<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ascii for Breakfast &#187; Security Assessment</title>
	<atom:link href="http://www.xenuser.org/tag/security-assessment/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.xenuser.org</link>
	<description></description>
	<lastBuildDate>Tue, 29 Nov 2011 23:19:03 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.4</generator>
		<item>
		<title>Simple LAN Scanner 1.0 released</title>
		<link>http://www.xenuser.org/2011/01/08/simple-lan-scanner-1-0-released/</link>
		<comments>http://www.xenuser.org/2011/01/08/simple-lan-scanner-1-0-released/#comments</comments>
		<pubDate>Sat, 08 Jan 2011 13:15:53 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security in general]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[discover]]></category>
		<category><![CDATA[IP]]></category>
		<category><![CDATA[LAN Scanner]]></category>
		<category><![CDATA[local area network]]></category>
		<category><![CDATA[local network]]></category>
		<category><![CDATA[MAC]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Simple LAN Scanner]]></category>
		<category><![CDATA[tool]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=1326</guid>
		<description><![CDATA[Today I am releasing my Simple LAN Scanner 1.0 (08th January 2011). [Download] Description The Simple LAN Scanner is a very simple LAN scanner written in Python. It scans the local network and tries to give you the MAC and IP addresses of the discovered running systems. Furthermore it creates a small log file at [...]]]></description>
			<content:encoded><![CDATA[<p>Today I am releasing my Simple LAN Scanner 1.0 (08th January 2011).<br />
[<a href="http://www.xenuser.org/my-tools/" target="_blank">Download</a>]</p>
<p><strong>Description</strong><br />
The Simple LAN Scanner is a very simple LAN scanner written in Python. It scans the local network and tries to give you the MAC and IP addresses of the discovered running systems. Furthermore it creates a small log file at the end of the scan.</p>
<p><strong>Usage</strong><br />
sudo ./simple_lan_scan.py &#8211;network=&lt;your network&gt;</p>
<p><strong>Usage example</strong><br />
sudo ./simple_lan_scan.py &#8211;network=192.168.1.0/24</p>
<p><strong>Installation</strong><br />
Make sure you install the package python-scapy before you run the Simple LAN Scanner.</p>
<p><strong>Feature list</strong><br />
- Tries to give you the MACs and IPs of discovered running systems.<br />
- Creates a small log file.</p>
<p><strong>Some notes</strong><br />
- Tested with Python 2.6.5.<br />
- Modify, distribute, share and copy the code in any way you like!<br />
- Please note that this tool was created for educational purposes only.<br />
- Power to teh c0ws! <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=1326" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2011/01/08/simple-lan-scanner-1-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple Local File Inclusion Vulnerability Scanner version 1.0 released</title>
		<link>http://www.xenuser.org/2010/12/29/simple-local-file-inclusion-vulnerability-scanner-version-1-0-released/</link>
		<comments>http://www.xenuser.org/2010/12/29/simple-local-file-inclusion-vulnerability-scanner-version-1-0-released/#comments</comments>
		<pubDate>Wed, 29 Dec 2010 16:52:46 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[LFI]]></category>
		<category><![CDATA[Security in general]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[local file inclusion]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Simple Local File Inclusion Vulnerability Scanner]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[vulnerability scanner]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=1309</guid>
		<description><![CDATA[Today I am releasing my Simple Local File Inclusion Vulnerability Scanner 1.0 (29th December 2010). [Download] Description The Simple Local File Inclusion Vulnerability Scanner helps you to find LFI vulnerabilities. Usage ./lfi_scanner.py &#8211;url= Usage example ./lfi_scanner.py &#8211;url=&#8221;http://www.example.com/page.php?file=main&#8221; Usage notes - Always use http://…. - This tool does not work with SEO URLs, such as http://www.example.com/news-about-the-internet/. [...]]]></description>
			<content:encoded><![CDATA[<p>Today I am releasing my Simple Local File Inclusion Vulnerability Scanner 1.0 (29th December 2010).<br />
[<a href="http://www.xenuser.org/my-tools/" target="_blank">Download</a>]</p>
<p><strong>Description</strong><br />
The Simple Local File Inclusion Vulnerability Scanner helps you to find LFI vulnerabilities.</p>
<p><strong>Usage</strong><br />
./lfi_scanner.py &#8211;url=</p>
<p><strong>U</strong><span style="font-size: 13.3333px;"><strong>sage example</strong></span><br />
./lfi_scanner.py &#8211;url=&#8221;http://www.example.com/page.php?file=main&#8221;</p>
<p><strong>Usage notes</strong><br />
