<?xml version='1.0' encoding="ISO-8859-1"?>
				<rss version='2.0'>
				<channel>
				<copyright>Copyright Malerisch.net 2008, all rights reserved.</copyright>
				<pubDate>Mon, 24 Nov 2008 06:25:27 GMT</pubDate>
 
				<description>Malerisch.net :: Site dedicated to security research, tools and articles</description>
   
				<link>http://malerisch.net/</link>

   
				<title>Malerisch.net</title>
				
				<webMaster>http://tinyurl.com/2s935s</webMaster>
   
				<language>en-gb</language>

<item>
    <title>Multiple Adobe Products - XML External Entity And XML Injection</title>
    <link>http://malerisch.net/docs/advisories/2010-02-22_multiple_adobe_products_xml_external_entity_-_xml_injection.html</link>
    <description>22/02/2010 - Multiple Adobe Products are vulnerable to XML External Entity (XXE) and XML Injection attacks. <a href="http://malerisch.net/docs/advisories/2010-02-22_multiple_adobe_products_xml_external_entity_-_xml_injection.html">advisory</a></description>
	<pubDate>Mon, 22 Feb 2010 01:00:00 GMT</pubDate>
</item>		



			<item>
    <title>Defcon 17 Video Online</title>
    <link>http://www.defcon.org/html/links/dc-archives/dc-17-archive.html#Liverani</link>
    <description>24/01/2010 - The video of our Defcon 17 presentation is finally online and it is available from the Defcon web site. Some live demos are included in the second part of the talk. <a href="https://media.defcon.org/dc-17/video/DEFCON%2017%20Hacking%20Conference%20Presentation%20By%20Roberto%20Suggi%20Liverani%20and%20Nick%20Freeman%20-%20Abusing%20Firefox%20Addons%20-%20Video%20and%20Slides.m4v">Enjoy</a>!</description>
	<pubDate>Sun, 24 Jan 2010 10:00:00 GMT</pubDate>
</item>		
				
				
				<item>
    <title>Another Firefox Extension advisory</title>
    <link>http://security-assessment.com/files/advisories/Yoono_Firefox_Extension_Privileged_Code_Injection.pdf</link>
    <description>13/01/2010 - This comes from <a href="http://atta.cked.me/">Nick Freeman</a> and affects the <a href="http://security-assessment.com/files/advisories/Yoono_Firefox_Extension_Privileged_Code_Injection.pdf">Yoono Firefox extension</a>. A very sweet bug ;-).</description>
	<pubDate>Wed, 13 Jan 2010 10:00:00 GMT</pubDate>
</item>	
				
<item>
    <title>SecurityByte &amp; OWASP AppSec Asia 2009 and three 0days released</title>
    <link>http://www.net-security.org/secworld.php?id=8527</link>
    <description>19/11/2009 - I have been talking at the <a href="http://www.securitybyte.org/index.php/conference/sessions/14-exploiting-firefox-extensions.html">SecurityByte and OWASP AppSec Asia 2009</a> conference in India, Gurgaon. It was my first time there and as I love travelling, I coulnd't miss this opportunity. The conference was great, well organised and I have met very interesting people. Definitely recommended! During the talk, <a href="http://www.net-security.org/secworld.php?id=8527">three 0days</a> were finally released, which myself and <a href="http://atta.cked.me/">Nick Freeman</a> previously disclosed to the vendors. A <a href="http://www.youtube.com/watch?v=EPAWQr9X9mw">video interview</a> was also published online, just after the conference.</description>
	<pubDate>Sat, 19 Nov 2009 10:00:00 GMT</pubDate>
</item>	
				
<item>
    <title>Twitter XSS</title>
    <link>http://sites.google.com/site/tentacoloviola/twitterhorror</link>
    <description>14/11/2009 - Not sure if some people noticed, but an interesting <a href="http://sites.google.com/site/tentacoloviola/twitterhorror">XSS vector was found affecting the Twitter web site last November</a>, by Rosario Valotta. When Rosario contacted me, I couldn't believe when looking at the XSS payload. After some talking, I suggested the use of  document.write to bypass some Twitter input filtering controls. This allowed Rosario's injection to include a script tag as well. The bug was also disclosed on <a href="http://seclists.org/fulldisclosure/2009/Nov/179">Full-Disclosure.</a> I just wonder about the so "many" implications of having that kind of XSS bug on Twitter. Happy to not use Twitter ;-)</description>
	<pubDate>Mon, 14 Nov 2009 10:00:00 GMT</pubDate>
</item>	
				

