<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: AttackAPI</title>
	<atom:link href="http://www.gnucitizen.org/projects/attackapi/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.gnucitizen.org/projects/attackapi/</link>
	<description>Cutting-edge Think tank &#124; Ethical Hacker Outfit</description>
	<pubDate>Fri, 04 Jul 2008 17:23:50 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>By: 2007 Security Testing tools in review &#124; tssci security</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-76439</link>
		<dc:creator>2007 Security Testing tools in review &#124; tssci security</dc:creator>
		<pubDate>Sat, 24 Nov 2007 17:43:43 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-76439</guid>
		<description>[...] (and these could be open-sourced like the SQL Hooker tool). For now, the Metasploit, GNUCITIZEN AttackAPI, and the BeEF framework appear to be the dominant exploit tools for web applications. The W3AF [...]</description>
		<content:encoded><![CDATA[<p>[...] (and these could be open-sourced like the SQL Hooker tool). For now, the Metasploit, GNUCITIZEN AttackAPI, and the BeEF framework appear to be the dominant exploit tools for web applications. The W3AF [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-32338</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Wed, 27 Jun 2007 13:31:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-32338</guid>
		<description>rootkid, I've created &lt;a href="http://groups.google.com/group/attackapi" rel="nofollow"&gt;AttackAPI Google group&lt;/a&gt;. Feel free to post your stuff there. I would like to build community around the library too since V3 looks very promising in terms of new features. I am not sure whether I discussed this thing somewhere else, but AttackAPIv3 has features to export the most basic set of requirements for each attack payload.</description>
		<content:encoded><![CDATA[<p>rootkid, I&#8217;ve created <a href="http://groups.google.com/group/attackapi" rel="nofollow">AttackAPI Google group</a>. Feel free to post your stuff there. I would like to build community around the library too since V3 looks very promising in terms of new features. I am not sure whether I discussed this thing somewhere else, but AttackAPIv3 has features to export the most basic set of requirements for each attack payload.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rootkid</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-32336</link>
		<dc:creator>rootkid</dc:creator>
		<pubDate>Wed, 27 Jun 2007 13:16:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-32336</guid>
		<description>pdp, I really like your library so far, helped me a _LOT_ developing my own stuff. At the moment I am pretty much stuck here with a problem regarding execution of an AttackApi script in an IE 6 environment. Is there anything like a chat or forum which can be used for problems like this (I'd rather do it this way than posting it to code.google.com, as I am not sure if this really is an issue or simply stupidity of me). I'd really like to see a AttackAPI community out there..:)</description>
		<content:encoded><![CDATA[<p>pdp, I really like your library so far, helped me a _LOT_ developing my own stuff. At the moment I am pretty much stuck here with a problem regarding execution of an AttackApi script in an IE 6 environment. Is there anything like a chat or forum which can be used for problems like this (I&#8217;d rather do it this way than posting it to code.google.com, as I am not sure if this really is an issue or simply stupidity of me). I&#8217;d really like to see a AttackAPI community out there..:)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Web App Security: Comparing and contrasting Black Box, White Box, Fault Injection, and SCA - QuietMove</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-28646</link>
		<dc:creator>Web App Security: Comparing and contrasting Black Box, White Box, Fault Injection, and SCA - QuietMove</dc:creator>
		<pubDate>Thu, 14 Jun 2007 00:57:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-28646</guid>
		<description>[...] At the same time, the population of attackers has vastly increased. The maxim goes that a security system is only as strong as its weakest link, so thatâ€™s what attackers look for. Attacks have moved both up and down the stack. By this I mean, up to the application and even client level, and down to the system internals and driver level. Blue Pill, a virtual machine malware platform, is one such example that takes advantage of hardware features at the bottom level, while at the top level you have the world of web application attacks, where web applications are used as proxies to attack the integrity of the application as well as its architectural dependencies, and Javascript attacks, which are used to attack the softest target of all â€“ the end user. At the Javascript / client attack level, state of the art is represented by PDPâ€™s AttackAPI. [...]</description>
