<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>eazel</title>
	<atom:link href="http://www.eazel.es/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.eazel.es</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Fri, 16 Apr 2010 22:43:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Conferencia sobre Ataques de Denegación de Servicio en Aplicaciones Web para el 2º OWASP Spain Chapter Meeting</title>
		<link>http://www.eazel.es/2007/07/06/conferencia-sobre-ataques-de-denegacion-de-servicio-en-aplicaciones-web-para-el-2%c2%ba-owasp-spain-chapter-meeting/</link>
		<comments>http://www.eazel.es/2007/07/06/conferencia-sobre-ataques-de-denegacion-de-servicio-en-aplicaciones-web-para-el-2%c2%ba-owasp-spain-chapter-meeting/#comments</comments>
		<pubDate>Fri, 06 Jul 2007 21:12:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Presentaciones]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=138</guid>
		<description><![CDATA[


Autor:

Jaime Blasco: jaime.blasco(at)eazel(dot).es
http://www.eazel.es




Descripción:




Esta conferencia habla sobre ataques de  denegación de servicio que se pueden llevar a cabo contra aplicaciones  web y algunas formas de mitigarlos.
Conferencia_OWASP 







]]></description>
			<content:encoded><![CDATA[<table border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<th valign="top" scope="row">Autor:</th>
<td>
<div>Jaime Blasco: jaime.blasco(at)eazel(dot).es</p>
<p><a href="../">http://www.eazel.es</a></p>
</div>
</td>
</tr>
<tr>
<th valign="top" scope="row">Descripción:</th>
<td>
<table border="0" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td colspan="2">Esta conferencia habla sobre ataques de  denegación de servicio que se pueden llevar a cabo contra aplicaciones  web y algunas formas de mitigarlos.</p>
<p><a href="/wp-content/uploads/2007/07/Conferencia_OWASP.pdf">Conferencia_OWASP</a> <a href="http://www.eazel.es/wp-content/uploads/2010/04/IMG_0013.jpg" rel="lightbox[138]"><img class="alignnone size-medium wp-image-140" title="IMG_0013" src="http://www.eazel.es/wp-content/uploads/2010/04/IMG_0013-300x199.jpg" alt="" width="300" height="199" /></a></td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2007/07/06/conferencia-sobre-ataques-de-denegacion-de-servicio-en-aplicaciones-web-para-el-2%c2%ba-owasp-spain-chapter-meeting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Artículo publicado en la revista Hakin9 sobre seguridad y técnicas de fuzzing en controles ActiveX</title>
		<link>http://www.eazel.es/2007/06/27/articulo-publicado-en-la-revista-haking9-sobre-seguridad-y-tecnicas-de-fuzzing-en-controles-activex/</link>
		<comments>http://www.eazel.es/2007/06/27/articulo-publicado-en-la-revista-haking9-sobre-seguridad-y-tecnicas-de-fuzzing-en-controles-activex/#comments</comments>
		<pubDate>Wed, 27 Jun 2007 21:05:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[activex]]></category>
		<category><![CDATA[fuzzing]]></category>
		<category><![CDATA[hakin9]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=130</guid>
		<description><![CDATA[


Autor:


Jaime Blasco: jaime.blasco(at)eazel(dot).es
http://www.eazel.es




Descripción:




This article is focus on ActiveX control, this  kind of controls can be automatically executed by a Web browser and  enables to embed interactive elements in HTML documents.





keywords: auditing-and-fuzzing-activex









]]></description>
			<content:encoded><![CDATA[<table border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<th valign="top" scope="row">Autor:</th>
<td>
<div>
<p>Jaime Blasco: jaime.blasco(at)eazel(dot).es</p>
<p><a href="../">http://www.eazel.es</a></p>
</div>
</td>
</tr>
<tr>
<th valign="top" scope="row">Descripción:</th>
<td>
<table border="0" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td colspan="2">This article is focus on ActiveX control, this  kind of controls can be automatically executed by a Web browser and  enables to embed interactive elements in HTML documents.</td>
</tr>
<tr>
<td valign="top">
<div>
<p><a rel="nofollow" href="http://www.hakin9.org/en/haking/issues/4_2007.html"><img class="alignnone size-full wp-image-134" title="activex" src="http://www.eazel.es/wp-content/uploads/2010/04/activex.png" alt="" width="200" height="283" /></a></p>
<p>keywords: <cite>auditing-and-fuzzing-activex</cite></p>
</div>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2007/06/27/articulo-publicado-en-la-revista-haking9-sobre-seguridad-y-tecnicas-de-fuzzing-en-controles-activex/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Mono XSP ASP.NET Server sourcecode disclosure vulnerability</title>
		<link>http://www.eazel.es/2006/12/19/mono-xsp-asp-net-server-sourcecode-disclosure-vulnerability/</link>
		<comments>http://www.eazel.es/2006/12/19/mono-xsp-asp-net-server-sourcecode-disclosure-vulnerability/#comments</comments>
		<pubDate>Tue, 19 Dec 2006 20:24:24 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[asp.net]]></category>
		<category><![CDATA[disclosure]]></category>
		<category><![CDATA[xsp]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=104</guid>
		<description><![CDATA[


