<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
  <channel>
    <title>Web Application Security Forum</title>
    <link>http://sla.ckers.org/forum/index.php</link>
    <description><![CDATA[]]></description>
    <language>EN</language>
    <pubDate>Sun, 07 Mar 2010 03:08:43 -0600</pubDate>
    <lastBuildDate>Sun, 07 Mar 2010 03:08:43 -0600</lastBuildDate>
    <category>Web Application Security Forum</category>
    <generator>sla.ckers.org web application security forum</generator>
    <ttl>600</ttl>
    <item>
      <title>[XSS Info] Using cookies</title>
      <link>http://sla.ckers.org/forum/read.php?2,33747,33747#msg-33747</link>
      <author>doody</author>
      <description><![CDATA[How do I go about using cookies to log in on another computer? On computer A I have logged in onto a secure site (using SSO) and I retrieved the contents of document.cookie. Can I go to computer B, visit the same site, and set the cookie with the same values in order to &quot;log in&quot; to that same site on computer B?]]></description>
      <category>XSS Info</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?2,33747,33747#msg-33747</guid>
      <pubDate>Sun, 07 Mar 2010 03:08:43 -0600</pubDate>
    </item>
    <item>
      <title>[Projects] Building JSP website with PostgreSQL</title>
      <link>http://sla.ckers.org/forum/read.php?12,33746,33746#msg-33746</link>
      <author>doody</author>
      <description><![CDATA[I'm currently working on a project that involves building a website in JSP and with a backend PostgreSQL database. Are there any points that I can look out for with regards to securing this website against attacks? The only thing I can think of currently is SQL injection, which has already been covered by using PreparedStatement for all SQL queries. Are there any other attack vectors that I should be looking out for?]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,33746,33746#msg-33746</guid>
      <pubDate>Sun, 07 Mar 2010 00:58:05 -0600</pubDate>
    </item>
    <item>
      <title>[XSS Info] Re: Clickjacking Prevention</title>
      <link>http://sla.ckers.org/forum/read.php?2,32339,33745#msg-33745</link>
      <author>p0deje</author>
      <description><![CDATA[even though using comment like  worked in simple HTML file, when I added it to drupal, document.writing wasn't stopped by this comment. I had to change comment to  and that way it worked in all major browsers]]></description>
      <category>XSS Info</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?2,32339,33745#msg-33745</guid>
      <pubDate>Sun, 07 Mar 2010 00:05:51 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: New JavaScript obfuscator: JScrambler</title>
      <link>http://sla.ckers.org/forum/read.php?24,33722,33744#msg-33744</link>
      <author>sirdarckcat</author>
      <description><![CDATA[would you mind if I make a website called www.unjscrambler.com that deobfuscates your code?]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33722,33744#msg-33744</guid>
      <pubDate>Sat, 06 Mar 2010 20:29:45 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: JavaScript Smallest NonAlnum Quine</title>
      <link>http://sla.ckers.org/forum/read.php?24,33201,33743#msg-33743</link>
      <author>sirdarckcat</author>
      <description><![CDATA[so we are on 37 still
_=/'_='+[_,_(_)]|'.+?]/,'_='+[_,_(_)]]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33201,33743#msg-33743</guid>
      <pubDate>Sat, 06 Mar 2010 20:10:31 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: JavaScript Smallest NonAlnum Quine</title>
      <link>http://sla.ckers.org/forum/read.php?24,33201,33742#msg-33742</link>
      <author>sirdarckcat</author>
      <description><![CDATA[wait, we fail:
1.- Your code must allow arbitrary code to be part of the code... so it can be reused for other stuff.]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33201,33742#msg-33742</guid>
      <pubDate>Sat, 06 Mar 2010 20:10:06 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: JavaScript Smallest NonAlnum Quine</title>
      <link>http://sla.ckers.org/forum/read.php?24,33201,33741#msg-33741</link>
      <author>thornmaker</author>
      <description><![CDATA[grr... sniper!!!  well i can beat that...

