<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7781828600680666626</id><updated>2011-11-27T16:50:32.210-08:00</updated><category term='Microsoft'/><category term='security logic flaws'/><category term='yahoo groups vulnerability'/><category term='Application Security'/><category term='Security Trends'/><category term='logic flaws'/><category term='security vulnerability'/><category term='CSRF'/><category term='Web Applicaiton Security Trends analysis'/><category term='Security'/><category term='yahoo groups bugs'/><category term='Microsoft Innovation Day'/><category term='Web Application Security Trends'/><title type='text'>Mostafa Siraj's Application Security Blog</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://allaboutapplicationsecurity.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Mostafa Siraj</name><uri>http://www.blogger.com/profile/18276443600709227885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://1.bp.blogspot.com/_x4LAhW8QREc/SN_4UUBiAlI/AAAAAAAAAXY/KR_LaYV0UNE/S220/Image(416).jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>5</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7781828600680666626.post-6328160872732823253</id><published>2009-06-14T03:24:00.000-07:00</published><updated>2009-06-14T03:52:52.809-07:00</updated><title type='text'>What happened in the last quarter of 2007</title><content type='html'>&lt;div&gt;This post is totally unrelated to "Application Security", I was quering &lt;a href="http://www.google.com/trends"&gt;Google Trends&lt;/a&gt; for some websites and I found a very strange peek at the last quarter of 2007 for all major websites, does anyone know what happened?&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.google.com/trends?q=google.com&amp;amp;ctab=0&amp;amp;geo=all&amp;amp;date=all&amp;amp;sort=0"&gt;Google&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_x4LAhW8QREc/SjTVK4U9gyI/AAAAAAAABS8/jwzRVV8h0MM/s1600-h/Google.png"&gt;&lt;img src="http://3.bp.blogspot.com/_x4LAhW8QREc/SjTVK4U9gyI/AAAAAAAABS8/jwzRVV8h0MM/s320/Google.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5347133040491332386" style="float: left; margin-top: 0px; margin-right: 10px; margin-bottom: 10px; margin-left: 0px; cursor: pointer; width: 320px; height: 162px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.google.com/trends?q=yahoo.com&amp;amp;ctab=0&amp;amp;geo=all&amp;amp;date=all&amp;amp;sort=0"&gt;Yahoo&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_x4LAhW8QREc/SjTVph0RbkI/AAAAAAAABTE/NDk6uZXPvfY/s1600-h/Yahoo.png"&gt;&lt;img src="http://2.bp.blogspot.com/_x4LAhW8QREc/SjTVph0RbkI/AAAAAAAABTE/NDk6uZXPvfY/s320/Yahoo.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5347133567024590402" style="float: left; margin-top: 0px; margin-right: 10px; margin-bottom: 10px; margin-left: 0px; cursor: pointer; width: 320px; height: 159px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.google.com/trends?q=msn.com&amp;amp;ctab=0&amp;amp;geo=all&amp;amp;date=all&amp;amp;sort=0"&gt;MSN&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 238); -webkit-text-decorations-in-effect: underline; "&gt;&lt;img src="http://3.bp.blogspot.com/_x4LAhW8QREc/SjTV2UQnNQI/AAAAAAAABTM/QiS1s3nTf94/s320/MSN.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5347133786723661058" style="float: left; margin-top: 0px; margin-right: 10px; margin-bottom: 10px; margin-left: 0px; cursor: pointer; width: 320px; height: 161px; " /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#0000EE;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.google.com/trends?q=blogspot.com&amp;amp;ctab=0&amp;amp;geo=all&amp;amp;date=all&amp;amp;sort=0"&gt;Blogger&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_x4LAhW8QREc/SjTWIFLY-HI/AAAAAAAABTU/NRnJ1nQzLqQ/s1600-h/Blogger.png"&gt;&lt;img src="http://3.bp.blogspot.com/_x4LAhW8QREc/SjTWIFLY-HI/AAAAAAAABTU/NRnJ1nQzLqQ/s320/Blogger.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5347134091912870002" style="float: left; margin-top: 0px; margin-right: 10px; margin-bottom: 10px; margin-left: 0px; cursor: pointer; width: 320px; height: 159px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Try any other major website and you'll see this peak, is it a bug in Trends or was there an important event that I missed?