<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.9.2" -->
<rss version="0.92">
<channel>
	<title>Computer Security Is My Interest!</title>
	<link>http://soroush.secproject.com/blog</link>
	<description>Soroush Dalili's Weblog</description>
	<lastBuildDate>Mon, 08 Mar 2010 01:33:59 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Improve File Uploaders’ Protections &#8211; Bypass Methods- Rev. 1.0</title>
		<description><![CDATA[
Some new methods of bypassing file uploaders protections have been discussed. As an example bypassing by using: trailing spaces and dots, “::$data.”, direct Null char, IIS semi-colon  bug, and so on.

Uploading files by using web applications is very common. However, there is always a high risk around this matter. In case of uploading a web-shell [...]]]></description>
		<link>http://soroush.secproject.com/blog/2010/03/improve-file-uploaders%e2%80%99-protections-rev-1-0/</link>
			</item>
	<item>
		<title>IE7-8 drive list enumeration!</title>
		<description><![CDATA[Iframe delay in loading the local drives in IE7 and IE8 can cause drive list enumeration!
Proof of Concept is available from this link:
http://plaincipher.com/demo/IE-Drive-Enum-Demo.html
Cheers,
Soroush Dalili
]]></description>
		<link>http://soroush.secproject.com/blog/2010/03/ie7-8-drive-list-enumeration/</link>
			</item>
	<item>
		<title>The Web Application Security Consortium Threat Classification v2.0</title>
		<description><![CDATA[After OWASP updated its Top 10, now I&#8217;m very glad to quote this:
The Web Application Security Consortium (WASC) is pleased to announce the long awaited release of the WASC Threat Classification v2.0.
You can read more information from these links: http://projects.webappsec.org/Threat-Classification and http://projects.webappsec.org/f/WASC-TC-v2_0.pdf
Cheers,
Soroush
]]></description>
		<link>http://soroush.secproject.com/blog/2010/01/the-web-application-security-consortium-threat-classification-v2-0/</link>
			</item>
	<item>
		<title>Microsoft Contradiction</title>
		<description><![CDATA[First of all, Microsoft is one of the best companies which leads us to the better world. But, nothing is free of fault except God!
I’m writing this post as a response to the Microsoft security response in: “http://blogs.technet.com/msrc/archive/2009/12/29/results-of-investigation-into-holiday-iis-claim.aspx”.
They said that “We’ve completed our investigation into the claims that came up over the holiday of a [...]]]></description>
		<link>http://soroush.secproject.com/blog/2010/01/microsoft-contradiction/</link>
			</item>
	<item>
		<title>Mirror Blog</title>
		<description><![CDATA[


As my website cannot be opened from Iran, I made a mirror blog at: http://irsdl.wordpress.com/
However, I do not think that I can sync. the comments.
Cheers,
Soroush



