<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>webgoat &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/webgoat/</link>
	<description>Feed of posts on WordPress.com tagged "webgoat"</description>
	<pubDate>Wed, 10 Feb 2010 10:14:56 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[WebGoat]]></title>
<link>http://securitydown.wordpress.com/2009/07/08/webgoat/</link>
<pubDate>Wed, 08 Jul 2009 03:06:25 +0000</pubDate>
<dc:creator>Brenn0</dc:creator>
<guid>http://securitydown.wordpress.com/2009/07/08/webgoat/</guid>
<description><![CDATA[WebGoat é uma aplicação web J2EE mantida pela OWASP criada para ensinar lições de segurança sobre ap]]></description>
<content:encoded><![CDATA[WebGoat é uma aplicação web J2EE mantida pela OWASP criada para ensinar lições de segurança sobre ap]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP WebGoat - Practicing WebApp and Network Security]]></title>
<link>http://israelany.wordpress.com/2009/03/10/owasp-webgoat-practicing-webapp-and-network-security/</link>
<pubDate>Tue, 10 Mar 2009 15:44:51 +0000</pubDate>
<dc:creator>israelagnouhyattara</dc:creator>
<guid>http://israelany.wordpress.com/2009/03/10/owasp-webgoat-practicing-webapp-and-network-security/</guid>
<description><![CDATA[After a long period of procrastination, I finally went ahead and downloaded the OWASP WebGoat Projec]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>After a long period of procrastination, I finally went ahead and downloaded the OWASP WebGoat Project ISO and installed it in VMWare using the labRAT LiveCD. Here are some screenshots:</p>
<div id="attachment_78" class="wp-caption alignnone" style="width: 510px"><img class="size-full wp-image-78" title="OWASP LabRat VMWare Configuration" src="http://israelagnouhyattara.files.wordpress.com/2009/03/owasp-labrat-vmware-configuration2.png?w=500&#038;h=312" alt="OWASP LabRat VMWare Configuration" width="500" height="312" /><p class="wp-caption-text">OWASP LabRat VMWare Configuration</p></div>
<p><img class="size-full wp-image-75" title="OWASP WebGoat practice from Browser" src="http://israelagnouhyattara.files.wordpress.com/2009/03/owasp-webgoat-practice-from-browser.png?w=500&#038;h=338" alt="OWASP WebGoat practice from Browser" width="500" height="338" /></p>
<div class="mceTemp">
<dl class="wp-caption alignnone">
<dd class="wp-caption-dd">OWASP WebGoat practice from Browser</dd>
</dl>
</div>
<p>To my surprise, now, the OWASP Project already has images available for download:</p>
<p>ISO: <a title="http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.iso" href="http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.iso" target="_self">http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.iso</a><br />
VMWare: <a title="http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.vmdk.rar" href="http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.vmdk.rar" target="_self">http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.vmdk.rar</a><br />
Virtual Box: <a title="http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.vdi.rar" href="http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.vdi.rar" target="_self">http://mtesauro.com/files/owasp-livecd-AustinTerrier-Feb2009.vdi.rar</a></p>
<p>Here are the most recent screenshots of the environment:</p>
