<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CQ-CSER &#187; Hack</title>
	<atom:link href="http://cq-cser.cn/tag/hack/feed/" rel="self" type="application/rss+xml" />
	<link>http://cq-cser.cn</link>
	<description>计算机爱好者</description>
	<lastBuildDate>Sun, 15 Jan 2012 08:17:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Top Ten Web Hacking Techniques of 2009!</title>
		<link>http://cq-cser.cn/2010/01/top-ten-web-hacking-techniques-of-2009/</link>
		<comments>http://cq-cser.cn/2010/01/top-ten-web-hacking-techniques-of-2009/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 03:24:04 +0000</pubDate>
		<dc:creator>cq</dc:creator>
				<category><![CDATA[WEB]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[Hack]]></category>

		<guid isPermaLink="false">http://cq-cser.cn/?p=651</guid>
		<description><![CDATA[Jeremiah Grossman 一直有做这种收集的和评选工作，还是比较具有代表意义的。放眼望去，确实还都是些好文章。 原文： http://feedproxy.google.com/~r/JeremiahGrossman/~3/2LGGL8bgrJI/top-ten-web-hacking-techniques-of-2009.html Top Ten Web Hacking Techniques of 2009! 1. Creating a rogue CA certificate Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, Benne de Weger 2. HTTP Parameter Pollution (HPP) Luca Carettoni, Stefano diPaola 3. Flickr&#8217;s API Signature Forgery Vulnerability (MD5 extension attack) Thai Duong and [...]


