Open Source Security

Discussion of security flaws, concepts, and practices in the Open Source community

[0x1] RE: libupnp buffer overflows

[0x2] Re: libupnp buffer overflows

[0x3] Re: CVE id request: devotee (debian vote engine) cryptographically weak random numbers permit discovery of secret ballot submissions

[0x4] CVE id request: devotee (debian vote engine) cryptographically weak random numbers permit discovery of secret ballot submissions

[0x5] CVE-2012-2762 Serendipity include/functions_trackbacks.inc.php SQL injection

[0x6] Re: CVE Request -- kernel: incomplete fix for CVE-2011-4131

[0x7] Re: CVE Request -- Tornado (python-tornado): Tornado v2.2.1 tornado.web.RequestHandler.set_header() fix to prevent header injection

[0x8] Re: CVE Request -- kernel: mm: read_pmd_atomic: 32bit PAE pmd walk vs pmd_populate SMP race condition

[0x9] CVE-2012-2759 WordPress Login With Ajax plugin re-enlistment XSS

[0xA] Re: sudo: IP addresses in sudoers with netmask may match additional hosts (CVE-2012-2337)

Dana Epp's ramblings at the Sanctuary

Life, the Universe and everything Security

[0x1] Announcing Elevation of Privilege: The Threat Modeling Game

[0x2] Reflecting on our Windows 7 birthday party

[0x3] Time to party! Windows 7 is here!

[0x4] RunAs Radio podcasts you might want to listen to

[0x5] Coding Tip: Why you should always use well known SIDs over usernames for security groups

[0x6] Major Windows 7 gotcha you should know about that may block you from upgrading

[0x7] Microsoft SDL bans mempcy()... next it will be zeros!!!!

[0x8] Using TS RemoteApp as an attack vector

[0x9] Is Twittering safe?

[0xA] Come have Coffee and Code in Vancouver with me and Microsoft tomorrow

Ed Smiley's Blog

IT and Infosec Security Ramblings

[0x1] Bookmarks for October 11th through October 13th

[0x2] Bookmarks for October 11th from 00:00 to 20:00

[0x3] Bookmarks for October 9th through October 10th

[0x4] Bookmarks for October 8th through October 9th

[0x5] Bookmarks for October 7th through October 8th

[0x6] Bookmarks for October 6th through October 7th

[0x7] Bookmarks for October 6th from 00:00 to 06:01

[0x8] Bookmarks for October 5th from 17:00 to 23:01

[0x9] Bookmarks for October 5th from 10:00 to 16:00

[0xA] Bookmarks for October 5th from 03:00 to 09:00

Twitter / ToolsWatch

Twitter updates from Security Tools Watch / ToolsWatch.

[0x1] ToolsWatch: RT @ziplock581: Brad "theNurse" Smith had a setback this morning, has been moved from nursing home back into VA Hospital http://t.co/KCQ ...

[0x2] ToolsWatch: RT @gustavorobertux: The call for papers for H2HC 9th edition is now open. Sao Paulo, Brazil, from 18 to 23 October 2012. #h2hc

[0x3] ToolsWatch: RT @eEye: Hey #netsec! Download our free #vulnerability assessment agent for #Android devices from the Google Play Store http://t.co/tqR ...

[0x4] ToolsWatch: RT @ekoparty: Are you aware that 2010 and 2011 top webhacking techniques was presented at the ekoparty?

[0x5] ToolsWatch: @Rajae87 NETpeas signifie NETwork Pentest As A Service. Par contre, on voit que votre mindset frise le ridicule !

[0x6] ToolsWatch: RT @maxisoler: #PHDays: Positive Hack Days May 30-31 @ Moscow, Russia http://t.co/mhzJqd50

[0x7] ToolsWatch: RT @hnfirehose: 100 examples of C++ bugs: http://t.co/Ai0vPQUi

[0x8] ToolsWatch: RT @maxisoler: #ToolsWatch - @ClubHack Magazine Issue #28, May 2012 Released http://t.co/LxJHEBek

[0x9] ToolsWatch: RT @zetzero: DAILY NOMADS is out! http://t.co/Ua9CdMNy ▸ Top stories today via @omarseashepherd @toolswatch @loloster @marcj6ii

[0xA] ToolsWatch: Turning your Chrome to a Pentest Machine http://t.co/irfGw6Jh

Reformed(?) Hacker

[0x1] Simple way to do a headless install of Sun/Oracle Java6 on ubuntu

[0x2] NoSQL in a Sharded MySQL Context

[0x3] P != NP

[0x4] Lessons learned from a vendor

[0x5] Wiki tab sweep

[0x6] Graph processing

[0x7] Tab Sweep: Search

[0x8] Identifier Tab Sweep

[0x9] When two people know less than one

[0xA] Typical scaling progression for a large website

Rational Survivability

PLEASE NOTE: I HAVE PERMANENTLY MOVED MY BLOG TO http://www.rationalsurvivability.com/blog <-- All these posts/comments have been moved there and all new posts since May 2009 appear there.

[0x1] IMPORTANT REMINDER: My Blog and RSS Feed Have Moved To http://www.rationalsurvivability.com/blog

[0x2] IMPORTANT REMINDER: My Blog and RSS Feed Have Moved

[0x3] IMPORTANT: Moving My Blog & RSS Feed

[0x4] BeanSec! Wednesday, March 18, 2009 - 6PM to ?

[0x5] How To Be PCI Compliant in the Cloud...

[0x6] On the Overcast Podcast with Geva Perry and James Urquhart

[0x7] More On Clouds & Botnets: MeatClouds, CloudFlux, LeapFrog, EDoS and More!

[0x8] Source Boston - Video Interviews of Security Rockstars...

[0x9] Oh Noes: We Can't Monitor/Protect Against Intra-VM Traffic!

[0xA] Sun vs. Cisco? I'm Getting My Popcorn...

EduGeek.net

EduGeek.net - The I.T. professionals' life line

[0x1] App Store Setup for Multiple Lion iMacs

[0x2] BCC IT Operations Manager Grade 4 JD

[0x3] [For Sale] For Sale - Canon EOS 600D

[0x4] Secret Teacher Letter

[0x5] [HAP+][v8] - Developer Reference

[0x6] How Yahoo Killed Flickr

[0x7] Anyone fitted a remote central locking kit to a car?

[0x8] Million Short - Remove the top million websites from Google's search results

[0x9] [Android] Voltage Too High message

[0xA] [For Sale] 2 x Proliant Servers

Oracle Bloggers

Welcome to Oracle Blogs

Welcome to the Oracle blogging community!

.tagscompact{ display: none;}

[0x1] ArchBeat Link-o-Rama for 2012-05-18

[0x2] New Smart Card Features for Oracle Desktop Virtualization

[0x3] OTN Architect Day Presentation Slides

[0x4] SecuritEE in the Cloud

[0x5] Best Practices for Database Privileged User Access Controls

[0x6] St. Joseph’s Security and Compliance Success Story: Implementing Identity Management in Healthcare

[0x7] ArchBeat Link-o-Rama Top 20 for May 6-12, 2012

[0x8] Java EE 7 Permission Declarations

[0x9] ArchBeat Link-o-Rama for 2012-05-09

[0xA] Oracle Desktop Virtualization Security Solution at DISA Mission Partner Conference 2012

Free and Useful Online Resources for Designers and Developers

Free and useful online resources for designer and developers

[0x1] 7 Typography Tools Every Designer Should Know

[0x2] 40 (More) Creative Negative Space Logo Designs

[0x3] 20 Useful PHP Tutorials For Beginners

[0x4] 16 Useful Free Handwritten Fonts For Your Designs

[0x5] 50 Essential And Free Web Template PSD Layouts

[0x6] 45 Examples Of Websites Designed With HTML5

[0x7] 25 (More) Free And Useful Photoshop Actions

[0x8] Congratulations To The Winners Of DesignModo’s Impressionist UI Pack

[0x9] 50 Photoshop And Illustrator Tutorials For Creating Text Effect

[0xA] 40+ Beautiful And Creative Letterpress Designs

Security Intelligence and Big Data | raffy.ch - blog

Big data analytics and visualization

[0x1] Advanced Network Graph Visualization with AfterGlow

[0x2] Visualizing Packet Captures For Fun and Profit

[0x3] Big Data Security Intelligence – nothing to see here – move along

[0x4] The Steps To a Mature Visual Analytics Practice

[0x5] Cyber Security Visualization – Grand Challenge

[0x6] Learning About Log Analysis and Visualization in Taipei

[0x7] Logging Guidelines Enable Actions

[0x8] Why a Cloud Logging Standard Doesn’t Make Any Sense

[0x9] Mid January Roundup

[0xA] links for 2011-01-07

Internet Security

Internet security news and updates

[0x1] Android Apps found to be Distributing Malware

[0x2] eIQnetworks Webinar on How to Address Advanced Persistent Threats without Increasing Budgets or Personnel

[0x3] Hacking Group hit US security firm Stratfor

[0x4] Origins of Computer Viruses and Protecting your PC from them

[0x5] Social Networking danger signs to your Internet Security this Holiday Season

[0x6] iPhone apps vulnerability discovered, researcher faces 1 year ban

[0x7] Show Password Bookmarklet

[0x8] Best Internet Security Software to tackle online security threats

[0x9] How to secure your network from Malware

[0xA] How helpful are Internet Security software Reviews

Twitter / RuggedSoftware

Twitter updates from Rugged / RuggedSoftware.

[0x1] RuggedSoftware: RT @SpiderLabs: We're hiring! Here is a list of the current openings. AppSec, PenTest, Research, and Interns. http://t.co/JqyEqWM6 #infosec

[0x2] RuggedSoftware: RT @jeffsussna: @joshcorman @realgenekim Here's another one on #lean #devops #servicedesign "Beyond DevOps: User-Centered IT" http://t.c ...

[0x3] RuggedSoftware: RT @jeffsussna: Among other multi-read-worthy things this awesome preso by @realgenekim & @joshcorman discusses #devops #techdebt http:/ ...

[0x4] RuggedSoftware: RT @brennantom: Did you enjoy #SourceBos and the @SpiderLabs @Trustwave talks? -- Join the crew (71) openings globally - http://t.co/1EP ...

[0x5] RuggedSoftware: RT @wikidsystems: Blog spam: Accidental Rugged Devops http://t.co/uxrhk0G3 cc @RealGeneKim @joshcorman <- Glad you see it!

[0x6] RuggedSoftware: RT @WeldPond: Dan Geer "Application Security Matters", keynote address, OWASP AppSecDC http://t.co/YYpjDFoo < go read this now

[0x7] RuggedSoftware: RT @joshcorman: Excited to give #Rugged #DevOps talk @ #AppSecDC Wed. Great Line-Up starts w/ Dan Geer http://t.co/Bpf5oZOB #RuggedSoftware

[0x8] RuggedSoftware: RT @RuggedDevOps: DevOps Days Austin Live Streaming http://t.co/0vSLl219

[0x9] RuggedSoftware: RT @benoitnewton: @joshcorman @wickett Part 2 just went live - https://t.co/jbtcN6vo Rugged #DevOps

[0xA] RuggedSoftware: RT @wickett: Today at the hackathon, we are launching Gauntlet, a tool for Rugged Dev. Get a sneak peak at the slides > http://t.co/ ...

PHP Vulnerabilities in World Laboratory of Bugtraq 2 (CVEMAP)

PHP Vulnerabilities - CXSecurity WLB2CVEMAP Database

[0x1] CVE-2012-2336: sapi/cgi/cgi_main.c in PHP before 5.3.13...

[0x2] CVE-2012-2335: php-wrapper.fcgi does not properly handl...

[0x3] CVE-2012-2329: Buffer overflow in the apache_request_he...

[0x4] CVE-2012-2311: sapi/cgi/cgi_main.c in PHP before 5.3.13...

[0x5] CVE-2012-1823: sapi/cgi/cgi_main.c in PHP before 5.3.12...

[0x6] CVE-2012-0789: Memory leak in the timezone functionalit...

[0x7] CVE-2012-0788: The PDORow implementation in PHP before ...

[0x8] CVE-2012-0831: PHP before 5.3.10 does not properly perf...

[0x9] CVE-2012-0830: The php_register_variable_ex function in...

[0xA] CVE-2012-0781: The tidy_diagnose function in PHP 5.3.8 ...

CSOONLINE.com - Compliance

[0x1] Report: PHI security is MIA

[0x2] Is your definition of security holding you back?

[0x3] How the Red Cross found its ID management groove

[0x4] Hey, CSOs: Suck it up and accept budget cuts

[0x5] Legal quicksand: Shrink-wrap and click-wrap agreements

[0x6] Mobile payments and PCI DSS compliance: Some, but not much, clarity (yet)

[0x7] They're baaack! National data breach notification bills resurface

[0x8] 4 tips for using Facebook legally to conduct background checks (includes video)

[0x9] How ALPS Advisors found its log management groove

[0xA] Security in 3D

Security forum - dslreports.com community

Security forum current topics

[0x1] MarkMonitor accumulates Internet Power - to what end?

[0x2] Oldest security post by an active user

[0x3] Facebook Hit with Lawsuit Alleging Privacy Wrongs

[0x4] Twitter users given legal warning in Britain

[0x5] Router with access time limit

[0x6] Video: Angry Birds Space Trojan & Drive-by Android

[0x7] This Hard Drive Will Self Destruct in...

[0x8] Best Buy's surprisingly insecure approach to new PC setup

[0x9] Kaspersky defends data retention, secretive breaches

[0xA] Update: Estimated 300,000 DNS Changer-infected computers

Microsoft Sec Notification

Beware that MS often uses these security bulletins as marketing propaganda to downplay serious vulnerabilities in their products—note how most have a prominent and often-misleading "mitigating factors" section.

[0x1] Microsoft Security Bulletin Minor Revisions

[0x2] Microsoft Security Bulletin Re-Releases

[0x3] Microsoft Security Bulletin Minor Revisions

[0x4] Microsoft Security Bulletin Minor Revisions

[0x5] Microsoft Security Bulletin Summary for May 2012

[0x6] Microsoft Security Bulletin Advance Notification for May 2012

[0x7] Microsoft Security Bulletin Re-Releases

[0x8] Microsoft Security Bulletin Minor Revisions

[0x9] Microsoft Security Bulletin Minor Revisions

[0xA] Microsoft Security Bulletin Minor Revisions

Nibble Security

"I've forgotten your password, could you please remind me?"

[0x1] "No More Free Bugs" Initiatives

[0x2] On exploits and assessing security

[0x3] MS Access SQL Injection Cheat Sheet Reloaded

[0x4] TYPO3-SA-2010-020, TYPO3-SA-2010-022 explained

[0x5] Unspecified vulnerabilities

[0x6] VASTO has a new home!

[0x7] Announcing VASTO 0.2

[0x8] Announcing VASTO beta

[0x9] Modern magicians

[0xA] [Confidence0902] The Glass Cage - Virtualization Security

CSOONLINE.com - Application Security

[0x1] Kaspersky denies it's working with Apple on Mac security

[0x2] Secure360: The failure of risk management

[0x3] BeyondTrust eyes app security with eEye acquisition

[0x4] APT attackers are increasingly using booby-trapped RTF documents, experts say

[0x5] CSOs warned of serious cyber-espionage attack

[0x6] PHP patches actively exploited CGI vulnerability

[0x7] Microsoft security patches include fixes for Word, Office, Windows

[0x8] Windows 8 privacy worry overblown, says Microsoft analyst

[0x9] Red Sky Alliance: An experiment in information sharing

[0xA] PHP working on new patch for critical vulnerability after initial one failed

Twitter / unitedsummit

Twitter updates from UNITEDSecuritySummit / unitedsummit.

[0x1] unitedsummit: Early bird registration is open for the UNITED Security Summit: http://t.co/gOmYRzqR #UNITEDsummit

[0x2] unitedsummit: We've also opened up the sponsorship opportunities for the event: http://t.co/fPJvY37y #UNITEDsummit

[0x3] unitedsummit: Call for papers for the UNITED Security Summit is now open: http://t.co/CmlTtVjK

[0x4] unitedsummit: RT @CarolJMeyers:  TRUTH, LIES & DECISIONS: Moving forward in an insecure world. Register now for the #UNITEDsummit: http://t.co/x ...

[0x5] unitedsummit: RT @tsemchenko11:  Don’t miss out on the Early Bird Discount for the UNITED Security Summit: http://t.co/SEsfULb3 #UNITEDsummit

[0x6] unitedsummit: RT @PatrickCH: Which critical issues facing the information security industry do you think UNITED should address? http://t.co/xKXwIEUb ...

[0x7] unitedsummit: Part 8 of our series on getting the most from CSV exports in Nexpose is out: http://t.co/jJpI0yQD

[0x8] unitedsummit: Who is excited for #Secure360? we are! Catch @hdmoore presenting tomorrow afternoon and stop by booth 2 for swag!

[0x9] unitedsummit: RT @mvarmazis: Got a compelling #infosec story or viewpoint to share? The CALL FOR PAPERS for the #UNITEDsummit is now open: http://t.co ...

[0xA] unitedsummit: Got a compelling infosec story or viewpoint to share? The CALL FOR PAPERS for the #UNITEDsummit is now open: http://t.co/oxPMzGDk

Twitter / steaIth

Twitter updates from Sebastian Krahmer / steaIth.

[0x1] steaIth: ach na denn sind wa ja schonmal zu dritt :p

[0x2] steaIth: und wer kommt jetzt alles so zur BerlinSides?

[0x3] steaIth: Ich versteh garnicht wie man sich so über Format-String bugs aufregen ka%n%n. :p

[0x4] steaIth: Discovered a critical hole in my socks. No patch available yet. Already reported upstream.

[0x5] steaIth: Einmal Brille gesagt, Kontaktlinsenversand followed. Kondom.

[0x6] steaIth: WE ist wieder Nerd Party. Mal sehn ob sie mich diesmal reinlassen. Zur Not muss ich nem "echten" Nerd die Brille klaun.

[0x7] steaIth: sha256sum f8583142f984a89f6604ecf978ac1d4dc4730444a3242ae5a7dd603b9267191a

[0x8] steaIth: And now, Beatsteaks for the win. Wir rocken jetzt mal die Kantine.

[0x9] steaIth: would looking at tizen mobile OS pay? is jailbreak needed there at all?

[0xA] steaIth: @wishinet dunno. I didnt investigate deeply.

Enterprise Storage Forum News

Covering security, storage, and networking for the enterprise IT professional

[0x1] Solid State Drives Get Faster with TRIM

[0x2] Solid State Drives in Enterprise Applications

[0x3] Oracle to Keep Sun's Data Storage, Tape Businesses

[0x4] LTO-5 Breathes New Life into Tape Storage

[0x5] NetApp Deepens Ties with Cisco, VMware

[0x6] EMC Reports Strong Data Storage, Deduplication Sales

[0x7] Symantec Adds Deduplication to Backup Software

[0x8] EMC Doubles Clariion, Celerra Density with 2TB SATA Drives

[0x9] RAID Storage Levels Explained

[0xA] NetApp, Cisco and VMware Deal May Be Coming

InfoSecPodcast.com » Security Tools

[0x1] MIT Lincoln Lab Network Security Software

[0x2] Record IM video on the network?

