<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Web Application Security Forum - News and Links</title>
        <description>If you have some interesting news or want to throw up a link to discuss it, heres the place. Anything is okay, even shameless vendor launches (since that is often applicable to what we work on).</description>
        <link>http://sla.ckers.org/forum/list.php?13</link>
        <lastBuildDate>Thu, 23 May 2013 10:51:46 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51748,51748#msg-51748</guid>
            <title>Game developers getting consulting from Kapersky for more realism in game. (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51748,51748#msg-51748</link>
            <description><![CDATA[http://www.pcgamer.com/2013/05/14/watch-dogs-developers-consult-with-internet-security-firm-for-more-realistic-hacking/<br />
<br />
I don't know how much cross-over there is for the sla.ckers and gaming, but I thought this was really cool. <br />
<br />
Any of you consultants lurking?]]></description>
            <dc:creator>Kyran</dc:creator>
            <category>News and Links</category>
            <pubDate>Tue, 21 May 2013 11:50:36 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51743,51743#msg-51743</guid>
            <title>XCon 2013 XFocus Information Security Conference Call for Paper (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51743,51743#msg-51743</link>
            <description><![CDATA[XCon 2013 XFocus Information Security Conference Call for Paper<br />
<br />
August,  22th–23th , 2013, Beijing, China (http://xcon.xfocus.net)<br />
<br />
Upholding rigorous work style, XCon sincerely welcomes contributions from information security technique enthusiasts and expects your participation and sharing.<br />
<br />
Attenders:<br />
Anyone who loves information security, including information security experts and fans,network administrators, network security consultants, CIO, hacker technique fans.<br />
<br />
 Location : Beijing Jin Tai Hotel ( http://www.bjjintaihotel.com )<br />
<br />
<br />
Topics Range (but unlimited):<br />
   --- Windows 8 defensive technologies<br />
     - New Bugs digging<br />
     - New offensive technologies<br />
     - SNS Application<br />
     - Mobile Handset (IPhone / Android)<br />
     - Web 2.0 security technologies<br />
<br />
    ---Special Network and Devices Security<br />
      - RFID<br />
      - Transportation Control and Management Networks  <br />
<br />
    --- Application security<br />
      - Routing device <br />
      - Encryption &amp; decryption technique <br />
      - Protocol security &amp; exploitation<br />
      - Web application vulnerability research<br />
      - Application reverse engineering and related automated tools<br />
      - Database security &amp; attacks<br />
      - Advanced Trojans, worms and backdoor technique<br />
<br />
   --- Intrusion detection/forensics analysis<br />
     - Traffic analysis<br />
     - Real-time data structure recovery <br />
     - File system analysis &amp; recovery<br />
     - Intrusion detection and anti-detection technique<br />
     - Reverse engineering (malicious code analysis technique,vulnerability research) <br />
     <br />
<br />
   --- Wireless &amp; VoIP security<br />
     - Wireless gateway <br />
     - PDA &amp; mobile protocol analysis<br />
     - WLANs hardening &amp; vulnerability analysis<br />
     - VoIP security &amp; vulnerability analysis<br />
     - 802.11x, CDPD, Bluetooth, WAP/TD-SCDMA, GSM, SMS<br />
<br />
   --- P2P technique<br />
     - Instant messenger (QQ,MSN, Skype, ICQ, etc.)<br />
     - P2P application (BT, Emule, Thunder, etc.)<br />
<br />
   --- Any topics that will catch the attention of the CFP committee and/or the world.<br />
 <br />
Paper Submission:<br />
The papers need include information as follow:<br />
   1) Brief introduction to the topic and whether the topic had been publicized, and if so, the publicized range.<br />
   2) Introduction to yourself.<br />
   3) Contact information: full name, alias, nationality, network nickname, e-mail,tel,fax,current working place and company, IM (QQ,MSN, ICQ,YM, AIM or others).<br />
   4) Presentation details:<br />
   - How long is the presentation<br />
   - If any new tool/vulnerability/Exploit code will be released<br />
   5) The paper need include both PPT (for presentation) and WORD (for detailed description) in MS Office or OpenOffice format.<br />
<br />
All the papers will be submitted to xcon@huayongxingan.com for preliminary selection.<br />
   The deadline for submission is on July,20th,2013, and the deadline for confirmation is on August,1st,2013.<br />
No matter if the paper is accepted, we will officially inform you within 7 work days.<br />
<br />
Important dates:<br />
  * Deadline for submission: July,20th, 2013<br />
  * Deadline for confirmation: August,1st,2013<br />
<br />
Speakers' privilege:<br />
   If your paper is accepted by XCon, you will be invited to give an individual lecture in XCon.<br />
 The speakers will be provided with:<br />
   - Round-trip plane ticket (Economy class, one person only, Foreign speakers up to$1,400.) <br />
   - Two days' food and accommodation<br />
   - Invitation to celebration party<br />
   - Sightseeing some famous places of interests in Beijing, tasting Chinese flavored food<br />
   - Luck draw<br />
<br />
PS:<br />
   - Speakers must provide corresponding invoice or credential.<br />
   - XCon owns the right of final explanation about the conference.<br />
<br />
For more information about the conference, please contact xcon@xfocus.org,xcon@huayongxingan.com or professional XCon2012 organizer. MSN: xcon@xfocus.org; tel: 086-010-62029792<br />
<br />
Application for Attending:<br />
  In order to attend the conference, please register at XCon website (http://xcon.xfocus.org) or directly contact the organizer mentioned above.<br />