<p><div id="attachment_79" class="wp-caption alignnone" style="width: 510px">&#8220;]<img class="size-full wp-image-79" title="OWASP LiveCD 2008 [1]" src="http://israelagnouhyattara.files.wordpress.com/2009/03/owasp-livecd-2008-1.png?w=500&#038;h=375" alt="OWASP LiveCD 2008 [1]" width="500" height="375" /><p class="wp-caption-text">OWASP LiveCD 2008 [1</p></div>[caption id="attachment_81" align="alignnone" width="500" caption="OWASP LiveCD 2008 [2"]&#8220;]<img class="size-full wp-image-81" title="OWASP LiveCD 2008 [2]" src="http://israelagnouhyattara.files.wordpress.com/2009/03/owasp-livecd-2008-21.png?w=500&#038;h=362" alt="OWASP LiveCD 2008 [2]" width="500" height="362" />[/caption]Free tutorials and training are made available by YGN Ethical/Elite Hacking Group:</p>
<p><a title="http://yehg.net/lab/pr0js/training/webgoat.php" href="http://yehg.net/lab/pr0js/training/webgoat.php" target="_self">http://yehg.net/lab/pr0js/training/webgoat.php</a></p>
<p>But, in the end, some people still would like to save all of that virtualization space  by installing the binary files directly onto their systems. This is how WebGoat started; and, Google Code is making sure that the OWASP WebGoat project thrives still:</p>
<p><a title="http://code.google.com/p/webgoat/downloads/list" href="http://code.google.com/p/webgoat/downloads/list" target="_self">http://code.google.com/p/webgoat/downloads/list</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WebGoat 5.2 Kurulum (Local) ]]></title>
<link>http://fentanyl.wordpress.com/2008/12/15/webgoat-52-kurulum-local/</link>
<pubDate>Mon, 15 Dec 2008 14:14:01 +0000</pubDate>
<dc:creator>fentanyl</dc:creator>
<guid>http://fentanyl.wordpress.com/2008/12/15/webgoat-52-kurulum-local/</guid>
<description><![CDATA[Webgoat’ın En Son Sürümünü (5.2) İndirin. Daha Sonra Çalışmak İstediğiniz Yere .zip’li Dosyayı Açın.]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><span style="font-family:Verdana,Arial,Helvetica,sans-serif;font-size:xx-small;"><strong> <span>Web</span><span>goat</span>’ın En Son Sürümünü (5.2) İndirin. Daha Sonra Çalışmak İstediğiniz Yere .zip’li Dosyayı Açın. Örn. c:\\\\<span>web</span><span>goat</span> 5.2\\\\</p>
<p>Dosya İçeriği ;<br />
java<br />
tomcat<br />
readme.txt<br />
<span>web</span><span>goat</span>.bat<br />
<span>web</span><span>goat</span>.sh<br />
<span>web</span><span>goat</span>_8080.bat ’tır. Bknz Resim 1</strong></span></p>
<p><span style="font-family:Verdana,Arial,Helvetica,sans-serif;font-size:xx-small;"><strong><!--more--></strong></span><img class="alignleft size-full wp-image-684" title="119" src="http://fentanyl.wordpress.com/files/2008/12/119.jpg" alt="119" width="590" height="240" /></p>
<p><span style="font-family:Verdana,Arial,Helvetica,sans-serif;font-size:xx-small;"><strong>Daha Sonra <span>web</span><span>goat</span>.bat veya <span>web</span><span>goat</span>_8080.bat Dosyasını Çalıştırın. PC’nizde DOS Ekranı Çıkacak Bekleyin. Daha Sonra TomCat Ekranı Çıkacak(Bknz Resim 2)</strong></span></p>
<p><span style="font-family:Verdana,Arial,Helvetica,sans-serif;font-size:xx-small;"><strong>Resim 2</strong></span></p>
<p><img class="alignleft size-full wp-image-685" title="212" src="http://fentanyl.wordpress.com/files/2008/12/212.jpg" alt="212" width="666" height="338" /></p>
<p><span style="font-family:Verdana,Arial,Helvetica,sans-serif;font-size:xx-small;"><strong>Tomcat Gerekli Ayarları Yaptıktan Sonra Server’ı Başlatacak. Browser’a http://localhost:8080/<span>web</span><span>goat</span>/attacks Yazın. Kullanıcı Adı ve Şifre İsteyecek. Kullanıcı Adı : guest ve Şifre : guest Yazdıktan Sonra <span>web</span><span>goat</span> Hazır. İyi Testler <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </strong><strong>Not : <span>web</span><span>goat</span>_8080.bat Dosyası PC’sinde IIS Yani Internet Information Services Yüklü Olanlar İçindir. PC’sinde 80 Portunu Kullanmayanlar <span>web</span><span>goat</span>.bat Dosyasını Çalıştırsınlar..</strong></span></p>
