<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	>
<channel>
	<title>Comments on: New technique to perform universal website hijacking</title>
	<atom:link href="http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/</link>
	<description>Information Security Think Tank</description>
	<pubDate>Tue, 06 Jan 2009 08:11:35 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.7</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123922</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Thu, 02 Oct 2008 21:26:25 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123922</guid>
		<description>@maxdj: can't comment on any details yet unfortunately :(</description>
		<content:encoded><![CDATA[<p>@maxdj: can&#8217;t comment on any details yet unfortunately :(</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: maxdj</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123902</link>
		<dc:creator>maxdj</dc:creator>
		<pubDate>Tue, 30 Sep 2008 15:06:41 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123902</guid>
		<description>Hi, Is it by chance related to Web security gateway software (Web filtering), aka Internet content-control ?</description>
		<content:encoded><![CDATA[<p>Hi, Is it by chance related to Web security gateway software (Web filtering), aka Internet content-control ?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123880</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Fri, 26 Sep 2008 19:40:22 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123880</guid>
		<description>@ax0n: no, my finding is not related with those advisories you mentioned.</description>
		<content:encoded><![CDATA[<p>@ax0n: no, my finding is not related with those advisories you mentioned.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ax0n</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123855</link>
		<dc:creator>ax0n</dc:creator>
		<pubDate>Thu, 25 Sep 2008 00:37:39 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123855</guid>
		<description>I know some of my favorite vuln finds are serendipitous ones. That's always awesome.

On a side note, your finding wouldn't happen to have anything to do with the huge pile of Cisco advisories that went out today, would it?</description>
		<content:encoded><![CDATA[<p>I know some of my favorite vuln finds are serendipitous ones. That&#8217;s always awesome.</p>
<p>On a side note, your finding wouldn&#8217;t happen to have anything to do with the huge pile of Cisco advisories that went out today, would it?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123844</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Wed, 24 Sep 2008 07:26:27 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123844</guid>
		<description>Sure there is always a possibility that someone else can find the same vulnerability. I wouldn't be so naive to think I'm the only one who found it. 

However, I must warn you that this vuln is a *weird one*. In fact I discovered it by pure accident. I'm planning to explain what lead me to discover it at HITBSecConf, because it's actually kind of a funny story ;)</description>
		<content:encoded><![CDATA[<p>Sure there is always a possibility that someone else can find the same vulnerability. I wouldn&#8217;t be so naive to think I&#8217;m the only one who found it. </p>
<p>However, I must warn you that this vuln is a *weird one*. In fact I discovered it by pure accident. I&#8217;m planning to explain what lead me to discover it at HITBSecConf, because it&#8217;s actually kind of a funny story ;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FilipM</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123832</link>
		<dc:creator>FilipM</dc:creator>
		<pubDate>Tue, 23 Sep 2008 06:18:47 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123832</guid>
		<description>You're right, I should have been more clear. I ment selling it to irresponsible groups or individuals who have some bad intentions with it. 

What about my concern? I know it's possibly impossible to answer correct, but if you have to make a guess, what are the chances that this vuln is already found (and abused) by someone else? 
Without revealing the details on howto, is there a way to check if someone has been a victim of the vuln? Or are there no traces at all? 
As you can notice, you post scared the sh*t out of me   :oÞ</description>
		<content:encoded><![CDATA[<p>You&#8217;re right, I should have been more clear. I ment selling it to irresponsible groups or individuals who have some bad intentions with it. </p>
<p>What about my concern? I know it&#8217;s possibly impossible to answer correct, but if you have to make a guess, what are the chances that this vuln is already found (and abused) by someone else?<br />
Without revealing the details on howto, is there a way to check if someone has been a victim of the vuln? Or are there no traces at all?<br />
As you can notice, you post scared the sh*t out of me   :oÞ</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ax0n</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123831</link>
		<dc:creator>ax0n</dc:creator>
		<pubDate>Tue, 23 Sep 2008 03:49:39 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123831</guid>
		<description>I'd not think listing the vendor would fall into the realm "irresponsible disclosure" and I understand that disclosure is tricky business, and selling vulnerabilities is NOT always a bad thing. 