  We will offer different discounts according to the time of application.<br />
  Attenders' food and accommodation will be covered by themselves, and XCon will provide restaurant reservation and other service.<br />
<br />
Other information :<br />
  All the information about XCon will be released on XCon and Xfocus website.<br />
  Please visit http://xcon.xfocus.org/ for more information about speakers, agenda and previous XCon documents.<br />
<br />
Thank you for your support to XCon.]]></description>
            <dc:creator>xcon2009</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 05 May 2013 22:19:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51703,51703#msg-51703</guid>
            <title>Social Network Information Harvesting (SNIH) (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51703,51703#msg-51703</link>
            <description><![CDATA[Social Networks have a wealth of information to collect ! :) Check this out ! <br />
<br />
http://xc0re.net/web/social-network-information-harvesting-snih/]]></description>
            <dc:creator>xc0r3</dc:creator>
            <category>News and Links</category>
            <pubDate>Thu, 21 Mar 2013 04:12:22 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51701,51701#msg-51701</guid>
            <title>mysql_ depreciated, use mysqli or pdo. lol. (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51701,51701#msg-51701</link>
            <description><![CDATA[PHP is working for a couple of years to ditch mysql_ extension from PHP. See this post: <a href="http://news.php.net/php.internals/53799" rel="nofollow" >http://news.php.net/php.internals/53799</a><br />
<br />
So if you are like me and have created hundreds of thousands of lines of code in the 'ol mysql_ extention, you might want to rewrite all that stuff before PHP6 comes out. Clever move, PHP. The object orientated folks know it all!<br />
<br />
They think that using mysqli or pdo will solve everything. No more hacking, right? Now the scripter can sit back and relax... or can they? lol. <br />
<br />
Nice PDO exploit: <a href="http://www.securityfocus.com/bid/54777/info" rel="nofollow" >http://www.securityfocus.com/bid/54777/info</a><br />
<br />
<br />
-]]></description>
            <dc:creator>SAS</dc:creator>
            <category>News and Links</category>
            <pubDate>Sat, 09 Mar 2013 06:21:34 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51692,51692#msg-51692</guid>
            <title>.BlowBrain CryptoGame (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51692,51692#msg-51692</link>
            <description><![CDATA[Welcome to .Blowbrain, <br />
<br />
this is a simple game of logic, encryption and hacking, which will be used to measure <br />
your skills in this specific fields. On the homepage you can get your own encrypted code. <br />
Your task is to decrypt this code, overcoming the difficulties you will find in your path. <br />
When you will find the solution, just click on the brain and use the form to send us the <br />
random number that you'll get. <br />
We will contact you to be sure that you won our game. The Winner will be rewarded. <br />
The entire project has been conceived, designed, programmed and developed in one night, <br />
between London, Milan and Rome. <br />
<br />
Blow your brain. <br />
<br />
http://blowbrain.clicklife.it]]></description>
            <dc:creator>Nerder</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 11 Feb 2013 19:11:59 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51662,51662#msg-51662</guid>
            <title>Hacking Industrial Control &amp; Building Automation Systems (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51662,51662#msg-51662</link>
            <description><![CDATA[QJax has shared a great hacking video showing #Tridium #ICS and Building Automation at Risk! http://vimeo.com/56069427 Follow:@SSKblog]]></description>
            <dc:creator>qreck</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 07 Jan 2013 11:27:58 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51659,51659#msg-51659</guid>
            <title>Merry (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51659,51659#msg-51659</link>
            <description><![CDATA[Merry Xmas, holidays, Kwanzaa, Chanukah, whatever your made up holiday is.]]></description>
            <dc:creator>id</dc:creator>
            <category>News and Links</category>
            <pubDate>Tue, 01 Jan 2013 03:04:27 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51638,51638#msg-51638</guid>
            <title>Security Advent Calendar (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51638,51638#msg-51638</link>
            <description><![CDATA[Hello,<br />
<br />
This year there is an advent calendar aimed at security -<br />
http://secadvent.com<br />
Every day for the period Dec 1 -25 a security related article will be<br />
published on the website.<br />
<br />
Today's article is a crypto type puzzle.<br />
<br />
Best of luck from the Security Advent Calendar]]></description>
            <dc:creator>wireghoul</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 09 Dec 2012 18:21:19 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51545,51545#msg-51545</guid>
            <title>Xss wafbypass 2012[New]+detailed process of webpage rendering (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51545,51545#msg-51545</link>
            <description><![CDATA[Xss waf bypass using non-alphanumeric characters.Generate alert without using characters or numbers.<br />
+<br />
Detailed process for webpage rendering for begineers who want to go for XSS.<br />
<br />
here is the link<br />
http://adf.ly/E81iz]]></description>
            <dc:creator>Vaibs</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 29 Oct 2012 08:02:37 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51349,51349#msg-51349</guid>
