<?xml version="1.0" encoding="ISO-8859-1" ?>
				<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
		<channel>
		<title>Vulnerability Lab (News)</title>
		<link>http://www.vulnerability-lab.com/</link>
		<description><![CDATA[Vulnerability-Lab Project news content rss feed!]]></description>
		<atom:link href="http://www.vulnerability-lab.com/rss/rss_news.php" rel="self" type="application/rss+xml" />
		
			<item>
			<title><![CDATA[Lab Member discovered 4 Skype zero-day Vulnerabilities]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=3</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=3</guid>
			<description><![CDATA[Benjamin K.M. discovered 4 Skype zero -day Vulnerabilities.<br />
<br />
Reference - Upcoming: http://www.vulnerability-lab.com/upcoming.php<br />
<br />
Skype 5.3.x 2.2.x 5.2.x 	- Persistent Software Vulnerability  			- High 		- Verified and  Accepted by Vendor<br />
Skype v5.3.x 			- Transfer Standby Buffer Overflow Vulnerability 	- High 		- Accepted by Vendor<br />
Skype v5.2.x and  v5.3.x 	- Critical Pointer Vulnerability 			- Critical 	- Verified and  Accepted by Vendor<br />
Skype v5.3.x v2.2.x v5.2.x 	- Denial of Service Vulnerability 			- Medium(+) 	- Verified and Accepted by Vendor]]></description>
			<pubDate><![CDATA[Wed, 15 Jun 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Laboratory discovered 2 new Kaspersky Vulnerabilities]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=5</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=5</guid>
			<description><![CDATA[An anonymous vulnerability-laboratory researcher/member discovered 2 vulnerabilities for the newst version of Kaspersky Internet Security 2011/2012 & Anti-Virus 2010/2011.<br />
<br />
Reference - Upcoming: http://www.vulnerability-lab.com/upcoming.php<br />
<br />
Kaspersky IS 2011 - Denial of Service Vulnerability   - Low<br />
http://www.vulnerability-lab.com/get_content.php?id=184<br />
<br />
Kaspersky IS & AV 2011 - Memory Corruption Vulnerability   - High<br />
http://www.vulnerability-lab.com/get_content.php?id=129]]></description>
			<pubDate><![CDATA[Tue, 14 Jun 2011 13:01:50 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Adobe Shockwave Flashplayer v10.3.181.14 - Memory Corruption]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=6</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=6</guid>
			<description><![CDATA[A new critical vulnerability has been identified in Adobe SW Flash Player, which may be exploited by remote attackers to <br />
execute arbitrary commands. This issue is due to a memory corruption error when embedding a specially crafted .swf file through <br />
a xul on browser players. Adobe Flash crashes (NPSWF32.dll) due to an null pointer exception, which allows an attacker to <br />
overwrite &amp; read a pointer in memory.<br />
<br />
Affected: Adobe Shockwave Flashplayer 10.3.181.14 - NPSWF32.dll<br />
Credits: Benjamin K.M. - Vulnerability Lab<br />
<br />
URL: http://www.vulnerability-lab.com/get_content.php?id=179]]></description>
			<pubDate><![CDATA[Sat, 18 Jun 2011 22:48:55 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[New Skype 0 Day Vulnerabilities - Accepted by Vendor (Verified)]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=11</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=11</guid>
			<description><![CDATA[We are happy to announce some good news around the new Skype bugs.  <br />
Skype Security team accepted the Skype Vulnerabilities and is providing the updates as soon as possible.<br />
Skype is actually providing no date to fix the different vulnerabilities.<br />
<br />
Author: Vulnerability Research Laboratory - Benjamin Kunz Mejri<br />
<br />
Affected:<br />
Windows v5.3.0.120 and older versions<br />
MacOS v5.2.0.1523 and older versions<br />
Linux 2.2.0.35.x  and older versions<br />
<br />
Skype 5.3.x 2.2.x 5.2.x 	- Persistent XSS Vulnerability  			- High 		- Verified and  Accepted by Vendor<br />
Skype 5.3.x 2.2.x 5.2.x 	- Persistent Software Vulnerability  			- High 		- Verified and  Accepted by Vendor<br />
Skype v5.3.x 			- Transfer Standby Buffer Overflow Vulnerability 	- High 		- Accepted by Vendor<br />
Skype v5.2.x and  v5.3.x 	- Critical Pointer Vulnerability 			- Critical 	- Verified and  Accepted by Vendor<br />
Skype v5.3.x v2.2.x v5.2.x 	- Denial of Service Vulnerability 			- Medium(+) 	- Verified and Accepted by Vendor<br />
<br />
Upcoming: http://www.vulnerability-lab.com/upcoming.php]]></description>
			<pubDate><![CDATA[Thu, 07 Jul 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[0 Day Skype Exploitation Video - Released by Noptrix and VLab]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=13</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=13</guid>
			<description><![CDATA[We are happy to announce that a researcher of the community droped a video about Skype Exploitation.<br />
The video explains how to reproduce &amp;amp; exploit the new skype xss vulnerability on myphone profile.<br />
Our video is a verification session of the bug for Linux, Windows &amp;amp; MacOS. <br />
Enjoy the first skype hacking video ... its free.<br />
<br />
Title:	        Skype 5.3.x 2.2.x 5.2.x - Persistent Profile Vulnerability<br />
Advisory:	http://www.vulnerability-lab.com/get_content.php?id=222<br />
Author:	        noptrix<br />
<br />
View:		http://www.youtube.com/watch?v=eIgb9D-0DWs  (HD)<br />
Download:	http://www.vulnerability-lab.com/resources/videos/222.wmv<br />
<br />
07/15/11     Added Skype-PoC-Youtube-Video link. Thanks and greets to vulnerability-lab.com<br />
URL:	        http://www.noptrix.net/advisories/skype_xss.txt<br />
<br />
<br />
<br />
<br />
]]></description>
			<pubDate><![CDATA[Tue, 12 Jul 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[ICQ v7.5 Remote Vulnerability discovered  by Lab Researcher]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=16</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=16</guid>
			<description><![CDATA[This morning noptrix discovered a new high priority vulnerability on our security laboratory.<br />
Multiple persistent remote bugs are detected on the new ICQ 7.5 version. The product vendor is informed!<br />
<br />
<br />
Title:<br />
======<br />
ICQ Software v7.5 - Persistent Cross Site Vulnerabilities<br />
<br />
<br />
Date:<br />
=====<br />
2011-07-25<br />
<br />
<br />
References:<br />
===========<br />
News > http://www.vulnerability-lab.com/news/get_news.php?id=16<br />
Advisory > http://www.vulnerability-lab.com/get_content.php?id=231<br />
Profile > http://www.vulnerability-lab.com/show.php?user=noptrix<br />
<br />
Public News/Press:<br />
http://www.heise.de/security/meldung/ICQ-anfaellig-fuer-Account-Diebstahl-1286014.html<br />
http://www.golem.de/1107/85249.html<br />
http://seclists.org/fulldisclosure/2011/Jul/321<br />
http://www.securityhome.eu/os/wince/exploit.php?eid=7097215994e2ef2ed7c0382.28269287<br />
<br />
<br />
VL-ID:<br />
=====<br />
231<br />
<br />
<br />
Introduction:<br />
=============<br />
Mit der Chat-Software ICQ 7.5 bleiben Sie mit Ihren Freunden auf der ganzen Welt in Kontakt. <br />
Die neue Version gibt es exklusiv bei CHIP Online zum Download.<br />
 <br />
Fotostrecke: ICQ 7.5 - Next Generation Messenger Mit dem kostenlosen ICQ lassen sich schnell <br />
Text-Mitteilungen und Dateien zwischen angemeldeten Nutzern verschicken. Zudem können Sie gegen <br />
Ihre Freunde in Online-Games antreten, Fotos miteinander austauschen oder coole Animationen auf <br />
das Chat-Fenster des Gegenüber zaubern. Dank der integrierten Audio- und Video-Chatfunktion können <br />
Besitzer eines Headsets und/oder einer Webcam mit ICQ kostenlos miteinander telefonieren, auf <br />
Wunsch sogar samt Live-Bild.<br />
<br />
Kompatibel zu sozialen Netzwerken<br />
Neben der reinen Messenger-Funktionen haben Sie mit ICQ direkten Zugriff auf Social-Networks wie <br />
Facebook (inklusive Facebook Chat), Twitter, YouTube oder Flickr.<br />
<br />
So können Sie Ihren ICQ-Status nun automatisch auf Ihrer Facebook- oder Twitter-Seite veröffentlichen <br />
oder schnell und einfach Bilder und Links austauschen. Umgekehrt sehen Sie im neuen Tab »Feeds from <br />
Friends« in der ICQ-Kontaktliste auch sämtliche Updates Ihrer Freunde in deren sozialen Netzwerken. <br />
Neue Postings lassen sich direkt aus ICQ heraus kommentieren.<br />
<br />
Neue Funktionen in der Version 7.5<br />
    Verbesserter Audio- & Video-Chat<br />
    Mehr als 80 Moods versetzen ICQ in Stimmung<br />
    Einfacher Zugriff auf Emoticons und -tZers über ICQ-Galerie<br />
    Datenschutzsymbole in der ICQ-Kontaktliste zeigen, welche Kontakte gesperrt sind etc.<br />
<br />
(Copy of the Homepage: http://www.chip.de/downloads/ICQ_13004923.html )<br />
<br />
<br />
Abstract:<br />
=========<br />
The vulnerability-lab researcher (noptrix) discovered multiple persistent remote vulnerabilities on ICQ  v7.5 Software.<br />
<br />
<br />
Report-Timeline:<br />
================<br />
2011-07-12:	Vendor Notification<br />
2011-07-15:	Vendor Response/Feedback<br />
2011-07-25:	Public or Non-Public Disclosure<br />
<br />
<br />
Status:<br />
========<br />
Published<br />
<br />
<br />
Affected Products:<br />
==================<br />
Digital Sky Technologies - Mail.RU Group<br />
Product: ICQ v7.5<br />
<br />
<br />
Exploitation-Technique:<br />
=======================<br />
Remote<br />
<br />
<br />
Severity:<br />
=========<br />
High<br />
<br />
<br />
Details:<br />
========<br />
Multiple persistent cross site scripting vulnerability are detected on the famous ICQ v7.5.<br />
The bug allows an remote attacker to inplement malicious persistent script codes on main modules of the software.<br />
The successful exploitation of the vulnerability allows an remote attacker to hijack <br />
icq sessions, manipulate profile content requests, redirect to external targets(websites) & can <br />
lead to malware infiltration.<br />
<br />
Vulnerable Module(s):<br />
				                        [+] Profile - Users<br />
			                        	[+] Feeds Index<br />
<br />
Pictures:<br />
			                              	../icq_cli_xss.png<br />
				                        ../icq_cli_xss2.png<br />
<br />
<br />
Proof of Concept:<br />
=================<br />
The vulnerabilities can be exploited by remote attackers. For demonstration or reproduce ...<br />
<br />
PoC: <br />
"><iframe src=z onload=alert('persistent_xss_p0wer_noptrix') <<br />
... or<br />
%22%3E%3C%69%66%72%61%6D%65%20%73%72%63%3D%7A%20%6F%6E%6C%6<br />
F%61%64%3D%61%6C%65%72%74%28%27%70%65%72%73%69%73%74%65%6E%<br />
74%5F%78%73%73%5F%70%30%77%65%72%5F%6E%6F%70%74%72%69%78%27<br />
%29%20%3C<br />
<br />
<br />
Solution:<br />
=========<br />
Icq.com & the specific nodes has to validate the input characters and sanitize the output to client users.<br />
<br />
<br />
Risk:<br />
=====<br />
The security risk of the remote xss vulnerability is estimated as high because of the persistent attack vector.<br />
<br />
<br />
Credits:<br />
========<br />
noptrix - http://www.noptrix.net/<br />
<br />
<br />
Disclaimer:<br />
===========<br />
The information provided in this advisory is provided as it is without any warranty. Vulnerability-Lab disclaims all warranties, <br />
either expressed or implied, including the warranties of merchantability and capability for a particular purpose. Vulnerability-<br />
Lab or its suppliers are not liable in any case of damage, including direct, indirect, incidental, consequential loss of business <br />
profits or special damages, even if Vulnerability-Lab or its suppliers have been advised of the possibility of such damages. Some <br />
states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation <br />
may not apply. Any modified copy or reproduction, including partially usages, of this file requires authorization from Vulnerability-<br />
Lab. Permission to electronically redistribute this alert in its unmodified form is granted. All other rights, including the use of <br />
other media, are reserved by Vulnerability-Lab or its suppliers.<br />
<br />
    						Copyright © 2011|Vulnerability-Lab]]></description>
			<pubDate><![CDATA[Mon, 25 Jul 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Facebook Bug Bounty #1 #2 - Multiple Web Vulnerabilities]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=19</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=19</guid>
			<description><![CDATA[After the official startup of the vulnerability/bug-bounty program of facebook, we have submitted two vulnerabilities to the FB Security Team for verification.<br />
<br />
2011-08-02  - Facebook #2 BugBounty - SQL Injection Vulnerability  - Remote  - Vulnerability-Lab<br />
Link: http://www.vulnerability-lab.com/get_content.php?id=44<br />
Authors: Benjamin K.M. - Rem0ve<br />
<br />
2011-08-02  - Facebook #1 BugBounty - Persistent Web Vulnerabilities  - Remote  - Vulnerability-Lab<br />
Link: http://www.vulnerability-lab.com/get_content.php?id=239<br />
Authors: Levent Kayan - Noptrix]]></description>
			<pubDate><![CDATA[Tue, 02 Aug 2011 14:51:11 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Lab discovered new StarMoney Banking Software Vulnerabilities]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=31</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=31</guid>
			<description><![CDATA[Some minutes ago a vulnerability researcher (rem0ve) discovered multiple bugs on the starmoney banking software.<br />
<br />
StarMoney Banking Software v8.0 - Multiple Vulnerabilities<br />
Advisory:  http://www.vulnerability-lab.com/get_content.php?id=77]]></description>
			<pubDate><![CDATA[Mon, 29 Aug 2011 21:29:25 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Kaspersky IS AV 2012 Bug released by Laboratory Researcher]]></title>
			<category><![CDATA[Advisories]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=67</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=67</guid>
			<description><![CDATA[The laboratory founder and research team leader Benjamin Kunz Mejri alias Rem0ve discovered a local memory corruption vulnerability<br />
on the famous Kaspersky Antivirus &amp;amp;amp; Internet Security 2011/2012 software. The vulnerability has been identified about 1 year ago. <br />
The bug is located on the vulnerable .cfg import function of the software. <br />
<br />
<br />
V-Lab KIS/KAV Article:<br />
				[+] http://www.vulnerability-lab.com/dev/?p=372<br />
<br />
Advisory:<br />
				[+] http://www.vulnerability-lab.com/get_content.php?id=129<br />
<br />
Video(s):<br />
				[+] http://www.vulnerability-lab.com/get_content.php?id=19<br />
<br />
<br />
News Article(s):<br />
				[+] http://news.softpedia.com/news/Kaspersky-Anti-Virus-and-Internet-Security-2012-Vulnerable-to-Hackers-242508.shtml<br />
				[+] http://packetstormsecurity.org/files/108043/VL-129.txt<br />
				[+] http://www.securityfocus.com/bid/51161/discuss<br />
				[+] http://forums.malwarebytes.org/index.php?showtopic=102805<br />
				[+] http://thehackernews.com/2011/12/kaspersky-internet-security-memory.html<br />
				[+] http://www.honkwin.com/show/1674.html<br />
				[+] http://www.securityfocus.com/bid/51161/info<br />
				[+] http://seclists.org/fulldisclosure/2011/Dec/424<br />
				[+] http://news.hitb.org/content/researcher-discovered-memory-corruption-vulnerability-kaspersky-20112012-products<br />
				[+] http://www.governmentsecurity.org/forum/topic/33575-kaspersky-is-av-20112012-memory-corruption-vulnerability/<br />
				[+] http://news.enigmagroup.org/security/kaspersky-internet-security-memory-corruption-vulnerability/<br />
				[+] http://downloads.securityfocus.com/vulnerabilities/exploits/51161.txt<br />
				[+] http://letsbytecode.com/security/researcher-found-0day-vulnerabilities-in-products-of-kaspersky-20112012/<br />
				[+] http://www.securityhome.eu/exploits/exploit_pdf.php?eid=1262904474ef14c0b47da02.35101581<br />
]]></description>
			<pubDate><![CDATA[Tue, 03 Jan 2012 23:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[DIMVA 2011 (NL) - Capture the Flag Contest (dCTF)]]></title>
			<category><![CDATA[Events]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=4</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=4</guid>
			<description><![CDATA[Our Team is now also registered for a remote session on the dCTF 2011 (Netherlands) .<br />
A lot of famous  teams/participants are available on this contest ... http://www.cs.vu.nl/~sullivan/dCTF/participants.php<br />
<br />
The Capture the Flag (CTF) competition is a hacking-oriented contest in which participants express their creativity <br />
and outside-the-box hacker-thinking attitude in facing a set of security-related challenges.Since the beginning, CTF <br />
competitions required challengers to show their technical and intellectual skills while defending and attacking the <br />
systems of the other contestants. While formats have varied in recent years (e.g., attack-only, treasure hunt, botnet <br />
life-cycle), the spirit and the hacker attitude remained the same.<br />
<br />
It is with this same spirit that we are eager to announce dCTF 2011, a 1-day Capture the Flag competition co-located with <br />
the 2011 edition of DIMVA, the Conference on Detection of Intrusions and Malware &amp; Vulnerability Assessment.<br />
<br />
dCTF will take place on July 7th 2011 and will run approximately from 8:30am CEST to 4:30pm CEST. Teams can take part to <br />
the challenge either remotely or locally. We expect to limit the remote and local number of teams to 30 and 5, respectively. <br />
<br />
... Join the dCTF Contest!<br />
<br />
Register:             http://www.cs.vu.nl/~sullivan/dCTF/dCTF.php#registration]]></description>
			<pubDate><![CDATA[Mon, 13 Jun 2011 04:57:20 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Pim Campers and Benjamin Kunz Mejri Speakers @ HITB Malaysia]]></title>
			<category><![CDATA[Events]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=22</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=22</guid>
			<description><![CDATA[Speakers: Benjamin Kunz Mejri(Germany) and Pim J.F. Campers (Netherlands)<br />
<br />
The popular VOIP client Skype has been beaten?! As everyone knows Skype takes security very seriously according to their <br />
own words: The security of your information is of the utmost concern to us here at Skype and something we take very <br />
seriously  So we rose up to the challenge and tried to see if we could beat the system filters and/or software out of the box. <br />
This presentation will offer the first indepth view and analyses of the bugs that where found in skype by the vulnerability-lab.com <br />
research team (2011).  The presentation will also provide exclusive attack scheme from an attackers point of view <br />
which were also used for verification.<br />
<br />
Buglist:<br />
- Skype 5.3.x 2.2.x 5.2.x – Persistent Cross Site Scripting Vulnerability<br />
- Skype 5.3.x 2.2.x 5.2.x – Persistent Software Vulnerability<br />