[0x3] RFP for PenTesting

[0x4] Declassified window film stops wireless / cell signals

[0x5] List of Malware Analysis tool from SANS

[0x6] Malware Analyzing Sandbox

[0x7] Free Windows Honeypot from NetVigilance

[0x8] Ajax based port scanner

[0x9] Web based VMX file creator

[0xA] Bootable Linux security distros

chandanlog(3C)

Chandan's blog or sayings of an hearer

[0x1] CVSS Worksheet

[0x2] Cross Domain Blog Migration

[0x3] Everything you need to know about cryptography in 1 hour

[0x4] Fast Forward in Time: Flower Bloom

[0x5] Desktop OS for Personal Computing

[0x6] Netbooks and the end of the Laptop Decade

[0x7] Home Theater Architecture

[0x8] Doing the same thing again and expecting different results

[0x9] To prevent auto-reply e-mails

[0xA] Secure your Wi-Fi networks now!

Packetstan

A blog about packets, tools, and bacon

[0x1] Snort Fortification Against Evasions

[0x2] What I Learned At Camp

[0x3] Sorting Packet Captures with Scapy

[0x4] Crafting Overlapping Fragments ….. Finally!

[0x5] Crafting Overlapping Fragments ..... Eventually (Part 2)

[0x6] Crafting Overlapping Fragments ..... Eventually

[0x7] NBNS Spoofing on your way to World Domination

[0x8] Extracting AP names from Packet Captures

[0x9] Exploiting Networks with Loki on Backtrack 4 R2

[0xA] Scapy, and Random Acts of Packety Violence

Free Information Technology Magazines and Downloads from bestsecuritytips.tradepub.com

Free publications about information technology and digital communication.

[0x1] Hardware vs. Software Deduplication: Finding What's Right for You

[0x2] Enterprise Strategy Group: The Next Wave of Data Deduplication

[0x3] Advances in Deduplication Help Tame Big Data

[0x4] The State of Master Data Management, 2012: Building the Foundation for a Better Enterprise

[0x5] B2B Collaboration: No Longer Optional

[0x6] Managing the TCO of BI: The Path to ROI is Paved with Adoption

[0x7] Cloud Financial Management: Cost-Effective Implementation of Budgeting and Forecasting Measures

[0x8] To ERP or Not to ERP for SMBs: What Can ERP Do For Me?

[0x9] Business Intelligence - A Guide for Midsize Companies

[0xA] Think Your Organization is Too Small for ERP? Think Again

Foro de elhacker.net - Noticias

Información en vivo desde Foro de elhacker.net

[0x1] “Sin ‘hackers’ no habría seguridad”

[0x2] Nero Burning ROM. Clasicos del software (XII)

[0x3] Cómo eliminar el virus de la SGAE

[0x4] Internet mantiene con vida al correo tradicional y le obliga a renovarse

[0x5] Desarrollan un sistema de captación de energía solar desde el espacio

[0x6] Orange lanza ADSL de 20 Mb sin llamadas desde 9,95 euros al mes

[0x7] Los Mossos retirarán la web para identificar sospechosos

[0x8] Gmail actualiza los datos de los contactos e introduce mejoras en su correo

[0x9] La UE impedirá que Internet Explorer sea el único navegador que funcione en ...

[0xA] Google Chrome 20.0.1132.11 Dev con mejoras en seguridad y estabilidad

Splunk Blogs

[0x1] Splunk = Customer Satisfaction

[0x2] Analytics Staffing for Big Data: A Perspective

[0x3] Dallas Splunk Users Group – June 12th @ 6:00p CST

[0x4] #SplunkGovt Twitter Chat: A Sneak Peak at What We’ll Explore at SplunkLIVE! Washington, D.C.

[0x5] Doing More With What You Have

[0x6] That happened: episode 9

[0x7] Quantifying the Benefits of Splunk with SSDs

[0x8] Identifying Phishing Sites in Your Events

[0x9] I invested in a shiny new tool/technology…

[0xA] That happened: episode 8

Linux Techbits and hackery

A Simple blog debating good linux hacks, security and programming and general sysadministration..

[0x1] Woah how long before a post?

[0x2] Argh blow up parts..

[0x3] Happy Sysadmin appreciation day

[0x4] choosing a web language...

[0x5] Epic fail ftw..

[0x6] found a bug?

[0x7] shellcodes more shellcode stuff.

[0x8] upcoming blog post..

[0x9] amd64/x86_64 shellcode..

[0xA] grabbing a table from a mysql backup...

Why Joseph

InfoSec Thoughts Ideas and Practice

[0x1] Busting an Attacker: article 201202

[0x2] My Errata for C Programming in easy steps 3rd edition: article 201201

[0x3] BASH WHILE Loop: article 201107

[0x4] Breakdown of C Format Parameters: article 201106

[0x5] Notes on Memory Segmentation: article 201105

[0x6] Incident Repsonse; When To Call the Posse: article 201104

[0x7] Honeynet Forensics Challenge 7 winner: article 201103

[0x8] PCRE CHEAT SHEET: article 201102

[0x9] Malicious Domain Check: article 201101

[0xA] iPHONE Apps for Information Security: article 201003

CERT/CC Blog

[0x1] CERT Basic Fuzzing Framework 2.5 Released

[0x2] CERT Linux Triage Tools 1.0 Released

[0x3] CERT Failure Observation Engine 1.0 Released

[0x4] Vulnerability Severity Using CVSS

[0x5] CNAME flux

[0x6] Challenges in Network Monitoring above the Enterprise

[0x7] Signed Java and Cisco AnyConnect

[0x8] Effectiveness of Microsoft Office File Validation

[0x9] A Security Comparison: Microsoft Office vs. Oracle Openoffice

[0xA] Announcing the CERT Basic Fuzzing Framework 2.0

Liquidmatrix Security Digest

Bringing Fire To The Village: Your Source For Computer, Network & Information Security News

[0x1] #FreeByron is no more, long live #ByronIsFree (UPDATED) (UPDATED AGAIN)

[0x2] VMWare Vulnerability Security Advisory

[0x3] Stupid Human Tricks: Security Job Interviews

[0x4] You Lose America. CISPA Passes 248-168

[0x5] Onion Browser For iOS Private Browsing

[0x6] EU Parliament To Turn Over Passenger Data To US

[0x7] Iran Says It’s Building A Drone Aircraft Copy

[0x8] Aviva Fires 1,300 Via Email…By Accident

[0x9] Mercedes Adds Remote Updates

[0xA] Link: Apple holds the master decryption key when it comes to iCloud security, privacy

Twitter / Panda_Security

Twitter updates from Panda Security / Panda_Security.

[0x1] Panda_Security: @rlinux Obrigado!!

[0x2] Panda_Security: Do you want to get a free 3-month Panda Internet Security 2012? Just click on the link and download the promo: https://t.co/UKDeeVPK

[0x3] Panda_Security: Stop feeling like a fish out of water! Today at #LaPiazza #PandaSecurity LOL XXX http://t.co/0in2m1lX

[0x4] Panda_Security: Happy Internet Day! Here you have some free tools to optimize the security of your PC. http://t.co/04qw3gej

[0x5] Panda_Security: @OK_Kat22 Gracias por informarnos y tu feedback.

[0x6] Panda_Security: @OK_Kat22 Por favor, síguenos para que podamos enviarte un directo. Necesitaríamos tu número de cliente para ver el problema. Gracias!

[0x7] Panda_Security: @OK_Kat22 Desactiva el firewall de nuestro producto para entrar en Internet. Ponemos copia a @PandaTechSup para que te ayuden. Gracias!

[0x8] Panda_Security: 10 Things You Should Know About Facebook's New Privacy Policy http://t.co/jL3xT5qQ via @pcmag

[0x9] Panda_Security: @OK_Kat22 Nos puedes comentar qué te ha pasado para poder ayudarte? Gracias. Nos puedes escribir a communication @ http://t.co/BMwAFELm

[0xA] Panda_Security: New Beta Version of Panda Global Protection 2013 and Beta Tester Contest -->http://t.co/b95ArYsx

pentestmonkey

Taking the monkey work out of pentesting

[0x1] mimikatz: Tool To Recover Cleartext Passwords From Lsass

[0x2] windows-privesc-check

[0x3] Finding IP Addresses of Other Network Interfaces on Linux

[0x4] gateway-finder

[0x5] The Science of Safely Finding an Unused IP Address

[0x6] timing-attack-checker

[0x7] Exposing only part of C: over Terminal Services

[0x8] Post-Exploitation in Windows: From Local Admin To Domain Admin (efficiently)

[0x9] Reverse Shell Cheat Sheet

[0xA] “Hackers for Charity” Needs You

An Expert's Guide to Database Solutions

Experienced DBA, Strategist, Architect, and Performance Expert James Koopmann provides information, guidance, technical savvy, and solutions for your database needs.

[0x1] 3 Steps to Configuring Oracle for Automatic Database Monitoring

[0x2] Monitoring an Oracle Database Automatically

[0x3] Methods of Performance Tuning

[0x4] Getting Ready to Tune Your Oracle Database

[0x5] The PL/SQL Developer Job Interview; Query Tactics

[0x6] How Do You Address Security for Your Next PL/SQL Developer Job Interview - User Defined Encryption

[0x7] How Do You Address Security for Your Next PL/SQL Developer Job Interview - Oracle's Transparent Encryption

[0x8] Know How to Answer Questions on Performance for Your Next PL/SQL Developer Job Interview

[0x9] The PL/SQL Developer Job Interview; Procedures, Functions, and Packages

[0xA] Passing the Oracle Database SQL Test for Your Next PL/SQL Job Interview

Leetupload News

The latest news for Leetupload.com's largest hacker's database!

[0x1] Mind the Gap!

[0x2] No Root for You -- ISACA

[0x3] Good.Times.Search.Engine -- Hack a Day

[0x4] New Tutorial - How the Microprocessor Works

[0x5] Famous - Copper Heatsink/Wine Chiller Idea on engadget and Hack a Day!

[0x6] Copper Heatsink on the Rocks Mod Finished

[0x7] Another Tutorial - Technical Practical Jokes

[0x8] New Tutorial - Campus WarWalking

[0x9] IRC Up For Use, and IRC Java Client is Here to Stay!

[0xA] VIRII AND EXPLOIT DATABASE IS UP!

The MITRE Digest

The MITRE Digest is an online magazine that showcases our latest work in aviation systems, defense and intelligence, federal sector modernization, homeland security, and cutting–edge research. We cover timely topics that affect our sponsors and the national interest.

[0x1] In Search of the Green Glow: Using Fluorescence to Detect Deadly Viruses

[0x2] NextGen Hub Enables More Frequent, Secure Multi–Agency Experiments and Simulations

[0x3] Handheld Sensor Could Put Biothreat Detection Capability in First Responders' Hands

[0x4] Human Odor: Sniffing Out Identity and Deception

[0x5] Resilient Cyber Architectures Keep Government IT Operations Mission–Ready

[0x6] MITRE Experimentation Lab Gives Wings to Aviation Technology Research

[0x7] Smart Thinking: Making Mobile Communications Work for the Warfighter

[0x8] Glycoprotein Films: A Sweet Defense Against Infectious Disease

[0x9] Airborne Network Gateway Keeps Warfighters on the Same Wavelength

[0xA] hData: Electronic Health Records Go Mobile for Better Patient Care

Tactical Web Application Security

Tac-ti-cal: of or relating to combat tactics: of or occurring at the battlefront <a tactical defense>

[0x1] Mass Joomla Component LFI Attacks Identified

[0x2] What Web Application Security Monitoring Can Learn From Casino Surveillance

[0x3] WASC WHID Semi-Annual Report for 2010

[0x4] Moving to the Trustwave SpiderLabs Research Team

[0x5] Spammers using Twitter's Update Status API

[0x6] Back to the Future - Economies of Scale Techniques from 2008 Still in Use Today

[0x7] Zone-H Defacement Statistics Report for Q1 2010

[0x8] BSIMM2 and WAFs

[0x9] Botnet Herders Targeting Web Servers

[0xA] Apache.org Compromised Through XSS

Securityvulns exploits channel

Securityvulns exploits newsline

[0x1] iptoolsex.pl

[0x2] p_cve-2011-4362.c

[0x3] enumerator_asterisk_nat_peers.rb

[0x4] https://twitter.com/#!/w3bd3vil/status/148454992989261824

[0x5] 7350roaringbeastv3.zip

[0x6] oracleocepoc.php

[0x7] zftpex.py

[0x8] knftpd_exploit.py

[0x9] bwocxrun_1.zip

[0xA] killapache.pl

Jeremiah Grossman

A page to show up #1 on Google when searching for "Jeremiah" (Currently #4).
Only the prophet and TV show left!
I have the edge, TV show is cancelled and the prophet isn't generating any new content.

The prophet, TV show, and that pesky Owyang guy going down!
A page to show up #1 on Google when searching for "Jeremiah Grossman", and it FINALLY has!

[0x1] Written Speech: TEDxMaui -- Hack Yourself First

[0x2] TEDxMaui -- Hack Yourself First

[0x3] Terrified

[0x4] How I got my start -- in Brazilian Jiu-Jitsu

[0x5] Web security content moving to new WhiteHat Security corp blog

[0x6] Sentinel SecurityCheck

[0x7] 11th WhiteHat Website Security Statistic Report: Windows of Exposure

[0x8] Robert “RSnake” Hansen, age 34, has passed away, on Facebook

[0x9] Top Ten Web Hacking Techniques of 2011

[0xA] BINGO! for Application Security

CSOONLINE.com - Disaster Recovery

[0x1] How to start a business continuity program

[0x2] Severe space weather: How big a threat?

[0x3] Does my company need business continuity software?

[0x4] Cloud and disaster recovery: Load-balanced data centers are not a perfect solution

[0x5] BC/DR spending not a top budget priority

[0x6] BC/DR and cloud-services lessons learned from a recent Amazon outage

[0x7] Cloud services as part of a BC/DR plan after a terror attack

[0x8] Amazon's cloud failed: How can your cloud be better?

[0x9] CSO's ultimate guide to business continuity and disaster recovery

[0xA] In Canterbury earthquake, mobiles for emergency calls only

XSSed syndication

You are welcome to syndicate and share xssed.com contents

[0x1] Diigo Toolbar - Global XSS and Information Leakage in SSL URLs

[0x2] Dot Net Nuke (DNN) XSS Vulnerability

[0x3] Sun Java Server Faces Input Handling Cross-Site Scripting

[0x4] ManageEngine ServiceDesk Plus Cross-Site Scripting Vulnerability

[0x5] Savvy Content Manager "searchterms" Cross-Site Scripting

[0x6] Alkacon OpenCms "filePath" Cross-Site Scripting and File Disclosure

[0x7] IBM Lotus QuickPlace Cross-Site Scripting Vulnerability

[0x8] BosClassifieds Classified Ads System "returnTo" Cross-Site Scripting

[0x9] Zimbra Collaboration Suite Script Insertion Vulnerability

[0xA] WebCT Mail/Discussion Board Message Script Insertion

Dr Anton Chuvakin Blog PERSONAL Blog

LogChat: Andrew Hay and Anton Chuvakin talk about logging, log management and related topics

[0x1] Links for 2012-05-18 [del.icio.us]

[0x2] Book Review: “Security De-Engineering: Solving the Problems in Information Risk Management” by Ian Tibble

[0x3] Links for 2012-05-17 [del.icio.us]

[0x4] Links for 2012-05-08 [del.icio.us]

[0x5] Monthly Blog Round-Up – April 2012

[0x6] Links for 2012-04-30 [del.icio.us]

[0x7] Metricon 7 Call for Papers

[0x8] Links for 2012-04-22 [del.icio.us]

[0x9] Links for 2012-04-04 [del.icio.us]

[0xA] Monthly Blog Round-Up – March 2012

IBM Internet Security Systems Frequency X Blog

Frequency X, the blog site for IBM Internet Security Systems' world-renowned security research and development team, X-Force, provides an opportunity for the researchers to converse directly with the world about threats and vulnerability research.

[0x1] The Advanced Persistent Threat in 2012

[0x2] May 2012 Microsoft Super Tuesday

[0x3] April 2012 Microsoft Super Tuesday

[0x4] Key highlights in the IBM X-Force 2011 Trend & Risk Report

[0x5] March 2012 Microsoft Super Tuesday

[0x6] February 2012 Microsoft Super Tuesday

[0x7] Remote Code Execution in PHP 5.3.9

[0x8] CVE-2012-0003 Exploited in the Wild

[0x9] January 2012 Microsoft Super Tuesday

[0xA] A Note on Critical Infrastructure

Twitter / mdowd

Twitter updates from mdowd / mdowd.

[0x1] mdowd: Lenovo X1 carbon (ivy bridge): http://t.co/cnIiKRAp

[0x2] mdowd: RT @riskybusiness: Just posted the interview I did with @beaker at #auscert http://t.co/ElldKSOV

[0x3] mdowd: @kernelpool Looks like they've done it in the past: http://t.co/OviVoYNb

[0x4] mdowd: @wireghoul @kernelpool He better not be! We are going to the pub for lunch!

[0x5] mdowd: Happy Norway Independence Day! How are you celebrating it?

[0x6] mdowd: @raistolo Yeah :) Everyone waiting until the last second this year

[0x7] mdowd: Avalanche of last minute BH submissions over the last 48 hours

[0x8] mdowd: @jaqpants Organized by the same guy; they're intended to be complimentary conferences

[0x9] mdowd: @kernelpool Let's quit this security hocus pocus and go in to app dev

[0xA] mdowd: I nominate @kernelpool as our new UI developer

Securelist / Blog

[0x1] We Need More Than Jelly Bean

[0x2] Carolina Dieckmann, Brazilian cybercrime legislation and la “Viveza criolla”

[0x3] Public points of data loss

[0x4] Is ‘SexyDefense’ The Future of Anti-Espionage?

[0x5] Update to "DNSChanger - Cleaning Up 4 Million Infected Hosts"

[0x6] OS X Mass Exploitation - Why Now?

[0x7] SOURCE Boston Security Conference and Training 2012 Day 2 - Dan Geer Keynote, Android Modding and Cloud Security

[0x8] New Spam campaign on Twitter Leads to Rogue AV

[0x9] SOURCE Boston Security Conference and Training 2012 - Hacktivism, Duqu and Building Successful Security Programs

[0xA] New Version of OSX.SabPub & Confirmed Mac APT attacks

HSC Security Portal

Hackers Center Security Portal is one of the most complete, updated and visited Securty portals on the net. We offer Security Blogs, Exploits, Texts, Tools

[0x1] Scrubyt 0.4

[0x2] Sahi V3

[0x3] UrlParams 2.2.0

[0x4] TemperIE

[0x5] Nikto 2

[0x6] hcraft 1.0.0

[0x7] MSNPawn 1.1

[0x8] httprint

[0x9] DIRB

[0xA] WebInject 1.4

Wired Top Stories

Top Stories

[0x1] Stop the Tarbosaurus Auction!

[0x2] Which of These Insane Stunt Crews Will Be the Jackass of the Future?

[0x3] SpaceX Launch Aborted As Engine Ignition Begins

[0x4] A Google-a-Day Puzzle for May 19

[0x5] Microsoft to Launch Amazon EC2 Rival. Again

[0x6] Kickstarter of the Week: A Portable Scanner for Smartphones

[0x7] Full Coverage, Including Livestream: Historic SpaceX Launch to the ISS

[0x8] ITC Awards Microsoft an Import Ban on Motorola Phones, Tablets

[0x9] Dear Google: AT&T Locked Down the Best Android Handset Ever, and It's Your Fault

[0xA] The Launch Pad: SpaceX Falcon 9 Ready for Liftoff

Twitter / TrendMicro

Twitter updates from TrendMicro / TrendMicro.