            <title>The most realistic hacking contest (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51349,51349#msg-51349</link>
            <description><![CDATA[Everybody is welcome to try on the crown during the King of the Hill contest from the 20 August to 2 of September.<br />
<br />
To try to repeat the feats of the CTF battle participants and fight for the prizes provided by Positive Technologies, please register at the official web site http://www.phdays.com/ctf/king/<br />
<br />
During the Capture The Flag hacking contest at PHDays 2012 twelve teams from ten countries have been attacking the networks of other teams and protecting their own networks for two days and one night non-stop. The conditions were as close to real life as possible – no invented vulnerabilities, only those that occur in real contemporary information systems.<br />
<br />
The infrastructure for the hacking battle was organized according to the principle of the King of the Hill game: the points were given not only for successful attacks against the systems, but also for keeping control over the systems, which made the contest more intriguing.<br />
<br />
The contest became the highlight of the forum program, that is why an idea came to our minds... Why not to repeat the &quot;royal battle&quot; separately for the Internet community, let us say, in the second half of August?<br />
<br />
What is King of the Hill?<br />
<br />
Following the principle maximum authenticity, the contest infrastructure imitates typical infrastructure of enterprise networks: its external perimeter includes web applications, DBMS servers and various directories (LDAP), taking control of which allows reaching the internal perimeter – Microsoft Active Directory. Everything is like in real life.<br />
<br />
The task of the participants of King of the Hill is to detect vulnerabilities of the systems, exploit them and, the most important of all, keep control over the systems as long as it is possible. The trick is in regeneration of the sets of vulnerabilities in the systems. The participants face a dilemma — whether to try to attack the neighboring systems or to proceed with vulnerability detection on the systems which are under control already<br />
As in real life, the largest number of points is given for keeping control over Active Directory, since attacking AD requires keeping control over first level systems.<br />
<br />
The King of the Hill contest was developed by the Positive Technologies experts and was presented for the first time at PHDays CTF 2012 as part of the hacking contest.]]></description>
            <dc:creator>s4avrd0w</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 20 Aug 2012 08:36:40 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51094,51094#msg-51094</guid>
            <title>Plesk plaintext FTW. (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51094,51094#msg-51094</link>
            <description><![CDATA[Incredible:<br />
<br />
[<a href="http://blog.unmaskparasites.com/2012/06/26/millions-of-website-passwords-stored-in-plain-text-in-plesk-panel/" rel="nofollow" >blog.unmaskparasites.com</a>]<br />
<br />
Plesk stores passwords in... you got that right: PLAINTEXT.<br />
<br />
Plesk boats 250 million installations. Gotta love that.<br />
<br />
/facepalm.]]></description>
            <dc:creator>Skyphire</dc:creator>
            <category>News and Links</category>
            <pubDate>Wed, 08 Aug 2012 04:34:01 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,51082,51082#msg-51082</guid>
            <title>Chillin at Defcon if anyone wants to grab a beer (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,51082,51082#msg-51082</link>
            <description><![CDATA[It's alwasy fun to hang out with sla.ckers in RL, ping me]]></description>
            <dc:creator>id</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 29 Jul 2012 05:43:48 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,50612,50612#msg-50612</guid>
            <title>The SQL Injection Knowledge Base (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,50612,50612#msg-50612</link>
            <description><![CDATA[I've transformed the old SQLi Pocket Reference document into a Knowledge Base. I added and updated a lot of information and is now easier to navigate.<br />
<br />
You can find it at: <a href="http://websec.ca/kb/sql_injection" rel="nofollow" >SQL Injection KB</a><br />
<br />
Any feedback is always appreciated. Thanks!]]></description>
            <dc:creator>lightos</dc:creator>
            <category>News and Links</category>
            <pubDate>Thu, 12 Jul 2012 12:21:17 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,50106,50106#msg-50106</guid>
            <title>LinkedIn Hacked and 6.5 Million Passwords Leaked (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,50106,50106#msg-50106</link>
            <description><![CDATA[<a href="https://www.zdnet.com/blog/btl/646-million-linkedin-passwords-leaked-online/79290" rel="nofollow" >https://www.zdnet.com/blog/btl/646-million-linkedin-passwords-leaked-online/79290</a>]]></description>
            <dc:creator>idisappear</dc:creator>
            <category>News and Links</category>
            <pubDate>Wed, 06 Jun 2012 22:38:07 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,49856,49856#msg-49856</guid>
            <title>Code execution prevention mechanims for JavaScript (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,49856,49856#msg-49856</link>
            <description><![CDATA[I am cautiously (and shamelessly) launching a product called CliqueSafe, www.cliquesafe.com, which is a code execution prevention mechanism for JavaScript designed to prevent Reflected, Persistent and Self-XSS from succeeding in its goal: i.e. extracting information from a website and/or causing the website to manner not intended by the owner.<br />
<br />
