<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress/2.6" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>SecuriTeam Blogs</title>
	<link>http://blogs.securiteam.com</link>
	<description>Thoughts about the world of security</description>
	<pubDate>Sat, 13 Mar 2010 09:41:44 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
			<item>
		<title>Ipswitch Means Business</title>
		<link>http://blogs.securiteam.com/index.php/archives/1323</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1323#comments</comments>
		<pubDate>Fri, 25 Sep 2009 22:46:31 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Culture</category>

		<category>Corporate Security</category>

		<category>Sec Tools</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1323</guid>
		<description><![CDATA[A while back I was fuzzing with Hzzp and found a remote format string vulnerability in Ipswitch&#8217;s WS_FTP. But, I couldn&#8217;t find a security contact for Ipswitch. I waited a few months and made the vulnerability public. The day afterwards, a representative from Ipswitch contacted me and I explained why I hadn&#8217;t contacted them previously. [...]]]></description>
			<content:encoded><![CDATA[<p>A while back I was fuzzing with Hzzp and found a remote format string vulnerability in Ipswitch&#8217;s WS_FTP. But, I couldn&#8217;t find a security contact for Ipswitch. I waited a few months and made the vulnerability public. The day afterwards, a representative from Ipswitch contacted me and I explained why I hadn&#8217;t contacted them previously. He was eager to get the vulnerability fixed and made the comment that they&#8217;ll need to do a better job publicizing the security contact information. I was happy to have had received a more professional, non-automated email from someone who seemed to care about the security of their company&#8217;s product.</p>
<p>I didn&#8217;t worry too much about the update process. I know it can take some companies months or even years to release new patches for vulnerabilities in their products, which most of the time is completely unreasonable. Then, a little more than two weeks later, I received an email from that same Ipswitch representative informing me that a new release of WS_FTP was available and the date in the Help-&gt;About window should say Sept 18th (10 days after we discussed the vulnerability). What an excellent example of how vendors should handle security issues within their products.</p>
<p>Fast response, efficient security policy, good business. Thanks Ipswitch!
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323&amp;title=Ipswitch+Means+Business"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323&amp;title=Ipswitch+Means+Business"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Ipswitch+Means+Business&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323&amp;title=Ipswitch+Means+Business"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323&amp;title=Ipswitch+Means+Business"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323&amp;title=Ipswitch+Means+Business"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323&amp;t=Ipswitch+Means+Business"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323&amp;title=Ipswitch+Means+Business"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Ipswitch+Means+Business&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1323" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Expose the security holes in your products during development. <a href="http://www.beyondsecurity.com/black-box-testing.html">Black Box Testing</a> makes it safer!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1323/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Linux Kernel Bashing</title>
		<link>http://blogs.securiteam.com/index.php/archives/1313</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1313#comments</comments>
		<pubDate>Fri, 14 Aug 2009 16:46:09 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Culture</category>

		<category>Insider Threat</category>

		<category>Networking</category>

		<category>Sec Tools</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1313</guid>
		<description><![CDATA[This summer may have caused a few burden&#8217;s on linux administrators. By all the patching necessary to keep their systems out of the hands of those who would choose to exploit it, unless your using something like Ksplice, you&#8217;ve more than likely rebooted many times already. Well, here is one more reason to wake this [...]]]></description>
			<content:encoded><![CDATA[<p>This summer may have caused a few burden&#8217;s on linux administrators. By all the patching necessary to keep their systems out of the hands of those who would choose to exploit it, unless your using something like <a href="http://www.ksplice.com">Ksplice</a>, you&#8217;ve more than likely rebooted many times already. Well, here is one more reason to wake this early this morning&#8230;</p>
<p>New exploits for the &#8220;Linux NULL pointer dereference due to incorrect proto_ops initializations&#8221; vulnerability have been released, <a href="http://www.milw0rm.com/exploits/9435">here</a> and <a href="http://www.milw0rm.com/exploits/9436">here</a>. I just tried the second one out myself on a (currently) fully updated Ubuntu Jaunty workstation, with (_default_) successful results.</p>
<p>linux@ubuntu:~/2009-proto_ops$ sh run.sh<br />
run.c: In function ‘main’:<br />
run.c:13: warning: missing sentinel in function call<br />
padlina z lublina!<br />
# id<br />
uid=0(root) gid=0(root) groups=4(adm),20(dialout),24(cdrom),46(plugdev)<br />
# exit<br />
linux@ubuntu:~/2009-proto_ops$</p>
<p>A reliable local root exploit for that affects all linux kernels 2.x. Feels like 2003 all over again :X
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313&amp;title=Linux+Kernel+Bashing"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313&amp;title=Linux+Kernel+Bashing"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Linux+Kernel+Bashing&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313&amp;title=Linux+Kernel+Bashing"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313&amp;title=Linux+Kernel+Bashing"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313&amp;title=Linux+Kernel+Bashing"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313&amp;t=Linux+Kernel+Bashing"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313&amp;title=Linux+Kernel+Bashing"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Linux+Kernel+Bashing&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1313" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safe from SQL Injection attacks. Signup for a daily <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1313/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Who Hacks the Hackers that Hack Hackers?</title>
		<link>http://blogs.securiteam.com/index.php/archives/1299</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1299#comments</comments>
		<pubDate>Sat, 11 Jul 2009 06:23:37 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Web</category>

