<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/'><id>tag:blogger.com,1999:blog-732257695511948254.post3416084475748372185..comments</id><updated>2009-09-16T04:47:38.749-07:00</updated><category term='hpp'/><category term='virtualization'/><category term='java'/><category term='tool'/><category term='joomla'/><category term='confidence'/><category term='vmware'/><category term='snagg'/><category term='security'/><category term='blackfire'/><category term='mac os x'/><category term='tomcat'/><category term='hacking'/><category term='exploit acquisition program'/><category term='cloud'/><category term='bug bounty program'/><category term='sql injection'/><category term='vasto'/><category term='forensics'/><category term='oracle'/><category term='black hat'/><category term='iphone'/><category term='daath'/><category term='disclosure'/><category term='typo3'/><category term='owasp'/><category term='ikki'/><category term='xss'/><category term='syscan'/><category term='ms access'/><category term='exploit'/><category term='vulnerability acquisition program'/><title type='text'>Comments on Nibble Security: One-Day Knowledge</title><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://blog.nibblesec.org/feeds/3416084475748372185/comments/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3416084475748372185/comments/default'/><link rel='alternate' type='text/html' href='http://blog.nibblesec.org/2009/09/one-day-knowledge.html'/><author><name>Claudio Criscione</name><uri>http://www.blogger.com/profile/12202628660778574382</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>2</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-732257695511948254.post-2716545382644498280</id><published>2009-09-16T04:47:38.749-07:00</published><updated>2009-09-16T04:47:38.749-07:00</updated><title type='text'>Nice to see you here!
The idea is to inject a fake...</title><content type='html'>Nice to see you here!&lt;br /&gt;The idea is to inject a fake option (e.g. –-fake) in order to get the usage screen which does not contain strings as “Error”, “login incorrect”, etc. In this case, the username matches the format as well as the “authenticate()” function does not return errors.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;Luca</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3416084475748372185/comments/default/2716545382644498280'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3416084475748372185/comments/default/2716545382644498280'/><link rel='alternate' type='text/html' href='http://blog.nibblesec.org/2009/09/one-day-knowledge.html?showComment=1253101658749#c2716545382644498280' title=''/><author><name>Luca Carettoni</name><uri>http://www.blogger.com/profile/09957564681262364569</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='31' src='http://1.bp.blogspot.com/_5TMxqPSTp9k/SXnAA-dClZI/AAAAAAAAA1s/80j8Ko3ETb4/S220/lucacarettoni_small.jpg'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.nibblesec.org/2009/09/one-day-knowledge.html' ref='tag:blogger.com,1999:blog-732257695511948254.post-3416084475748372185' source='http://www.blogger.com/feeds/732257695511948254/posts/default/3416084475748372185' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-871964520'/></entry><entry><id>tag:blogger.com,1999:blog-732257695511948254.post-380132604891786058</id><published>2009-09-15T09:47:23.117-07:00</published><updated>2009-09-15T09:47:23.117-07:00</updated><title type='text'>Great work Luca!! 
Now it makes sense, the &amp;#39;--...</title><content type='html'>Great work Luca!! &lt;br /&gt;Now it makes sense, the &amp;#39;--&amp;#39; in the username field is causing the command line tool to return with no errors right? I think posting the section of the code calling the command-line tool might provide more insight.</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3416084475748372185/comments/default/380132604891786058'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/732257695511948254/3416084475748372185/comments/default/380132604891786058'/><link rel='alternate' type='text/html' href='http://blog.nibblesec.org/2009/09/one-day-knowledge.html?showComment=1253033243117#c380132604891786058' title=''/><author><name>Lavakumar Kuppan</name><uri>http://www.blogger.com/profile/13649160238198743851</uri><email>noreply@blogger.com</email><gd:image xmlns:gd='http://schemas.google.com/g/2005' rel='http://schemas.google.com/g/2005#thumbnail' width='31' height='26' src='http://4.bp.blogspot.com/_GBIICVXn8gA/SmdlUgxk11I/AAAAAAAAAAY/jM_nvzz4XDo/S220/lava.JPG'/></author><thr:in-reply-to xmlns:thr='http://purl.org/syndication/thread/1.0' href='http://blog.nibblesec.org/2009/09/one-day-knowledge.html' ref='tag:blogger.com,1999:blog-732257695511948254.post-3416084475748372185' source='http://www.blogger.com/feeds/732257695511948254/posts/default/3416084475748372185' type='text/html'/><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='blogger.itemClass' value='pid-1019220683'/></entry></feed>
