<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: trusty]]></title>
    <link>http://securityratty.com/tag/trusty</link>
    <description></description>
    <pubDate>Fri, 28 Mar 2008 11:28:30 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[XSS Comedy at McAfee Secure's Expense]]></title>
      <link>http://securityratty.com/article/415bc504c211b5ee78ee15ea0a533277</link>
      <guid>http://securityratty.com/article/415bc504c211b5ee78ee15ea0a533277</guid>
      <description><![CDATA[In celebration of the deadline for PCI Requirement 6.6 compliance as of June 30, 2008, I thought I'd share a little web app sec comedy at McAfee Secure's expense
As well you should know by know, the...]]></description>
      <content:encoded><![CDATA[In celebration of the deadline for PCI Requirement 6.6 compliance as of June 30, 2008, I thought I'd share a little web app sec comedy at McAfee Secure's expense.<br />As well you should know by know, the existence of XSS vulnerabilities in a site that is required to meet PCI DSS standards means that the site IS NOT PCI COMPLIANT. Very simple, right?<br />Let's consider the McAfee Secure/Hacker Safe-branded site for <a href="http://www.organizeit.com/index.asp" target="_blank">Organize-It</a>.  <br />A seemingly handy site, perfect for your HGTV types, likely with healthy credit card limits. Uh-oh, here it comes. Oh yes, Organize-It handles credit cards and is thus beholden to PCI DSS.<br />Organize-It is also proudly displaying a <span style="font-weight:bold;">current</span> McAfee Secure <a href="https://www.mcafeesecure.com/RatingVerify?ref=www.organizes-it.com" target="_blank">badge</a>, indicating that it's tested <span style="font-weight:bold;">daily</span>.<br />Given the focus of many a recent discussion it shouldn't shock you that Organize-It is vulnerable to XSS. <br />What's funny is what Organize-It does with regard to "handling" malformed requests.<br />Where a typical test string for XSS might be <span style="font-style:italic;">" script payload /script</span> (characters removed or Blogger will let me XSS myself), you won't get much use from such a string via either direct form submittal or URL encoding. But when the site barfed up <span style="font-style:italic;">'; // LEAVE THIS VALUE var sli_cId = 90;</span>, while under investigation, my ruh-roh meter went off. <br />I decided to play with my trusty <span style="font-style:italic;">marquee</span> test and found interesting results. The actual search form field is limited to 41 characters (er?). So my complete string of   <span style="font-style:italic;">" marquee message /marquee</span> didn't fit for direct submittal BUT THE MARQUEE RENDERED ANYWAY! Basically, half the test string worked: <span style="font-style:italic;">" marquee h1 This_site_is_NOT_McAfee_S</span><br />Forget the marquee tag on the blacklist, did we?<br />But here's the real icing on the cake. The uber-intuitive search index reinterpreted my message with what I can only imagine are index keywords. Thus <span style="font-style:italic;">"This site is NOT McAfee Secure"</span> scrolls across the Organize-It site as <span style="font-style:italic;">"this <span style="font-weight:bold;">sit</span> is not <span style="font-weight:bold;">coffee</span> secure"</span>. <br />OMG! My daily quad shot Americano has been pwn3d to the core!<br />Here's the <a href="http://storage.organizeit.com/search?p=Q&ts=custom&w=%22%3E%3Cmarquee%3E%3Ch1%3EThis_site_is_NOT_McAfee_Secure&restricted=mt_restricted_organizesit" target="_blank">URL</a> if you don't believe me, or the <a href="http://holisticinfosec.org/video/organizeit/organizeit.html" target="_blank">video</a> if you prefer.<br />Forget PCI compliance, bring on the Gong Show hook, Chuck!<br />Cheers.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/06/xss-comedy-at-mcafee-secures-expense.html&title=XSS%20Comedy%20at%20McAfee%20Secure's%20Expense " title="XSS Comedy at McAfee Secure's Expense ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/06/xss-comedy-at-mcafee-secures-expense.html" title="XSS Comedy at McAfee Secure's Expense ">digg</a>]]></content:encoded>
      <pubDate>Mon, 30 Jun 2008 17:10:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/seemingly handy site">seemingly handy site</category>
      <category domain="http://securityratty.com/tag/mcafee secure">mcafee secure</category>
      <category domain="http://securityratty.com/tag/mcafee">mcafee</category>
      <category domain="http://securityratty.com/tag/test">test</category>
