<?xml version="1.0" encoding="ISO-8859-1" ?>
<?xml-stylesheet type="text/xsl" href="/xsl/index.xsl"?>

<BODY>
<TITLE>
Welcome to the ThreatPerspective Security Information Center
</TITLE>
<MENU>
    <MENUOBJECT>

	<MENUTITLE>
		Vulnerability Info	
	</MENUTITLE>

	<MENUITEM>
		<menuurl>http://www.securityfocus.com</menuurl>
		<MENUBODY>
			Security Focus	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.osvdb.org</menuurl>
		<MENUBODY>
			OSVDB
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://nvd.nist.gov</menuurl>
		<MENUBODY>
			Nist NVD
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://cve.mitre.org</menuurl>
		<MENUBODY>
			Mitre
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://ciac.llnl.gov</menuurl>
		<MENUBODY>
			CIAC
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.cert.org</menuurl>
		<MENUBODY>
			CERT
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://iase.disa.mil</menuurl>
		<MENUBODY>
			ISAE
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Exploit Info	
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.exploit-db.com</menuurl>
		<MENUBODY>
			Exploit DB
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.packetstormsecurity.org</menuurl>
		<MENUBODY>
			Packet Storm
		</MENUBODY>
	</MENUITEM>


    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Active Groups
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.shmoo.com</menuurl>
		<MENUBODY>
			The Shmoo Group
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.thc.org</menuurl>
		<MENUBODY>
			THC
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>http://www.phenoelit-us.org/</menuurl>
		<MENUBODY>
			Phenoelit
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>

	<MENUTITLE>
		Commercial Groups
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.ngssoftware.com</menuurl>
		<MENUBODY>
			NGS
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.immunitysec.com</menuurl>
		<MENUBODY>
			Immunitysec
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.secunia.com</menuurl>
		<MENUBODY>
			Secunia
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.securiteam.com</menuurl>
		<MENUBODY>
			Securiteam
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://xforce.iss.net</menuurl>
		<MENUBODY>
			Xforce
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.idefense.com</menuurl>
		<MENUBODY>
			Idefense
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.eeye.com</menuurl>
		<MENUBODY>
			Eeye
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.2600.com</menuurl>
		<MENUBODY>
			2600
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Security Organizations
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.owasp.org</menuurl>
		<MENUBODY>
			OWASP
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.isc2.org</menuurl>
		<MENUBODY>
			ISC2
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.isecom.org</menuurl>
		<MENUBODY>
			ISECOM
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.sans.org</menuurl>
		<MENUBODY>
			SANS
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.infragard.com</menuurl>
		<MENUBODY>
			Infragard
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Methodologies	
	</MENUTITLE>

	<MENUITEM>
		<menuurl>http://www.osissg.org</menuurl>
		<MENUBODY>
			OISSG
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.isecom.org/</menuurl>
		<MENUBODY>
			ISECOM
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.osstmm.org</menuurl>
		<MENUBODY>
			OSSTMM
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>

	<MENUTITLE>
		Free Tools
	</MENUTITLE>

	<MENUITEM>
		<menuurl>http://www.nessus.org</menuurl>
		<MENUBODY>
			Nessus
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.openvas.org/</menuurl>
		<MENUBODY>
			OpenVAS
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.insecure.org</menuurl>
		<MENUBODY>
			Nmap
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.cqure.net</menuurl>
		<MENUBODY>
			Cqure Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.sqlsecurity.com/DesktopDefault.aspx?tabid=26</menuurl>
		<MENUBODY>
			MS SQL Utils
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.cirt.net</menuurl>
		<MENUBODY>
			Nikto
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.sysinternals.com</menuurl>
		<MENUBODY>
			Sysinternals
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.bindview.com/services/razor/utilities/</menuurl>
		<MENUBODY>
			Bindview
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://thc.org/releases.php</menuurl>
		<MENUBODY>
			THC Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.metasploit.org</menuurl>
		<MENUBODY>
			Metasploit
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://beefproject.com/</menuurl>
		<MENUBODY>
		 BeEF
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.parosproxy.org/</menuurl>
		<MENUBODY>
			Paros Proxy
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.portswigger.net/proxy/</menuurl>
		<MENUBODY>
			Burp Proxy
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.securityforest.com</menuurl>
		<MENUBODY>
			Exploit Tree
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.tank.net</menuurl>
		<MENUBODY>
			Spork
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://ettercap.sourceforge.net/</menuurl>
		<MENUBODY>
			Ettercap
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.cirt.net/code/nikto.shtml</menuurl>
		<MENUBODY>
			nikto
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.sensepost.com/research/wikto/</menuurl>
		<MENUBODY>
			wikto
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.nstalker.com/eng/products/nstealth/</menuurl>
		<MENUBODY>
			nStealth
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://reedarvin.thearvins.com/tools/PWDumpX14.zip</menuurl>
		<MENUBODY>
			 pwdumpx
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.foofus.net/fizzgig/fgdump/</menuurl>
		<MENUBODY>
			fgdump 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.off-by-one.net/misc/cachedump.html</menuurl>
		<MENUBODY>
			Cachedump
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://studenti.unina.it/~ncuomo/syskey/</menuurl>
		<MENUBODY>
			samdump2
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>http://www.ethereal.com/</menuurl>
		<MENUBODY>
			Ethereal
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.immunitysec.com/resources-freesoftware.shtml</menuurl>
		<MENUBODY>
			Immunitysec
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.foundstone.com/resources/freetools.htm</menuurl>
		<MENUBODY>
			Foundstone
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.eeye.com/html/Research/Tools/index.html</menuurl>
		<MENUBODY>
			Eeye
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://sectools.org/</menuurl>
		<MENUBODY>
			Sectools.org
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Free Virtualization Tools	
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.vmware.com/products/server/</menuurl>
		<MENUBODY>
			VMWare Server
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://bochs.sourceforge.net/</menuurl>
		<MENUBODY>
			Bochs
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://pearpc.sourceforge.net/</menuurl>
		<MENUBODY>
			PearPC	
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.microsoft.com/windows/virtualpc/default.mspx</menuurl>
		<MENUBODY>
			MS Virtual PC
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Reverse Engineering	
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://directory.fsf.org/GNU/binutils.html</menuurl>
		<MENUBODY>
			binutils
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.gnu.org/software/gdb/</menuurl>
		<MENUBODY>
			GDB
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://directory.fsf.org/GNU/GUSS.html</menuurl>
		<MENUBODY>
			Guss
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.gnu.org/software/ddd/</menuurl>
		<MENUBODY>
			DDD
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.ollydbg.de/</menuurl>
		<MENUBODY>
			Ollydbg 
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://labs.idefense.com/labs-software.php</menuurl>
		<MENUBODY>
			iDefense
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://oss.coresecurity.com/projects/uhooker.htm</menuurl>
		<MENUBODY>
			CORE
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Defaced Websites
	</MENUTITLE>


	<MENUITEM>
		<menuurl>http://www.zone-h.org/component/option,com_attacks/Itemid,43/</menuurl>
		<MENUBODY>
			Zone H
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Default Passwords
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.cirt.net/cgi-bin/passwd.pl</menuurl>
		<MENUBODY>
			Cirt
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.phenoelit.de/dpl/dpl.html</menuurl>
		<MENUBODY>
			Phenoelit
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.petefinnigan.com/default/default_password_list.htm</menuurl>
		<MENUBODY>Oracle</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php</menuurl>
		<MENUBODY>
			Gov Sec
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://defaultpassword.com/</menuurl>
		<MENUBODY>
			def pass
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.cyxla.com/passwords/passwords.html</menuurl>
		<MENUBODY>
			Cyxla
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.e-tech.ca/017-Default_Passwords_ad.asp</menuurl>
		<MENUBODY>
			e-tech
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.uktsupport.co.uk/reference/biosp.htm</menuurl>
		<MENUBODY>
			Bios Passwords
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Technical Conferences
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.defcon.org</menuurl>
		<MENUBODY>
			DefCon
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference</menuurl>
		<MENUBODY>
		 	AppSec	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.blackhat.com</menuurl>
		<MENUBODY>
			Blackhat
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.cansecwest.com</menuurl>
		<MENUBODY>
			CanSecWest
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://toorcon.com</menuurl>
		<MENUBODY>
			Toorcon
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.shmoocon.org/</menuurl>
		<MENUBODY>
			ShmooCon
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.hopenumbersix.net/</menuurl>
		<MENUBODY>
			H.O.P.E.
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.ccc.de/</menuurl>
		<MENUBODY>
			CCC
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://conference.hackinthebox.org/</menuurl>
		<MENUBODY>
			HiTB
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		CD Distros
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.remote-exploit.org/index.php/Auditor_main</menuurl>
		<MENUBODY>
			Auditor
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.knoppix.org</menuurl>
		<MENUBODY>
			Knoppix
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>http://www.backtrack-linux.org/</menuurl>
		<MENUBODY>
			BackTrack
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Wireless Tools
	</MENUTITLE>

	<MENUITEM>
		<menuurl>http://www.netstumbler.com</menuurl>
		<MENUBODY>
			Netstumbler
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://codebutler.com/firesheep</menuurl>
		<MENUBODY>
		 	Firesheep	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.kismetwireless.net</menuurl>
		<MENUBODY>
			Kismet
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://kismac.de/</menuurl>
		<MENUBODY>
			Kismac
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://airsnort.shmoo.com</menuurl>
		<MENUBODY>
			Airsnort
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://wepcrack.sourceforge.net</menuurl>
		<MENUBODY>
			WEPCrack
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.aircrack-ng.org/doku.php</menuurl>
		<MENUBODY>
			Aircrack-ng
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://csrc.nist.gov/publications/nistpubs/800-48/NIST_SP-48.pdf</menuurl>
		<MENUBODY>
			Wireless SP
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>http://www.blackalchemy.to/project/fakeap/</menuurl>
		<MENUBODY>
			FakeAP
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.802.11mercenary.net/lorcon/</menuurl>
		<MENUBODY>
			Lorcon
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://theta44.org/karma/index.html</menuurl>
		<MENUBODY>
			Karma
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.tacnetsol.com/news/2011/12/28/cracking-wifi-protected-setup-with-reaver.html</menuurl>
		<MENUBODY>
			Weaver
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Checklists
	</MENUTITLE>

	<MENUITEM>
		<menuurl>http://csrc.nist.gov</menuurl>
		<MENUBODY>
			NIST CSRC
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://nvd.nist.gov/cvss.cfm?version=2</menuurl>
		<MENUBODY>
		 	CVSS	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://checklists.nist.gov</menuurl>
		<MENUBODY>
			NIST Checklists
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.cisecurity.org</menuurl>
		<MENUBODY>
			CIS
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.nsa.gov/snac/index.cfm?MenuID=scg10.3.1</menuurl>
		<MENUBODY>
			NSA
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>

		<menuurl>http://otn.oracle.com/deploy/security/oracle9i/pdf/9i_checklist.pdf</menuurl>
		<MENUBODY>
			Oracle 9i
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>

		<menuurl>http://www.petefinnigan.com/orasec.htm</menuurl>
		<MENUBODY>
			PF's Checklists
		</MENUBODY>

	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.microsoft.com/technet/archive/security/chklist/default.mspx</menuurl>
		<MENUBODY>
			Microsoft
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.openna.com/pdfs/Securing-Optimizing-Linux-The-Ultimate-Solution-v2.0.pdf</menuurl>
		<MENUBODY>
			SaOL
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		OS Hardening
        </MENUTITLE>


        <MENUITEM>
                <menuurl>http://www.sun.com/software/security/jass/</menuurl>
                <MENUBODY>
			Solaris - JASS
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>http://www.sun.com/service/serviceplans/software/patchmanagement/patchmanager.html</menuurl>
                <MENUBODY>
			Solaris - Patch Manager
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>http://www.bastille-unix.org/</menuurl>
                <MENUBODY>
			Bastille Unix
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>http://www.microsoft.com/technet/security/tools/default.mspx#EZE</menuurl>
                <MENUBODY>
			Microsoft Security Tools
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>
   <MENUOBJECT>
	<MENUTITLE>
		Defunct Groups ?
	</MENUTITLE>
	<MENUITEM>
		<menuurl>http://www.attrition.org</menuurl>
		<MENUBODY>
			Attrition
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.w00w00.org</menuurl>
		<MENUBODY>
			w00w00
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://adm.freelsd.net/ADM/</menuurl>
		<MENUBODY>
			ADM
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://en.wikipedia.org/wiki/TESO</menuurl>
		<MENUBODY>
			TESO	
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>


    <MENUOBJECT>
	<MENUTITLE>
		Professional Security Programs
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.pcisecuritystandards.org/</menuurl>
		<MENUBODY>
		  PCI	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.isc2.org</menuurl>
		<MENUBODY>
			ISC2
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.eccouncil.org/</menuurl>
		<MENUBODY>
		 	EC Council	
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
                Password Crackers
        </MENUTITLE>


	<MENUITEM>
		<menuurl>http://www.insecure.org/stf/lc5-setup.exe</menuurl>
		<MENUBODY>
			LC5 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.insecure.org/stf/lc5-crack.zip</menuurl>
		<MENUBODY>
			LC5 Keygen
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://www.oxid.it/cain.html</menuurl>
		<MENUBODY>
			Cain and Abel
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://www.openwall.com/john/</menuurl>
		<MENUBODY>
			John the Ripper
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.banquise.net/misc/patch-john.html</menuurl>
		<MENUBODY>
			John Bigpatch 
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://en.wikipedia.org/wiki/RainbowCrack</menuurl>
		<MENUBODY>
			RainbowCrack 
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>http://rainbowtables.shmoo.com/</menuurl>
		<MENUBODY>
			Rainbow Tables
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>


   <MENUOBJECT>
        <MENUTITLE>
                OSI
        </MENUTITLE>

        <MENUITEM>
                <menuurl>http://johnny.ihackstuff.com/</menuurl>
                <MENUBODY>
                        Google Hacking
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://news.netcraft.com/</menuurl>
                <MENUBODY>
                        NetCraft
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://www.archive.org/</menuurl>
                <MENUBODY>
                        Way Back Machine
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>http://www.domaintools.com</menuurl>
                <MENUBODY>
                        DomainTools
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>http://whois.webhosting.info</menuurl>
                <MENUBODY>
                        Hosting info 
                </MENUBODY>
        </MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Compliance Resources
        </MENUTITLE>

        <MENUITEM>
                <menuurl>http://www.hhs.gov/ocr/hipaa/</menuurl>
                <MENUBODY>
                        HIPAA
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://www.aicpa.org/info/sarbanes_oxley_summary.htm</menuurl>
                <MENUBODY>
			SOX
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://banking.senate.gov/conf/</menuurl>
                <MENUBODY>
			FMA (GLBA)
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://csrc.nist.gov/sec-cert/</menuurl>
                <MENUBODY>
			FISMA
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://www.iso.org/iso/en/prods-services/popstds/informationsecurity.html</menuurl>
                <MENUBODY>
			ISO 17799
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://csrc.nist.gov/fasp/</menuurl>
                <MENUBODY>
			NIST FASP
                </MENUBODY>
        </MENUITEM>



        <MENUITEM>
                <menuurl>http://www.sans.org/resources/policies/</menuurl>
                <MENUBODY>
			SANS Policies
                </MENUBODY>
        </MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Email Lists
        </MENUTITLE>

        <MENUITEM>
                <menuurl>http://www.securityfocus.com/archive</menuurl>
                <MENUBODY>
			Security Focus
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://lists.grok.org.uk/mailman/listinfo/full-disclosure</menuurl>
                <MENUBODY>
			Full Disclosure
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>http://www.immunitysec.com/mailman/listinfo/dailydave</menuurl>
                <MENUBODY>
			Daily Dave
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>http://www.seclists.org</menuurl>
                <MENUBODY>
			Security Lists
                </MENUBODY>
        </MENUITEM>


   </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Defense / IDS
        </MENUTITLE>

        <MENUITEM>
                <menuurl>http://www.snort.org</menuurl>
                <MENUBODY>
			Snort
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://www.bleedingsnort.com</menuurl>
                <MENUBODY>
			"Bleeding Edge" Snort
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://acidlab.sourceforge.net/</menuurl>
                <MENUBODY>
			ACID Snort Interface
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>





   <MENUOBJECT>
        <MENUTITLE>
		Load Testing / Denial of Service Info
        </MENUTITLE>
        <MENUITEM>
                <menuurl>http://staff.washington.edu/dittrich/misc/ddos/</menuurl>
                <MENUBODY>
			DDOS Info
                </MENUBODY>
        </MENUITEM>

   </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		IDS Testing
        </MENUTITLE>

        <MENUITEM>
                <menuurl>ftp://ftp.st.ryuAkoku.ac.jp/pub/security/tool/snot/</menuurl>
                <MENUBODY>
			Snot
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>http://securityfocus.com/data/tools/stick.tgz</menuurl>
                <MENUBODY>
			Stick
                </MENUBODY>
        </MENUITEM>

   </MENUOBJECT>
   <MENUOBJECT>
        <MENUTITLE>
		Firewall Ruleset Testing Tools
        </MENUTITLE>