		<content:encoded><![CDATA[<p>[...] At the same time, the population of attackers has vastly increased. The maxim goes that a security system is only as strong as its weakest link, so thatâ€™s what attackers look for. Attacks have moved both up and down the stack. By this I mean, up to the application and even client level, and down to the system internals and driver level. Blue Pill, a virtual machine malware platform, is one such example that takes advantage of hardware features at the bottom level, while at the top level you have the world of web application attacks, where web applications are used as proxies to attack the integrity of the application as well as its architectural dependencies, and Javascript attacks, which are used to attack the softest target of all â€“ the end user. At the Javascript / client attack level, state of the art is represented by PDPâ€™s AttackAPI. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: The Security Catalyst &#187; Blog Archive &#187; Web App Security: Comparing and contrasting Black Box, White Box, Fault Injection, and SCA</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-26258</link>
		<dc:creator>The Security Catalyst &#187; Blog Archive &#187; Web App Security: Comparing and contrasting Black Box, White Box, Fault Injection, and SCA</dc:creator>
		<pubDate>Mon, 04 Jun 2007 11:38:56 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-26258</guid>
		<description>[...] At the same time, the population of attackers has vastly increased. The maxim goes that a security system is only as strong as its weakest link, so thatâ€™s what attackers look for. Attacks have moved both up and down the stack. By this I mean, up to the application and even client level, and down to the system internals and driver level. Blue Pill, a virtual machine malware platform, is one such example that takes advantage of hardware features at the bottom level, while at the top level you have the world of web application attacks, where web applications are used as proxies to attack the integrity of the application as well as its architectural dependencies, and Javascript attacks, which are used to attack the softest target of all â€“ the end user. At the Javascript / client attack level, state of the art is represented by PDPâ€™s AttackAPI. [...]</description>
		<content:encoded><![CDATA[<p>[...] At the same time, the population of attackers has vastly increased. The maxim goes that a security system is only as strong as its weakest link, so thatâ€™s what attackers look for. Attacks have moved both up and down the stack. By this I mean, up to the application and even client level, and down to the system internals and driver level. Blue Pill, a virtual machine malware platform, is one such example that takes advantage of hardware features at the bottom level, while at the top level you have the world of web application attacks, where web applications are used as proxies to attack the integrity of the application as well as its architectural dependencies, and Javascript attacks, which are used to attack the softest target of all â€“ the end user. At the Javascript / client attack level, state of the art is represented by PDPâ€™s AttackAPI. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: f0rg3</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-23095</link>
		<dc:creator>f0rg3</dc:creator>
		<pubDate>Tue, 22 May 2007 02:09:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-23095</guid>
		<description>I'm really banking alot of the future of web  application security on XSS, As in i'm staking my career on it. Sure BUffer overflows are still gonna exist and teh skillz are requisite but xss is the future and any hacker worth his salt should know about this. thanks Mr pdp, you are an invaluable resource/person. Big Up.</description>
		<content:encoded><![CDATA[<p>I&#8217;m really banking alot of the future of web  application security on XSS, As in i&#8217;m staking my career on it. Sure BUffer overflows are still gonna exist and teh skillz are requisite but xss is the future and any hacker worth his salt should know about this. thanks Mr pdp, you are an invaluable resource/person. Big Up.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pdp</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-7413</link>
		<dc:creator>pdp</dc:creator>
		<pubDate>Sat, 17 Mar 2007 16:57:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-7413</guid>
		<description>sure, give it a go. If you find any problems with it please post them &lt;a href="http://code.google.com/p/attackapi/issues/list" rel="nofollow"&gt;here&lt;/a&gt;. Thanks.</description>
		<content:encoded><![CDATA[<p>sure, give it a go. If you find any problems with it please post them <a href="http://code.google.com/p/attackapi/issues/list" rel="nofollow">here</a>. Thanks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan Novak</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-7397</link>
		<dc:creator>Jan Novak</dc:creator>
		<pubDate>Sat, 17 Mar 2007 16:11:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-7397</guid>
		<description>i'd like to test this api</description>
		<content:encoded><![CDATA[<p>i&#8217;d like to test this api</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AttackAPI 2.0 Alpha - JavaScript Hacking Suite &#187;</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-2167</link>
		<dc:creator>AttackAPI 2.0 Alpha - JavaScript Hacking Suite &#187;</dc:creator>
		<pubDate>Wed, 10 Jan 2007 05:04:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-2167</guid>
