djeaux logo
FasterSlasher RSS Newsfeed Display Script

FasterSlasher is a Perl script that displays a list of articles or headlines taken from a remote RSS or RDF file. Basically, you feed FasterSlasher the URL of an RSS file on the web & it will fetch the file, interpret the XML coding & display a nicely formatted list.

Output can be formatted for full-page display or SSI use. Other controls include the number of headlines/articles shown & whether descriptions are displayed in addition to titles.

XML parsing is handled by the Perl module XML::RSSLite. This is not a "standard" Perl module & your ISP may not support it. But it's easy to install locally in your own cgi-bin. (Details included in the download file.)

  • Example A: Headline listing embedded in this page using SSI. Display of item descriptions is enabled. The number of titles is set to allow this site's RSS list to "max out"...

    Bugtraq
    The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!

     
    CORE-2010-0311 - eFront-learning PHP file inclusion vulnerability
    <p>Posted by CORE Security Technologies Advisories on Mar 17</p> eFront-learning PHP file inclusion vulnerability<br> <br> 1. *Advisory Information*<br> <br> Title: eFront-learning PHP file inclusion vulnerability<br> Advisory Id: CORE-2010-0311<br> Advisory URL:<br> <a rel="nofollow" href="http://www.coresecurity.com/content/efront-php-file-inclusion">http://www.coresecurity.com/content/efront-php-file-inclusion</a><br> Date published: 2010-03-16<br> Date of last update: 2010-03-16<br> Vendors contacted: Vendor name<br> Release mode: Coordinated release<br> <br> 2. *Vulnerability Information*<br> <br> Class: PHP file inclusion [CWE-98]<br> Impact: Code...<br>
    Sahana 0.6.2.2 Authentication Bypass
    <p>Posted by Christopher on Mar 17</p>Ability to completely disable authentication via stream.php and commented<br> out module authentication code within it.<br> <br> <a rel="nofollow" href="http://victim/">http://victim/</a><sahana_path>/index.php?mod=admin&act=acl_enable_acl<br> Authenticates correctly.<br> <br> <a rel="nofollow" href="http://victim/">http://victim/</a><sahana_path>/stream.php?mod=admin&act=acl_enable_acl<br> Does not.<br>
    Secunia Research: Quicksilver Forums "mysqldump" Password Disclosure
    <p>Posted by Secunia Research on Mar 17</p>====================================================================== <br> <br> Secunia Research 17/03/2010<br> <br> - Quicksilver Forums "mysqldump" Password Disclosure -<br> <br> ====================================================================== <br> Table of Contents<br> <br> Affected Software....................................................1<br> Severity.............................................................2<br> Vendor's Description...<br>
    Secunia Research: Quicksilver Forums Cross-Site Request Forgery Vulnerability
    <p>Posted by Secunia Research on Mar 17</p>====================================================================== <br> <br> Secunia Research 17/03/2010<br> <br> - Quicksilver Forums Cross-Site Request Forgery Vulnerability -<br> <br> ====================================================================== <br> Table of Contents<br> <br> Affected Software....................................................1<br> Severity.............................................................2<br> Vendor's Description of...<br>
    Secunia Research: Quicksilver Forums Backup Information Disclosure
    <p>Posted by Secunia Research on Mar 17</p>====================================================================== <br> <br> Secunia Research 17/03/2010<br> <br> - Quicksilver Forums Backup Information Disclosure -<br> <br> ====================================================================== <br> Table of Contents<br> <br> Affected Software....................................................1<br> Severity.............................................................2<br> Vendor's Description of...<br>
    CORE-2009-0803: Virtual PC Hypervisor Memory Protection Vulnerability
    <p>Posted by CORE Security Technologies Advisories on Mar 17</p> Core Security Technologies - CoreLabs Advisory<br> <a rel="nofollow" href="http://www.coresecurity.com/corelabs/">http://www.coresecurity.com/corelabs/</a><br> <br> Virtual PC Hypervisor Memory Protection Vulnerability<br> <br> 1. *Advisory Information*<br> <br> Title: Virtual PC Hypervisor Memory Protection Vulnerability<br> Advisory Id: CORE-2009-0803<br> Advisory URL:<br> <a rel="nofollow" href="http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug">http://www.coresecurity.com/content/virtual-pc-2007-hypervisor-memory-protection-bug</a><br> Date published: 2010-03-16<br> Date of last update: 2010-03-16<br> Vendors...<br>
    Miranda IM silent TLS failure
    <p>Posted by Jan Schejbal on Mar 17</p>Summary:<br> Under certain conditions, Miranda ignores the "Use TLS" setting in <br> Jabber accounts and uses an unencrypted connection.<br> <br> Affected: Miranda IM (instant messenger), at least versions 0.8.16, <br> 0.9.0 alpha build #6 Unicode and SVN rev. 11383<br> <br> Description:<br> If the following conditions are met:<br> - "Use TLS" is enabled in the jabber account settings (Network - <br> Jabber - Account),<br> <br> - "Validate SSL certificates" is...<br>
    Vulnerabilities in VXDate for Joomla