Version:
Tested on mono  1.2.1
Version: XSP for ASP.NET 1.1 and  2.0  (This is a regression as this issue didn&#8217;t exists in Mono 1.0)


Discovered by:
José Ramón Palanco:  jose.palanco(at)eazel(dot)es
http://www.eazel.es


Time Line:


Nov 29, 2006: Discovered security issue by Jose Ramon  Palanco
Nov 30, 2006: Reported to Mono Project
Dec  1, 2006: Patch in subversion rev 68776
Dec [...]]]></description>
			<content:encoded><![CDATA[<table style="height: 790px;" border="1" cellspacing="0" width="664">
<tbody>
<tr>
<th width="159" scope="row">Version:</th>
<td width="634">Tested on mono  1.2.1<br />
Version: XSP for ASP.NET 1.1 and  2.0  (This is a regression as this issue didn&#8217;t exists in Mono 1.0)</td>
</tr>
<tr>
<th scope="row">Discovered by:</th>
<td>José Ramón Palanco:  jose.palanco(at)eazel(dot)es</p>
<p><a href="../">http://www.eazel.es</a></td>
</tr>
<tr>
<th scope="row">Time Line:</th>
<td>
<ul>
<li><strong>Nov 29, 2006</strong>: Discovered security issue by Jose Ramon  Palanco</li>
<li><strong>Nov 30, 2006</strong>: Reported to Mono Project</li>
<li><strong>Dec  1, 2006</strong>: <a href="http://www.eazel.es/wp-content/uploads/2006/12/19/advisory007-mono-xsp-source-disclosure-vulnerability.patch">Patch</a> in subversion rev 68776</li>
<li><strong>Dec  5, 2006</strong>: Mono is testing the patch and building  packages for the fix</li>
<li><strong>Dec 19, 2006</strong>: Published advisory CVE-2006-6104</li>
</ul>
</td>
</tr>
<tr>
<th scope="row">Description:</th>
<td>Attackers use source code disclosure attacks to try to <strong>obtain the  source code of server-side applications</strong>. The basic role of Web  servers is to serve files as requested by clients. Files can be static,  such as image and HTML files, or dynamic, such as <strong>ASPX</strong>, <strong>ASHX</strong>,  <strong>ASCX</strong>, <strong>ASAX</strong>, webservices like <strong>ASMX</strong> files and any  language supported by Mono like: C#, boo, nemerle, vb files: .cs, .boo,  vb, .n, &#8230; When the browser requests a dynamic file, the Web server  first executes the file and then returns the result to the browser.  Hence, dynamic files are actually code executed on the Web server.</p>
<p>Using a source code disclosure attack, an attacker can retrieve the  source code of server-side file. Obtaining the source code of  server-side files grants the attacker deeper knowledge of the <strong>logic  behind the Web application</strong>, how the application <strong>handles requests  and their parameters</strong>, the <strong>structure of the database</strong>, <strong>vulnerabilities  in the code</strong> and <strong>source code comments</strong>. Having the source  code, and possibly a duplicate application to test on, helps the  attacker to prepare an attack on the application.</p>
<p>An attacker can cause source code disclosure using adding %20 (space  char) after the uri, for example</p>
<p><strong>http://www.server.com/app/Default.aspx%20</strong></p>
<p><strong>Update</strong>: is also possible retrieve Web.Config file. This file  contains sensible informatin like credentials.</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2006/12/19/mono-xsp-asp-net-server-sourcecode-disclosure-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>GForge Cross Site Scripting vulnerability</title>
		<link>http://www.eazel.es/2006/10/26/gforge-cross-site-scripting-vulnerability/</link>
		<comments>http://www.eazel.es/2006/10/26/gforge-cross-site-scripting-vulnerability/#comments</comments>
		<pubDate>Thu, 26 Oct 2006 20:23:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[gforge]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=102</guid>
		<description><![CDATA[


Version:
Tested on  GForge 4.5.11


Discovered by:
José Ramón Palanco:  jose.palanco(at)eazel(dot)es
http://www.eazel.es