- Always use http://….<br />
- This tool does not work with SEO URLs, such as http://www.example.com/news-about-the-internet/.<br />
- If you only have a SEO URL, try to find out the real URL which contents parameters.</p>
<p><strong>Feature list</strong><br />
- Provides a random user agent for the connection.<br />
- Checks if a connection to the target can be established.<br />
- Tries to catch most errors with error handling.<br />
- Contains a LFI vulnerability scanner.<br />
- Finds out how a possible LFI vulnerability can be exploited (e.g. directory depth).<br />
- Supports nullbytes!<br />
- Supports common *nix targets, but no Windows systems.</p>
<p><strong>Known issues</strong><br />
- This tool is only able to handle “simple” LFI vulnerabilities, but not complex ones.<br />
- Like most other LFI scanners, this tool here also has trouble with handling certain server responses.</p>
<p><strong>Some notes</strong><br />
- Tested with Python 2.6.5.<br />
- Modify, distribute, share and copy the code in any way you like!<br />
- Please note that this tool was created for educational purposes only.<br />
- Do not use this tool in an illegal way. Know and respect your local laws.<br />
- Only use this tool for legal purposes, such as pentesting your own website<br />
- I am not responsible if you cause any damage or break the law.<br />
- Power to teh c0ws!</p>
<p><strong>Screenshot</strong></p>
<div id="attachment_1311" class="wp-caption alignleft" style="width: 308px"><a href="http://www.xenuser.org/wp-content/uploads/2010/12/lfi_scanner.png"><img class="size-medium wp-image-1311" title="lfi_scanner" src="http://www.xenuser.org/wp-content/uploads/2010/12/lfi_scanner-298x300.png" alt="Simple Local File Inclusion Vulnerability Scanner screenshot" width="298" height="300" /></a>
<p class="wp-caption-text">Simple Local File Inclusion Vulnerability Scanner screenshot</p>
</div>
<p> <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=1309" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2010/12/29/simple-local-file-inclusion-vulnerability-scanner-version-1-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple Local File Inclusion Exploiter version 1.1 released</title>
		<link>http://www.xenuser.org/2010/11/23/simple-local-file-inclusion-exploiter-version-1-1-released/</link>
		<comments>http://www.xenuser.org/2010/11/23/simple-local-file-inclusion-exploiter-version-1-1-released/#comments</comments>
		<pubDate>Tue, 23 Nov 2010 21:51:27 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[local file inclusion]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Simple Local Fiile Inclusion Exploiter]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[vulnerability scanner]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=1255</guid>
		<description><![CDATA[I just uploaded a new version of the Simple Local File Inclusion Exploiter, version 1.1. It was updated with some new user agents, &#8220;interesting files&#8221; and now creates a small log file. Just visit the &#8220;My Tools&#8221; section for the download link.]]></description>
			<content:encoded><![CDATA[<p>I just uploaded a new version of the Simple Local File Inclusion Exploiter, version 1.1. It was updated with some new user agents, &#8220;interesting files&#8221; and now creates a small log file.</p>
<p>Just visit the &#8220;My Tools&#8221; section for the download link. <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=1255" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2010/11/23/simple-local-file-inclusion-exploiter-version-1-1-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple Local File Inclusion Exploiter version 1.0 released</title>
		<link>http://www.xenuser.org/2010/11/21/simple-local-file-inclusion-exploiter-version-1-0-released/</link>
		<comments>http://www.xenuser.org/2010/11/21/simple-local-file-inclusion-exploiter-version-1-0-released/#comments</comments>
		<pubDate>Sun, 21 Nov 2010 18:20:02 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[Tools]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[local file inclusion]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Simple Local File Inclusion Scanner]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[vulnerability scanner]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=1248</guid>
		<description><![CDATA[Today I am releasing my Simple Local File Inclusion Exploiter 1.0 (21th November 2010). [Download] Description The Simple Local File Inclusion Exploiter helps you to exploit LFI vulnerabilities. After you found one, simply pass the URL of the affected website and the vulnerable parameter to this tool. You can also use this tool to scan [...]]]></description>
			<content:encoded><![CDATA[<p>Today I am releasing my Simple Local File Inclusion Exploiter 1.0 (21th November 2010).<br />
[<a href="http://www.xenuser.org/my-tools/" target="_blank">Download</a>]</p>
