<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: digg]]></title>
    <link>http://securityratty.com/tag/digg</link>
    <description></description>
    <pubDate>Mon, 15 Sep 2008 17:32:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Mamma.com: Insider trading and XSS]]></title>
      <link>http://securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</link>
      <guid>http://securityratty.com/article/56fd5d403c630cbec7e9ec62becaafc5</guid>
      <description><![CDATA[Mamma.com 's got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked 4064 on Alexa as of today
I won't profess to following...]]></description>
      <content:encoded><![CDATA[<a href="http://mamma.com/" target="_blank">Mamma.com</a>'s got issues other than Mark Cuban's insider trading allegations. As a point of reference for this conversation, Mamma.com is ranked <a href="http://www.alexa.com/search?q=mamma.com" target="_blank">4064</a> on <a href="http://www.alexa.com" target="_blank">Alexa</a> as of today.<br />I won't profess to following Mr. Cuban's public life and the occasional antics. Obviously, he's a colorful and popular figure; certainly in Dallas, if not nationally. <br />What follows is not a judgment of Mr. Cuban or his pending legal challenges. I'm sure the process will play itself out accordingly.<br />A quick summary and some reference material:<br />The SEC has <a href="http://www.businessweek.com/the_thread/blogspotting/archives/2008/11/sec_hits_mark_c.html?chan=technology_technology+index+page_top+stories" target="_blank">filed</a> insider trading charges against Mr. Cuban. "According to the SEC, Cuban dumped 600,000 shares, or all of his 6.3% stake, in the search engine Mamma.com (The Mother of All Search Engines), in June 2004 after learning about private financing that the company was proposing. By selling, he avoided losing $750,000, the SEC alleges."<br />The whole issue for Mr. Cuban was <a href="http://blogmaverick.com/2008/11/17/the-sec/" target="_blank">PIPE</a> financing because it's "dilutive to existing shareholders’ stakes."<br />That's the long and the short of the current issue, and again, not my real interest here, with the exception of the bet I made with myself regarding the probable web application security posture of mamma.com. <br />All this talk about a popular site immediately sets off the little bell in my head (I hear it a lot). <span style="font-weight:bold;"><br />"What's wrong with the site?" is always the first question I ask myself.</span> <br /><br />I was not disappointed. <br /><br />Mamma.com exhibits the following issues:<br />1) XSS vulnerability in the <span style="font-style:italic;">utfout<span style="font-weight:bold;"><span style="font-style:italic;"></span></span></span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s1600-h/mamma1.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 184px;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SSNDBtG5jhI/AAAAAAAAAEs/rIT7buzVsao/s320/mamma1.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129685521075730" /></a><br /><br />2) XSS vulnerability in the <span style="font-style:italic;">qtype</span> variable.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s1600-h/mamma2.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 201px;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/SSNDSxiGVeI/AAAAAAAAAE0/E-McmPqvoDQ/s320/mamma2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270129978766677474" /></a><br /><br />3) XSS vulnerability in their Mammajobs site at the <span style="font-style:italic;">pid</span> variable. This one's weirder still; if you drop an IFRAME in, it simply redirects to any URL you include in the IFRAME string.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s1600-h/mamma3.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 99px;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SSNDd-U7c0I/AAAAAAAAAE8/GCrCAoYom5k/s320/mamma3.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5270130171179660098" /></a><br /><br />4) The prospect of CSRF (rather pointless here given that its just a search engine, but but still defies best practices) appears likely given that mamma.com blindly accepts updates via GET and POST with no sign of a formkey (canary) in sight.<br /><br />I figured it best to stop there, and have submitted all these to Copernic (the Momma parent company). <br />I am however truly disappointed that an enterprise as ambitious and motivated as Momma/Copernic seems to have thrown the baby out with the bath water when it comes to web application security.<br />With regard to Mark Cuban dumping his shares: maybe he was afraid of getting pwned. ;-) All kidding aside, it's a shame that the whimsical and pessimistic thoughts regarding web site security that bounce around in my head inevitably bear themselves out.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html&title=Mamma.com:%20Insider%20trading%20and%20XSS " title="Mamma.com: Insider trading and XSS ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html" title="Mamma.com: Insider trading and XSS ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 18 Nov 2008 06:55:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mamma">mamma</category>
      <category domain="http://securityratty.com/tag/mark cuban">mark cuban</category>
      <category domain="http://securityratty.com/tag/cuban">cuban</category>
      <category domain="http://securityratty.com/tag/engine">engine</category>
      <category domain="http://securityratty.com/tag/engine mamma">engine mamma</category>
      <category domain="http://securityratty.com/tag/xss vulnerability">xss vulnerability</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/insider">insider</category>
      <category domain="http://securityratty.com/tag/web site security">web site security</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/mammacom-insider-trading-and-xss.html">Mamma.com: Insider trading and XSS</source>
    </item>
    <item>
      <title><![CDATA[XSS Comedy III: Tax Cheats with Small Equipment]]></title>
      <link>http://securityratty.com/article/231bdf97af3811aa73d852717e216a77</link>
      <guid>http://securityratty.com/article/231bdf97af3811aa73d852717e216a77</guid>
      <description><![CDATA[As part of an ongoing series, if I may I, the third in a series on the absurd, inane, and perhaps even funny. Lest you forget: the first and second in the series