        <MENUITEM>
                <menuurl>http://www.packetfactory.net/projects/firewalk/</menuurl>
                <MENUBODY>
			Firewalk
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>http://dev.inversepath.com/trac/ftester</menuurl>
                <MENUBODY>
			FTester
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>
</MENU>
<MSG>
    <MSGARTICLE>
	<MSGTITLE>
Welcome to the Security Information Center
	</MSGTITLE>
	<MSGBODY>
This is a portal site created by ThreatPerspective to enable our clients and other interested parties to learn more about Information Security.  The boxes on the left correlate to free information and tools that realate to Information Security.  The boxes on the right are various Information Security related news feeds. 
	</MSGBODY>
    </MSGARTICLE>
</MSG>
<rss version="2.0">
<channel>
    <title>Tenable Network Security</title>
    <link rel="self" type="application/atom+xml" href="http://blog.tenablesecurity.com/atom.xml" />
    <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/" />
        <title>#7 Nessus Versus Malware - Top Ten Things You Didn&#39;t Know About Nessus</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2012/01/top-ten-things-you-didnt-know-about-nessus-7-nessus-versus-malware.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2012/01/top-ten-things-you-didnt-know-about-nessus-7-nessus-versus-malware.html" />
        <title>Tenable Network Security Podcast 110</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-podcast-110.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-podcast-110.html" />
        <link rel="enclosure" type="audio/mpeg" href="http://traffic.libsyn.com/tenable/tenablepodcast-episode110.mp3" length="0" />
        <link rel="enclosure" type="audio/mpeg" href="http://traffic.libsyn.com/tenable/tenablepodcast-episode110.mp3" length="0" />
        <title>Tenable Network Security Episode 109</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-episode-109.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-episode-109.html" />
        <link rel="enclosure" type="audio/mpeg" href="http://traffic.libsyn.com/tenable/tenablepodcast-episode109.mp3" length="0" />
        <link rel="enclosure" type="audio/mpeg" href="http://traffic.libsyn.com/tenable/tenablepodcast-episode109.mp3" length="0" />
        <title>Tenable Network Security Podcast Episode 108</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-podcast-episode-108.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-podcast-episode-108.html" />
        <link rel="enclosure" type="audio/mpeg" href="http://blog.tenable.com/files/tenablepodcast-episode108.mp3" length="0" />
        <link rel="enclosure" type="audio/mpeg" href="http://blog.tenable.com/files/tenablepodcast-episode108.mp3" length="0" />
        <title>Microsoft Patch Tuesday - January 2012</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2012/01/microsoft-patch-tuesday-january-2012.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2012/01/microsoft-patch-tuesday-january-2012.html" />
        <title>Tenable Network Security Podcast Episode 107</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-podcast-episode-107.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2012/01/tenable-network-security-podcast-episode-107.html" />
        <link rel="enclosure" type="audio/mpeg" href="http://blog.tenable.com/files/tenablepodcast-episode107.mp3" length="0" />
        <link rel="enclosure" type="audio/mpeg" href="http://blog.tenable.com/files/tenablepodcast-episode107.mp3" length="0" />
        <title>An introduction to Nessus - The Video</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2011/12/an-introduction-to-nessus-the-video.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2011/12/an-introduction-to-nessus-the-video.html" />
        <title>Microsoft Patch Management Integration with Nessus - Part 1 WSUS</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2011/12/wsus-patch-management-and-nessus.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2011/12/wsus-patch-management-and-nessus.html" />
        <title>Microsoft Patch Tuesday - December 2011</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2011/12/microsoft-patch-tuesday-december-2011.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2011/12/microsoft-patch-tuesday-december-2011.html" />
        <title>Tenable Network Security Podcast Episode 106</title>
        <link rel="alternate" type="text/html" href="http://blog.tenablesecurity.com/2011/12/tenable-network-security-podcast-episode-106.html" />
        <link rel="replies" type="text/html" href="http://blog.tenablesecurity.com/2011/12/tenable-network-security-podcast-episode-106.html" />
        <link rel="enclosure" type="audio/mpeg" href="http://blog.tenable.com/files/tenablepodcast-episode106.mp3" length="0" />
        <link rel="enclosure" type="audio/mpeg" href="http://blog.tenable.com/files/tenablepodcast-episode106.mp3" length="0" />
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Bugtraq</title>
    <link>http://seclists.org/#bugtraq</link>
    <description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
  <item>
    <title>AdaCore Security Advisory SA-2012-L119-003 Hash collisions in AWS</title>
    <link>http://seclists.org/bugtraq/2012/Jan/168</link>
    <description>&lt;p&gt;Posted by Thomas Quinot on Jan 27&lt;/p&gt;AdaCore Security Advisory&lt;br&gt;
  Impact:...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Announce] Reminder: HITB2012AMS Call For Papers Closing Soon</title>
    <link>http://seclists.org/bugtraq/2012/Jan/167</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jan 27&lt;/p&gt;This is a gentle reminder that the Call for Papers for the third annual&lt;br&gt;
featuring keynote speakers Andy Ellis (Chief...&lt;br&gt;</description>
  </item>
  <item>
    <title>[ GLSA 201201-15 ] ktsuss: Privilege escalation</title>
    <link>http://seclists.org/bugtraq/2012/Jan/166</link>
    <description>&lt;p&gt;Posted by Sean Amoss on Jan 27&lt;/p&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br&gt;
     Date: January 27, 2012...&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY] [DSA 2394-1] libxml2 security update</title>
    <link>http://seclists.org/bugtraq/2012/Jan/165</link>
    <description>&lt;p&gt;Posted by Luciano Bello on Jan 27&lt;/p&gt;-------------------------------------------------------------------------&lt;br&gt;
Problem type   : remote...&lt;br&gt;</description>
  </item>
  <item>
    <title>ESA-2012-007: RSA, The Security Division of EMC, announces security fixes for RSA enVision</title>
    <link>http://seclists.org/bugtraq/2012/Jan/164</link>
    <description>&lt;p&gt;Posted by Security_Alert on Jan 26&lt;/p&gt;ESA-2012-007: RSA, The Security Division of EMC, announces security fixes for RSA enVision&lt;br&gt;
This release addresses an environmental variable disclosure vulnerability. The...&lt;br&gt;</description>
  </item>
  <item>
    <title>ESA-2012-005: EMC NetWorker buffer overflow vulnerability</title>
    <link>http://seclists.org/bugtraq/2012/Jan/163</link>
    <description>&lt;p&gt;Posted by Security_Alert on Jan 26&lt;/p&gt;ESA-2012-005: EMC NetWorker buffer overflow vulnerability. &lt;br&gt;
denial...&lt;br&gt;</description>
  </item>
  <item>
    <title>Cisco Security Advisory: Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability</title>
    <link>http://seclists.org/bugtraq/2012/Jan/162</link>
    <description>&lt;p&gt;Posted by Cisco Systems Product Security Incident Response Team on Jan 26&lt;/p&gt;Cisco Security Advisory: Cisco IronPort Appliances Telnet Remote Code&lt;br&gt;
allow a remote,...&lt;br&gt;</description>
  </item>
  <item>
    <title>ZDI-12-018 : Symantec PCAnywhere awhost32 Remote Code Execution Vulnerability</title>
    <link>http://seclists.org/bugtraq/2012/Jan/161</link>
    <description>&lt;p&gt;Posted by ZDI Disclosures on Jan 25&lt;/p&gt;ZDI-12-018 : Symantec PCAnywhere awhost32 Remote Code Execution&lt;br&gt;
vulnerable installations of Symantec PCAnywhere....&lt;br&gt;</description>
  </item>
  <item>
    <title>NX Web Companion Spoofing Arbitrary Code Execution Vulnerability</title>
    <link>http://seclists.org/bugtraq/2012/Jan/160</link>
    <description>&lt;p&gt;Posted by otr on Jan 25&lt;/p&gt;# Vuln Title: NX Web Companion Spoofing Arbitrary Code Execution&lt;br&gt;
Machine software...&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY] [DSA-2393-1] bip security update</title>
    <link>http://seclists.org/bugtraq/2012/Jan/159</link>
    <description>&lt;p&gt;Posted by dann frazier on Jan 25&lt;/p&gt;-------------------------------------------------------------------------&lt;br&gt;
Problem type   :...&lt;br&gt;</description>
  </item>
  <item>
    <title>D-Link DIR-601 TFTP Directory Traversal Vulnerability</title>
    <link>http://seclists.org/bugtraq/2012/Jan/158</link>
    <description>&lt;p&gt;Posted by robkraus on Jan 25&lt;/p&gt;Vulnerability title: D-Link DIR-601 TFTP Directory Traversal Vulnerability&lt;br&gt;
Solutionary public disclosure URL:...&lt;br&gt;</description>
  </item>
  <item>
    <title>CSRF (Cross-Site Request Forgery) in DClassifieds</title>
    <link>http://seclists.org/bugtraq/2012/Jan/157</link>
    <description>&lt;p&gt;Posted by advisory on Jan 25&lt;/p&gt;Advisory ID: HTB23067&lt;br&gt;
Credit: High-Tech Bridge SA Security Research Lab (...&lt;br&gt;</description>
  </item>
  <item>
    <title>Multiple vulnerabilities in OSclass</title>
    <link>http://seclists.org/bugtraq/2012/Jan/156</link>
    <description>&lt;p&gt;Posted by advisory on Jan 25&lt;/p&gt;Advisory ID: HTB23068&lt;br&gt;
Credit: High-Tech Bridge SA Security...&lt;br&gt;</description>
  </item>
  <item>
    <title>NGS00117 Patch Notification: Symantec PCAnywhere Local Privilege Escalation</title>
    <link>http://seclists.org/bugtraq/2012/Jan/155</link>
    <description>&lt;p&gt;Posted by Research () NGSSecure on Jan 25&lt;/p&gt;High Risk Vulnerability in Symantec PCAnywhere &lt;br&gt;
An updated version of the software has been released to address these vulnerabilities:...&lt;br&gt;</description>
  </item>
  <item>
    <title>NGS00118 Patch Notification: Symantec PCAnywhere Remote Code Execution as SYSTEM</title>
    <link>http://seclists.org/bugtraq/2012/Jan/154</link>
    <description>&lt;p&gt;Posted by Research () NGSSecure on Jan 25&lt;/p&gt;Critical Vulnerability in Symantec PCAnywhere &lt;br&gt;
An updated version of the software has been released to address these vulnerabilities:...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>CERT Advisories</title>
    <link>http://seclists.org/#cert</link>
    <description>The &lt;a href=&quot;http://www.cert.org/&quot;&gt;Computer Emergency Response Team&lt;/a&gt; has been responding to security incidents and sharing vulnerability information since the Morris Worm hit in 1986. This archive combines their technical security alerts, tips, and current activity lists.</description>
  <item>
    <title>TA12-024A -- &amp;quot;Anonymous&amp;quot; DDoS Activity</title>
    <link>http://seclists.org/cert/2012/13</link>
    <description>&lt;p&gt;Posted by US-CERT Technical Alerts on Jan 24&lt;/p&gt;                    National Cyber Alert System&lt;br&gt;
   industry...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Denial-of-Service Malware Campaign</title>
    <link>http://seclists.org/cert/2012/12</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 24&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
US-CERT encourages users and administrators to do the following...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Google Releases Chrome 16.0.912.77</title>
    <link>http://seclists.org/cert/2012/11</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 24&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
US-CERT encourages users and administrators to review the Google...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Symantec pcAnywhere Hotfix</title>
    <link>http://seclists.org/cert/2012/10</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 24&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
pcAnywhere hot fix...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Best Practices for Recovery from the Malicious Erasure of Files</title>
    <link>http://seclists.org/cert/2012/9</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 19&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
wiping, or &amp;quot;zeroing out,&amp;quot; the hard disk...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Oracle Releases Critical Patch Update for January 2012</title>
    <link>http://seclists.org/cert/2012/8</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 18&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
 * 1 for Oracle Supply Chain Products Suite...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Phishing Campaign Using Spoofed US-CERT Email Addresses</title>
    <link>http://seclists.org/cert/2012/7</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 11&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
number of private sector organizations as well as federal, state,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Adobe Releases Security Advisory for Adobe Reader and Acrobat</title>
    <link>http://seclists.org/cert/2012/6</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 10&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
  * Adobe Reader 9.4.7 and earlier...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Microsoft Releases January Security Bulletin</title>
    <link>http://seclists.org/cert/2012/5</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 10&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
operate with elevated...&lt;br&gt;</description>
  </item>
  <item>
    <title>TA12-010A -- Microsoft Updates for Multiple Vulnerabilities</title>
    <link>http://seclists.org/cert/2012/4</link>
    <description>&lt;p&gt;Posted by US-CERT Technical Alerts on Jan 10&lt;/p&gt;                    National Cyber Alert System&lt;br&gt;
   Microsoft Developer Tools and Software....&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Phishing Campaign Using Spoofed US-CERT E-mail Addresses</title>
    <link>http://seclists.org/cert/2012/3</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 10&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
state, and local governments. US-CERT began receiving reports of...&lt;br&gt;</description>
  </item>
  <item>
    <title>TA12-006A -- Wi-Fi Protected Setup (WPS) Vulnerable to Brute-Force Attack</title>
    <link>http://seclists.org/cert/2012/2</link>
    <description>&lt;p&gt;Posted by US-CERT Technical Alerts on Jan 06&lt;/p&gt;                    National Cyber Alert System&lt;br&gt;
   configure secure...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Google Releases Chrome 16.0.912.75</title>
    <link>http://seclists.org/cert/2012/1</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 06&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
Chrome Releases blog entry and update to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Microsoft Releases Advance Notification for January Security Bulletin</title>
    <link>http://seclists.org/cert/2012/0</link>
    <description>&lt;p&gt;Posted by Current Activity on Jan 05&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
Developer...&lt;br&gt;</description>
  </item>
  <item>
    <title>Current Activity - Multiple Programming Language Implementations Vulnerable to Hash Table Collision Attacks</title>
    <link>http://seclists.org/cert/2011/217</link>
    <description>&lt;p&gt;Posted by Current Activity on Dec 28&lt;/p&gt;US-CERT Current Activity&lt;br&gt;
launch a denial-of-service...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Daily Dave</title>
    <link>http://seclists.org/#dailydave</link>
    <description>This technical discussion list covers vulnerability research, exploit development, and security events/gossip.  It was started by &lt;a href=&quot;http://www.immunitysec.com/&quot;&gt;ImmunitySec&lt;/a&gt; founder Dave Aitel and many security luminaries participate.  Many posts simply advertise Immunity products, but you can&#39;t really fault Dave for being self-promotional on a list named DailyDave.</description>
  <item>
    <title>Cyber Politics By Other Means</title>
    <link>http://seclists.org/dailydave/2012/q1/14</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Jan 27&lt;/p&gt;Dear DD - attached is some red meat. :&amp;gt;&lt;br&gt;
&amp;lt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>Alligators</title>
    <link>http://seclists.org/dailydave/2012/q1/13</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Jan 19&lt;/p&gt;INFILTRATE 2012 is over (as of an hour from now). I will say that all&lt;br&gt;
And here is Mark&amp;apos;s Prezi:...&lt;br&gt;</description>
  </item>
  <item>
    <title>Open Bars</title>
    <link>http://seclists.org/dailydave/2012/q1/12</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Jan 09&lt;/p&gt;So we ordered quite a few open bars for INFILTRATE people - one of which&lt;br&gt;
&amp;lt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>Security Event Horizons</title>
    <link>http://seclists.org/dailydave/2012/q1/11</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Jan 09&lt;/p&gt;Every so often you see a ton of effort from a security person go into a&lt;br&gt;
own...&lt;br&gt;</description>
  </item>
  <item>
    <title>New Paper - Acquisition and Analysis of Volatile Memory	from Android Devices</title>
    <link>http://seclists.org/dailydave/2012/q1/10</link>
    <description>&lt;p&gt;Posted by Andrew Case on Jan 09&lt;/p&gt;We are writing to announce that our paper on Android memory forensics has&lt;br&gt;
   Andrew&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Symantec AV source compromised and the questions it	raises</title>
    <link>http://seclists.org/dailydave/2012/q1/9</link>
    <description>&lt;p&gt;Posted by Michal Zalewski on Jan 06&lt;/p&gt;This reminds me of the wise words of the chairman of Trend Micro:&lt;br&gt;
now looks like Symantec will,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Symantec AV source compromised and the questions it	raises</title>
    <link>http://seclists.org/dailydave/2012/q1/8</link>
    <description>&lt;p&gt;Posted by Mohammad Hosein on Jan 06&lt;/p&gt;&amp;quot;Sadly, we&amp;apos;ll likely never know the answer.&amp;quot;&lt;br&gt;
forums and tweets are...&lt;br&gt;</description>
  </item>
  <item>
    <title>Symantec AV source compromised and the questions it	raises</title>
    <link>http://seclists.org/dailydave/2012/q1/7</link>
    <description>&lt;p&gt;Posted by William Arbaugh on Jan 06&lt;/p&gt;Security Week ran a story that Symantec&amp;apos;s AV source was obtained (and soon to be released) via a compromise of an &lt;br&gt;
since the source is 4+ years old....&lt;br&gt;</description>
  </item>
  <item>
    <title>Apache Struts</title>
    <link>http://seclists.org/dailydave/2012/q1/6</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Jan 06&lt;/p&gt;Just how bad is that Sec-Consult Apache Struts vulnerability...&lt;br&gt;
                        &amp;lt;param...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: INFILTRATE Book Club Part 2</title>
    <link>http://seclists.org/dailydave/2012/q1/5</link>
    <description>&lt;p&gt;Posted by h1kari on Jan 05&lt;/p&gt;Hey guys,&lt;br&gt;
have a...&lt;br&gt;</description>
  </item>
  <item>
    <title>INFILTRATE Book Club Part 2</title>
    <link>http://seclists.org/dailydave/2012/q1/4</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Jan 04&lt;/p&gt;So I personally wasn&amp;apos;t a huge fan, but more than one person has&lt;br&gt;
At this year&amp;apos;s INFILTRATE, due to a few factors, we have...&lt;br&gt;</description>
  </item>
  <item>
    <title>InfoSec Southwest 2012 CFP First-round Speaker	Selections</title>
    <link>http://seclists.org/dailydave/2012/q1/3</link>
    <description>&lt;p&gt;Posted by I)ruid on Jan 04&lt;/p&gt;Hello,&lt;br&gt;
Keynote...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: WebHacking and lcamtuf</title>
    <link>http://seclists.org/dailydave/2012/q1/2</link>
    <description>&lt;p&gt;Posted by Michal Zalewski on Jan 03&lt;/p&gt;Okay!&lt;br&gt;