quine: 

length: 0  :)]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33201,33741#msg-33741</guid>
      <pubDate>Sat, 06 Mar 2010 20:05:50 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: JavaScript Smallest NonAlnum Quine</title>
      <link>http://sla.ckers.org/forum/read.php?24,33201,33740#msg-33740</link>
      <author>sirdarckcat</author>
      <description><![CDATA[1


prints itself and it's length]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33201,33740#msg-33740</guid>
      <pubDate>Sat, 06 Mar 2010 20:05:03 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: JavaScript Smallest NonAlnum Quine</title>
      <link>http://sla.ckers.org/forum/read.php?24,33201,33739#msg-33739</link>
      <author>thornmaker</author>
      <description><![CDATA[quine: /x/  

length: 3!!! :D]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33201,33739#msg-33739</guid>
      <pubDate>Sat, 06 Mar 2010 20:03:58 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: JavaScript Smallest NonAlnum Quine</title>
      <link>http://sla.ckers.org/forum/read.php?24,33201,33738#msg-33738</link>
      <author>thornmaker</author>
      <description><![CDATA[@satyr well done!

does anyone know of *any* (nontrivial) JS quine that is shorter?]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33201,33738#msg-33738</guid>
      <pubDate>Sat, 06 Mar 2010 19:38:26 -0600</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: Can SQL Injection beat parameterized queries</title>
      <link>http://sla.ckers.org/forum/read.php?16,33633,33737#msg-33737</link>
      <author>thornmaker</author>
      <description><![CDATA[doody Wrote:
&gt; Could you give an example of how this would look
&gt; like?


http://blogs.sans.org/appsecstreetfighter/2010/03/01/top-25-series-rank-2-sql-injection/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=top-25-series-rank-2-sql-injection gives an example of using parameterized queries insecurely in java and also has some other basic info on SQLi that's worth reading.

@ Matt Presson  good point about the oracle date vector - I forgot about that]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,33633,33737#msg-33737</guid>
      <pubDate>Sat, 06 Mar 2010 19:34:52 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: New JavaScript obfuscator: JScrambler</title>
      <link>http://sla.ckers.org/forum/read.php?24,33722,33736#msg-33736</link>
      <author>thornmaker</author>
      <description><![CDATA[hm...

*5 minute pause* 

yeah, it still sucks]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33722,33736#msg-33736</guid>
      <pubDate>Sat, 06 Mar 2010 19:17:24 -0600</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: Can SQL Injection beat parameterized queries</title>
      <link>http://sla.ckers.org/forum/read.php?16,33633,33735#msg-33735</link>
      <author>Reiners</author>
      <description><![CDATA[python:

cur.execute(&quot;select comment from black_book where vuln = ' &quot;+name+&quot; ' and notvuln = %s&quot;, name)

and btw, this one is not safe either:

cur.execute(&quot;select comment from black_book where victim = '%s';&quot; % name)]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,33633,33735#msg-33735</guid>
      <pubDate>Sat, 06 Mar 2010 14:08:13 -0600</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Bypass addslashes</title>
      <link>http://sla.ckers.org/forum/read.php?16,33734,33734#msg-33734</link>
      <author>darkplayer</author>
      <description><![CDATA[Im trying to login on my own made loginsystem and im trying to hack into it without using a password. So far no luck but i know its possible im searching on the web how to get into it.

I have written it al in php. used addslashes and everything

tryed SQL injections found on the web
but the didnt work

I know a little about it and wanne learn more but i just cant find the right sites
maybe this all wil seem stupid but thanks anyways.

sorry for the bad english.]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,33734,33734#msg-33734</guid>
      <pubDate>Sat, 06 Mar 2010 13:21:08 -0600</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: Can SQL Injection beat parameterized queries</title>
      <link>http://sla.ckers.org/forum/read.php?16,33633,33733#msg-33733</link>
      <author>doody</author>
      <description><![CDATA[thornmaker Wrote:
-------------------------------------------------------
&gt; However, there's nothing stopping a
&gt; developer from dynamically constructing the query
&gt; string (so that it contains user-generated data)
&gt; and using it in a parameterized query, in which
&gt; case you're still vulnerable.  And yes, I've seen
&gt; this happen.

