<?xml version="1.0"?>
<rss version="2.0">
<channel>
  <title>Ivan Buetler - Web Application Security category</title>
  <link>http://www.csnc.ch/blog/categories/websec/</link>
  <description>Ivan Buetler - Blog</description>
  <language>en</language>
  <copyright>Ivan Buetler</copyright>
  <lastBuildDate>Fri, 02 Jul 2010 12:22:00 GMT</lastBuildDate>
  <generator>Pebble (http://pebble.sourceforge.net)</generator>
  <docs>http://backend.userland.com/rss</docs>
  
  <image>
    <url>http://www.csnc.ch/misc/images/team/ibuetler.jpg</url>
    <title>Ivan Buetler (Web Application Security category)</title>
    <link>http://www.csnc.ch/blog/</link>
  </image>
  
  
  <item>
    <title>OWASP Guide Online</title>
    <link>http://www.csnc.ch/blog/2010/07/02/1278073320000.html</link>
    
      
        <description>
          &lt;br /&gt;
Ever wanted to know how to defeat web hacking attacks - what to do with the identified OWASP TOP 10 vulnerabilities? I really much appreciate the OWASP TOP 10 papers, but when it comes to mitigation and remediation, everything is deeply hidden somewhere. &lt;br /&gt;
&lt;br /&gt;
That&#039;s why I like the following OWASP page - clear and simple to use&lt;br /&gt;
&lt;a href=&#034;http://code.google.com/p/owasp-development-guide/wiki/Guide&#034;&gt;http://code.google.com/p/owasp-development-guide/wiki/Guide&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Cheers&lt;br /&gt;
Ivan
        </description>
      
      
    
    
    
    <category>Web Application Security</category>
    
    <comments>http://www.csnc.ch/blog/2010/07/02/1278073320000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2010/07/02/1278073320000.html</guid>
    <pubDate>Fri, 02 Jul 2010 12:22:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Apache ORG hacked - Good Incident Response</title>
    <link>http://www.csnc.ch/blog/2010/04/15/1271319420000.html</link>
    
      
        <description>
          &lt;br /&gt;
APACHE ORG wurde am 6. April &amp;uuml;ber eine XSS Sicherheitsl&amp;uuml;cke kompromittiert. Dabei konnte eine ADMIN Session &amp;uuml;bernommen werden (Session Hijacking) und &amp;uuml;ber Brute Force Methoden weitere g&amp;uuml;ltige Login Daten geknackt werden. &lt;br /&gt;
&lt;br /&gt;
Ich finde die Apache hat sehr gut und seri&amp;ouml;s reagiert. Entsprechend liest sich deren Incident Report vorbildlich - ich empfehle das Studium der Lekt&amp;uuml;re um vielleicht bei einem Incident auf die eigene Webseite vorbereitet zu sein. &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#034;https://blogs.apache.org/infra/entry/apache_org_04_09_2010&#034;&gt;https://blogs.apache.org/infra/entry/apache_org_04_09_2010&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gr&amp;uuml;sse&lt;br /&gt;
Ivan
        </description>
      
      
    
    
    
    <category>Web Application Security</category>
    
    <comments>http://www.csnc.ch/blog/2010/04/15/1271319420000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2010/04/15/1271319420000.html</guid>
    <pubDate>Thu, 15 Apr 2010 08:17:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Cross Site Scripting Problem in Microsoft Sharepoint</title>
    <link>http://www.csnc.ch/blog/2010/02/23/1266939720000.html</link>
    