Description:
GForge is vulnerable to a security vulnerability that allow Cross-Site  Scripting attacks. Due to improper filtering, a remote attacker can cause a cross site  scripting.
To exploit any attacker may send via GET method the &#8220;words&#8221; variable to:
&#62;&#8221;&#60;script&#62;alert(&#8216;www.eazel.es&#8217;)&#60;/script&#62;
to http://site/search/advanced_search.php?group_id=X&#38;search=1
where X is any active project in [...]]]></description>
			<content:encoded><![CDATA[<table style="height: 313px;" border="1" cellspacing="0" width="676">
<tbody>
<tr>
<th width="159" scope="row">Version:</th>
<td width="634">Tested on  GForge 4.5.11</td>
</tr>
<tr>
<th scope="row">Discovered by:</th>
<td>José Ramón Palanco:  jose.palanco(at)eazel(dot)es</p>
<p><a href="../">http://www.eazel.es</a></td>
</tr>
<tr>
<th scope="row">Description:</th>
<td>GForge is vulnerable to a security vulnerability that allow Cross-Site  Scripting attacks. Due to improper filtering, a remote attacker can cause a cross site  scripting.</p>
<p>To exploit any attacker may send via GET method the &#8220;words&#8221; variable to:<br />
<strong>&gt;&#8221;&lt;script&gt;alert(&#8216;www.eazel.es&#8217;)&lt;/script&gt;</strong><br />
to http://site/search/advanced_search.php?group_id=X&amp;search=1<br />
where X is any active project in the gforge installation.<br />
<strong>Timeline</strong>:<br />
discovered: 26/10/2006<br />
published: 5/01/2007</p>
<p>keywords: advisory006-gforge-cross-site-scripting-vulnerability.html</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2006/10/26/gforge-cross-site-scripting-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>D-Link DSL-G624T several vulnerabilities</title>
		<link>http://www.eazel.es/2006/10/20/d-link-dsl-g624t-several-vulnerabilities/</link>
		<comments>http://www.eazel.es/2006/10/20/d-link-dsl-g624t-several-vulnerabilities/#comments</comments>
		<pubDate>Fri, 20 Oct 2006 20:21:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[d-link]]></category>
		<category><![CDATA[directory transversal]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=100</guid>
		<description><![CDATA[


Version:
Tested on  D-Link DSL-G624T
Version: Firmware Version :   V3.00B01T01.YA-C.20060616


Discovered by:
José Ramón Palanco:  jose.palanco(at)eazel(dot).es
http://www.eazel.es


Description:
D-Link DSL-G624T ADSL  Router is vulnerable to several securities.
Directory transversal
http://router/cgi-bin/webcm?getpage=/./././././././etc/passwd
http://router/cgi-bin/webcm?getpage=/./././././././etc/config.xml
Cross Site Scripting
Url:: http://router/cgi-bin/webcm
Method:: POST
Variable:: upnp%3Asettings%2Fstate
Value:: &#62;&#8221;&#62;&#60;ScRiPt%20%0a%0d&#62;alert(20102006)%3B&#60;/ScRiPt&#62;
Url:: http://router/cgi-bin/webcm
Method:: POST
Variable::  upnp%3Asettings%2Fconnection
Value::  &#62;&#8221;&#62;&#60;ScRiPt%20%0a%0d&#62;alert(20102006)%3B&#60;/ScRiPt&#62;
Url::  http://router/cgi-bin/webcm
Method:: POST
Variable::  upnp%3Asettings%2Fconnection
Value::  &#8220;+onmouseover=&#8221;alert(20102006)
Directory listing
Is possible to list the /cgi-bin directory
keywords: advisory005-D-Link-DSL-G624T-directoy-transversal-xss-cross-site-scripting-directory-listing-vulnerabilities.html