		<description>[...] http://www.gnucitizen.org/projects/attackapi/ [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.gnucitizen.org/projects/attackapi/" rel="nofollow">http://www.gnucitizen.org/projects/attackapi/</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Operation n &#187; Hacking with Images 1</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-1626</link>
		<dc:creator>Operation n &#187; Hacking with Images 1</dc:creator>
		<pubDate>Sat, 30 Dec 2006 01:08:59 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-1626</guid>
		<description>[...] Note: This is the port scanning technique jssWebImage  uses, which was originally taken from AttackAPI [...]</description>
		<content:encoded><![CDATA[<p>[...] Note: This is the port scanning technique jssWebImage  uses, which was originally taken from AttackAPI [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Depressive Developer &#187; Backframe und AttackAPI installieren und nutzen</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-775</link>
		<dc:creator>Depressive Developer &#187; Backframe und AttackAPI installieren und nutzen</dc:creator>
		<pubDate>Sun, 26 Nov 2006 12:25:40 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-775</guid>
		<description>[...] Dieser Beitrag liefert ein Step-By-Setp-Tutorial, wie man die Kombination aus Backframe und der AttackAPI auf einem lokalen Server installieren und nutzen kann. Backframe ist ein Hacking-Framework aus der Feder von Petko Petkov - ebenfalls Autor der AttackAPI. Backframe bietet eine GUI, mit der sich Channels verwalten lassen, &#252;ber die beliebiger JavaScript-Code in Webseiten eingeschlust werden kann. Die AttackAPI hingegen ist eine JavaScript-Library, das die gebr&#228;uchlichsten Methoden bereith&#228;lt, mit denen Angreifer Webseiten testen und Informationen vom Client, der die Webseite besucht, ermiteln k&#246;nnen. [...]</description>
		<content:encoded><![CDATA[<p>[...] Dieser Beitrag liefert ein Step-By-Setp-Tutorial, wie man die Kombination aus Backframe und der AttackAPI auf einem lokalen Server installieren und nutzen kann. Backframe ist ein Hacking-Framework aus der Feder von Petko Petkov - ebenfalls Autor der AttackAPI. Backframe bietet eine GUI, mit der sich Channels verwalten lassen, &#252;ber die beliebiger JavaScript-Code in Webseiten eingeschlust werden kann. Die AttackAPI hingegen ist eine JavaScript-Library, das die gebr&#228;uchlichsten Methoden bereith&#228;lt, mit denen Angreifer Webseiten testen und Informationen vom Client, der die Webseite besucht, ermiteln k&#246;nnen. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AttackAPI 0.8 JavaScript Hacking Suite Available &#187;</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-725</link>
		<dc:creator>AttackAPI 0.8 JavaScript Hacking Suite Available &#187;</dc:creator>
		<pubDate>Tue, 21 Nov 2006 16:09:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-725</guid>
		<description>[...] http://www.gnucitizen.org/projects/attackapi/build/standalone/AttackAPI.js [...]</description>
		<content:encoded><![CDATA[<p>[...] <a href="http://www.gnucitizen.org/projects/attackapi/build/standalone/AttackAPI.js" rel="nofollow">http://www.gnucitizen.org/proj.....tackAPI.js</a> [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Operation n &#187; Blog Archive &#187; JSScanner</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-308</link>
		<dc:creator>Operation n &#187; Blog Archive &#187; JSScanner</dc:creator>
		<pubDate>Mon, 23 Oct 2006 22:53:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-308</guid>
		<description>[...] Credits: pdp (http://gnucitizen.org) I hope to incorporate this project into pdp&#8217;s AttackAPI at some point. It currently uses AttackAPI&#8217;s IP Calculator script. [...]</description>
		<content:encoded><![CDATA[<p>[...] Credits: pdp (http://gnucitizen.org) I hope to incorporate this project into pdp&#8217;s AttackAPI at some point. It currently uses AttackAPI&#8217;s IP Calculator script. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Talk at 0sec at Disenchant&#8217;s Blog</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-263</link>
		<dc:creator>Talk at 0sec at Disenchant&#8217;s Blog</dc:creator>
		<pubDate>Tue, 17 Oct 2006 19:57:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-263</guid>
		<description>[...] I&#8217;ll also release my XSS-Toolkit in a few days (I hope  ) which I used to show some demos during the talk but first I&#8217;ll have a look on the newest version of pdp&#8217;s Attack API because the I can include also some stuff he did or replace some stuff of mine. [...]</description>
		<content:encoded><![CDATA[<p>[...] I&#8217;ll also release my XSS-Toolkit in a few days (I hope  ) which I used to show some demos during the talk but first I&#8217;ll have a look on the newest version of pdp&#8217;s Attack API because the I can include also some stuff he did or replace some stuff of mine. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GNUCITIZEN &#187; AttackAPI 0.8 is OUT</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-257</link>
		<dc:creator>GNUCITIZEN &#187; AttackAPI 0.8 is OUT</dc:creator>
		<pubDate>Mon, 16 Oct 2006 04:39:21 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-257</guid>
		<description>[...] I would recommend AttackAPI 0.8 to everyone who is interested in high-end hacking not because I wrote it but because it provides a good demonstration of what is possible today. That, I hope will take our awareness even further. [...]</description>
