<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>chackraview.net &#187; Web Security</title>
	<atom:link href="http://blog.chackraview.net/category/web-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.chackraview.net</link>
	<description>There is no such thing as closed source software…the processor sees every instruction and so does the reverse engineer…</description>
	<lastBuildDate>Fri, 03 Feb 2012 17:51:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Analysis of .jar attack from blackhole exploit pack.</title>
		<link>http://blog.chackraview.net/2011/11/20/analysis-of-jar-attack-from-blackhole-exploit-pack/</link>
		<comments>http://blog.chackraview.net/2011/11/20/analysis-of-jar-attack-from-blackhole-exploit-pack/#comments</comments>
		<pubDate>Sun, 20 Nov 2011 11:56:39 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[.jar exploits]]></category>
		<category><![CDATA[Blachole]]></category>
		<category><![CDATA[CVE 2010-0840]]></category>
		<category><![CDATA[exploit pack]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=783</guid>
		<description><![CDATA[Yesterday, one of my friend received a legitimate looking email from Internal Revenue Service with subject: Your Federal Tax Payment with a link to tax report.pdf file. He reported it to me and I got a chance to analyze it. Below are some of my findings from the analysis. The link had below obfuscated javascript in [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2011/11/20/analysis-of-jar-attack-from-blackhole-exploit-pack/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Outburst of HDFC and IDBI bank phishing emails</title>
		<link>http://blog.chackraview.net/2010/04/05/outburst-of-hdfc-and-idbi-bank-phishing-emails/</link>
		<comments>http://blog.chackraview.net/2010/04/05/outburst-of-hdfc-and-idbi-bank-phishing-emails/#comments</comments>
		<pubDate>Mon, 05 Apr 2010 08:37:15 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Email security]]></category>
		<category><![CDATA[HDFC]]></category>
		<category><![CDATA[IDBI phishing]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[social engineering]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=629</guid>
		<description><![CDATA[For past few days, I was getting fraud emails impersonating HDFC and IDBI banks. Emails looked pretty legitimate unless you looked into the email headers or actually visited the link provided in them. Below are some screen shots of the emails that I received. You may also see some superficial investigation I underwent to make [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/04/05/outburst-of-hdfc-and-idbi-bank-phishing-emails/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Yet another information disclosure vulnerability in Internet explorer.</title>
		<link>http://blog.chackraview.net/2010/02/04/yet-another-information-disclosure-vulnerability-in-internet-explorer/</link>
		<comments>http://blog.chackraview.net/2010/02/04/yet-another-information-disclosure-vulnerability-in-internet-explorer/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 05:42:53 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[ConferenceTalks]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Abusing Insecure features of IE]]></category>
		<category><![CDATA[Black Hat DC]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[CVE-2010-0255]]></category>
		<category><![CDATA[Information Leakage]]></category>
		<category><![CDATA[URL Security Zone bypass]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=604</guid>
		<description><![CDATA[IE Aurora&#8216;s dust was not even settled in our minds and yet another critical vulnerability in IE has emerged with a bang !! A Security Consultant from CORE Security Technologies, Mr.Jorge Luis Alvarez Medina discussed a vulnerability in BlackHat DC 10 conference. His presentation demonstrated a Proof of Concept code which exploits this vulnerability and allows [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/02/04/yet-another-information-disclosure-vulnerability-in-internet-explorer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>URL shortening: Social engineering attack vector</title>
		<link>http://blog.chackraview.net/2010/01/29/url-shortening-social-engineering-attack-vector/</link>
		<comments>http://blog.chackraview.net/2010/01/29/url-shortening-social-engineering-attack-vector/#comments</comments>
		<pubDate>Fri, 29 Jan 2010 06:54:21 +0000</pubDate>
		<dc:creator>Abhijeet</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[url shortning]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=575</guid>
		<description><![CDATA[URL shortening is a technique in the World Wide Web wherein a provider makes a web page available under a very short URL in addition to the original address. For example, the page http://blog.chackraview.net/2010/01/19/operation-aurora/ can be shortened to http://bit.ly/5RJICq As web clients tends to pass more and more data in the URL to communicate with [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/29/url-shortening-social-engineering-attack-vector/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Decode: eval_gzinflate_base64_decode</title>
		<link>http://blog.chackraview.net/2010/01/25/decode-eval_gzinflate_base64_decode-2/</link>
		<comments>http://blog.chackraview.net/2010/01/25/decode-eval_gzinflate_base64_decode-2/#comments</comments>
		<pubDate>Tue, 26 Jan 2010 01:42:12 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[eval gzinflate base64]]></category>
		<category><![CDATA[malwares]]></category>
		<category><![CDATA[php decode]]></category>

		<guid isPermaLink="false">http://blog.chackraview.net/?p=569</guid>
		<description><![CDATA[If you follow my posts&#8230;.sometime back i wrote about the my encounter with web attacks which was amazing experience. I am lazy kinda person and with all this IPL fever these days, I don&#8217;t even think of blogging or doing personal research. So what made me sit and write today? The answer is,  my same [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/25/decode-eval_gzinflate_base64_decode-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>My Encounter with Live Web Attack</title>
		<link>http://blog.chackraview.net/2010/01/19/my-encounter-with-live-web-attack/</link>
		<comments>http://blog.chackraview.net/2010/01/19/my-encounter-with-live-web-attack/#comments</comments>
		<pubDate>Tue, 19 Jan 2010 07:16:55 +0000</pubDate>
		<dc:creator>bughira</dc:creator>
				<category><![CDATA[General Talks]]></category>
		<category><![CDATA[HOWTO's]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Malware analysis]]></category>
		<category><![CDATA[Malware Techniques]]></category>
		<category><![CDATA[Security Tools]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[De-obfuscation]]></category>
		<category><![CDATA[Decode malicious JavaScript]]></category>
		<category><![CDATA[iFrame injections]]></category>
		<category><![CDATA[Rhino]]></category>
		<category><![CDATA[Web attacks]]></category>
		<category><![CDATA[web based malware]]></category>

		<guid isPermaLink="false">http://bughira.wordpress.com/?p=234</guid>
		<description><![CDATA[It will not be an average day, I knew from the dawn, as EOD I will be on my way to Pune. You might think whats so special about visiting pune? Let me tell you, people who have spent at least a year or two in city like Pune or Bangalore will hate to stay [...]]]></description>
		<wfw:commentRss>http://blog.chackraview.net/2010/01/19/my-encounter-with-live-web-attack/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
	</channel>
</rss>

