<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>gnucitizen &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/gnucitizen/</link>
	<description>Feed of posts on WordPress.com tagged "gnucitizen"</description>
	<pubDate>Sat, 26 Dec 2009 12:44:33 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[Websecurify &ndash; Web Security Testing Framework]]></title>
<link>http://aksgeek.wordpress.com/2009/09/23/websecurify-web-security-testing-framework/</link>
<pubDate>Wed, 23 Sep 2009 17:30:00 +0000</pubDate>
<dc:creator>Akshat</dc:creator>
<guid>http://aksgeek.wordpress.com/2009/09/23/websecurify-web-security-testing-framework/</guid>
<description><![CDATA[&#160; &#160; Websecurify is a web and web2.0 security initiative specializing in researching securi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><font size="3" face="Georgia">&#160; <img src="http://i34.tinypic.com/9thkzt.jpg" width="433" height="78" /> </font></p>
<p><font size="3" face="Georgia">&#160; Websecurify is a web and web2.0 security initiative specializing in researching security issues and building the next generation of tools to defeat and protect web technologies.</font></p>
<p> <!--more-->
<p><font size="3" face="Georgia"></font><font face="Arial">&#160;</font><strong><u><img src="http://i35.tinypic.com/p1xko.jpg" width="427" height="223" /> </u></strong></p>
<p><font size="3" face="Georgia"><strong><u>Key Features:-</u></strong></font></p>
<p><font size="3" face="Georgia">1.<strong> JavaScript </strong>- Websecurify Security Testing Framework is the first tool of its kind to be written entirely in JavaScript using only standard technologies adopted by the leading browsers. </font></p>
<p><font size="3" face="Georgia">2.<strong> Multiple Environments </strong>- The core technology can run in normal browsers, xulrunner, xpcshell (command line), inside Java or as part of a custom V8 (Chrome&#8217;s JavaScript Engine) build. The core is written with extensibility in mind so that more environments can be supported without changing even a single line of code. </font></p>
<p><font size="3" face="Georgia">3. <strong>Multi-platform </strong>- The tool is available and successfully runs on Windows, Mac OS, Linux and other operating systems. </font></p>
<p><font size="3" face="Georgia">&#160;<img src="http://i35.tinypic.com/wmmkb4.jpg" width="435" height="259" /> </font></p>
<p><font size="3" face="Georgia">4.<strong> Automatic Updates</strong> &#8211; Every single piece of the tool is subjected to automatic updates. This means that newer and more advanced versions of the tool can be shipped to your front door without you lifting your finger. This however is completely optional. The automatic update can be turned off if needed. </font></p>
<p><font size="3" face="Georgia">5. <strong>Extensions</strong> &#8211; Because the tool comes wrapped in xulrunner by default (keep in mind that we can support any other JavaScript environment) we benefit from all cool features that Firefox has, such as extensions. Extensions are easy to write and maintain and can customize every single aspect of the tool and there are already tones of resources and documentation, including books and what not, out there to teach you exactly how to do that. We will be providing documentation as well.</font></p>
<p><font size="3" face="Georgia"><strong>Download Websecurify 0.3</strong></font></p>
<p><font size="3" face="Georgia">For <a href="http://websecurify.googlecode.com/files/Websecurify%200.3.dmg">Mac</a>&#160; &#124;&#160; <a href="http://websecurify.googlecode.com/files/Websecurify%200.3.exe">Windows</a>&#160; &#124;&#160; <a href="http://websecurify.googlecode.com/files/Websecurify%200.3.tgz">Linux</a>&#160; &#124;&#160; <a href="http://websecurify.googlecode.com/files/Websecurify%200.3.zip">ZIP File</a></font></p>
<p><font size="3" face="Georgia"></font></p>
<p><font size="3" face="Georgia">To know more visit <a href="http://code.google.com/p/websecurify/" target="_blank">here</a></font></p>
<p>&#160;</p>
<div style="display:inline;float:none;margin:0;padding:0;" id="scid:0767317B-992E-4b12-91E0-4F059A8CECA8:a134662f-5be5-4ff3-bd56-90d5ccda0d6f" class="wlWriterEditableSmartContent">Technorati Tags: <a href="http://technorati.com/tags/websecurify" rel="tag">websecurify</a>,<a href="http://technorati.com/tags/web" rel="tag">web</a>,<a href="http://technorati.com/tags/web+security" rel="tag">web security</a>,<a href="http://technorati.com/tags/testing" rel="tag">testing</a>,<a href="http://technorati.com/tags/framework" rel="tag">framework</a>,<a href="http://technorati.com/tags/testing+framework" rel="tag">testing framework</a>,<a href="http://technorati.com/tags/testing+tool" rel="tag">testing tool</a>,<a href="http://technorati.com/tags/free" rel="tag">free</a>,<a href="http://technorati.com/tags/gnucitizen" rel="tag">gnucitizen</a></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exactly WHAT is SKYPE?  And are we VULNERABLE?]]></title>
<link>http://skypeon.wordpress.com/2009/04/27/exactly-what-is-skype-and-are-we-vulnerable/</link>
<pubDate>Mon, 27 Apr 2009 10:15:04 +0000</pubDate>
<dc:creator>theuniversityofme</dc:creator>
<guid>http://skypeon.wordpress.com/2009/04/27/exactly-what-is-skype-and-are-we-vulnerable/</guid>
