<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Xss in BitDefender.ro, .es, .fr and co.uk</title>
	<atom:link href="http://blog.rstcenter.com/2009/09/30/bitdefender-ro-es-fr-and-co-uk/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.rstcenter.com/2009/09/30/bitdefender-ro-es-fr-and-co-uk/</link>
	<description></description>
	<lastBuildDate>Fri, 10 Sep 2010 02:26:50 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: antivirus</title>
		<link>http://blog.rstcenter.com/2009/09/30/bitdefender-ro-es-fr-and-co-uk/comment-page-1/#comment-3546</link>
		<dc:creator>antivirus</dc:creator>
		<pubDate>Wed, 30 Sep 2009 16:22:55 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=2621#comment-3546</guid>
		<description>Adica mai exact BitDefender au site-urile varza !</description>
		<content:encoded><![CDATA[<p>Adica mai exact BitDefender au site-urile varza !</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: B7ackAnge7z</title>
		<link>http://blog.rstcenter.com/2009/09/30/bitdefender-ro-es-fr-and-co-uk/comment-page-1/#comment-3533</link>
		<dc:creator>B7ackAnge7z</dc:creator>
		<pubDate>Wed, 30 Sep 2009 01:07:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=2621#comment-3533</guid>
		<description>@ 2fingers,
Aha, asta am observat si eu.

Apropo, ceva nu e in regula cu forma de raportare a vulenrabilitatilor. Poti te rog sa te uiti sau sa ma contactezi? merci</description>
		<content:encoded><![CDATA[<p>@ 2fingers,<br />
Aha, asta am observat si eu.</p>
<p>Apropo, ceva nu e in regula cu forma de raportare a vulenrabilitatilor. Poti te rog sa te uiti sau sa ma contactezi? merci</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 2fingers</title>
		<link>http://blog.rstcenter.com/2009/09/30/bitdefender-ro-es-fr-and-co-uk/comment-page-1/#comment-3531</link>
		<dc:creator>2fingers</dc:creator>
		<pubDate>Wed, 30 Sep 2009 00:15:03 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=2621#comment-3531</guid>
		<description>Probabil e un copy/paste tradus pe domeniile respective. Nu absolut toate sunt la fel. Bitdefender.com.mx spre exemplu este diferit. Dar nu neaparat intr-un sens mai bun. 

Daca cineva se apuca sa caute cu mare atentie in toate domeniile va gasi probabil mult mai multe vulnerabilitati si nu bag mana in foc ca vor fi doar cele de tip xss. Eu mi-am pierdut rabdarea sa caut cu mare atentie si am stat foarte putin timp ca sa gasesc xss-urile astea, dar pe com.mx, spre exemplu, am vazut niste erori sql care ma fac sa cred ca exista probleme si mai mari in acel domeniu.

Exemplu: &lt;code&gt;Query SQL:
SELECT url,type,description,position FROM catalog.images WHERE id_domain = &#039;bitdefender.com.mx&#039;AND id_item = &#039;4768&#039;&#039; AND type=&#039;Image&#039; ORDER BY position ASC
WARNING [/usr/local/idem/framework/lib/ensi/isql.class.php:80] You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near &#039;Image&#039; ORDER BY position ASC&#039; at line 3 &lt;/code&gt;</description>
		<content:encoded><![CDATA[<p>Probabil e un copy/paste tradus pe domeniile respective. Nu absolut toate sunt la fel. Bitdefender.com.mx spre exemplu este diferit. Dar nu neaparat intr-un sens mai bun. </p>
<p>Daca cineva se apuca sa caute cu mare atentie in toate domeniile va gasi probabil mult mai multe vulnerabilitati si nu bag mana in foc ca vor fi doar cele de tip xss. Eu mi-am pierdut rabdarea sa caut cu mare atentie si am stat foarte putin timp ca sa gasesc xss-urile astea, dar pe com.mx, spre exemplu, am vazut niste erori sql care ma fac sa cred ca exista probleme si mai mari in acel domeniu.</p>
<p>Exemplu: <code>Query SQL:<br />
SELECT url,type,description,position FROM catalog.images WHERE id_domain = 'bitdefender.com.mx'AND id_item = '4768'' AND type='Image' ORDER BY position ASC<br />
WARNING [/usr/local/idem/framework/lib/ensi/isql.class.php:80] You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'Image' ORDER BY position ASC' at line 3 </code></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: B7ackAnge7z</title>
		<link>http://blog.rstcenter.com/2009/09/30/bitdefender-ro-es-fr-and-co-uk/comment-page-1/#comment-3530</link>
		<dc:creator>B7ackAnge7z</dc:creator>
		<pubDate>Wed, 30 Sep 2009 00:04:34 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=2621#comment-3530</guid>
		<description>@ 2fingers,
Pe mine m-a invins curiozitatea - chiar fiecare site foloseste aceleasi erori?? :)

Si am descoperit ca numai pe BitDefender.SE se foloseste ceva diferit, in rest doar o banala traducere.

Si daca ar fi (nici nu ma indoiesc) un SQL injection? Sau poate toate site-urile folosesc aceeasi Baza de Date?
:D</description>
		<content:encoded><![CDATA[<p>@ 2fingers,<br />
Pe mine m-a invins curiozitatea &#8211; chiar fiecare site foloseste aceleasi erori?? <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Si am descoperit ca numai pe BitDefender.SE se foloseste ceva diferit, in rest doar o banala traducere.</p>
<p>Si daca ar fi (nici nu ma indoiesc) un SQL injection? Sau poate toate site-urile folosesc aceeasi Baza de Date?<br />
 <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: 2fingers</title>
		<link>http://blog.rstcenter.com/2009/09/30/bitdefender-ro-es-fr-and-co-uk/comment-page-1/#comment-3529</link>
		<dc:creator>2fingers</dc:creator>
		<pubDate>Tue, 29 Sep 2009 23:49:07 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=2621#comment-3529</guid>
		<description>Sincer iti spun ca mi-a fost lene sa le iau pe toate la rand.</description>
		<content:encoded><![CDATA[<p>Sincer iti spun ca mi-a fost lene sa le iau pe toate la rand.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: B7ackAnge7z</title>
		<link>http://blog.rstcenter.com/2009/09/30/bitdefender-ro-es-fr-and-co-uk/comment-page-1/#comment-3528</link>
		<dc:creator>B7ackAnge7z</dc:creator>
		<pubDate>Tue, 29 Sep 2009 23:44:56 +0000</pubDate>
		<guid isPermaLink="false">http://blog.rstcenter.com/?p=2621#comment-3528</guid>
		<description>@ 2fingers,
Ai facut o mica eroare &quot;gramaticala&quot;, caci linga BitDefender.ro, intre paranteze trabuia sa mai indici si .it, .com, .de, .com.au, .es, .fr, .co.uk
;)</description>
		<content:encoded><![CDATA[<p>@ 2fingers,<br />
Ai facut o mica eroare &#8220;gramaticala&#8221;, caci linga BitDefender.ro, intre paranteze trabuia sa mai indici si .it, .com, .de, .com.au, .es, .fr, .co.uk<br />
 <img src='http://blog.rstcenter.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
</channel>
</rss>
