<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:series="http://unfoldingneurons.com/"
	>

<channel>
	<title>a4apphack &#187; Code</title>
	<atom:link href="http://a4apphack.com/category/security/sec-code/feed" rel="self" type="application/rss+xml" />
	<link>http://a4apphack.com</link>
	<description>Get more out of the Apps!</description>
	<lastBuildDate>Thu, 26 Apr 2012 15:44:13 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<image>
<link>http://a4apphack.com</link>
<url>http://a4apphack.com/blog/wp-content/themes/primus/favicon.ico</url>
<title>a4apphack</title>
</image>
		<item>
		<title>Py Script to Update Backtrack 5 Tools</title>
		<link>http://a4apphack.com/security/sec-code/py-script-to-update-backtrack-5-tools</link>
		<comments>http://a4apphack.com/security/sec-code/py-script-to-update-backtrack-5-tools#comments</comments>
		<pubDate>Wed, 11 Jan 2012 19:44:19 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Code]]></category>
		<category><![CDATA[backtrack]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://a4apphack.com/?p=2271</guid>
		<description><![CDATA[This Python script by the author &#8216;sickness&#8217; updates many of the tools present in Backtrack suite, which otherwise would&#8217;ve to be updated manually. Get the script Screenshot Source: backtrack-linux.org]]></description>
			<content:encoded><![CDATA[<p>This Python script by the author &#8216;sickness&#8217; updates many of the tools present in Backtrack suite, which otherwise would&#8217;ve to be updated manually.</p>
<p><strong>Get the script</strong></p>
<script type='text/javascript' src='http://snipt.net/embed/efac568d70a1554af513af5c2551ac68'></script>
<p><strong>Screenshot</strong></p>
<div class="wp-caption alignnone" style="width: 610px"><a href="http://img.a4apphack.com/backtrack5update.jpg" rel="lightbox[2271]" title="Backtrack5 Update Script"><img title="Backtrack5 Update Script" src="http://img.a4apphack.com/backtrack5update.jpg" alt="Backtrack5 Update Script" width="600" height="479" /></a><p class="wp-caption-text">Backtrack5 Update Script</p></div>
<p><strong>Source:</strong> <a title="Update Script for Backtrack 5" href="http://www.backtrack-linux.org/forums/showthread.php?t=41766" target="_blank">backtrack-linux.org</a></p>
<table id="cft">
  <thead>
  <tr>
    <th colspan="2">Backtrack5 Update Script Info</th>
  </tr>
  </thead>
  <tbody>
    <tr>
      <td  width="40%">App Name</td>
      <td>Backtrack5 Update Script</td>
    </tr>
    <tr>
      <td>License</td>
      <td>free</td>
    </tr>
    <tr>
      <td>Type</td>
      <td>code</td>
    </tr>
    <tr>
      <td>App URL</td>
      <td>
      <a target="_blank" href="http://sickness.tor.hu/wp-content/uploads/2011/06/backtrack5_update.py"><img
 style="" alt="Download"
 src="http://img.a4apphack.com/site/a4apphack-download.png"
 title="Download" witdh="30" height="30"></a></td>
    </tr>
    <tr>
      <td>More Info</td>
      <td> <a href="http://www.backtrack-linux.org/forums/showthread.php?t=41766">link</a></td>
    </tr>
  </tbody>
</table>

<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=2271&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/sec-code/py-script-to-update-backtrack-5-tools/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Batch File Decompiles Android apk to Java Source With a Single Command</title>
		<link>http://a4apphack.com/featured/batch-file-decompiles-android-apk-to-java-source-with-a-single-command</link>
		<comments>http://a4apphack.com/featured/batch-file-decompiles-android-apk-to-java-source-with-a-single-command#comments</comments>
		<pubDate>Thu, 21 Jul 2011 21:59:11 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Code]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[batch]]></category>
		<category><![CDATA[code]]></category>

		<guid isPermaLink="false">http://a4apphack.com/?p=2190</guid>
		<description><![CDATA[This batch file decompiles an apk to its corresponding java sources. People who are looking forward to do a code review on an android app who&#8217;s source code is not readily available can utilize this bat. This batch runs various free tools available on the internet in a sequence to obtain the java source files. [...]]]></description>
