<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>Web Application Security Forum - Vendor Talk</title>
        <description>This is a place for us to start seriously talking about vendors. Whos great, whos not, whats it cost, how does it relate to their competitors and would we buy it? A place to talk about snakeoil, and brilliant products alike. Marketing fluff is forbidden.</description>
        <link>http://sla.ckers.org/forum/list.php?21</link>
        <lastBuildDate>Tue, 18 Jun 2013 16:17:44 -0500</lastBuildDate>
        <generator>Phorum 5.2.15a</generator>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,51676,51676#msg-51676</guid>
            <title>security plan automation (like RSAM) (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?21,51676,51676#msg-51676</link>
            <description><![CDATA[Hello posters,<br />
<br />
We use RSAM (http://www.rsam.com/) to do move security plans through workflow, providing stats, and sending email notifcations. Does anyone know of similar products that could be used for this? We only need a web interface, workflow, automatic email alerts and ldap integration.]]></description>
            <dc:creator>toolbox</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Sat, 26 Jan 2013 16:50:31 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,48370,48370#msg-48370</guid>
            <title>iGuard Biometrics Access Control Webserver Cross Site Scripting (no replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,48370,48370#msg-48370</link>
            <description><![CDATA[iGuard Biometrics Access Control Webserver Cross Site Scripting Zeroday vulnerability !! <br />
<br />
<br />
http://www.xc0re.net/index.php?p=1_25_iGuard-Biometrics-Access-Control-Webserver-XSS]]></description>
            <dc:creator>xc0r3</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Wed, 02 May 2012 06:03:27 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,35999,35999#msg-35999</guid>
            <title>Is Barracuda WAF any good? (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,35999,35999#msg-35999</link>
            <description><![CDATA[All,<br />
<br />
Any opinion on this?<br />
<br />
Thanks!]]></description>
            <dc:creator>nexz</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Tue, 29 May 2012 10:07:01 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,32955,32955#msg-32955</guid>
            <title>web app scanner (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,32955,32955#msg-32955</link>
            <description><![CDATA[Hello sla.ckers.org posters,<br />
<br />
I'm looking for recommendations on a generally easy-to use web application scanner. It doesn't need to be free. It can be an application or server-based, but I'd like to steer clear of appliances.<br />
<br />
I need one that can handle form, cookie, HTTP, and NTLM authentication and provides decent reporting and logging. Missing critical but hard-to-find vulnerabilities is acceptable, as long as the tool catches the most common issues (xss, plain text credentials, injection, etc) quickly.<br />
<br />
Thanks for the opinions. :-D]]></description>
            <dc:creator>toolbox</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Thu, 04 Mar 2010 08:43:04 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,32088,32088#msg-32088</guid>
            <title>WAFs we wouldn't recommend people use (9 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,32088,32088#msg-32088</link>
            <description><![CDATA[So, instead of people asking for responses about particular WAFs, I thought it might be better (and more amusing) to simply list the WAFs we know how to bypass, or have actual vulnerabilities in/exploits for.<br />
<br />
Now, I realise everyone's a hippy and wants their free info, but I don't want to be awfully specific about the exact vulnerabilities, so you're going to have to take this on faith.<br />
If anyone wants to post details, I can't stop you, but (as much as this seems to be acceptable development methodology) I'm not planning on posting details here so that WAF vendors can go do spot-fixes and keep claiming their stuff is secure because there are no known bypasses.<br />
<br />
Feel free to chime in with a product you have a bypass for (for a common situation, e.g. generic filter evasion (aka, this WAF might as well not be there), or generic directory traversal filter evasion, etc) or have a vulnerability in (please don't post things like reflected xss/csrf in the management interface, scout's honour and all), even if it's been listed before, this way people can get a feeling for how common the knowledge is too.<br />