&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7781828600680666626-6328160872732823253?l=allaboutapplicationsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://allaboutapplicationsecurity.blogspot.com/feeds/6328160872732823253/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/06/what-happened-in-last-quarter-of-2007.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/6328160872732823253'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/6328160872732823253'/><link rel='alternate' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/06/what-happened-in-last-quarter-of-2007.html' title='What happened in the last quarter of 2007'/><author><name>Mostafa Siraj</name><uri>http://www.blogger.com/profile/18276443600709227885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://1.bp.blogspot.com/_x4LAhW8QREc/SN_4UUBiAlI/AAAAAAAAAXY/KR_LaYV0UNE/S220/Image(416).jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_x4LAhW8QREc/SjTVK4U9gyI/AAAAAAAABS8/jwzRVV8h0MM/s72-c/Google.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7781828600680666626.post-7656553382078260344</id><published>2009-06-02T05:39:00.000-07:00</published><updated>2009-06-02T17:24:18.240-07:00</updated><title type='text'>Torpig: The most advanced pieces of crimeware ever created, Part 1</title><content type='html'>&lt;span class="Apple-style-span"  style="font-size:small;"&gt;A group of researchers from the University of California, Department of Computer Science, Security Group made a &lt;/span&gt;&lt;a href="http://www.cs.ucsb.edu/~seclab/projects/torpig/torpig.pdf"&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;comprehensive research&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;[must read] about what is known to be "&lt;/span&gt;&lt;a href="http://news.bbc.co.uk/2/hi/technology/7701227.stm"&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;The most advanced pieces of crimeware ever created&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;". &lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Torpig worth a lot of attention from the community so I decided to write two posts about Torpig.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;part 1 will be just an overview about how Torpig works, and most importantly part 2 which will discuss the &lt;/span&gt;&lt;span style="line-height: 115%;   font-family:Georgia, serif;color:black;"&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;weaknesses &lt;/span&gt;&lt;/span&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;of the Torpig and raise the question of "If this malware were designed without these weaknesses -I'll suggest how-. How can good guys defeat it"&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;Torpig is a sophisticated malware program that is designed to harvest sensitive information (such as banks account and credit cards data) from the machines it infects. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;What is very unique about this malware is its ability to spread, collect sensitive information from infected machines and communicate with the botmaster to provide him with the collected data.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;First, let's start by understanding how this malware works -according to the paper-. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;* The malware spread using different techniques (&lt;/span&gt;&lt;a href="http://en.wikipedia.org/wiki/Drive-by_download"&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;drive-by download&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;).&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;The fact here that we have at least 182,800 infected machines and the number is increasing&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_x4LAhW8QREc/SiXAxPPuEGI/AAAAAAAABHs/qJ2srLLPWxM/s1600-h/croud.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 226px; height: 277px;" src="http://2.bp.blogspot.com/_x4LAhW8QREc/SiXAxPPuEGI/AAAAAAAABHs/qJ2srLLPWxM/s320/croud.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5342888485083549794" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;* The downloaded executable acts as an installer for Mebroot. The installer injects a DLL into the file manager process (explorer.exe), and execution continues in the file manager’s context.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;This makes all subsequent actions appear as if they were performed by a legitimate system process. The installer then loads a kernel driver that wraps the original disk driver (disk.sys). At this point, the installer has raw disk access on the infected machine. The installer can then overwrite the MBR of the machine with Mebroot. After a few minutes, the machine automatically reboots, and Mebroot is loaded from the MBR.