<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>Michael Sutton's Blog</title><link>http://www.communities.hp.com/securitysoftware/blogs/msutton/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/MichaelSuttonsBlog" type="application/rss+xml" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item><title>Michael Sutton's Blog Status Change</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/tiKAxcJhqNA/michael-sutton-s-blog-status-change.aspx</link><pubDate>Wed, 22 Apr 2009 20:36:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89090</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=89090</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2009/04/22/michael-sutton-s-blog-status-change.aspx#comments</comments><description>&lt;p&gt;Michael Sutton&amp;#39;s Blog will no longer be an active HP Application Security Center blog. Michael is no longer with HP, and won&amp;#39;t be actively maintaining this blog. While no future comments will be accepted, all posts will still be archived and available for viewing. For other perspectives on web application security, see both the &lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/default.aspx"&gt;HP Security Laboratory Team Blog&lt;/a&gt; and &lt;a href="http://www.communities.hp.com/securitysoftware/blogs/rafal/default.aspx"&gt;Following the White Rabbit&lt;/a&gt;, the blog of Rafal Los.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89090" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ZbWoi4G4a4bP7azXgJwfE-V4k8I/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZbWoi4G4a4bP7azXgJwfE-V4k8I/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ZbWoi4G4a4bP7azXgJwfE-V4k8I/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ZbWoi4G4a4bP7azXgJwfE-V4k8I/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/MichaelSuttonsBlog?a=tiKAxcJhqNA:x2Tg8GrkeOs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MichaelSuttonsBlog?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/MichaelSuttonsBlog?a=tiKAxcJhqNA:x2Tg8GrkeOs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/MichaelSuttonsBlog?i=tiKAxcJhqNA:x2Tg8GrkeOs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/tiKAxcJhqNA" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2009/04/22/michael-sutton-s-blog-status-change.aspx</feedburner:origLink></item><item><title>PCI Requirement 6.6 - The Clock is Ticking</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/AT5AqxlDrQ4/PCI-Requirement-6.6-_2D00_-The-Clock-is-Ticking.aspx</link><pubDate>Thu, 31 Jan 2008 10:24:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:73795</guid><dc:creator>erik.peterson</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=73795</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2008/01/31/PCI-Requirement-6.6-_2D00_-The-Clock-is-Ticking.aspx#comments</comments><description>Welcome to 2008. By now you have no doubt made and broken a
number of New Year&amp;#39;s resolutions. Not to worry if you&amp;#39;ve already wasted $50
bucks on a gym membership, there&amp;#39;s always next year. I do however hope that taking
PCI seriously was on the list and that it remains a top priority. Why this
year? What&amp;#39;s different about PCI in 2008?

&lt;p&gt;On June 30, 2008, section 6.6 goes from being a best
practice to a mandatory requirement. This section has often been debated as it
isn&amp;#39;t as clear as it could be. Therefore, it has yet to be implemented by many
corporations. Unfortunately, procrastination time is over as you now have 5
months to interpret and take section 6.6 seriously. Let&amp;#39;s start by taking a
look at it:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;Ensure that web-facing applications are protected against known attacks
by applying either of the following methods:&lt;/em&gt;&lt;/p&gt;&lt;ul class="unIndentedList"&gt;&lt;li&gt;
&lt;em&gt;Having all
custom application code reviewed for common vulnerabilities by an organization
that specializes in application security&lt;/em&gt;&lt;/li&gt;&lt;li&gt;
&lt;em&gt;Installing
an application layer firewall in front of web facing applications&lt;/em&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;





&lt;p&gt;Now I&amp;#39;m not a big fan of this section for two reasons. First
I don&amp;#39;t feel that it goes far enough. I believe in defense in depth and these choices
are not mutually exclusive. An application review and an application firewall
are two separate and complementary controls. Both should be implemented. They
should not be presented as a la carte replacements for one another. &amp;nbsp;However, sometimes you can&amp;#39;t change the rules
and you&amp;#39;ve still gotta play the game. So let&amp;#39;s dig deeper.&lt;/p&gt;

&lt;p&gt;My second concern with section 6.6 relates to the wording
used in the first option. It leaves a lot of grey area. First off, what is &amp;lsquo;custom
application code&amp;#39;? If I take a packaged web application and add a custom style
sheet, do I need a code review? In my opinion, canned web applications present
significant risk themselves and should be treated no differently.&lt;/p&gt;

&lt;p&gt;Beyond this, what constitutes a &amp;lsquo;review&amp;#39; of custom application
code? As I&amp;#39;ve &lt;a href="http://portal.spidynamics.com/blogs/msutton/archive/2006/11/30/The-Best-Way-to-Find-Vulnerabilities.aspx" target="_blank"&gt;argued
in the past&lt;/a&gt;, white box testing (aka static code review) is not a
replacement for black box testing, or vice versa. They are separate and
distinct methodologies with their own strengths and weaknesses. As with other
controls, they should be used to complement one another, not compete for solo
status. Why would the PCI Standards Council advocate one approach over the
other? Fortunately, Dennis Hurst cleared up the confusion when he &lt;a href="http://portal.spidynamics.com/blogs/dennis/archive/2007/03/16/PCI-v1.1-Section-6.6-_2800_a-bit-of-clarification-please_2900_.aspx" target="_blank"&gt;posted
a response&lt;/a&gt; from the PCI council on his blog which addressed this very
question. When asked if section 6.6 specifically require static code analysis,
the council responded as follows:&lt;/p&gt;

&lt;blockquote&gt;&lt;p&gt;&lt;em&gt;Using
specialized 3rd-party tools that perform thorough analysis of applications to
detect vulnerabilities and defects may well meet the intention and objectives
of the source code review requirement in PCI Data Security Standard requirement
6.6, if the company using the 3rd-party tool also has the internal expertise to
understand the findings and make appropriate changes.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;The
PCI Security Standards Council will look to clarify this section of the
standard during the next revision, to include that testing of web-facing
applications can be done via source code review or products that test the
application thoroughly for defects and vulnerabilities (when internal staff
have the skills to use the tool and fix defects). The PCI Security Standards
Council will also consider including prescriptive requirements as to what both
the application firewall and application analysis tool or process should test
for.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;Thank
you and regards,&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;The
PCI Security Standards Council Response Team&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;







&lt;p&gt;There you have it, black box testing is acceptable.
Unfortunately, at present this causes even more confusion as we&amp;#39;re now left
with three choices for satisfying section 6.6 - static code analysis,
vulnerability scanning or an application firewall. Hopefully, the council will
clarify t in the next iteration of the PCI DSS but in the meantime, if you are
not adhering to section 6.6, you need to ASAP. Given the choices that you have for
compliance this means either hiring a third party to conduct static code
analysis/scanning or procuring and implementing an application firewall. The
good news is that you have choices. The bad news is that you have five months
to get it done.&lt;/p&gt;

&lt;p&gt;- michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=73795" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/C_901o3TYb_Id_NYqQJ3wRWGnco/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/C_901o3TYb_Id_NYqQJ3wRWGnco/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/C_901o3TYb_Id_NYqQJ3wRWGnco/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/C_901o3TYb_Id_NYqQJ3wRWGnco/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=sBnZr5D9"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=QLggkvHP"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=QLggkvHP" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/AT5AqxlDrQ4" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2008/01/31/PCI-Requirement-6.6-_2D00_-The-Clock-is-Ticking.aspx</feedburner:origLink></item><item><title> Microsoft Black Tuesday - June 2007</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/uRlcKci2s2k/-Microsoft-Black-Tuesday-_2D00_-June-2007.aspx</link><pubDate>Wed, 13 Jun 2007 01:09:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:30421</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=30421</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/06/13/-Microsoft-Black-Tuesday-_2D00_-June-2007.aspx#comments</comments><description>The June edition of Microsoft Black Tuesday
marked two important events - an all out assault on client side vulnerabilities
and the end of the security honeymoon for Windows Vista. I&amp;#39;ve been saying for some
time now that we&amp;#39;re in the midst of a revolution as attackers shift their focus
from gaping server side vulnerabilities, which are becoming increasingly rare,
to stealthy client side holes that make phishers salivate. This month&amp;#39;s patches
illustrated that we need to focus our efforts on better securing client side
applications as there are a plethora of holes ripe for exploitation. Vista also
received a dose of reality as the latest and greatest operating system appeared
in 8 of the published vulnerabilities, with 3 of them being critical. Also of
interest is MS07-035, a remote code execution vulnerability in the Windows API
which can apparently be exploited via Internet Explorer. This is certainly one
to keep an eye on as it will be interesting to see if public exploit code
emerges in the coming days.

&lt;p&gt;This month Microsoft patched 15
vulnerabilities that were packaged into 6 security bulletins, 13 of which were
critical. The patch release was average by recent standards. The 15 vulnerabilities
had the following overall severity rankings.&lt;/p&gt;

&lt;ul&gt;&lt;li&gt;8
     Critical&lt;/li&gt;&lt;li&gt;4
     Important&lt;/li&gt;&lt;li&gt;3
     Moderate&lt;/li&gt;&lt;/ul&gt;

&lt;p&gt;This month&amp;#39;s bulletins included patches for 3
public vulnerabilities, none of which were already being actively exploited. The
following publicly known issues received patches:&lt;/p&gt;

&lt;ul&gt;&lt;li&gt;MS07-033
     (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1499"&gt;CVE-2007-1499&lt;/a&gt;)
     Navigation Cancel Page Spoofing Vulnerability&lt;/li&gt;&lt;li&gt;MS07-034
     (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2111"&gt;CVE-2006-2111&lt;/a&gt;)
     URL Redirect Cross Domain Information Disclosure Vulnerability&lt;/li&gt;&lt;li&gt;MS07-034
     (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1658"&gt;CVE-2007-1658&lt;/a&gt;)
     Windows Mail UNC Navigation Request Remote Code Execution Vulnerability&lt;/li&gt;&lt;/ul&gt;

&lt;p&gt;Below is a cheat sheet for all 15
vulnerabilities.&lt;/p&gt;

&lt;p&gt;Enjoy!&lt;/p&gt;

