<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DUMASXc6fSp7ImA9WhVXEko.&quot;"><id>tag:blogger.com,1999:blog-3245689738496809889</id><updated>2012-04-13T02:37:28.915+02:00</updated><category term="clickjacking" /><category term="xss" /><category term="defense" /><category term="tools" /><category term="html5" /><category term="bug" /><category term="interesting" /><category term="chrome" /><title>web security</title><subtitle type="html" /><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://websec.rooted.pl/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://websec.rooted.pl/" /><author><name>Dawid Skomski</name><uri>http://www.blogger.com/profile/02937543690676014189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/websecrooted" /><feedburner:info uri="websecrooted" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry gd:etag="W/&quot;DEQCR3k8eip7ImA9WhRVEEQ.&quot;"><id>tag:blogger.com,1999:blog-3245689738496809889.post-992367727685700541</id><published>2012-01-08T20:55:00.001+01:00</published><updated>2012-01-09T09:06:06.772+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-09T09:06:06.772+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="interesting" /><title>IT Security central point of conferences</title><summary type="html">Practically there is no place around the world focusing on IT Security conferences.

I did not know anything like this ever, so I created a calendar of events (most interesting from my point of view) on this blog.
Unfortunately, updates and keeping it fresh was too much time consuming so stopped him updating.

Fortunately, in the wild has appeard the great service secore.info, which aggregates &lt;img src="http://feeds.feedburner.com/~r/websecrooted/~4/qgscfz5wZ0o" height="1" width="1"/&gt;</summary><link rel="replies" type="text/html" href="http://websec.rooted.pl/2012/01/it-security-central-point-of.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/992367727685700541?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/992367727685700541?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/websecrooted/~3/qgscfz5wZ0o/it-security-central-point-of.html" title="IT Security central point of conferences" /><author><name>Dawid Skomski</name><uri>http://www.blogger.com/profile/02937543690676014189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://websec.rooted.pl/2012/01/it-security-central-point-of.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkIHRHs9fip7ImA9WhdSFk0.&quot;"><id>tag:blogger.com,1999:blog-3245689738496809889.post-4036476633681190187</id><published>2011-07-16T10:52:00.048+02:00</published><updated>2011-07-25T17:42:15.566+02:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2011-07-25T17:42:15.566+02:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="defense" /><category scheme="http://www.blogger.com/atom/ns#" term="html5" /><category scheme="http://www.blogger.com/atom/ns#" term="clickjacking" /><title>More accurate framebusting</title><summary type="html">
I would like to draw attention to use of framebusting in many websites. Modern browsers with HTML5 support require a different approach to this problem.

Briefly I would like to remind you that framebusting is a technique to protect against so called clickjacking (wiki).



Commonly there are used two methods to avoid this attack vector:

HTTP header X-FRAME-OPTIONS with values DENY or &lt;img src="http://feeds.feedburner.com/~r/websecrooted/~4/inXbBJsJ9uE" height="1" width="1"/&gt;</summary><link rel="replies" type="text/html" href="http://websec.rooted.pl/2011/07/more-accurate-framebusting.html#comment-form" title="1 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/4036476633681190187?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/4036476633681190187?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/websecrooted/~3/inXbBJsJ9uE/more-accurate-framebusting.html" title="More accurate framebusting" /><author><name>Dawid Skomski</name><uri>http://www.blogger.com/profile/02937543690676014189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>1</thr:total><feedburner:origLink>http://websec.rooted.pl/2011/07/more-accurate-framebusting.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkcFSXYyeCp7ImA9WhRVEUk.&quot;"><id>tag:blogger.com,1999:blog-3245689738496809889.post-2737687629387900387</id><published>2011-05-27T19:13:00.003+02:00</published><updated>2012-01-09T23:26:58.890+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-09T23:26:58.890+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="xss" /><category scheme="http://www.blogger.com/atom/ns#" term="bug" /><category scheme="http://www.blogger.com/atom/ns#" term="chrome" /><title>Chrome, anti-XSS filter bypass</title><summary type="html">In Chrome web browser was found the design flaw that can be used to make universal XSS attacks.
The bug is in the same time a browser feature because it is used for code completion, which was just poorly coded (i.e. missing something small such as a closed tag or quotation).