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_x4LAhW8QREc/SiW5bNuqy-I/AAAAAAAABG0/ZnAN6aYQw1I/s1600-h/HARDDISK.GIF"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://2.bp.blogspot.com/_x4LAhW8QREc/SiW5bNuqy-I/AAAAAAAABG0/ZnAN6aYQw1I/s320/HARDDISK.GIF" border="0" alt="" id="BLOGGER_PHOTO_ID_5342880410137971682" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;* The malware gather sensitive information using a lot of techniques (e.g. gather all web traffic made by the infected machine, use phishing attacks for banks and major financial sites (PayPal), email clients, instant messengers, etc)&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_x4LAhW8QREc/SiW_SUxtN9I/AAAAAAAABHU/z9Av0P3Eoso/s1600-h/credit_cards.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 150px;" src="http://2.bp.blogspot.com/_x4LAhW8QREc/SiW_SUxtN9I/AAAAAAAABHU/z9Av0P3Eoso/s200/credit_cards.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5342886854480705490" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;* The malware uses the "domain flux" (periodically generate a large list of domain names infected machines are to report  to&lt;/span&gt;&lt;span class="Apple-style-span"   style="font-family:Verdana;color:#333333;"&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;)&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_x4LAhW8QREc/SiW7hEPyDVI/AAAAAAAABHM/qaAvnq1DIFc/s1600-h/domains.jpg"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 200px; height: 189px;" src="http://2.bp.blogspot.com/_x4LAhW8QREc/SiW7hEPyDVI/AAAAAAAABHM/qaAvnq1DIFc/s200/domains.jpg" border="0" alt="" id="BLOGGER_PHOTO_ID_5342882709694975314" /&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;well this is how generally Torpig works, please refer to the &lt;/span&gt;&lt;a href="http://www.cs.ucsb.edu/~seclab/projects/torpig/torpig.pdf"&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt;paper&lt;/span&gt;&lt;/a&gt;&lt;span class="Apple-style-span"  style="font-size:small;"&gt; to get more details about it. and follow the next post that will discuss the weaknesses of Torpig and how it could have been mitigated.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7781828600680666626-7656553382078260344?l=allaboutapplicationsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://allaboutapplicationsecurity.blogspot.com/feeds/7656553382078260344/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/06/torpig-most-advanced-pieces-of.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/7656553382078260344'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/7656553382078260344'/><link rel='alternate' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/06/torpig-most-advanced-pieces-of.html' title='Torpig: The most advanced pieces of crimeware ever created, Part 1'/><author><name>Mostafa Siraj</name><uri>http://www.blogger.com/profile/18276443600709227885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://1.bp.blogspot.com/_x4LAhW8QREc/SN_4UUBiAlI/AAAAAAAAAXY/KR_LaYV0UNE/S220/Image(416).jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_x4LAhW8QREc/SiXAxPPuEGI/AAAAAAAABHs/qJ2srLLPWxM/s72-c/croud.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7781828600680666626.post-1417361964994213842</id><published>2009-05-28T01:22:00.000-07:00</published><updated>2009-06-02T16:34:55.650-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Web Applicaiton Security Trends analysis'/><category scheme='http://www.blogger.com/atom/ns#' term='Web Application Security Trends'/><category scheme='http://www.blogger.com/atom/ns#' term='Security Trends'/><title type='text'>Web Application Security Trends Q3-Q4 2008</title><content type='html'>The "&lt;a href="http://viewer.bitpipe.com/viewer/viewDocument.do?accessId=9643968"&gt;Web Application Security Trends Q3- Q4 2008&lt;/a&gt;" is published, I guess there are a lot of interesting findings in this report, I'm sharing here with you what I see the most important stuff&lt;br /&gt;&lt;br /&gt;1- SQL injection got its first position back over XSS&lt;div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_x4LAhW8QREc/Sh5Kvf8dwEI/AAAAAAAABFo/pXiLACkDlxw/s1600-h/breakdown.