			<content:encoded><![CDATA[<p>This batch file decompiles an apk to its corresponding java sources. People who are looking forward to do a code review on an android app who&#8217;s source code is not readily available can utilize this bat. This batch runs various free tools available on the internet in a sequence to obtain the java source files.</p>
<p>This is not made to encourage piracy/plagiarism in any case.</p>
<h3>How To</h3>
<p>1. Extract batch file and lib folder to <span style="font-family: courier new,courier;">C:\apk2java\</span> (or any folder that <strong>doesnt have space in its path</strong>)</p>
<p>2. Backup the target app&#8217;s apk from phone to PC via ASTRO Browser (check <a title="this post" href="http://a4apphack.com/security/sec-code/extract-android-apk-from-market-and-decompile-it-to-java-source">this post</a> for details)</p>
<p>3. Keep the target apk in the root folder where batch file is present</p>
<p><a href="http://img.a4apphack.com/apk2java-copytargetapk.jpg" rel="lightbox[2190]" title="Copy target apk to exec folder"><img title="Copy target apk to exec folder" src="http://img.a4apphack.com/apk2java-copytargetapk.jpg" alt="Copy target apk to exec folder" width="600" height="368" /></a></p>
<p>4. Run &#8216;apk2java.bat target.apk&#8217; in cmd</p>
<p><code>c:\apk2java&gt;apk2java.bat target.apk</code></p>
<p><a href="http://img.a4apphack.com/apk2java-executebatch.jpg" rel="lightbox[2190]" title="Execute Command"><img class="alignnone" title="Execute Command" src="http://img.a4apphack.com/apk2java-executebatch.jpg" alt="Execute Command" width="600" height="227" /></a></p>
<p><a href="http://img.a4apphack.com/apk2java-processcomplete.jpg" rel="lightbox[2190]" title="Process Complete"><img title="Process Complete" src="http://img.a4apphack.com/apk2java-processcomplete.jpg" alt="Process Complete" width="600" height="393" /></a></p>
<p><span id="more-2190"></span>5. Result : java and resource files available in &#8216;src&#8217;</p>
<p><a href="http://img.a4apphack.com/apk2java-outputsrc.jpg" rel="lightbox[2190]" title="src folder containing decompiled files"><img class="alignnone" title="src folder containing decompiled files" src="http://img.a4apphack.com/apk2java-outputsrc.jpg" alt="src folder containing decompiled files" width="600" height="367" /></a></p>
<p><strong>Note</strong>: This batch just automates the sequence in which various tools are initiated and does not handle any error events. You will have to go through the cmd verbose to figure out the problem.</p>
<p><strong>Note 2:</strong> &#8216;lib&#8217; folder contains apk-tool files (apk-tool.jar, aapt.exe), jad.exe, 7zip (7za.exe), dex2jar files (all other jars).  If required, update each of those tools by replacing it with latest copy from links mentioned below.</p>
<h3>Requirements</h3>
<ul>
<li>Windows (but can be ported to *NIX)</li>
<li>JRE 1.6 (Java Runtime Environment)</li>
</ul>
<h3>Tools in lib</h3>
<ul>
<li>Dex2jar &#8211; Converts Android dex format to jar (<a title="Dex2jar" href="http://code.google.com/p/dex2jar/">link</a>)</li>
<li>JAD &#8211; Java Decompiler CLI (<a title="JAD" href="http://www.varaneckas.com/jad">link</a>)</li>
<li>7Zip &#8211; Unarchival  (<a title="7Zip" href="http://www.7-zip.org/download.html">link</a>)</li>
<li>apk-tool &#8211; Extracts resources from apk (<a title="apk-tool" href="http://code.google.com/p/android-apktool/">link</a>)</li>
<li>aapt &#8211; Android Asset Packaging Tool <a title="Android Dev Guid" href="http://developer.android.com/guide/developing/building/index.html">(link)</a></li>
<li>aapt commands (<a title="aapt commands" href="http://elinux.org/Android_aapt">link)</a></li>
</ul>
<script type='text/javascript' src='http://snipt.net/embed/00aea84a3ffd7b7b8150241c20727adf'></script>
<table id="cft">
  <thead>
  <tr>
    <th colspan="2">apk2java Info</th>
  </tr>
  </thead>
  <tbody>
    <tr>