[0x1] TrendMicro: The Identical Twins ~ Cloud Security and APT Defense? [Blog Post] http://t.co/xcTGmhWf @DaveAsprey bestows us with more #cloud wisdom

[0x2] TrendMicro: Data in Motion: The Other Side of the Cloud Encryption Coin [Blog Post] http://t.co/X77TYctO A #cloud must-read from @DaveAsprey

[0x3] TrendMicro: @MattMcLDC hey Matt, glad you found it useful. Thanks for mentioning! ^AL

[0x4] TrendMicro: @AdvistorTony great to hear that!! ^AL

[0x5] TrendMicro: The Most Important Preventive Measures to Secure Your Smartphone [Blog Post] http://t.co/eYrhAQ8O

[0x6] TrendMicro: Malware Masquerades as Flash Player for Android [Blog Post] http://t.co/xIV4hqkd

[0x7] TrendMicro: BlackBerry Mobile Fusion and other Announcements. Is RIM Opening up to Consumer Technology? [Blog] http://t.co/rPJ55oav @CesareGarlati

[0x8] TrendMicro: Diablo 3 Scams Preempt Game Release [Blog Post] http://t.co/swnVKfd1

[0x9] TrendMicro: iPad Configurator and other Announcements. Is Apple Getting Serious with the Enterprise? http://t.co/beRPm9Ba @CesareGarlati

[0xA] TrendMicro: @eleanorcecilia hello Eleanor I will pass your comments along to support and ask that they work with you to resolve. Thanks! ^AL

Managing Intellectual Property & IT Security

New methods of communications are changing the way that we do business, from hiring people, to designing scalable systems, to breaking down silos across organizations, how we manage information and systems in the Web 2.0 world is going to determine how well we compete as people and as companies in the future.

[0x1] Brave New Worlds the tightening of Copyright and Downloading

[0x2] Facebook ups the Ante on Employers asking for your Facebook password

[0x3] Would you turn over your Facebook account to get a job?

[0x4] Feeling a little tracked and monitored online

[0x5] Anonymous Releases their own OS filled with Malware

[0x6] Wow you can still Google Hack P2P Systems

[0x7] Google hacking Amazon CloudFront objects

[0x8] Create your own Job World Economic Forum thoughts

[0x9] Promoting and Enhancing Cybersecurity and Information Sharing Effectiveness Act of 2011

[0xA] New Google hack exposes internal home cameras

DVLabs: Published Advisories

Published Advisories

[0x1] TPTI-12-03 - Adobe Reader X True Type Font MINDEX Remote Code Execution Vulnerability

[0x2] TPTI-12-02 - Novell iPrint Client ActiveX GetPrinterURLList2 Remote Code Execution Vulnerability

[0x3] TPTI-12-01 - Oracle Java True Type Font IDEF Opcode Parsing Remote Code Execution Vulnerability

[0x4] TPTI-11-14 - Adobe Shockwave DEMX Remote Code Execution Vulnerability

[0x5] TPTI-11-13 - McAfee SaaS myCIOScn.dll Scan Method Script Injection Remote Code Execution Vulnerability

[0x6] TPTI-11-12 - McAfee SaaS MyAsUtil5.2.0.603.dll SecureObjectFactory Instantiation Design Flaw Remote Code Execution Vulnerability

[0x7] TPTI-11-08 - Adobe Shockwave iml32.dll DEMX Chunk GIF Parsing Remote Code Execution Vulnerability

[0x8] TPTI-11-09 - Adobe Shockwave iml32.dll CSWV Chunk Byte Array Parsing Remote Code Execution Vulnerability

[0x9] TPTI-11-10 - Adobe Shockwave dirapi.dll rcsL Chunk Parsing Remote Code Execution Vulnerability

[0xA] TPTI-11-11 - Adobe Shockwave Lnam Chunk Parsing Remote Code Execution Vulnerability

Data center news from Network World Fusion

The latest data-center news and analysis from NetworkWorld.com.

[0x1] Ethernet switching gets specialized

[0x2] Microsoft anti-bloatware service to apply to Windows 8 PCs, too

[0x3] Wozniak reveals why Steve Jobs loved secrecy

[0x4] New DDR4 memory to boost tablet, server performance

[0x5] Largest Illinois healthcare system uproots Cisco to build $40M private cloud

[0x6] HP has all the ingredients for software defined networking, almost

[0x7] Five ways to improve data center power efficiency you might not have thought of

[0x8] Cisco nemesis Huawei to demo 96-port 100G Ethernet switch

[0x9] Going Wireless in the Data Center

[0xA] Hitachi starts all-in-one data center service, covers construction to IT support

Network World on Firewalls

The latest firewall news, analysis and reviews on NetworkWorld.com.

[0x1] Forrester outlines 5 rising, 5 declining security technologies

[0x2] Secure360: The failure of risk management

[0x3] Palo Alto next-gen firewall stacks up well

[0x4] Basic firewall functionality: Check Point's maturity shows through

[0x5] Fortinet has highest catch rate in IPS testing

[0x6] SonicWall stands tall in SSL decryption testing

[0x7] Check Point takes best approach to URL filtering

[0x8] Next-gen firewalls: Off to a good start

[0x9] Scaling Up With SonicWALL's Supermassive

[0xA] How we tested the next-generation firewalls

Security Labs

[0x1] The Amnesty International UK website was compromised to serve Gh0st RAT [Update]

[0x2] Canada’s Cybercrime Report Card: Better or Worse in 2012?

[0x3] Pinning Down Pinterest

[0x4] Widespread malware abuses unsecured Geolocation Service of Adult Website

[0x5] The Institute for National Security Studies (Israel) falls prey to Poison Ivy infection

[0x6] Websense Security Labs at Infosec2012

[0x7] Weibo Accounts Compromised to Spread Phishing Campaign

[0x8] Is CVE-2012-0507 the best toolkit to exploit Mac OS X?

[0x9] Flashback Mac malware

[0xA] The Android "GoldDream" Malware Server is Still Alive

CSOONLINE.com - Business Continuity

[0x1] Disaster recovery is a success just waiting to happen

[0x2] How to start a business continuity program

[0x3] 4 critical trends in IT business continuity

[0x4] A clear-eyed look at APT

[0x5] Does my company need business continuity software?

[0x6] Cloud and disaster recovery: Load-balanced data centers are not a perfect solution

[0x7] Government engineers actively plan for cyberwar

[0x8] BC/DR spending not a top budget priority

[0x9] 68 great ideas for running a security department

[0xA] Storm brewing

US-CERT Tips

US-CERT Tips describe and offer advice about common security issues for non-technical computer users. Tips are restricted to a single topic, although complex issues may span multiple tips. Each tip builds upon the knowledge, both terminology and content, of those published prior to it.

[0x1] ST11-001: Holiday Traveling with Personal Internet-Enabled Devices

[0x2] ST06-001: Understanding Hidden Threats: Rootkits and Botnets

[0x3] ST04-024: Understanding ISPs

[0x4] ST06-005: Dealing with Cyberbullies

[0x5] ST05-002: Keeping Children Safe Online

[0x6] ST08-001: Using Caution with USB Drives

[0x7] ST06-004: Avoiding the Pitfalls of Online Trading

[0x8] ST06-006: Understanding Hidden Threats: Corrupted Software Files

[0x9] ST06-002: Debunking Some Common Myths

[0xA] ST06-003: Staying Safe on Social Network Sites

Tech Digest

Gadgets, mobile phones, news and reviews

[0x1] Canon EOS 650D snapping away from June: Specs leaked

[0x2] ViewQuest Retro Radio's get Wi-Fi connectivity and Union Jack makeover

[0x3] iPhone 5 had hands-on work from Steve Jobs: did he have a change of heart over perfect screen size?

[0x4] New leak reveals LG Eclipse NFC tech

[0x5] Add a bit of science to your workout

[0x6] Samsung Galaxy S3 tots up 9 million pre-orders

[0x7] The 10 Richest People In Tech - Zuckerberg, Gates, Dell and more!

[0x8] Facebook IPO sees shares sell at $38, company valued at $104 billion

[0x9] Kindle with built-in light launching by July?

[0xA] BBC Sports app headed to PS3 in time for Wimbledon, Olympics

LinuxSecurity.com: SuSE Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] SuSE: 2012-001: systemd

[0x4] SuSE: 2011-042: Linux kernel

[0x5] SuSE: 2011-041: Linux kernel

[0x6] SuSE: 2011-040: Linux kernel

[0x7] SuSE: 2011-038: Linux kernel

[0x8] SuSE: 2011-037: Mozilla Firefox

[0x9] SuSE: 2011-036: IBM Java 1.4.2

[0xA] SuSE: 2011-035:

IT Management & Trends White Papers

CIO, Emerging Technologies, and Project Management White Papers

[0x1] Insiders' Guide to Evaluating Remote Control Software

[0x2] Best-Practice Automation of Invoice Delivery from SAP(R) Solutions - Keeping Customers Satisfied While Making the Move

[0x3] The Learning Organization Goes Digital

[0x4] 10 Tips - IT Training Support

[0x5] How to Make Your IT Staff Smarter

[0x6] Improving Application Development with Digital Libraries

[0x7] Working Green with Digital Libraries - How it Can Help

[0x8] Minimizing Technology Project Delays with Digital Libraries

[0x9] How VMware Virtualization Right-sizes IT Infrastructure to Reduce Power Consumption

[0xA] Reduce Energy Costs and Go Green with VMware Virtualization

Network World on Security

The latest security news, analysis, reviews and feature articles from NetworkWorld.com.

[0x1] Cyber warfare in sights at government training conference

[0x2] Social Networking Security in the Workplace

[0x3] Twitter jumps on Do Not Track bandwagon

[0x4] Flashback Mac Trojan earned $14,000 from ad clicks, Symantec

[0x5] Anonymous hater claims responsibility for Pirate Bay DDoS attack

[0x6] Windows 8 Security: What's New

[0x7] New approaches to combat 'sources of evil' and other security issues

[0x8] Android in enterprises 'severely limited' by weak management support from Google

[0x9] Will voluntary cyber threat sharing plan cast doubt over CISPA?

[0xA] Anonymous Takes Aim at Indian Government

physicsworld.com: all content

Latest content from physicsworld.com

[0x1] Infrared vision could help the blind to see

[0x2] 11th International Computational Accelerator Physics Conference (ICAP)

[0x3] Microscopy & Microanalysis

[0x4] Silicon Quantum Information Processing (SiQIP)

[0x5] Levitating drops controlled by fridge magnets

[0x6] Thermal Imaging Helps Improve Safety in Space

[0x7] Doteck Digital Technologies

[0x8] Reality bites

[0x9] Reality bites

[0xA] Surface roughness measurement of media and substrate

XSSed syndication

You are welcome to syndicate and share xssed.com contents

[0x1] Exploitation of Self-Only Cross-Site Scripting in Google Code

[0x2] The Beginners Guide to XSS

[0x3] Blog: Reducing XSS by way of Automatic Context-Aware Escaping in Template Systems

[0x4] Browser Hijacking Techniques 2009

[0x5] WordPress.com permanent XSS vulnerability

[0x6] How to write a XSS (cross site scripting) worm for McCodes sites

[0x7] Open redirect vulnerabilities: definition and prevention

[0x8] Paper: Smashing the Web for fun & profit using XSS

[0x9] Paper: Defending against XSS with .NET

[0xA] Paper: Carnival, or how to camouflage data for XSS filters

Advisory Files ≈ Packet Storm

Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers

[0x1] libwpd WPXContentListener::_closeTableRow() Memory Overwrite

[0x2] HP Security Bulletin HPSBOV02780 SSRT100766

[0x3] HP Security Bulletin HPSBUX02782 SSRT100844

[0x4] Mandriva Linux Security Advisory 2012-078

[0x5] Epicor Returns Management SOAP-Based Blind SQL Injection

[0x6] Debian Security Advisory 2475-1

[0x7] Ubuntu Security Notice USN-1445-1

[0x8] Ubuntu Security Notice USN-1444-1

[0x9] Secunia Security Advisory 49185

[0xA] Secunia Security Advisory 49220

Google Online Security Blog

The latest news and insights from Google on security and safety on the Internet.

[0x1] Spurring more vulnerability research through increased rewards

[0x2] An improved Google Authenticator app to celebrate millions of 2-step verification users

[0x3] Celebrating one year of web vulnerability research

[0x4] Android and Security

[0x5] Landing another blow against email phishing

[0x6] Tech tips that are Good to Know

[0x7] Expanding Safe Browsing Alerts to include malware distribution domains

[0x8] Reminder: Safe Browsing version 1 API turning down December 1

[0x9] Protecting data for the long term with forward secrecy

[0xA] Safe Browsing Alerts for Network Administrators is graduating from Labs

National Vulnerability Database

This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.

[0x1] CVE-2012-2341

[0x2] CVE-2012-2322

[0x3] CVE-2012-2321

[0x4] CVE-2012-2320

[0x5] CVE-2012-2120

[0x6] CVE-2012-2118

[0x7] CVE-2012-2093

[0x8] CVE-2012-2010

[0x9] CVE-2012-1589

[0xA] CVE-2012-2411

Free Information Technology Magazines and Downloads from bestsecuritytips.tradepub.com

Free publications about information technology and digital communication.

[0x1] Hardware vs. Software Deduplication: Finding What's Right for You

[0x2] Enterprise Strategy Group: The Next Wave of Data Deduplication

[0x3] Advances in Deduplication Help Tame Big Data

[0x4] The State of Master Data Management, 2012: Building the Foundation for a Better Enterprise

[0x5] B2B Collaboration: No Longer Optional

[0x6] Managing the TCO of BI: The Path to ROI is Paved with Adoption

[0x7] Cloud Financial Management: Cost-Effective Implementation of Budgeting and Forecasting Measures

[0x8] To ERP or Not to ERP for SMBs: What Can ERP Do For Me?

[0x9] Business Intelligence - A Guide for Midsize Companies

[0xA] Think Your Organization is Too Small for ERP? Think Again

Gizmo's Freeware: Top selections

The best freeware finds from Gizmo's Freeware (www.techsupportalert.com)

[0x1] If You Use Mobile Apps I Hope You are not Missing Out on This

[0x2] A Superb Free Text Editor for When Notepad Isn't Good Enough

[0x3] Finds of the Week

[0x4] Updated: The Best Android Tips and Tricks

[0x5] Wallpaper of the Week

[0x6] Website of the Week

[0x7] Get Ten Free Full-Length E-Books From Microsoft Press

[0x8] "Fat Fingers" - a Free Mobile App that Could Save you Big Money on eBay

[0x9] Simple Online Tool Helps Verify Suspicious Emails

[0xA] A Shameless Plug by Gizmo for one of our First Editors

Reuters: Top News

Reuters.com is your source for breaking news, business, financial and investing news, including personal finance and stocks. Reuters is the leading global provider of news, financial information and technology solutions to the world's media, financial institutions, businesses and individuals.

[0x1] World leaders back Greece, vow to combat financial turmoil

[0x2] G8, raising pressure on Iran, puts oil stocks on standby

[0x3] Blind Chinese activist arrives in New York

[0x4] Syria bomb kills 9, Damascus blames foreign plot

[0x5] Yemen clashes kill 34 militants, soldiers: officials

[0x6] Anti-NATO activists weighed Obama HQ attack: prosecutors

[0x7] Google says it has China's approval for Motorola deal

[0x8] Motorcycle bomber kills 10 in eastern Afghanistan

[0x9] Thousands march in Frankfurt against austerity measures

[0xA] Obama pledges tough enforcement of Wall Street reforms

Security Basics

A high-volume list which permits people to ask "stupid questions" without being derided as "n00bs". I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.

[0x1] Re: Tool to find rouge wireless access points?

[0x2] Re: Enterprise Password & Session Management Tool

[0x3] Re: Tool to find rouge wireless access points?

[0x4] RE: Enterprise Password & Session Management Tool

[0x5] Re: Enterprise Password & Session Management Tool

[0x6] RE: Enterprise Password & Session Management Tool

[0x7] Risk Tracking Software

[0x8] Re: Enterprise Password & Session Management Tool

[0x9] Enterprise Password & Session Management Tool

[0xA] Re: Open Source Web Security & Content Filtering

LinuxSecurity.com: Foresight Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] Foresight: firefox

[0x4] Foresight: python

[0x5] Foresight: firefox

[0x6] Foresight: imageop

[0x7] Foresight: nss_ldap

[0x8] Foresight: rsync

[0x9] Foresight: e2fsprogs

[0xA] Foresight: tetex

Xatrix Security Headlines

Latest Computer Security Headlines

[0x1] Hack Attack: Get Windows XP SP3 Through Windows Update

[0x2] TPB files charges against media companies

[0x3] Storm worm: again.

[0x4] Onslaught on .ORGs

[0x5] OpenOffice.org insecure

[0x6] Leave your laptop at home

[0x7] Hack in the Box – Capture the Flag

[0x8] 35% of pay-per-click fraud?

[0x9] New variant mobile worm

[0xA] Google will help users surf safely

Kioptrix

Learning Security together

[0x1] Challenge VM #4 finally done

[0x2] Merry Christmas and Happy New Year

[0x3] Recovering Hashes from Domain Controller

[0x4] Another Hackfest has come and gone…

[0x5] SSH tunnel yourself out of the work place…

[0x6] Hackfest_ca 2011

[0x7] Metasploit Penetration Tester’s Guide

[0x8] Generic Letter one can use…

[0x9] Well… We’ve been hacked

[0xA] Challenge VM #3 is now available.

Unwired: Building & Maintaining Secure Wireless Networks

Journey into the latest in wireless technology! You'll find updates on new security issues and vulnerabilities, information on IEEE standards, advice on networking hardware, and unique insight on building and maintaining a secure wireless network.

[0x1] Quantum Cryptography

[0x2] In-Flight Wi-Fi

[0x3] Economic effects on IT Field

[0x4] Blackberry Storm Simulator

[0x5] 3G Wireless

[0x6] Wireless Network Users have Come a Long Way!

[0x7] Dilemma of a Passionate Programmer

[0x8] Can Old Wireless Network Interface Cards be Upgraded to Support WPA?

[0x9] Ramifications of a Cracked WPA Passphrase

[0xA] More Ramblings on WiFi Allergies

Lenny Zeltser on Information Security

Discussing IT with a focus on information security. Lenny Zeltser helps safeguard customers’ IT operations at NCR Corporation. He also teaches how to analyze and combat malware at SANS Institute.

[0x1] 5 Favorite Security Reads of the Week

[0x2] How Malicious Code Can Run in Microsoft Office Documents

[0x3] Confusing the Padlock and the Favicon in the Web Browser

[0x4] 5 Favorite Security Reads of the Week

[0x5] Slides for Presentation on Real-World Social Engineering Attacks

[0x6] Are Anxious People More Vigilant in Information Security?

[0x7] 4 Favorite Security Reads of the Week

[0x8] The Risks of Remote Desktop for Access Over the Internet

[0x9] At the BSides San Francisco conference I presented with Lee...

[0xA] "I recognize that my code will be used in ways I cannot anticipate, in ways it was not designed, and..."

LinuxSecurity.com

The central voice for Linux and Open Source security news.