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 213px;" src="http://3.bp.blogspot.com/_x4LAhW8QREc/Sh5Kvf8dwEI/AAAAAAAABFo/pXiLACkDlxw/s320/breakdown.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5340788387997401154" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;2- as expected more and more hackers are joining the club&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_x4LAhW8QREc/Sh5LYo2z5aI/AAAAAAAABFw/gKd4g_mN58M/s1600-h/total_web_application_vuln.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 199px;" src="http://2.bp.blogspot.com/_x4LAhW8QREc/Sh5LYo2z5aI/AAAAAAAABFw/gKd4g_mN58M/s320/total_web_application_vuln.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5340789094764242338" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;3- IE and FF are gaining almost the same attention&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_x4LAhW8QREc/Sh5LiR3JfkI/AAAAAAAABF4/oUaCpHB74n4/s1600-h/browsers.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 198px;" src="http://3.bp.blogspot.com/_x4LAhW8QREc/Sh5LiR3JfkI/AAAAAAAABF4/oUaCpHB74n4/s320/browsers.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5340789260390334018" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;4- CSRF  is gaining more attention everyday&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_x4LAhW8QREc/Sh5LrY8bEHI/AAAAAAAABGA/Wv0_Bga4gZ8/s1600-h/CSRF_in_Misc.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 251px;" src="http://1.bp.blogspot.com/_x4LAhW8QREc/Sh5LrY8bEHI/AAAAAAAABGA/Wv0_Bga4gZ8/s320/CSRF_in_Misc.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5340789416910327922" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;5- more important, CSRF was usually exploited by whitehats for demonstrations, Q3-Q4 2008 is the first time for blackhats to use it. So I guess more attention should be paid now for it.&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_x4LAhW8QREc/Sh5L3CCmwOI/AAAAAAAABGI/2aHNtOp2rBk/s1600-h/CSRF.png"&gt;&lt;img style="float:left; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 320px; height: 230px;" src="http://3.bp.blogspot.com/_x4LAhW8QREc/Sh5L3CCmwOI/AAAAAAAABGI/2aHNtOp2rBk/s320/CSRF.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5340789616920674530" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;if you have any comments about this report please share it with me in the comments area.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7781828600680666626-1417361964994213842?l=allaboutapplicationsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://allaboutapplicationsecurity.blogspot.com/feeds/1417361964994213842/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/05/web-application-security-trends-q3-q4.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/1417361964994213842'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/1417361964994213842'/><link rel='alternate' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/05/web-application-security-trends-q3-q4.html' title='Web Application Security Trends Q3-Q4 2008'/><author><name>Mostafa Siraj</name><uri>http://www.blogger.com/profile/18276443600709227885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://1.bp.blogspot.com/_x4LAhW8QREc/SN_4UUBiAlI/AAAAAAAAAXY/KR_LaYV0UNE/S220/Image(416).jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_x4LAhW8QREc/Sh5Kvf8dwEI/AAAAAAAABFo/pXiLACkDlxw/s72-c/breakdown.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7781828600680666626.post-6791801607950062300</id><published>2009-05-19T02:08:00.000-07:00</published><updated>2009-05-20T01:21:06.633-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='yahoo groups bugs'/><category scheme='http://www.blogger.com/atom/ns#' term='yahoo groups vulnerability'/><category scheme='http://www.blogger.com/atom/ns#' term='security logic flaws'/><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><category scheme='http://www.blogger.com/atom/ns#' term='logic flaws'/><title type='text'>Yahoo Groups Voting Vulnerability</title><content type='html'>&lt;div&gt;I found a very interesting security bug at Yahoo Groups Voting System, exploiting this bug leads to complete control of the voting result. