<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>With DK</title>
	
	<link>http://www.withdk.com</link>
	<description>World of DK</description>
	<lastBuildDate>Wed, 13 May 2009 08:10:57 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/WithDK" /><feedburner:info uri="withdk" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><item>
		<title>Tool: SSL-Enum</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/rw3rRDpNTyc/</link>
		<comments>http://www.withdk.com/2009/05/12/ssl-enum/#comments</comments>
		<pubDate>Tue, 12 May 2009 08:07:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>
		<category><![CDATA[projects]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[ssl]]></category>
		<category><![CDATA[tls]]></category>
		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.withdk.com/?p=40</guid>
		<description><![CDATA[Beta version of SSL-Enum released. 
The tool allows SSL cipher scanning and enumeration without requiring OpenSSL or SSLeay.
Details here.
]]></description>
			<content:encoded><![CDATA[<p>Beta version of SSL-Enum released. </p>
<p>The tool allows SSL cipher scanning and enumeration without requiring OpenSSL or SSLeay.</p>
<p>Details <a href="http://www.withdk.com/projects/tool-ssl-enum-ssl-cipher-scanner/">here</a>.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/rw3rRDpNTyc" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2009/05/12/ssl-enum/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2009/05/12/ssl-enum/</feedburner:origLink></item>
		<item>
		<title>cURL/LibcURL Redirect Arbitrary File Access</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/5Swg5wvtTzw/</link>
		<comments>http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/#comments</comments>
		<pubDate>Tue, 03 Mar 2009 08:14:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/?p=28</guid>
		<description><![CDATA[Release date: 03/Jan/2009
Last Modified: N/A
Author: David Kierznowski http://withdk.com
Risk: Medium-High
This vulnerability could permit remote arbitrary file access and command execution under &#8220;less-likely&#8221; circumstances.
Full advisory here:
http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf
]]></description>
			<content:encoded><![CDATA[<p>Release date: 03/Jan/2009<br />
Last Modified: N/A<br />
Author: David Kierznowski http://withdk.com<br />
Risk: Medium-High</p>
<p>This vulnerability could permit remote arbitrary file access and command execution under &#8220;less-likely&#8221; circumstances.</p>
<p>Full advisory here:<br />
<a href="http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf">http://www.withdk.com/archives/Libcurl_arbitrary_file_access.pdf</a></p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/5Swg5wvtTzw" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2009/03/03/curllibcurl-redirect-arbitrary-file-access/</feedburner:origLink></item>
		<item>
		<title>OWASP Talk: PHP Code Analysis: Real World Examples</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/6ShVWiP7O-s/</link>
		<comments>http://www.withdk.com/2008/03/19/owasp-talk-php-code-analysis-real-world-examples/#comments</comments>
		<pubDate>Wed, 19 Mar 2008 13:38:23 +0000</pubDate>
		<dc:creator>dk</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/03/19/owasp-talk-php-code-analysis-real-world-examples/</guid>
		<description><![CDATA[
There have been some delays around the next London OWASP meeting, but its currently set for Thu, 3 Apr 2008.