I don't know about you, but I enjoy...]]></description>
      <content:encoded><![CDATA[As part of an ongoing series, if I may I, the third in a series on the absurd, inane, and perhaps even funny. Lest you forget: the <a href="http://holisticinfosec.blogspot.com/2008/06/xss-comedy-at-mcafee-secures-expense.html" target="_blank">first</a> and <a href="http://holisticinfosec.blogspot.com/2008/09/xss-fortune-cookie.html" target="_blank">second</a> in the series.<br />I don't know about you, but I enjoy occasionally watching offerings like the History Channel, AMC, or the Military Channel. I'm a 40ish, white male and as such I likely fit the general demographic as perceived by the marketing geniuses who buy the late evening advertising blocks on these channels. <br />That does NOT mean that I cheat of my taxes and thus need the services of a plethora of scam artists selling tax relief. Nor does it mean that I have any interest in "enhancement" opportunities like Enzyte or ExtenZe. <br />I just love people who choose to skip out on a primary obligation of citizenship that most of us choose to meet, and expect to magically turn $100,000 in tax debt into $999. Then there are the "businesses" who exploit these folks and willingly convince them of their "success" via the power of advertising, at which point my patience just snaps, as it did last night. <br />Thus, part one of this rant is a mighty <span style="font-weight:bold;">bugger off</span> to all the "tax relief" companies. To their patrons, may I suggest simply paying taxes like the rest of us?<br />Here's an XSS vulnerability in the Freedom Financial Network, "as seen on TV", designed to express precisely how I feel: <br /><br /><a href="http://www.freedomfinancialnetwork.com/tax_debt.php?pid=ffn+go&key=%22%3E%3Cmarquee%3E%3Ch1%3ENOTHING_IS_FREE!%3C%2Fh1%3E%3C%2Fmarquee%3E" target="_blank">http://www.freedomfinancialnetwork.com/tax_debt.php?pid=ffn+go&key=%22%3E%3Cmarquee%3E%3Ch1%3ENOTHING_IS_FREE!%3C%2Fh1%3E%3C%2Fmarquee%3E</a><br /><br />If and when they fix this issue, here's the <a href="http://holisticinfosec.org/video/freedomtaxrelief/nothingisfree.html" target="_blank">video</a> for posterity.<br /><br />Part two of this rant will get you more bang for your buck, and I'm not talking enhancement.<br />Thanks to my utter disdain for the endlessly annoying advertising I went to the ExtenZe site to see what might be broken which immediately led me to discover an entire platform vulnerability in the ColdFusion application built by <a href="http://www.internet-direct-response.com/portfolio.html" target="_blank">Internet Direct Response (IDR)</a>, the wankers who proudly bring you Maxoderm, Vivaxa, Vazomyne, Smoke Away, and Hydroxydrene; all such reputable products, and all repetitively wearing me out via DirectTV. At the ExtenZe site I spotted a variable that seemed worthy of building a <a href="http://www.google.com/search?hl=en&q=inurl:%22microppcsite%22&start=0&sa=N" target="_blank">Googledork</a> from, and I soon discovered that it was a consistent variable in most of the sites pimping this crap; specifically, <span style="font-style:italic;">microppcsite</span>. You can follow all the search results back to our friends at IDR. <br />A little experimentation and I quickly discovered that the similar <span style="font-style:italic;">microppcterm</span> variable was vulnerable to entertaining XSS exploitation so I started with:<br /><br /><a href="http://www.extenzeforlife.com/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EToo_short,_Morningwood?%3C%2Fh1%3E%3C%2Fmarquee%3E&gclid=CJ3T2NXH8JYCFQQCagod7xyBrA" target="_blank">http://www.extenzeforlife.com/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EToo_short,_Morningwood?%3C%2Fh1%3E%3C%2Fmarquee%3E&gclid=CJ3T2NXH8JYCFQQCagod7xyBrA</a><br /><br />Pick your poison, it works on most IDR gems.<br /><br /><a href="http://www.enzyte-male-enhancement.com/google/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EBob_just_wants_your_money.%3C%2Fh1%3E%3C%2Fmarquee%3E" target="_blank">http://www.enzyte-male-enhancement.com/google/?microppcsite=google&microppcterm=%22%3E%3Cmarquee%3E%3Ch1%3EBob_just_wants_your_money.%3C%2Fh1%3E%3C%2Fmarquee%3E</a><br /><br />Again, a <a href="http://holisticinfosec.org/video/enhancement/enhancement.html" target="_blank">video</a>, should IDR choose to fix their app.<br /><br />And now, the grand prize for pathetic: The ExtenZe site is <a href="https://www.mcafeesecure.com/RatingVerify?ref=www.extenzeforlife.com" target="_blank">McAfee Secure</a>. <br /><br />I couldn't make this stuff up if I tried.<br />You thought www stood for world wide web. Try wee willy wankers. *sigh*<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html&title=XSS%20Comedy%20III:%20Tax%20Cheats%20with%20Small%20Equipment " title="XSS Comedy III: Tax Cheats with Small Equipment ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html" title="XSS Comedy III: Tax Cheats with Small Equipment ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 13:52:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/idr">idr</category>
      <category domain="http://securityratty.com/tag/idr choose">idr choose</category>
      <category domain="http://securityratty.com/tag/extenze site">extenze site</category>
      <category domain="http://securityratty.com/tag/extenze">extenze</category>
      <category domain="http://securityratty.com/tag/variable">variable</category>
      <category domain="http://securityratty.com/tag/consistent variable">consistent variable</category>
      <category domain="http://securityratty.com/tag/wankers">wankers</category>
      <category domain="http://securityratty.com/tag/choose">choose</category>
      <category domain="http://securityratty.com/tag/tax relief">tax relief</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/xss-comedy-iii-tax-cheats-with-small.html">XSS Comedy III: Tax Cheats with Small Equipment</source>
    </item>
    <item>
      <title><![CDATA[Vulnerabilities quickly mitigated by security-conscious vendors]]></title>
      <link>http://securityratty.com/article/7953938c09c36aba1397daeec84ac8ab</link>
      <guid>http://securityratty.com/article/7953938c09c36aba1397daeec84ac8ab</guid>