]]></description>
			<content:encoded><![CDATA[<table style="height: 171px;" border="1" cellspacing="0" width="803">
<tbody>
<tr>
<th width="159" scope="row">Version:</th>
<td width="634">Tested on  D-Link DSL-G624T<br />
Version: Firmware Version :   V3.00B01T01.YA-C.20060616</td>
</tr>
<tr>
<th scope="row">Discovered by:</th>
<td>José Ramón Palanco:  jose.palanco(at)eazel(dot).es</p>
<p><a href="http://web.archive.org/web/20061107145816/http://www.eazel.es/">http://www.eazel.es</a></td>
</tr>
<tr>
<th scope="row">Description:</th>
<td>D-Link DSL-G624T ADSL  Router is vulnerable to several securities.</p>
<h5>Directory transversal</h5>
<p>http://router/cgi-bin/webcm?getpage=/./././././././etc/passwd</p>
<p>http://router/cgi-bin/webcm?getpage=/./././././././etc/config.xml</p>
<h5>Cross Site Scripting</h5>
<p><strong>Url:</strong>: http://router/cgi-bin/webcm<br />
<strong>Method:</strong>: POST<br />
<strong>Variable:</strong>: upnp%3Asettings%2Fstate<br />
<strong>Value:</strong>: &gt;&#8221;&gt;&lt;ScRiPt%20%0a%0d&gt;alert(20102006)%3B&lt;/ScRiPt&gt;</p>
<p><strong>Url:</strong>: http://router/cgi-bin/webcm<br />
<strong>Method:</strong>: POST<br />
<strong>Variable:</strong>:  upnp%3Asettings%2Fconnection<br />
<strong>Value:</strong>:  &gt;&#8221;&gt;&lt;ScRiPt%20%0a%0d&gt;alert(20102006)%3B&lt;/ScRiPt&gt;</p>
<p><strong>Url:</strong>:  http://router/cgi-bin/webcm<br />
<strong>Method:</strong>: POST<br />
<strong>Variable:</strong>:  upnp%3Asettings%2Fconnection<br />
<strong>Value:</strong>:  &#8220;+onmouseover=&#8221;alert(20102006)</p>
<h5>Directory listing</h5>
<p>Is possible to list the /cgi-bin directory</p>
<p>keywords: advisory005-D-Link-DSL-G624T-directoy-transversal-xss-cross-site-scripting-directory-listing-vulnerabilities.html</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2006/10/20/d-link-dsl-g624t-several-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Artículo publicado en la revista Hakin9 sobre técnicas de Xpath Injection</title>
		<link>http://www.eazel.es/2006/08/05/xpath-injection/</link>
		<comments>http://www.eazel.es/2006/08/05/xpath-injection/#comments</comments>
		<pubDate>Sat, 05 Aug 2006 20:58:23 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Papers]]></category>
		<category><![CDATA[hakin9]]></category>
		<category><![CDATA[xpath]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=126</guid>
		<description><![CDATA[


Autor:


Jaime Blasco: jaime.blasco(at)eazel(dot)es
http://www.eazel.es




Descripción:




Un ataque de tipo Xpath Injection consiste en  manipulación de las consultas xpath para extraer información de las  bases de datos XML. Esta es una técnica relativamente nueva que tiene  algunas similutes con los ataques Sql injection.














]]></description>
			<content:encoded><![CDATA[<table border="1" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<th valign="top" scope="row">Autor:</th>
<td>
<div>
<p>Jaime Blasco: jaime.blasco(at)eazel(dot)es</p>
<p><a href="../">http://www.eazel.es</a></p>
</div>
</td>
</tr>
<tr>
<th valign="top" scope="row">Descripción:</th>
<td>
<table border="0" cellspacing="0" cellpadding="5">
<tbody>
<tr>
<td colspan="2">Un ataque de tipo Xpath Injection consiste en  manipulación de las consultas xpath para extraer información de las  bases de datos XML. Esta es una técnica relativamente nueva que tiene  algunas similutes con los ataques Sql injection.</td>
</tr>
<tr>
<td valign="top">
<div>
<p><a href="http://www.eazel.es/wp-content/uploads/2010/04/xpath_new_en.pdf"><img class="alignnone size-medium wp-image-131" title="xpath" src="http://www.eazel.es/wp-content/uploads/2006/08/xpath-212x300.png" alt="" width="212" height="300" /></a></p>
</div>
</td>
</tr>
</tbody>
</table>
</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2006/08/05/xpath-injection/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zyxel Prestige 660H-61  Cross Site Scripting</title>
		<link>http://www.eazel.es/2006/07/26/zyxel-prestige-660h-61-cross-site-scripting/</link>
		<comments>http://www.eazel.es/2006/07/26/zyxel-prestige-660h-61-cross-site-scripting/#comments</comments>
		<pubDate>Wed, 26 Jul 2006 20:12:49 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[xss]]></category>
		<category><![CDATA[zyxel]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=97</guid>
		<description><![CDATA[


Version:
Tested on Zyxel  Prestige 660H-61
ZyNOS F/W Version:  V3.40(PT.0)b32 &#124; 1/28/2005
Standard:NORMAL


Discovered by:
José Ramón Palanco:  jose.palanco(at)eazel(dot).es
http://www.eazel.es


