
<?phpxml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
>
<channel>
<title>infosec news / InfoSec Institute / All</title>
<link>http://news.infosecinstitute.com</link>
<description>Your Source for Infosec News and Networking</description>
<pubDate>Wed, 16 Mar 2011 22:26:04 -0400</pubDate>
<language>en</language>
<item>
<title><![CDATA[500 Internal Server Error]]></title>
<link>http://news.infosecinstitute.com/featured/500-internal-server-error-3/</link>
<comments>http://news.infosecinstitute.com/featured/500-internal-server-error-3/</comments>
<pubDate>Wed, 16 Mar 2011 22:26:04 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/500-internal-server-error-3/</guid>
<description><![CDATA[500 Internal Server Error<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Anonymous speaks: the inside story of the HBGary hack]]></title>
<link>http://news.infosecinstitute.com/featured/anonymous-speaks-the-inside-story-of-the-hbgary-hack/</link>
<comments>http://news.infosecinstitute.com/featured/anonymous-speaks-the-inside-story-of-the-hbgary-hack/</comments>
<pubDate>Wed, 16 Feb 2011 20:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/anonymous-speaks-the-inside-story-of-the-hbgary-hack/</guid>
<description><![CDATA[<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Advanced Trojan Could Zombify Your Android Device]]></title>
<link>http://news.infosecinstitute.com/featured/advanced-trojan-could-zombify-your-android-device/</link>
<comments>http://news.infosecinstitute.com/featured/advanced-trojan-could-zombify-your-android-device/</comments>
<pubDate>Thu, 30 Dec 2010 13:26:06 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/advanced-trojan-could-zombify-your-android-device/</guid>
<description><![CDATA[An advanced new Android trojan named Geinimi has been found in the wild, mobile security firm Lookout reports.<br/><br/>7 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Why Don't Firewalls Work?]]></title>
<link>http://news.infosecinstitute.com/featured/why-dont-firewalls-work/</link>
<comments>http://news.infosecinstitute.com/featured/why-dont-firewalls-work/</comments>
<pubDate>Thu, 30 Dec 2010 01:26:05 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/why-dont-firewalls-work/</guid>
<description><![CDATA[Even the best firewalls might fail an audit -- or get hacked -- if your enterprise doesn&#039;t follow proper change and configuration management practices. Here&#039;s a look at some of the common pitfalls that trip up firewall administrators<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[VERA 0.3 Released]]></title>
<link>http://news.infosecinstitute.com/featured/vera-0-3-released/</link>
<comments>http://news.infosecinstitute.com/featured/vera-0-3-released/</comments>
<pubDate>Thu, 23 Dec 2010 14:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/vera-0-3-released/</guid>
<description><![CDATA[VERA, is a visualization tool to help understand the dynamic execution of a program. It&#039;s made to take the instruction traces from Ether and generate directed graphs showing the overall flow and composition of a program. Identifying OEP is easy, as well as looking for main loops and initialization sections of the program. <br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[University Of Wisconsin-Madison Leaves 60,000 SSNs Unprotected For Two Years]]></title>
<link>http://news.infosecinstitute.com/featured/university-of-wisconsin-madison-leaves-60000-ssns-unprotected-for-two-years/</link>
<comments>http://news.infosecinstitute.com/featured/university-of-wisconsin-madison-leaves-60000-ssns-unprotected-for-two-years/</comments>
<pubDate>Mon, 20 Dec 2010 22:26:05 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/university-of-wisconsin-madison-leaves-60000-ssns-unprotected-for-two-years/</guid>
<description><![CDATA[A recent database breach that potentially exposed the Social Security Numbers of 60,000 former students and staff at the University of Wisconsin is bringing attention to the way higher education institutions store and protect SSNs -- even after they&#039;ve been discontinued as a student identification number.<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Recent Email Breaches Demonstrate Cloud Breach Ripple Effect]]></title>
<link>http://news.infosecinstitute.com/featured/recent-email-breaches-demonstrate-cloud-breach-ripple-effect/</link>
<comments>http://news.infosecinstitute.com/featured/recent-email-breaches-demonstrate-cloud-breach-ripple-effect/</comments>
<pubDate>Sat, 18 Dec 2010 01:26:07 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/recent-email-breaches-demonstrate-cloud-breach-ripple-effect/</guid>
