<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/rss2full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0">

<channel>
	<title>With DK</title>
	
	<link>http://www.withdk.com</link>
	<description>World of DK</description>
	<pubDate>Fri, 04 Apr 2008 10:44:48 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/WithDK" type="application/rss+xml" /><item>
		<title>OWASP Talk: PHP Code Analysis: Real World Examples</title>
		<link>http://feeds.feedburner.com/~r/WithDK/~3/254287890/</link>
		<comments>http://www.withdk.com/2008/03/19/owasp-talk-php-code-analysis-real-world-examples/#comments</comments>
		<pubDate>Wed, 19 Mar 2008 13:38:23 +0000</pubDate>
		<dc:creator>dk</dc:creator>
		
		<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/03/19/owasp-talk-php-code-analysis-real-world-examples/</guid>
		<description><![CDATA[
There have been some delays around the next London OWASP meeting, but its currently set for Thu, 3 Apr 2008.


If it all goes ahead with plan, I&#8217;ll be speaking on PHP Code Analysis, so if your around and have a night free please feel free to join in.
]]></description>
			<content:encoded><![CDATA[<p>
There have been some delays around the next <a href="http://www.owasp.org/index.php/London">London OWASP meeting,</a> but its currently set for Thu, 3 Apr 2008.
</p>
<p>
If it all goes ahead with plan, I&#8217;ll be speaking on PHP Code Analysis, so if your around and have a night free please feel free to join in.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/254287890" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/03/19/owasp-talk-php-code-analysis-real-world-examples/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.withdk.com/2008/03/19/owasp-talk-php-code-analysis-real-world-examples/</feedburner:origLink></item>
		<item>
		<title>Persists Software XUpload Buffer Overflow</title>
		<link>http://feeds.feedburner.com/~r/WithDK/~3/241538996/</link>
		<comments>http://www.withdk.com/2008/02/26/persists-software-xupload-buffer-overflow/#comments</comments>
		<pubDate>Tue, 26 Feb 2008 15:23:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/02/26/persists-software-xupload-buffer-overflow/</guid>
		<description><![CDATA[I discovered a buffer overflow in Persist Software XUpload package while researching ActiveX exploitation.
XUpload is prone to a buffer overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.
An exploit is in the wild. See the SecurityFocus advisory for more details.
]]></description>
			<content:encoded><![CDATA[<p>I discovered a buffer overflow in Persist Software XUpload</b> package while researching ActiveX exploitation.</p>
<p>XUpload is prone to a buffer overflow vulnerability because it fails to perform adequate boundary checks on user-supplied input.</p>
<p>An exploit is in the wild. See the <a href="http://www.securityfocus.com/bid/27456/info">SecurityFocus advisory</a> for more details.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/241538996" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/02/26/persists-software-xupload-buffer-overflow/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.withdk.com/2008/02/26/persists-software-xupload-buffer-overflow/</feedburner:origLink></item>
		<item>
		<title>Livelink UTF-7 XSS Vulnerability</title>
		<link>http://feeds.feedburner.com/~r/WithDK/~3/226565735/</link>
		<comments>http://www.withdk.com/2008/01/31/livelink-utf-7-xss-vulnerability/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 14:17:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/01/31/livelink-utf-7-xss-vulnerability/</guid>
		<description><![CDATA[
Release date: 31/Jan/2008
Last Modified: N/A
Author: David Kierznowski http://withdk.com
Application: Linklink ]]></description>
			<content:encoded><![CDATA[<p>
Release date: 31/Jan/2008<br />
Last Modified: N/A<br />
Author: David Kierznowski http://withdk.com<br />
Application: Linklink <= 9.7.0<br />
Risk: Medium
</p>
<p>
Full advisory available <a href="http://withdk.com/archives/livelink-utf7-xss-advisory.pdf">here</a>.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/226565735" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/01/31/livelink-utf-7-xss-vulnerability/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.withdk.com/2008/01/31/livelink-utf-7-xss-vulnerability/</feedburner:origLink></item>
		<item>
		<title>Textlinkads SQL Injection Vulnerability released</title>
		<link>http://feeds.feedburner.com/~r/WithDK/~3/218891006/</link>
		<comments>http://www.withdk.com/2008/01/18/textlinkads-sql-injection-vulnerability-released/#comments</comments>
		<pubDate>Fri, 18 Jan 2008 14:41:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/01/18/textlinkads-sql-injection-vulnerability-released/</guid>
		<description><![CDATA[
BlogSecurity: WP Textlinkads SQL Injection Advisory


I left it with them for 2 weeks before disclosing the advisory. It was fixed within 24hrs of release.
]]></description>
			<content:encoded><![CDATA[<p>
<a href="http://blogsecurity.net/wordpress/wp-textlinkads-plugin-sql-injection-vulnerability/">BlogSecurity: WP Textlinkads SQL Injection Advisory</a>
</p>
<p>
I left it with them for 2 weeks before disclosing the advisory. It was fixed within 24hrs of release.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/218891006" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/01/18/textlinkads-sql-injection-vulnerability-released/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.withdk.com/2008/01/18/textlinkads-sql-injection-vulnerability-released/</feedburner:origLink></item>
		<item>
		<title>Full Disclosure Saga Continues</title>
		<link>http://feeds.feedburner.com/~r/WithDK/~3/216520100/</link>
		<comments>http://www.withdk.com/2008/01/14/full-disclosure-saga-continues/#comments</comments>
		<pubDate>Mon, 14 Jan 2008 16:46:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/01/14/full-disclosure-saga-continues/</guid>
		<description><![CDATA[So its now been 20 days since finding and disclosing a criticial SQL injection issue that has the potential to affect 20,000 websites. See my first post here.

