<?xml version="1.0" encoding="ISO-8859-1" ?>
<?xml-stylesheet type="text/xsl" href="/xsl/index.xsl"?>

<BODY>
<TITLE>
Welcome to the ThreatPerspective Security Information Center
</TITLE>
<MENU>
    <MENUOBJECT>

	<MENUTITLE>
		Vulnerability Info	
	</MENUTITLE>

	<MENUITEM>
		<menuurl>http://www.securityfocus.com</menuurl>
		<MENUBODY>
			Security Focus	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.osvdb.org</menuurl>
		<MENUBODY>
			OSVDB
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://nvd.nist.gov</menuurl>
		<MENUBODY>
			Nist NVD
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://cve.mitre.org</menuurl>
		<MENUBODY>
			Mitre
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://ciac.llnl.gov</menuurl>
		<MENUBODY>
			CIAC
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.cert.org</menuurl>
		<MENUBODY>
			CERT
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://iase.disa.mil</menuurl>
		<MENUBODY>
			ISAE
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Exploit Info	
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.milw0rm.com</menuurl>
		<MENUBODY>
			Milw0rm
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.packetstormsecurity.nl</menuurl>
		<MENUBODY>
			Packet Storm
		</MENUBODY>
	</MENUITEM>


    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Active Research Groups
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.shmoo.com</menuurl>
		<MENUBODY>
			The Shmoo Group
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.thc.org</menuurl>
		<MENUBODY>
			THC
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl> http://www.phenoelit.de</menuurl>
		<MENUBODY>
			Phenoelit
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>

	<MENUTITLE>
		Commercial Groups
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.ngssoftware.com</menuurl>
		<MENUBODY>
			NGS
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.immunitysec.com</menuurl>
		<MENUBODY>
			Immunitysec
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.secunia.com</menuurl>
		<MENUBODY>
			Secunia
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.securiteam.com</menuurl>
		<MENUBODY>
			Securiteam
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://xforce.iss.net</menuurl>
		<MENUBODY>
			Xforce
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.idefense.com</menuurl>
		<MENUBODY>
			Idefense
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.eeye.com</menuurl>
		<MENUBODY>
			Eeye
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.2600.com</menuurl>
		<MENUBODY>
			2600
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Security Organizations
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.owasp.org</menuurl>
		<MENUBODY>
			OWASP
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.isc2.org</menuurl>
		<MENUBODY>
			ISC2
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.isecom.org</menuurl>
		<MENUBODY>
			ISECOM
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.sans.org</menuurl>
		<MENUBODY>
			SANS
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.infragard.com</menuurl>
		<MENUBODY>
			Infragard
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Methodologies	
	</MENUTITLE>

	<MENUITEM>
		<menuurl> http://www.osissg.org</menuurl>
		<MENUBODY>
			OISSG
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.isecom.org/</menuurl>
		<MENUBODY>
			ISECOM
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.osstmm.org</menuurl>
		<MENUBODY>
			OSSTMM
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>

	<MENUTITLE>
		Free "Auditing" Tools
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.nessus.org</menuurl>
		<MENUBODY>
			Nessus
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.insecure.org</menuurl>
		<MENUBODY>
			Nmap
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.cqure.net</menuurl>
		<MENUBODY>
			Cqure Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.sqlsecurity.com/DesktopDefault.aspx?tabid=26</menuurl>
		<MENUBODY>
			MS SQL Utilities
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.cirt.net</menuurl>
		<MENUBODY>
			Nikto
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.sysinternals.com</menuurl>
		<MENUBODY>
			Sysinternals Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.bindview.com/services/razor/utilities/</menuurl>
		<MENUBODY>
			Bindview Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://thc.org/releases.php</menuurl>
		<MENUBODY>
			THC Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.metasploit.org</menuurl>
		<MENUBODY>
			Metasploit
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.parosproxy.org/</menuurl>
		<MENUBODY>
			Paros Proxy
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.portswigger.net/proxy/</menuurl>
		<MENUBODY>
			Burp Proxy
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.securityforest.com</menuurl>
		<MENUBODY>
			Exploit Tree
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.tank.net</menuurl>
		<MENUBODY>
			Spork
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://ettercap.sourceforge.net/</menuurl>
		<MENUBODY>
			Ettercap
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.cirt.net/code/nikto.shtml</menuurl>
		<MENUBODY>
			nikto
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.sensepost.com/research/wikto/</menuurl>
		<MENUBODY>
			wikto
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.nstalker.com/eng/products/nstealth/</menuurl>
		<MENUBODY>
			nStealth
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>http://reedarvin.thearvins.com/tools/PWDumpX14.zip</menuurl>
		<MENUBODY>
			 pwdumpx (Obtain MS Hashes)
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.foofus.net/fizzgig/fgdump/</menuurl>
		<MENUBODY>
			fgdump (Obtain MS Hashes)
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.off-by-one.net/misc/cachedump.html</menuurl>
		<MENUBODY>
			Cachedump (Obtain MS Hashes)
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://studenti.unina.it/~ncuomo/syskey/</menuurl>
		<MENUBODY>
			samdump2
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl> http://www.ethereal.com/</menuurl>
		<MENUBODY>
			Ethereal
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.immunitysec.com/resources-freesoftware.shtml</menuurl>
		<MENUBODY>
			Free Immunitysec Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.foundstone.com/resources/freetools.htm</menuurl>
		<MENUBODY>
			Free Foundstone Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.eeye.com/html/Research/Tools/index.html</menuurl>
		<MENUBODY>
			Free Eeye Tools
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://sectools.org/</menuurl>
		<MENUBODY>
			Sectools.org
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Free Virtualization Tools	
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.vmware.com/products/server/</menuurl>
		<MENUBODY>
			VMWare Server
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://bochs.sourceforge.net/</menuurl>
		<MENUBODY>
			Bochs
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://pearpc.sourceforge.net/</menuurl>
		<MENUBODY>
			PearPC	
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>	http://www.microsoft.com/windows/virtualpc/default.mspx</menuurl>
		<MENUBODY>
			MS Virtual PC
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Free Reverse Engineering/Debugging Tools	
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://directory.fsf.org/GNU/binutils.html</menuurl>
		<MENUBODY>
			binutils
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.gnu.org/software/gdb/</menuurl>
		<MENUBODY>
			GDB
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://directory.fsf.org/GNU/GUSS.html</menuurl>
		<MENUBODY>
			Guss
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.gnu.org/software/ddd/</menuurl>
		<MENUBODY>
			DDD
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.ollydbg.de/</menuurl>
		<MENUBODY>
			Ollydbg 
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://labs.idefense.com/labs-software.php</menuurl>
		<MENUBODY>
			iDefense Labs Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://oss.coresecurity.com/projects/uhooker.htm</menuurl>
		<MENUBODY>
			CORE Tools
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Defaced Websites
	</MENUTITLE>


	<MENUITEM>
		<menuurl> http://www.zone-h.org/component/option,com_attacks/Itemid,43/</menuurl>
		<MENUBODY>
			Zone H
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Default Password Lists
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.cirt.net/cgi-bin/passwd.pl</menuurl>
		<MENUBODY>
			Cirt's Passwords
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.phenoelit.de/dpl/dpl.html</menuurl>
		<MENUBODY>
			Phenoelit's Passwords
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.petefinnigan.com/default/default_password_list.htm</menuurl>
		<MENUBODY> Pete Finnigan's Default Oracle Passwords</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php</menuurl>
		<MENUBODY>
			GovernmentSecurity.org
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://defaultpassword.com/</menuurl>
		<MENUBODY>
			defaultpassword.com
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.cyxla.com/passwords/passwords.html</menuurl>
		<MENUBODY>
			Cyxla's Password Database
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.e-tech.ca/017-Default_Passwords_ad.asp</menuurl>
		<MENUBODY>
			e-tech Default Passwords
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.uktsupport.co.uk/reference/biosp.htm</menuurl>
		<MENUBODY>
			Bios Passwords
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Technical Conferences
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.defcon.org</menuurl>
		<MENUBODY>
			DefCon
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.blackhat.com</menuurl>
		<MENUBODY>
			Blackhat
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.cansecwest.com</menuurl>
		<MENUBODY>
			CanSecWest
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://toorcon.com</menuurl>
		<MENUBODY>
			Toorcon
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.shmoocon.org/</menuurl>
		<MENUBODY>
			ShmooCon
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.hopenumbersix.net/</menuurl>
		<MENUBODY>
			H.O.P.E.
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.ccc.de/</menuurl>
		<MENUBODY>
			Chaos Computer Club
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://conference.hackinthebox.org/</menuurl>
		<MENUBODY>
			Hack in the Box
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		CD Distros
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.remote-exploit.org/index.php/Auditor_main</menuurl>
		<MENUBODY>
			Auditor
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.knoppix.org</menuurl>
		<MENUBODY>
			Knoppix
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.whoppix.net/index.php/Tools</menuurl>
		<MENUBODY>
			Whoppix / Whax
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.remote-exploit.org/index.php/Main_Page</menuurl>
		<MENUBODY>
			BackTrack
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Wireless Tools
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.netstumbler.com</menuurl>
		<MENUBODY>
			Netstumbler
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://prismstumbler.sourceforge.net</menuurl>
		<MENUBODY>
			Prismstubler
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.kismetwireless.net</menuurl>
		<MENUBODY>
			Kismet
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://kismac.de/</menuurl>
		<MENUBODY>
			Kismac (For Macs)
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://airsnort.shmoo.com</menuurl>
		<MENUBODY>
			Airsnort
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://wepcrack.sourceforge.net</menuurl>
		<MENUBODY>
			WEPCrack
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.aircrack-ng.org/doku.php</menuurl>
		<MENUBODY>
			Aircrack-ng
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://csrc.nist.gov/publications/nistpubs/800-48/NIST_SP-48.pdf</menuurl>
		<MENUBODY>
			Wireless SP
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl> http://www.blackalchemy.to/project/fakeap/</menuurl>
		<MENUBODY>
			FakeAP
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.802.11mercenary.net/lorcon/</menuurl>
		<MENUBODY>
			Lorcon
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://theta44.org/karma/index.html</menuurl>
		<MENUBODY>
			Karma
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Checklists / Hardening Guides
	</MENUTITLE>