      <description><![CDATA[As you are likely aware, I spend a fair bit of time heckling those I believe deserving due to their shortcomings with regard to protecting online consumers
I do, however, continue to seek...]]></description>
      <content:encoded><![CDATA[As you are likely aware, I spend a fair bit of time heckling those I believe deserving due to their shortcomings with regard to protecting online consumers.<br />I do, however, continue to seek opportunities to shed positive light as well, and recent responses from a number of vendor/developers warrant an opportunity to do just that.<br />In the last 30 days, I've discovered vulnerabilities in products from four different vendors, and <a href="http://holisticinfosec.org/content/category/6/23/45/" target="_blank">advised</a> them all immediately upon discovery. Usually, that's where the story ends, as sadly, my repeated requests for action are often ignored. The last 30 days have proven to be entirely different, with swift responses and action from ALL vendors to whom I reported vulnerabilities. In all cases I received replies within 24 hours or less, and patches/fixes/updates were typically released within 24-72 additional hours. These are exemplary responses, and reflect why I choose to conduct vulnerability research. I believe we, as web application professionals (both developers and security practitioners), are beholden to the greater public and must endeavor to protect the online safety of the Internet consumer. <br />To each of these vendors/developers I'd like to issue a hearty "well done" and issue public kudos for their diligence and security consciousness, on behalf of consumers and website operators.<br />To Lukas of <a href="http://planetluc.com/en/" target="_blank">PlanetLuc</a>, Jasper and Eric of <a href="http://infrae.com/products/silva" target="_blank">Infrae/Silva</a>, Alexander of <a href="http://www.compactcms.nl/" target="_blank">CompactCMS</a>, and Peter from <a href="http://activecampaign.com/" target="_blank">ActiveCampaign</a> may I say that your efforts are greatly appreciated. Where too few choose to do the right thing, your responses leave us with the perception of caring and integrity.<br />Thank you.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/11/vulnerabilities-quickly-mitigated-by.html&title=Vulnerabilities%20quickly%20mitigated%20by%20security-conscious%20vendors " title="Vulnerabilities quickly mitigated by security-conscious vendors ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/11/vulnerabilities-quickly-mitigated-by.html" title="Vulnerabilities quickly mitigated by security-conscious vendors ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/11/vulnerabilities-quickly-mitigated-by.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 11 Nov 2008 17:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/responses">responses</category>
      <category domain="http://securityratty.com/tag/swift responses">swift responses</category>
      <category domain="http://securityratty.com/tag/exemplary responses">exemplary responses</category>
      <category domain="http://securityratty.com/tag/issue public kudos">issue public kudos</category>
      <category domain="http://securityratty.com/tag/public">public</category>
      <category domain="http://securityratty.com/tag/issue">issue</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/web application professionals">web application professionals</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/vulnerabilities-quickly-mitigated-by.html">Vulnerabilities quickly mitigated by security-conscious vendors</source>
    </item>
    <item>
      <title><![CDATA[Ticketmaster/Paciolan XSS: Thanks, but I'll buy at the stadium]]></title>
      <link>http://securityratty.com/article/6f061166c9d2ed01f029ede10862d142</link>
      <guid>http://securityratty.com/article/6f061166c9d2ed01f029ede10862d142</guid>
      <description><![CDATA[As if the extra Ticketmaster fees weren't enough, how about the prospect of your PII being stolen because they forgot to perform proper due diligence via a web application security assessment on...]]></description>
      <content:encoded><![CDATA[As if the extra Ticketmaster fees weren't enough, how about the prospect of your <a href="http://en.wiktionary.org/wiki/PII" target="_blank">PII</a> being stolen because they forgot to perform proper due diligence via a web application security assessment on recent <a href="http://press.ticketmaster.com/Extranet/TMPRArticlePressReleases.aspx?id=5530" target="_blank">acquisition</a> <a href="http://paciolan.com/" target="_blank">Paciolan</a>?<br />Consider the following Google search <a href="http://www.google.com/search?hl=en&q=site:ev12.evenue.net&start=10&sa=N">results</a>. The server referenced therein hosts an "integrated ticketing system that enables venues to manage their own tickets."<br />Rutgers, University of Washington, Army, Air Force, Navy, Baylor, Notre Dame, even the American Museum of Natural History; all sell their tickets online through the Ticketmaster/Paciolan offering.<br />And they're all vulnerable as a result.<br />I've made multiple attempts to notify these folks, and have been ignored, so time for a scolding as my Gran used to say.<br />It's been awhile since I've brought video to bear and while I've nothing against the Arkansas Razorbacks, I had to utilize someone's instance of this service to prove my point, so away we go.<br />By the way, I just love the Verisign Secured badge (it's not going to help here).<br />Here's the full URL:<br /><a href="http://ev12.evenue.net/cgi-bin/ncommerce3/SEGetEventList?groupCode=FB&linkID=arkansas&shopperContext=&caller=&appCode=&RSRC=TM&RDAT=FB08SPLASH" target="_blank">http://ev12.evenue.net/cgi-bin/ncommerce3/SEGetEventList?groupCode=FB&linkID=arkansas&shopperContext=&caller=&appCode=&RSRC=TM&RDAT=FB08SPLASH</a><br />The <span style="font-style:italic;">shopperContext</span> (how ironic) variable is the parameter with issues. Mind you, this holds true for any university or venue using this service.<br /><br />For your viewing pleasure, the <a href="http://holisticinfosec.org/video/paciolan/paciolan.html" target="_blank">video</a>.<br /><br />Yes, they take your credit card information, and conduct the ticket purchase transaction. If you've read my blog, you know by now the risks inherent to cross-site scripting vulnerabilities under circumstances like these. Verisign SSL certs are nice, but won't help the consumer if the web app is vulnerable.<br /><br />Thanks, but I'll buy my tickets at the stadium. ;-)<br /><br />Should Ticketmaster/Paciolan fix this issue, I'll update the post accordingly.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/10/ticketmasterpaciolan-xss-thanks-but-ill.html&title=Ticketmaster/Paciolan%20XSS:%20Thanks,%20but%20I'll%20buy%20at%20the%20stadium " title="Ticketmaster/Paciolan XSS: Thanks, but I'll buy at the stadium ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/10/ticketmasterpaciolan-xss-thanks-but-ill.html" title="Ticketmaster/Paciolan XSS: Thanks, but I'll buy at the stadium ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/10/ticketmasterpaciolan-xss-thanks-but-ill.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 28 Oct 2008 17:30:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tickets">tickets</category>