- Skype v5.3.x – Transfer Standby Buffer Overflow Vulnerability<br />
- Skype v5.3.x – DLL HIPS Buffer Overflow Vulnerability<br />
- Skype v5.2.x and v5.3.x – Critical Pointer Vulnerability<br />
- Skype v5.3.x v2.2.x v5.2.x – Denial of Service Vulnerability<br />
<br />
Attack Schemes:<br />
- Client Side Skype Exploitation (Local and Remote)<br />
- Server Side Exploitation #1 (Local and Remote)<br />
- Server Side Exploitation #2 (Local and Remote)<br />
- Denial of Service Exploitation (Local and Remote)<br />
- Buffer Overflow Exploitation #1 (Local)<br />
- Buffer Overflow Exploitation #2 (Remote)<br />
- Pointer Bug Exploitation (Local and Remote)<br />
<br />
Also at the presentation if time lets us. Some videos, crash logs etc for those interested.<br />
<br />
About us (Vulnerability Lab Team)<br />
<br />
Benjamin Kunz M.(28) is active as a penetration tester and security analyst for private and public security firms, hosting entities, <br />
banks, isp(telecom) and ips. His specialties are security checks(penetrationtests) on services, software, applications, malware<br />
 analysis, underground economy, military intelligence/cyberwar, reverse engineering, lectures and workshops about IT Security. <br />
During his work as a penetration tester and vulnerability researcher, many open- or closed source applications, software and <br />
services were formed more secure. In 1997, Benjamin K.M. founded a non-commercial and independent security research <br />
group called, Global Evolution – Security Research Group which is still active today.<br />
<br />
From 2010 to 2011, Benjamin M. and Pim C. (Research Team) identified over 300 zero day vulnerabilities in well known <br />
products from companies such as DELL, Barracuda, Mozilla, Kaspersky, McAfee, Google, Cyberoam, Safari, Bitdefender, Asterisk, <br />
Telecom, PBX and SonicWall. In 2010 he founded the company Evolution Security. After the firm’s establishment arose the <br />
Vulnerability Lab as the legal european initiative for vulnerability researchers, analysts, penetration testers, and serious hacker <br />
groups. Ben is also the leader of the Contest + Vulnerability-Lab Research Team. He have a lot of stable references by solved <br />
events or contests like ePost SecCup, SCS2, EH2008, Har2009, Da-op3n and exclusive zero-day exploitation sessions/releases.<br />
<br />
Pim J. F. Campers (24) has worked around five years in the IT Security sector. It began as a hobby, but after high school, he <br />
decided to expand his experience in the area of IT Security. His specialties are security checks on web applications, server and <br />
client applications, underground economy, bypass/crack filters or walls and risk/threat analysis. He currently works closely <br />
with academia and high class software manufacturers and companies.<br />
<br />
Pim has joined the Global Evolution Research Team 2007. From 2010 to 2011, Pim J.C. and Benjamin M. (Research Team) identified <br />
over 300 zero day vulnerabilities in well known products from companies such as DELL, Mozilla, Kaspersky, McAfee, Google, <br />
Cyberoam, Safari, Bitdefender, Asterisk, Telecom, PBX and SonicWall. In 2010 he founded the company Evolution Security with<br />
 Benjamin K.M.. After the firm’s establishment arose the european Vulnerability Lab as the legal european initiative for vulnerability <br />
researchers, analysts, penetration testers, and serious hacker groups. Pim is also the co-leader of the european Wargaming + <br />
Vulnerability-Lab Research Team and have a lot of stable references by solved events or contests like ePost SecCup, SCS2, EH2008, <br />
Har2009, Da-op3n and exclusive zero-day exploitation sessions/releases.<br />
<br />
Conference: http://conference.hitb.org/<br />
Speakers: http://conference.hitb.org/hitbsecconf2011kul/?page_id=24<br />
#1 Sponsor: Microsoft Corporation]]></description>
			<pubDate><![CDATA[Sun, 07 Aug 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[HITB Malaysia - Skype Vulnerabilities: 0Day Exploitation 2011]]></title>
			<category><![CDATA[Events]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=39</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=39</guid>
			<description><![CDATA[On the 11th till 14th october is the  - Hack in the Box - conference in Malaysia.<br />
A laboratory researcher of our team (rem0ve) will visit the conference as speaker.<br />
<br />
Title: Skype Vulnerabilities: Zero Day Exploitation 2011<br />
Authors: Benjamin Kunz Mejri (Rem0ve) [DE] & Pim J.F. Campers (X4lt) [NL]<br />
Profil: http://conference.hitb.org/hitbsecconf2011kul/?page_id=1757<br />
Information: We also provide videos, pictures, full advisories, attack schemes(6-7) and a nice documentation as pdf<br />
<br />
Visit the HITB 2011 Malaysia (KUL) with us ...<br />
Register: https://conference.hitb.org/hitbsecconf2011kul/register/]]></description>
			<pubDate><![CDATA[Thu, 22 Sep 2011 05:06:26 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[CONFERENCE AGENDA -­ HITB MALAYSIA|KUL 2011]]></title>
			<category><![CDATA[Events]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=43</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=43</guid>
			<description><![CDATA[The finalized agenda of the hack in the box malaysia 2011 conference is now available on our partners website. <br />
<br />
Download: http://conference.hitb.org/hitbsecconf2011kul/finalized-agenda.pdf<br />
<br />
Registration: https://conference.hitb.org/hitbsecconf2011kul/register/]]></description>
			<pubDate><![CDATA[Wed, 28 Sep 2011 17:23:20 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Call for Paper x 2 - HackinTheBox Amsterdam 2012]]></title>
			<category><![CDATA[Events]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=64</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=64</guid>
			<description><![CDATA[Today 3 of our vulnerability laboratory researchers called for paper on the HackInTheBox Amsterdam 2012 Security Conference.<br />
<br />
Speaker:	Pim J.F.P. Campers (NL) & Benjamin Kunz Mejri (DE)<br />
Topic: #1:	Banking Nightmare 2012 - PenetrationTests, 0Day Exploitation & Technical Analyses<br />
Language:	ENGLISH<br />
<br />
Speaker:	Chokri B.A. (TN) & Benjamin Kunz Mejri (DE)<br />
Topic: #1:	National Security Agency - 0Day Web Exploitation, Techniques & Methods<br />
Language:	ENGLISH]]></description>
			<pubDate><![CDATA[Tue, 20 Dec 2011 18:33:54 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[CONFidence Security Conference - 23.-24. MAY 2012|Poland]]></title>
			<category><![CDATA[Events]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=84</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=84</guid>
			<description><![CDATA[CONFidence is an annual IT security conference that will take place on 23-24th May, 2012 in Krakow, Poland <br />
for the 10th time! The best speakers, latest issues, laid-back atmosphere and Krakow crazy night life – <br />
that is why CONFidence has become a meeting point of hackers’ community in Europe.<br />
<br />
The core of CONFidence is a two-day conference with workshops, but the whole event is so much more. CONFidence <br />
offers not only the best speakers, current topics and top trainings, but (even more importantly) great parties, <br />
cool contests, crazy social events and a time and space to meet community members face-to-face, talk, <br />
drink and hack.<br />
<br />
This year, apart from the technical part we are planning to deploy a special SpyGames game where attendees <br />
will participate in real spy contests including sneaking past sensors, lockpicking, and will have to rescue <br />
a prisoner from a bunker.A special 15% discount on registration for vulnerability lab members and active researchers.<br />
<br />
CONFERENCE WEBSITE:  	http://2012.confidence.org.pl]]></description>
			<pubDate><![CDATA[Thu, 12 Apr 2012 16:17:25 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[New Partnership - Wargames Malaysia (Wargames.my)]]></title>
			<category><![CDATA[Partnership]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=8</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=8</guid>
			<description><![CDATA[We confirm &amp; announce a new and exotic partnership with wargames malaysia. Wargames.my is a stable &amp; trusted partner for vulnerability-lab. <br />
mCTF is malaysia s first capture the flag competition/contest.<br />
<br />
URL1:                 http://wargames.my<br />
URL2:                 http://wargames.my/rules.php<br />
<br />
Partner:            http://www.vulnerability-lab.com/partner.php<br />
<br />
<br />
Information:<br />
2011 - This Contest is just for malaysian/asian people (Startup: 2011-07.05)<br />
2012 - The Contest will be available for all countries]]></description>
			<pubDate><![CDATA[Fri, 01 Jul 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[New Partnership - Security Guardian (security-guardian.com)]]></title>
			<category><![CDATA[Partnership]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=30</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=30</guid>
			<description><![CDATA[We confirm and announce a new and european partnership with the famous security guardian company. <br />
Security Guardians is our new trusted partner on vulnerability-labs and over 10 years active on the it-security scene in europe.<br />
<br />
URL1:                 www.security-guardian.com<br />
URL2:                 www.security-guardian.com/web-security-customers<br />
Partner:            www.vulnerability-lab.com/partner.php<br />
<br />
]]></description>
			<pubDate><![CDATA[Fri, 26 Aug 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[New Partnership - HuneLock Keyu Intelligence (hunelock.com)]]></title>
			<category><![CDATA[Partnership]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=36</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=36</guid>
			<description><![CDATA[We announce and confirm a new partnership with the famous chinese Hune-Lock Keyu Intelligence security company. <br />
HuneLock is our new trusted partner on vulnerability-labs and over 15 years(1993) active on the security lock business in china/asia/europe.<br />
<br />
URL1:                 http://www.hunelock.com/<br />
URL2:                 http://www.hunelock.com/en/products.asp<br />
Partner:              www.vulnerability-lab.com/partner.php<br />
<br />
]]></description>
			<pubDate><![CDATA[Sun, 18 Sep 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Disclosure partnership between Endian and Vulnerability Lab]]></title>
			<category><![CDATA[Partnership]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=50</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=50</guid>
			<description><![CDATA[Today we announce a new disclosure partnership between endian security community and vulnerability lab.<br />
<br />
The Endian Firewall is a specialized in the functions of router, firewall and gateway security<br />
Linux distribution in the South Tyrolean company endian. Alternatively, the product as free software as a commercial<br />
Software with guaranteed support or installed as a complete hardware (appliance) including<br />
Support services available. Endian is the leader in open-source market for firewalls - utm appliances and monitoring applications.<br />
<br />
URL: http://www.endian.com/en/<br />
Partner: http://www.vulnerability-lab.com/partner.php]]></description>
			<pubDate><![CDATA[Wed, 19 Oct 2011 15:27:49 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Technical exchange with China National Vulnerability Database]]></title>
			<category><![CDATA[Partnership]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=52</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=52</guid>
			<description><![CDATA[Today we will announce our new partnership (high technical exchange) with the chinas national vulnerability database <br />
of information security. As one of the biggest and most successful advisories websites in China, the CNNVD <br />
is listing alert messages, security press news or information and zero day vulnerabilties.<br />
<br />
This partnership gave us the opportunity to work side by side with the CNNVD Team. And they will help us on the <br />
verification and notification process to list exclusive material on the famous CNNVD website.<br />
<br />
Once again we want to thank The CNNVD Team for their partnership with us. We are looking forward to this great partnership.<br />
<br />
Website:		http://www.cnnvd.org.cn<br />
Organisation:		http://www.itsec.gov.cn<br />
Official Partners:	http://www.vulnerability-lab.com/partner.php]]></description>
			<pubDate><![CDATA[Thu, 20 Oct 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Research Team Partnership - PrivateerLabs (US)]]></title>
			<category><![CDATA[Partnership]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=77</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=77</guid>
			<description><![CDATA[Today we want to announce a new partnership between the famous Privateer-Labs & Vulnerability-Lab.<br />
Privateer Labs is a company with focus on mobile security like Android, W7P or iOS. We work on <br />
providing a mobile vulnerability feed which provids kernel, app und service 0-day vulnerabilities.<br />
The feed will be streamed to our partners lab infrastructure.<br />
<br />
OFFICIAL URL:	http://www.privateerlabs.net<br />
<br />
EXCHANGE#1:	http://www.vulnerability-lab.com/partner.php<br />
EXCHANGE#2:	http://www.privateerlabs.net/partners]]></description>
			<pubDate><![CDATA[Fri, 24 Feb 2012 20:10:34 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[New trusted Partnership with OpenSight Software LCC]]></title>
			<category><![CDATA[Partnership]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=80</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=80</guid>
			<description><![CDATA[Today we announce a new and trusted partnership between the opensight software company and the vulnerability lab team.<br />
In the pursuit of excellence in providing the best quality products, experience and services is the remit in which <br />
opensight software base there honesty and relative success. OpenSight is the creater of the well known commercial <br />
FlashFXP Software Client. Our goal is to secure the client software by stable penetration tests in combination with <br />
our vulnerability laboratory disclosure partnership program.<br />
<br />
URL: 		http://www.flashfxp.com/about_us<br />
PARTNER: 	http://www.vulnerability-lab.com/partner.php]]></description>
			<pubDate><![CDATA[Fri, 23 Mar 2012 19:23:36 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Press HITB News - Vulnerability Lab Boots up!]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=2</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=2</guid>
			<description><![CDATA[Today a press article got droped on our partners site of the hackinthebox conference and community.<br />
We are glad to read about ... and hope a lot people will help us or join the vulnerability laboratory project.<br />
<br />
URL: http://news.hitb.org/content/vulnerability-lab-boots<br />
<br />
Please,  remember to join the dCTF Cipher Contest on July 7th 2011.<br />
URL: http://www.cs.vu.nl/~sullivan/dCTF/dCTF.php]]></description>
			<pubDate><![CDATA[Thu, 09 Jun 2011 21:06:11 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Infomercial Radio Technocrate (Venezuela) - Ivan M.M. (VLab)]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=9</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=9</guid>
			<description><![CDATA[Ivan Montilla Miralles discovered a nice informercial on radio - Technocrate.<br />
<br />
<br />
<br />
Themes:	Cyberwar situation, famous hacking attacks, political influence and activist groups<br />
Language: 	Spain<br />
<br />
View:		http://www.youtube.com/watch?v=qNUNZP8Rpfk<br />
Download:	http://www.vulnerability-lab.com/resources/iv-07-technocrate.mp3]]></description>
			<pubDate><![CDATA[Sat, 02 Jul 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[TRUSTe Seal Website - SQL Injection Vulnerability [FIXED!] ]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=12</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=12</guid>
			<description><![CDATA[A critical SQL Injection vulnerability on the TRUSTe Seal Website Service has been fixed/patched by the developers. <br />
Truste is a famous online privacy seals and services provider. The bug allows remote attackers to inject/ execute own sql commands/statements.<br />
The vulnerability was located on the ?sealid= of the click2verify trusted URL service.<br />
<br />
Vendor: <br />
              			                      [+] TRUSTe (truste.com)<br />
<br />
Vulnerable Module(s):<br />
              			                      [+] SealID<br />
<br />
Author:	<br />
              			                      [+] Chokri B.A. (http://www.vulnerability-lab.com/show.php?user=Chokri%20-%20B.A)]]></description>
			<pubDate><![CDATA[Thu, 07 Jul 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[(CFP) HITB Malaysia - Skype VoIP Software Exploitation 2011]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=14</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=14</guid>
			<description><![CDATA[Theme:  Skype VoIP Software Exploitation - Zero Day Vulnerabilities 2011<br />
Author: Benjamin Kunz Mejri alias rem0ve (-rm)<br />
<br />
Phase 1: <br />
(Overview) Published Skype Vulnerabilities 2006-2010 and risk level<br />
<br />
Phase 2:(Informercial)<br />
How to detect own Skype zero-day vulnerabilities?<br />
How to exploit skype zero-day vulnerabilities out of the box?<br />
<br />
Phase 3:(Main Presentation)<br />
Presentation of own zero-day issues ... (explain and technics)<br />
Skype 5.3.x 2.2.x 5.2.x 	- Persistent XSS Vulnerability  			- High 		- Verified and  Accepted by Vendor<br />
Skype 5.3.x 2.2.x 5.2.x 	- Persistent Software Vulnerability  			- High 		- Verified and  Accepted by Vendor<br />
Skype v5.3.x 			- Transfer Standby Buffer Overflow Vulnerability 	- High 		- Accepted by Vendor<br />
Skype v5.2.x and  v5.3.x 	- Critical Pointer Vulnerability 			- Critical 	- Verified and  Accepted by Vendor<br />
Skype v5.3.x v2.2.x v5.2.x 	- Denial of Service Vulnerability 			- Medium(+) 	- Verified and Accepted by Vendor<br />
<br />
Phase 4: (Review and Pictures)<br />
+ 3 mal Videos, Exploitation Review, Exceptions Logs and Pictures<br />
<br />
Technical Requirements: <br />
Beamer/Projector for Pictures and Videos + 1x ClubMate<br />
<br />
Duration: <br />
60 - 120 Minutes]]></description>
			<pubDate><![CDATA[Thu, 14 Jul 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[0 Day Skype Denial of Service Vulnerability released on Lab]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=17</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=17</guid>
			<description><![CDATA[We are happy to announce ... the new skype 0-day denial of service vulnerability have been released in the morning.<br />
<br />
