<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Computer Security Is My Interest!</title>
	<atom:link href="http://soroush.secproject.com/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://soroush.secproject.com/blog</link>
	<description>Soroush Dalili's Weblog</description>
	<lastBuildDate>Mon, 08 Mar 2010 01:33:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Improve File Uploaders’ Protections &#8211; Bypass Methods- Rev. 1.0</title>
		<link>http://soroush.secproject.com/blog/2010/03/improve-file-uploaders%e2%80%99-protections-rev-1-0/</link>
		<comments>http://soroush.secproject.com/blog/2010/03/improve-file-uploaders%e2%80%99-protections-rev-1-0/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 23:59:35 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[fckeditor bypass methods]]></category>
		<category><![CDATA[file uploader bypass methods]]></category>
		<category><![CDATA[file uploader security bypass]]></category>
		<category><![CDATA[file uploader security improvement]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=232</guid>
		<description><![CDATA[
Some new methods of bypassing file uploaders protections have been discussed. As an example bypassing by using: trailing spaces and dots, “::$data.”, direct Null char, IIS semi-colon  bug, and so on.

Uploading files by using web applications is very common. However, there is always a high risk around this matter. In case of uploading a web-shell [...]]]></description>
			<content:encoded><![CDATA[<blockquote>
<p style="text-align: justify;"><span style="color: #ff0000;"><span style="color: #000000;">Some new methods of bypassing file uploaders protections have been discussed. As an example bypassing by using:<strong> </strong></span><span style="color: #000000;"><strong>trailing spaces and dots, </strong><strong>“::$data.”, </strong><strong>direct Null char, IIS semi-colon  bug,</strong> and so on.</span></span></p>
</blockquote>
<p style="text-align: justify;">Uploading files by using web applications is very common. However, there is always a high risk around this matter. In case of uploading a web-shell file which can be absolutely malicious, an attacker can get the same privilege of access as the web application to the server. In this paper, which is mostly around the Windows-based web applications, some general solutions for protecting against this type of attack have been suggested. Moreover, as a proof of concept, some of the most general protection methods and the way of bypassing them have been discussed.</p>
<p style="text-align: justify;">This article is an educational article to improve the security of the web applications. And, the author of this article (“Soroush Dalili”) does not accept and has no responsibility about the content or usage of this article in any other way. Any other usage of this article except the legal ones is completely prohibited.</p>
<p style="text-align: justify;">Please respect the copyright and mention the name of the author (“Soroush Dalili”) in case of using this article.</p>
<p style="text-align: left;"><a title="http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf" href="http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf" target="_blank"><strong>Download</strong> this article by clicking here.</a> (<a title="http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf" href="http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf" target="_blank">http://soroush.secproject.com/downloadable/Improve File Uploaders’ Protections.pdf</a>)</p>
<p style="text-align: justify;"> </p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2010/03/improve-file-uploaders%e2%80%99-protections-rev-1-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IE7-8 drive list enumeration!</title>
		<link>http://soroush.secproject.com/blog/2010/03/ie7-8-drive-list-enumeration/</link>
		<comments>http://soroush.secproject.com/blog/2010/03/ie7-8-drive-list-enumeration/#comments</comments>
		<pubDate>Thu, 04 Mar 2010 23:48:53 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[My Advisories]]></category>
		<category><![CDATA[Security Posts]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=230</guid>
		<description><![CDATA[Iframe delay in loading the local drives in IE7 and IE8 can cause drive list enumeration!
Proof of Concept is available from this link:
http://plaincipher.com/demo/IE-Drive-Enum-Demo.html
Cheers,
Soroush Dalili
]]></description>
			<content:encoded><![CDATA[<p>Iframe delay in loading the local drives in IE7 and IE8 can cause drive list enumeration!<br />
Proof of Concept is available from this link:<br />
<a href="http://plaincipher.com/demo/IE-Drive-Enum-Demo.html">http://plaincipher.com/demo/IE-Drive-Enum-Demo.html</a></p>
<p>Cheers,<br />
Soroush Dalili</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2010/03/ie7-8-drive-list-enumeration/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Web Application Security Consortium Threat Classification v2.0</title>
		<link>http://soroush.secproject.com/blog/2010/01/the-web-application-security-consortium-threat-classification-v2-0/</link>
		<comments>http://soroush.secproject.com/blog/2010/01/the-web-application-security-consortium-threat-classification-v2-0/#comments</comments>
		<pubDate>Mon, 04 Jan 2010 23:46:00 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[WASC Threat Classification v2.0]]></category>
		<category><![CDATA[Web Application Security Consortium Threat Classification]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=208</guid>
		<description><![CDATA[After OWASP updated its Top 10, now I&#8217;m very glad to quote this:
The Web Application Security Consortium (WASC) is pleased to announce the long awaited release of the WASC Threat Classification v2.0.
You can read more information from these links: http://projects.webappsec.org/Threat-Classification and http://projects.webappsec.org/f/WASC-TC-v2_0.pdf
Cheers,
Soroush
]]></description>
			<content:encoded><![CDATA[<p>After OWASP updated its <a href="http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project" target="_blank">Top 10</a>, now I&#8217;m very glad to quote this:</p>
<blockquote><p>The Web Application Security Consortium (WASC) is pleased to announce the long awaited release of the WASC Threat Classification v2.0.</p></blockquote>
<p>You can read more information from these links: <a href="http://projects.webappsec.org/Threat-Classification" target="_blank">http://projects.webappsec.org/Threat-Classification</a> and <a href="http://projects.webappsec.org/f/WASC-TC-v2_0.pdf" target="_blank">http://projects.webappsec.org/f/WASC-TC-v2_0.pdf</a></p>
<p>Cheers,</p>
<p>Soroush</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2010/01/the-web-application-security-consortium-threat-classification-v2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Contradiction</title>
		<link>http://soroush.secproject.com/blog/2010/01/microsoft-contradiction/</link>
		<comments>http://soroush.secproject.com/blog/2010/01/microsoft-contradiction/#comments</comments>
		<pubDate>Sun, 03 Jan 2010 15:36:56 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[Microsoft IIS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=204</guid>
		<description><![CDATA[First of all, Microsoft is one of the best companies which leads us to the better world. But, nothing is free of fault except God!
I’m writing this post as a response to the Microsoft security response in: “http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx”.
They said that “We’ve completed our investigation into the claims that came up over the holiday of a [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">First of all, Microsoft is one of the best companies which leads us to the better world. But, nothing is free of fault except God!</p>
<p style="text-align: justify;">I’m writing this post as a response to the Microsoft security response in: “<a href="http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx" target="_blank">http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx</a>”.</p>
<p style="text-align: justify;">They said that “We’ve completed our investigation into the claims that came up over the holiday of a possible vulnerability in IIS and found that there is no vulnerability in IIS.”. Therefore, I realized that this is not a Microsoft IIS hole. So, it should be a feature of IIS 6.0! In my opinion it’s a good feature for the attackers to bypass the web uploaders protection. Now my question is: why have they removed this feature from IIS version 7 and 7.5 then? And why are the others so concerned about this feature and some people added it to their exploits collection?</p>
<p>I think it’s not even a critical bug for IIS, but it is highly critical for most of the web applications.</p>
<p style="text-align: justify;">Besides, Microsoft is so wrong about the default configurations since they said “customers who are using IIS 6.0 in the default don’t need to worry about this issue”.  I think they should look at the shared servers default configurations as well as the dedicated ones.</p>
<p style="text-align: justify;">Finally, I think Microsoft should fix this feature as soon as possible to eliminate its risks! And, it is up to the web security researchers and the web penetration testers to decide about the impact of this vulnerability on the web applications.</p>
<p>PS:</p>
<p>You can also look at these links:</p>
<p>-          <a href="http://www.darknet.org.uk/2009/12/microsoft-iis-semicolon-bug-leaves-servers-vulnerable/" target="_blank">http://www.darknet.org.uk/2009/12/microsoft-iis-semicolon-bug-leaves-servers-vulnerable/</a></p>
<p>-          <a href="http://www.esecurityplanet.com/trends/article.php/3855936/article.htm" target="_blank">http://www.esecurityplanet.com/trends/article.php/3855936/article.htm</a></p>
<p>-          <a href="http://www.securityfocus.com/bid/37460/references" target="_blank">http://www.securityfocus.com/bid/37460/references</a></p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2010/01/microsoft-contradiction/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mirror Blog</title>
		<link>http://soroush.secproject.com/blog/2009/12/mirror-blog-4/</link>
		<comments>http://soroush.secproject.com/blog/2009/12/mirror-blog-4/#comments</comments>
		<pubDate>Sat, 26 Dec 2009 01:44:54 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[Mirror Blog]]></category>
		<category><![CDATA[soroush dalili blog]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=200</guid>
		<description><![CDATA[