		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Culture</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1299</guid>
		<description><![CDATA[Just thought I&#8217;d bring it up since there has been prolific chatter on the lists lately&#8230;

-
Expose the security holes in your products during development. Black Box Testing makes it safer!
]]></description>
			<content:encoded><![CDATA[<p>Just thought I&#8217;d bring it up since there has been <a href="http://seclists.org/fulldisclosure/2009/Jul">prolific chatter</a> on the lists lately&#8230;
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299&amp;title=Who+Hacks+the+Hackers+that+Hack+Hackers%3F"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299&amp;title=Who+Hacks+the+Hackers+that+Hack+Hackers%3F"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Who+Hacks+the+Hackers+that+Hack+Hackers%3F&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299&amp;title=Who+Hacks+the+Hackers+that+Hack+Hackers%3F"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299&amp;title=Who+Hacks+the+Hackers+that+Hack+Hackers%3F"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299&amp;title=Who+Hacks+the+Hackers+that+Hack+Hackers%3F"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299&amp;t=Who+Hacks+the+Hackers+that+Hack+Hackers%3F"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299&amp;title=Who+Hacks+the+Hackers+that+Hack+Hackers%3F"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Who+Hacks+the+Hackers+that+Hack+Hackers%3F&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1299" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Expose the security holes in your products during development. <a href="http://www.beyondsecurity.com/black-box-testing.html">Black Box Testing</a> makes it safer!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1299/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Phrack #66 is out!</title>
		<link>http://blogs.securiteam.com/index.php/archives/1291</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1291#comments</comments>
		<pubDate>Thu, 11 Jun 2009 16:34:50 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Culture</category>

		<category>Ask the Expert</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1291</guid>
		<description><![CDATA[0x01 Introduction
0x02 Phrack Prophile on The PaX Team
0x03 Phrack World News
0x04 Abusing the Objective C runtime
0x05 Backdooring Juniper Firewalls
0x06 Exploiting DLmalloc frees in 2009
0x07 Persistent BIOS infection
0x08 Exploiting UMA : FreeBSD kernel heap exploits
0x09 Exploiting TCP Persist Timer Infiniteness
0x0A Malloc Des-Maleficarum
0x0B A Real SMM Rootkit
0x0C Alphanumeric RISC ARM Shellcode
0x0D Power cell buffer overflow
0x0E Binary Mangling [...]]]></description>
			<content:encoded><![CDATA[<pre>0x01 Introduction
0x02 Phrack Prophile on The PaX Team
0x03 Phrack World News
0x04 Abusing the Objective C runtime
0x05 Backdooring Juniper Firewalls
0x06 Exploiting DLmalloc frees in 2009
0x07 Persistent BIOS infection
0x08 Exploiting UMA : FreeBSD kernel heap exploits
0x09 Exploiting TCP Persist Timer Infiniteness
0x0A Malloc Des-Maleficarum
0x0B A Real SMM Rootkit
0x0C Alphanumeric RISC ARM Shellcode
0x0D Power cell buffer overflow
0x0E Binary Mangling with Radare
0x0F Linux Kernel Heap Tempering Detection
0x10 Developing MacOSX Rootkits
0x11 How close are they of hacking your brain ?</pre>
<p>You can check it out <a href="http://www.phrack.org/issues.html?issue=66">here</a>.</p>
<p>Now we have something to keep us busy while the <a href="http://www.savetheinternet.com/">net neutrality</a> debates are going on&#8230;
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291&amp;title=Phrack+%2366+is+out%21"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291&amp;title=Phrack+%2366+is+out%21"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Phrack+%2366+is+out%21&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291&amp;title=Phrack+%2366+is+out%21"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291&amp;title=Phrack+%2366+is+out%21"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291&amp;title=Phrack+%2366+is+out%21"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291&amp;t=Phrack+%2366+is+out%21"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291&amp;title=Phrack+%2366+is+out%21"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Phrack+%2366+is+out%21&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1291" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Let the experts make sure your website is safe. <a href="http://www.beyondsecurity.com/vulnerability-assessment.html">Vulnerability Assessment</a> is the answer.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1291/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Severe T-Mobile Data Breach</title>
		<link>http://blogs.securiteam.com/index.php/archives/1288</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1288#comments</comments>
		<pubDate>Sat, 06 Jun 2009 21:23:15 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Law</category>

		<category>Culture</category>

		<category>Corporate Security</category>

		<category>Insider Threat</category>

		<category>Hacked</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1288</guid>
		<description><![CDATA[
From the looks of it, T-Mobile has been hacked and the goods stolen.
They also seem to love running HP-UX.