Author: 	Rem0ve - Benjamin Kunz M.<br />
Title: 		Skype v5.3.x v2.2.x v5.2.x - Denial of Service Vulnerability<br />
Link:  		http://www.vulnerability-lab.com/get_content.php?id=181<br />
<br />
Download:	http://www.vulnerability-lab.com/resources/videos/234.wmv<br />
View: 		http://www.youtube.com/watch?v=b9p4BZ0vsAI<br />
<br />
<br />
OS &amp; Version:<br />
Windows v5.3.0.120 and older versions<br />
MacOS v5.2.0.1523 and older versions<br />
Ubuntu v2.2.0.35 and older versions<br />
Debian v2.2.0.35-1 and older versions<br />
Fedora v2.2.0.35-f and older versions<br />
Suse v2.2.0.35-s and older versions<br />
<br />
]]></description>
			<pubDate><![CDATA[Thu, 28 Jul 2011 01:18:24 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[AOK GesundheitsKasse fixed critical SQL Injection Vulnerability]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=20</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=20</guid>
			<description><![CDATA[AOK website developers have fixed a critical sql injection vulnerability on a main module of the website.<br />
The vulnerability allows  remote attackers to read user details, profiles & e-mails of registered customers from the application dbms. <br />
The vulnerability is located on the dsp_font_main module of the public aok website.<br />
<br />
Vulnerable Module(s):<br />
			                              [+] dsp_front_main<br />
<br />
<br />
Report-Timeline:<br />
================<br />
2011-02-06:	Vendor Notification<br />
2011-06-03:	Vendor Response/Feedback<br />
2011-07-27:	Vendor Fix/Patch<br />
2011-08-02:	Public or Non-Public Disclosure<br />
<br />
<br />
Solution:<br />
=========<br />
2011-07-27:	Vendor Fix/Patch<br />
<br />
<br />
Risk:<br />
=====<br />
The security risk of the remote sql injection vulnerability is estimated as high]]></description>
			<pubDate><![CDATA[Tue, 02 Aug 2011 18:11:02 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Medical Center of Neurologie Columbia - SQL Injection [FIXED!] ]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=23</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=23</guid>
			<description><![CDATA[Last month we got a very nice submission by an anonymous researcher/analyst via mail. The researcher tried to discover a vulnerability <br />
on the medical center of neurologie (university of columbia). The bug got fixed this week by the developers of the application service.<br />
<br />
Title: Medical Center of Neurologie Columbia EDU Website - SQL Injection Vulnerability<br />
URL: http://www.vulnerability-lab.com/get_content.php?id=189<br />
<br />
<br />
]]></description>
			<pubDate><![CDATA[Mon, 15 Aug 2011 15:30:16 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Noptrix released new persistent Skype Vulnerability]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=24</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=24</guid>
			<description><![CDATA[A persistent input validation vulnerability is detected on Skype (VoIP) 5.5.x 5.3.x Windows & Macos.<br />
The vulnerability allows an remote attacker to implement malicious persistent script code over an input field (phone number entries)<br />
on the user profile settings. The successfully exploitation of the vulnerability allows an attacker to hijack customer <br />
sessions or can lead to malicous persistent script code execution over the review display listing of the User Profil.<br />
<br />
Vulnerable Module(s):<br />
<br />
			[+] Profile Input Field - Home & office<br />
            		[+] Profile Input Field - Mobile & Office Phone<br />
            		[+] Profile Input Field - Website URL<br />
<br />
Affected:<br />
			[+] Profile Card - Listing<br />
<br />
Risk:<br />
The security risk of the  persistent input validation vulnerabilities are estimated as medium(+).<br />
<br />
<br />
News/Press:<br />
http://www.golem.de/1108/85829.html<br />
http://www.gulli.com/news/16891-skype-mit-neuer-sicherheitsluecke-2011-08-18<br />
http://www.noptrix.net/advisories/skype_inject.txt]]></description>
			<pubDate><![CDATA[Thu, 18 Aug 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Critical Pointer Vulnerability on Skype Software [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=26</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=26</guid>
			<description><![CDATA[A critical pointer vulnerability is located in the macosx &amp; windows version of skype. The bug/vulnerability is located in <br />
2 input forms of an uni-code http search request to the skype search directory server. The vulnerability allows an local attacker <br />
to crash the complete skype process via an unknown unhandled software exception(memory-corruption). The bug allows an local <br />
attacker also to overwrite or read a new adress.<br />
<br />
Vulnerable:<br />
						[+] MacOS v5.2.0.1523<br />
						[+] Windows (x32&amp;x64) - v5.3.0.120<br />
<br />
<br />
Author:<br />
                             http://www.vulnerability-lab.com/show.php?user=Rem0ve<br />
<br />
Advisory:<br />
                             http://www.vulnerability-lab.com/get_content.php?id=180]]></description>
			<pubDate><![CDATA[Mon, 22 Aug 2011 19:33:41 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Strato GmbH patched multiple DOM XSS Bugs on ACP [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=27</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=27</guid>
			<description><![CDATA[Last week we discovered multiple medium priority dom cross site scripting issues for the strato gmbh server admin control panel.<br />
10 days later all of the discovered vulnerabilities on the acp module has been fixed by the strato dev/sec team.<br />
The bug was located on the dns-editor of the control panel for game servers & dedicated servers.<br />
<br />
2011-08-15:	             Vendor Notification<br />
2011-08-17:	             Vendor Response/Feedback<br />
2011-08-23:	             Vendor Fix/Patch<br />
2011-08-26:	             Public or Non-Public Disclosure<br />
             <br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=141]]></description>
			<pubDate><![CDATA[Thu, 25 Aug 2011 21:24:04 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[RTL closed multiple medium priority vulnerabilities [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=29</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=29</guid>
			<description><![CDATA[After anonymous annouced to attack the RTL Portal we decided to drop all our detected vulnerabilities on the RLT Webportal to secure <br />
the community. A vulnerability researcher (Alexander Fuchs) identified the persistent vulnerabilities and tried to notify the vendor <br />
multiple times. No repsonse has been arrived over weeks. The researcher decided to call RTL via phone and explained the bugs on the web portal.<br />
<br />
Some hours later, we saw that some people of anonymous tried to attack the webportal of RTL with a denial of service attack. <br />
This attack was not connected with the persistent script code inject of Alexander Fuchs. Alex is no member of the anonymous group <br />
and tried to protect the community against future attacks on a main module of the MyRTL Service.<br />
The persistent executed script code was non malicious to show what kind of power is behind this medium priority bug.<br />
<br />
BUGS FIXED: 2011-08-27<br />
<br />
Press Spreaker of RTL: 	„Wir wissen derzeit nicht, ob es ein Hack oder nur ein technischer Fehler war“<br />
V-Lab Administration: 	„We know that it is a persistent script code injection on the groups module of the RTL (MY) Website“<br />
Comment by Researcher: „An apology from RTL was definitely okey. The bad reporters around the portals should do the same.“<br />
<br />
Real News ...<br />
http://www.vulnerability-lab.com/news/get_news.php?id=29<br />
<br />
Advisory:<br />
http://www.vulnerability-lab.com/get_content.php?id=257<br />
<br />
Alexander Fuchs (Stellungnahme zu "GAMEZ". Der RTL Gamescom "Hack". ):<br />
http://www.youtube.com/watch?feature=player_embedded&v=1HwpPas3o6M<br />
<br />
<br />
Wrong News ...<br />
http://www.shortnews.de/id/913043/Hacker-legen-RTL-lahm-Website-gehackt<br />
http://de.ign.com/articles/news/9767/RTL-Website-gehackt-Update-Exploit-wurde-ausgenutzt-<br />
http://games-news.xchar.de/2011/08/round-5-gamescom-schaltet-sich-ein-hacker-attackieren-und-rtl-meldet-sich-zu-wort/<br />
http://www.satundkabel.de/index.php/nachrichtenueberblick/medien/83175-update-rtl-bericht-qgamescomq-medienhueter-schalten-sich-ein<br />
http://www.dwdl.de/nachrichten/32536/gamer_hacken_rtlde_nach_diffamierendem_bericht/<br />
http://www.gamers.de/news/14498/aktuell/die-rache-der-gamer-rtlde-wurde-gehackt.html<br />
http://meedia.de/internet/anonyme-hackten-rtlde/2011/08/25.html<br />
http://www.gamestar.de/specials/reports/2560501/explodiert_p2.html]]></description>
			<pubDate><![CDATA[Sat, 27 Aug 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Skype patched a new persistent high priority vulnerability]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=32</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=32</guid>
			<description><![CDATA[The Vulnerability Laboratory researcher Benjamin Kunz Mejri (Rem0ve) discovered last month (upcomings) a new high priority <br />
vulnerability on a main module of the skype software client. The last persistent skype vulnerability by noptrix was located on the bound preview <br />
module (active users) of the software. The new vulnerability of Benjamin K.M. is located in the status message bar of the software index <br />
listing when processing usernames.<br />
<br />
Ben will show a detailed description of the bug on the hack in the box malaysia conference 2011 (October 10th).<br />
URL: http://conference.hitb.org/hitbsecconf2011kul/?page_id=1757<br />
<br />
A technical description for press, cert and portals are public available. Pictures and proof of concept can be requested via research@vulnerability-lab.com<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=182<br />
]]></description>
			<pubDate><![CDATA[Tue, 06 Sep 2011 17:03:54 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[LaPoste (FR) - Multiple critical Vulnerabilities [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=33</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=33</guid>
			<description><![CDATA[Last days we have reported some critical vulnerabilities on the famous La Poste Website (FR). Chokri B.A. alias Me!ster <br />
and the analyst A-HEALL a.k.a F0x discovered the both issues. After vendor notification process all website vulnerabilities has <br />
been fixed (very fast) by official dev/sec team of laPoste.<br />
<br />
Title: La Poste FR Website - Multiple SQL Injection Vulnerabilities<br />
Advisory1:  http://www.vulnerability-lab.com/get_content.php?id=267<br />
<br />
Title: La Poste FR Website - Local File Include Vulnerability<br />
Advisory2:  http://www.vulnerability-lab.com/get_content.php?id=266]]></description>
			<pubDate><![CDATA[Mon, 12 Sep 2011 18:07:30 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[SQL Injection & persistent XSS on TvTotal Website [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=37</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=37</guid>
			<description><![CDATA[The vulnerability laboratory researcher alexander fuchs discovered 2 nice bugs for the tvtotal website. 1x Cross Site Scripting & <br />
1x SQL Injection vulnerability on the portal website. After the patch the bugs will be published on the portal index website <br />
of vulnerability-lab.com In the year 2010 we discovered another critical SQL Injection vulnerability which was disclosed by Rem0ve.<br />
<br />
Benefit: Thanks to TvTotal.de because of the 2 free tickets for the stefan raab show!<br />
<br />
Article(Alexander Fuchs)[DE]: http://www.1337core.de/2011/tv-total-zwei-freikarten-fur-hack/]]></description>
			<pubDate><![CDATA[Wed, 21 Sep 2011 03:21:26 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[USGS Gov - Fast patch of critical SQL Injection issue [FIXED]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=38</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=38</guid>
			<description><![CDATA[The vulnerability laboratory researcher Chokri B.A. (TN) discovered a critical sql injection vulnerability on the U.S. Geological Survey website.<br />
The USGS (U.S. Geological Survey) website team (*@alaska.gov) fixed the security issue within 12h.<br />
<br />
2011-09-20:	Vendor Notification<br />
2011-09-20:	Vendor Response/Feedback<br />
2011-09-21:	Vendor Fix/Patch<br />
2011-09-21:	Public or Non-Public Disclosure<br />
<br />
Advisory:  http://www.vulnerability-lab.com/get_content.php?id=278<br />
Author:  http://www.vulnerability-lab.com/show.php?user=Chokri%20-%20B.A]]></description>
			<pubDate><![CDATA[Wed, 21 Sep 2011 08:17:01 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[International Atomic Energy Agency fixed critical issue [FIXED]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=41</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=41</guid>
			<description><![CDATA[A critical remote blind sql injection vulnerability has been fixed by the International Atomic Energy Agency developer team.<br />
Successful exploitation of the blind injection may result in dbms compromise, defacement or manipulation of service/application content.<br />
<br />
2011-09-06:	Vendor Notification<br />
2011-09-23:	Vendor Response/Feedback<br />
2011-09-24:	Vendor Fix/Patch<br />
2011-09-26:	Public or Non-Public Disclosure<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=268]]></description>
			<pubDate><![CDATA[Mon, 26 Sep 2011 06:22:25 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[ServersCheck monitoring software v8.8.11 available [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=42</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=42</guid>
			<description><![CDATA[3 different serverscheck monitoring software [v8.8.10] bugs [VL-ID: 93] has been fixed/patched by the developer team in cooperation <br />
with Maarten Van Laere. A new version of the monitoring software is now available [v8.8.11] on the official vendor website [serverscheck.com].<br />
<br />
Download: http://www.serverscheck.com/monitoring_software/download.asp<br />
<br />
Report-Timeline:<br />
================<br />
2011-09-26:	Last Vendor Notification<br />
2011-09-27:	Public or Non-Public Disclosure<br />
2011-09-27:	Vendor Response/Feedback<br />
2011-09-27:	Vendor Fix/Patch<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=93]]></description>
			<pubDate><![CDATA[Tue, 27 Sep 2011 17:03:52 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[HotFix available for SonicWalls ViewPoint v6.0 SP2 [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=44</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=44</guid>
			<description><![CDATA[A high(+), multiple medium(+) &amp; low(+) priority vulnerabilities has been fixed/patched by the SonicWall Developer/Security Team. <br />
A new HotFix is now available (viewpoint v6.0 SP2) for download on the official SonicWall vendor website for customers (www.mysonicwall.com).<br />
<br />
VENDOR: http://www.sonicwall.com<br />
HOTFIX: 104767<br />
VERSION: 6.0 SP2<br />
<br />
ISSUE#1: http://www.vulnerability-lab.com/get_content.php?id=195<br />
ISSUE#2: http://www.vulnerability-lab.com/get_content.php?id=196<br />
]]></description>
			<pubDate><![CDATA[Sat, 01 Oct 2011 18:21:33 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Canadian ISP patched critical database injection bug [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=45</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=45</guid>
			<description><![CDATA[A SQL Injection vulnerability is detected on canadians isp website. After our secound response one of the canadian isp (ca) developers <br />
fixed the critical issue within 2 hours. The bug allows remote attackers to inject/execute own sql statements/commands over <br />
a vulnerable applicataion parameter on the main web service. Successful exploitation of the remote sql injection vulnerability can <br />
result in database management system compromise, dbms access and website manipulations.<br />
<br />
Report-Timeline:<br />
================<br />
2011-09-24:	Vendor Notification<br />
2011-10-03:	Vendor Response/Feedback<br />
2011-10-04:	Vendor Fix/Patch<br />
2011-10-04:	Public or Non-Public Disclosure<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=282]]></description>
			<pubDate><![CDATA[Tue, 04 Oct 2011 20:23:22 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[eFront Enterprise Edition fixed critical SQL Injection [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=47</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=47</guid>
			<description><![CDATA[eFront closed a critical SQL Injection vulnerability on the eLearning CMS v3.6.9 within 2 days.<br />
<br />
Update: http://www.efrontlearning.net/download<br />
<br />
Exploitable Version: eFront v3.6.9<br />
New secure Version: eFront v3.6.10<br />
<br />
eFront Log: Fixed SQL injection security vulnerability reported by Vulnerability Research Laboratory, vulnerability-lab.com (Mohammed A.A.)]]></description>
			<pubDate><![CDATA[Thu, 06 Oct 2011 22:54:01 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Apple fixed client-side XSS issue in http exception handling]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=48</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=48</guid>
			<description><![CDATA[The apple product security team patched a client-side cross site scripting issue on the discussions portal.<br />
The bug has been fixed within 12 hours after a request to the noc product security contact of apple.<br />
The vulnerability was located on the http exception-handling output of the we are sorry module context.<br />
<br />
<br />
Report-Timeline:<br />
================<br />
2011-10-05:	Vendor Notification<br />
2011-10-06:	Vendor Response/Feedback<br />
2011-10-07:	Vendor Fix/Patch<br />
2011-10-07:	Public or Non-Public Disclosure<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=289<br />
Credits: http://support.apple.com/kb/HT1318<br />
<br />
<br />
Press Article: http://news.softpedia.com/news/Apple-com-Suffering-from-a-Scripting-Vulnerability-Says-Advisory-226701.shtml]]></description>
			<pubDate><![CDATA[Thu, 06 Oct 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Softpedia Exclusive Interview: Benjamin Kunz Mejri, VL Founder]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=51</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=51</guid>
			<description><![CDATA[Title: Softpedia Exclusive Interview: Benjamin Kunz Mejri, VLab Founder<br />
The Hack in the Box conference in Malaysia is over, but our interviews continue with the last of the speakers who was willing to <br />
share his professional insight on some of the issues that currently affect the security industry.<br />
<br />