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can watch the video to see how I made 4 polls -they could be more- using a single account&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;embed src="http://images.video.msn.com/flash/soapbox1_1.swf" width="432" height="364" id="coeuvlbg" type="application/x-shockwave-flash" allowFullScreen="true" allowScriptAccess="always" pluginspage="http://macromedia.com/go/getflashplayer" flashvars="c=v&amp;v=cf581209-ad25-4920-821f-0a11bf849cf4&amp;ifs=true&amp;fr=msnvideo&amp;mkt=en-US"&gt;&lt;/embed&gt;&lt;noembed&gt;&lt;br/&gt;&lt;a href="http://video.msn.com/video.aspx?vid=cf581209-ad25-4920-821f-0a11bf849cf4" target="_new" title="Yahoo Groups Voting Bug"&gt;Video: Yahoo Groups Voting Bug&lt;/a&gt;&lt;/noembed&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="text-decoration: underline;"&gt;Bug Demonstration&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style=" ;font-size:medium;"&gt;It's clear that the voting system is differentiating between different users by examining the email address that is &lt;span style="line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; mso-bidi-Times New Roman&amp;quot;;mso-ansi-language:EN-US; mso-fareast-language:EN-US;mso-bidi-language:AR-SAfont-family:&amp;quot;;font-size:12.0pt;color:black;"&gt;associated &lt;/span&gt;with the group, and since you can add unlimited number of emails &lt;span style="line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; mso-bidi-Times New Roman&amp;quot;;mso-ansi-language:EN-US; mso-fareast-language:EN-US;mso-bidi-language:AR-SAfont-family:&amp;quot;;font-size:12.0pt;color:black;"&gt;associated &lt;/span&gt;with single Yahoo ID and the group settings allow you to change between these emails. you can simply add your vote then change the &lt;span style="line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; mso-bidi-Times New Roman&amp;quot;;mso-ansi-language:EN-US; mso-fareast-language:EN-US;mso-bidi-language:AR-SAfont-family:&amp;quot;;font-size:12.0pt;color:black;"&gt;associated &lt;/span&gt;email then vote again as a new voter, you can keep repeating this until you fully manipulate the voting results to the one of your choice.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="text-decoration: underline;"&gt;Simple steps to reproduce this security bug&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;1- go to the poll of your choice&lt;/div&gt;&lt;div&gt;2- select your candidate of the choices&lt;/div&gt;&lt;div&gt;3- click "Edit Membership"&lt;/div&gt;&lt;div&gt;4- under "Email Address" click "Add new email address" and verify it&lt;/div&gt;&lt;div&gt;5- keep repeating step 4 until you add sufficient number of email addresses&lt;/div&gt;&lt;div&gt;6- now choose any of them as your default associated email&lt;/div&gt;&lt;div&gt;7- go to the poll again and congratulations you can add your vote as it's your first time to add it&lt;/div&gt;&lt;div&gt;8- keep changing the associated email address until your candidate of the vote options win :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="font-size:large;"&gt;&lt;span class="Apple-style-span" style="text-decoration: underline;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Conclusion&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;It's very clear that this bug is a security logic vulnerability and hince no static code analysis tool is able to find it (never depend on static code analysis tools only).&lt;/div&gt;&lt;div&gt;Although it's very easy to exploit this vulnerability (I didn't write scripts, didn't run automated scans or use any complex method to exploit this vulnerability) the imact of the vulnerability is very high (maybe all the votes that were created before were manipulated).&lt;/div&gt;&lt;div&gt;There could be more vulnerabilities in Yahoo Groups that I didn't investigate if they have more stuff &lt;span style="line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; mso-bidi-Times New Roman&amp;quot;;mso-ansi-language:EN-US; mso-fareast-language:EN-US;mso-bidi-language:AR-SAfont-family:&amp;quot;;font-size:12.0pt;color:black;"&gt;depending &lt;/span&gt;on the &lt;span style="line-height:115%; font-family:&amp;quot;Georgia&amp;quot;,&amp;quot;serif&amp;quot;;mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;; mso-bidi-Times New Roman&amp;quot;;mso-ansi-language:EN-US; mso-fareast-language:EN-US;mso-bidi-language:AR-SAfont-family:&amp;quot;;font-size:12.0pt;color:black;"&gt;associated &lt;/span&gt;email &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Keep checking this blog as I decided to publish more and more security vulnerabilities at major websites, since they never fix their issues unless you