<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Sec &#34;IP&#34; nix &#187; Web Application Security</title>
	<atom:link href="http://www.ugurengin.com/blog/category/web-application-security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.ugurengin.com/blog</link>
	<description>Uğur Engin</description>
	<lastBuildDate>Fri, 03 Feb 2012 23:00:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Nikto2  with LibWhisker Fast Installation Code</title>
		<link>http://www.ugurengin.com/blog/nikto2-with-libwhisker-fast-installation-code.html</link>
		<comments>http://www.ugurengin.com/blog/nikto2-with-libwhisker-fast-installation-code.html#comments</comments>
		<pubDate>Fri, 25 Dec 2009 08:01:58 +0000</pubDate>
		<dc:creator>Uğur Engin</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[LibWhisker]]></category>
		<category><![CDATA[Nikto2]]></category>
		<category><![CDATA[Web Scanner]]></category>

		<guid isPermaLink="false">http://ugurengin.com/blog/?p=413</guid>
		<description><![CDATA[Nikto2  ve  LibWhisker kutuphanesini, asagida yazdigim ufak bash scripti ile  hizlica kurabilirsiniz. Shell de ilgili scripti .sh formatinda kaydettikten sonra permission degerini 755 olarak set edip Nikto web security scanner  uygulamanizi hızlıca kurup kullanabilirsiniz. Not: Scriptin orjinal/duzgun halini buradan gorebilirsiniz. Centos 5.4 x86-64  isletim sistemlerinde test edilmistir. #/bin/bash #GNU&#124;Nikto2 WAS (Web Application Scanner) Fast Installation [...]]]></description>
			<content:encoded><![CDATA[<p>Nikto2  ve  LibWhisker kutuphanesini, asagida yazdigim ufak bash scripti ile  hizlica kurabilirsiniz. Shell de ilgili scripti .sh formatinda kaydettikten sonra permission degerini 755 olarak set edip Nikto web security scanner  uygulamanizi hızlıca kurup kullanabilirsiniz.</p>
<p>Not: Scriptin orjinal/duzgun halini<strong> <a title="Nikto2 Web Security Scanner Fast Installation Code" href="http://sploit.ugurengin.com/nikto.txt" target="_blank">buradan</a></strong> gorebilirsiniz.<br />
Centos 5.4 x86-64  isletim sistemlerinde test edilmistir.</p>
<address> </address>
<address><span style="color: #008000;">#/bin/bash</span></address>
<address><span style="color: #008000;">#GNU|Nikto2 WAS (Web Application Scanner) Fast Installation</span></address>
<address><span style="color: #008000;"># Coded Ugur Engin</span></address>
<address><span style="color: #008000;">#http://ugurengin.com<br />
</span></address>
<address><span style="color: #008000;"> function start() {</span></address>
<address><span style="color: #008000;">read -p &#8220;Are you ready?&#8221;</span></address>
<address><span style="color: #008000;">}</span></address>
<address><span style="color: #008000;">start</span></address>
<address><span style="color: #008000;"> sleep 1<br />
</span></address>
<address><span style="color: #008000;">if [ $UID = 0 ]; then</span></address>
<address><span style="color: #008000;">wget http://cirt.net/nikto/nikto-current.tar.gz;</span></address>
<address><span style="color: #008000;">tar -xf nikto-current.tar.gz;</span></address>
<address><span style="color: #008000;">mv nikto-2.1.0 nikto;</span></address>
<address><span style="color: #008000;">rm -rf nikto-current.tar.gz;</span></address>
<address><span style="color: #008000;">cd nikto;</span></address>
<address><span style="color: #008000;">wget http://www.wiretrip.net/rfp/libwhisker/libwhisker2-current.tar.gz;</span></address>
