<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MattJay Security &#187; Web App</title>
	<atom:link href="http://www.mattjaysecurity.com/category/web-app/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mattjaysecurity.com</link>
	<description>The musings of a young information security professional on current security events.</description>
	<lastBuildDate>Wed, 02 Feb 2011 17:09:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
		<item>
		<title>Missing in Action -&gt; Return to Action</title>
		<link>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 23:56:35 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Personal]]></category>
		<category><![CDATA[Random]]></category>
		<category><![CDATA[Web App]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=105</guid>
		<description><![CDATA[So it has been about 6 months since I wrote a blog post and I’ve promised to myself to get back into it for the new year. I miss you all. I guess I should start by explaining my absence from the blogosphere as I had some pretty damn good reasons: I got a new [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: left;"><a href="http://www.mattjaysecurity.com/wp-content/uploads/2010/12/2010-06-24-13.19.26.jpg#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed"><img class="size-medium wp-image-110 aligncenter" title="2010-06-24 13.19.26" src="http://www.mattjaysecurity.com/wp-content/uploads/2010/12/2010-06-24-13.19.26-e1293754164746-300x195.jpg" alt="" width="300" height="195" /></a>So  it has been about 6 months since I wrote a blog post and I’ve promised  to myself to get back into it for the new year. I miss you all. I guess I  should start by explaining my absence from the blogosphere as I had  some pretty damn good reasons:</p>
<ol>
<li>I got a new job</li>
<li>Said job was 3000 miles away</li>
<li><a href="http://www.google.com/maps?f=d&amp;source=s_d&amp;saddr=new+york,+ny&amp;daddr=San+Francisco,+CA&amp;hl=en&amp;geocode=FXFAbQIdK8KW-yk7CD_TpU_CiTFi_nfhBo8LyA%3BFVJmQAIdKAe0-CkhAGkAbZqFgDH_rXbwZxNQSg&amp;mra=ls&amp;sll=37.0625,-95.677068&amp;sspn=53.741627,95.009766&amp;ie=UTF8&amp;ll=39.774769,-98.173828&amp;spn=52.041139,95.009766&amp;t=h&amp;z=4">I drove the 3000 miles</a></li>
<li>First week in new location my house was broken into and my computers were among the more than $5k worth of stuff stolen.</li>
<li>I had just blown all my money moving 3000 miles =no way to replace computer (or go to BlackHat/Defcon/BSidesLV <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_sad.gif' alt=':(' class='wp-smiley' /> </li>
<li>New job has been keeping me supremely busy in a good way.</li>
</ol>
<p style="text-align: left;">This  whole extravaganza started in May so the summer was kind of a whirlwind  of craziness, the fall was work kicking into overdrive. I’ve kind of  hit my stride at the new job and gotten used to the giant piles of work  so I’m planning on setting aside time to blog again.</p>
<p>The job I started was at <a href="http://www.whitehatsec.com/">WhiteHat Security</a> as a resident appsec bug hunter. Drinking from a fire hose for 6 months  would be no exaggeration as we have a very unique playground of  websites to find/test vulnerabilities on. I’ve found some very high  profile vulnerabilities that I wish I could talk about but I’ll have to  settle for severely obfuscated posts in the future merely describing the  attack vector with all client information withheld.</p>
<p>Since I joined the team we have about doubled in size and gone from the “Operations” department to <a href="http://www.whitehatsec.com/home/services/threat_research.html">WhiteHat’s “Threat Research Center”</a> which just sounds so muchs spiffier and more official.</p>
<p>We also participated pretty avidly in the Google bug bounty program. Mighty successfully I might add: <a href="http://www.google.com/corporate/halloffame.html">Google Security Hall of Fame</a>.  5 people on our team found rewardable bugs in Google apps. I say  rewardable because a number of us found bugs that they didn’t qualify as  rewardable, mostly minor XSS or open redirects.</p>
<p>I might add that this is 5 <strong>so far</strong>, we have a few more emails sitting in their queue and I’ve had a bit of fun with their<a href="http://www.google.com/chromeos/pilot-program-cr48.html"> Cr-48 as a beta tester </a> <img src='http://www.mattjaysecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  (more details to come after bug is reported and fixed but this one is a fun one).</p>
<p>So  there is a run down of my absence from the blog world, cliff notes of  course. I did a fair amount of weekend getaways enjoying the west coast  weather.</p>
<p style="text-align: left;">I  hope anybody reading this had a great Christmas and will have a safe  and happy new year. My better half put a grill / smoker under the tree  for me and I’ll be breaking that out to ring in 2011 with some smoked  meat.<br />
So  now that you know one of my resolutions is to start blogging again what  are some of yours? I miss you. You look great by the way.</p>
<p>Cheers,<br />