CliqueSafe is a client/server solution, which uses a &quot;rewiter&quot; script to password protect access to DOM methods that can modify a page, send or retrieve data directly (i.e. XMLHttpRequest) or indirectly (i.e. HTMLImageElement.src). <br />
<br />
The rewriter deadlocks the protection using the latest ECMAScript standards for property setters/getters and maintains the anonymity of the password. <br />
<br />
Deploying CliqueSafe is relatively straight forward, though certainly not a case of &quot;drop it in and you're done&quot;. <br />
<br />
Web pages employing CliqueSafe have to be modified so that any JavaScript containing calls to rewritten methods is served up by the CliqueSafe script server. Calls to rewritten methods are replaced with a CliqueSafe equivilent, which usually just means adding a placeholder for the password as an extra parameter. e.g. n.appendChild(node) becomed n.appendChild(node,&quot;/*!param:hash*/&quot;). /*!param:hash*/ is replaced by a session-linked password by the script server.<br />
<br />
I have managed (after loosing much hair) to get the thing to deadlock on IE9, Firefox 6.0+, Chrome 18+ and Safari 5.1+. Nobody should ever knock IE9 again, of all the browsers it's the only one that full and properly supports the ECMAScript standards for property setters/getters!<br />
<br />
CliqueSafe is, I think, the first of its kind. In my research I have found similar concepts to CliqueSafe that have come and gone and failed. These mechanism have all worked by creating a script loader, that sanitisies or rewrites the script as it is loaded by the webpage. These rather heavy weight mechanims offer no protection against Self-XSS and are vulnerable to many different kinds of reflected XSS. The difference with CliqueSafe is that it rewrites the language itself and does not need a loader. This makes it very lean and it protects against Self-XSS.]]></description>
            <dc:creator>W177.1.am</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 11 Jun 2012 04:46:59 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,49851,49851#msg-49851</guid>
            <title>Online competitions on PHDays 2012 (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,49851,49851#msg-49851</link>
            <description><![CDATA[If by any reason you do not get into the participant list of Positive Hack Days 2012 (http://phdays.com) or cannot visit Digital October Center, the forum’s platform, on May 30 and 31, you still have an opportunity to participate in this event. Join the online battle with competitors from all over the world at Positive Hack Days 2012! Description and participation terms are under the cut.<br />
<br />
Hash runner (http://phdays.com/program/contests/#6332)<br />
<br />
The competitors will be provided with a list of hash functions generated according to various algorithms (MD5, SHA-1, BlowFish, GOST3411, etc.). Points for each decrypted password are scored according to the algorithm’s level of difficulty. To become a winner, a competitor should gain the most points in a limited period of time, leaving the rivals behind.<br />
<br />
Any Internet user can participate in the competition. Competitors can register during PHDays on the forum's website. The competition will be held as part of PHDays 2012 and will last through the forum days.<br />
<br />
WAF Bypass (http://phdays.com/program/contests/#6321)<br />
<br />
This competition is for enthusiasts and experts engaged in web application security. The competitors are to attack vulnerable web applications protected by Web Application Firewall using SQL Injection technique. The applications function in connection with DBMSes of various vendors.<br />
<br />
Participants will be offered to attack (or demonstrate the attack possibility) for the purpose of gaining data from a DBMS. There are four vulnerable web applications employed in the contest, each of them uses its own DBMS type. All attacks exploiting any SQL injection vector, inclusive of gaining file system access, OS commanding, brute force and binary search attacks are counted.<br />
<br />
The winner is the first who implements an SQL injection exploitation technique in one of the web applications.<br />
The winner will be awarded Apple iPad 3. The best ten competitors will receive prizes and gifts from Positive Technologies (the PHDays organizers) and from the forum sponsors.<br />
<br />
WikiLeaks (http://phdays.com/program/contests/#6325)<br />
<br />
The competition will enable participants of the forum to find out how quickly and accurately they can find hidden information on the Internet.<br />
<br />
The competition web page will contain questions about certain organization, information about which can be found online. The task of the competition participants is to find as many correct answers to the questions as possible in the shortest time. Results will be announced at the end of the second day of the PHDays 2012 forum.<br />
<br />
Best Reverser (http://phdays.com/program/contests/#6323)<br />
<br />
This competition enables the participants to try their skills in reverse engineering of executable files for MS Windows platform. Every participant gets a program specially crafted for analysis. There are no limitations on techniques or software used for capturing the flags (except for the applicable laws of the Russian Federation). The winner is the first who gets all three flags and shortly describes the ways to get them.<br />
<br />
The participants who deal with the competition tasks later than the winner or get less than three flags take the second and third places by the jury’s decision.<br />
<br />
PHDays Online HackQuest 2012 (http://phdays.com/program/contests/#6330)<br />
<br />
The PHDays 2012 program will include Online HackQuest, a competition for the Internet users that offers participants to try their hands at solving various information security tasks. On the forum’s second day, Online HackQuest participants will have a chance to influence the results of PHDays CTF 2012, the on-site contest.<br />