<br />
<br />
<br />
So, without further ado, let me introduce WAFs I personally know are useless (or worse):<br />
<br />
F5 ASM<br />
<br />
Imperva's WAF (sorry, forgot the name)]]></description>
            <dc:creator>kuza55</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Wed, 04 Nov 2009 23:04:20 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,32071,32071#msg-32071</guid>
            <title>NetScaler Web Application Firewall (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,32071,32071#msg-32071</link>
            <description><![CDATA[Hi guys,<br />
<br />
Does anyone have been in touch with this WAF ? <br />
And how did you feel it ? <br />
<br />
Is it a good product compared to other WAF ????]]></description>
            <dc:creator>Spoint</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Mon, 28 Dec 2009 04:36:02 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,29575,29575#msg-29575</guid>
            <title>Web Application security options (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,29575,29575#msg-29575</link>
            <description><![CDATA[I know that there are lots of Hardware solutions available and seen some software solutions also.  What makes one better than another?  Any suggestions and comparison help would be greatly appreciated.  <br />
<br />
Thanks,]]></description>
            <dc:creator>GMan415</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Fri, 30 Oct 2009 07:11:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,28822,28822#msg-28822</guid>
            <title>dotDefender (11 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,28822,28822#msg-28822</link>
            <description><![CDATA[I have downloaded the dotDefender from Applicure<br />
The thing is free for 30 days (evaluation). Everything seems to work fine, no problem, nice statistics and very easy to install on my Linux and IIS servers.<br />
<br />
What I am interested in is does anyone has any experience with the dotDefender? Are there problems or issues and is it fast enough?<br />
<br />
You can download it here: http://www.applicure.com/downloads/dotdefender and try it for yourself<br />
<br />
Wim]]></description>
            <dc:creator>wimvincken</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Sat, 22 May 2010 05:50:43 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,27427,27427#msg-27427</guid>
            <title>questions about how securityfocus works (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,27427,27427#msg-27427</link>
            <description><![CDATA[http://it.slashdot.org/comments.pl?sid=396432&amp;cid=21780042<br />
<br />
That post seems rather illuminating. It suggests, among other things, that a lot of Security Focus' vulnerabilities may come from changelogs. Is there a way to tell when a vulnerability has or hasn't come from a changelog?<br />
<br />
http://www.securityfocus.com/bid/32842/info<br />
<br />
Due to the release dates, I think that vulnerability was pulled from a changelog. It was published on December 15, 2008 when phpBB 3.0.4 was, itself, released on December 12, 2008, per http://www.phpbb.com/community/viewtopic.php?f=14&amp;t=1352565.<br />
<br />
One thing I am unsure about, though... why was the vulnerability updated on March 30, 2009? I ask because I recently saw it in my RSS feed for Security Focus - presumably because of this update.<br />
<br />
Also, why, when a vulnerability is found to be bogus does Security Focus flag it as RETIRED? This, to me, seems highly misleading. Why not flag it as BOGUS? Maybe Security Focus is trying to control their reputation by not belaboring the fact that they accepted a bogus vulnerability? If so, that would be rather hypocritical, it seems to me, given that Security Focus doesn't seem to give others the same courtesy, as evidenced by what the slashdot.org link referred to as &quot;bottom-fishing changelogs&quot;.<br />
<br />
And why are these &quot;bottom-fishing changelog&quot; submitters even given credit? If I disclose an exploit to Wordpress but not to Security Focus and Wordpress fixes it and notes it in their changelog, will some random third party come along and essentially steal the credit for it? If the source of vulnerability claim is, say, Wordpress's changelog, shouldn't Wordpress receive the credit? If The Pirate Bay worked liked Security Focus seems to, people wouldn't be downloading Microsoft Windows - they'd be downloading TPBRema Windows or m00ns Windows.]]></description>