	<MENUITEM>
		<menuurl> http://csrc.nist.gov</menuurl>
		<MENUBODY>
			NIST CSRC
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://nvd.nist.gov/cvss.cfm?version=2</menuurl>
		<MENUBODY>
			NIST NVD Common Vulnerability Scoring System (Risk Rating Standardization)
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://checklists.nist.gov</menuurl>
		<MENUBODY>
			NIST Checklists
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.cisecurity.org</menuurl>
		<MENUBODY>
			Center for Internet Security
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.nsa.gov/snac/index.cfm?MenuID=scg10.3.1</menuurl>
		<MENUBODY>
			NSA Security Configuration Guides
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>

		<menuurl> http://otn.oracle.com/deploy/security/oracle9i/pdf/9i_checklist.pdf</menuurl>
		<MENUBODY>
			Oracle's 9i Checklist
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>

		<menuurl> http://www.petefinnigan.com/orasec.htm</menuurl>
		<MENUBODY>
			PF's Checklists
		</MENUBODY>

	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.microsoft.com/technet/archive/security/chklist/default.mspx</menuurl>
		<MENUBODY>
			Microsoft Checklists
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.openna.com/pdfs/Securing-Optimizing-Linux-The-Ultimate-Solution-v2.0.pdf</menuurl>
		<MENUBODY>
			Securing and Optimizing Linux
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		OS and Service Hardening Tools
        </MENUTITLE>


        <MENUITEM>
                <menuurl> http://www.sun.com/software/security/jass/</menuurl>
                <MENUBODY>
			Solaris - JASS
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl> http://www.sun.com/service/serviceplans/software/patchmanagement/patchmanager.html</menuurl>
                <MENUBODY>
			Solaris - Patch Manager
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl> http://www.bastille-unix.org/</menuurl>
                <MENUBODY>
			Bastille Unix
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl> http://www.microsoft.com/technet/security/tools/default.mspx#EZE</menuurl>
                <MENUBODY>
			Microsoft Security Tools
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>
   <MENUOBJECT>
	<MENUTITLE>
		Defunct Research Groups ?
	</MENUTITLE>
	<MENUITEM>
		<menuurl> http://www.attrition.org</menuurl>
		<MENUBODY>
			Attrition
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.w00w00.org</menuurl>
		<MENUBODY>
			w00w00
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://adm.freelsd.net/ADM/</menuurl>
		<MENUBODY>
			ADM
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://en.wikipedia.org/wiki/TESO</menuurl>
		<MENUBODY>
			TESO	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://en.wikipedia.org/wiki/Gobbles</menuurl>
		<MENUBODY>
			Gobbles	
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>


    <MENUOBJECT>
	<MENUTITLE>
		Professional Security Programs
	</MENUTITLE>

	<MENUITEM>
		<menuurl>https://www.pcisecuritystandards.org/</menuurl>
		<MENUBODY>
		  Payment Card Industry	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.isc2.org</menuurl>
		<MENUBODY>
			ISC2
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>http://www.eccouncil.org/</menuurl>
		<MENUBODY>
		 	EC Council	
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
                Password Crackers/Auditors
        </MENUTITLE>


	<MENUITEM>
		<menuurl> http://www.insecure.org/stf/lc5-setup.exe</menuurl>
		<MENUBODY>
			LC5 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.insecure.org/stf/lc5-crack.zip</menuurl>
		<MENUBODY>
			LC5 Keygen
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://www.oxid.it/cain.html</menuurl>
		<MENUBODY>
			Cain and Abel
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl> http://www.openwall.com/john/</menuurl>
		<MENUBODY>
			John the Ripper
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl> http://www.banquise.net/misc/patch-john.html</menuurl>
		<MENUBODY>
			John Bigpatch (For more hash types)
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://en.wikipedia.org/wiki/RainbowCrack</menuurl>
		<MENUBODY>
			RainbowCrack 
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl> http://rainbowtables.shmoo.com/</menuurl>
		<MENUBODY>
			Rainbow Tables
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>


   <MENUOBJECT>
        <MENUTITLE>
                Open Source Intelligence
        </MENUTITLE>

        <MENUITEM>
                <menuurl> http://johnny.ihackstuff.com/</menuurl>
                <MENUBODY>
                        Google Hacking
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://news.netcraft.com/</menuurl>
                <MENUBODY>
                        NetCraft
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://www.archive.org/</menuurl>
                <MENUBODY>
                        Way Back Machine
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl> http://www.domaintools.com</menuurl>
                <MENUBODY>
                        DomainTools
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl> http://whois.webhosting.info</menuurl>
                <MENUBODY>
                        Web Hosting dot info 
                </MENUBODY>
        </MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Compliance Resources
        </MENUTITLE>

        <MENUITEM>
                <menuurl> http://www.hhs.gov/ocr/hipaa/</menuurl>
                <MENUBODY>
                        HIPAA
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://www.aicpa.org/info/sarbanes_oxley_summary.htm</menuurl>
                <MENUBODY>
			SOX
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://banking.senate.gov/conf/</menuurl>
                <MENUBODY>
			FMA (GLBA)
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://csrc.nist.gov/sec-cert/</menuurl>
                <MENUBODY>
			FISMA
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://www.iso.org/iso/en/prods-services/popstds/informationsecurity.html</menuurl>
                <MENUBODY>
			ISO 17799
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://csrc.nist.gov/fasp/</menuurl>
                <MENUBODY>
			NIST FASP Resources
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp.html</menuurl>
                <MENUBODY>
			Visa PCI
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://www.sans.org/resources/policies/</menuurl>
                <MENUBODY>
			SANS Security Policies
                </MENUBODY>
        </MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Email Lists
        </MENUTITLE>

        <MENUITEM>
                <menuurl> http://www.securityfocus.com/archive</menuurl>
                <MENUBODY>
			Security Focus E-mail Lists
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://lists.grok.org.uk/mailman/listinfo/full-disclosure</menuurl>
                <MENUBODY>
			Full Disclosure (Unmoderated)
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl> http://www.immunitysec.com/mailman/listinfo/dailydave</menuurl>
                <MENUBODY>
			Daily Dave
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl> http://www.seclists.org</menuurl>
                <MENUBODY>
			Security List Archives
                </MENUBODY>
        </MENUITEM>


   </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Defense / IDS
        </MENUTITLE>

        <MENUITEM>
                <menuurl> http://www.snort.org</menuurl>
                <MENUBODY>
			Snort
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://www.bleedingsnort.com</menuurl>
                <MENUBODY>
			"Bleeding Edge" Snort
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://acidlab.sourceforge.net/</menuurl>
                <MENUBODY>
			ACID Snort Interface
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>





   <MENUOBJECT>
        <MENUTITLE>
		Load Testing / Denial of Service Info
        </MENUTITLE>
        <MENUITEM>
                <menuurl> http://staff.washington.edu/dittrich/misc/ddos/</menuurl>
                <MENUBODY>
			DDOS Info
                </MENUBODY>
        </MENUITEM>

   </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		IDS Testing/Tuning Tools
        </MENUTITLE>

        <MENUITEM>
                <menuurl> ftp://ftp.st.ryuAkoku.ac.jp/pub/security/tool/snot/</menuurl>
                <MENUBODY>
			Snot
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl> http://securityfocus.com/data/tools/stick.tgz</menuurl>
                <MENUBODY>
			Stick
                </MENUBODY>
        </MENUITEM>

   </MENUOBJECT>
   <MENUOBJECT>
        <MENUTITLE>
		Firewall Ruleset Testing Tools
        </MENUTITLE>

