<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-33672028</id><updated>2009-02-21T11:10:10.495+08:00</updated><title type='text'>SECAWARE</title><subtitle type='html'>Research and Development</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://secaware.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33672028/posts/default'/><link rel='alternate' type='text/html' href='http://secaware.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Secaware Research</name><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-33672028.post-115748544084383037</id><published>2006-09-06T03:38:00.000+08:00</published><updated>2006-09-06T04:14:21.656+08:00</updated><title type='text'>Timesheet 1.2.1 Blind SQL Injection Vulnerability</title><content type='html'>About:&lt;br /&gt;&lt;br /&gt;Timesheet.php is a PHP application designed to keep track of&lt;br /&gt;the hours worked by multiple people on multiple projects. It&lt;br /&gt;allows users to log in through their web browser and manage&lt;br /&gt;the times that they are clocked on or clocked off.&lt;br /&gt;&lt;br /&gt;Description:&lt;br /&gt;&lt;br /&gt;A vulnerability can be found on the file login.php on&lt;br /&gt;$_POST['username'] variable. When magic_quotes_gpc is set to Off&lt;br /&gt;an intruder can trigger a blind sql injection.&lt;br /&gt;&lt;br /&gt;Escalation:&lt;br /&gt;&lt;br /&gt;1. Disclosure of administrator username and password&lt;br /&gt; hash (MD5, PASSWORD) credentials.&lt;br /&gt;2. Remote code execution in case the intruder knows where&lt;br /&gt; to save the output of the sql injection on the local path.&lt;br /&gt;&lt;br /&gt;Solution:&lt;br /&gt;&lt;br /&gt;Create addslashes function that will filter the $_POST and&lt;br /&gt;$_GET variables.&lt;br /&gt;&lt;br /&gt;Vendor:&lt;br /&gt;&lt;br /&gt;http://sourceforge.net/projects/tsheet&lt;br /&gt;dwayner79 at users.sourceforge.net&lt;br /&gt;vexil at users.sourceforge.net&lt;br /&gt;&lt;br /&gt;Time table:&lt;br /&gt;&lt;br /&gt;Notified: 09/04/2006&lt;br /&gt;Response: No Response&lt;br /&gt;Public disclosure: 09/05/2006&lt;br /&gt;Updates: N/A&lt;br /&gt;&lt;br /&gt;Credits:&lt;br /&gt;&lt;br /&gt;Research By: Secaware Research&lt;br /&gt;Research Site: http://secaware.blogspot.com&lt;br /&gt;Research Mail: secaware2006 at yahoo dot com&lt;br /&gt;&lt;br /&gt;References:&lt;br /&gt;&lt;br /&gt;http://secaware.blogspot.com/2006/09/timesheet-121-blind-sql-injection.html&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33672028-115748544084383037?l=secaware.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33672028/posts/default/115748544084383037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33672028/posts/default/115748544084383037'/><link rel='alternate' type='text/html' href='http://secaware.blogspot.com/2006/09/timesheet-121-blind-sql-injection.html' title='Timesheet 1.2.1 Blind SQL Injection Vulnerability'/><author><name>Secaware Research</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03871867342203373769'/></author></entry><entry><id>tag:blogger.com,1999:blog-33672028.post-115707023730387506</id><published>2006-09-01T08:11:00.000+08:00</published><updated>2006-09-06T03:52:37.123+08:00</updated><title type='text'>Listing of Secaware Research Output for selected Vulnerable Open Source Web Application</title><content type='html'>Web Application Vulnerabilities are the following:&lt;br /&gt;&lt;br /&gt;1. Arbitrary Local File Inclusion Vulnerability&lt;br /&gt;2. Arbitrary Local File Retrieval Vulnerability&lt;br /&gt;3. Remote File Inclusion Vulnerability&lt;br /&gt;4. Remote Code Execution Vulnerability&lt;br /&gt;5. Remote SQL Injection Vulnerability&lt;br /&gt;6. Remote Blind SQL Injection Vulnerability&lt;br /&gt;7. XSS Cross-site Scripting Vulnerability&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33672028-115707023730387506?l=secaware.blogspot.com'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33672028/posts/default/115707023730387506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33672028/posts/default/115707023730387506'/><link rel='alternate' type='text/html' href='http://secaware.blogspot.com/2006/08/listing-of-secaware-research-output.html' title='Listing of Secaware Research Output for selected Vulnerable Open Source Web Application'/><author><name>Secaware Research</name><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03871867342203373769'/></author></entry></feed>