      
        <description>
          &lt;br /&gt;
Wenn man Sharepoint als CMS (Content Management System) versteht, dann ist es mehr als logisch, dass man auch HTML und Java Scripts Dateien verwalten und hochladen kann. Die &lt;a href=&#034;http://www.hacktics.com/#view=Resources|Advisory&#034;&gt;Hacktics Security Gruppe&lt;/a&gt; macht in ihrem Advisory auf eine persistente XSS Sicherheitsl&amp;uuml;cke aufmerksam,&amp;nbsp; die gem&amp;auml;ss den Nachforschungen von &lt;strong&gt;Hacktics &lt;/strong&gt;von Microsoft nicht gepatcht werden kann. Es gibt jedoch einen Workaround...&lt;br /&gt;
&lt;br /&gt;
Wer sich mit &lt;strong&gt;Sharepoint &lt;/strong&gt;besch&amp;auml;ftigt, dem empfehle ich das Mail an Bugtraq zu lesen. Habe es als PDF abgelegt.&lt;br /&gt;
&lt;br /&gt;
&lt;link rel=&#034;File-List&#034; href=&#034;file:///C:\Users\IBUETL~1.CSN\AppData\Local\Temp\msohtmlclip1\01\clip_filelist.xml&#034; /&gt;
&lt;link rel=&#034;themeData&#034; href=&#034;file:///C:\Users\IBUETL~1.CSN\AppData\Local\Temp\msohtmlclip1\01\clip_themedata.thmx&#034; /&gt;
&lt;link rel=&#034;colorSchemeMapping&#034; href=&#034;file:///C:\Users\IBUETL~1.CSN\AppData\Local\Temp\msohtmlclip1\01\clip_colorschememapping.xml&#034; /&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
&lt;w:WordDocument&gt;
&lt;w:View&gt;Normal&lt;/w:View&gt;
&lt;w:Zoom&gt;0&lt;/w:Zoom&gt;
&lt;w:TrackMoves /&gt;
&lt;w:TrackFormatting /&gt;
&lt;w:PunctuationKerning /&gt;
&lt;w:ValidateAgainstSchemas /&gt;
&lt;w:SaveIfXMLInvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;
&lt;w:IgnoreMixedContent&gt;false&lt;/w:IgnoreMixedContent&gt;
&lt;w:AlwaysShowPlaceholderText&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;
&lt;w:DoNotPromoteQF /&gt;
&lt;w:LidThemeOther&gt;EN-US&lt;/w:LidThemeOther&gt;
&lt;w:LidThemeAsian&gt;X-NONE&lt;/w:LidThemeAsian&gt;
&lt;w:LidThemeComplexScript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;
&lt;w:Compatibility&gt;
&lt;w:BreakWrappedTables /&gt;
&lt;w:SnapToGridInCell /&gt;
&lt;w:WrapTextWithPunct /&gt;
&lt;w:UseAsianBreakRules /&gt;
&lt;w:DontGrowAutofit /&gt;
&lt;w:SplitPgBreakAndParaMark /&gt;
&lt;w:DontVertAlignCellWithSp /&gt;
&lt;w:DontBreakConstrainedForcedTables /&gt;
&lt;w:DontVertAlignInTxbx /&gt;
&lt;w:Word11KerningPairs /&gt;
&lt;w:CachedColBalance /&gt;
&lt;/w:Compatibility&gt;
&lt;w:DoNotOptimizeForBrowser /&gt;
&lt;m:mathPr&gt;
&lt;m:mathFont m:val=&#034;Cambria Math&#034; /&gt;
&lt;m:brkBin m:val=&#034;before&#034; /&gt;
&lt;m:brkBinSub m:val=&#034;&amp;#45;-&#034; /&gt;
&lt;m:smallFrac m:val=&#034;off&#034; /&gt;
&lt;m:dispDef /&gt;
&lt;m:lMargin m:val=&#034;0&#034; /&gt;
&lt;m:rMargin m:val=&#034;0&#034; /&gt;
&lt;m:defJc m:val=&#034;centerGroup&#034; /&gt;
&lt;m:wrapIndent m:val=&#034;1440&#034; /&gt;
&lt;m:intLim m:val=&#034;subSup&#034; /&gt;
&lt;m:naryLim m:val=&#034;undOvr&#034; /&gt;
&lt;/m:mathPr&gt;&lt;/w:WordDocument&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
&lt;w:LatentStyles DefLockedState=&#034;false&#034; DefUnhideWhenUsed=&#034;true&#034;
DefSemiHidden=&#034;true&#034; DefQFormat=&#034;false&#034; DefPriority=&#034;99&#034;
LatentStyleCount=&#034;267&#034;&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;0&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Normal&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;heading 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; QFormat=&#034;true&#034; Name=&#034;heading 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; QFormat=&#034;true&#034; Name=&#034;heading 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; QFormat=&#034;true&#034; Name=&#034;heading 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; QFormat=&#034;true&#034; Name=&#034;heading 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; QFormat=&#034;true&#034; Name=&#034;heading 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; QFormat=&#034;true&#034; Name=&#034;heading 7&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; QFormat=&#034;true&#034; Name=&#034;heading 8&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;9&#034; QFormat=&#034;true&#034; Name=&#034;heading 9&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 7&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 8&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; Name=&#034;toc 9&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;35&#034; QFormat=&#034;true&#034; Name=&#034;caption&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;10&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Title&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;1&#034; Name=&#034;Default Paragraph Font&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;11&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Subtitle&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;22&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Strong&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;20&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Emphasis&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;59&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Table Grid&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; UnhideWhenUsed=&#034;false&#034; Name=&#034;Placeholder Text&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;1&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;No Spacing&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;60&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Shading&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;61&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light List&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;62&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Grid&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;63&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;64&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;65&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;66&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;67&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;68&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;69&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;70&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Dark List&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;71&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Shading&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;72&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful List&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;73&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Grid&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;60&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Shading Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;61&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light List Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;62&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Grid Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;63&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 1 Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;64&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 2 Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;65&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 1 Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; UnhideWhenUsed=&#034;false&#034; Name=&#034;Revision&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;34&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;List Paragraph&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;29&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Quote&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;30&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Intense Quote&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;66&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 2 Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;67&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 1 Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;68&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 2 Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;69&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 3 Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;70&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Dark List Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;71&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Shading Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;72&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful List Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;73&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Grid Accent 1&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;60&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Shading Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;61&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light List Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;62&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Grid Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;63&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 1 Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;64&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 2 Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;65&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 1 Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;66&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 2 Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;67&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 1 Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;68&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 2 Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;69&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 3 Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;70&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Dark List Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;71&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Shading Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;72&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful List Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;73&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Grid Accent 