PS. And yeah, thanks for the review :-)&lt;br&gt;</description>
  </item>
  <item>
    <title>WebHacking and lcamtuf</title>
    <link>http://seclists.org/dailydave/2012/q1/1</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Jan 02&lt;/p&gt;So this is my review of lcamtuf&amp;apos;s book, which is this: It&amp;apos;s the best&lt;br&gt;
only...&lt;br&gt;</description>
  </item>
  <item>
    <title>INFILTRATE book club part 1</title>
    <link>http://seclists.org/dailydave/2012/q1/0</link>
    <description>&lt;p&gt;Posted by Dave Aitel on Jan 02&lt;/p&gt;For those of you traveling to INFILTRATE (in just a few short days!) I&lt;br&gt;
(Syriana) that were based on his books, just...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Educause Security Discussion</title>
    <link>http://seclists.org/#educause</link>
    <description>Securing networks and computers in an academic environment.</description>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/244</link>
    <description>&lt;p&gt;Posted by Pollock, Joseph on Jan 27&lt;/p&gt;My response was immediate and reflexive when I saw I would have to create an Amazon account - No Way.  It&amp;apos;s not worth &lt;br&gt;
comfortable telling the caller that I wanted information only and have no...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/243</link>
    <description>&lt;p&gt;Posted by John Ladwig on Jan 27&lt;/p&gt;I need to look over the descriptions of DPD, to see to what degree they cover the issue of the current massive trend of &lt;br&gt;
I haven&amp;apos;t dug down deeply into Amazon&amp;apos;s Kindle and other user/privacy...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/242</link>
    <description>&lt;p&gt;Posted by Morrow Long on Jan 27&lt;/p&gt;They might even get a few to install the Kindle app or buy a Kindle.&lt;br&gt;
    I don&amp;apos;t think your rant was...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/241</link>
    <description>&lt;p&gt;Posted by Morrow Long on Jan 27&lt;/p&gt;And actually you can now read it in the Cloud -- you don&amp;apos;t have to install&lt;br&gt;
Subject: Re: [SECURITY] Free Download of Matt...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/240</link>
    <description>&lt;p&gt;Posted by Wayne S. Martin on Jan 27&lt;/p&gt;I apologize for the tone, I shouldn&amp;apos;t have been so direct.  I suppose where I&amp;apos;m confused is that I view Data Privacy &lt;br&gt;
IMHO, Wayne&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/239</link>
    <description>&lt;p&gt;Posted by Charlie Derr on Jan 27&lt;/p&gt;As someone who understood John&amp;apos;s irony (and agrees with it), the reason for the irony is that to some of us, the word &lt;br&gt;
exchange they (probably? hopefully?) get a bunch of new people to sign...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/238</link>
    <description>&lt;p&gt;Posted by Tonkin, Derek K. on Jan 27&lt;/p&gt;I apologize for the tone, I shouldn&amp;apos;t have been so direct.  I suppose where I&amp;apos;m confused is that I view Data Privacy &lt;br&gt;
I&amp;apos;m curious what the stance is of others on the list.  As...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/237</link>
    <description>&lt;p&gt;Posted by Chuck Dunn on Jan 27&lt;/p&gt;Valarie,&lt;br&gt;
publisher.   It&amp;apos;s...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/236</link>
    <description>&lt;p&gt;Posted by Don M. Blumenthal on Jan 27&lt;/p&gt;I have an Amazon account from which I download Kindle books regularly for a Kindle, iPad, and Android phone,  and have &lt;br&gt;
intend to download the book but, despite the fact that I can understand why free distribution is being done this way, I...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/235</link>
    <description>&lt;p&gt;Posted by Mclaughlin, Kevin (mclaugkl) on Jan 27&lt;/p&gt;I love my Kindle,  I love my Kindle IPhone App, I love my Kindle Android app and I love my Kindle computer app.  By the &lt;br&gt;
University of Cincinnati...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/234</link>
    <description>&lt;p&gt;Posted by Tonkin, Derek K. on Jan 27&lt;/p&gt;John,&lt;br&gt;
to complain about?  I&amp;apos;m not sure what privacy concerns you have with Amazon but it didn&amp;apos;t take...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/233</link>
    <description>&lt;p&gt;Posted by Valerie Vogel on Jan 27&lt;/p&gt;Please note: Although the download is only for Kindle, Amazon has free reading apps for the iPad and other devices. &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.amazon.com/lol-OMG-Reputation-Citizenship-Cyberbullying-ebook/dp/B0060FRNNQ&quot;&gt;http://www.amazon.com/lol-OMG-Reputation-Citizenship-Cyberbullying-ebook/dp/B0060FRNNQ&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/232</link>
    <description>&lt;p&gt;Posted by John Ladwig on Jan 27&lt;/p&gt;And, you can&amp;apos;t download the free book without logging in to Amazon.   And, near as I can tell, it&amp;apos;s Kindle- or &lt;br&gt;
To: The EDUCAUSE Security Constituent Group...&lt;br&gt;</description>
  </item>
  <item>
    <title>Free Download of Matt Ivester&apos;s Book Available Now (until Jan. 30)!</title>
    <link>http://seclists.org/educause/2012/q1/231</link>
    <description>&lt;p&gt;Posted by Valerie Vogel on Jan 27&lt;/p&gt;Starting today (through January 30), you can download Matt Ivester&amp;apos;s book - &amp;quot;lol...OMG! What Every Student Needs to &lt;br&gt;
Matt Ivester will also be joining us for a special EDUCAUSE Policy webinar next Monday, January 30, 1-2 pm EST....&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Google announces privacy changes, no opt out for users</title>
    <link>http://seclists.org/educause/2012/q1/230</link>
    <description>&lt;p&gt;Posted by Mike Porter on Jan 27&lt;/p&gt;Without knowing what our contract states, and what portions of the&lt;br&gt;
PGP Fingerprint: F4 AE E1...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Firewall Wizards</title>
    <link>http://seclists.org/#firewall-wizards</link>
    <description>Tips and tricks for firewall administrators</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>IDS Focus</title>
    <link>http://seclists.org/#focus-ids</link>
    <description>Technical discussion about Intrusion Detection Systems.  You can also read the archives of a &lt;A HREF=&quot;http://seclists.org/ids/&quot;&gt;previous IDS list&lt;/A&gt;</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Full Disclosure</title>
    <link>http://seclists.org/#fulldisclosure</link>
    <description>A &lt;a href=&quot;http://seclists.org/fulldisclosure/2010/Mar/459&quot;&gt;lightly moderated&lt;/a&gt; high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately, most of the posts are worthless drivel, so finding the gems takes patience.</description>
  <item>
    <title>..twitter rights</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/536</link>
    <description>&lt;p&gt;Posted by RandallM on Jan 28&lt;/p&gt;is posting attacking us gov site, or exposing personal info of another&lt;br&gt;
What is twitters take?&lt;br&gt;</description>
  </item>
  <item>
    <title>FatCat Auto SQLl Injector</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/535</link>
    <description>&lt;p&gt;Posted by sandeep k on Jan 28&lt;/p&gt;This is an automatic SQL Injection tool called as FatCat, Use of FatCat for&lt;br&gt;
vulnerability and start exploiting...&lt;br&gt;</description>
  </item>
  <item>
    <title>FatCat Auto SQLl Injector</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/534</link>
    <description>&lt;p&gt;Posted by sandeep k on Jan 28&lt;/p&gt;This is an automatic SQL Injection tool called as FatCat, Use of FatCat for&lt;br&gt;
vulnerability and start exploiting...&lt;br&gt;</description>
  </item>
  <item>
    <title>[ GLSA 201201-17 ] Chromium: Multiple	vulnerabilities</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/533</link>
    <description>&lt;p&gt;Posted by Tim Sammut on Jan 27&lt;/p&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br&gt;
     Date: January 28,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when did piracy/theft become expression of	freedom</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/532</link>
    <description>&lt;p&gt;Posted by Zach C. on Jan 27&lt;/p&gt;the&lt;br&gt;
you prefer,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when did piracy/theft become expression	of	freedom</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/531</link>
    <description>&lt;p&gt;Posted by Thor (Hammer of God) on Jan 27&lt;/p&gt;These arguments do more harm than good.  You can&amp;apos;t base property law on what people may not have done (of course there &lt;br&gt;
street and buy a similar product for less money.  That...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when did piracy/theft become expression of	freedom</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/530</link>
    <description>&lt;p&gt;Posted by Valdis . Kletnieks on Jan 27&lt;/p&gt;On Fri, 27 Jan 2012 18:06:28 GMT, Michael Schmidt said:&lt;br&gt;
2) Who gets those...&lt;br&gt;</description>
  </item>
  <item>
    <title>[ GLSA 201201-16 ] X.Org X Server/X Keyboard	Configuration Database: Screen lock bypass</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/529</link>
    <description>&lt;p&gt;Posted by Alex Legler on Jan 27&lt;/p&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br&gt;
    Title: X.Org X Server/X Keyboard Configuration Database: Screen...&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY] [DSA 2396-1] qemu-kvm security update</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/528</link>
    <description>&lt;p&gt;Posted by Moritz Muehlenhoff on Jan 27&lt;/p&gt;-------------------------------------------------------------------------&lt;br&gt;
Problem type   :...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when did piracy/theft become expression of freedom</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/527</link>
    <description>&lt;p&gt;Posted by Laurelai on Jan 27&lt;/p&gt;Yeah and the US is becoming a police state, so using US law as examples&lt;br&gt;
of morality is pretty shaky ground.&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY] [DSA 2395-1] wireshark security update</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/526</link>
    <description>&lt;p&gt;Posted by Moritz Muehlenhoff on Jan 27&lt;/p&gt;-------------------------------------------------------------------------&lt;br&gt;
Problem type...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when did piracy/theft become expression of freedom</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/525</link>
    <description>&lt;p&gt;Posted by Michael Schmidt on Jan 27&lt;/p&gt;You want to be very careful with that line of thought. You are taking the creator the rightful owners profits, which &lt;br&gt;
When you make a copy, you are performing a step that the manufacturer takes with physical products. Just because...&lt;br&gt;</description>
  </item>
  <item>
    <title>Advisory: Remote Command Execution in Gitorious</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/524</link>
    <description>&lt;p&gt;Posted by joernchen of Phenoelit on Jan 27&lt;/p&gt;Hi,&lt;br&gt;
joernchen&lt;br&gt;</description>
  </item>
  <item>
    <title>Fortigate UTM WAF Appliance - Multiple Web	Vulnerabilities</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/523</link>
    <description>&lt;p&gt;Posted by research () vulnerability-lab com on Jan 27&lt;/p&gt;Title:&lt;br&gt;
and Web traffic such as viruses, worms, intrusions, inappropriate Web content and more in real time...&lt;br&gt;</description>
  </item>
  <item>
    <title>[ GLSA 201201-15 ] ktsuss: Privilege escalation</title>
    <link>http://seclists.org/fulldisclosure/2012/Jan/522</link>
    <description>&lt;p&gt;Posted by Sean Amoss on Jan 27&lt;/p&gt;- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -&lt;br&gt;
     Date: January 27, 2012...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Funsec</title>
    <link>http://seclists.org/#funsec</link>
    <description>While most security lists ban off-topic discussion, Funsec is a haven for free community discussion and enjoyment of the lighter, more humorous side of the security community</description>
  <item>
    <title>..twitter rights</title>
    <link>http://seclists.org/funsec/2012/q1/113</link>
    <description>&lt;p&gt;Posted by RandallM on Jan 28&lt;/p&gt;is posting attacking us gov site, or exposing personal info of another&lt;br&gt;
What is twitters take?&lt;br&gt;</description>
  </item>
  <item>
    <title>Really simple security blog</title>
    <link>http://seclists.org/funsec/2012/q1/112</link>
    <description>&lt;p&gt;Posted by Robert Slade on Jan 27&lt;/p&gt;This was a new one to me, anyway.&lt;br&gt;
for your boss  :-)&lt;br&gt;</description>
  </item>
  <item>
    <title>Twitter nation-based censorship</title>
    <link>http://seclists.org/funsec/2012/q1/111</link>
    <description>&lt;p&gt;Posted by Robert Slade on Jan 27&lt;/p&gt;A large stake in Twitter was recently bought by a Saudi prince.  He said he agreed with the concept.&lt;br&gt;
Of course, this timing is simply a coincidence.  There couldn&amp;apos;t possibly be any relationship.&lt;br&gt;</description>
  </item>
  <item>
    <title>Privacy Policy</title>
    <link>http://seclists.org/funsec/2012/q1/110</link>
    <description>&lt;p&gt;Posted by Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah on Jan 26&lt;/p&gt;This seems vaguely familiar, but what the heck:&lt;br&gt;
victoria.tc.ca/techrev/rms.htm &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.infosecbc.org/links&quot;&gt;http://www.infosecbc.org/links&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>OK, we don&apos;t need the Borg for &quot;Total Recall&quot;</title>
    <link>http://seclists.org/funsec/2012/q1/109</link>
    <description>&lt;p&gt;Posted by Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah on Jan 26&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.scientificamerican.com/article.cfm?id=totaling-recall&quot;&gt;http://www.scientificamerican.com/article.cfm?id=totaling-recall&lt;/a&gt;&lt;br&gt;
victoria.tc.ca/techrev/rms.htm &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.infosecbc.org/links&quot;&gt;http://www.infosecbc.org/links&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Announce] Reminder: HITB2012AMS Call For Papers	Closing Soon</title>
    <link>http://seclists.org/funsec/2012/q1/108</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jan 26&lt;/p&gt;This is a gentle reminder that the Call for Papers for the third annual&lt;br&gt;
featuring keynote speakers Andy Ellis (Chief...&lt;br&gt;</description>
  </item>
  <item>
    <title>Resistance is futile: you will be assimilated ...</title>
    <link>http://seclists.org/funsec/2012/q1/107</link>
    <description>&lt;p&gt;Posted by Rob, grandpa of Ryan, Trevor, Devon &amp; Hannah on Jan 26&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://thenextweb.com/socialmedia/2012/01/25/facebook-is-killing-local-social-&quot;&gt;http://thenextweb.com/socialmedia/2012/01/25/facebook-is-killing-local-social-&lt;/a&gt;&lt;br&gt;
victoria.tc.ca/techrev/rms.htm &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.infosecbc.org/links&quot;&gt;http://www.infosecbc.org/links&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Teaching reporters infosec ...</title>
    <link>http://seclists.org/funsec/2012/q1/106</link>
    <description>&lt;p&gt;Posted by Kyle Creyts on Jan 25&lt;/p&gt;Flashy and interesting like using the mouse to move your cursor around,&lt;br&gt;
not quite &amp;quot;strong&amp;quot; protection, but better than nothing in some cases.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Teaching reporters infosec ...</title>
    <link>http://seclists.org/funsec/2012/q1/105</link>
    <description>&lt;p&gt;Posted by Paul M Moriarty on Jan 25&lt;/p&gt;While doing something flashy and interesting with your left hand, type your message quickly with your right hand.  The &lt;br&gt;
keyloggers fall for it every time.  :)&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Teaching reporters infosec ...</title>
    <link>http://seclists.org/funsec/2012/q1/104</link>
    <description>&lt;p&gt;Posted by Patrick Laverty on Jan 25&lt;/p&gt;I thought this line interesting:&lt;br&gt;
What does that mean to trick a keylogger?&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Teaching reporters infosec ...</title>
    <link>http://seclists.org/funsec/2012/q1/103</link>
    <description>&lt;p&gt;Posted by Paul M Moriarty on Jan 25&lt;/p&gt;It&amp;apos;s a step in the right direction, though clearly it will be a long journey.&lt;br&gt;
- Paul -&lt;br&gt;</description>
  </item>
  <item>
    <title>Teaching reporters infosec ...</title>
    <link>http://seclists.org/funsec/2012/q1/102</link>
    <description>&lt;p&gt;Posted by Robert Slade on Jan 25&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cjr.org/the_news_frontier/teaching_cyber-security.php&quot;&gt;http://www.cjr.org/the_news_frontier/teaching_cyber-security.php&lt;/a&gt;&lt;br&gt;
CISSP...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Google Docs illegal in Norway</title>
    <link>http://seclists.org/funsec/2012/q1/101</link>
    <description>&lt;p&gt;Posted by Paul Ferguson on Jan 25&lt;/p&gt;Funny you should mention that:&lt;br&gt;
- ferg&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Google Docs illegal in Norway</title>
    <link>http://seclists.org/funsec/2012/q1/100</link>
    <description>&lt;p&gt;Posted by Jeffrey Walton on Jan 25&lt;/p&gt;The PATRIOT Act is gestapo legislation - its a subversion of the&lt;br&gt;
who drafted and...&lt;br&gt;</description>
  </item>
  <item>
    <title>BitDefender, you&apos;ve created a monster! (story ...)</title>
    <link>http://seclists.org/funsec/2012/q1/99</link>
    <description>&lt;p&gt;Posted by Robert Slade on Jan 25&lt;/p&gt;www.infosecurity-magazine.com/view/23465/viruses-and-worms-are-evolving-into-frankenmalware/&lt;br&gt;
threats from 25 years ago and dress...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Honeypots</title>
    <link>http://seclists.org/#honeypots</link>
    <description>Discussions about tracking attackers by setting up decoy honeypots or entire &lt;A HREF=&quot;http://www.honeynet.org&quot;&gt;honeynet&lt;/A&gt; networks.</description>
  <item>
    <title>[HONEYPOTS] Cyber Warfare / Network Defense Simulation</title>
    <link>http://seclists.org/honeypots/2012/q1/1</link>
    <description>&lt;p&gt;Posted by Teóphilo Athos Brauns on Jan 24&lt;/p&gt;Hi,&lt;br&gt;
managed to create a whole...&lt;br&gt;</description>
  </item>
  <item>
    <title>Cyber Warfare / Network Defense Simulation</title>
    <link>http://seclists.org/honeypots/2012/q1/0</link>
    <description>&lt;p&gt;Posted by Teóphilo Athos Brauns on Jan 24&lt;/p&gt;Hi,&lt;br&gt;
managed to create a...&lt;br&gt;</description>
  </item>
  <item>
    <title>CanSecWest 2012 Mar 7-9; 2nd call for papers, closes next week, Monday. Dec 5 2011</title>
    <link>http://seclists.org/honeypots/2011/q4/0</link>
    <description>&lt;p&gt;Posted by Dragos Ruiu on Dec 01&lt;/p&gt;So after a dozen years or so organizing conferences, you &lt;br&gt;
submissions and missing  the CFP. So for my control set,...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Incidents</title>
    <link>http://seclists.org/#incidents</link>
    <description>Lightly moderated list for dicussing actual security incidents (unexplained probes, breakins, etc).  Topics include information about new rootkits, backdoors, trojans, virii, and worms.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
  <title>Packet Storm &#8776; Full Disclosure Information Security</title>
  <description>Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers</description>
  <link>http://packetstormsecurity.org/</link>
  <image>
    <title>Packet Storm</title>
    <link>http://packetstormsecurity.org/</link>
    <url>http://www.google-analytics.com/__utm.gif?utmwv=1.3&amp;utmn=1363314962&amp;utmcs=ISO-8859-1&amp;utmsr=31337x31337&amp;utmsc=32-bit&amp;utmul=en-us&amp;utmje=0&amp;utmfl=-&amp;utmcn=1&amp;utmdt=%u2248%20Packet%20Storm&amp;utmhn=packetstormsecurity.org&amp;utmr=-&amp;utmp=%2F&amp;utmac=UA-18885198-1&amp;utmcc=__utma%3D32867617.1363314962.1327781348.1327781348.1327781348.1%3B%2B__utmz%3D32867617.1327781348.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none)</url>