      <category domain="http://securityratty.com/tag/tickets online">tickets online</category>
      <category domain="http://securityratty.com/tag/verisign ssl certs">verisign ssl certs</category>
      <category domain="http://securityratty.com/tag/verisign">verisign</category>
      <category domain="http://securityratty.com/tag/credit card information">credit card information</category>
      <category domain="http://securityratty.com/tag/ticket purchase transaction">ticket purchase transaction</category>
      <category domain="http://securityratty.com/tag/extra ticketmaster fees">extra ticketmaster fees</category>
      <category domain="http://securityratty.com/tag/recent acquisition paciolan">recent acquisition paciolan</category>
      <category domain="http://securityratty.com/tag/natural history">natural history</category>
      <source url="http://holisticinfosec.blogspot.com/2008/10/ticketmasterpaciolan-xss-thanks-but-ill.html">Ticketmaster/Paciolan XSS: Thanks, but I'll buy at the stadium</source>
    </item>
    <item>
      <title><![CDATA[Open Redirects and Common Weakness Enumeration]]></title>
      <link>http://securityratty.com/article/2b11b1167225de8773bed54b38eba5fc</link>
      <guid>http://securityratty.com/article/2b11b1167225de8773bed54b38eba5fc</guid>
      <description><![CDATA[Hopefully, you're more than familiar with CVE (Common Vulnerabilities and Exposures), but perhaps you're less familiar with CWE (Common Weaknesses Enumeration). Both are significant efforts,...]]></description>
      <content:encoded><![CDATA[Hopefully, you're more than familiar with <a href="http://cve.mitre.org/" target="_blank">CVE</a> (Common Vulnerabilities and Exposures), but perhaps you're less familiar with <a href="http://cwe.mitre.org/index.html" target="_blank">CWE</a> (Common Weaknesses Enumeration). Both are significant efforts, international in scope, and the excellent products of <a href="http://www.mitre.org/" target="_blank">The MITRE Corporation</a>, sponsored by the <a href="http://www.us-cert.gov/" target="_blank">National Cyber Security Division</a> of the <a href="http://www.dhs.gov/" target="_blank">U.S. Department of Homeland Security</a>.<br />Approximately six months ago I was discussing open redirect vulnerabilities with Steven Christey of MITRE, who mentioned that that CWE <a href="http://web.archive.org/web/20080114070538/http://cwe.mitre.org/data/definitions/601.html" target="_blank">entry</a> for open redirects was sparse and dated, with little reference material. In particular, he pointed out the lack of defining papers. I accepted this information as a challenge and produced an article that was published in <a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-17.pdf" target="_blank">(IN)SECURE Issue 17</a>. Soon after Issue 17 went live, I also took note of an excellent academic paper specific to the topic of open redirect vulnerabilities; Shue, Kalafut and Gupta's <a href="http://www.cs.indiana.edu/cgi-pub/cshue/research/woot08.pdf" target="_blank">Exploitable Redirects on the Web: Identification, Prevalence, and Defense</a>. Complete with these two papers as references, as well as two current CVE identifiers for popular web applications suffering from open redirect vulnerabilities (discovered by yours truly), CVE-2008-<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2052" target="_blank">2052</a> & <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2951" target="_blank">2951</a>, <a href="http://cwe.mitre.org/data/definitions/601.html" target="_blank">CWE-601: URL Redirection to Untrusted Site (aka 'Open Redirect')</a> is now current and complete.<br />As open redirects are undoubtedly one of my <a href="http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html" target="_blank">biggest</a> <a href="http://holisticinfosec.blogspot.com/2008/07/bitrix-open-redirect-vulnerability.html" tagte="_blank">pet</a> <a href="http://holisticinfosec.blogspot.com/2008/06/open-redirect-vulnerabilities-article.html" target="_blank">peeves</a>, I am pleased to no end. Hopefully CWE-601 will help drive more application vendors and site operators to put an end to this easily mitigated vulnerability.<br /><br /><span style="font-style:italic;">CWE:<br />"International in scope and free for public use, CWE™ provides a unified, measurable set of software weaknesses that is enabling more effective discussion, description, selection, and use of software security tools and services that can find these weaknesses in source code and operational systems as well as better understanding and management of software weaknesses related to architecture and design."</span><br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/10/open-redirects-and-common-weakness.html&title=Open%20Redirects%20and%20Common%20Weakness%20Enumeration " title="Open Redirects and Common Weakness Enumeration ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/10/open-redirects-and-common-weakness.html" title="Open Redirects and Common Weakness Enumeration ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/10/open-redirects-and-common-weakness.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Thu, 16 Oct 2008 10:58:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/redirects">redirects</category>
      <category domain="http://securityratty.com/tag/common weaknesses enumeration">common weaknesses enumeration</category>