As my website cannot be opened from Iran, I made a mirror blog at: http://irsdl.wordpress.com/
However, I do not think that I can sync. the comments.
Cheers,
Soroush



]]></description>
			<content:encoded><![CDATA[<div>
<div>
<div>
<p>As my website cannot be opened from Iran, I made a mirror blog at: <a href="http://irsdl.wordpress.com/" target="_blank">http://irsdl.wordpress.com/</a></p>
<p>However, I do not think that I can sync. the comments.</p>
<p>Cheers,</p>
<p>Soroush</p>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/12/mirror-blog-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browsers’ Pain: A recursive function!</title>
		<link>http://soroush.secproject.com/blog/2009/12/browsers%e2%80%99-pain-a-recursive-function/</link>
		<comments>http://soroush.secproject.com/blog/2009/12/browsers%e2%80%99-pain-a-recursive-function/#comments</comments>
		<pubDate>Fri, 25 Dec 2009 20:36:55 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[Browsers’ Pain]]></category>
		<category><![CDATA[Mozilla Crash Function]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=188</guid>
		<description><![CDATA[I have written a recursive function by using Javascript “setInterval” function which calls itself. Unfortunately, none of the last version of famous browsers such as Internet Explorer (8), Chrome (3.0.195.38), and Mozilla Firefox (3.5.6) blocks this script. Moreover, it takes more than 50% of my CPU which is Intel Core 2 Dou 2.50 GHz.
And the [...]]]></description>
			<content:encoded><![CDATA[<p>I have written a recursive function by using Javascript “setInterval” function which calls itself. Unfortunately, none of the last version of famous browsers such as Internet Explorer (8), Chrome (3.0.195.38), and Mozilla Firefox (3.5.6) blocks this script. Moreover, it takes more than 50% of my CPU which is Intel Core 2 Dou 2.50 GHz.<br />
And the worst one is Mozilla Firefox which stops working after running this script instead of showing a page to stop the script.<br />
This script is:</p>
<blockquote><p>&lt;script&gt;<br />
function recursiveFunc(){setInterval(&#8220;recursiveFunc()&#8221;,1);}<br />
recursiveFunc();<br />
&lt;/script&gt;</p></blockquote>
<p>Just save it as an HTML file, and try to open it with your browsers. You can convert “1” to “0” to get better result in Mozilla Firefox and Chrome.<br />
I reported it to Mozilla Firefox as a bug.<br />
Good luck.</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/12/browsers%e2%80%99-pain-a-recursive-function/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft IIS Semi-Colon Vulnerability</title>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/</link>
		<comments>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/#comments</comments>
		<pubDate>Fri, 25 Dec 2009 17:50:44 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[My Advisories]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[Execute ASP by JPG]]></category>
		<category><![CDATA[IIS File Extension Security Bypass]]></category>
		<category><![CDATA[IIS semicolon bug]]></category>
		<category><![CDATA[IIS semicolon vulnerability]]></category>
		<category><![CDATA[Microsoft IIS Vulnerability]]></category>
		<category><![CDATA[Run ASP by JPG]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=185</guid>
		<description><![CDATA[I found a vulnerability in Microsoft IIS when I was searching about a method to execute an ASP file when we can only upload a JPG file.
The result was too simple, but interesting! I need only a semicolon between the &#8220;.asp&#8221; and the &#8220;.jpg&#8221; to execute an ASP file. So, the answer was &#8220;myfilename.asp;,jpg&#8221;. I [...]]]></description>
			<content:encoded><![CDATA[<p>I found a vulnerability in Microsoft IIS when I was searching about a method to execute an ASP file when we can only upload a JPG file.</p>
<p>The result was too simple, but interesting! I need only a semicolon between the &#8220;.asp&#8221; and the &#8220;.jpg&#8221; to execute an ASP file. So, the answer was &#8220;myfilename.asp;,jpg&#8221;. I have written some information about this vulnerability in:</p>
<p><a href="http://soroush.secproject.com/downloadable/iis-semicolon-report.pdf" target="_blank">http://soroush.secproject.com/downloadable/iis-semicolon-report.pdf</a></p>
<p>I&#8217;ll try to update this PDF file if there was a need to add or change some information.</p>
<p>Description of this vulnerability from Secunia.com is:</p>
<blockquote><p>Description:<br />
Soroush Dalili has discovered a vulnerability in Microsoft Internet Information Services (IIS), which can be exploited by malicious people to potentially bypass certain security restrictions and compromise a vulnerable system.</p>
<p>The vulnerability is caused due to the web server incorrectly executing e.g. ASP code included in a file having multiple extensions separated by &#8220;;&#8221;, only one internal extension being equal to &#8220;.asp&#8221; (e.g. &#8220;file.asp;.jpg&#8221;). This can be exploited to potentially upload and execute arbitrary ASP code via a third-party application using file extensions to restrict uploaded file types.</p>
<p>The vulnerability is confirmed on a fully patched Windows Server 2003 R2 SP2 running Microsoft IIS version 6. Other versions may also be affected.</p></blockquote>
<p>There are also several websites which wrote about this weakness:</p>
<p>1. Secunia Advisory: <a href="http://secunia.com/advisories/37831/" target="_blank">Microsoft IIS ASP Multiple Extensions Security Bypass</a></p>
<p>2. Securityfocus: <a href="http://www.securityfocus.com/bid/37460" target="_blank"><span>Microsoft IIS Malformed Local Filename Security Bypass Vulnerability</span></a></p>
<p>3. The Register: <a href="http://www.theregister.co.uk/2009/12/25/microsoft_iis_semicolon_bug/" target="_blank">Microsoft IIS vuln leaves users open to remote attack</a></p>
<p>4. VUPEN Security: <a href="http://www.vupen.com/english/advisories/2009/3634" target="_blank">Microsoft IIS File Extension Processing Security Bypass Vulnerability</a></p>
<p>5. Securitytracker: <a href="http://securitytracker.com/alerts/2009/Dec/1023387.html" target="_blank">Microsoft Internet Information Services (IIS) Filename Extension Parsing Flaw May Let Users Bypass Security Controls</a></p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Google captured my privacy!</title>
		<link>http://soroush.secproject.com/blog/2009/12/google-captured-my-privacy/</link>
		<comments>http://soroush.secproject.com/blog/2009/12/google-captured-my-privacy/#comments</comments>
		<pubDate>Sat, 05 Dec 2009 15:32:40 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[Google captured my privacy]]></category>
		<category><![CDATA[Google captured your privacy]]></category>
		<category><![CDATA[Google is the best Firewall]]></category>
		<category><![CDATA[Google is the best Forensic Tool]]></category>
		<category><![CDATA[Privacy by Google]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=183</guid>
		<description><![CDATA[Google will be the best Firewall and Forensic Tool of the near future!
Google will (or already) know the users&#8217; information!
News:
&#8220;Google pushes security with Public DNS&#8221; -&#62; So, Google DNS can collect all the websites which is viewed by the users &#8230;
&#8220;Browsers use Google to detect web forgery -&#62; So, a browser send a request to [...]]]></description>
			<content:encoded><![CDATA[<h3><strong>Google will be the best Firewall and Forensic Tool of the near future!</strong></h3>
<p>Google will (or already) know the users&#8217; information!</p>
<p>News:</p>
<p>&#8220;Google pushes security with Public DNS&#8221; -&gt; So, Google DNS can collect all the websites which is viewed by the users &#8230;</p>
<p>&#8220;Browsers use Google to detect web forgery -&gt; So, a browser send a request to Google before openning a website for you! &#8230;</p>
<p>&#8220;The best search engine for all&#8221; -&gt; So, Google can collect your keywords! &#8230;</p>
<p>&#8220;The best public mail service&#8221; -&gt; So, Google can collect your emails &#8230;</p>
<p>&#8220;Google owned Youtube&#8221; -&gt; So, Google can collect your videos &#8230;</p>
<p>&#8220;Google codes&#8221; -&gt; So, Google can collect your source codes &#8230;</p>
<p>&#8220;Google documents&#8221; -&gt; So, Google can collect your documents &#8230;</p>
<p>&#8220;Google photos&#8221; -&gt; So, Google can collect your photos &#8230;</p>
<p>&#8220;Google messenger&#8221; -&gt; So, Google can collect the messages &#8230;</p>
<p>&#8220;Most of the websites use Google web analyzer (tracker)&#8221; -&gt; So, Google can track the websites&#8217; information and also their customers! &#8230;</p>
<p>&#8220;Google Wave&#8221; -&gt; So, Google can collect the blogs ,e-mails, instant messaging, FTPs, social networking’s, and so on&#8217;s information! &#8230;</p>
<p>&#8220;Google powerful translators&#8221; -&gt; So, Google can understand why you are saying in other languages!</p>
<p>&#8220;Searchable images/sounds/videos by text or another object!&#8221; -&gt; So, Google can search in users&#8217; collected data &#8230;</p>
<p>&#8220;Chrome OS&#8221; -&gt; So, Google can do anything with your computer &#8230;</p>