2&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;60&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Shading Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;61&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light List Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;62&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Grid Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;63&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 1 Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;64&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 2 Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;65&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 1 Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;66&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 2 Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;67&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 1 Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;68&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 2 Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;69&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 3 Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;70&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Dark List Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;71&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Shading Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;72&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful List Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;73&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Grid Accent 3&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;60&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Shading Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;61&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light List Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;62&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Grid Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;63&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 1 Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;64&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 2 Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;65&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 1 Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;66&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 2 Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;67&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 1 Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;68&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 2 Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;69&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 3 Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;70&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Dark List Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;71&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Shading Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;72&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful List Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;73&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Grid Accent 4&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;60&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Shading Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;61&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light List Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;62&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Grid Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;63&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 1 Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;64&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 2 Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;65&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 1 Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;66&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 2 Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;67&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 1 Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;68&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 2 Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;69&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 3 Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;70&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Dark List Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;71&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Shading Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;72&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful List Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;73&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Grid Accent 5&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;60&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Shading Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;61&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light List Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;62&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Light Grid Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;63&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 1 Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;64&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Shading 2 Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;65&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 1 Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;66&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium List 2 Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;67&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 1 Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;68&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 2 Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;69&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Medium Grid 3 Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;70&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Dark List Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;71&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Shading Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;72&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful List Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;73&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; Name=&#034;Colorful Grid Accent 6&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;19&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Subtle Emphasis&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;21&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Intense Emphasis&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;31&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Subtle Reference&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;32&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Intense Reference&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;33&#034; SemiHidden=&#034;false&#034;
UnhideWhenUsed=&#034;false&#034; QFormat=&#034;true&#034; Name=&#034;Book Title&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;37&#034; Name=&#034;Bibliography&#034; /&gt;
&lt;w:LsdException Locked=&#034;false&#034; Priority=&#034;39&#034; QFormat=&#034;true&#034; Name=&#034;TOC Heading&#034; /&gt;
&lt;/w:LatentStyles&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;style type=&#034;text/css&#034;&gt;
&lt;!--
 /* Font Definitions */
 @font-face
	{font-family:&#034;Cambria Math&#034;;
	panose-1:2 4 5 3 5 4 6 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:roman;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1107304683 0 0 159 0;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:swiss;
	mso-font-pitch:variable;
	mso-font-signature:-1610611985 1073750139 0 0 159 0;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;
	mso-font-charset:0;
	mso-generic-font-family:modern;
	mso-font-pitch:fixed;
	mso-font-signature:-1610611985 1073750091 0 0 159 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
	{mso-style-unhide:no;
	mso-style-qformat:yes;
	mso-style-parent:&#034;&#034;;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:&#034;Calibri&#034;,&#034;sans-serif&#034;;
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:&#034;Times New Roman&#034;;
	mso-bidi-theme-font:minor-bidi;}
p.MsoPlainText, li.MsoPlainText, div.MsoPlainText
	{mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-link:&#034;Plain Text Char&#034;;
	margin:0in;
	margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:10.5pt;
	font-family:Consolas;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-bidi-font-family:&#034;Times New Roman&#034;;
	mso-bidi-theme-font:minor-bidi;}
span.PlainTextChar
	{mso-style-name:&#034;Plain Text Char&#034;;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-unhide:no;
	mso-style-locked:yes;
	mso-style-link:&#034;Plain Text&#034;;
	mso-ansi-font-size:10.5pt;
	mso-bidi-font-size:10.5pt;
	font-family:Consolas;
	mso-ascii-font-family:Consolas;
	mso-hansi-font-family:Consolas;}
.MsoChpDefault
	{mso-style-type:export-only;
	mso-default-props:yes;
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-fareast-font-family:Calibri;
	mso-fareast-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:&#034;Times New Roman&#034;;
	mso-bidi-theme-font:minor-bidi;}
@page Section1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;
	mso-header-margin:.5in;
	mso-footer-margin:.5in;
	mso-paper-source:0;}
div.Section1
	{page:Section1;}
--&gt;
&lt;/style&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
/* Style Definitions */
table.MsoNormalTable
{mso-style-name:&#034;Table Normal&#034;;
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-priority:99;
mso-style-qformat:yes;
mso-style-parent:&#034;&#034;;
mso-padding-alt:0in 5.4pt 0in 5.4pt;
mso-para-margin:0in;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:10.0pt;
font-family:&#034;Times New Roman&#034;,&#034;serif&#034;;
mso-fareast-font-family:&#034;Times New Roman&#034;;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;a href=&#034;http://www.hacking-lab.com/misc/downloads/xss_sharepoint.pdf&#034;&gt;http://www.hacking-lab.com/misc/downloads/xss_sharepoint.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gr&amp;uuml;sse aus Bern&lt;br /&gt;
Ivan
        </description>
      
