The WIse SECurity
| .italian .english |
News
|
Security Thoughts[ Back ] Monday, December 03, 2007, 21:21 ExploitMe Tools - A Little Warning Few days ago two interesting new tools were released and donated to the sec-community, XSSMe and SQLiMe by Security Compass.
Ok. This is the good tale about it. The problem is that XSSMe attack patterns use as external source www.securitycompass .com:
and this should not happen, or, at least XssMe should ask the user to change www.securitycompass.com to a custom server. Why? Because if you're doing some Ethical Hacking activity using XssMe for automated testing, whenever the victim host would have a Xss, www.securitycompass.com web server would get a request like the following:
Do you see? The referrer header is a great resource for statistics, and supposing you're doing the testing under some NDA you're almost screwed. So in order to resolve this issue, i exported the xss attacks to xml, replaced to my local server, deleted every pattern from the option dialog and imported the replaced xss.xml. Even though I really think this was due to an oversight, if anyone intends to use XssMe, fix it by yourself, or use it at your own risk! FAQ: Q: Did you reported this issue to Security Compass? A: Yes. They added a known issues link with the description of the problem. Comments: kuza55, Monday, December 03, 2007, 23:27 Yeah, I get paranoid about that, and unless its breaking a site I simply have referers disabled, just in case. Stefano, Monday, December 03, 2007, 23:59 Yes, disabling referrers could be a good choice, until sites check for them. kuza55, Tuesday, December 04, 2007, 23:22 Ouch, 1 tab per request..... Stefano, Wednesday, December 05, 2007, 00:11 agree, probably using iframe could get some false positive as it shares the same sandbox because of same origin policy. dan sinclair, Friday, December 07, 2007, 18:37 With the release of XSS-Me 0.2.1 we have corrected this issue of securitycompass.com being referenced in the default XSS string list. Comments are disabled
Admin login | This weblog is from www.mylittlehomepage.net Wisec is brought to you by...Wisec is written and mantained by Stefano Di Paola. Wisec uses open standards, including XHTML, CSS2, and XML-RPC. |
All Rights Reserved 2004
All hosted messages and metadata are owned by their respective authors.