      <td  width="40%">App Name</td>
      <td>apk2java</td>
    </tr>
    <tr>
      <td>License</td>
      <td>free</td>
    </tr>
    <tr>
      <td>Type</td>
      <td>code</td>
    </tr>
    <tr>
      <td>App URL</td>
      <td>
      <a target="_blank" href="http://img.a4apphack.com/dl/apk2java.zip"><img
 style="" alt="Download"
 src="http://img.a4apphack.com/site/a4apphack-download.png"
 title="Download" witdh="30" height="30"></a></td>
    </tr>
    <tr>
      <td>More Info</td>
      <td> <a href="">link</a></td>
    </tr>
  </tbody>
</table>

<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=2190&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/featured/batch-file-decompiles-android-apk-to-java-source-with-a-single-command/feed</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>Extract Android apk from Market and Decompile it to Java Source</title>
		<link>http://a4apphack.com/security/sec-code/extract-android-apk-from-market-and-decompile-it-to-java-source</link>
		<comments>http://a4apphack.com/security/sec-code/extract-android-apk-from-market-and-decompile-it-to-java-source#comments</comments>
		<pubDate>Wed, 20 Apr 2011 18:29:53 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Android]]></category>
		<category><![CDATA[Code]]></category>
		<category><![CDATA[apps]]></category>
		<category><![CDATA[automate]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[scan]]></category>

		<guid isPermaLink="false">http://a4apphack.com/?p=2152</guid>
		<description><![CDATA[This post talks about process of extracting apk file of any app available in market and then decompiling it to Java source. This can be helpful for those who perform code review (for security vulnerabilities) on apps whose source code is not available. Once Java source code is obtained, we can either do manual code [...]]]></description>
			<content:encoded><![CDATA[<p>This post talks about process of extracting apk file of any app available in market and then decompiling it to Java source. This can be helpful for those who perform code review (for security vulnerabilities) on apps whose source code is not available. Once Java source code is obtained, we can either do manual code review or run any free/commercial automated code scanners.</p>
<p><span id="more-2152"></span></p>
<h3>Download .apk file from market</h3>
<ol>
<li>Search in market for the app you want to decompile and install it on your phone.</li>
<li>Install Astro File Manager from market (<a title="Astro File Manager (Android Market Link)" href="https://market.android.com/details?id=com.metago.astro">link</a>). Open Astro &gt; Tools &gt; Application Manager/Backup and select the application to backup on to the SD card .</li>
<li>Mount phone as USB drive and access <code>'\backups\apps\'</code> folder to find the apk of target app (lets call it targetapp.apk) . Copy it to your local drive.</li>
</ol>
<h3>Decomiling apk to Dex format</h3>
<ol>
<li>Download Dex2Jar (<a title="Dex2Jar" href="http://code.google.com/p/dex2jar/">link</a>) (Android runs applications which are in <a rel="nofollow" href="http://en.wikipedia.org/wiki/Dalvik_%28software%29">Dalvik Executable (.dex) format</a>).</li>
<li>Run the command to convert apk to jar<code></code><code></code></li>
</ol>
<p><code>dex2jar targetapp.apk file(./dex2jar targetapp.apk on terminal)</code></p>
<p style="padding-left: 30px;">File ‘targetapp.apk.dex2jar.jar’ is created</p>
<p><a href="http://img.a4apphack.com/androiddecompile-04.jpg" rel="lightbox[2152]" title="Converting Apk (Dex) to Jar"><img title="Converting Apk (Dex) to Jar" src="http://img.a4apphack.com/androiddecompile-04.jpg" alt="Converting Apk (Dex) to Jar" width="600" height="396" /></a></p>
<h3>Viewing/Decompiling the Jar files to Java</h3>
<h4>Method 1 : Use JavaDecompiler (JD)</h4>
<ol>
<li>Open ‘targetapp.apk.dex2jar.jar’ with jd-gui (<a title="JD GUI" href="http://java.decompiler.free.fr/?q=jdgui">link</a>)</li>
<li>File &gt; Save All Sources to sava the class files in jar to java files.</li>
</ol>