Related posts:<ol><li><a href='http://cq-cser.cn/2010/05/crlf-injection/' rel='bookmark' title='Permanent Link: CRLF Injection'>CRLF Injection</a></li>
<li><a href='http://cq-cser.cn/2010/01/%e5%9b%9b%e5%b9%b4300%e4%b8%aa%e6%94%bb%e5%87%bb%e6%8a%80%e6%9c%af%e6%80%bb%e7%bb%93/' rel='bookmark' title='Permanent Link: 四年300个攻击技术总结'>四年300个攻击技术总结</a></li>
<li><a href='http://cq-cser.cn/2010/01/a-new-approach-to-chinazz/' rel='bookmark' title='Permanent Link: A new approach to China[zz]'>A new approach to China[zz]</a></li>
</ol>]]></description>
			<content:encoded><![CDATA[<p>Jeremiah Grossman 一直有做这种收集的和评选工作，还是比较具有代表意义的。放眼望去，确实还都是些好文章。</p>
<p>原文：</p>
<p>http://feedproxy.google.com/~r/JeremiahGrossman/~3/2LGGL8bgrJI/top-ten-web-hacking-techniques-of-2009.html</p>
<p><span style="FONT-SIZE: 130%"><span style="COLOR: #990000; FONT-WEIGHT: bold">Top Ten Web Hacking Techniques of 2009!<span id="more-651"></span></p>
<p></span></span><span style="FONT-WEIGHT: bold">1. </span><a style="FONT-WEIGHT: bold" href="http://www.phreedom.org/research/rogue-ca/" target="_blank">Creating a rogue CA certificate</a><br />
<span style="FONT-STYLE: italic">Alexander Sotirov, Marc Stevens, Jacob Appelbaum, Arjen Lenstra, David Molnar, Dag Arne Osvik, Benne de Weger</span></p>
<p><span style="FONT-WEIGHT: bold">2. </span><a style="FONT-WEIGHT: bold" href="http://blog.mindedsecurity.com/2009/05/http-parameter-pollution-new-web-attack.html" target="_blank">HTTP Parameter Pollution (HPP)</a><br />
<span style="FONT-STYLE: italic">Luca Carettoni, Stefano diPaola </span></p>
<p><span style="FONT-WEIGHT: bold">3. </span><a style="FONT-WEIGHT: bold" href="http://netifera.com/research/" target="_blank">Flickr&#8217;s API Signature Forgery Vulnerability (MD5 extension attack)</a><br />
<span style="FONT-STYLE: italic">Thai Duong and Juliano Rizzo</span></p>
<p><span style="FONT-WEIGHT: bold">4. </span><a style="FONT-WEIGHT: bold" href="http://scarybeastsecurity.blogspot.com/2009/12/cross-domain-search-timing.html" target="_blank">Cross-domain search timing</a><br />
<span style="FONT-STYLE: italic">Chris Evans</span></p>
<p><span style="FONT-WEIGHT: bold">5. </span><a style="FONT-WEIGHT: bold" href="http://ha.ckers.org/blog/20090617/slowloris-http-dos/" target="_blank">Slowloris HTTP DoS</a><br />
<span style="FONT-STYLE: italic">Robert Hansen, (additional credit for earlier discovery to </span><a style="FONT-STYLE: italic" href="http://www.securityfocus.com/archive/1/456339/30/0/threaded" target="_blank">Adrian Ilarion Ciobanu</a><span style="FONT-STYLE: italic"> &amp; Ivan Ristic &#8211; “Programming Model Attacks” section of <a href="http://www.apachesecurity.net/about/table-of-contents.html" target="_blank">Apache Security</a> for describing the attack, but did not produce a tool)</span></p>
<p><span style="FONT-WEIGHT: bold">6. </span><a style="FONT-WEIGHT: bold" href="http://soroush.secproject.com/downloadable/iis-semicolon-report.pdf" target="_blank">Microsoft IIS 0-Day Vulnerability Parsing Files (semi‐colon bug)</a><br />
<span style="FONT-STYLE: italic">Soroush Dalili</span></p>
<p><span style="FONT-WEIGHT: bold">7. </span><a style="FONT-WEIGHT: bold" href="http://stephensclafani.com/2009/05/26/exploiting-unexploitable-xss/" target="_blank">Exploiting unexploitable XSS</a><br />
<span style="FONT-STYLE: italic">Stephen Sclafani</span></p>
<p><span style="FONT-WEIGHT: bold">8. </span><a style="FONT-WEIGHT: bold" href="http://sirdarckcat.blogspot.com/2009/08/our-favorite-xss-filters-and-how-to.html" target="_blank">Our Favorite XSS Filters and how to Attack them</a><br />
<span style="FONT-STYLE: italic">Eduardo Vela (sirdarckcat), David Lindsay</span> (thornmaker)</p>
<p><span style="FONT-WEIGHT: bold">9. </span><a style="FONT-WEIGHT: bold" href="http://www.sectheory.com/rfc1918-security-issues.htm" target="_blank">RFC1918 Caching Security Issues</a><br />
<span style="FONT-STYLE: italic">Robert Hansen</span></p>
<p><span style="FONT-WEIGHT: bold">10. DNS Rebinding (3-part series </span><a style="FONT-WEIGHT: bold" href="http://ha.ckers.org/blog/20090120/persistent-cookies-and-dns-rebinding-redux/" target="_blank">Persistent Cookies</a><span style="FONT-WEIGHT: bold">, </span><a style="FONT-WEIGHT: bold" href="http://ha.ckers.org/blog/20091118/dns-rebinding-for-scraping-and-spamming/" target="_blank">Scraping &amp; Spammin</a><span style="FONT-WEIGHT: bold"><a href="http://ha.ckers.org/blog/20091118/dns-rebinding-for-scraping-and-spamming/" target="_blank">g</a>, and </span><a style="FONT-WEIGHT: bold" href="http://ha.ckers.org/blog/20091116/session-fixation-via-dns-rebinding/" target="_blank">Session Fixation</a><span style="FONT-WEIGHT: bold">)</span><br />
<span style="FONT-STYLE: italic">Robert Hansen</span></p>


<p>Related posts:<ol><li><a href='http://cq-cser.cn/2010/05/crlf-injection/' rel='bookmark' title='Permanent Link: CRLF Injection'>CRLF Injection</a></li>
<li><a href='http://cq-cser.cn/2010/01/%e5%9b%9b%e5%b9%b4300%e4%b8%aa%e6%94%bb%e5%87%bb%e6%8a%80%e6%9c%af%e6%80%bb%e7%bb%93/' rel='bookmark' title='Permanent Link: 四年300个攻击技术总结'>四年300个攻击技术总结</a></li>
<li><a href='http://cq-cser.cn/2010/01/a-new-approach-to-chinazz/' rel='bookmark' title='Permanent Link: A new approach to China[zz]'>A new approach to China[zz]</a></li>
</ol></p>]]></content:encoded>
			<wfw:commentRss>http://cq-cser.cn/2010/01/top-ten-web-hacking-techniques-of-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