  </image>
<item>
<title>Students Busted For Hacking Computers, Changing Grades</title>
<link>http://packetstormsecurity.org/news/view/20518/Students-Busted-For-Hacking-Computers-Changing-Grades.html</link>
<description></description>
</item>
<item>
<title>European Parliament Rapporteur Quits In Acta Protest</title>
<link>http://packetstormsecurity.org/news/view/20514/European-Parliament-Rapporteur-Quits-In-Acta-Protest.html</link>
<description></description>
</item>
<item>
<title>Kelios Botnet Suspect Denies Microsoft Accusations</title>
<link>http://packetstormsecurity.org/news/view/20519/Kelios-Botnet-Suspect-Denies-Microsoft-Accusations.html</link>
<description></description>
</item>
<item>
<title>Anonymous&#39; Topiary Gets A Plea Date</title>
<link>http://packetstormsecurity.org/news/view/20520/Anonymous-Topiary-Gets-A-Plea-Date.html</link>
<description></description>
</item>
<item>
<title>US Lawmakers Question Google Over Privacy Policy</title>
<link>http://packetstormsecurity.org/news/view/20517/US-Lawmakers-Question-Google-Over-Privacy-Policy.html</link>
<description></description>
</item>
<item>
<title>Judges Set Timetable For McKinnon Case Resolution</title>
<link>http://packetstormsecurity.org/news/view/20516/Judges-Set-Timetable-For-McKinnon-Case-Resolution.html</link>
<description></description>
</item>
<item>
<title>Facebook And Washington State Take On A Clickjacker</title>
<link>http://packetstormsecurity.org/news/view/20515/Facebook-And-Washington-State-Take-On-A-Clickjacker.html</link>
<description></description>
</item>
<item>
<title>Linux Vendors Urgently Patch A Security Flaw</title>
<link>http://packetstormsecurity.org/news/view/20513/Linux-Vendors-Urgently-Patch-A-Security-Flaw.html</link>
<description></description>
</item>
<item>
<title>Sophos Warns Of Rising Android Malware Threats In 2012</title>
<link>http://packetstormsecurity.org/news/view/20512/Sophos-Warns-Of-Rising-Android-Malware-Threats-In-2012.html</link>
<description></description>
</item>
<item>
<title>How Google Keeps Your Secrets Private</title>
<link>http://packetstormsecurity.org/news/view/20511/How-Google-Keeps-Your-Secrets-Private.html</link>
<description></description>
</item>
<item>
<title>FBI Plans Social Network Map Alert Mash-Up Application</title>
<link>http://packetstormsecurity.org/news/view/20510/FBI-Plans-Social-Network-Map-Alert-Mash-Up-Application.html</link>
<description></description>
</item>
<item>
<title>Backlash Over Google Move To Change Privacy Settings</title>
<link>http://packetstormsecurity.org/news/view/20509/Backlash-Over-Google-Move-To-Change-Privacy-Settings.html</link>
<description></description>
</item>
<item>
<title>O2 Caught Revealing Users&#39; Mobile Phone Numbers</title>
<link>http://packetstormsecurity.org/news/view/20508/O2-Caught-Revealing-Users-Mobile-Phone-Numbers.html</link>
<description></description>
</item>
<item>
<title>Judges Probe Minister&#39;s Role In McKinnon Extradition Saga</title>
<link>http://packetstormsecurity.org/news/view/20507/Judges-Probe-Ministers-Role-In-McKinnon-Extradition-Saga.html</link>
<description></description>
</item>
<item>
<title>Gitorious Remote Command Execution</title>
<link>http://packetstormsecurity.org/files/109178/advisory_gitorious.txt</link>
<description>Gitorious versions prior to 2.1.1 suffer from a remote command execution vulnerability.</description>
</item>
<item>
<title>HP Diagnostics Server magentservice.exe Overflow</title>
<link>http://packetstormsecurity.org/files/109177/hp_magentservice.rb.txt</link>
<description>This Metasploit module exploits a stack buffer overflow in HP Diagnostics Server magentservice.exe service. By sending a specially crafted packet, an attacker may be able to execute arbitrary code. Originally found and posted by AbdulAziz Harir via ZDI.</description>
</item>
<item>
<title>MS12-004 midiOutPlayNextPolyEvent Heap Overflow</title>
<link>http://packetstormsecurity.org/files/109176/ms12_004_midi.rb.txt</link>
<description>This Metasploit module exploits a heap overflow vulnerability in the Windows Multimedia Library (winmm.dll). The vulnerability occurs when parsing specially crafted MIDI files. Remote code execution can be achieved by using Windows Media Player&#39;s ActiveX control. Exploitation is done by supplying a specially crafted MIDI file with specific events, causing the offset calculation being higher than how much is available on the heap (0x400 allocated by WINMM!winmmAlloc), and then allowing us to either &quot;inc al&quot; or &quot;dec al&quot; a byte. This can be used to corrupt an array (CImplAry) we setup, and force the browser to confuse types from tagVARIANT objects, which leverages remote code execution under the context of the user. At this time, for IE 8 target, JRE (Java Runtime Environment) is required to bypass DEP (Data Execution Prevention). Note: Based on our testing, the vulnerability does not seem to trigger when the victim machine is operated via rdesktop.</description>
</item>
<item>
<title>AWS Hash Collisions</title>
<link>http://packetstormsecurity.org/files/109175/SA-2012-L119-003.txt</link>
<description>AdaCore Security Advisory - All AWS releases and wavefronts prior to 2012-01-21 suffer from hash collision vulnerabilities.</description>
</item>
<item>
<title>Studio Manolibera Listarivisteuk SQL Injection</title>
<link>http://packetstormsecurity.org/files/109174/smlistarivisteuk-sql.txt</link>
<description>Studio Manolibera&#39;s listarivisteuk.php suffers from a remote SQL injection vulnerability.</description>
</item>
<item>
<title>Dark D0rk3r 0.5</title>
<link>http://packetstormsecurity.org/files/109171/darkd0rk3r-0.5.py.txt</link>
<description>Dark D0rk3r is a python script that performs dork searching and searches for local file inclusion and SQL injection errors.</description>
</item>
<item>
<title>IBBY SQL Injection</title>
<link>http://packetstormsecurity.org/files/109169/ibbynouvelles-sql.txt</link>
<description>IBBY&#39;s nouvelles.php suffers from a remote SQL injection vulnerability.</description>
</item>
<item>
<title>Kraken Payload Generator Beta 1.0</title>
<link>http://packetstormsecurity.org/files/109170/kraken-script.rar</link>
<description>Kraken Payload Generator is a bash script that makes use of msfpayload to generate various shellcode.</description>
</item>
<item>
<title>Fortigate UTM WAF Appliance Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109168/VL-144.txt</link>
<description>The Fortigate UTM WAF appliance suffers from persistent and reflective cross site scripting vulnerabilities.</description>
</item>
<item>
<title>Adobe Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109167/adobesite-xss.txt</link>
<description>Adobe&#39;s forgotten password flow suffers from a cross site scripting vulnerability.</description>
</item>
<item>
<title>Gentoo Linux Security Advisory 201201-16</title>
<link>http://packetstormsecurity.org/files/109166/glsa-201201-16.txt</link>
<description>Gentoo Linux Security Advisory 201201-16 - A debugging functionality in the X.Org X Server that is bound to a hotkey by default can be used by local attackers to circumvent screen locking utilities. Versions less than 2.4.1-r3 are affected.</description>
</item>
<item>
<title>Debian Security Advisory 2396-1</title>
<link>http://packetstormsecurity.org/files/109165/dsa-2396-1.txt</link>
<description>Debian Linux Security Advisory 2396-1 - Nicolae Mogoraenu discovered a heap overflow in the emulated e1000e network interface card of KVM, a solution for full virtualization on x86 hardware, which could result in denial of service or privilege escalation.</description>
</item>
<item>
<title>Debian Security Advisory 2395-1</title>
<link>http://packetstormsecurity.org/files/109164/dsa-2395-1.txt</link>
<description>Debian Linux Security Advisory 2395-1 - Laurent Butti discovered a buffer underflow in the LANalyzer dissector of the Wireshark network traffic analyzer, which could lead to the execution of arbitrary code.</description>
</item>
<item>
<title>Interactive Web Design SQL Injection</title>
<link>http://packetstormsecurity.org/files/109156/interactivewebdesign-sql.txt</link>
<description>Interactive Web Design suffers from a remote SQL injection vulnerability.</description>
</item>
<item>
<title>Global Media Service SQL Injection</title>
<link>http://packetstormsecurity.org/files/109155/gms-sql.txt</link>
<description>Global Media Service suffers from a remote SQL injection vulnerability.</description>
</item>
<item>
<title>Gentoo Linux Security Advisory 201201-15</title>
<link>http://packetstormsecurity.org/files/109154/glsa-201201-15.txt</link>
<description>Gentoo Linux Security Advisory 201201-15 - Two vulnerabilities have been found in ktsuss, allowing local attackers to gain escalated privileges. Versions less than or equal to 1.4 are affected.</description>
</item>
<item>
<title>Debian Security Advisory 2394-1</title>
<link>http://packetstormsecurity.org/files/109153/dsa-2394-1.txt</link>
<description>Debian Linux Security Advisory 2394-1 - Many security problems had been fixed in libxml2, a popular library to handle XML data files.</description>
</item>
<item>
<title>vBSEO 3.6.0 proc_deutf() Remote PHP Code Injection</title>
<link>http://packetstormsecurity.org/files/109179/vbseo-exec.rb.txt</link>
<description>This Metasploit module exploits a vulnerability in the &#39;proc_deutf()&#39; function defined in /includes/functions_vbseocp_abstract.php. User input passed through &#39;char_repl&#39; POST parameter isn&#39;t properly sanitized before being used in a call to preg_replace() function which uses the &#39;e&#39; modifier. This can be exploited to inject and execute arbitrary code leveraging the PHP&#39;s complex curly syntax.</description>
</item>
<item>
<title>Peel SHOPPING 2.8 / 2.9 Cross Site Scripting / SQL Injection</title>
<link>http://packetstormsecurity.org/files/109130/peelshopping-sqlxss.txt</link>
<description>Peel SHOPPING versions 2.8 and 2.9 suffer from cross site scripting and remote SQL injection vulnerabilities.</description>
</item>
<item>
<title>RSA enVision Variable Disclosure</title>
<link>http://packetstormsecurity.org/files/109129/ESA-2012-007.txt</link>
<description>RSA has announced security fixes to address an environmental variable disclosure vulnerability in RSA enVision 4.x.</description>
</item>
<item>
<title>EMC NetWorker Buffer Overflow</title>
<link>http://packetstormsecurity.org/files/109128/ESA-2012-005.txt</link>
<description>EMC NetWorker Server 7.5.x and 7.6.x contain a buffer overflow vulnerability which may possibly be exploited to cause a denial of service or, possibly, arbitrary code execution.</description>
</item>
<item>
<title>xClick Cart 1.0.1 / 1.0.2 Cross Site Scripting</title>
<link>http://packetstormsecurity.org/files/109126/xclickcart-xss.txt</link>
<description>xClick Cart versions 1.0.1 and 1.0.2 suffer from a cross site scripting vulnerability.</description>
</item>
<item>
<title>Register Plus 3.5.1 Cross Site Scripting / Code Execution</title>
<link>http://packetstormsecurity.org/files/109125/registerplus-shellxss.txt</link>
<description>Register Plus versions 3.5.1 and below for WordPress suffer from code execution, cross site scripting and path disclosure vulnerabilities.</description>
</item>
<item>
<title>Sysax Multi Server 5.50 Create Folder Buffer Overflow</title>
<link>http://packetstormsecurity.org/files/109124/sysax2.rb.txt</link>
<description>This Metasploit module exploits a stack buffer overflow in the create folder function in Sysax Multi Server 5.50. This issue was fixed in 5.52. You must have valid credentials to trigger the vulnerability. Your credentials must also have the create folder permission and the HTTP option has to be enabled. This Metasploit module will log into the server, get your a SID token and then proceed to exploit the server. Successful exploits result in LOCALSYSTEM access. This exploit works on XP and 2003.</description>
</item>
<item>
<title>Cisco Security Advisory 20120126-ironport</title>
<link>http://packetstormsecurity.org/files/109123/cisco-sa-20120126-ironport.txt</link>
<description>Cisco Security Advisory - Cisco IronPort Email Security Appliances (ESA) and Cisco IronPort Security Management Appliances (SMA) contain a vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code with elevated privileges. Workarounds that mitigate this vulnerability are available.</description>
</item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Info Security News</title>
    <link>http://seclists.org/#isn</link>
    <description>Carries news items (generally from mainstream sources) that relate to security.</description>
  <item>
    <title>DHS disputes memo on purported railway computer breach</title>
    <link>http://seclists.org/isn/2012/Jan/80</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 25&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://news.cnet.com/8301-27080_3-57366341-245/dhs-disputes-memo-on-purported-railway-computer-breach/&quot;&gt;http://news.cnet.com/8301-27080_3-57366341-245/dhs-disputes-memo-on-purported-railway-computer-breach/&lt;/a&gt;&lt;br&gt;
&amp;quot;Following more in-depth analysis, it appears that...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: The digital hacktivist</title>
    <link>http://seclists.org/isn/2012/Jan/79</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 25&lt;/p&gt;Forwarded from: security curmudgeon &amp;lt;jericho (at) attrition.org&amp;gt;&lt;br&gt;
: out of information that is freely available...&lt;br&gt;</description>
  </item>
  <item>
    <title>IT pros say data breach assessment is more valuable than notification, study says</title>
    <link>http://seclists.org/isn/2012/Jan/78</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 25&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.computerworld.com/s/article/9223706/IT_pros_say_data_breach_assessment_is_more_valuable_than_notification_study_says&quot;&gt;http://www.computerworld.com/s/article/9223706/IT_pros_say_data_breach_assessment_is_more_valuable_than_notification_study_says&lt;/a&gt;&lt;br&gt;
the day the European Union&amp;apos;s proposed a...&lt;br&gt;</description>
  </item>
  <item>
    <title>DOD to allow Android on classified networks</title>
    <link>http://seclists.org/isn/2012/Jan/77</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 25&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://fcw.com/articles/2012/01/24/android-smart-phones-tablets-classified-sipr-network.aspx&quot;&gt;http://fcw.com/articles/2012/01/24/android-smart-phones-tablets-classified-sipr-network.aspx&lt;/a&gt;&lt;br&gt;
approving the standards, according to Michael...&lt;br&gt;</description>
  </item>
  <item>
    <title>Symantec advises users to turn off PCAnywhere in hack	aftermath</title>
    <link>http://seclists.org/isn/2012/Jan/76</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 25&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.v3.co.uk/v3-uk/news/2141452/symantec-advises-users-pcanywhere-hack-aftermath&quot;&gt;http://www.v3.co.uk/v3-uk/news/2141452/symantec-advises-users-pcanywhere-hack-aftermath&lt;/a&gt;&lt;br&gt;
attackers gaining access to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Newt Threatens China and Russia With Cyberwar</title>
    <link>http://seclists.org/isn/2012/Jan/75</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 25&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.wired.com/dangerroom/2012/01/newt-goes-to-cyberwar/&quot;&gt;http://www.wired.com/dangerroom/2012/01/newt-goes-to-cyberwar/&lt;/a&gt;&lt;br&gt;
“I think that we have to treat state-based covert activities as the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Royal Canadian Navy officer charged with espionage</title>
    <link>http://seclists.org/isn/2012/Jan/74</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 25&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.theargus.ca/articles/news/2012/01/royal-canadian-navy-officer-charged-with-espionage&quot;&gt;http://www.theargus.ca/articles/news/2012/01/royal-canadian-navy-officer-charged-with-espionage&lt;/a&gt;&lt;br&gt;
of Information Act, which superseded the Official Secrets Act shortly...&lt;br&gt;</description>
  </item>
  <item>
    <title>10K Reasons to Worry About Critical Infrastructure</title>
    <link>http://seclists.org/isn/2012/Jan/73</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 24&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.wired.com/threatlevel/2012/01/10000-control-systems-online/&quot;&gt;http://www.wired.com/threatlevel/2012/01/10000-control-systems-online/&lt;/a&gt;&lt;br&gt;
Infrastructure software vendors and critical...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Names Alleged Botnet Operator Behind Kelihos</title>
    <link>http://seclists.org/isn/2012/Jan/72</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 24&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.darkreading.com/insider-threat/167801100/security/client-security/232500407/microsoft-names-alleged-botnet-operator-behind-kelihos.html&quot;&gt;http://www.darkreading.com/insider-threat/167801100/security/client-security/232500407/microsoft-names-alleged-botnet-operator-behind-kelihos.html&lt;/a&gt;&lt;br&gt;
been added to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Linux vendors rush to patch privilege escalation flaw after root exploits emerge</title>
    <link>http://seclists.org/isn/2012/Jan/71</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 24&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.computerworld.com/s/article/9223675/Linux_vendors_rush_to_patch_privilege_escalation_flaw_after_root_exploits_emerge&quot;&gt;http://www.computerworld.com/s/article/9223675/Linux_vendors_rush_to_patch_privilege_escalation_flaw_after_root_exploits_emerge&lt;/a&gt;&lt;br&gt;
by JA1/4ri Aedla and...&lt;br&gt;</description>
  </item>
  <item>
    <title>Navy faces crushing demand for information warfare systems</title>
    <link>http://seclists.org/isn/2012/Jan/70</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 24&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.nextgov.com/nextgov/ng_20120124_9453.php&quot;&gt;http://www.nextgov.com/nextgov/ng_20120124_9453.php&lt;/a&gt;&lt;br&gt;
Last year, the Navy installed...&lt;br&gt;</description>
  </item>
  <item>
    <title>The digital hacktivist</title>
    <link>http://seclists.org/isn/2012/Jan/69</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 24&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.livemint.com/2012/01/24210113/The-digital-hacktivist.html&quot;&gt;http://www.livemint.com/2012/01/24210113/The-digital-hacktivist.html&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityerrata.org/errata/charlatan/ankit_fadia/&quot;&gt;http://securityerrata.org/errata/charlatan/ankit_fadia/&lt;/a&gt;  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Hackers manipulated railway computers, TSA memo says</title>
    <link>http://seclists.org/isn/2012/Jan/68</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 24&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.nextgov.com/nextgov/ng_20120123_3491.php&quot;&gt;http://www.nextgov.com/nextgov/ng_20120123_3491.php&lt;/a&gt;&lt;br&gt;
while&amp;quot; and...&lt;br&gt;</description>
  </item>
  <item>
    <title>U.S. Government Online Security Website Hacked</title>
    <link>http://seclists.org/isn/2012/Jan/67</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 24&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.pcworld.com/businesscenter/article/248644/us_government_online_security_website_hacked.html&quot;&gt;http://www.pcworld.com/businesscenter/article/248644/us_government_online_security_website_hacked.html&lt;/a&gt;&lt;br&gt;
threatened &amp;quot;a...&lt;br&gt;</description>
  </item>
  <item>
    <title>Cameras May Open Up the Board Room to Hackers</title>
    <link>http://seclists.org/isn/2012/Jan/66</link>