        <MENUITEM>
                <menuurl> http://www.packetfactory.net/projects/firewalk/</menuurl>
                <MENUBODY>
			Firewalk
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl> http://dev.inversepath.com/trac/ftester</menuurl>
                <MENUBODY>
			FTester
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>
</MENU>
<MSG>
    <MSGARTICLE>
	<MSGTITLE>
Welcome to the ThreatPerspective Security Information Center.
	</MSGTITLE>
	<MSGBODY>
This is a portal site created by ThreatPerspective to enable our clients and other interested parties to learn more about Information Security.
	</MSGBODY>
    </MSGARTICLE>
</MSG>
<rss version="2.0">
<channel>
    <title>Bugtraq</title>
    <link>http://seclists.org/#bugtraq</link>
    <description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!</description>
  <item>
    <title>[SECURITY] [DSA 2077-1] New openldap packages fix potential code execution</title>
    <link>http://seclists.org/bugtraq/2010/Jul/264</link>
    <description>&lt;p&gt;Posted by Florian Weimer on Jul 29&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
Problem type   : remote...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Ann] Reminder: HITB2010 Malaysia Call for Papers Closing August 9th</title>
    <link>http://seclists.org/bugtraq/2010/Jul/263</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jul 29&lt;/p&gt;This is a reminder that the Call for Papers for Asia's largest network&lt;br&gt;
Venue: Crowne Plaza Mutiara Kuala Lumpur...&lt;br&gt;</description>
  </item>
  <item>
    <title>CFP NcN 2010</title>
    <link>http://seclists.org/bugtraq/2010/Jul/262</link>
    <description>&lt;p&gt;Posted by Jose Nicolas Castellano on Jul 29&lt;/p&gt;*************************************************&lt;br&gt;
** What is No cON Name...&lt;br&gt;</description>
  </item>
  <item>
    <title>[ MDVSA-2010:142 ] openldap</title>
    <link>http://seclists.org/bugtraq/2010/Jul/261</link>
    <description>&lt;p&gt;Posted by security on Jul 29&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
           Enterprise Server 5.0...&lt;br&gt;</description>
  </item>
  <item>
    <title>PBBooking 1.0.4_3 Joomla Component Multiple Blind SQL Injection</title>
    <link>http://seclists.org/bugtraq/2010/Jul/260</link>
    <description>&lt;p&gt;Posted by Salvatore Fresta aka Drosophila on Jul 29&lt;/p&gt;PBBooking 1.0.4_3 Joomla Component Multiple Blind SQL Injection&lt;br&gt;
 IV....&lt;br&gt;</description>
  </item>
  <item>
    <title>[security bulletin] HPSBUX02556 SSRT100014 rev.2 - HP-UX Running rpc.ttdbserver, Remote Execution of Arbitrary Code</title>
    <link>http://seclists.org/bugtraq/2010/Jul/259</link>
    <description>&lt;p&gt;Posted by security-alert on Jul 29&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
Source: Hewlett-Packard Company, HP Software Security Response Team...&lt;br&gt;</description>
  </item>
  <item>
    <title>New vulnerabilities in Cetera eCommerce</title>
    <link>http://seclists.org/bugtraq/2010/Jul/258</link>
    <description>&lt;p&gt;Posted by MustLive on Jul 28&lt;/p&gt;Hello Bugtraq!&lt;br&gt;
31.10.2009 - informed developers about...&lt;br&gt;</description>
  </item>
  <item>
    <title>Vulnerabilities in Cetera eCommerce</title>
    <link>http://seclists.org/bugtraq/2010/Jul/257</link>
    <description>&lt;p&gt;Posted by MustLive on Jul 28&lt;/p&gt;Hello Bugtraq!&lt;br&gt;
01.03.2009 -...&lt;br&gt;</description>
  </item>
  <item>
    <title>PhotoMap Gallery 1.6.0 Joomla Component Multiple Blind SQL Injection</title>
    <link>http://seclists.org/bugtraq/2010/Jul/256</link>
    <description>&lt;p&gt;Posted by Salvatore Fresta aka Drosophila on Jul 28&lt;/p&gt;PhotoMap Gallery 1.6.0 Joomla Component Multiple Blind SQL Injection&lt;br&gt;
 IV....&lt;br&gt;</description>
  </item>
  <item>
    <title>[security bulletin] HPSBMA02549 SSRT090158 rev.2 - HP Insight Control Power Management for Windows, Local Unauthorized Read Access to Data</title>
    <link>http://seclists.org/bugtraq/2010/Jul/255</link>
    <description>&lt;p&gt;Posted by security-alert on Jul 28&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
Source: Hewlett-Packard Company, HP...&lt;br&gt;</description>
  </item>
  <item>
    <title>Jira Enterprise 4.0.1 - Multiple Low Risk Vulnerabilities</title>
    <link>http://seclists.org/bugtraq/2010/Jul/254</link>
    <description>&lt;p&gt;Posted by advisories on Jul 28&lt;/p&gt; Jira - Multiple Low Risk Vulnerabilities&lt;br&gt;
Jira is prone to Cross...&lt;br&gt;</description>
  </item>
  <item>
    <title>Secunia Research: Autonomy KeyView wkssr.dll Record Parsing Buffer Overflows</title>
    <link>http://seclists.org/bugtraq/2010/Jul/253</link>
    <description>&lt;p&gt;Posted by Secunia Research on Jul 28&lt;/p&gt;====================================================================== &lt;br&gt;
Vendor's Description of...&lt;br&gt;</description>
  </item>
  <item>
    <title>Secunia Research: Autonomy KeyView wkssr.dll String Indexing Vulnerability</title>
    <link>http://seclists.org/bugtraq/2010/Jul/252</link>
    <description>&lt;p&gt;Posted by Secunia Research on Jul 28&lt;/p&gt;====================================================================== &lt;br&gt;
Vendor's Description of...&lt;br&gt;</description>
  </item>
  <item>
    <title>Secunia Research: Autonomy KeyView wkssr.dll Integer Underflow Vulnerability</title>
    <link>http://seclists.org/bugtraq/2010/Jul/251</link>
    <description>&lt;p&gt;Posted by Secunia Research on Jul 28&lt;/p&gt;====================================================================== &lt;br&gt;
Vendor's Description of...&lt;br&gt;</description>
  </item>
  <item>
    <title>Secunia Research: Autonomy KeyView wosr.dll Data Block Parsing Buffer Overflow</title>
    <link>http://seclists.org/bugtraq/2010/Jul/250</link>
    <description>&lt;p&gt;Posted by Secunia Research on Jul 28&lt;/p&gt;====================================================================== &lt;br&gt;
Vendor's Description...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Daily Dave</title>
    <link>http://seclists.org/#dailydave</link>
    <description>This technical discussion list covers vulnerability research, exploit development, and security events/gossip.  It was started by &lt;a href=&quot;http://www.immunitysec.com/&quot;&gt;ImmunitySec&lt;/a&gt; founder Dave Aitel and many security luminaries participate.  Many posts simply advertise Immunity products, but you can&#39;t really fault Dave for being self-promotional on a list named DailyDave.</description>
  <item>
    <title>Re: Things that slipped the pwnie net.</title>
    <link>http://seclists.org/dailydave/2010/q3/16</link>
    <description>&lt;p&gt;Posted by Alexander Sotirov on Jul 25&lt;/p&gt;NGINX got a pwnie nomination by proxy, Dr. Raid's song 'Pwned' mentions the&lt;br&gt;
  Those pics of you and your sis, they base64 encoded that shit and...&lt;br&gt;</description>
  </item>
  <item>
    <title>Call For Papers - Hackers 2 Hackers Conference 7th	Edition - Brazil</title>
    <link>http://seclists.org/dailydave/2010/q3/15</link>
    <description>&lt;p&gt;Posted by Rodrigo Rubira Branco (BSDaemon) on Jul 25&lt;/p&gt; CALL FOR PAPERS - Hackers 2 Hackers Conference 7th edition&lt;br&gt;
from 27 to 28 November 2010, and aims to get together industry,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: there might be three people who missed it...</title>
    <link>http://seclists.org/dailydave/2010/q3/14</link>
    <description>&lt;p&gt;Posted by Jon Oberheide on Jul 22&lt;/p&gt;This brings up an interesting question I had related to cross-vendor&lt;br&gt;
disclosure (via an innocent-sounding...&lt;br&gt;</description>
  </item>
  <item>
    <title>there might be three people who missed it...</title>
    <link>http://seclists.org/dailydave/2010/q3/13</link>
    <description>&lt;p&gt;Posted by Michal Zalewski on Jul 22&lt;/p&gt;...so FYI:&lt;br&gt;
/mz&lt;br&gt;</description>
  </item>
  <item>
    <title>SILICA-U</title>
    <link>http://seclists.org/dailydave/2010/q3/12</link>
    <description>&lt;p&gt;Posted by dave on Jul 22&lt;/p&gt;So it's been a while since I've posted about wireless penetration testing. And&lt;br&gt;
to implement....&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Your trusted computing base is not what you think	it	is! :&gt;</title>
    <link>http://seclists.org/dailydave/2010/q3/11</link>
    <description>&lt;p&gt;Posted by Florian Weimer on Jul 19&lt;/p&gt;Only if the key is virtually unused.  If it is not, revocation is&lt;br&gt;
which cannot leak the key material,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Mini Fuzzer Shootout</title>
    <link>http://seclists.org/dailydave/2010/q3/10</link>
    <description>&lt;p&gt;Posted by Ben Nagy on Jul 19&lt;/p&gt;Hi all,&lt;br&gt;
and decided that one of the things...&lt;br&gt;</description>
  </item>
  <item>
    <title>Kiwicon IV: Our Worst CFP Yet</title>
    <link>http://seclists.org/dailydave/2010/q3/9</link>
    <description>&lt;p&gt;Posted by Kiwicon on Jul 15&lt;/p&gt; ----[ TRULY THE FUTURE IS NOW, FOR IT IS THE YEAR&lt;br&gt;
          |::.. . ||::.. . |  |::.||::.. . ||::.|:. ||::.. . /...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Your trusted computing base is not what you think it	is! :&gt;</title>
    <link>http://seclists.org/dailydave/2010/q3/8</link>
    <description>&lt;p&gt;Posted by Shane on Jul 15&lt;/p&gt;The good thing about their signing key is that it's static (does not&lt;br&gt;
I've almost never seen a verified FF addon...&lt;br&gt;</description>
  </item>
  <item>
    <title>Your trusted computing base is not what you think it	is! :&gt;</title>
    <link>http://seclists.org/dailydave/2010/q3/7</link>
    <description>&lt;p&gt;Posted by dave on Jul 15&lt;/p&gt;Here are some trojans signed by a key from realtek, supposably. How cool is that! You&lt;br&gt;
And, as pointed out:...&lt;br&gt;</description>
  </item>
  <item>
    <title>FW: Black Hat Abu Dhabi CFP - November 10 - 11 2010</title>