            <dc:creator>slacker</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Wed, 29 Apr 2009 20:17:51 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,27258,27258#msg-27258</guid>
            <title>Source Code Analysis (8 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,27258,27258#msg-27258</link>
            <description><![CDATA[Does anybody have any thoughts on Fortify vs. Ounce vs Klockwork vs. Coverity?  Preferred choice?]]></description>
            <dc:creator>br0kan</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Mon, 30 Mar 2009 13:45:16 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,24994,24994#msg-24994</guid>
            <title>WAF vendors (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,24994,24994#msg-24994</link>
            <description><![CDATA[We were debating WAF's at Bluehat and I mentioned a lack of contribution from them on sla.ckers. So here's your chance vendors, lets see some communication, some demo pages, some filter source. Anything!]]></description>
            <dc:creator>Gareth Heyes</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Thu, 26 Mar 2009 15:19:41 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,24985,24985#msg-24985</guid>
            <title>Acunetix Web App Scanner has GPL'ed some sections ? (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,24985,24985#msg-24985</link>
            <description><![CDATA[List,<br />
<br />
    For some reason I finally decided to give Acunetix scanner a try, so I opened the very nice (?) CD case they gave me at OWASP with the evaluation version, and installed it in my box. The installation failed (I only tried with wine), and whenever I tried to run it I got a nice &quot;report your bug&quot; window (once again, my fault because I was trying it with wine). So... without being able to actually run the tool, I went to the directory and started reading some files, until something got my attention:<br />
<br />
...<br />
&lt;Copyright&gt;GPL&lt;/Copyright&gt;<br />
...<br />
<br />
    WTF? Then I did some more checking...<br />
<br />
dz0@brick:~/.wine/drive_c/Program Files/Acunetix/Web Vulnerability Scanner 5/Data/Profiles/VulnXML$ grep GPL * -Rs | wc -l<br />
596<br />
dz0@brick:~/.wine/drive_c/Program Files/Acunetix/Web Vulnerability Scanner 5/Data/Profiles/VulnXML$<br />
<br />
    And well... yes... it seems that they have GPL copyright for all the VulnXML, which has some interesting information (at least for me), because they have all the errors database for SQL injection, and other &quot;error based detection&quot; vulnerabilities. I know that copyright is not the same as License... but... in this case I think that it could be? Or maybe the copyrights for those files are assigned to a company called GPL?  (????)<br />
<br />
    After that, I decided to see which files weren't actually GPL:<br />
<br />
dz0@brick:~/.wine/drive_c/Program Files/Acunetix/Web Vulnerability Scanner 5/Data/Profiles/VulnXML$ grep Copyright * -Rs | grep -v GPL<br />
Blind_SQL_injection_(number_no_end).xml:    &lt;Copyright&gt;&lt;/Copyright&gt;<br />
Blind_SQL_injection_(number).xml:    &lt;Copyright&gt;&lt;/Copyright&gt;<br />
Blind_SQL_injection_(second_string_no_end).xml:    &lt;Copyright/&gt;<br />
Blind_SQL_injection_(second_string).xml:    &lt;Copyright&gt;&lt;/Copyright&gt;<br />
Blind_SQL_injection_(string_no_end).xml:    &lt;Copyright/&gt;<br />
Blind_SQL_injection_(string).xml:    &lt;Copyright&gt;&lt;/Copyright&gt;<br />
Sift_Unity_Cross-Site_Scripting.xml:								&lt;Value&gt;Copyright Sift Group Ltd&lt;/Value&gt;<br />
dz0@brick:~/.wine/drive_c/Program Files/Acunetix/Web Vulnerability Scanner 5/Data/Profiles/VulnXML$ <br />
<br />
    So... this is interesting... Some files don't have copyright, and one of them is copyrighted to &quot;Sift Group Ltd&quot;.<br />
<br />
    Finally, I would like to ask you guys some questions:<br />
<br />
- Anyone noticed this before?<br />
- Is this a &quot;licensing bug&quot;?<br />
- I'm just guessing but... maybe they HAD to leave this as GPL because they took the information from a GPL project?<br />
<br />
    If anyone has some insight info, please share ;)<br />
<br />
Cheers,]]></description>
            <dc:creator>andresRiancho</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Thu, 23 Oct 2008 23:55:50 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,24484,24484#msg-24484</guid>