      
    
    
    
    <category>Web Application Security</category>
    
    <comments>http://www.csnc.ch/blog/2010/02/23/1266939720000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2010/02/23/1266939720000.html</guid>
    <pubDate>Tue, 23 Feb 2010 15:42:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Second Order Injection - Terminal Breakout</title>
    <link>http://www.csnc.ch/blog/2010/01/12/1263281280000.html</link>
    
      
        <description>
          &lt;br /&gt;
What is Second Order Injection? In some cases the attackers are able to store their malicious code into a storage area of a web application that may be executed at later time or date. Some smart &amp;quot;hackers&amp;quot; change the Browsers &amp;quot;User Agent&amp;quot; into a Cross Site Scripting pattern and when the log is analyzed at later time, a successful cross site scripting exploitation could be executed. &lt;br /&gt;
&lt;br /&gt;
This is all known - but one could &lt;strong&gt;insert special characters&lt;/strong&gt; that have a special meaning in your shell (bash/csh/ksh/..) to exploit a &amp;quot;grep&amp;quot; or &amp;quot;tail&amp;quot; command once the log is analyzed manually with a terminal. &lt;br /&gt;
&lt;br /&gt;
The authors name it as &amp;quot;&lt;em&gt;&lt;strong&gt;log escape sequence injection&lt;/strong&gt;&lt;/em&gt;&amp;quot;. A large list of web application servers are vulnerable! (not Apache)&lt;br /&gt;
&lt;br /&gt;
Please review the &lt;a href=&#034;http://www.csnc.ch/blog/files/Second_Order_Terminal_Breakout.pdf&#034;&gt;alert message &lt;/a&gt;from the authors. &lt;br /&gt;
&lt;br /&gt;
Have a safe day&lt;br /&gt;
&lt;br /&gt;
Ivan
        </description>
      
      
    
    
    
    <category>Web Application Security</category>
    
    <comments>http://www.csnc.ch/blog/2010/01/12/1263281280000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2010/01/12/1263281280000.html</guid>
    <pubDate>Tue, 12 Jan 2010 07:28:00 GMT</pubDate>
  </item>
  
