;PunBB Password Change and Cross Site Scripting&lt;/a&gt; has been published.
&lt;p&gt;
As you may know our &lt;a href=&quot;http://forum.xssing.com&quot; target=&quot;_blank&quot;&gt;Forum&lt;/a&gt; is using that &lt;strong&gt;Bulletin Board&lt;/strong&gt; and in order to keep the data safe we already updated the software to the latest patched version &lt;em&gt;1.2.17&lt;/em&gt;, which solved this and other security issues affecting the previous versions.
&lt;/p&gt;
The Cascading Style Sheet files will be restored within today, but if you notice any malfunctioning feel free to contact us.</summary>
    </entry>
    <entry>
        <title>XSSing got RSS!</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=7"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=7</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>With the new update of the website a new important feature has been added: RSS Feeds for the most important sections.&lt;br /&gt;
It was already planned from the beginning of the development but has been introduced only now for timing problems; the sections are:&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/news.php&quot; target=&quot;_blank&quot;&gt;News&lt;/a&gt;&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/cheats.php&quot; target=&quot;_blank&quot;&gt;XSS Cheats&lt;/a&gt;&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/worms.php&quot; target=&quot;_blank&quot;&gt;XSS Worms&lt;/a&gt;&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/docs.php&quot; target=&quot;_blank&quot;&gt;Docs&lt;/a&gt;&lt;br /&gt;
- &lt;a href=&quot;http://www.xssing.com/rss/vulns.php&quot; target=&quot;_blank&quot;&gt;Vulns&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
You can find an &amp;quot;RSS&amp;quot; link on the top-right corner of each page featuring it.&lt;br /&gt;
Enjoy!</summary>
    </entry>
    <entry>
        <title>Routers Hacking Challenge</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=6"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=6</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>&lt;a href=&quot;http://www.gnicitizen.org&quot; target=&quot;_blank&quot;&gt;Gnuciticen&lt;/a&gt; is organizing a Routers Hacking Challenge open to everyone interested in joining it!
&lt;p&gt;
It simply consists in a very flexible challenge where anyone can submit their discoveries about their own home Routers security flaws: Buffer overflow, XSS, CSRF.. everything is allowed!&lt;br /&gt;
Stress up your own home device and find as much vulnerabilities as you can, write them down and submit everything to the project page at this address: &lt;a href=&quot;http://www.gnucitizen.org/projects/router-hacking-challenge&quot; target=&quot;_blank&quot;&gt;visit&lt;/a&gt;.&lt;br /&gt;
The most interesting and effective ones will be involved in media coverage and several researches about it.
&lt;/p&gt;
Have fun!</summary>
    </entry>
    <entry>
        <title>PHP Bypass Testing Page</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=5"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=5</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>For your interest i made a simple page that you can disfrut in order to try if your own vectors are able to bypass the most common PHP html encoding functions such as &lt;em&gt;htmlspecialchars&lt;/em&gt;, &lt;em&gt;htmlentities&lt;/em&gt; and &lt;em&gt;strip_tags&lt;/em&gt;: the input will be parsed through this function and printed on the page as it is.&lt;br /&gt;
&lt;br /&gt;
You can reach the page at this address: &lt;a href=&quot;http://bypass.xssing.com&quot; target=&quot;_blank&quot;&gt;bypass.xssing.com&lt;/a&gt;.&lt;br /&gt;
You can discuss your results on the &lt;a href=&quot;http://forum.xssing.com/viewforum.php?id=8&quot; target=&quot;_blank&quot;&gt;forum&lt;/a&gt;, enjoy!</summary>
    </entry>
    <entry>
        <title>XSSed and XSSing now together</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=4"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=4</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>We are really proud and happy to announce that from now over the two sites &lt;a href=&quot;http://www.xssing.com&quot;&gt;XSSing.com&lt;/a&gt; and &lt;a href=&quot;http://www.xssed.com&quot;&gt;XSSed.com&lt;/a&gt; are affiliated and connected for the same informational purpose.&lt;br /&gt;
XSSed.com is one of the main reference website for the XSS security topic, and provide several great services such as:&lt;br /&gt;
- &lt;b&gt;XSS Afflicted website database&lt;/b&gt;, updated daily on the users submissions&lt;br /&gt;
- A complete &lt;b&gt;Articles section&lt;/b&gt; with the very best papers on this topic&lt;br /&gt;
- The &lt;b&gt;Early Warning Mailing List&lt;/b&gt;, which provide news concerning any eventual XSS found on the specified website.</summary>
    </entry>
    <entry>
        <title>New Seride major release</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=3"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=3</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>&lt;a href=&quot;http://www.xssing.com/index.php?x=9&amp;amp;y=1\&quot; target=\&quot;_blank\&quot;&gt;Nexus&lt;/a&gt; released the new version of &lt;a href=&quot;http://projects.playhack.net/project.php?id=3&quot; target=\&quot;_blank\&quot;&gt;Seride PHP Library&lt;/a&gt; (updated to 0.1.1).&lt;br /&gt;
It's available for the download at this link: &lt;a href=&quot;http://files.playhack.net/projects/seride/seride_0.1.1-beta.tar.gz&quot;&gt;download&lt;/a&gt;.&lt;br /&gt;
With the new features addition, Seride reached a stable release that provide a more professional and complete solution for CSRF preventing needs.</summary>
    </entry>
    <entry>
        <title>Open up the curtains</title>
        <link rel="alternate" type="text/html" href="http://www.xssing.com/index.php?x=8&amp;y=2"/>
        <published>2008-08-21T18:38:14+01:00</published>
        <updated>2008-08-21T18:38:14+01:00</updated>
        <id>http://www.xssing.com/index.php?x=8&amp;y=2</id>
        <author>
            <name>nexus@IHATEJUNK.playhack.net</name>
        </author>
        <summary>&amp;quot;&lt;em&gt;Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users&lt;/em&gt;&amp;quot; - &lt;a href=&quot;http://www.wikipedia.org&quot;&gt;Wikipedia&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
XSS is kicking ass from some times now, and it is growing up day by day thanks to very large interest obtained on the net: XSSing just follows that way.</summary>
    </entry>
</feed>
