<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Cross-site File Upload Attacks</title>
	<atom:link href="http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/</link>
	<description>Information Security Think Tank</description>
	<lastBuildDate>Sat, 02 Feb 2013 17:50:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: Top Ten Web Hacking Techniques of 2008 : RootBrain.Com · The Best IT Security Training &#38; Consulting · Pusat Pelatihan dan Konsultasi TI Terbaik di Yogyakarta</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-134051</link>
		<dc:creator>Top Ten Web Hacking Techniques of 2008 : RootBrain.Com · The Best IT Security Training &#38; Consulting · Pusat Pelatihan dan Konsultasi TI Terbaik di Yogyakarta</dc:creator>
		<pubDate>Mon, 14 May 2012 08:39:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-134051</guid>
		<description>[...] Cross-site File Upload Attacks [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross-site File Upload Attacks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Submit Your Top Web Hacking Techniques for 2008 &#124; GNUCITIZEN</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-130870</link>
		<dc:creator>Submit Your Top Web Hacking Techniques for 2008 &#124; GNUCITIZEN</dc:creator>
		<pubDate>Fri, 13 May 2011 23:35:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-130870</guid>
		<description>[...] Cross-site File Upload Attacks [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross-site File Upload Attacks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: What&#8217;s new in web hacking techniques of 2008</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-128137</link>
		<dc:creator>What&#8217;s new in web hacking techniques of 2008</dc:creator>
		<pubDate>Tue, 09 Feb 2010 05:36:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-128137</guid>
		<description>[...] Cross-site File Upload Attacks [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross-site File Upload Attacks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sohbet</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-127638</link>
		<dc:creator>Sohbet</dc:creator>
		<pubDate>Wed, 22 Jul 2009 04:52:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-127638</guid>
		<description>Thank you for article. I took great pleasure to read (:</description>
		<content:encoded><![CDATA[<p>Thank you for article. I took great pleasure to read (:</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: site ekle</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-127435</link>
		<dc:creator>site ekle</dc:creator>
		<pubDate>Tue, 09 Jun 2009 08:29:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-127435</guid>
		<description>Thank you for article. I took great pleasure to read</description>
		<content:encoded><![CDATA[<p>Thank you for article. I took great pleasure to read</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Le migliori tecniche di Web Hacking del 2008 &#124; lonerunners.net</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-126313</link>
		<dc:creator>Le migliori tecniche di Web Hacking del 2008 &#124; lonerunners.net</dc:creator>
		<pubDate>Sun, 15 Mar 2009 17:19:35 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-126313</guid>
		<description>[...] Cross-site File Upload Attacks [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross-site File Upload Attacks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Heuristic Delta :: Top 70 Hacking Methods :: http://blogs.heuristicdelta.com</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-126127</link>
		<dc:creator>Heuristic Delta :: Top 70 Hacking Methods :: http://blogs.heuristicdelta.com</dc:creator>
		<pubDate>Wed, 25 Feb 2009 07:44:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-126127</guid>
		<description>[...] Cross-site File Upload Attacks [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross-site File Upload Attacks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: blake</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-126113</link>
		<dc:creator>blake</dc:creator>
		<pubDate>Tue, 24 Feb 2009 22:03:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-126113</guid>
		<description>it works great for webmail (yahoo/symantec &amp; gmail).