I have bounced a few E-Mails off the CEO, and he has kept in touch, however, nothing yet. So that means I have now left 20K of websites [...]]]></description>
			<content:encoded><![CDATA[<p>So its now been 20 days since finding and disclosing a criticial SQL injection issue that has the potential to affect 20,000 websites. See my first post <a href="http://www.withdk.com/2008/01/03/fire-and-flames/">here</a>.</p>
<p>
I have bounced a few E-Mails off the CEO, and he has kept in touch, however, nothing yet. So that means I have now left 20K of websites at risk for 20 days and counting&#8230;
</p>
<p>
The bigger players (Microsoft, Cisco etc) with more experience have procedures in place to deal with security issues like this, so &quot;responsible&quot; disclosure makes sense, but by the time this advisory is released, I would have spent the same amount of time (if not more) disclosing the vulnerability then actually researching the vulnerability.
</p>
<p>
These things are never as black and white as they first appear.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/216520100" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/01/14/full-disclosure-saga-continues/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.withdk.com/2008/01/14/full-disclosure-saga-continues/</feedburner:origLink></item>
		<item>
		<title>Fire and Flames</title>
		<link>http://feeds.feedburner.com/~r/WithDK/~3/210593440/</link>
		<comments>http://www.withdk.com/2008/01/03/fire-and-flames/#comments</comments>
		<pubDate>Thu, 03 Jan 2008 16:28:22 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2008/01/03/fire-and-flames/</guid>
		<description><![CDATA[I found an SQL Injection vulnerability in a peice of software that according to the site may affect over 20,000 websites. I have kept the advisory and proof of concept exploit private, but am curious how long it will take for the vendor to release a fix.
I have often felt that full-disclosure (FD) is the [...]]]></description>
			<content:encoded><![CDATA[<p>I found an SQL Injection vulnerability in a peice of software that according to the site may affect over 20,000 websites. I have kept the advisory and proof of concept exploit private, but am curious how long it will take for the vendor to release a fix.</p>
<p>I have often felt that full-disclosure (FD) is the way forward. In other words, we release first and ask questions later. This approach appears to have &#8216;inspired&#8217; vendors to patch more efficiently in the past, but at the same time it alerts the bad guys to write more exploits!</p>
<p>The argument by FD is that attackers may already be exploiting the vulnerability in the wild and that by releasing FD the security researcher is merely putting out a warning - as one would if a dam wall was about to collapse.</p>
<p>If we can measure and detect attacks on a global scale this argument may be addressed and debated in a better light. I do think FD can be terribly destructive if used by attention seekers who may choose not to release the advisory to the vendor at all.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/210593440" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2008/01/03/fire-and-flames/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.withdk.com/2008/01/03/fire-and-flames/</feedburner:origLink></item>
		<item>
		<title>Added new content</title>
		<link>http://feeds.feedburner.com/~r/WithDK/~3/206295689/</link>
		<comments>http://www.withdk.com/2007/12/26/added-new-content/#comments</comments>
		<pubDate>Wed, 26 Dec 2007 00:44:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/2007/12/26/added-new-content/</guid>
		<description><![CDATA[Its taking longer to find, order and place content then originally thought, however, it really gives one perspective with regards to achievements.
I have added content to both the Articles and News/Interview Sections.

Content Added
In Articles:
    * Paper: Ad-Jacking - XSSing for Fun and Profit
    * Presentation: Automated Web FOO or [...]]]></description>
			<content:encoded><![CDATA[<p>Its taking longer to find, order and place content then originally thought, however, it really gives one perspective with regards to achievements.</p>
<p>I have added content to both the <a href="http://www.withdk.com/articles/">Articles</a> and <a href="http://www.withdk.com/news/">News/Interview</a> Sections.</p>
<p>
Content Added<br />
In Articles:<br />
    * Paper: Ad-Jacking - XSSing for Fun and Profit<br />
    * Presentation: Automated Web FOO or FUD?<br />
In News &#038; Interviews:<br />
    * Survey: Finds Most WordPress Blogs Vulnerable<br />
    * Vul: Adobe Acrabat JavaScript Vulnerabilities</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/206295689" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2007/12/26/added-new-content/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.withdk.com/2007/12/26/added-new-content/</feedburner:origLink></item>
		<item>
		<title>WithDK site in progress</title>
		<link>http://feeds.feedburner.com/~r/WithDK/~3/205321681/</link>
		<comments>http://www.withdk.com/2007/12/23/withdk-site-in-progress/#comments</comments>
		<pubDate>Sun, 23 Dec 2007 22:39:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Archives]]></category>

		<guid isPermaLink="false">http://www.withdk.com/23/12/2007/test-post/</guid>
		<description><![CDATA[WithDK.com site development in progress.
]]></description>
			<content:encoded><![CDATA[<p>WithDK.com site development in progress.</p>
<img src="http://feeds.feedburner.com/~r/WithDK/~4/205321681" height="1" width="1"/>]]></content:encoded>
			<wfw:commentRss>http://www.withdk.com/2007/12/23/withdk-site-in-progress/feed/</wfw:commentRss>
		<feedburner:origLink>http://www.withdk.com/2007/12/23/withdk-site-in-progress/</feedburner:origLink></item>
	</channel>
</rss>