Description:
Zyxel Prestige 660H-61 ADSL  Router is vulnerable to a security vulnerability that allow Cross-Site  Scripting attacks.
Due to improper filtering, a  remote attacker can cause a cross site scripting in this script:
http://router/Forms/rpSysAdmin?a=%3Cscript%3Ealert(&#8216;www.eazel.es&#8217;)%3C/script%3E
keywords: advisory004-Zyxel-Prestige-660H-61-Cross-Site-Scripting.php



]]></description>
			<content:encoded><![CDATA[<table style="height: 171px;" border="1" cellspacing="0" width="803">
<tbody>
<tr>
<th width="159" scope="row">Version:</th>
<td width="634">Tested on Zyxel  Prestige 660H-61<br />
ZyNOS F/W Version:  V3.40(PT.0)b32 | 1/28/2005<br />
Standard:NORMAL</td>
</tr>
<tr>
<th scope="row">Discovered by:</th>
<td>José Ramón Palanco:  jose.palanco(at)eazel(dot).es</p>
<p><a href="../">http://www.eazel.es</a></td>
</tr>
<tr>
<th scope="row">Description:</th>
<td>Zyxel Prestige 660H-61 ADSL  Router is vulnerable to a security vulnerability that allow Cross-Site  Scripting attacks.<br />
Due to improper filtering, a  remote attacker can cause a cross site scripting in this script:</p>
<p>http://router/Forms/rpSysAdmin?a=%3Cscript%3Ealert(&#8216;www.eazel.es&#8217;)%3C/script%3E</p>
<p>keywords: advisory004-Zyxel-Prestige-660H-61-Cross-Site-Scripting.php</td>
</tr>
</tbody>
</table>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2006/07/26/zyxel-prestige-660h-61-cross-site-scripting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Siemens SpeedStream 2624 Denial of Service Vulnerability</title>
		<link>http://www.eazel.es/2006/07/25/siemens-speedstream-2624-denial-of-service-vulnerability/</link>
		<comments>http://www.eazel.es/2006/07/25/siemens-speedstream-2624-denial-of-service-vulnerability/#comments</comments>
		<pubDate>Tue, 25 Jul 2006 20:06:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Advisories]]></category>
		<category><![CDATA[dos]]></category>
		<category><![CDATA[siemens]]></category>
		<category><![CDATA[speedstream]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=94</guid>
		<description><![CDATA[﻿CVE Reference:  CVE-2006-3907   (Links to External Site)
Updated:  Jun 13 2008
Original Entry Date:  Jul 26 2006
Impact:  Denial of service via network
Version(s): Model 2624; possibly others
Description:  A vulnerability was reported in SpeedStream. A remote user can cause denial of service conditions.
A remote user can send a specially crafted packet to the administrative web server to cause the [...]]]></description>
			<content:encoded><![CDATA[<p>﻿CVE Reference:  CVE-2006-3907   (Links to External Site)<br />
Updated:  Jun 13 2008<br />
Original Entry Date:  Jul 26 2006<br />
Impact:  Denial of service via network<br />
Version(s): Model 2624; possibly others<br />
Description:  A vulnerability was reported in SpeedStream. A remote user can cause denial of service conditions.</p>
<p>A remote user can send a specially crafted packet to the administrative web server to cause the target router to freeze. A reboot is necessary to return to normal operations.</p>
<p>The vendor was notified on May 4, 2006.</p>
<p>Jaime Blasco discovered this vulnerability.</p>
<p>The original advisory is available at:</p>
<p>http://www.digitalarmaments.com/2006310665340982.html</p>
<p>Impact:  A remote user can cause the target device to freeze.<br />
Solution:  No solution was available at the time of this entry.<br />
Vendor URL:  www.siemens.com/ (Links to External Site)<br />
Cause:  Exception handling error<br />
Reported By:  info@digitalarmaments.com<br />
Message History:   None.</p>
<p><span id="more-94"></span></p>
<p><span><br />
<span> </span></p>
<pre><span>
Digital Armaments advisory is 05.4.2006

http://www.digitalarmaments.com/2006310665340982.html

I. Background

The SpeedStream Wireless DSL/Cable Router is usually adopted for home and small business solutions. T
ogether with an existing DSL
 or cable modem connection, this affordable, easy to use connection sharing solution brings the freed
om of high-speed, wireless broadband
 connectivity to home and SOHO networks. Its comprehensive functionality provides vital firewall prot
ection, IP sharing capabilities,
 and fundamental routing features that support popular protocols like NetMeeting and VPN.

For further information or detail about the software you can refer to the vendor's homepage:

http://subscriber.communications.siemens.com/

II. Problem Description

It is possible with a specially crafted packet sent to the Web Server that permit Administration of t
he Router to freeze it.