<p><strong>Description</strong><br />
The Simple Local File Inclusion Exploiter helps you to exploit LFI vulnerabilities. After you found one, simply pass the URL of the affected website and the vulnerable parameter to this tool. You can also use this tool to scan a parameter of an ULR for a LFI vulnerability.</p>
<p><strong>Usage</strong><br />
./lfi_sploiter.py &#8211;exploit-url= &#8211;vulnerable-parameter=</p>
<p><strong>Usage example</strong><br />
./lfi_sploiter.py &#8211;exploit-url=http://www.example.com/page.php?file=main &#8211;vulnerable-parameter=file</p>
<p><strong>Usage notes</strong><br />
- Always use http://&#8230;.<br />
- When you pass a vulnerable parameter, this tool assumes that it is really vulnerable.<br />
- If you do not know if a parameter is vulnerable, simply pass it to this script and let the scanner have a look.<br />
- Only use one vulnerable parameter at once.<br />
- This tool does not work with SEO URLs, such as http://www.example.com/news-about-the-internet/.<br />
- If you only have a SEO URL, try to find out the real URL which contents parameters.</p>
<p><strong>Feature list</strong><br />
- Provides a random user agent for the connection.<br />
- Checks if a connection to the target can be established.<br />
- Tries catch most errors with error handling.<br />
- Contains a LFI scanner (only scans one parameter at once).<br />
- Finds out how a LFI vulnerability can be exploited (e.g. directory depth).<br />
- Supports nullbytes!<br />
- Exploit features: Dumps a list of interesting files to your hard disk.<br />
- Supports common *nix targets, but no Windows systems.</p>
<p><strong>Known issues</strong><br />
- I know there is more about LFI than it is covered in this tool. But this is the first release,<br />
and more features will be implemented in future versions.<br />
- This tool is only able to handle &#8220;simple&#8221; LFI vulnerabilities, but not complex ones. For example: Some LFI vulnerabilities consist of two URL parameters or require to find a way around filters. In those cases, this tool unfortunately does not work.<br />
- Like most other LFI exploiter / scanner, this tool here also has problems with handling certain server responses. So this tool does not work with every website.</p>
<p><strong>Some notes</strong><br />
- Tested with Python 2.6.5.<br />
- Modify, distribute, share and copy the code in any way you like!<br />
- Please note that this tool was created for educational purposes only.<br />
- Do not use this tool in an illegal way. Know and respect your local laws.<br />
- Only use this tool for legal purposes, such as pentesting your own website <img src='http://www.xenuser.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /><br />
- I am not responsible if you cause any damage or break the law.<br />
- Power to teh c0ws!</p>
<p><strong>Screenshot</strong></p>
<div id="attachment_1252" class="wp-caption alignleft" style="width: 297px"><a href="http://www.xenuser.org/wp-content/uploads/2010/11/lfi_sploiter-1_0-screenshot.png"><img class="size-medium wp-image-1252" title="lfi_sploiter-1_0-screenshot" src="http://www.xenuser.org/wp-content/uploads/2010/11/lfi_sploiter-1_0-screenshot-287x300.png" alt="Simple Local File Inclusion Exploiter screenshot" width="287" height="300" /></a>
<p class="wp-caption-text">Simple Local File Inclusion Exploiter screenshot</p>
</div>
<p> <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=1248" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2010/11/21/simple-local-file-inclusion-exploiter-version-1-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple SQL Injection Vulnerability Scanner 0.5 released</title>
		<link>http://www.xenuser.org/2010/06/17/simple-sql-injection-vulnerability-scanner-0-5-released/</link>
		<comments>http://www.xenuser.org/2010/06/17/simple-sql-injection-vulnerability-scanner-0-5-released/#comments</comments>
		<pubDate>Thu, 17 Jun 2010 21:15:45 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[column fuzzer]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Simple SQL Injection Vulnerability Scanner]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[vulnerability scanner]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=947</guid>
		<description><![CDATA[Today I am releasing version 0.5 of my Simple SQL Injection Vulnerability Scanner. [Download here] It contains all the features from the first released version 0.3 and now contains &#8211; in addition &#8211; a column fuzzer. Simply start a scan by using python sqli_scanner.py -u &#8220;target&#8221; and then start fuzzing by using the parameter -fuzz [...]]]></description>
			<content:encoded><![CDATA[<p>Today I am releasing version 0.5 of my Simple SQL Injection Vulnerability Scanner.<br />
[<a href="http://www.xenuser.org/my-tools/" target="_blank">Download here</a>]</p>
