<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for www.notsosecure.com</title>
	<atom:link href="http://www.notsosecure.com/folder2/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.notsosecure.com/folder2</link>
	<description>From Pentesters To Pentesters</description>
	<lastBuildDate>Fri, 12 Feb 2010 18:42:49 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>Comment on Hacking Oracle 11g by Bug in Oracle 11g &#171; Shimoon Security</title>
		<link>http://www.notsosecure.com/folder2/2010/02/04/hacking-oracle-11g/comment-page-1/#comment-94702</link>
		<dc:creator>Bug in Oracle 11g &#171; Shimoon Security</dc:creator>
		<pubDate>Fri, 12 Feb 2010 18:42:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=361#comment-94702</guid>
		<description>[...] Il codice fornito da Litchfield e presente sul sito notsosecure. [...]</description>
		<content:encoded><![CDATA[<p>[...] Il codice fornito da Litchfield e presente sul sito notsosecure. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hacking Oracle 11g by Gildus&#187; Blog Archive &#187; Las bases de datos de Oracle pueden hackearse remotamente</title>
		<link>http://www.notsosecure.com/folder2/2010/02/04/hacking-oracle-11g/comment-page-1/#comment-94668</link>
		<dc:creator>Gildus&#187; Blog Archive &#187; Las bases de datos de Oracle pueden hackearse remotamente</dc:creator>
		<pubDate>Wed, 10 Feb 2010 21:22:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=361#comment-94668</guid>
		<description>[...] 10.2.0.4), pero no fue solucionado en los parches de seguridad de enero. Por lo que ha decidido hacerlo público (”11g 0day exploit”) durante la conferencia Black Hat en Washington el [...]</description>
		<content:encoded><![CDATA[<p>[...] 10.2.0.4), pero no fue solucionado en los parches de seguridad de enero. Por lo que ha decidido hacerlo público (”11g 0day exploit”) durante la conferencia Black Hat en Washington el [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hacking Oracle 11g by admin</title>
		<link>http://www.notsosecure.com/folder2/2010/02/04/hacking-oracle-11g/comment-page-1/#comment-94634</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Tue, 09 Feb 2010 19:29:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=361#comment-94634</guid>
		<description>btw, the video is now online again:

