<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>pentesters.pl blog</title>
	<atom:link href="http://pentesterspl.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://pentesterspl.wordpress.com</link>
	<description>testy penetracyjne, testy bezpieczeństwa, analiza malware, analiza oprogramowania, bezpieczeństwo informacji, bezpieczeństwo IT</description>
	<lastBuildDate>Tue, 25 Jan 2011 10:55:31 +0000</lastBuildDate>
	<language>pl</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='pentesterspl.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>pentesters.pl blog</title>
		<link>http://pentesterspl.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://pentesterspl.wordpress.com/osd.xml" title="pentesters.pl blog" />
	<atom:link rel='hub' href='http://pentesterspl.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Advisory 1/2011</title>
		<link>http://pentesterspl.wordpress.com/2011/01/25/advisory-12011/</link>
		<comments>http://pentesterspl.wordpress.com/2011/01/25/advisory-12011/#comments</comments>
		<pubDate>Tue, 25 Jan 2011 10:54:09 +0000</pubDate>
		<dc:creator>pentesterspl1</dc:creator>
		
		<guid isPermaLink="false">http://pentesterspl.wordpress.com/?p=19</guid>
		<description><![CDATA[Application Piwik versions prior to 1.1 http://piwik.org/ Summary Multiple cross-site scripting issues exist in the Piwik software in versions prior to 1.1. These issues allow for reflective and persistent XSS attacks and could be used to attack the website’s administrator by an anonymous users of the Internet. Details The ‘url’ parameter of the piwik script [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pentesterspl.wordpress.com&amp;blog=11478821&amp;post=19&amp;subd=pentesterspl&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Application</strong><br />
Piwik versions prior to 1.1</p>
<p>http://piwik.org/</p>
<p><strong>Summary</strong><br />
Multiple cross-site scripting issues exist in the Piwik software in versions prior to 1.1. These issues allow for reflective and persistent XSS attacks and could be used to attack the website’s administrator by an anonymous users of the Internet.</p>
<p><strong>Details</strong><br />
The ‘url’ parameter of the piwik script seems to be not properly filtered. Therefore, a malicious content could be embedded in several places of the Piwik panel. This example illustrates the idea:<br />
1)    request for this URL on the piwik site:<br />
/piwik/piwik.php?idsite=1&amp;rec=1&amp;url=&#8221;&gt;&lt;script&gt;alert(document.cookie)&lt;/script&gt;&amp;res=1400&#215;1050&amp;h=8&amp;m=48&amp;s=30&amp;cookie=1&amp;urlref=&amp;rand=0.5656348866609716&amp;pdf=1&amp;qt=0&amp;realp=0&amp;wma=1&amp;dir=0&amp;fla=1&amp;java=1&amp;gears=0&amp;ag=0&amp;action_name=<br />
2)    once logged on to the panel, one should see the alert popup.<br />
This flaw is located in the LiveVisitors module. Other vulnerable modules:<br />
•    Actions-&gt;pages<br />
•    Visitors-&gt;log<br />
•    possible others</p>
<p><strong>Links</strong></p>
<p>http://piwik.org/blog/2011/01/piwik-1-1-security-advisory/</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/pentesterspl.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/pentesterspl.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/pentesterspl.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/pentesterspl.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/pentesterspl.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/pentesterspl.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/pentesterspl.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/pentesterspl.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/pentesterspl.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/pentesterspl.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/pentesterspl.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/pentesterspl.wordpress.com/19/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/pentesterspl.wordpress.com/19/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/pentesterspl.wordpress.com/19/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pentesterspl.wordpress.com&amp;blog=11478821&amp;post=19&amp;subd=pentesterspl&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://pentesterspl.wordpress.com/2011/01/25/advisory-12011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/482e024285a1b25764dc49157f41ac79?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">pentesterspl1</media:title>
		</media:content>
	</item>
		<item>
		<title>HW.txt</title>
		<link>http://pentesterspl.wordpress.com/2010/01/16/hello-world/</link>
		<comments>http://pentesterspl.wordpress.com/2010/01/16/hello-world/#comments</comments>
		<pubDate>Sat, 16 Jan 2010 21:08:25 +0000</pubDate>
		<dc:creator>whilter</dc:creator>
				<category><![CDATA[Inne]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Witaj na blogu pentesters.pl!<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pentesterspl.wordpress.com&amp;blog=11478821&amp;post=1&amp;subd=pentesterspl&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Witaj na blogu pentesters.pl!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/pentesterspl.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/pentesterspl.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/pentesterspl.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/pentesterspl.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/pentesterspl.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/pentesterspl.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/pentesterspl.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/pentesterspl.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/pentesterspl.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/pentesterspl.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/pentesterspl.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/pentesterspl.wordpress.com/1/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/pentesterspl.wordpress.com/1/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/pentesterspl.wordpress.com/1/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=pentesterspl.wordpress.com&amp;blog=11478821&amp;post=1&amp;subd=pentesterspl&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://pentesterspl.wordpress.com/2010/01/16/hello-world/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/ab720133d4a9524828cbca21b74e0616?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">whilter</media:title>
		</media:content>
	</item>
	</channel>
</rss>