&lt;p&gt;- michael&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;table cellpadding="0" cellspacing="0"&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Bulletin&amp;nbsp;&amp;nbsp; &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Title&lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-030&amp;nbsp;&amp;nbsp; &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Visio Version
  Memory Corruption Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0934"&gt;CVE-2007-0934&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Important &lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-030&amp;nbsp;&amp;nbsp; &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Visio Document
  Packaging Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0936"&gt;CVE-2007-0936&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Important &lt;br /&gt;
  Discovered By: Chris Ries of &lt;a href="http://www.vigilantminds.com/"&gt;Vigilant
  Minds&lt;/a&gt;&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-031&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Vulnerability in
  the Windows Schannel Security Package&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2218"&gt;CVE-2007-2218&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Critical &lt;br /&gt;
  Discovered By: Thomas Lim of COSEINC&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-032&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Permissive User
  Information Store ACLs Information Disclosure Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2229"&gt;CVE-2007-2229&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Moderate&lt;br /&gt;
  Discovered By: Robbie Sohlman&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-033&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;COM Object
  Instantiation Memory Corruption Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0218"&gt;CVE-2007-0218&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Critical &lt;br /&gt;
  Discovered By:&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; An anonymous researcher working with &lt;a href="http://idefense.com/"&gt;iDefense VCP&lt;/a&gt;&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; Tom Cross of &lt;a href="http://www.iss.net/"&gt;ISS&lt;/a&gt;&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;br /&gt;
  Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=542"&gt;iDefense&lt;/a&gt;&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-033&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;CSS Tag Memory
  Corruption Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1750"&gt;CVE-2007-1750&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Critical&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-033&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Language Pack
  Installation Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3027"&gt;CVE-2007-3027&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Critical&lt;br /&gt;
  Discovered By: An anonymous researcher working with &lt;a href="http://www.tippingpoint.com/"&gt;TippingPoint&lt;/a&gt;&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;br /&gt;
  Advisory: &lt;a href="http://www.zerodayinitiative.com/advisories/ZDI-07-037.html"&gt;ZDI-07-037&lt;/a&gt;&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-033&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Uninitialized
  Memory Corruption Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1751"&gt;CVE-2007-1751&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Critical&lt;br /&gt;
  Discovered By: Sam Thomas working with &lt;a href="http://www.tippingpoint.com/"&gt;TippingPoint&lt;/a&gt;&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;br /&gt;
  Advisory: &lt;a href="http://www.zerodayinitiative.com/advisories/ZDI-07-037.html"&gt;ZDI-07-038&lt;/a&gt;&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-033&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Navigation Cancel
  Page Spoofing Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1499"&gt;CVE-2007-1499&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Moderate&lt;br /&gt;
  Public: Yes&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-033&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Speech Control
  Memory Corruption Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2222"&gt;CVE-2007-2222&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Critical&lt;br /&gt;
  Discovered By:&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; Will Dorman of &lt;a href="http://www.cert.org/certcc.html"&gt;CERT/CC&lt;/a&gt;&lt;/p&gt;
  &lt;p&gt;&amp;nbsp;&amp;nbsp; cocoruder of &lt;a href="http://www.fortinet.com/"&gt;Fortinet Security Research&lt;/a&gt;&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-034&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;URL Redirect Cross
  Domain Information Disclosure Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-2111"&gt;CVE-2006-2111&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Important &lt;br /&gt;
  Public: Yes&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-034&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Windows Mail UNC
  Navigation Request Remote Code Execution Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1658"&gt;CVE-2007-1658&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Critical &lt;br /&gt;
  Public: Yes&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-034&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;URL Parsing Cross
  Domain Information Disclosure Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2225"&gt;CVE-2007-2225&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Important &lt;br /&gt;
  Discovered By: &lt;a href="http://isc.sans.org/"&gt;SANS ISC&lt;/a&gt;&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-034&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Content Disposition
  Parsing Cross Domain Information Disclosure Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2227"&gt;CVE-2007-2227&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Moderate&lt;br /&gt;
  Discovered By: Yosuke Hasegawa of &lt;a href="https://www.webappsec.jp/"&gt;WebAppSec.JP&lt;/a&gt;&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;MS07-035&lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;br /&gt;
  &lt;/strong&gt;&lt;/p&gt;
  &lt;/td&gt;
  &lt;td&gt;
  &lt;p&gt;&lt;strong&gt;Win32 API
  Vulnerability&lt;br /&gt;
  &lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2219"&gt;CVE-2007-2219&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;
  &lt;/strong&gt;Critical &lt;br /&gt;
  Discovered By: Billy Rios from &lt;a href="http://www.verisign.com/"&gt;VeriSign&lt;/a&gt;&lt;br /&gt;
  Public: No&lt;br /&gt;
  Exploited: No&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
&lt;/table&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=30421" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/uboWIJOCEOX9f4bxMXpz7XgH7hA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uboWIJOCEOX9f4bxMXpz7XgH7hA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/uboWIJOCEOX9f4bxMXpz7XgH7hA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/uboWIJOCEOX9f4bxMXpz7XgH7hA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=Bg3Wjeul"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=RMUtpUvq"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=RMUtpUvq" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/uRlcKci2s2k" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/06/13/-Microsoft-Black-Tuesday-_2D00_-June-2007.aspx</feedburner:origLink></item><item><title>Identifying Web Application Technologies</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/7KJp_ftK-po/Identifying-Web-Application-Technologies.aspx</link><pubDate>Fri, 08 Jun 2007 18:13:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:30361</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=30361</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/06/08/Identifying-Web-Application-Technologies.aspx#comments</comments><description>Jeff Forristal has an &lt;a href="http://portal.spidynamics.com/blogs/jeff/archive/2007/06/07/Identify-these-HTTP-servers_2F00_devices_2C00_-receive-something-cool_2100_.aspx" target="_blank"&gt;interesting initiative&lt;/a&gt; and for those able to help out, there are cash and prizes to be had! Well ok, no cash, but you could walk away with some stylish SPI clothing or a few drinks on us. Jeff is looking for assistance in identifying the devices (web servers and proxies) that are responsible for some odd but consistent response headers. To see if you can help out, take a look at the &lt;a href="http://portal.spidynamics.com/blogs/jeff/archive/2007/06/07/Identify-these-HTTP-servers_2F00_devices_2C00_-receive-something-cool_2100_.aspx" target="_blank"&gt;three response challenges&lt;/a&gt; that he&amp;#39;s identified. &lt;p&gt;&amp;nbsp;When auditing web applications, in order to efficiently test the application it is necessary to quickly determine the underlying technology that is being tested. Sure you could throw every single known attack at a web app but that would be extremely inefficient. There&amp;#39;s no reason to send a known ColdFusion information leakage issue at an Java app., nor would you include stacked SQL queries when attacking a PHP/MySQL app. When auditing complex applications, efficiency is important in order to ensure that the audit can be completed during the timeframe provided and to ensure that it can be done regularly.&lt;/p&gt;&lt;p&gt;Assuming that a true black box test is being performed, knowledge of the underlying web application technologies will not be available. It is therefore necessary to monitor the behavior of the application in order to identify clues that will aid in identifying the technologies that have been used. Below is a list of typical clues to look for.&lt;/p&gt;&lt;h1&gt;Server Response Header&lt;/h1&gt;&lt;p&gt;The Server response header can be a goldmine of information as it &amp;quot;identif[ies] the server and any significant subproducts&amp;quot;. RFC 2616 (Hypertext Transfer Protocol - HTTP/1.1) actually warns of the dangers of providing an overly verbose server header by stating that &amp;quot;revealing the specific software version of the server might allow the server machine to become more vulnerable to attacks against software that is known to contain security holes&amp;quot;. Don&amp;#39;t however be fooled as this header can easily be omitted, spoofed or altered by an intermediate device such as a proxy, even though RFC 2616 prohibits such behavior.&lt;/p&gt;&lt;h1&gt;Response Header Format/Order&lt;/h1&gt;&lt;p&gt;Different web servers provide response headers that adhere to protocol specifications but are still unique. Depending upon the structure of the request received, servers may respond with headers listed in a different order or perhaps with additional/omitted headers. Entire &lt;a href="http://net-square.com/httprint/httprint_paper.html" target="_blank"&gt;whitepapers&lt;/a&gt; have been written on this topic and this behavior has led to the creation of various web server fingerprinting technologies such as &lt;a href="http://net-square.com/httprint/httprint_paper.html" target="_blank"&gt;HTTPrint&lt;/a&gt; or &lt;a href="http://ujeni.murkyroc.com/hmap/" target="_blank"&gt;HMAP&lt;/a&gt;.&lt;/p&gt;&lt;h1&gt;Verbose Error Messages&lt;/h1&gt;&lt;p&gt;When verbose error messages are not suppressed they can reveal not only the web/application servers being used but also complimentary technologies such as the database server that has been employed or the programming language used. For example, take a look at the following Google queries which identify revealing verbose error messages:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.google.com/search?sourceid=navclient&amp;amp;ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;q=%22Error+Diagnostic+Information%22+intitle%3A%22Error+Occurred+While%22+" target="_blank"&gt;ColdFusion&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.google.com/search?ie=UTF-8&amp;amp;oe=UTF-8&amp;amp;q=intitle%3A%22the+page+cannot+be+found%22+inetmgr" target="_blank"&gt;Microsoft IIS 4.0&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.google.com/search?q=intitle%3A%22Apache+Tomcat%22+%22Error+Report%22" target="_blank"&gt;Apache Tomcat&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;h1&gt;Known Pages/Directories/Functionality&lt;/h1&gt;&lt;p&gt;By default, most servers/applications arrive out of the box with a number of sample apps, help files and common directory structures. Identifying such items on a site can once again reveal important details about the technologies used. Once again consider the following Google queries:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;safe=off&amp;amp;client=firefox-a&amp;amp;rls=org.mozilla%3Aen-US%3Aofficial&amp;amp;hs=yb6&amp;amp;q=intitle%3A%22login%22+inurl%3A%22isqlplus%22&amp;amp;btnG=Search" target="_blank"&gt;Oracle&lt;/a&gt; - iSQL*Plus is a web based SQL query tool that is included by default in Oracle HTTP Server, which is part of Oracle Application Server and Oracle Database Server&lt;/li&gt;&lt;/ul&gt;&lt;h1&gt;Page Extensions&lt;/h1&gt;&lt;p&gt;This one is a bit of a no brainer but even this can be misleading at times as extensions can be changed, not displayed or be generic extensions used by multiple technologies (e.g. .htl or .html). Below is a sample of common page extensions and their underlying technologies:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;ColdFusion&lt;/li&gt;&lt;ul&gt;&lt;li&gt;.cfm - ColdFusion Markup File&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Microsoft&lt;/li&gt;&lt;ul&gt;&lt;li&gt;.asa - ASP Configuration File&lt;/li&gt;&lt;li&gt;.ascx - Active Server Custom Control&lt;/li&gt;&lt;li&gt;.asmx - Active Server Method File&lt;/li&gt;&lt;li&gt;.asp - Active Server Page&lt;/li&gt;&lt;li&gt;.aspx - Active Server Page Extended&lt;/li&gt;&lt;li&gt;.chm - Compiled HTML Help File&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Java&lt;/li&gt;&lt;ul&gt;&lt;li&gt;.jhtml - Java within Hypertext Markup Language&lt;/li&gt;&lt;li&gt;.jnlp - Java Web Start File&lt;/li&gt;&lt;li&gt;.jsp - Java Server Page&lt;/li&gt;&lt;li&gt;.jspx - XML Java Server Page&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;PHP&lt;/li&gt;&lt;ul&gt;&lt;li&gt;.php - Hypertext Preprocessor File&lt;/li&gt;&lt;li&gt;.php3 - PHP 3 Script&lt;/li&gt;&lt;li&gt;.php4 - PHP 4 Script&lt;/li&gt;&lt;li&gt;.php5 - PHP 5 Script&lt;/li&gt;&lt;li&gt;.phtm - PHP Web Page&lt;/li&gt;&lt;li&gt;.phtml - PHP Web Page&lt;/li&gt;&lt;/ul&gt;&lt;li&gt;Ruby&lt;/li&gt;&lt;ul&gt;&lt;li&gt;.rhtml - Ruby HTML Web Page&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;p&gt;What is the &amp;lsquo;correct&amp;#39; way to identify underlying web application technologies? As with just about everything in security, there is no silver bullet. A combination of all of the aforementioned approaches is your best bet but in the end everything can be obfuscated either intentionally or otherwise. Nothing short of a chat with the developers and/or system administrators will reveal the true answer but with a little detective work you should be able to quickly identify the technologies with a reasonable level of confidence.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=30361" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/tA0KnTzEOlfEOHXcUY7RfFhhyoU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tA0KnTzEOlfEOHXcUY7RfFhhyoU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/tA0KnTzEOlfEOHXcUY7RfFhhyoU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/tA0KnTzEOlfEOHXcUY7RfFhhyoU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=peKjjFuF"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=bHENmN6s"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=bHENmN6s" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/7KJp_ftK-po" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/06/08/Identifying-Web-Application-Technologies.aspx</feedburner:origLink></item><item><title>Microsoft Black Tuesday - May 2007 </title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/dXTaLZZ_Deo/Microsoft-Black-Tuesday-_2D00_-May-2007-.aspx</link><pubDate>Wed, 09 May 2007 01:05:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:29202</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=29202</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/05/09/Microsoft-Black-Tuesday-_2D00_-May-2007-.aspx#comments</comments><description>&lt;p&gt;The break that we were given in April when only 8 vulnerabilities were delivered is now a long lost memory. While May was not a record month, it was big with 18 overall vulnerabilities in seven advisories. More importantly, the vulnerabilities were strongly skewed toward critical with 14 of 18 reports receiving the top severity ranking. As always, while it&amp;#39;s refreshing to get such a large bundle out of the way, don&amp;#39;t relax just yet. Instead, take a quick look at upcoming advisories for 3Com&amp;#39;s &lt;a href="http://www.zerodayinitiative.com/upcoming_advisories.html"&gt;Zero Day Initiative&lt;/a&gt; or &lt;a href="http://research.eeye.com/html/advisories/upcoming/index.html"&gt;eEye Research&lt;/a&gt; and you&amp;#39;ll see that they still collectively have more than a dozen unpatched Microsoft vulnerabilities despite the fact that two TippingPoint issues were addressed this month.&lt;/p&gt;&lt;p&gt;The 18 total vulnerabilities had the following overall severity rankings.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;14 Critical&lt;/li&gt;&lt;li&gt;4 Important&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This month&amp;#39;s bulletins included patches for three public vulnerabilities.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;MS07-024 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-0870"&gt;CVE-2007-0870&lt;/a&gt;) Word Document Stream Vulnerability&lt;/li&gt;&lt;li&gt;MS07-027 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0942"&gt;CVE-2007-0942&lt;/a&gt;) COM Object Instantiation Memory Corruption Vulnerability&lt;/li&gt;&lt;li&gt;MS07-029 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1748"&gt;CVE-2007-1748&lt;/a&gt;) DNS RPC Management Vulnerability&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Most importantly, the zero-day &lt;a href="http://www.microsoft.com/technet/security/advisory/935964.mspx"&gt;Windows DNS RPC&lt;/a&gt; vulnerability was addressed. This was important as Microsoft had acknowledged targeted exploitation of this issue nearly a month ago.&lt;/p&gt;&lt;p&gt;Below is a cheat sheet for all 18 vulnerabilities.&lt;/p&gt;&lt;p&gt;Enjoy!&lt;/p&gt;&lt;p&gt;- michael&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Bulletin&amp;nbsp;&amp;nbsp; &lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Title&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-023&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel BIFF Record Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0215"&gt;CVE-2007-0215&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Manuel Santamarina Suarez, working with &lt;a href="http://www.tippingpoint.com/" target="_blank"&gt;TippingPoint&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://www.zerodayinitiative.com/advisories/ZDI-07-026.html"&gt;TippingPoint&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-023&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel Set Font Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1203"&gt;CVE-2007-1203&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-023&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel Filter Record Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1214"&gt;CVE-2007-1214&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Greg MacManus of &lt;a href="http://labs.idefense.com/"&gt;iDefense Labs&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=527"&gt;iDefense Labs&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-024&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word Array Overflow Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0035"&gt;CVE-2007-0035&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-024&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word Document Stream Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-0870"&gt;CVE-2007-0870&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Craig Schmugar of &lt;a href="http://www.avertlabs.com/"&gt;McAfee Avert Labs&lt;/a&gt;&lt;br /&gt;Andreas Marx of &lt;a href="http://www.av-test.org/"&gt;AV-Test&lt;/a&gt; &lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: Yes&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-024&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word RTF Parsing Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1202"&gt;CVE-2007-1202&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: &lt;a href="http://labs.idefense.com/"&gt;iDefense Labs&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=525"&gt;iDefense Labs&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-025&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Drawing Object Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1747"&gt;CVE-2007-1747&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-026&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Outlook Web Access Script Injection Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0220"&gt;CVE-2007-0220&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: Martijn Brinkers of &lt;a href="http://www.izecom.com/"&gt;Izecom&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-026&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Malformed iCal Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0039"&gt;CVE-2007-0039&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: Alexander Sotirov of &lt;a href="http://www.determina.com/security.research"&gt;Determina Security Research&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://www.determina.com/security.research/vulnerabilities/exchange-ical-modprops.html"&gt;Determina Security Research&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-026&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MIME Decoding Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0213"&gt;CVE-2007-0213&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-026&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;IMAP Literal Processing Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0221"&gt;CVE-2007-0221&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: Joxean Koret, working with the &lt;a href="http://labs.idefense.com/"&gt;iDefense&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=526"&gt;iDefense Labs&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-027&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;COM Object Instantiation Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0942"&gt;CVE-2007-0942&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: &lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-027&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Uninitialized Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0944"&gt;CVE-2007-0944&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: &lt;a href="http://www.tippingpoint.com/" target="_blank"&gt;TippingPoint&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://www.zerodayinitiative.com/advisories/ZDI-07-027.html"&gt;TippingPoint&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-027&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Property Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0945"&gt;CVE-2007-0945&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: &lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-027&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;HTML Objects Memory Corruption Vulnerabilities&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0946"&gt;CVE-2007-0946&lt;/a&gt;, &lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0947"&gt;CVE-2007-0947&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: JJ Reyes of &lt;a href="http://secunia.com/"&gt;Secunia Research&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-027&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Arbitrary File Rewrite Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-02221"&gt;CVE-2007-2221&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: cocoruder of &lt;a href="http://www.fortinet.com/"&gt;Fortinet Security Research&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-028&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;CAPICOM.Certificates Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0940"&gt;CVE-2007-0940&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Chris Ries of &lt;a href="http://www.vigilantminds.com/"&gt;VigilantMinds Inc.&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-029&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;DNS RPC Management Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1748"&gt;CVE-2007-1748&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By:&lt;br /&gt;Mark Hofman of the &lt;a href="http://isc.sans.org/"&gt;SANS ISC Handlers&lt;/a&gt;&lt;br /&gt;Bill O&amp;#39;Malley with the &lt;a href="http://www.cmu.edu/iso/"&gt;Information Security Office at Carnegie Mellon University&lt;/a&gt;&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: Yes&lt;br /&gt;Advisory: &lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=29202" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/TMkDQ4fshuWro1ji7Kko6o79q7w/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TMkDQ4fshuWro1ji7Kko6o79q7w/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/TMkDQ4fshuWro1ji7Kko6o79q7w/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/TMkDQ4fshuWro1ji7Kko6o79q7w/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=gVCVZrq8"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=6UW5fSWs"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=6UW5fSWs" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/dXTaLZZ_Deo" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/05/09/Microsoft-Black-Tuesday-_2D00_-May-2007-.aspx</feedburner:origLink></item><item><title>Educating Developers</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/HZh1AZqYeSE/Educating-Developers.aspx</link><pubDate>Wed, 11 Apr 2007 12:03:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:28459</guid><dc:creator>erik.peterson</dc:creator><slash:comments>4</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=28459</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/04/11/Educating-Developers.aspx#comments</comments><description>&lt;p&gt;I spend much of my time on the
road conducting presentations on application security for various audiences. Of
all the groups that I speak to, developers are a favorite of mine. Developers
get a bad rap when it comes to security. They are generally blamed for creating
vulnerabilities, not thanked for preventing them. While it&amp;#39;s true that a
developer somewhere is responsible for creating just about any vulnerability, I
don&amp;#39;t blame them. Developers build what we ask them to build. Plain and simple.
The problem lies in the fact that we&amp;#39;ve not historically asked for security.
What we&amp;#39;ve asked for is functionality and a project that is released on
schedule. Unfortunately, those two requirements generally work in opposition to
security.&lt;/p&gt;