Could you give an example of how this would look like?]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,33633,33733#msg-33733</guid>
      <pubDate>Sat, 06 Mar 2010 13:03:45 -0600</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: What can be done with a successful SQL injection?</title>
      <link>http://sla.ckers.org/forum/read.php?16,33716,33732#msg-33732</link>
      <author>thespoon</author>
      <description><![CDATA[Im working in my localk mysql 5.0.36 server.

And when I say &quot;nothing useful&quot;, I mean nothing useful in every context you can imagenine. So with this premiss, and all the stuff I said above;  what can be dine with THIS PARTICULAR sql injection?

And when I say &quot;what can be done?&quot;, I mean something worth checking out. E.g. OS interaction somehow( but not by load_file() or into outfile), or maybe a directory list is possible. Or maybe theres somehow possible to inject data into the db( without the use of UPDATE or INSERT ).

I would like to know more about sql injection, and there is probabaly a lot of tricks/syntax that I dont know about.]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,33716,33732#msg-33732</guid>
      <pubDate>Sat, 06 Mar 2010 11:36:37 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: New JavaScript obfuscator: JScrambler</title>
      <link>http://sla.ckers.org/forum/read.php?24,33722,33731#msg-33731</link>
      <author>fsilva</author>
      <description><![CDATA[Gareth Heyes Wrote:
-------------------------------------------------------
&gt; Using for..in loops for objects is bad because it
&gt; will break code whenever a object prototype is
&gt; modified

But when? After obfuscation or before obfuscation? If it is after obfuscation forget it, because there is no point trying to change the object prototype after obfuscation. If it is before obfuscation, no worries because the transformation you are referring to targets only DOM objects and you are not able to mess with internal DOM prototypes so easily. Even if doing so it would work for a specific browser, it would not work for all, and that is what I would call break the code - even before the transformation is applied. 

So the use of for..in loops to access DOM properties by enumerating associative arrays that represent the content of DOM objects are not condemned to fail because of that. They would fail more easily if the differences between the content of those associative arrays in all the existing browsers are not taken in consideration.

Gareth Heyes Wrote:
-------------------------------------------------------
&gt; is trivial to decode

Anything of that size or anything using only one obfuscation transformation is, in most cases, easily de-obfuscated. Now, when using a set of transformations (more than one) that go further than what can be called polymorphic transformations, e.g., transformations that change the execution flow, data structures, even the introduction of anti-debugging techniques, make the &quot;is trivial to decode&quot; argument disappear.

Gareth Heyes Wrote:
-------------------------------------------------------
&gt; You use...

Do not make it personal because I'm just sharing information. I'm not the inventor. But since you did...

Gareth Heyes Wrote:
-------------------------------------------------------
&gt; ...ternary operations to obfuscate numbers???

Transformation like that one produce the base for others to act. Anyone that knows what obfuscation quality means, knows that this particular transformation it is not an enough resilient transformation on its own. Maybe with (as an example) hardly predictable variables in the place of the literals found at the ternary operations' arguments would make the trick.

Gareth Heyes Wrote:
-------------------------------------------------------
&gt; http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php#aT08QGRfamF2YXNjcmlwdF80PjI1My4yMz4weGZlP3RoaXM6MmUxPjEzPzA6MTU8MHgzPzE6TWF0aCA8QC9kX2phdmFzY3JpcHRfND4%3D

http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php#aT08QGRfamF2YXNjcmlwdF80PigoKDB4NDQzNSw3Lik%2BPSguNjEsOS4xMmUyKT8oMSw0LjAzM2UzKTooMjY2LDcuMWUxKSksKCgweDk3PD0uMT83LjYxNmUzOjIuMTc2ZTMpLCguMzk8OGUwPzA6MjAzMikpKTxAL2RfamF2YXNjcmlwdF80Pg%3D%3D

Gareth Heyes Wrote:
-------------------------------------------------------
&gt; It sucks.