So in this code:
&amp;lt;img src=1 onerror=alert(1);character will be replaced to allow proper execution code snippet for example&lt;img src="http://feeds.feedburner.com/~r/websecrooted/~4/XKa2Y6v_JM0" height="1" width="1"/&gt;</summary><link rel="replies" type="text/html" href="http://websec.rooted.pl/2011/05/chrome-omijanie-filtru-anty-xss.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/2737687629387900387?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/2737687629387900387?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/websecrooted/~3/XKa2Y6v_JM0/chrome-omijanie-filtru-anty-xss.html" title="Chrome, anti-XSS filter bypass" /><author><name>Dawid Skomski</name><uri>http://www.blogger.com/profile/02937543690676014189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://websec.rooted.pl/2011/05/chrome-omijanie-filtru-anty-xss.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUIBRnw4fip7ImA9WhRVEUk.&quot;"><id>tag:blogger.com,1999:blog-3245689738496809889.post-7338971352669660188</id><published>2011-04-26T23:53:00.008+02:00</published><updated>2012-01-09T23:19:17.236+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-09T23:19:17.236+01:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="tools" /><title>Essential for pentester</title><summary type="html">I add to the stuff a few JavaScript scripts that can help in the rapid encoding or decoding of characters HTML and more (click)

There are only a few though but it was fast written and the list of scripts will increase.

If you need any additional tools or hand-saw things to have here or other proposals - let me know.&lt;img src="http://feeds.feedburner.com/~r/websecrooted/~4/5FeJdbk0L5E" height="1" width="1"/&gt;</summary><link rel="replies" type="text/html" href="http://websec.rooted.pl/2011/04/niezbednik-web-pentestera.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/7338971352669660188?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/7338971352669660188?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/websecrooted/~3/5FeJdbk0L5E/niezbednik-web-pentestera.html" title="Essential for pentester" /><author><name>Dawid Skomski</name><uri>http://www.blogger.com/profile/02937543690676014189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://websec.rooted.pl/2011/04/niezbednik-web-pentestera.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUUBQHs4cCp7ImA9WhRVEUk.&quot;"><id>tag:blogger.com,1999:blog-3245689738496809889.post-6114147839004577843</id><published>2011-04-17T11:51:00.001+02:00</published><updated>2012-01-09T23:14:11.538+01:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2012-01-09T23:14:11.538+01:00</app:edited><title>Welcome</title><summary type="html">It happened. I forced myself to breathe life into this site:)

First of all it should be mentioned a word about websec and why websec.

I don't like greetings so it will be brief.

WebSec is a special case of information security. Special because of the popularity of web applications. These days most of the technology arrangements "for the people" are created mainly in web technologies.

Why?

&lt;img src="http://feeds.feedburner.com/~r/websecrooted/~4/1oIZ3_GP8Rg" height="1" width="1"/&gt;</summary><link rel="replies" type="text/html" href="http://websec.rooted.pl/2011/04/test-ride.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/6114147839004577843?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/3245689738496809889/posts/default/6114147839004577843?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/websecrooted/~3/1oIZ3_GP8Rg/test-ride.html" title="Welcome" /><author><name>Dawid Skomski</name><uri>http://www.blogger.com/profile/02937543690676014189</uri><email>noreply@blogger.com</email><gd:image rel="http://schemas.google.com/g/2005#thumbnail" width="16" height="16" src="http://img2.blogblog.com/img/b16-rounded.gif" /></author><thr:total>0</thr:total><feedburner:origLink>http://websec.rooted.pl/2011/04/test-ride.html</feedburner:origLink></entry></feed>