		<content:encoded><![CDATA[<p>[...] I would recommend AttackAPI 0.8 to everyone who is interested in high-end hacking not because I wrote it but because it provides a good demonstration of what is possible today. That, I hope will take our awareness even further. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Johannes Gumbel [Pentestare] : XSS blir ett allvarligt hot</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-177</link>
		<dc:creator>Johannes Gumbel [Pentestare] : XSS blir ett allvarligt hot</dc:creator>
		<pubDate>Tue, 03 Oct 2006 14:54:02 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-177</guid>
		<description>[...] XSS blir ett allvarligt hot   Cross Site Scripting (XSS), SQL-injektion, Kommando-injektion, etc. Alla populära brister i webbapplikationer. Till för inte så länge sedan har XSS ofta ansetts som ganska harmlöst, inte alls lika allvarligt som SQL/LDAP/Kommando-injektion. Inte ens efter att de första XSS maskarna/virus blev alla övertygade om att det verkligen var ett problem.För er som redan är övertygade och bara vill få ta del av den magiska världen av browser-hacking, och för er som inte alls är övertygade och behöver få mera information, föreslår jag att ni kollar in http://www.gnucitizen.org/projects/attackapi/. Denna site inkluderar även länkar/artiklar om hur ni kan trojanisera både mp3 och pdf (har inte hunnit läsa själv än, tyvärr) osv.Gnucitizen (länken ovan) har även en intressant artikel om hur man kan bygga en slave/master relation mellan en browser som kört vårat javascript och en av oss kontrollerad webbserver. Ganska sweet och skrämmande (på samma gång) i mina öron.Jag tänkte jag skulle ge er en till länk, en presentation från blackhat där det demonstreras hur javascript kan användas för att angripa interna resurser, mycket inressant. http://www.blackhat.com/presentations/bh-usa-06/BH-US-06-Grossman.pdf#search=%22hacking%20intranet%20websites%20from%20the%20outside%22   Published den 3 oktober 2006 16:41 by Johannes Gumbel [...]</description>
		<content:encoded><![CDATA[<p>[...] XSS blir ett allvarligt hot   Cross Site Scripting (XSS), SQL-injektion, Kommando-injektion, etc. Alla populära brister i webbapplikationer. Till för inte så länge sedan har XSS ofta ansetts som ganska harmlöst, inte alls lika allvarligt som SQL/LDAP/Kommando-injektion. Inte ens efter att de första XSS maskarna/virus blev alla övertygade om att det verkligen var ett problem.För er som redan är övertygade och bara vill få ta del av den magiska världen av browser-hacking, och för er som inte alls är övertygade och behöver få mera information, föreslår jag att ni kollar in <a href="http://www.gnucitizen.org/projects/attackapi/" rel="nofollow">http://www.gnucitizen.org/projects/attackapi/</a>. Denna site inkluderar även länkar/artiklar om hur ni kan trojanisera både mp3 och pdf (har inte hunnit läsa själv än, tyvärr) osv.Gnucitizen (länken ovan) har även en intressant artikel om hur man kan bygga en slave/master relation mellan en browser som kört vårat javascript och en av oss kontrollerad webbserver. Ganska sweet och skrämmande (på samma gång) i mina öron.Jag tänkte jag skulle ge er en till länk, en presentation från blackhat där det demonstreras hur javascript kan användas för att angripa interna resurser, mycket inressant. <a href="http://www.blackhat.com/presentations/bh-usa-06/BH-US-06-Grossman.pdf#search=%22hacking%20intranet%20websites%20from%20the%20outside%22" rel="nofollow">http://www.blackhat.com/presen.....outside%22</a>   Published den 3 oktober 2006 16:41 by Johannes Gumbel [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Depressive Developer &#187; F?hr! Mich! Aus!</title>
		<link>http://www.gnucitizen.org/projects/attackapi/#comment-143</link>
		<dc:creator>Depressive Developer &#187; F?hr! Mich! Aus!</dc:creator>
		<pubDate>Sun, 24 Sep 2006 16:06:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.gnucitizen.org/projects/attackapi#comment-143</guid>
		<description>[...] Nein, nun muss auch Argwohn walten, wenn man einen Link auf ein Video, auf ein MP3 oder ein PDF bekommt - was sich alles in den Files verbergen kann, verdeutlicht ein Blick auf Gnucitizen&#8217;s Attack API und die Annahme, dass der Virenscanner bei XSS-Attacken anschlagen w?rde muss ich hier leider als naive Illusion brandmarken. Trotzdem kein grund, in Panik auszubrechen - von echten Angriffen ?ber versechte Videos oder ?hnliches habe ich bislang noch nichts geh?rt und es geh?rt schon einiges an krimineller Eneregie dazu, Quicktime Videos entsprechend zu pr?parieren. [...]</description>
		<content:encoded><![CDATA[<p>[...] Nein, nun muss auch Argwohn walten, wenn man einen Link auf ein Video, auf ein MP3 oder ein PDF bekommt - was sich alles in den Files verbergen kann, verdeutlicht ein Blick auf Gnucitizen&#8217;s Attack API und die Annahme, dass der Virenscanner bei XSS-Attacken anschlagen w?rde muss ich hier leider als naive Illusion brandmarken. Trotzdem kein grund, in Panik auszubrechen - von echten Angriffen ?ber versechte Videos oder ?hnliches habe ich bislang noch nichts geh?rt und es geh?rt schon einiges an krimineller Eneregie dazu, Quicktime Videos entsprechend zu pr?parieren. [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