    <description>&lt;p&gt;Posted by InfoSec News on Jan 24&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.nytimes.com/2012/01/23/technology/flaws-in-videoconferencing-systems-put-boardrooms-at-risk.html&quot;&gt;http://www.nytimes.com/2012/01/23/technology/flaws-in-videoconferencing-systems-put-boardrooms-at-risk.html&lt;/a&gt;&lt;br&gt;
occasionally zooming...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Metasploit</title>
    <link>http://seclists.org/#metasploit</link>
    <description>Development discussion for &lt;a href=&quot;http://metasploit.com/&quot;&gt;Metasploit&lt;/a&gt;, the premier open source remote exploitation tool</description>
  <item>
    <title>Re: wdbrpc_memory_dump.rb bug and question</title>
    <link>http://seclists.org/metasploit/2012/q1/45</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 25&lt;/p&gt;The only reason I moved the original file away was in case it&lt;br&gt;
some time in the future....&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: wdbrpc_memory_dump.rb bug and question</title>
    <link>http://seclists.org/metasploit/2012/q1/44</link>
    <description>&lt;p&gt;Posted by Joshua J. Drake on Jan 25&lt;/p&gt;Robin,&lt;br&gt;
supported. This is due to some strangeness with ruby&amp;apos;s...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: wdbrpc_memory_dump.rb bug and question</title>
    <link>http://seclists.org/metasploit/2012/q1/43</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 25&lt;/p&gt;I&amp;apos;ve just reproduced this showing the directory exists but the file&lt;br&gt;
[*] Dumping 0x10000000 bytes from base...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: mssql_enum bug</title>
    <link>http://seclists.org/metasploit/2012/q1/42</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;I&amp;apos;ve created a ticket for it, I&amp;apos;ll see about getting a PCAP but it is&lt;br&gt;
Robin&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: wdbrpc_memory_dump.rb bug and question</title>
    <link>http://seclists.org/metasploit/2012/q1/41</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;The directory existed. I had started dumping with a 2 on the end and&lt;br&gt;
Robin&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: mssql_enum bug</title>
    <link>http://seclists.org/metasploit/2012/q1/40</link>
    <description>&lt;p&gt;Posted by HD Moore on Jan 24&lt;/p&gt;Our hand-coded MSSQL driver likely can&amp;apos;t cope with MSSQL 7 - a Redmine&lt;br&gt;
-HD&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: wdbrpc_memory_dump.rb bug and question</title>
    <link>http://seclists.org/metasploit/2012/q1/39</link>
    <description>&lt;p&gt;Posted by HD Moore on Jan 24&lt;/p&gt;This is a problem with your local filesystem - you may need to mkdir&lt;br&gt;
-HD&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: http_ntlm module output file format</title>
    <link>http://seclists.org/metasploit/2012/q1/38</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;I was planning to have a go, just wanted to check there was no reason&lt;br&gt;
Robin&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: http_ntlm module output file format</title>
    <link>http://seclists.org/metasploit/2012/q1/37</link>
    <description>&lt;p&gt;Posted by Tod Beardsley on Jan 24&lt;/p&gt;The SMB capture module will output a John the Ripper compatible file.&lt;br&gt;
Robin...&lt;br&gt;</description>
  </item>
  <item>
    <title>http_ntlm module output file format</title>
    <link>http://seclists.org/metasploit/2012/q1/36</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;I&amp;apos;m playing with NBNS spoofing from this post on Packetstan&lt;br&gt;
Robin&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: mssql_enum bug</title>
    <link>http://seclists.org/metasploit/2012/q1/35</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;I just tried to connect to this with the MS SQL Enterprise Manager&lt;br&gt;
Robin&lt;br&gt;</description>
  </item>
  <item>
    <title>mssql_enum bug</title>
    <link>http://seclists.org/metasploit/2012/q1/34</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;Everything is set correctly and Nessus reported the install as having&lt;br&gt;
the specified...&lt;br&gt;</description>
  </item>
  <item>
    <title>wdbrpc_memory_dump.rb bug and question</title>
    <link>http://seclists.org/metasploit/2012/q1/33</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;First the bug, I think this is because I set an offset but pointed it&lt;br&gt;
/Users/robin/.msf4/logs/vxworks_memory3.dump...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: H.D. Moore in NY Times</title>
    <link>http://seclists.org/metasploit/2012/q1/32</link>
    <description>&lt;p&gt;Posted by HD Moore on Jan 23&lt;/p&gt;Additional information on the blog:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://community.rapid7.com/community/solutions/metasploit/blog/2012/01/23/video-conferencing-and-self-selecting-targets&quot;&gt;https://community.rapid7.com/community/solutions/metasploit/blog/2012/01/23/video-conferencing-and-self-selecting-targets&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: possible bug in auxiliary/gather/shodan_search</title>
    <link>http://seclists.org/metasploit/2012/q1/31</link>
    <description>&lt;p&gt;Posted by Jonathan Cran on Jan 23&lt;/p&gt;BG - I believe this has been resolved in the trunk by sinn3r, can you&lt;br&gt;
jcran&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Microsoft Sec Notification</title>
    <link>http://seclists.org/#microsoft</link>
    <description>Beware that MS often uses these security bulletins as marketing propaganda to downplay serious vulnerabilities in their products&amp;mdash;note how most have a prominent and often-misleading &quot;mitigating factors&quot; section.</description>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2012/q1/10</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 27&lt;/p&gt;********************************************************************&lt;br&gt;
* MS12-004 -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2012/q1/9</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 24&lt;/p&gt;********************************************************************&lt;br&gt;
=====================...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2012/q1/8</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 18&lt;/p&gt;********************************************************************&lt;br&gt;
Bulletin Information:...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2012/q1/7</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 17&lt;/p&gt;********************************************************************&lt;br&gt;
  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2012/q1/6</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 16&lt;/p&gt;********************************************************************&lt;br&gt;
* MS12-007 - Important...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Re-Releases</title>
    <link>http://seclists.org/microsoft/2012/q1/5</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 11&lt;/p&gt;********************************************************************&lt;br&gt;
* MS12-007 -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2012/q1/4</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 11&lt;/p&gt;********************************************************************&lt;br&gt;
  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Summary for January 2012</title>
    <link>http://seclists.org/microsoft/2012/q1/3</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 10&lt;/p&gt;********************************************************************&lt;br&gt;
With...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Advisory Notification</title>
    <link>http://seclists.org/microsoft/2012/q1/2</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 10&lt;/p&gt;********************************************************************&lt;br&gt;
  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2012/q1/1</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 10&lt;/p&gt;********************************************************************&lt;br&gt;
* MS11-099 - Important...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Advance Notification for January 2012</title>
    <link>http://seclists.org/microsoft/2012/q1/0</link>
    <description>&lt;p&gt;Posted by Microsoft on Jan 08&lt;/p&gt;********************************************************************&lt;br&gt;
Notification for January 2012 can be found at...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2011/q4/33</link>
    <description>&lt;p&gt;Posted by Microsoft on Dec 30&lt;/p&gt;********************************************************************&lt;br&gt;
* MS11-100 - Critical...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Advisory Notification</title>
    <link>http://seclists.org/microsoft/2011/q4/32</link>
    <description>&lt;p&gt;Posted by Microsoft on Dec 29&lt;/p&gt;********************************************************************&lt;br&gt;
  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Summary for December 2011</title>
    <link>http://seclists.org/microsoft/2011/q4/31</link>
    <description>&lt;p&gt;Posted by Microsoft on Dec 29&lt;/p&gt;********************************************************************&lt;br&gt;
December 2011 can be found at...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Advance Notification for December 2011</title>
    <link>http://seclists.org/microsoft/2011/q4/30</link>
    <description>&lt;p&gt;Posted by Microsoft on Dec 28&lt;/p&gt;********************************************************************&lt;br&gt;
Notification for December 2011 can be...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Nmap Development</title>
    <link>http://seclists.org/#nmap-dev</link>
    <description>Unmoderated technical development forum for debating ideas, patches, and suggestions regarding proposed changes to &lt;A HREF=&quot;http://nmap.org&quot;&gt;Nmap&lt;/A&gt; and related projects. Subscribe &lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-dev&quot;&gt;here&lt;/a&gt;.</description>
  <item>
    <title>New VA Modules: MSF: 2, Nessus: 11</title>
    <link>http://seclists.org/nmap-dev/2012/q1/245</link>
    <description>&lt;p&gt;Posted by New VA Module Alert Service on Jan 28&lt;/p&gt;This report describes any new scripts/modules/exploits added to Nmap,&lt;br&gt;
VMWare...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/244</link>
    <description>&lt;p&gt;Posted by Henri Doreau on Jan 27&lt;/p&gt;2012/1/27 Henri Doreau &amp;lt;henri.doreau () gmail com&amp;gt;:&lt;br&gt;
Regards.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/243</link>
    <description>&lt;p&gt;Posted by Henri Doreau on Jan 27&lt;/p&gt;2012/1/27 David Fifield &amp;lt;david () bamsoftware com&amp;gt;:&lt;br&gt;
with the bitfields used by select(), but that&amp;apos;s expensive...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/242</link>
    <description>&lt;p&gt;Posted by David Fifield on Jan 27&lt;/p&gt;Can you describe the bug and fix?&lt;br&gt;
David Fifield&lt;br&gt;</description>
  </item>
  <item>
    <title>New VA Modules: NSE: 3, OpenVAS: 2, MSF: 3, Nessus: 10</title>
    <link>http://seclists.org/nmap-dev/2012/q1/241</link>
    <description>&lt;p&gt;Posted by New VA Module Alert Service on Jan 27&lt;/p&gt;This report describes any new scripts/modules/exploits added to Nmap,&lt;br&gt;
allowing access are marked using the keyword Willing in...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/240</link>
    <description>&lt;p&gt;Posted by Henri Doreau on Jan 27&lt;/p&gt;2012/1/27 Ron &amp;lt;ron () skullsecurity net&amp;gt;:&lt;br&gt;
Thanks for testing, I have committed it as r27935.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/239</link>
    <description>&lt;p&gt;Posted by Ron on Jan 27&lt;/p&gt;The patch fixed the issue. Thanks!&lt;br&gt;
Ron&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/238</link>
    <description>&lt;p&gt;Posted by Henri Doreau on Jan 27&lt;/p&gt;2012/1/27 Ron &amp;lt;ron () skullsecurity net&amp;gt;:&lt;br&gt;
Regards.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/237</link>
    <description>&lt;p&gt;Posted by Ron on Jan 27&lt;/p&gt;I got it loaded in gdb. I don&amp;apos;t really know how to use gdb, though, so let me know if there are any commands you want &lt;br&gt;
    ms=&amp;lt;optimized out&amp;gt;,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/236</link>
    <description>&lt;p&gt;Posted by Henri Doreau on Jan 27&lt;/p&gt;2012/1/27 Ron &amp;lt;ron () skullsecurity net&amp;gt;:&lt;br&gt;
Regards.&lt;br&gt;</description>
  </item>
  <item>
    <title>Exception fail / crash</title>
    <link>http://seclists.org/nmap-dev/2012/q1/235</link>
    <description>&lt;p&gt;Posted by Ron on Jan 27&lt;/p&gt;Hey,&lt;br&gt;
not *fuzz* and not *firewalk* and not...&lt;br&gt;</description>
  </item>
  <item>
    <title>New VA Modules: OpenVAS: 2, MSF: 1, Nessus: 28</title>
    <link>http://seclists.org/nmap-dev/2012/q1/234</link>
    <description>&lt;p&gt;Posted by New VA Module Alert Service on Jan 26&lt;/p&gt;This report describes any new scripts/modules/exploits added to Nmap,&lt;br&gt;
EPractize Labs Subscription Manager &amp;apos;showImg.php&amp;apos; PHP Code Injection...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Unused captures in nmap-service-probes</title>
    <link>http://seclists.org/nmap-dev/2012/q1/233</link>
    <description>&lt;p&gt;Posted by David Fifield on Jan 26&lt;/p&gt;Thank you. This was very helpful. I committed your patch, some&lt;br&gt;
David Fifield&lt;br&gt;</description>
  </item>
  <item>
    <title>New VA Modules: NSE: 2, OpenVAS: 25, Nessus: 26</title>
    <link>http://seclists.org/nmap-dev/2012/q1/232</link>
    <description>&lt;p&gt;Posted by New VA Module Alert Service on Jan 25&lt;/p&gt;This report describes any new scripts/modules/exploits added to Nmap,&lt;br&gt;
r27899 iax2-brute...&lt;br&gt;</description>
  </item>
  <item>
    <title>Problems downloading</title>
    <link>http://seclists.org/nmap-dev/2012/q1/231</link>
    <description>&lt;p&gt;Posted by Brian Poppe on Jan 24&lt;/p&gt;Your servers are constantly timing out when trying to download the Windows installer.  The speeds will be 140-150KB/s &lt;br&gt;
Just...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Nmap Hackers</title>
    <link>http://seclists.org/#nmap-hackers</link>
    <description>Moderated list for the most important new releases and announcements regarding the &lt;A HREF=&quot;http://nmap.org&quot;&gt;Nmap Security Scanner&lt;/A&gt; and related projects. We recommend that all Nmap users &lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot;&gt;subscribe&lt;/a&gt;.</description>
  <item>
    <title>Updates on Download.Com caught adding malware to Nmap installer</title>
    <link>http://seclists.org/nmap-hackers/2011/6</link>
    <description>&lt;p&gt;Posted by Fyodor on Dec 06&lt;/p&gt;Hi Folks.  A lot has happened since yesterday&amp;apos;s email about&lt;br&gt;
software as a gift to the community, only to have it used as bait by...&lt;br&gt;</description>
  </item>
  <item>
    <title>C|Net Download.Com is now bundling Nmap with malware!</title>
    <link>http://seclists.org/nmap-hackers/2011/5</link>
    <description>&lt;p&gt;Posted by Fyodor on Dec 05&lt;/p&gt;Hi Folks.  I&amp;apos;ve just discovered that C|Net&amp;apos;s Download.Com site has&lt;br&gt;
The way it works is that C|Net&amp;apos;s download page (screenshot attached)...&lt;br&gt;</description>
  </item>
  <item>
    <title>SecTools.Org relaunched based on your survey responses!</title>
    <link>http://seclists.org/nmap-hackers/2011/4</link>
    <description>&lt;p&gt;Posted by Fyodor on Nov 04&lt;/p&gt;Hi folks!  Remember the latest Nmap survey that almost 3,000 of you&lt;br&gt;
lets you nominate your...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.59BETA1 Released!</title>
    <link>http://seclists.org/nmap-hackers/2011/3</link>
    <description>&lt;p&gt;Posted by Fyodor on Jun 30&lt;/p&gt;Hi Folks.  Other than the recent informal IPv6 commemorative edition,&lt;br&gt;
 o 40 new...&lt;br&gt;</description>
  </item>
  <item>
    <title>Happy World IPv6 Day From the Nmap Project!</title>
    <link>http://seclists.org/nmap-hackers/2011/2</link>
    <description>&lt;p&gt;Posted by Fyodor on Jun 08&lt;/p&gt;Hi Folks.  You have probably heard that today is World IPv6 Day, with&lt;br&gt;
That system now has native IPv6 support.  So...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.51 and SoC Opportunity</title>
    <link>http://seclists.org/nmap-hackers/2011/1</link>
    <description>&lt;p&gt;Posted by Fyodor on Apr 05&lt;/p&gt;Hi Folks!  I&amp;apos;m happy to report that the Nmap 5.50 release was a big&lt;br&gt;
threat to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.50: Now with Gopher protocol support!</title>
    <link>http://seclists.org/nmap-hackers/2011/0</link>
    <description>&lt;p&gt;Posted by Fyodor on Jan 28&lt;/p&gt;Hi folks!  It has been a year since the last Nmap stable release&lt;br&gt;
application protocols,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap Defcon Release: Version 5.35DC1</title>
    <link>http://seclists.org/nmap-hackers/2010/7</link>
    <description>&lt;p&gt;Posted by Fyodor on Jul 16&lt;/p&gt;Hi folks.  It has been 3.5 months since the last Nmap release&lt;br&gt;
Hat in a couple weeks (see...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap News and Last Chance to Take the Survey</title>
    <link>http://seclists.org/nmap-hackers/2010/6</link>
    <description>&lt;p&gt;Posted by Fyodor on Apr 30&lt;/p&gt;Hi Folks.  I have some Nmap news to share with you:&lt;br&gt;
Drazen Popovic and Djalal Harouni will be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Survey Reminder</title>
    <link>http://seclists.org/nmap-hackers/2010/5</link>
    <description>&lt;p&gt;Posted by Fyodor on Apr 14&lt;/p&gt;Hi folks, I have a quick question for you:&lt;br&gt;
survey up, tabulate and share results, choose the prize winners,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap/SecTools Survey and GSoC Deadline</title>
    <link>http://seclists.org/nmap-hackers/2010/4</link>
    <description>&lt;p&gt;Posted by Fyodor on Apr 07&lt;/p&gt;Hello everyone.  I hope you&amp;apos;re enjoying the 5.30BETA1 release.  So far&lt;br&gt;
summer!  SoC...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.30BETA1 Released w/37 new scripts and new Apple vuln</title>
    <link>http://seclists.org/nmap-hackers/2010/3</link>
    <description>&lt;p&gt;Posted by Fyodor on Mar 29&lt;/p&gt;Hi folks!  It has been two months since the 5.21 release and we&amp;apos;ve&lt;br&gt;
  ipidseq. Learn about them all at...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.21 released</title>
    <link>http://seclists.org/nmap-hackers/2010/2</link>
    <description>&lt;p&gt;Posted by Fyodor on Jan 27&lt;/p&gt;Hello everyone.  I&amp;apos;m pleased to release Nmap 5.21, which contains zero&lt;br&gt;
development projects.  If you want to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Lots of Nmap News</title>
    <link>http://seclists.org/nmap-hackers/2010/1</link>
    <description>&lt;p&gt;Posted by Fyodor on Jan 22&lt;/p&gt;Hi folks.  I&amp;apos;m happy to report that the 5.20 release went well.  But&lt;br&gt;
If you&amp;apos;re running from a build of the latest SVN...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.20 Released</title>
    <link>http://seclists.org/nmap-hackers/2010/0</link>
    <description>&lt;p&gt;Posted by Fyodor on Jan 20&lt;/p&gt;Happy new year, everyone.  I&amp;apos;m happy to announce Nmap 5.20--our first&lt;br&gt;
 o massive OS and version detection DB updates (10,000+ signatures)...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>OpenVAS</title>
    <link>http://seclists.org/#openvas</link>
    <description>Development and announcements regarding &lt;a href=&quot;http://www.openvas.com/&quot;&gt;OpenVAS&lt;/a&gt;, a free network security scanner which forked from Nessus. This is a combination of the English openvas-announce, openvas-devel, openvas-discuss, and openvas-plugins lists.</description>
  <item>
    <title>Windows 7 scan</title>
    <link>http://seclists.org/openvas/2012/q1/114</link>