<p><span style="font-family:Verdana,Arial,Helvetica,sans-serif;font-size:xx-small;"><strong>Yazar : </strong></span>ZeroTolerance</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Web Goat Nedir ?]]></title>
<link>http://fentanyl.wordpress.com/2008/12/15/web-goat-nedir/</link>
<pubDate>Mon, 15 Dec 2008 13:57:40 +0000</pubDate>
<dc:creator>fentanyl</dc:creator>
<guid>http://fentanyl.wordpress.com/2008/12/15/web-goat-nedir/</guid>
<description><![CDATA[web goat Nedir? webgoat OWASP (Open web Application Security Project) tarafından geliştirilen , kast]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p><strong><span>web</span> <span>goat</span> Nedir?</strong></p>
<p><span>web</span><span>goat</span> OWASP (<strong>Open <span>web</span> Application Security Project) </strong>tarafından geliştirilen , kastılı olarak yüzlerce açık içeren J2EE platformunda yazılmış olan, <span>web</span> uygulamarındaki açıkları kendi kendize öğrenebileceğiniz güvenlik test yazılımıdır. Yazılımın odak noktasında <span>web</span> uygulamaları yer almaktadır. Çeşitli kategorileride ki dersler ile güvenlik uzmanlarına yada <span>web</span> uygulaması geliştirenlere; ilgili açığı anlayabilme, çözebilme ve exploit edebilme yetenekleri kazandırmak amacındadır.</p>
<p>Örnek olarak SQLInjection açığı kullanarak sahte kredi kartı bilgileri ile alışveriş yapmanız istenmektedir. Bu aşamada sistemdeki form bilgilerini SQLInjection yöntemi ile atlatıp exploit edebilmeniz gerekmektedir. Eğer başarıya ulaşırsanız bir sonraki teste yönlendirilmekte ve her geçtiğiniz test için puan almaktasınız.</p>
<p><span>web</span><span>goat</span> içerisinde yer alan testlerini tamamı başarı ile tamamlayan kişiler bu konuda ciddi bir deyeim ve bilgi birikimine sahip olmuş olcağından ilerde yapacağı denetimlerde, uygulamalarda güvenlik risklerinide minimum düzeyde tutabilmeyi hedeflemiş olacaktır.</p>
<p>Temel olarak aşağıdaki konularda ( her geçen gün artan açıklara paralel olarak güncellenmektedir) testler içermektedir :</p>
<p>· Cross Site Scripting<br />
· Access Control<br />
· Thread Safety<br />
· Hidden Form Field Manipulation<br />
· Parameter Manipulation<br />
· Weak Session Cookies<br />
· Blind SQL Injection<a href="http://www.olympos.org/glossary/term/563" target="_blank"> </a><br />
· Numeric SQL Injection<br />
· String SQL Injection<br />
· <span>web</span> Services<br />
· Fail Open Authentication<br />
· Dangers of HTML Comments</p>
<p><!--more--><strong><span>web</span><span>goat</span>’ı Kimler Kullanabilir ?</strong></p>
<p>Öncelikle <span>web</span> tabanlı uygulama geliştirenler, <span>web</span> tabanlı yazılım güvenliği ile uğraşanlar, kendi sitesini kurup yönetenler, sistem güvenlik uzmanları veya bu konuya ilgi duyan ve temel düzeyde bilgisi olan herkes <span>web</span><span>goat</span>’ı kurup testleri çözebilir.</p>
<p><strong><span>web</span><span>goat</span>’a Kendimizde Dersler Ekleyebilir miyiz?<br />
</strong>Evet <span>web</span><span>goat</span>’ın böyle bir desteği var. OWASP’ın sitesinde nasıl ders yazılacağı ile ilgili detaylı dokümanlara ulaşabilirsiniz.</p>
<p><strong>Nereden İndirebilirim?</strong></p>
<p>Kurulum dosyasını Google Code arşivinden :</p>