see screenshots of yahoo and gmail in .ppt presentation back in July ‘08 on www.appfuzzer.com</description>
		<content:encoded><![CDATA[<p>it works great for webmail (yahoo/symantec &amp; gmail).</p>
<p>see screenshots of yahoo and gmail in .ppt presentation back in July ‘08 on <a href="http://www.appfuzzer.com" rel="nofollow">http://www.appfuzzer.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CSRF-ing File Upload Fields &#124; secdefence.com</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-125838</link>
		<dc:creator>CSRF-ing File Upload Fields &#124; secdefence.com</dc:creator>
		<pubDate>Thu, 05 Feb 2009 14:58:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-125838</guid>
		<description>[...] Oh well, pdp has an interesting post over at gnucitizen.org about how to perform CSRF attacks against File upload fields using Flash: http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Oh well, pdp has an interesting post over at gnucitizen.org about how to perform CSRF attacks against File upload fields using Flash: <a href="http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/" rel="nofollow">http://www.gnucitizen.org/blog.....d-attacks/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ??? &#187; Blog Archive &#187; What&#8217;s new in web hacking techniques of 2008</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-125810</link>
		<dc:creator>??? &#187; Blog Archive &#187; What&#8217;s new in web hacking techniques of 2008</dc:creator>
		<pubDate>Tue, 03 Feb 2009 04:18:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-125810</guid>
		<description>[...] Cross-site File Upload Attacks [...]</description>
		<content:encoded><![CDATA[<p>[...] Cross-site File Upload Attacks [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-124856</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Tue, 23 Dec 2008 14:36:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-124856</guid>
		<description>this method should work although it could also fail from time to time.</description>
		<content:encoded><![CDATA[<p>this method should work although it could also fail from time to time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: maosud</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-124853</link>
		<dc:creator>maosud</dc:creator>
		<pubDate>Tue, 23 Dec 2008 10:45:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-124853</guid>
		<description>i want to upload file with a large size</description>
		<content:encoded><![CDATA[<p>i want to upload file with a large size</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Protocolos de publicaciÃ³n remota en WordPress en Buayacorp - DiseÃ±o y ProgramaciÃ³n</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-122782</link>
		<dc:creator>Protocolos de publicaciÃ³n remota en WordPress en Buayacorp - DiseÃ±o y ProgramaciÃ³n</dc:creator>
		<pubDate>Wed, 02 Jul 2008 03:01:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-122782</guid>
		<description>[...] [1] Por ejemplo las pÃ¡ginas que permiten subir archivos y que generalmente no tienen protecciÃ³n contra ataques CSRF. Actualmente casi todas las versiones de WordPress sufren este problema y se puede explotar usando lo descrito en Cross-site File Upload Attacks. [...]</description>
		<content:encoded><![CDATA[<p>[...] [1] Por ejemplo las pÃ¡ginas que permiten subir archivos y que generalmente no tienen protecciÃ³n contra ataques CSRF. Actualmente casi todas las versiones de WordPress sufren este problema y se puede explotar usando lo descrito en Cross-site File Upload Attacks. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: CSRF-ing File Upload Fields &#187; Inking's Security Blog</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-116401</link>
		<dc:creator>CSRF-ing File Upload Fields &#187; Inking's Security Blog</dc:creator>
		<pubDate>Sat, 15 Mar 2008 05:23:44 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-116401</guid>
		<description>[...] Oh well, pdp has an interesting post over at gnucitizen.org about how to perform CSRF attacks against File upload fields using Flash: http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/ [...]</description>
		<content:encoded><![CDATA[<p>[...] Oh well, pdp has an interesting post over at gnucitizen.org about how to perform CSRF attacks against File upload fields using Flash: <a href="http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/" rel="nofollow">http://www.gnucitizen.org/blog.....d-attacks/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Danno</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-116061</link>
		<dc:creator>Danno</dc:creator>
		<pubDate>Sat, 08 Mar 2008 10:07:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-116061</guid>
		<description>Routers and modems bypassed, now cross site file upload attacks. Good thing I stopped playing poker online for cash. I don&#039;t use this thing to bank or trade stock on either. Cheeky, aren&#039;t they.

What is a n00b to do?</description>
		<content:encoded><![CDATA[<p>Routers and modems bypassed, now cross site file upload attacks. Good thing I stopped playing poker online for cash. I don&#8217;t use this thing to bank or trade stock on either. Cheeky, aren&#8217;t they.</p>
<p>What is a n00b to do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Matt Presson</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-115824</link>
		<dc:creator>Matt Presson</dc:creator>
		<pubDate>Mon, 03 Mar 2008 22:54:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-115824</guid>
		<description>Just a thought here, but after doing some simple research on Flash and file access, an attacker could use &quot;one of the wrapper programs that have been written to allow local file access (SWF Studio, Zinc, Screenweaver, etc)&quot; (per http://www.flash-creations.com/notes/servercomm_textfile.php) along with the above code to create a drive-by file upload service. Especially if you used sendToURL().