-
Is your site safe from SQL Injection attacks? Use an SQL Injection Scanner on a daily basis to protect your network!
]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://dailymobile.se/wp-content/uploads/2009/03/t-mobile400x320_1-30-09.gif" /></p>
<p>From the looks of <a href="http://seclists.org/fulldisclosure/2009/Jun/0062.html">it</a>, T-Mobile has been hacked and the goods stolen.</p>
<p>They also seem to love running HP-UX.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288&amp;title=Severe+T-Mobile+Data+Breach"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288&amp;title=Severe+T-Mobile+Data+Breach"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Severe+T-Mobile+Data+Breach&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288&amp;title=Severe+T-Mobile+Data+Breach"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288&amp;title=Severe+T-Mobile+Data+Breach"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288&amp;title=Severe+T-Mobile+Data+Breach"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288&amp;t=Severe+T-Mobile+Data+Breach"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288&amp;title=Severe+T-Mobile+Data+Breach"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Severe+T-Mobile+Data+Breach&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1288" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection attacks? Use an <a href="http://www.beyondsecurity.com/sql-injection.html">SQL Injection Scanner</a> on a daily basis to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1288/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Linux SCTP All Shook Up</title>
		<link>http://blogs.securiteam.com/index.php/archives/1278</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1278#comments</comments>
		<pubDate>Tue, 28 Apr 2009 19:39:14 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Corporate Security</category>

		<category>Sec Tools</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1278</guid>
		<description><![CDATA[
An exploit for the denial-of-service-considered remote SCTP vulnerability in the linux kernel has been released.
http://sgrakkyu.antifork.org/sctp_houdini.c
The exploit contains multiple targets and covers 32/64 bits architectures&#8230; play time started this morning =X

-
Is your site safe from SQL Injection? Website Security Audit is the way to protect your network!
]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://www.breakitdownblog.com/wp-content/uploads/2009/04/linux-penguin-tux.jpg" /></p>
<p>An exploit for the denial-of-service-considered remote SCTP vulnerability in the linux kernel has been released.</p>
<h3><a href="http://sgrakkyu.antifork.org/sctp_houdini.c"rel="nofollow" >http://sgrakkyu.antifork.org/sctp_houdini.c</a></h3>
<p>The exploit contains multiple targets and covers 32/64 bits architectures&#8230; play time started this morning =X
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278&amp;title=Linux+SCTP+All+Shook+Up"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278&amp;title=Linux+SCTP+All+Shook+Up"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Linux+SCTP+All+Shook+Up&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278&amp;title=Linux+SCTP+All+Shook+Up"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278&amp;title=Linux+SCTP+All+Shook+Up"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278&amp;title=Linux+SCTP+All+Shook+Up"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278&amp;t=Linux+SCTP+All+Shook+Up"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278&amp;title=Linux+SCTP+All+Shook+Up"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Linux+SCTP+All+Shook+Up&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1278" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection? <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">Website Security Audit</a> is the way to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1278/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Bugtraq SPAM</title>
		<link>http://blogs.securiteam.com/index.php/archives/1276</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1276#comments</comments>
		<pubDate>Tue, 21 Apr 2009 21:15:57 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Web</category>