    <link>http://seclists.org/dailydave/2010/q3/6</link>
    <description>&lt;p&gt;Posted by The Dark Tangent on Jul 15&lt;/p&gt;Call for Papers - Black Hat Abu Dhabi 2010&lt;br&gt;
East's first edition of the Las...&lt;br&gt;</description>
  </item>
  <item>
    <title>Pwnie Awards 2010</title>
    <link>http://seclists.org/dailydave/2010/q3/5</link>
    <description>&lt;p&gt;Posted by Alexander Sotirov on Jul 14&lt;/p&gt;The Pwnie Awards ceremony will return for the fourth consecutive year to the&lt;br&gt;
 * Best...&lt;br&gt;</description>
  </item>
  <item>
    <title>AI is a good problem to have.</title>
    <link>http://seclists.org/dailydave/2010/q3/4</link>
    <description>&lt;p&gt;Posted by dave on Jul 14&lt;/p&gt;Lcamtuf says&lt;br&gt;
right...&lt;br&gt;</description>
  </item>
  <item>
    <title>&quot;Finding 0days&quot;</title>
    <link>http://seclists.org/dailydave/2010/q3/3</link>
    <description>&lt;p&gt;Posted by dave on Jul 12&lt;/p&gt;In just a few days Immunity has a training called &amp;quot;Finding 0days&amp;quot; here in Miami&lt;br&gt;
0days tends to shift a bit depending on who the instructor is. Which generally brings...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Solutions</title>
    <link>http://seclists.org/dailydave/2010/q3/2</link>
    <description>&lt;p&gt;Posted by Andre Gironda on Jul 07&lt;/p&gt;Rich,&lt;br&gt;
Dave says that...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Firewall Wizards</title>
    <link>http://seclists.org/#firewall-wizards</link>
    <description>Tips and tricks for firewall administrators</description>
  <item>
    <title>covert timing channel data</title>
    <link>http://seclists.org/firewall-wizards/2010/Jul/0</link>
    <description>&lt;p&gt;Posted by Melissa Stockman on Jul 29&lt;/p&gt;Hi,&lt;br&gt;
Melissa Stockman&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Taking a traffic snapshot with network IDS</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/13</link>
    <description>&lt;p&gt;Posted by vern on Jun 21&lt;/p&gt;You might want to check out Bro in this regard, which IMHO excels at this&lt;br&gt;
                Vern&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: firewall-wizards Digest, Vol 50, Issue 5</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/12</link>
    <description>&lt;p&gt;Posted by Bernie on Jun 21&lt;/p&gt;Personally I'd use wireshark Daniel. The ability to create file sets&lt;br&gt;
Wireshark by Laura Chappell is a great resource.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Taking a traffic snapshot with network IDS</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/11</link>
    <description>&lt;p&gt;Posted by Marcus J. Ranum on Jun 21&lt;/p&gt;Yack, Daniel wrote:&lt;br&gt;
That said, an IDS can be turned into one heck of a nice...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Taking a traffic snapshot with network IDS</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/10</link>
    <description>&lt;p&gt;Posted by Farrukh Haroon on Jun 21&lt;/p&gt;Instead of capturing each packet, you would be better off going via the&lt;br&gt;
On Fri, Jun 18, 2010 at 4:58 PM,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Taking a traffic snapshot with network IDS</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/9</link>
    <description>&lt;p&gt;Posted by Yack, Daniel on Jun 21&lt;/p&gt;There are probably one thousand ways to do this, but I wanted to toss&lt;br&gt;
template that says...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Firewall Best Practice regarding XMPP traffic?</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/8</link>
    <description>&lt;p&gt;Posted by paddy joesoap on Jun 17&lt;/p&gt;Hi Kevin and all,&lt;br&gt;
handle security on...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Firewall Best Practice regarding XMPP traffic?</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/7</link>
    <description>&lt;p&gt;Posted by K K on Jun 17&lt;/p&gt;In my experience, yes -- XMPP servers are generally deployed in the&lt;br&gt;
clients connect to an edge device using the legacy...&lt;br&gt;</description>
  </item>
  <item>
    <title>Firewall Best Practice regarding XMPP traffic?</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/6</link>
    <description>&lt;p&gt;Posted by paddy joesoap on Jun 16&lt;/p&gt;Hi all,&lt;br&gt;
firewall helps...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hidden ISP firewall/filtering</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/5</link>
    <description>&lt;p&gt;Posted by Paul Melson on Jun 08&lt;/p&gt;IPSec, but when &lt;br&gt;
airport, etc.)  If the ports...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hidden ISP firewall/filtering</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/4</link>
    <description>&lt;p&gt;Posted by Kurt Buff on Jun 08&lt;/p&gt;Layer 4 traceroute (&lt;a  rel=&quot;nofollow&quot; href=&quot;http://pwhois.org/lft/&quot;&gt;http://pwhois.org/lft/&lt;/a&gt;) comes to mind, or nmap,&lt;br&gt;
Kurt&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hidden ISP firewall/filtering</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/3</link>
    <description>&lt;p&gt;Posted by Craig Van Tassle on Jun 08&lt;/p&gt;Your best bet is to check with your ISP.&lt;br&gt;
a box that you can wipe after you do this test.&lt;br&gt;</description>
  </item>
  <item>
    <title>R:  Hidden ISP firewall/filtering</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/2</link>
    <description>&lt;p&gt;Posted by Andrea Mennini - Mobile on Jun 08&lt;/p&gt;Try grc.com shields up. It should give you a basic idea.&lt;br&gt;
Subject: [fw-wiz] Hidden ISP firewall/filtering&lt;br&gt;</description>
  </item>
  <item>
    <title>Hidden ISP firewall/filtering</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/1</link>
    <description>&lt;p&gt;Posted by Jerrod Fuller on Jun 04&lt;/p&gt; &lt;br&gt;
way to find out if our ISP actually has a...&lt;br&gt;</description>
  </item>
  <item>
    <title>EUSecWest 2010 MiniCFP (conf Jun 16/17) and PacSec 2010	CFP (conf Nov 10/11, deadline July 30)</title>
    <link>http://seclists.org/firewall-wizards/2010/Jun/0</link>
    <description>&lt;p&gt;Posted by Dragos Ruiu on Jun 04&lt;/p&gt;-- EUSecWest 2010 MiniCFP (PacSec CFP Follows)&lt;br&gt;
at the Melkweg in Amsterdam.) Please forward submissions to...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>IDS Focus</title>
    <link>http://seclists.org/#focus-ids</link>
    <description>Technical discussion about Intrusion Detection Systems.  You can also read the archives of a &lt;A HREF=&quot;http://seclists.org/ids/&quot;&gt;previous IDS list&lt;/A&gt;</description>
  <item>
    <title>CFP: Deadline Extended: SLAML'10</title>
    <link>http://seclists.org/focus-ids/2010/Jun/2</link>
    <description>&lt;p&gt;Posted by Mohror, Kathryn on Jun 18&lt;/p&gt;       Workshop on Managing Systems via Log Analysis and Machine &lt;br&gt;
              ********...&lt;br&gt;</description>
  </item>
  <item>
    <title>Announcement: xtractr updates</title>
    <link>http://seclists.org/focus-ids/2010/Jun/1</link>
    <description>&lt;p&gt;Posted by pcapr on Jun 08&lt;/p&gt;Just a quick note to let you know that the lite version of xtractr can&lt;br&gt;
If you are...&lt;br&gt;</description>
  </item>
  <item>
    <title>Performance measurement tool for IDS/IPS</title>
    <link>http://seclists.org/focus-ids/2010/Jun/0</link>
    <description>&lt;p&gt;Posted by wittybugz on Jun 01&lt;/p&gt;Hi All,&lt;br&gt;
on your web...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Full Disclosure</title>
    <link>http://seclists.org/#fulldisclosure</link>
    <description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
  <item>
    <title>Re: Day of bugs in WordPress 2</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/400</link>
    <description>&lt;p&gt;Posted by Elazar Broad on Jul 29&lt;/p&gt;ed or nano? :)&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Day of bugs in WordPress 2</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/399</link>
    <description>&lt;p&gt;Posted by Valdis . Kletnieks on Jul 29&lt;/p&gt;On Thu, 29 Jul 2010 17:18:28 PDT, Zach C said:&lt;br&gt;
vi or emacs. Take your pick, I'm not starting an editor war. ;)&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Day of bugs in WordPress 2</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/398</link>
    <description>&lt;p&gt;Posted by Zach C on Jul 29&lt;/p&gt;So if Drupal and WordPress, etc. are so terrible, what would you all recommend?&lt;br&gt;
-Zach&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Day of bugs in WordPress 2</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/397</link>
    <description>&lt;p&gt;Posted by coderman on Jul 29&lt;/p&gt;when the bar is wordpress, .. well, you get the picture.&lt;br&gt;
(those modules though, most could use regular scrubbing)&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Day of bugs in WordPress 2</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/396</link>
    <description>&lt;p&gt;Posted by Christian Sciberras on Jul 29&lt;/p&gt;Drupal or other decent [0]&lt;br&gt;
Please! Don't put &amp;quot;Drupal&amp;quot; and &amp;quot;decent&amp;quot; in the same sentence!&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Day of bugs in WordPress 2</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/395</link>
    <description>&lt;p&gt;Posted by coderman on Jul 29&lt;/p&gt;Hewlett Packard has a soul mate! anyone who cares uses Drupal or other&lt;br&gt;
python gevent based publishing pipe...&lt;br&gt;</description>
  </item>
  <item>
    <title>Day of bugs in WordPress 2</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/394</link>
    <description>&lt;p&gt;Posted by MustLive on Jul 29&lt;/p&gt;Hello Full-Disclosure!&lt;br&gt;
switched to smaller and less time-consuming, but still very...&lt;br&gt;</description>
  </item>
  <item>
