<?xml version="1.0" encoding="ISO-8859-1" ?>

 <rss version="2.0">
<channel>
    <title>Dror Shalev Security workshop</title> 
    <link>http://sec.drorshalev.com</link> 
    <description>This Internet Security workshop deal with recent security and privacy 	online threats .
	This demonstrations WILL NOT harm your PC.
	Please don't use this source for other uses ,except doing good to the world .
	feel free to Copy and Pasta :-) !
	Peace and Love,	Dror.
		</description> 

    <language>en-us</language> 
    <copyright>Copyright 2005 by dror shalev</copyright> 
    <managingEditor>drorshalev@yahoo.com</managingEditor> 
    <webMaster>drorshalev@yahoo.com</webMaster> 
    <image>
        <title>Dror Shalev Security workshop</title> 
        <url>http://sec.drorshalev.com/images/logo.gif</url> 
        <link>http://sec.drorshalev.com/</link> 
        <width>160</width> 
        <height>40</height> 
        <description>Dror Shalev Security workshop</description> 
    </image>

<item>

        <title> focus stealing vulnerabilities  </title> 
    <link>http://sec.drorshalev.com/dev/focus/</link> 
    <description> MSIE upload    by Michal Zalewski  </description> 
    </item>

        <title> focus stealing vulnerabilities , MSIE Paste & Steal file  </title> 
    <link>http://sec.drorshalev.com/dev/focus/1.htm</link> 
    <description>  MSIE Paste & Steal file demo ,  my ver </description> 
    </item>


	<item>

        <title> GreenBorder Online Security Test  </title> 
    <link>http://www.greenborder.com/test/GreenBorder-Security-Test.hta</link> 
    <description> HTA + IE at it best  , my ver , GreenBorder Online Security Test  

</description> 
    </item>



	<item>

        <title>IE Exploits Threats , Tel-Aviv University |11-2-07</title> 
    <link>
https://secure11.brinkster.com/drorshalev/tausec</link> 
    <description> IE Exploits Threats History,  JavaScript evasion techniques, Heap Spray, Ajax worm 

</description> 
    </item>





	<item>

        <title>IE WMF downloader</title> 
    <link>http://sec.drorshalev.com/dev/wmf/exploit.htm</link> 
    <description> Buffer Overrun on WMF files demo , on the wild , my Spyware vendor

</description> 
    </item>
	<item>

        <title>IE WMF downloader tool</title> 
    <link>http://sec.drorshalev.com/dev/wmf/ms06-001.exe</link> 
    <description> tool , make your own WMF downloader that run your Exe after crash

</description> 
    </item>
<item>

        <title>IE  mshtml.dll DOS</title> 
    <link>http://sec.drorshalev.com/dev/crash/CrashIEsrc1.htm</link> 
    <description> IE crash via  mshtml.dll Denial of Service by ,Christian Deneke, Thomas Waldegger 

</description> 
    </item>
		<item>

        <title>IE Crash1 datasrc </title> 
    <link>http://sec.drorshalev.com/dev/crash/CrashIEsrc.htm</link> 
    <description> IE crash via  datasrc Denial of Service ,by Christian Deneke, Thomas Waldegger 

</description> 
    </item>   
	<item>

        <title>IE Killer Nested Style </title> 
    <link>http://sec.drorshalev.com/dev/crash/img1.htm</link> 
    <description> IE crash via nested Style

</description> 
    </item>
	
	

	<item>

        <title>IE Killer Nested Style </title> 
    <link>http://sec.drorshalev.com/dev/crash/test1.htm</link> 
    <description> IE crash via nested Style , my ver , can lead to Remote compermise

</description> 
    </item>
	
	
<item>

        <title>IE Null Problemo </title> 
    <link>http://sec.drorshalev.com/dev/null/</link> 
    <description>Internet Explorer ignores NUL characters ,by heise Security 

</description> 
    </item>


<item>

        <title>IE Null Problemo </title> 
    <link>http://sec.drorshalev.com/dev/null/exploit.txt</link> 
    <description>[paper]Internet Explorer ignores NUL characters ,by heise Security 

</description> 
    </item>

	
	
	
	
<item>

        <title>Firefox URL Domain Name Buffer Overflow(IDN) </title> 
    <link>http://sec.drorshalev.com/dev/mozilla/idn.htm</link> 
    <description>Mozilla Kill - IDN Host: ,by Tom Ferris ,Firefox URL Domain Name Buffer Overflow(IDN) 

</description> 
    </item>


<item>

        <title>Sending Unlimited Nudge In Msn Messenger 7</title> 
    <link>http://sec.drorshalev.com/dev/honey/MsnNUDGE.htm</link> 
    <description>Tutorial For Sending Unlimited Nudge In Msn Messenger 7 !!! 
guyz Want to Play with ur friends while chatting on Msn Messenger?
by badboyz honey
</description> 
    </item>