<p>AND <strong>etc</strong> (see <a href="http://www.google.co.uk/intl/en/options/" target="_blank">http://www.google.co.uk/intl/en/options/</a> and <a href="http://www.googlelabs.com/" target="_blank">http://www.googlelabs.com/</a>)&#8230;</p>
<p>We are waiting for the most powerful shopping centre by Google!</p>
<h3><strong>However, we should trust Google in order to have happier and easier life!</strong></h3>
<h3><strong>Google = No Pain, No Gain!</strong></h3>
<p>Best wishes ;)</p>
<p>Soroush</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/12/google-captured-my-privacy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>My belief: 70% of websites are vulnerable</title>
		<link>http://soroush.secproject.com/blog/2009/11/my-belief-70-of-websites-are-vulnerable/</link>
		<comments>http://soroush.secproject.com/blog/2009/11/my-belief-70-of-websites-are-vulnerable/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 15:57:31 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[Critical vulnerabilities]]></category>
		<category><![CDATA[CSRF Attacks]]></category>
		<category><![CDATA[OWASP top 10]]></category>
		<category><![CDATA[SQL Injection Vulnerability]]></category>
		<category><![CDATA[website vulnerability]]></category>
		<category><![CDATA[XSS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=180</guid>
		<description><![CDATA[When I was searching for a ticket in nationalrail.co.uk website, I suddenly found an XSS and also a SQL Injection vulnerabilities in it.
I reported these two vulns. to its website just for having more security. And, I think these two vulnerabilities are fixed now.
However, I believe that still 70% of webistes are vulnerable against the [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">When I was searching for a ticket in nationalrail.co.uk website, I suddenly found an XSS and also a SQL Injection vulnerabilities in it.</p>
<p style="text-align: justify;">I reported these two vulns. to its website just for having more security. And, I think these two vulnerabilities are fixed now.</p>
<p style="text-align: justify;">However, <strong>I believe that still 70% of webistes are vulnerable against the <a href="http://owasp.org/">OWASP</a> TOP 10! </strong></p>
<p style="text-align: justify;">Also, I think you should read &#8220;<a href="http://www.securityfocus.com/brief/1036"><span>Survey: Majority of Web sites vulnerable</span></a>&#8221; as well.</p>
<p style="text-align: justify;">Cheers,</p>
<p style="text-align: justify;">Soroush</p>
<p style="text-align: justify;">
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/11/my-belief-70-of-websites-are-vulnerable/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Travian Game Vulnerabilities in progress&#8230;</title>
		<link>http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/</link>
		<comments>http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 14:54:08 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[logical flaw]]></category>
		<category><![CDATA[travian game]]></category>
		<category><![CDATA[travian hack]]></category>
		<category><![CDATA[travian online game]]></category>
		<category><![CDATA[website vulnerability]]></category>
		<category><![CDATA[XSS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=176</guid>
		<description><![CDATA[3 weeks ago, I sent an email about some small but effective vulnerabilities in Travian online game to its providers. By using these vulnerabilities a player can make several accounts by the same email address (because of a logical flaw), and also, he/she can login to other players&#8217; accounts (by using an XSS vulnerability which [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">3 weeks ago, I sent an email about some small but effective vulnerabilities in Travian online game to its providers. By using these vulnerabilities a player can make several accounts by the same email address (because of a logical flaw), and also, he/she can login to other players&#8217; accounts (by using an XSS vulnerability which is completely proved).</p>
<p>Now, I&#8217;m still waiting for their final response as I don&#8217;t want to be harmful for them!</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to stop hardware key-loggers</title>
		<link>http://soroush.secproject.com/blog/2009/11/how-to-stop-hardware-key-loggers/</link>
		<comments>http://soroush.secproject.com/blog/2009/11/how-to-stop-hardware-key-loggers/#comments</comments>
		<pubDate>Sun, 29 Nov 2009 14:33:22 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[Dynamic Keyboard]]></category>
		<category><![CDATA[Hardware Keyloggers]]></category>
		<category><![CDATA[Keyloggers]]></category>
		<category><![CDATA[Stop Hardware Keyloggers]]></category>
		<category><![CDATA[TPM for hardware keyloggers]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=171</guid>
		<description><![CDATA[Nowadays new generations of hardware key-loggers are emerged, and unfortunately attackers are using them intensively to steal the keystrokes of users. These key-loggers are OS independent and are in different shapes. They are even capable of stealing the BIOS password. Most of them look like a convertor for PS/2 and/or USB to PS/2 and/or USB [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify;">Nowadays new generations of hardware key-loggers are emerged, and unfortunately attackers are using them intensively to steal the keystrokes of users. These key-loggers are OS independent and are in different shapes. They are even capable of stealing the BIOS password. Most of them look like a convertor for PS/2 and/or USB to PS/2 and/or USB (Fig. 1). Besides, some of them are chipsets which are embedded in the keyboard itself (Fig. 2). And others use electromagnetic features to steal the keystrokes which are put around the wire of the keyboard or work remotely by capturing the frequency spectrum of the keyboard communication<a href="#_ftn1">[1]</a>. The problem is that these hardware key-loggers have become very cheap and simply available<a href="#_ftn2">[2]</a>. Moreover, there are some free articles about how to make their circuits<a href="#_ftn3">[3]</a>.</p>
<p style="text-align: center;"><img class=" aligncenter" title="Simple Hardware Keyloggers" src="http://i45.tinypic.com/153216a.jpg" alt="Simple Hardware Keyloggers" width="400" height="120" /></p>
<p style="text-align: center;"><img class=" aligncenter" title="Embeded Hardware Keylogger" src="http://i45.tinypic.com/2sa1qhy.gif" alt="Figure 2. Embeded Hardware Keylogger" /></p>
<p style="text-align: justify;"><strong>So, how can we stop it if we could not remove its hardware from our computer or there is a danger of electromagnetic key-logger?</strong></p>
<p style="text-align: justify;">The first and the simplest idea is using an on-screen keyboard and click on it by using a mouse. However in order to get the best result, this on-screen keyboard should be dynamic in order to prevent a hardware key-logger for the mouse itself, which captures the mouse movements and its clicks. Another way is using encryption between the keyboard and its driver. For instance, there is no doubt that by using TPM and having strong encryption methods between keyboard and motherboard (or OS itself), the keyboard can encrypt the keystrokes before sending them to the computer. But, I want to be more initiative. Another idea can be using an optical-dynamic keyboard device which shows a keyboard on your desk or on your palm, and you can touch it in order to press a key (Fig. 3). There is also an application which claims that it can detect a hardware key-logger, but I have not tried it yet and I think it is still possible to hide a hardware key-logger completely from the OS.</p>
<div class="wp-caption aligncenter" style="width: 337px"><img class=" " title="iTech Dynamic Bluetooth Virtual Keyboard" src="http://i49.tinypic.com/r1kduf.jpg" alt="Figure 3." width="327" height="325" /><p class="wp-caption-text">Figure 3.</p></div>
<p style="text-align: justify;"><em>This text is completely based on my own idea, so please respect the copyright. </em></p>
<hr size="1" /><a href="#_ftnref1">[1]</a> http://keznews.com/4985_Researchers_hack_wired_keyboards__hijack_keystrokes</p>
<p><a href="#_ftnref2">[2]</a> http://www.google.co.uk/products?q=hardware+keylogger</p>
<p><a href="#_ftnref3">[3]</a> http://derek.chezmarcotte.ca/?page_id=24</p>
<div id="_mcePaste" style="overflow: hidden; position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px;">
<p>.</p>
<p class="MsoNormal" style="text-align: justify;"><span>So, how can we stop it if we could not remove its hardware from our computer or there is a danger of electromagnetic key-logger?</span></p>
<p class="MsoNormal" style="text-align: justify;"><span>The first and the simplest idea is using an on-screen keyboard and click on it by using a mouse. However in order to get the best result, this on-screen keyboard should be dynamic in order to prevent a hardware key-logger for the mouse itself, which captures the mouse movements and its clicks. Another way is using encryption between the keyboard and its driver. For instance, there is no doubt that by using TPM and having strong encryption methods between keyboard and motherboard (or OS itself), the keyboard can encrypt the keystrokes before sending them to the computer. But, I want to be more initiative. Another idea can be using an optical-dynamic keyboard device which shows a keyboard on your desk or on your palm, and you can touch it in order to press a key (Fig. 3). There is also an application which claims that it can detect a hardware key-logger, but I have not tried it yet and I think it is still possible to hide a hardware key-logger completely from the OS.</span></p>