<description><![CDATA[The recent breach exposing McDonald&#039;s customer information was the result of a widespread series of spear-phishing attacks against email service providers that have been under way for about a year and are under investigation by the FBI.<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hacker warning over internet-connected HDTVs • The Register]]></title>
<link>http://news.infosecinstitute.com/featured/hacker-warning-over-internet-connected-hdtvs-•-the-register/</link>
<comments>http://news.infosecinstitute.com/featured/hacker-warning-over-internet-connected-hdtvs-•-the-register/</comments>
<pubDate>Sat, 18 Dec 2010 01:26:07 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/hacker-warning-over-internet-connected-hdtvs-•-the-register/</guid>
<description><![CDATA[Internet-connected HDTVs could be used by hackers to infiltrate home networks, according to a firm that markets device security software for smartphones, VoIP devices and TVs.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[OpenBSD/FBI allegations denied by named participants]]></title>
<link>http://news.infosecinstitute.com/featured/openbsdfbi-allegations-denied-by-named-participants/</link>
<comments>http://news.infosecinstitute.com/featured/openbsdfbi-allegations-denied-by-named-participants/</comments>
<pubDate>Fri, 17 Dec 2010 13:26:09 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/openbsdfbi-allegations-denied-by-named-participants/</guid>
<description><![CDATA[Amidst startling accusations revealed by OpenBSD founder and lead developer Theo de Raadt today that 10 years ago the US Federal Bureau of Investigations paid developers to insert security holes into OpenBSD code, some confusion about the accusations has already emerged, with one named party strongly denying any involvement.<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Stuxnet Worm Still Out of Control at Iran's Nuclear Sites, Experts Say]]></title>
<link>http://news.infosecinstitute.com/featured/stuxnet-worm-still-out-of-control-at-irans-nuclear-sites-experts-say/</link>
<comments>http://news.infosecinstitute.com/featured/stuxnet-worm-still-out-of-control-at-irans-nuclear-sites-experts-say/</comments>
<pubDate>Wed, 15 Dec 2010 00:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/stuxnet-worm-still-out-of-control-at-irans-nuclear-sites-experts-say/</guid>
<description><![CDATA[<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Mac OS X 10.6.5: 100+ Good Security Reasons To Upgrade, But Tread Carefully]]></title>
<link>http://news.infosecinstitute.com/featured/mac-os-x-10-6-5-100-good-security-reasons-to-upgrade-but-tread-carefully/</link>
<comments>http://news.infosecinstitute.com/featured/mac-os-x-10-6-5-100-good-security-reasons-to-upgrade-but-tread-carefully/</comments>
<pubDate>Tue, 14 Dec 2010 02:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/mac-os-x-10-6-5-100-good-security-reasons-to-upgrade-but-tread-carefully/</guid>
<description><![CDATA[<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Teen Confesses To Hacking Lady Gaga's PC]]></title>
<link>http://news.infosecinstitute.com/featured/teen-confesses-to-hacking-lady-gagas-pc/</link>
<comments>http://news.infosecinstitute.com/featured/teen-confesses-to-hacking-lady-gagas-pc/</comments>
<pubDate>Tue, 14 Dec 2010 02:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/teen-confesses-to-hacking-lady-gagas-pc/</guid>
<description><![CDATA[&#039;DJ Stolen&#039; apologizes for using Trojan horse to steal unfinished songs and selling them online<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Dns2tcp]]></title>
<link>http://news.infosecinstitute.com/featured/dns2tcp/</link>
<comments>http://news.infosecinstitute.com/featured/dns2tcp/</comments>
<pubDate>Sat, 11 Dec 2010 00:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/dns2tcp/</guid>
<description><![CDATA[Dns2tcp is a network tool designed to relay TCP connections through DNS traffic. Encapsulation is done on the TCP level, thus no specific driver is needed (i.e: TUN/TAP). Dns2tcp client doesn&#039;t need to be run with specific privileges.<br />Dns2tcp is composed of two parts : a server-side tool and a client-side tool. The server has a list of resources specified in a configuration file. Each resource is a local or remote service listening for TCP connections. The client listen on a predefined TCP port and relays each incoming connection through DNS to the final service.<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft plans major end-of-year Patch Tuesday]]></title>