    <p>Posted by MustLive on Mar 17</p>Hello Bugtraq!<br> <br> I want to warn you about vulnerabilities in component VXDate for Joomla.<br> <br> -----------------------------<br> Advisory: Vulnerabilities in VXDate for Joomla<br> -----------------------------<br> URL: <a rel="nofollow" href="http://websecurity.com.ua/3849/">http://websecurity.com.ua/3849/</a><br> -----------------------------<br> Timeline:<br> <br> 10.05.2009 - found the vulnerabilities.<br> 12.01.2010 - announced at my site.<br> 18.01.2010 - informed developers.<br> 13.03.2010 - disclosed at my site.<br> -----------------------------...<br>
    [CORELAN-10-13] - Windisc Local Stack BOF
    <p>Posted by Security on Mar 17</p><a rel="nofollow" href="http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-013-windisc-buffer-overflow-bnz">http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-013-windisc-buffer-overflow-bnz</a><br> <br> ------------------------------------------------------------------ <br> __ __ <br> _________ ________ / /___ _____ / /____ ____ _____ ___ <br> / ___/ __ / ___/ _ / / __ / __ / __/ _ / __ / __ __ <br> / /__/ /_/ / / / __/ / /_/ / / / / / /_/ __/ /_/ / / / / / /...<br>
    [security bulletin] HPSBGN02511 SSRT100022 rev.2 - HP Small Form Factor or Microtower PC with Broadcom Integrated NIC Firmware, Remote Execution of Arbitrary Code
    <p>Posted by security-alert on Mar 17</p>SUPPORT COMMUNICATION - SECURITY BULLETIN<br> <br> Document ID: c02048471<br> Version: 2<br> <br> HPSBGN02511 SSRT100022 rev.2 - HP Small Form Factor or Microtower PC with Broadcom Integrated NIC Firmware, Remote <br> Execution of Arbitrary Code<br> <br> NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.<br> <br> Release Date: 2010-03-15<br> Last Updated: 2010-03-16<br> <br> Potential Security Impact: Remote execution of arbitrary code<br> <br> Source:...<br>
    [USN-913-1] libpng vulnerabilities
    <p>Posted by Marc Deslauriers on Mar 16</p>===========================================================<br> Ubuntu Security Notice USN-913-1 March 16, 2010<br> libpng vulnerabilities<br> CVE-2009-2042, CVE-2010-0205<br> ===========================================================<br> <br> A security issue affects the following Ubuntu releases:<br> <br> Ubuntu 6.06 LTS<br> Ubuntu 8.04 LTS<br> Ubuntu 8.10<br> Ubuntu 9.04<br> Ubuntu 9.10<br> <br> This advisory also applies to the corresponding versions of<br> Kubuntu, Edubuntu, and Xubuntu....<br>
    Last Call for Papers, CONFidence 2010, 25-26May, Last Call for Papers
    <p>Posted by Andrzej Targosz on Mar 16</p>CONFidence 2010 Last Call for Papers<br> ####################################<br> <br> Calling all practitioners in the field of IT security! The 7th edition<br> of CONFidence 2010, is taking place in Krakow on May 25/26, 2010.<br> <a rel="nofollow" href="http://2010.confidence.org.pl">http://2010.confidence.org.pl</a><br> <br> We invite all to send the proposed topic and abstracts of presentation<br> till the 25th of March. Please, remember that CONFidence is an open,<br> international conference and all presentations should be given in...<br>
    ZDI-10-032: SAP MaxDB Malformed Handshake Request Remote Code Execution Vulnerability
    <p>Posted by ZDI Disclosures on Mar 16</p>ZDI-10-032: SAP MaxDB Malformed Handshake Request Remote Code Execution Vulnerability<br> <a rel="nofollow" href="http://www.zerodayinitiative.com/advisories/ZDI-10-032">http://www.zerodayinitiative.com/advisories/ZDI-10-032</a><br> March 16, 2010<br> <br> -- Affected Vendors:<br> SAP<br> <br> -- Affected Products:<br> SAP MaxDB<br> <br> -- TippingPoint(TM) IPS Customer Protection:<br> TippingPoint IPS customers have been protected against this<br> vulnerability by Digital Vaccine protection filter ID 9403. <br> For further product information on the TippingPoint IPS, visit:...<br>
    [USN-912-1] Audio File Library vulnerability
    <p>Posted by Marc Deslauriers on Mar 16</p>===========================================================<br> Ubuntu Security Notice USN-912-1 March 16, 2010<br> audiofile vulnerability<br> CVE-2008-5824<br> ===========================================================<br> <br> A security issue affects the following Ubuntu releases:<br> <br> Ubuntu 6.06 LTS<br> Ubuntu 8.04 LTS<br> Ubuntu 8.10<br> Ubuntu 9.04<br> Ubuntu 9.10<br> <br> This advisory also applies to the corresponding versions of<br> Kubuntu, Edubuntu, and Xubuntu.<br> <br> The problem...<br>
    ZDI-10-031: Apple Webkit Blink Event Dangling Pointer Remote Code Execution Vulnerability
    <p>Posted by ZDI Disclosures on Mar 16</p>ZDI-10-031: Apple Webkit Blink Event Dangling Pointer Remote Code Execution Vulnerability<br> <a rel="nofollow" href="http://www.zerodayinitiative.com/advisories/ZDI-10-031">http://www.zerodayinitiative.com/advisories/ZDI-10-031</a><br> March 16, 2010<br> <br> -- Affected Vendors:<br> Apple<br> <br> -- Affected Products:<br> Apple WebKit<br> <br> -- TippingPoint(TM) IPS Customer Protection:<br> TippingPoint IPS customers have been protected against this<br> vulnerability by Digital Vaccine protection filter ID 9598. <br> For further product information on the TippingPoint IPS,...<br>

    View the last 25 posts.

  • Example B: The link below will open a full-page display for kuro5hin.org & descriptions are provided in addition to titles...

    Open a full page listing with descriptions (kuro5hin.org uses verbose descriptions!).

  • Example C: The same headlines but without the descriptions & constrained to 8 headlines.

    Open a full page listing without descriptions

In general, the SSI method is easier for most folks to use, since style sheets & other markups can be set conventionally. The full-page method requires some editing of the Perl source in order to incorporate style sheets or fancy formatting.

DOWNLOAD
 

back to djeaux home page

©2003, Joe Cliburn