<p><a href="http://img.a4apphack.com/androiddecompile-05.jpg" rel="lightbox[2152]" title="JD GUI Viewer"><img class="alignnone" title="JD GUI Viewer" src="http://img.a4apphack.com/androiddecompile-05.jpg" alt="JD GUI Viewer" width="600" height="374" /></a></p>
<h4>Method 2: JAD</h4>
<ol>
<li>Extract contents of jar file on to a folder named src. Use and unarchival utility like 7zip</li>
<li>Keep ‘src’ folder in the same directory where JAD and targetapp jar is present</li>
<li>Open JAD in cmd and execute the following command</li>
<li><code>jad -o -r -sjava -dsrc src/**/*.class</code> (./jad on terminal)</li>
</ol>
<p><a href="http://img.a4apphack.com/androiddecompile-07.jpg" rel="lightbox[2152]" title="Extract jar contents to src folder"><img class="alignnone" title="Extract jar contents to src folder" src="http://img.a4apphack.com/androiddecompile-07.jpg" alt="Extract jar contents to src folder" width="600" height="441" /></a></p>
<p><a href="http://img.a4apphack.com/androiddecompile-08.jpg" rel="lightbox[2152]" title="Running jad command"><img class="alignnone" title="Running jad command" src="http://img.a4apphack.com/androiddecompile-08.jpg" alt="Running jad command" width="600" height="413" /></a></p>
<p>Now src will contain decompiled Java files ready for manual code review.</p>
<p><a href="http://img.a4apphack.com/androiddecompile-09.jpg" rel="lightbox[2152]" title="Decompiled java files"><img class="alignnone" title="Decompiled java files" src="http://img.a4apphack.com/androiddecompile-09.jpg" alt="Decompiled java files" width="600" height="413" /></a></p>
<h3>Tools Used</h3>
<ol>
<li>Sample app &#8211; RemoteDroid (Opensource &#8211; <a title="RemoteDroid" href="http://code.google.com/p/remotedroid/downloads/detail?name=RemoteDroid-v1.4.apk&amp;can=2&amp;q=">link</a>)</li>
<li>Astro File Manager (Android Market &#8211; <a title="Astro File Manager (Android Market Link)" href="https://market.android.com/details?id=com.metago.astro">link</a>)</li>
<li>Dex2Jar (<a title="Dex2Jar" href="http://code.google.com/p/dex2jar/">link</a>)</li>
<li>jd-gui (<a title="JD GUI" href="http://java.decompiler.free.fr/?q=jdgui">link</a>)</li>
<li>JAD (<a title="Java Decompiler Download" href="http://www.varaneckas.com/jad">link</a>)</li>
</ol>
<table id="cft">
  <thead>
  <tr>
    <th colspan="2">Dex2Jar Info</th>
  </tr>
  </thead>
  <tbody>
    <tr>
      <td  width="40%">App Name</td>
      <td>Dex2Jar</td>
    </tr>
    <tr>
      <td>License</td>
      <td>free</td>
    </tr>
    <tr>
      <td>Type</td>
      <td><ul>
<li>portable</li>
<li>code</li>
</ul>
</td>
    </tr>
    <tr>
      <td>App URL</td>
      <td>
      <a target="_blank" href="http://code.google.com/p/dex2jar/"><img
 style="" alt="Download"
 src="http://img.a4apphack.com/site/a4apphack-download.png"
 title="Download" witdh="30" height="30"></a></td>
    </tr>
    <tr>
      <td>More Info</td>
      <td> <a href="http://code.google.com/p/dex2jar/">link</a></td>
    </tr>
  </tbody>
</table>

<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=2152&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/sec-code/extract-android-apk-from-market-and-decompile-it-to-java-source/feed</wfw:commentRss>
		<slash:comments>34</slash:comments>
		</item>
		<item>
		<title>Gruyere &#8211; Vulnerable Web Application At Google Code (Previously Jarlsberg)</title>
		<link>http://a4apphack.com/security/sec-code/jarlsberg-vulnerable-web-application-at-google-code</link>
		<comments>http://a4apphack.com/security/sec-code/jarlsberg-vulnerable-web-application-at-google-code#comments</comments>
		<pubDate>Mon, 17 May 2010 19:11:29 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Code]]></category>
		<category><![CDATA[Tutorials]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[learn]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[xsrf]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1936</guid>
		<description><![CDATA[Gruyere is a vulnerable application which can be used to learn and understand web vulnerabilities. Detailed documentation is provided on the type of the vulnerabilities present in the application and ways to exploits it. Update: Jarlsberg is now Gruyere This codelab shows how web application vulnerabilities can be exploited and how to defend against these attacks. [...]]]></description>