		<category>Commentary</category>

		<category>Spam</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1276</guid>
		<description><![CDATA[It seems I get this IN MY INBOX everytime I post&#8230;
We have received your request to join the puitika
group hosted by Yahoo! Groups, a free, easy-to-use community service.
This request will expire in 7 days.
TO BECOME A MEMBER OF THE GROUP:
1) Go to the Yahoo! Groups site by clicking on this link:
http://groups.yahoo.com/i?i=oyhn042ed3ckqjsszqpggnyd5xxe0l1b&#38;e=0xjbrown41%40gmail%2Ecom
(If clicking doesn&#8217;t work, &#8220;Cut&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>It seems I get this IN MY INBOX everytime I post&#8230;</p>
<p>We have received your request to join the puitika<br />
group hosted by Yahoo! Groups, a free, easy-to-use community service.</p>
<p>This request will expire in 7 days.</p>
<p>TO BECOME A MEMBER OF THE GROUP:</p>
<p>1) Go to the Yahoo! Groups site by clicking on this link:<br />
<a href="http://groups.yahoo.com/i?i=oyhn042ed3ckqjsszqpggnyd5xxe0l1b&amp;e=0xjbrown41%40gmail%2Ecom">http://groups.yahoo.com/i?i=oyhn042ed3ckqjsszqpggnyd5xxe0l1b&amp;e=0xjbrown41%40gmail%2Ecom</a></p>
<p>(If clicking doesn&#8217;t work, &#8220;Cut&#8221; and &#8220;Paste&#8221; the line above into your<br />
Web browser&#8217;s address bar.)</p>
<p>-OR-</p>
<p>2) REPLY to this email by clicking &#8220;Reply&#8221; and then &#8220;Send&#8221;<br />
in your email program</p>
<p>If you did not request, or do not want, a membership in the<br />
puitika group, please accept our apologies<br />
and ignore this message.</p>
<p>Regards,</p>
<p>Yahoo! Groups Customer Care</p>
<p>Your use of Yahoo! Groups is subject to <a href="http://docs.yahoo.com/info/terms/">http://docs.yahoo.com/info/terms/</a>
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276&amp;title=Bugtraq+SPAM"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276&amp;title=Bugtraq+SPAM"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Bugtraq+SPAM&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276&amp;title=Bugtraq+SPAM"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276&amp;title=Bugtraq+SPAM"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276&amp;title=Bugtraq+SPAM"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276&amp;t=Bugtraq+SPAM"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276&amp;title=Bugtraq+SPAM"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Bugtraq+SPAM&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1276" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection attacks? Use an <a href="http://www.beyondsecurity.com/sql-injection.html">SQL Injection Scanner</a> on a daily basis to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1276/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Major Browsers Pwnd</title>
		<link>http://blogs.securiteam.com/index.php/archives/1267</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1267#comments</comments>
		<pubDate>Thu, 26 Mar 2009 04:42:01 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Web</category>

		<category>Microsoft</category>

		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Apple</category>

		<category>Corporate Security</category>

		<category>Sec Tools</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1267</guid>
		<description><![CDATA[
0day exploits for Internet Explorer, Firefox, and Safari were used to own machines at the Pwn2Own contest @ CanSecWest 2009. Is now the time for someone to port Windows 3.1 to MIPS and install a good telnet client? Roffles.
Credit www.dailygalaxy.com for the fierce FF/IE photo 

-
Let the experts make sure your website is safe. Vulnerability [...]]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://www.dailygalaxy.com/my_weblog/images/2008/03/26/firefox.jpg" /></p>
<p>0day exploits for Internet Explorer, Firefox, and Safari were used to own machines at the <a href="http://dvlabs.tippingpoint.com/blog/2009/03/18/pwn2own-2009-day-1---safari-internet-explorer-and-firefox-taken-down-by-four-zero-day-exploits">Pwn2Own</a> contest @ <a href="http://cansecwest.com">CanSecWest</a> 2009. Is now the time for someone to port Windows 3.1 to MIPS and install a good telnet client? Roffles.</p>
<p>Credit www.dailygalaxy.com for the fierce FF/IE photo <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267&amp;title=Major+Browsers+Pwnd"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267&amp;title=Major+Browsers+Pwnd"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Major+Browsers+Pwnd&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267&amp;title=Major+Browsers+Pwnd"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267&amp;title=Major+Browsers+Pwnd"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267&amp;title=Major+Browsers+Pwnd"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267&amp;t=Major+Browsers+Pwnd"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267&amp;title=Major+Browsers+Pwnd"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Major+Browsers+Pwnd&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1267" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Let the experts make sure your website is safe. <a href="http://www.beyondsecurity.com/vulnerability-assessment.html">Vulnerability Assessment</a> is the answer.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1267/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The R(evolution) of Bug Hunters</title>
		<link>http://blogs.securiteam.com/index.php/archives/1266</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1266#comments</comments>
		<pubDate>Tue, 24 Mar 2009 17:47:55 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1266</guid>
		<description><![CDATA[
Getting real money for computer security research is making its way from early development and ideas to mainstream, and bug hunters probably have mixed feelings, like teenagers. Its an interesting concept that might actually work. What will become of the vulnerability market when something like this becomes popular?
Either way, these guys are basically saying no [...]]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://trailofbits.files.wordpress.com/2009/03/nomorefreebugs.jpg?w=300&amp;h=181" /></p>
<p>Getting real money for computer security research is making its way from early development and ideas to mainstream, and bug hunters probably have mixed feelings, like teenagers. Its an <a rel="nofollow" href="http://www.securityfocus.com/brief/933">interesting concept</a> that might actually work. What will become of the vulnerability market when something like <a rel="nofollow" href="http://www.securityfocus.com/news/11437">this</a> becomes popular?</p>
<p>Either way, these guys are basically <a href="http://blog.trailofbits.com/2009/03/22/no-more-free-bugs/">saying</a> no more freeloading, Mr. Vendor.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266&amp;title=The+R%28evolution%29+of+Bug+Hunters"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266&amp;title=The+R%28evolution%29+of+Bug+Hunters"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=The+R%28evolution%29+of+Bug+Hunters&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266&amp;title=The+R%28evolution%29+of+Bug+Hunters"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266&amp;title=The+R%28evolution%29+of+Bug+Hunters"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266&amp;title=The+R%28evolution%29+of+Bug+Hunters"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266&amp;t=The+R%28evolution%29+of+Bug+Hunters"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266&amp;title=The+R%28evolution%29+of+Bug+Hunters"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=The+R%28evolution%29+of+Bug+Hunters&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1266" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection? <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">Website Security Audit</a> is the way to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1266/feed/</wfw:commentRss>
		</item>
		<item>
		<title>uCon Security Conference 2009</title>
		<link>http://blogs.securiteam.com/index.php/archives/1264</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1264#comments</comments>
		<pubDate>Fri, 20 Mar 2009 17:14:39 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1264</guid>
		<description><![CDATA[
uCon Security Conference 2009 materials have been released!