&lt;p&gt;Slowly, we are coming to the
realization that when it comes to application security, the only complete
solution is to ensure that the application itself is secure. While defense in
depth solutions such as firewalls, IDS/IPS technologies, etc. can increase the enterprise&amp;#39;s
overall security posture, in the end, they are band-aid solutions designed to
protect vulnerable applications. With enough time and effort, these defenses
can be bypassed and the vulnerable technology exploited.&lt;/p&gt;

&lt;p&gt;With this realization we&amp;#39;re now finally
asking our developers to start worrying about security. That&amp;#39;s a bit of a scary
proposition for most developers who have been building applications for many
years without a need to focus on secure coding because &amp;lsquo;the security team takes
care of security&amp;#39;. We&amp;#39;re now asking developers to learn a new discipline on top
of the ever evolving world of software development. Why then do I enjoy
speaking to developers? The answer is simple - despite the challenge, they want
to learn. Developers do not for the most part despise security. On the
contrary, they want to embrace it but no one has ever shown them the way. Take
a look at any programming textbook or university course syllabus - where are
the chapters or lectures on security? There not there, but they need to be.
Developers, like anyone tasked with building something from nothing, take pride
in their work. They want their code to be secure just as much as they want their
project to have adequate functionality but they need the resources and training
to make that happen. I enjoy speaking to developers because I so often see that
&amp;lsquo;lightbulb moment&amp;#39;. For the first time they say &amp;lsquo;ah, so that&amp;#39;s what XSS/SQL
Injection/[Fill in vulnerability type here] is. I&amp;#39;d heard the term but had no
idea what it was or how to fix it&amp;#39;. As a presenter, that&amp;#39;s a very satisfying
moment.&lt;/p&gt;

&lt;p&gt;Educating developers to produce
secure code is no small task and will not happen overnight. A first step
requires providing developers and their employers with a metric to measure both
current developer knowledge and assess progress over time. &lt;a href="http://sans.org/" target="_blank"&gt;SANS&lt;/a&gt; has recently launched the &lt;a href="http://www.sans-ssi.org/" target="_blank"&gt;Secure Programming Skills Assessment&lt;/a&gt;, a
collection six examinations covering various programming languages (C, C++,
Java, .Net, PHP and Perl). The &lt;a href="http://www.sans-ssi.org/#pgoals" target="_blank"&gt;goals&lt;/a&gt;
of the project include enabling employers, consumers and the developers
themselves to be able to assess the secure coding knowledge of those involved in
a software project. While the exams are designed to benefit multiple parties, I
expect that developers will receive the greatest benefit as the exams will
allow them to identify their own deficiencies. SPI Dynamics was one of the many
&lt;a href="http://www.sans-ssi.org/#pteam" target="_blank"&gt;contributors&lt;/a&gt; to this initiative
and having looked at some of the content, I can assure you that the questions
can be quite challenging and I expect that the exams will be an eye opening
experience for those that choose to take the exams. If you&amp;#39;re interested, in
learning more take the time to listen to a recent &lt;a href="https://www.sans.org/webcasts/show.php?webcastid=91206" target="_blank"&gt;webcast&lt;/a&gt; that
was conducted to launch the initiative. I had the pleasure of sitting on a panel
with a group of industry leaders where we discussed the types of application
vulnerabilities that we&amp;#39;re seeing and what we believe needs to be done about
them going forward.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=28459" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/gZk1edvdCaWAcHJcoi7SZ_KEe7k/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gZk1edvdCaWAcHJcoi7SZ_KEe7k/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/gZk1edvdCaWAcHJcoi7SZ_KEe7k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/gZk1edvdCaWAcHJcoi7SZ_KEe7k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=Le3Mj9hs"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=ocpc8Pq3"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=ocpc8Pq3" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/HZh1AZqYeSE" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/04/11/Educating-Developers.aspx</feedburner:origLink></item><item><title>Microsoft Black Tuesday - April 2007 </title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/qkSjOrtVJ7A/Microsoft-Black-Tuesday-_2D00_-April-2007-.aspx</link><pubDate>Tue, 10 Apr 2007 16:56:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:28391</guid><dc:creator>erik.peterson</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=28391</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/04/10/Microsoft-Black-Tuesday-_2D00_-April-2007-.aspx#comments</comments><description>&lt;p&gt;The month of April started off with a bang, when Microsoft released &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS07-017.mspx" target="_blank"&gt;MS07-017&lt;/a&gt;, a rare out of cycle patch but ended with a fizzle, with 8 additional vulnerabilities. While four critical vulnerabilities were addressed, that is down significantly from the 13 critical vulnerabilities that were patched in February 2007, the last full patch cycle (March was skipped). While it may at first appear encouraging to see the number of patches diminishing, don&amp;#39;t be fooled. Take a quick look at upcoming advisories for 3Com&amp;#39;s &lt;a href="http://www.zerodayinitiative.com/upcoming_advisories.html" target="_blank"&gt;Zero Day Initiative&lt;/a&gt; or &lt;a href="http://research.eeye.com/html/advisories/upcoming/index.html" target="_blank"&gt;eEye Research&lt;/a&gt; and you&amp;#39;ll see that they collectively have more than a dozen unpatched Microsoft vulnerabilities.&lt;/p&gt;&lt;p&gt;The February patch release was relatively small when compared to recent months. We ended up with 8 vulnerabilities in 5 bulletins having the following overall severity rankings.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;4 Critical&lt;/li&gt;&lt;li&gt;3 Important&lt;/li&gt;&lt;li&gt;1 Moderate&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This month&amp;#39;s bulletins included patches for one public vulnerability, beyond MS07-017 which was patched last week. The following publicly known issue received a patch:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;MS07-021 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6696" target="_blank"&gt;CVE-2006-6696&lt;/a&gt;) MsgBox (CSRSS) Remote Code Execution Vulnerability&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Below is a cheat sheet for all 8 vulnerabilities.&lt;/p&gt;&lt;p&gt;Enjoy!&lt;/p&gt;&lt;p&gt;- michael&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Bulletin&amp;nbsp;&amp;nbsp; &lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Title&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-018&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;CMS Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0938" target="_blank"&gt;CVE-2007-0938&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-018&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;CMS Cross-Site Scripting and Spoofing Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0939" target="_blank"&gt;CVE-2007-0939&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: Martyn Tovey of &lt;a href="http://news.netcraft.com/" target="_blank"&gt;Netcraft&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-019&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;UPnP Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1204" target="_blank"&gt;CVE-2007-1204&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Greg MacManus of &lt;a href="http://labs.idefense.com/" target="_blank"&gt;iDefense Labs&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=509" target="_blank"&gt;iDefense&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-020&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Microsoft Agent URL Parsing Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1205" target="_blank"&gt;CVE-2007-1205&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: JJ Reyes and Carsten Eiram of &lt;a href="http://secunia.com/" target="_blank"&gt;Secunia&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://secunia.com/secunia_research/2006-74/advisory/" target="_blank"&gt;Secunia&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-021&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MsgBox (CSRSS) Remote Code Execution Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6696" target="_blank"&gt;CVE-2006-6696&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Tim Garnett of &lt;a href="http://www.determina.com/" target="_blank"&gt;Determina Security Research&lt;/a&gt;&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-021&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;CSRSS Local Elevation of Privilege Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1209" target="_blank"&gt;CVE-2007-1209&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: &lt;a href="http://www.eeye.com/" target="_blank"&gt;eEye&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://research.eeye.com/html/advisories/published/AD20070410b.html" target="_blank"&gt;eEye&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-021&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;CSRSS DoS Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6797" target="_blank"&gt;CVE-2006-6797&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Moderate&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-022&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Kernel Local Elevation of Privilege Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1206" target="_blank"&gt;CVE-2007-1206&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: &lt;a href="http://www.eeye.com/" target="_blank"&gt;eEye&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://research.eeye.com/html/advisories/published/AD20070410a.html" target="_blank"&gt;eEye&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=28391" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/Tnq_apflJ8KKv1jBEcm0KOXhlWQ/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Tnq_apflJ8KKv1jBEcm0KOXhlWQ/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/Tnq_apflJ8KKv1jBEcm0KOXhlWQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/Tnq_apflJ8KKv1jBEcm0KOXhlWQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=uHQ6WFBX"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=Ok2HGkLb"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=Ok2HGkLb" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/qkSjOrtVJ7A" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/04/10/Microsoft-Black-Tuesday-_2D00_-April-2007-.aspx</feedburner:origLink></item><item><title>Debug Message XSS Vulnerabilities</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/IwgZGbl-C3c/Debug-Message-XSS-Vulnerabilities.aspx</link><pubDate>Fri, 23 Mar 2007 00:35:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:27805</guid><dc:creator>erik.peterson</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=27805</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/03/23/Debug-Message-XSS-Vulnerabilities.aspx#comments</comments><description>&lt;p&gt;I was excited this afternoon when I thought that I&amp;#39;d
stumbled upon a universal XSS vulnerability in verbose ColdFusion error
messages. While testing a site, I had noted that a verbose debug error message
(see below) echoed back many of the request headers, including the Referrer and
User-Agent (aka Browser) headers.&lt;/p&gt;