<p><a href="http://code.google.com/p/%3Cspan%20style=" target="_blank">http://code.google.com/p/<span>web</span><span>goat</span>/downloads/list </a></p>
<p><strong>XSS Yöntemi ile bir Phising Saldırısı Yapmamız Bekleniyor :</strong></p>
<p><img class="alignleft size-full wp-image-677" title="adszok1" src="http://fentanyl.wordpress.com/files/2008/12/adszok1.png" alt="adszok1" width="600" height="504" /></p>
<p><strong>ByPass yöntemi ile Alt dizin erişimleri yapmamız isteniyor :</strong></p>
<p><strong><img class="alignleft size-full wp-image-678" title="24" src="http://fentanyl.wordpress.com/files/2008/12/24.png" alt="24" width="600" height="493" /></strong></p>
<p><strong>Session HiJacking yöntemi :</strong></p>
<p><strong><img class="alignleft size-full wp-image-679" title="31" src="http://fentanyl.wordpress.com/files/2008/12/31.png" alt="31" width="600" height="480" /></strong></p>
<p><a href="http://www.owasp.org/index.php/Category:OWASP_%3Cspan%20style=" target="_blank">http://www.owasp.org/index.php/Category:OWASP_<span>web</span><span>goat</span>_Project</a></p>
<p><strong><span>web</span><span>goat</span> Çözümler</strong> <strong>General – Http Basics ( http Temelleri)</strong></p>
<p>Bu testin amacı Http Request nesnesinin nasıl işlendiğini(handling) edilebildğini gösterebilmektedir. Bizden adımızı girmemiz isteniyor, adımız girip GO! dediğimizde http Request ile alınan form değeri tam tersine çevirilerek bize tekrar gösteriliyor. Eğer biz aynı şekilde adımızı ( Örnekte Murat) tersinden yazıp ( taruM) O! dersek bu dersi geçmiş olacağız. Buradaki test bir güvenlik açığından çok temel işleyişi anlatmaktadır</p>
<p><img class="alignleft size-full wp-image-680" title="15" src="http://fentanyl.wordpress.com/files/2008/12/15.png" alt="15" width="600" height="600" /></p>
<p>Burada gördüğünüz gibi Tebrikler mesajını aldık ve bu testi geçtik.</p>
<p>Dikkat ettiyseniz yukarıda Show Params ve Show Cookies butonları yer almakta, bu butonlar bizlere o anki verilerin neler olduğunu göstermektedir. Aynı zamanda atak yapmadan önce bu verileri görerek atağımızıda belirleyebiliriz.</p>
<p>Aşağıdaki resimde göndermiş olduğmuz &#8220;taruM&#8221; parametresi işlenerek (handling) Murat olarak çevrilmiştir.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Das legale Trainingslager für Nachwuchshacker]]></title>
<link>http://itsicherheit.wordpress.com/2008/08/06/das-legale-trainingslager-fur-nachwuchshacker/</link>
<pubDate>Wed, 06 Aug 2008 07:22:05 +0000</pubDate>
<dc:creator>Guido Strunck</dc:creator>
<guid>http://itsicherheit.wordpress.com/2008/08/06/das-legale-trainingslager-fur-nachwuchshacker/</guid>
<description><![CDATA[So mancher Nachwuchshacker wünscht sich so etwas wie eine Gelegenheit zum Erproben seiner Hackerfähi]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>So mancher Nachwuchshacker wünscht sich so etwas wie eine Gelegenheit zum Erproben seiner Hackerfähigkeiten oder auch nur zum Ausprobieren von Dingen, über die er etwas gelesen hat, die man aber legal nur auf dem eigenen Rechner testen kann. Schließlich hat nicht jeder eine Testumgebung mit Servern, Netzwerk, Routern etc. zuhause unter dem Schreibtisch stehen.</p>
<p>Vielen ist bereits mit Werkzeugen wie der <a href="http://itsicherheit.wordpress.com/2008/06/25/webanwendungen-hacken-lernen-das-webgoat-projekt/" target="_blank">Webgoat-Software von OWASP</a> geholfen, mit der sich Angriffstechniken auf unsichere Web-Applikationen anhand eines CBT einüben lassen.</p>
