<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ethicalhack3r &#187; Security</title>
	<atom:link href="http://www.ethicalhack3r.co.uk/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ethicalhack3r.co.uk</link>
	<description></description>
	<lastBuildDate>Tue, 24 Jan 2012 13:20:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>WordPress 3.3 Cross-Site Scripting (XSS)</title>
		<link>http://www.ethicalhack3r.co.uk/security/wordpress-3-3-cross-site-scripting-xss/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/wordpress-3-3-cross-site-scripting-xss/#comments</comments>
		<pubDate>Tue, 03 Jan 2012 18:56:14 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16709</guid>
		<description><![CDATA[Yesterday two Indian security researchers, Aditya Modha &#038; Samir Shah, released an advisory outlining a Cross-Site Scripting (XSS) vulnerability within the latest version (at the time of writing) of WordPress 3.3. Many people started re-tweeting the news (including myself) and blogging about it. The problem came when I tried to reproduce the vulnerability, I couldn&#8217;t. [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/wordpress-3-3-cross-site-scripting-xss/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
		</item>
		<item>
		<title>WordPress Plugin Disqus Comment System XSS</title>
		<link>http://www.ethicalhack3r.co.uk/security/wordpress-plugin-disqus-comment-system-xss/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/wordpress-plugin-disqus-comment-system-xss/#comments</comments>
		<pubDate>Sun, 11 Dec 2011 16:15:17 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16648</guid>
		<description><![CDATA[# Exploit Title: WordPress Plugin Disqus Comment System < = 2.68 Reflected Cross-Site Scripting (XSS) # Google Dork: inurl:/wp-content/plugins/disqus-comment-system/ # Date: 11.12.11 # Author: Ryan Dewhurst (@ethicalhack3r) # Software Link: http://downloads.wordpress.org/plugin/disqus-comment-system.2.68.zip # Version: 2.68 # Tested on: Cross-Platform ** Vulnerability Description ** The WordPress Disqus Commment System version 2.68 was found to be effected by [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/wordpress-plugin-disqus-comment-system-xss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>EC-Council &#8211; CEH &#8211; Unethical Behavior</title>
		<link>http://www.ethicalhack3r.co.uk/security/ec-council-ceh-unethical-behavior/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/ec-council-ceh-unethical-behavior/#comments</comments>
		<pubDate>Sun, 27 Nov 2011 17:42:58 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16619</guid>
		<description><![CDATA[The EC-Council or &#8216;The International Council of E-Commerce Consultants&#8217; as they like to call themselves offer a range of different services, mostly in the field of Information Security training and certifications. One of their certifications, the Certified Ethical Hacker (CEH) claims to aspire to training &#8216;ethical&#8217; hackers. &#8220;CEHv7 provides a comprehensive ethical hacking and network [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/ec-council-ceh-unethical-behavior/feed/</wfw:commentRss>
		<slash:comments>28</slash:comments>
		</item>
		<item>
		<title>WPScan 1.1 released</title>
		<link>http://www.ethicalhack3r.co.uk/security/wpscan-1-1-released/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/wpscan-1-1-released/#comments</comments>
		<pubDate>Fri, 25 Nov 2011 12:32:09 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16610</guid>
		<description><![CDATA[I am pleased to announce, after 5 months of work, that WPScan version 1.1 has been released! With 780 more lines of code the most notable changes are: Detection for 750 more plugins. Detection for 107 new plugin vulnerabilities. Detection for 447 possible timthumb file locations. Advanced version fingerprinting implemented. Full Path Disclosure (FPD) checks. [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/wpscan-1-1-released/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>WordPress &#8216;In the Wild&#8217; and WPScan Update</title>
		<link>http://www.ethicalhack3r.co.uk/security/wordpress-in-the-wild-and-wpscan-update/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/wordpress-in-the-wild-and-wpscan-update/#comments</comments>
		<pubDate>Wed, 23 Nov 2011 00:36:47 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16592</guid>