			<content:encoded><![CDATA[<p>Gruyere is a vulnerable application which can be used to learn and understand web vulnerabilities. Detailed documentation is provided on the type of the vulnerabilities present in the application and ways to exploits it.</p>
<p><strong><span style="color: #800000;">Update</span>: Jarlsberg is now Gruyere<br />
</strong></p>
<ul>
</ul>
<p><em>This codelab shows how web application vulnerabilities can be exploited and how to defend against these attacks. The best way to learn things is by doing, so you&#8217;ll get a chance to do some real penetration testing, actually exploiting a real application. Specifically, you&#8217;ll learn the following:</em></p>
<ul>
<li><em> How an application can be attacked using common web security vulnerabilities, like cross-site scripting vulnerabilities (XSS) and cross-site request forgery (XSRF). </em></li>
<li><em> How to find, fix, and avoid these common vulnerabilities and other bugs that have a security impact, such as denial-of-service, information disclosure, or remote code execution. </em></li>
</ul>
<p><a title="Jarlsberg Documentation" href="http://jarlsberg.appspot.com/part2">Documentation Here</a></p>
<p><img class="alignnone" title="Jarlsberg - Hosted Vulnerable App" src="http://img.a4apphack.com/jarlsbergapp-main.jpg" alt="Jarlsberg - Hosted Vulnerable App" width="600" height="412" /></p>
<p><span id="more-1936"></span></p>
<p><strong>Some Exploit Screenshots</strong></p>
<p>Information Disclosure &#8211; Read the contents of the database off of a running server by exploiting a configuration vulnerability.</p>
<p><em>Debug Dump Page URL</em> &#8211; http://google-gruyere.appspot.com/<span style="color: #ff0000;">457262944951</span>/dump.jtl</p>
<p>The id changes based on your session.</p>
<p><img class="alignnone" title="Jarlsberg Dump Page" src="http://img.a4apphack.com/jarlsbergapp-dump.jpg" alt="Jarlsberg Dump Page" width="600" height="405" /></p>
<p><strong>Reflected XSS</strong></p>
<p>Alert Dialog box which indicates the presence of <a title="Cross Site Scripting Vulnerability" href="http://a4apphack.com/index.php/security/xss-made-simple-flash-animation">Cross Site Scripting Vulnerability</a> present in Jarlsberg</p>
<p><br class="spacer_" /></p>
<div class="wp-caption alignnone" style="width: 610px"><img class="" title="Stored XSS alert" src="http://img.a4apphack.com/jarlsbergapp-storedxss.jpg" alt="Stored XSS alert" width="600" height="340" /><p class="wp-caption-text">Stored XSS alert</p></div>
<p><br class="spacer_" /></p>
<h3><strong>Features</strong></h3>
<p>Jarlsberg includes a number of special features and technologies which add attack surface.</p>
<ul>
<li> HTML in Snippets: Users can include a limited subset of HTML in their snippets. </li>
<li> File upload: Users can upload files to the server, e.g., to include pictures in their snippets. </li>
<li> Web administration: System administrators can manage the system using a web interface. </li>
<li> New accounts: Users can create their own accounts. </li>
<li> Template language: Jarlsberg Template Language(JTL) is a new language that makes writing web pages easy as the templates connect directly to the database. Documentation for JTL can be found in <code><a href="http://google-gruyere.appspot.com/code/?jtl.py">gruyere/jtl.py</a></code>. </li>
<li> AJAX: Jarlsberg uses AJAX to implement refresh on the home and snippets page. You should ignore the AJAX parts of Jarlsberg except for the challenges that specifically tell you to focus on AJAX. </li>
</ul>
<h3><strong>Vulnerabilities In Gruyere</strong></h3>
<ul>
<li>Cross-Site Scripting (XSS)
<ul>
<li>File Upload XSS</li>
<li>Reflected XSS</li>
<li>Stored XSS</li>
<li>Stored XSS via HTML Attribute</li>
<li>Stored XSS via AJAX</li>
<li>Reflected XSS via AJAX</li>
</ul>
</li>
<li>Client-State Manipulation
<ul>
<li>Elevation of Privilege</li>
