What about a wiki on the submissions?

1 view
Skip to first unread message

Mario Heiderich

unread,
Sep 30, 2007, 3:59:41 PM9/30/07
to PHPIDS » Web Application Security 2.0
Hi!

I just talked to Gareth about his latest vector submission and got the
idea of building up a wiki to persist the issues found on slackers and
the group like:

- interesting but hard to understand vectors
- strange JavaScript behavior
- more strange JavaScript behavior
- parsing peculiarities for browsers and their components
- etc.

What do you think? Currently we have the problem that the information
is there but too wide spread and not very usable - a wiki should help
fighting those hitches and with the information already gathered we
could build up a pretty unique knowledge base.

Greetings,
.mario

thornmaker

unread,
Sep 30, 2007, 9:24:20 PM9/30/07
to PHPIDS » Web Application Security 2.0
I really like the idea. It would make collaboration a bit easier, and
it would be nice to have a central place for discussing things. Just
make sure the wiki allows one to post code easily, without having to
do any special markup on it; that would be a real drag.

On Sep 30, 3:59 pm, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:

Mario Heiderich

unread,
Oct 1, 2007, 3:23:39 AM10/1/07
to php...@googlegroups.com
We could use the existing Trac Wiki or I could set up a new. What domain would you propose to use for this purpose? We could use wiki.php-ids.org or something with the h4k.in domain or even register a new one.

I'd propose the easiest way and use wiki.php-ids.org combined with the trac wiki which is pretty comfortable for posting code and other elements.

2007/10/1, thornmaker <thorn...@gmail.com>:



--
_______________________
php-ids.org

Mario Heiderich

unread,
Oct 1, 2007, 3:56:06 AM10/1/07
to PHPIDS » Web Application Security 2.0
Just found that one:

http://wiki.splitbrain.org/wiki:dokuwiki

Looks promising too I think...

On 1 Okt., 09:23, "Mario Heiderich" <mario.heider...@googlemail.com>
wrote:


> We could use the existing Trac Wiki or I could set up a new. What domain
> would you propose to use for this purpose? We could use wiki.php-ids.org or
> something with the h4k.in domain or even register a new one.
>
> I'd propose the easiest way and use wiki.php-ids.org combined with the trac
> wiki which is pretty comfortable for posting code and other elements.
>

> 2007/10/1, thornmaker <thornma...@gmail.com>:

kishord

unread,
Oct 1, 2007, 9:13:06 AM10/1/07
to PHPIDS » Web Application Security 2.0
Thats a great idea!

Actually I had thought about this some days ago, and collected few
vectors.

Here is how an entry in the list looked like..


1 Thornmaker
*************************************************************
URL/POST:
http://demo.php-ids.org/?test=%7B%7A%3D%28%31%3D%3D%34%29%3F%68%65%72%65%3A%7B%7A%3A%28%31%21%3D%35%29%3F%27%27%3A%62%65%7D%7D%7B%79%3D%28%39%3D%3D%32%29%3F%64%72%61%67%6F%6E%73%3A%7B%79%3A%27%6C%27%2B%7A%2E%7A%7D%7D%7B%78%3D%28%36%3D%3D%35%29%3F%33%3A%7B%78%3A%27%61%27%2B%79%2E%79%7D%7D%7B%77%3D%28%35%3D%3D%38%29%3F%39%3A%7B%77%3A%27%65%76%27%2B%78%2E%78%7D%7D%7B%76%3D%28%37%3D%3D%39%29%3F%33%3A%7B%76%3A%27%74%72%28%32%29%27%2B%7A%2E%7A%7D%7D%7B%75%3D%28%33%3D%3D%38%29%3F%34%3A%7B%75%3A%27%73%68%2E%73%75%62%73%27%2B%76%2E%76%7D%7D%7B%74%3D%28%36%3D%3D%32%29%3F%36%3A%7B%74%3A%79%2E%79%2B%27%6F%63%61%74%69%6F%6E%2E%68%61%27%2B%75%2E%75%7D%7D%7B%73%3D%28%34%3D%3D%33%29%3F%33%3A%7B%73%3A%28%38%21%3D%33%29%3F%28%32%29%5B%77%2E%77%5D%3A%7A%7D%7D%7B%72%3D%73%2E%73%28%74%2E%74%29%7D%7B%73%2E%73%28%72%29%2B%7A%2E%7A%7D#7alert%28%27boo%21%27%29

Decoded Version:
{z=(1==4)?here:{z:(1!=5)?'':be}}
{y=(9==2)?dragons:{y:'l'+z.z}}
{x=(6==5)?3:{x:'a'+y.y}}
{w=(5==8)?9:{w:'ev'+x.x}}
{v=(7==9)?3:{v:'tr(2)'+z.z}}
{u=(3==8)?4:{u:'sh.subs'+v.v}}
{t=(6==2)?6:{t:y.y+'ocation.ha'+u.u}}
{s=(4==3)?3:{s:(8!=3)?(2)[w.w]:z}}
{r=s.s(t.t)}
{s.s(r)+z.z}


On the first line is the name of the inventor, next is the url/post
body used (I think this is important as it indicates how certain chars
may need to be url encoded),
next section is the broken down vector.

It would be nice to have an explanation in english along with every
vector. But I am not sure about the feasibility because we have too
many vectors.

we could collect all the entries now and then add explanation
gradually.

What do you guys think?

Regards,
Kishor

On Oct 1, 3:56 am, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:

Gareth

unread,
Oct 1, 2007, 9:49:13 AM10/1/07
to PHPIDS » Web Application Security 2.0
Yeah I would do it now and again, we've got so much to go through
though :)

On Oct 1, 2:13 pm, kishord <kishor.t...@gmail.com> wrote:
> Thats a great idea!
>
> Actually I had thought about this some days ago, and collected few
> vectors.
>
> Here is how an entry in the list looked like..
>
> 1 Thornmaker
> *************************************************************

> URL/POST:http://demo.php-ids.org/?test=%7B%7A%3D%28%31%3D%3D%34%29%3F%68%65%72...

Mario Heiderich

unread,
Oct 1, 2007, 9:51:36 AM10/1/07
to php...@googlegroups.com
So - what tool should we use to maintain the collection. Any suggestions?

2007/10/1, Gareth <gazh...@gmail.com>:



--
_______________________
php-ids.org

SirDarckCat

unread,
Oct 13, 2007, 1:05:23 AM10/13/07
to PHPIDS » Web Application Security 2.0
A wiki would be awezome, count me in.

Greetz!!

can

unread,
Oct 23, 2007, 11:43:50 AM10/23/07
to PHPIDS » Web Application Security 2.0
great idea, but i would prefer a more comfortable wiki than dokuwiki.
dokuwiki is unfortunately the only wiki i worked with, but i think
there must be some better ones..
surly someone has more expirences with different wikis than me.
a good site for comparing the functionalities is wikimatrix.org


On 1 Okt., 09:56, Mario Heiderich <Mario.Heider...@googlemail.com>
wrote:

Mario Heiderich

unread,
Oct 23, 2007, 11:49:13 AM10/23/07
to php...@googlegroups.com
Nice hint can - I will take a deeper look as soon as I find some time!

2007/10/23, can <christian...@googlemail.com>:
Reply all
Reply to author
Forward
0 new messages