I find hard to believe when that is said so ligthly, even more when a chance to try a solution was not given yet.  A wise man once told me that we should not express or opinion as fast as we take a shit . That is something that always comes to my mind when reading something like &quot;it sucks.&quot;.]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33722,33731#msg-33731</guid>
      <pubDate>Sat, 06 Mar 2010 08:07:37 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: Browser detection game</title>
      <link>http://sla.ckers.org/forum/read.php?24,31765,33730#msg-33730</link>
      <author>LeverOne</author>
      <description><![CDATA[Konqueror can generate an error, if it to leave out of account.
[code]alert(+'1\0'&amp;1-'\0'?'Konqueror':'!Konqueror')[/code]
[code]alert('1\0'-'\0'?'Konqueror':'!Konqueror')[/code] 

So we can make the full code:
without optimization (Konqueror 4.4, Safari 4.04, GChrome 4.0, IE 8, Opera 10.50, FF 3.6)
[code]browser=+'\v1'?1-'\0'?'Konqueror':+'1\0'?'Safari':(typeof/./)[0]=='f'?'GChrome':+{valueOf:function(x){return!x}}?'Opera':'Firefox':'IE'[/code]

or
[code]b=+'\v1'?1-'\0'?'K':+'1\0'?'S':(typeof/./)[0]=='f'?'C':+{valueOf:function(x){return!x}}?'O':'F':'I'  //99[/code]

or: 1-&gt;IE, 0-&gt;FF, 2-&gt;GCrome, 3-&gt;Safari, 4-&gt;Opera, 5-&gt;Konqueror
[code]b=+'\v1'?1-'\0'?5:+'1\0'?3:(typeof/./)[0]=='f'?2:+{valueOf:function(x){return!x}}?4:0:1   // 87[/code]

without Konqueror
[code]b=1-'\0'?'I':+'1\0'?'S':(typeof/./)[0]=='f'?'C':+{valueOf:function(x){return!x}}?'O':'F'   // 88[/code]

or: 1-&gt;IE, 0-&gt;FF, 2-&gt;GCrome, 3-&gt;Safari, 4-&gt;Opera
[code]b=1-'\0'?1:+'1\0'?3:(typeof/./)[0]=='f'?2:+{valueOf:function(x){return!x}}?4:0    // 78[/code]

Separation of FF from Opera still too long.

LeverOne]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,31765,33730#msg-33730</guid>
      <pubDate>Sat, 06 Mar 2010 05:05:12 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: Make this code smaller</title>
      <link>http://sla.ckers.org/forum/read.php?24,33201,33729#msg-33729</link>
      <author>satyr</author>
      <description><![CDATA[_=/'_='+[_,_(_)]|'.+?]/,'_='+[_,_(_)]

37]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33201,33729#msg-33729</guid>
      <pubDate>Sat, 06 Mar 2010 03:08:12 -0600</pubDate>
    </item>
    <item>
      <title>[XSS Info] Re: Clickjacking Prevention</title>
      <link>http://sla.ckers.org/forum/read.php?2,32339,33728#msg-33728</link>
      <author>sirdarckcat</author>
      <description><![CDATA[note that you can also disable the stylesheet via the xss filter, but if you add the HTTP header it should be fine

have u tested the comment tricks on all browsers? I was afraid that some browsers may want to close it, so I opted for using  instead..

Greetings!!]]></description>
      <category>XSS Info</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?2,32339,33728#msg-33728</guid>
      <pubDate>Fri, 05 Mar 2010 23:28:00 -0600</pubDate>
    </item>
    <item>
      <title>[Projects] Re: Is this encryption method secure?</title>
      <link>http://sla.ckers.org/forum/read.php?12,33725,33727#msg-33727</link>
      <author>Matt Presson</author>
      <description><![CDATA[From the code snippet here, it appears that the salt is static so all I would need to do is login one time and I have the &quot;salt&quot; for every user's cookie (not good).  Second I can look at the time the cookie was created and get pretty close to the correct time that the user logged in so that would give me the second part of the cookie (not good).  The last part is what really makes the &quot;attack&quot; infeasible but still, with enough resources it could also be brute forced.