<br />
For the competition, participants are provided with access to a VPN gateway. After connecting to it, the participants are to identify target systems and detect their vulnerabilities. If exploitation of a vulnerability is successful, the participant gains access to a key (a flag), which should be submitted to the jury via the form on the participant’s personal page. If the flag is valid, the participant gains the corresponding number of points.<br />
<br />
PHDays Online HackQuest 2012 (http://phdays.com/program/contests/#6330): recon, networking, crypto, web, reversing, forensics, exploiting and much more!<br />
<br />
Online HackQuest will also be available for out-of-competition participation during 14 days after PHDays 2012.<br />
<br />
Registration is now open: http://phdays.com/personal/?register=yes]]></description>
            <dc:creator>s4avrd0w</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 27 May 2012 06:53:03 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,49839,49839#msg-49839</guid>
            <title>Psychological Warfare &amp; Social Engineering (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,49839,49839#msg-49839</link>
            <description><![CDATA[Must Read !!! <br />
<br />
http://xc0re.wordpress.com/2012/05/23/psychological-warfare/]]></description>
            <dc:creator>xc0r3</dc:creator>
            <category>News and Links</category>
            <pubDate>Fri, 25 May 2012 04:20:07 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,49120,49120#msg-49120</guid>
            <title>PHDays Online HackQuest 2012 (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,49120,49120#msg-49120</link>
            <description><![CDATA[The PHDays 2012 program will include Online HackQuest (http://phdays.com/program/contests/), a competition for the Internet users that offers participants to try their hands at solving various information security tasks. On the forum’s second day, Online HackQuest participants will have a chance to influence the results of PHDays CTF 2012, an on-site contest.<br />
<br />
Rules<br />
For the competition, participants are provided with access to a VPN gateway. After connecting to it, the participants are to identify target systems and detect their vulnerabilities. If exploitation of a vulnerability is successful, the participant gains access to a key (a flag), which should be submitted to the jury via the form on the participant’s personal page. If the flag is valid, the participant gains the corresponding number of points.<br />
<br />
All flags are in the MD5 format. The winner is the first participant to gain 100 points (which is the maximum possible amount). Participants who manage to gain more than 100 points are traditionally awarded with individual prizes :)<br />
<br />
Participation Terms<br />
Any Internet user is welcome to participate in the competition. The registration will open on the PHDays 2012 web site after the forum begins. Moreover, the Online HackQuest will also be available for out-of-competition participation during 14 days after PHDays 2012.<br />
<br />
Prizes<br />
Positive Technologies (the PHDays organizers) and the sponsors of the forum provide prizes and gifts for the competition.<br />
<br />
Technical Details<br />
The participation requires Internet connection and a possibility to establish connection to a VPN gateway via PPTP or IPSec.]]></description>
            <dc:creator>s4avrd0w</dc:creator>
            <category>News and Links</category>
            <pubDate>Wed, 16 May 2012 01:13:14 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,47893,47893#msg-47893</guid>
            <title>SPAM/Moderation/Registration (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,47893,47893#msg-47893</link>
            <description><![CDATA[Sorry I had to turn on Moderator confirmation for registration. I'm tired of the spam though, so all new users will have to wait for a moderator to approve the account.<br />
<br />
sucks, but o well]]></description>
            <dc:creator>id</dc:creator>
            <category>News and Links</category>
            <pubDate>Thu, 28 Feb 2013 08:58:13 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,47457,47457#msg-47457</guid>
            <title>NSA Whistleblower: The US Government has Most of Your Emails (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,47457,47457#msg-47457</link>
            <description><![CDATA[http://www.alternet.org/rights/155084/whistleblower%3A_the_nsa_is_lying_--_the_u.s._government_has_copies_of_most_of_your_emails/]]></description>
            <dc:creator>idisappear</dc:creator>
            <category>News and Links</category>
            <pubDate>Sat, 21 Apr 2012 18:35:34 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,46066,46066#msg-46066</guid>
            <title>New CISPA Worse Invasion of Privacy than SOPA? (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,46066,46066#msg-46066</link>
            <description><![CDATA[This is about a week late, but I noticed that nobody brought it up on this forum yet. <br />
<br />
Electronic Frontier Foundation on CISPA:<br />
&quot;a company like Google, Facebook or Twitter could intercept your emails and text messages, send copies to one another and to the government, and modify those communications or prevent them from reaching their destination if it fits into their plan to stop cybersecurity threats&quot;<br />
<br />
https://action.eff.org/o/9042/p/dia/action/public/?action_KEY=8444<br />
<br />
<br />
Russia Today news &quot;CISPA: Nightmare Security Bill&quot;:<br />
https://www.youtube.com/watch?v=vjZ8-xO2pMM<br />
<br />
Russia Today news &quot;CISPA 101&quot;:<br />
https://www.youtube.com/watch?v=vt3FTz9E-RQ<br />
<br />
Wikipedia Entry:<br />
https://en.wikipedia.org/wiki/Cyber_Intelligence_Sharing_and_Protection_Act<br />
<br />