<p>Für Leute mit darüber hinausgehendem Übungsbedarf wurde von einer ehrenamtlich tätigen Hacker-Community auf <a href="http://www.hackthissite.org/" target="_blank">Hackthissite.org</a> ein (englischsprachiges) Lehr- und Lernportal für Hackertechniken eingerichtet. Die Community beschreibt sich selbst und ihr Projekt so:</p>
<p><em>“Hack This Site is a free, safe and legal training ground for hackers to test and expand their hacking skills. More than just another hacker wargames site, we are a living, breathing community with many active projects in development, with a vast selection of hacking articles and a huge forum where users can discuss hacking, network security, and just about everything. Tune in to the hacker underground and get involved with the project.”</em></p>
<p>Zu zahlreichen Themen aus den Bereichen Programmierung, Systemverwaltung, Netzwerke sowie natürlich zum Hacken an sich gibt es Fachartikel. Das ebenfalls angebotene „HackThisZine“ enthält interessante Informationen aus dem Bereich freie Informations- und Netzkultur sowie zum informationellen Selbstschutz.</p>
<p>Die Fachinfos sind allgemein zugänglich. Für die Teilnahme an den Hackerübungen ist eine (kostenlose) Registrierung erforderlich.</p>
<p>Die Hackerübungen beginnen mit zehn sog. „Basic Missions“ mit steigendem Schwierigkeitsgrad über Aufgaben bei denen man Websites angreifen muss (Teilbereiche von Hackthissite, in die bestimmte Fehler eingebaut wurden), oder bei denen etwas programmiert, decodiert, manipuliert oder sonst wie gehackt werden muss bis hin zu anspruchsvollen „Spezialaufträgen“, die man erst präsentiert bekommt, wenn man alle zehn „Basic Missions“ erfolgreich abgeschlossen hat.</p>
<p>In einem Forum kann man sich mit anderen über die Inhalte der Hackeraufgaben sowie das dahinterstehende IT-Knowhow austauschen. Um anderen den Spaß nicht zu verderben, werden allerdings Lösungsleitfäden von der Forenadministration sofort gelöscht. Hinzu kommen Foren über zahlreiche weitere Themen rund um den kreativen Umgang mit Computern.</p>
<p>Alles in allem ist <a href="http://www.hackthissite.org/" target="_blank">Hackthissite.org</a> eine Mischung aus Fachinfothek und Forum für alle an der IT-Sicherheit Interessierten und einer Art Online-Spiel mit sehr realistischem Hintergrund zur Erprobung der eigenen Hackerfähigkeiten.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WebGoat - cause everyone else is doing it!]]></title>
<link>http://insanesecurity.wordpress.com/2008/07/15/webgoat-cause-everyone-else-is-doing-it/</link>
<pubDate>Tue, 15 Jul 2008 08:13:47 +0000</pubDate>
<dc:creator>dblackshell</dc:creator>
<guid>http://insanesecurity.wordpress.com/2008/07/15/webgoat-cause-everyone-else-is-doing-it/</guid>
<description><![CDATA[The unzip and run insecure J2EE web application&#8230; at least under windows&#8230; WebGoat is a de]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>The unzip and run insecure J2EE web application&#8230; at least under windows&#8230;</p>
<blockquote><p>
<b>WebGoat</b> is a deliberately insecure J2EE web application maintained by OWASP designed to teach web application security lessons. In each lesson, users must demonstrate their understanding of a security issue by exploiting a real vulnerability in the WebGoat application. For example, in one of the lessons the user must use SQL injection to steal fake credit card numbers. The application is a realistic teaching environment, providing users with hints and code to further explain the lesson.