fully disclose their bugs :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7781828600680666626-6791801607950062300?l=allaboutapplicationsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://allaboutapplicationsecurity.blogspot.com/feeds/6791801607950062300/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/05/yahoo-groups-voting-vulnerability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/6791801607950062300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/6791801607950062300'/><link rel='alternate' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/05/yahoo-groups-voting-vulnerability.html' title='Yahoo Groups Voting Vulnerability'/><author><name>Mostafa Siraj</name><uri>http://www.blogger.com/profile/18276443600709227885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://1.bp.blogspot.com/_x4LAhW8QREc/SN_4UUBiAlI/AAAAAAAAAXY/KR_LaYV0UNE/S220/Image(416).jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7781828600680666626.post-2483104371741213770</id><published>2009-04-26T07:20:00.000-07:00</published><updated>2009-05-19T15:15:02.992-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='Security'/><category scheme='http://www.blogger.com/atom/ns#' term='CSRF'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft Innovation Day'/><category scheme='http://www.blogger.com/atom/ns#' term='Microsoft'/><category scheme='http://www.blogger.com/atom/ns#' term='Application Security'/><title type='text'>CSRF session at Microsoft innovation day (22nd April, 2009)</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://lh3.ggpht.com/_x4LAhW8QREc/Se-CcIcP77I/AAAAAAAAA2s/MQM_DyZtW78/s640/SNC00232.jpg"&gt;&lt;img style="float:center; margin:0 10px 10px 0;cursor:pointer; cursor:hand;width: 480px; height: 640px;" src="http://lh3.ggpht.com/_x4LAhW8QREc/Se-CcIcP77I/AAAAAAAAA2s/MQM_DyZtW78/s640/SNC00232.jpg" border="0" alt="" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;I was invited by the CuttingEdge Club to make a presentation about "Application Security" in Microsoft Innovation Day, I thought first that most of the attendees will be professional developers so I decided to exclude common topics in application security like "XSS, SQL Injection, Input Validation".&lt;/div&gt;&lt;div&gt;&lt;br /&gt;I decided to make it about "Cross Site Request Forgery" specifically the session title was "How do I: Protect from Cross Site Request Forgery in ASP.NET". I think it was quite interesting for the audience -specially that most of the other sessions were about SharePoint-.&lt;br /&gt;&lt;br /&gt;I found out later that most of the attendees are students so I tried to use only simple terms -I don't think I managed to do it- as CSRF is quite complicated by nature and most developers confuse it with XSS.&lt;br /&gt;&lt;br /&gt;Anyway I think I managed to spread the awareness of application security vulnerabilities and their huge impact -either financially or from privacy prospective- on the internet today.&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Here is the presentation&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;iframe src="http://docs.google.com/EmbedSlideshow?docid=dcn76rt7_876ftskkqj5" frameborder="0" width="410" height="342"&gt;&lt;/iframe&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7781828600680666626-2483104371741213770?l=allaboutapplicationsecurity.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://allaboutapplicationsecurity.blogspot.com/feeds/2483104371741213770/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/04/csrf-session-at-microsoft-innovation.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/2483104371741213770'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7781828600680666626/posts/default/2483104371741213770'/><link rel='alternate' type='text/html' href='http://allaboutapplicationsecurity.blogspot.com/2009/04/csrf-session-at-microsoft-innovation.html' title='CSRF session at Microsoft innovation day (22nd April, 2009)'/><author><name>Mostafa Siraj</name><uri>http://www.blogger.com/profile/18276443600709227885</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='30' height='32' src='http://1.bp.blogspot.com/_x4LAhW8QREc/SN_4UUBiAlI/AAAAAAAAAXY/KR_LaYV0UNE/S220/Image(416).jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://lh3.ggpht.com/_x4LAhW8QREc/Se-CcIcP77I/AAAAAAAAA2s/MQM_DyZtW78/s72-c/SNC00232.jpg' height='72' width='72'/><thr:total>0</thr:total></entry></feed>