Let's write congress and hope this gets overturned like SOPA. Most of the politician only care about being re-elected, so tell the politicians they won't get your vote if they support it.]]></description>
            <dc:creator>idisappear</dc:creator>
            <category>News and Links</category>
            <pubDate>Wed, 11 Apr 2012 11:38:50 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,43576,43576#msg-43576</guid>
            <title>XCon 2012 XFocus Information Security Conference Call for Paper (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,43576,43576#msg-43576</link>
            <description><![CDATA[XCon 2012 XFocus Information Security Conference Call for Paper<br />
<br />
August,  15th–16th , 2012, Beijing, China (http://xcon.xfocus.net)<br />
<br />
Upholding rigorous work style, XCon sincerely welcomes contributions from information security technique enthusiasts and expects your participation and sharing.<br />
<br />
Attenders:<br />
Anyone who loves information security, including information security experts and fans,network administrators, network security consultants, CIO, hacker technique fans.<br />
<br />
 Location : Beijing Jin Tai Hotel ( http://www.bjjintaihotel.com )<br />
<br />
<br />
Topics Range (but unlimited):<br />
   --- Security in new fields<br />
     - New Bugs digging<br />
     - New offensive technologies<br />
     - Cloud Security    <br />
     - 3G/4G/WINMAX,TD-SCDMA<br />
     - Web2.0  <br />
     - SNS Application<br />
     - Virtualization<br />
     - Mobile Handset (IPhone / Android / Windows Mobile 7 )<br />
<br />
    ---Special Network and Devices Security<br />
      - RFID<br />
      - Emergency Services<br />
      - Telecommunication Networks<br />
      - Transportation Control and Management Networks<br />
      - Supervisory Control and Data Acquisition system (SCADA)<br />
<br />
    --- Application security<br />
      - Routing device <br />
      - Encryption &amp; decryption technique <br />
      - Protocol security &amp; exploitation<br />
      - Web application vulnerability research<br />
      - Application reverse engineering and related automated tools<br />
      - Database security &amp; attacks<br />
      - Advanced Trojans, worms and backdoor technique<br />
<br />
   --- Intrusion detection/forensics analysis<br />
     - Traffic analysis<br />
     - Real-time data structure recovery <br />
     - File system analysis &amp; recovery<br />
     - Intrusion detection and anti-detection technique<br />
     - Reverse engineering (malicious code analysis technique, vulnerability research) <br />
     <br />
<br />
   --- Wireless &amp; VoIP security<br />
     - Wireless gateway <br />
     - PDA &amp; mobile protocol analysis<br />
     - WLANs hardening &amp; vulnerability analysis<br />
     - VoIP security &amp; vulnerability analysis<br />
     - 802.11x, CDPD, Bluetooth, WAP/TD-SCDMA, GSM, SMS<br />
<br />
   --- P2P technique<br />
     - Instant messenger (QQ,MSN, Skype, ICQ, etc.)<br />
     - P2P application (BT, Emule, Thunder, etc.)<br />
<br />
   --- Any topics that will catch the attention of the CFP committee and/or the world.<br />
 <br />
Paper Submission:<br />
The papers need include information as follow:<br />
   1) Brief introduction to the topic and whether the topic had been publicized, and if so, the publicized range.<br />
   2) Introduction to yourself.<br />
   3) Contact information: full name, alias, nationality, network nickname, e-mail,tel,fax,current working place and company, IM (QQ,MSN, ICQ,YM, AIM or others).<br />
   4) Presentation details:<br />
   - How long is the presentation<br />
   - If any new tool/vulnerability/Exploit code will be released<br />
   5) The paper need include both PPT (for presentation) and WORD (for detailed description) in MS Office or OpenOffice format.<br />
<br />
All the papers will be submitted to cfp@huayongxingan.com for preliminary selection.<br />
   The deadline for submission is on July,1st,2012, and the deadline for confirmation is on July,15th,2012.<br />
No matter if the paper is accepted, we will officially inform you within 5 work days.<br />
<br />
Important dates:<br />
  * Deadline for submission: July,1st, 2012<br />
  * Deadline for confirmation: July,15th,2012<br />
<br />
Speakers' privilege:<br />
   If your paper is accepted by XCon, you will be invited to give an individual lecture in XCon.<br />
 The speakers will be provided with:<br />
   - Round-trip plane ticket (Economy class, one person only, Foreign speakers up to$1,400.) <br />
   - Two days' food and accommodation<br />
   - Invitation to celebration party<br />
   - Sightseeing some famous places of interests in Beijing, tasting Chinese flavored food<br />
   - Luck draw<br />
<br />
PS:<br />
   - Speakers must provide corresponding invoice or credential.<br />
   - XCon owns the right of final explanation about the conference.<br />
<br />
For more information about the conference, please contact xcon@xfocus.org,xcon@huayongxingan.com or professional XCon2012 organizer. MSN: xfocusxcon@hotmail.com; tel: 086-010-62029792<br />
<br />
Application for Attending:<br />
  In order to attend the conference, please register at XCon website (http://xcon.xfocus.net) or directly contact the organizer mentioned above.<br />
  We will offer different discounts according to the time of application.<br />
  Attenders' food and accommodation will be covered by themselves, and XCon will provide restaurant reservation and other service.<br />
<br />
Other information :<br />
  All the information about XCon will be released on XCon and Xfocus website.<br />
  Please visit http://xcon.xfocus.org/ for more information about speakers, agenda and previous XCon documents.<br />
<br />
Thank you for your support to XCon.]]></description>
            <dc:creator>xcon2009</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 11 Mar 2012 22:24:31 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,43006,43006#msg-43006</guid>