<li>Cookie Manipulation</li>
</ul>
</li>
<li>Cross-Site Request Forgery (XSRF)</li>
<li>Cross Site Script Inclusion (XSSI)</li>
<li>Path Traversal
<ul>
<li>Information disclosure via path traversal</li>
<li>Data tampering via path traversal</li>
</ul>
</li>
<li>Denial of Service
<ul>
<li>DoS &#8211; Quit the Server</li>
<li>DoS &#8211; Overloading the Server</li>
</ul>
</li>
<li>Code Execution</li>
<li>Information disclosure</li>
<li>AJAX vulnerabilities
<ul>
<li>DoS via AJAX</li>
<li>Phishing via AJAX</li>
</ul>
</li>
<li>Buffer Overflow and Integer Overflow</li>
<li>SQL Injection</li>
</ul>
<p>Explore hosted version of Jarlsberg and start uncovering the vulnerabilities</p>
<p><a title="Gruyere" href="http://google-gruyere.appspot.com/start">Gruyere Hosted Version</a></p>
<table id="cft">
  <thead>
  <tr>
    <th colspan="2">Gruyere (Previously Jarlsberg) Info</th>
  </tr>
  </thead>
  <tbody>
    <tr>
      <td  width="40%">App Name</td>
      <td>Gruyere (Previously Jarlsberg)</td>
    </tr>
    <tr>
      <td>License</td>
      <td>free</td>
    </tr>
    <tr>
      <td>Type</td>
      <td><ul>
<li>online</li>
<li>code</li>
</ul>
</td>
    </tr>
    <tr>
      <td>App URL</td>
      <td>
      <a target="_blank" href="http://google-gruyere.appspot.com//start"><img
 style="" alt="Download"
 src="http://img.a4apphack.com/site/a4apphack-download.png"
 title="Download" witdh="30" height="30"></a></td>
    </tr>
    <tr>
      <td>More Info</td>
      <td> <a href="http://google-gruyere.appspot.com/">link</a></td>
    </tr>
  </tbody>
</table>

<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1936&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/sec-code/jarlsberg-vulnerable-web-application-at-google-code/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HTML5 CheatSheet Project</title>
		<link>http://a4apphack.com/security/sec-browser/html5-cheatsheet-project</link>
		<comments>http://a4apphack.com/security/sec-browser/html5-cheatsheet-project#comments</comments>
		<pubDate>Thu, 13 May 2010 21:49:50 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Browser]]></category>
		<category><![CDATA[Code]]></category>
		<category><![CDATA[appsec]]></category>
		<category><![CDATA[chrome]]></category>
		<category><![CDATA[code]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[html5]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1962</guid>
		<description><![CDATA[HTML5 is a new and upcoming technology which has enough features to introduce potential security issues if not properly implemented. A new project has been initiated in Google Code to keep developers updated on the security concerns to be kept in mind while developing their apps with HTML5. Description of Project in Authors Terms, This [...]]]></description>
			<content:encoded><![CDATA[<p>HTML5 is a new and upcoming technology which has enough features to introduce potential security issues if not properly implemented. A new project has been initiated in Google Code to keep developers updated on the security concerns to be kept in mind while developing their apps with <a title="HTML5" href="http://en.wikipedia.org/wiki/HTML5">HTML5</a>.</p>
<p>Description of Project in Authors Terms,</p>
<blockquote><p><em>This project is an attempt to create a well maintained, informative and categorized cheat sheet to highlight HTML5 as well as other client side and related security issues and ways to avoid them.  The project is meant to target web developers as well as security researchers and especially browser vendors since many of the problems we found are based on faulty or quirky implementations. Focus is on completeness, comprehensibility and timeliness as well as continuity &#8211; benefits many other related cheat sheets don&#8217;t exactly provide.</em></p>
<p></em></p>
</blockquote>
<p><span id="more-1962"></span></p>
<p><a href="http://img.a4apphack.com/html5sec-main.jpg" rel="lightbox[1962]" title="HTML5 Security Cheatsheet"><img class="alignnone" title="HTML5 Security Cheatsheet" src="http://img.a4apphack.com/html5sec-main.jpg" alt="HTML5 Security Cheatsheet" width="600" height="493" /></a></p>
