<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Interesting JForum vulnerabilties and the ESAPI WAF</title>
	<atom:link href="http://i8jesus.com/?feed=rss2&#038;p=102" rel="self" type="application/rss+xml" />
	<link>http://i8jesus.com/?p=102</link>
	<description>because arshan's too cheap to license OneNote</description>
	<lastBuildDate>Wed, 01 Sep 2010 06:10:02 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Giorgio Fedon</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-33062</link>
		<dc:creator>Giorgio Fedon</dc:creator>
		<pubDate>Tue, 29 Jun 2010 08:12:44 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-33062</guid>
		<description>ahahah, Italian soccer team plays better on my PS3 !

I will have a look on it... ;D</description>
		<content:encoded><![CDATA[<p>ahahah, Italian soccer team plays better on my PS3 !</p>
<p>I will have a look on it&#8230; ;D</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-32919</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Fri, 25 Jun 2010 04:53:50 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-32919</guid>
		<description>nice flaw giorgio! why don&#039;t you go bang on antisamy for a while =] the new SAX parser needs some attention, and it&#039;s not like you have anything to watch in the world cup anymore</description>
		<content:encoded><![CDATA[<p>nice flaw giorgio! why don&#8217;t you go bang on antisamy for a while =] the new SAX parser needs some attention, and it&#8217;s not like you have anything to watch in the world cup anymore</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Giorgio Fedon</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-32876</link>
		<dc:creator>Giorgio Fedon</dc:creator>
		<pubDate>Thu, 24 Jun 2010 09:37:00 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-32876</guid>
		<description>We found a nice stored Cross Site Scripting in BBCode; actually we have included jforum as a sample application in our Java Secure coding classroom.

http://www.mindedsecurity.com/MSA130510.html</description>
		<content:encoded><![CDATA[<p>We found a nice stored Cross Site Scripting in BBCode; actually we have included jforum as a sample application in our Java Secure coding classroom.</p>
<p><a href="http://www.mindedsecurity.com/MSA130510.html" rel="nofollow">http://www.mindedsecurity.com/MSA130510.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: aaron</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-29434</link>
		<dc:creator>aaron</dc:creator>
		<pubDate>Sat, 13 Mar 2010 22:41:38 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-29434</guid>
		<description>Rafael, are these fixed in a 2.x release?</description>
		<content:encoded><![CDATA[<p>Rafael, are these fixed in a 2.x release?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-27832</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Tue, 26 Jan 2010 13:30:20 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-27832</guid>
		<description>hi rafael! i emailed you directly on 10/26/2009. i can re-forward you the email if you&#039;d like. don&#039;t feel bad about the vulns - it&#039;s easy to poke holes =]

keep up the good work!</description>
		<content:encoded><![CDATA[<p>hi rafael! i emailed you directly on 10/26/2009. i can re-forward you the email if you&#8217;d like. don&#8217;t feel bad about the vulns &#8211; it&#8217;s easy to poke holes =]</p>
<p>keep up the good work!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rafael Steil</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-27584</link>
		<dc:creator>Rafael Steil</dc:creator>
		<pubDate>Thu, 14 Jan 2010 22:44:35 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-27584</guid>
		<description>Hello Arshan, 

quite impressive I&#039;d say. The hash bugs (md5 with timemillis) is so obvious now you have pointed it out that I shame myself for doing such n00b thing. The XSS attack amazed me as well :)

You said you contacted us about these bugs, but I can&#039;t remember right now, so I think I should have more attention to the forum or the emails, sorry. 

I&#039;ll fix these issues in JForum 3 source code as well (http://github.com/jforum/jforum3)

Cheers,
Rafael</description>
		<content:encoded><![CDATA[<p>Hello Arshan, </p>
<p>quite impressive I&#8217;d say. The hash bugs (md5 with timemillis) is so obvious now you have pointed it out that I shame myself for doing such n00b thing. The XSS attack amazed me as well <img src='http://i8jesus.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>You said you contacted us about these bugs, but I can&#8217;t remember right now, so I think I should have more attention to the forum or the emails, sorry. </p>
<p>I&#8217;ll fix these issues in JForum 3 source code as well (<a href="http://github.com/jforum/jforum3" rel="nofollow">http://github.com/jforum/jforum3</a>)</p>
<p>Cheers,<br />
Rafael</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-27582</link>
		<dc:creator>Scott</dc:creator>
		<pubDate>Thu, 14 Jan 2010 21:53:23 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-27582</guid>
		<description>Thanks for the heads up.  My install was vulnerable so I changed the code.  There was already a USER_HASH_SEQUENCE in the SystemGlobals so I used it go generate the hash:

String hash = MD5.crypt(SystemGlobals.getValue(ConfigKeys.USER_HASH_SEQUENCE) + user.getEmail() + System.currentTimeMillis());

The key, of course, is that the installer should have changed the user.hash.sequence value in WEB-INF/config/jforum-custom.conf

I&#039;m working on the rest.</description>
		<content:encoded><![CDATA[<p>Thanks for the heads up.  My install was vulnerable so I changed the code.  There was already a USER_HASH_SEQUENCE in the SystemGlobals so I used it go generate the hash:</p>
<p>String hash = MD5.crypt(SystemGlobals.getValue(ConfigKeys.USER_HASH_SEQUENCE) + user.getEmail() + System.currentTimeMillis());</p>
<p>The key, of course, is that the installer should have changed the user.hash.sequence value in WEB-INF/config/jforum-custom.conf</p>
<p>I&#8217;m working on the rest.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: arshan dabirsiaghi</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-27301</link>
		<dc:creator>arshan dabirsiaghi</dc:creator>
		<pubDate>Mon, 04 Jan 2010 17:24:40 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-27301</guid>
		<description>given the track record of the others you mentioned, i don&#039;t think you&#039;re in any more trouble choosing JForum</description>
		<content:encoded><![CDATA[<p>given the track record of the others you mentioned, i don&#8217;t think you&#8217;re in any more trouble choosing JForum</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brian</title>
		<link>http://i8jesus.com/?p=102&#038;cpage=1#comment-27122</link>
		<dc:creator>Brian</dc:creator>
		<pubDate>Mon, 28 Dec 2009 18:30:07 +0000</pubDate>
		<guid isPermaLink="false">http://i8jesus.com/?p=102#comment-27122</guid>
		<description>Would you recommend JForum then considering these vulnerabilities? I&#039;ve been asked to evaluate forum software that can hopefully integrate (if possible )with our current Java application. I was looking at JForum, phpBB, and vBulletin. 
Thanks!</description>
		<content:encoded><![CDATA[<p>Would you recommend JForum then considering these vulnerabilities? I&#8217;ve been asked to evaluate forum software that can hopefully integrate (if possible )with our current Java application. I was looking at JForum, phpBB, and vBulletin.<br />
Thanks!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