      <category domain="http://securityratty.com/tag/weaknesses">weaknesses</category>
      <category domain="http://securityratty.com/tag/redirect">redirect</category>
      <category domain="http://securityratty.com/tag/cwe">cwe</category>
      <category domain="http://securityratty.com/tag/redirect vulnerabilities">redirect vulnerabilities</category>
      <category domain="http://securityratty.com/tag/cwe-601">cwe-601</category>
      <category domain="http://securityratty.com/tag/software weaknesses">software weaknesses</category>
      <category domain="http://securityratty.com/tag/cve">cve</category>
      <source url="http://holisticinfosec.blogspot.com/2008/10/open-redirects-and-common-weakness.html">Open Redirects and Common Weakness Enumeration</source>
    </item>
    <item>
      <title><![CDATA[Expanding Response: Deeper Analysis for Incident Handlers]]></title>
      <link>http://securityratty.com/article/3bd8455fedce6ac873ea3b9f63cd7b90</link>
      <guid>http://securityratty.com/article/3bd8455fedce6ac873ea3b9f63cd7b90</guid>
      <description><![CDATA[To achieve my GCIH Gold, I recently completed a paper called Expanding Response: Deeper Analysis for Incident Handlers , now available in the SANS Reading Room . The premise was to further expand on...]]></description>
      <content:encoded><![CDATA[To achieve my GCIH Gold, I recently completed a paper called <a href="http://www.sans.org/reading_room/whitepapers/incident/32904.php">Expanding Response: Deeper Analysis for Incident Handlers</a>, now available in the <a href="http://www.sans.org/reading_room/">SANS Reading Room</a>. The premise was to further expand on the topics discussed in my <a href="http://holisticinfosec.blogspot.com/2007/12/malware-analysis-tools.html">Malware analysis tools</a> post. This paper includes tools discussed at various times in my <a href="http://holisticinfosec.org/content/view/12/26/">toolsmith</a> column in the <a href="http://issa.org/Members/Journal.html">ISSA Journal</a>, and includes details on <a href="http://qosient.com/argus/">Argus</a>, <a href="http://www.rawpacket.org/projects/hex/hex-livecd/version-20-release">HeX</a>, <a href="http://writequit.org/projects/nsm-console/">NSM-Console</a>, and <a href="http://sourceforge.net/projects/networkminer/">NetworkMiner</a>.<br /><br />Abstract:<br />    <span style="font-style:italic;">"The perspective embraced for this discussion is that of an analyst who is working a process to determine the exact nature of malicious software on his network. He is in receipt of the above mentioned .exe and .pcap files and seeks to further his understanding with the use of less typical tools. She begins the process with the network capture, and then takes a closer look at the binary to see what can be learned and what the impacts of an outbreak on her network might be."</span><br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html&title=Expanding%20Response:%20Deeper%20Analysis%20for%20Incident%20Handlers " title="Expanding Response: Deeper Analysis for Incident Handlers ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html" title="Expanding Response: Deeper Analysis for Incident Handlers ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Fri, 10 Oct 2008 04:38:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/paper includes tools">paper includes tools</category>
      <category domain="http://securityratty.com/tag/incident handlers">incident handlers</category>
      <category domain="http://securityratty.com/tag/network capture">network capture</category>
      <category domain="http://securityratty.com/tag/deeper analysis">deeper analysis</category>
      <category domain="http://securityratty.com/tag/paper">paper</category>
      <category domain="http://securityratty.com/tag/gcih gold">gcih gold</category>
      <category domain="http://securityratty.com/tag/includes details">includes details</category>
      <category domain="http://securityratty.com/tag/pcap files">pcap files</category>
      <source url="http://holisticinfosec.blogspot.com/2008/10/expanding-response-deeper-analysis-for.html">Expanding Response: Deeper Analysis for Incident Handlers</source>
    </item>
    <item>
      <title><![CDATA[The McAfee Secure Standard: Sort Of]]></title>
      <link>http://securityratty.com/article/93a923291bb66872facd096a29cc894d</link>
      <guid>http://securityratty.com/article/93a923291bb66872facd096a29cc894d</guid>
      <description><![CDATA[I need your help
I am in receipt of the McAfee Secure Standard, drafted to transparently describe the McAfee Secure service, as promised during my meeting with Joe Pierini and Kirk Lawrence of McAfee...]]></description>
      <content:encoded><![CDATA[I need your help.<br />I am in receipt of the McAfee Secure Standard, drafted to transparently describe the McAfee Secure service, as promised during my <a href="http://holisticinfosec.blogspot.com/2008/08/mcirony-unexpected-response-from-mcafee.html" target="_blank">meeting</a> with Joe Pierini and Kirk Lawrence of McAfee some weeks ago. I admit my attitude has soured since last I discussed it here, as the Standard is not yet ready for public release (I last said 2-3 weeks and that was five weeks ago), but bear with me. I can't publish exact quotes from the Standard, as I've promised not to, but let me give you insight on the upside, then the downside.<br /><br />The upside includes all the transparency we'd hoped for. You'll read the McAfee Secure Standard and know exactly where they stand with regard as to what can be expected of the McAfee Secure Service. My discussions with Joe Pierini have been productive and respectful, he means well, and I believe he will try to drive the greater McAfee leadership to officially incorporate suggestions made in this blog. <br />I have even had the pleasure of reading a Researcher/Finder Policy that very succinctly describes what researchers can expect when they submit vulnerabilities found in McAfee Secure sites. That's all good stuff and to be applauded.<br /><br />Now for the downside.<br /><br />The McAfee Secure Standard will draw a clear distinction between "enterprise" customers and all the Ma & Pa websites who have so loved McAfee Secure / ScanAlert Hacker Safe for conversions.