<item>
    <title>Attacking MD5 (2 html with 1 md5)- Dan Kaminsky </title> 
    <link>http://sec.drorshalev.com/dev/hash/t1.htm</link> 
    <description>
Attacking MD5 ,Lockheed Martin page , md5sum
c0f3adb824590b40944614268e627421 
by Creazy Dan Kaminsky :-) 
http://www.doxpara.com/
</description> 
    </item>
<item>
    <title>Attacking MD5 (2 html with 1 md5)- Dan Kaminsky </title> 
    <link>http://sec.drorshalev.com/dev/hash/t2.htm</link> 
    <description>
Attacking MD5 ,Boeing   page , md5sum
c0f3adb824590b40944614268e627421 
by Creazy Dan Kaminsky :-)
http://www.doxpara.com/
</description> 
    </item>
<item>
    <title>Orkut - hacking an orkut ID </title> 
    <link>http://sec.drorshalev.com/dev/orkut/</link> 
    <description>
Orkut - hacking an orkut ID , Orkut Hacking Tutorial Pasted !!! by badboyz honey
</description> 
    </item>

 


<item>
    <title>Mozilla XPCOMM Race Conditions </title> 
    <link>http://sec.drorshalev.com/dev/mozilla/wrecko.html</link> 
    <description>
Mozilla XPCOMM Race Conditions , kill FireFox
</description> 
    </item>



 <item>
    <title>Jpeg Shit -again ICC  </title> 
    <link>http://sec.drorshalev.com/dev/jpeg/index.htm</link> 
    <description>Vulnerability in Microsoft Color Management Module Could Allow Remote Code Execution ,On the Wild , MS05-036  , 4 demos for malformed Jpeg
</description> 
    </item>





  <item>
    <title>Fox on Fire - Remote compermise FireFox</title> 
    <link>http://sec.drorshalev.com/dev/mozilla/FirefoxWallpaper.htm</link> 
    <description>Mozilla Firefox "Set As Wallpaper" Code Execution Exploit , by Michael Krax (Mikx)</description> 
    </item>

  <item>
    <title>Fox on Fire - Remote compermise FireFox</title> 
    <link>http://sec.drorshalev.com/dev/mozilla/FirefoxWallpaperMKDir.htm</link> 
    <description>Mozilla Firefox Set As Wallpaper make Dir, my ver</description> 
    </item>

  <item>
    <title>Base64 IMG dataFireFox</title> 
    <link>http://sec.drorshalev.com/dev/mozilla/FirefoxIMGElements.htm</link> 
    <description>Mozilla Firefox Base64 IMG data injection , by Michael Krax (Mikx)</description> 
    </item>



  <item>
    <title>Java Java  , Proxy ProxyA COM Object (javaprxy.dll) Could Cause IE Kill(MS05-037)-patced
</title> 
    <link>http://sec.drorshalev.com/dev/javaproxy/</link> 
    <description>A COM Object (javaprxy.dll) Could Cause IE Kill</description> 
    </item>

 	 
  <item>
    <title>Multi Broswer Spoofing Trick:dialog origin vulnerability
</title> 
    <link>http://sec.drorshalev.com/dev/spoof/multiple_browsers_dialog_origin_vulnerability_test.htm</link> 
    <description>dialog origin vulnerability   by  secunia</description> 
    </item>


  <item>
    <title>Adobe Reader 7 XML External Entity (XXE) Attack
</title> 
    <link>http://sec.drorshalev.com/dev/acrobat/BootIni.pdf</link> 
    <description>Raed And Steal BootIni</description> 
    </item>


  <item>
    <title>Adobe Reader 7 XML External Entity -Read TomCat Users
</title> 
    <link>http://sec.drorshalev.com/dev/acrobat/TomcatUsers.pdf</link> 
    <description>Raed And Steal EtcPasswd from Tomcat@win , by   Sverre H. </description> 
    </item>


  <item>
    <title>Adobe Reader 7 XML External Entity -Read and steal EtcPasswd
 </title> 
    <link>http://sec.drorshalev.com/dev/acrobat/EtcPasswd.pdf</link> 
    <description>Raed And Steal EtcPasswd from Linux  by   Sverre H. 
Huseb</description> 
    </item>





  <item>
    <title>
JS Ghost Script </title> 
    <link>http://sec.drorshalev.com/dev/spoof/exploit_javascript_ie_6_bug.htm</link> 
    <description>JS  Ghost  Script  by Pascal Vyncke,bl  </description> 
    </item>
  