&lt;hr align="center" /&gt;

&lt;h3&gt;Error Occurred While Processing Request&lt;/h3&gt;

&lt;table cellpadding="0"&gt;
 
&lt;tr&gt;
  
&lt;td&gt;
  &lt;h4&gt;Error Diagnostic Information&lt;/h4&gt;
  
&lt;p&gt;An error occurred while evaluating the expression: &lt;/p&gt;
  
&lt;pre&gt;#Form.XXX#&lt;/pre&gt;
  
&lt;p&gt;Error near line 5, column 20. &lt;/p&gt;
  
  
&lt;hr align="center" /&gt;
  
  
&lt;p&gt;Error resolving parameter &lt;strong&gt;FORM.XXX&lt;/strong&gt; &lt;/p&gt;
  
&lt;p&gt;The specified form field cannot be found. This problem is very likely due
  to the fact that you have misspelled the form field name. &lt;/p&gt;
  
&lt;p&gt;The error occurred while processing an element with a general identifier
  of (#Form.XXX#), occupying document position (5:19) to (5:33).&lt;/p&gt;
  
&lt;p&gt;Date/Time: 03/22/07 22:36:03&lt;br /&gt;
  &lt;strong&gt;Browser: Mozilla/4.0 (compatible; MSIE
  6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)&lt;/strong&gt;&lt;br /&gt;
  Remote Address: 69.255.12.149&lt;br /&gt;
  &lt;strong&gt;HTTP Referer:
  http://www.XXX.org:80/admin/&lt;/strong&gt;&lt;br /&gt;
  Query String: action=login&amp;amp;sub=validate&lt;/p&gt;
  &lt;/td&gt;
 &lt;/tr&gt;
&lt;/table&gt;
&lt;hr align="center" /&gt;

&lt;p&gt;Naturally, curiosity got the best of me and I attempted to
inject JavaScript into the headers only to find that yes indeed, the injected
JavaScript was echoed back without being sanitized, which makes for a nice XSS
vulnerability on all ColdFusion sites which don&amp;#39;t suppress such error messages.
Alas, my hopes were dashed when I realized that I&amp;#39;d been &lt;a href="http://www.securityfocus.com/archive/1/459178/100/0/threaded" target="_blank"&gt;beaten to
the punch&lt;/a&gt;. Despite the setback, I was still curious to see how many sites
would be affected by the vulnerability and was blown away when my friend &lt;a href="http://www.google.com/search?q=%22Error+Occurred+While+Processing+Request%22+referer" target="_blank"&gt;Google
suggested&lt;/a&gt; that the number may be in the six figure range.&lt;/p&gt;

&lt;p&gt;Knowing that, my curiosity was peaked again, so I started
poking around to see if I could find other third party or custom web apps which
exposed XSS vulnerabilities by echoing back raw request headers. A bit of
creative Googling suggested that many have made the same mistake:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;safe=off&amp;amp;q=%E2%80%A2%09%22Error+Occurred+While+Processing+Request%22+referrer" target="_blank"&gt;&amp;quot;Error
     Occurred While Processing Request&amp;quot; referrer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;safe=off&amp;amp;q=intitle%3A%22PHPWrap+Error%22" target="_blank"&gt;intitle:&amp;quot;PHPWrap
     Error&amp;quot;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;safe=off&amp;amp;q=intitle%3A%22CGIWrap+Error%22+%22+-%22Local+-Information+-and+-Documentation%22" target="_blank"&gt;intitle:&amp;quot;CGIWrap
     Error&amp;quot; &amp;quot; -&amp;quot;Local -Information -and -Documentation&amp;quot;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;safe=off&amp;amp;q=%22The+requested+URL%22+%22was+not+found+on+this+server%22" target="_blank"&gt;&amp;quot;The
     requested URL&amp;quot; &amp;quot;was not found on this server&amp;quot;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.google.com/search?hl=en&amp;amp;safe=off&amp;amp;q=intitle%3A%22File+Not+Found%22+intext%3A%22HTTP_USER_AGENT%22" target="_blank"&gt;intitle:&amp;quot;File
     Not Found&amp;quot; intext:&amp;quot;HTTP_USER_AGENT&amp;quot;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The moral of this story is that we must think broadly when
defining user input. Data does not need to come from a web form to be considered
user supplied input. Headers, cookies, hidden form fields, etc. all come from
the client and can therefore be manipulated by an attacker. When building web
apps, we need to define user input as ANYTHING that is sent from the client to
the server.&lt;/p&gt;

&lt;p&gt;- michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=27805" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/nPnE5Xr0Dc1ybBPdpCJED8QQsh4/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nPnE5Xr0Dc1ybBPdpCJED8QQsh4/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/nPnE5Xr0Dc1ybBPdpCJED8QQsh4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/nPnE5Xr0Dc1ybBPdpCJED8QQsh4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=eVHVpPwZ"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=1107cIQE"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=1107cIQE" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/IwgZGbl-C3c" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/XSS/default.aspx">XSS</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/ColdFusion/default.aspx">ColdFusion</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/03/23/Debug-Message-XSS-Vulnerabilities.aspx</feedburner:origLink></item><item><title>What is Web 2.0?</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/ngJTPZkZFvA/What-is-Web-2.0_3F00_.aspx</link><pubDate>Thu, 15 Feb 2007 01:02:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:2558</guid><dc:creator>erik.peterson</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=2558</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/02/15/What-is-Web-2.0_3F00_.aspx#comments</comments><description>Web 2.0 may be the most ill
defined technology term to date. Everyone uses the term but I have yet to hear
a decent definition of it. O&amp;#39;Reilly Media is credited with coining the phrase
and &lt;a href="http://radar.oreilly.com/archives/2006/12/web_20_compact.html" target="_blank"&gt;Tim
O&amp;#39;Reilly&lt;/a&gt; defines Web 2.0 as:

&lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;em&gt; &amp;quot;&lt;em&gt;Web
2.0 is the business revolution in the computer industry caused by the move to
the internet as platform, and an attempt to understand the rules for success on
that new platform. Chief among those rules is this: Build applications that
harness network effects to get better the more people use them.&amp;quot;&lt;/em&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;If someone can decipher that please contact
me because I have no idea what it means.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Wikipedia on the other hand has &lt;a href="http://en.wikipedia.org/wiki/Web_2.0" target="_blank"&gt;this&lt;/a&gt; to say about Web 2.0:&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;em&gt; &amp;quot;&lt;/em&gt;&lt;/em&gt;&lt;em&gt;a perceived or proposed second generation of
Web-based services-such as social networking sites, wikis, communication tools,
and folksonomies-that emphasize online collaboration and sharing among users&lt;em&gt;&amp;quot;&lt;/em&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;That&amp;#39;s a bit better; at least I
can picture the sites that they&amp;#39;re referring to. The truth is that Web 2.0
doesn&amp;#39;t have a definition; it is simply referring to the emergence of more user
friendly, responsive web applications that take advantage of new technologies
to create a better user experience. In a nutshell, web applications are
beginning to feel like desktop applications, with the advantage of being interconnected
globally.&lt;/p&gt;

&lt;p&gt;There are a number of
technologies being leveraged to create these next generation applications
including AJAX,
RSS, JSON, SOAP, Atom, etc. These technologies are in turn being used to create
fancy web sites such as &lt;a href="http://maps.google.com/" target="_blank"&gt;Google Maps&lt;/a&gt;, &lt;a href="http://www.flickr.com/" target="_blank"&gt;flickr&lt;/a&gt;, &lt;a href="http://del.icio.us/" target="_blank"&gt;del.icio.us&lt;/a&gt;,
&lt;a href="http://docs.google.com/" target="_blank"&gt;Google Docs and Spreadsheets&lt;/a&gt;, etc.&lt;/p&gt;

&lt;p&gt;What does this mean from a
security perspective? First off, Web 2.0 has not created any new
vulnerabilities, it has only changed the way that we build web applications.
All of the aforementioned technologies are layered on top of HTTP and are
subject to the same vulnerabilities that affect traditional web applications.
What has changed is where we need to look for the vulnerabilities. Virtually
all web application vulnerabilities exist when input is accepted and processed
without being properly sanitized. Identifying input is now less straight
forward. Input does not have to come from a web form, it does not need to be
generated by a user action and it does not even need to come from a user. Take
for example the case of Asynchronous JavaScript and XML (AJAX). AJAX instructs the
browser to make requests and receive responses behind the scenes. It creates a
more rich application as screen content can change without the need for a full
page refresh. Each of those requests occurring in the background represents
input. Take for example &lt;a href="http://www.blinklist.com/?Action=Userpage/Startpage/getmytag.ax.php" target="_blank"&gt;this
AJAX request&lt;/a&gt; being sent to BlinkList, a link sharing site. The request
triggers the following verbose SQL error message!&lt;/p&gt;

&lt;p&gt;&lt;font face="courier new"&gt;select usertag.name
from usertag where usertag.userid =&amp;nbsp;
order by usertag.name&amp;lt;br&amp;gt;You have an error in&amp;nbsp; your SQL syntax; check the manual that
corresponds to your MySQL server version for the right syntax&amp;nbsp; to use near &amp;#39;order by usertag.name&amp;#39; at line 1&lt;/font&gt;&lt;/p&gt;

&lt;p&gt;How did I find it? No, I didn&amp;#39;t
attack BlinkList, I spotted it when I had the XMLHttpRequest monitor enabled in
&lt;a href="https://addons.mozilla.org/firefox/1843/" target="_blank"&gt;FireBug&lt;/a&gt;, a popular
FireFox extension. This is a request that the BlinkList developers built into
the application. They have actually built a SQL injection attack into their
website which is triggered any time a user visits the &lt;a href="http://www.blinklist.com/" target="_blank"&gt;BlinkList homepage&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;How about a mashup which pulls
various RSS feeds together to create a dynamic news site? Is that site
accepting input even if it&amp;#39;s a read-only page? Absolutely. The feeds from third
party sites should be treated as untrusted inputs and be subject to the same
scrutiny as a web form accepting user input. Bob Auger warned us about this in
a whitepaper on &lt;a href="http://www.spidynamics.com/assets/documents/HackingFeeds.pdf" target="_blank"&gt;injection
attacks in RSS and Atom feeds&lt;/a&gt; last year.&lt;/p&gt;

&lt;p&gt;The point is that when testing
so called Web 2.0 applications we need to redefine what we consider to be
untrusted input. You cannot appropriately audit a web application without first
identifying all potential input vectors. Whether using commercial or freeware
tools or manually auditing a page, ensure that your approach is capable of
identifying and interpreting the input vectors contained in the application
being audited. Whether that input comes from an AJAX XMLHttpRequest, a third
party RSS feed of a SOAP based web service, it all represents a potential
attack vector and must therefore be tested with the same level of scrutiny as
would a user controlled web form.&lt;/p&gt;

&lt;p&gt;Let the revolution begin.&lt;/p&gt;