[0x1] Facebook Hacker Gets a Year in Jail

[0x2] Drunken 'Call of Duty' hacker jailed for selling gamers' info

[0x3] Pirate Bay Under DDoS Attack From Unknown Enemy

[0x4] 10 hacks that made headlines

[0x5] Apple Mac Flashback Trojan Gang Still Making Money

[0x6] Wikipedia warns users about malware injecting ads

[0x7] Ubuntu: 1445-1: Linux kernel vulnerabilities

[0x8] Ubuntu: 1445-1: Linux kernel vulnerabilities

[0x9] Debian: 2475-1: openssl: integer underflow

[0xA] Ubuntu: 1444-1: BackupPC vulnerability

Network-7 : Cyberwarfare - Homeland Security - Financial & Privacy Intrusions

[0x1] US warns Dragon: ‘China wants to launch cyber war’

[0x2] Electric car network gets first test in Israel

[0x3] New Gadget Opens Cans and Bottles Instantly

[0x4] Gadget review: Enjoy pure good music on the go

[0x5] China is a lead cyberattacker of US military computers, Pentagon reports

[0x6] Slow cars causing big concerns on Speedway’s fast Friday

[0x7] Gadget Chargers Go Viral…Literally

[0x8] Gadget Of The Week: The Omega J8006 Juicer

[0x9] Facebook’s History: From Dorm To IPO Darling

[0xA] Twitter Adds Do Not Track Capability

Wired: Threat Level

Kevin Poulsen and Ryan Singel's daily briefing on security, freedom and privacy in the wired and unwired world.

[0x1] The Ultimate Counterfeiter Isn’t a Crook—He’s an Artist

[0x2] Jamming Tripoli: Inside Moammar Gadhafi’s Secret Surveillance Network

[0x3] Top Handset Maker Confirms Backdoor in One of Its Models

[0x4] Feds Considering Allowing DVD-Encryption Cracking

[0x5] It’s Tinkerers v. Hollywood as Copyright Office Mulls New Jailbreaking Rules

[0x6] Comcast Suspends Data Cap Temporarily, Will Test New Overage Fees

[0x7] To Warrant or Not to Warrant? ACLU, Police Clash Over Cellphone Location Data

[0x8] Justice Dept. Defends Public’s Constitutional ‘Right to Record’ Cops

[0x9] ‘Dead Man Walking’ Tricks Airport Into Giving Him Top Security Job

[0xA] Banned PlayStation Hacker Sees Hope of Return in Jailbreaking Deliberations

Infosec Writers Latest Security Papers

Papers submitted by security professionals are published on the site and archived for readers. Categories include cryptography, E-mail security, exploitation, firewalls, forensics, honeypots, IDS, malware & wireless security.

[0x1] Internet Acceptable Use Policies: Drawing the line

[0x2] Securing Amazon Web Services (AWS) and Simple Storage Service (Amazon S3) Security

[0x3] Getting maximum value from Penetration Testing

[0x4] Old School Newbie Guide circa 2000

[0x5] Analysis of Malicious Software Infections

[0x6] Malware in Information Security

[0x7] DoS! Denial of Service

[0x8] An Analysis of the IDS Penetration Tool: Metasploit

[0x9] Experimental Review of IPSec Features to Enhance IP Security

[0xA] Cloud Computing – Storm Clouds or is it Smooth Flying?

Security Systems News - Top Stories

[0x1] AT&T ‘bullish’ on security

[0x2] Netwatch open for business in U.S.

[0x3] Determining intelligibility of emergency messages—not so simple anymore

[0x4] Leadership change at Stanley CSS

[0x5] Xandem TMD sensing technology ‘sees through walls’

[0x6] AT&T enters security market, but can it become a billion-dollar business?

[0x7] Industry wins court case where municipality limited fire alarm business

[0x8] Owners driving market for mass notification systems

[0x9] AT&T to do home security in Dallas, Atlanta

[0xA] Dakota Security opens seventh office

Twitter / exploitdb

Twitter updates from Exploit Database / exploitdb.

[0x1] exploitdb: [webapps] - FreeNAC version 3.02 SQL Injection and XSS Vulnerabilties: FreeNAC version 3.02 SQL Injection and XS... http://t.co/scVPGjtw

[0x2] exploitdb: [webapps] - PHP Address Book 7.0.0 Multiple Vulnerabilities: PHP Address Book 7.0.0 Multiple Vulnerabilities http://t.co/s9Dp5sdP

[0x3] exploitdb: [remote] - Active Collab "chat module" http://t.co/mpYn9oIq

[0x4] exploitdb: [remote] - Squiggle 1.7 SVG Browser Java Code Execution: Squiggle 1.7 SVG Browser Java Code Execution http://t.co/baiKM2xN

[0x5] exploitdb: [remote] - Oracle Weblogic Apache Connector POST Request Buffer Overflow: Oracle Weblogic Apache Connector POST ... http://t.co/V5hbSiFc

[0x6] exploitdb: [local] - SkinCrafter ActiveX Control version 3.0 Buffer Overflow: SkinCrafter ActiveX Control version 3.0 Buffe... http://t.co/o508QW6w

[0x7] exploitdb: [remote] - HP VSA Remote Command Execution Exploit: HP VSA Remote Command Execution Exploit http://t.co/WBDSj7Zi

[0x8] exploitdb: [papers] - Complete Cross-site Scripting Walkthrough: Complete Cross-site Scripting Walkthrough http://t.co/ZNXKJka5

[0x9] exploitdb: [dos] - Trigerring Java Code from a SVG Image: Trigerring Java Code from a SVG Image http://t.co/hYhysHQa

[0xA] exploitdb: [webapps] - Artiphp CMS 5.5.0 Database Backup Disclosure Exploit: Artiphp CMS 5.5.0 Database Backup Disclosure Exploit http://t.co/XSh8Eiau

AVG Top Threats

Latest security threats

[0x1] AVI 271.1.1/5010 - new threats

[0x2] AVI 271.1.1/5009 - new threats

[0x3] AVI 271.1.1/5008 - new threats

[0x4] AVI 271.1.1/5007 - new threats

[0x5] AVI 271.1.1/5006 - new threats

[0x6] AVI 271.1.1/5005 - new threats

[0x7] AVI 271.1.1/5004 - new threats

[0x8] AVI 271.1.1/5003 - new threats

[0x9] AVI 271.1.1/5002 - new threats

[0xA] AVI 271.1.1/5001 - new threats

الأخبار - iSecur1ty

مجتمع عربي للهاكر الأخلاقي وخبراء الحماية يركّز على مفهوم اختبار الاختراق وجديد أخبار الحماية والثغرات, شروحات فيديو ومقالات أمنيّة.

[0x1] للمرة الاولي في مصر ورشة عمل وملتقى مهندسي أمن المعلومات بالمعهد المصرفي المصري

[0x2] مؤتمر كات سكوب

[0x3] ثغره جديده في متصفح Internet Explorer

[0x4] كتاب: A Bug Hunter’s Diary

[0x5] ثغره جديده في متصفح FireFox بسبب Java

[0x6] كتاب: Metasploit The Penetration Tester’s Guide

[0x7] ثغرة XSS خطيرة في Skype قد تؤدي لسرقة الحساب

[0x8] ثغرة 0-Day في نظام iOS

[0x9] ثغرات خطيرة في phpMyAdmin

[0xA] توقف شبكة Playstation عن العمل

Help Net Security - News

Help Net Security - your homepage for all the information security news

[0x1] Twitter supports “Do Not Track” option

[0x2] Facebook IPO advanced fee scam hitting inboxes

[0x3] MacScan 2.9.3 with Google Chrome and SeaMonkey support released

[0x4] Hacker jailed for targeting Call of Duty gamers

[0x5] Worm targets Facebook users via PMs

[0x6] Review: LOK-IT Secure Flash Drive

[0x7] Spam with malicious attachments rising

[0x8] Password creation policies are the enemy of secure passphrases

[0x9] Malicious fake Android AV apps pushed onto users

[0xA] Secure data on Android devices with SecureZIP

/dev/one

yet another device character

[0x1] Some thoughts about MySQL proxy as a DB Firewall

[0x2] Holograms!

[0x3] Lost in translation: WTF is happening inside my Android phone

[0x4] Python + divert sockets + scapy

[0x5] Video Streamming - Flash/Flex/Actionscript3 - NetConnection+NetStream+RTMP FMS (Flash Media Server)

[0x6] Suricata 1.0.2 Released

[0x7] HowTo setup suricata 1.0.0 on Mac OS X on IDS and IPS mode with IPFW

[0x8] New suricata release 0.8.2

[0x9] Improved version of pcap2rawc

[0xA] Rule2Alert

Identity Management

[0x1] Not ready to give up on single-sign on

[0x2] Stuck in CAPTCHA Hell: When Security Disables

[0x3] Stopping The Insider Threat: The Case for SIEM in Government IT (Part 3 - Wrap-up)

[0x4] More Holiday Cheer: SCIM Cloud Provisioning Standard Reaches A Big Milestone

[0x5] Stopping The Insider Threat: The Case for SIEM in Government IT (Part 2)

[0x6] Security Metrics and the Balanced Scorecard

[0x7] The Dark Side of Collaboration

[0x8] Foxnews.com - Drones, Malware and a Continued Lack of Infosec - Rinse and Repeat

[0x9] Hey, what’s for supper? We are having a risk-based pot roast tonight! Roll the dice.

[0xA] Cyber Surveillance & Warning Striker

Security Tool Files ≈ Packet Storm

Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers

[0x1] HULK - Http Unbearable Load King

[0x2] Admin Page Finder Script

[0x3] 360-FAAR Firewall Analysis Audit And Repair 0.2.4

[0x4] Web Application Vulnerability Scanner 0.11

[0x5] OpenDNSSEC 1.3.8

[0x6] Bluelog Bluetooth Scanner/Logger 1.0.3

[0x7] XCat 1.5

[0x8] Cura 0.4.0

[0x9] 360-FAAR Firewall Analysis Audit And Repair 0.2.3

[0xA] NetcatPHPShell 1.10

I Am Security

[0x1] Sexy Defense

[0x2] March – April Events

[0x3] Cyber, Cyber, Cyber. What are we talking about anyway?

[0x4] Guest post: Why you need patch management

[0x5] Hackers, Credit Cards, and the Media

[0x6] Advanced Data Exfiltration – full paper

[0x7] IL-CERT finally picking up speed

[0x8] [Offtopic] AirPlay on the home network

[0x9] Intelligence on Ashiyane and the Iranian Cyber Army

[0xA] So, what about that SecurityZone?

got privacy?  Musings on the state of Privacy in a connected world. - Blog

Blog

[0x1] Why Information Security (InfoSec) differs from Information Technology security (IT Security)

[0x2] Working Party’s Opinion 13/2011 on the current EU personal data breach framework and recommendations for future policy developments.

[0x3] UK and Germany interception actions

[0x4] RESPONSIBILITY FOR PRIVACY VIOLATIONS IN USER GENERATED CONTENT PROVIDERS (GOOGLE CASE IN ITALY)

[0x5] THE UNITED STATES OF MEXICO’S PRIVACY LAW

[0x6] HB1149: Part II - Who needs to worry about HB1149? (or, Who's Who in the Zoo?)

[0x7] What does the Bavarian Lager case signify for Privacy?

[0x8] Analysis of the EC "Cookie Directive"

[0x9] Privacy implications of Bavarian Lager

[0xA] HB 1149: Did anyone involved in drafting this legislation actually read the PCI DSS?

Steve (GRC) Gibson's Blog

Steve's Public Brain Dumping Ground (watch where you step!)

[0x1] Reverse Engineering RSA’s “Statement”

[0x2] Why Firesheep’s Time Has Come

[0x3] Instant Hotspot Protection from “FireSheep”

[0x4] iPhone 4 External Antenna Problem

[0x5] HCP 0-Day Quick Fix

[0x6] FLASH Adobe Forward to v10.1

[0x7] Pads ARE Next

[0x8] The Obvious Genius of iPad

[0x9] Facebook and the Ford Pinto

[0xA] Steve Gets a Blog!

Technology News

Get the latest technology news, comment and anlaysis from the Telegraph.

[0x1] Tory ministers met Google chiefs 23 times

[0x2] Sony's designs on your computer

[0x3] Should I wait for Windows 8?

[0x4] Facebook IPO: as it happened

[0x5] Facebook IPO: social network floats on the stock exchange - live

[0x6] Apple invests in renewable power for iCloud

[0x7] Mark Zuckerberg rings in Facebook's stock market debut

[0x8] Facebook IPO live

[0x9] YouView 'on track for summer launch'

[0xA] Monmouth to be world's first 'Wikipedia town'

LinuxSecurity.com: FreeBSD Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] FreeBSD: Kernel memory disclosure in procfs and linprocfs

[0x4] FreeBSD: fetch Overflow error

[0x5] FreeBSD: syscons Boundary checking errors in syscons

[0x6] FreeBSD: cvs number of vulnerabilities

[0x7] FreeBSD: kernel Improper memory access vulnerability

[0x8] FreeBSD: kernel Excessive privilege vulnerability

[0x9] FreeBSD: core:sys Buffer cache invalidation vulnerability

[0xA] FreeBSD: cvs Heap overflow vulnerability

Techworld Blogs

Aggregate feed of all active Techworld Blogs

[0x1] Digital Shoreditch: Britain's South by Southwest?

[0x2] Always consider the eventualities

[0x3] Getting to grips with corporate social networking (CSN)

[0x4] ROI in a Flash: deploying storage memory in the data centre

[0x5] Tech City: hiding behind the numbers?

[0x6] Whose PaaS is it anyway?

[0x7] Tech City needs better communications infrastructure

[0x8] Data's two masters - Performance and persistence

[0x9] Data’s two masters - Performance and persistence

[0xA] How to prepare for HTML 5 using cloud services

Security Justice

Security Justice

[0x1] Security Justice Episode 37 – All Good Things Must Come To An End

[0x2] Security Justice Episode 36 – Security Turtles, Podcast Updates, DEFCON and Black Hat

[0x3] Security Justice Episode 35- THOTCON Edition

[0x4] Streaming Live at #THOTCON

[0x5] Security Justice Episode 34 – THOTCON, Notacon and the Penetration Testing Execution Standard with @kaospunk

[0x6] Shmoocon 2011 Podcaster Meetup Details

[0x7] Security Justice Episode 33 – ShmooCon, BSidesCLE, Notacon, THOTCON, O-ISC, AIDE and DerbyCon

[0x8] Security Justice Episode 32 – Talking Risk with Alex Hutton (@alexhutton)

[0x9] Security Justice Episode 31 – The Kevin Johnson (@secureideas) Special

[0xA] Security Justice Episode 30 – Rafal Los (@Wh1t3Rabbit) and Dave Kennedy (@dave_rel1k) at the InfoSec Summit

CSOONLINE.com - Network Security

[0x1] iPhone, iPad become apple of cyber criminals' eye

[0x2] 10 hacks that made headlines

[0x3] Thwarted by security at enterprises, cyber criminals target SMBs

[0x4] Public vs. private cyberattack responsibility debate heats up

[0x5] Cloud computing tools: Improving security through visibility and automation

[0x6] Secure360: The failure of risk management

[0x7] Red Sky Alliance: An experiment in information sharing

[0x8] Hacktivists have the enterprises' attention. Now what?

[0x9] Could 'bullet time' stop a cyberattack?

[0xA] First Look: ZoneAlarm Free Antivirus + Firewall Launches Today

US-CERT Technical Cyber Security Alerts

US-CERT Technical Cyber Security Alerts provide timely information about current security issues, vulnerabilities, and exploits.

[0x1] TA12-129A: Microsoft Updates for Multiple Vulnerabilities

[0x2] TA12-101B: Adobe Reader and Acrobat Security Updates and Architectural Improvements

[0x3] TA12-101A: Microsoft Updates for Multiple Vulnerabilities

[0x4] TA12-073A: Microsoft Updates for Multiple Vulnerabilities

[0x5] TA12-045A: Microsoft Updates for Multiple Vulnerabilities

[0x6] TA12-024A: "Anonymous" DDoS Activity

[0x7] TA12-010A: Microsoft Updates for Multiple Vulnerabilities

[0x8] TA12-006A: Wi-Fi Protected Setup (WPS) Vulnerable to Brute-Force Attack

[0x9] TA11-350A: Adobe Updates for Multiple Vulnerabilities

[0xA] TA11-347A: Microsoft Updates for Multiple Vulnerabilities

Shlomi Narkolayev

Cutting Edge Information Security Posts.

[0x1] IRANGE - Pays close attention to your valueable items

[0x2] Linkedin ViewLink and ViewArticle mechanism opens new kind of Phishing attacks

[0x3] SCADA Exploitation - Hacking into national infrastructures

[0x4] Source-Link-Phishing (A.K.A. TabNabbing) - New technique for phishing attacks

[0x5] Directory Traversal Cheat Sheet

[0x6] ClickJacking Advertisement

[0x7] Hacking Citrix and Terminal Server Techniques

[0x8] Hacking the Planet - By TinKode

[0x9] ClickJacking Facebook

[0xA] Find SQL Injection using Google Dorks

Peter Guerra

All about security

[0x1] Malware implicated in fatal Spanair plane crash

[0x2] Cybersecurity and National Policy

[0x3] How Robber Barons hijacked the telegraph system

[0x4] The Bedazzler

[0x5] iPhone fix

[0x6] Twitter for Botnet control

[0x7] BlackHat 2009 Presentation

[0x8] SLE, Quantitative versus Qualitative Risk, and Finance

[0x9] BlackHat 2009

[0xA] White House Cyber Security Review is out

Palisade Magazine : Application Security Intelligence

A publication by Paladion Networks

[0x1] Quiz: Specifying life time for a webpage

[0x2] SAP Baseline Security Audit

[0x3] Defeating Encryption in Some Thick Clients

[0x4] Database Links Security

[0x5] Quiz: Proposal to amend Same Origin Policy

[0x6] Cache Control Directives Demystified

[0x7] The Payment Application Data Security Standard (PA DSS)

[0x8] Defend against Reverse Engineering

[0x9] Quiz: Cross Site Printing

[0xA] CSRF - The hidden menace

Twitter / i0n1c

Twitter updates from Stefan Esser / i0n1c.

[0x1] i0n1c: @TeamAndIRC i do not use google+

[0x2] i0n1c: RT @bSr43: This is just the beginning :) (still lot of work to be done!) http://t.co/akDzR0lE

[0x3] i0n1c: I guess i should Check Out hopper in the next days.

[0x4] i0n1c: RT @HITBSecConf: Online registration for #HITB2012AMS is now closed! WALK IN REGISTRATIONS STILL ACCEPTED (cash / credit card only) - Se ...

[0x5] i0n1c: RT @m0rbz: The one who pirated iOS hacker handbook left his a.id in metadata <string>aidan.harris1@hotmail.co.uk</string>@0x ...

[0x6] i0n1c: @b_fishr noone takes Discover

[0x7] i0n1c: QOTD: "Your followers prove that the world needs to allow abortion up until the fetus is 18 yrs old"

[0x8] i0n1c: There are far more people sending credit card information than Apple IDs... However all those CC# look fake.

[0x9] i0n1c: Lets try that again: "Please tweet me your credit card information"

[0xA] i0n1c: RT @carsiXme: @i0n1c Irgendein arschloch hat meine Daten gelöscht.

Social-Engineer.Org » Blog

Security Through Education

[0x1] Defcon 20 SECTF For Kids: Return of the Schmooze

[0x2] Defcon 20 SECTF – Battle of the SExes

[0x3] Too Cheap To Hire a Designer T-Shirt Contest

[0x4] Women and Social Engineering

[0x5] Social Engineering for Penetration Testers – Day 5

[0x6] Social Engineering For Penetration Testers – Day 4

[0x7] 6 Preventative Tips against Malicious Social Engineering

[0x8] Social Engineering For Pentesters – Day 3

[0x9] Social Engineering For Pentesters – Day 2

[0xA] Social Engineering Training – A New Era – Day 1

Gandi IWI Blog

[0x1] IP Transit Outage in France Telecom

[0x2] Maintenance Gandi.Net and API

[0x3] .CN domain creation suspension

[0x4] -50% discount for .ME extensions

[0x5] .HK domains now available at Gandi!