    <title>[SECURITY] [DSA 2077-1] New openldap packages fix	potential code execution</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/393</link>
    <description>&lt;p&gt;Posted by Florian Weimer on Jul 29&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
Problem type   : remote...&lt;br&gt;</description>
  </item>
  <item>
    <title>the real stuxnet authors plz stand up</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/392</link>
    <description>&lt;p&gt;Posted by coderman on Jul 29&lt;/p&gt;stuxnet is strategic, and misleading. ... red team off roading?&lt;br&gt;
0. &amp;quot;Blowing the Whistle on the Snitch Racket&amp;quot;...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Ann] Reminder: HITB2010 Malaysia Call for	Papers Closing August 9th</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/391</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jul 29&lt;/p&gt;This is a reminder that the Call for Papers for Asia's largest network&lt;br&gt;
Venue: Crowne Plaza Mutiara Kuala Lumpur...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Patent Absurdity - How software patents broke	the system</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/390</link>
    <description>&lt;p&gt;Posted by M.B.Jr. on Jul 28&lt;/p&gt;I'm sorry, Rohit.&lt;br&gt;
Marcio Barbado, Jr.&lt;br&gt;</description>
  </item>
  <item>
    <title>[ MDVSA-2010:142 ] openldap</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/389</link>
    <description>&lt;p&gt;Posted by security on Jul 28&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
           Enterprise Server 5.0...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Patent Absurdity - How software patents broke	the system</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/388</link>
    <description>&lt;p&gt;Posted by M.B.Jr. on Jul 28&lt;/p&gt;Hi Rohit,&lt;br&gt;
So, if your company's employees write...&lt;br&gt;</description>
  </item>
  <item>
    <title>New vulnerabilities in Cetera eCommerce</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/387</link>
    <description>&lt;p&gt;Posted by MustLive on Jul 28&lt;/p&gt;Hello Full-Disclosure!&lt;br&gt;
31.10.2009 - informed developers...&lt;br&gt;</description>
  </item>
  <item>
    <title>Vulnerabilities in Cetera eCommerce</title>
    <link>http://seclists.org/fulldisclosure/2010/Jul/386</link>
    <description>&lt;p&gt;Posted by MustLive on Jul 28&lt;/p&gt;Hello Full-Disclosure!&lt;br&gt;
Timeline:...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Honeypots</title>
    <link>http://seclists.org/#honeypots</link>
    <description>Discussions about tracking attackers by setting up decoy honeypots or entire &lt;A HREF=&quot;http://www.honeynet.org&quot;&gt;honeynet&lt;/A&gt; networks.</description>
  <item>
    <title>[HITB-Ann] Reminder: HITB2010 Malaysia Call for Papers Closing August 9th</title>
    <link>http://seclists.org/honeypots/2010/q3/1</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jul 29&lt;/p&gt;This is a reminder that the Call for Papers for Asia's largest network&lt;br&gt;
Venue: Crowne Plaza Mutiara Kuala Lumpur...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Announce] HITB Magazine Issue 003 + HITBSecConf2010 - Amsterdam</title>
    <link>http://seclists.org/honeypots/2010/q3/0</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jul 04&lt;/p&gt;Our first ever HITBSecConf in Europe is over! A big big thank you to all&lt;br&gt;
All conference materials from the event can be downloaded from...&lt;br&gt;</description>
  </item>
  <item>
    <title>CFP: Deadline Extended: SLAML'10</title>
    <link>http://seclists.org/honeypots/2010/q2/8</link>
    <description>&lt;p&gt;Posted by Mohror, Kathryn on Jun 16&lt;/p&gt;       Workshop on Managing Systems via Log Analysis and Machine &lt;br&gt;
              ********...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Announce] HITBSecConf2010 - Malaysia Call for Papers</title>
    <link>http://seclists.org/honeypots/2010/q2/7</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on May 19&lt;/p&gt;The Call for Papers for HITB Security Conference 2010 Malaysia is now open!&lt;br&gt;
Keynote 1: Chris Wysopal...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: info reg Zeus bot detection and analysis</title>
    <link>http://seclists.org/honeypots/2010/q2/6</link>
    <description>&lt;p&gt;Posted by Younger Tyler on May 19&lt;/p&gt;Any tips on how to selectively get infected with Zeus?&lt;br&gt;
Interesting thoughts as I am just...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: info reg Zeus bot detection and analysis</title>
    <link>http://seclists.org/honeypots/2010/q2/5</link>
    <description>&lt;p&gt;Posted by Gary Derania on May 19&lt;/p&gt;------Original Message------&lt;br&gt;
analysis.  I...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: info reg Zeus bot detection and analysis</title>
    <link>http://seclists.org/honeypots/2010/q2/4</link>
    <description>&lt;p&gt;Posted by Michele Zoerb on May 19&lt;/p&gt;Interesting thoughts as I am just starting the same type of project.  I want to get infected by Zeus and perform some &lt;br&gt;
From: listbounce () securityfocus...&lt;br&gt;</description>
  </item>
  <item>
    <title>info reg Zeus bot detection and analysis</title>
    <link>http://seclists.org/honeypots/2010/q2/3</link>
    <description>&lt;p&gt;Posted by Mayank.2.Bhatnagar on May 19&lt;/p&gt;Hi everyone,&lt;br&gt;
What...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Announce] HITB eZine Issue 002 out now!</title>
    <link>http://seclists.org/honeypots/2010/q2/2</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Apr 23&lt;/p&gt;The second quarterly HITB eZine (issue 002) has been released! Grab your&lt;br&gt;
over 20K downloads just weeks after its...&lt;br&gt;</description>
  </item>
  <item>
    <title>[HITB-Announce] FINAL CALL - CFP for HITBSecConf2010 Amsterdam</title>
    <link>http://seclists.org/honeypots/2010/q2/1</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Apr 08&lt;/p&gt;This is the FINAL CALL to submit your talk / presentation proposals for&lt;br&gt;
To submit your presentation proposals and for further details...&lt;br&gt;</description>
  </item>
  <item>
    <title>Call For Papers - hack.lu 2010 - 27-29 October - Luxembourg</title>
    <link>http://seclists.org/honeypots/2010/q2/0</link>
    <description>&lt;p&gt;Posted by Alexandre Dulaunoy on Apr 04&lt;/p&gt;Call for Papers Hack.lu 2010&lt;br&gt;
Grand-Duchy of  Luxembourg in  October 2010 (27-29.10.2010).  The...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Incidents</title>
    <link>http://seclists.org/#incidents</link>
    <description>Lightly moderated list for dicussing actual security incidents (unexplained probes, breakins, etc).  Topics include information about new rootkits, backdoors, trojans, virii, and worms.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Microsoft Sec Notification</title>
    <link>http://seclists.org/#microsoft</link>
    <description>Beware that MS often uses these security bulletins as marketing propaganda to downplay serious vulnerabilities in their products&amp;mdash;note how most have a prominent and often-misleading &quot;mitigating factors&quot; section.</description>
  <item>
    <title>Microsoft Security Bulletin Minor Revision</title>
    <link>http://seclists.org/microsoft/2010/q3/7</link>
    <description>&lt;p&gt;Posted by Microsoft on Jul 21&lt;/p&gt;********************************************************************&lt;br&gt;
  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Advisory Notification</title>
    <link>http://seclists.org/microsoft/2010/q3/6</link>
    <description>&lt;p&gt;Posted by Microsoft on Jul 20&lt;/p&gt;********************************************************************&lt;br&gt;
  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Advisory Notification</title>
    <link>http://seclists.org/microsoft/2010/q3/5</link>
    <description>&lt;p&gt;Posted by Microsoft on Jul 19&lt;/p&gt;********************************************************************&lt;br&gt;
  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Advisory Notification</title>
    <link>http://seclists.org/microsoft/2010/q3/4</link>
    <description>&lt;p&gt;Posted by Microsoft on Jul 16&lt;/p&gt;********************************************************************&lt;br&gt;
  -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2010/q3/3</link>
    <description>&lt;p&gt;Posted by Microsoft on Jul 14&lt;/p&gt;********************************************************************&lt;br&gt;
Bulletin Information:...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Minor Revisions</title>
    <link>http://seclists.org/microsoft/2010/q3/2</link>
    <description>&lt;p&gt;Posted by Microsoft on Jul 13&lt;/p&gt;********************************************************************&lt;br&gt;
*...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Re-Release</title>
    <link>http://seclists.org/microsoft/2010/q3/1</link>
    <description>&lt;p&gt;Posted by Microsoft on Jul 13&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Summary for July 2010</title>
    <link>http://seclists.org/microsoft/2010/q3/0</link>
    <description>&lt;p&gt;Posted by Microsoft on Jul 13&lt;/p&gt;********************************************************************&lt;br&gt;
With the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Summary for June 2010</title>
    <link>http://seclists.org/microsoft/2010/q2/5</link>
    <description>&lt;p&gt;Posted by Microsoft on Jun 08&lt;/p&gt;********************************************************************&lt;br&gt;
With the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletim Summary for May 2010</title>
    <link>http://seclists.org/microsoft/2010/q2/4</link>
    <description>&lt;p&gt;Posted by Microsoft on May 11&lt;/p&gt;********************************************************************&lt;br&gt;
With the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Major Revision MS10-016</title>
