<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.6" -->
<rss version="0.92">
<channel>
	<title>SecuriTeam Blogs</title>
	<link>http://blogs.securiteam.com</link>
	<description>Thoughts about the world of security</description>
	<lastBuildDate>Sat, 13 Mar 2010 09:41:44 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>ASCII gone bad / Zer0-overflow</title>
		<description>This post is a followup on my previous post on KISS shellcoding and exploitation. Like before this is part of the job I do for SecuriTeam’s SSD. Those that are not aware of the project its aim is to give researchers compensation for their researcher efforts, compensation of course being ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1348</link>
			</item>
	<item>
		<title>Security Seal company sued by FTC</title>
		<description>Lets start with the proper disclosure; we provide a Web Site Security Seal service which competes with ControlScan's. That said, I'm not about to bash ControlScan but rather the poor practices of security seal companies giving out seals to whoever pays them without the proper security checks.

Some background: The FTC ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1349</link>
			</item>
	<item>
		<title>Google and security. Oil and Water. (Or: How to DoS google groups)</title>
		<description>The buzz was on about google buzz sharing your list of contacts (which they then quickly fixed in their casual we-did-nothing-wrong-these-are-not-the-droids-you're-looking-for mind trick).

Readers of this blog remember when google calendar let you see the full name behind every gmail address. At that time, google ignored, then decided there's nothing wrong ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1347</link>
			</item>
	<item>
		<title>Thoughts on Haiti, Olympics, and other disasters</title>
		<description>Absent those who have gone gaga over the iPad, the top news for the past two weeks has been the earthquake and disaster in Haiti.  The concern, the outpourings of support (and, yes, the malware and phishing sites that have been attempting to capitalize on the crisis) are all reminiscent ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1346</link>
			</item>
	<item>
		<title>Mac Virus update</title>
		<description>I know, there ain't no such thing! 

Well, we could have a lively debate on that topic, but not right now. 

On this occasion, I'm just letting anyone who wonders what happened to the Mac Virus web site (http://www.macvirus.com), which I inherited from Susan Lesch some years ago, what's happening ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1345</link>
			</item>
	<item>
		<title>So Microsoft has known about the IE vulnerability (CVE-2010-0249) since last September.</title>
		<description>So, let me get this straight, MS was informed about this vulnerability by a security researcher (Meron Sellen) last August, and it's sat in the Microsoft Security Response Center's queue to be fixed until Google got hacked, and then they checked their queue to see if they knew about it?

Even ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1344</link>
			</item>
	<item>
		<title>How not to handle a responsible XSS disclosure!</title>
		<description>Okay, so a few days ago I found a ton of XSS vulnerabilities on various high profile web sites, and on the whole, after eventually managing to contact the relevant teams for the sites, everyone was very grateful.

When will web sites owners learn that it's a good idea to have ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1343</link>
			</item>
	<item>
		<title>Vendor response to vulnerability disclosure</title>
		<description>My wish for 2010: I want this guide to be taught in CS classes to developers everywhere:

http://vrt-sourcefire.blogspot.com/2009/12/matts-guide-to-vendor-response.html

Happy new year everybody.

 </description>
		<link>http://blogs.securiteam.com/index.php/archives/1342</link>
			</item>
	<item>
		<title>Signs of the (end) times &#8230;</title>
		<description>Rev. 6:6, OCD [1]

"Then it was as if I heard a voice saying: And they shalt go into the storehouses, and look there for the snack foods made from corn [2] which the hands of men have made into hollow cones or cornets [3].  And they shall go unto the ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1341</link>
			</item>
	<item>
		<title>Adobe 0-Day (CVE-2009-4324) Fix To Be Pushed 12th January 2010</title>
		<description>Well, what more can I say really, good old Adobe have decided that it's better to hold off on this patch, then to have people working around the clock to try and get this out asap. I suppose they also need to have some time off, after all it is ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1340</link>
			</item>
	<item>
		<title>Adobe 0-day vulnerability (CVE-2009-4324) - what this means?</title>
		<description>     
      
SecuriTeam Blogs contains several FAQ documents about MS Office vulnerabilities used in targeted attacks since 2006. This time I'm not writing a FAQ. This document has answers to What this means type questions.
What an organization can make to protect?

 ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1339</link>
			</item>
	<item>
		<title>Latest Adobe 0-Day Exploit Now In Metasploit</title>
		<description>Just reading through Twitter and I saw this from HDM, and thought I'd share

"Adobe PDF 0.9-day added to Metasploit: [msf&#62; use exploit/windows/fileformat/adobe_media_newplayer.rb] (via jduck/pusscat/myself) SVN r7881"

Night All... </description>
		<link>http://blogs.securiteam.com/index.php/archives/1338</link>
			</item>
	<item>
		<title>KISS shellcoding and exploitation</title>
		<description>In this blog i will talk about anything and everything to do with vulnerability exploitation. This is part of the job I do for SecuriTeam's SSD. Those that are not aware of the project its aim is to give researchers compensation for their researcher efforts, compensation of course being money ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1329</link>
			</item>
	<item>
		<title>Using Nmap Remotely Through F5 FirePass VPN</title>
		<description>Well, we all use the common hacking tools of the trade like Nmap. Some of us use it on Windows and some on Linux. This post is for the people using it on Windows.
I was connected to a network remotely through the company's F5 VPN appliance and I wanted to ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1337</link>
			</item>
	<item>
		<title>Bypassing Windows Unknown Publisher Verification For Web Downloaded Executables</title>
		<description>I was in another day of jumping from a client to a client, securing another bank in Israel when my girlfriend called and said "Honey, I am at the office, I have absolutely nothing to do and I can't connect from here to our computer at home to continue my ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1336</link>
			</item>
	<item>
		<title>Exploiting WebView through Internet Explorer to remotely discover windows directory</title>
		<description>As for any large product, Microsoft Windows operating system is built on its previous versions code. Some of this code even goes back until Microsoft Windows 98.

In Windows 98 a new look was introduced called "WebView" which included the way folders are displayed and the way the desktop is displayed ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1335</link>
			</item>
</channel>
</rss>
