<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.3.3" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>Justin Samuel</title>
	<link>http://www.justinsamuel.com</link>
	<description>Security, Linux, Development</description>
	<pubDate>Tue, 15 Jan 2008 22:00:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.3.3</generator>
	<language>en</language>
			<item>
		<title>Vulnerability: AWBS magic_quotes_gpc &#8220;Off&#8221; SQL Injection and XSS</title>
		<link>http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/</link>
		<comments>http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/#comments</comments>
		<pubDate>Sun, 10 Jun 2007 16:01:56 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[Security Vulnerabilities]]></category>

		<category><![CDATA[sql injection]]></category>

		<category><![CDATA[vulnerability]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/</guid>
		<description><![CDATA[Advisory: AWBS magic_quotes_gpc &#8220;Off&#8221; SQL Injection and XSS Vulnerabilities
Release Date: 2007-06-10
Last Modified: 2007-07-26
Author: Justin Samuel [http://www.justinsamuel.com]
Application: AWBS &#60; 2.6.0
Severity: Highly Critical
Impact: Disclosure of sensitive information
Cross site scripting
Vendor Status: Vendor released version 2.6.0 to address issue. Testing still needed to verify that issue is corrected.
Vendor: Total Online Solutions, Inc.
App. Website: http://www.awbs.com/
References: http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;
Description:
Advanced Webhost Billing System (AWBS) [...]]]></description>
			<content:encoded><![CDATA[<p>Advisory: AWBS magic_quotes_gpc &#8220;Off&#8221; SQL Injection and XSS Vulnerabilities<br />
Release Date: 2007-06-10<br />
Last Modified: 2007-07-26<br />
Author: Justin Samuel [<a href="http://www.justinsamuel.com">http://www.justinsamuel.com</a>]</p>
<p>Application: AWBS &lt; 2.6.0<br />
Severity: Highly Critical<br />
Impact: Disclosure of sensitive information<br />
Cross site scripting<br />
Vendor Status: Vendor released version 2.6.0 to address issue. Testing still needed to verify that issue is corrected.</p>
<p>Vendor: Total Online Solutions, Inc.<br />
App. Website: <a href="http://www.awbs.com/">http://www.awbs.com/</a><br />
References: <a href="http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/">http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/</a></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Description:</p>
<p>Advanced Webhost Billing System (AWBS) contains multiple SQL injection and XSS<br />
vulnerabilities due to a lack of user input validation.<br />
 <a href="http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/#more-17" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2007/06/10/awbs-magic_quotes_gpc-off-sql-injection-and-xss-vulnerabilities/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Vulnerability: AWBS Dedicated Server Info Visible to All Users</title>
		<link>http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/</link>
		<comments>http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/#comments</comments>
		<pubDate>Sun, 10 Jun 2007 16:00:55 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[Security Vulnerabilities]]></category>