    <link>http://seclists.org/microsoft/2010/q2/3</link>
    <description>&lt;p&gt;Posted by Microsoft on May 03&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Re-Release</title>
    <link>http://seclists.org/microsoft/2010/q2/2</link>
    <description>&lt;p&gt;Posted by Microsoft on Apr 27&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Major Revision</title>
    <link>http://seclists.org/microsoft/2010/q2/1</link>
    <description>&lt;p&gt;Posted by Microsoft on Apr 21&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;</description>
  </item>
  <item>
    <title>Microsoft Security Bulletin Summary for April 2010</title>
    <link>http://seclists.org/microsoft/2010/q2/0</link>
    <description>&lt;p&gt;Posted by Microsoft on Apr 13&lt;/p&gt;********************************************************************&lt;br&gt;
With...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Nmap Development</title>
    <link>http://seclists.org/#nmap-dev</link>
    <description>Unmoderated technical development forum for debating ideas, patches, and suggestions regarding proposed changes to &lt;A HREF=&quot;http://nmap.org&quot;&gt;Nmap&lt;/A&gt; and related projects.</description>
  <item>
    <title>Re: Nmap Scan Results</title>
    <link>http://seclists.org/nmap-dev/2010/q3/217</link>
    <description>&lt;p&gt;Posted by Jon Svede on Jul 29&lt;/p&gt;I had the same issue a while back.  After I left that job I decided  &lt;br&gt;
If you a solution already though, there isn't any need to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Nmap Scan Results</title>
    <link>http://seclists.org/nmap-dev/2010/q3/216</link>
    <description>&lt;p&gt;Posted by Tuan Nguyen on Jul 29&lt;/p&gt;I want to be able to parse the Nmap XML output in Java and convert it to&lt;br&gt;
Do you have another way to parse Nmap and convert it to Java object?&lt;br&gt;</description>
  </item>
  <item>
    <title>nmap can detect printer?</title>
    <link>http://seclists.org/nmap-dev/2010/q3/215</link>
    <description>&lt;p&gt;Posted by Jacky Jack on Jul 29&lt;/p&gt;Hi&lt;br&gt;
Thanks.&lt;br&gt;</description>
  </item>
  <item>
    <title>NMap Scripts Vs Nessus</title>
    <link>http://seclists.org/nmap-dev/2010/q3/214</link>
    <description>&lt;p&gt;Posted by Jacky Jack on Jul 29&lt;/p&gt;Hi&lt;br&gt;
writing/converting Nessus plugins to NSEs....&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Nmap Scan Results</title>
    <link>http://seclists.org/nmap-dev/2010/q3/213</link>
    <description>&lt;p&gt;Posted by Jon Svede on Jul 29&lt;/p&gt;What do you want to do with the results?  I.e., are you looking just&lt;br&gt;
Jon&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: fix to build nmap on some OpenBSD archs</title>
    <link>http://seclists.org/nmap-dev/2010/q3/212</link>
    <description>&lt;p&gt;Posted by Sebastian Reitenbach on Jul 29&lt;/p&gt;Hi,&lt;br&gt;
I tried to remove above two patches and removed the patch above from...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: fix to build nmap on some OpenBSD archs</title>
    <link>http://seclists.org/nmap-dev/2010/q3/211</link>
    <description>&lt;p&gt;Posted by Sebastian Reitenbach on Jul 28&lt;/p&gt;Hi,&lt;br&gt;
Sebastian&lt;br&gt;</description>
  </item>
  <item>
    <title>typo in nmap-service-probes</title>
    <link>http://seclists.org/nmap-dev/2010/q3/210</link>
    <description>&lt;p&gt;Posted by Gutek on Jul 28&lt;/p&gt;just a small typo in the &amp;quot;Canon iR3570 printer ftpd&amp;quot; fingerprint (reads&lt;br&gt;
A.G.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: New Feature in zenmap interface - Script Selection</title>
    <link>http://seclists.org/nmap-dev/2010/q3/209</link>
    <description>&lt;p&gt;Posted by kirubakaran S on Jul 28&lt;/p&gt;     Yes, The formatting of text in Description box is not done. It is just&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://kirubakaran-blessedblogger.blogspot.com/&quot;&gt;http://kirubakaran-blessedblogger.blogspot.com/&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: [Ncat] I'd like to contribute a feature</title>
    <link>http://seclists.org/nmap-dev/2010/q3/208</link>
    <description>&lt;p&gt;Posted by David Fifield on Jul 28&lt;/p&gt;Thanks for your interest! Please help us understand what you have in&lt;br&gt;
As for code organization, --sh-exec and --exec are handled in the files...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: [nmap-svn] r19330 - in nmap: . libnetutil</title>
    <link>http://seclists.org/nmap-dev/2010/q3/207</link>
    <description>&lt;p&gt;Posted by David Fifield on Jul 28&lt;/p&gt;Good catch on this. We had a test for --mtu in Nping, but I guess we&lt;br&gt;
David Fifield&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: fix to build nmap on some OpenBSD archs</title>
    <link>http://seclists.org/nmap-dev/2010/q3/206</link>
    <description>&lt;p&gt;Posted by David Fifield on Jul 28&lt;/p&gt;Thanks. I see that this patch is mostly about not mixing code and&lt;br&gt;
gcc -c -I../../nbase...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Bugfixes for smb-psexec</title>
    <link>http://seclists.org/nmap-dev/2010/q3/205</link>
    <description>&lt;p&gt;Posted by David Fifield on Jul 28&lt;/p&gt;I think this is fine to commit now.&lt;br&gt;
David Fifield&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: New Feature in zenmap interface - Script Selection</title>
    <link>http://seclists.org/nmap-dev/2010/q3/204</link>
    <description>&lt;p&gt;Posted by David Fifield on Jul 28&lt;/p&gt;Thank you for testing, Kris. I agree, we should collapse single newlines&lt;br&gt;
David Fifield&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: New Feature in zenmap interface - Script Selection</title>
    <link>http://seclists.org/nmap-dev/2010/q3/203</link>
    <description>&lt;p&gt;Posted by Kris Katterjohn on Jul 28&lt;/p&gt;I have one comment on the Description box: the text tends to look rather goofy&lt;br&gt;
paragraph separation.  This is just a...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Nmap Hackers</title>
    <link>http://seclists.org/#nmap-hackers</link>
    <description>Moderated list for the most important new releases and announcements regarding the &lt;A HREF=&quot;http://nmap.org&quot;&gt;Nmap Security Scanner&lt;/A&gt; and related projects. We recommend that all Nmap users &lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot;&gt;subscribe&lt;/a&gt;.</description>
  <item>
    <title>Nmap Defcon Release: Version 5.35DC1</title>
    <link>http://seclists.org/nmap-hackers/2010/7</link>
    <description>&lt;p&gt;Posted by Fyodor on Jul 16&lt;/p&gt;Hi folks.  It has been 3.5 months since the last Nmap release&lt;br&gt;
Hat in a couple weeks (see...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap News and Last Chance to Take the Survey</title>
    <link>http://seclists.org/nmap-hackers/2010/6</link>
    <description>&lt;p&gt;Posted by Fyodor on Apr 30&lt;/p&gt;Hi Folks.  I have some Nmap news to share with you:&lt;br&gt;
Drazen Popovic and Djalal Harouni will be working on...&lt;br&gt;</description>
  </item>
  <item>
    <title>Survey Reminder</title>
    <link>http://seclists.org/nmap-hackers/2010/5</link>
    <description>&lt;p&gt;Posted by Fyodor on Apr 14&lt;/p&gt;Hi folks, I have a quick question for you:&lt;br&gt;
post...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap/SecTools Survey and GSoC Deadline</title>
    <link>http://seclists.org/nmap-hackers/2010/4</link>
    <description>&lt;p&gt;Posted by Fyodor on Apr 07&lt;/p&gt;Hello everyone.  I hope you're enjoying the 5.30BETA1 release.  So far&lt;br&gt;
summer!  SoC previously brought us...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.30BETA1 Released w/37 new scripts and new Apple vuln</title>
    <link>http://seclists.org/nmap-hackers/2010/3</link>
    <description>&lt;p&gt;Posted by Fyodor on Mar 29&lt;/p&gt;Hi folks!  It has been two months since the 5.21 release and we've&lt;br&gt;
  ipidseq. Learn about them all at...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.21 released</title>
    <link>http://seclists.org/nmap-hackers/2010/2</link>
    <description>&lt;p&gt;Posted by Fyodor on Jan 27&lt;/p&gt;Hello everyone.  I'm pleased to release Nmap 5.21, which contains zero&lt;br&gt;
development projects.  If you want to know...&lt;br&gt;</description>
  </item>
  <item>
    <title>Lots of Nmap News</title>
    <link>http://seclists.org/nmap-hackers/2010/1</link>
    <description>&lt;p&gt;Posted by Fyodor on Jan 22&lt;/p&gt;Hi folks.  I'm happy to report that the 5.20 release went well.  But&lt;br&gt;
If you're running from a build of the latest SVN checkout, you...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.20 Released</title>
    <link>http://seclists.org/nmap-hackers/2010/0</link>
    <description>&lt;p&gt;Posted by Fyodor on Jan 20&lt;/p&gt;Happy new year, everyone.  I'm happy to announce Nmap 5.20--our first&lt;br&gt;
The...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 5.00 Released!</title>
    <link>http://seclists.org/nmap-hackers/2009/3</link>
    <description>&lt;p&gt;Posted by Fyodor on Jul 16&lt;/p&gt;Hello everyone.  I'm delighted to announce the release of Nmap 5.00!&lt;br&gt;
1) The new Ncat tool aims to be your Swiss Army Knife...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap news: stable release candidate 4.90RC1, SoC team,	and new translations</title>
    <link>http://seclists.org/nmap-hackers/2009/2</link>
    <description>&lt;p&gt;Posted by Fyodor on Jun 26&lt;/p&gt;Hi Folks.  I'm pleased to announce some exciting Nmap news:&lt;br&gt;
Please test it out, and let us know if you find any problems...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap 4.85BETA6 now avail w/Conficker detection</title>
    <link>http://seclists.org/nmap-hackers/2009/1</link>
    <description>&lt;p&gt;Posted by Fyodor on Apr 01&lt;/p&gt;Hi Folks!  In case you missed all the news reports yesterday, a couple&lt;br&gt;