<p><span style="font-size: 11pt; line-height: 115%; font-family: &amp;amp;amp;">This text is completely based on my own idea, so please respect the copyright.</span></p>
<div>
<p><!--[if !supportFootnotes]--></p>
<hr size="1" /><!--[endif]--></p>
<div id="ftn1">
<p class="MsoFootnoteText"><a name="_ftn1" href="#_ftnref1"><span class="MsoFootnoteReference"><span lang="EN-GB"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp;" lang="EN-GB">[1]</span></span><!--[endif]--></span></span></span></a><span lang="EN-GB"> http://keznews.com/4985_Researchers_hack_wired_keyboards__hijack_keystrokes</span><span> </span></p>
</div>
<div id="ftn2">
<p class="MsoFootnoteText"><a name="_ftn2" href="#_ftnref2"><span class="MsoFootnoteReference"><span lang="EN-GB"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp;" lang="EN-GB">[2]</span></span><!--[endif]--></span></span></span></a><span lang="EN-GB"> http://www.google.co.uk/products?q=hardware+keylogger</span><span> </span></p>
</div>
<div id="ftn3">
<p class="MsoFootnoteText"><a name="_ftn3" href="#_ftnref3"><span class="MsoFootnoteReference"><span lang="EN-GB"><span><!--[if !supportFootnotes]--><span class="MsoFootnoteReference"><span style="font-size: 10pt; line-height: 115%; font-family: &amp;amp;amp;" lang="EN-GB">[3]</span></span><!--[endif]--></span></span></span></a><span lang="EN-GB"> http://derek.chezmarcotte.ca/?page_id=24</span><span> </span></p>
</div>
</div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/11/how-to-stop-hardware-key-loggers/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How to prevent phishing attacks? ‐ In 3 Pages ‐</title>
		<link>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/</link>
		<comments>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/#comments</comments>
		<pubDate>Sat, 21 Nov 2009 18:06:46 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[Phishing attacks]]></category>
		<category><![CDATA[Phishing methods]]></category>
		<category><![CDATA[Phishing prevention]]></category>
		<category><![CDATA[XSS in phishing attacks]]></category>
		<category><![CDATA[XSS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=166</guid>
		<description><![CDATA[In only 3 pages, I tried to explain Phishing attacks and prevention methods. Although there are some books about this topic, I tried to do my best in 3 pages only! :D
I hope you enjoy :)
Click here to download this mini-article!
Cheers,
Soroush
]]></description>
			<content:encoded><![CDATA[<p>In only 3 pages, I tried to explain Phishing attacks and prevention methods. Although there are some books about this topic, I tried to do my best in 3 pages only! :D</p>
<p>I hope you enjoy :)</p>
<p><a title="phishing_in_3_pages_march_2009.pdf" href="http://soroush.secproject.com/downloadable/phishing_in_3_pages_march_2009.pdf" target="_blank">Click here to download this mini-article!</a></p>
<p>Cheers,</p>
<p>Soroush</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Finding vulnerabilities of YaFtp 1.0.14 (a client-side FTP application)</title>
		<link>http://soroush.secproject.com/blog/2009/11/finding-vulnerabilities-of-yaftp-1-0-14-a-client-side-ftp-application/</link>
		<comments>http://soroush.secproject.com/blog/2009/11/finding-vulnerabilities-of-yaftp-1-0-14-a-client-side-ftp-application/#comments</comments>
		<pubDate>Mon, 16 Nov 2009 19:31:44 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[computer science vulnerabilities]]></category>
		<category><![CDATA[educational bug finding]]></category>
		<category><![CDATA[ftp vulnerabilities]]></category>
		<category><![CDATA[java vulnerabilities]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=160</guid>
		<description><![CDATA[Abstract: In this report we are going to find the vulnerabilities of YaFtp program, a client-side FTP application, and we are also going to suggest some mitigation methods. This process will be performed by using a specific plan which plays an important role in finding the security issues and analyzing the program. First of all [...]]]></description>
			<content:encoded><![CDATA[<p>Abstract: In this report we are going to find the vulnerabilities of YaFtp program, a client-side FTP application, and we are also going to suggest some mitigation methods. This process will be performed by using a specific plan which plays an important role in finding the security issues and analyzing the program. First of all we must understand the problem and gather the information which is related to this program. In fact, gathering the information is the most important phase in finding the vulnerabilities which clears the problem for us. In the next phase, model of the application will be drawn. Then, possible vulnerabilities will be discussed and we will draw two possible attack trees for YaFtp program. Finally, by using some automation tools and also manually, we will find the vulnerable candidate points, and we will investigate them to find the vulnerabilities. To summarize, 9 important vulnerabilities were found in this report. And, there are some solutions and suggestions in the last section of this report for developers of this application.</p>
<p><a title="YaFtp Vulns. Report" href="http://soroush.secproject.com/downloadable/yaftp-report.pdf" target="_blank">Click here to download the PDF file.</a></p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/11/finding-vulnerabilities-of-yaftp-1-0-14-a-client-side-ftp-application/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web application security in ASP &#8211; (simple) JSP</title>
		<link>http://soroush.secproject.com/blog/2009/08/web-application-security-in-asp-simple-jsp/</link>
		<comments>http://soroush.secproject.com/blog/2009/08/web-application-security-in-asp-simple-jsp/#comments</comments>
		<pubDate>Mon, 31 Aug 2009 03:32:14 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Articles]]></category>
		<category><![CDATA[final project article]]></category>
		<category><![CDATA[soroush dalili]]></category>
		<category><![CDATA[Web application security in ASP]]></category>
		<category><![CDATA[Web application security in ASP - (simple) JSP]]></category>
		<category><![CDATA[Web application security in JSP]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=158</guid>
		<description><![CDATA[Language of this article is Farsi (Persian).
This article is ready to download from these links:
http://soroush.secproject.com/downloadable/ASP_Security_Soroush_Dalili.pdf
or
http://rapidshare.com/files/273684865/ASP_Security_Soroush_Dalili.zip
Cheers
Soroush
]]></description>
			<content:encoded><![CDATA[<p>Language of this article is Farsi (Persian).</p>
<p>This article is ready to download from these links:</p>
<p><a href="http://soroush.secproject.com/downloadable/ASP_Security_Soroush_Dalili.pdf" target="_blank">http://soroush.secproject.com/downloadable/ASP_Security_Soroush_Dalili.pdf</a></p>
<p>or</p>
<p><a href="http://rapidshare.com/files/273684865/ASP_Security_Soroush_Dalili.zip" target="_blank">http://rapidshare.com/files/273684865/ASP_Security_Soroush_Dalili.zip</a></p>
<p>Cheers</p>
<p>Soroush</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/08/web-application-security-in-asp-simple-jsp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Critical vulnerabilities in the website of my department! &#8230; were solved!</title>
		<link>http://soroush.secproject.com/blog/2009/02/critical-vulnerabilities-in-the-website-of-my-department-were-solved/</link>
		<comments>http://soroush.secproject.com/blog/2009/02/critical-vulnerabilities-in-the-website-of-my-department-were-solved/#comments</comments>
		<pubDate>Sat, 21 Feb 2009 23:24:11 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[computer science vulnerabilities]]></category>
		<category><![CDATA[Critical vulnerabilities]]></category>
		<category><![CDATA[university of birmingham vulnerabilities]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=155</guid>
		<description><![CDATA[There were some critical vulnerabilities in website of Computer Science Department, University of Birmingham.
Addresses of the website:
www.cs.bham.ac.uk
supportweb.cs.bham.ac.uk
I reported them to the computer support section, and all of them are solved now.
The vulnerabilities were:
1- File uploading attack (In WWW, attacker could upload a php file and execute it.)
2- Directory traversal (In WWW, attacker could see the [...]]]></description>
			<content:encoded><![CDATA[<p>There were some critical vulnerabilities in website of Computer Science Department, University of Birmingham.<br />
Addresses of the website:<br />
<em><strong><a href="http://www.cs.bham.ac.uk" target="_blank">www.cs.bham.ac.uk</a></strong></em><br />
<a href="http://supportweb.cs.bham.ac.uk" target="_blank"><em><strong>supportweb.cs.bham.ac.uk</strong></em></a></p>
<p>I reported them to the computer support section, and all of them are solved now.<br />