  <item>
    <title>XSS vulnerabilities in 34 millions flash files</title>
    <link>http://www.csnc.ch/blog/2010/01/11/1263190980000.html</link>
    
      
        <description>
          &lt;br /&gt;
Shortly, Compass Security found out some cross site scripting vulnerabilities in Camtasia generated flash applications. This vulnerability is the basis of a new Hacking Lab Challenge, especially for the audience of the next &lt;a href=&#034;http://www.hacking-lab.com/events/scsIII/en/&#034;&gt;Swiss Cyber Storm III Challenge&lt;/a&gt;. &lt;br /&gt;
&lt;br /&gt;
Nevertheless, this morning I was made aware of another &lt;a href=&#034;http://www.csnc.ch/blog/files/tagcloud.swf.pdf&#034;&gt;Flash vulnerability in tagcloud.swf&lt;/a&gt;, potentially available in more than 34 million flash files world wide. In the last couple of weeks Compass is being asked about the security implications of adding a flash application to the secure web container like e-banking, online trading or the secure portal area. Compass highly recommends analyzing your flash files for cross site and similar, especially when they are generated out of tool than written manually by your professionals. &lt;br /&gt;
&lt;br /&gt;
Have a safe day&lt;br /&gt;
Ivan&lt;br /&gt;
        </description>
      
      
    
    
    
    <category>Web Application Security</category>
    
    <comments>http://www.csnc.ch/blog/2010/01/11/1263190980000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2010/01/11/1263190980000.html</guid>
    <pubDate>Mon, 11 Jan 2010 06:23:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Tomcat Server Banner Hiding Technique</title>
    <link>http://www.csnc.ch/blog/2009/12/02/1259788680000.html</link>
    
      
        <description>
          &lt;br /&gt;
I am not a big fan of security by obscurity. But if this helps to stop automated scanners from attacking our servers day and night, I am more than willing to change the server banner of my web server. This is an easy task for Apache web servers, but how to change the banner in your Tomcat application server? &lt;br /&gt;
&lt;br /&gt;
Use the &amp;quot;&lt;strong&gt;server&lt;/strong&gt;&amp;quot; directive in your web.xml!&lt;br /&gt;
&lt;pre&gt;&amp;lt;!-- Entry for intranet.csnc.ch --&amp;gt;&lt;br /&gt;  &amp;lt;Connector port=&amp;quot;8081&amp;quot; maxHttpHeaderSize=&amp;quot;8192&amp;quot;&lt;br /&gt;     maxThreads=&amp;quot;150&amp;quot; server=&amp;quot;Compass-Coyote&amp;quot; &lt;br /&gt;	 minSpareThreads=&amp;quot;25&amp;quot; maxSpareThreads=&amp;quot;75&amp;quot;&lt;br /&gt;     enableLookups=&amp;quot;false&amp;quot; redirectPort=&amp;quot;8443&amp;quot; &lt;br /&gt;	 acceptCount=&amp;quot;100&amp;quot;&lt;br /&gt;     proxyName=&amp;quot;www.mypage.com&amp;quot; proxyPort=&amp;quot;80&amp;quot;&lt;br /&gt;     connectionTimeout=&amp;quot;20000&amp;quot; disableUploadTimeout=&amp;quot;true&amp;quot; /&amp;gt;&lt;br /&gt;&lt;/pre&gt;
&lt;br /&gt;
Thanks to Daniel Stirnimann for sharing this tipp.&lt;br /&gt;
E1
        </description>
      
      
    
    
    
    <category>Web Application Security</category>
    
    <comments>http://www.csnc.ch/blog/2009/12/02/1259788680000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2009/12/02/1259788680000.html</guid>
    <pubDate>Wed, 02 Dec 2009 21:18:00 GMT</pubDate>
  </item>
  
  <item>
    <title>STRATO Provider Deutschland überfordert</title>
    <link>http://www.csnc.ch/blog/2009/11/06/1257495480000.html</link>
    