Advanced SQL Injection
Slides
&#160;


Hacking PDF Readers
Slides
&#160;


Intro to Windows Kernel Security Development
Slides
&#160;


From theory to practice: Bringing down the house with EXTENDED DHCP Exhausting Attack
Slides
&#160;


Practical (Introduction to) Reverse Engineering
Slides
&#160;


Secure Log Centralization, Analysis &#38; Security Visualization
Slides
&#160;


Ut cognitione visus: ut ipso intellecto - BinNavi v2
Slides
&#160;


GSM For Fun and Profit
Slides
&#160;


Dispelling the myths and discussing [...]]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://www.madeira.eng.br/storage/users/3/3/images/158/medium.png" /></p>
<p>uCon Security Conference 2009 materials have been <a href="http://www.ucon-conference.org/archives.php">released</a>!</p>
<table width="501">
<tr>
<td>Advanced SQL Injection</td>
<td><a href="http://www.ucon-conference.org/materials/2009/Advanced_SQL_Injection.ppt">Slides</a></td>
<td>&nbsp;</td>
</tr>
<tr>
<td>Hacking PDF Readers</td>
<td><a href="http://www.ucon-conference.org/materials/2009/HackingPDFReaders-uCon-2009.pdf">Slides</a></td>
<td>&nbsp;</td>
</tr>
<tr>
<td>Intro to Windows Kernel Security Development</td>
<td><a href="http://www.ucon-conference.org/materials/2009/Intro_NT_kernel_security_stuff.pdf">Slides</a></td>
<td>&nbsp;</td>
</tr>
<tr>
<td>From theory to practice: Bringing down the house with EXTENDED DHCP Exhausting Attack</td>
<td><a href="http://http//www.ucon-conference.org/materials/2009/uCon2009-EXTENDED_DHCP_Exhausting_Attack-public.pdf">Slides</a></td>
<td>&nbsp;</td>
</tr>
<tr>
<td>Practical (Introduction to) Reverse Engineering</td>
<td><a href="http://www.ucon-conference.org/materials/2009/Practical-Intro-to-RE.ppt">Slides</a></td>
<td>&nbsp;</td>
</tr>
<tr>
<td>Secure Log Centralization, Analysis &amp; Security Visualization</td>
<td><a href="http://www.ucon-conference.org/materials/2009/Secure-Log-Centralization.ppt">Slides</a></td>
<td>&nbsp;</td>
</tr>
<tr>
<td>Ut cognitione visus: ut ipso intellecto - BinNavi v2</td>
<td><a href="http://www.ucon-conference.org/materials/2009/ut_cognitione_visus-ut_ipso_intellecto.pdf">Slides</a></td>
<td>&nbsp;</td>
</tr>
<tr>
<td>GSM For Fun and Profit</td>
<td><a href="http://www.ucon-conference.org/materials/2009/GSM-for-fun-and-profit-uCon-2009.pdf">Slides</a></td>
<td>&nbsp;</td>
</tr>
<tr>
<td>Dispelling the myths and discussing the facts of global cyber-warfare</td>
<td>Slides</td>
<td>&nbsp;</td>
</tr>
<tr>
<td>Advanced Payload Strategies: What is new, what works and what is hoax?</td>
<td>Slides</td>
<td></td>
</tr>
</table>
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264&amp;title=uCon+Security+Conference+2009"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264&amp;title=uCon+Security+Conference+2009"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=uCon+Security+Conference+2009&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264&amp;title=uCon+Security+Conference+2009"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264&amp;title=uCon+Security+Conference+2009"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264&amp;title=uCon+Security+Conference+2009"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264&amp;t=uCon+Security+Conference+2009"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264&amp;title=uCon+Security+Conference+2009"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=uCon+Security+Conference+2009&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1264" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection attacks? Use an <a href="http://www.beyondsecurity.com/sql-injection.html">SQL Injection Scanner</a> on a daily basis to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1264/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DJBDNS Security Broken</title>
		<link>http://blogs.securiteam.com/index.php/archives/1257</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1257#comments</comments>
		<pubDate>Thu, 05 Mar 2009 16:37:22 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Corporate Security</category>