<p>It contains all the features from the first released version 0.3 and now contains &#8211; in addition &#8211; a column fuzzer. Simply start a scan by using python sqli_scanner.py -u &#8220;target&#8221; and then start fuzzing by using the parameter -fuzz &#8220;exploit url&#8221;. The exploit url will be provided by the scanner (when a vulnerability was found). <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=947" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2010/06/17/simple-sql-injection-vulnerability-scanner-0-5-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Simple SQL Injection Vulnerability Scanner 0.3 released</title>
		<link>http://www.xenuser.org/2010/06/03/simple-sql-injection-vulnerability-scanner-version-0-3-released/</link>
		<comments>http://www.xenuser.org/2010/06/03/simple-sql-injection-vulnerability-scanner-version-0-3-released/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 17:59:43 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[Python]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Simple SQL Injection Vulnerability Scanner]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[vulnerability scanner]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=879</guid>
		<description><![CDATA[Today I am releasing my Simple SQL Injection Vulnerability Scanner (version 0.3, not 1.0 since it contains not many features). [Download here] Description The Simple SQL Injection Vulnerability Scanner helps you to find SQL injection vulnerabilities within your website. Simply provide an URL and let the tool do all the work. Features - Scan a [...]]]></description>
			<content:encoded><![CDATA[<p>Today I am releasing my Simple SQL Injection Vulnerability Scanner (version 0.3, not 1.0 since it contains not many features).<br />
[<a href="http://www.xenuser.org/my-tools/" target="_self">Download here</a>]</p>
<p><strong>Description</strong><br />
The Simple SQL Injection Vulnerability Scanner helps you to find SQL injection vulnerabilities within your website. Simply provide an URL and let the tool do all the work.</p>
<p><strong>Features</strong><br />
- Scan a single URL<br />
- Detect SQL injection vulnerabilities<br />
- User agent for web requests<br />
- User friendly (easy to use, everything is automated)<br />
- Error handling for http requests<br />
- Display a short scan report<br />
- Check if the provided URL is reachable</p>
<p><strong>Additional information</strong><br />
Written in Python (less than 400 lines).</p>
<p><strong>Usage</strong><br />
<em>python sqli_scanner.py -u “http://target/index.php?var1=x&amp;var2=y″</em></p>
<p><strong>Disclaimer</strong><br />
This tool was written for educational and penetration testing purposes. Only check websites you are allowed to test, e.g. your own or one of your customers/friends. I am not responsible for any damage you or my script could cause. Please know and respect your local laws.</p>
<p><strong>Known issue</strong><br />
Sometimes the target webserver throws back specific errors (403, 500 etc.). The Simple SQL Injection Vulnerability Scanner then fails to find SQL injection vulnerabilities.</p>
<p><strong>Screenshot</strong></p>
<div id="attachment_883" class="wp-caption aligncenter" style="width: 287px"><a href="http://www.xenuser.org/wp-content/uploads/2010/06/simple_sqli_scanner.png"><img class="size-medium wp-image-883" title="Simple SQL Injection Vulnerability Scanner - sample output" src="http://www.xenuser.org/wp-content/uploads/2010/06/simple_sqli_scanner-277x300.png" alt="Simple SQL Injection Vulnerability Scanner - sample output" width="277" height="300" /></a>
<p class="wp-caption-text">Simple SQL Injection Vulnerability Scanner - sample output</p>
</div>
<p> <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=879" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2010/06/03/simple-sql-injection-vulnerability-scanner-version-0-3-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Premium addons/extensions/plugins for Joomla, WordPress and other popular CMS?</title>
		<link>http://www.xenuser.org/2010/05/15/premium-addonsextensionsplugins-for-joomla-wordpress-and-other-popular-cms/</link>
		<comments>http://www.xenuser.org/2010/05/15/premium-addonsextensionsplugins-for-joomla-wordpress-and-other-popular-cms/#comments</comments>
		<pubDate>Fri, 14 May 2010 23:17:11 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[Security in general]]></category>
		<category><![CDATA[CMS]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[local file inclusion]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[premium extensions]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[webmaster]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=697</guid>