III. Detection

This problem has been detected on latest version of Siemens Speedstrem Router. It has been tested on
the Speedstream 2624.

IV. Impact analysis

Successful exploitation allow an attacker to freeze the router. Reboot is necessary.

V. Solution

First notification 05.04.2006.

Second notification 05.24.2006.

No answer from the vendor.

VI. Credit

Jaime Blasco - jaime.blasco@eazel.es is credited with this discovery.

Get paid and get stocks by vulnerability submission

http://www.digitalarmaments.com/contribute.html

VII. Legal Notices

Copyright © 2006 Digital Armaments LLC.

Redistribution of this alert electronically is allowed. It should not be edited in any way. Reprint t
he whole is allowed, partial
 reprint is not permitted. For any other request please email customerservice@digitalarmaments.com fo
r permission.

Disclaimer: The information in the advisory is believed to be accurate at the time of publishing base
d on currently available information.
 Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties
 with regard to this information.
 Neither the author nor the publisher accepts any liability for any direct, indirect, or consequentia
l loss or damage arising from
 use of, or reliance on, this information. 

</span></pre>
<p></span></p>
<p><span> <span> </span></p>
<pre><span>
Digital Armaments advisory is 05.4.2006

http://www.digitalarmaments.com/2006310665340982.html

I. Background

The SpeedStream Wireless DSL/Cable Router is usually adopted for home and small business solutions. T
ogether with an existing DSL
 or cable modem connection, this affordable, easy to use connection sharing solution brings the freed
om of high-speed, wireless broadband
 connectivity to home and SOHO networks. Its comprehensive functionality provides vital firewall prot
ection, IP sharing capabilities,
 and fundamental routing features that support popular protocols like NetMeeting and VPN.

For further information or detail about the software you can refer to the vendor's homepage:

http://subscriber.communications.siemens.com/

II. Problem Description

It is possible with a specially crafted packet sent to the Web Server that permit Administration of t
he Router to freeze it.

III. Detection

This problem has been detected on latest version of Siemens Speedstrem Router. It has been tested on
the Speedstream 2624.

IV. Impact analysis

Successful exploitation allow an attacker to freeze the router. Reboot is necessary.

V. Solution

First notification 05.04.2006.

Second notification 05.24.2006.

No answer from the vendor.

VI. Credit

Jaime Blasco - jaime.blasco@eazel.es is credited with this discovery.

Get paid and get stocks by vulnerability submission

http://www.digitalarmaments.com/contribute.html

VII. Legal Notices

Copyright © 2006 Digital Armaments LLC.

Redistribution of this alert electronically is allowed. It should not be edited in any way. Reprint t
he whole is allowed, partial
 reprint is not permitted. For any other request please email customerservice@digitalarmaments.com fo
r permission.

Disclaimer: The information in the advisory is believed to be accurate at the time of publishing base
d on currently available information.
 Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties
 with regard to this information.
 Neither the author nor the publisher accepts any liability for any direct, indirect, or consequentia
l loss or damage arising from
 use of, or reliance on, this information. 