<description><![CDATA[This is excerpted from GNU Citizen.  For the blog in it&#8217;s entirety, go to VULNERABILITES in SK]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p style="text-align:center;"><a href="http://www.gnucitizen.org/images/125252891_e22f8e0406.jpg"><img class="alignnone" src="http://www.gnucitizen.org/images/125252891_e22f8e0406.jpg" alt="" width="500" height="375" /></a></p>
<h3>This is excerpted from GNU Citizen.  For the blog in it&#8217;s entirety, go to <a href="http://www.gnucitizen.org/blog/vulnerabilities-in-skype/">VULNERABILITES in SKYPE</a></h3>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[House of Hackers, una nueva red social para hackers]]></title>
<link>http://hispasystem.wordpress.com/2008/05/11/house-of-hackers-una-nueva-red-social-para-hackers/</link>
<pubDate>Sun, 11 May 2008 21:51:00 +0000</pubDate>
<dc:creator>hispasystem</dc:creator>
<guid>http://hispasystem.wordpress.com/2008/05/11/house-of-hackers-una-nueva-red-social-para-hackers/</guid>
<description><![CDATA[Miembros de la comunidad GNU Citizen han anunciado el proyecto llamado House of Hackers (la Casa de ]]></description>
<content:encoded><![CDATA[Miembros de la comunidad GNU Citizen han anunciado el proyecto llamado House of Hackers (la Casa de ]]></content:encoded>
</item>
<item>
<title><![CDATA[Para <i>Hacker</i> Ciptakan Jejaring Sosial Sendiri ]]></title>
<link>http://insideit.wordpress.com/2008/05/10/para-hacker-ciptakan-jejaring-sosial-sendiri/</link>
<pubDate>Sat, 10 May 2008 16:12:58 +0000</pubDate>
<dc:creator>den Koplak</dc:creator>
<guid>http://insideit.wordpress.com/2008/05/10/para-hacker-ciptakan-jejaring-sosial-sendiri/</guid>
<description><![CDATA[Para hacker kini memiiki situs jejaring sosial sendiri yang didukung oleh GnuCitizen, salah satu kel]]></description>
<content:encoded><![CDATA[Para hacker kini memiiki situs jejaring sosial sendiri yang didukung oleh GnuCitizen, salah satu kel]]></content:encoded>
</item>
<item>
<title><![CDATA[House of Hackers]]></title>
<link>http://ramsesoriginal.wordpress.com/2008/05/05/hoh/</link>
<pubDate>Mon, 05 May 2008 17:10:45 +0000</pubDate>
<dc:creator>ramsesoriginal</dc:creator>
<guid>http://ramsesoriginal.wordpress.com/2008/05/05/hoh/</guid>
<description><![CDATA[Scrivo su hancproject: Come segnalato dal sempre ottimo pdp, é nata la “House of Hackers“. Si tratta]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Scrivo su <a href="http://www.hancproject.org/wp/">hancproject</a>:</p>
<blockquote><p>Come segnalato dal sempre ottimo <a href="http://www.gnucitizen.org/blog/landing-house-of-hackers/">pdp</a>, é nata la “<a href="http://houseofhackers.ning.com/">House of Hackers</a>“. Si tratta di una community creata da Hacker per Hacker, e supporta lacultura Hacker, il cosidetto “Hacker Mindset”, le ideologie e visioni politiche di hacker, e molto altro. Inoltre si pone come mercato libero per esperti di sicurezza, dove cercare e trovare lavoro. Chiaramente siete tutti invitati a partecipare!</p></blockquote>
<p>Chiaramente l&#8217;invito lo passo a tutti i miei cari lettori.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[XSS When Payload is Limited]]></title>
<link>http://cyberphob1a.wordpress.com/2008/02/13/xss-when-payload-is-limited/</link>
<pubDate>Wed, 13 Feb 2008 15:58:29 +0000</pubDate>
<dc:creator>cyberphob1a</dc:creator>
<guid>http://cyberphob1a.wordpress.com/2008/02/13/xss-when-payload-is-limited/</guid>
<description><![CDATA[Another interesting posting by pdp from GnuCitizen: He found an XSS and XSRF flaw in Pownce, however]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><a href="http://www.flickr.com/photos/ogil/140751090/" target="_blank"><img src="http://farm1.static.flickr.com/47/140751090_69d1c9a16b_m.jpg" align="left" height="160" hspace="7" width="240" /></a>Another <a href="http://www.gnucitizen.org/projects/the-pownce-worm/" target="_blank">interesting posting</a> by pdp from <a href="http://www.gnucitizen.org/" target="_blank">GnuCitizen</a>: He found an XSS and XSRF flaw in <a href="http://pownce.com/" target="_blank">Pownce</a>, however this is not the interesting thing about the article.</p>
<p>What makes it worth reading is pdp&#8217;s technique to inject the javascript. Only a field of 16 characters at max is vulnerable as it does not escape the userinput. Any useful attack requires way more than just 16 chars.</p>
<p>What makes the technique work is that below the vulnerable field, there&#8217;s another field that takes user input but does in fact correctly escape it. In between the two fields there&#8217;s some HTML garbage. By just opening a script tag and a multiline JS comment, all that needs to be done in the second field is closing the comment and writing javascript code that works without using angle brackets or quotes.</p>
<p>As I&#8217;m writing this I realize that I&#8217;m probably not very good at explaining, so just have a look at the code and you&#8217;ll see what I mean:</p>
<pre><code>[html junk]

*/&#60;script&#62;/*

[html junk]

*/document.write(atob(/PHN[...]EtLQ==/.toString().substr(1,56)));/*

[html junk]</code></pre>
<p>By using the eval() function, you can actually execute arbitrarily long base64 encoded javascript.</p>
<p><font color="#666666" size="-2">Picture of small house by <a href="http://www.flickr.com/photos/ogil/" target="_blank">Dom Dada</a></font></p>
</div>]]></content:encoded>
</item>

</channel>
</rss>