</p></blockquote>
<p><a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project">http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project</a><br />
<a href="http://code.google.com/p/webgoat/">http://code.google.com/p/webgoat/</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Webanwendungen hacken lernen - Das WebGoat-Projekt]]></title>
<link>http://itsicherheit.wordpress.com/2008/06/25/webanwendungen-hacken-lernen-das-webgoat-projekt/</link>
<pubDate>Wed, 25 Jun 2008 17:35:26 +0000</pubDate>
<dc:creator>Guido Strunck</dc:creator>
<guid>http://itsicherheit.wordpress.com/2008/06/25/webanwendungen-hacken-lernen-das-webgoat-projekt/</guid>
<description><![CDATA[Das Open Web Application Security Project (OWASP) ist eine weltweite Community, die sich mit der Ent]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Das <a title="Open Web Application Security Project (OWASP)" href="http://www.owasp.org/" target="_blank">Open Web Application Security Project (OWASP)</a> ist eine weltweite Community, die sich mit der Entwicklung sicherer Webapplikationen befasst. Sie haben dazu umfängliche Materialien (in englisch) sowie selbstentwickelte Open-Source-Software ins Netz gestellt, mit der man sich autodidaktisch die nötigen Kenntnisse über sichere Webanwendungen erarbeiten kann.</p>
<p>Eines dieser Werkzeuge ist <a title="WebGoat" href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank">WebGoat</a>. Dabei handelt es sich um eine J2EE-Webanwendung, die man sich runterladen und lokal installieren kann. In ihr wurden bewusst zahlreiche Sicherheitslücken eingebaut. WebGoat ist als Lernprogramm in Kapitel gegliedert, die sich mit gängigen Sicherheitslücken befassen. In jedem Kapitel gibt es praktische Übungen, in denen man versuchen kann, eine Sicherheitslücke auszunutzen und so eine bestimmte Angriffsart selber praktisch nachzuvollziehen. Auch der Quellcode von WebGoat ist verfügbar, so dass Entwickler die Applikation selbst zur Analyse auseinandernehmen können.</p>
<p>Der Name Goat („Bock“) wurde der Anwendung angeblich deshalb gegeben, da auch Entwickler gerne dazu neigen, bei Schwierigkeiten einen Sündenbock zu suchen. Hier ist einer.</p>
<p>Zu den mit WebGoat praktisch nachvollziehbaren Angriffsmethoden und Schwachstellen in Webanwendungen zählen:</p>
<p>•    Cross Site Scripting<br />
•    Access Control<br />
•    Thread Safety<br />
•    Hidden Form Field Manipulation<br />
•    Parameter Manipulation<br />
•    Weak Session Cookies<br />
•    Blind SQL Injection<br />
•    Numeric SQL Injection<br />
•    String SQL Injection<br />
•    Web Services<br />
•    Fail Open Authentication<br />
•    Dangers of HTML Comments</p>
<p>Etliche der seit einiger Zeit von Bildungsträgern vermehrt und für vierstellige Beträge angebotenen „Hackerkurse“ benutzen u.a. WebGoat als Trainingsumgebung für Angriffe auf Webanwendungen. Auch ich habe das Tool auf diese Weise entdeckt. OWASP stellt es kostenfrei für die interessierte Fachwelt zur Verfügung, so dass man auch zuhause und ohne teures Seminar damit experimentieren kann.</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Interesting Information Security Bits for June 9th, 2008]]></title>
<link>http://infosecramblings.wordpress.com/2008/06/09/interesting-information-security-bits-for-june-9th-2008/</link>
<pubDate>Mon, 09 Jun 2008 18:03:50 +0000</pubDate>
<dc:creator>Kevin Riggins</dc:creator>
<guid>http://infosecramblings.wordpress.com/2008/06/09/interesting-information-security-bits-for-june-9th-2008/</guid>
<description><![CDATA[Good afternoon everyone or at least those who share my timezone. We have a good bunch of interesting]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Good afternoon everyone or at least those who share my timezone.  We have a good bunch of interesting things to look at that were posted over the weekend.  So here we go!</p>
<p><a href="http://securityincite.com" target="_blank">Mike Rothman</a> posted some thoughts on the <a href="http://securityincite.com/blog/mike-rothman/thoughts-on-mss" target="_blank">rapidly evolving Manage Security Services space</a>.  He likens it to the process banking went through.  It&#8217;s an interesting read.</p>
<p><a href="http://securityuncorked.squarespace.com" target="_blank">Jennifer Jabbusch</a> shares a really good analogy with us regarding <a href="http://securityuncorked.squarespace.com/security-uncorked/2008/6/6/logging-correlation-and-it-search-an-analogy.html" target="_blank">Logging, Correlation and IT Search</a>.  Very helpful for those times when you are trying to get across an inherently technical topic to a group of non-technical people.</p>