millions of infections, and this massive botnet...&lt;br&gt;</description>
  </item>
  <item>
    <title>Nmap News: 4.84BETA4 release, Nmap book news, Summer of Code, Twitter,	etc.</title>
    <link>http://seclists.org/nmap-hackers/2009/0</link>
    <description>&lt;p&gt;Posted by Fyodor on Mar 27&lt;/p&gt;Hello everyone.  We've seen 848 messages on nmap-dev this year, but&lt;br&gt;
4.85BETA4 release,...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Penetration Testing</title>
    <link>http://seclists.org/#pen-test</link>
    <description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.</description>
  <item>
    <title>[HITB-Ann] Reminder: HITB2010 Malaysia Call for Papers Closing August 9th</title>
    <link>http://seclists.org/pen-test/2010/Jul/57</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jul 29&lt;/p&gt;This is a reminder that the Call for Papers for Asia's largest network&lt;br&gt;
Venue: Crowne Plaza Mutiara Kuala Lumpur...&lt;br&gt;</description>
  </item>
  <item>
    <title>HELP. How to dump one NDS?</title>
    <link>http://seclists.org/pen-test/2010/Jul/56</link>
    <description>&lt;p&gt;Posted by Alonso Jose da Silva II on Jul 28&lt;/p&gt;Guys,&lt;br&gt;
AlonsoII&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: People are bad at trust.... new article</title>
    <link>http://seclists.org/pen-test/2010/Jul/55</link>
    <description>&lt;p&gt;Posted by Pete Herzog on Jul 28&lt;/p&gt;Jeff,&lt;br&gt;
-pete.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: demoing sslv2 vulns</title>
    <link>http://seclists.org/pen-test/2010/Jul/54</link>
    <description>&lt;p&gt;Posted by Saleh on Jul 28&lt;/p&gt;Here is a demonstration for SSL Strip Attack:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securitytube.net/SSLstrip-Tutorial-video.aspx&quot;&gt;http://securitytube.net/SSLstrip-Tutorial-video.aspx&lt;/a&gt;&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: demoing sslv2 vulns</title>
    <link>http://seclists.org/pen-test/2010/Jul/53</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jul 28&lt;/p&gt;A we've pointed out quite a few times, I was looking for attacks on&lt;br&gt;
and CEPT certs require a full practical examination in order...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: People are bad at trust.... new article</title>
    <link>http://seclists.org/pen-test/2010/Jul/52</link>
    <description>&lt;p&gt;Posted by Pete Herzog on Jul 28&lt;/p&gt;Hi Saleh,&lt;br&gt;
prove...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when to fix , when to not to fix the vuln.</title>
    <link>http://seclists.org/pen-test/2010/Jul/51</link>
    <description>&lt;p&gt;Posted by Tony Turner on Jul 28&lt;/p&gt;You need to put the findings in context. It's not enough to say &amp;quot;Fix the&lt;br&gt;
have an...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when to fix , when to not to fix the vuln.</title>
    <link>http://seclists.org/pen-test/2010/Jul/50</link>
    <description>&lt;p&gt;Posted by Jason Ross on Jul 25&lt;/p&gt;In 2 of those 3 scenarios, this shouldn't be a question.&lt;br&gt;
In the third example (you...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when to fix , when to not to fix the vuln.</title>
    <link>http://seclists.org/pen-test/2010/Jul/49</link>
    <description>&lt;p&gt;Posted by Robert Portvliet on Jul 25&lt;/p&gt;If they gave a you a good report you should have the vulnerabilities&lt;br&gt;
severity of their...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: when to fix , when to not to fix the vuln.</title>
    <link>http://seclists.org/pen-test/2010/Jul/48</link>
    <description>&lt;p&gt;Posted by Todd Haverkos on Jul 25&lt;/p&gt;a bv &amp;lt;vbavbalist () gmail com&amp;gt; writes:&lt;br&gt;
In the report, hopefully there are CVE numbers as...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: How to tweak tools against targets that block ICMP</title>
    <link>http://seclists.org/pen-test/2010/Jul/47</link>
    <description>&lt;p&gt;Posted by Jacky Jack on Jul 24&lt;/p&gt;Hi Demetris Papapetrou&lt;br&gt;
Thanks....&lt;br&gt;</description>
  </item>
  <item>
    <title>People are bad at trust.... new article</title>
    <link>http://seclists.org/pen-test/2010/Jul/46</link>
    <description>&lt;p&gt;Posted by Pete Herzog on Jul 24&lt;/p&gt;&amp;quot;People are bad at trust....&lt;br&gt;
A new article called Essential Trust Analysis is now available...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: How to tweak tools against targets that block ICMP</title>
    <link>http://seclists.org/pen-test/2010/Jul/45</link>
    <description>&lt;p&gt;Posted by Robert Portvliet on Jul 24&lt;/p&gt;What is the behavior you are seeing? (Does it fail because it can't&lt;br&gt;
Also, take into consideration that although they are blocking...&lt;br&gt;</description>
  </item>
  <item>
    <title>when to fix , when to not to fix the vuln.</title>
    <link>http://seclists.org/pen-test/2010/Jul/44</link>
    <description>&lt;p&gt;Posted by a bv on Jul 24&lt;/p&gt;Hi,&lt;br&gt;
Prove to peers and potential employers without a doubt that you...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: demoing sslv2 vulns</title>
    <link>http://seclists.org/pen-test/2010/Jul/43</link>
    <description>&lt;p&gt;Posted by Richard Miles on Jul 24&lt;/p&gt;Hi chintan,&lt;br&gt;
and CEPT certs require a...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>The RISKS Forum</title>
    <link>http://seclists.org/#risks</link>
    <description>Peter G. Neumann moderates this regular digest of current events which demonstrate risks to the public in computers and related systems.  Security risks are often discussed.</description>
  <item>
    <title>Risks Digest 26.11</title>
    <link>http://seclists.org/risks/2010/q3/2</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Jul 21&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Wednesday 21 July 2010  Volume 26 : Issue 11&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.10</title>
    <link>http://seclists.org/risks/2010/q3/1</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Jul 10&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Saturday 10 July 2010  Volume 26 : Issue 10&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.09</title>
    <link>http://seclists.org/risks/2010/q3/0</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Jul 03&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Saturday 3 July 2010  Volume 26 : Issue 09&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.08</title>
    <link>http://seclists.org/risks/2010/q2/7</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Jun 10&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Thursday 10 June 2010  Volume 26 : Issue 08&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.07</title>
    <link>http://seclists.org/risks/2010/q2/6</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on May 29&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Saturday 29 May 2010  Volume 26 : Issue 07&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.06</title>
    <link>http://seclists.org/risks/2010/q2/5</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on May 08&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Saturday 8 May 2010  Volume 26 : Issue 06&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.05</title>
    <link>http://seclists.org/risks/2010/q2/4</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on May 04&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 4 April 2010  Volume 26 : Issue 05&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.04</title>
    <link>http://seclists.org/risks/2010/q2/3</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Apr 28&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Wednesday 28 April 2010  Volume 26 : Issue 04&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.03</title>
    <link>http://seclists.org/risks/2010/q2/2</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Apr 25&lt;/p&gt;ACM FORUM ON RISKS TO THE PUBLIC IN COMPUTERS AND RELATED SYSTEMS (comp.risks)&lt;br&gt;
  Contents:...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.02</title>
    <link>http://seclists.org/risks/2010/q2/1</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Apr 18&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Sunday 18 April 2010  Volume 26 : Issue 02&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
  <item>
    <title>Risks Digest 26.01</title>
    <link>http://seclists.org/risks/2010/q2/0</link>
    <description>&lt;p&gt;Posted by RISKS List Owner on Apr 08&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Thursday 8 April 2010  Volume 26 : Issue 01&lt;br&gt;
The current issue can be...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Security Basics</title>
    <link>http://seclists.org/#basics</link>
    <description>A high-volume list which permits people to ask &quot;stupid questions&quot; without being derided as &quot;n00bs&quot;.  I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.</description>
  <item>
    <title>[HITB-Ann] Reminder: HITB2010 Malaysia Call for Papers Closing August 9th</title>
    <link>http://seclists.org/basics/2010/Jul/190</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jul 29&lt;/p&gt;This is a reminder that the Call for Papers for Asia's largest network&lt;br&gt;
Venue: Crowne Plaza Mutiara Kuala Lumpur...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: People on Google Security blog don't understand cyber terrorism</title>
    <link>http://seclists.org/basics/2010/Jul/189</link>
    <description>&lt;p&gt;Posted by Curt Purdy on Jul 29&lt;/p&gt;Sometimes when I am full of myself, like when I am the last man&lt;br&gt;
When beyond-national corporations use clueless...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: make nmap not to scan fragile devices</title>
    <link>http://seclists.org/basics/2010/Jul/188</link>
    <description>&lt;p&gt;Posted by Shawn Merdinger on Jul 29&lt;/p&gt;Hi,&lt;br&gt;
