Re: [Full-Disclosure] Supposed SaS "encryption" weak - Coments and Infor about wrong claims

From: petard (petard_at_sdf.lonestar.org)
Date: 10/15/03

  • Next message: bobby manly: "Re: [Full-Disclosure] Fw: finally got it right!"
    To: Lorenzo Hernandez Garcia-Hierro <lorenzohgh@nsrg-security.com>
    Date: Wed, 15 Oct 2003 18:10:08 +0000
    
    

    On Wed, Oct 15, 2003 at 07:05:35PM +0200, Lorenzo Hernandez Garcia-Hierro wrote:
    > Dear Paul,
    > I've testing your exploit ( good one ) for the supposed html encryption weak
    > of SaS.
    > I think yo toke the exploit/perl script from a developers site because SaS
    > is using an standard of encoding,
    > here is the proof :
    > variables for function _fwk_filter_encrypt($content)
    > $table = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ_@";
    > $xor = 165;
    > as you see it's not encryption , so , you didn't cracked nothing....
    > you decoded it !
    Then perhaps you'd like to correct your site. In your source code, you write:
    <!-- Web Site desing by Lorenzo Hernandez Garcia-Hierro--><!-- Encrypted using S
    ecurity Application Server of No Secure Root Group Security Research -->

    It would appear that Paul was only quoting your term ("encryption" was enclosed
    in quotation marks within his mail) rather than indicating that he really
    considered it to be encryption.

    FWIW, it's completely useless to encode your content in this way. Try an
    even simpler exercise:
    [my version of the "exploit", if you will]
    1. Visit your site in a browser (I used Mozilla 1.5)
    2. Choose "Select All" from the "Edit" menu.
    3. Right-click and choose "View Selection Source".

    regards,
    petard

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: bobby manly: "Re: [Full-Disclosure] Fw: finally got it right!"

    Relevant Pages

    • Re: Need Help
      ... Then you'll have to read the source code and see what it does... ... Paul T. ... When I press a button I get thye buttondown message, ... I think this is the touch controller problem. ...
      (microsoft.public.windowsce.embedded)
    • Re: depend and launch in init registry
      ... launch sequence and wait for IsAPIReadyor something like that ... > As for creating a named event, unfortunately I don't have the source code ... >> Both of your assumptions about the key meanings are wrong, ... >> Paul T. ...
      (microsoft.public.windowsce.platbuilder)
    • Re: Converting Commodore text files to The Numerica Format?
      ... >> byte for every character. ... The fun starts if you use a more complex ... > ago I ported a QBasic encryption program to C128 BASIC 7.0 If Paul is ... > Encryption is really pretty secure using the program I converted. ...
      (comp.sys.cbm)
    • Re: Magnifying Glass
      ... I was wanting a magnifying program that runs on the CE device. ... If source code is available, ... Rudy ... > Paul T. ...
      (microsoft.public.windowsce.app.development)
    • Re: Expansion of HLA Adventure
      ... >>> If wanted to include a bunch of DATA files with descriptions of each ... >>> source code file to the game. ... >>> Paul ... a structure that can be indexed by a single code block rather than ...
      (alt.lang.asm)

  • Quantcast