If you do not want users to have to log in, generate a session cookie and simply set the expire attribute to some date in 2056 or something way far out.  Let the application generate your cookie.  Don't reinvent the wheel.


-Matt]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,33725,33727#msg-33727</guid>
      <pubDate>Fri, 05 Mar 2010 20:38:28 -0600</pubDate>
    </item>
    <item>
      <title>[SQL and Code Injection] Re: What can be done with a successful SQL injection?</title>
      <link>http://sla.ckers.org/forum/read.php?16,33716,33726#msg-33726</link>
      <author>Matt Presson</author>
      <description><![CDATA[It depends on what you call &quot;useful&quot;.  Passwords may not be the end goal for a compromise.  What about payment information, personally identifiable information (PII), health information, patent pending information, undisclosed financial/earnings information, intellectual property, or a number of other things.  My point is that while passwords are nice, but they are far from the only useful thing that can be obtained through SQLi.  In the end, it really depends on what type of system you are attacking.


-Matt]]></description>
      <category>SQL and Code Injection</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?16,33716,33726#msg-33726</guid>
      <pubDate>Fri, 05 Mar 2010 20:32:53 -0600</pubDate>
    </item>
    <item>
      <title>[Projects] Is this encryption method secure?</title>
      <link>http://sla.ckers.org/forum/read.php?12,33725,33725#msg-33725</link>
      <author>Ben</author>
      <description><![CDATA[Okay, so I'm using PHP and want to make an encryption method for storing a random value in the user's cookie as a method of authentication so they don't need to log back in every time they visit the site. Would the code below be secure?

$salt = &quot;some random characters I made up&quot;;
hash('sha256', $salt.microtime(true).mt_rand(10000000,99999999));

Thanks!]]></description>
      <category>Projects</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?12,33725,33725#msg-33725</guid>
      <pubDate>Fri, 05 Mar 2010 19:23:54 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: New JavaScript obfuscator: JScrambler</title>
      <link>http://sla.ckers.org/forum/read.php?24,33722,33724#msg-33724</link>
      <author>Gareth Heyes</author>
      <description><![CDATA[It sucks.

Using for..in loops for objects is bad because it will break code whenever a object prototype is modified and is trivial to decode. You use ternary operations to obfuscate numbers??? Yeah that's really good

http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php#aT08QGRfamF2YXNjcmlwdF80PjI1My4yMz4weGZlP3RoaXM6MmUxPjEzPzA6MTU8MHgzPzE6TWF0aCA8QC9kX2phdmFzY3JpcHRfND4%3D

You might want to look at this:-
http://www.businessinfo.co.uk/labs/hackvertor/hackvertor.php#PEBoYXNlZ2F3YV8wKCKqwMHCw8TGyMnKy8zNzs%2FQ0dLT1NXW2Nna29zd3t%2Fg4eLj5OXm5%2Bjp6uvs7e7v8PHy8%2FT19vj5%2Bvv8%2Ff4kXyIpPmFsZXJ0KCdXYWtlIHVwIGFuZCBzbWVsbCB0aGUgbm9uLWFscGhhbnVtZXJpYyBjb2RlJyk8QC9oYXNlZ2F3YV8wPg%3D%3D]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33722,33724#msg-33724</guid>
      <pubDate>Fri, 05 Mar 2010 10:45:56 -0600</pubDate>
    </item>
    <item>
      <title>[Bugs] Re: IBM Full Disclosure [Hacked]</title>
      <link>http://sla.ckers.org/forum/read.php?10,33720,33723#msg-33723</link>
      <author>PaPPy</author>
      <description><![CDATA[good timing
IBM Named Best Security Company by SC Magazine - http://money.cnn.com/news/newsfeeds/articles/prnewswire/NY65493.htm]]></description>
      <category>Bugs</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?10,33720,33723#msg-33723</guid>
      <pubDate>Fri, 05 Mar 2010 09:07:31 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] New JavaScript obfuscator: JScrambler</title>
      <link>http://sla.ckers.org/forum/read.php?24,33722,33722#msg-33722</link>
      <author>fsilva</author>
      <description><![CDATA[Hello guys,