		<category><![CDATA[information disclosure]]></category>

		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/</guid>
		<description><![CDATA[Advisory: AWBS Dedicated Server Info Visible to All Users
Release Date: 2007-06-10
Last Modified: 2007-07-26
Author: Justin Samuel [http://www.justinsamuel.com]
Application: AWBS &#60; 2.6.0
Severity: Less Critical
Impact: Disclosure of sensitive information
Vendor Status: Vendor released version 2.6.0 to address issue. Testing still needed to verify that issue is corrected.
Vendor: Total Online Solutions, Inc.
App. Website: http://www.awbs.com/
References: http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;
Description:
Advanced Webhost Billing System (AWBS) allows any [...]]]></description>
			<content:encoded><![CDATA[<p>Advisory: AWBS Dedicated Server Info Visible to All Users<br />
Release Date: 2007-06-10<br />
Last Modified: 2007-07-26<br />
Author: Justin Samuel [<a href="http://www.justinsamuel.com">http://www.justinsamuel.com</a>]</p>
<p>Application: AWBS &lt; 2.6.0<br />
Severity: Less Critical<br />
Impact: Disclosure of sensitive information<br />
Vendor Status: Vendor released version 2.6.0 to address issue. Testing still needed to verify that issue is corrected.</p>
<p>Vendor: Total Online Solutions, Inc.<br />
App. Website: <a href="http://www.awbs.com/">http://www.awbs.com/</a><br />
References: <a href="http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/">http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/</a></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>Description:</p>
<p>Advanced Webhost Billing System (AWBS) allows any user access to the details of<br />
all dedicated servers sold through AWBS.<br />
 <a href="http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/#more-16" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2007/06/10/awbs-dedicated-server-info-visible-to-all-users-vulnerability/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Vulnerability: ModernBill Insecure CURL Settings</title>
		<link>http://www.justinsamuel.com/2006/07/11/vulnerability-modernbill-insecure-curl-settings/</link>
		<comments>http://www.justinsamuel.com/2006/07/11/vulnerability-modernbill-insecure-curl-settings/#comments</comments>
		<pubDate>Tue, 11 Jul 2006 19:48:22 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[Security Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/security-vulnerabilities/12/vulnerability-modernbill-insecure-curl-settings</guid>
		<description><![CDATA[#################################################################
Vulnerability discovered by: Justin Samuel (www.justinsamuel.com)
Discovery Date: 2006-07-11
Severity: Less Critical
Impact: Exposure of sensitive information
Product: ModernBill
Affected Versions: 5.0.1
Vendor: ModernGigabyte, LLC (www.moderngigabyte.com)
Product Link: http://www.modernbill.com/
#################################################################
]]></description>
			<content:encoded><![CDATA[<p>#################################################################</p>
<p>Vulnerability discovered by: Justin Samuel (<a href="http://www.justinsamuel.com">www.justinsamuel.com</a>)<br />
Discovery Date: 2006-07-11<br />
Severity: Less Critical<br />
Impact: Exposure of sensitive information</p>
<p>Product: ModernBill<br />
Affected Versions: 5.0.1<br />
Vendor: ModernGigabyte, LLC (www.moderngigabyte.com)<br />
Product Link: http://www.modernbill.com/</p>
<p>#################################################################<br />
 <a href="http://www.justinsamuel.com/2006/07/11/vulnerability-modernbill-insecure-curl-settings/#more-12" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2006/07/11/vulnerability-modernbill-insecure-curl-settings/feed/</wfw:commentRss>
		</item>
		<item>
		<title>php 5.1.4 rpms for rhel4 added (with apc)</title>
		<link>http://www.justinsamuel.com/2006/05/25/php-514-rpms-for-rhel4-added-with-apc/</link>
		<comments>http://www.justinsamuel.com/2006/05/25/php-514-rpms-for-rhel4-added-with-apc/#comments</comments>
		<pubDate>Fri, 26 May 2006 03:45:06 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[PHP]]></category>

		<category><![CDATA[RPMs]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/uncategorized/11/php-514-rpms-for-rhel4-added-with-apc</guid>
		<description><![CDATA[php 5.1.4 rpms for rhel 4 have been added to the rpm downloads section. These are based off of the current fedora core 5 rpms with the following changes:
    * shared hosting security: removed posix functions [shared hosting security]
    * removed pcntl functions [shared hosting security]
    [...]]]></description>
			<content:encoded><![CDATA[<p>php 5.1.4 rpms for rhel 4 have been added to the rpm downloads section. These are based off of the current fedora core 5 rpms with the following changes:</p>
<p>    * shared hosting security: removed posix functions [shared hosting security]<br />
    * removed pcntl functions [shared hosting security]<br />
    * added dummy domxml package [compatibility with other packages that depend on it, such as certain plesk 8 packages]</p>
<p>This build does have cgi compiled with fastcgi support.</p>
<p>Additionally, there is a corresponding php-apc 3.1.0 rpm available in the downloads section for this build of php. <a href="http://www.justinsamuel.com/2006/05/25/php-514-rpms-for-rhel4-added-with-apc/#more-11" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2006/05/25/php-514-rpms-for-rhel4-added-with-apc/feed/</wfw:commentRss>
		</item>
		<item>
		<title>scponly rpms with chroot enabled added for rhel4</title>
		<link>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/</link>
		<comments>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#comments</comments>
		<pubDate>Thu, 30 Mar 2006 15:53:58 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[Plesk]]></category>