If I understand what is presented on the above referenced page, and I may not, then if you could get anyone to visit your page you could upload any file you wished to your server from their local machine.

Any thoughts? Am I crazy?</description>
		<content:encoded><![CDATA[<p>Just a thought here, but after doing some simple research on Flash and file access, an attacker could use &#8220;one of the wrapper programs that have been written to allow local file access (SWF Studio, Zinc, Screenweaver, etc)&#8221; (per <a href="http://www.flash-creations.com/notes/servercomm_textfile.php" rel="nofollow">http://www.flash-creations.com.....xtfile.php</a>) along with the above code to create a drive-by file upload service. Especially if you used sendToURL().</p>
<p>If I understand what is presented on the above referenced page, and I may not, then if you could get anyone to visit your page you could upload any file you wished to your server from their local machine.</p>
<p>Any thoughts? Am I crazy?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-115720</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 27 Feb 2008 11:16:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-115720</guid>
		<description>it used to work but not sure what is the situation right now.</description>
		<content:encoded><![CDATA[<p>it used to work but not sure what is the situation right now.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: guesty</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-115719</link>
		<dc:creator>guesty</dc:creator>
		<pubDate>Wed, 27 Feb 2008 10:57:07 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-115719</guid>
		<description>and how about spoofing the refe(f)rer with flash?</description>
		<content:encoded><![CDATA[<p>and how about spoofing the refe(f)rer with flash?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 757362</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-115530</link>
		<dc:creator>757362</dc:creator>
		<pubDate>Sun, 24 Feb 2008 17:56:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-115530</guid>
		<description>Interesting project. 

&quot;Like CSRF attacks, there are plenty of things one can do with this type of technique.&quot;

- DOM XSS attack entry point.

Using haXe with the Flex2 Framework
http://haxe.org/manual/3/interop#using_haxe_with_the_flex2_framework</description>
		<content:encoded><![CDATA[<p>Interesting project. </p>
<p>&#8220;Like CSRF attacks, there are plenty of things one can do with this type of technique.&#8221;</p>
<p>- DOM XSS attack entry point.</p>
<p>Using haXe with the Flex2 Framework<br />
<a href="http://haxe.org/manual/3/interop#using_haxe_with_the_flex2_framework" rel="nofollow">http://haxe.org/manual/3/inter....._framework</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/comment-page-1/#comment-115403</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Fri, 22 Feb 2008 07:44:08 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/blog/cross-site-file-upload-attacks/#comment-115403</guid>
		<description>&lt;code&gt;LoadVars&lt;/code&gt; is inferior when compared to &lt;code&gt;URLRequest&lt;/code&gt; combined with &lt;code&gt;navigateToURL&lt;/code&gt; or even better &lt;code&gt;sendToURL&lt;/code&gt;. Simply put, the &lt;code&gt;navigateToURL&lt;/code&gt; function will open the result into a browser window/tab while &lt;code&gt;sendToURL&lt;/code&gt; will silently execute it in the background. No restrictions applied!

btw, setting up flex environment is not very hard. you just need the FlexSDK .zip file. Decompress it somewhere on the disk. write your MXML or AS and compile with mxmlc like this:

&lt;pre&gt;&lt;code&gt;path/to/flexsdk/&lt;strong&gt;bin/mxmlc path/to/app.mxml&lt;/strong&gt;&lt;/code&gt;&lt;/pre&gt;</description>
		<content:encoded><![CDATA[<p><code>LoadVars</code> is inferior when compared to <code>URLRequest</code> combined with <code>navigateToURL</code> or even better <code>sendToURL</code>. Simply put, the <code>navigateToURL</code> function will open the result into a browser window/tab while <code>sendToURL</code> will silently execute it in the background. No restrictions applied!</p>
<p>btw, setting up flex environment is not very hard. you just need the FlexSDK .zip file. Decompress it somewhere on the disk. write your MXML or AS and compile with mxmlc like this:</p>
<pre><code>path/to/flexsdk/<strong>bin/mxmlc path/to/app.mxml</strong></code></pre>
]]></content:encoded>
	</item>
</channel>
</rss>