		<item>
    <title>2 Firefox Extensions Chrome Privileged Code Injection</title>
    <link>http://malerisch.net/docs/security_docs.html</link>
    <description>25/08/2009 - Coolpreviews and Update Scanner Firefox Extensions are vulnerable to Cross Site Scripting injection. <a href="docs/advisories/coolpreviews_chrome_privileged_code_injection.html">coolpreviews advisory</a> - <a href="docs/advisories/updatescanner_chrome_privileged_code_injection.html">update scanner advisory</a>.</description>
	<pubDate>Tue, 25 Aug 2009 10:00:00 GMT</pubDate>
</item>	
		
		
		<item>
    <title>2 Firefox Extensions Chrome Privileged Code Injection</title>
    <link>http://malerisch.net/docs/security_docs.html</link>
    <description>25/08/2009 - Coolpreviews and Update Scanner Firefox Extensions are vulnerable to Cross Site Scripting injection. <a href="docs/advisories/coolpreviews_chrome_privileged_code_injection.html">coolpreviews advisory</a> - <a href="docs/advisories/updatescanner_chrome_privileged_code_injection.html">update scanner advisory</a>.</description>
	<pubDate>Tue, 25 Aug 2009 10:00:00 GMT</pubDate>
</item>	
		
		<item>
    <title>Exploiting Firefox Extensions - Interview on Risky.biz</title>
    <link>http://www.risky.biz/netcasts/rb2/rb2-owasp-day-podcast-exploiting-firefox-extensions</link>
    <description>24/08/2009 - Risky.biz recently published our interview with Paul Craig at the OWASP New Zealand Day about exploiting Firefox extensions.</description>
	<pubDate>Mon, 24 Aug 2009 10:00:00 GMT</pubDate>
</item>	
		
		<item>
    <title>Defcon 17 - Presentation</title>
    <link>http://www.malerisch.net/docs/defcon17/roberto_suggi_liverani_nick_freeman_abusing_firefox_extensions_defcon17.pdf</link>
    <description>24/08/2009 - Defcon was great and we have managed to upload our presentation ;-)- download</description>
	<pubDate>Mon, 24 Aug 2009 10:00:00 GMT</pubDate>
</item>	
		
		<item>
    <title>Defcon 17</title>
    <link>http://www.defcon.org/html/defcon-17/dc-17-speakers.html#Liverani</link>
    <description>24/07/2009 - Myself and Nick Freeman are going to Las Vegas to present at Defcon 17 on "<a href="http://www.defcon.org/html/defcon-17/dc-17-speakers.html#Liverani">Abusing Firefox extensions</a>". This time we will show more exploits and bugs ;-). We are on track 4 - 2pm. Check the Defcon <a href="http://www.defcon.org/html/defcon-17/dc-17-schedule.html#saturday" target="_blank">schedule</a>.</description>
	<pubDate>Mon, 24 Jul 2009 10:00:00 GMT</pubDate>
</item>	

<item>
    <title>Backdooring Windows Media Files</title>
    <link>http://sites.google.com/site/tentacoloviola/backdooring-windows-media-files</link>
    <description>20/07/2009 - Rosario Valotta recently released a comprehensive white paper on &quot;Backdooring Windows Media Files&quot;. Many interesting points are covered, especially intranet scanning and ftp attacks via SAMI files. More info on his <a href="http://sites.google.com/site/tentacoloviola/backdooring-windows-media-files" target="_blank">blog</a>.</description>
	<pubDate>Mon, 20 Jul 2009 10:00:00 GMT</pubDate>
</item>	

<item>
    <title>OWASP New Zealand Day 2009</title>
    <link>http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2009#tab=Presentations</link>
    <description>13/07/2009 - OWASP NZ Day has been a great event with more than 150 attendees, 7 talks, lot of drinks and fun! ;-) The presentations have been published online and are available for <a href="http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2009#tab=Presentations" target="_blank">download</a>. Key points of the day are covered in an excellent article of  <a href="http://pageofwords.com/blog/CategoryView,category,OWASP.aspxhttp://pageofwords.com/blog/CategoryView,category,OWASP.aspx">Kirk Jackson</a>.</description>
	<pubDate>Mon, 13 Jul 2009 10:00:00 GMT</pubDate>
</item>	
		