		<category><![CDATA[RPMs]]></category>

		<category><![CDATA[Server Security]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/10/scponly-rpms-with-chroot-enabled-added-for-rhel4</guid>
		<description><![CDATA[i&#8217;ve added scponly rpms with chroot enabled for rhel4.  get the files here or by apt/yum.  this is more useful in a shared hosting environment than the rpms found at DAG and elsewhere that don&#8217;t have chroot enabled.
to use this, for example on a plesk box to allow domains to use sftp without [...]]]></description>
			<content:encoded><![CDATA[<p>i&#8217;ve added scponly rpms with chroot enabled for rhel4.  <a href="http://www.justinsamuel.com/downloads/rpms/redhat/el4/en/i386/RPMS.js/">get the files here</a> or by apt/yum.  this is more useful in a shared hosting environment than the rpms found at DAG and elsewhere that don&#8217;t have chroot enabled.</p>
<p>to use this, for example on a plesk box to allow domains to use sftp without having to give them a chroot&#8217;ed bash shell, do the following: <a href="http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/#more-10" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2006/03/30/scponly-rpms-with-chroot-enabled-added-for-rhel4/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HOWTO: use forwards in bind to only answer queries for domains on your servers (and not be an open dns server)</title>
		<link>http://www.justinsamuel.com/2006/03/16/use-forwards-in-bind-to-only-answer-queries-for-domains-on-your-servers/</link>
		<comments>http://www.justinsamuel.com/2006/03/16/use-forwards-in-bind-to-only-answer-queries-for-domains-on-your-servers/#comments</comments>
		<pubDate>Fri, 17 Mar 2006 05:43:25 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[HOWTOs]]></category>

		<category><![CDATA[Linux]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/howtos/2006/03/howto-use-forwards-in-bind-so-that-your-dns-servers-answer-for-all-domains-on-your-other-servers-not-be-open-dns-servers/9/</guid>
		<description><![CDATA[This howto is meant to be a quick fix for those moving from one server to two or those with two servers who want to disable recursion.  This only works if at least one of your nameservers answers authoritatively for each zone already.  I believe it should work for those with more than [...]]]></description>
			<content:encoded><![CDATA[<p>This howto is meant to be a quick fix for those moving from one server to two or those with two servers who want to disable recursion.  This only works if at least one of your nameservers answers authoritatively for each zone already.  I believe it should work for those with more than two servers as long as one of the nameserver listed for any given domain does answer authoritatively.  But if you have more servers than two, you should probably looking to setup your dns properly rather than using this quick fix shown here. <a href="http://www.justinsamuel.com/2006/03/16/use-forwards-in-bind-to-only-answer-queries-for-domains-on-your-servers/#more-9" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2006/03/16/use-forwards-in-bind-to-only-answer-queries-for-domains-on-your-servers/feed/</wfw:commentRss>
		</item>
		<item>
		<title>php APC rpms added for php 5.1.2 / APC 3.0.10 / rhel 4</title>
		<link>http://www.justinsamuel.com/2006/03/15/php-apc-rpms-added-for-php-512-apc-3010-rhel-4/</link>
		<comments>http://www.justinsamuel.com/2006/03/15/php-apc-rpms-added-for-php-512-apc-3010-rhel-4/#comments</comments>
		<pubDate>Wed, 15 Mar 2006 08:11:04 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[PHP]]></category>

		<category><![CDATA[RPMs]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/uncategorized/2006/03/php-apc-rpms-added-for-php-512-apc-3010-rhel-4/8/</guid>
		<description><![CDATA[I&#8217;ve added php-apc rpms for php 5.1.2 on rhel4, using the current stable release of APC (3.0.10).   get the files here or by apt/yum.  Additional notes:
]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve added php-apc rpms for php 5.1.2 on rhel4, using the current stable release of APC (3.0.10).   <a href="http://www.justinsamuel.com/downloads/rpms/redhat/el4/en/i386/RPMS.js/">get the files here</a> or by apt/yum.  Additional notes:  <a href="http://www.justinsamuel.com/2006/03/15/php-apc-rpms-added-for-php-512-apc-3010-rhel-4/#more-8" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2006/03/15/php-apc-rpms-added-for-php-512-apc-3010-rhel-4/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HOWTO: Create a self-signed (wildcard) SSL certificate</title>
		<link>http://www.justinsamuel.com/2006/03/11/howto-create-a-self-signed-wildcard-ssl-certificate/</link>
		<comments>http://www.justinsamuel.com/2006/03/11/howto-create-a-self-signed-wildcard-ssl-certificate/#comments</comments>
		<pubDate>Sun, 12 Mar 2006 06:35:44 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[HOWTOs]]></category>