Benjamin Kunz Mejri, the founder of the Vulnerability Laboratory was kind enough to answer some questions about the flaws they <br />
found is Skype, his research team and some aspects of their important quest to make the internet a safer place.<br />
<br />
<br />
Softpedia: The Vulnerability Lab project is doing extremely well, constantly discovering potential weaknesses in websites, software <br />
and applications, at the same time providing help in the patching process. Can you tell us a bit about the latest, more interesting <br />
vulnerabilities you`ve discovered?<br />
<br />
Benjamin Kunz Mejri: We mostly discover vulnerabilities on security products like software, applications and websites. We are more <br />
interested in vendor product vulnerabilities then in protection for example a customer website but we also focus on specific strategic <br />
nodes like you can see on our website. We also produce videos and verified + free documents for prevention. The most famous publications <br />
of the last month were ...<br />
<br />
- Upek Protector Suite QL 2011 - Buffer Overflow Vulnerability<br />
- StarMoney Banking Software v8.0 - Multiple Vulnerabilities<br />
- Skype 5.3.x 2.2.x 5.2.x - Persistent Software Vulnerability<br />
- International Atomic Energy Agency Website Service - Blind SQL Injection Vulnerability<br />
- U.S. Geological Survey Center Website - SQL Injection Vulnerability<br />
- SonicWall Viewpoint v6.0 SP2 - SQL Injection Vulnerability<br />
- Facebook BugBounty #2 - Persistent Web Vulnerabilities<br />
- Sonicwall Viewpoint v6.0 SP2 - Multiple Web Vulnerabilities<br />
- Fortigates FortiAnalyzer Appliance - Multiple Web Vulnerabilities<br />
- Google SketchUp v8.x - Memory Corruption Vulnerability<br />
- Kaspersky ISandAV 2011/12 - Memory Corruption Vulnerability<br />
- Barracuda Spam and Virus Web Application Firewall 600 - Multiple Web Vulnerabilities<br />
<br />
To highlight 3 of them i picked out the persistent skype bug, the Upek protector suite buffer overflow vulnerability and another critical <br />
website vulnerability.<br />
<br />
Skype 5.3.x 2.2.x 5.2.x - Persistent Software Vulnerability (http://www.vulnerability-lab.com/get_content.php?id=182)<br />
The Bug is located in the status-bar module of the slide index. The vulnerability allows an local attacker to implement persistent malicious <br />
script codes on the skype software. The successfully exploitation can lead to redirects, client exploitation, session hijacking and request <br />
manipulation over the specific vulnerable software module.<br />
<br />
Upek Protector Suite QL 2011 - Buffer Overflow Vulnerability (http://www.vulnerability-lab.com/get_content.php?id=259)<br />
The vulnerability allows an local attacker to crash the EikonTouch USB peripheral device driver/software via local buffer overflow. The bug <br />
is located on the profile import module of the software when processing special crafted (manipulated) .vtp profile files.<br />
<br />
International Atomic Energy Agency Website Service - Blind SQL Injection Vulnerability (http://www.vulnerability-lab.com/get_content.php?id=268)<br />
An unsecure application parameter request allows remote attackers to implement/execute own sql commands via sql-injection.<br />
Successful exploitation of the blind injection may result in dbms compromise, defacement or manipulation of service/application content.<br />
<br />
<br />
Softpedia: How do the newly discovered Skype vulnerabilities affect the everyday user? What are the risks involved in using the application?<br />
<br />
Benjamin Kunz Mejri: The discovered local and remote vulnerabilities can result in the an account steal, session hijacking or for example <br />
execution of malicious content out of the software context. Skype exploitation on the black scene is very rarely because of the tricky art of <br />
exploitation inside of the software. On Skype there are not much techniques know which could lead to mass exploitation because skype security <br />
works in cooperation with hackers and researchers. Skype is for me actually one of the most secure messengers and voip software i have ever <br />
penetrated because of the fact that all other messengers fall down after some minutes/hours (Adium, ICQ, MSN and Co.) ... and skype exploitation <br />
needs mostly days/weeks of research. I do not say skype is the most secure client but i definitly know skype really cares about security and <br />
vulnerabilities inside of there products. After a vulnerability has been disclosed/published to skype security the bug is mostly patched/fixed <br />
after some days or weeks. I also need to say that real bugs are mostly very tricky to exploit. I also discovered also a denial of service <br />
vulnerability which is from local to remote exploitable and can crash the software of the end user via a persistent weakness. The security risk <br />
for end users depends from issue to issue. The most vulnerabilities i have discovered are with medium priority for end users.<br />
<br />
<br />
Softpedia: How do you approach a website owner to tell him that his domain can be compromised and how do they react to the news?<br />
<br />
Benjamin Kunz Mejri: There are 2 options for the product vendor ... he hates us because he can not see his own flaws/mistakes/fails ... or he <br />
loves us because he can now see his flaws/mistakes/fails. Nothing between. The most vendors reply very friendly and ask us for disclosure <br />
partnership (cooperation) for future bug publications. Very often they fix the issue(s) within some hours. Every vendor needs to be notified on a <br />
special way over the website forms, mail or by phone. Sometimes it`s very easy to contact the product vendor and sometimes the bureaucracy, spam <br />
filters or employees of a company are blocking the verification process. It depends from issue to issue and vendor to vendor but the most are <br />
really nice on cooperation with the vulnerability lab research team.<br />
<br />
<br />
Softpedia: In most cases, do you find the vulnerabilities on your own or do vendors seek your aid?<br />
<br />
Benjamin Kunz Mejri: Both! We have product vendors on the lab which forwards us as partner to discover bugs inside of the own software, application <br />
or service. Sometimes they provide us hardware, demos or information to identify zer0-day vulnerabilities. Sometimes the researchers interact on <br />
there own to identify zero-day vulnerabilities.<br />
Depends from case to case of the exploitation scenario.<br />
<br />
<br />
Softpedia: I know that the team you work with is a perfect example of cultural diversity as most of them come from different countries. Tell us a bit <br />
more about them.<br />
<br />
Benjamin Kunz Mejri: Thanks! We are a good team with a lot of different countries. The displayed website team is just a part of the public <br />
representatives of the team. A lot of them want to stay in background because of other reasons. In 1997, Benjamin K.M. founded a non-commercial <br />
and independent security research group called,  Global Evolution - Security Research Group  which is still active today. In 2010 Benjamin K.M. <br />
founded the company  Evolution Security . After the firm`s establishment arose the Vulnerability Lab as the legal european initiative for vulnerability <br />
researchers, analysts, penetration testers, and serious hacker groups. We have a lot of stable references as team by solved events or contests and <br />
exclusive zero-day exploitation sessions/releases.<br />
<br />
<br />
Softpedia: Do you have any advice for webmasters on what they should do to better protect their sites?<br />
<br />
Benjamin Kunz Mejri: Share knowledge and exchange information or data to protect yourself, vendors and other people. Bring the customers more <br />
transparence to prevent against attacks and data lost. Test your own products, functions, process or modules to identify and fix/patch vulnerabilities <br />
inside. Include for example bugbounty- or reward programs and implement security contacts to show stable presence.<br />
<br />
<br />
Softpedia: Cloud-based systems are covering ground fast, but there`s also a large number of risks involved. What`s your opinion on the matter?<br />
<br />
Benjamin Kunz Mejri: Cloud-based systems provides computation, softwares, data access, and storage services that do not require end-user knowledge <br />
of the physical location and configuration of the system that delivers the services. I think that the use of a remote system without knowing anything <br />
about it or what services are running into it represents a high risk if for example a cracker can hack into one of the remote computers.<br />
<br />
<br />
Softpedia: What should be the security industry`s greatest fear? What`s in store for the world at the way things are going right now?<br />
<br />
Benjamin Kunz Mejri: The greatest fear of the security industry is that the private industry (like us) jumps into the market to show what they missed <br />
or completly ignored over years. Sometimes the security industry needs to change the tactics of prevention to secure the most important infrastructures.<br />
<br />
Article: http://news.softpedia.com/news/Softpedia-Exclusive-Interview-Benjamin-Kunz-Mejri-Vulnerability-Laboratory-Founder-228545.shtml]]></description>
			<pubDate><![CDATA[Wed, 19 Oct 2011 22:02:43 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Prosieben Community - Persistent Script Code Injection [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=53</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=53</guid>
			<description><![CDATA[The vulnerability researcher alexander fuchs (21) discovered a high priority sript code injection vulnerability in <br />
the Prosieben Community Portal. The vulnerability allows an remote attacker with registered user account to <br />
inject/execute persistent malicious script codes on the profile section of the user listing. After our last submission<br />
we have now a stable contact to prosieben which allows to fix/patch issues within hours or a few days. The attacker <br />
vector has been removed by the developer within 12 hours but the complete issue has been fixed after 3/4 days.<br />
<br />
Report-Timeline:<br />
================<br />
2011-10-23:	Vendor Notification<br />
2011-10-24:	Vendor Response/Feedback<br />
2011-10-26:	Vendor Fix/Patch<br />
2011-11-01:	Public or Non-Public Disclosure<br />
<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=306]]></description>
			<pubDate><![CDATA[Mon, 31 Oct 2011 20:32:55 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[NATO Research and Technology Organisation fixed RFI [FIXED!]]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=55</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=55</guid>
			<description><![CDATA[A vulnerability researcher of the laboratory named Alexander Fuchs (f0x23) has discovered a critical vulnerability<br />
in the vendor website of the NATO Research and Technology Organisation. Successful exploitation of the detected <br />
file inclusion may result in dbms compromise, defacement, theft of webmail and login portal accounts or manipulation <br />
of service/application content.<br />
<br />
The vulnerability has been closed within 24 hours by the rto development team in cooperation with Benjamin Kunz Mejri.<br />
<br />
2011-11-01:	Vendor Notification<br />
2011-11-01:	Vendor Response/Feedback<br />
2011-11-02:	Vendor Fix/Patch<br />
2011-11-02:	Public or Non-Public Disclosure<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=307<br />
]]></description>
			<pubDate><![CDATA[Thu, 03 Nov 2011 23:25:13 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Researcher discovered high priority bug on WhiteHouse Service]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=56</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=56</guid>
			<description><![CDATA[A Laboratory Researcher (Alexander Fuchs) f0x23 discovered 2 persistent cross site scripting bugs on <br />
the official website of the whitehouse. Successful exploitation of the vulnerability allows an attacker <br />
to inject persistent script code on application side and can result in account steal or persistent manipulations. <br />
The malicious script code is getting executed on all petitions the attacker signs or create. The vulnerability was <br />
located on the online petition service of the official whitehouse website.<br />
<br />
Benjamin Kunz Mejri has formed and reported the issue to a Director of New Media Technologies (Executive Office of the President). <br />
The vulnerability will be fixed within 48h by a hotfix of the development/security team.<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=308<br />
<br />
<br />
<br />
<br />
<br />
]]></description>
			<pubDate><![CDATA[Mon, 07 Nov 2011 00:51:30 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Interview with Alexander Fuchs - NATO RTO/OTAN Vulnerability]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=61</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=61</guid>
			<description><![CDATA[Last week Alexander Fuchs alias f0x23 had a nice interview with HackInTheBox after his last penetrationtests and security audits.<br />
<br />
HITB Security News (HackInTheBox) published an exclusive interview with Alexander Fuchs (22) alias f0x23.  Alexander is a member <br />
of the Vulnerability-Lab research team and lives in germany near Düsseldorf (DUS). After his last publication and press articles we <br />
asked him some questions about the NATO – RTO OTAN (Research and Technologie Organisation) vulnerability he discovered some days ago.<br />
<br />
Reporter: Can you tell us something about your work in the vulnerability laboratory team?<br />
Alexander F.: I joined the vulnerability laboratory team 4 months ago. My first advisory was about a persistent XSS vulnerability <br />
(cross site scripting) on a big german television website. Last week i discovered a new vulnerability in the petition system of the <br />
whitehouse.gov. I also found some SQL Injections and local file include vulnerabilities in laposte.fr which is a french post service <br />
with 20 Billion € sales in 2007. Last month i detected a vulnerability in the exception-handling of the apple vendor website. I am <br />
glad to work with my team. We are a special constalation of real security researchers and exploiters.<br />
<br />
Lab Profile:  http://www.vulnerability-lab.com/show.php?user=f0x23<br />
<br />
Reporter:  How long did you need to identify the vulnerability on the nato webserver?<br />
Alexander F.: I first searched for subdomains on the NATO domain for a news article. As i found the Research and Technology site, it <br />
wasn’t hard to find the vulernability. In about 10 minutes, I found the issue and the vulnerability was identified, then I discussed <br />
it with Benjamin Kunz Mejri, the founder of the vulernability-lab team. He did the notification stuff between the vendor website <br />
(nato) and our laboratory.<br />
<br />
Reporter:  What security priority (low;medium;high;critical) has the discovered vulnerability?<br />
Alexander F.: The security risk of the file include vulnerabilities are estimated as critical, because it is possible to take over <br />
(control) the webserver. The NATO Research and Technology Organisation promotes and conducts co-operative scientific research and <br />
exchange of technical information amongst 26 NATO nations and 38 NATO partners. The largest such collaborative body in the world, <br />
the RTO encompasses over 3000 scientists and engineers addressing the complete scope of defence technologies and operational domains. <br />
On the vulnerable server runs also the webmail service of the Research and Technology Organisation.<br />
<br />
Reporter:  What does the successful exploitation of the vulnerability allows an attacker?<br />
Alexander F.: If an attacker successfully exploit this vulnerability, then he’ll get a full access to read all the files he wants to, <br />
and at this point there are a lot of possible attack scenarios. The most dangerous are infecting the server and clients with malwares, <br />
espionage the research and technology team or use the trusted communication for infiltration and manipulation.<br />
<br />
Reporter:  What type of vulnerabilities has been discovered on the advisory?<br />
Alexander F.: The local file include vulernability was discovered on the advisory. The bug allows an attacker to read/request internal <br />
system/webserver files (exp. the system config of the webserver). The vulnerability also allows an remote attacker to run commands on <br />
the affected webserver.<br />
<br />
Reporter:  How the manufacturer or development team responds to the security report?<br />
Alexander F.: First, the webmaster asked for more details about the security issue. Then he was grateful for the vulnerability-lab team <br />
for taking the time and effort to look at this vulnerability. The communication was very good and fast as it should be.<br />
<br />
Reporter:   How can the manufacturer fix the problem?<br />
Alexander F.: To fix the security issue the manufacturer have to restrict request to allowed files and parse the input. It’s always a <br />
good idea to check all inputs with a whitelist of expect inputs and take care about the major security issues in the webapplication by <br />
patching the systems and monitoring it. Thanks!<br />
<br />
Reporter:   The vulnerability has been fixed/patched by the development team?<br />
Alexander F.: Yes, 24 hours after the submission arrived on the vendors website postbox.<br />
<br />
<br />
Advisory: 		http://www.vulnerability-lab.com/get_content.php?id=307<br />
Video: 			http://www.vulnerability-lab.com/get_content.php?id=318<br />
<br />
Dev News:		http://www.vulnerability-lab.com/dev/?p=320<br />
Original Article:	http://news.hitb.org/content/critical-bug-nato-research-technologie-rtootan-0]]></description>
			<pubDate><![CDATA[Fri, 02 Dec 2011 16:34:01 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Critical Postgre SQL issue in chinese Academy of Governance NSA]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=62</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=62</guid>
			<description><![CDATA[A tunisian researcher of vulnerability-labs discovered a critical prostgre sql issue on the Chinese Academy of Governance NSA.<br />
Chokri B.A. alias &quot;Me!ster&quot; discovered this week a nice issue to the china national vulnerability database of information security. <br />
The vulnerability has been fixed/patched within 7 days after our security report arrived on the chinese postbox and the coordination <br />
process via CNNVD was perfect navigated. The bug was located in a wrong validated server request in the main website.<br />
<br />
The vulnerability allows an attacker (remote) to infiltrate the vulnerable application database management system of the affected <br />