[0x6] Accented .EU domain names open on December 10th at 11:00 CET!

[0x7] .PT domains available at Gandi

[0x8] Network Maintenance overnight 19-20 November

[0x9] Hosting: Launch of multiple IP addresses for your servers

[0xA] Your server on IPv6?

The Grey Corner

A blog focused on the related subjects of software exploitation, penetration testing and computer incident detection and response.

[0x1] Restricted Character Set Buffer Overflow Tutorial for Vulnserver

[0x2] Egghunter based exploit for Vulnserver

[0x3] SEH Based Buffer Overflow Tutorial for Vulnserver

[0x4] Running Dradis in Apache on Ubuntu

[0x5] High Level Windows Shellcode Development Methods

[0x6] Simple Stack Based Buffer Overflow Tutorial for Vulnserver

[0x7] Exploit Writers Debugging Tutorial

[0x8] An Introduction to Fuzzing: Using SPIKE to find vulnerabilities in Vulnserver

[0x9] Introducing Vulnserver

[0xA] Version 0.4 of SSL Testing Tool ssltest.pl

shell-fu

[0x1] Tip #894: Watch for Ubuntu 9.10 Launch

[0x2] Tip #892: Check memory and swap from command line

[0x3] Tip #889: Convert virtually any video into a DVD-valid MPEG2 stream

[0x4] Tip #885: Random password generator.

[0x5] Tip #882: Find last modified files on a filesystem

[0x6] Tip #879: Learn not to mistype ls

[0x7] Tip #878: Random xkcd comic

[0x8] Tip #874: Count how many packages have been installed by pacman

[0x9] Tip #873: Import ssh host keys without verification

[0xA] Tip #872: Reverse geocode with bash

CSOONLINE.com - Fraud Prevention

[0x1] U.S. seeking to build international unity around cyberdefense for industrial control systems

[0x2] FBI issues warning on hotel Internet connections

[0x3] Police-themed ransomware starts targeting US and Canadian users

[0x4] Financial malware tricks users with claims of free credit card fraud insurance

[0x5] Dutch court temporarily frees 17-year-old KPN hacking suspect

[0x6] Russia-speaking cybercriminals earned $4.5 billion in 2011, researchers estimate

[0x7] Twitter spam campaign infects users with fake antivirus programs

[0x8] How to Tell If an Email Is a Phishing Scam

[0x9] Ice IX malware tricks Facebook users into exposing credit card details, says Trusteer

[0xA] How to fight check fraud

TaoSecurity

Richard Bejtlich's blog on digital security and the practices of network security monitoring, intrusion detection, and incident response.

[0x1] SEC Guidance Is a Really Big Deal

[0x2] Clowns Base Key Financial Rate on Feelings, Not Data

[0x3] Salvaging Poorly Worded Statistics

[0x4] Inside a Commission Hearing on the Chinese Threat

[0x5] Impressions: Fuzzing

[0x6] Impressions: Hunting Security Bugs

[0x7] Impressions: The Web Application Hacker's Handbook, 2nd Ed

[0x8] Impressions: Web Application Security: A Beginner's Guide

[0x9] Review of SSH Mastery Posted

[0xA] Bejtlich's Take on RSA 2012

Published Security Alerts

Published Security Alerts

[0x1] SQL Injection in SYS.KUPV$FT in Oracle 10g. Rel. 1

[0x2] SQL Injection in SYS.KUPV$FT_INT in Oracle 10g. Rel. 1

[0x3] Event 10053 logs TDE wallet password in cleartext

[0x4] Transparent Data Encryption stores key unencrypted in the SGA

[0x5] Cross-Site-Scripting in Oracle Workflow wf_route

[0x6] Cross-Site-Scripting in Oracle Workflow wf_monitor

[0x7] Shutdown listener via iSQL*Plus

[0x8] Shutdown listener via Forms Servlet

[0x9] Plaintext Passwords logged during Installation of Oracle HTMLDB

[0xA] Cross-Site-Scripting Vulnerabilities in Oracle HTMLDB

Casper Dik's Weblog

Casper Dik's Weblog

[0x1] OGP election

[0x2] NLOSUG: 26/10/2006 Dutch OpenSolaris User Group First Meeting

[0x3] Updated drivers: but only at www.opensolaris.org

[0x4] Small acpidrv update

[0x5] OpenSolaris User Group Meeting, Amsterdam, October 18th

[0x6] Laptop community live!

[0x7] Laptops

[0x8] First Installment (of frkit)

[0x9] User Credentials and all that

[0xA] Southpark Stdio

Splunk Blogs

[0x1] Splunk = Customer Satisfaction

[0x2] Analytics Staffing for Big Data: A Perspective

[0x3] Dallas Splunk Users Group – June 12th @ 6:00p CST

[0x4] #SplunkGovt Twitter Chat: A Sneak Peak at What We’ll Explore at SplunkLIVE! Washington, D.C.

[0x5] Doing More With What You Have

[0x6] That happened: episode 9

[0x7] Quantifying the Benefits of Splunk with SSDs

[0x8] Identifying Phishing Sites in Your Events

[0x9] I invested in a shiny new tool/technology…

[0xA] That happened: episode 8

Codenomicon News - RSS Feed

Codenomicon News - RSS Feed

[0x1] New Fuzzing Platform Defensics X Released!

[0x2] Codenomicon and FH Brandenburg work together for safer tomorrow

[0x3] Codenomicon Network Analyzer wins IT Security Product of the Year Award

[0x4] MultiServiceForum Introduces Robustness Testing at VoLTE Interoperability Event

[0x5] Codenomicon warns about poor quality of Bluetooth equipment

[0x6] Webcast on NGN Security featuring Ovum Analyst

[0x7] Check out the August 2011 issue of Codenomicon Newsletter

[0x8] Codenomicon brings fuzzing to the cloud

[0x9] Codenomicon endorses rugged software movement

[0xA] The Leading Experts in Fuzz Testing Come Together in Las Vegas

Upcoming Security Alerts

Upcoming Security Alerts

[0x1] Oracle Database

[0x2] Oracle Database

[0x3] Oracle Database

[0x4] Oracle Secure Enterprise Search

[0x5] Documentation bug concerning a special privilege

[0x6] Oracle Database

[0x7] Oracle Database

[0x8] Oracle Database

[0x9] Oracle Database

[0xA] Oracle Database

The Oracle Software Security Assurance Blog

[0x1] Security Alert for CVE-2012-1675 Released

[0x2] April 2012 Critical Patch Update Released

[0x3] Security Alert for CVE-2011-5035 Updated

[0x4] February 2012 Critical Patch Update for Java SE Released

[0x5] Security Alert for CVE-2011-5035 Released

[0x6] Learning More About Oracle Database Systems Change Number (“SCN”)

[0x7] January 2012 Critical Patch Update Released

[0x8] Keeping Up With Newer Releases is Good Security Practice

[0x9] October 2011 Critical Patch Updates Released

[0xA] Security Alert for CVE-2011-3192 Released

[0x1] Hakin9 Magazine Extra May Issue Adobe Security Released

[0x2] Pentest Market Magazine May Issue Released

[0x3] Live Online CEH Exam Prep Clinic for Free

[0x4] HashDays Security Conference 2012

[0x5] Pentest Auditing and Standards Magazine May Issue Released

[0x6] Hakin9 Magazine On Demand May Issue Released

[0x7] Pentest Magazine Cloud Pentesting New May 2012 Issue

[0x8] Hakin9 Magazine May Issue Released: Cloud Computing

[0x9] Phrack Magazine Issue 68 Released

[0xA] Pentest Magazine Web App Pentesting New April 2012 Issue

Network World on Windows

The latest Windows news, analysis and feature articles from NetworkWorld.com.

[0x1] Microsoft tunes up Windows 8 multi-screen

[0x2] Windows 8 Update: Firefox, Chrome cry foul over Windows 8 ARM

[0x3] U.S.-Israel project with Motorola leads to security-hardened industrial control system

[0x4] Remember Windows Live? Forget it.

[0x5] Wait, IS desktop Linux a flop? Readers weigh in

[0x6] Microsoft may take on Kindles and Nooks

[0x7] BYOD policy bites vacationing CEO

[0x8] Windows 8 Update: Windows 8 preview popularity kicking Windows 7's butt

[0x9] BYOD could hurt Windows Phone growth

[0xA] An RDP client and a Smartphone 'Copter

Security

[0x1] More than 140,000 Macs Still Infected by Flashback

[0x2] HP's ProCurve Switches Bundled with Compact Flash Virus

[0x3] Mac Users: Avoid Flashback.K by Disabling Java

[0x4] Verizon Report: Companies Overlook Key Security Precautions

[0x5] Anonymous Defaces PandaLabs Website

[0x6] Top Password Security Tips for SMBs

[0x7] Government Accountability Office Offers Cyber Security Guidance

[0x8] Security Flaw in Wi-Fi Routers Puts Data at Risk

[0x9] Mobile Malware a Growing Threat

[0xA] Survey: Law Firms Conscious of Cloud Security

Security Bytes

[0x1] Division of CISO responsibilities may prevent burnout

[0x2] Peter Kuper: VCs renewing their love affair with security companies

[0x3] Cloud security issues: Provider transparency, data-centric security

[0x4] Going after the middlemen in the fight against financial cybercrime

[0x5] Organizations lagging on cloud security training, survey shows

[0x6] Windows exploits: Data finds Windows Vista infections outpace Windows XP

[0x7] Creativity makes information security awareness training stick

[0x8] Virtualization security best practices in wake of ESX hypervisor code leak

[0x9] Oracle trips on TNS zero-day workaround

[0xA] CISPA intelligence information sharing bill passes House, headed to Senate

ComPly With Me--- a HIPAA Forum

[0x1] Sooner or Later...

[0x2] Preventing Cybercrime

[0x3] 3 I's

[0x4] Blue Suit, Red Cape and Red Boots

[0x5] International Talk Like a Pirate Day!

[0x6] Ah, Sweet Mystery

[0x7] Baby One More Time

[0x8] Over and over

[0x9] My Way

[0xA] Time After Time

The UNIX and Linux Forums

UNIX and Linux Forums - Learn UNIX, UNIX commands, Linux, Operating Systems, System Administration, Programming, Shell, Shell Scripts

[0x1] uniq -c in the pipeline

[0x2] Unix egrep

[0x3] Regarding grep

[0x4] coming out from vi editior

[0x5] gnuplot do not take my variable

[0x6] Ubuntu ruby on rails

[0x7] Searching the file in a directory

[0x8] Remove 3rd character from the end of a random-length string

[0x9] Combining 2 files

[0xA] Application with communication between process

Security - Infoworld

[0x1] Mac-based Flashback click fraud campaign was a bust

[0x2] Cyber spies exploiting Java, Flash flaws

[0x3] The firestorm over firewalls

[0x4] A tale of two Facebooks

[0x5] Wikipedia warns users about malware injecting ads into its pages

[0x6] Why you don't need a firewall

[0x7] Apple ships first Leopard security update in nearly a year

[0x8] Companies slow to react to mobile security threat

[0x9] Facebook proposes more changes to privacy policy

[0xA] Adobe backpedals, will now patch recent Creative Suite versions for free

Capi's Corner

Development, Network, Security, Ideas & Opinions

[0x1] A geek’s unified instant messaging setup

[0x2] Fix two Ubuntu 10.04 window manager annoyances

[0x3] The power of git aliases

[0x4] OCZ Vertex2, Linux, and ancient nForce 430 chipset

[0x5] Remaining Windows Vista/7 “rearm count”

[0x6] Novatel Merlin U740 using only Windows 7 onboard tools

[0x7] tr.im to be shut down

[0x8] URL shortening services soon to be under siege?

[0x9] Windows Vista Home/Business/Enterprise has a telnet client, too

[0xA] How to force Git to consider a file as binary

Networking & Infrastructure White Papers

Hardware, Linux, Networking, Security, Storage, UNIX, Windows, and Wireless White Papers

[0x1] Insiders' Guide to Evaluating Remote Control Software

[0x2] The Learning Organization Goes Digital

[0x3] 10 Tips - IT Training Support

[0x4] How to Make Your IT Staff Smarter

[0x5] Improving Application Development with Digital Libraries

[0x6] Working Green with Digital Libraries - How it Can Help

[0x7] Minimizing Technology Project Delays with Digital Libraries

[0x8] How VMware Virtualization Right-sizes IT Infrastructure to Reduce Power Consumption

[0x9] Reduce Energy Costs and Go Green with VMware Virtualization

[0xA] VMware Customer Success: Consolidating Data Centers at First American

WindowSecurity.com blogs

Welcome to our Network Security blogs. The blogs are updated on a regular basis with the latest news, information and insider gossip within the network security world and security related fields, such as cryptography.

[0x1] Is your website blacklisted?

[0x2] Would a .secure top-level domain make the Internet safer?

[0x3] Chrome 19 fixes 20 security flaws

[0x4] Adobe changes mind about free security fixes

[0x5] Hosting providers losing half of capacity to bots

[0x6] Writing Malware Reports

[0x7] IT security professional failing on risk strategies

[0x8] APT attackers using booby-trapped RTF docs

[0x9] Is the Cloud the solution to SMB security woes?

[0xA] Antivirus update gone seriously wrong

Virus and worm news from Network World

The latest virus and worm news and analysis from NetworkWorld.com.

[0x1] Apple releases security update, Flashback removal tool for Leopard

[0x2] 'Smishing' Attacks Are on the Rise

[0x3] NotCompatible Android Trojan: What You Need to Know

[0x4] Free Antivirus You Can Trust

[0x5] Who is threatening the security of your network?

[0x6] How to detect and remove the SabPub Mac Trojan

[0x7] Flashback Malware Still Affects 140,000 Macs

[0x8] Kaspersky fixes Flashback-fighting tool; Norton joins the fray

[0x9] New Java update from Apple removes Flashback malware

[0xA] Kaspersky launches free Flashback removal tool and website to check for infections

Security Labs

[0x1] The Amnesty International UK website was compromised to serve Gh0st RAT [Update]

[0x2] Canada’s Cybercrime Report Card: Better or Worse in 2012?

[0x3] Pinning Down Pinterest

[0x4] Widespread malware abuses unsecured Geolocation Service of Adult Website

[0x5] The Institute for National Security Studies (Israel) falls prey to Poison Ivy infection

[0x6] Websense Security Labs at Infosec2012

[0x7] Weibo Accounts Compromised to Spread Phishing Campaign

[0x8] Is CVE-2012-0507 the best toolkit to exploit Mac OS X?

[0x9] Flashback Mac malware

[0xA] The Android "GoldDream" Malware Server is Still Alive

Darknet - The Darkside

Ethical Hacking, Penetration Testing & Computer Security

[0x1] Hackers Break Into Bitcoin Exchange Site Bitcoinica

[0x2] CODENAME: Samurai Skills – Real World Penetration Testing Training

[0x3] Basic Fuzzing Framework (BFF) From CERT – Linux & Mac OSX Fuzzer Tool

[0x4] Russian Cyber-Crime Market Doubled In 2011

[0x5] creepy – A Geolocation Information Aggregator AKA OSINT Tool

[0x6] Anonymous Take Down Official F1 Site As Bahrain Protest

[0x7] NfSpy – ID-spoofing NFS Client Tool – Mount NFS Shares Without Account

[0x8] Android Trojan Targets Japanese Market – Steals Personal Data

[0x9] web-sorrow – Remote Web Security Scanner (Enumeration/Version Detection etc)

[0xA] Microsoft Delivers 6 Out Of Band High Priority Security Updates

Slashdot

News for nerds, stuff that matters

[0x1] On Hand for the SpaceX Launch That Almost Was (Video)

[0x2] Twitter Confirms Support For Do Not Track

[0x3] Software Patents Good For Open Source?

[0x4] MS Will Remove OEM 'Crapware' For $99

[0x5] Northrop Grumman Sues US Postal Service Over Automated Snail-mail Sort Contract

[0x6] Kinect In the Operating Room

[0x7] Sidestepping Tactical Nuclear Weapons Limits With Strategic Bombs

[0x8] Ask Slashdot: Recommendations For a Laptop With a Keypad That Doesn't Suck

[0x9] Amazon Patents Pitching As-Seen-On-TV Products

[0xA] Apple Commits To 100% Renewable Energy Sources for NC Data Center

Zscaler Research

The Zscaler Research Team is focused on bleeding edge web security research in the cloud computing era. This blog provides an opportunity for us to share our thoughts and ideas and interact with the community at-large. We welcome your feedback and encourage you to join the dialogue.

[0x1] Follow up on the top blacklisted sites

[0x2] A look at the top websites blacklisted

[0x3] Search Engine Security for Internet Explorer

[0x4] Multiple hijacking

[0x5] French Budget Minister website hijacked

[0x6] Search Engine Security for Google Chrome

[0x7] Details of a "new" Fake AV page

[0x8] PDF exploits targeted through Blackhole exploit kits.

[0x9] Blackhat SEO back in Google searches

[0xA] Mac OSX Flashback Confusion and Hype

TechRadar: Internet news

TechRadar UK latest feeds

[0x1] Government blasted for 'cosy' relationship with Google

[0x2] Did a tweet give away Facebook's IPO closing price?

[0x3] Twitter now supports Do Not Track, loves privacy

[0x4] Gary Marshall: ISPs are filtering more than porn

[0x5] Opinion: Why is Flash video so awful?

[0x6] Mobile madness as wrong sites censored by telecoms providers

[0x7] Official: Facebook to sell shares at $38, values company at $104bn

[0x8] Gmail gets more Google+ with people-friendly makeover

[0x9] Google unveils its semantic search plans - the Knowledge Graph

[0xA] Yahoo in embarrassing Facebook lawsuit blunder

CSOONLINE.com - Executive Communication

[0x1] Securing your Board of Directors' communication portal

[0x2] Who should the CISO report to?

[0x3] Is your definition of security holding you back?

[0x4] Patent trolls in our midst

[0x5] Three reasons why asking risky questions reduces risk

[0x6] Getting stuff done, your style

[0x7] How your signature can propel your security career

[0x8] Navigating your political landscape

[0x9] Getting stuff done: Public vs private sector edition

[0xA] 9 secrets of getting stuff done in a big company

Paranoia, Insecurity, and Overall Anxiety

I decided to create this blog to share information with those readers who are interested in some of the topics addressed. These topics will primarily be information security focused, but don't be surprised if I throw in a conspiracy theory or two from time to time.

[0x1] PA School Activates Spycam on Laptop

[0x2] Spyware for Your Blackberry

[0x3] Don't Forget Iron Man

[0x4] Pursuit Robots

[0x5] I Have Returned

[0x6] Ubiquitous Computing - I Don't Like IT!

[0x7] A Little Satire

[0x8] Bundled Facial Recognition Software on New Laptops

[0x9] I Have Been Slipping!