<link>http://news.infosecinstitute.com/featured/microsoft-plans-major-end-of-year-patch-tuesday/</link>
<comments>http://news.infosecinstitute.com/featured/microsoft-plans-major-end-of-year-patch-tuesday/</comments>
<pubDate>Sat, 11 Dec 2010 00:26:03 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/microsoft-plans-major-end-of-year-patch-tuesday/</guid>
<description><![CDATA[Microsoft is planning a huge end-of-year patch to fix flaws in Windows, Office, Internet Explorer, SharePoint and Exchange. The company said in a security patch advance notification that all but one of the 17 updates are rated &#039;important&#039; or &#039;critical&#039;.This has been the busiest year ever for Microsoft&#039;s flaw fixing team, which has issued a total of 106 software bulletins since January.<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[And Now, an MBR Ransomware]]></title>
<link>http://news.infosecinstitute.com/featured/and-now-an-mbr-ransomware/</link>
<comments>http://news.infosecinstitute.com/featured/and-now-an-mbr-ransomware/</comments>
<pubDate>Tue, 30 Nov 2010 00:26:05 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/and-now-an-mbr-ransomware/</guid>
<description><![CDATA[Some interesting ransomware that encrypts your MBR. Taking this concept to the next level.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Google and Microsoft Cheat on Slow-Start. Should You?]]></title>
<link>http://news.infosecinstitute.com/featured/google-and-microsoft-cheat-on-slow-start-should-you/</link>
<comments>http://news.infosecinstitute.com/featured/google-and-microsoft-cheat-on-slow-start-should-you/</comments>
<pubDate>Sat, 27 Nov 2010 00:26:06 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/google-and-microsoft-cheat-on-slow-start-should-you/</guid>
<description><![CDATA[<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Storing a Rootkit On your NIC]]></title>
<link>http://news.infosecinstitute.com/featured/storing-a-rootkit-on-your-nic/</link>
<comments>http://news.infosecinstitute.com/featured/storing-a-rootkit-on-your-nic/</comments>
<pubDate>Tue, 23 Nov 2010 23:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/storing-a-rootkit-on-your-nic/</guid>
<description><![CDATA[The main interest is developing a rootkit which will be residing inside the network card. A network card rootkit offers some very interesting features:<br /><br />A very stealthy communication end-point over the Ethernet link. It can intercept and forge network frames without the operating system knowing about it.<br />A physical system memory access using DMA over the PCI link, leading to OS corruption.<br />No trace of the rootkit on the operating system, as it is being hidden inside the NIC.<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[How To Reverse Engineer USB Devices]]></title>
<link>http://news.infosecinstitute.com/featured/how-to-reverse-engineer-usb-devices/</link>
<comments>http://news.infosecinstitute.com/featured/how-to-reverse-engineer-usb-devices/</comments>
<pubDate>Tue, 23 Nov 2010 00:26:09 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/how-to-reverse-engineer-usb-devices/</guid>
<description><![CDATA[Today we&#039;re going to be reverse engineering the Xbox Kinect Motor, one part of the Kinect device.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Whitehat cracks notorious rootkit wide open • The Register]]></title>
<link>http://news.infosecinstitute.com/featured/whitehat-cracks-notorious-rootkit-wide-open-•-the-register/</link>
<comments>http://news.infosecinstitute.com/featured/whitehat-cracks-notorious-rootkit-wide-open-•-the-register/</comments>
<pubDate>Thu, 18 Nov 2010 02:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/whitehat-cracks-notorious-rootkit-wide-open-•-the-register/</guid>
<description><![CDATA[The analysis was written by Giuseppe Bonfa, a malware researcher specializing in reverse engineering at InfoSec Institute, an information security services company. It documents a rootkit that&#039;s almost impossible to remove without damaging the host operating system and uses low-level programming calls to create hard disk volumes that are virtually impossible to detect using normal forensic techniques. Sophos&#039;s description of the rootkit, which is also known as Smiscer, is here.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Image of the Day: Dissecting The ZeroAccess Crimeware | threatpost]]></title>
<link>http://news.infosecinstitute.com/featured/image-of-the-day-dissecting-the-zeroaccess-crimeware-|-threatpost/</link>