<br />The most glaring and painful distinction for me is this. While enterprise customers will have a clearly defined time line in which to remediate script injection vulnerabilities like XSS and open redirects, before losing their McAfee Secure badge, <span style="font-weight:bold;">the Ma & Pa sites will have absolutely no requirement to fix their XSS issues</span>. XSS vulnerabilities and the McAfee Secure badge will remain consistent on all those sites that care more about "convincing" their customers that they're secure with a McAfee Secure badge; a badge that, by its own pending standard, will contradict what we know to be truly secure.<br /><br />My views are clear. I have made every effort to convince McAfee that this stance is counter intuitive to good web application security standards. I believe that, in their own way, they are listening. So here's your chance.<br />1) Is transparency enough?<br />2) Is holding only enterprise customers accountable acceptable?<br />3) Should ALL McAfee Secure customers be expected to fix their vulnerabilities, even if on different timelines?<br />4) What else do you want McAfee to hear, in the form of constructive feedback only?<br />I will publish all well written, thoughtful comments here. Let's keep it positive and see if we can help convince McAfee that script injection vulnerabilities and McAfee Secure can't exist in the same physical space. Like matter and anti-matter. ;-)<br />The floor is yours...<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/10/mcafee-secure-standard-sort-of.html&title=The%20McAfee%20Secure%20Standard:%20Sort%20Of " title="The McAfee Secure Standard: Sort Of ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/10/mcafee-secure-standard-sort-of.html" title="The McAfee Secure Standard: Sort Of ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/10/mcafee-secure-standard-sort-of.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 19:47:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mcafee">mcafee</category>
      <category domain="http://securityratty.com/tag/mcafee secure customers">mcafee secure customers</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/mcafee secure sites">mcafee secure sites</category>
      <category domain="http://securityratty.com/tag/mcafee secure standard">mcafee secure standard</category>
      <category domain="http://securityratty.com/tag/mcafee secure service">mcafee secure service</category>
      <category domain="http://securityratty.com/tag/mcafee secure">mcafee secure</category>
      <category domain="http://securityratty.com/tag/loved mcafee secure">loved mcafee secure</category>
      <category domain="http://securityratty.com/tag/convince mcafee">convince mcafee</category>
      <source url="http://holisticinfosec.blogspot.com/2008/10/mcafee-secure-standard-sort-of.html">The McAfee Secure Standard: Sort Of</source>
    </item>
    <item>
      <title><![CDATA[FileAdvisor: software file search engine]]></title>
      <link>http://securityratty.com/article/856af459093a6fe1d8cb8a725ef66103</link>
      <guid>http://securityratty.com/article/856af459093a6fe1d8cb8a725ef66103</guid>
      <description><![CDATA[Troy Larson sent me a heads up on Bit9's FileAdvisor , a service they describe as &quot;a comprehensive catalog of executables, drivers, and patches found in commercial Windows applications and software...]]></description>
      <content:encoded><![CDATA[<a href="http://www.itsec.e-symposium.com/speakers/troy-larson.php" target="_blank">Troy Larson</a> sent me a heads up on Bit9's <a href="http://fileadvisor.bit9.com/services/search.aspx" target="_blank">FileAdvisor</a>, a service they describe as "a comprehensive catalog of executables, drivers, and patches found in commercial Windows applications and software packages. Malware and other unauthorized software that affects Windows computers is also indexed." <br />I immediately checked the FileAdvisor db for malware results as well non-Windows binaries and was pleasantly surprised with immediate and comprehensive results. You do have to register, but I was further impressed with the fact that they offered the option for a short or full <a href="http://fileadvisor.bit9.com/services/register.aspx" target="_blank">registration</a>.<br />This appears to be worthy of a bookmark in your incident handler/malware researcher/forensic investigator toolkit.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/10/fileadvisor-software-file-search-engine.html&title=FileAdvisor:%20software%20file%20search%20engine " title="FileAdvisor: software file search engine ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/10/fileadvisor-software-file-search-engine.html" title="FileAdvisor: software file search engine ">digg</a>]]></content:encoded>
      <pubDate>Wed, 01 Oct 2008 10:34:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/fileadvisor">fileadvisor</category>
      <category domain="http://securityratty.com/tag/commercial windows applications">commercial windows applications</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware results">malware results</category>
      <category domain="http://securityratty.com/tag/software packages">software packages</category>
      <category domain="http://securityratty.com/tag/affects windows computers">affects windows computers</category>
      <category domain="http://securityratty.com/tag/comprehensive results">comprehensive results</category>
      <category domain="http://securityratty.com/tag/incident handlermalware">incident handlermalware</category>
      <source url="http://holisticinfosec.blogspot.com/2008/10/fileadvisor-software-file-search-engine.html">FileAdvisor: software file search engine</source>
    </item>
    <item>
      <title><![CDATA[XSF & XSS: Double your pleasure, double your fun]]></title>
      <link>http://securityratty.com/article/1fae85d8335f0c9fbe56b8858c8692c2</link>
      <guid>http://securityratty.com/article/1fae85d8335f0c9fbe56b8858c8692c2</guid>
      <description><![CDATA[If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less...]]></description>