The vulnerabilities were:<br />
1- File uploading attack (In WWW, attacker could upload a php file and execute it.)<br />
2- Directory traversal (In WWW, attacker could see the files and directories of the server and download the web files via the browser)<br />
3- Local file inclusion (In Supportweb, attacker could use LFI techniques to do some malicious works)<br />
4- Critical XSS attack in Gate Keeper&#8217;s Login (In Both, attacker could steal all the usernames and passwords of the users by using some simple social engineering techniques.)</p>
<p>Most of these vulnerabilities were because of the old part of the website.</p>
<p>Cheers.</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/02/critical-vulnerabilities-in-the-website-of-my-department-were-solved/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Domain for sale was added to my webblog!</title>
		<link>http://soroush.secproject.com/blog/2009/02/domain-for-sale-was-added-to-my-webblog/</link>
		<comments>http://soroush.secproject.com/blog/2009/02/domain-for-sale-was-added-to-my-webblog/#comments</comments>
		<pubDate>Mon, 02 Feb 2009 02:25:49 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=152</guid>
		<description><![CDATA[I added Domain 4 Sale section to my weblog.
Hope you enjoy these domains.
http://soroush.secproject.com/blog/domain4sale/
]]></description>
			<content:encoded><![CDATA[<p>I added <a title="Domain4Sale Section" href="http://soroush.secproject.com/blog/domain4sale/" target="_self">Domain 4 Sale</a> section to my weblog.<br />
Hope you enjoy these domains.</p>
<p><a title="Domain4Sale Section" href="http://soroush.secproject.com/blog/domain4sale/" target="_self">http://soroush.secproject.com/blog/domain4sale/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/02/domain-for-sale-was-added-to-my-webblog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SQL Injection Tutorial Video</title>
		<link>http://soroush.secproject.com/blog/2009/01/sql-injection-tutorial-video/</link>
		<comments>http://soroush.secproject.com/blog/2009/01/sql-injection-tutorial-video/#comments</comments>
		<pubDate>Sat, 31 Jan 2009 23:44:10 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[hacking videos]]></category>
		<category><![CDATA[sql injection tutorial]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=143</guid>
		<description><![CDATA[This is a good tutorial video about SQL Injection. Although in this video, it works with mysql, you can learn the concept of SQL Injection and also some useful techniques.
Creator: killerguppy101
Part1 (http://aria-security.persiangig.com/video/sqltut-Part1.rar)
&#8212;&#8212;-
Part2.1 (http://aria-security.persiangig.com/video/sqltut-Part2.1.rar)
Part2.2 (http://aria-security.persiangig.com/video/sqltut-Part2.2.rar)
&#8212;&#8212;-
Part3 (http://aria-security.persiangig.com/video/sqltut-Part3.rar)
Thanks from aria-security.com, Secr00t3r, ali_aria
Copy/Paste these links in your browser if they don&#8217;t work by clicking.
]]></description>
			<content:encoded><![CDATA[<p>This is a good tutorial video about SQL Injection. Although in this video, it works with mysql, you can learn the concept of SQL Injection and also some useful techniques.</p>
<p>Creator: <a href="http://www.google.co.uk/search?hl=en&amp;q=killerguppy101" target="_blank">killerguppy101</a></p>
<p><a href="http://aria-security.persiangig.com/video/sqltut-Part1.rar" target="_blank">Part1</a> (http://aria-security.persiangig.com/video/sqltut-Part1.rar)</p>
<p>&#8212;&#8212;-</p>
<p><a href="http://aria-security.persiangig.com/video/sqltut-Part2.1.rar" target="_blank">Part2.1</a> (http://aria-security.persiangig.com/video/sqltut-Part2.1.rar)</p>
<p><a href="http://aria-security.persiangig.com/video/sqltut-Part2.2.rar" target="_blank">Part2.2</a> (http://aria-security.persiangig.com/video/sqltut-Part2.2.rar)</p>
<p>&#8212;&#8212;-</p>
<p><a href="http://aria-security.persiangig.com/video/sqltut-Part3.rar" target="_blank">Part3</a> (http://aria-security.persiangig.com/video/sqltut-Part3.rar)</p>
<p>Thanks from <a href="http://www.aria-security.com/" target="_blank">aria-security.com</a>, Secr00t3r, ali_aria</p>
<p>Copy/Paste these links in your browser if they don&#8217;t work by clicking.</p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/01/sql-injection-tutorial-video/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Hacking Videos: A Useful Link!</title>
		<link>http://soroush.secproject.com/blog/2009/01/hacking-videos-a-useful-link/</link>
		<comments>http://soroush.secproject.com/blog/2009/01/hacking-videos-a-useful-link/#comments</comments>
		<pubDate>Sat, 31 Jan 2009 23:29:59 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Security Posts]]></category>
		<category><![CDATA[hacking videos]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=141</guid>
		<description><![CDATA[There are some good hacking videos in this link:
http://www.forcehacker.kit.net/videos.html
]]></description>
			<content:encoded><![CDATA[<p>There are some good hacking videos in this link:</p>
<p><a href="http://www.forcehacker.kit.net/videos.html" target="_blank">http://www.forcehacker.kit.net/videos.html</a></p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/01/hacking-videos-a-useful-link/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>March 2009 Updated: FaceBook Automatic Friends Adder from the Apllications&#8217; Walls</title>
		<link>http://soroush.secproject.com/blog/2009/01/facebook-automatic-friends-adder-from-the-apllications-walls/</link>
		<comments>http://soroush.secproject.com/blog/2009/01/facebook-automatic-friends-adder-from-the-apllications-walls/#comments</comments>
		<pubDate>Sat, 31 Jan 2009 23:07:27 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[All Facebook Application Walls]]></category>
		<category><![CDATA[Facebook Add Friend]]></category>
		<category><![CDATA[Facebook Automatic Friend Add]]></category>
		<category><![CDATA[Facebook Automation Friend]]></category>
		<category><![CDATA[Facebook Game Cheat]]></category>
		<category><![CDATA[FaceBook MobWars Cheat]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=134</guid>
		<description><![CDATA[March 2009 Updated:
Facebook changed some forms and modules in its website in March 2009, so I updated my previous code to the new one:
At last I wrote the universal friend adder for the Facebook.com!
So, you can use this code to add your friends from your arbitrary wall such as Mobwars, Mafia Wars, Eleven Blood, Knighthood, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>March 2009 Updated:</strong></p>
<p><strong>Facebook changed some forms and modules in its website in March 2009, so I updated my previous code to the new one:</strong></p>
<p>At last I wrote the universal friend adder for the Facebook.com!</p>
<p>So, you can use this code to add your friends from your arbitrary wall such as Mobwars, Mafia Wars, Eleven Blood, Knighthood, and so on.</p>
<p>There are some important notes:</p>
<p>0- You must download and setup the iMacros first from <a href="http://www.iopus.com/download/" target="_blank">here</a> (<a href="http://www.iopus.com/download/" target="_blank">http://www.iopus.com/download/</a>).</p>
<p>1- You must bypass the CAPTCHA by adding more than 30 friends (maybe a bit less or more than this) manually.</p>
<p>2- You must find your application ID number by going to your application page and check the URL. There is always something like this:</p>
<p>http://www.facebook.com/apps/application.php?id=XXXXXXXXX</p>
<p>Which &#8220;XXXXXXXXX&#8221; is the application number which you must set it as &#8220;applicationIDNumber&#8221; in this code.</p>
<p>3- Please configure your settings in this code before usage if you want to get the best result.</p>
<p><strong>Note: </strong><strong>Unfortunately in this fast revision, you must choose a &#8220;friend list&#8221; name for the new friends which stands before all the friend list names. For ex. this name can be look  like: &#8220;000000myfriendlist</strong>&#8221;</p>
<p>You can copy/paste it as Facebook_Wall_Add.js to your iMacros.</p>
<pre style="padding-left: 30px;"><em>/********* FaceBook Automatic Friends Adder from Apllications' Walls (After Passing the CAPTCHA manually)*********/
/********* You can bypass the CAPTCHA by adding more than 30 friends manually at the first *********/
/********* By Soroush Dalili March-2009 Soroush.SecProject.Com *********/
/********* Begin Configuration - You can change these settings *********/
var startPage = 2; // You can change this value to your page number!
var mobInviteMessage = "Please invite me to your Mafia Wars!"; // You can add your message here
var mobFriendList = "000000myfriendlist"; // You can add your special friend list (you must made it before)
var showImages = "1"; // You can change it to "0" (for disabling) and to "1" (for enabling)
// Wall ID Number: Mobwars = 8743457343 /  Mafia Wars = 56556324950 /  Eleven Blood = 29886835263 / Knighthood = 5541055185
// Just goto your application page which is something like "http://www.facebook.com/apps/application.php?id=XXXXXXXXX". This "XXXXXXXXX" is your application number
var applicationIDNumber = "56556324950"; // Default = MobWars Wall = 8743457343
/********* End Configuration - You can change these settings *********/