<comments>http://news.infosecinstitute.com/featured/image-of-the-day-dissecting-the-zeroaccess-crimeware-|-threatpost/</comments>
<pubDate>Thu, 18 Nov 2010 02:26:04 -0500</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/image-of-the-day-dissecting-the-zeroaccess-crimeware-|-threatpost/</guid>
<description><![CDATA[We know a lot about the effects of malicious programs like rootkits and Trojan downloaders. The job of finding out exactly how the programs work, however, is painstaking. That&#039;s because most malware authors worth their salt take steps to make their creations hard to understand. Code obfuscation and anti-debugging are common features of most sophisticated, modern malware. With patience and endurance, however, researchers are often able to pierce the veil, anyway.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Google Online Security Blog: Rewarding web application security research]]></title>
<link>http://news.infosecinstitute.com/featured/google-online-security-blog-rewarding-web-application-security-research/</link>
<comments>http://news.infosecinstitute.com/featured/google-online-security-blog-rewarding-web-application-security-research/</comments>
<pubDate>Mon, 01 Nov 2010 22:26:03 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/google-online-security-blog-rewarding-web-application-security-research/</guid>
<description><![CDATA[Google offers bounty for finding web app bugs<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Open Source Network Forensics With Xplico]]></title>
<link>http://news.infosecinstitute.com/featured/open-source-network-forensics-with-xplico/</link>
<comments>http://news.infosecinstitute.com/featured/open-source-network-forensics-with-xplico/</comments>
<pubDate>Mon, 11 Oct 2010 20:26:01 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/open-source-network-forensics-with-xplico/</guid>
<description><![CDATA[The goal of Xplico to extract application specific data sets from traffic captured. For example, from a pcap file Xplico extracts each email (POP, IMAP, and SMTP protocols), all HTTP contents, each VoIP call (SIP), FTP, TFTP, and so on. Xplico isn't a network protocol analyzer. Xplico is an open source Network Forensic Analysis Tool (NFAT).<br/><br/>4 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Fannie Mae logic-bomb saboteur convicted]]></title>
<link>http://news.infosecinstitute.com/featured/fannie-mae-logic-bomb-saboteur-convicted/</link>
<comments>http://news.infosecinstitute.com/featured/fannie-mae-logic-bomb-saboteur-convicted/</comments>
<pubDate>Mon, 11 Oct 2010 14:26:02 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/fannie-mae-logic-bomb-saboteur-convicted/</guid>
<description><![CDATA[A computer contractor has been convicted of planting a logic bomb on the servers of Fannie Mae, the financially troubled US housing and mortgage giant.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Turn Workers Into Security Partners]]></title>
<link>http://news.infosecinstitute.com/featured/turn-workers-into-security-partners/</link>
<comments>http://news.infosecinstitute.com/featured/turn-workers-into-security-partners/</comments>
<pubDate>Tue, 21 Sep 2010 22:26:02 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/turn-workers-into-security-partners/</guid>
<description><![CDATA[Rather than just protect employees or protect against them, security managers should rely on users to help defend the business<br/><br/>13 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft sounds alert on massive Web bug]]></title>
<link>http://news.infosecinstitute.com/featured/microsoft-sounds-alert-on-massive-web-bug/</link>
<comments>http://news.infosecinstitute.com/featured/microsoft-sounds-alert-on-massive-web-bug/</comments>
<pubDate>Tue, 21 Sep 2010 18:26:03 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/microsoft-sounds-alert-on-massive-web-bug/</guid>
<description><![CDATA[At Ekoparty, Juliano Rizzo and Thai Duong demonstrated how a flaw in ASP.Net&#039;s encryption can be exploited to decrypt session cookies or other encrypted data on a remote server, and access and snatch files from a site or Web application that relies on the framework.<br/><br/>15 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Stuxnet attackers used 4 Windows zero-day exploits]]></title>
<link>http://news.infosecinstitute.com/featured/stuxnet-attackers-used-4-windows-zero-day-exploits/</link>
<comments>http://news.infosecinstitute.com/featured/stuxnet-attackers-used-4-windows-zero-day-exploits/</comments>