https://media.blackhat.com/bh-dc-10/video/Litchfield_David/BlackHat-DC-2010-Litchfield-Oracle11g-video.m4v</description>
		<content:encoded><![CDATA[<p>btw, the video is now online again:</p>
<p><a href="https://media.blackhat.com/bh-dc-10/video/Litchfield_David/BlackHat-DC-2010-Litchfield-Oracle11g-video.m4v" rel="nofollow">https://media.blackhat.com/bh-dc-10/video/Litchfield_David/BlackHat-DC-2010-Litchfield-Oracle11g-video.m4v</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Local File Inclusion with Magic_quotes_gpc enabled by Week 5 in Review &#124; Infosec Events</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94604</link>
		<dc:creator>Week 5 in Review &#124; Infosec Events</dc:creator>
		<pubDate>Mon, 08 Feb 2010 14:28:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94604</guid>
		<description>[...] Local File Inclusion with Magic_quotes_gpc enabled &#8211; notsosecure.com Penetration using magic_quote_gpc and PHP [...]</description>
		<content:encoded><![CDATA[<p>[...] Local File Inclusion with Magic_quotes_gpc enabled &#8211; notsosecure.com Penetration using magic_quote_gpc and PHP [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hacking Oracle 11g by Alexander Kornbrust Oracle Security Blog &#187; Blog Archive &#187; Oracle 11g 0day exploit published</title>
		<link>http://www.notsosecure.com/folder2/2010/02/04/hacking-oracle-11g/comment-page-1/#comment-94536</link>
		<dc:creator>Alexander Kornbrust Oracle Security Blog &#187; Blog Archive &#187; Oracle 11g 0day exploit published</dc:creator>
		<pubDate>Sat, 06 Feb 2010 07:42:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=361#comment-94536</guid>
		<description>[...] just read on Sumit Siddarth&#8217;s (Sid) blog that the video recording from David Litchfield&#8217;s BH presentation is was [...]</description>
		<content:encoded><![CDATA[<p>[...] just read on Sumit Siddarth&#8217;s (Sid) blog that the video recording from David Litchfield&#8217;s BH presentation is was [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Open Redirection by sysmox.com</title>
		<link>http://www.notsosecure.com/folder2/2010/01/22/open-redirection/comment-page-1/#comment-94515</link>
		<dc:creator>sysmox.com</dc:creator>
		<pubDate>Sat, 06 Feb 2010 00:20:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=329#comment-94515</guid>
		<description>good technice to avoid xss</description>
		<content:encoded><![CDATA[<p>good technice to avoid xss</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Local File Inclusion with Magic_quotes_gpc enabled by kuza55</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94376</link>
		<dc:creator>kuza55</dc:creator>
		<pubDate>Wed, 03 Feb 2010 06:16:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94376</guid>
		<description>Similar stuff is possible on linux: http://www.ush.it/2009/02/08/php-filesystem-attack-vectors/</description>
		<content:encoded><![CDATA[<p>Similar stuff is possible on linux: <a href="http://www.ush.it/2009/02/08/php-filesystem-attack-vectors/" rel="nofollow">http://www.ush.it/2009/02/08/php-filesystem-attack-vectors/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Local File Inclusion with Magic_quotes_gpc enabled by sid</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94331</link>
		<dc:creator>sid</dc:creator>
		<pubDate>Tue, 02 Feb 2010 16:16:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94331</guid>
		<description>Hi skully, please see the update, you dont need magic quote at all. I managed to make so many mistakes in a small blog post :(
</description>
		<content:encoded><![CDATA[<p>Hi skully, please see the update, you dont need magic quote at all. I managed to make so many mistakes in a small blog post <img src='http://www.notsosecure.com/folder2/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Local File Inclusion with Magic_quotes_gpc enabled by skully</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94329</link>
		<dc:creator>skully</dc:creator>
		<pubDate>Tue, 02 Feb 2010 16:07:27 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94329</guid>
		<description>Hi,
Very interesting only I am not able to reproduce it. I tested from 100 to &gt; 4096 dots, this does not disable the NULL byte from being escaped.

You say you tested on WAMP ? ie: Windows ? How can /etc/passwd work on windows ?

I tried in windows also, and it failed. Could you please explain or give poc code ?

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,<br />
Very interesting only I am not able to reproduce it. I tested from 100 to &gt; 4096 dots, this does not disable the NULL byte from being escaped.</p>
<p>You say you tested on WAMP ? ie: Windows ? How can /etc/passwd work on windows ?</p>
<p>I tried in windows also, and it failed. Could you please explain or give poc code ?</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Local File Inclusion with Magic_quotes_gpc enabled by sid</title>
		<link>http://www.notsosecure.com/folder2/2010/02/02/local-file-inclusion-with-magic_quotes_gpc-enabled/comment-page-1/#comment-94321</link>
		<dc:creator>sid</dc:creator>
		<pubDate>Tue, 02 Feb 2010 12:18:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.notsosecure.com/folder2/?p=347#comment-94321</guid>
		<description>Hi Bogan,

i have only tested it on windows, while the backslash(\) will get escaped by magic quote the forward slash will not be escaped, so that explains why it will only work if include is relational in windows.

&lt;del datetime=&quot;2010-02-02T12:39:39+00:00&quot;&gt;I can confirm that in my windows setup, it worked with null byte&lt;/del&gt;. As you pointed out, it doesn&#039;t work with null byte and the null byte is actually not required.</description>
		<content:encoded><![CDATA[<p>Hi Bogan,</p>
<p>i have only tested it on windows, while the backslash(\) will get escaped by magic quote the forward slash will not be escaped, so that explains why it will only work if include is relational in windows.</p>
<p><del datetime="2010-02-02T12:39:39+00:00">I can confirm that in my windows setup, it worked with null byte</del>. As you pointed out, it doesn&#8217;t work with null byte and the null byte is actually not required.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