Matty Jay</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;bodytext=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;notes=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;t=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;annotation=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;title=Missing%20in%20Action%20-%3E%20Return%20to%20Action" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F&amp;t=Missing%20in%20Action%20-%3E%20Return%20to%20Action&amp;s=So%20%20it%20has%20been%20about%206%20months%20since%20I%20wrote%20a%20blog%20post%20and%20I%E2%80%99ve%20promised%20%20to%20myself%20to%20get%20back%20into%20it%20for%20the%20new%20year.%20I%20miss%20you%20all.%20I%20guess%20I%20%20should%20start%20by%20explaining%20my%20absence%20from%20the%20blogosphere%20as%20I%20had%20%20some%20pretty%20damn%20good%20reason" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  href="http://twitter.com/home?status=Missing%20in%20Action%20-%3E%20Return%20to%20Action%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2010%2F12%2Fmissing-in-action-return-to-action%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2010/12/missing-in-action-return-to-action/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Attack These Apps</title>
		<link>http://www.mattjaysecurity.com/2009/05/attack-these-apps/#utm_source=feed&#038;utm_medium=feed&#038;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2009/05/attack-these-apps/#comments</comments>
		<pubDate>Sat, 30 May 2009 06:38:13 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Educational]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Web App]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=51</guid>
		<description><![CDATA[I&#8217;ve been messing around a bit with some purposefully vulnerable web applications and beating them up as best I can. My problem for a while was my inexperience with Linux and the lack of documentation for some of the applications I was using. So instead of spending a lot of time learning to hack and [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been messing around a bit with some purposefully vulnerable web applications and beating them up as best I can.  My problem for a while was my inexperience with Linux and the lack of documentation for some of the applications I was using.</p>
<p>So instead of spending a lot of time learning to hack and defend I was spending a lot of time getting my java set up correctly and editing some of the shell scripts so they would stop complaining.</p>
<p>I figured I can&#8217;t be the only one who has these kinds of troubles so I started a fresh install of Ubuntu updated it, and i got a number of the web apps I was having trouble with up and running properly and decided I would distribute it to save some people who just want to get to the hacking all ready some time and headaches in installing all of these things.</p>
<p>Like I said, this is my first write up on this sort of stuff so be gentle but here is some of the guidance I can give you in getting these apps up and hackable.</p>
<p>First of all you can download the .ova file <a href="http://mattjaysecurity.com/Attack_This_App_Appliance.ova">HERE</a> for now.  It is pretty big I apologize maybe on my next release I&#8217;ll try to use Debian or something so the lack of GUI will get it under a gig.</p>
<p>Use whichever VM software you prefer I know VMware accepts .ova files but if you&#8217;re using Fusion you might have to create a .vmx file for it.</p>
<p>It should log you in automatically but the info is<br />
UN: hacker<br />
PW: p@ssword<br />
(please change the credentials ASAP!)</p>
<p>First you&#8217;re going to have to start apache-tomcat<br />
<b><br />
$ cd Desktop/apache-tomcat-6.0.18/bin<br />
$ sh startup.sh<br />
Using CATALINA_BASE:   /home/hacker/Desktop/apache-tomcat-6.0.18<br />
Using CATALINA_HOME:   /home/hacker/Desktop/apache-tomcat-6.0.18<br />
Using CATALINA_TMPDIR: /home/hacker/Desktop/apache-tomcat-6.0.18/temp<br />
Using JRE_HOME:       /usr<br />
$<br />
</b></p>
<p>You should be good, but to check open firefox and go to http://localhost:8080 and you should see the tomcat intro page.</p>
<p>Once tomcat is up and running you can start up WebGoat (and the fun begins!)</p>
<p>Navigate back to /Desktop<br />
<b><br />
$ cd WebGoat-5.2/<br />
$ sudo sh webgoat.sh start8080<br />
(reminder: the sudo password for the default account is p@ssword which I hope you will change!)<br />
note: sometimes after you start tomcat the first time starting WebGoat will get stuck at this:<br />
at org.apache.catalina.startup.Bootstrap.main(Bootstrap.java:409)<br />
</b></p>
<p>If this happens just restart the VM and start WebGoat again it should go all the way through to here: <b><br />
INFO: Severver startup in XXXX ms</b><br />
where the X&#8217;s are numbers.</p>
<p>Now you can open Firefox again and navigate to http://localhost:8080/WebGoat/attack/</p>
<p>It will ask you for a username and password which are both &#8220;guest&#8221;</p>
<p>Click the &#8220;Start WebGoat&#8221; button and go nuts. (I am aiming to do some write-ups on how to get through some of the lessons soon).</p>
<p>In order to start up the burp proxy that allows you to complete some of the WebGoat lessons just navigate back to the Destop and:<br />
<b><br />
$ cd burpsuite_v1.2.01/<br />
$ java -jar burpsuite_v1.2.01.jar<br />
</b></p>
<p>Easy enough.</p>
<p>The rest of the web apps are much easier and less buggy but also less step by step educational.  These are just kind of put up and have fun in whichever way you want, the developers suggest looking at the <a href="http://www.owasp.org/index.php/Top_10_2007">OWASP Top Ten</a> picking one and trying it out.</p>
<p>The rest just require you to start up some LAMPP<br />
<b><br />
$ sudo /opt/lampp/lampp start<br />
</b></p>