    <description>&lt;p&gt;Posted by Guillaume Castagnino on Jan 27&lt;/p&gt;Hi,&lt;br&gt;
For point...&lt;br&gt;</description>
  </item>
  <item>
    <title>smb_reg_service_pack.nasl (10401)</title>
    <link>http://seclists.org/openvas/2012/q1/113</link>
    <description>&lt;p&gt;Posted by Guillaume Castagnino on Jan 27&lt;/p&gt;Hi list,&lt;br&gt;
   report = string(&amp;quot;The &amp;quot;, winName, &amp;quot; &amp;quot;,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: gsad not responding -&gt; 100% CPU</title>
    <link>http://seclists.org/openvas/2012/q1/112</link>
    <description>&lt;p&gt;Posted by Andreas Pflug on Jan 27&lt;/p&gt;Am 27.01.12 15:17, schrieb Andreas Pflug:&lt;br&gt;
I&amp;apos;m talking about gsad 2.0.1.&lt;br&gt;</description>
  </item>
  <item>
    <title>gsad not responding -&gt; 100% CPU</title>
    <link>http://seclists.org/openvas/2012/q1/111</link>
    <description>&lt;p&gt;Posted by Andreas Pflug on Jan 27&lt;/p&gt;When connecting to gsad via port 9392, the daemon will enter an endless&lt;br&gt;
this, the daemon has to be killed.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Small bug in vnc_security_types.nasl</title>
    <link>http://seclists.org/openvas/2012/q1/110</link>
    <description>&lt;p&gt;Posted by Michael Meyer on Jan 27&lt;/p&gt;Hello,&lt;br&gt;
Micha     &lt;br&gt;</description>
  </item>
  <item>
    <title>Task startup takes forever</title>
    <link>http://seclists.org/openvas/2012/q1/109</link>
    <description>&lt;p&gt;Posted by Derek Wuelfrath on Jan 26&lt;/p&gt;Hi list,&lt;br&gt;
132761198046E74B...&lt;br&gt;</description>
  </item>
  <item>
    <title>Small bug in vnc_security_types.nasl</title>
    <link>http://seclists.org/openvas/2012/q1/108</link>
    <description>&lt;p&gt;Posted by Torbjorn . Wictorin on Jan 26&lt;/p&gt;hello,&lt;br&gt;
Uppsala...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Regression GSD1.20-&gt;1.21: can&apos;t save report</title>
    <link>http://seclists.org/openvas/2012/q1/107</link>
    <description>&lt;p&gt;Posted by Andreas Pflug on Jan 26&lt;/p&gt;Am 26.01.2012 20:55, schrieb Matthew Mundell:&lt;br&gt;
All versions are the latest from the debian 6 repository, it&amp;apos;s 2.0.4.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Regression GSD1.20-&gt;1.21: can&apos;t save report</title>
    <link>http://seclists.org/openvas/2012/q1/106</link>
    <description>&lt;p&gt;Posted by Matthew Mundell on Jan 26&lt;/p&gt;Thanks Andreas.  This sounds related to the OMP time format change.  Which&lt;br&gt;
version of OpenVAS Manager are you using?&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Downtime next monday (30th)</title>
    <link>http://seclists.org/openvas/2012/q1/105</link>
    <description>&lt;p&gt;Posted by Jan-Oliver Wagner on Jan 26&lt;/p&gt;You mean www.openvas.com I guess.&lt;br&gt;
        Jan&lt;br&gt;</description>
  </item>
  <item>
    <title>GSD schedule ignores start date/time</title>
    <link>http://seclists.org/openvas/2012/q1/104</link>
    <description>&lt;p&gt;Posted by Andreas Pflug on Jan 26&lt;/p&gt;Creating a schedule using GSD 1.2.1 doesn&amp;apos;t allow setting the start date&lt;br&gt;
and time; the current date and time is always used.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Downtime next monday (30th)</title>
    <link>http://seclists.org/openvas/2012/q1/103</link>
    <description>&lt;p&gt;Posted by Tim Brown on Jan 26&lt;/p&gt;Any chance to use the US mirror for the website?&lt;br&gt;
Tim&lt;br&gt;</description>
  </item>
  <item>
    <title>Regression GSD1.20-&gt;1.21: can&apos;t save report</title>
    <link>http://seclists.org/openvas/2012/q1/102</link>
    <description>&lt;p&gt;Posted by Andreas Pflug on Jan 26&lt;/p&gt;With GSD 1.2.1, saving of reports fails silently on Windows as well as&lt;br&gt;
Andreas&lt;br&gt;</description>
  </item>
  <item>
    <title>Downtime next monday (30th)</title>
    <link>http://seclists.org/openvas/2012/q1/101</link>
    <description>&lt;p&gt;Posted by Jan-Oliver Wagner on Jan 26&lt;/p&gt;Hello,&lt;br&gt;
        Jan&lt;br&gt;</description>
  </item>
  <item>
    <title>Install instructions on Debian6</title>
    <link>http://seclists.org/openvas/2012/q1/100</link>
    <description>&lt;p&gt;Posted by Andreas Pflug on Jan 25&lt;/p&gt;The installation instructions at&lt;br&gt;
Andreas&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Open Source Security</title>
    <link>http://seclists.org/#oss-sec</link>
    <description>Discussion of security flaws, concepts, and practices in the Open Source community</description>
  <item>
    <title>(maybe) CVE request: libvpx before 1.0 crasher</title>
    <link>http://seclists.org/oss-sec/2012/q1/315</link>
    <description>&lt;p&gt;Posted by Hanno Böck on Jan 28&lt;/p&gt;libvpx (webm library) has released a new version that fixes a crasher&lt;br&gt;
(e.g. backends of video...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients</title>
    <link>http://seclists.org/oss-sec/2012/q1/314</link>
    <description>&lt;p&gt;Posted by Kurt Seifried on Jan 27&lt;/p&gt;Confirmed the code is basically identical, didn&amp;apos;t actually run them to&lt;br&gt;
test (since it&amp;apos;s been fixed in OpenBSD for quite some time now).&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: non-Linux advance notification list</title>
    <link>http://seclists.org/oss-sec/2012/q1/313</link>
    <description>&lt;p&gt;Posted by Solar Designer on Jan 27&lt;/p&gt;Hi,&lt;br&gt;
Or a port-security@ exploder that you&amp;apos;re...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: non-Linux advance notification list</title>
    <link>http://seclists.org/oss-sec/2012/q1/312</link>
    <description>&lt;p&gt;Posted by Stuart Henderson on Jan 27&lt;/p&gt;Could you add myself for OpenBSD ports please? If acceptable I&amp;apos;ll send a&lt;br&gt;
public key out of band. Thanks.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients</title>
    <link>http://seclists.org/oss-sec/2012/q1/311</link>
    <description>&lt;p&gt;Posted by Kurt Seifried on Jan 27&lt;/p&gt;Ok so we (myself and vdanen () redhat com) have done some more research and&lt;br&gt;
debug1: Remote: Forced...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: non-Linux advance notification list</title>
    <link>http://seclists.org/oss-sec/2012/q1/310</link>
    <description>&lt;p&gt;Posted by Solar Designer on Jan 27&lt;/p&gt;...&lt;br&gt;
Alexander&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: non-Linux advance notification list</title>
    <link>http://seclists.org/oss-sec/2012/q1/309</link>
    <description>&lt;p&gt;Posted by Solar Designer on Jan 27&lt;/p&gt;...&lt;br&gt;
Alexander&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Subscribe to linux-distros</title>
    <link>http://seclists.org/oss-sec/2012/q1/308</link>
    <description>&lt;p&gt;Posted by Ramon de C Valle on Jan 27&lt;/p&gt;Thanks.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Subscribe to linux-distros</title>
    <link>http://seclists.org/oss-sec/2012/q1/307</link>
    <description>&lt;p&gt;Posted by Solar Designer on Jan 27&lt;/p&gt;Subscribed.&lt;br&gt;
Alexander&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients</title>
    <link>http://seclists.org/oss-sec/2012/q1/306</link>
    <description>&lt;p&gt;Posted by Yves-Alexis Perez on Jan 27&lt;/p&gt;That was my question, in fact. Are separate keys (to the same user&lt;br&gt;
Regards,&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients</title>
    <link>http://seclists.org/oss-sec/2012/q1/305</link>
    <description>&lt;p&gt;Posted by Kurt Seifried on Jan 27&lt;/p&gt;I created three separate keys, so three separate accounts. I can&amp;apos;t see&lt;br&gt;
some automated job by the backup user) for example.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Subscribe to linux-distros</title>
    <link>http://seclists.org/oss-sec/2012/q1/304</link>
    <description>&lt;p&gt;Posted by Kurt Seifried on Jan 27&lt;/p&gt;I can confirm he is.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CVE request: PostfixAdmin SQL injections and XSS</title>
    <link>http://seclists.org/oss-sec/2012/q1/303</link>
    <description>&lt;p&gt;Posted by Christian Boltz on Jan 27&lt;/p&gt;Hello,&lt;br&gt;
which was found by Matthias Bethke &amp;lt;msbethke [at] sourceforge...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CVE Request: Debian (others?) openssh-server: Forced Command handling leaks private information to ssh clients</title>
    <link>http://seclists.org/oss-sec/2012/q1/302</link>
    <description>&lt;p&gt;Posted by Yves-Alexis Perez on Jan 27&lt;/p&gt;By the way, is the ForceCommand (and other directives) really supposed&lt;br&gt;
Regards,&lt;br&gt;</description>
  </item>
  <item>
    <title>Subscribe to linux-distros</title>
    <link>http://seclists.org/oss-sec/2012/q1/301</link>
    <description>&lt;p&gt;Posted by Ramon de C Valle on Jan 27&lt;/p&gt;Hi Solar,&lt;br&gt;
sub...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>PaulDotCom</title>
    <link>http://seclists.org/#pauldotcom</link>
    <description>General discussion of security news, research, vulnerabilities, and the PaulDotCom Security Weekly podcast.</description>
  <item>
    <title>XSS challenge, Filter #2 is up, can you break it?</title>
    <link>http://seclists.org/pauldotcom/2012/q1/114</link>
    <description>&lt;p&gt;Posted by Abraham Aranguren on Jan 28&lt;/p&gt;Hi folks,&lt;br&gt;
Thanks for trying!&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Bitcasa invites</title>
    <link>http://seclists.org/pauldotcom/2012/q1/113</link>
    <description>&lt;p&gt;Posted by Frank Forresrer on Jan 24&lt;/p&gt;I have infinite invites now.&lt;br&gt;
Sent from my iPod&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/112</link>
    <description>&lt;p&gt;Posted by David Freedman on Jan 24&lt;/p&gt;Agreed.  We already agreed that the log server and anywhere that data gets&lt;br&gt;
We have included this DB as an in scope system as per...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/111</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;One place I&amp;apos;ve found that isn&amp;apos;t always automatically considered in scope is&lt;br&gt;
that machine isn&amp;apos;t in the normal flow of data so people forget...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/110</link>
    <description>&lt;p&gt;Posted by Tony Turner on Jan 24&lt;/p&gt;Not yet. The SIG is moving very slowly. The only things I&amp;apos;ve seen so far are a comprehensive problem statement &lt;br&gt;
together and the issues that are preventing airlines from becoming compliant....&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/109</link>
    <description>&lt;p&gt;Posted by David Freedman on Jan 24&lt;/p&gt;I love Robin&amp;apos;s point about being concerned with the assessor&amp;apos;s abilities to&lt;br&gt;
solid compensating controls for the airlines?  I mean this with...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/108</link>
    <description>&lt;p&gt;Posted by Scott Rosenthal on Jan 24&lt;/p&gt;My response wasn&amp;apos;t about assuming that they were PCI compliant I was&lt;br&gt;
question was that he was merely questioning the storage of those cards. I...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Bitcasa invites</title>
    <link>http://seclists.org/pauldotcom/2012/q1/107</link>
    <description>&lt;p&gt;Posted by Xavier Mertens on Jan 24&lt;/p&gt;Am I not too late? Still one available? &lt;br&gt;
Tx!&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/106</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 24&lt;/p&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/105</link>
    <description>&lt;p&gt;Posted by Bill Swearingen on Jan 24&lt;/p&gt;Trent and I have discussed this with a stewardess, yes it is stored into&lt;br&gt;
stripe data on a valid...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/104</link>
    <description>&lt;p&gt;Posted by Tony Turner on Jan 24&lt;/p&gt;Many airlines are not PCI compliant. There are complexities to their business model with airports, common use platforms &lt;br&gt;
Sent from Yahoo! Mail on Android&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/103</link>
    <description>&lt;p&gt;Posted by Scott Rosenthal on Jan 24&lt;/p&gt;Hi Robin, here in the states many if not all of the airlines are required&lt;br&gt;
Scott&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Bitcasa invites</title>
    <link>http://seclists.org/pauldotcom/2012/q1/102</link>
    <description>&lt;p&gt;Posted by Udiggity on Jan 24&lt;/p&gt;I&amp;apos;d love one of you have any more&lt;br&gt;
Please excuse typos, I&amp;apos;m on my mobile&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/101</link>
    <description>&lt;p&gt;Posted by Bacon Zombie on Jan 24&lt;/p&gt;the fact that you can use a CC that is 10 years out of date I&amp;apos;m sure they&lt;br&gt;
 On Jan 24, 2012 5:43 AM, &amp;quot;Robin Wood&amp;quot; &amp;lt;robin () digininja org&amp;gt; wrote:&lt;br&gt;</description>
  </item>
  <item>
    <title>CC numbers stored on planes</title>
    <link>http://seclists.org/pauldotcom/2012/q1/100</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 23&lt;/p&gt;I&amp;apos;ve been on quite a few planes where the duty free and the bar allow&lt;br&gt;
Robin&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Penetration Testing</title>
    <link>http://seclists.org/#pen-test</link>
    <description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
  <item>
    <title>[HITB-Announce] Reminder: HITB2012AMS Call For Papers Closing Soon</title>
    <link>http://seclists.org/pen-test/2012/Jan/14</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jan 27&lt;/p&gt;This is a gentle reminder that the Call for Papers for the third annual&lt;br&gt;
featuring keynote speakers Andy Ellis (Chief...&lt;br&gt;</description>
  </item>
  <item>
    <title>DoS attacks using Exploit Pack</title>
    <link>http://seclists.org/pen-test/2012/Jan/13</link>
    <description>&lt;p&gt;Posted by noreply on Jan 22&lt;/p&gt;DoS attacks by using Exploit Pack&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://exploitpack.com&quot;&gt;http://exploitpack.com&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>Technology Neutral Healthcheck</title>
    <link>http://seclists.org/pen-test/2012/Jan/12</link>
    <description>&lt;p&gt;Posted by cribbar on Jan 19&lt;/p&gt;Can I ask if any of you have roles as security admins or managers if you have&lt;br&gt;
3rd party offering a solution/application for you that will give...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Goofile 1.0 - Command line google search for files by domain</title>
    <link>http://seclists.org/pen-test/2012/Jan/11</link>
    <description>&lt;p&gt;Posted by James Condron on Jan 18&lt;/p&gt;Tom,&lt;br&gt;
then having this value set to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Exploit Pack - New release</title>
    <link>http://seclists.org/pen-test/2012/Jan/10</link>
    <description>&lt;p&gt;Posted by noreply on Jan 18&lt;/p&gt;Exploit Pack is a Security Tool that will assist you while you test the &lt;br&gt;
Make your workstation safe by testing it...&lt;br&gt;</description>
  </item>
  <item>
    <title>Goofile 1.0 - Command line google search for files by domain</title>
    <link>http://seclists.org/pen-test/2012/Jan/9</link>
    <description>&lt;p&gt;Posted by tom on Jan 18&lt;/p&gt;Greetings!&lt;br&gt;
Prove to peers and potential employers without a doubt that you can actually do a proper penetration...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Best route to penetration testing learning</title>
    <link>http://seclists.org/pen-test/2012/Jan/8</link>
    <description>&lt;p&gt;Posted by wlandymore on Jan 11&lt;/p&gt;Thanks for the tips guys. I&amp;apos;ve seen the offensive-security.com website and I&lt;br&gt;
Archangel Amael wrote:&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Best route to penetration testing learning</title>
    <link>http://seclists.org/pen-test/2012/Jan/7</link>
    <description>&lt;p&gt;Posted by robertwood50 on Jan 07&lt;/p&gt;The SANS courses are pretty good in that you will actually be learning useful information, not just information &lt;br&gt;
it is put into practice. For reading I would...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Best route to penetration testing learning</title>
    <link>http://seclists.org/pen-test/2012/Jan/6</link>
    <description>&lt;p&gt;Posted by Archangel Amael on Jan 07&lt;/p&gt;Hello,&lt;br&gt;
metasploit and some other pentesting tools, check out...&lt;br&gt;</description>
  </item>
  <item>
    <title>Best route to penetration testing learning</title>
    <link>http://seclists.org/pen-test/2012/Jan/5</link>
    <description>&lt;p&gt;Posted by wlandymore on Jan 06&lt;/p&gt;I&amp;apos;m new to penetration testing and recently took the CEH. I found that it was&lt;br&gt;
Thanks.&lt;br&gt;</description>
  </item>
  <item>
    <title>AppSec DC 2012 CFP EXTENDED!</title>
    <link>http://seclists.org/pen-test/2012/Jan/4</link>
    <description>&lt;p&gt;Posted by AppSec DC on Jan 06&lt;/p&gt;All,&lt;br&gt;
move the platform we ask that...&lt;br&gt;</description>
  </item>
  <item>
    <title>Arachni v0.4 has been released (Open Source Web Application Security Scanner Framework)</title>
    <link>http://seclists.org/pen-test/2012/Jan/3</link>
    <description>&lt;p&gt;Posted by Tasos Laskos on Jan 06&lt;/p&gt;Hi guys,&lt;br&gt;
   * Updated WebUI to provide access to HPG...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: Nmap</title>
    <link>http://seclists.org/pen-test/2012/Jan/2</link>
    <description>&lt;p&gt;Posted by S Walker on Jan 02&lt;/p&gt;Just an added note to the current replies (which are all great for hosts not in the local broadcast domain): It is &lt;br&gt;
----------------------------------------...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Nmap</title>
    <link>http://seclists.org/pen-test/2012/Jan/1</link>
    <description>&lt;p&gt;Posted by Juan Pablo on Jan 02&lt;/p&gt;Sorry for the late answer...&lt;br&gt;
Here...&lt;br&gt;</description>
  </item>
  <item>
    <title>[TOOL RELEASE] Technitium MAC Address Changer v6 (FREEWARE)</title>
    <link>http://seclists.org/pen-test/2012/Jan/0</link>
    <description>&lt;p&gt;Posted by Shreyas Zare on Jan 02&lt;/p&gt;Hi,&lt;br&gt;
windows drivers to access Ethernet Network (LAN)....&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
  <title>The Passive Vulnerability Scanner (PVS) Plugins</title>
  <link>http://www.tenablesecurity.com/tenable_plugins.pdf</link>
  <description>All the newest security checks for the Tenable Passive Vulnerability Scanner (PVS)</description>
  <image resource="http://www.tenablesecurity.com/images/RssLogo.jpg" />
  <items>
  </items>
<image about="http://www.tenablesecurity.com/images/RssLogo.jpg">
<title>PVS Plugins</title>
<url>http://www.tenablesecurity.com/images/RssLogo.jpg</url>
<link>http://www.tenablesecurity.com/</link>
</image>
<item about="http://www.tenablesecurity.com/6296.html">
<title>CentOS version detection</title>
<description><![CDATA[<br />
INFO<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6296.html</link>
</item>
<item about="http://www.tenablesecurity.com/6295.html">
<title>Opera &lt; 11.61 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
HIGH<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6295.html</link>
</item>
<item about="http://www.tenablesecurity.com/6294.html">
<title>Google Chrome &lt; 16.0.912.77 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6294.html</link>
</item>
<item about="http://www.tenablesecurity.com/6293.html">
<title>Schweitzer Engineering Laboratories (SEL) Management Server Detection (SCADA) default level 1 credentials</title>
<description><![CDATA[<br />
MEDIUM<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6293.html</link>
</item>
<item about="http://www.tenablesecurity.com/6292.html">
<title>Netwave Video server detection</title>
<description><![CDATA[<br />
INFO<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6292.html</link>
</item>
<item about="http://www.tenablesecurity.com/6291.html">
<title>SIP server deteciton</title>
<description><![CDATA[<br />
INFO<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6291.html</link>