		<description><![CDATA[What if there was a project which checks all available extensions for popular CMS (such as Joomla or WordPress) for vulnerabilities and therefore creates a list of &#8220;trusted&#8221; and secure plugins on which ppl can rely on? During the last weeks I spent much time thinking about the security of websites in general. While many [...]]]></description>
			<content:encoded><![CDATA[<p><strong>What if there was a project which checks all available extensions for popular CMS (such as Joomla or WordPress) for vulnerabilities and therefore creates a list of &#8220;trusted&#8221; and secure plugins on which ppl can rely on?</strong></p>
<p>During the last weeks I spent much time thinking about the security of websites in general. While many webmasters are unaware of many security threads and simply don&#8217;t possess much knowledge in this area, a lot of them welcome popular CMS (such as Joomla, WordPress, Drupal etc.) and use addons to enhance their sites.</p>
<p>What some of them forget is to check if the used software is vulnerable in any way. The result is that thousands of new insecure websites are created every day and can be abused easily in many ways. I find it very shocking that even large companies rely on the script vendors and store sensitive company/customer data in the website. One heavy case I was able to witness is a component supplier for the German car industry.</p>
<p>While the corporation itself seems to be very large, their website was made by a freelancer. He uses a well known CMS with a few modifications and commercial themes/layouts. While browsing the website it was obvious that there might be several SQL injection vulnerabilities which allow attackers to access the whole database and obtain information which can be used for industrial spying.</p>
<p>But it is so easy to check if the own website is vulnerable to the most common attacks (SQL injection, local/remote file inclusion, XSS, CSRF, information disclosure, weak passwords, false software configuration). A good beginning would be to simply browse vulnerability databases. Or googling for &#8220;software product name vulnerability&#8221;. Or asking someone with security knowledge to check the own website. Or learning about the most popular web vulnerabilities and checking the website yourself.</p>
<p>I find it rather sad to see that so many website owners fail to do so. More said is probably the fact that you can&#8217;t even make them responsible for not knowing much about IT security since not everyone is aware of such issues or does have the necessary technology affinity for knowing such stuff.</p>
<p>When I have learned something during the past weeks (except the stuff for my final exams <img src='http://www.xenuser.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  ), then it is the fact that even very experienced webmasters/users/developers may simply not be familiar with web security. While doing some vulnerability research for fun I was given the opportunity to get in contact with many security enthusiasts, security professionals and developers (e.g. for Joomla components). Sometimes it took me many mails to explain to them how their software is vulnerable and how they can fix their products. Some of them even sell their software for a lot of money. And this is in fact a bad thing.</p>
<p>Imagine all the plugins for popular CMS which are released daily &#8211; and how many might be vulnerable to simple attacks.</p>
<p>How can normal webmasters be expected to keep up with the daily amount of information and recently published vulnerabilities?</p>
<p>So when building a new website, many of them simply download the CMS (e.g. Joomla), some required components (let&#8217;s say a gallery and guestbook component) and a cool theme. The new website can be completed within hours and the results are still awesome. But maybe also &#8220;awesome&#8221; insecure.</p>
<p>Especially when someone sells a website to a customer who has no IT knowledge at all this can be a very huge problem. They most probably never update their scripts and you can imagine what problems may occur in such cases.</p>
<p>So, what is the solution? How to fight the problem that there are so many plugins/extensions for popular CMS and so many of them might be vulnerable?</p>
<p>One idea might be to found a new project which contains a list of checked extensions. As soon as a new plugin is released the members of this project check it for vulnerabilities and rate it as secure when all tests are passed.</p>
<p>The result would be a list of extensions which were checked by people who are familiar with web security. We then would have a &#8220;trusted list of secure software extensions&#8221; and everyone can rely on it. Of course new software versions of existing plugins also have to be tested and the perfection would be that software vendors let their software be checked first before they release it.</p>
