<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.12-alpha" -->
<rss version="0.92">
<channel>
	<title>SecuriTeam Blogs</title>
	<link>http://blogs.securiteam.com</link>
	<description>Thoughts about the world of security</description>
	<lastBuildDate>Mon, 05 May 2008 15:05:04 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Random stuff</title>
		<description>I'm hyped!  The much-anticipated Maltego version 2.0 is out.  I had previously alluded to maltego here.  To the 1% of you who haven't heard of Maltego, it's a tool for determining relationships between domains, users, email addresses, etc.  I can't think of an Infosec or traditional ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1091</link>
			</item>
	<item>
		<title>Plan B</title>
		<description>The Daily WTF has a good story that may sound a little too familiar to some:
How the aptly-named Super Hacker had managed to shut down the system remotely and provide a fix so quickly intrigued Kiefer. After poking around the network, he finally found the Python file that contained the ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1090</link>
			</item>
	<item>
		<title>Q: Cisco Site to Site VPN</title>
		<description>New week a new question, in this case the question is a bit more generic and I believe raises a few dilemmas, feel free to take a shot at it:
Hi Experts,

Is it secure to just configure Cisco IPSEC/GRE site to site tunnel without firewall/IPS/IDS. The argument here is although it ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1089</link>
			</item>
	<item>
		<title>Q: Outlook attachments</title>
		<description>Another one for you this week, we especially liked XenoMuta's answer to our previous one.
Lets go:
Dear SecuriTeam,

i am not sure if you are able to help us to find a solution for a special problem but i've tried everything and spent a lot of time in the internet without any ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1084</link>
			</item>
	<item>
		<title>Arrested for security research?</title>
		<description>Anyone who has ever done serious security research reached the line that separates good from evil. If you are working with phishing emails you get links to kiddie porn. If you research security holes you deal with exploits. If you are researching botnets you are up to your neck in ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1085</link>
			</item>
	<item>
		<title>Q: THC PPTP Bruter</title>
		<description>Once again - another security question from our readers to the security experts who read this blog:
I ran across your site looking for information regarding the security of PPTP.  I then found the PPTP bruter program from THC.  I am a small business owner.  I am a ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1083</link>
			</item>
	<item>
		<title>A new WMF attack looming?</title>
		<description>It appears that a new WMF attack is coming, as you recall about a year back an WMF vulnerability was used on several high profile sites to infect visitors, this now appears to start happening again.

The first sign of this is the appearance of exploits for the vulnerability, starting off ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1082</link>
			</item>
	<item>
		<title>Marketer on Marketer crime</title>
		<description>I have a strong distrust of most marketing and sales individuals.  I hate evaluating software and getting a dozen calls or emails from some overzealous, inside-sales weenie.  For this reason, I usually use bogus information when I fill out the obligatory form requesting the software that I want ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1081</link>
			</item>
	<item>
		<title>Manual Vishing</title>
		<description>This Hebrew post in linmagazine describes what first sounds like a typical Vishing attack. The author's mother receives a phone call telling her there's been a terrible accident and she needs to call the hospital for the details. They give her the ER's number but tell her to use only ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1080</link>
			</item>
	<item>
		<title>Open source pollenation</title>
		<description>I'm rushing this post out so that this post can be the 1,000th post :)

I've got a project that I'd love to run, but I just don't have the time.  Here's what I'm thinking of.  I want to crawl Fortune 1000 sites and generate fingerprints on their code ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1079</link>
			</item>
	<item>
		<title>Google calendar as a spam platform</title>
		<description>Apparently Google's calendar has been elected to become a new spam platform.

I started receiving these a few days ago, at first I thought it to be a fluke but not it has become a flood.

Someone in Google should probably start looking at this and getting it fixed, as this isn't ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1078</link>
			</item>
	<item>
		<title>Spam term turned 15 years this week</title>
		<description>And it was
...almost 30 years since the first spam message was sent.
We can read more here:

news.bbc.co.uk/2/hi/technology/7322615.stm </description>
		<link>http://blogs.securiteam.com/index.php/archives/1077</link>
			</item>
	<item>
		<title>List of April Fool&#8217;s Day 2008 links can be found here</title>
		<description>SANS ISC has collected a very coverage list of April Fool's Day stories.

It can be found here:

isc.sans.org/diary.html?storyid=4225

My own favorite is Gmail's new Custom Time feature ;) </description>
		<link>http://blogs.securiteam.com/index.php/archives/1076</link>
			</item>
	<item>
		<title>Why coding after a long drinking night is not a good idea</title>
		<description>I'd love to hear the background story behind this one:
[CiscoWorks IPM] version 2.6 for Solaris and Windows contains a process that causes a command shell to automatically be bound to a randomly selected TCP port.
Why on earth? And why a random port?

And if you're still wondering, yes - it's a ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1075</link>
			</item>
	<item>
		<title>State of targeted attacks - criminals exploiting Excel vuln during two months</title>
		<description>It's time to look the recent state of targeted attacks. Like we already know the main attack vector in these attacks is Microsoft Office attachment. There are no many organizations that simply can filter .DOC, .XLS and .PPT files.
In mid-January Microsoft confirmed that a new, previously unknown Excel vulnerability was ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1074</link>
			</item>
	<item>
		<title>Q: Socket Security</title>
		<description>A new question for you guys - you have been great answering the previous one:
----
Hi I’m a bit new to java and socket programming.
Anyway I just wrote a client server socket program and I have an open port listening on my unix box.
 
I was told that this is vulnerable ...</description>
		<link>http://blogs.securiteam.com/index.php/archives/1073</link>
			</item>
</channel>
</rss>