      <content:encoded><![CDATA[If you've read this blog, or those of my peers, you're likely quite familiar with cross-site scripting, and the problems associated with open redirect vulnerabilities. A vulnerability you may be less familiar with is <a href="http://www.xssed.com/news/26/Cross-site_framed/" target="_blank">cross-site framing</a>, which largely couples the best of both above-mentioned vulnerabilities. <br />What then, if there's a cross-site framing vulnerability coupled with cross-site scripting in the content offered by the frame? All sorts of problems come to mind: phishing, malware, credential theft; all arguably twice removed from the attacker's source, tucked away in the context of two victim sites.<br />First, I'll discuss the original XSS issue that led to this finding.<br />Recently, I was investigating a flawed parameter in <a href="http://www.openhire.com/" target="_blank">Openhire</a>, a career posting vendor used by major companies like <a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?company_id=15635&version=1" target="_blank">Crate&Barrel</a>, Eileen Fisher, Enterprise, Benjamin Moore, Scottrade, and Getty Images.<br />Most of these sites simply link to the Openhire offering that hosts job postings on their behalf which, in turn, has been crafted to look like the referring site.<br />As an example, here's Scottrade's employment page hosted by Openhire.<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?version=1&company_id=15624" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?version=1&company_id=15624</a></span><br /><br />Standard stuff, looks nicely like the Scottrade site, so everything's cool, right?<br />Wrong? What if someone hosting a service on your behalf suffers a security gap?<br /><span style="font-weight:bold;">You're only as strong as your weakest link!</span><br />Here's the posting for an Application Security Engineer (funny, eh?) at Scottrade as hosted on their behalf by Openhire:<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=976367&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters%3B%3B%3BInformation%20Technology%3B%3B%3BSecurity&startflag=3&CFID=66851845&CFTOKEN=29a95-d12594d4-47d9-49e8-9067-1091bdf68e80" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=976367&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters%3B%3B%3BInformation%20Technology%3B%3B%3BSecurity&startflag=3&CFID=66851845&CFTOKEN=29a95-d12594d4-47d9-49e8-9067-1091bdf68e80</a></span><br /><br />Now here the same job posting spewing massive cookie data:<br /><br /><span style="font-style:italic;"><a href="http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3" target="_blank">http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3</a></span><br /><br />Screen shot offered below, as the code above will likely be repaired very soon by Openhire. I notified them this past Thursday.<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNcebDIT4JI/AAAAAAAAADA/2umzh0wbmmw/s1600-h/Scottrade_Openhire.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNcebDIT4JI/AAAAAAAAADA/2umzh0wbmmw/s320/Scottrade_Openhire.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248697340769067154" /></a><br /><br />It's bad enough when there's an application security hole in code someone else is hosting on your behalf, but what if your method of displaying said code is also at risk? Enter the Getty Images Jobs page.<br /><br /><span style="font-style:italic;"><a href="http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=careeropps&startflag=0&company_id=15531&version=2&CFID=12265212&CFTOKEN=60213778" target="_blank">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=careeropps&startflag=0&company_id=15531&version=2&CFID=12265212&CFTOKEN=60213778</a></span><br /><br />Watch what happens when you pull the Openhire code. Can you say self-replicating frame loop from hell (in Firefox)? Trust me your browser will crash if you leave this running too long. This will likely be fixed soon, so if the URL doesn't work, the screen shot exemplifies the issue.<br /><br /><a href="http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html" target="_blank">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html</a><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SNcqO933d4I/AAAAAAAAADY/SSzLv3ZpiN0/s1600-h/GettyonGetty.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SNcqO933d4I/AAAAAAAAADY/SSzLv3ZpiN0/s320/GettyonGetty.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248710327339022210" /></a><br /><br />What if, instead of Openhire's Getty Images page, or nothing at all (which obviously creates its own issue), we drop in an arbitrary URL?<br />Yep, you guessed it.<br /><span style="font-style:italic;"><br />http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://www.xssed.com/news/26/Cross-site_framed/</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SNcmqF3wQyI/AAAAAAAAADI/EhR6rYOmwlI/s1600-h/Getty_XSF.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SNcmqF3wQyI/AAAAAAAAADI/EhR6rYOmwlI/s320/Getty_XSF.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248706395295990562" /></a><br /><br />Now, bringing it all home for double the pleasure, double the fun, what if we coupled the original Openhire cross-site scripting vuln with Getty Images cross-site frame vuln?<br /><br />It hurts twice as much, in my book.<br /><br /><span style="font-style:italic;">http://www.gettyimagesjobs.com/gettyImagesJobsDisplay.html?http://hostedjobs.openhire.com/epostings/jobs/submit.cfm?fuseaction=dspjob&id=23&jobid=130527&company_id=15624&version=1&source=ONLINE&JobOwner=%22%3E%3CSCRIPT%3Ealert(document.cookie)%3C/SCRIPT%3E&level=levelid3&levelid3=18247&parent=St.%20Louis%20Corporate%20Headquarters;;;Information%20Technology;;;Security&startflag=3</span><br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNco1c6ensI/AAAAAAAAADQ/QaKByEFozTU/s1600-h/Getty%2BScottrade.png" target="_blank"><img style="cursor:pointer; cursor:hand;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/SNco1c6ensI/AAAAAAAAADQ/QaKByEFozTU/s320/Getty%2BScottrade.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5248708789483249346" /></a><br /><br />The lessons learned:<br />1) Ensure your partners are writing secure code on you behalf.<br />2) Ensure that the code you utilize to incorporate said partner's code is also well written. ;-)<br /><br />Double the headache, double the dumb.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html&title=XSF%20&%20XSS:%20Double%20your%20pleasure,%20double%20your%20fun " title="XSF & XSS: Double your pleasure, double your fun ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html" title="XSF & XSS: Double your pleasure, double your fun ">digg</a>]]></content:encoded>