<pubDate>Wed, 15 Sep 2010 11:26:02 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/stuxnet-attackers-used-4-windows-zero-day-exploits/</guid>
<description><![CDATA[<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Update kills code-execution threat in Samba]]></title>
<link>http://news.infosecinstitute.com/featured/update-kills-code-execution-threat-in-samba/</link>
<comments>http://news.infosecinstitute.com/featured/update-kills-code-execution-threat-in-samba/</comments>
<pubDate>Wed, 15 Sep 2010 11:26:02 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/update-kills-code-execution-threat-in-samba/</guid>
<description><![CDATA[<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Video Made By Here You Have Virus Explains His Motives]]></title>
<link>http://news.infosecinstitute.com/featured/video-made-by-here-you-have-virus-explains-his-motives/</link>
<comments>http://news.infosecinstitute.com/featured/video-made-by-here-you-have-virus-explains-his-motives/</comments>
<pubDate>Mon, 13 Sep 2010 23:26:06 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/video-made-by-here-you-have-virus-explains-his-motives/</guid>
<description><![CDATA[He doesn&#039;t like the US. I think kanye&#039;s toast was for him.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft helps Adobe block PDF zero-day exploit]]></title>
<link>http://news.infosecinstitute.com/featured/microsoft-helps-adobe-block-pdf-zero-day-exploit/</link>
<comments>http://news.infosecinstitute.com/featured/microsoft-helps-adobe-block-pdf-zero-day-exploit/</comments>
<pubDate>Mon, 13 Sep 2010 21:26:04 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/microsoft-helps-adobe-block-pdf-zero-day-exploit/</guid>
<description><![CDATA[Redmond recommends you turn on ASLR for the dll used by the exploit... Kind of a silly fix because I am sure there is another dll you could use that has ASLR disabled.<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Twitter XSS Allows for Account Hijack]]></title>
<link>http://news.infosecinstitute.com/featured/twitter-xss-allows-for-account-hijack/</link>
<comments>http://news.infosecinstitute.com/featured/twitter-xss-allows-for-account-hijack/</comments>
<pubDate>Wed, 08 Sep 2010 23:26:06 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/twitter-xss-allows-for-account-hijack/</guid>
<description><![CDATA[Apparently the vulnerability has not yet been patched, its remarkably easy to hijack twitter accounts.<br/><br/>17 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Retooling Vulnerability Scanning, Penetration Testing For IPv6]]></title>
<link>http://news.infosecinstitute.com/featured/retooling-vulnerability-scanning-penetration-testing-for-ipv6/</link>
<comments>http://news.infosecinstitute.com/featured/retooling-vulnerability-scanning-penetration-testing-for-ipv6/</comments>
<pubDate>Wed, 08 Sep 2010 12:26:06 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/retooling-vulnerability-scanning-penetration-testing-for-ipv6/</guid>
<description><![CDATA[Pen testing IPv6 networks are a challenge, here is an overview on how to do it right. Also link to Fierce, a great DNS discovery tool<br/><br/>5 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Cyber-jihadists Deface Home Of Teddy Bears' Picnic]]></title>
<link>http://news.infosecinstitute.com/featured/cyber-jihadists-deface-home-of-teddy-bears-picnic/</link>
<comments>http://news.infosecinstitute.com/featured/cyber-jihadists-deface-home-of-teddy-bears-picnic/</comments>
<pubDate>Thu, 02 Sep 2010 16:26:08 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/cyber-jihadists-deface-home-of-teddy-bears-picnic/</guid>
<description><![CDATA[Geographically mixed-up Algerian hackers made themselves look rather silly by defacing the website of an English stately home instead of Belvoir Fortress in Israel, their intended target.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Brazilian banker's crypto baffles FBI]]></title>
<link>http://news.infosecinstitute.com/featured/brazilian-bankers-crypto-baffles-fbi/</link>
<comments>http://news.infosecinstitute.com/featured/brazilian-bankers-crypto-baffles-fbi/</comments>
<pubDate>Thu, 02 Sep 2010 16:26:08 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/brazilian-bankers-crypto-baffles-fbi/</guid>
<description><![CDATA[FBI called in to break 256 bit AES, has no luck. They should call me, I can slice through that like a Pentium Pro through DES.<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[DARPA seeks assistance with insider threats]]></title>
<link>http://news.infosecinstitute.com/featured/darpa-seeks-assistance-with-insider-threats/</link>