&lt;p&gt;- michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=2558" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/lS5necLSDSfIBH7qaEntDoln5nk/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/lS5necLSDSfIBH7qaEntDoln5nk/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/lS5necLSDSfIBH7qaEntDoln5nk/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/lS5necLSDSfIBH7qaEntDoln5nk/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=p9dD6n8q"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=ys6UPzQh"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=ys6UPzQh" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/ngJTPZkZFvA" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/Web+2.0/default.aspx">Web 2.0</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/AJAX/default.aspx">AJAX</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/02/15/What-is-Web-2.0_3F00_.aspx</feedburner:origLink></item><item><title>Microsoft Black Tuesday - February 2007 </title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/Mm_2V1YhLv0/Microsoft-Black-Tuesday-_2D00_-February-2007-.aspx</link><pubDate>Wed, 14 Feb 2007 00:32:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:2521</guid><dc:creator>erik.peterson</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=2521</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/02/14/Microsoft-Black-Tuesday-_2D00_-February-2007-.aspx#comments</comments><description>This month Microsoft decided to play catch-up and hit us with a hefty 12 security bulletins covering 20 vulnerabilities, 13 of which were critical. The volume was not surprising given that Microsoft &lt;a href="http://news.zdnet.com/2100-1009_22-6147705.html" target="_blank"&gt;pulled four of eight planned bulletins&lt;/a&gt; four days before the January release. We had also been anxiously awaiting patches for a &lt;a href="http://www.scmagazine.com.au/news/45876,microsoft-says-word-2000-flaw-is-limited-to-dos-attacks.aspx" target="_blank"&gt;growing number of Microsoft Word vulnerabilities&lt;/a&gt; which had been outstanding for up to two months, with public exploit code being available along with admissions from Microsoft of active exploitation. Fortunately, all now appear to have patches available. Once again, client side vulnerabilities were king, with most of the critical vulnerabilities falling into this category. &lt;p&gt;The February patch release was significant leaving us with 20 vulnerabilities in 12 bulletins having the following overall severity rankings.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;13 Critical&lt;/li&gt;&lt;li&gt;7 Important&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This month&amp;#39;s bulletins included patches for 7 public vulnerabilities, most of which were already being actively exploited. The following publicly known issues received patches:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;MS07-009 (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5559"&gt;CVE-2006-5559&lt;/a&gt;) Microsoft Windows MDAC ActiveX Vulnerability&lt;/li&gt;&lt;li&gt;MS07-014 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5994"&gt;CVE-2006-5994&lt;/a&gt;) Word Malformed String Vulnerability&lt;/li&gt;&lt;li&gt;MS07-014 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6456"&gt;CVE-2006-6456&lt;/a&gt;) Word Malformed Data Structures Vulnerability&lt;/li&gt;&lt;li&gt;MS07-014 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-XXXX"&gt;CVE-2006-6561&lt;/a&gt;) Word Count Vulnerability&lt;/li&gt;&lt;li&gt;MS07-014 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0515"&gt;CVE-2007-0515&lt;/a&gt;) Word Malformed Function Vulnerability&lt;/li&gt;&lt;li&gt;MS07-015 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0671"&gt;CVE-2007-0671&lt;/a&gt;) Excel Malformed Record Vulnerability&lt;/li&gt;&lt;li&gt;MS07-016 (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4697"&gt;CVE-2006-4697&lt;/a&gt;) COM Object Memory Instantiation Vulnerability&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Below is a cheat sheet for all 20 vulnerabilities.&lt;/p&gt;&lt;p&gt;Enjoy!&lt;/p&gt;&lt;p&gt;- michael&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;table cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Bulletin&amp;nbsp;&amp;nbsp; &lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Title&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-005&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Interactive Training Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3448"&gt;CVE-2006-3448&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: Brett Moore of &lt;a href="http://www.security-assessment.com/"&gt;Security-Assessment.com&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://security-assessment.com/files/advisories/MS_Interactive_Training_.cbo_Overflow_2.pdf"&gt;Security-Assessment.com&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-006&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Windows Shell Hardware Detection Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0211" target="_blank"&gt;CVE-2007-0211&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-007&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Windows Image Acquisition Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0210" target="_blank"&gt;CVE-2007-0210&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-008&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;HTML Help ActiveX Control Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0214"&gt;CVE-2007-0214&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: HD Moore of &lt;a href="http://www.bpointsys.com/"&gt;BreakingPoint Systems&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-009&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Microsoft Windows MDAC ActiveX Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5559"&gt;CVE-2006-5559&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: &lt;a href="http://www.frsirt.com/english/security-advisories"&gt;FrSIRT&lt;/a&gt;&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-010&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Microsoft Malware Protection Engine Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5270"&gt;CVE-2006-5270&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Neel Mehta and Alex Wheeler of &lt;a href="http://www.iss.net/"&gt;ISS X-Force&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-011&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;OLE Dialog Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0026"&gt;CVE-2007-0026&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By:&lt;br /&gt;&amp;nbsp;&amp;nbsp; Kostya Kortchinsky of &lt;a href="http://www.immunityinc.com/"&gt;Immunity, Inc.&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; Fabrice Desclaux from &lt;a href="http://www.eads.net/"&gt;EADS Common Research Center&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-012&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MFC Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0025"&gt;CVE-2007-0025&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;/p&gt;&lt;p&gt;Discovered By:&lt;br /&gt;&amp;nbsp;&amp;nbsp; Kostya Kortchinsky of &lt;a href="http://www.immunityinc.com/"&gt;Immunity, Inc.&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; Fabrice Desclaux from &lt;a href="http://www.eads.net/"&gt;EADS Common Research Center&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-013&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Microsoft RichEdit Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1311"&gt;CVE-2006-1311&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By:&lt;br /&gt;&amp;nbsp;&amp;nbsp; Kostya Kortchinsky of &lt;a href="http://www.immunityinc.com/"&gt;Immunity, Inc.&lt;/a&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp; Fabrice Desclaux from &lt;a href="http://www.eads.net/"&gt;EADS Common Research Center&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-014&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word Malformed String Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5994"&gt;CVE-2006-5994&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Shih-hao Weng of &lt;a href="http://www.icst.org.tw/"&gt;Information and Communication Security Technology Center&lt;/a&gt;&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: Yes&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-014&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word Malformed Data Structures Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6456"&gt;CVE-2006-6456&lt;/a&gt;&lt;br /&gt;Critical&lt;br /&gt;Discovered By: Shih-hao Weng of &lt;a href="http://www.icst.org.tw/"&gt;Information and Communication Security Technology Center&lt;/a&gt;&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: Yes&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-014&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word Count Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-XXXX"&gt;CVE-2006-6561&lt;/a&gt;&lt;br /&gt;Critical&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: Yes&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-014&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word Macro Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0208"&gt;CVE-2007-0208&lt;/a&gt;&lt;br /&gt;Important&lt;br /&gt;Discovered By: &lt;a href="https://www.usaa.com/"&gt;USAA&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-014&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word Malformed Drawing Object Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0209"&gt;CVE-2007-0209&lt;/a&gt;&lt;br /&gt;Critical&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-014&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Word Malformed Function Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0515"&gt;CVE-CVE-2007-0515&lt;/a&gt;&lt;br /&gt;Critical&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: Yes&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-015&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;PowerPoint Malformed Record Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3877"&gt;CVE-2006-3877&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Chris Ries of &lt;a href="http://www.vigilantminds.com/"&gt;VigilantMinds Inc.&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-015&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel Malformed Record Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0671"&gt;CVE-2007-0671&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: Yes&lt;br /&gt;Advisory: &lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-016&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;COM Object Instantiation Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-4697"&gt;CVE-2006-4697&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Public: Yes &lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-016&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;COM Object Instantiation Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0219"&gt;CVE-2007-0219&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: H D Moore of &lt;a href="http://www.bpointsys.com/"&gt;BreakingPoint Systems&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;strong&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-016&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;FTP Server Response Parsing Memory Corruption Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0217"&gt;CVE-2007-0217&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: &lt;a href="http://idefense.com/"&gt;iDefense&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473"&gt;iDefense&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=2521" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/T9-k-TUenH1tQGQneHI4Ff8LgqU/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/T9-k-TUenH1tQGQneHI4Ff8LgqU/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/T9-k-TUenH1tQGQneHI4Ff8LgqU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/T9-k-TUenH1tQGQneHI4Ff8LgqU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=HZMy9xQ8"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=ZYoIHCl4"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=ZYoIHCl4" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/Mm_2V1YhLv0" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/Black+Tuesday/default.aspx">Black Tuesday</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/02/14/Microsoft-Black-Tuesday-_2D00_-February-2007-.aspx</feedburner:origLink></item><item><title>Phree Phishing</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/-maAWWTYzUk/Phree-Phishing.aspx</link><pubDate>Fri, 09 Feb 2007 01:15:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:2387</guid><dc:creator>erik.peterson</dc:creator><slash:comments>4</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=2387</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/02/09/Phree-Phishing.aspx#comments</comments><description>&lt;p&gt;I recently blogged about the phishing pages that I found during a &lt;a href="http://portal.spidynamics.com/blogs/msutton/archive/2007/01/04/A-Tour-of-the-Google-Blacklist.aspx"&gt;Tour of the Google Blacklist&lt;/a&gt;. In that posting I noted how I was surprised to find that Yahoo! was actually hosting phishing sites designed to phish Yahoo! credentials. Not surprisingly, Yahoo! quickly removed the pages that I&amp;#39;d pointed out. When questioned about the issue by Network World news editor Paul McNamara, &lt;a href="http://www.networkworld.com/community/?q=node/10314" target="_blank"&gt;Yahoo! stated&lt;/a&gt; that they &amp;quot;proactively scan hosted sites for potential phishing activity and deactivate suspicious sites&amp;quot; and that they &amp;quot;are continually improving and modifying [their] efforts to remain at the forefront of the industry&amp;quot;. Fair enough, perhaps Yahoo! had not been aware of the Google blacklist and my blog posting had encouraged them to add monitoring the list to their &amp;quot;use of enhanced technologies, industry collaboration, public policy efforts, and increasing consumer awareness&amp;quot;, which they are apparently employing to combat phishing. I therefore revisited the Google blacklist today and was disappointed to see that it still includes active phising sites hosted by Yahoo! Geocities. The good news for Yahoo! - they&amp;#39;re far from being the worst offender.&lt;/p&gt;&lt;p&gt;This time around, I decided to see which hosting providers are aiding phishers by maintaining their websites - for free. To do this, I spent a couple of hours sifting through various publicly available resources including search engines, &lt;a href="http://www.phishtank.com/" target="_blank"&gt;phishing archives&lt;/a&gt;, the &lt;a href="http://sb.google.com/safebrowsing/update?version=goog-black-url:1:-1" target="_blank"&gt;Google Blacklist&lt;/a&gt; and the &lt;a href="http://sb.google.com/safebrowsing/update?version=goog-black-enchash:1:-1" target="_blank"&gt;Google Hashed/Encoded Blacklist&lt;/a&gt;. Sadly, I found that most free hosting providers are contributing to the problem of phishing. Given that I was able to find dozens of sites with minimal effort and no special resources, it is clear to me that the hosting providers are making no effort whatsoever to combat this problem. Why? Do they lack the resources? Is the challenge too difficult? I have a different theory. I believe that they benefit from the ad revenue that these web pages provide. They choose not to combat the problem because they are profiting from it.&lt;/p&gt;&lt;p&gt;What can be done to change this? Hosting providers must be held responsible for the content that is hosted on their servers. Companies such as HSBC, MySpace, Microsoft (Hotmail) and eBay were among the targets of the phishing sites that I investigated. It is their clients that are paying the price for this and it is therefore time that such companies took action. MySpace has repeatedly removed content when &lt;a href="http://news.com.com/2100-1030_3-6136829.html" target="_blank"&gt;facing legal action&lt;/a&gt; for copyright infringement. I suspect that the free hosting providers would try a little harder if they likewise faced legal action for their negligence when combating phishing.