/********* Begin Code *********/
// Replace &lt;SP&gt; instead of space character
mobInviteMessage = addImacrosSpace(mobInviteMessage);
mobFriendList = addImacrosSpace(mobFriendList);
var jsNewLine="\n";

/********* Begin Openning Mobwars Wall's Pages *********/
var FaceBook_AddFromWall_Pages_Code;
FaceBook_AddFromWall_Pages_Code = "CODE:";
FaceBook_AddFromWall_Pages_Code = FaceBook_AddFromWall_Pages_Code+"SET !ERRORIGNORE YES" + jsNewLine;
if(showImages == "0"){
// Disable images to have more speed
FaceBook_AddFromWall_Pages_Code = FaceBook_AddFromWall_Pages_Code+"FILTER TYPE=IMAGES STATUS=ON" + jsNewLine;
}
// Open mobwars wall
FaceBook_AddFromWall_Pages_Code = FaceBook_AddFromWall_Pages_Code+"URL GOTO=http://www.facebook.com/wall.php?id=" + applicationIDNumber + "&amp;page={{PageNumber}}" + jsNewLine;
FaceBook_AddFromWall_Pages_Code = FaceBook_AddFromWall_Pages_Code+"FILTER TYPE=IMAGES STATUS=OFF" + jsNewLine;
FaceBook_AddFromWall_Pages_Code = FaceBook_AddFromWall_Pages_Code+"WAIT SECONDS=1";
/********* End Openning Mobwars Wall's Pages *********/