vulnerable website (web-server). Remote Attackers and privileged user accounts can inject/execute (pre-auth) own sql statements to <br />
compromise the important and stable government web-server system. Successful exploitation results in dbms and server system compromise, <br />
account steal, server take-over and manipulation of webcontent.<br />
<br />
CNNVD ID: 	201111-474<br />
VL ID:		2011-311<br />
<br />
Advisory: 	http://www.vulnerability-lab.com/get_content.php?id=311<br />
Article:  	http://news.hitb.org/content/critical-postgre-sql-issue-chinese-academy-governance-nsa]]></description>
			<pubDate><![CDATA[Tue, 06 Dec 2011 00:20:01 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Memory Corruption in Kaspersky IS&AV 2011/2012 released]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=63</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=63</guid>
			<description><![CDATA[The vulnerability researcher Benjamin Kunz Mejri discovered yesterday a new zero-day memory corruption vulnerability in <br />
&amp;quot;Kaspersky Anti-Virus 2011/2012 &amp;amp; Internet Security 2011/2012&amp;quot;. The security vulnerability is local exploitable while <br />
loading a manipulated .CFG (Configuration/Setting) File. The vulnerability is caused by an invalid pointer corruption <br />
through the kaspersky exception/protection filters, which could be exploited by attackers to crash the complete software <br />
process on all instances (Browser+Addon, Sidebar &amp;amp; Software). Benjamin K.M. used a new concept to identify the  memory <br />
corruption issue and has bypassed the protection filter exception (import) of the software.<br />
<br />
<br />
Affected Version(s):<br />
Kaspersky Anti-Virus 2012 &amp;amp; Kaspersky Internet Security 2012<br />
- KIS 2012 v12.0.0.374<br />
- KAV 2012 v12.x<br />
<br />
Kaspersky Anti-Virus 2011 &amp;amp; Kaspersky Internet Security 2011<br />
- KIS 2011 v11.0.0.232 (a.b)<br />
- KAV 11.0.0.400<br />
- KIS 2011 v12.0.0.374<br />
<br />
Kaspersky Anti-Virus 2010 &amp;amp; Kaspersky Internet Security 2010<br />
<br />
<br />
Advisory:	http://www.vulnerability-lab.com/get_content.php?id=129<br />
PoC Video:	http://www.vulnerability-lab.com/get_content.php?id=19<br />
Article:          http://news.hitb.org/content/researcher-discovered-memory-corruption-vulnerability-kaspersky-20112012-products]]></description>
			<pubDate><![CDATA[Tue, 20 Dec 2011 15:47:47 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[FAQ Center Vulnerability - Fast Update by Strato Dev Team]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=68</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=68</guid>
			<description><![CDATA[After a short check this early morning, we can announce a nice and very fast patch/fix by the famous strato dev team. <br />
5 Days ago we discovered a client-side issue on the strato faq center which is integrated everywhere on the website.<br />
 <br />
The bug was located in a special listing (input/output) of the faq finder module. The vulnerability allows remote <br />
attacker to hijack customer sessions with required user inter action click. Successful exploitation can result in <br />
client-side content manipulation, client side cross site scripting, session hijacking and client side phishing attacks.<br />
<br />
The patch/fix has been released faster then the last one ... (http://www.vulnerability-lab.com/get_content.php?id=372)<br />
<br />
Title: 		Strato FAQ Center 2012 - Cross Site Scripting Vulnerability<br />
<br />
		2012-01-03:	Vendor Notification<br />
		2012-01-04:	Vendor Response/Feedback<br />
		2012-01-05:	Vendor Fix/Patch<br />
		2012-01-06:	Public or Non-Public Disclosure<br />
<br />
<br />
Review also the last strato time-line and issue ... (http://www.vulnerability-lab.com/get_content.php?id=141)<br />
<br />
Title: 		Strato Server ACP - Persistent DOM XSS Vulnerabilities<br />
<br />
		2011-08-14:	Vendor Notification<br />
		2011-08-17:	Vendor Response/Feedback<br />
		2011-08-19:	Vendor Fix/Patch<br />
		2011-08-26:	Public or Non-Public Disclosure<br />
<br />
At the end we can say our provider (strato) is fast(good+) in patching security vulnerabilities and cares about its customers.<br />
<br />
<br />
Advisory: 	http://www.vulnerability-lab.com/get_content.php?id=372]]></description>
			<pubDate><![CDATA[Fri, 06 Jan 2012 01:49:46 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Vulnerability in AirPort DuesselDorf closed by DUS INT Team]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=69</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=69</guid>
			<description><![CDATA[An anonymous vulnerability laboratory researcher discovered this week multiple critical sql injection vulnerabilities on the <br />
famous Duesseldorf Airport Server System and Web-Server.The remote vulnerability allows an remote attacker to execute <br />
own sql commands on the vulnerable value or module.<br />
Successful exploitation of the remote SQL Injection vulnerabilities can result in access to all db tables, read sensitive information <br />
like customer  passwords, usernames and Co. The vulnerabilities has been patched within 1 year and the issue was <br />
published yesterday [2012-01-13].<br />
<br />
<br />
Vulnerable Module(s): <br />
<br />
			[+] Fotoarchiv<br />
			[+] Shoplist<br />
			[+] Media info<br />
<br />
<br />
Advisory:		http://www.vulnerability-lab.com/get_content.php?id=173]]></description>
			<pubDate><![CDATA[Sat, 14 Jan 2012 23:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Lab discovered Bugs on Airport Duesseldorf Infrastructure]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=70</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=70</guid>
			<description><![CDATA[An anonymous Vulnerability Laboratory Researcher discovered this week a security advisory with multiple critical sql <br />
injection vulnerabilities on the web infrastructure of the famous german Duesseldorf Internalional Airport. The security <br />
issue has been submitted multiple times to the DUS-INT Airport Web Team. After no response arrived regarding the <br />
security issue the bug has been disclosed by Pim J.F.P. Campers and Benjamin Kunz Mejri.<br />
<br />
The Vulnerabilities are located on multiple web service modules of the airport application. Some vulnerable example <br />
modules were located on the Shoplist, Media Info and Photoarchiv. The remote vulnerability allows an remote attacker <br />
to execute own sql commands on the vulnerable value or module. Successful exploitation of the remote SQL Injection <br />
vulnerabilities can result in access to all db tables, read of sensitive information like customer  passwords, <br />
usernames, id, address and Co.<br />
<br />
After the report has been public confirmed by heise security news ticker  the DUS-INT Airport Team responded to vulnerability-labs.<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=173<br />
Article: http://www.heise.de/security/meldung/Bericht-Flughafen-Duesseldorf-schliesst-Sicherheitsluecken-1414554.html<br />
News: http://news.hitb.org/content/laboratory-discovered-critical-bugs-airport-duesseldorf-infrastructure]]></description>
			<pubDate><![CDATA[Sat, 21 Jan 2012 15:57:41 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Critical SQL Injection Vulnerabilities on Koeln/Bonn Airport]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=71</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=71</guid>
			<description><![CDATA[In the last days we discovered multiple vulnerabilities on the the duesseldorf international(dus-int) airport. <br />
2 days after the publication of the dus-int airport the same researcher published the next sql vulnerabilities on the <br />
famous koeln/bonn international(kb-int) airport.<br />
<br />
<br />
Article by Softpedia: http://news.softpedia.com/news/Koeln-Bonn-Airport-Fixes-SQLI-Vulnerabilities-247798.shtml<br />
<br />
After yesterday we’ve learned that the international airport in Dusseldorf patched up some serious vulnerabilities that <br />
could have allowed a remote attacker to execute arbitrary code, today researchers publicly disclose that another major <br />
German airport (kb-int) patched up the same types of flaws.<br />
<br />
Multiple blind SQL injection vulnerabilities were present on the official website of the Koeln Bonn Airport. The security <br />
weakness may have been exploited by a hacker to inject his own SQL commands in the affected application’s database <br />
management system (DBMS). If successfully exploited, the website, the DBMS and the application could have been compromised. <br />
<br />
The airport was notified on the existence of the flaws back in March 2011, but they only provided a fix in the first days of 2012. <br />
It’s a good thing that airport representatives dealt with the issue because it had been estimated as a critical weakness.<br />
<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=174]]></description>
			<pubDate><![CDATA[Mon, 23 Jan 2012 19:04:37 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Verkehrsbetriebe Berlin Brandenburg closed Bug via hotfix]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=72</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=72</guid>
			<description><![CDATA[Yesterday, three security researchers from vulnerability labs (Pim Campers, Bejamin Kunz Mejri and Marcel Bernhardt) discovered <br />
a critical security vulnerability in the transport operators service of Berlin Brandenburg (VBB). The vulnerability allows an <br />
attacker to execute sql commands on the affected dbms. The problem is located in the unescaped variable id_language. <br />
The vulnerabilty was fixed at the same response day but the response time took over 7 months.<br />
<br />
2011-02-09:	Vendor Notification 1<br />
2011-03-06:	Vendor Notification 2<br />
2011-04-13:	Vendor Notification 3<br />
2012-01-25:	Vendor Response/Feedback<br />
2012-01-25:	Vendor Fix/Patch<br />
2012-01-25:	Public or Non-Public Disclosure<br />
<br />
The security advisory is available on the laboratory index website ...<br />
<br />
Advisory: http://www.vulnerability-lab.com/get_content.php?id=138]]></description>
			<pubDate><![CDATA[Thu, 26 Jan 2012 23:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Softpedia Interview with Ucha Gobejishvili M. alias longrifle0x]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=75</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=75</guid>
			<description><![CDATA[This week Ucha an upcoming vulnerability researcher & whitehat had an interview with the softpedia security team …<br />
<br />
This week’s episode of Hackers around the world features the first white hat hacker to take part in our series. Up until <br />
now, we’ve only talked to black hats and gray hats, so we’ve decided to take a look at what a white hat has to say about <br />
vulnerabilities, hacktivist movements and life in general. Ucha Gobejishvili, also known as Longrifle0x, from Georgia, is <br />
a Vulnerability Lab researcher that recently uncovered some pretty impressive flaws in websites such as Apple, Oracle, Sun, <br />
NASA, ESA, Java.com, Nero.com, Google, Forbes, MySpace, MTV, Ferrari and even some US government sites.<br />
<br />
<br />
Softpedia:<br />
Thanks to your latest findings you have become a respected white hat, maybe even among the best. Have you ever considered <br />
yourself a grey hat or a black hat, or you knew right from the start that you want to be on the good side of computer security?<br />
<br />
Ucha Gobejishvili:<br />
Good question! I think I am a White/Grey Hat and I am personally not connected to the black hat scene. I have a lot of friends <br />
on this scene but I am working on the white part of it as you can see in the news. My decision to work on the white side of life <br />
is a perspective for the future, but sometimes I have a grey influence. I think I am a respected and maybe an advanced/good <br />
researcher, but I do not think I am one of the best. I will try to get more respect and assistance because I will publish other <br />
software or service product issues in the future.<br />
<br />
Softpedia:<br />
What is the significance of the name “longrifle0x”?<br />
<br />
Ucha Gobejishvili:<br />
The name is split into 3 words … long rifle -0x! I think I do not need to comment on this name. It is as it is.<br />
<br />
Softpedia:<br />
How old are you now and at what age did you start “playing” with computers? At what age did you start taking the security <br />
business more seriously?<br />
<br />
Ucha Gobejishvili:<br />
I started learning about computers and hardware at 12 and now I am 19 years old. I began working in the field of security about 4 <br />
years ago. Four years ago, my country had some problems because of a Russian web attacker; I’m referring to the 2008 August occupation. <br />
I wanted to protect my country’s web-servers after this incident so I started getting deeper into the security & exploitation scene.<br />
<br />
Softpedia:<br />
I know you are among the people that contribute with their findings to the Vulnerability Lab. How did you end up working there?<br />
<br />
Ucha Gobejishvili:<br />
I looked around at the content of the Vulnerability-Lab about 1 year ago. To me, it is the only program I want to join because I do <br />
not wish to sell my issues to the government for any bounty. The Laboratory is working on an independent level that grants the researcher <br />
a 100% payout of the vendor 0-day issues. All the material stored inside the Laboratory is exclusive and it’s not stuff you can find on <br />
the mirrors of 1337day, packetstorm, exp-hub or exploit-db. I like the team and I like the idea behind it. That’s maybe one of the reasons <br />
why people decided to let me join the internal research/lab team.<br />
<br />
Softpedia:<br />
Tell us more about your work prior to joining the Vulnerability Lab team.<br />
<br />
Ucha Gobejishvili:<br />
A year ago, I searched for a good and well-known group to sometimes discover an issue on public news sites like Forbes or MySpace. <br />
At first, my statistics were really bad on exploitation or publication, and I would release about one issue per month. After I joined <br />
the Lab with a new account in December 2011, I have discovered the following remote vulnerabilities: (some exclusded)<br />
<br />
2012-02-01 Sun Microsystems (Print) – Cross Site Scripting Vulnerability Remote<br />
2012-01-28 Oracle Solution Website – Cross Site Scripting Vulnerabilities Remote<br />
2012-01-26 Google BugBounty#9 – Cross Site Scripting Vulnerability Remote<br />
2012-01-24 Opera Website – Cross Site Scripting Vulnerability Remote<br />
2012-01-22 Parallels H Sphere v3.3 P1 – Multiple Persistent Vulnerabilities Remote<br />
2012-01-13 Tine v2.0 Maischa – Cross Site Scripting Vulnerability Remote<br />
2011-12-23 Facebook Global Football – SQL Injection Vulnerability Remote<br />
2011-12-22 Gwibber v2.29.1 & v3.x – Persistent Software Vulnerability Remote<br />
2011-12-22 Yahoo Babelfish Service – Cross Site Scripting Vulnerability Remote<br />
2011-12-21 Facebook JuniorsCheesecakeFoxwoods – SQL Vulnerability Remote<br />
2011-12-20 FBC Market v1.1 – Cross Site Scripting Vulnerability Remote<br />
2011-12-18 Facebook Fit-ify! – SQL Injection Vulnerability Remote<br />
2011-12-14 Facebook FitnessGrade – SQL Injection Vulnerability Remote<br />
2011-12-05 Facebook Chartity (TAG) – SQL Injection Vulnerability Remote<br />
<br />
….                      ….                         …..<br />
<br />
Now I am happy with my work and shared experience about it – security or vulnerability research. I hope I can top my statistics with <br />
better issues in the future. When I review the last publications, I consider them a good startup.<br />
<br />
Softpedia:<br />
You have found a lot of vulnerabilities in important websites. What was the vulnerability you found that you are most proud of? <br />
Is there one that stands out?<br />
<br />
Ucha Gobejishvili:<br />
One of the most interesting issues was the Apple shop vulnerability. It was reported to Apple and they fixed it by shutting <br />
the shop down for 1-2 hours. It has a great effect on customers and vendors if a shop needs to shut down its infrastructure for <br />
a medium (+) severity issue patch. I think I am a bit proud to have reported this issue because it protected the end-user and vendor.<br />
<br />
Softpedia:<br />
I saw you posted many XSS vulnerabilities on XSSed.com. What do you think about the fact that most websites still contain the flaws <br />
you pointed out? Do you think they’re irresponsible for leaving their visitors exposed?<br />
<br />
Ucha Gobejishvili:<br />
I think that the vendors mostly do not know how easily exploitable a cross-site scripting issue is. For example, Apple understands <br />
the problem and shuts down the shop for 1-2 hours to update the issue trying to prevent attacks against its customers. Most people <br />
do not understand the problem, which is a big mistake from my perspective. My main website is Vulnerability-Labs, but I sometimes <br />
drop issues to mirror websites after the publication is in progress. I think it’s OK that they know about the research I did and I <br />
hope they will soon recognize it directly.<br />
<br />
Softpedia:<br />
What is your opinion on the work of hacktivists like Anonymous and such?<br />
<br />
Ucha Gobejishvili:<br />
Do not work with or against Anonymous or other activist groups. I also do not define myself with H/Activist groups because for me <br />
it is just like all the other illegal working groups. They are not protecting the end user and not protecting the vendor, and this <br />
is something I can personally not accept as a researcher. They inform us as end users with compromised information, but I would not <br />
exchange private information for transparency against my right to not get my passwords listed in plain-text. It’s like an invasion <br />
of the real exploiter/hacker scene that people like them try to get our tricks to follow their criminal ideology. The same happened <br />
in 2003-2009 with the carder scene that tried to get more influence on the hacking/exploit market to obtain more information for themselves. <br />
I think a big problem in this case is also the press & daily news because they forward the information on specific groups to give <br />
them more influence. When the publication of news about this specific group is stopped, they will go down and get busted within the <br />
next half year, or become very insignificant. At the end, these people will bring us more private observation than censorship or <br />
transparency freedom.<br />
<br />
Softpedia:<br />
What do you do in your spare time, besides dealing with computer security related activities? What are your hobbies?<br />
<br />
Ucha Gobejishvili:<br />