<p>Check if it started up by going to http://localhost/ and seeing the XAMPP page.</p>
<p>Now the other vulnerable web apps are preloaded so all you have to do is navigate to them:</p>
<p>http://localhost/mutillidae</p>
<p>http://localhost/DVWA</p>
<p>Here are some other resources to look at to play with if you are interested in this area:</p>
<p><a href="http://www.bonsai-sec.com/en/research/moth.php">Moth</a> &#8211; a VMware image with a set of vulnerable Web Applications and scripts. <i>I haven&#8217;t gotten a chance to sit down and play with this one but it has come highly recommended </i></p>
<p><a href="http://samurai.inguardians.com/#">Samurai WTF</a> &#8211; The Samurai Web Testing Framework is a live linux environment that has been pre-configured to function as a web pen-testing environment. <i>Consider it the BackTrack of web apps.</i></p>
<p>That is all I&#8217;ve got for now, hopefully I&#8217;ll sit down and make some instructional screen cap videos in the near future.</p>
<p>Special thanks to <a href="http://portswigger.net/suite/">Port Swigger</a>, <a href="http://www.ethicalhack3r.co.uk/damn-vulnerable-web-app/">Damn Vulnerable Web App</a>, <a href="http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project">OWASP WebGoat</a>, and <a href="http://www.irongeek.com/">Iron Geek</a> for giving me permission to distribute your applications. I appreciate it and I hope you guys keep up the amazing work.</p>
<p>Again download the VM: <a href="http://mattjaysecurity.com/Attack_This_App_Appliance.ova">HERE</a></p>
<p>Hope you enjoy and please let me know any ways you&#8217;d like me to make this better and re-release.</p>
<p>Matt</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F&amp;title=Attack%20These%20Apps&amp;bodytext=I%27ve%20been%20messing%20around%20a%20bit%20with%20some%20purposefully%20vulnerable%20web%20applications%20and%20beating%20them%20up%20as%20best%20I%20can.%20%20My%20problem%20for%20a%20while%20was%20my%20inexperience%20with%20Linux%20and%20the%20lack%20of%20documentation%20for%20some%20of%20the%20applications%20I%20was%20using.%0D%0A%0D%0ASo%20" title="Digg"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://delicious.com/post?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F&amp;title=Attack%20These%20Apps&amp;notes=I%27ve%20been%20messing%20around%20a%20bit%20with%20some%20purposefully%20vulnerable%20web%20applications%20and%20beating%20them%20up%20as%20best%20I%20can.%20%20My%20problem%20for%20a%20while%20was%20my%20inexperience%20with%20Linux%20and%20the%20lack%20of%20documentation%20for%20some%20of%20the%20applications%20I%20was%20using.%0D%0A%0D%0ASo%20" title="del.icio.us"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.facebook.com/share.php?u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F&amp;t=Attack%20These%20Apps" title="Facebook"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F&amp;title=Attack%20These%20Apps&amp;annotation=I%27ve%20been%20messing%20around%20a%20bit%20with%20some%20purposefully%20vulnerable%20web%20applications%20and%20beating%20them%20up%20as%20best%20I%20can.%20%20My%20problem%20for%20a%20while%20was%20my%20inexperience%20with%20Linux%20and%20the%20lack%20of%20documentation%20for%20some%20of%20the%20applications%20I%20was%20using.%0D%0A%0D%0ASo%20" title="Google Bookmarks"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F&amp;title=Attack%20These%20Apps&amp;source=MattJay+Security+The+musings+of+a+young+information+security+professional+on+current+security+events.&amp;summary=I%27ve%20been%20messing%20around%20a%20bit%20with%20some%20purposefully%20vulnerable%20web%20applications%20and%20beating%20them%20up%20as%20best%20I%20can.%20%20My%20problem%20for%20a%20while%20was%20my%20inexperience%20with%20Linux%20and%20the%20lack%20of%20documentation%20for%20some%20of%20the%20applications%20I%20was%20using.%0D%0A%0D%0ASo%20" title="LinkedIn"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://slashdot.org/bookmark.pl?title=Attack%20These%20Apps&amp;url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F" title="Slashdot"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F&amp;title=Attack%20These%20Apps" title="StumbleUpon"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://reddit.com/submit?url=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F&amp;title=Attack%20These%20Apps" title="Reddit"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/reddit.png" title="Reddit" alt="Reddit" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  href="http://www.tumblr.com/share?v=3&amp;u=http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F&amp;t=Attack%20These%20Apps&amp;s=I%27ve%20been%20messing%20around%20a%20bit%20with%20some%20purposefully%20vulnerable%20web%20applications%20and%20beating%20them%20up%20as%20best%20I%20can.%20%20My%20problem%20for%20a%20while%20was%20my%20inexperience%20with%20Linux%20and%20the%20lack%20of%20documentation%20for%20some%20of%20the%20applications%20I%20was%20using.%0D%0A%0D%0ASo%20" title="Tumblr"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/tumblr.png" title="Tumblr" alt="Tumblr" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  href="http://twitter.com/home?status=Attack%20These%20Apps%20-%20http%3A%2F%2Fwww.mattjaysecurity.com%2F2009%2F05%2Fattack-these-apps%2F" title="Twitter"><img src="http://www.mattjaysecurity.com/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/05/attack-these-apps/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