/********* Begin Openning Mobwars Wall's Links *********/
var FaceBook_AddFromWall_Links_Code;
FaceBook_AddFromWall_Links_Code = "CODE:";
FaceBook_AddFromWall_Links_Code = FaceBook_AddFromWall_Links_Code+"SET !ERRORIGNORE NO" + jsNewLine;
FaceBook_AddFromWall_Links_Code = FaceBook_AddFromWall_Links_Code+"SET !TIMEOUT 15" + jsNewLine;
if(showImages == "0"){
// Disable images to have more speed
FaceBook_AddFromWall_Links_Code = FaceBook_AddFromWall_Links_Code+"FILTER TYPE=IMAGES STATUS=ON" + jsNewLine;
}
FaceBook_AddFromWall_Links_Code = FaceBook_AddFromWall_Links_Code+"TAG POS={{LinkNumber}} TYPE=A ATTR=HREF:http://www.facebook.com/s.php?k=100000080*&amp;&amp;CLASS:profile_link" + jsNewLine;
FaceBook_AddFromWall_Links_Code = FaceBook_AddFromWall_Links_Code+"WAIT SECONDS=1";
/********* End Openning Mobwars Wall's Links *********/

/********* Begin Add  - Step1: Press "Add As Friend" *********/
var FaceBook_AddFromWall_Add_Step1_Code;
FaceBook_AddFromWall_Add_Step1_Code = "CODE:";
FaceBook_AddFromWall_Add_Step1_Code = FaceBook_AddFromWall_Add_Step1_Code+"SET !ERRORIGNORE NO" + jsNewLine;
FaceBook_AddFromWall_Add_Step1_Code = FaceBook_AddFromWall_Add_Step1_Code+"SET !TIMEOUT 15" + jsNewLine;
FaceBook_AddFromWall_Add_Step1_Code = FaceBook_AddFromWall_Add_Step1_Code+"TAG POS=1 TYPE=A ATTR=TXT:Add&lt;SP&gt;as&lt;SP&gt;Friend" + jsNewLine;
FaceBook_AddFromWall_Add_Step1_Code = FaceBook_AddFromWall_Add_Step1_Code+"FILTER TYPE=IMAGES STATUS=OFF" + jsNewLine;
FaceBook_AddFromWall_Add_Step1_Code = FaceBook_AddFromWall_Add_Step1_Code+"WAIT SECONDS=1";
/********* End Add  - Step1: Press "Add As Friend" *********/