Two of my favorite hobbies are Network/Server Administration with Linux and cooking food, like my Georgian special 1337 lasagna.<br />
Thanks for the interview ~longrifle0x<br />
<br />
<br />
Source: http://news.softpedia.com/news/Hackers-Around-the-World-No-Flaws-Escape-This-Georgian-s-Longrifle0x-252180.shtml<br />
<br />
Article Dev: http://www.vulnerability-lab.com/dev/?p=409]]></description>
			<pubDate><![CDATA[Mon, 13 Feb 2012 00:41:44 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Elitsoft patched critical bug in Central Console Appliance]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=78</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=78</guid>
			<description><![CDATA[ElitSoft has patched the discovered File Include Vulnerability on Cyberoams Central Console  Appliances v2.00.2. <br />
The new hotfix has been released 2012-02-29 in the morning and is now available for all appliance customers of the Central Console.<br />
<br />
The vulnerability allows an attacker to request local system or application files (example:telnet-service jsp). <br />
Successful exploitation can result in dbms or service/appliance compromise via file include vulnerability.<br />
The vulnerability was located on the vulnerable  WWWHELP service ?file value.<br />
<br />
UPGRADE CUSTOMERS:	CCC Firmware v02.00.4 Build 007<br />
UPGRADE TICKETS:	Cyberoam.com #323301<br />
<br />
ADVISORY:		http://www.vulnerability-lab.com/get_content.php?id=405<br />
VIDEO:			http://www.vulnerability-lab.com/get_content.php?id=411]]></description>
			<pubDate><![CDATA[Thu, 01 Mar 2012 14:48:14 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Skype Corruption & Peristent Weakness Vulnerability released]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=82</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=82</guid>
			<description><![CDATA[Today the vulnerability-lab team (Benjamin Kunz Mejri and Alexander Fuchs) and a external researcher (Ucha Gobejishvili) <br />
discovered a new skype remote vulnerability. The bug is located when processing special crafted symbole strings on <br />
conversations and input masks of the skype software context. The bug is located in the software when processing <br />
special crafted symbole messages via communication box. The vulnerability allows an attacker to freeze, block, crash <br />
or destroy the communication messagebox of the connected conference persons/teams. The bug also has an persistent <br />
weakness vector which allows an remote attacker to implement the symbole string to the contact user requests messagebox.<br />
<br />
The result is also a stable persistent error message and a client denial of service. Attackers can also implement the <br />
test poc to the group labelname which results in a stable group error with different exceptions. The facebook integration <br />
allows to sync the account with skype and can also redisplay the issue with the error via facebook module and wall-<br />
posting. The callto function allows an attacker to implement the issue persistent on a victim user profile by using <br />
the symbole string as nickname.<br />
<br />
Vulnerable Module(s):<br />
                               [+] MessageBox and Request Contact<br />
                               [+] Contact Request Messagebox - Add Skype User<br />
                               [+] Group Topic and Group Information Name<br />
                               [+] Facebook integration - Connect Account Wall Postings<br />
<br />
Affected Version(s):<br />
                               > Windows v5.8.0.156, MacOS 5.5.0.2340 and Linux 2.2 Beta<br />
<br />
The disclosure process has been coordinated by Micorsoft Security Center (MSRC) to Skype Security. The attack vector has <br />
been removed in the old version (5.8.0.156) via hotfix and the issue is addressed by skype.(exp. v5.8.0.158).<br />
<br />
URL: http://news.hitb.org/content/skype-corruption-peristent-weakness-vulnerability-released]]></description>
			<pubDate><![CDATA[Thu, 29 Mar 2012 05:08:04 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Researchers @ Hall of Fame - Microsoft, Apple and Google]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=83</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=83</guid>
			<description><![CDATA[This month we got multiple times listed with several group members on different vendor hall of fame <br />
or credit sites. To get listed it is required to submit a 0day issue and you need to accept the <br />
different company security/disclosure policy (MSRC, Apple, Google Security and Co.). Last month we submitted <br />
multiple issues to google, apple and microsoft. Alexander Fuchs, Subho Halder, Dev Kar and Aditya Gupta <br />
got listed for excellent research activity in march 2012.<br />
<br />
Released Vulnerabilities:<br />
<br />
Title:	Microsoft Bing - Persistent Editor Flash Component Vulnerability (MSRC ID: 12227)<br />
URL:	http://www.vulnerability-lab.com/get_content.php?id=449<br />
Author:	Aditya Gupta, Dev Kar  &amp; Subho Halder<br />
<br />
<br />
Title:	Microsoft MSDN - Persistent Web Service Vulnerability (MSRC ID #1: 12152 and MSRC ID #2: 12228)<br />
URL:	http://www.vulnerability-lab.com/get_content.php?id=450<br />
Author:	Subho Halder, Dev Kar &amp; Aditya Gupta<br />
<br />
<br />
Title:	Apple Website Service - SQL Injection Vulnerabilities (APPLE ID: 196579501)<br />
URL:	http://www.vulnerability-lab.com/get_content.php?id=476<br />
Author:	Alexander Fuchs (f0x23)<br />
<br />
<br />
DEV ARTICLE:  http://www.vulnerability-lab.com/dev/?p=428]]></description>
			<pubDate><![CDATA[Sat, 07 Apr 2012 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Critical blind SQL Injection Vulnerbailities on Oracle Corp fixed]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=85</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=85</guid>
			<description><![CDATA[The well known Vulnerability Laboratory Researcher Shadab Siddiqui (23) from Indian has discovered this week <br />
a remote vulnerability with critical severity to oracle. Oracle Corporation (NASDAQ: ORCL) is an american <br />
multi-national computer technology corporation that specializes in developing and marketing computer hardware <br />
systems and enterprise software products – particularly database management systems. <br />
<br />
Shadab Siddiqui disovered multiple remote blind SQL Injection vulnerabilities on different parts of the Oracle <br />
web infrastructure. The vulnerability allows an attacker (remote) to inject/execute own sql commands on the <br />
affected application dbms. Successful exploitation of the vulnerability results in dbms, service and application <br />
compromise. The vulnerabilities are located on the shop, campus, education and academy service of oracle.<br />
<br />
Affected Service(s):<br />
                             [+] https://shop.oracle.com<br />
                             [+] https://campus.oracle.com<br />
                             [+] https://education.oracle.com<br />
                             [+] https://academy.oracle.com<br />
<br />
With coordination of the oracle security team (Steve Meert) the issue has been fixed quickly on all instances <br />
of the different web service. The hotfix on the web-servers has been released within 12 days after the issue has <br />
been analysed by oracle security team.<br />
<br />
                             [+] 2012-03-28:	Vendor Notification<br />
                             [+] 2012-03-29:	Vendor Response/Feedback<br />
                             [+] 2012-04-11:	Vendor Fix/Patch <br />
                             [+] 2012-04-12:	Public or Non-Public Disclosure<br />
<br />
<br />
Advisory:			<br />
                             [+] http://www.vulnerability-lab.com/get_content.php?id=478<br />
<br />
Press/News:<br />
http://news.softpedia.com/news/Oracle-Fixes-SQL-Injection-Flaws-on-its-Public-Sites-264140.shtml<br />
http://www.online.com.es/17213/actualidad/oracle-corrige-problemas-sql-inyection-en-sus-sitios-publicos/<br />
http://news.hitb.org/content/oracle-patched-blind-sql-injection-flaws-public-websites]]></description>
			<pubDate><![CDATA[Fri, 13 Apr 2012 20:26:22 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Researcher disclosed Vulnerability in IPhone SMS WebServer]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=87</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=87</guid>
			<description><![CDATA[Researchers from the Vulnerability Lab have found high severity HTML Inject and File Include security holes <br />
in TreasonSMS, an iPhone application that allows users to send text messages from their desktop computers by <br />
turning the phone into a SMS webserver.According to the experts, the vulnerabilities can be exploited remotely, <br />
allowing an attacker to “include malicious persistent script codes on the application-side of the iPhone.”<br />
<br />
The security hole can also be leveraged to inject webshell scripts that would give cybercriminals complete control <br />
of the affected application directory. If the device is jailbroken, things become even more complicated. On <br />
tampered iPhones an attacker could take control not only of the application folder, but also of the entire phone. <br />
“The Bug is located in the input fields of the Message Sending and Message Output. An attacker can scan the victim <br />
on walkthrough because the IP of the webserver makes the TreasonSMS available to anybody without password,” <br />
Benjamin Kunz Mejri, the founder and CEO of Vulnerability Lab, explained. “To exploit somebody on a walkthrough it’s <br />
only required to scan for the stable IP via WLAN and access the panel for exploitation.”<br />
<br />
It’s uncertain at this time if the vendor has responded to the notification sent by the experts, but hopefully the <br />
company that develops the app will rush to address the security holes.<br />
<br />
Security researchers from the Vulnerability Lab have done a great job this month helping organizations protect their <br />
assets, especially their public facing website. Companies such as Apple, Microsoft and Oracle have been aided by <br />
them in fixing SQL Injection vulnerabilities, persistent script code inject flaws and other serious weaknesses that <br />
could have been leveraged by cybercriminals to launch malicious operations. Eduard Andrei - Softpedia<br />
<br />
[SOFTPEDIA - PARTNERS] <br />
ARTICLE: http://news.softpedia.com/news/TreasonSMS-Bug-Allows-Hackers-to-Execute-Malicious-Code-on-iPhones-266214.shtml<br />
<br />
<br />
Press/News:<br />
http://news.hitb.org/content/treasonsms-bug-allows-hackers-execute-malicious-code-iphones<br />
http://threatpost.com/en_us/blogs/researchers-find-bug-sms-app-can-lead-iphone-exploits-042312<br />
http://www.ehackingnews.com/2012/04/vulnerability-in-treasonsms-allows.html<br />
http://cyberseecure.com/2012/04/researchers-find-bug-in-sms-app-that-can-lead-to-iphone-exploits-threatpost/<br />
<br />
<br />
Advisory Original:	http://www.vulnerability-lab.com/get_content.php?id=154<br />
Advisory Public:	http://seclists.org/fulldisclosure/2012/Apr/257]]></description>
			<pubDate><![CDATA[Tue, 24 Apr 2012 23:26:23 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Mobile Spy App Vulnerabilities discovered by lab member]]></title>
			<category><![CDATA[Press]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=89</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=89</guid>
			<description><![CDATA[Researchers from the Vulnerability Lab have identified a number of web flaws in the popular spy app <br />
called MobileSpy. Since the vendor has failed to reply to their inquiries, they have decided to make <br />
their findings public to raise awareness among users. Before moving on to the actual security holes, <br />
let’s take a look at the app itself. MobileSpy is an application that allows smartphone owners to log <br />
the activities of the devices on which the program is installed. This includes call information, <br />
SMS data, GPS location and much more.<br />
<br />
The surveillance app is designed to work on most platforms, including Symbian, iOS, Android, BlackBerry <br />
and Windows Phone. The fact that it’s compatible with a large number of devices makes this piece of <br />
software a tempting target for cybercriminals, which is why it’s recommended that customers act with <br />
caution until the vendor manages to address these weaknesses.<br />
<br />
The first security hole found by experts from Vulnerability Lab refers to a number of persistent server-side <br />
input validation issues, which can allow a remote attacker to manipulate application requests and hijack sessions.<br />
<br />
The founder and CEO of the company, Benjamin Kunz Mejri, provides a great example on how this flaw could be <br />
leveraged. ``If you know for example your mobile is observed you can inject script code to your SMS and send it <br />
via service. The SMS spy service is logging the issue and the script code is getting executed on the display <br />
website of the observer,`` he explains. Basically, this bug can turn the spy into the one who’s spied on. <br />
The same type of vulnerability can be found in a non-persistent form in MobileSpy.<br />
<br />
These weaknesses are considered to be of medium severity because they require low user inter action in <br />
order to be exploited, unlike the persistent ones that can be leveraged without the need of social engineering. <br />
The last flaw is a dangerous SQL Injection that can be utilized to compromise the application’s database <br />
management system.<br />
<br />
URL: http://news.softpedia.com/news/Multiple-Web-Vulnerabilities-Expose-MobileSpy-App-to-Attacks-Experts-Say-269892.shtml<br />
<br />
<br />
[PRESS/NEWS]:<br />
http://www.msnbc.msn.com/id/47451130/ns/technology_and_science-security/<br />
http://news.hitb.org/content/multiple-web-vulnerabilities-expose-mobilespy-app-attacks-experts-say]]></description>
			<pubDate><![CDATA[Wed, 16 May 2012 22:26:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[[Customer] First 7 Skype Exploitation Maps Released]]></title>
			<category><![CDATA[Research]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=18</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=18</guid>
			<description><![CDATA[Benjamin K.M. discovered as first person 7 fresh attacker maps for skype after his out of the box exploitation sessions.<br />
<br />
1. Client Side Skype Exploitation<br />
2. Server Side Skype Exploitation 1<br />
3. Server Side Skype Exploitation 2<br />
4. Denial of Service Skype Exploitation<br />
5. Exchange Buffer Overflow Exploitation<br />
6. HIPS Hooking User-Mode Buffer Overflow Exploitation<br />
7. Pointer Skype Exploitation]]></description>
			<pubDate><![CDATA[Sat, 30 Jul 2011 17:07:01 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Quick Laboratory Updates, more Information & new Features]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=7</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=7</guid>
			<description><![CDATA[Startup:  Sunday  2011-06-26 <br />
Ending:    Monday 2011-06-27<br />
<br />
Update List:<br />
                                 [+] Login<br />
                                 [+] Customer Area<br />
                                 [+] News, Documents &amp; Video Categories<br />
                                 [+] Upcoming Feed<br />
                                 [+] Benefit<br />
                                 [+] FAQ (Role Description; Customer Feed<br />
                                 [+] Sidebar<br />
                                 [+] 2 x Bugs<br />
                                 [+] Customer Subscribe<br />
                                 [+] Youtube Video Channel<br />
                                 [+] Twitter Feed<br />
                                 [+] Dev Blog<br />
<br />
... thanks.]]></description>
			<pubDate><![CDATA[Mon, 27 Jun 2011 13:02:47 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Customer Section, Listing and Infrastructure Upgrade]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=10</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=10</guid>
			<description><![CDATA[Startup:  Sunday  2011-07-06<br />
Ending:    Monday 2011-07-08<br />
<br />
Update List:<br />
                                 [+] Customer Subscribe<br />
                                 [+] Include new Website Vendor Vulnerability Section<br />
                                 [+] Customer Section - Listings and Status<br />
                                 [+] News - Listing and Style<br />
                                 [+] Navigation<br />
                                 [+] FAQ<br />
                                 [+] 1 x Bug<br />
<br />
Notice: <br />
The Advisory listing is not up-to-date 1 day because we working on specific section till 2011-07-08 (19:00|EU-TZ). <br />
The customer &amp;amp;amp; main sections will be available all the time. Be a patient, please ... we will score back with new zero-day issues &amp;amp;amp; new laboratory features.<br />
<br />
... thanks.]]></description>
			<pubDate><![CDATA[Fri, 08 Jul 2011 08:10:34 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[New Laboratory Updates - Information, Details and Upcomings]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=15</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=15</guid>
			<description><![CDATA[Ending:    Monday 2011-07-22 (TZ DE|EU - 00:00)<br />
<br />
Update List:<br />
                                 [+] Customer Subscribe (http://www.vulnerability-lab.com/subscribe.php)<br />
                                 [+] Upcoming Listing Update 250+<br />
                                 [+] 260+ new zero-day issues verification<br />
                                 [+] Navigation - Mobile Feed &amp; Quick Links<br />
                                 [+] FAQ (http://www.vulnerability-lab.com/help.php)<br />
                                 [+] 1 x Bug - ACP<br />
                                 [+] 1 x Error Listing<br />
                                 [+] Search - Output<br />
                                 [+] Exception-Handling Lab &amp; Customer Section<br />
                                 [+] Brute Force Account Protection<br />
                                 [+] Countermeasures Exploits<br />
                                 [+] Manager Account Implementation<br />
                                 [+] Anonymous User Role - Can access Videos 6 Documents on Index<br />
                                 [+] Partnership Program on Help &amp; Partners<br />
<br />
Lab Stats:              +14 Researcher<br />
Lab Stats:              +260 z0d Produkt Advisories<br />
<br />
<br />
In the next few hours we will publish some major vulnerabilities product. <br />
There should be no problems during the update with the Customer Login or vulnerability listing.<br />
The Time-Line on the Index will be updated soon because we want to verify as much as possible to publish daily.]]></description>