      
        <description>
          &lt;br /&gt;
&lt;u&gt;&lt;strong&gt;Java Script Malware&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;
In der Zeit vom 20-26. Oktober 2009 wurde die Webseite einer Schweizer Firma gehackt und jeweils folgende &lt;em&gt;&lt;strong&gt;&amp;lt;SCRIPT SRC=...&amp;gt;&lt;/strong&gt;&lt;/em&gt; Anweisung in die Webseite hinterlegt: &lt;em&gt;&lt;strong&gt;http://dobrodeya.com/cgi-bin/Archiv.php&lt;/strong&gt;&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;u&gt;&lt;strong&gt;Same Origin Bypass&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;
Die Anweisung &lt;em&gt;&lt;strong&gt;&amp;lt;SCRIPT SRC=...&amp;gt;&lt;/strong&gt;&lt;/em&gt; bedeutet, dass die JavaScripts von obiger URL im gleichen Context wie die Webseite der Schweizer Firma ausgef&amp;uuml;hrt wird und ist der Bypass f&amp;uuml;r die Same Origin Policy. Der Host &amp;quot;dobrodeya.com&amp;quot; wird vom deutschen Provider &lt;strong&gt;STRATO &lt;/strong&gt;gehostet. Die Malware hat Sicherheitsl&amp;uuml;cken in den&lt;br /&gt;
Browsern ausgen&amp;uuml;tzt und Trojaner im Browser installiert. Eine ziemlich gef&amp;auml;hrliche Sache also....wie hat die Zusammenarbeit mit STRATO funktioniert? Was macht die Malware? Lesen Sie weiter als PDF unter &lt;a href=&#034;http://www.hacking-lab.com/download/&#034;&gt;http://www.hacking-lab.com/download/&lt;br /&gt;
&lt;/a&gt;&lt;br /&gt;
Gr&amp;uuml;sse &lt;br /&gt;
E1&lt;br /&gt;
        </description>
      
      
    
    
    
    <category>Advisory</category>
    
    <category>Exploits</category>
    
    <category>Web Application Security</category>
    
    <category>compass</category>
    
    <comments>http://www.csnc.ch/blog/2009/11/06/1257495480000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2009/11/06/1257495480000.html</guid>
    <pubDate>Fri, 06 Nov 2009 08:18:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Bypassing Same Origin Policy mit XDR</title>
    <link>http://www.csnc.ch/blog/2009/11/03/1257261720000.html</link>
    
      
        <description>
          &lt;br /&gt;
Die Same Origin Policy (SOP) die sicherstellt, dass ein Java Script keine Cross Talks zu anderen Domains macht ist eines der Eckpfeiler f&amp;uuml;r Web App Security. Doch die SOP ist auch ein Problem f&amp;uuml;r Mash-Ups und Portalseiten, die von &amp;uuml;berall her guten Content zu einer neuen Seite aggregieren m&amp;ouml;chten. &lt;br /&gt;
&lt;u&gt;&lt;strong&gt;&lt;br /&gt;
&lt;font face=&#034;Courier New&#034;&gt;var xdr = new XDomainRequest();&lt;/font&gt;&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;
Microsoft hat ein Konzept namens XDomainRequest (XDR), wodurch die Same Origin Policy aufgeweicht wird, &amp;auml;hnlich wie man das bei der crossdomain.xml von Flash her kennt. Das neue Konzept heisst XDR und steht f&amp;uuml;r Cross Domain Requests. Die Idee ist dabei, dass der Server &amp;uuml;ber einen speziellen HTTP Response Header dem Browser mitteilt, dass ein Cross Domain Talk m&amp;ouml;glich ist. &lt;br /&gt;
&lt;a href=&#034;http://msdn.microsoft.com/en-us/library/dd573303(VS.85).aspx&#034;&gt;&lt;br /&gt;
http://msdn.microsoft.com/en-us/library/dd573303(VS.85).aspx&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Der Internet Explorer 8 unterst&amp;uuml;tzt XDR bereits. Die anderen Browser werden nachziehen m&amp;uuml;ssen, weil&amp;nbsp; sonst coole Seiten &amp;quot;nur&amp;quot; noch mit dem IE anschaubar sind. &lt;br /&gt;
&lt;u&gt;&lt;strong&gt;&lt;br /&gt;
SANS schreibt &amp;uuml;ber XDR:&lt;/strong&gt;&lt;/u&gt;&lt;br /&gt;
&lt;em&gt;Initially proposed by Microsoft, and so far only implemented in Internet Explorer 8, XDomainRequest (XDR) is removing the same-origin policy from XHR. In return, to improve security, XDR is more limited in what headers it can set, and how the origin information is applied to access control. Currently, there is no open standard defining XDR.&lt;/em&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Speziell mit AJAX entsteht das Bed&amp;uuml;rfnis nach Cross Talks. Siehe auch folgende AJAX Library &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#034;http://www.ajax-cross-domain.com/&#034;&gt;http://www.ajax-cross-domain.com/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Wie man sieht, werden die Header von HTTP laufend erweitert, um die neuen Anforderungen an Mash-Up, Streaming etc. gerecht zu werden. Sozusagen ein Standard in Entwicklung. &lt;br /&gt;
&lt;br /&gt;
Have a save day&lt;br /&gt;
&lt;br /&gt;
e1&lt;br /&gt;
&lt;br /&gt;
        </description>
      