</span></pre>
<p></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2006/07/25/siemens-speedstream-2624-denial-of-service-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Flexwatch Authorization Bypassing and XSS Vulnerability</title>
		<link>http://www.eazel.es/2006/07/11/flexwatch-authorization-bypassing-and-xss-vulnerability/</link>
		<comments>http://www.eazel.es/2006/07/11/flexwatch-authorization-bypassing-and-xss-vulnerability/#comments</comments>
		<pubDate>Tue, 11 Jul 2006 19:47:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Advisories]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=88</guid>
		<description><![CDATA[Description:
Multiple FlexWATCH Network Cameras are vulnerable to cross-site  scripting, caused by improper validation of user-supplied input by the  built-in Web server. A remote attacker could exploit this vulnerability  using unspecified scripts and parameters to execute arbitrary script in a  victim&#8217;s Web browser within the security context of the affected  device, [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Description:</strong></p>
<p>Multiple FlexWATCH Network Cameras are vulnerable to cross-site  scripting, caused by improper validation of user-supplied input by the  built-in Web server. A remote attacker could exploit this vulnerability  using unspecified scripts and parameters to execute arbitrary script in a  victim&#8217;s Web browser within the security context of the affected  device, allowing the attacker to steal the victim&#8217;s cookie-based  authentication credentials.</p>
<p><strong>*CVSS:</strong></p>
<table border="0" cellspacing="0" cellpadding="0" width="75%">
<tbody>
<tr>
<td>Base Score:</td>
<td>3.7</td>
</tr>
<tr>
<td>Access Vector:</td>
<td>Remote</td>
</tr>
<tr>
<td>Access Complexity:</td>
<td>High</td>
</tr>
<tr>
<td>Authentication:</td>
<td>Not Required</td>
</tr>
<tr>
<td>Confidentiality Impact:</td>
<td>Partial</td>
</tr>
<tr>
<td>Integrity Impact:</td>
<td>Partial</td>
</tr>
<tr>
<td>Availability Impact:</td>
<td>None</td>
</tr>
<tr>
<td></td>
</tr>
<tr>
<td>Temporal Score:</td>
<td>2.7</td>
</tr>
<tr>
<td>Exploitability:</td>
<td>Unproven</td>
</tr>
<tr>
<td>Remediation Level:</td>
<td>Official-Fix</td>
</tr>
<tr>
<td>Report Confidence:</td>
<td>Confirmed</td>
</tr>
</tbody>
</table>
<p><strong>Consequences:</strong></p>
<p>Gain Access</p>
<p><strong>Remedy:</strong></p>
<p>Refer to the FlexWATCH Web site for patch information. See  References.</p>
<p><strong>References:</strong></p>
<ul>
<li><a href="http://archives.neohapsis.com/archives/bugtraq/2006-07/0123.html" target="_blank">BugTraq Mailing List, Mon Jul 10 2006 &#8211; 04:38:31 CDT </a>:  Digital Armaments Security Advisory 10.07.2006: Flexwath Authorization  Bypassing and XSS Vulnerability.</li>
<li><a href="http://www.flexwatch.com/Seyeon_eng/prointro/camerasvr.asp?id=" target="_blank">FlexWATCH Web site</a>: FlexWATCH &#8211; Network Camera  Server.</li>
<li><a href="http://www.securityfocus.com/bid/18936" target="_blank"><strong>BID-18936</strong></a>:   FlexWATCH Network Camera Cross-Site Scripting Vulnerability</li>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3603" target="_blank"><strong>CVE-2006-3603</strong></a>:   Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH  Network Camera 3.0 and earlier allows remote attackers to inject  arbitrary web script or HTML via the URL.</li>
<li><a href="http://secunia.com/advisories/20994" target="_blank"><strong>SA20994</strong></a>:   FlexWATCH Network Camera FW-3400 Two Vulnerabilities</li>
</ul>
<pre><span id="more-88"></span>

I. Background

FlexWATCH is a stand-alone network camera server with built-in CMOS camera and web server which deliver crisp real time
live videos at a rate up to 30fps over the network. It is normally used as security camera.
For further information or detail about the software you can refer to the vendor's homepage:

<a rel="nofollow" href="http://www.flexwatch.com/">http://www.flexwatch.com/</a>

II. Problem Description

Flexwatch Network Cameras are vulnerable to two security flaws, allowing a cross site scripting and bypassing the
protected areas. Here detailed:

- Cross-site scripting:

An attacker can cause a Cross-site-scripting:
<a rel="nofollow" href="http://camera/%3Cscript%3Ealert">http://camera/%3Cscript%3Ealert</a>('www.eazel.es')%3C/script%3E

- Authorization Bypassing:

An attacker can bypass the protection of protected pages using /..%2f and access to administrative area:
Network Camera V3.0: <a rel="nofollow" href="http://camera/..%2fadmin/aindex.asp">http://camera/..%2fadmin/aindex.asp</a>
Networks Camera Prior versions: <a rel="nofollow" href="http://camera/app/..%2fadmin/aindex.htm">http://camera/app/..%2fadmin/aindex.htm</a>

III. Detection

This problem has been detected on latest and older version of Flexwatch Network Cameras.
Network Camera Versions tested on:
- ver 3.0 for FW-3400-A(PAL)
- ver 2.0 (PAL)
- ver 2.3 (NTSC)

IV. Impact analysis

Successful exploitation allow an attacker to bypass authorization and access the image/video of the security camera.
Cross site attacks are also possible.

V. Solution

First notification 04.16.2006.
Second notification 04.22.2006.
No answer from the vendor.

VI. Credit

Jaime Blasco - jaime.blasco () eazel es is credited with this discovery.

Get paid and get stocks by vulnerability submission
<a rel="nofollow" href="http://www.digitalarmaments.com/contribute.html">http://www.digitalarmaments.com/contribute.html</a>

VII. Legal Notices

Copyright © 2006 Digital Armaments LLC.

Redistribution of this alert electronically is allowed. It should not be edited in any way. Reprint the whole is
allowed, partial reprint is not permitted. For any other request please email customerservice () digitalarmaments com
for permission.