		<category>Networking</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1257</guid>
		<description><![CDATA[
According to this thread, DJBDNS&#8217;s security has officially been broken. A patch is available and the reward for the bug by Mr. Bernstein will be awarded to Matthew Dempsky. Quoting from the thread:
&#8220;If the administrator of example.com publishes the example.com DNS data through tinydns and axfrdns, and includes data for sub.example.com transferred from an untrusted [...]]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://tbn1.google.com/images?q=tbn:d8oJWdPGutoWjM:http://www.ultraviolet.org/Linux/powered-by-djbdns.gif" /></p>
<p>According to this <a href="http://marc.info/?l=djbdns&amp;m=123613000920446&amp;w=2">thread</a>, DJBDNS&#8217;s security has officially been broken. A patch is available and the reward for the bug by Mr. Bernstein will be awarded to Matthew Dempsky. Quoting from the thread:</p>
<p>&#8220;If the administrator of example.com publishes the example.com DNS data through tinydns and axfrdns, and includes data for sub.example.com transferred from an untrusted third party, then that third party can control cache entries for example.com, not just sub.example.com. This is the result of a bug in djbdns pointed out by Matthew Dempsky. (In short, axfrdns compresses some outgoing DNS packets incorrectly.)</p>
<p>Even though this bug affects very few users, it is a violation of the expected security policy in a reasonable situation, so it is a security hole in djbdns. Third-party DNS service is discouraged in the djbdns documentation but is nevertheless supported. Dempsky is hereby awarded $1000.</p>
<p>The next release of djbdns will be backed by a new security guarantee. In the meantime, if any users are in the situation described above, those users are advised to apply Dempsky&#8217;s patch and requested to accept my apologies. The patch is also recommended for other users; it corrects the bug without any side effects. A copy of the patch appears below.</p>
<p>&#8212;D. J. Bernstein</p>
<p>Research Professor, Computer Science, University of Illinois at Chicago&#8221;</p>
<p>I still believe <a href="http://www.guninski.com/where_do_you_want_billg_to_go_today_4.html">Georgi Guninski&#8217;s bug</a> was enough for a reward, but oh well. I wonder what the &#8220;new security guarentee&#8221; will be, anyway.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257&amp;title=DJBDNS+Security+Broken"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257&amp;title=DJBDNS+Security+Broken"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=DJBDNS+Security+Broken&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257&amp;title=DJBDNS+Security+Broken"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257&amp;title=DJBDNS+Security+Broken"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257&amp;title=DJBDNS+Security+Broken"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257&amp;t=DJBDNS+Security+Broken"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257&amp;title=DJBDNS+Security+Broken"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=DJBDNS+Security+Broken&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1257" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Expose the security holes in your products during development. <a href="http://www.beyondsecurity.com/black-box-testing.html">Black Box Testing</a> makes it safer!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1257/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Hack this and get what ever you want!</title>
		<link>http://blogs.securiteam.com/index.php/archives/1256</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1256#comments</comments>
		<pubDate>Sun, 01 Mar 2009 21:47:01 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Spam</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1256</guid>
		<description><![CDATA[
Emails from seemingly no where and from no one trustworthy.. haha
&#8220;Dear Hacker,
Manish from this side, i have a good hacking project on linux machine, configuration are below: please considue and if u are able to hack  this system our company can pay whatever u want.  or creat custom exploit that provide reverse shell . this [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://static.flickr.com/32/99805321_37ca1f6ada_o.jpg" /></p>
<p>Emails from seemingly no where and from no one trustworthy.. haha<br />
&#8220;Dear Hacker,</p>
<p>Manish from this side, i have a good hacking project on linux machine, configuration are below: please considue and if u are able to hack  this system our company can pay whatever u want.  or creat custom exploit that provide reverse shell . this server is online [ip address will be dilivered after project accepted by you] after u hack this system u just provide screen shot of any email header from any user on this server&#8230;I am sending you some details that are helpful for you.</p>
<p>Linux 2.6.18, sendmail: 8.13.1, apache 2.0.52, and open webmail 2.52</p>
<p>Suspected open ports:<br />
25, 111(rpc), 443, 1720(SIP), 870(unkwon), 80, 79(finger), 110(pop), 143(imap),<br />
3333(dec-notes), 4444(krb524)</p>
<p>and system is protected by firewall have ttl of system is: 53<br />
Network distance: 10 hops.</p>
<p>Send me mail if u are ready to accept this challenge with project cost and time, so after i send IP address of live server, and money will be dilvered by Wire of paypal or bank transfer, any option that u want.&#8221;
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256&amp;title=Hack+this+and+get+what+ever+you+want%21"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256&amp;title=Hack+this+and+get+what+ever+you+want%21"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Hack+this+and+get+what+ever+you+want%21&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256&amp;title=Hack+this+and+get+what+ever+you+want%21"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256&amp;title=Hack+this+and+get+what+ever+you+want%21"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256&amp;title=Hack+this+and+get+what+ever+you+want%21"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256&amp;t=Hack+this+and+get+what+ever+you+want%21"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256&amp;title=Hack+this+and+get+what+ever+you+want%21"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Hack+this+and+get+what+ever+you+want%21&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1256" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safer. Use an external <a href="http://www.beyondsecurity.com/vulnerability-scanner.html">vulnerability scanner</a>. Nothing to install, zero maintenance!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1256/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The Internet Almost Crashed!</title>
		<link>http://blogs.securiteam.com/index.php/archives/1253</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1253#comments</comments>
		<pubDate>Sun, 22 Feb 2009 20:00:05 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Cisco</category>

