<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Websecurity.ro bloggers</title>
	<atom:link href="http://websecure.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://websecure.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Thu, 29 Nov 2007 09:12:36 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='websecure.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/01f54ba67264ad758310f71d32f1bad8?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>Websecurity.ro bloggers</title>
		<link>http://websecure.wordpress.com</link>
	</image>
			<item>
		<title>We&#8217;ve moved</title>
		<link>http://websecure.wordpress.com/2007/11/08/weve-moved/</link>
		<comments>http://websecure.wordpress.com/2007/11/08/weve-moved/#comments</comments>
		<pubDate>Thu, 08 Nov 2007 13:23:20 +0000</pubDate>
		<dc:creator>websecure</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://websecure.wordpress.com/2007/11/08/weve-moved/</guid>
		<description><![CDATA[We&#8217;ve moved to
http://websecurity.ro/blog
http://websecurity.ro
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=websecure.wordpress.com&blog=1960799&post=6&subd=websecure&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>We&#8217;ve moved to</p>
<p><a href="http://websecurity.ro/blog" title="Websecurity.ro">http://websecurity.ro/blog</a></p>
<p><a href="http://websecurity.ro" title="Websecurity.ro">http://websecurity.ro</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/websecure.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/websecure.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/websecure.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/websecure.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/websecure.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/websecure.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/websecure.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/websecure.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/websecure.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/websecure.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/websecure.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/websecure.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=websecure.wordpress.com&blog=1960799&post=6&subd=websecure&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://websecure.wordpress.com/2007/11/08/weve-moved/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6f06a5711e5c58a676bc668db7763f9e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">websecure</media:title>
		</media:content>
	</item>
		<item>
		<title>Another random LFI</title>
		<link>http://websecure.wordpress.com/2007/10/21/3/</link>
		<comments>http://websecure.wordpress.com/2007/10/21/3/#comments</comments>
		<pubDate>Sun, 21 Oct 2007 23:26:46 +0000</pubDate>
		<dc:creator>websecure</dc:creator>
				<category><![CDATA[lfi]]></category>
		<category><![CDATA[eLouai's Force Download]]></category>
		<category><![CDATA[plaint text passwords]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://websecure.wordpress.com/2007/10/21/3/</guid>
		<description><![CDATA[
// Script Title: eLouai&#8217;s Force Download
// Home Script: http://elouai.com/force-download.php
// Vuln Type: Local File Inclusion / LFI
// Discovered by: The_PitBull aNd iNs
// Bug:
$filename = $_GET['file'];
// PoC: http://www.site.com/force-download.php?file=[LFI]
// D0rk: allinurl: force-download।php?file=
So i first looked at the google dork. Seems ok, but i preferred to change it a little bit to:
allinurl:force-download.php.file=
And i started to play around with it.
Started [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=websecure.wordpress.com&blog=1960799&post=3&subd=websecure&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><font face="verdana" size="1"><br />
// Script Title: eLouai&#8217;s Force Download<br />
// Home Script: http://elouai.com/force-download.php<br />
// Vuln Type: Local File Inclusion / LFI<br />
// Discovered by: The_PitBull aNd iNs<br />
// Bug:<br />
$filename = $_GET['file'];<br />
// PoC: http://www.site.com/force-download.php?file=[LFI]<br />
// D0rk: allinurl: force-download।php?file=</p>
<p>So i first looked at the google dork. Seems ok, but i preferred to change it a little bit to:</font><br />
allinurl:force-download.php.file=</p>
<p>And i started to play around with it.<br />
Started my firefox turned on hackbar view on, took the first result in google (i never do this, but this time i was high a bit) and started to test the site.<br />
I saw that i can include the index.php file like this</p>
<p>http://vulnerabile.site/force-download.php?file=index.php</p>
<p>And i could download the file. Wow! This is nice. What does this actually mean ?<br />
That the file is not included in the script, and the headers were similar to this:</p>
<p>Content-Disposition: attachment; filename=index.php</p>
<p>Hmm, i cannot use log poisoning and including&#8230; damn.<br />
I&#8217;m looking around though the files and i&#8217;m trying to see all the saved passwords and information that could help me.<br />
Interesting files like: config.php, config.inc.php, db.php.<br />
I can see mysql passwords, smtp servers, everything.<br />
I&#8217;m getting bored with this site and i go looking for another one.</p>
<p>I finally find an interesting site. I see that the /admin directory exists and automatically redirects me to login.php.<br />
I&#8217;m thinking, are they stupid enough to put the password in plain text ? A few seconds and&#8230; yes they are.<br />
Hello, i have admin over the whole site. Cool!</p>
<p>No defacement. I don&#8217;t like full defacements. Only a few scary clowns pictures added.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/websecure.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/websecure.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/websecure.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/websecure.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/websecure.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/websecure.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/websecure.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/websecure.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/websecure.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/websecure.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/websecure.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/websecure.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=websecure.wordpress.com&blog=1960799&post=3&subd=websecure&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://websecure.wordpress.com/2007/10/21/3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6f06a5711e5c58a676bc668db7763f9e?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">websecure</media:title>
		</media:content>
	</item>
	</channel>
</rss>