<p>While this might be a good idea this would take many volunteers who are a) competent enough to perform such tests and b) who are active on regular basis. Furthermore such a project should be supported by both the software and security industries.</p>
<p>Maybe there will be such a project one day and maybe I will even start it one day by myself.</p>
<p>Simply the idea of having a list of secure plugins &#8211; no matter for which CMS &#8211;  is awesome enough, isn&#8217;t it? <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=697" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2010/05/15/premium-addonsextensionsplugins-for-joomla-wordpress-and-other-popular-cms/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Google Skipfish version 1.34b released</title>
		<link>http://www.xenuser.org/2010/05/14/google-skipfish-version-1-34b-released/</link>
		<comments>http://www.xenuser.org/2010/05/14/google-skipfish-version-1-34b-released/#comments</comments>
		<pubDate>Fri, 14 May 2010 15:08:27 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[LFI]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Security in general]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[html code injection]]></category>
		<category><![CDATA[local file inclusion]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Skipfish]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Vulnerability Research]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=683</guid>
		<description><![CDATA[On the 6th May 2010 a new version of Google Skipfish (penetration testing tool/vulnerability scanner) was released. View the changelog here. Download it here. According to the changelog not many things were changed.]]></description>
			<content:encoded><![CDATA[<p>On the 6th May 2010 a new version of Google Skipfish (penetration testing tool/vulnerability scanner) was released.</p>
<p>View the changelog <a href="http://www.sfr-fresh.com/unix/privat/skipfish-1.34b.tgz:a/skipfish/ChangeLog" target="_blank">here</a>.</p>
<p>Download it <a href="http://code.google.com/p/skipfish/downloads/list" target="_blank">here</a>.</p>
<p>According to the changelog not many things were changed. <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=683" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2010/05/14/google-skipfish-version-1-34b-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Penetration Testing with Google&#8217;s Skipfish (Debian/Ubuntu)</title>
		<link>http://www.xenuser.org/2010/04/29/penetration-testing-with-googles-skipfish-debianubuntu/</link>
		<comments>http://www.xenuser.org/2010/04/29/penetration-testing-with-googles-skipfish-debianubuntu/#comments</comments>
		<pubDate>Thu, 29 Apr 2010 18:47:43 +0000</pubDate>
		<dc:creator>valentin</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Security in general]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[html code injection]]></category>
		<category><![CDATA[Penetration Testing]]></category>
		<category><![CDATA[scanner]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security Assessment]]></category>
		<category><![CDATA[Skipfish]]></category>
		<category><![CDATA[sql injection]]></category>
		<category><![CDATA[tool]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[Vulnerability Research]]></category>

		<guid isPermaLink="false">http://www.xenuser.org/?p=568</guid>
		<description><![CDATA[I recently had the time to test Google&#8217;s Skipfish. It is a fully automated penetration testing tool and was just published some weeks ago. This little tutorial will show Debian/Ubuntu users how to install it and perform the first test. I. Introduction Tools like Nessus and Nmap are indispensable when it comes down to security [...]]]></description>
			<content:encoded><![CDATA[<p>I recently had the time to test Google&#8217;s Skipfish. It is a fully automated penetration testing tool and was just published some weeks ago.</p>
<p>This little tutorial will show Debian/Ubuntu users how to install it and perform the first test.</p>
<p><strong>I. Introduction</strong></p>
<p>Tools like Nessus and Nmap are indispensable when it comes down to security assessment and penetration testing. Many researchers have to rely on those tools in order to find weaknesses in websites/web apps.</p>
<p>But like it is often the case, every application got it&#8217;s disadvantages.Especially in the area of vulnerability detection it is very hard to determine which tool is the best one.</p>
<p>On the 18th March 2010 Google entered the &#8220;market&#8221; and tries to deliver a very fast but comprehensive vulnerability scanner. &#8220;Skipfish&#8221; is free, coded in C, very fast, doesn&#8217;t need many resources, achieves more than 2000 requests per second, opens up to 100 simultaneous TCP connections, creates decent reports and even reveals vulnerabilities in popular web apps which haven&#8217;t been found yet.</p>
<p>Link: <a href="http://code.google.com/p/skipfish/" target="_blank">http://code.google.com/p/skipfish/</a></p>