There is a new JavaScript obfuscation service (www.jscrambler.com) opened for beta test register atm. Testing the available transformations might be an interesting thing to do :) so here it goes an enumeration of the features, transformations and techniques that can be found there:

    * Size code reduction transformations
    * Potent and resilient obfuscation transformations
    * Anti-debugging techniques
    * Lexical and syntactic analysis of the JavaScript source code

    * Remove code comments, white spaces and newlines
    * Replace identifiers for smaller and randomly created ones
    * Replace common DOM calls for associative array selection

Example:

Source:

document.write(navigator.plugins.length);

Obfuscated:

var H8_o=this;
for (H in H8_o){
   if (H.length==9){
      if (H.charCodeAt(0)==110){
         if (H.charCodeAt(8)==114){
            break;
         }
      }
   }
}
for (J3a in H8_o[H]){
   if (J3a.length==7){
      if (J3a.charCodeAt(0)==112){
         if (J3a.charCodeAt(6)==115){
            break;
         }
      }
   }
}
var s=this;
for (K in s){
   if (K.length==8){
      if (K.charCodeAt(0)==100){
         if (K.charCodeAt(7)==116){
            break;
         }
      }
   }
}
s[K][&quot;write&quot;](H8_o[H][J3a][&quot;length&quot;]);

    * Replace literals for a randomly number of conditional operators (?:)

Example:

Source:

i=0

Obfuscated:

i=253.23&gt;0xfe?this:2e1&gt;13?0:15]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,33722,33722#msg-33722</guid>
      <pubDate>Fri, 05 Mar 2010 08:07:20 -0600</pubDate>
    </item>
    <item>
      <title>[XSS Info] Re: Clickjacking Prevention</title>
      <link>http://sla.ckers.org/forum/read.php?2,32339,33721#msg-33721</link>
      <author>p0deje</author>
      <description><![CDATA[thanks to everybody, module was released
http://drupal.org/project/safeclick]]></description>
      <category>XSS Info</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?2,32339,33721#msg-33721</guid>
      <pubDate>Fri, 05 Mar 2010 06:45:44 -0600</pubDate>
    </item>
    <item>
      <title>[Bugs] IBM Full Disclosure [Hacked]</title>
      <link>http://sla.ckers.org/forum/read.php?10,33720,33720#msg-33720</link>
      <author>TinKode</author>
      <description><![CDATA[More here:
http://insecurity.baywords.com/index.php/ibm-full-disclosure-sql-injection/]]></description>
      <category>Bugs</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?10,33720,33720#msg-33720</guid>
      <pubDate>Fri, 05 Mar 2010 06:28:58 -0600</pubDate>
    </item>
    <item>
      <title>[News and Links] Re: TinKode News Blog</title>
      <link>http://sla.ckers.org/forum/read.php?13,32882,33719#msg-33719</link>
      <author>TinKode</author>
      <description><![CDATA[http://insecurity.baywords.com/ -&gt; My new blog]]></description>
      <category>News and Links</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?13,32882,33719#msg-33719</guid>
      <pubDate>Fri, 05 Mar 2010 06:27:24 -0600</pubDate>
    </item>
    <item>
      <title>[Obfuscation] Re: Browser detection game</title>
      <link>http://sla.ckers.org/forum/read.php?24,31765,33718#msg-33718</link>
      <author>sirdarckcat</author>
      <description><![CDATA[yeah, the safari one is neat :D]]></description>
      <category>Obfuscation</category>
      <guid isPermaLink="true">http://sla.ckers.org/forum/read.php?24,31765,33718#msg-33718</guid>
      <pubDate>Fri, 05 Mar 2010 03:21:11 -0600</pubDate>
    </item>
  </channel>
</rss>