&lt;/p&gt;&lt;p&gt;Below, from least to most prolific offenders are the free hosting sites which I uncovered this evening. All were active phishing sites at the time of this posting.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;FreeWebPage.org&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://mypics4u6969.freewebpage.org/mypics2.html"&gt;http://mypics4u6969.freewebpage.org/mypics2.html&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;50 Megs&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://sgi.com.50megs.com/SWcgi3-bin0-ISAPIdll-viewtheitem-4583745438.htm"&gt;http://sgi.com.50megs.com/SWcgi3-bin0-ISAPIdll-viewtheitem-4583745438.htm&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Tripod (Lycos)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://jokaowns.tripod.com/"&gt;http://jokaowns.tripod.com/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://daulamoe.tripod.com/"&gt;http://daulamoe.tripod.com/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Geocities (Yahoo!)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.geocities.com/maria_bitch69/album_photo.html"&gt;http://www.geocities.com/maria_bitch69/album_photo.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/myphotos30021/"&gt;http://www.geocities.com/myphotos30021/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/sweet_aqnes/Album_Photo.html"&gt;http://www.geocities.com/sweet_aqnes/Album_Photo.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/you_want_my_cookies/"&gt;http://www.geocities.com/you_want_my_cookies/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/sweet_angel_eyez_of_tears/"&gt;http://www.geocities.com/sweet_angel_eyez_of_tears/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/lxxl_kiss_me_fool_lxxl/"&gt;http://www.geocities.com/lxxl_kiss_me_fool_lxxl/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/sydneypulse/"&gt;http://www.geocities.com/sydneypulse/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.geocities.com/ravish334/yahoophoto.htm"&gt;http://www.geocities.com/ravish334/yahoophoto.htm&lt;/a&gt;&lt;/p&gt;&lt;p&gt;...and by far the worst offender (I stopped at 50+, but there&amp;#39;s plenty where that came from)...&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Angelfire (Lycos)&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="http://www.angelfire.com/ab7/serviceupdate/index.htm"&gt;http://www.angelfire.com/ab7/serviceupdate/index.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/goth/login0/index.htm"&gt;http://www.angelfire.com/goth/login0/index.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/punk5/xxhaterxx4/"&gt;http://www.angelfire.com/punk5/xxhaterxx4/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/myspacelogin.error"&gt;http://www.angelfire.com/blog/myspacelogin.error&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/band2/hahheresahint/"&gt;http://www.angelfire.com/band2/hahheresahint/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/myspace-login"&gt;http://www.angelfire.com/blog/myspace-login&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/myspacecom0/"&gt;http://www.angelfire.com/blog/myspacecom0/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/ultra2/cambo/"&gt;http://www.angelfire.com/ultra2/cambo/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/funky/myspace1/"&gt;http://www.angelfire.com/funky/myspace1/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/funky/fakemyspace/"&gt;http://www.angelfire.com/funky/fakemyspace/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/ultra2/iocinlin/1234567890.html"&gt;http://www.angelfire.com/ultra2/iocinlin/1234567890.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/hiphop/rapperzz/"&gt;http://www.angelfire.com/hiphop/rapperzz/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/dc2/box1/login.html"&gt;http://www.angelfire.com/dc2/box1/login.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/ab/ljshouse/"&gt;http://www.angelfire.com/ab/ljshouse/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/myspcelogin"&gt;http://www.angelfire.com/blog/myspcelogin&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/ihatemidgets619/"&gt;http://www.angelfire.com/blog/ihatemidgets619/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/sizeofmylad-login"&gt;http://www.angelfire.com/blog/sizeofmylad-login&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/anime6idk/miespacio.htm"&gt;http://www.angelfire.com/blog/anime6idk/miespacio.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/crazy2/wowo30/ebayo.html"&gt;http://www.angelfire.com/crazy2/wowo30/ebayo.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/ct3/ebaydll"&gt;http://www.angelfire.com/ct3/ebaydll&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/password_recovery/login"&gt;http://www.angelfire.com/blog/password_recovery/login&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/stars5/freeallstars4u/"&gt;http://www.angelfire.com/stars5/freeallstars4u/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/folk/x_jroc_x/haha.html"&gt;http://www.angelfire.com/folk/x_jroc_x/haha.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/me5/hawaiian/Sign_in.html"&gt;http://www.angelfire.com/me5/hawaiian/Sign_in.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/oz/yahoox2/"&gt;http://www.angelfire.com/oz/yahoox2/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/sk3/hotmail.com/"&gt;http://www.angelfire.com/sk3/hotmail.com/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/tn3/cardandboardtournies/"&gt;http://www.angelfire.com/tn3/cardandboardtournies/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/yt3/liloohaykid/"&gt;http://www.angelfire.com/yt3/liloohaykid/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/magic/hawaiianstud96817/Log_in.html"&gt;http://www.angelfire.com/magic/hawaiianstud96817/Log_in.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/hiphop3/superstarz/chat.html"&gt;http://www.angelfire.com/hiphop3/superstarz/chat.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/comics/behnamshayani/Picture.html"&gt;http://www.angelfire.com/comics/behnamshayani/Picture.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/freak2/friendship0/card.html"&gt;http://www.angelfire.com/freak2/friendship0/card.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/goth/account/"&gt;http://www.angelfire.com/goth/account/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/droid/hairytick/update2.html"&gt;http://www.angelfire.com/droid/hairytick/update2.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/film/tahirrizvi/hotmail.htm"&gt;http://www.angelfire.com/film/tahirrizvi/hotmail.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/in/revolutionize/hotmail.html"&gt;http://www.angelfire.com/in/revolutionize/hotmail.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/retro/hackers/java-y.htm"&gt;http://www.angelfire.com/retro/hackers/java-y.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/mi4/anoop/ServiceLogin.htm"&gt;http://www.angelfire.com/mi4/anoop/ServiceLogin.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/crazy2/hobbix/"&gt;http://www.angelfire.com/crazy2/hobbix/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/pq/fos2/"&gt;http://www.angelfire.com/pq/fos2/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/un/hotmailauthenticity/"&gt;http://www.angelfire.com/un/hotmailauthenticity/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/alt/aimexpress/index2.html"&gt;http://www.angelfire.com/alt/aimexpress/index2.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/cantina/test2/"&gt;http://www.angelfire.com/cantina/test2/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog2/crimerecord/"&gt;http://www.angelfire.com/blog2/crimerecord/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/hi5/bot_remover/"&gt;http://www.angelfire.com/hi5/bot_remover/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/ult/dream10/"&gt;http://www.angelfire.com/ult/dream10/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/in4/member/yahoomail.html"&gt;http://www.angelfire.com/in4/member/yahoomail.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog/rahul180proof/"&gt;http://www.angelfire.com/blog/rahul180proof/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/ia3/falcon23/Yahoo_New.htm"&gt;http://www.angelfire.com/ia3/falcon23/Yahoo_New.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/blog2/myspacepwnd/"&gt;http://www.angelfire.com/blog2/myspacepwnd/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/biz7/myspace_error/"&gt;http://www.angelfire.com/biz7/myspace_error/&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/droid/dd3fgadsgasd554/pic.html"&gt;http://www.angelfire.com/droid/dd3fgadsgasd554/pic.html&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/music2/JDVONmusic/privatephotos.htm"&gt;http://www.angelfire.com/music2/JDVONmusic/privatephotos.htm&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.angelfire.com/funky/andrews/"&gt;http://www.angelfire.com/funky/andrews/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Why can&amp;#39;t we all just get along?&lt;/p&gt;&lt;p&gt;- michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=2387" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/f3vxOJ7tnTKD5wVxbUVaoh9daBA/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/f3vxOJ7tnTKD5wVxbUVaoh9daBA/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/f3vxOJ7tnTKD5wVxbUVaoh9daBA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/f3vxOJ7tnTKD5wVxbUVaoh9daBA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=6YmX89W7"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=0GRsDRzb"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=0GRsDRzb" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/-maAWWTYzUk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/phishing/default.aspx">phishing</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/02/09/Phree-Phishing.aspx</feedburner:origLink></item><item><title>How Prevalent Are XSS Vulnerabilities?</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/TftAoaRt0Z0/How-Prevalent-Are-XSS-Vulnerabilities_3F00_.aspx</link><pubDate>Wed, 31 Jan 2007 13:27:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:2134</guid><dc:creator>erik.peterson</dc:creator><slash:comments>4</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=2134</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/01/31/How-Prevalent-Are-XSS-Vulnerabilities_3F00_.aspx#comments</comments><description>&lt;p&gt;How Prevalent Are Cross Site Scripting (XSS) Vulnerabilities? Based on a recent experiment, I wasn&amp;#39;t surprised to see that they&amp;#39;re everywhere and finding dozens at a time doesn&amp;#39;t present much of a challenge. Back in September, 2006 I sought to find empirical evidence of the prevalence of SQL Injection flaws. I &lt;a href="http://portal.spidynamics.com/blogs/msutton/archive/2006/09/26/How-Prevalent-Are-SQL-Injection-Vulnerabilities_3F00_.aspx" target="_blank"&gt;blogged about my effort&lt;/a&gt; to leverage the Google API to find such evidence and it quickly became one of my more popular postings. Since then, I&amp;#39;ve wanted to conduct a similar experiment to investigate the prevalence of XSS vulnerabilities and have finally found the time to do so.&lt;/p&gt;&lt;p&gt;&lt;a href="http://cwe.mitre.org/documents/vuln-trends.html#table1" target="_blank"&gt;Mitre CVE statistics&lt;/a&gt; tell us that XSS is now the most common vulnerability, accounting for 21.5% of all newly discovered vulnerabilities in 2006. This is an important statistic but it only tells us what is being discovered in commercial and open source software, not what actually exists out there in the abyss we know as the Internet. When it comes to web application vulnerabilities, what&amp;#39;s actually deployed is far more meaningful. Web apps commonly contain custom code, and vulnerabilities in custom code don&amp;#39;t get CVE numbers. What I&amp;#39;m looking for is statistics on live, publicly accessible web apps.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Search Terms&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Google is a powerful tool. It can help you make dinner reservations but it can also help you find vulnerable web sites and in my quest to look for vulnerable sites, I once again sought assistance from my old friend. In order to leverage Google, you need one thing - a search query, but what search terms would assist in identifying sites potentially vulnerable to XSS? &lt;a href="http://www.cgisecurity.com/questions/xss.shtml" target="_blank"&gt;XSS flaws exist&lt;/a&gt; because user supplied input is not properly sanitized before being included in a dynamically generated webpage. That weakness in turn allows attackers to inject client side script into the page. Therefore, what I needed were search terms that would allow me to identify requests containing user input and web pages that echoed back that same input. I chose to target search pages using GET requests. Search pages are common victims of XSS and identifying those using GET requests would ensure that the user supplied values were included in the URL and would therefore be included in the Google index. I ultimately chose the following terms:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;inurl:&amp;quot;search=xxx&amp;quot; intext:&amp;quot;search results for xxx&amp;quot;&lt;/li&gt;&lt;li&gt;inurl:&amp;quot;query=xxx&amp;quot; intext:&amp;quot;search results for xxx&amp;quot;&lt;/li&gt;&lt;li&gt;inurl:&amp;quot;q=xxx&amp;quot; intext:&amp;quot;search results for xxx&amp;quot;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The &amp;lsquo;xxx&amp;#39; within each query was replaced with various words and letters such as &amp;lsquo;the&amp;#39;, &amp;lsquo;microsoft&amp;#39;, &amp;lsquo;clock&amp;#39;, &amp;lsquo;d&amp;#39;, etc. Some had meaning, some were chosen simply because it was 3am and it was all that I could come up with. They were however purposely chosen to be very different and hopefully identify results from unique websites. By including &amp;lsquo;inurl&amp;#39; queries, I was able to target variables within the URL sent via a GET method. By combining that with an &amp;lsquo;intext&amp;#39; query I could look for the same value being included within the page itself, a necessary ingredient for a XSS vulnerability. Overall the search terms were designed to identify search result pages that were echoing back the user supplied query.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Automation&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Rather than manually run Google queries ten results at a time, I automated the process by once again turning to the &lt;a href="http://www.google.com/apis/reference.html" target="_blank"&gt;Google API&lt;/a&gt;, a programmatic interface which would allow me to build a tool to automate interaction with Google. To build the Google XSS tool I simply made a few modifications to the &lt;a href="http://portal.spidynamics.com/blogs/msutton/archive/2006/09/26/How-Prevalent-Are-SQL-Injection-Vulnerabilities_3F00_.aspx" target="_blank"&gt;Google SQL Injection tool&lt;/a&gt; built back in September, 2006. The only real change involved altering code to clean up the results given the different search terms that were used. Eliminating duplicates turned out to be a real challenge in this experiment. I wanted to ensure that I was testing only one page from each unique website and although I started out with 7,436 search results, my ultimate population was quickly whittled down to 288 when I imposed the restriction of requiring unique sites. This occurs as Google does not limit the number of results that can come from a given site and my search terms were specific enough that they kept drawing from the same web sites.