		<category><![CDATA[Linux]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/howtos/2006/03/howto-create-a-self-signed-wildcard-ssl-certificate/6/</guid>
		<description><![CDATA[The following commands are all you need to create a self-signed (wildcard, if you want) SSL certificate:
]]></description>
			<content:encoded><![CDATA[<p>The following commands are all you need to create a self-signed (wildcard, if you want) SSL certificate: <a href="http://www.justinsamuel.com/2006/03/11/howto-create-a-self-signed-wildcard-ssl-certificate/#more-6" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2006/03/11/howto-create-a-self-signed-wildcard-ssl-certificate/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HOWTO: Setup SSL certificates for mail services (pop3s, imaps, smtps) on Plesk / Courier-Imap / Qmail</title>
		<link>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/</link>
		<comments>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#comments</comments>
		<pubDate>Sun, 12 Mar 2006 06:23:44 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[HOWTOs]]></category>

		<category><![CDATA[Plesk]]></category>

		<category><![CDATA[Server Security]]></category>

		<guid isPermaLink="false">http://www.justinsamuel.com/linux/server-security/2006/03/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-pleskcourier-imapqmail/5/</guid>
		<description><![CDATA[This howto will show you how to setup an SSL certificate on a Plesk server so that it will be used when people connect through secure pop, smtp and imap.
]]></description>
			<content:encoded><![CDATA[<p>This howto will show you how to setup an SSL certificate on a Plesk server so that it will be used when people connect through secure pop, smtp and imap. <a href="http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/#more-5" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2006/03/11/howto-setup-ssl-certificates-for-mail-pop3s-imaps-smtps-on-plesk-courier-imap-qmail/feed/</wfw:commentRss>
		</item>
		<item>
		<title>HOWTO: Backup and restore a Plesk domain from the command line</title>
		<link>http://www.justinsamuel.com/2006/03/09/howto-backup-and-restore-a-plesk-domain-from-the-command-line/</link>
		<comments>http://www.justinsamuel.com/2006/03/09/howto-backup-and-restore-a-plesk-domain-from-the-command-line/#comments</comments>
		<pubDate>Fri, 10 Mar 2006 06:14:36 +0000</pubDate>
		<dc:creator>justin</dc:creator>
		
		<category><![CDATA[HOWTOs]]></category>

		<category><![CDATA[Plesk]]></category>

		<guid isPermaLink="false">http://justinsamuel.com/archives/2006/03/howto-backup-and-restore-a-plesk-domain-from-the-command-line/4/</guid>
		<description><![CDATA[This HOWTO shows how to use the Plesk command line utilties to backup and restore a single domain.  This can be useful, among other reasons, as a way to move a site between servers (though now they have the Migration Manager for that) or as a way to make a final backup of a [...]]]></description>
			<content:encoded><![CDATA[<p>This HOWTO shows how to use the Plesk command line utilties to backup and restore a single domain.  This can be useful, among other reasons, as a way to move a site between servers (though now they have the Migration Manager for that) or as a way to make a final backup of a domain before removing it (though to be safe you should make other backups and have regular periodic backups as well). <a href="http://www.justinsamuel.com/2006/03/09/howto-backup-and-restore-a-plesk-domain-from-the-command-line/#more-4" class="more-link">(more&#8230;)</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.justinsamuel.com/2006/03/09/howto-backup-and-restore-a-plesk-domain-from-the-command-line/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>

<!-- Dynamic Page Served (once) in 0.250 seconds -->
<!-- Cached page served by WP-Cache -->