[0xA] Unleash the Cracken aka DARPA

Latest Linux Kernel Versions

Latest Linux Kernel Versions

[0x1] 3.4-rc7: mainline

[0x2] 3.3.6: stable

[0x3] 3.2.17: stable

[0x4] 3.1.10: stable

[0x5] 3.0.31: stable

[0x6] 2.6.35.13: stable

[0x7] 2.6.34.12: stable

[0x8] 2.6.32.59: stable

[0x9] 2.6.27.62: stable

[0xA] next-20120518: linux-next

Latest Security Advisories

[0x1] Microsoft Security Advisory (2695962): Update Rollup for ActiveX Kill Bits - Version: 1.0

[0x2] Microsoft Security Advisory (2647518): Update Rollup for ActiveX Kill Bits - Version: 1.0

[0x3] Microsoft Security Advisory (2269637): Insecure Library Loading Could Allow Remote Code Execution - Version: 15.0

[0x4] Microsoft Security Advisory (2641690): Fraudulent Digital Certificates Could Allow Spoofing - Version: 3.0

[0x5] Microsoft Security Advisory (2588513): Vulnerability in SSL/TLS Could Allow Information Disclosure - Version: 2.0

[0x6] Microsoft Security Advisory (2659883): Vulnerability in ASP.NET Could Allow Denial of Service - Version: 2.0

[0x7] Microsoft Security Advisory (2639658): Vulnerability in TrueType Font Parsing Could Allow Elevation of Privilege - Version: 2.0

[0x8] Microsoft Security Advisory (2607712): Fraudulent Digital Certificates Could Allow Spoofing - Version: 5.0

[0x9] Microsoft Security Advisory (2562937): Update Rollup for ActiveX Kill Bits - Version: 1.0

[0xA] Microsoft Security Advisory (2524375): Fraudulent Digital Certificates Could Allow Spoofing - Version: 5.0

M86 Security Labs Blog

News and commentary about Internet-borne security threats from M86 Security.

[0x1] M86 Security Labs now part of Trustwave’s SpiderLabs

[0x2] The Cridex Trojan Targets 137 Financial Organizations in One Go

[0x3] Cutwail Drives Spike in Malicious HTML Attachment Spam

[0x4] M86 Security Threat Report for the Second Half of 2011 is Now Available

[0x5] MIDI Files – Mid-Way to Infection

[0x6] Massive Compromise of WordPress-based Sites but ‘Everything will be Fine’

[0x7] Zbot Trojan spreads through fake ConEdison billing notification email

[0x8] Web Hijacks with AJAX

[0x9] Prevalent Exploit Kits Updated with a New Java Exploit

[0xA] A new Adobe 0-day In the Wild – – But No Worries, You are Already Protected with Our Secure Web Gateway!

Linux, Network and Security Research

[0x1] Wireshark updates close security holes

[0x2] Security threats Toolkit

[0x3] Unusual disk latency: The other day I met a friend and between...

[0x4] Untangle 7.1

[0x5] Lynis 1.2.9

[0x6] Wireshark 1.2.5

[0x7] Multiple Cisco WebEx WRF Player Vulnerabilities

[0x8] US drones hacked by Iraqi insurgents

[0x9] Video Interview with MacBook Bullet Girl

[0xA] Android Forensics

Network Security Blog

Join me as I spend 30 minutes each week talking about the computer security issues facing us today. I discuss privacy, hacking, malware and the Payment Card Industry (PCI) Data Security Standards.

[0x1] Network Security Podcast, Episode 275

[0x2] Network Security Podcast, Episode 272 v2

[0x3] Something to think on from Source Boston

[0x4] Network Security Podcast, Episode 274

[0x5] This is why CISPA scares me

[0x6] Network Security Podcast, Episode 273

[0x7] Network Security Podcast, Episode 272

[0x8] Global Payment Systems delisted by Visa

[0x9] Network Security Podcast, Episode 271

[0xA] TSA blocks Schneier from testifying

NovaInfosec.com

News, events, & resources for infosec professionals in NoVA, DC, & MD

[0x1] Grecs’ Weekend Best Bets for 2012-05-18

[0x2] Top 3 NoVA Infosec Blog Posts of the Week

[0x3] Kid Hacking – Learning to Program

[0x4] Video of the Week – How DNS Works

[0x5] Weekly Rewind – Top Industry News, DuckDuckGo, PHP Insecurity, & More…

[0x6] Duck … Duck … VI

[0x7] PHP Insecurity Notes

[0x8] Can Asking for Your Facebook Password Save the Economy?

[0x9] Google, Privacy, & DuckDuckGo

[0xA] Where You Want to Be This Week for 05-14-2012

Dogbert's Blog

hardware hacking and other ramblings...

[0x1] Password Recovery for FSI Amilo Pi Laptops

[0x2] Conrado strikes again

[0x3] Dell 1D3B

[0x4] "Donate" Button

[0x5] Free Unlocker for Palm/HP Phones

[0x6] Shmuck of the Week: Alexis Toledo / novatec / biosremoval

[0x7] Roll Call - State of Electronics

[0x8] Shmuck of the Month: Sony

[0x9] Shmuck of the Month: Conrado Davila / laptoprebirth.com

[0xA] Yet Another BIOS Broken by Design: InsydeH20

Twitter / exploitdb

Twitter updates from Exploit Database / exploitdb.

[0x1] exploitdb: [webapps] - FreeNAC version 3.02 SQL Injection and XSS Vulnerabilties: FreeNAC version 3.02 SQL Injection and XS... http://t.co/scVPGjtw

[0x2] exploitdb: [webapps] - PHP Address Book 7.0.0 Multiple Vulnerabilities: PHP Address Book 7.0.0 Multiple Vulnerabilities http://t.co/s9Dp5sdP

[0x3] exploitdb: [remote] - Active Collab "chat module" http://t.co/mpYn9oIq

[0x4] exploitdb: [remote] - Squiggle 1.7 SVG Browser Java Code Execution: Squiggle 1.7 SVG Browser Java Code Execution http://t.co/baiKM2xN

[0x5] exploitdb: [remote] - Oracle Weblogic Apache Connector POST Request Buffer Overflow: Oracle Weblogic Apache Connector POST ... http://t.co/V5hbSiFc

[0x6] exploitdb: [local] - SkinCrafter ActiveX Control version 3.0 Buffer Overflow: SkinCrafter ActiveX Control version 3.0 Buffe... http://t.co/o508QW6w

[0x7] exploitdb: [remote] - HP VSA Remote Command Execution Exploit: HP VSA Remote Command Execution Exploit http://t.co/WBDSj7Zi

[0x8] exploitdb: [papers] - Complete Cross-site Scripting Walkthrough: Complete Cross-site Scripting Walkthrough http://t.co/ZNXKJka5

[0x9] exploitdb: [dos] - Trigerring Java Code from a SVG Image: Trigerring Java Code from a SVG Image http://t.co/hYhysHQa

[0xA] exploitdb: [webapps] - Artiphp CMS 5.5.0 Database Backup Disclosure Exploit: Artiphp CMS 5.5.0 Database Backup Disclosure Exploit http://t.co/XSh8Eiau

CGISecurity - Website and Application Security News

All things related to website, database, SDL, and application security since 2000.

[0x1] Security Industry Plagiarism: Finding 3 examples in 5 minutes with Google

[0x2] Quick defcon/blackhat preparation list

[0x3] Summary of Google+ browser security protections

[0x4] Paper: Web Application finger printing Methods/Techniques and Prevention

[0x5] Oracle website vulnerable to SQL Injection

[0x6] WASC Announcement: 'Static Analysis Tool Evaluation Criteria' Call For Participants

[0x7] Results of internet SSL usage published by SSL Labs

[0x8] Another use of Clickjacking, Cookiejacking!

[0x9] NIST publishes 50kish vulnerable code samples in Java/C/C++, is officially krad

[0xA] How not to publish SCADA security advisories

Jeremiah Grossman

A page to show up #1 on Google when searching for "Jeremiah" (Currently #4).
Only the prophet and TV show left!
I have the edge, TV show is cancelled and the prophet isn't generating any new content.

The prophet, TV show, and that pesky Owyang guy going down!
A page to show up #1 on Google when searching for "Jeremiah Grossman", and it FINALLY has!

[0x1] Written Speech: TEDxMaui -- Hack Yourself First

[0x2] TEDxMaui -- Hack Yourself First

[0x3] Terrified

[0x4] How I got my start -- in Brazilian Jiu-Jitsu

[0x5] Web security content moving to new WhiteHat Security corp blog

[0x6] Sentinel SecurityCheck

[0x7] 11th WhiteHat Website Security Statistic Report: Windows of Exposure

[0x8] Robert “RSnake” Hansen, age 34, has passed away, on Facebook

[0x9] Top Ten Web Hacking Techniques of 2011

[0xA] BINGO! for Application Security

GLOBAL SECURITY ADVISOR RESEARCH BLOG

[0x1] Hoax Lottery emails from Mark Zuckerberg

[0x2] Ransomware exploits Microsoft Windows Update Center Service

[0x3] Beware of False E-Commerce Websites

[0x4] Digital Resurrections - malicious links piggybacking on trending videos

[0x5] OSX/SabPub - New Backdoor Malware Threat for Mac OS X

[0x6] Fraud Wiki Repair Guide

[0x7] Malware Targeting Windows and MAC OSX

[0x8] Mac OS X Threat Flashback is Back!

[0x9] Mac OS X Threat Masquerading as Image Files

[0xA] MS09-027 Target: Mac OSX & Tibetan NGOs

Free IT - Data Management Magazines and Downloads from bestsecuritytips.tradepub.com

Free publications and offers about databases and data management.

[0x1] Hardware vs. Software Deduplication: Finding What's Right for You

[0x2] Enterprise Strategy Group: The Next Wave of Data Deduplication

[0x3] Creating Business Value Through Location-Based Intelligence

[0x4] Think Your Organization is Too Small for ERP? Think Again

[0x5] Seven Reasons You Need Predictive Analytics Today

[0x6] Customer Analytics Pay Off: Driving Top-line Growth by Bringing Science to the Art of Marketing

[0x7] Five Predictive Imperatives for Maximizing Customer Value

[0x8] High Performance Organizations Empower Employees with Real-Time Mobile Analytics

[0x9] Webroot SecureAnywhere Business -Endpoint Protection

[0xA] Boosting Enterprise Application Performance in Distributed Environments

Podcasts

Listen to the latest Podcasts from Veracode

[0x1] Detecting "Certified Pre-owned" Software and Devices

[0x2] Application Outsourcing Podcast

[0x3] PCI Primer - Introduction to PCI Compliance

[0x4] Veracode Talks Security with InfoWorld

[0x5] How Vulnerabilities Get Into All Software

[0x6] Software Security Testing: Strengthening Your Defense Strategy

[0x7] Software Security Testing: Demanding Software Security

[0x8] Software Security Testing: Future of Software Flaws

[0x9] Veracode Shines Spotlight on Application Backdoors Threat

[0xA] Security Media Group: Interview with Veracode Founders

Carnal0wnage & Attack Research Blog

carnal0wnage and Attack Research Blog

[0x1] From LOW to PWNED [9] Apple Filing Protocol (AFP)

[0x2] PowerShell, Shellcode, metasploit, x64

[0x3] From LOW to PWNED [8] Honorable Mention: Log File Injection

[0x4] Update - Android & SSL Cert

[0x5] Android Emulator, Trusted CA, and Persistent Storage

[0x6] From LOW to PWNED [7] HTTP PUT/WebDAV/SEARCH

[0x7] From LOW to PWNED [6] SharePoint

[0x8] From LOW to PWNED [5] Honorable Mention: Null Sessions

[0x9] From LOW to PWNED [4] Browsable Directories

[0xA] Privilege Escalation via "Sticky" Keys

News ≈ Packet Storm

Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers

[0x1] FBI Looking At Law Making Websites WIretap Ready

[0x2] Facebook Sued For $15 Billion Over Alleged Privacy Infractions

[0x3] Apache OpenOffice Security Fixes Emerge

[0x4] Call Of Duty Hacker Jailed After Meatspace Burglary

[0x5] Twitter Backs Browser Privacy Project

[0x6] Atlassian Warns Of Critical Security Flaw

[0x7] UK Prosecutions For Hacking Appear To Be Dropping

[0x8] Met Police To Extract Phone Data

[0x9] Seeing Ads On Wikipedia? Then You're Infected

[0xA] UK-Based Hacking Doubled In First Quarter Of 2012

CIO Security

Latest Security issues from CIO UK

[0x1] Demand for IT contractors may grow due to Vickers bank report

[0x2] Universal Credit IT plans too optimistic, MPs warn

[0x3] Criminals impersonate UK police to spread ransom Trojan

[0x4] John Lewis's IT director Paul Coby outlines IT strategy

[0x5] HP in DWP job offshoring U-turn

[0x6] Algorithmic stock trading rapidly replacing humans

[0x7] Algorithmic stock trading rapidly replacing humans, warns government paper

[0x8] Poundland spends on new LAN

[0x9] Many businesses lining up cloud computing but not yet migrating

[0xA] Many businesses lining up cloud computing but not yet migrating, report claims

Web App Security

Provides insights on the unique challenges which make web applications notoriously hard to secure, as well as attack methods including SQL injection, cross-site scripting (XSS), cross-site request forgery, and more.

[0x1] t2'12: Call for Papers 2012 (Helsinki / Finland)

[0x2] A survey on web application attacks

[0x3] Abusing Password Managers with XSS

[0x4] [HITB-Announce] HITB Magazine Issue 008 (now with print edition!)

[0x5] Ruxcon 2012 Call For Papers

[0x6] Passwords^12 : Call for Presentations

[0x7] winAUTOPWN v3.0 Released

[0x8] SEC Consult whitepaper :: The Source Is A Lie

[0x9] OWASP ZAP 1.4.0 released

[0xA] Re: Time based Blind SQL injection

LinuxSecurity.com: Slackware Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] Slackware: 2012-041-03: glibc: Security Update

[0x4] Slackware: 2012-041-04: proftpd: Security Update

[0x5] Slackware: 2012-041-01: httpd: Security Update

[0x6] Slackware: 2012-041-02: php: Security Update

[0x7] Slackware: 2012-041-05: vsftpd: Security Update

[0x8] Slackware: 2011-284-01: httpd: Security Update

[0x9] Slackware: 2011-252-01: httpd: Security Update

[0xA] Slackware: 2011-249-01: mozilla-firefox: Security Update

ThinkGeek - What's New

ThinkGeek's latest and greatest stuff for smart masses brought to you with love from the minions of the Zombie Monkey Army.

[0x1] T-Shirts & Apparel : MythBusters' Gear - Jamie Wants Big Boom

[0x2] T-Shirts & Apparel : Wolverine Dash - tokidoki x marvel

[0x3] T-Shirts & Apparel : We Met on the Internet Babydoll

[0x4] Gadgets : Monkey Light 8-Bit Bike Wheel Light

[0x5] Caffeine & Edibles : Teastick

[0x6] Caffeine & Edibles : Pekoe Tea Glass

[0x7] T-Shirts & Apparel : Captain America Bangle Bracelet

[0x8] T-Shirts & Apparel : Thor Dangle Earrings

[0x9] ThinkGeek's cheaper shipping for the UK

[0xA] Home & Office : Doctor's Prescription Flask

Paul Thurrott's WinInfo News

News about Windows and Microsoft. No fluff.

[0x1] WinInfo Short Takes, May 18, 2012

[0x2] Google: Hey, We Can Update Our Search Engine Too

[0x3] New Bing Is a Bit Socially Awkward

[0x4] No, Windows RT Isn’t Windows . . . Yet

[0x5] Intel, AMD Align for Windows 8 Battles of 2012

[0x6] Senate Judiciary Committee to Examine Windows RT Browser Allegations

[0x7] Disgraced Yahoo! CEO Steps Down

[0x8] WinInfo Short Takes, May 11, 2012

[0x9] Mozilla, Google Gripe About Windows RT Limitations

[0xA] Microsoft: More Than 50,000 Smartphones Have Been “Smoked” by Windows Phone

CSOONLINE.com - Wireless/Mobile Security

[0x1] Wireless tech makes health care security a 'major concern'

[0x2] iPhone, iPad become apple of cyber criminals' eye

[0x3] Android hackers honing skills in Russia

[0x4] Smartphone security is heading for 'apocalypse'

[0x5] Companies slow to react to mobile security threat

[0x6] Mobile BYOD users want more security

[0x7] Symantec leapfrogs McAfee in mobile security

[0x8] Symantec conference puts focus on mobile security

[0x9] Is Facebook use in the enterprise too risky to allow?

[0xA] Will Flashback hurt Macs in the enterprise?

Search Engine Watch

Keep updated with major stories about search engine marketing and search engines as published by Search Engine Watch.

[0x1] 6 Tools to Manage Your Twitter Followers

[0x2] 4 Ways to Rethink a Facebook Advertising Campaign

[0x3] For Better Facebook Engagement, Post on Topics Related To, But Not About, Your Brand [Study]

[0x4] Google Launches Knowledge Graph, 'First Step in Next Generation Search'

[0x5] Mobile Sites: Choosing an Implementation Process & Strategies

[0x6] Why Your SEO & Social Strategy Should Include Pinterest

[0x7] Google NSA Relationship Secrecy Continues Despite Courts Efforts

[0x8] Ford Retains Confidence in Facebook Ads as GM Quits

[0x9] Life After Google Penguin – Going Beyond the Name

[0xA] 7 Time-Saving Google Analytics Custom Reports

Danger Room

What's Next in National Security

[0x1] Surprise! China’s Stealth Jets Are 2 Years Ahead of Schedule

[0x2] The Rocket Factory – SpaceX Builds Them From top To Bottom

[0x3] Cell Doors ‘Incapable of Locking’ at Giant Afghan Jail

[0x4] Smile! U.S. Troops Cover Up With New ‘Facial Armor’

[0x5] Face Down, Cash Up, Then Pakistan Lets in Our Trucks

[0x6] China Flies New Stealth Fighter as Problems Plague U.S. Jets

[0x7] Step 1 in U.S. Plan to Rule Sea and Sky: Actually Share Data

[0x8] Why the World Isn’t Freaking Out About Iran’s Plasma-Powered Spy Sat

[0x9] Majority of Mexicans Want More U.S. Help in Drug War

[0xA] Defense Chief Restricts Stealth Jet Till It Stops Choking Pilots

Techworld.com operating-systems

Latest IT articles from Techworld's operating-systems channel

[0x1] How to delete linked calendar entries in Android

[0x2] How delete linked calendar entries in Android

[0x3] Developers, busy with Ice Cream Sandwich, not holding back for Android 5

[0x4] Apple updates Mac OS X 10.8 Mountain Lion Developer Preview

[0x5] Firefox on Windows RT 'probably not worth it'

[0x6] Firefox on Window RT 'probably not worth it'

[0x7] Microsoft battles PC bloat with new Signature tune-up

[0x8] Ubuntu Business Desktop Remix gets 12.04 'Precise Pangolin' update

[0x9] Android 5.0 'Jelly Bean' autumn launch will be on Google devices first

[0xA] Windows 8 to offer enhanced multi-screen working

LinuxSecurity.com: Mandriva Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] Mandriva: 2012:078: imagemagick

[0x4] Mandriva: 2012:077: imagemagick

[0x5] Mandriva: 2012:076: ffmpeg

[0x6] Mandriva: 2012:075: ffmpeg

[0x7] Mandriva: 2012:074: ffmpeg

[0x8] Mandriva: 2012:073: openssl

[0x9] Mandriva: 2012:072: roundcubemail

[0xA] Mandriva: 2012:071: php

News from trapkit.de

News from trapkit.de

[0x1] [16.07.2010] Oracle Solaris Kernel Security Advisory

[0x2] [22.02.2010] avast! Security Advisory

[0x3] [02.02.2010] Apple iPhone OS and Mac OS X Security Advisory

[0x4] [31.01.2010] Oracle Solaris Kernel Security Advisory

[0x5] [27.12.2009] New version of checksec.sh

[0x6] [09.09.2009] Apple iPhone OS AudioCodecs Heap Buffer Overflow (TKADV2009-007)

[0x7] [16.05.2009] libsndfile/Winamp Security Advisory (TKADV2009-006)

[0x8] [04.04.2009] xine-lib Security Advisory (TKADV2009-005)

[0x9] [15.02.2009] xine-lib also affected by TKADV2009-004

[0xA] [28.01.2009] FFmpeg Security Advisory (TKADV2009-004)

Computer Security News

News on Computer Security continually updated from thousands of sources around the net.