		<category>DDoS</category>

		<category>Networking</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1253</guid>
		<description><![CDATA[
Yeah, it is true. I guess some programming errors are more serious than others, so lets give these guys a break: I also suppose the dark clouds gathered for all the recent DDoS characters, too.

-
Make your website safe from SQL Injection attacks. Signup for a daily penetration testing to protect your network!
]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://anticipatethis.files.wordpress.com/2008/03/cisco.gif" /><br />
Yeah, it is <a href="http://www.renesys.com/blog/2009/02/longer-is-not-better.shtml">true</a>. I guess some programming errors are more serious than others, so lets give these guys a break: I also suppose the dark clouds gathered for all the <a href="http://blog.metasploit.com/2009/02/metasploit-ddos-redux.html">recent DDoS</a> characters, too.
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253&amp;title=The+Internet+Almost+Crashed%21"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253&amp;title=The+Internet+Almost+Crashed%21"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=The+Internet+Almost+Crashed%21&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253&amp;title=The+Internet+Almost+Crashed%21"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253&amp;title=The+Internet+Almost+Crashed%21"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253&amp;title=The+Internet+Almost+Crashed%21"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253&amp;t=The+Internet+Almost+Crashed%21"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253&amp;title=The+Internet+Almost+Crashed%21"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=The+Internet+Almost+Crashed%21&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1253" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safe from SQL Injection attacks. Signup for a daily <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1253/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Microsoft explains browser security</title>
		<link>http://blogs.securiteam.com/index.php/archives/1252</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1252#comments</comments>
		<pubDate>Sun, 22 Feb 2009 19:52:29 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Microsoft</category>

		<category>Commentary</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1252</guid>
		<description><![CDATA[
And you thought this day would never come&#8230; read more here.
No, this is not a joke 

-
Is your site safe from SQL Injection attacks? Use an SQL Injection Scanner on a daily basis to protect your network!
]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://davidnaylor.org/temp/ie8.png" /></p>
<p>And you thought this day would never come&#8230; read more<a rel="nofollow" href="http://research.microsoft.com/apps/pubs/default.aspx?id=79655"> here</a>.</p>
<p>No, this is not a joke <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' />
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252&amp;title=Microsoft+explains+browser+security"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252&amp;title=Microsoft+explains+browser+security"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Microsoft+explains+browser+security&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252&amp;title=Microsoft+explains+browser+security"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252&amp;title=Microsoft+explains+browser+security"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252&amp;title=Microsoft+explains+browser+security"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252&amp;t=Microsoft+explains+browser+security"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252&amp;title=Microsoft+explains+browser+security"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Microsoft+explains+browser+security&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1252" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Is your site safe from SQL Injection attacks? Use an <a href="http://www.beyondsecurity.com/sql-injection.html">SQL Injection Scanner</a> on a daily basis to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1252/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Don&#8217;t open that PDF!</title>
		<link>http://blogs.securiteam.com/index.php/archives/1251</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1251#comments</comments>
		<pubDate>Sat, 21 Feb 2009 19:24:03 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Microsoft</category>

		<category>Commentary</category>

		<category>Privacy</category>

		<category>Full Disclosure</category>

		<category>Corporate Security</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1251</guid>
		<description><![CDATA[
Adobe Acrobat, at least the reader, has been owned. Again. So Surprising.
The good news is that Xpdf probably isn&#8217;t vulnerable 