            <title>TeamMentor (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,24484,24484#msg-24484</link>
            <description><![CDATA[Does anyone have access to Security Innovation TeamMentor?  It was announced in mid-April, 2007.<br />
<br />
I checked out the demo and collateral, and it's coming along nicely.  Too bad it costs $25k.<br />
<br />
SI's e-Learning offerings (check out the demos!) also look great.  I was hoping that their stuff would be priced better, especially considering that Holodeck is one of the cheaper fault-injection test harnesses at $1800.]]></description>
            <dc:creator>ntp</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Fri, 19 Sep 2008 09:30:19 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,23748,23748#msg-23748</guid>
            <title>Splunk (11 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,23748,23748#msg-23748</link>
            <description><![CDATA[Anyone played with <a href="http://www.splunk.com/" rel="nofollow" >Splunk</a>?<br />
<br />
I read <a href="http://blogs.splunk.com/raffy/" rel="nofollow" >Raffy</a>'s slides from his talk at HITB2007 on visualization, and this got me really interested log analysis through visualization. I flipped through his book (the first one, not the new Applied Security Visualization) at my local bookstore and liked it even more.<br />
<br />
Around the same time, the company I work for finally decided that we need a log aggregation and analysis tool so that we know wtf is happening on our servers. So we called up Splunk, and I was impressed by a demo. Now we have them coming in to set Splunk up on our network and slurp up the logs from all our servers, firewalls, etc.<br />
<br />
The demo impressed me. Hopefully this upcoming proof of concept doesn't disappoint.]]></description>
            <dc:creator>hexfortyfive</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Tue, 05 Aug 2008 18:35:20 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,22877,22877#msg-22877</guid>
            <title>Javeline Platform (2 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,22877,22877#msg-22877</link>
            <description><![CDATA[Wasn't sure where to put this..<br />
<br />
http://www.javeline.com/<br />
<br />
Anyway, Javeline Platform is an AJAX framework which integrates XML and JavaScript and melts them into their own JSL syntax. I've been playing around with it for a few days learning the syntax and properties of different containers/components. There isn't much support at all, and it takes a steely resolve to sit through hours of wondering &quot;why on earth has my list suddenly stopped displaying data&quot;, but this could be quite a powerful tool (if only they had decent tutorials, a manual and a forum), especially when they release another product they're working on, DeskRun (allows you to package a full zip of your web app and convert it into an exe which can access the filesystem and act like a normal windows app - very nifty). Anyway, just thought I'd let you guys know in case you wanted to take a look and try and build a few things with it.. Its easy to learn, just frustratingly fragile (the littlest things stop your xml data from actually converting and being listed properly.... UGH).<br />
<br />
Cheers.]]></description>
            <dc:creator>fragge</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Mon, 30 Jun 2008 10:37:13 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,22433,22433#msg-22433</guid>
            <title>AJAX IM (4 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,22433,22433#msg-22433</link>
            <description><![CDATA[I want to use the following on one of my sites http://www.ajaxim.com/ and was wondering if I take all the measures to sanitize and validate the information being send to the server does that protect me? I know since its client-side all security done to the JS app can be tampered with, but what other security issues can an AJAX app such as this otherwise cause to my site? I haven't dabbled with AJAX much so still learning of its potential risks. Thanks in advance.]]></description>
            <dc:creator>CrYpTiC_MauleR</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Sat, 01 Nov 2008 01:14:28 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,22432,22432#msg-22432</guid>
            <title>NeXpose (10 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,22432,22432#msg-22432</link>