</item>
<item about="http://www.tenablesecurity.com/6290.html">
<title>DCS Video server deteciton</title>
<description><![CDATA[<br />
INFO<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6290.html</link>
</item>
<item about="http://www.tenablesecurity.com/6289.html">
<title>Polycom Audio/Video server detection</title>
<description><![CDATA[<br />
INFO<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6289.html</link>
</item>
<item about="http://www.tenablesecurity.com/6288.html">
<title>OpenSSL 0.9.8s / 1.0.0f DTLS Denial of Service</title>
<description><![CDATA[<br />
<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6288.html</link>
</item>
<item about="http://www.tenablesecurity.com/6287.html">
<title>Modicon PLC HTTP Default Account/Password Detection (SCADA)</title>
<description><![CDATA[<br />
HIGH<br /><br />Copyright Tenable Network Security Inc. 2012]]></description>
<link>http://www.tenablesecurity.com/6287.html</link>
</item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>The RISKS Forum</title>
    <link>http://seclists.org/#risks</link>
    <description>Peter G. Neumann moderates this regular digest of current events which demonstrate risks to the public in computers and related systems.  Security risks are often discussed.</description>
  <item>
    <title>Risks Digest 26.70</title>
    <link>http://seclists.org/risks/2012/q1/0</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Jan 02&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Monday 2 January 2012  Volume 26 : Issue 70&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.69</title>
    <link>http://seclists.org/risks/2011/q4/10</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Dec 29&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Thursday 29 December 2011  Volume 26 : Issue 69&lt;br&gt;
The current issue can...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.68</title>
    <link>http://seclists.org/risks/2011/q4/9</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Dec 28&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Weds 28 December 2011  Volume 26 : Issue 68&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.67</title>
    <link>http://seclists.org/risks/2011/q4/8</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Dec 20&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 20 December 2011  Volume 26 : Issue 67&lt;br&gt;
The current issue can...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.66</title>
    <link>http://seclists.org/risks/2011/q4/7</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Dec 06&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 6 December 2011  Volume 26 : Issue 66&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.65</title>
    <link>http://seclists.org/risks/2011/q4/6</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Nov 29&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 29 November 2011  Volume 26 : Issue 65&lt;br&gt;
The current issue can...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.64</title>
    <link>http://seclists.org/risks/2011/q4/5</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Nov 26&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Saturday 26 November 2011  Volume 26 : Issue 64&lt;br&gt;
The current issue can...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.63</title>
    <link>http://seclists.org/risks/2011/q4/4</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Nov 22&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 22 November 2011  Volume 26 : Issue 63&lt;br&gt;
The current issue can...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.62</title>
    <link>http://seclists.org/risks/2011/q4/3</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Nov 18&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Friday 18 November 2011  Volume 26 : Issue 62&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.61</title>
    <link>http://seclists.org/risks/2011/q4/2</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Nov 13&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Sunday 13 November 2011  Volume 26 : Issue 61&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.60</title>
    <link>http://seclists.org/risks/2011/q4/1</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Nov 11&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Friday 11 November 2011  Volume 26 : Issue 60&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.59</title>
    <link>http://seclists.org/risks/2011/q4/0</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Oct 23&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Sunday 23 October 2011  Volume 26 : Issue 59&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
<link rel="shortcut icon" href="/sites/all/themes/tenable/_res/img/favicon.ico" type="image/x-icon" />
<link rel="canonical" href="http://tenable.com/rss-feeds" />
<title>RSS Feeds | Tenable Network Security</title>
<link type="text/css" rel="stylesheet" media="all" href="/modules/node/node.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/defaults.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/system.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/system-menus.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/user/user.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/cck/theme/content-module.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/ctools/css/ctools.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/date/date.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/filefield/filefield.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/lightbox2/css/lightbox.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/panels/css/panels.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/views/css/views.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/themes/tenable/_res/css/t.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/themes/tenable/_res/css/admin.css?u" />
</channel>
</rss>
<rss version="2.0">
<channel>
<link rel="shortcut icon" href="/sites/all/themes/tenable/_res/img/favicon.ico" type="image/x-icon" />
<link rel="canonical" href="http://tenable.com/rss-feeds" />
<title>RSS Feeds | Tenable Network Security</title>
<link type="text/css" rel="stylesheet" media="all" href="/modules/node/node.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/defaults.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/system.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/system-menus.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/user/user.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/cck/theme/content-module.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/ctools/css/ctools.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/date/date.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/filefield/filefield.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/lightbox2/css/lightbox.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/panels/css/panels.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/views/css/views.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/themes/tenable/_res/css/t.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/themes/tenable/_res/css/admin.css?u" />
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Tenable News Feed</title>
    <link>http://www.nessus.org/feed/news</link>
    <description></description>
          <item>
    <title>Digital Bond and Tenable Network Security Collaborate  on Continuous Critical Infrastructure Protection</title>
    <link>http://www.nessus.org/news-events/press-releases/2012-digital-bond-and-tenable-network-security-collaborate-on-continuous-</link>
    <description>&lt;div class=&quot;field field-type-text field-field-teaserdescription&quot;&gt;
&lt;p&gt;&lt;a href=&quot;http://www.nessus.org/news-events/press-releases/2012-digital-bond-and-tenable-network-security-collaborate-on-continuous-&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
  </item>
  <item>
    <title>Tenable CEO, Ron Gula, on Impact of Microsoft&#039;s Improved Security Efforts</title>
    <link>http://www.nessus.org/tenable/in-the-news/1121</link>
    <description>&lt;p&gt;In this article on eWeek.com, Ron Gula comments on improved security development processes and its’ positive impact on the vulnerability of the operating system.&lt;/p&gt;&lt;div class=&quot;field field-type-link field-field-link&quot;&gt;
</description>
  </item>
  <item>
    <title>How to Turn a Tablet into a Security Tool - By Marcus Ranum</title>
    <link>http://www.nessus.org/tenable/in-the-news/1120</link>
    <description>&lt;p&gt;Government Heath IT has published Tenable CSO Marcus Ranum&#039;s article on overcoming mobile and personal computing challenges.&lt;/p&gt;&lt;div class=&quot;field field-type-link field-field-link&quot;&gt;
</description>
  </item>
  <item>
    <title>NetworkWorld Selects Tenable Patch Management Integration for Product of the Week</title>
    <link>http://www.nessus.org/tenable/in-the-news/1114</link>
    <description>&lt;p&gt;Tenable’s Patch Management Integration included in &lt;em&gt;Network World’s &lt;/em&gt;‘Product of the Week’ slideshow.&lt;/p&gt;&lt;div class=&quot;field field-type-link field-field-link&quot;&gt;
</description>
  </item>
  <item>
    <title>Tenable CEO Ron Gula Discusses Recent International Cyber Attacks and Threat Prevention</title>
    <link>http://www.nessus.org/tenable/in-the-news/1112</link>
    <description>&lt;p&gt;In an interview by &lt;a href=&quot;http://wapo.st/vsmaWL%20&quot; target=&quot;_blank&quot;&gt;The Washington Post&lt;/a&gt;, Ron Gula discusses recent exploitation of&amp;nbsp; U.S.&lt;/p&gt;&lt;div class=&quot;field field-type-link field-field-link&quot;&gt;
&lt;p&gt;&lt;a href=&quot;http://www.nessus.org/tenable/in-the-news/1112&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
  </item>
  <item>
    <title>Tenable Network Security Offers Unique Integration with Top Patch Management Solutions </title>
    <link>http://www.nessus.org/news-events/press-releases/2011-tenable-patch-management-integration-solution</link>
    <description>&lt;div class=&quot;field field-type-text field-field-teaserdescription&quot;&gt;
&lt;p&gt;&lt;a href=&quot;http://www.nessus.org/news-events/press-releases/2011-tenable-patch-management-integration-solution&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
  </item>
  <item>
    <title>Tenable&#039;s Ron Gula Discusses Protection of University Data</title>
    <link>http://www.nessus.org/tenable/in-the-news/1101</link>
    <description>&lt;p&gt;Gula explains why universities are at risk, and action needed to prevent breaches.&lt;/p&gt;&lt;div class=&quot;field field-type-link field-field-link&quot;&gt;
</description>
  </item>
  <item>
    <title>Tenable Network Security Selected as Finalist for Best Vulnerability Management Solution at 2012 SC Magazine Reader Trust Awards</title>
    <link>http://www.nessus.org/news-events/press-releases/2011-tenable-network-security-selected-as-finalist-for-best-vulnerability</link>
    <description>&lt;div class=&quot;field field-type-text field-field-teaserdescription&quot;&gt;
&lt;p&gt;&lt;a href=&quot;http://www.nessus.org/news-events/press-releases/2011-tenable-network-security-selected-as-finalist-for-best-vulnerability&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
  </item>
  <item>
    <title>Tenable&#039;s Marcus Ranum Interviewed for Security Incident Response Article</title>
    <link>http://www.nessus.org/tenable/in-the-news/1094</link>
    <description>&lt;p&gt;Ranum comments on forensic evaluation aspect of &amp;nbsp;network security incident response.&lt;/p&gt;&lt;div class=&quot;field field-type-link field-field-link&quot;&gt;
</description>
  </item>
  <item>
    <title>Tenable Nessus Chosen #1</title>
    <link>http://www.nessus.org/tenable/in-the-news/1086</link>
    <description>&lt;p&gt;&lt;span&gt;Tenable Nessus was selected the winner in the Security Scanner Software category of the WindowSecurity.com Readers’ Choice Awards.&lt;/span&gt;&lt;/p&gt;&lt;div class=&quot;field field-type-link field-field-link&quot;&gt;
</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
<title>Nessus.org Plugins</title>
<link>http://www.nessus.org/scripts.php</link>
<description>All the newest security checks for the Nessus scanner</description>
<items>
</items>
<image about="http://www.nessus.org/images/RssLogo.jpg">
<title>Nessus Plugins</title>
<url>http://www.nessus.org/images/RssLogo.jpg</url>
<link>http://www.nessus.org/</link>
</image>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57712">
<title>OpenSSL 1.0.0f DTLS Denial of Service</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57712</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57711">
<title>OpenSSL 0.9.8s DTLS Denial of Service</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57711</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57710">
<title>WebSphere MQ Client &lt; 6.0.2.7 / 7.0.1.0 Buffer Overflow</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57710</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57709">
<title>WebSphere MQ Server &lt; 6.0.2.7 / 7.0.1.0 Buffer Overflow</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57709</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57708">
<title>WebSphere MQ Server and Client Detection</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57708</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57707">
<title>USN-1349-1 : xorg vulnerability</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57707</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57706">
<title>USN-1348-1 : icu vulnerability</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57706</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57705">
<title>FreeBSD : acroread9 -- Multiple Vulnerabilities (fa2f386f-4814-11e1-89b4-001ec9578670)</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57705</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57704">
<title>FreeBSD : mpack -- Information disclosure (e465159c-4817-11e1-89b4-001ec9578670)</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57704</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57703">
<title>Fedora 15 2012-0420</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57703</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57702">
<title>Debian DSA-2394-1 : libxml2 - several vulnerabilities</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57702</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57701">
<title>HP Managed Printing Administration jobDelivery Script Directory Traversal (intrusive check)</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57701</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57700">
<title>HP Managed Printing Administration &lt; 2.6.4 Multiple Vulnerabilities</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57700</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57699">
<title>HP Managed Printing Administration Detection</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57699</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57698">
<title>USN-1347-1 : evince vulnerability</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57698</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57697">
<title>USN-1342-1 : linux-lts-backport-oneiric vulnerability</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57697</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57696">
<title>SuSE Security Update:  gnutls (2012-01-23)</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57696</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57695">
<title>Fedora 16 2012-0643</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57695</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57694">
<title>Fedora 15 2012-0626</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57694</link>
</item>
<item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=57693">
<title>Debian DSA-2393-1 : bip - buffer overflow</title>
<description><![CDATA[<br />
]]></description>
<link>http://www.nessus.org/plugins/index.php?view=single&amp;id=57693</link>
</item>
</channel>
</rss>
<rss version="2.0">
<channel>
<link rel="shortcut icon" href="/sites/all/themes/tenable/_res/img/favicon.ico" type="image/x-icon" />
<link rel="canonical" href="http://tenable.com/rss-feeds" />
<title>RSS Feeds | Tenable Network Security</title>
<link type="text/css" rel="stylesheet" media="all" href="/modules/node/node.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/defaults.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/system.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/system-menus.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/user/user.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/cck/theme/content-module.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/ctools/css/ctools.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/date/date.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/filefield/filefield.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/lightbox2/css/lightbox.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/panels/css/panels.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/views/css/views.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/themes/tenable/_res/css/t.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/themes/tenable/_res/css/admin.css?u" />
</channel>
</rss>
<rss version="2.0">
<channel>
<link rel="shortcut icon" href="/sites/all/themes/tenable/_res/img/favicon.ico" type="image/x-icon" />
<link rel="canonical" href="http://tenable.com/rss-feeds" />
<title>RSS Feeds | Tenable Network Security</title>
<link type="text/css" rel="stylesheet" media="all" href="/modules/node/node.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/defaults.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/system.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/system/system-menus.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/modules/user/user.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/cck/theme/content-module.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/ctools/css/ctools.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/date/date.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/filefield/filefield.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/lightbox2/css/lightbox.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/panels/css/panels.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/modules/views/css/views.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/themes/tenable/_res/css/t.css?u" />
<link type="text/css" rel="stylesheet" media="all" href="/sites/all/themes/tenable/_res/css/admin.css?u" />
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Secure Coding</title>
    <link>http://seclists.org/#securecoding</link>
    <description>The Secure Coding list (SC-L) is an open forum for the discussion on developing secure applications. It is moderated by the authors of &lt;a href=&quot;http://www.amazon.com/dp/0596002424?tag=secbks-20&quot;&gt;Secure Coding: Principles and Practices&lt;/a&gt;.</description>
  <item>
    <title>informIT: vBSIMM revised</title>
    <link>http://seclists.org/securecoding/2012/q1/3</link>
    <description>&lt;p&gt;Posted by Gary McGraw on Jan 26&lt;/p&gt;hi sc-l,&lt;br&gt;
Instead of focusing on an individual applications, the vBSIMM approach focuses on software...&lt;br&gt;</description>
  </item>
  <item>
    <title>Only 7 Days Left: SANS AppSec 2012 CFP</title>
    <link>http://seclists.org/securecoding/2012/q1/2</link>
    <description>&lt;p&gt;Posted by SANS AppSec CFP on Jan 24&lt;/p&gt;Hi everyone,&lt;br&gt;
enterprise. Untold...&lt;br&gt;</description>
  </item>
  <item>
    <title>OWASP AsiaPac 2012 - Sydney,	Australia: CFP and call for trainers</title>
    <link>http://seclists.org/securecoding/2012/q1/1</link>
    <description>&lt;p&gt;Posted by Andrew van der Stock on Jan 12&lt;/p&gt;Colleagues,&lt;br&gt;
been held on the Gold Coast Australia, in 2012 the event has been moved to Sydney, and...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: informIT: BSIMM versus SAFECode</title>
    <link>http://seclists.org/securecoding/2012/q1/0</link>