<p>For me this sounds great, so I decided to give it a try.</p>
<p><strong>II. Downloading and installing</strong></p>
<p>I assume that you got a Debian/Ubuntu box and some time. Some of the commands may require &#8220;sudo&#8221;, but you are already familiar with your OS and know what to do <img src='http://www.xenuser.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Let&#8217;s install some required packages first:</p>
<p><em>apt-get install libidn11-dev make gcc libssl-dev</em></p>
<p>Now we download the app:</p>
<p><em>wget http://skipfish.googlecode.com/files/skipfish-1.33b.tgz</em></p>
<p><em>tar xfvz skipfish-1.33b.tgz</em></p>
<p><em>make</em></p>
<p>Skipfish is now ready to be launched, but let&#8217;s provide the tool with a dictionary first:</p>
<p><em>cp dictionaries/default.wl skipfish.wl</em></p>
<p><strong>III. Running Skipfish</strong></p>
<p style="text-align: center;">Ok, time to start!<br />
<em>./skipfish -o /home/your-target http://www.your-target.tld</em><br />
<a href="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_2_final.png"></a></p>
<p style="text-align: center;"><a href="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_2_final.png"><img class="size-medium wp-image-569 aligncenter" title="Skipfish is scanning" src="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_2_final-300x199.png" alt="Skipfish is scanning" width="300" height="199" /></a></p>
<p style="text-align: center;">As you can see here, one of my small machines is heavy occupied because of the test:</p>
<p style="text-align: center;"><a href="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_3.png"><img class="size-medium wp-image-570 aligncenter" title="VPS is heavy occupied" src="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_3-300x143.png" alt="VPS is heavy occupied" width="300" height="143" /></a></p>
<pre>In the test I did for this little tutorial, I had thousands of request sent after a few minutes.. after 5 minutes, only like 3,3 % percent of the whole scan was completed. Jesus! <img src='http://www.xenuser.org/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </pre>
<pre>Furthermore my little VPS was in the same state like it was being DoSed.</pre>
<p>=&gt; Skipfish really can small down a Linux box if the machine is small and not very well optimized.</p>
<p>Well, let&#8217;s cancel the test after a few minutes and have a look at the report:</p>
<p style="text-align: center;"><a href="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_5_final.png"><img class="size-medium wp-image-572 aligncenter" title="Cancel the scan" src="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_5_final-300x122.png" alt="Cancel the scan" width="300" height="122" /></a></p>
<pre style="text-align: center;"><a href="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_6_final.png"><img class="size-medium wp-image-573 aligncenter" title="Skipfish generated report" src="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_6_final-300x165.png" alt="Skipfish generated report" width="300" height="165" /></a></pre>
<p style="text-align: center;">In my eyes, this is a very well generated report.</p>
<pre><strong>IV. Some additional words</strong></pre>
<pre>Well, the best would be if you play around a little bit and have a look at all the options:</pre>
<p style="text-align: center;"><em>./skipfish -h</em></p>
<pre style="text-align: center;"><a href="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_1.png">
<img class="size-medium wp-image-574 aligncenter" title="Skipfish help" src="http://www.xenuser.org/wp-content/uploads/2010/04/skipfish_1-300x101.png" alt="Skipfish help" width="300" height="101" /></a></pre>
<p style="text-align: center;">
<p>According to many comments (which you are able to find through Google) Skipfish doesn&#8217;t find all obvious vulnerabilities, like SQL injection or XSS.  In my tests, quite the contrary was the case. Google&#8217;s Skipfish even found some vulnerabilities in some well known web apps which haven&#8217;t been discovered or published yet.</p>
<p>I will definitely use this tool for future penetration tests and my vulnerability research, and of course I highly recommend that you do the same <img src='http://www.xenuser.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><strong>V. Sources</strong></p>
<p>http://www.redspin.com/blog/2010/03/19/installing-google-skipfish-on-ubuntudebian/</p>
<p>http://questions.securitytube.net/questions/546/is-skipfish-really-so-different-from-nessus-appscan-and-others<br />
 <img src="http://www.xenuser.org/wp-content/plugins/wordpress-feed-statistics/feed-statistics.php?view=1&post_id=568" width="1" height="1" style="display: none;" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.xenuser.org/2010/04/29/penetration-testing-with-googles-skipfish-debianubuntu/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>

