Full Disclosure mailing list archives
Re: Supposed SaS "encryption" weak - Coments and Infor about wrong claims
From: petard <petard () sdf lonestar org>
Date: Wed, 15 Oct 2003 18:10:08 +0000
On Wed, Oct 15, 2003 at 07:05:35PM +0200, Lorenzo Hernandez Garcia-Hierro wrote:
Dear Paul, I've testing your exploit ( good one ) for the supposed html encryption weak of SaS. I think yo toke the exploit/perl script from a developers site because SaS is using an standard of encoding, here is the proof : variables for function _fwk_filter_encrypt($content) $table = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ_@"; $xor = 165; as you see it's not encryption , so , you didn't cracked nothing.... you decoded it !
Then perhaps you'd like to correct your site. In your source code, you write: <!-- Web Site desing by Lorenzo Hernandez Garcia-Hierro--><!-- Encrypted using S ecurity Application Server of No Secure Root Group Security Research --> It would appear that Paul was only quoting your term ("encryption" was enclosed in quotation marks within his mail) rather than indicating that he really considered it to be encryption. FWIW, it's completely useless to encode your content in this way. Try an even simpler exercise: [my version of the "exploit", if you will] 1. Visit your site in a browser (I used Mozilla 1.5) 2. Choose "Select All" from the "Edit" menu. 3. Right-click and choose "View Selection Source". regards, petard _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
Current thread:
- Supposed SaS "encryption" weak - Coments and Infor about wrong claims Lorenzo Hernandez Garcia-Hierro (Oct 15)
- Re: Supposed SaS "encryption" weak - Coments and Infor about wrong claims petard (Oct 15)
- Re: Supposed SaS "encryption" weak - Coments and Infor about wrong claims Lorenzo Hernandez Garcia-Hierro (Oct 15)
- Re: Supposed SaS "encryption" weak - Coments and Infor about wrong claims KF (Oct 15)
- Re: Supposed SaS "encryption" weak - Coments and Infor about wrong claims Valdis . Kletnieks (Oct 15)
- Re: Supposed SaS "encryption" weak - Coments and Infor about wrong claims Nick FitzGerald (Oct 16)
- Re: Supposed SaS "encryption" weak - Coments and Infor about wrong claims Valdis . Kletnieks (Oct 15)
- Re: Supposed SaS "encryption" weak - Coments and Infor about wrong claims petard (Oct 15)