I've deployed many different solutions for customers, so there's a good chance I have a client whose dick is hanging in the breeze because of this.  I just don't know which one(s). HITBSecConf is a long ways off. And people wonder why I get 15 hours of sleep per week.</description>
		<content:encoded><![CDATA[<p>I&#8217;d not think listing the vendor would fall into the realm &#8220;irresponsible disclosure&#8221; and I understand that disclosure is tricky business, and selling vulnerabilities is NOT always a bad thing. </p>
<p>I&#8217;ve deployed many different solutions for customers, so there&#8217;s a good chance I have a client whose dick is hanging in the breeze because of this.  I just don&#8217;t know which one(s). HITBSecConf is a long ways off. And people wonder why I get 15 hours of sleep per week.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123826</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Mon, 22 Sep 2008 20:35:44 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123826</guid>
		<description>@FlipM: we shouldn't turn selling a vulnerability into a synonym for irresponsible disclosure. There are several *responsible* vulnerability disclosure programs which pay researchers. ZDI for instance is the one I used, which reported the vulnerability I found to the vendor. Of course, the details will only be available once a fix is released.</description>
		<content:encoded><![CDATA[<p>@FlipM: we shouldn&#8217;t turn selling a vulnerability into a synonym for irresponsible disclosure. There are several *responsible* vulnerability disclosure programs which pay researchers. ZDI for instance is the one I used, which reported the vulnerability I found to the vendor. Of course, the details will only be available once a fix is released.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: FilipM</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123823</link>
		<dc:creator>FilipM</dc:creator>
		<pubDate>Mon, 22 Sep 2008 10:21:00 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123823</guid>
		<description>@NurBo: At least Adrian is taking the appropriate steps after finding vulnerabilities, instead of abusing (or even selling!) them. 

But I am concerned. If Adrian found this one, who else found the same? And when? Did someone already abused any of my systems? We'll know after HITBSecConf Malaysia...</description>
		<content:encoded><![CDATA[<p>@NurBo: At least Adrian is taking the appropriate steps after finding vulnerabilities, instead of abusing (or even selling!) them. </p>
<p>But I am concerned. If Adrian found this one, who else found the same? And when? Did someone already abused any of my systems? We&#8217;ll know after HITBSecConf Malaysia&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adrian 'pagvac' Pastor</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123814</link>
		<dc:creator>Adrian 'pagvac' Pastor</dc:creator>
		<pubDate>Sun, 21 Sep 2008 10:06:09 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123814</guid>
		<description>guys, as I said I can't provide full details at this point, even though I would love to! I simply wanted to share what I could regarding the new material which I will present at HITBSecConf Malaysia.</description>
		<content:encoded><![CDATA[<p>guys, as I said I can&#8217;t provide full details at this point, even though I would love to! I simply wanted to share what I could regarding the new material which I will present at HITBSecConf Malaysia.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123812</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sun, 21 Sep 2008 09:33:04 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123812</guid>
		<description>There will never be a good way of disclosing vulnerabilities! At least we try to give you the heads up that an issue exists. The more inform you are the better decisions you can make.</description>
		<content:encoded><![CDATA[<p>There will never be a good way of disclosing vulnerabilities! At least we try to give you the heads up that an issue exists. The more inform you are the better decisions you can make.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NurBo</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123809</link>
		<dc:creator>NurBo</dc:creator>
		<pubDate>Sun, 21 Sep 2008 02:29:20 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123809</guid>
		<description>why tell us about something if your not going to share thats like saying heres some new shoes but you can't wear them.</description>
		<content:encoded><![CDATA[<p>why tell us about something if your not going to share thats like saying heres some new shoes but you can&#8217;t wear them.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ax0n</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123807</link>
		<dc:creator>ax0n</dc:creator>
		<pubDate>Sat, 20 Sep 2008 23:03:26 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123807</guid>
		<description>From a responsible disclosure standpoint, I would much rather have gotten the name of a product family than a list of bad stuff that this vulnerability exposes users to. Now I have to sit around wondering if any of the firewall appliances I've deployed are "the one" and throw extra wide-spectrum effort at the problem despite if I'm actually affected or not.</description>
		<content:encoded><![CDATA[<p>From a responsible disclosure standpoint, I would much rather have gotten the name of a product family than a list of bad stuff that this vulnerability exposes users to. Now I have to sit around wondering if any of the firewall appliances I&#8217;ve deployed are &#8220;the one&#8221; and throw extra wide-spectrum effort at the problem despite if I&#8217;m actually affected or not.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: randomer</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123802</link>
		<dc:creator>randomer</dc:creator>
		<pubDate>Sat, 20 Sep 2008 20:27:51 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123802</guid>
		<description>I bet it's Agnitum Outpost firewall.</description>
		<content:encoded><![CDATA[<p>I bet it&#8217;s Agnitum Outpost firewall.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: N</title>
		<link>http://www.gnucitizen.org/blog/new-technique-to-perform-universal-website-hijacking/comment-page-1/#comment-123801</link>
		<dc:creator>N</dc:creator>
		<pubDate>Sat, 20 Sep 2008 18:41:47 +0000</pubDate>
		<guid isPermaLink="false">https://www.gnucitizen.org/?p=1347#comment-123801</guid>
		<description>cisco pix?</description>
		<content:encoded><![CDATA[<p>cisco pix?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