			<pubDate><![CDATA[Fri, 22 Jul 2011 17:02:54 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Upgrade, more details & information available on laboratory!]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=21</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=21</guid>
			<description><![CDATA[After we got a lot of mail/phone response by different teams, offices, vendors, companies, press & co. <br />
We will make the following laboratory listing restriction available for all users. enjoy ;)<br />
<br />
<br />
Available: [INDEX]<br />
                                                                       [+] Title<br />
                                                                       [+] Date<br />
                                                                       [+] VL-ID<br />
                                                                       [+] Introduction<br />
                                                                       [+] Abstract<br />
                                                                       [+] Report-Timeline<br />
                                                                       [+] Status<br />
                                                                       [+] Affected Products<br />
                                                                       [+] Exploitation-Technique<br />
                                                                       [+] Severity<br />
                                                                       [+] Technical Details<br />
                                                                       [+] Risk<br />
                                                                       [+] Credits<br />
                                                                       [+] Discalimer<br />
<br />
Restricted: [INDEX]<br />
                                                                       [+] PoC & Resources   - Role: [Anonymous]]]></description>
			<pubDate><![CDATA[Wed, 03 Aug 2011 22:15:17 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Vulnerability Lab - Disclosure Partnership Program]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=25</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=25</guid>
			<description><![CDATA[Vulnerability Lab - Disclosure Partnership Program<br />
<br />
Step 1: Allowing inclusion<br />
Consent for inclusion in the Security Vulnerability Lab Products List and delivery of specific <br />
product names. support[at]vulnerability-lab.com<br />
<br />
Step 2: Admission to product testing list<br />
The appropriate application or software can be included in a special private list for product safety testing.<br />
<br />
Step 3: Penetration tests, List and Publication<br />
The list is only provided for approved/qualifier lab users and penetration testers. Our certified testers can <br />
search for vulnerabilities in its products. You can decide whether they require additional demo systems available <br />
to increase the hit rate. Our goal is the publication of (minimum) 1 product vulnerability per month.<br />
<br />
Step 4: Disclosure Process for Partners<br />
After the submission of a vulnerability, the advisory will be verified in the laboratory and moved through the <br />
processes [Pending on Laboratory] over [Verified by Laboratory] to [Accepted by Vendor]. The partnership ensures <br />
that the forwarding of security holes are only the product vendor/manufacturer. [View: Upcoming]<br />
<br />
Step 5: Public disclosure?<br />
The vendor has the choice if the vulnerability is made publicly after fixing. Normal procedure is that after a bug <br />
is fixed its made public. If for a reason a vender doesnt want the bug to be public the vendor has to give prior <br />
notice to the Vulnerability-Lab team. (Before the fix has been released) If a vendor chooses to not wanting the <br />
bug to be publicly made available the bug will only stay in the private area of the Vulnerability-Lab.<br />
<br />
Step 6: Banner<br />
A banner will be placed on our partner site in the laboratory. On our partner site are all the trusted partners <br />
or sponsors that the Vulnerability-Lab has. vulnerability-lab.com/partners Its also possible to exchange banners.<br />
<br />
Step 7: Now wait ...<br />
At this point the Vulnerability-Lab team and its researchers will try and find bugs in your programs/appliances/etc.<br />
<br />
<br />
URL:  http://www.vulnerability-lab.com/partner.php]]></description>
			<pubDate><![CDATA[Sun, 21 Aug 2011 18:52:55 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Vulnerability Laboratory User registration - Startup 12h+]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=34</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=34</guid>
			<description><![CDATA[We will open the laboratory user registration in about 12 hours. Registered Vulnerability Laboratory users (Role) can review <br />
the full details of the 0day advisories(Index) with poc & resources.<br />
<br />
Available: 12h+<br />
                                                                       [+] Laboratory User registration Form (INDEX)<br />
<br />
URL: <br />
                                                                       http://www.vulnerability-lab.com/register.php]]></description>
			<pubDate><![CDATA[Tue, 13 Sep 2011 01:08:13 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Registration for V-Laboratory researchers available!]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=35</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=35</guid>
			<description><![CDATA[Register on the vulnerability laboratory to view all details on the index. The &quot;Lab User&quot; role accounts are limited to active researchers, <br />
analysts, exploiters, penetration testers &amp; security hackers. This means that not everybody that signs up with this form will receive an account. <br />
The selection will be done manually. Any misbehavior will not be tolerated!<br />
<br />
Role &gt; Laboratory User or Lab User<br />
A lab user is a registered user (stable) in the laboratory and can view all advisory details on the index. (+poc)<br />
<br />
<br />
URL: http://www.vulnerability-lab.com/register/<br />
<br />
Note: The reference(s), comments, experience and website detail(s) will not be stored on our dbms! (Daily cleanup via delete)]]></description>
			<pubDate><![CDATA[Sat, 17 Sep 2011 22:29:56 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[V-Laboratory RSS Feeds available on Index and Upcomings]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=40</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=40</guid>
			<description><![CDATA[In the last hours we integrated 2 new rss feeds. One for upcoming advisories/vulnerabilities and one for the discovered <br />
vulnerabilities by the vulnerability-labs index website. I hope you like our new rss feeds to stay up to date with vulnerability-lab. Enjoy ...<br />
<br />
Available: [Release]<br />
                                         [+] RSS Feed Index (Orange) ( http://www.vulnerability-lab.com/rss/rss.php )<br />
<br />
Available: [Upcoming]<br />
                                         [+] RSS Feed Upcomings (Grey) (http://www.vulnerability-lab.com/rss/rss_upcoming.php )]]></description>
			<pubDate><![CDATA[Sat, 24 Sep 2011 02:52:54 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Multiple little features and updates successful implemented]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=46</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=46</guid>
			<description><![CDATA[In the last hours we activated some new cool features on the index website. Enjoy ...<br />
<br />
Available: [Release]<br />
                                         [+] Index RSS, Upcoming RSS, Multi RSS Feed and YouTube Security Channel Icons<br />
                                         [+] Global-Evolution Contest and Reference Site + Index  Update<br />
                                         [+] VL Dev Blog, Navigation and Category  Update<br />
                                         [+] VL Team Site  Update<br />
                                         [+] Partners  Update<br />
                                         [+] VL News Category Update]]></description>
			<pubDate><![CDATA[Mon, 03 Oct 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Service and infrastructure updates of today]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=54</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=54</guid>
			<description><![CDATA[In the last hours we updated some newsections of the website. Enjoy ...<br />
<br />
Available: [Release]<br />
                                         [+] Index gallery link static (top)<br />
                                         [+] Login & Website text updates<br />
                                         [+] Registration is now available for everybody - 100%<br />
                                         [+] VL Team site  update references<br />
                                         [+] Dev Blog attack schemes update<br />
                                         [+] CNNVD ID References now available on advisories<br />
                                         [+] Partner website now with different categories available<br />
]]></description>
			<pubDate><![CDATA[Wed, 02 Nov 2011 16:39:03 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[3 new Modules & different Laboratory Section Upgrades]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=58</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=58</guid>
			<description><![CDATA[The following vulnerability-lab.com sections has been integrated or updated ...<br />
<br />
Available: [Release]<br />
                                         [+] Confirm Users Registration<br />
                                         [+] Vendor or Owner Email Notification<br />
                                         [+] Gallery Pictures Updates<br />
                                         [+] Dev/news Blog Updates<br />
                                         [+] DownTime Monitoring Service<br />
<br />
Note: We provide now 17 different service modules for information security & vulnerability management<br />
<br />
<br />
<br />
The following global-evolution.info sections has been integrated or updated ...<br />
<br />
Available: [Release]<br />
                                         [+] Dev Blog - Mobile & RSS Feed<br />
                                         [+] Dev Blog - Partner Program Update<br />
                                         [+] Design Mistake Navibar]]></description>
			<pubDate><![CDATA[Sat, 19 Nov 2011 01:56:46 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Forum available within 1 week for researchers & customers]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=59</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=59</guid>
			<description><![CDATA[The Forum will be activated for lab researchers, the team and customers within 1 week. Enjoy!<br />
<br />
Available: [Release]<br />
                                         [+] Forum (Customers/Researchers)]]></description>
			<pubDate><![CDATA[Tue, 29 Nov 2011 01:20:40 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[New features - Upcomings, Index and Customer Section]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=60</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=60</guid>
			<description><![CDATA[This night we have done some nice updates for vulnerability-labs. The main index and upcoming section allows to download <br />
the advisories as plain file from the server with the specific declared user privileges of the lab user account. A secound <br />
function will be implemented  within  1/2 days. The secound new module allows to see the product vendor site or download <br />
the specific application/service.<br />
<br />
<br />
Available: [Release]<br />
                                                      [+] Advisories download link as plain file (INDEX)<br />
<br />
Available: [1/2 Day(s)]<br />
                                                      [+] Advisories - Vendor and Software links (INDEX)]]></description>
			<pubDate><![CDATA[Fri, 02 Dec 2011 16:12:10 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Benefit, Rewards, Partners & Intro Website Updates]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=73</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=73</guid>
			<description><![CDATA[The following vulnerability-lab.com areas has been integrated or updated ...<br />
<br />
Available: [Release]<br />
                                         [+] Benefit Section to Reward Section (Text, Picture + Policy)<br />
                                         [+] Team Website - Member Reference Updates<br />
                                         [+] Partner Section (Text, Sections, Companies & Sponsors)<br />
                                         [+] Intro Page (www.vulnerability-lab.com/vulnerabilitylab.php)<br />
                                         [+] Youtube Channel (http://www.youtube.com/user/vulnerability0lab)]]></description>
			<pubDate><![CDATA[Wed, 01 Feb 2012 12:41:31 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Little website service updates by Chokri B.A.]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=74</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=74</guid>
			<description><![CDATA[The following vulnerability-lab.com areas has been integrated or updated ...<br />
<br />
Available: [Release]<br />
                                         [+] Team, Intro & Partners Website<br />
                                         [+] Impressum<br />
                                         [+] FAQ & Rewards<br />
                                         [+] Browser Agent Input/Output (Client-Side)<br />
<br />
Note:<br />
We know about the client side agent validation problem on the user agent section.<br />
The issue with low priority has been reported by me!ster  (2012-01-26) & fixed by x4lt (2012-02-06) ... who implemented the script 2011-12-01. <br />
The issue has been reported a third time by a person we do not want to know or respect ;)<br />
<br />
Article:<br />
                                         [+] http://www.vulnerability-lab.com/news/get_news.php?id=74]]></description>
			<pubDate><![CDATA[Mon, 06 Feb 2012 15:16:35 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Gallery, Rewards, Text & Videos - New Updates available]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=76</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=76</guid>
			<description><![CDATA[The following vulnerability-lab.com sections has been integrated or updated ...<br />
<br />
Available: [Release]<br />
				[+] Converted all Videos to 3D (Youtube Channel)<br />
				[+] Partners Documents (COMMERCIAL PARTNERSHIP POLICY | UNCOMMERCIAL PARTNERSHIP POLICY)<br />
				[+] FAQ - Pictures and Text + Policy<br />
				[+] Benefit => Reward Section<br />
				[+] Buttons and Listing on Index<br />
				[+] Gallery 2 & 3 on Index<br />
<br />
<br />
Available: [2012-03-01]<br />
				[+] Vulnerability Scoring System implementation (Standard)]]></description>
			<pubDate><![CDATA[Sun, 19 Feb 2012 20:32:11 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Multiple Laboratory upgrades on main- and panel infrastructure]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=86</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=86</guid>
			<description><![CDATA[The following vulnerability-lab.com areas has been implemented/integrated or updated ...<br />
<br />
Available: [Infrastructure]<br />
                                         [+] Team (Texts and Links)<br />
                                         [+] Submit (Text and Links)<br />
                                         [+] Bottom and Top Bar - Menu<br />
                                         [+] Mobile Vulnerability Feed<br />
                                         [+] Scoring System Administration (CVS)<br />
<br />
Available: [Community]<br />
                                         [+] Vlab Sync - Facebook, Twitter and Youtube<br />
                                         [+] Facebook Page integration on Index<br />
                                         [+] Dev Blog - Text and Links<br />
<br />
Available: [Security]<br />
                                         [+] Protection: Bruteforce Blocker<br />
                                         [+] Protection: Application Firewall Filter<br />
                                         [+] Wall of Sheep for Attacker<br />
                                         [+] Honeypot - Error Fake C&amp;amp;D File System + Catcher<br />
                                         [+] Unauthorized Access Requests (Password/Strings) - Prevent via BoF<br />
<br />
Available: [Coming Soon!]<br />
                                         [+] CVS (Scoring System) Index implementation on |R|<br />
                                         [+] Video and Security TV website - Internal Host<br />
                                         [+] Forum - External Host back Public]]></description>
			<pubDate><![CDATA[Sat, 14 Apr 2012 04:58:28 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[New Domains, CVSS, Members and Mobile Section]]></title>
			<category><![CDATA[Updates]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=88</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=88</guid>
			<description><![CDATA[In the last 2 weeks we updated several sections of the vulnerability-lab.com infrastructure ...<br />
<br />
<br />
Available: [Infrastructure]<br />
                                         [+] Mobile Section (Customer &amp;amp;amp; Index)<br />
                                         [+] Common Vulnerability Scoring System (Customer &amp;amp;amp; Index)<br />
                                         [+] Public Representative of the Team (+2)<br />
                                         [+] Website Intro - All Categories of Community Listing<br />
<br />
Note: The CVSS Scoring Display will also be used to rate videos & documents 1.0 (lame) -10 (epic).<br />
<br />
<br />
Available: [Community]<br />
                                         [+] forum.vulnerability-lab.com<br />
                                         [+] video.vulnerability-lab.com<br />
                                         [+] news.vulnerability-lab.com<br />
<br />
<br />
Available: [Coming Soon!]<br />
<br />
                                         [+] conference.vulnerability-lab.com]]></description>
			<pubDate><![CDATA[Mon, 07 May 2012 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[PROJECT: SECURITY VULNERABILITY LABORATORY]]></title>
			<category><![CDATA[Vulnerability-Lab]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=1</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=1</guid>