		
		<item>
    <title>OWASP New Zealand Day 2009 - Speakers announcement</title>
    <link>http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2009#tab=Speakers</link>
    <description>08/06/2009 - Speakers have been announced for the OWASP NZ Day 2009 conference! Also, more than one hundred of registered people attending! Great result! ;-)</description>
	<pubDate>Mon, 08 Jun 2009 10:00:00 GMT</pubDate>
</item>	
			
			<item>
    <title>EUSecWest 2009</title>
    <link>http://malerisch.net/docs/eusecwest09_exploiting_firefox_extensions/eusecwest09_-_Roberto_Suggi_Liverani_-_Nick Freeman_-_Exploiting_Firefox_Extensions.pdf</link>
    <description>07/06/2009 - Just came back from Europe, London, after been presenting at EUSecWest about "Exploiting Firefox Extensions" with Nick Freeman. It was a really cool conference with very good topics. Our presentation slides are online.</description>
	<pubDate>Sun, 07 Jun 2009 10:00:00 GMT</pubDate>
</item>	
				
				<item>
    <title>OWASP Testing Guide v3.0</title>
    <link>http://www.lulu.com/content/5691953</link>
    <description>05/03/2009 - OWASP Testing Guide v3.0 has been recently published. I partially contributed to it. For those interested, it is also available as a printed book from Lulu.</description>
	<pubDate>Thu, 05 Mar 2000 10:00:00 GMT</pubDate>
</item>
				
				
				
				<item>
    <title>Google Analytics - Stored Cross Site Scripting</title>
    <link>http://malerisch.net/docs/advisories/google_analytics_stored_cross_scripting.html</link>
    <description>08/12/2008 - Google Analytics is vulnerable to Stored Cross Site Scripting. A malicious user is able to inject arbitrary browser content through web sites subscribed to the Google Analytics service.</description>
	<pubDate>Mon, 08 Dec 2008 10:00:00 GMT</pubDate>
</item>
				
				<item>
    <title>sed v0.2</title>
    <link>http://malerisch.net/tools/negativeseo/sed.html</link>
    <description>25/11/2008 - search engine de-optimisation tool update.</description>
	<pubDate>Tue, 25 Nov 2008 12:00:00 GMT</pubDate>
</item>
					
					<item>
    <title>opera stored cross site scripting</title>
    <link>http://malerisch.net/docs/advisories/opera_stored_cross_site_scripting.html</link>
    <description>22/10/2008 - Opera browser is vulnerable to stored Cross Site Scripting. A malicious attacker is able to inject arbitrary browser content through the websites visited with the Opera.</description>
	<pubDate>Wed, 22 Oct 2008 10:00:00 GMT</pubDate>
</item>

<item>
    <title>sed v0.1</title>
    <link>http://malerisch.net/tools/negativeseo/sed.html</link>
    <description>28/09/2008 - search engine de-optimisation tool released.</description>
	<pubDate>Tue, 28 Oct 2008 12:00:00 GMT</pubDate>
</item>

<item>
    <title>Ruxcon 2008</title>
    <link>http://www.ruxcon.org.au/presentations.shtml#15</link>
    <description>12/09/2008 - I will also speaking at Ruxcon about negative SEO. Don't miss this talk if you can't make it at Kiwicon! ;-)</description>
	<pubDate>Fri, 12 Sep 2008 12:00:00 GMT</pubDate>
</item>

<item>
    <title>browser security</title>
    <link>http://malerisch.net/docs/browser_security/browser_security.ppt</link>
    <description>07/09/2008 - I have done some research in the area of browser security and presented this argument at the last OWASP NZ meeting.</description>
	<pubDate>Sun, 07 Sep 2008 12:00:00 GMT</pubDate>
</item>

<item>
    <title>Kiwicon 2008</title>
    <link>http://www.kiwicon.org/presentations#Roberto%20Suggi%20Liverani</link>
    <description>01/09/2008 - I will be speaking at Kiwicon about negative SEO. Don't miss this talk if you love playing with search engines ;-) .</description>
	<pubDate>Mon, 01 Sep 2008 12:00:00 GMT</pubDate>
</item>

</channel>
</rss>