it benefits your company and how your customers can tell if a site is...&lt;br&gt;</description>
  </item>
  <item>
    <title>Security Hand-on in Philly</title>
    <link>http://seclists.org/basics/2010/Jul/187</link>
    <description>&lt;p&gt;Posted by Far McKon on Jul 29&lt;/p&gt;Hey,&lt;br&gt;
Philly (NYC is 2 hours away,...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Beginner questions regarding PHP and MySQL Injection</title>
    <link>http://seclists.org/basics/2010/Jul/186</link>
    <description>&lt;p&gt;Posted by zero9zero on Jul 29&lt;/p&gt;Well sql injection doesn't have to be in a lnput validation.. Usually they inject it through the url too...&lt;br&gt;
powered by Sinyal...&lt;br&gt;</description>
  </item>
  <item>
    <title>make nmap not to scan fragile devices</title>
    <link>http://seclists.org/basics/2010/Jul/185</link>
    <description>&lt;p&gt;Posted by Jacky Jack on Jul 29&lt;/p&gt;Hi&lt;br&gt;
it benefits your company and how your customers can tell if a site is secure. You will...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Fw: North Korea conflict with US and South Korea could spark 	cyber war</title>
    <link>http://seclists.org/basics/2010/Jul/184</link>
    <description>&lt;p&gt;Posted by Chester Enright on Jul 29&lt;/p&gt;n3td3v...yet another example of the creation of a phony organization&lt;br&gt;
Please stop with...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Wikileaks, Afghanistan war logs leaked by hackers</title>
    <link>http://seclists.org/basics/2010/Jul/183</link>
    <description>&lt;p&gt;Posted by Florian Rommel on Jul 29&lt;/p&gt;blah blah blah... yes i would rather sit back in the times when all we heard was the propaganda of the war machine and &lt;br&gt;
worlds interest to know or &amp;quot;leaking&amp;quot; real information that is in direct contrast to lies published by the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Wikileaks, Afghanistan war logs leaked by hackers</title>
    <link>http://seclists.org/basics/2010/Jul/182</link>
    <description>&lt;p&gt;Posted by pryorda pryor on Jul 29&lt;/p&gt;I think we should have access to all the warlogs anyways.. We are&lt;br&gt;
it benefits your company and how your customers can tell if a site is secure. You will find out how to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: People on Google Security blog don't understand cyber terrorism</title>
    <link>http://seclists.org/basics/2010/Jul/181</link>
    <description>&lt;p&gt;Posted by Jan G.B. on Jul 29&lt;/p&gt;Let's see what you posted on twitter not so long ago..&lt;br&gt;
In this guide we examine the importance of...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Firefox Bypass Master password Vulnerability</title>
    <link>http://seclists.org/basics/2010/Jul/180</link>
    <description>&lt;p&gt;Posted by Andre Pawlowski on Jul 29&lt;/p&gt;I tested this for myself with Firefox 3.6.8 and Google Chrome&lt;br&gt;
Andre Pawlowski...&lt;br&gt;</description>
  </item>
  <item>
    <title>FW: People on Google Security blog don't understand cyber terrorism</title>
    <link>http://seclists.org/basics/2010/Jul/179</link>
    <description>&lt;p&gt;Posted by Murda on Jul 29&lt;/p&gt;Sorry, Tamer, I think you may have misunderstood this phrase:&lt;br&gt;
Incidentally(and coincidentally) my response would be the same...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: Pwnie Awards 2010 should be condemned by the security community</title>
    <link>http://seclists.org/basics/2010/Jul/178</link>
    <description>&lt;p&gt;Posted by Murda on Jul 29&lt;/p&gt;I will bring this up at the next security community meeting. I will also&lt;br&gt;
going to...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: People on Google Security blog don't understand cyber terrorism</title>
    <link>http://seclists.org/basics/2010/Jul/177</link>
    <description>&lt;p&gt;Posted by Chad Perrin on Jul 29&lt;/p&gt;While Mr. Gillett (who also responded to you) made very good points, and&lt;br&gt;
what...&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: Fw: North Korea conflict with US and South Korea could spark 	cyber war</title>
    <link>http://seclists.org/basics/2010/Jul/176</link>
    <description>&lt;p&gt;Posted by Murda on Jul 29&lt;/p&gt;I wonder if he can hear us trip-trapping on 'his' list. Just wait 'til my&lt;br&gt;
while there are a few trolls, andrew being...&lt;br&gt;</description>
  </item>
</channel>
</rss>
<rss version="2.0">
<channel>
<title>Security Jobs (jobs) Mailing List</title>
<link>http://seclists.org/#jobs</link>
<description>A popular list for advertising or finding jobs in the security field.  Employers post openings and job seekers post resumes (run by SecurityFocus).  For privacy reasons, only the current year is archived.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
<title>Vulnerability Development (vuln-dev) Mailing List</title>
<link>http://seclists.org/#vuln-dev</link>
<description>A moderated list for discussing possible security issues and devising exploits for them.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>VulnWatch</title>
    <link>http://seclists.org/#vulnwatch</link>
    <description>A non-discussion, non-patch, all-vulnerability annoucement list supported and run by a community of volunteer moderators distributed around the world.</description>
</channel>
</rss>
<rss version="2.0">
<channel>
    <title>Web App Security</title>
    <link>http://seclists.org/#webappsec</link>
    <description>Provides insights on the unique challenges which make web applications notoriously hard to secure, as well as attack methods including SQL injection, cross-site scripting (XSS), cross-site request forgery, and more.</description>
  <item>
    <title>[HITB-Ann] Reminder: HITB2010 Malaysia Call for Papers Closing August 9th</title>
    <link>http://seclists.org/webappsec/2010/q3/28</link>
    <description>&lt;p&gt;Posted by Hafez Kamal on Jul 29&lt;/p&gt;This is a reminder that the Call for Papers for Asia's largest network&lt;br&gt;
Venue: Crowne Plaza Mutiara Kuala Lumpur...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Fwd: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/27</link>
    <description>&lt;p&gt;Posted by Robert Hajime Lanning on Jul 28&lt;/p&gt;You can hash the form data, then encrypt the hash with a shared transaction&lt;br&gt;
SSL/TLS and second via the internal signing.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Fwd: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/26</link>
    <description>&lt;p&gt;Posted by richardhigh on Jul 27&lt;/p&gt;Saleh,&lt;br&gt;
Request...&lt;br&gt;</description>
  </item>
  <item>
    <title>Fwd: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/25</link>
    <description>&lt;p&gt;Posted by Saleh on Jul 26&lt;/p&gt;---------- Forwarded message ----------&lt;br&gt;
Using CRC, there is absolutely...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/24</link>
    <description>&lt;p&gt;Posted by Peter M. Jansson on Jul 21&lt;/p&gt;So section 3.7.5 if the DISA Application Security and Development STIG V3R1 seems to be the requirement in question, &lt;br&gt;
(Actually, I worry a bit more about potential bugs in the...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/23</link>
    <description>&lt;p&gt;Posted by Robert Hajime Lanning on Jul 21&lt;/p&gt;Well, outside of an AES128-SHA1 SSL connection, there really isn't much that can&lt;br&gt;
client platform?&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/22</link>
    <description>&lt;p&gt;Posted by Richard Moore on Jul 21&lt;/p&gt;If the intention is to protect against malicious changes (as the&lt;br&gt;
rich.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/21</link>
    <description>&lt;p&gt;Posted by Martin Tartarelli on Jul 21&lt;/p&gt;Hi Richard,&lt;br&gt;
2010/7/20 Nikhil Wagholikar &amp;lt;visitnikhil () gmail com&amp;gt;:&lt;br&gt;</description>
  </item>
  <item>
    <title>RE: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/20</link>
    <description>&lt;p&gt;Posted by Jacqueline.Primrose on Jul 21&lt;/p&gt;Have you checked out GlobalScape EFT?&lt;br&gt;
Does anyone know of any tools out there that can be used to ensure the integrity of data while in transit from a web...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/19</link>
    <description>&lt;p&gt;Posted by Saleh on Jul 21&lt;/p&gt;According to one of my friends (voulnet () gmail com)&lt;br&gt;
HTTPS will do good =D&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: mysql selecting into outfile in an insert</title>
    <link>http://seclists.org/webappsec/2010/q3/18</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jul 21&lt;/p&gt;As I said, on my box I'm root, I've all the privs available and the&lt;br&gt;
--------------------------------------&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/17</link>
    <description>&lt;p&gt;Posted by Nikhil Wagholikar on Jul 20&lt;/p&gt;Hi Richard,&lt;br&gt;
It's Finally Here - The Cenzic...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: mysql selecting into outfile in an insert</title>
    <link>http://seclists.org/webappsec/2010/q3/16</link>
    <description>&lt;p&gt;Posted by Camilo Uribe on Jul 20&lt;/p&gt;Look for the file privilege:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;...&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: Hash for data in transit</title>
    <link>http://seclists.org/webappsec/2010/q3/15</link>
    <description>&lt;p&gt;Posted by Robert Hajime Lanning on Jul 20&lt;/p&gt;https will between the browser and the webserver.&lt;br&gt;</description>
  </item>
  <item>
    <title>Re: mysql selecting into outfile in an insert</title>
    <link>http://seclists.org/webappsec/2010/q3/14</link>
    <description>&lt;p&gt;Posted by Robin Wood on Jul 20&lt;/p&gt;Not sure on the vulnerable app I'm testing but in my lab I'm on as&lt;br&gt;
--------------------------------------&lt;br&gt;</description>
  </item>
</channel>
</rss>
</BODY>