Disclaimer: The information in the advisory is believed to be accurate at the time of publishing based on currently
available information. Use of the information constitutes acceptance for use in an AS IS condition. There are no
warranties with regard to this information. Neither the author nor the publisher accepts any liability for any direct,
indirect, or consequential loss or damage arising from use of, or reliance on, this information.
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2006/07/11/flexwatch-authorization-bypassing-and-xss-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Siemens Speedstream 2624 Password Protection Bypass</title>
		<link>http://www.eazel.es/2006/06/30/siemens-speedstream-2624-password-protection-bypass/</link>
		<comments>http://www.eazel.es/2006/06/30/siemens-speedstream-2624-password-protection-bypass/#comments</comments>
		<pubDate>Fri, 30 Jun 2006 19:16:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Security Advisories]]></category>

		<guid isPermaLink="false">http://www.eazel.es/?p=81</guid>
		<description><![CDATA[CVE Reference:  CVE-2006-3344   (Links to External Site)
Updated:  Aug 12 2008
Original Entry Date:  Jun 29 2006
Impact:  User access via network
Exploit Included:  Yes
Version(s): Tested on Model 2624
Description:  A vulnerability was reported in the SpeedStream wireless  router. A remote user can access restricted files.
A remote user can access protected files without having to login to  the [...]]]></description>
			<content:encoded><![CDATA[<p>CVE Reference:  CVE-2006-3344   (Links to External Site)<br />
Updated:  Aug 12 2008<br />
Original Entry Date:  Jun 29 2006<br />
Impact:  User access via network<br />
Exploit Included:  Yes<br />
Version(s): Tested on Model 2624<br />
Description:  A vulnerability was reported in the SpeedStream wireless  router. A remote user can access restricted files.</p>
<p>A remote user can access protected files without having to login to  the system by using the UPnP support interface.</p>
<p>The vendor was notified on May 2, 2006, without response.</p>
<p>Jaime Blasco discovered this vulnerability.</p>
<p>The original advisory is available at:</p>
<p>http://www.digitalarmaments.com/2006290674551938.html</p>
<p>Impact:  A remote user can access ostensibly protected files on the  target device.<br />
Solution:  No solution was available at the time of this entry.<br />
Vendor URL:  www.siemens.com/ (Links to External Site)<br />
Cause:  Access control error<br />
Reported By:  info@digitalarmaments.com<br />
Message History:   None.</p>
<p><span id="more-81"></span></p>
<pre>Digital Armaments advisory is 05.02.2006

http://www.digitalarmaments.com/2006290674551938.html

I. Background

The SpeedStream Wireless DSL/Cable Router is usually adopted for home and small business solutions. T
ogether with an existing DSL
 or cable modem connection, this affordable, easy to use connection sharing solution brings the freed
om of high-speed, wireless broadband
 connectivity to home and SOHO networks. Its comprehensive functionality provides vital firewall prot
ection, IP sharing capabilities,
 and fundamental routing features that support popular protocols like NetMeeting and VPN.

For further information or detail about the software you can refer to the vendor's homepage:

http://subscriber.communications.siemens.com/

II. Problem Description

Speedstream routers have UPnP/1.0 support. An attacker can access protected files and bypass the pass
word protection without login
 using the UPnP part of the tree.

III. Detection

This problem has been detected on latest version of Siemens Speedstrem Router. It has been tested on
the Speedstream 2624.

IV. Impact analysis

Successful exploitation allow an attacker to bypass the password protection. It also allow an attacke
r to access protected files without
 login.

V. Solution

First notification 05.02.2006.

Second notification 05.20.2006.

No answer from the vendor.

VI. Credit

Jaime Blasco - jaime.blasco@eazel.es is credited with this discovery.

Get paid and get stocks by vulnerability submission

http://www.digitalarmaments.com/contribute.html

VII. Legal Notices

Copyright © 2006 Digital Armaments LLC.

Redistribution of this alert electronically is allowed. It should not be edited in any way. Reprint t
he whole is allowed, partial
 reprint is not permitted. For any other request please email customerservice@digitalarmaments.com fo
r permission.

Disclaimer: The information in the advisory is believed to be accurate at the time of publishing base
d on currently available information.
 Use of the information constitutes acceptance for use in an AS IS condition. There are no warranties
 with regard to this information.
 Neither the author nor the publisher accepts any liability for any direct, indirect, or consequentia
l loss or damage arising from
 use of, or reliance on, this information.
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.eazel.es/2006/06/30/siemens-speedstream-2624-password-protection-bypass/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