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Detection&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Once the target URLs had been identified, it was necessary to devise a test that would determine if the page was vulnerable. XSS is commonly tested by submitting a request that includes code to produce a JavaScript pop-up window such as &amp;lt;script&amp;gt;alert(&amp;lsquo;xss&amp;#39;);&amp;lt;/script&amp;gt;. This code presents two problems for our experiment. First, we would defeat the purpose of producing an automated test if it required sitting in front of a computer screen trying to visually identify pop-up windows. Additionally, many sites implement inadequate blacklist filtering. Although these pages remain vulnerable they would be most likely to catch such a request given its popularity. What I needed was a way for the resulting web page to &amp;lsquo;phone home&amp;#39; when a vulnerability was identified. This could certainly be done using JavaScript, but a far more simple solution exists in standard HTML. IMG tags request content from alternate locations as the page is rendered. Moreover, because exploitation is occurring on the client side, not the server, I can use an IMG tag to request resources on my local network. In the end I settled on the following IMG tag:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&amp;quot;img+src%3dhttp%3a%2f%2flocalhost%2fxss-&amp;quot; + host + &amp;quot;%3e&amp;quot;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;The above is a URL encoded version of an image tag pointed at a non-existent page on my local web server. The Google XSS tool is also dynamically inserting the name of the targeted host into the URL. By doing this, identifying sites vulnerable to XSS is as simple as looking at the log files on my local web server. If a site is vulnerable, the host will show up in the web server log. For example, an unencoded URL for testing would look like the following:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;http://vulnerable.com?search=&amp;lt;img src=http://localhost/xss- vulnerable.com&amp;gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;If vulnerable.com were indeed vulnerable, our web server log files would include the following entry:&lt;/p&gt;&lt;p&gt;&lt;font face="courier new"&gt;#Software: Microsoft Internet Information Services 5.1&lt;br /&gt;#Version: 1.0&lt;br /&gt;#Date: 2007-01-31 00:57:34&lt;br /&gt;#Fields: time c-ip cs-method cs-uri-stem sc-status&lt;br /&gt;00:57:34 127.0.0.1 GET /xss-http:/vulnerable.com 404&lt;/font&gt;&lt;/p&gt;&lt;p&gt;The HTML encoding used in the actual URL is merely a simple obfuscation technique designed to bypass basic validation routines that may check for certain characters but not their encoded equivalents. The results did reveal numerous sites that had some level of validation that would prohibit unencoded JavaScript requests but failed to filter our encoded IMG tag.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Results&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Mitre tells us that &lt;a href="http://cwe.mitre.org/documents/vuln-trends.html#table1" target="_blank"&gt;21.5% of new vulnerabilities&lt;/a&gt; are due to XSS. Jeremiah Grossman recently released a report stating that WhiteHat Security found XSS flaws in &lt;a href="https://whitehatsec.market2lead.com/go/whitehatsec/webappstats1106" target="_blank"&gt;71% of the websites they audited&lt;/a&gt; during the first half of 2006. RSnake suggests that the number should be &lt;a href="http://www.darkreading.com/document.asp?doc_id=111482" target="_blank"&gt;closer to 80%&lt;/a&gt;. I believe all of them. In this simple experiment, which looked at a single input vector on each website and supplied only one XSS injection variable, 17.3% of sites were found to be vulnerable. That&amp;#39;s scary. The raw results are below:&lt;/p&gt;&lt;table cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Unique sites identified by Google&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;288&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Unique sites accessible at time of testing&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;272&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Sites with confirmed XSS vulnerabilities&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;47&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;Percentage vulnerable&amp;nbsp;&amp;nbsp; &lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;17.3%&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;p&gt;Who was vulnerable? In order to protect the innocent, I&amp;#39;m not going name names, but I will paint a picture of what I saw. Given the search terms used, not surprisingly, results included blogging, search, video sharing and news sites. There were a few retail web sites as well including a couple of online music stores and a consumer electronics retailer. The sites ranged from small to large with the two most notable participants being a major sports network and one of the largest newspapers in the US. Unfortunately, it&amp;#39;s not surprising that even large corporations have vulnerable websites when you look at the names which litter the sla.ckers.org &lt;a href="http://sla.ckers.org/forum/read.php?3,44" target="_blank"&gt;XSS Wall of Shame&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;How long did it take me to identify 47 vulnerable websites? Once the methodology was in place and the tool was built - less than five minutes. Once again, we&amp;#39;re setting the bar for web application security far too low. It shouldn&amp;#39;t be this easy.&lt;/p&gt;&lt;p&gt;- michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=2134" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/ybCtqAPTa85vM5xa_3chrdj0sk0/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ybCtqAPTa85vM5xa_3chrdj0sk0/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/ybCtqAPTa85vM5xa_3chrdj0sk0/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/ybCtqAPTa85vM5xa_3chrdj0sk0/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=X2O88Wpo"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=LsF1CaiY"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=LsF1CaiY" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/TftAoaRt0Z0" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/google/default.aspx">google</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/XSS/default.aspx">XSS</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/01/31/How-Prevalent-Are-XSS-Vulnerabilities_3F00_.aspx</feedburner:origLink></item><item><title>Evaluating Security Tools</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/HXMenWRdrwE/Evaluating-Security-Tools.aspx</link><pubDate>Fri, 26 Jan 2007 15:50:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:2015</guid><dc:creator>erik.peterson</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=2015</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/01/26/Evaluating-Security-Tools.aspx#comments</comments><description>All companies face the challenge of evaluating security tools that they will procure, but knowing where to start can be a daunting task. While there&amp;#39;s no perfect way to ensure that a product meets your needs a little due diligence is essential. Fortunately, various resources are available to assist. &lt;p&gt;The most logical place to start is by looking at third party product evaluations. Technology publications love to conduct bake offs of competing technologies and score the contestants. Moreover, technology vendors line up to be considered for awards bestowed by the same publications but buyer beware - awards and reviews may require vendors to pay a fee to be considered in the competition, so do your research to ensure that you&amp;#39;re receiving an unbiased opinion. Personally, next to hands on experience with the tools themselves, I would place faith first and foremost in the past experiences of current customers that you have an existing relationship with - not the happy customers put forth by the vendor. No one knows the ins and outs of a technology better than those that rely upon it on a daily basis.&lt;/p&gt;&lt;p&gt;While it&amp;#39;s great to know what others think, there&amp;#39;s no substitute for hands on experience. Making an apples to apples comparison among competing technologies requires using an appropriate benchmark. I would actually recommend against testing security tools by using an in-house application as the benchmark. While this may seem to be a logical approach since you&amp;#39;ll be using the tool in your own environment, an in house application is likely (we hope) to only contain a small population of vulnerabilities and as such will not provide a broad view of the strengths and weaknesses of the security tool being evaluated. In the web application security space there are fortunately a number of options available in the form of freely available, intentionally vulnerable web applications that can be used for testing purposes. &lt;a href="http://www.foundstone.com/" target="_blank"&gt;Foundstone&lt;/a&gt; for example provides a series of &amp;lsquo;&lt;a href="http://www.foundstone.com/resources/s3i_tools.htm" target="_blank"&gt;Hackme&lt;/a&gt;&amp;#39; web applications. Each of the Hackme applications are written in different languages which allows you to target the appropriate platform(s) used in your own development efforts. &lt;a href="http://www.foundstone.com/resources/proddesc/hacmebank.htm" target="_blank"&gt;Hackme Bank&lt;/a&gt; for example, is written in C#, with a backend Microsoft SQL database, while &lt;a href="http://www.foundstone.com/resources/proddesc/hacmebooks.htm" target="_blank"&gt;Hackme Books&lt;/a&gt; is a J2EE application. &lt;a href="http://www.owasp.org/" target="_blank"&gt;OWASP&lt;/a&gt; makes available &lt;a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project" target="_blank"&gt;WebGoat&lt;/a&gt;, an insecure J2EE application, but a promising new initiative is their &lt;a href="http://www.owasp.org/index.php/Owasp_SiteGenerator" target="_blank"&gt;Site Generator&lt;/a&gt; project. Site Generator allows users to dynamically design different vulnerable web apps by selecting the desired vulnerable components.&lt;/p&gt;&lt;p&gt;If you still prefer to rely on third party evaluations but aren&amp;#39;t comfortable with the potential bias of technology publications, the National Institute of Standards and Technology (&lt;a href="http://www.nist.gov/" target="_blank"&gt;NIST&lt;/a&gt;), is working on a solution. The Software Assurance Metrics and Tool Evaluation (&lt;a href="http://samate.nist.gov/index.php/Main_Page" target="_blank"&gt;SAMATE&lt;/a&gt;) project, sponsored by &lt;a href="http://www.dhs.gov/" target="_blank"&gt;DHS&lt;/a&gt;, seeks to define the baseline functional behavior that should be present in security tools. The first SAMATE initiative will focus on &lt;a href="http://samate.nist.gov/index.php/Source_Code_Security_Analyzers" target="_blank"&gt;source code analyzers&lt;/a&gt; (SCA). At this point, they are excluding byte code and binary code scanners from the SCA definition but a &lt;a href="http://samate.nist.gov/docs/SAMATE_source_code_analysis_tool_spec_09_15_06.pdf" target="_blank"&gt;draft functional specification&lt;/a&gt; for this project is already available. Beyond the draft specification, they also plan to develop test suites that will allow for independent analysis of SCAs. In speaking with NIST, it appears that web application scanners will be their next project under the SAMATE umbrella. Given that these specifications only seek to identify baseline functionality for like tools, it remains to be seen how useful they will be in evaluating security tools, but we&amp;#39;ll certainly follow their progress.&lt;/p&gt;&lt;p&gt;Regardless of the process that you use when evaluating security tools, never forget that as a buyer, you have more power than you realize. Don&amp;#39;t simply hand over a hefty check simply because one vendor has a tool that is better than the others. If additional features are required to meet your needs, ensure that they make it into the product road map. These tools don&amp;#39;t come cheap, so get your money&amp;#39;s worth.&lt;/p&gt;&lt;p&gt;- michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=2015" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/cp4ARJtFF3A2D8PQ6WE8nrk2FbM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/cp4ARJtFF3A2D8PQ6WE8nrk2FbM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/cp4ARJtFF3A2D8PQ6WE8nrk2FbM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/cp4ARJtFF3A2D8PQ6WE8nrk2FbM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=BTQPt0OI"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=s4hv9bWb"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=s4hv9bWb" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/HXMenWRdrwE" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/01/26/Evaluating-Security-Tools.aspx</feedburner:origLink></item><item><title>Decoding the Google Blacklist</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/Lp8NxVKMCNc/Decoding-the-Google-Blacklist.aspx</link><pubDate>Wed, 10 Jan 2007 16:07:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:1657</guid><dc:creator>erik.peterson</dc:creator><slash:comments>3</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=1657</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/01/10/Decoding-the-Google-Blacklist.aspx#comments</comments><description>After publishing last week&amp;#39;s blog entitled &lt;a href="http://portal.spidynamics.com/blogs/msutton/archive/2007/01/04/A-Tour-of-the-Google-Blacklist.aspx"&gt;&amp;lsquo;A Tour of the Google Blacklist&amp;#39;&lt;/a&gt;, I received a few queries about Google&amp;#39;s encoded/hashed blacklist (enchash). This blacklist is separate from the unencoded blacklist that was the focus of the previous blog. It is also much larger, currently maintaining 14,000+ entries to the 1,000+ entries contained in the unencoded blacklist. Beyond that, it takes a more functional approach by providing regular expressions to match phishing URLs as opposed to exact string matches. &lt;p&gt;&lt;strong&gt;Structure&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;As with all of the Google safe browsing lists, the enchash list can be pulled from a standard URL as noted below:&lt;/p&gt;&lt;p&gt;&lt;a href="http://sb.google.com/safebrowsing/update?version=goog-black-enchash:1:1" target="_blank"&gt;http://sb.google.com/safebrowsing/update?version=goog-black-enchash:1:1&lt;/a&gt;&lt;/p&gt;&lt;p&gt;The final two integers in the URL represent major:minor version numbers, allowing you to pull specific versions of the list. When requesting the enchash list you will see the following structure:&lt;/p&gt;&lt;blockquote&gt;&lt;font face="Courier New"&gt;[goog-black-enchash 1.16026]&lt;br /&gt;+000063A6E10172D71383F41E62D518A4&amp;nbsp;&amp;nbsp; ZFhjcVk2R1mwTTbpCYVT5twpRd6hypeo4... &lt;br /&gt;+0000E099D1DD9B0CA2A834A20A20C7AF&amp;nbsp;&amp;nbsp; cFhWWGd6NGVz/L8ye10PpA6dgRqtTftTu...&lt;br /&gt;+00011C8D5B3C6B7E58EFE31EBD4DBE04&amp;nbsp;&amp;nbsp; bFNvcGRvNmq62yRf0TeY3Lwdn7Z+y61S2...&lt;br /&gt;+000351FD5CF55A398FF6360DA108ED03&amp;nbsp;&amp;nbsp; UUxza1hyQzTbScPPx/MpphX/iQmMbYKET...&lt;/font&gt;&lt;/blockquote&gt;&lt;p&gt;The first row simply identifies the version of the enchash list being displayed. The data following is contained in two columns with the first being an MD5 hash of a database salt (see below) + hostname and the second, an encrypted array of regular expressions.