<address><span style="color: #008000;">tar -xf libwhisker2-current.tar.gz;</span></address>
<address><span style="color: #008000;">rm -rf libwhisker2-current.tar.gz;</span></address>
<address><span style="color: #008000;">cd libwhisker2-2.4;</span></address>
<address><span style="color: #008000;">perl Makefile.pl lib &gt; log.txt</span></address>
<address><span style="color: #008000;">cp LW2.pm ../</span></address>
<address><span style="color: #008000;">cd ..</span></address>
<address><span style="color: #008000;">perl nikto.pl -update &gt; log.txt</span></address>
<address><span style="color: #008000;">echo &#8220;Installation completed&#8230;&#8221;;</span></address>
<address><span style="color: #008000;">exit 0;</span></address>
<address><span style="color: #008000;">else</span></address>
<address><span style="color: #008000;">echo &#8220;Please, receive Root Acces!&#8221; </span></address>
<address><span style="color: #008000;">su -c $0</span></address>
<address><span style="color: #008000;"> exit -1</span></address>
<address><span style="color: #008000;">fi</span></address>
<address> </address>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.ugurengin.com%2Fblog%2Fnikto2-with-libwhisker-fast-installation-code.html&amp;t=Nikto2%20%20with%20LibWhisker%20Fast%20Installation%20Code" id="facebook_share_both_413" style="font-size:11px; line-height:13px; font-family:'lucida grande',tahoma,verdana,arial,sans-serif; text-decoration:none; padding:2px 0 0 20px; height:16px; background:url(http://b.static.ak.fbcdn.net/images/share/facebook_share_icon.gif) no-repeat top left;">Share on Facebook</a>
	<script type="text/javascript">
	<!--
	var button = document.getElementById('facebook_share_link_413') || document.getElementById('facebook_share_icon_413') || document.getElementById('facebook_share_both_413') || document.getElementById('facebook_share_button_413');
	if (button) {
		button.onclick = function(e) {
			var url = this.href.replace(/share\.php/, 'sharer.php');
			window.open(url,'sharer','toolbar=0,status=0,width=626,height=436');
			return false;
		}
	
		if (button.id === 'facebook_share_button_413') {
			button.onmouseover = function(){
				this.style.color='#fff';
				this.style.borderColor = '#295582';
				this.style.backgroundColor = '#3b5998';
			}
			button.onmouseout = function(){
				this.style.color = '#3b5998';
				this.style.borderColor = '#d8dfea';
				this.style.backgroundColor = '#fff';
			}
		}
	}
	-->
	</script>
	]]></content:encoded>
			<wfw:commentRss>http://www.ugurengin.com/blog/nikto2-with-libwhisker-fast-installation-code.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WordPress Firewall Script-Plugin</title>
		<link>http://www.ugurengin.com/blog/wordpress-firewall-script-plugin.html</link>
		<comments>http://www.ugurengin.com/blog/wordpress-firewall-script-plugin.html#comments</comments>
		<pubDate>Sun, 12 Jul 2009 09:18:02 +0000</pubDate>
		<dc:creator>Uğur Engin</dc:creator>
				<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[wordpress security]]></category>
		<category><![CDATA[wp guvenligi]]></category>
		<category><![CDATA[wp plugin]]></category>

		<guid isPermaLink="false">http://ugurengin.com/blog/?p=142</guid>