/********* Begin Add  - Step2: Fill the forms *********/
var FaceBook_AddFromWall_Add_Step2_Code;
FaceBook_AddFromWall_Add_Step2_Code = "CODE:";
FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"SET !ERRORIGNORE YES" + jsNewLine;
FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"SET !TIMEOUT 15" + jsNewLine;
// Insert Message
if(mobInviteMessage!=""){
FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"TAG POS=1 TYPE=A ATTR=TXT:Add&lt;SP&gt;a&lt;SP&gt;personal&lt;SP&gt;message*" + jsNewLine;
//FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"WAIT SECONDS=1"+ jsNewLine;
FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"TAG POS=1 TYPE=TEXTAREA ATTR=ID:message CONTENT=" + mobInviteMessage + jsNewLine;
}
// Select Friendlist
if(mobFriendList!=""){
	//FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"TAG POS=1 TYPE=SELECT FORM=NAME:NoFormName ATTR=ID:add_to_friend_list_widget_select_* CONTENT=$" + mobFriendList + jsNewLine;
	FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"TAG POS=1 TYPE=SPAN ATTR=BINDPOINT:main&amp;&amp;CLASS:UIActionMenu_Main" + jsNewLine;
	FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"TAG POS=1 TYPE=A ATTR=CLASS:UICheckList_Label CONTENT=" + mobFriendList + jsNewLine;
	//FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"TAG POS=1 TYPE=INPUT:TEXT ATTR=CLASS:inputtext FriendAddingTool_CreateNewList CONTENT=" + mobFriendList + jsNewLine;
}
// Press Add Button
FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"TAG POS=1 TYPE=INPUT:BUTTON ATTR=ID:dialog_button1" + jsNewLine;
FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"FILTER TYPE=IMAGES STATUS=OFF" + jsNewLine;
FaceBook_AddFromWall_Add_Step2_Code = FaceBook_AddFromWall_Add_Step2_Code+"WAIT SECONDS=2";

/********* End Add - Step2: Fill the forms *********/

/********* Begin Close Box *********/
var FaceBook_AddFromWall_Close_Code;

FaceBook_AddFromWall_Close_Code = "CODE:";
FaceBook_AddFromWall_Close_Code = FaceBook_AddFromWall_Close_Code+"SET !ERRORIGNORE YES" + jsNewLine;
FaceBook_AddFromWall_Close_Code = FaceBook_AddFromWall_Close_Code+"SET !TIMEOUT 15" + jsNewLine;
FaceBook_AddFromWall_Close_Code = FaceBook_AddFromWall_Close_Code+"TAG POS=1 TYPE=INPUT:BUTTON ATTR=NAME:close&amp;&amp;VALUE:Close" + jsNewLine;
FaceBook_AddFromWall_Close_Code = FaceBook_AddFromWall_Close_Code+"FILTER TYPE=IMAGES STATUS=OFF" + jsNewLine;
FaceBook_AddFromWall_Close_Code = FaceBook_AddFromWall_Close_Code+"WAIT SECONDS=2";

/********* End Close Box *********/

/********* Begin Internal JavaScript Code *********/
var i1=0;
var i2=0;
var i3=0;
var i4=0;
var j=0;
var p=0;
for(p=startPage;p&gt;=0;p--){
	iimSet ("-var_PageNumber", p);
	i1 = iimPlay(FaceBook_AddFromWall_Pages_Code);
	for(j=0;j&lt;20;j++){
		iimSet ("-var_LinkNumber", j*2+1);
		i2 = iimPlay(FaceBook_AddFromWall_Links_Code);

		if (i2 &gt;= 0) {
			iimSet ("-var_LinkNumber", j);
		    i3 = iimPlay(FaceBook_AddFromWall_Add_Step1_Code);
			if(i3 &gt;= 0)
				i4 = iimPlay(FaceBook_AddFromWall_Add_Step2_Code);
		}else{
			break;
		}

	}
}

function addImacrosSpace(str){
	str = str.replace(/ /g, "&lt;SP&gt;");
	return str;
}
/********* End Internal JavaScript Code *********/
/********* End Code*********/
/********* By Soroush Dalili March-2009 Soroush.SecProject.Com *********/</em></pre>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/01/facebook-automatic-friends-adder-from-the-apllications-walls/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Blog Template Was Updated</title>
		<link>http://soroush.secproject.com/blog/2009/01/blog-template-was-updated/</link>
		<comments>http://soroush.secproject.com/blog/2009/01/blog-template-was-updated/#comments</comments>
		<pubDate>Sat, 31 Jan 2009 22:20:30 +0000</pubDate>
		<dc:creator>Soroush Dalili</dc:creator>
				<category><![CDATA[Normal Posts]]></category>
		<category><![CDATA[Blog Template]]></category>
		<category><![CDATA[XSS Vulnerability]]></category>

		<guid isPermaLink="false">http://soroush.secproject.com/blog/?p=130</guid>
		<description><![CDATA[I found some XSS vulnerabilities in my blog&#8217;s template, so I reported them to its creator (Inanis).
Thanks from Inanis because of fast fix and also for this beautiful template.
You can see these in this link:
http://www.inanis.net/blog/index.php/downloads/inanis-glass-wordpress-theme/inanis-glass-readme/
]]></description>
			<content:encoded><![CDATA[<p>I found some XSS vulnerabilities in my blog&#8217;s template, so I reported them to its creator (Inanis).</p>
<p>Thanks from Inanis because of fast fix and also for this beautiful template.</p>
<p>You can see these in this link:</p>
<p><a href="http://www.inanis.net/blog/index.php/downloads/inanis-glass-wordpress-theme/inanis-glass-readme/" target="_blank">http://www.inanis.net/blog/index.php/downloads/inanis-glass-wordpress-theme/inanis-glass-readme/</a></p>
]]></content:encoded>
			<wfw:commentRss>http://soroush.secproject.com/blog/2009/01/blog-template-was-updated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