            <description><![CDATA[I got this email today, and I thought I'd forward it off...  Any comments?<br />
<br />
<blockquote class="bbcode"><div><small>Quote<br/></small><strong></strong><br/>
Was wondering if you knew much about Rapid7’s NeXpose product and whether its reputable or not. It’s apparently one of very few commercial products out there that scans various platforms &amp; technologies, incl. some webapp and DB stuff (web 2.0 stuff  - JavaScript, AJAX, Flash Flex, ActionScript, ASP.NET 2.0 (Atlas) and .NET 3.0). Ive also heard a top guy at Foundstone took a high level job there. Ive searched for some objective reviews of their product but haven’t come across a whole lot.</div></blockquote>]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Thu, 26 Aug 2010 00:57:26 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,22020,22020#msg-22020</guid>
            <title>Vulture Applicative Firewall (1 reply)</title>
            <link>http://sla.ckers.org/forum/read.php?21,22020,22020#msg-22020</link>
            <description><![CDATA[i am on mission from god to implement a PoC for a client for a hardened (like in &quot;oh my god, this box is a fracking tank&quot;) vulture box. i open this thread for two reasons :<br />
<br />
1 : if you have experience with its success and failures, i'd be happy to hear from it<br />
<br />
2 : report my own findings, and c/c the documentation i'll write. maybe i'll post the whole box design as a howto.<br />
<br />
EDIT: <br />
<br />
oh bugger, i forgot the url [<a href="http://vulture.open-source.fr/wiki/" rel="nofollow" >vulture.open-source.fr</a>]<br />
<br />
yeah i know it's in french. i do not choose the products, and managers aren't particularly known for their language proficiency :)]]></description>
            <dc:creator>Malkav</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Thu, 24 Apr 2008 14:14:46 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,21704,21704#msg-21704</guid>
            <title>opensource webmail/collaboration platform review (7 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,21704,21704#msg-21704</link>
            <description><![CDATA[i recently installed a fully fledged postfix/dovecot on a new server, but he wanted a webmail/calendar/whatever too, and i don't know those products very well.<br />
<br />
so i tried horde, and roundcube. both do their job (altough roundcube is largely heavier (mainly due to javascript))<br />
<br />
did you have to pentest webmails/CP recently ? would you recommend one in particular ? the only requirement is that it can run in lighttpd-fcgi and over PostgreSQL.<br />
<br />
i am no php coder, so if i had to code one, it would be perl or RoR. and i have not much time.<br />
<br />
as i dedicated most my time spent on this one to harden the underlying freebsd 7, i think i'd be pretty pissed of if some random kiddy started to attack the database via SQLi (or worse, sent mail with JS. XSS via mail. NOOoOOoooOoOoO)]]></description>
            <dc:creator>Malkav</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Wed, 05 Nov 2008 06:03:28 -0600</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,21474,21474#msg-21474</guid>
            <title>Avast (8 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,21474,21474#msg-21474</link>
            <description><![CDATA[Whelp, this appears to be a major false positive for Avast: http://ha.ckers.org/blog/20080318/yahoo-mail-gives-users-trojan-horses/#comment-66615<br />
<br />
Anyone have any better luck with the other AV vendors for this kind of detection?  I've played with half a dozen and most of them appear to be so-so, but I've also done almost no testing against the different signatures out there.]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Fri, 19 Sep 2008 08:12:10 -0500</pubDate>
        </item>
        <item>
            <guid>http://sla.ckers.org/forum/read.php?21,21421,21421#msg-21421</guid>
            <title>F5 WAF (3 replies)</title>
            <link>http://sla.ckers.org/forum/read.php?21,21421,21421#msg-21421</link>
            <description><![CDATA[Does anyone have experience with the F5 WAFs?  I've been asked by at least one of my clients about it, and I was curious if anyone here had done an install, if it's any good compared to the other WAFs, what the interface looks lie, list price, et al?]]></description>
            <dc:creator>rsnake</dc:creator>
            <category>Vendor Talk</category>
            <pubDate>Thu, 26 Mar 2009 10:31:13 -0500</pubDate>
        </item>
    </channel>
</rss>