            <title>cyber terrorism attack by an Indian ..Is the government aware????? (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,43006,43006#msg-43006</link>
            <description><![CDATA[Cyber terrorism is one of the most modern acts of terrorism .Instead of arms and weapons the internet launches the attack here .Below is a story of a criminal called Prashanth who was initially a paid worker of this company later betraying the owner and disobeying the cyber law at the same time .Read more about this ungrateful man and see for yourself .<br />
<br />
http://www.dontoutsource.com/<br />
<br />
<br />
http://digg.com/newsbar/topnews/february_13th_2012_we_re_back_again_don_t_outsource]]></description>
            <dc:creator>roberttt67</dc:creator>
            <category>News and Links</category>
            <pubDate>Fri, 09 Mar 2012 11:24:34 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,42516,42516#msg-42516</guid>
            <title>TinKode Arrested in Romania (13 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,42516,42516#msg-42516</link>
            <description><![CDATA[TinKode Arrested in Romania for hacking into NASA and the Pentagon<br />
http://www.pcmag.com/article2/0,2817,2399698,00.asp]]></description>
            <dc:creator>PaPPy</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 08 Oct 2012 14:40:23 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,42504,42504#msg-42504</guid>
            <title>HEx Edit+GIMP to find Debug Mode in UPLOAD AVATAR php (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,42504,42504#msg-42504</link>
            <description><![CDATA[HELLO GUYS I WAS EXPERIMENTING AND TAMPERING AROUND WITH A PICTURE AND DOING IMAGE INJECTION.I TOOK OF  A HALO PICTURE I SHOT THEN I USED HXD HEX EDITOR AND EMBEDDED PHPINFO CODE INSIDE PIC, AFTER JPEG HEADER,  I SAVED IT AS ,PHP,JPEG. THEN I USED GIMP AND CONVERTED THE PICTURE TO BLACK AND WHITE, i saved the file as .php.jpeg,in gimp FUNNY THING IS GIMP OPENS THE FILE AFTER I INSERTED THE PHP CODE in black and white mode, what did i do after this??<br />
<br />
well i decided to go to a forum: foro, re vo lu cion al dia.org, checked myself in and uploaded the picture, the site had no problems uploading the picture to my surpise i got an error:<br />
<br />
<br />
HERE ARE THE PICS, HALO, INJECTED IMAGE WITH HXD EDITOR AND THE ERROR ON FORUM:<br />
<br />
<img src="http://i.imgur.com/MOuDv.jpg" class="bbcode" border="0" /><br />
<br />
<br />
<img src="http://i.imgur.com/vQoFI.png" class="bbcode" border="0" /><br />
<br />
RESULTS AFTER UPLOADING PICTURE IN THE FORUM, THIS IS AFTER UPLOADP:<br />
<br />
<img src="http://i.imgur.com/bzDPY.png[/mode]

THIS IS WHILE STILL IN PROFILE.PHP

any ideas how to exploit this?gimp was able to open the .php.gif image in black and white mode


Unable to upload file

DEBUG MODE

Line : 251
File : usercp_avatar.php


THIS WAS PRODUCED RIGHT AFTER UPLOAD.PHP RECOGNIZED THE PICTURE AS LEGIT." class="bbcode" border="0" />]]></description>
            <dc:creator>johndoe</dc:creator>
            <category>News and Links</category>
            <pubDate>Mon, 18 Jun 2012 17:54:11 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,42147,42147#msg-42147</guid>
            <title>Positive Hack Days 2012 - Call For Papers (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,42147,42147#msg-42147</link>
            <description><![CDATA[What comes to your mind when you think of Russia? Fyodor [Dostoevsky] and Moscow? Sputnik and bears? Vodka and matryoshkas? Or Russian hackers? <br />
<br />
Positive Russian hackers, organizers of the Positive Hack Days 2012 forum on practical information security invite you to participate in the forum as a speaker.<br />
<br />
Positive Hack Days is a unique event, where the elite of the hacker world, leaders in the information security industry and the Internet community meet face to face to join their efforts to cooperate in addressing the most topical issues of the IT world. <br />
<br />
PHDays 2012 means theory hand in hand with practice, professional discussion intertwined with hardcore contests, maximum experience and minimum ceremonies.  <br />
<br />
On May 30 and 31, 2012, we will be waiting for you in one of the most beautiful cities in the world – Moscow!    <br />
<br />
CONTACTS<br />
Web site: www.phdays.com <br />
Twitter: https://twitter.com/#!/search/phdays  (@phdays)<br />
Blog: http://phdays.blogspot.com/<br />
LinkedIn: http://www.linkedin.com/groups/phdays-3850821?mostPopular=&amp;gid=3850821<br />
<br />
Submit your presentation and materials by sending a mail at:  cfp@phdays.com.<br />
<br />
PARTICIPATION<br />
<br />
The program of Positive Hack Days includes: <br />
-	round tables and discussions for business audience<br />
-	seminars and workshops for experts and hackers<br />
-	security challenges for all comers<br />
-	CTF and HackQuest contests <br />
<br />
PHDays offers several participation formats: <br />
- report (1 hour)<br />
- brief report (30 minutes)<br />
- lightning talk (15 minutes)<br />
- hands-on lab/workshop (up to 4 hours)<br />
<br />
SELECTION PRINCIPLES<br />
There are no strict restrictions for participants: anyone from a novice to a recognized expert in information security can be a speaker. Our goal is to facilitate animated, informal communication between all representatives of the information security industry. <br />
<br />
The main requirements are an interesting topic concerning information security, novelty and urgency of the issues under consideration, professionalism and competence.<br />
<br />
The organizers will consider every single application and select the best ones. <br />
<br />
TOPICS<br />
Themes of the reports should be relevant to information security. We are mostly interested in the following topics: <br />
-	security of critical information systems<br />
-	fraud management<br />