]]></description>
		<link>http://soroush.secproject.com/blog/2009/12/mirror-blog-4/</link>
			</item>
	<item>
		<title>Browsers’ Pain: A recursive function!</title>
		<description><![CDATA[I have written a recursive function by using Javascript “setInterval” function which calls itself. Unfortunately, none of the last version of famous browsers such as Internet Explorer (8), Chrome (3.0.195.38), and Mozilla Firefox (3.5.6) blocks this script. Moreover, it takes more than 50% of my CPU which is Intel Core 2 Dou 2.50 GHz.
And the [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/12/browsers%e2%80%99-pain-a-recursive-function/</link>
			</item>
	<item>
		<title>Microsoft IIS Semi-Colon Vulnerability</title>
		<description><![CDATA[I found a vulnerability in Microsoft IIS when I was searching about a method to execute an ASP file when we can only upload a JPG file.
The result was too simple, but interesting! I need only a semicolon between the &#8220;.asp&#8221; and the &#8220;.jpg&#8221; to execute an ASP file. So, the answer was &#8220;myfilename.asp;,jpg&#8221;. I [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/12/microsoft-iis-semi-colon-vulnerability/</link>
			</item>
	<item>
		<title>Google captured my privacy!</title>
		<description><![CDATA[Google will be the best Firewall and Forensic Tool of the near future!
Google will (or already) know the users&#8217; information!
News:
&#8220;Google pushes security with Public DNS&#8221; -&#62; So, Google DNS can collect all the websites which is viewed by the users &#8230;
&#8220;Browsers use Google to detect web forgery -&#62; So, a browser send a request to [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/12/google-captured-my-privacy/</link>
			</item>
	<item>
		<title>My belief: 70% of websites are vulnerable</title>
		<description><![CDATA[When I was searching for a ticket in nationalrail.co.uk website, I suddenly found an XSS and also a SQL Injection vulnerabilities in it.
I reported these two vulns. to its website just for having more security. And, I think these two vulnerabilities are fixed now.
However, I believe that still 70% of webistes are vulnerable against the [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/11/my-belief-70-of-websites-are-vulnerable/</link>
			</item>
	<item>
		<title>Travian Game Vulnerabilities in progress&#8230;</title>
		<description><![CDATA[3 weeks ago, I sent an email about some small but effective vulnerabilities in Travian online game to its providers. By using these vulnerabilities a player can make several accounts by the same email address (because of a logical flaw), and also, he/she can login to other players&#8217; accounts (by using an XSS vulnerability which [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/11/travian-game-vulnerabilities-in-progress/</link>
			</item>
	<item>
		<title>How to stop hardware key-loggers</title>
		<description><![CDATA[Nowadays new generations of hardware key-loggers are emerged, and unfortunately attackers are using them intensively to steal the keystrokes of users. These key-loggers are OS independent and are in different shapes. They are even capable of stealing the BIOS password. Most of them look like a convertor for PS/2 and/or USB to PS/2 and/or USB [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/11/how-to-stop-hardware-key-loggers/</link>
			</item>
	<item>
		<title>How to prevent phishing attacks? ‐ In 3 Pages ‐</title>
		<description><![CDATA[In only 3 pages, I tried to explain Phishing attacks and prevention methods. Although there are some books about this topic, I tried to do my best in 3 pages only! :D
I hope you enjoy :)
Click here to download this mini-article!
Cheers,
Soroush
]]></description>
		<link>http://soroush.secproject.com/blog/2009/11/how-to-prevent-phishing-attacks-%e2%80%90-in-3-pages-%e2%80%90/</link>
			</item>
	<item>
		<title>Finding vulnerabilities of YaFtp 1.0.14 (a client-side FTP application)</title>
		<description><![CDATA[Abstract: In this report we are going to find the vulnerabilities of YaFtp program, a client-side FTP application, and we are also going to suggest some mitigation methods. This process will be performed by using a specific plan which plays an important role in finding the security issues and analyzing the program. First of all [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/11/finding-vulnerabilities-of-yaftp-1-0-14-a-client-side-ftp-application/</link>
			</item>
	<item>
		<title>Web application security in ASP &#8211; (simple) JSP</title>
		<description><![CDATA[Language of this article is Farsi (Persian).
This article is ready to download from these links:
http://soroush.secproject.com/downloadable/ASP_Security_Soroush_Dalili.pdf
or
http://rapidshare.com/files/273684865/ASP_Security_Soroush_Dalili.zip
Cheers
Soroush
]]></description>
		<link>http://soroush.secproject.com/blog/2009/08/web-application-security-in-asp-simple-jsp/</link>
			</item>
	<item>
		<title>Critical vulnerabilities in the website of my department! &#8230; were solved!</title>
		<description><![CDATA[There were some critical vulnerabilities in website of Computer Science Department, University of Birmingham.
Addresses of the website:
www.cs.bham.ac.uk
supportweb.cs.bham.ac.uk
I reported them to the computer support section, and all of them are solved now.
The vulnerabilities were:
1- File uploading attack (In WWW, attacker could upload a php file and execute it.)
2- Directory traversal (In WWW, attacker could see the [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/02/critical-vulnerabilities-in-the-website-of-my-department-were-solved/</link>
			</item>
	<item>
		<title>Domain for sale was added to my webblog!</title>
		<description><![CDATA[I added Domain 4 Sale section to my weblog.
Hope you enjoy these domains.
http://soroush.secproject.com/blog/domain4sale/
]]></description>
		<link>http://soroush.secproject.com/blog/2009/02/domain-for-sale-was-added-to-my-webblog/</link>
			</item>
	<item>
		<title>SQL Injection Tutorial Video</title>
		<description><![CDATA[This is a good tutorial video about SQL Injection. Although in this video, it works with mysql, you can learn the concept of SQL Injection and also some useful techniques.
Creator: killerguppy101
Part1 (http://aria-security.persiangig.com/video/sqltut-Part1.rar)
&#8212;&#8212;-
Part2.1 (http://aria-security.persiangig.com/video/sqltut-Part2.1.rar)
Part2.2 (http://aria-security.persiangig.com/video/sqltut-Part2.2.rar)
&#8212;&#8212;-
Part3 (http://aria-security.persiangig.com/video/sqltut-Part3.rar)
Thanks from aria-security.com, Secr00t3r, ali_aria
Copy/Paste these links in your browser if they don&#8217;t work by clicking.
]]></description>
		<link>http://soroush.secproject.com/blog/2009/01/sql-injection-tutorial-video/</link>
			</item>
	<item>
		<title>Hacking Videos: A Useful Link!</title>
		<description><![CDATA[There are some good hacking videos in this link:
http://www.forcehacker.kit.net/videos.html
]]></description>
		<link>http://soroush.secproject.com/blog/2009/01/hacking-videos-a-useful-link/</link>
			</item>
	<item>
		<title>March 2009 Updated: FaceBook Automatic Friends Adder from the Apllications&#8217; Walls</title>
		<description><![CDATA[March 2009 Updated:
Facebook changed some forms and modules in its website in March 2009, so I updated my previous code to the new one:
At last I wrote the universal friend adder for the Facebook.com!
So, you can use this code to add your friends from your arbitrary wall such as Mobwars, Mafia Wars, Eleven Blood, Knighthood, [...]]]></description>
		<link>http://soroush.secproject.com/blog/2009/01/facebook-automatic-friends-adder-from-the-apllications-walls/</link>
			</item>
	<item>
		<title>Blog Template Was Updated</title>
		<description><![CDATA[I found some XSS vulnerabilities in my blog&#8217;s template, so I reported them to its creator (Inanis).
Thanks from Inanis because of fast fix and also for this beautiful template.
You can see these in this link:
http://www.inanis.net/blog/index.php/downloads/inanis-glass-wordpress-theme/inanis-glass-readme/
]]></description>
		<link>http://soroush.secproject.com/blog/2009/01/blog-template-was-updated/</link>
			</item>
</channel>
</rss>