		<description><![CDATA[WordPress Open Source alanında en basarili , devamlı kendini yenileyen ve harden (saglam) yapısı sebebi ile binlerce kisi hatta kitleler tarafindan tercih edilen bir blog sistemi.Pluginlerinde zaman zaman cikan web uygulama acikliklarini saymazsak ,default olarak bizlere sunulan simdiki WordPress  cok basarili ve guvenilir diyebilirim. Ben daha spesifik cozum arayan arkadaslar icin kendi blog sistemimde de [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;">WordPress Open Source alanında en basarili , devamlı kendini yenileyen ve harden (saglam) yapısı sebebi ile binlerce kisi hatta kitleler tarafindan tercih edilen bir blog sistemi.Pluginlerinde zaman zaman cikan web uygulama acikliklarini saymazsak ,default olarak bizlere sunulan simdiki WordPress  cok basarili ve guvenilir diyebilirim.</p>
<p style="text-align: center;"><a href="http://www.ugurengin.com/blog/img/wplogo.jpg" rel="lightbox[142]"><img class="aligncenter" src="http://www.ugurengin.com/blog/img/wplogo.jpg" alt="" width="210" height="197" /></a></p>
<p style="text-align: left;">Ben daha spesifik cozum arayan arkadaslar icin kendi blog sistemimde de kullandigim URL filtreleyen, wordpress icin yazilmis bir güvenlik kutuphanesin den bahsedecegim.Scriptin arayuzu asagidaki gibidir.</p>
<p style="text-align: center;"><a href="http://ugurengin.com/blog/img/wpsecscript.JPG" rel="lightbox[142]"><img class="aligncenter" src="http://ugurengin.com/blog/img/wpsecscript.JPG" alt="" width="544" height="337" /></a></p>
<p style="text-align: left;">Belirttigim script, wordpress de  exploit edilen web acikliklarindan buyuk oranda   korunmanizi  sagliyor, yani wordpress de kesfedilecek  (SQL Injection,Local Life İnclude) acikliklari bu plugin ile birlik de  sizin siteniz de execute edilemiyor.</p>
<p style="text-align: left;">Örnegin wordpress de kesfedilmesi muhtemel bir LFI acikligi olsun<br />
<span style="color: #008000;">http://ugurengin.com/blog/?s=../../../etc/passwd</span><br />
veya sql injection da kullanilan union,select,group_concat gibi sorgular vb.</p>
<p style="text-align: left;">Bu plugin ile birlikde ilgili ataklar calismayacaktir.Mantiginan bahsedelim isterseniz;<br />
Script kendi icerisinde  yukarıda parantez icinde belirttigim acikliklar da kullanilan sorgulari  loglayarak , ilgili acikliklarda kullanilan atak mekanizmasini pasif ediyor. Bunun yanında bir kac ozelligi daha sizler scripti aktif ettiginiz de goreceksiniz, en onemli olan kısımlara deginmeyi tercih ediyorum.Asagidaki resimde scriptin bir bolumunden fotosunu cektigim ekran goruntusunu gorebilirsiniz.</p>
<p style="text-align: center;"><a href="http://ugurengin.com/blog/img/wpfirewall.JPG" rel="lightbox[142]"><img class="aligncenter" src="http://ugurengin.com/blog/img/wpfirewall.JPG" alt="" width="608" height="367" /></a></p>
<p>Sitenize atak yapan kisinin network bilgilerini (Sadece  IP adresi ) ve yaptigi &#8220;atak turunu&#8221; mail olarak adresinize gondertebilirsiniz.</p>
<p style="text-align: center;"><a href="http://ugurengin.com/blog/img/xmail.JPG" rel="lightbox[142]"><img class="aligncenter" src="http://ugurengin.com/blog/img/xmail.JPG" alt="" width="372" height="207" /></a></p>
<p>Bunun yanında sitenize atak geldiginde ilgili script ile istediginiz özel bir hata sayfasina veya anasayfaya yonlendirmeniz de mumkun , tabi bu durumda saldırgan her adımda loglanmaya devem ediyor olacaktir.Asagidaki resim de ornegini gorebilirsiniz.</p>
<p><a href="http://ugurengin.com/blog/img/wpalert.jpg" rel="lightbox[142]"><img class="alignnone" src="http://ugurengin.com/blog/img/wpalert.jpg" alt="" width="472" height="260" /></a></p>