      
    
    
    
    <category>Web Application Security</category>
    
    <category>compass</category>
    
    <comments>http://www.csnc.ch/blog/2009/11/03/1257261720000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2009/11/03/1257261720000.html</guid>
    <pubDate>Tue, 03 Nov 2009 15:22:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Sichere Browser - Anti XSS Blueprint</title>
    <link>http://www.csnc.ch/blog/2009/05/20/1242811200000.html</link>
    
      
        <description>
          &lt;br /&gt;
Wie soll man sich effizient gegen XSS (Cross Site Scripting) sch&amp;uuml;tzen? Was muss man als Entwickler von Browsern oder Web Anwendungen beachten? Falls Sie das interessiert, sollten Sie den Blueprint durchgehen, der diese Woche ver&amp;ouml;ffentlicht wurde. &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#034;http://alcazar.sisl.rites.uic.edu/wiki/pub/Main/LibraryPublicationOakland09Blueprint/blueprint-oakland-final.pdf&#034;&gt;http://alcazar.sisl.rites.uic.edu/wiki/pub/Main/LibraryPublicationOakland09Blueprint/blueprint-oakland-final.pdf&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gruss &lt;br /&gt;
E1&lt;br /&gt;
        </description>
      
      
    
    
    
    <category>Web Application Security</category>
    
    <comments>http://www.csnc.ch/blog/2009/05/20/1242811200000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2009/05/20/1242811200000.html</guid>
    <pubDate>Wed, 20 May 2009 09:20:00 GMT</pubDate>
  </item>
  
  <item>
    <title>Microsoft IIS Unicode Sicherheitslücke in WebDAV</title>
    <link>http://www.csnc.ch/blog/2009/05/19/1242716820000.html</link>
    
      
        <description>
          &lt;br /&gt;
Vor ein paar Jahren wurde bereits eine Unicode Sicherheitsl&amp;uuml;cke beim IIS bekannt, mit welcher man auf das System zugreifen konnte. Viele Hacker Script Kiddies Tools haben danach gesucht und ausgen&amp;uuml;tzt. Heute ist grunds&amp;auml;tzlich das gleiche Problem im IIS Web DAV Handler publiziert worden. Ein Zusatz zum IIS der das gleiche Sicherheitsproblem hat wodurch man via Web DAV auf passwort gesch&amp;uuml;tzte Inhalte ohne Angabe von Passw&amp;ouml;rtern zugreifen kann (Bypass Authentication). &lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#034;http://www.microsoft.com/technet/security/advisory/971492.mspx&#034;&gt;Info bei Microsoft&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&#034;http://www.securityfocus.com/bid/34993/exploit&#034;&gt;Info bei Security Focus (Exploit)&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
Gruss Ivan&lt;br /&gt;
        </description>
      
      
    
    
    
    <category>Windows Security</category>
    
    <category>Malware via Web</category>
    
    <category>Web Application Security</category>
    
    <comments>http://www.csnc.ch/blog/2009/05/19/1242716820000.html#comments</comments>
    <guid isPermaLink="true">http://www.csnc.ch/blog/2009/05/19/1242716820000.html</guid>
    <pubDate>Tue, 19 May 2009 07:07:00 GMT</pubDate>
  </item>
  
  </channel>
</rss>