[0x1] Mu Dynamics

[0x2] Meigs man pleads guilty to extortion, computer intrustion

[0x3] Google's Advanced Email Security Can't Protect Users From Their Own Stupidity

[0x4] Hackers Briefly Take Over City Web Site

[0x5] Computer Security Breach at ULM

[0x6] Be prepared for a hacker attack

[0x7] UK government staff caught snooping on citizen data

[0x8] social network makes stock market debut – live blog

[0x9] Police Blotter: Phone Hacker Makes Overseas Calls

[0xA] Who Did the WikiLeaks DDoS Attack?

CNET News.com

Tech news and business reports by CNET News. Focused oninformation technology, core topics include computers, hardware, software,networking, and Internet media..

[0x1] FBI 'looking at' law making Web sites wiretap-ready, director says

[0x2] Facebook sued for $15 billion over alleged privacy infractions

[0x3] Caught snooping: U.K. government staffers

[0x4] Socialcam closes hole that enabled accidental sharing

[0x5] Pirate Bay, WikiLeaks fight off crippling attacks

[0x6] U.S. cybersecurity chief Howard Schmidt retiring

[0x7] Twitter announces support for Do Not Track

[0x8] Friday debut of SF bar-cams stirs sour reception

[0x9] Euclid downplays privacy concerns about Wi-Fi tracking

[0xA] Flashback makers missed out on their payday, Symantec says

Wired: Politics

The intersection of technology and government.

[0x1] Twitter Improves Privacy Options, Now Supports 'Do Not Track'

[0x2] Cell Doors 'Incapable of Locking' at Giant Afghan Jail

[0x3] Face Down, Cash Up, Then Pakistan Lets in Our Trucks

[0x4] Your First Class Seat For Space

[0x5] Step 1 in U.S. Plan to Rule Sea and Sky: Actually Share Data

[0x6] How Plants Deal With Space Travel

[0x7] Why the World Isn't Freaking Out About Iran's Plasma-Powered Spy Sat

[0x8] Defense Chief Restricts Stealth Jet Till It Stops Choking Pilots

[0x9] Another Afghanistan Commander Bails on the War Early

[0xA] Pakistan Shuts Its Border; Pentagon Shuts Its Mouth

Linux Journal - The Original Magazine of the Linux Community

Since 1994: The Original Monthly Magazine of the Linux Community

[0x1] Make TV Awesome with Bluecop

[0x2] Hack and / - Password Cracking with GPUs, Part I: the Setup

[0x3] An Introduction to Application Development with Catalyst and Perl

[0x4] Cryptocurrency: Your Total Cost Is 01001010010

[0x5] HTML5 for Audio Applications

[0x6] May 2012 Issue of Linux Journal: Programming

[0x7] Three Ways to Web Server Concurrency

[0x8] Tales From the Server Room: Zoning Out

[0x9] Mercurial - Revision Control Approximated

[0xA] New Products

Irongeek's Security Site

Irongeek.com, Adrian Crenshaw's Information Security site (along with a bit about weightlifting and other things that strike my fancy). Home of my articles and videos on computer security. As I write articles and tutorials I will be posting them here. If you would like to republish one of the articles from this site on your webpage or print journal please e-mail me. Enjoy the site and write us if you have any good ideas for articles or links.

[0x1] Intro to Scanning: Nmap, Hping, Amap, TCPDump, Metasploit, etc. Jeremy Druin

[0x2] Jeremy Druin did some more Mutillidae/Web Pen-testing videos

[0x3] More Mutillidae/Web Pen-testing videos from Jeremy Druin

[0x4] DerbyCon tickets go on sale this today! (Friday April 27th) – CFP OPEN!

[0x5] 2 more Mutillidae/Web Pen-testing videos from Jeremy Druin

[0x6] Outerz0ne 8 (2012) Videos

[0x7] Notacon 9 (2012) Videos

[0x8] More Mutillidae/Web Pen-testing videos from Jeremy Druin

[0x9] Finding Comments And File Metadata Using Multiple Techniques

[0xA] Pen-testing practice in a box: How to assemble a virtual network

Dell SecureWorks Info Feed

Dell SecureWorks news, press releases, events, and research alerts.

[0x1] Carrier IQ: Requires Additional Review

[0x2] Transitive trust and SSL certificate verification

[0x3] PCI Guidance on Virtualization and Cloud

[0x4] DELL SECUREWORKS PARTNERS WITH QUALYS TO DELIVER SAAS-BASED VULNERABILITY MANAGEMENT SERVICES

[0x5] Recent events cause re-assessment of SecurID integrity

[0x6] "Imperva SecureSphere XSS and the nature of security-product vulnerabilities"

[0x7] News: Happy birthday Dell: The beginning of an evolution/revolution (TG Daily)

[0x8] "Sony PlayStation Network Breach"

[0x9] April 2011 Patch Tuesday sets a new record

[0xA] The Cloud Security Silver Lining

Corelan Team

:: Knowledge is not an object, it's a flow ::

[0x1] Hack In The Box Amsterdam 2012 – Preview

[0x2] Reversing 101 – Solving a protection scheme

[0x3] BlackHat EU 2012 – Day 3

[0x4] BlackHat EU 2012 – Day 2

[0x5] BlackHat EU 2012 – Day 1

[0x6] Debugging Fun – Putting a process to sleep()

[0x7] Exploit writing tutorial part 11 : Heap Spraying Demystified

[0x8] Donations

[0x9] Many roads to IAT

[0xA] WoW64 Egghunter

Xatrix Security Advisories

Xatrix Security Advisories

[0x1] Ubuntu Linux: Firefox vulnerabilities

[0x2] Red Hat: Ruby safe-level vulnerability

[0x3] Red Hat: Seamonkey critical security vulnerabilities

[0x4] Debian: Drupal several remote vulnerabilities

[0x5] Debian: Kernel local race condition

[0x6] SUSE: Kernel local privilege escalation

[0x7] Ubuntu Linux: Update introduced regression

[0x8] Ubuntu Linux: Mozilla-Thunderbird vulnerabilities

[0x9] Mandriva: Perl log flaw

[0xA] Ubuntu Linux: Mozilla various vulnerabilities

SecurityVibes UK

Security & Compliance Community

[0x1] The analyst view: 2011 in perspective

[0x2] The pen tester’s view of 2011: awareness rises but complacency reigns

[0x3] Stratfor clients braced for disclosures

[0x4] Northrop Grumman and Finmeccanica aim for NATO cyber role

[0x5] Security poised for place on government fast track?

[0x6] Spammers turn on festive themes

[0x7] Company bosses: barrier to security in essential services

[0x8] Cisco: get to work on known unknowns in 2012

[0x9] Tough cookies – ICO on new privacy rules

[0xA] Are reports of the death of the hardware token premature?

SecuObs.com

Observatoire de la securite Internet

[0x1] Tutorial gia Metasploit Framework

[0x2] configuracion de esquid proxy

[0x3] WIRELESS ASOCIATION EAP PEAP SUPPLICANT WINDOWS 7

[0x4] Metasploit 3 Video msfconsole with db autopwn by nnp

[0x5] botnet

[0x6] Firewalls With Sarah

[0x7] CVE 2011 3658 Firefox 7 8 nsSVGValue Vulnerability Metasploit Demo

[0x8] SDR based GSM Jammer USRP 2 and GNU Radio Open BTS HD

[0x9] iExploitTube Episode 5 Exploiting a remote service with metasploit web to get a VNC remote desktop

[0xA] Heap Overflow

US-CERT Technical Cyber Security Alerts

US-CERT Technical Cyber Security Alerts provide timely information about current security issues, vulnerabilities, and exploits.

[0x1] TA12-129A: Microsoft Updates for Multiple Vulnerabilities

[0x2] TA12-101B: Adobe Reader and Acrobat Security Updates and Architectural Improvements

[0x3] TA12-101A: Microsoft Updates for Multiple Vulnerabilities

[0x4] TA12-073A: Microsoft Updates for Multiple Vulnerabilities

[0x5] TA12-045A: Microsoft Updates for Multiple Vulnerabilities

[0x6] TA12-024A: "Anonymous" DDoS Activity

[0x7] TA12-010A: Microsoft Updates for Multiple Vulnerabilities

[0x8] TA12-006A: Wi-Fi Protected Setup (WPS) Vulnerable to Brute-Force Attack

[0x9] TA11-350A: Adobe Updates for Multiple Vulnerabilities

[0xA] TA11-347A: Microsoft Updates for Multiple Vulnerabilities

Help Net Security - Vulnerabilities

Help Net Security - your homepage for all the information security news

[0x1] Zend Server Multiple HTML Injection Vulnerabilities

[0x2] EJBCA "issuer" Parameter Cross-Site Scripting

[0x3] OpenLDAP LDAP Search Request Remote Denial of Service

[0x4] Vegas Movie Studio HD "CFHDDecoder.dll" DLL Loading Arbitrary Code Execution

[0x5] Microsoft Expression "wintab32.dll" DLL Loading Arbitrary Code Execution

[0x6] Jenkins Multiple Cross-Site Scripting and Directory Traversal Vulnerabilities

[0x7] SquirrelMail Autocomplete Plugin Email Addresses Cross-Site Scripting

[0x8] Google Chrome Remote Code Execution

[0x9] XnView Multiple Buffer Overflow Vulnerabilities

[0xA] Microsoft Windows "DirectWrite" API Denial of Service

Data Protection

[0x1] Howard Schmidt went the distance

[0x2] #FFSec: Security pros to follow on Twitter, May 18

[0x3] DHS cybersecurity official leaves more questions than answers

[0x4] Maiffret: If it's a Linux flaw, your phone is directly threatened

[0x5] Alan Paller on cutting through the bull

[0x6] ISSA-LA's Security Summit IV is tomorrow

[0x7] Application Security Inc. vows to 'give away' up $1 million in database security software

[0x8] Many blacklisted sites were hijacked, says Zscaler ThreatLabZ

[0x9] McAfee-Intel eye critical infrastructure protection

[0xA] Not your older brother's security landscape

Black Hat Forum Black Hat SEO

BlackHatWorld is a blackhat SEO Forum dedicated to learning black hat seo, cloaking, doorway pages, blogging, automatic content generators and more. Master the ART of "BlackHat"!

[0x1] Fiverr Algorithm is Getting Fucked UP

[0x2] Highest converting method for PPD and youtube?

[0x3] Panda just hit my Google Places Clients

[0x4] 100% Authentic Designer Clothes, Handbags, Shoes, Electronics, TV's, Jewelry, Appliances..

[0x5] .com Domain for $3.39

[0x6] how to use large budget with adwords , thanks!!!

[0x7] Non organic classifieds traffic to adsense site. Is it safe?

[0x8] Keywords and scrapebox

[0x9] A PM wont let me mark as read and continue to get popup notification

[0xA] Kylo Cho On Facebook [READ]

Abysssec Security Research

Security Researches , Advisories , Coding , Projects , Reversing , Exploitation , Fuzzing

[0x1] Exploiting CVE-2011-2140 another flash player vulnerability

[0x2] Microsoft Excel 2007 SP2 Buffer Overwrite Vulnerability BA / Exploit (MS11-021)

[0x3] bypassing all anti-virus in the world (Good Bye Detection , Hello Infection)

[0x4] Exploit for CVE-2011-0222 Safari SVG Vulnerability

[0x5] Analysis of CVE-2011-0041 vulnerability in GDI+

[0x6] DEP/ASLR bypass using 3rd party + Clarification

[0x7] Exploiting Adobe Flash Player on Windows 7

[0x8] Hacking / Exploiting / Cheating in Online Games

[0x9] Exploiting Internet Explorer 8 on Windows 7

[0xA] Adobe Shockwave player rcsL chunk memory corruption 0day

Episteme: Belief. Knowledge. Wisdom

[0x1] How to Quickly Create New Habits in Your Life

[0x2] Matching and Mirroring (or: Cybernetic Issues in NLP)

[0x3] My Newest Experiment – The Kindle Book

[0x4] Maturity and Business

[0x5] What is it to be Mature?

[0x6] A Branding MAD Lib

[0x7] Suppressing Dissent

[0x8] Byron (and influence through the media)

[0x9] Influence and Failing Kindergarten

[0xA] Return-to-Barry-White Human Exploitation

Check Point Update Services Advisories

You are viewing a feed that contains frequently updated content. When you subscribe to a feed, it is added to the Common Feed List. Updated information from the feed is automatically downloaded to your computer and can be viewed in Internet Explorer and other programs.

[0x1] Microsoft Excel SERIES Record Parsing Code Execution (MS12-030; CVE-2012-1847)

[0x2] Microsoft .NET Framework XBAP Buffer Allocation Code Execution (MS12-034; CVE-2012-0162)

[0x3] Microsoft Silverlight Double-Free Remote Code Execution (MS12-034; CVE-2012-0176)

[0x4] Microsoft Windows Malformed TrueType Font Remote Code Execution (MS12-034; CVE-2012-0159)

[0x5] Microsoft Excel SXLI Record Memory Corruption (MS12-030; CVE-2012-0184)

[0x6] Microsoft Excel Record Structure Memory Corruption (MS12-030; CVE-2012-0143)

[0x7] Microsoft Excel File Format Code Execution (MS12-030; CVE-2012-0141)

[0x8] Microsoft Windows GDI+ EMF Heap Overflow (MS12-034; CVE-2012-0167)

[0x9] Microsoft Office RTF Mismatch Memory Corruption (MS12-029; CVE-2012-0183)

[0xA] Microsoft Windows GDI+ Record Type Code Execution (MS12-034; CVE-2012-0165)

Rootsecure.net

The security news site for systems administrators & hackers - keeping you informed about all the top security news stories updated daily

[0x1] Cisco Zine: Unicast flooding due to asymmetric routing

[0x2] Acros Security: Adobe Reader X (10.1.2) msiexec.exe Planting

[0x3] Cisco Zine: Twelve Cisco vulnerabilities

[0x4] Marco Ramilli's Blog: CVE-2012-0507

[0x5] Cisco Zine: How to perform SSH RSA User Authentication

[0x6] Offensive Security: FreePBX Exploit Phone Home

[0x7] Cisco Zine: Cisco Linksys WVC200 Wireless-G PTZ Internet Video Camera buffer overflow

[0x8] arstechnica: How Anonymous plans to use DNS as a weapon

[0x9] arstechnica: Doxed: how Sabu was outed by former Anons long before his arrest

[0xA] Marco Ramilli's Blog: Steganography Tools - a non exhaustive survey

CAcert NEWS Blog

CAcert NEWS and up coming events.

[0x1] CAcert and secure-u e.V. on LinuxTag 2012

[0x2] OpenSSL gap in ASN1 parser

[0x3] ATE Karlsruhe, 2012-05-15

[0x4] CACert in the UK

[0x5] CAcert OA for The Document Foundation

[0x6] NLUUG spring conference

[0x7] ATE-Leipzig, 10. April 2012

[0x8] Maintenance / Changes infrastructure

[0x9] Piratenpartei Mecklenburg-Vorpommern im CAcert Organisation Assurance Program

[0xA] CACert and OpenPGP party at Madrid (Spain)

FaberBrent Security Blog

Security risk resilience TSCM debugging security news corporate espionage counter surveillance covert investigations counter terrorism ITSEC Bug sweeping

[0x1] The birth of the mobile phone and PCI payment

[0x2] Nearly half of Brits use the same password for all accounts

[0x3] $27 billion lawsuit could fold due to $50 covert surveillance device

[0x4] Shocking - The DWP do not keep records of how many times your data has been abused

[0x5] Met Police report shows CCTV costs £20,000 per single conviction - how many would an extra officer get per year?

[0x6] Charity offices bugged

[0x7] Mobile-phone handset complexity - the criminals friend.

[0x8] The security lessons from Britian's largest jewellery robbery

[0x9] Labour MP and Dutch VIP's suffer website data leaks found by a Google search

[0xA] Black-hatter shows how to utilise memory in Apple keyboard to create a hardware key-logger

Science | Mail Online

All the latest UK and international science and technology news, video and pictures from the Daily Mail and Mail on Sunday

[0x1] Analyst slaps 'SELL' rating on Facebook shares after proclaiming them 'implausibly priced' at trading debut

[0x2] Henry V's Welsh birthplace becomes world's first Wikipedia town... But will it be accurate?

[0x3] Facebook IPO: Mark Zuckerberg becomes $19billion wealthier as 100m shares sold in FIVE minutes

[0x4] It's coming! Apple registers iPhone5.com as sources reveal next phone will be the last model designed by Steve Jobs

[0x5] Google Maps project shows you how far the bus can take you in 30 minutes in major cities across the world

[0x6] Could fungi break down plastic and stop a very modern scourge?

[0x7] New iPhone app uses wireless sensor that lets your plants tell you if they are thirsty or too hot

[0x8] Pre-orders for Samsung Galaxy S3 phone shoot up to nine million - meaning phone will sell as many on first day as predecessor sold in six months

[0x9] China's first stealth jet goes from strength to strength as U.S. air technology falters (but is it just another Chinese rip-off?)

[0xA] Human-dolphin communication is one step closer: New marine speaker can recreate the animals' clicks and whistles

Info Security News

Carries news items (generally from mainstream sources) that relate to security.

[0x1] Obama Cybersecurity Czar Schmidt Steps Down

[0x2] How Stuxnet Came Back to Haunt the U.S.

[0x3] KSE site hacked on day of launching

[0x4] Fake Google Chrome Installer Steals Banking Details

[0x5] UK now a top ten nation for hacking traffic, logs show

[0x6] Chicago Police Department computers hacked?

[0x7] 'Dead Man Walking' Tricks Airport Into Giving Him Top Security Job

[0x8] Delete Data To Delete Risk

[0x9] Hong Kong CERT wants bigger team to tackle cyber threats

[0xA] After 7 Years, No End in Sight to Phone Hacking Scandal

Michael Howard's Web Log

A Simple Software Security Guy at Microsoft!

[0x1] Security Sessions at TechEd in Australia and New Zealand

[0x2] ATL, MS09-035 and the SDL

[0x3] Integrating the SDL process into Visual Studio

[0x4] A Conversation About Threat Modeling

[0x5] Ken Johnson (Skywing) joins Microsoft

[0x6] Free Download: Writing Secure Code for Windows Vista

[0x7] Secure software development practices 'not rocket science'

[0x8] A Proactive Approach to Building a Successful Security Development Lifecycle Program

[0x9] Improvements in Office Security

[0xA] Volume 5 of the Microsoft Security Intelligence Report is out

DEFCON Announcements!