      <category domain="http://securityratty.com/tag/trusty marquee test">trusty marquee test</category>
      <category domain="http://securityratty.com/tag/organize-it site">organize-it site</category>
      <category domain="http://securityratty.com/tag/marquee">marquee</category>
      <category domain="http://securityratty.com/tag/xss">xss</category>
      <source url="http://holisticinfosec.blogspot.com/2008/06/xss-comedy-at-mcafee-secures-expense.html">XSS Comedy at McAfee Secure's Expense</source>
    </item>
    <item>
      <title><![CDATA[To be liberated, you need to be educated in the facts]]></title>
      <link>http://securityratty.com/article/4f8accdfe2729a3a297f7983e04e293a</link>
      <guid>http://securityratty.com/article/4f8accdfe2729a3a297f7983e04e293a</guid>
      <description><![CDATA[Online safety 101. When will it happen? Sadly, never. Uninformed users will continue to fall for scams and allow their computer and others to be infected and give the malware marketeers lots of...]]></description>
      <content:encoded><![CDATA[<div > Online safety 101. When will it happen? Sadly, never.<br/>Uninformed users will continue to fall for scams and allow their computer and others to be infected and give the malware marketeers lots of profit.<br/>Ok, Im done ranting, Im fine now, really. </div>
<table cellpadding="0" cellspacing="0" width="100%" style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;">
<tr>
<td valign="top">
<table cellpadding="0" cellspacing="0" width="100%" style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;">
<tr>
<td valign="top"><a href="http://clipmarks.com/clipmark/128A15F3-B0FC-4169-BABB-9D7B1F10DF66/" title="go to this clipmark"><img src="http://content.clipmarks.com/blog_icon/bfbf9289-8b18-413c-9f3e-acbfd92ee6a4/128A15F3-B0FC-4169-BABB-9D7B1F10DF66/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /></a>clipped from <a title="http://www.download.com/8301-2007_4-9904894-12.html?tag=bubbl_3" href="http://www.download.com/8301-2007_4-9904894-12.html?tag=bubbl_3" style="font-size: 11px;">www.download.com</a></td>
</tr>
</table>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.download.com/8301-2007_4-9904894-12.html?tag=bubbl_3 -->
<div style="margin: 4px 0px; color: #000000; font-size: 20px;">Spyware Horror Story: Debugging for newbies</div>
</td>
</tr>
</table>
<div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"></div>
<table cellpadding="0" cellspacing="0" width="100%" style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;">
<tr>
<td valign="top"><!-- CLIPPED FROM: http://www.download.com/8301-2007_4-9904894-12.html?tag=bubbl_3 --><P>As liberating as computers are, it&#8217;s terrifying when things go wrong. You&#8217;re left abandoned, even mocked!, by the tools on which you&#8217;ve come so heavily to rely. It&#8217;s like having your trusty accountant wipe a stack of forms to the floor, storm out of the office, and leave you to sort out your own taxes.</P></td>
</tr>
</table>
</td>
</tr>
</table>
<div style="margin: 0px 6px 6px 4px;">
<table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%">
<tr>
<td style="background:transparent;border-width:0px;padding:0px;">&nbsp;</td>
<td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"><a href="http://clipmarks.com/share/128A15F3-B0FC-4169-BABB-9D7B1F10DF66/blog/" title="blog or email this clip"><img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /></a></td>
</tr>
</table>
</div>
</td>
</tr>
</table>
]]></content:encoded>
      <pubDate>Fri, 28 Mar 2008 11:28:30 +0000</pubDate>
      <category domain="http://securityratty.com/tag/malware marketeers lots">malware marketeers lots</category>
      <category domain="http://securityratty.com/tag/trusty accountant wipe">trusty accountant wipe</category>
      <category domain="http://securityratty.com/tag/spyware horror story">spyware horror story</category>
      <category domain="http://securityratty.com/tag/online safety">online safety</category>
      <category domain="http://securityratty.com/tag/taxes">taxes</category>
      <category domain="http://securityratty.com/tag/sadly">sadly</category>
      <category domain="http://securityratty.com/tag/floor">floor</category>
      <category domain="http://securityratty.com/tag/heavily">heavily</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <source url="http://spywarebiz.com/spywarebizblog/?p=409">To be liberated, you need to be educated in the facts</source>
    </item>
  </channel>
</rss>