<p><span style="color: #ff6600;">Not  : Sunucu&#8217;nun onunde   IDS veya web server icin derlenmis  bir uygulama  ( Apache icin Mod Security) yoksa, kesinlik scriptleriniz icin guvenlik kutuphanesi gelistirmenizi , kullanmanızı oneririm.</span></p>
<p>Kendi sitenize, guvenligini test etmek icib kimi deneme amaclı web ataklari yapmak isteyebilirsiniz , dolayisiyla sizin yaptiginiz web atak turleri de loglanip belirttiginiz email adresine gonderiliyor olacaktir, bu durumdan bir zaman sonra sıkılabilirsiniz.</p>
<p>Bunun icin de scriptin ara yonetiminde, asagidaki bolume,</p>
<p style="text-align: center;"><a href="http://ugurengin.com/blog/img/list.jpg" rel="lightbox[142]"><img class="aligncenter" src="http://ugurengin.com/blog/img/list.jpg" alt="" width="498" height="142" /></a></p>
<p>belirtli bir &#8221; IP&#8221; (IP adresinin Statik olmasi sart degilse de, dinamik IP  girmek bir o kadar mantıksız) adresi girerseniz ilgili ataklar dan belirttiginiz  network muaf olacaktir.  Belirttiginiz network dan gelen atak parametrelerin de   plugin pasif olacak , ayrica bu ataklar loglanmayacaktir.</p>
<p>Scripti, wordpress blogunuza kurmak icin asagidaki linkler araciligiyla ilgili plugin&#8217;i indirip wordpress blogunuzda /wp-content/plugins/ klasorune yükledikten sonra wp plugins bolumunde scripti aktif edebilir,ayarlar (Settings) altinda &#8220;Firewall&#8221; isimli  bolumden diğer ayarlamalari yapabilirsiniz.</p>
<p>Scriptin indirme bilgileri.<br />
<a title="Plugin Download" href="http://ugurengin.com/wordpress-firewall.tar.gz" target="_self"><span style="color: #008080;">wordpress-firewall.tar.gz</span></a><br />
<span style="color: #008080;">md5 Hash  : e36d51e96b796294890f6afaea1c1e74<br />
</span></p>
<address><span style="color: #333399;">Daha detayli bilgi &gt;<br />
http://www.seoegghead.com/software/wordpress-firewall.seo</span><span style="color: #008080;"><br />
</span></address>
<p><span style="color: #ff6600;">Yazan : Ugur Engin<br />
Iletisim  : mail(at)ugurengin(dat)com</span></p>
<a href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.ugurengin.com%2Fblog%2Fwordpress-firewall-script-plugin.html&amp;t=Wordpress%20Firewall%20Script-Plugin" id="facebook_share_both_142" style="font-size:11px; line-height:13px; font-family:'lucida grande',tahoma,verdana,arial,sans-serif; text-decoration:none; padding:2px 0 0 20px; height:16px; background:url(http://b.static.ak.fbcdn.net/images/share/facebook_share_icon.gif) no-repeat top left;">Share on Facebook</a>
	<script type="text/javascript">
	<!--
	var button = document.getElementById('facebook_share_link_142') || document.getElementById('facebook_share_icon_142') || document.getElementById('facebook_share_both_142') || document.getElementById('facebook_share_button_142');
	if (button) {
		button.onclick = function(e) {
			var url = this.href.replace(/share\.php/, 'sharer.php');
			window.open(url,'sharer','toolbar=0,status=0,width=626,height=436');
			return false;
		}
	
		if (button.id === 'facebook_share_button_142') {
			button.onmouseover = function(){
				this.style.color='#fff';
				this.style.borderColor = '#295582';
				this.style.backgroundColor = '#3b5998';
			}
			button.onmouseout = function(){
				this.style.color = '#3b5998';
				this.style.borderColor = '#d8dfea';
				this.style.backgroundColor = '#fff';
			}
		}
	}
	-->
	</script>
	]]></content:encoded>
			<wfw:commentRss>http://www.ugurengin.com/blog/wordpress-firewall-script-plugin.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