<p>Via Xavier at <a href="http://blog.rootshell.be/2008/06/07/shit-happens-3/" target="_blank">/dev/random</a> a free and nifty looking tool.</p>
<blockquote><p><a href="http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis" target="_blank"><strong>HijackThis™</strong></a> is a free utility which quickly scans your Windows computer to find settings that may have been changed by spyware, malware or other unwanted programs. HijackThis creates a report, or log file, with the results of the scan.</p></blockquote>
<p><a href="http://security4all.blogspot.com" target="_blank">Security4all</a> points us towards a video that gives us a <a href="http://security4all.blogspot.com/2008/06/video-introduction-into-xss-using.html" target="_blank">introduction to XSS using Webgoat</a>.  The video is hosted at <a href="http://securitydistro.com/video-tutorials/54/Introduction-to-XSS-using-WebGoat.php" target="_blank">securitydistro.com</a>.</p>
<p>By way of <a href="http://www.johnmwillis.com/other/20-great-windows-open-source-projects/" target="_blank">John M Willis</a>, a pointer to an article on Network World, <a href="http://www.networkworld.com/community/20-open-source-windows-tools?page=0%2C0" target="_blank">20 great Windows open source projects you should get to know</a>.</p>
<p><a href="http://taosecurity.blogspot.com/" target="_blank">Richard Bejtlich</a> <a href="http://taosecurity.blogspot.com/2008/06/best-single-day-class-ever.html" target="_blank">shares</a> his experience attending a <a href="http://www.tufte.com/" target="_blank">Edward Tufte</a> class on <a href="http://www.edwardtufte.com/tufte/courses" target="_blank">Presenting Data and Information</a>.  I have not read Edward&#8217;s stuff, but it is on my list to check out.</p>
<p><a href="http://www.bloginfosec.com/author/jlowder/" target="_blank">Jeff Lowder</a> has an article up on <a href="http://www.bloginfosec.com" target="_blank">BlogInfoSec.com</a> about <a href="http://www.bloginfosec.com/2008/06/09/agility-and-risk-compensation-exploring-the-connection/" target="_blank">Agility and Risk Compensation</a>.  He has some interesting points about perceived risk and the actions that people take in light of their understanding of risk as it pertains to agility in business.  He also points to a good article on wikipedia about <a href="http://en.wikipedia.org/wiki/Risk_compensation" target="_blank">Risk Compensation Theory</a>.  Both are worth a gander.</p>
<p>Well that&#8217;s it for now.</p>
<p>Have a good day.</p>
<p>Kevin</p>
<p>Technorati Tags: <a class="performancingtags" rel="tag" href="http://technorati.com/tag/mss">mss</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/logging">logging</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/correlation">correlation</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/search">search</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/hijackthis">hijackthis</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/xss">xss</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/webgoat">webgoat</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/open%20source">open source</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/powerpoint">powerpoint</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/presentation">presentation</a>, <a class="performancingtags" rel="tag" href="http://technorati.com/tag/risk%20compensation">risk compensation</a></p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Reflected XSS]]></title>
<link>http://webappsecurity.wordpress.com/2008/05/27/reflected-xss/</link>
<pubDate>Tue, 27 May 2008 04:06:07 +0000</pubDate>
<dc:creator>webappsecurity</dc:creator>
<guid>http://webappsecurity.wordpress.com/2008/05/27/reflected-xss/</guid>
<description><![CDATA[Esse e&#8217; mais um video usando o webgoat pra mostrar como fazer alguns ataques, todos os videos ]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Esse e&#8217; mais um video usando o webgoat pra mostrar como fazer alguns ataques, todos os videos que estou fazendo serao mostrados no FGSL agora no dia 31 de maio na faculdade senac <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Bom ainda estao sem narracao mas a ideia e que venham a ter <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/XBY1lGcOBvE&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/XBY1lGcOBvE&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