    <description>&lt;p&gt;Posted by Kevin W. Wall on Jan 02&lt;/p&gt;Gary,&lt;br&gt;
Specifically, the SAFECode _Fundamental Practices_ paper...&lt;br&gt;</description>
  </item>
  <item>
    <title>Silver Bullet 69: Steve Myers</title>
    <link>http://seclists.org/securecoding/2011/q4/19</link>
    <description>&lt;p&gt;Posted by Gary McGraw on Dec 31&lt;/p&gt;happy new year sc-l,&lt;br&gt;
As always, we welcome your feedback on the...&lt;br&gt;</description>
  </item>
  <item>
    <title>informIT: BSIMM versus SAFECode</title>
    <link>http://seclists.org/securecoding/2011/q4/18</link>
    <description>&lt;p&gt;Posted by Gary McGraw on Dec 31&lt;/p&gt;Lets try that again, this time with the proper email address…&lt;br&gt;
How about a little software security controversy for the tweener holiday week?...&lt;br&gt;</description>
  </item>
  <item>
    <title>ANNOUNCEMENT: SecAppDev 2012, Leuven, Belgium</title>
    <link>http://seclists.org/securecoding/2011/q4/17</link>
    <description>&lt;p&gt;Posted by Kenneth Van Wyk on Dec 22&lt;/p&gt;We are pleased to announce SecAppDev 2012, an intensive one-week&lt;br&gt;
SecAppDev 2012 is the 8th edition of our widely...&lt;br&gt;</description>
  </item>
  <item>
    <title>MoST 2012 CFP - Mobile Security Technologies (MoST) 2012	Workshop</title>
    <link>http://seclists.org/securecoding/2011/q4/16</link>
    <description>&lt;p&gt;Posted by Larry Koved on Dec 22&lt;/p&gt;On behalf of the workshop co-chairs and program chair, we would like to &lt;br&gt;
in the security and privacy...&lt;br&gt;</description>
  </item>
  <item>
    <title>W2SP 2012 CFP - Web 2.0 Security and Privacy 2012 Workshop	Call for Papers</title>
    <link>http://seclists.org/securecoding/2011/q4/15</link>
    <description>&lt;p&gt;Posted by Larry Koved on Dec 22&lt;/p&gt;W2SP 2012 CFP - Web 2.0 Security and Privacy 2012 Workshop Call for Papers&lt;br&gt;
W2SP is co-located with the IEEE Security &amp;amp; Privacy...&lt;br&gt;</description>
  </item>
  <item>
    <title>SANS AppSec 2012 CFP reminder</title>
    <link>http://seclists.org/securecoding/2011/q4/14</link>
    <description>&lt;p&gt;Posted by SANS AppSec CFP on Dec 01&lt;/p&gt;Hi everyone,&lt;br&gt;
The theme for this conference...&lt;br&gt;</description>
  </item>
  <item>
    <title>Silver Bullet 68</title>
    <link>http://seclists.org/securecoding/2011/q4/13</link>
    <description>&lt;p&gt;Posted by Gary McGraw on Nov 30&lt;/p&gt;hi sc-l,&lt;br&gt;
a very active OWASP participant.  I have worked closely with jS for many...&lt;br&gt;</description>
  </item>
  <item>
    <title>informIT: third-party software and security</title>
    <link>http://seclists.org/securecoding/2011/q4/12</link>
    <description>&lt;p&gt;Posted by Gary McGraw on Nov 30&lt;/p&gt;hi sc-l,&lt;br&gt;
As you know, the BSIMM is mostly about SSDL activities and governance.  However,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Call for papers - i-Society</title>
    <link>http://seclists.org/securecoding/2011/q4/11</link>
    <description>&lt;p&gt;Posted by Call for papers on Nov 06&lt;/p&gt;Apologies for cross-postings!&lt;br&gt;
The...&lt;br&gt;</description>
  </item>
  <item>
    <title>silver bullet: bill pugh</title>
    <link>http://seclists.org/securecoding/2011/q4/10</link>
    <description>&lt;p&gt;Posted by Gary McGraw on Oct 31&lt;/p&gt;hi sc-l,&lt;br&gt;
Our conversation ranged far and wide on this episode and is likely to be appreciated by more technical listeners....&lt;br&gt;</description>
  </item>
  <item>
    <title>informIT: Software Security Training</title>
    <link>http://seclists.org/securecoding/2011/q4/9</link>
    <description>&lt;p&gt;Posted by Gary McGraw on Oct 31&lt;/p&gt;hi sc-l,&lt;br&gt;
FWIW, we estimate we have trained 14,000 developers using instructor...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Security Basics</title>
    <link>http://seclists.org/#basics</link>
    <description>A high-volume list which permits people to ask &quot;stupid questions&quot; without being derided as &quot;n00bs&quot;.  I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.</description>
  <item>
    <title>Re: Building an Information Asset database</title>
    <link>http://seclists.org/basics/2012/Jan/118</link>
    <description>&lt;p&gt;Posted by Bharat Gosalia on Jan 27&lt;/p&gt;I FOUND chapter 4 somewhat relevent.&lt;br&gt;
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase,...&lt;br&gt;</description>
  </item>
  <item>
    <title>SOAP</title>
    <link>http://seclists.org/basics/2012/Jan/117</link>
    <description>&lt;p&gt;Posted by Thugzclub on Jan 27&lt;/p&gt;All,&lt;br&gt;
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: Regularly Vulnerability Assessment using QualysGuard - Pro/Cons?</title>
    <link>http://seclists.org/basics/2012/Jan/116</link>
    <description>&lt;p&gt;Posted by Wright, Joe # ATLANTA on Jan 27&lt;/p&gt;Andre;&lt;br&gt;
are trying to achieve. Qualys however tends to be expensive on initial cost and recurring...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Announce] Reminder: HITB2012AMS Call For Papers Closing Soon</title>
    <link>http://seclists.org/basics/2012/Jan/115</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jan 27&lt;/p&gt;This is a gentle reminder that the Call for Papers for the third annual&lt;br&gt;
featuring keynote speakers Andy Ellis (Chief...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: [Full-disclosure] DNS bind attacks</title>
    <link>http://seclists.org/basics/2012/Jan/114</link>
    <description>&lt;p&gt;Posted by Chris Granger on Jan 27&lt;/p&gt;Your theory&amp;apos;s likely correct - do you allow external IPs to make recursive queries to your server? &lt;br&gt;
amplification factor is greatly increased. Can you check to see if +edns=0 was set in the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: [Full-disclosure] DNS bind attacks</title>
    <link>http://seclists.org/basics/2012/Jan/113</link>
    <description>&lt;p&gt;Posted by Jeffrey Walton on Jan 27&lt;/p&gt;What&amp;apos;s the query. Could it be related to&lt;br&gt;
it benefits your company and how your customers can tell if a site is secure. You will find...&lt;br&gt;</description>
  </item>
  <item>
    <title>DNS bind attacks</title>
    <link>http://seclists.org/basics/2012/Jan/112</link>
    <description>&lt;p&gt;Posted by J. von Balzac on Jan 27&lt;/p&gt;I&amp;apos;m seeing a lot of hosts in my named logs (I mean log files, it&amp;apos;s not&lt;br&gt;
these queries and...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: DoS attacks using Exploit Pack</title>
    <link>http://seclists.org/basics/2012/Jan/111</link>
    <description>&lt;p&gt;Posted by Thugzclub on Jan 27&lt;/p&gt;Any proxy will do, as long as it has not been blocked by that site!&lt;br&gt;
install...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Cyber Warfare / Network Defense Simulation</title>
    <link>http://seclists.org/basics/2012/Jan/110</link>
    <description>&lt;p&gt;Posted by Thugzclub on Jan 27&lt;/p&gt;Yup !&lt;br&gt;
In this guide we examine...&lt;br&gt;</description>
  </item>
  <item>
    <title>PPP / NCP Vulnerability Research</title>
    <link>http://seclists.org/basics/2012/Jan/109</link>
    <description>&lt;p&gt;Posted by Miguel Regala on Jan 25&lt;/p&gt;Hi,&lt;br&gt;
it benefits your company and how your customers can tell if a site is...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Cyber Warfare / Network Defense Simulation</title>
    <link>http://seclists.org/basics/2012/Jan/108</link>
    <description>&lt;p&gt;Posted by Jim Elkins on Jan 24&lt;/p&gt;Here are a couple of suggested books. &lt;br&gt;
articles, references, books, sites, ideas, anything) on...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Cyber Warfare / Network Defense Simulation</title>
    <link>http://seclists.org/basics/2012/Jan/107</link>
    <description>&lt;p&gt;Posted by Henri Salo on Jan 24&lt;/p&gt;Key-point in my opinion is to have the setup up and running fast from scratch.&lt;br&gt;
it benefits your company and how your customers can tell if a site is secure. You will find out how to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Cyber Warfare / Network Defense Simulation</title>
    <link>http://seclists.org/basics/2012/Jan/106</link>
    <description>&lt;p&gt;Posted by Christopher Siedlecki on Jan 24&lt;/p&gt;That is very neat, but in my opinion little bit to broad idea. For&lt;br&gt;
E-mail:...&lt;br&gt;</description>
  </item>
  <item>
    <title>Cyber Warfare / Network Defense Simulation</title>
    <link>http://seclists.org/basics/2012/Jan/105</link>
    <description>&lt;p&gt;Posted by Teóphilo Athos Brauns on Jan 24&lt;/p&gt;Hi,&lt;br&gt;
managed to create a...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: DoS attacks using Exploit Pack</title>
    <link>http://seclists.org/basics/2012/Jan/104</link>
    <description>&lt;p&gt;Posted by Richard Steinbrück on Jan 24&lt;/p&gt;try this ... &lt;a  rel=&quot;nofollow&quot; href=&quot;https://youtubeproxy.org/&quot;&gt;https://youtubeproxy.org/&lt;/a&gt;&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
<title>Vulnerability Development (vuln-dev) Mailing List</title>
<link>http://seclists.org/#vuln-dev</link>
<description>A moderated list for discussing possible security issues and devising exploits for them.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>VulnWatch</title>
    <link>http://seclists.org/#vulnwatch</link>
    <description>A non-discussion, non-patch, all-vulnerability annoucement list supported and run by a community of volunteer moderators distributed around the world.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Web App Security</title>
    <link>http://seclists.org/#webappsec</link>
    <description>Provides insights on the unique challenges which make web applications notoriously hard to secure, as well as attack methods including SQL injection, cross-site scripting (XSS), cross-site request forgery, and more.</description>
  <item>
    <title>Re: Apache Killer - take 2?</title>
    <link>http://seclists.org/webappsec/2012/q1/13</link>
    <description>&lt;p&gt;Posted by Anestis Bechtsoudis on Jan 23&lt;/p&gt;Apache byte-range killer use many small byte-range chunks in a single&lt;br&gt;
I attach a simple perl PoC to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Apache Killer - take 2?</title>
    <link>http://seclists.org/webappsec/2012/q1/12</link>
    <description>&lt;p&gt;Posted by Damiano Bolzoni on Jan 23&lt;/p&gt;You are right, I didn&amp;apos;t write it down properly...what I meant is&lt;br&gt;
around but couldn&amp;apos;t find any other example......&lt;br&gt;</description>
  </item>
  <item>
    <title>Apache Killer - take 2?</title>
    <link>http://seclists.org/webappsec/2012/q1/11</link>
    <description>&lt;p&gt;Posted by Damiano Bolzoni on Jan 22&lt;/p&gt;Hi all,&lt;br&gt;
the version/patching level. The server went ahead...&lt;br&gt;</description>
  </item>
  <item>
    <title>CarolinaCon-8/2012 - Final Announcement/Call for Papers/Presenters/Speakers</title>
    <link>http://seclists.org/webappsec/2012/q1/10</link>
    <description>&lt;p&gt;Posted by Vic Vandal on Jan 12&lt;/p&gt;h4x0rs, InfoSec professionals, international spies, script kidz, and posers,&lt;br&gt;
thermonuclear war, etc. (but mostly hacking), and are interested in presenting at CarolinaCon-8, we cordially...&lt;br&gt;</description>
  </item>
  <item>
    <title>OWASP AsiaPac 2012 - Sydney Australia CFP and CFT</title>
    <link>http://seclists.org/webappsec/2012/q1/9</link>
    <description>&lt;p&gt;Posted by Andrew van der Stock on Jan 11&lt;/p&gt;Colleagues,&lt;br&gt;
been held on the Gold Coast Australia, in 2012 the event has been moved to Sydney, and...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: Application Security</title>
    <link>http://seclists.org/webappsec/2012/q1/8</link>
    <description>&lt;p&gt;Posted by Milind Nanal on Jan 11&lt;/p&gt;Reference on the subject. Members view on these points how they are managing similar  &lt;br&gt;
Not sure...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Application Security</title>
    <link>http://seclists.org/webappsec/2012/q1/7</link>
    <description>&lt;p&gt;Posted by Yiannis Koukouras on Jan 11&lt;/p&gt;Hi,&lt;br&gt;
It&amp;apos;s Finally...&lt;br&gt;</description>
  </item>
  <item>
    <title>Application Security</title>
    <link>http://seclists.org/webappsec/2012/q1/6</link>
    <description>&lt;p&gt;Posted by Milind Nanal on Jan 08&lt;/p&gt;Hi Mailing list,&lt;br&gt;
3) Plan for training developers, quality staff &amp;amp; apps testing team on various info sec aspect of application...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: stacking proxies</title>
    <link>http://seclists.org/webappsec/2012/q1/5</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 08&lt;/p&gt;I know this is what he was talking about and I&amp;apos;ve got the chain that&lt;br&gt;
to improve the...&lt;br&gt;</description>
  </item>
  <item>
    <title>AppSec DC 2012 CFP EXTENDED!</title>
    <link>http://seclists.org/webappsec/2012/q1/4</link>
    <description>&lt;p&gt;Posted by AppSec DC on Jan 08&lt;/p&gt;All,&lt;br&gt;
move the platform we ask that...&lt;br&gt;</description>
  </item>
  <item>
    <title>Arachni v0.4 has been released (Open Source Web Application Security Scanner Framework)</title>
    <link>http://seclists.org/webappsec/2012/q1/3</link>
    <description>&lt;p&gt;Posted by Tasos Laskos on Jan 08&lt;/p&gt;Hi guys,&lt;br&gt;
   * Updated WebUI to provide access to HPG...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: stacking proxies</title>
    <link>http://seclists.org/webappsec/2012/q1/2</link>
    <description>&lt;p&gt;Posted by Jamie Riden on Jan 03&lt;/p&gt;To be honest, I just use Burp (Pro).&lt;br&gt;
 Jamie&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: stacking proxies</title>
    <link>http://seclists.org/webappsec/2012/q1/1</link>
    <description>&lt;p&gt;Posted by Robert Hajime Lanning on Jan 03&lt;/p&gt;I am putting together: (in this order)Nginx (ssl)Varnish&lt;br&gt;
(caching)Haproxy (load balancing/fail over)&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: stacking proxies</title>
    <link>http://seclists.org/webappsec/2012/q1/0</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jan 03&lt;/p&gt;Most of my clients like to know where the attack will be coming from&lt;br&gt;
Request...&lt;br&gt;</description>
  </item>
  <item>
    <title>stacking proxies</title>
    <link>http://seclists.org/webappsec/2011/q4/27</link>
    <description>&lt;p&gt;Posted by Robin Wood on Dec 31&lt;/p&gt;I watched Jason Haddix talk at BruCon and he talked about stacking&lt;br&gt;
Request Yours...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Wireshark</title>
    <link>http://seclists.org/#wireshark</link>
    <description>Discussion of the free and open source &lt;a href=&quot;http://www.wireshark.org/&quot;&gt;Wireshark&lt;/a&gt; network sniffer.  No other sniffer (commercial or otherwise) comes close. This archive combines the Wireshark announcement, users, and developers mailing lists.</description>
  <item>
    <title>Re: disabling loopback</title>
    <link>http://seclists.org/wireshark/2012/Jan/371</link>
    <description>&lt;p&gt;Posted by Maynard, Chris on Jan 28&lt;/p&gt;_______________________________________&lt;br&gt;
You can very likely accomplish this using iptables.  Search for &amp;quot;iptables tee&amp;quot; and I think you&amp;apos;ll find a...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: disabling loopback</title>
    <link>http://seclists.org/wireshark/2012/Jan/370</link>
    <description>&lt;p&gt;Posted by Andrej van der Zee on Jan 28&lt;/p&gt;Thanks. Is there also a way to send the captured traffic on the loopback interface to a non-local IP address on the &lt;br&gt;
Andrej&lt;br&gt;</description>
  </item>
  <item>
    <title>PCoIP</title>
    <link>http://seclists.org/wireshark/2012/Jan/369</link>
    <description>&lt;p&gt;Posted by Neel Sheyal on Jan 28&lt;/p&gt;[I had also posted this on the users list but  thought might be relevant here.]&lt;br&gt;
Neel&lt;br&gt;</description>
  </item>
  <item>
    <title>PCoIP</title>
    <link>http://seclists.org/wireshark/2012/Jan/368</link>
    <description>&lt;p&gt;Posted by Neel Sheyal on Jan 27&lt;/p&gt;Do we have any wireshark plugins for decoding PCoIP payloads? I am&lt;br&gt;
Neel&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Issue Related to Unrecognized Text in	Manifest File</title>
    <link>http://seclists.org/wireshark/2012/Jan/367</link>
    <description>&lt;p&gt;Posted by NITIN GOYAL on Jan 27&lt;/p&gt;Hi&lt;br&gt;
Nitin&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: [Wireshark-users]	Issue Related to Unrecognized Text in	 Manifest	File</title>
    <link>http://seclists.org/wireshark/2012/Jan/366</link>
    <description>&lt;p&gt;Posted by Chris Maynard on Jan 27&lt;/p&gt;NITIN GOYAL &amp;lt;nitinkumgoyal ()    &amp;gt; writes:&lt;br&gt;
- Chris&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Conference room before FOSDEM</title>
    <link>http://seclists.org/wireshark/2012/Jan/365</link>
    <description>&lt;p&gt;Posted by Chris Maynard on Jan 27&lt;/p&gt;Graham Bloice &amp;lt;graham.bloice ()    &amp;gt; writes:&lt;br&gt;
Chris&lt;br&gt;</description>
  </item>
  <item>
    <title>CMake can&apos;t find  glib</title>
    <link>http://seclists.org/wireshark/2012/Jan/364</link>
    <description>&lt;p&gt;Posted by Stephen Fisher on Jan 27&lt;/p&gt;I&amp;apos;m anxious to try out the beginnings of a Qt Wireshark, but I&amp;apos;m having trouble with CMake on FreeBSD.  After making a &lt;br&gt;
 The only way I&amp;apos;ve found so far...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: disabling loopback</title>
    <link>http://seclists.org/wireshark/2012/Jan/363</link>
    <description>&lt;p&gt;Posted by Guy Harris on Jan 27&lt;/p&gt;The relevant part of which is &amp;quot;you can capture on the loopback interface on Linux&amp;quot;.&lt;br&gt;
of the other OSes).&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: disabling loopback</title>
    <link>http://seclists.org/wireshark/2012/Jan/362</link>
    <description>&lt;p&gt;Posted by Tim.Poth on Jan 27&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://wiki.wireshark.org/CaptureSetup/Loopback&quot;&gt;http://wiki.wireshark.org/CaptureSetup/Loopback&lt;/a&gt;&lt;br&gt;
I was wondering if there is a way to prevent packets sent to a local IP address to be shortcut-ed in the...&lt;br&gt;</description>
  </item>
  <item>
    <title>disabling loopback</title>
    <link>http://seclists.org/wireshark/2012/Jan/361</link>
    <description>&lt;p&gt;Posted by Andrej van der Zee on Jan 27&lt;/p&gt;Hi,&lt;br&gt;
Andrej&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Extending VoIP Call Flow</title>
    <link>http://seclists.org/wireshark/2012/Jan/360</link>
    <description>&lt;p&gt;Posted by Weir, Alan on Jan 27&lt;/p&gt;Thanks Jaap, That’s exactly what I was looking for, Alan&lt;br&gt;
It already has a tap listener and takes whatever information you feed it....&lt;br&gt;</description>
  </item>
  <item>
    <title>Issue Related to Unrecognized Text in Manifest	File</title>
    <link>http://seclists.org/wireshark/2012/Jan/359</link>
    <description>&lt;p&gt;Posted by NITIN GOYAL on Jan 27&lt;/p&gt;Hi&lt;br&gt;
    &amp;lt;field name=&amp;quot;&amp;quot; show=&amp;quot;[ ERROR: Unrecognized text ]&amp;quot; size=&amp;quot;10&amp;quot;...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Conference room before FOSDEM</title>
    <link>http://seclists.org/wireshark/2012/Jan/358</link>
    <description>&lt;p&gt;Posted by Graham Bloice on Jan 27&lt;/p&gt;As the FOSDEM Friday beer event, &lt;a  rel=&quot;nofollow&quot; href=&quot;http://fosdem.org/2012/beerevent&quot;&gt;http://fosdem.org/2012/beerevent&lt;/a&gt; takes&lt;br&gt;
I&amp;apos;m really sad I won&amp;apos;t be able to participate with...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Conference room before FOSDEM</title>
    <link>http://seclists.org/wireshark/2012/Jan/357</link>
    <description>&lt;p&gt;Posted by Jaap Keuter on Jan 27&lt;/p&gt;Sébastien, you&amp;apos;re a connoisseur. ;)&lt;br&gt;
Jaap&lt;br&gt;</description>
  </item>
</channel>
</rss>
</BODY>