			<description><![CDATA[The new Vulnerability-Lab is now live! We are certainly excited about this project and have much to work toward. The Vulnerability-Lab works <br />
very hard in bringing Europe and the world a great amount of information regarding vulnerabilities and urgent security advisories.  If you are <br />
a vendor, Vulnerability-Labs can be an extremely valuable resource for information in detail about the current state of security for your software.<br />
<br />
Vulnerability-Lab is a research team that finds vulnerabilities, security holes, and bad security practices in software and applications, bringing  this <br />
information to one site where vendors may be notified in a professional and timely manner. The Vulnerability-Lab is comprised currently of  eleven members <br />
who range from experts in the field of Information Security to managers of information and site content. All of these members, however, are greatly interested <br />
in security and is their primary concern. The research team releases,  on average, 25-40 vulnerabilities a month, ranging from important to critical. The process <br />
of releasing vulnerabilities and advisories is always generally followed in a professional manner. Sensitive  Information is censored and any contribution from <br />
third parties that may include or seem to encourage malicious or stolen content, or personal/group agendas is strictly forbidden. More information about this <br />
can be found in the FAQ. <br />
<br />
Not only does the Vulnerability-Lab provide advisories for software,  but it also allows the customisation of these advisories down to particular vendors, <br />
types of vulnerabilities, dates, and even informative videos. If your goal is to only be notified of security holes in your software and  to work with the <br />
researchers to have it patched, then this option is naturally available. However, collaboration amongst our team and with other  teams and vendors is a priority, <br />
as education and knowledge always lie in the  forefront. Read our blog or join our forum if you would simply like  to read more and keep up with the fast-paced <br />
world of information security and what  is going on in our labs!<br />
<br />
Vulnerability-Lab is committed to bringing vulnerabilities to light and collaborating with researchers for the betterment of software and application security. <br />
If you are a member of a research team and would like to work with Vulnerability-Lab, send us an E-Mail including who you are and what you are interested in <br />
contributing. We also need sponsors! If you are a vendor or research team that would like to employ our services, we would be more than happy to oblige. <br />
Donations  are, of course, also always welcome. This is a very dedicated and talented team of researchers and workers. Investing in the Vulnerability-Lab will <br />
help nurture both the security of your software as a vendor and also status of application and software security world-wide. Please contact us if you are <br />
interested sponsoring, benefits and internet prevention system projects for customers.<br />
<br />
Domains: www.vulnerability-lab.com ,  www.vuln-lab.com or www.vuln-db.com<br />
Contact: admin[A|T]vulnerability-lab.com<br />
Support: support[A|T]vulnerability-lab.com<br />
Research: research[A|T]vulnerability-lab.com<br />
Submit Advisories: submit[A|T]vulnerability-lab.com]]></description>
			<pubDate><![CDATA[Thu, 02 Jun 2011 22:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Updates, Cooperation, Thanks & Vendor Product Vulnerabilities]]></title>
			<category><![CDATA[Vulnerability-Lab]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=57</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=57</guid>
			<description><![CDATA[After the first wave of publications has been arrived on the market and press we want to expand our work on vendor <br />
product vulnerabilities. In the last weeks we got a lot of new and very strong partnerships with complex security <br />
companies.<br />
<br />
Some of our researchers and exploiters earned good money by different bug bounty programs. We are also <br />
very happy about the patch/fix time-line of discovered vulnerabilities which is mostly very close. The response <br />
from website owners, product vendors and parnters is very good. We get informed about all future steps, details or <br />
updates.<br />
<br />
China National Vulnerability Database of Information Security is now a exchange partner for exclsuive <br />
security issues and vulnerabilities. We include in all discovered vulnerabilities a cnnvd id as reference to the <br />
original verified issue.<br />
<br />
We want to use the announcement to say THANKS to all vendors, partners and vulnerability researchers. Our vulnerability <br />
researcher team has reported over 180+ vulnerabilities who are now fixed. Over 200+ Advisories are now in the upcoming <br />
& verification process of the laboratory.<br />
<br />
We are glad to take our part to make the www, applications and software (vendor products) more secure.<br />
<br />
Best Regards,<br />
Vulnerability Laboratory Research Team,<br />
Administration]]></description>
			<pubDate><![CDATA[Wed, 09 Nov 2011 19:46:10 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Merry X-Mas @ Team, Partners, Analysts and Researchers]]></title>
			<category><![CDATA[Vulnerability-Lab]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=65</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=65</guid>
			<description><![CDATA[We wish all partners, members, lab users, technical exchange partners, disclosure partners & connected trusted communities a happy x-mas.<br />
Enjoy the last days of the year & stay with your friends or familie. <br />
<br />
<br />
                                                .#####*,                                             <br />
                                              *##########.                                           <br />
                                            ,##############                                          <br />
                                           *################,                                        <br />
                                          ###################:                                       <br />
                                        ,#####################*                                      <br />
                                       :#######################*                                     <br />
                                      *#########################*                                    <br />
                                     ############################*                                   <br />
                                    ##############################+                                  <br />
                                  :################################.                                 <br />
                                 ###################################                                 <br />
                               +#####################################                                <br />
                            .#########################################                               <br />
                         +############################################:                              <br />
                       ,#*    ,########################################                              <br />
                       #,        *######################################                             <br />
                      .#           #####################################*                            <br />
                      *#             ####################################.                           <br />
                      *#              .###################################                           <br />
                      :#                *##################################                          <br />
                       #+                 #####################   ,########:                         <br />
                       ###:                ,##################       #######                         <br />
                      ## +##:                 ################        *######                        <br />
                     ,#    *##                       +#######:         .#####*                       <br />
                     #*      ##                        :#####,          ,#####,                      <br />
                     #        *#:                        ####             #####                      <br />
                    *#         .#*                        ###              #####                     <br />
                    #.          *##                        ##              ,#####   ,:***.           <br />
                ,:### :##       # ##*                      .#               *##############+         <br />
            ,######*  ####     ,#  ###.                    ,#                ###############+        <br />
          ,##+           :     ##   .###:                  +#               ######.      ####        <br />
         ,#+                   #,      *###,               ##               ###,          +##        <br />
         ##                    #         ,####.           *#.               ##,            ##        <br />
         ##                    #            ,*###+       ,##                ##+            ##        <br />
         ##                   .#                +###.   ,##                  ##            ##        <br />
          #:                  **                   *##.+##                   ##           .##        <br />
          +#.     :#####*.   ,#                      .##*                    +#           ##,        <br />
           *#######*,,:#######,                       ##                     ,#,          ##         <br />
           .###+,                                     +#                      #.         ##,         <br />
           #,                                          ##                     #*        :##          <br />
          *#*                                          ,##                    ##       ,##           <br />
          ,###,                                         .##                   *#####.,*##,           <br />
            .####+,                                      .##                   #########.            <br />
		###.                                      ,##,                    ,####,             <br />
              +#*                                           ##                                       <br />
           +##.                                              ##                                      <br />
           ##                                                ##                                      <br />
            #+                                               #.                                      <br />
             #*                                       :+*####.                                       <br />
             ##                                     ####**:                                          <br />
           :##                                     ##                                                <br />
         .##,                                      #,                                                <br />
        ##+                                        #,                                                <br />
       ,#                                          #+                                                <br />
       *+                                          ##                                                <br />
      *#                                           +#                                                <br />
   ,###*                                           ,#                                                <br />
  ,##.                                              #,                                               <br />
  ##                                                #+                                               <br />
  *#                                                ##                                               <br />
  :#                                              ,##+                                               <br />
  ,#                                           ,#####                                                <br />
   #                                         *####:                                                  <br />
   #                                      ,####.                                                     <br />
   #                                    ,###:                                                        <br />
  .#                                   ###                                                           <br />
  *##.                                ,#                                                             <br />
   ####*                              #:                                                             <br />
     *####,                           #                                                              <br />
       ,####,                        :#                                                              <br />
          :##*                       #.                                                              <br />
            +##    .#######*,        #                                                               <br />
             .#################:    :#                                                               <br />
               **,          +####*  #,                                                               <br />
                               :#####                                                                <br />
                                  ##,                                                                <br />
<br />
			@ VULNERABILITY-LAB ADMINISTRATION]]></description>
			<pubDate><![CDATA[Fri, 23 Dec 2011 23:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Happy New Year 2012 by Vulnerability Labs]]></title>
			<category><![CDATA[Vulnerability-Lab]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=66</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=66</guid>
			<description><![CDATA[We wish all our partners, friends, hackers, exploiters, analysts and researchers a happy new year 2012.<br />
<br />
H Ours Of Happy Times With Friends And Family<br />
A Bundant Time For Relaxation<br />
P Rosperity<br />
P Lenty Of Love When You Need It The Most<br />
Y Outhful Excitement At Lifes Simple Pleasures<br />
<br />
N Ights Of Restful Slumber<br />
E Verything You Need<br />
W Ishing You Love And Light<br />
<br />
Y Ears And Years Of Good Health<br />
E Njoyment And Mirth<br />
A Angels To Watch Over You<br />
R Embrances Of A Happy Years!<br />
<br />
<br />
         __<br />
      .'`  `'.<br />
     /        \ _<br />
    ;      __.'` `'.<br />
    |   .'`  `'.    \<br />
    ;  / HAPPY  \    ;<br />
     \;   NEW    ;   |<br />
      | Y E A R  |   ;   _<br />
      ; 2 0 1 2  ;-./-_-` '-.<br />
      /\        /_(;'/ `\()  '.<br />
     ;  '.__  .'\|| '    |     '.<br />
     |      ),\| \\      \()    (\<br />
     ;        \ \|/   __/    ()   \  __<br />
      \        \||\.~'_ `'.;-.___.~'` _'~.<br />
       '.__  _/|/|/{ (_`.'         '.`_) }<br />
           `)/`\\\\ \ .'  _ 0_._0 _  '. /     .,_<br />
                 \|| } -.'   (_)   '.- {    _{   `\<br />
                  \|{_ / '.___|___.' \  }  //`._   |<br />
                /`    \     |   |     }  }:'-. ()``'"--..==,<br />
               {      ,}    \-"-/   .'  } {,`-'.      (//>`\><br />
              {`   _./|\._.  '-'  ._ .~` /`    ;'.()  //>  |><br />
              {     {///(  `-.-.-`  ) _.'     /   '. ||>   /><br />
               \     \|\);--`( )`--`(`       }      `\\>_.'><br />
                ;  _/`/(__.'/`-'.,__/`,    .`         `"""`<br />
               .-'`     ;-.(     \_(;  \ .'     .--,<br />
              (`-._   ./   `       '.   `-._..~` /o\\<br />
               `'-;/``.              `;-"`:     |oo||<br />
          .--._ _.' .  \      o       ;  .      |  /|<br />
         /.-.  `     .  '._        _.'  '       \_//<br />
         ||oo\        `.   `'-----`  _.~`--..__,..'<br />
         |\o  |       .~`'--......--'<br />
          \'._/   _.~`<br />
           `.__.-' <br />
<br />
<br />
We will soon startup with the next publications in January [2012-01-05].<br />
<br />
				@ VULNERABILITY-LAB ADMINISTRATION]]></description>
			<pubDate><![CDATA[Fri, 30 Dec 2011 23:00:00 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[3 new internal Vulnerability Laboratory Team Members]]></title>
			<category><![CDATA[Vulnerability-Lab]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=79</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=79</guid>
			<description><![CDATA[We say welcome to Subho Halder, Dev Kar  and Julien Ahrens. The researchers (3) joined this week the internal Vulnerability Laboratory Team.<br />
All new members are stable available on the laboratory team sections with references and contact.<br />
<br />
                     [+] Subho Halder<br />
                     [+] Dev Kar<br />
                     [+] Julien Ahrens<br />
]]></description>
			<pubDate><![CDATA[Wed, 07 Mar 2012 16:37:38 +0000]]></pubDate>
			</item>
			
			<item>
			<title><![CDATA[Internal Vulnerability Laboratory Member got  kicked!]]></title>
			<category><![CDATA[Vulnerability-Lab]]></category>
			<link>http://www.vulnerability-lab.com/news/get_news.php?id=81</link>
			<guid>http://www.vulnerability-lab.com/news/get_news.php?id=81</guid>
			<description><![CDATA[We announce that a internal member and public representative got  kicked of the internal vulnerability laboratory research team.<br />
The information goes out to our friends and partners which had no possibilities to contact us the last days during the isp problems.<br />
<br />
Name: <br />
- Ucha G. (longrilfe0x)<br />
<br />
Reasons for our decision ...<br />
- Publication of unverified, wrong declared and unauthorized issues  (dcom media player &amp;amp;amp; co.)<br />
- Copy of Template of Laboratory Member<br />
- Copy of SecDay Blog - Alexander Fuchs at 1337day Site<br />
- Forcing multiple internal members (unsuccessful!) - Money Transfers<br />
- Full Disclosure of issues and technical details - No vendor Fix/Patch (Lab Disclosure Policy!)<br />
- False statements to project partners and  vendors<br />
- We got information by an anonymous person about Longrifle0x last year www.zone-h.org/archive/notifier=longrifle0x<br />
<br />
We hope you had a great time with the labs members but this is a TEAM decision ;)<br />
]]></description>
			<pubDate><![CDATA[Fri, 23 Mar 2012 18:25:29 +0000]]></pubDate>
			</item>
			</channel></rss>	