      <pubDate>Sun, 21 Sep 2008 17:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/openhire code">openhire code</category>
      <category domain="http://securityratty.com/tag/openhire">openhire</category>
      <category domain="http://securityratty.com/tag/original openhire cross-site">original openhire cross-site</category>
      <category domain="http://securityratty.com/tag/scottrade site">scottrade site</category>
      <category domain="http://securityratty.com/tag/scottrade">scottrade</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/secure code">secure code</category>
      <category domain="http://securityratty.com/tag/code">code</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/xsf-xss-double-your-pleasure-double.html">XSF &amp; XSS: Double your pleasure, double your fun</source>
    </item>
    <item>
      <title><![CDATA[EstDomains & Intercage: A Perfect Couple in Crime]]></title>
      <link>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</link>
      <guid>http://securityratty.com/article/8490240982532919695d5c4c9231e15f</guid>
      <description><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's take on the...]]></description>
      <content:encoded><![CDATA[If you track malware issues as readily as I do, you're likely aware of the failings of clownpacks like EstDomains and their hosting buddies Atrivo/Intercage. You need only follow Sunbelt's <a href="http://www.google.com/search?hl=en&q=site%3Asunbeltblog.blogspot.com+estdomains+atrivo+intercage&btnG=Search" target="_blank">take</a> on the topic, or <a href="http://www.emergingthreats.net/index.php?searchword=intercage&option=com_search&Itemid=5" target="_blank">search</a> Emergingthreats to come up to speed.<br />Yesterday, EstDomains posted the most inept, ridiculous <a href="http://www.domainnews.com/en/general/estdomains-denies-links-to-malware-distribution.html" target="_blank">response</a> ever issued to the endless and worthy criticism, largely <a href="http://technewsreview.com.au/article.php?article=5882" target="_blank">leveled</a> by Brian Krebs at the Washington Post. <br />Not only can't these morons from EstDomains write, they're either so deeply clueless or flagrantly malicious (likely both), it's beyond laughable. This section sums it up best:<br /><span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality. But the outstanding performance of hosting services is not the sole reason why EstDomains, Inc appreciates this partnership so greatly. Intercage, Inc generously provides EstDomains, Inc specialists with reports regarding discovered malware vehicles. As the main database for additional domain name management services is located in Intercage Data Center, EstDomains, Inc has the perfect opportunity to get notifications of the slightest mark of malware presence in the shortest time and take measures in advance."</span><br /><span style="font-weight:bold;">What? Really?</span> <br />Again, aside from the absolute butchery of the language, did they just say <span style="font-style:italic;">"The company also has a reliable ally in its battle against malware in a face of Intercage, Inc which provides company with the hosting services of the highest quality."</span>? SIGH...yes, they did.<br /><br />Allow me to exemplify just how ridiculous a claim that is.<br />Following is content from a packet capture I took during a recent Storm worm analysis.<br /><br />Using the ip2asn module included in <a href="http://writequit.org/projects/nsm-console/" target="_blank">NSM-console</a> availabe in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we find:<br />27595   | 216.255.189.211  | INTERCAGE - InterCage, Inc.<br /><br />Using Etherape, also included in <a href="http://www.rawpacket.org/projects/hex" target="_blank">HeX</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s1600-h/etherape_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://2.bp.blogspot.com/_kVOWaY1TAF0/SM880rNW5JI/AAAAAAAAACs/dWY8MUgSMUU/s320/etherape_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246478966559532178" /></a><br /><br />Using <a href="http://networkminer.wiki.sourceforge.net/NetworkMiner" target="_blank">Eric Hjelmvik's</a> <a href="http://holisticinfosec.org/toolsmith/docs/august2008.pdf" target="_blank">NetworkMiner</a>, we see:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s1600-h/NetworMiner_intercage.png"><img style="cursor:pointer; cursor:hand;" src="http://4.bp.blogspot.com/_kVOWaY1TAF0/SM8-JQvlEKI/AAAAAAAAAC0/vjYvpHAoFDw/s320/NetworMiner_intercage.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5246480419744190626" /></a><br /><br />See the recurring theme? Intercage, EstDomain's <span style="font-style:italic;">"reliable ally in its battle against malware"</span>.<br />Nice work, guys...keep it up.<br /><br />I'm submitting this to <a href="http://thedailywtf.com/" target="blank">The Daily WTF</a> as we speak.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html&title=EstDomains%20&%20Intercage:%20A%20Perfect%20Couple%20in%20Crime " title="EstDomains & Intercage: A Perfect Couple in Crime ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html" title="EstDomains & Intercage: A Perfect Couple in Crime ">digg</a>]]></content:encoded>
      <pubDate>Mon, 15 Sep 2008 17:32:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/intercage">intercage</category>
      <category domain="http://securityratty.com/tag/estdomains">estdomains</category>
      <category domain="http://securityratty.com/tag/malware">malware</category>
      <category domain="http://securityratty.com/tag/malware presence">malware presence</category>
      <category domain="http://securityratty.com/tag/intercage data center">intercage data center</category>
      <category domain="http://securityratty.com/tag/track malware issues">track malware issues</category>
      <category domain="http://securityratty.com/tag/reliable ally">reliable ally</category>
      <category domain="http://securityratty.com/tag/management services">management services</category>
      <category domain="http://securityratty.com/tag/malware vehicles">malware vehicles</category>
      <source url="http://holisticinfosec.blogspot.com/2008/09/estdomains-intercage-perfect-couple-in.html">EstDomains &amp; Intercage: A Perfect Couple in Crime</source>
    </item>
  </channel>
</rss>