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Security&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The enchash list isn&amp;#39;t designed to be secure per se. Information on its structure and how to decrypt the regular expressions is &lt;a href="http://wiki.mozilla.org/Phishing_Protection:_Server_Spec" target="_blank"&gt;publicly available&lt;/a&gt;. It is designed so that an individual URL can be checked against the list to determine if it is a phishing site, while preventing the entire list from being decrypted at once. This is accomplished by including the hostname in the decryption key. You must start with a hostname that is in the list, in order to decrypt the corresponding regular expressions. Therefore, in order to decrypt the entire list, you would also need to know all of the hostnames represented in the first column. This is likely done simply to prevent competitors from acquiring the full list.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Decryption&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;In order to understand how to decrypt the regular expressions, we&amp;#39;ll walk through a sample record.&lt;/p&gt;&lt;p&gt;1. Hostname&lt;/p&gt;&lt;ul&gt;&lt;li&gt;As mentioned, the list is designed to be able to check a known URL against the list to determine if a match exists. In order to do this, we&amp;#39;ll begin with a hostname taken from the &lt;a href="http://sb.google.com/safebrowsing/update?version=goog-black-url:1:1" target="_blank"&gt;unencoded blacklist&lt;/a&gt;, namely 210.212.141.146.&lt;/li&gt;&lt;li&gt;A canonical hostname should be broken down into sub hostnames with each one checked against the list separately. For example, with mail.yahoo.com, both mail.yahoo.com and yahoo.com should be checked separately. Since our hostname is an IP address, this is not required.&lt;/li&gt;&lt;li&gt;Next, compute an MD5 hash of the &amp;lsquo;database salt&amp;#39; and the hostname. The database salt is a constant equal to &amp;lsquo;oU3q.72p&amp;#39;. The MD5 hash of &amp;lsquo;oU3q.72p210.212.141.146&amp;#39; is equivalent to &amp;lsquo;74AC98F531F37D2DA9C221148F2F35C2&amp;#39;.&lt;/li&gt;&lt;li&gt;Ensure that all characters in the MD5 hash are capitalized and compare the result against data in the first column. If a match is found, proceed to the subsequent steps. In our case, the MD5 checksum does produce a match.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;2. Key&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Once a match is found, it&amp;#39;s time to produce the key that will be used to decrypt the data.&lt;/li&gt;&lt;li&gt;Base64 decode the data&lt;/li&gt;&lt;li&gt;Strip the first 8 characters from the decoded data. This will be used as the &amp;lsquo;random salt&amp;#39; and in our case is &amp;lsquo;Qjnv90jM&amp;#39;.&lt;/li&gt;&lt;li&gt;Compute an MD5 hash of the &amp;lsquo;random salt|database salt|hostname&amp;#39;. This produces a 128-bit encryption key.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;3. Decryption&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Apply the decryption key generated above using the RC4 algorithm to decrypt the data.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;4. Result&lt;/p&gt;&lt;ul&gt;&lt;li&gt;^http\:\/\/210\.212\.141\.146\:84\/\.confirm\/index\.php\?&lt;/li&gt;&lt;li&gt;Our example produced a single regular expression but it is possible for the data to contain multiple regular expressions separated by &amp;lsquo;\t&amp;#39; (tab stop) characters.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Code&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The following code was provided by Stephan Chenette and Alex Rice from &lt;a href="http://www.websense.com/securitylabs/" target="_blank"&gt;WebSense&lt;/a&gt; and will automate the aforementioned decryption procedure. I&amp;#39;d like to thank them both for their invaluable collaboration as they pointed out a key fault in my logic and ultimately saved me from chasing my tail.&lt;/p&gt;&lt;blockquote&gt;&lt;font face="Courier New"&gt;&lt;p&gt;#!/usr/bin/perl -w&lt;br /&gt;use strict;&lt;br /&gt;use Crypt::RC4;&lt;br /&gt;use MIME::Base64;&lt;br /&gt;use Digest::MD5 qw(md5);&lt;br /&gt;&lt;br /&gt;my $database_salt = &amp;#39;oU3q.72p&amp;#39;;&lt;br /&gt;my $hostname = &amp;#39;210.212.141.146&amp;#39;;&lt;br /&gt;my $enc_string =&amp;nbsp;decode_base64(&amp;#39;UWpudjkwak0iUBMO+xnGplKuo+fiEw1BVFQSuoi21jQ7DE2nTuO6esC67q88bcsM8TBVHQaEK29wmwzStc7SHQut&amp;#39;); &lt;br /&gt;my $random_salt = substr($enc_string, 0, 8);&lt;br /&gt;my $enc_data = substr($enc_string, 8);&lt;br /&gt;my $key = md5($database_salt . $random_salt . $hostname);&lt;br /&gt;my $rc4 = Crypt::RC4-&amp;gt;new($key);&lt;br /&gt;&lt;br /&gt;printf &amp;quot;Regular exp(s): %s\n&amp;quot;, $rc4-&amp;gt;RC4($enc_data);&lt;/p&gt;&lt;/font&gt;&lt;/blockquote&gt;&lt;p&gt;Enjoy!&lt;/p&gt;&lt;p&gt;- michael&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=1657" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/0donUPuZjzVwwVshtorMv1pX7RM/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0donUPuZjzVwwVshtorMv1pX7RM/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/0donUPuZjzVwwVshtorMv1pX7RM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/0donUPuZjzVwwVshtorMv1pX7RM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=659GMK4U"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=QKsoZZzr"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=QKsoZZzr" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/Lp8NxVKMCNc" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/tags/google/default.aspx">google</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/01/10/Decoding-the-Google-Blacklist.aspx</feedburner:origLink></item><item><title> Microsoft Black Tuesday - January 2007</title><link>http://feedproxy.google.com/~r/MichaelSuttonsBlog/~3/luz5TCym5ds/-Microsoft-Black-Tuesday-_2D00_-January-2007.aspx</link><pubDate>Tue, 09 Jan 2007 14:13:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:1628</guid><dc:creator>erik.peterson</dc:creator><slash:comments>7</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/msutton/rsscomments.aspx?PostID=1628</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/01/09/-Microsoft-Black-Tuesday-_2D00_-January-2007.aspx#comments</comments><description>&lt;p&gt;This month&amp;#39;s bulletins leave us with two major headlines. First, &amp;lsquo;What happened to half of the bulletins?&amp;#39; and secondly, Internet Explorer 7.0 isn&amp;#39;t apparently quite as bullet proof as advertised. Even before Black Tuesday arrived this month, we knew that we were going to be receiving less than expected as last Friday Microsoft &lt;a href="http://news.zdnet.com/2100-1009_22-6147705.html" target="_blank"&gt;pulled four of eight planned bulletins&lt;/a&gt;. No explanation has been given but it&amp;#39;s fair to assume that issues arose during final testing. While it&amp;#39;s understandable that Microsoft would want to ensure that the patches are solid before releasing them, it&amp;#39;s concerning given the number of outstanding Microsoft vulnerabilities that we&amp;#39;re already aware of. For over a month now, Microsoft has admitted to being aware of two 0day Microsoft Word vulnerabilities being used in targeted attacks ( see below), yet the January patch cycle came and went and these vulnerabilities remain outstanding. Beyond this, 3Com&amp;#39;s &lt;a href="http://www.zerodayinitiative.com/upcoming_advisories.html" target="_blank"&gt;Zero Day Initiative&lt;/a&gt; lists six pending Microsoft advisories, while &lt;a href="http://research.eeye.com/html/advisories/upcoming/index.html" target="_blank"&gt;eEye&lt;/a&gt; lists two. Expect a large volume of Microsoft bulletins in February.&lt;/p&gt;&lt;p&gt;The other big headline surrounds &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx" target="_blank"&gt;MS07-004&lt;/a&gt;. Microsoft and &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462" target="_blank"&gt;iDefense&lt;/a&gt; have released details of a Vector Markup Language (VML) integer overflow vulnerability which affects all modern versions of Internet Explorer including IE7. Given the significant user base affected by this issue, be sure to make &lt;a href="http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx" target="_blank"&gt;MS07-004&lt;/a&gt; a top patching priority.&lt;/p&gt;&lt;p&gt;The pared down patch release was still significant and left us with 10 vulnerabilities in four bulletins with the following overall severity rankings.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;7 Critical&lt;/li&gt;&lt;li&gt;2 Important&lt;/li&gt;&lt;li&gt;1 Moderate&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;This month&amp;#39;s bulletins included patches for 3 public vulnerabilities. More importantly, Microsoft admits to being aware of exploitation using the VML Buffer Overrun Vulnerability (CVE-2006-4704). The following publicly known issues received patches:&lt;/p&gt;&lt;ul&gt;&lt;li&gt;MS07-001 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5574" target="_blank"&gt;CVE-2006-5574&lt;/a&gt;) Office 2003 Brazilian Portuguese Grammar Checker Vulnerability&lt;/li&gt;&lt;li&gt;MS07-003 (&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1305" target="_blank"&gt;CVE-2006-1305&lt;/a&gt;) Microsoft Outlook Denial of Service Vulnerability&lt;/li&gt;&lt;li&gt;MS07-004 (&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0024" target="_blank"&gt;CVE-2007-0024&lt;/a&gt;) VML Buffer Overrun Vulnerability&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Unfortunately, this month&amp;#39;s bulletins did not address the following two Microsoft Word file format vulnerabilities which have now been outstanding for over a month. While Microsoft has acknowledged the vulnerabilities and the fact that they are being used in targeted attacks, they have not set release dates for patches.&lt;/p&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.microsoft.com/technet/security/advisory/929433.mspx" target="_blank"&gt;Microsoft Security Advisory 929433&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Microsoft Word vulnerability - &lt;a href="http://blogs.technet.com/msrc/archive/2006/12/10/new-report-of-a-word-zero-day.aspx" target="_blank"&gt;December 10, 2006 blog posting&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Below is a cheat sheet for all 10 vulnerabilities.&lt;/p&gt;&lt;p&gt;Enjoy!&lt;/p&gt;&lt;p&gt;- michael&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;table cellpadding="0" cellspacing="0"&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Bulletin&amp;nbsp;&amp;nbsp; &lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Title&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-001&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Office 2003 Brazilian Portuguese Grammar Checker Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-5574" target="_blank"&gt;CVE-2006-5574&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-002&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel Malformed IMDATA Record Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0027" target="_blank"&gt;CVE-2007-0027&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Jeff Gennari of &lt;a href="https://www.securecoding.cert.org/confluence/display/seccode/CERT+Secure+Coding+Standards" target="_blank"&gt;CERT&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-002&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel Malformed Record Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0028" target="_blank"&gt;CVE-2007-028&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Jie Ma of &lt;a href="http://www.fortinet.com/" target="_blank"&gt;Fortinet Security Research Team&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;p&gt;Advisory: &lt;a href="http://www.fortinet.com/FortiGuardCenter/advisory/FG-2007-01.html" target="_blank"&gt;Fortinet FG-2007-01&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-002&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel Malformed String Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2006-4701" target="_blank"&gt;CVE 2007-0029&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: &lt;a href="http://www.nsfocus.com/" target="_blank"&gt;NSFocus Security Team&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-002&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel Malformed Column Record Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0029" target="_blank"&gt;CVE-2007-0030&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Greg MacManus of &lt;a href="http://labs.idefense.com/" target="_blank"&gt;iDefense Labs&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=460" target="_blank"&gt;iDefense&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-002&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Excel Malformed Palette Record Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0031" target="_blank"&gt;CVE-2007-0031&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Greg MacManus of &lt;a href="http://labs.idefense.com/" target="_blank"&gt;iDefense Labs&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;br /&gt;Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=461" target="_blank"&gt;iDefense&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-003&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Microsoft Outlook VEVENT Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0033" target="_blank"&gt;CVE-2007-0033&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Important&lt;br /&gt;Discovered By: Lurene Grenier of &lt;a href="http://www.sourcefire.com/" target="_blank"&gt;Sourcefire&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-003&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Microsoft Outlook Denial of Service Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-1305" target="_blank"&gt;CVE-2006-1305&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Moderate&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-003&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;Microsoft Outlook Advanced Find Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0034" target="_blank"&gt;CVE-2007-0034&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Stuart Pearson of &lt;a href="http://www.computerterrorism.com/" target="_blank"&gt;Computer Terrorism&lt;/a&gt;&lt;br /&gt;Public: No&lt;br /&gt;Exploited: No&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;MS07-004&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt;&lt;td&gt;&lt;p&gt;&lt;strong&gt;VML Buffer Overrun Vulnerability&lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-0024" target="_blank"&gt;CVE-2007-0024&lt;/a&gt;&lt;strong&gt;&lt;br /&gt;&lt;/strong&gt;Critical&lt;br /&gt;Discovered By: Jospeh Moti working with the &lt;a href="http://www.idefense.com/" target="_blank"&gt;iDEFENSE&lt;/a&gt;&lt;br /&gt;Public: Yes&lt;br /&gt;Exploited: Yes&lt;/p&gt;&lt;p&gt;Advisory: &lt;a href="http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=462" target="_blank"&gt;iDefense&lt;/a&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/p&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=1628" width="1" height="1"&gt;
&lt;p&gt;&lt;a href="http://feedads.g.doubleclick.net/~a/3LRZHapCritYsWz6HrWNgj3B11M/0/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3LRZHapCritYsWz6HrWNgj3B11M/0/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;br/&gt;
&lt;a href="http://feedads.g.doubleclick.net/~a/3LRZHapCritYsWz6HrWNgj3B11M/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~a/3LRZHapCritYsWz6HrWNgj3B11M/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=E2rDOp1V"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?d=41" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?a=lTDP5WW9"&gt;&lt;img src="http://feeds.feedburner.com/~f/MichaelSuttonsBlog?i=lTDP5WW9" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/MichaelSuttonsBlog/~4/luz5TCym5ds" height="1" width="1"/&gt;</description><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/msutton/archive/2007/01/09/-Microsoft-Black-Tuesday-_2D00_-January-2007.aspx</feedburner:origLink></item></channel></rss>