<p> </p>
<p>Abracos e ate&#8217; algum post descente <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meu primeiro post no meu novo blog :)]]></title>
<link>http://webappsecurity.wordpress.com/2008/05/25/meu-primeiro-post-no-meu-novo-blog/</link>
<pubDate>Sun, 25 May 2008 15:14:32 +0000</pubDate>
<dc:creator>webappsecurity</dc:creator>
<guid>http://webappsecurity.wordpress.com/2008/05/25/meu-primeiro-post-no-meu-novo-blog/</guid>
<description><![CDATA[Bom pessoas estou novamente tentando fazer um blog, agora algo mais especifico sobre seguranca em ap]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>Bom pessoas estou novamente tentando fazer um blog, agora algo mais especifico sobre seguranca em aplicacao web <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Bom pro meu primeiro post vai um teste de alguns videos que estou fazendo sobre ataques em aplicacoes web <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><span style='text-align:center; display: block;'><object width='425' height='350'><param name='movie' value='http://www.youtube.com/v/femI7IMP8hw&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' /><param name='allowfullscreen' value='true' /><param name='wmode' value='transparent' /><embed src='http://www.youtube.com/v/femI7IMP8hw&#038;rel=1&#038;fs=1&#038;showsearch=0&#038;hd=0' type='application/x-shockwave-flash' allowfullscreen='true' width='425' height='350' wmode='transparent'></embed></object></span></p>
<p>Abracos!</p>
<p>ps: Desculpem ainda nao configurei meu teclado novo <img src='http://s.wordpress.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[WebGoat Install]]></title>
<link>http://strictlywork.wordpress.com/2008/05/02/webgoat-install/</link>
<pubDate>Fri, 02 May 2008 15:10:05 +0000</pubDate>
<dc:creator>shunyavada</dc:creator>
<guid>http://strictlywork.wordpress.com/2008/05/02/webgoat-install/</guid>
<description><![CDATA[WebGoat is running on the eiqtestpc (192.168.128.31). On startup tomcat starts up automatically (tho]]></description>
<content:encoded><![CDATA[<div class='snap_preview'><p>WebGoat is running on the eiqtestpc (192.168.128.31).</p>
<p>On startup tomcat starts up automatically (though only on port 8080 apparently, port 80 nothing seems to be running)</p>
<p>This prevents using the webgoat.bat (at c:\WebGoat-5.1) from starting up, it fails complaining that port is already in use. Though it is trying to start up on port 80.</p>
<p>Using regedit, webgoat.bat has been added in Registry-&#62;blahblah-&#62;Windows-&#62;CurrentVersion-&#62;Run. But this is currently not working, probably due to the problem noted above.</p>
<p>By default WebGoat does not allow remote login. This is due to the following setting in server.xml for port 80:</p>
<p>address=127.0.0.1</p>
<p>server.xml is recopied from server_80.xml everytime WebGoat is restarted. Hence modify server_80.xml and remove delete the above attribute and restart WebGoat. This should allow remote login.</p>
<p>The URL to login is localhost/WebGoat/attack. Username &#8211; guest, password &#8211; guest.</p>
<p>Note that for some reason the initial login HAS to be done from the localhost, then and then only the remote login seems to be enabled!!</p>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Installare WebGoat su GNU/Linux]]></title>
<link>http://tugulab.wordpress.com/2008/02/09/installare-webgoat-su-gnulinux/</link>
<pubDate>Sat, 09 Feb 2008 13:37:03 +0000</pubDate>
<dc:creator>jollyr0ger</dc:creator>
<guid>http://tugulab.wordpress.com/2008/02/09/installare-webgoat-su-gnulinux/</guid>
<description><![CDATA[Questo è un software, creato dall&#8217;OWASP, è un&#8217;applicazione che si prefigge lo scopo di i]]></description>
<content:encoded><![CDATA[Questo è un software, creato dall&#8217;OWASP, è un&#8217;applicazione che si prefigge lo scopo di i]]></content:encoded>
</item>
<item>
<title><![CDATA[OWASP WebGoat project. J2EE i hacking ;)]]></title>
<link>http://juneja.wordpress.com/2007/06/06/owasp-webgoat-project-j2ee-i-hacking/</link>
<pubDate>Wed, 06 Jun 2007 11:33:13 +0000</pubDate>
<dc:creator>Arvind Juneja</dc:creator>
<guid>http://juneja.wordpress.com/2007/06/06/owasp-webgoat-project-j2ee-i-hacking/</guid>
<description><![CDATA[Graliście kiedyś w hackgame? No pewnie że graliście. A jak Wam szło? Bo mi to różnie, czasem lepiej ]]></description>
<content:encoded><![CDATA[Graliście kiedyś w hackgame? No pewnie że graliście. A jak Wam szło? Bo mi to różnie, czasem lepiej ]]></content:encoded>
</item>

</channel>
</rss>