    
  <item>
    <title>
MyMSN Hack</title> 
    <link>http://sec.drorshalev.com/dev/myMSN</link> 
    <description>Screens Shots, by   Dror Shalev 2-6-2005 </description> 
    </item>
  <item>
    <title>
MyMSN Hack</title> 
    <link>http://sec.drorshalev.com/dev/myMSN/MyMsnHack.jpg</link> 
    <description>MyMSN JS revealing someones privacy, by   Dror Shalev 2-6-2005 </description> 
    </item>
  <item>
     <title>
I want my Hotmail Back</title> 
    <link>http://sec.drorshalev.com/dev/hotmail/AccessDenied.JPG</link> 
    <description>After Prev Bug , My Hotmail [2002]	Account Was Cancelled By Hotmail, by   Dror Shalev 2002 </description> 
    </item>
   	
    
    
  <item>
    <title>
IE Crash on processing embedded files with endless loop  </title> 
    <link>http://sec.drorshalev.com/dev/dos/btf1.htm</link> 
    <description>IE Crash on processing embedded files with endless loop, by   Benjamin Tobias Franz </description> 
    </item>

 
<item>
    <title>
IE Crash on to many stack overflows  </title> 
    <link>http://sec.drorshalev.com/dev/dos/IECrash%20on%20to%20many%20stack%20overflows%20.htm</link> 
    <description>IE Crash on to many stack overflows, by   Benjamin Tobias Franz </description> 
    </item>

 <item>
    <title>
	IE Crash on JavaScript "window()"-calling</title> 
    <link>http://sec.drorshalev.com/dev/dos/bnf3.htm</link> 
    <description>IE Crash on JavaScript "window()"-calling,Description:There is a bug in Microsoft Internet Explorer, which causes a crash in it. The bug occurs, because Microsoft Internet Explorer can't handle a call to a JavaScript-function with the name of the "window"-object.The bug was fixed in an earlier version. But it works again. </description> 
</item>
<item>
    <title>MSSQL BrutForce via IE</title> 
    <link>http://sec.drorshalev.com/dev/sql/sqlbrut.hta</link> 
    <description>MSSQL Server Passwords Bruteforce via SQL Injection  HTA,PoC by offtopic</description> 
    </item>

 
   <item>
    <title>
MSSQL BrutForce via IE  [zip version]</title> 
    <link>http://sec.drorshalev.com/dev/sql/sqlbrut.zip</link> 
    <description>MSSQL Server Passwords Bruteforce via SQL Injection , by offtopic. </description> 
    </item>

 
       <item>
    <title>
FireFox cross platform remote compermise </title> 
    <link>http://sec.drorshalev.com/dev/mozilla/yourinfo.htm</link> 
    <description>firefox 1.0.3 spoof+auto dl  on the wild  , by John smith@mozilla.org </description> 
    </item>
       
        <item>
    <title>
FireFox cross platform remote compermise </title> 
    <link>http://sec.drorshalev.com/dev/mozilla/poc1.htm</link> 
    <description>Mozilla Firefox 1.0.3 Remote Arbitrary Code Execution Exploit  ,  by k-otik </description> 
    </item>
              
           					

    <item>
    <title>Cross Site Clicking </title> 
    <link>http://sec.drorshalev.com/dev/CrossSiteClick</link> 
    <description>Cross Site Clicking by Viper </description> 
    </item>
        
        <item>
    <title>
FireFox cross platform remote compermise </title> 
    <link>http://sec.drorshalev.com/dev/mozilla/poc.htm</link> 
    <description>favicon UniversalXPConnect  ,  by mikx </description> 
    </item>
 
      <item>
    <title>
FireFox firelinking </title> 
    <link>http://sec.drorshalev.com/dev/mozilla/firelinking.htm</link> 
    <description>favicon UniversalXPConnect  ,  by mikx </description> 
    </item>
    
          <item>
    <title>
IE DHTML Object handling Exploit </title> 
    <link>http://sec.drorshalev.com/dev/InternetExploiter/dhtml_node_entry.htm</link> 
    <description>Basic  Exploit ,   by idefense </description> 
    </item>
       
              <item>
    <title>
IE DHTML Object handling Exploit </title> 
    <link>http://sec.drorshalev.com/dev/InternetExploiter/InternetExploiter2.htm</link> 
    <description>InternetExploiter2 ShellCode via IE bug (second time),  by  Berend-Jan Wever </description> 
    </item>          	  
       
<item>
    <title>
IE DHTML Object handling Exploit </title> 
    <link>http://sec.drorshalev.com/dev/InternetExploiter/more.htm</link> 
    <description>more Crashes,  by    milw0rm.com </description> 
    </item>          	  
        
 


</channel>
</rss>
