<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.2" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>hiredhacker.com</title>
	<link>http://www.hiredhacker.com</link>
	<description>relevant ramblings of an ethical hacker</description>
	<pubDate>Fri, 16 May 2008 18:36:23 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.2</generator>
	<language>en</language>
			<item>
		<title>w3af - Web Application Attack and Audit Framework</title>
		<link>http://www.hiredhacker.com/2008/05/16/w3af-web-application-attack-and-audit-framework/</link>
		<comments>http://www.hiredhacker.com/2008/05/16/w3af-web-application-attack-and-audit-framework/#comments</comments>
		<pubDate>Fri, 16 May 2008 18:36:23 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<category><![CDATA[python]]></category>

		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/05/16/w3af-web-application-attack-and-audit-framework/</guid>
		<description><![CDATA[w3af is a Web Application Attack and Audit Framework. The project goal is to create a framework to find and exploit web application vulnerabilities that is easy to use and extend.
w3af is a great (and getting better) framework that I just decided to start contributing to. I want to get as much attention to these [...]]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/05/16/w3af-web-application-attack-and-audit-framework/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Manny being Manny</title>
		<link>http://www.hiredhacker.com/2008/05/16/manny-being-manny/</link>
		<comments>http://www.hiredhacker.com/2008/05/16/manny-being-manny/#comments</comments>
		<pubDate>Fri, 16 May 2008 15:18:55 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/05/16/manny-being-manny/</guid>
		<description><![CDATA[A little off topic but if you are a fan of the Sox, or just like baseball you gotta see this. Here is Manny&#8217;s sprinting-wall-climbing-high-fiveing-double-play-catch from a few nights ago:
http://www.mlb.com/media/video_sl.jsp?video=200805142699480

]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/05/16/manny-being-manny/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Oh yea, I have a blog&#8230;</title>
		<link>http://www.hiredhacker.com/2008/05/16/oh-yea-i-have-a-blog/</link>
		<comments>http://www.hiredhacker.com/2008/05/16/oh-yea-i-have-a-blog/#comments</comments>
		<pubDate>Fri, 16 May 2008 13:15:20 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<category><![CDATA[site info]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/05/16/oh-yea-i-have-a-blog/</guid>
		<description><![CDATA[The past few months haven&#8217;t exactly been slow for me, hence the lack of new content here. There have been allot of interesting stuff to happen over the past 2 months, I will try to point out the ones I found most interesting. In no particular order (well, except for Mark Dowd&#8217;s inhuman paper, that [...]]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/05/16/oh-yea-i-have-a-blog/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mantis Bug Tracker XSS</title>
		<link>http://www.hiredhacker.com/2008/03/01/mantis-bug-tracker-xss/</link>
		<comments>http://www.hiredhacker.com/2008/03/01/mantis-bug-tracker-xss/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 21:52:15 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<category><![CDATA[xss 0day advisory]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/03/01/mantis-bug-tracker-xss/</guid>
		<description><![CDATA[&#8216;Mantis is a free popular web-based bugtracking system&#8217;  - http://www.mantisbt.org/
I didn&#8217;t audit this, I don&#8217;t want to audit this, I just found it while using Mantis. There may be more, but this is what I got:
/view_filters_page.php
?for_screen=1&#038;target_field=show_category[]%22;alert(1);x=%22
]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/03/01/mantis-bug-tracker-xss/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Quick Update</title>
		<link>http://www.hiredhacker.com/2008/03/01/quick-update/</link>
		<comments>http://www.hiredhacker.com/2008/03/01/quick-update/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 21:48:15 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/03/01/quick-update/</guid>
		<description><![CDATA[February was a very busy month for me, which makes it a slow month for hiredhacker.com. I did change hosts, but that was about it. Between the XBox 360, and my new iPhone I am lucky I even did any real work. Hopefully March will be a better month for hiredhacker and I will get [...]]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/03/01/quick-update/feed/</wfw:commentRss>
		</item>
		<item>
		<title>PyMSRPC Released.</title>
		<link>http://www.hiredhacker.com/2008/02/06/pymsrpc-released/</link>
		<comments>http://www.hiredhacker.com/2008/02/06/pymsrpc-released/#comments</comments>
		<pubDate>Wed, 06 Feb 2008 19:56:51 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/02/06/pymsrpc-released/</guid>
		<description><![CDATA[pymsrpc is an attempt to develop a working library for communicating with remote Microsoft RPC endpoints. It includes an IDL parser and NDR data types for making requests.
I wanted to get this up here in case you haven&#8217;t heard that Cody Pierce and Aaron Portnoy have released PyMSRPC.  I personally have been very excited [...]]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/02/06/pymsrpc-released/feed/</wfw:commentRss>
		</item>
		<item>
		<title>XSS in WP Contact Form III.</title>
		<link>http://www.hiredhacker.com/2008/02/02/xss-in-wp-contact-form-iii/</link>
		<comments>http://www.hiredhacker.com/2008/02/02/xss-in-wp-contact-form-iii/#comments</comments>
		<pubDate>Sat, 02 Feb 2008 17:46:20 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<category><![CDATA[0day]]></category>

