<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!--Web 2.0 Content Powered by MyST Blogsite® (http://blogsite.com)-->
<!--A service of MyST Technology Partners, Inc. (http://myst-technology.com)-->
<?xml-stylesheet href="http://blog.cenzic.com/public/styles/etc/object.xsl" type="text/xsl"?>

<?myst-baseUrl http://blog.cenzic.com/public/?>

<MySmartChannels Public="true" UserID="202607" dT="97" t0="1268712323584">
     <GetChannelItem_Result>
      <Item>
       <Resource>
        <ObjectID>222630</ObjectID>
        <ObjectClass>Resource</ObjectClass>
        <OwnerID ObjectClass="Domain" Title="[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities">202612</OwnerID>
        <CreatedByID ObjectClass="User" Title="eswanson">202768</CreatedByID>
        <ModifiedByID ObjectClass="User" Title="eswanson">202768</ModifiedByID>
        <CreateTime Title="2009-01-04 18:10:07 EST">1231110607224</CreateTime>
        <ModifyTime Title="2009-01-04 20:39:05 EST">1231119545301</ModifyTime>
        <SecurityModel>Controlled</SecurityModel>
        <Name>Cenzic Adds New SmartAttack for JavaScript Hijacking</Name>
        <Summary>New support added for JavaScript Hijacking Vulnerability in Cenzic SmartAttack library</Summary>
        <Description>&lt;p&gt;A New Year means adding a new SmartAttack for Cenzic &amp;ndash;&amp;nbsp;the &lt;strong&gt;JavaScript Hijacking SmartAttack&amp;nbsp;-&lt;/strong&gt; making it our 96th SmartAttack!&amp;nbsp; We added this support to&amp;nbsp;the&amp;nbsp;SmartAttack library arsenal on January 2, 2009 due to the rising number of eavesdropping attacks against AJAX-style Web applications.&amp;nbsp; This vulnerability was &lt;strong&gt;discovered on Gmail&lt;/strong&gt; and recently fixed.&amp;nbsp; &lt;/p&gt;&lt;p&gt;JavaScript Hijacking is an attack that tricks the victim into loading a page that contains a malicious request.&amp;nbsp; The request is malicious because it inherits the identity and privileges of the victim to perform an undesired function on the victim's behalf.&amp;nbsp; If an application is vulnerable, an attacker can force a logged-in victim's browser to send pre-authenticated AJAX request to a vulnerable Web application, potentially forcing the victim's browser to perform a hostile action.&amp;nbsp; This allows an attacker to perform all the legitimate actions which a legitimate user can perform after a log-in. &lt;/p&gt;&lt;p&gt;And because our development team felt extra ambitious over the holiday season, we also added enhanced support for our Web Server SmartAttack by updating it with the &lt;strong&gt;PHP 'imageRotate()' Uninitialized Memory Information Disclosure Vulnerability&lt;/strong&gt; (Bugtraq ID 33002).&amp;nbsp; More information about this vulnerability can be found at:&lt;br /&gt;&lt;a href="http://www.securityfocus.com/bid/33002/"&gt;&lt;strong&gt;&lt;u&gt;http://www.securityfocus.com/bid/33002/&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;To learn more details on how you can automatically update your Cenzic Hailstorm product, visit our &lt;a title="Cenzic SmartAttack Library" href="http://www.cenzic.com/index.php?id=technology_cia-research_smartAttacks" target="_blank"&gt;&lt;strong&gt;&lt;u&gt;Website&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;.&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;br /&gt;&lt;strong&gt;Background on Cenzic&amp;rsquo;s SmartAttacks&lt;/strong&gt;&lt;br /&gt;Every week, Cenzic&amp;rsquo;s suite of products is updated with the latest vulnerabilities (custom, commercial, and open-source) to use when it emulates a hacker and attacks our customer&amp;rsquo;s Websites to detect their security posture.&amp;nbsp;&amp;nbsp; These Web application vulnerabilities include (but not limited to) cross site scripting, buffer overflow, path or directory traversal, SQL injection, HTTP response splitting, and other workflow types.&lt;/p&gt;&lt;p&gt;by&lt;br /&gt;&lt;strong&gt;Erin Swanson&lt;br /&gt;&lt;/strong&gt;&lt;a href="mailto:ESwanson@cenzic.com"&gt;&lt;strong&gt;&lt;u&gt;ESwanson@cenzic.com&lt;/u&gt;&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt;</Description>
        <ResourceTypeID ObjectClass="ResourceType" Title="Item:Link">9</ResourceTypeID>
        <ContentType>application/xml</ContentType>
        <ContentDocument>
         <ItemProperties>
               <CommonProperties>
                <Hidden>false</Hidden>