If it all goes ahead with plan, I&#8217;ll be speaking on PHP Code Analysis, so if your around and have a night free please feel free to join in.
]]></description>
			<content:encoded><![CDATA[<p>
There have been some delays around the next <a href="http://www.owasp.org/index.php/London">London OWASP meeting,</a> but its currently set for Thu, 3 Apr 2008.
</p>
<p>
If it all goes ahead with plan, I&#8217;ll be speaking on PHP Code Analysis, so if your around and have a night free please feel free to join in.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/6ShVWiP7O-s" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/03/19/owasp-talk-php-code-analysis-real-world-examples/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2008/03/19/owasp-talk-php-code-analysis-real-world-examples/</feedburner:origLink></item>
		<item>
		<title>Persists Software XUpload Buffer Overflow</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/cmDqEPFvkx8/</link>
		<comments>http://www.withdk.com/2008/02/26/persists-software-xupload-buffer-overflow/#comments</comments>
		<pubDate>Tue, 26 Feb 2008 15:23:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/02/26/persists-software-xupload-buffer-overflow/</guid>
		<description><![CDATA[I discovered a buffer overflow in Persist Software XUpload package while researching ActiveX exploitation.
XUpload is prone to a buffer overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An exploit is in the wild. See the SecurityFocus advisory for more details.
]]></description>
			<content:encoded><![CDATA[<p>I discovered a buffer overflow in Persist Software XUpload</b> package while researching ActiveX exploitation.</p>
<p>XUpload is prone to a buffer overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.</p>
<p>An exploit is in the wild. See the <a href="http://www.securityfocus.com/bid/27456/info">SecurityFocus advisory</a> for more details.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/cmDqEPFvkx8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/02/26/persists-software-xupload-buffer-overflow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2008/02/26/persists-software-xupload-buffer-overflow/</feedburner:origLink></item>
		<item>
		<title>Livelink UTF-7 XSS Vulnerability</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/hkLmMi7seIY/</link>
		<comments>http://www.withdk.com/2008/01/31/livelink-utf-7-xss-vulnerability/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 14:17:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/01/31/livelink-utf-7-xss-vulnerability/</guid>
		<description><![CDATA[
Release date: 31/Jan/2008
Last Modified: N/A
Author: David Kierznowski http://withdk.com
Application: Linklink ]]></description>
			<content:encoded><![CDATA[<p>
Release date: 31/Jan/2008<br />
Last Modified: N/A<br />
Author: David Kierznowski http://withdk.com<br />
Application: Linklink <= 9.7.0<br />
Risk: Medium
</p>
<p>
Full advisory available <a href="http://withdk.com/archives/livelink-utf7-xss-advisory.pdf">here</a>.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/hkLmMi7seIY" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/01/31/livelink-utf-7-xss-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2008/01/31/livelink-utf-7-xss-vulnerability/</feedburner:origLink></item>
		<item>
		<title>Textlinkads SQL Injection Vulnerability released</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/TZP4jMVhqRE/</link>
		<comments>http://www.withdk.com/2008/01/18/textlinkads-sql-injection-vulnerability-released/#comments</comments>
		<pubDate>Fri, 18 Jan 2008 14:41:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/01/18/textlinkads-sql-injection-vulnerability-released/</guid>
		<description><![CDATA[
BlogSecurity: WP Textlinkads SQL Injection Advisory


I left it with them for 2 weeks before disclosing the advisory. It was fixed within 24hrs of release.
]]></description>
			<content:encoded><![CDATA[<p>
<a href="http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/">BlogSecurity: WP Textlinkads SQL Injection Advisory</a>
</p>
<p>
I left it with them for 2 weeks before disclosing the advisory. It was fixed within 24hrs of release.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/TZP4jMVhqRE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/01/18/textlinkads-sql-injection-vulnerability-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2008/01/18/textlinkads-sql-injection-vulnerability-released/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure Saga Continues</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/3pgrYBeGh9w/</link>
		<comments>http://www.withdk.com/2008/01/14/full-disclosure-saga-continues/#comments</comments>
		<pubDate>Mon, 14 Jan 2008 16:46:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/01/14/full-disclosure-saga-continues/</guid>
		<description><![CDATA[So its now been 20 days since finding and disclosing a criticial SQL injection issue that has the potential to affect 20,000 websites. See my first post here.