		<category><![CDATA[advisory]]></category>

		<category><![CDATA[exploit]]></category>

		<category><![CDATA[wordpress]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/02/02/xss-in-wp-contact-form-iii/</guid>
		<description><![CDATA[The WP Contact Form III 1.4.1 WordPress plugin by &#8216;KristinKWangen&#8217; is vulnerable to multiple cross site scripting attacks. 
Note to developers, this does not stop script injection attacks:
From wp-contactform.php line 105:
$_POST['wpcf_your_name'] = stripslashes(trim($_POST['wpcf_your_name']));
Also note that this is not a very good way to die:
From buttonsnap.php line 28:
$selection = isset($_POST['selection']) ? $_POST['selection'] : @$_GET['selection'];
$selection = apply_filters($dispatch, [...]]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/02/02/xss-in-wp-contact-form-iii/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Router Hacking Challenge.</title>
		<link>http://www.hiredhacker.com/2008/02/02/router-hacking-challenge/</link>
		<comments>http://www.hiredhacker.com/2008/02/02/router-hacking-challenge/#comments</comments>
		<pubDate>Sat, 02 Feb 2008 15:38:36 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<category><![CDATA[hacking]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/02/02/router-hacking-challenge/</guid>
		<description><![CDATA[Ronald has started a router hacking challenge over on 0&#215;000000.com. It&#8217;s an interesting topic, and something I have explored in the past with good results. Take a look and send him your findings.
]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/02/02/router-hacking-challenge/feed/</wfw:commentRss>
		</item>
		<item>
		<title>MySQL Errors, Lag, and Downtime.</title>
		<link>http://www.hiredhacker.com/2008/02/01/mysql-errors-lag-and-downtime/</link>
		<comments>http://www.hiredhacker.com/2008/02/01/mysql-errors-lag-and-downtime/#comments</comments>
		<pubDate>Fri, 01 Feb 2008 19:16:09 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<category><![CDATA[site info]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/02/01/mysql-errors-lag-and-downtime/</guid>
		<description><![CDATA[Over the past few days I have been experiencing some intermediate problems with my hosting provider. They have been short term, random, and not that severe but none the less it pisses me off and annoys the shit out of me. Needless to say I will be switching providers over the weekend, so if there [...]]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/02/01/mysql-errors-lag-and-downtime/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Keys&#8230;</title>
		<link>http://www.hiredhacker.com/2008/01/31/keys/</link>
		<comments>http://www.hiredhacker.com/2008/01/31/keys/#comments</comments>
		<pubDate>Thu, 31 Jan 2008 17:15:11 +0000</pubDate>
		<dc:creator>Gerry Eisenhaur</dc:creator>
		
		<category><![CDATA[Content]]></category>

		<category><![CDATA[reverse engineering]]></category>

		<guid isPermaLink="false">http://www.hiredhacker.com/2008/01/31/keys/</guid>
		<description><![CDATA[iPhone Key:
18 84 58 A6 D1 50 34 DF E3 86 F2 3B 61 D4 37 74
HD-DVD Processing Key:
09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
New AACS Processing Key:
45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B2
Any More?
]]></description>
		<wfw:commentRss>http://www.hiredhacker.com/2008/01/31/keys/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
