<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-11248384</id><updated>2012-01-31T09:20:53.442+01:00</updated><title type='text'>FalconDeOro Blogger</title><subtitle type='html'>Blog personal de FalconDeOro. Contaré cosas de mi vida, mis hobbies (informática y música) y otras cosas que me gusten.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://falcondeoro.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://falcondeoro.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>FalconDeOro</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>6</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-11248384.post-112271938819948513</id><published>2005-07-30T12:00:00.000+02:00</published><updated>2005-07-30T12:33:53.540+02:00</updated><title type='text'>Plugged-Blog XSS and SQL-Injection flaw &amp; Remove Admin</title><summary type='text'>###############################Plugged-Blog XSS and SQL-Injection flaw &amp; Remove Adminvendor url: http://www.pluggedout.comadvisory: http://falcondeoro.blogspot.com/2005/07/plugged-blog-xss-and-sql-injection.htmlvendor notify: yes exploit available: yes###############################Plugged-Blog is a CMS WebBlog-Portal content management systen, theinstall es very easy to use and configure,it's </summary><link rel='replies' type='application/atom+xml' href='http://falcondeoro.blogspot.com/feeds/112271938819948513/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11248384&amp;postID=112271938819948513' title='55 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/112271938819948513'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/112271938819948513'/><link rel='alternate' type='text/html' href='http://falcondeoro.blogspot.com/2005/07/plugged-blog-xss-and-sql-injection.html' title='Plugged-Blog XSS and SQL-Injection flaw &amp; Remove Admin'/><author><name>FalconDeOro</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>55</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11248384.post-112262830823209918</id><published>2005-07-29T11:09:00.000+02:00</published><updated>2005-07-29T12:59:12.906+02:00</updated><title type='text'>XSS flaws and data disclosure in Easyxp41</title><summary type='text'>################################################XSS flaws and data dliclosure in Easyxp41vendor url: http://www.easypx41.be/advisory: http://falcondeoro.blogspot.com/2005/07/xss-flaws-and-data-disclosure-in.htmlvendor notify: Yes exploit available: Yes##################################################Easyxp41 es a free script to make web portal.Yo can run it very easy.Easyxp41 , contains very </summary><link rel='replies' type='application/atom+xml' href='http://falcondeoro.blogspot.com/feeds/112262830823209918/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11248384&amp;postID=112262830823209918' title='58 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/112262830823209918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/112262830823209918'/><link rel='alternate' type='text/html' href='http://falcondeoro.blogspot.com/2005/07/xss-flaws-and-data-disclosure-in.html' title='XSS flaws and data disclosure in Easyxp41'/><author><name>FalconDeOro</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>58</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11248384.post-112197891324465169</id><published>2005-07-22T07:57:00.000+02:00</published><updated>2005-07-21T22:57:29.950+02:00</updated><title type='text'>SQL Injection &amp; XSS en la web de: counter-adiction.com</title><summary type='text'>Ante todo, decir que me resultó casi IMPOSIBLE ponerme en contacto con los administradores, no tienen email de contacto? si una web con 20 usuarios on-line no tiene email de contacto , y en el canal del quakenet nadie respondia, dejé varios mensajes, en querys y en mensajes generales. Espero que lo hayais visto.URL afectada: http://counter-adiction.comTipo de fallo: Sql Injection &amp; XSSBugs </summary><link rel='replies' type='application/atom+xml' href='http://falcondeoro.blogspot.com/feeds/112197891324465169/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11248384&amp;postID=112197891324465169' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/112197891324465169'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/112197891324465169'/><link rel='alternate' type='text/html' href='http://falcondeoro.blogspot.com/2005/07/sql-injection-xss-en-la-web-de-counter.html' title='SQL Injection &amp; XSS en la web de: counter-adiction.com'/><author><name>FalconDeOro</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11248384.post-111762899026891544</id><published>2005-06-01T14:21:00.000+02:00</published><updated>2005-06-01T14:31:49.373+02:00</updated><title type='text'>PayPal permite cambiar los precios</title><summary type='text'>Este fallo sirve para TODOS los vendedores que usen paypal.El fallo está confirmado por PayPal y tienen conciencia de este.En el caso de edonkey, por ejemplo , la url original es asi:https://www.paypal.com/cgi-bin/webscr?cmd=_xclick&amp;business=register@edonkey2000.com&amp;amp;item_name=eDonkey%20Pro&amp;item_number=1&amp;amount=19.95&amp;no_shipping=1&amp;return=http%3A%2F%2Fwww.overnet.com%2Fpaypal.php?cancel_return=</summary><link rel='replies' type='application/atom+xml' href='http://falcondeoro.blogspot.com/feeds/111762899026891544/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11248384&amp;postID=111762899026891544' title='2 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/111762899026891544'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/111762899026891544'/><link rel='alternate' type='text/html' href='http://falcondeoro.blogspot.com/2005/06/paypal-permite-cambiar-los-precios.html' title='PayPal permite cambiar los precios'/><author><name>FalconDeOro</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11248384.post-111004347712805756</id><published>2005-03-05T18:17:00.000+01:00</published><updated>2005-03-05T18:24:37.133+01:00</updated><title type='text'>Injeccion de comandos y XSS con phpcoin</title><summary type='text'>phpCOIN es un software libre , utilizado para webs de hosting resellers , ...bueno, directamente os lo copio de mi amigo lostmon , lo vereis más claramente:############sql injection:############dislose some sql data...http://[target]phpcoin/mod.php?mod=siteinfo&amp;id=1'ummm them ...http://[target]phpcoin/mod.php?mod=faq&amp;mode=show&amp;faq_id=2%20or%201=1http://[target]phpcoin/mod.php?mod=pages&amp;mode=view&amp;</summary><link rel='replies' type='application/atom+xml' href='http://falcondeoro.blogspot.com/feeds/111004347712805756/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11248384&amp;postID=111004347712805756' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/111004347712805756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/111004347712805756'/><link rel='alternate' type='text/html' href='http://falcondeoro.blogspot.com/2005/03/injeccion-de-comandos-y-xss-con.html' title='Injeccion de comandos y XSS con phpcoin'/><author><name>FalconDeOro</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-11248384.post-111001553309064989</id><published>2005-03-05T10:37:00.000+01:00</published><updated>2005-07-29T21:24:51.030+02:00</updated><title type='text'>Welcome!</title><summary type='text'>Today i start these new blog, in these blog, i post my bugs.</summary><link rel='replies' type='application/atom+xml' href='http://falcondeoro.blogspot.com/feeds/111001553309064989/comments/default' title='Enviar comentarios'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=11248384&amp;postID=111001553309064989' title='0 comentarios'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/111001553309064989'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11248384/posts/default/111001553309064989'/><link rel='alternate' type='text/html' href='http://falcondeoro.blogspot.com/2005/03/welcome.html' title='Welcome!'/><author><name>FalconDeOro</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