I have bounced a few E-Mails off the CEO, and he has kept in touch, however, nothing yet. So that means I have now left 20K of websites [...]]]></description>
			<content:encoded><![CDATA[<p>So its now been 20 days since finding and disclosing a criticial SQL injection issue that has the potential to affect 20,000 websites. See my first post <a href="http://www.withdk.com/2008/01/03/fire-and-flames/">here</a>.</p>
<p>
I have bounced a few E-Mails off the CEO, and he has kept in touch, however, nothing yet. So that means I have now left 20K of websites at risk for 20 days and counting&#8230;
</p>
<p>
The bigger players (Microsoft, Cisco etc) with more experience have procedures in place to deal with security issues like this, so &quot;responsible&quot; disclosure makes sense, but by the time this advisory is released, I would have spent the same amount of time (if not more) disclosing the vulnerability then actually researching the vulnerability.
</p>
<p>
These things are never as black and white as they first appear.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/3pgrYBeGh9w" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/01/14/full-disclosure-saga-continues/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2008/01/14/full-disclosure-saga-continues/</feedburner:origLink></item>
		<item>
		<title>Fire and Flames</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/YeZbcwviuiE/</link>
		<comments>http://www.withdk.com/2008/01/03/fire-and-flames/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 16:28:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/01/03/fire-and-flames/</guid>
		<description><![CDATA[I found an SQL Injection vulnerability in a peice of software that according to the site may affect over 20,000 websites. I have kept the advisory and proof of concept exploit private, but am curious how long it will take for the vendor to release a fix.
I have often felt that full-disclosure (FD) is the [...]]]></description>
			<content:encoded><![CDATA[<p>I found an SQL Injection vulnerability in a peice of software that according to the site may affect over 20,000 websites. I have kept the advisory and proof of concept exploit private, but am curious how long it will take for the vendor to release a fix.</p>
<p>I have often felt that full-disclosure (FD) is the way forward. In other words, we release first and ask questions later. This approach appears to have &#8216;inspired&#8217; vendors to patch more efficiently in the past, but at the same time it alerts the bad guys to write more exploits!</p>
<p>The argument by FD is that attackers may already be exploiting the vulnerability in the wild and that by releasing FD the security researcher is merely putting out a warning &#8211; as one would if a dam wall was about to collapse.</p>
<p>If we can measure and detect attacks on a global scale this argument may be addressed and debated in a better light. I do think FD can be terribly destructive if used by attention seekers who may choose not to release the advisory to the vendor at all.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/YeZbcwviuiE" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/01/03/fire-and-flames/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2008/01/03/fire-and-flames/</feedburner:origLink></item>
		<item>
		<title>Added new content</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/073OHMekIT8/</link>
		<comments>http://www.withdk.com/2007/12/26/added-new-content/#comments</comments>
		<pubDate>Wed, 26 Dec 2007 00:44:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2007/12/26/added-new-content/</guid>
		<description><![CDATA[Its taking longer to find, order and place content then originally thought, however, it really gives one perspective with regards to achievements.
I have added content to both the Articles and News/Interview Sections.

Content Added
In Articles:
    * Paper: Ad-Jacking &#8211; XSSing for Fun and Profit
    * Presentation: Automated Web FOO or [...]]]></description>
			<content:encoded><![CDATA[<p>Its taking longer to find, order and place content then originally thought, however, it really gives one perspective with regards to achievements.</p>
<p>I have added content to both the <a href="http://www.withdk.com/articles/">Articles</a> and <a href="http://www.withdk.com/news/">News/Interview</a> Sections.</p>
<p>
Content Added<br />
In Articles:<br />
    * Paper: Ad-Jacking &#8211; XSSing for Fun and Profit<br />
    * Presentation: Automated Web FOO or FUD?<br />
In News &#038; Interviews:<br />
    * Survey: Finds Most WordPress Blogs Vulnerable<br />
    * Vul: Adobe Acrabat JavaScript Vulnerabilities</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/073OHMekIT8" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2007/12/26/added-new-content/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2007/12/26/added-new-content/</feedburner:origLink></item>
		<item>
		<title>WithDK site in progress</title>
		<link>http://feedproxy.google.com/~r/WithDK/~3/BCXdmG_3fyM/</link>
		<comments>http://www.withdk.com/2007/12/23/withdk-site-in-progress/#comments</comments>
		<pubDate>Sun, 23 Dec 2007 22:39:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/23/12/2007/test-post/</guid>
		<description><![CDATA[WithDK.com site development in progress.
]]></description>
			<content:encoded><![CDATA[<p>WithDK.com site development in progress.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/BCXdmG_3fyM" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2007/12/23/withdk-site-in-progress/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		<feedburner:origLink>http://www.withdk.com/2007/12/23/withdk-site-in-progress/</feedburner:origLink></item>
	</channel>
</rss>