                <Keywords>
                 <Keyword>cenzic</Keyword>

                 <Keyword>JavaScript Hijacking</Keyword>

       </Keywords>

                <Links>
                 <Link>
                  <Title>Cenzic SmartAttack Library Updates</Title>

                  <Synopsis>Weekly updates made to Cenzic product suite</Synopsis>

                  <URL>http://www.cenzic.com/index.php?id=technology_cia-research_smartAttacks</URL>

        </Link>

       </Links>

      </CommonProperties>

               <RemoteInfo>
                <UserAgent>Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; GTB5; .NET CLR 1.1.4322; .NET CLR 2.0.50727)</UserAgent>

                <RemoteHost>127.0.0.1</RemoteHost>

                <RemoteAddr>127.0.0.1</RemoteAddr>

                <RemoteUser>eswanson</RemoteUser>

                <ForwardedFor>64.60.123.45</ForwardedFor>

      </RemoteInfo>

     </ItemProperties>
        </ContentDocument>
       </Resource>
       <Shares/>
       <Subjects/>
       <UserPermissions>
        <CanDelete>false</CanDelete>
        <CanDiscover>true</CanDiscover>
        <CanEdit>false</CanEdit>
        <CanEditPermissions>false</CanEditPermissions>
        <CanRead>true</CanRead>
       </UserPermissions>
       <CommentInfo>
        <CommentChannelRef AllowAnonymous="true" Inherited="true">
         <ChannelID ObjectClass="Channel" Title="[Public] Public Comments">204329</ChannelID>
         <UserPermissions>
          <CanCreateChannelItem>false</CanCreateChannelItem>
          <CanDelete>false</CanDelete>
          <CanDiscover>true</CanDiscover>
          <CanEdit>false</CanEdit>
          <CanEditPermissions>false</CanEditPermissions>
          <CanPublish>false</CanPublish>
          <CanRead>true</CanRead>
         </UserPermissions>
        </CommentChannelRef>
        <Comments/>
       </CommentInfo>
       <Views>
        <SourceID ObjectClass="Channel" Title="[Weblog] Cenzic SmartAttack Updates for Web Vulnerabilities">202612</SourceID>

               <View>
                <Name>blog</Name>

                <Model>blogsite/Cenzic/web</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>edit-item</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>left</Name>

                <Model>blogsite/Cenzic/left-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>right</Name>

                <Model>blogsite/Cenzic/right-content</Model>

                <Style/>

                <Scheme/>

       </View>

               <View>
                <Name>wide</Name>

                <Model>blogsite/Cenzic/wide-content</Model>

                <Style/>

                <Scheme/>

       </View>

      </Views>
        <Views>
         <SourceID ObjectClass="Channel" Shared="true" Title="[Public] What's New">202621</SourceID>

                <View>
                 <Name>blog</Name>

                 <Model>blogsite/Cenzic/whatsnew</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>edit-item</Name>

                 <Model>blogsite/Cenzic/right-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>left</Name>

                 <Model>blogsite/Cenzic/left-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>right</Name>

                 <Model>blogsite/Cenzic/right-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

                <View>
                 <Name>wide</Name>

                 <Model>blogsite/Cenzic/wide-content</Model>

                 <Style/>

                 <Scheme/>

       </View>

      </Views>
        </Item>
       </GetChannelItem_Result>
      </MySmartChannels>