<p>Time to this site if are a developer or security analyst.</p>
<p><a title="HTML5 Cheatsheet" href="http://heideri.ch/jso/">HTML5 CheatSheet</a></p>
<table id="cft">
  <thead>
  <tr>
    <th colspan="2">HTML5 CheatSheet Info</th>
  </tr>
  </thead>
  <tbody>
    <tr>
      <td  width="40%">App Name</td>
      <td>HTML5 CheatSheet</td>
    </tr>
    <tr>
      <td>License</td>
      <td>free</td>
    </tr>
    <tr>
      <td>Type</td>
      <td>online</td>
    </tr>
    <tr>
      <td>App URL</td>
      <td>
      <a target="_blank" href="http://heideri.ch/jso/"><img
 style="" alt="Download"
 src="http://img.a4apphack.com/site/a4apphack-download.png"
 title="Download" witdh="30" height="30"></a></td>
    </tr>
    <tr>
      <td>More Info</td>
      <td> <a href="http://code.google.com/p/html5security/">link</a></td>
    </tr>
  </tbody>
</table>

<p><br class="spacer_" /></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1962&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/sec-browser/html5-cheatsheet-project/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Disclosure of XSS Vulnerability in SharePoint 2007</title>
		<link>http://a4apphack.com/security/sec-code/disclosure-of-xss-vulnerability-in-sharepoint-2007</link>
		<comments>http://a4apphack.com/security/sec-code/disclosure-of-xss-vulnerability-in-sharepoint-2007#comments</comments>
		<pubDate>Thu, 06 May 2010 21:43:12 +0000</pubDate>
		<dc:creator>rajivvishwa</dc:creator>
				<category><![CDATA[Code]]></category>
		<category><![CDATA[attack]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[sharepoint]]></category>
		<category><![CDATA[va]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://a4apphack.com/index.php/?p=1954</guid>
		<description><![CDATA[An XSS vulnerability has been discovered and disclosed to public in SharePoint Server 2007 and Microsoft Windows SharePoint Services 3.0. The vulnerability could allow an attacker to run arbitrary script that could result in elevation of privilege within the SharePoint site, as opposed to elevation of privilege within the workstation or server environment. This vulnerability [...]]]></description>
			<content:encoded><![CDATA[<p>An XSS vulnerability has been discovered and disclosed to public in SharePoint Server 2007 and Microsoft Windows SharePoint Services 3.0. The vulnerability could allow an attacker to run arbitrary script that could result in elevation of privilege within the SharePoint site, as opposed to elevation of privilege within the workstation or server environment.</p>
<p>This vulnerability is discovered by <a title="HiTech Bridge" href="http://www.htbridge.ch/">High-Tech Bridge SA</a> and has been notified to Microsoft 12 April 2010. On the day of writing of this post, the vulnerability remains unfixed.</p>
<p>Read HTBridge advisory <a title="XSS in Microsoft SharePoint Server 2007" href="http://www.htbridge.ch/advisory/xss_in_microsoft_sharepoint_server_2007.html">here</a></p>
<p><strong>Vulnerable URL :</strong></p>

<div class="wp_syntax"><div class="code"><pre class="html" style="font-family:monospace;">http://TARGETSITE/_layouts/help.aspx?cid0=MS.WSS.manifest.xml%00%3Cscript%3Ealert%28%27XSS%27%29%3C/script%3E&amp;tid=X</pre></div></div>

<p><strong>Screenshot</strong></p>
<p><img class="alignnone" title="SharePoint 2007 XSS Vulnerability" src="http://img.a4apphack.com/sp07xss-main.jpg" alt="SharePoint 2007 XSS Vulnerability" width="600" height="304" /></p>
<p>Read more at <a title="Microsoft Security Advisory (983438)" href="http://www.microsoft.com/technet/security/advisory/983438.mspx">Microsoft Security Advisory (983438)</a></p>
<img src="http://a4apphack.com/blog/?ak_action=api_record_view&id=1954&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://a4apphack.com/security/sec-code/disclosure-of-xss-vulnerability-in-sharepoint-2007/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)
Object Caching 1122/1148 objects using disk: basic

Served from: a4apphack.com @ 2012-05-19 09:05:41 -->