		<description><![CDATA[As part of my on-going interest in WordPress security I wanted to find out for myself what the state of security was like on installations in the wild. A list of servers running WordPress was acquired from Shodan by searching for a particular HTTP response header and its value. The list contained 10,000 entries, I [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/wordpress-in-the-wild-and-wpscan-update/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Full Path Disclosure (FPD)</title>
		<link>http://www.ethicalhack3r.co.uk/security/full-path-disclosure-fpd/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/full-path-disclosure-fpd/#comments</comments>
		<pubDate>Wed, 05 Oct 2011 13:19:45 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16575</guid>
		<description><![CDATA[Many people including developers, vendors and security professionals believe that Full Path Disclosure (FPD) is mainly a Security Misconfiguration problem rather than a Input Sanitation or Error Handling problem. I&#8217;m not saying that they are wrong, but I hope to convince them that it is more of a coding bug than a configuration bug. I [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/full-path-disclosure-fpd/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Concrete5 </title>
		<link>http://www.ethicalhack3r.co.uk/security/concrete5/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/concrete5/#comments</comments>
		<pubDate>Tue, 04 Oct 2011 11:52:06 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16555</guid>
		<description><![CDATA[# Exploit Title: Concrete5 < = 5.4.2.1 SQL Injection and XSS Vulnerabilities # Date: 2011-10-04 # Author: Ryan Dewhurst (ryandewhurst at gmail) (@ethicalhack3r)(www.ethicalhack3r.co.uk) # Software Link: http://sourceforge.net/projects/concretecms/files/concrete5/5.4.2.1/ # Version: 5.4.2.1 (tested) 1.Vulnerability Description Multiple SQL Injection, Cross-Site Scripting (XSS) and Information Disclosure vulnerabilities were identified within Concrete5 version 5.4.2.1 Please note: Only a select few [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/concrete5/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>[Video] WPScan and Metasploit&#8217;s Meterpreter</title>
		<link>http://www.ethicalhack3r.co.uk/security/video-wpscan-and-metasploits-meterpreter/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/video-wpscan-and-metasploits-meterpreter/#comments</comments>
		<pubDate>Tue, 27 Sep 2011 13:10:56 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Toolz]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16537</guid>
		<description><![CDATA[Video demonstrating the PoC of WPScan using Metasploit&#8217;s meterpreter to exploit a vulnerable WordPress plugin. WPScan and Metasploit&#8217;s Meterpreter from ryan dewhurst on Vimeo.]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/video-wpscan-and-metasploits-meterpreter/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>[ES] Metasploit db_autopwn contra Windows 8</title>
		<link>http://www.ethicalhack3r.co.uk/security/es-metasploit-db_autopwn-contra-windows-8/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/es-metasploit-db_autopwn-contra-windows-8/#comments</comments>
		<pubDate>Wed, 14 Sep 2011 16:12:24 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[Español]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16508</guid>
		<description><![CDATA[Mi primer blog post en Español! (lo siento si mi Español escrito no es perfecto) Ayer (o el anterior) Microsoft hizo disponible &#8220;Windows 8 Developer Preview&#8221; para cualquier persona poder descargar. Yo hize la instalación en VirtualBox siguiendo este guía (en Ingles). Quería ver si Microsoft posiblemente han usado algunas librerías/programas de versiones de Windows [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/es-metasploit-db_autopwn-contra-windows-8/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Setting up Tor on BackTrack</title>
		<link>http://www.ethicalhack3r.co.uk/security/setting-up-tor-on-backtrack/</link>
		<comments>http://www.ethicalhack3r.co.uk/security/setting-up-tor-on-backtrack/#comments</comments>
		<pubDate>Thu, 08 Sep 2011 16:33:59 +0000</pubDate>
		<dc:creator>ethicalhack3r</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Toolz]]></category>

		<guid isPermaLink="false">http://www.ethicalhack3r.co.uk/?p=16496</guid>
		<description><![CDATA[I was playing around with getting wpscan to run through the Tor network so I needed to setup Tor (from source) and Privoxy on BackTrack. These are the steps I took to setup Tor and Privoxy on Backtrack 5 R1. (wpscan does not yet support scanning through the Tor network) I am no Tor expert [...]]]></description>
		<wfw:commentRss>http://www.ethicalhack3r.co.uk/security/setting-up-tor-on-backtrack/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