-
Expose the security holes in your products during development. Black Box Testing makes it safer!
]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://fc76.deviantart.com/fs12/f/2006/277/f/1/acrobat_reader_rg.png" /></p>
<p>Adobe Acrobat, at least the reader, has been <a href="http://www.shadowserver.org/wiki/pmwiki.php?n=Calendar.20090219">owned</a>. Again. So Surprising.</p>
<p>The good news is that Xpdf probably isn&#8217;t vulnerable <img src='http://blogs.securiteam.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251&amp;title=Don%27t+open+that+PDF%21"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251&amp;title=Don%27t+open+that+PDF%21"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Don%27t+open+that+PDF%21&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251&amp;title=Don%27t+open+that+PDF%21"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251&amp;title=Don%27t+open+that+PDF%21"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251&amp;title=Don%27t+open+that+PDF%21"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251&amp;t=Don%27t+open+that+PDF%21"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251&amp;title=Don%27t+open+that+PDF%21"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Don%27t+open+that+PDF%21&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1251" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Expose the security holes in your products during development. <a href="http://www.beyondsecurity.com/black-box-testing.html">Black Box Testing</a> makes it safer!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1251/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Kaspersky Injected</title>
		<link>http://blogs.securiteam.com/index.php/archives/1247</link>
		<comments>http://blogs.securiteam.com/index.php/archives/1247#comments</comments>
		<pubDate>Mon, 09 Feb 2009 04:32:56 +0000</pubDate>
		<dc:creator>jbrown</dc:creator>
		
		<category>Web</category>

		<category>Commentary</category>

		<category>Full Disclosure</category>

		<category>Corporate Security</category>

		<category>Networking</category>

		<guid isPermaLink="false">http://blogs.securiteam.com/index.php/archives/1247</guid>
		<description><![CDATA[
Kaspersky&#8217;s USA website was hacked by SQL injection. Maybe they should hire some virus writers to secure their website, or better yet, a good penetration testing team.
Grab more details about the incident here.


-
Make your website safe from SQL Injection attacks. Signup for a daily penetration testing to protect your network!
]]></description>
			<content:encoded><![CDATA[<p><img align="absmiddle" src="http://null3d.com/images/exploits_of_a_mom.png" /></p>
<p><a href="http://usa.kaspersky.com">Kaspersky&#8217;s USA website</a> was hacked by SQL injection. Maybe they should hire some virus writers to secure their website, or better yet, a good <a href="http://www.netragard.com">penetration testing team</a>.</p>
<p>Grab more details about the incident <a href="http://hackersblog.org/2009/02/07/usakasperskycom-hacked-full-database-acces-sql-injection/">here</a>.
</p>
<div><a href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247&amp;title=Kaspersky+Injected"rel="nofollow"  title="Digg"><img src="http://blogs.securiteam.com/wp-content/socializer-images/digg.png" title="Digg" alt="Digg" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://reddit.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247&amp;title=Kaspersky+Injected"rel="nofollow"  title="Reddit"><img src="http://blogs.securiteam.com/wp-content/socializer-images/reddit.png" title="Reddit" alt="Reddit" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://slashdot.org/bookmark.pl?title=Kaspersky+Injected&amp;url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247"rel="nofollow"  title="Slashdot"><img src="http://blogs.securiteam.com/wp-content/socializer-images/slashdot.png" title="Slashdot" alt="Slashdot" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://twitthis.com/twit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247"rel="nofollow"  title="TwitThis"><img src="http://blogs.securiteam.com/wp-content/socializer-images/twitter.png" title="TwitThis" alt="TwitThis" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://sphinn.com/submit.php?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247&amp;title=Kaspersky+Injected"rel="nofollow"  title="Sphinn"><img src="http://blogs.securiteam.com/wp-content/socializer-images/sphinn.png" title="Sphinn" alt="Sphinn" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247&amp;title=Kaspersky+Injected"rel="nofollow"  title="StumbleUpon"><img src="http://blogs.securiteam.com/wp-content/socializer-images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://del.icio.us/post?url=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247&amp;title=Kaspersky+Injected"rel="nofollow"  title="del.icio.us"><img src="http://blogs.securiteam.com/wp-content/socializer-images/delicious.png" title="del.icio.us" alt="del.icio.us" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.facebook.com/sharer.php?u=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247&amp;t=Kaspersky+Injected"rel="nofollow"  title="Facebook"><img src="http://blogs.securiteam.com/wp-content/socializer-images/facebook.png" title="Facebook" alt="Facebook" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247&amp;title=Kaspersky+Injected"rel="nofollow"  title="Google"><img src="http://blogs.securiteam.com/wp-content/socializer-images/googlebookmark.png" title="Google" alt="Google" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="http://technorati.com/faves?add=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247"rel="nofollow"  title="Technorati"><img src="http://blogs.securiteam.com/wp-content/socializer-images/technorati.png" title="Technorati" alt="Technorati" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a><a href="mailto:?subject=Kaspersky+Injected&amp;body=http%3A%2F%2Fblogs.securiteam.com%2Findex.php%2Farchives%2F1247" title="E-mail this story to a friend!"><img src="http://blogs.securiteam.com/wp-content/socializer-images/email_link.png"rel="nofollow"  title="E-mail this story to a friend!" alt="E-mail this story to a friend!" style="margin:5px; border:0px; opacity: .4; -moz-opacity: .4; filter: alpha(opacity=40);" /></a></div>
<p>-</p>
<p>Make your website safe from SQL Injection attacks. Signup for a daily <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> to protect your network!</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.securiteam.com/index.php/archives/1247/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