-	cybercrimes and investigation of incidents <br />
-	national and corporate security in the WikiLeaks epoch<br />
-	cyberwar and cyber spying<br />
-	protection of cloud computing and virtual infrastructure<br />
-	prevention of 0-day attacks<br />
-	forensics<br />
-	protection against DDoS<br />
-	applied cryptography<br />
-	security of industrial control systems (SCADA)<br />
-	security of business applications and ERP<br />
-	communication network security <br />
-	application security<br />
If your report does not concern any of the above topics but covers some other aspect of information security, and you believe it will be interesting for the community, please, feel free to apply.<br />
<br />
Note: We will not accept reports aimed at promoting certain products, services, or companies. We appreciate your understanding. <br />
<br />
APPLICATION<br />
Participation application should contain the following information: <br />
- Information about the speaker<br />
- first and last name<br />
- CV (educational and professional background, titles, main professional achievements)<br />
- residence (country, city)<br />
- contact information (telephone number, email)<br />
- Information about the report<br />
- title<br />
- brief summary (500 characters)<br />
- detailed outline <br />
- report status (whether it was published previously, where)<br />
We highly encourage and will favor submissions contains any of the following information: tool, slides, whitepaper<br />
It is desirable that the reports be in Russian or English.<br />
<br />
HOW TO APPLY<br />
Email us your application with all the required information. <br />
The applications for participation as a speaker will be accepted in two stages:<br />
•	the first stage from December 15, 2011 to January 30, 2012;<br />
•	the second stage from February 20, 2012 to April 16, 2012.<br />
<br />
Send your applications to cfp@phdays.com.<br />
<br />
For any additional information, contact us at cfp@phdays.com.<br />
<br />
After all applications are considered, the potential participants will receive letters with the results.<br />
<br />
TRANSPORT AND ACCOMMODATION<br />
The organizers will partially or fully pay for the transportation and accommodation of the speakers. The organizers' share is considered individually for each participant.<br />
<br />
On our part, we guarantee all the participants 2 days of positive emotions, a good mood, interesting people, and new experience. <br />
<br />
P.S. We are open to all positive people and ideas. Just do not suggest hard disk throwing, please.<br />
<br />
We are waiting for your papers!<br />
<br />
Bolshoyeh spasebaw, tovarishch!]]></description>
            <dc:creator>s4avrd0w</dc:creator>
            <category>News and Links</category>
            <pubDate>Tue, 10 Jan 2012 05:52:52 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,41218,41218#msg-41218</guid>
            <title>Last call: stop internet censorship. (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,41218,41218#msg-41218</link>
            <description><![CDATA[Stop American Censorship<br />
<br />
Congress is about to pass internet censorship, even though the vast majority of Americans are opposed. We need to kill the bill to protect our rights to free speech, privacy, and prosperity.<br />
<br />
Go To a Town Hall<br />
<br />
The Senate is scheduled to vote on the internet censorship bill on Tuesday, January 24th, and unless we can find 41 senators to block the vote, it is going to pass. Will you meet with your senators during the January recess and ask them to vote it down?<br />
<br />
http://americancensorship.org/]]></description>
            <dc:creator>Skyphire</dc:creator>
            <category>News and Links</category>
            <pubDate>Thu, 19 Jan 2012 14:47:07 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,40472,40472#msg-40472</guid>
            <title>Bypass Access Resrtiction by ISPs or Admins (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,40472,40472#msg-40472</link>
            <description><![CDATA[I wrote a little blog post for access restriction bypass ! Its in a very simple jargon. Even a newbie would understand what a Tunnel is ! :)<br />
<br />
https://xc0re.wordpress.com/2011/12/25/bypass-online-filter-restriction/<br />
<br />
Peace !]]></description>
            <dc:creator>xc0r3</dc:creator>
            <category>News and Links</category>
            <pubDate>Sun, 25 Dec 2011 07:12:21 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,40242,40242#msg-40242</guid>
            <title>Registrar changed (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,40242,40242#msg-40242</link>
            <description><![CDATA[Some people might not be able to get to the site for a few, we changed Registrar from Godaddy to Dynadot for ckers.org. <br />
<br />
Godaddy are of course huge dicks about it and drop DNS the second the registration changes. So some data is still cached with servers that recently did lookups for the domain, and it's been over an hour, but they seem to not be respecting the TTL.<br />
<br />
Oh well, fuck godaddy, can't wait to get the rest of our domains off there.]]></description>
            <dc:creator>id</dc:creator>
            <category>News and Links</category>
            <pubDate>Thu, 22 Dec 2011 14:47:22 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?13,38753,38753#msg-38753</guid>
            <title>SPAM (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?13,38753,38753#msg-38753</link>
            <description><![CDATA[Sorry about all the spam, I really don't want to add a CAPTCHA, but I might if this keeps up.<br />
<br />
I did make one change that hopefully will stop the current bot though.]]></description>
            <dc:creator>id</dc:creator>
            <category>News and Links</category>
            <pubDate>Tue, 20 Dec 2011 04:05:21 -0600</pubDate>
        </item>
    </channel>
</rss>