<comments>http://news.infosecinstitute.com/featured/darpa-seeks-assistance-with-insider-threats/</comments>
<pubDate>Tue, 31 Aug 2010 19:26:01 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/darpa-seeks-assistance-with-insider-threats/</guid>
<description><![CDATA[The CINDER program, according to DARPA, is looking for proposals that "greatly increase the accuracy, rate, and speed of detection and that impede the ability of adversaries to operate undetected within government and military interest networks".<br/><br/>2 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[State of Virginia Grinds To A Halt After SAN Fails]]></title>
<link>http://news.infosecinstitute.com/featured/state-of-virginia-grinds-to-a-halt-after-san-fails/</link>
<comments>http://news.infosecinstitute.com/featured/state-of-virginia-grinds-to-a-halt-after-san-fails/</comments>
<pubDate>Tue, 31 Aug 2010 19:26:01 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/state-of-virginia-grinds-to-a-halt-after-san-fails/</guid>
<description><![CDATA[A SAN failed with no good backup, and no DR, leads the State of VA to grind to a halt. 26 of 80 agencies were shut down, including the Office of the Governor and the Dept. of Motor Vehicles. Maybe virtualizing everything and putting all data on a SAN isnt such a great idea after all<br/><br/>1 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hardware Hack Busts Quantum Encryption]]></title>
<link>http://news.infosecinstitute.com/featured/hardware-hack-busts-quantum-encryption/</link>
<comments>http://news.infosecinstitute.com/featured/hardware-hack-busts-quantum-encryption/</comments>
<pubDate>Tue, 31 Aug 2010 13:26:01 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/hardware-hack-busts-quantum-encryption/</guid>
<description><![CDATA[Quantum encryption is supposed to be unbreakable, using phase state of photons to represent binary ones and zeros, leaves an effectively infinite number of bits to encrypt a message with. But, like all encryption, you have to implement it properly in order for it to work....<br/><br/>9 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[USB Flash Drive Worms Increase In Prevalence]]></title>
<link>http://news.infosecinstitute.com/featured/usb-flash-drive-worms-increase-in-prevalence/</link>
<comments>http://news.infosecinstitute.com/featured/usb-flash-drive-worms-increase-in-prevalence/</comments>
<pubDate>Mon, 30 Aug 2010 11:26:02 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/usb-flash-drive-worms-increase-in-prevalence/</guid>
<description><![CDATA[Panda Labs releases a report, shows USB worms do a lot of damage in the SMB sector<br/><br/>13 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[2010 smashes vulnerability records]]></title>
<link>http://news.infosecinstitute.com/featured/2010-smashes-vulnerability-records/</link>
<comments>http://news.infosecinstitute.com/featured/2010-smashes-vulnerability-records/</comments>
<pubDate>Thu, 26 Aug 2010 19:26:03 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/2010-smashes-vulnerability-records/</guid>
<description><![CDATA[35% more vulnerabilities reported in COTS software in first half of 2010 as compared to 2009. Maybe the 2009 decrease was an anomaly? Looks like it.<br/><br/>19 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hackers look forward to hacking the Cloud]]></title>
<link>http://news.infosecinstitute.com/featured/hackers-look-forward-to-hacking-the-cloud/</link>
<comments>http://news.infosecinstitute.com/featured/hackers-look-forward-to-hacking-the-cloud/</comments>
<pubDate>Wed, 25 Aug 2010 23:26:05 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/hackers-look-forward-to-hacking-the-cloud/</guid>
<description><![CDATA[Not much of a surprise, but Defcon attendees look forward to hacking cloud services.<br/><br/>27 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Google’s Market Licensing System Easy to Crack]]></title>
<link>http://news.infosecinstitute.com/featured/google’s-market-licensing-system-easy-to-crack/</link>
<comments>http://news.infosecinstitute.com/featured/google’s-market-licensing-system-easy-to-crack/</comments>
<pubDate>Wed, 25 Aug 2010 23:26:04 -0400</pubDate>
<dc:creator>InfoSec Institute</dc:creator>
<category>Featured</category>
<guid>http://news.infosecinstitute.com/featured/google’s-market-licensing-system-easy-to-crack/</guid>
<description><![CDATA[Piracy for android apps looks too easy. Some nice videos with this post.<br/><br/>13 Vote(s) ]]></description>
</item>

</channel>
</rss>

