<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0">
<channel>
<title>Ivan Markovic - Security Net - Site exposed</title>
<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195</link>
<description>RSS feed - Site Exposed</description>
<language>sr</language>
<ttl>15</ttl>

<item>
	<title>Telekomunikacioni portal | XSS</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=234</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=234</guid>
	<description>&lt;span style=&quot;font-weight: bold;&quot;&gt;- Tip sajta:&lt;/span&gt; Telekomunikacioni portal&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Tip propusta:&lt;/span&gt; XSS&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Detalji:&lt;/span&gt; Polje za pretragu nije pravilno zasticeno i omogucava XSS.&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Savet:&lt;/span&gt; Pretvorite specijalne karaktere u odgovarajuce html entitete.&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Pronasao:&lt;/span&gt; Aleksandar Nikolic</description>
	<pubDate>Thu, 14 Aug 2008 12:25:49 +0100</pubDate>
</item>

<item>
	<title>Biro | SQLi</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=232</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=232</guid>
	<description>- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip sajta:&lt;/span&gt; Biro&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip propusta:&lt;/span&gt; SQL injection&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Detalji:&lt;/span&gt; Parametri za pretragu nisu pravilno sankcionisani pre koriscenja u samom upitu na bazu.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Savet:&lt;/span&gt; &lt;a href=&quot;http://www.php.net/mysql_real_escape_string&quot; target=&quot;_blank&quot;&gt;mysql_real_escape_string&lt;/a&gt;&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Pronasao:&lt;/span&gt; &lt;a target=&quot;_blank&quot; href=&quot;http://security-net.biz&quot;&gt;Ivan Markovic&lt;/a&gt;</description>
	<pubDate>Thu, 31 Jul 2008 12:53:55 +0100</pubDate>
</item>

<item>
	<title>Drustvena mreza | Privilege Bypass</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=231</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=231</guid>
	<description>- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip sajta:&lt;/span&gt; Drustvena mreza&lt;br /&gt; - &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip propusta:&lt;/span&gt; Privilege Bypass&lt;br /&gt; - &lt;span style=&quot;font-weight: bold;&quot;&gt;Detalji:&lt;/span&gt; Ne postoji logika za proveru permisija i vlasnistva nad zapisima u sistemu.&lt;br /&gt; - &lt;span style=&quot;font-weight: bold;&quot;&gt;Savet:&lt;/span&gt; Obavezno je implementirati sistem permisija u ovakvim sistemima. Greska je pokusati nadoknaditi ovaj zahtev metodom '&lt;a href=&quot;http://en.wikipedia.org/wiki/Security_through_obscurity&quot; target=&quot;_blank&quot;&gt;security through obscurity&lt;/a&gt;'.&lt;br /&gt; - &lt;span style=&quot;font-weight: bold;&quot;&gt;Pronasao:&lt;/span&gt; &lt;a target=&quot;_blank&quot; href=&quot;http://security-net.biz&quot;&gt;Ivan Markovic&lt;/a&gt;</description>
	<pubDate>Wed, 23 Jul 2008 02:48:50 +0100</pubDate>
</item>

<item>
	<title>Mali oglasi | XSS</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=229</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=229</guid>
	<description>&lt;span style=&quot;font-weight: bold;&quot;&gt;- Tip sajta:&lt;/span&gt; Mali oglasi&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Tip propusta:&lt;/span&gt; XSS&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Detalji:&lt;/span&gt; Polje za pretragu nije pravilno zasticeno i omogucava XSS.&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Savet:&lt;/span&gt; Pretvorite specijalne karaktere u odgovarajuce html entitete.&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;- Pronasao:&lt;/span&gt; Aleksandar Nikolic</description>
	<pubDate>Tue, 22 Jul 2008 01:20:51 +0100</pubDate>
</item>

<item>
	<title>Berza | XSS</title>
	<link>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=228</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=233&amp;n=195&amp;bl=228</guid>
	<description>- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip sajta:&lt;/span&gt; Berza, vise sajtova svetskih berzi&amp;nbsp; &lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Tip propusta:&lt;/span&gt; XSS&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Detalji:&lt;/span&gt; Vise parametara za pretragu i sortiranje podataka nije pravilno zasticeno i omoguceno je direktno ispisivanje u html kod stranice. Ovaj pristup omogucava takozvani &lt;span style=&quot;font-style: italic;&quot;&gt;Cross-site scripting&lt;/span&gt;.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Savet:&lt;/span&gt; Pretvorite specijalne html karaktere u svoje html entitete.&lt;br /&gt;- &lt;span style=&quot;font-weight: bold;&quot;&gt;Pronasao&lt;/span&gt;: &lt;a href=&quot;http://netsec.rs/&quot; target=&quot;_blank&quot;&gt;Dejan Levaja&lt;/a&gt;</description>
	<pubDate>Mon, 21 Jul 2008 11:44:18 +0100</pubDate>
</item>

</channel>
</rss>