DEFCON is the world's largest annual hacker convention, held every year in Las Vegas, Nevada. The first DEFCON took place in June 1993. DEF CON is renowned for the "arcane arts" of drinking, socializing, debugging, and crowd control. DEFCON is what you make of it, so get involved and help the community grow. This Feed will keep you up to date with some announcements surrounding pre and post con events, references to DEFCON in the news, and other errata. For the most up to date information visit or subscribe to the rss feeds on the forums (http://forum.defcon.org/) See http://www.defcon.org/ for more details, discussion forums, past speeches, and planning for the next year.

[0x1] DEF CON Extended Room Block at Rio is almost SOLD OUT!

[0x2] More Rooms at the Rio!

[0x3] Press Registration for DEF CON 20!

[0x4] Reminders and New Pre-con Calendar

[0x5] DEF CON 20 CTF Updates!

[0x6] DEF CON 20 Site is Live!

[0x7] 200 for 20

[0x8] The Crystal Method at DEF CON 20!

[0x9] Which Past Shirts Should We Re-print for DEF CON 20?

[0xA] Reboot Sneak Preview at DEF CON 20!

InfoSecPodcast.com

[0x1] New InfoSec positions open in Maine

[0x2] Cyber Janitors? Really?

[0x3] Taking SANS FOR610 malware forensics class

[0x4] APT and attribution

[0x5] McAfee acquires NitroSecurity

[0x6] Splunk Users Conference

[0x7] RIM fix your Blackberry S/MIME experience, please?

[0x8] My new job: Fighting APT at RSA

[0x9] Some things to look for in your SecurID / Remote Access logs

[0xA] Call for papers — eCrime Researchers Summit

ha.ckers.org web application security lab

Web Application Security Blog

[0x1] And Beyond…

[0x2] FAQ

[0x3] What’s Left?

[0x4] Mod_Security and Slowloris

[0x5] Minimalistic UI Decisions in Browsers

[0x6] Cheating Part 2

[0x7] Cheating Part 1

[0x8] FireSheep

[0x9] Detecting Malice With ModSecurity

[0xA] Performance Primitives

Computerworld - Security RSS feed

[0x1] Twitter jumps on Do Not Track bandwagon

[0x2] Facebook IPO stumbles out of the gate

[0x3] Android in enterprises 'severely limited' by weak management support from Google

[0x4] Final count down to Facebook's IPO begins

[0x5] Download the Insider Threat Deep Dive Report

[0x6] AusCERT 2012 in pictures: Day three

[0x7] AusCERT 2012: Four questions enterprises should ask Cloud providers

[0x8] AusCERT 2012 in pictures: Awards night

[0x9] AusCERT 2012: Star Wars and lasers feature at AusCERT awards

[0xA] Anonymous Takes Aim at Indian Government

good coders code, great reuse

Peteris Krumins' blog about programming, hacking, software reuse, software ideas, computer security, google and technology.

[0x1] Introduction to Perl one-liners

[0x2] A quine in node.js

[0x3] A poem about division from Hacker's Delight

[0x4] The curious case of the DES algorithm

[0x5] A proof that Unix utility "sed" is Turing complete

[0x6] Here is why vim uses the hjkl keys as arrow keys

[0x7] Announcing dedicated servers for Browserling

[0x8] Announcing my third e-book "Perl One-Liners Explained"

[0x9] How Browserling Works [art]

[0xA] Node.js modules you should know about: procstreams

HeapOverflow Computer Security Community & Forums : Heap Overflow.com

Computer security community with forums, blogs and directory covering exploit, vulnerability, advisory with various penetration testing tools.

[0x1] CVE-2011-3637 (linux_kernel)

[0x2] CVE-2011-4097 (linux_kernel)

[0x3] CVE-2011-4112 (linux_kernel)

[0x4] CVE-2011-4131 (linux_kernel)

[0x5] CVE-2011-4326 (linux_kernel)

[0x6] CVE-2011-4594 (linux_kernel)

[0x7] CVE-2011-4611 (linux_kernel)

[0x8] CVE-2011-4621 (linux_kernel)

[0x9] CVE-2012-0038 (linux_kernel)

[0xA] CVE-2012-0044 (linux_kernel)

US-CERT Technical Cyber Security Alerts

US-CERT Technical Cyber Security Alerts provide timely information about current security issues, vulnerabilities, and exploits.

[0x1] TA12-129A: Microsoft Updates for Multiple Vulnerabilities

[0x2] TA12-101B: Adobe Reader and Acrobat Security Updates and Architectural Improvements

[0x3] TA12-101A: Microsoft Updates for Multiple Vulnerabilities

[0x4] TA12-073A: Microsoft Updates for Multiple Vulnerabilities

[0x5] TA12-045A: Microsoft Updates for Multiple Vulnerabilities

[0x6] TA12-024A: "Anonymous" DDoS Activity

[0x7] TA12-010A: Microsoft Updates for Multiple Vulnerabilities

[0x8] TA12-006A: Wi-Fi Protected Setup (WPS) Vulnerable to Brute-Force Attack

[0x9] TA11-350A: Adobe Updates for Multiple Vulnerabilities

[0xA] TA11-347A: Microsoft Updates for Multiple Vulnerabilities

Securelist / Analysis

[0x1] Spam Report: April 2012

[0x2] Spam in Q1 2012

[0x3] Monthly Malware Statistics: April 2012

[0x4] The anatomy of Flashfake. Part 1

[0x5] Spam report: March 2012

[0x6] Monthly Malware Review, March 2012

[0x7] Spam report: February 2012

[0x8] Monthly Malware Statistics: February 2012

[0x9] Kaspersky Security Bulletin. Malware Evolution 2011

[0xA] Kaspersky Security Bulletin. Statistics 2011

CSOONLINE.com - Identity & Access

[0x1] Cloud computing tools: Improving security through visibility and automation

[0x2] Will your next car steal itself?

[0x3] Will Obama preside over the coming of Big Brother?

[0x4] How to meet the challenges of 21st century security and privacy

[0x5] Who should be at the root of protecting the nation's healthcare data?

[0x6] Securing your Board of Directors' communication portal

[0x7] APT in action: The Heartland breach

[0x8] A clear-eyed look at APT

[0x9] Securing Facebook: With a little help from his 800 million friends

[0xA] CSO's Ultimate Guide to Social Engineering

The RISKS Digest

The website of the RISKS mailing list

[0x1] City Misses $1.6M in Parking Tickets Because of Computer Glitch

[0x2] Computer Glitch Forces Johnson County Motor Vehicle Offices to Close

[0x3] Computer Glitch Gave Free Education To College Students

[0x4] Computer glitch hampers Alaska deer hunt reporting

[0x5] Computer glitch means NC jobless can't collect

[0x6] Hundreds of potential jurors mistakenly head to Placer County courthouse

[0x7] NJ toddler on no-fly list was mistakenly pulled from JetBlue flight

[0x8] Risks of financial models being gamed

[0x9] Top judge: ditching software patents a "bad solution"

[0xA] Computerized prescriptions to stop fraud -- what could go wrong?

Outscribe

All The Tech That Matters...

[0x1] Binatone iHomePhone 2 Is An Android Landline Phone No One Should Own

[0x2] Smart Battery Charger

[0x3] 128 MB Is Gigantic File Size For Microsoft

[0x4] Happy New Year 2011

[0x5] Android Infographic

[0x6] The Android Privacy Fuss

[0x7] The 47 Top Apps On My Android Phone

[0x8] [Updated] Yes, Google Is Testing Android Paid Apps In India

[0x9] Successful Migration of My Blog to WordPress

[0xA] Blog Under Maintenance – Update

The Register - Security

Biting the hand that feeds IT

[0x1] Apache OpenOffice security fixes emerge

[0x2] Call of Duty hacker jailed after meatspace burglary

[0x3] UK prosecutions for hacking appear to be be dropping

[0x4] Atlassian warns of critical security flaw

[0x5] Anonymous turns its DDoS cannons on India

[0x6] Governments may hit social networks with cyber attacks

[0x7] Seeing ads on Wikipedia? Then you're infected

[0x8] Council fined £70k after burglars nick vulnerable kids' files

[0x9] UK man to spend year in the clink for Facebook account hack

[0xA] Off-the-shelf forensics tool slurps iPhone data via iCloud

Techrights

Free Software Sentry – watching and reporting maneuvers of those threatened by software freedom

[0x1] Links 19/5/2012: Mandriva Linux Freed, New Linux Mint RC

[0x2] Apple Patent Wars Make Android Devices Less Attractive, Everyone Suffers

[0x3] Defeat for Software Patents in the United Kingdom

[0x4] BSA and IDC Systematically Lie to the Public, Distort Press Coverage

[0x5] Links 17/5/2012: “Bio Computer” Runs Linux, Raspberry Pi Grows

[0x6] IRC Proceedings: May 11th-May 16th, 2012

[0x7] IRC Proceedings: May 5th-May 10th, 2012

[0x8] IRC Proceedings: April 29th-May 4th, 2012

[0x9] Android Under Patent Attacks From Nokia, Microsoft, and Oracle

[0xA] Helping OpenSUSE is Helping Microsoft Tax GNU/Linux

Information Security Thoughts - Allen Baranov

A blog dedicated to thoughts about Information Security.

[0x1] Why the Privacy Bill is important to you!

[0x2] The Meaning of Life Part 1 - The Firewall

[0x3] Information Security Analyst Available.

[0x4] Google's Next Big Thing

[0x5] A great loss to the IT world. One of its great inventors dies.

[0x6] What are your rights regarding personal email? [Extra Bit]

[0x7] What are your rights regarding personal email?

[0x8] ITWeb Security Summit - Wrap Up [Part One]

[0x9] ITWebSec Tag Cloud part 2

[0xA] ITWebSec tag cloud

Security

Hacking everything, by Chris Evans / scarybeasts

[0x1] vsftpd-3.0.0 and seccomp filter sandboxing is here!

[0x2] vsftpd-3.0.0-pre2

[0x3] vsftpd-3.0.0-pre1 and seccomp filter

[0x4] On the failings of Pwn2Own 2012

[0x5] Some random observations on Linux ASLR

[0x6] Chrome Linux 64-bit and Pepper Flash

[0x7] The dirty secret of browser security #1

[0x8] Alert: vsftpd download backdoored

[0x9] libxml vulnerability and interesting integer issues

[0xA] Bug bounties vs. black (& grey) markets

Development & Integration White Papers

C Languages, EAI, Java, Visual Basic, and Web Design White Papers

[0x1] Insiders' Guide to Evaluating Remote Control Software

[0x2] Improving Application Development with Digital Libraries

[0x3] Introduction to The Most Popular Commercial Open Source Backup Software - Amanda Enterprise

[0x4] How Can I Back Up MySQL Database Without Killing Application Performance? NetApp and Zmanda Have the Answer.

[0x5] Achieving the Impossible- Unlimited Application Scalability

[0x6] Data Centre Transitions: UNIX to Linux

[0x7] Data Grids and Service  Oriented Architecture

[0x8] An Innovative Approach to Managing Software Requirements

[0x9] Using Virtualization to Maximize Your IT Environment

[0xA] Why Every Data Center Needs Automation

Zend Developer Zone (DevZone) - Advancing the art of PHP

advancing the art of PHP. Best practices, samples, articles, news, and community for PHP 4, PHP 5, and beyond.

[0x1] Zend Framework 2.0.0beta1 Released!

[0x2] Zend Framework 1.11.11 Released

[0x3] Announcing September's Zend Framework Bug Hunt Days

[0x4] ZendCon Early Bird Registration ends soon!

[0x5] Announcing the August 2011 Zend Framework Bug-Hunt

[0x6] Zend Framework 1.11.10 Released

[0x7] ZendCon '11 Alumni Discount

[0x8] Announcing July's Zend Framework Bug Hunt Days

[0x9] Zend Framework 1.11.9 Released

[0xA] Zend Framework 1.11.8 Released

security_watchdog

All the IT security issues that affect you and your business. Direct reports from all the security conferences throughout the year, including RSA conference and Infosec.

[0x1] Google: complete privacy 'does not exist'

[0x2] Kiwi hacker to work for police

[0x3] Data leaks worst security threat

[0x4] UK businesses still don’t ‘get’ security

[0x5] Storm worm fabricates news

[0x6] Road warriors leaking secrets

[0x7] Cyber-crooks sting South Africa for £13m

[0x8] Public wants data breach legislation

[0x9] Hong Kong becomes most dangerous domain

[0xA] Scammers targeting LinkedIn

kuro5hin.org

technology and culture, from the trenches

[0x1] How It Went Down, a Play in One Act

[0x2] A Girl's Guide to Sex with Dogs

[0x3] FreeBSD X: Berkeley Unix, Apple Quality

[0x4] The Cookie Problem: A Mathematical Satire

[0x5] Top Technologies of 2012 Cater to The Common Man

[0x6] Sandra Fluke Is A Fucking Slut

[0x7] Saying good-bye to an old friend: Michael David Crawford

[0x8] The Rock Star as Charismatic CEO - OK Go's "Needing/Getting" Video

[0x9] Crawford's calling, and he's calling you gay.

[0xA] MICHAEL DAVID CRAWFORD and ORION BLASTAR v GOOGLE

Dragos Lungu Dot Com | Security Tools And Tips

100% Unbiased Security Tools Reviews. Computer Security Blog about Phishing, Spyware, Malware and other Threats and Vulnerabilities we face everyday .

[0x1] Animated Presentation on Sony PSN Hack

[0x2] ArcSight Tip #1 – arcsight managersetup notification test

[0x3] I’m a CISSP

[0x4] Operation:Payback or Social Vendetta is Here

[0x5] I got owned by Malware Destructor 2011 Virus

[0x6] New Downtime Cost Calculator by Storagepipe.com. What if ?

[0x7] Securing Your Network from Web Threats

[0x8] My Twitter Notes on 2010-07-25

[0x9] New NetWitness Visualize : Welcome To The Future!

[0xA] My Twitter Notes on 2010-07-18

F5 White Papers

F5 white papers provide information on critical technology areas and how F5 products help you improve upon or prepare for their deployment.

[0x1] Enable a Scalable and Secure VMware View Deployment

[0x2] Application Delivery in the Cloud: Minimizing Disruption and Maximizing Control

[0x3] Building a CDN with F5

[0x4] Application Delivery Optimization

[0x5] Accelerating Mobile Access

[0x6] HP Cloud Map for F5 Networks BIG-IP: Importing the template | HP White Paper

[0x7] Inside the HP Cloud Map for F5 Networks BIG-IP | HP White Paper

[0x8] HP CloudSystem Enterprise | HP White Paper

[0x9] Boosting Operational Efficiency by Streamlining File Storage Management

[0xA] Oracle Enterprise Manager 12c Cloud Control: Configuring OMS High Availability with F5 BIG-IP Local Traffic Manager | Oracle White Paper

Famous Pete Wood Security

My friends tease me about my role in promoting First Base Technologies through public speaking, articles and interviews ... hence calling me 'Famous Pete Wood Security'

[0x1] User awareness

[0x2] Out of the Blue: Responding to New Zero-Day Threats

[0x3]

[0x4] Cloud Security Alliance UK & Ireland

[0x5] Cyber Security In Real-Time Systems and CNI

[0x6] Cloud Security Alliance UK and Ireland

[0x7] A Software Engineer, a Hardware Engineer and a Departmental Manager ...

[0x8] Festive Greetings

[0x9] Fighting malware in your browser

[0xA] Vote for us!

Edible Apple

Apple News, Rumors, and Analysis

[0x1] 11-year old boy pees on and destroys MacBooks

[0x2] About those MacBooks with the Retina Display

[0x3] Apple certifies display suppliers for upcoming 7.85 inch iPad – Report

[0x4] Aaron Sorkin to write Steve Jobs screenplay for Sony Pictures movie

[0x5] WSJ reports Apple already ordering 4-inch screens from Asian suppliers for next-gen iPhone

[0x6] Imports of HTC One X and Evo 4G LTE delayed pending Customs investigation resulting from ITC ruling

[0x7] iOS 6, Google Maps, and Siri for iPad

[0x8] Apple’s amazing new Maps app will “blow your head off”

[0x9] Siri gone wild! Claims the Nokia Lumia 900 4G is the best smartphone ever

[0xA] Apple eyeing 7.85-inch iPad in ~$200 range for October release

CSOONLINE.com - Security Career/Staffing

[0x1] Who should the CISO report to?

[0x2] RSA Conference 2012: Stress and burnout in infosec careers

[0x3] Is your definition of security holding you back?

[0x4] Three reasons why asking risky questions reduces risk

[0x5] Resume Makeover: How an Information Security Professional Can Target CSO Jobs

[0x6] 2011 Women of Influence award winners named

[0x7] How your signature can propel your security career

[0x8] Security technology or staffing gap: Which is the greater enterprise challenge?

[0x9] Hey, CSOs: Suck it up and accept budget cuts

[0xA] Finding security's opportunity to engage

Evilcodecave's Weblog

Just another RCE Weblog

[0x1] Definitively Moved to Blogspot

[0x2] Fast Overview of SpyEye

[0x3] Rootkit Agent.adah Anatomy and Executables Carving via Cryptoanalytical Approach

[0x4] PHP/Spy.Bull Cryptanalysis of Encryption used and Threat Analysis

[0x5] Siberia ExploitPack and PDF Exploit Analysis

[0x6] DNAScan Malicious Network Activity Reverse Engineering

[0x7] Avast aswRdr.sys Kernel Pool Corruption and Local Privilege Escalation

[0x8] PHPSpyScanBot Analysis

[0x9] [Crimeware] Researches Reversing about Eleonore Exploit Pack

[0xA] [Crimeware] Researches and Reversing about Eleonore Exploit Pack

CSOONLINE.com - Access Control

[0x1] Hospital system pursues identity-management Holy Grail

[0x2] Forrester outlines 5 rising, 5 declining security technologies

[0x3] Thwarted by security at enterprises, cyber criminals target SMBs

[0x4] BeyondTrust eyes app security with eEye acquisition

[0x5] U.S. seeking to build international unity around cyberdefense for industrial control systems

[0x6] Symplified eases move to cloud with identity, access management

[0x7] BeyondTrust acquires eEye in union of security vendors

[0x8] Will BYOD revive the network-access control idea? Gartner thinks it will

[0x9] How to fight back against privacy pirates

[0xA] Commercial enterprises are putting our critical infrastructure at risk

Jeremy's Brain Dump

Some worthless information from my brain.

[0x1] FISMA

[0x2] Access Controls Article

[0x3] PMP Equations

[0x4] Math

[0x5] What is security

[0x6] New Hosting

[0x7] WordPress 2.3 and Feedburn Widget

[0x8] So, what is a CISSP anyways?

[0x9] Upgrading the OS on my MythBox

[0xA] Blogs vs. Forums

extraexploit

[0x1] the last/final touch!

[0x2] DigiNotar facts - just some links

[0x3] Operation Shady RAT - HTran

[0x4] an old bug for a new job ? CVE-2004-0194

[0x5] TDSS - SRVs list

[0x6] DroidKungFu - just some piece of code

[0x7] FlashUtil10m_Plugin.exe command line crash

[0x8] cve-2011-0609 - bugix blog analysis

[0x9] mmspicture.ru - mobile malware depot

[0xA] Egypt Telecom back online– ASN8452 TE DATA– prefix 81.10.0.0/17

Veracode Security Blog: Application security research, security trends and opinions

Application security testing, analysis, and metrics

[0x1] Weekly News Roundup

[0x2] Privacy and Confidentiality on the Eve of the Facebook IPO

[0x3] Interview with Dan Guido at SOURCE Boston 2012 – Part 3

[0x4] Veracode’s Chris Wysopal Appointed to Black Hat’s Content Review Panel

[0x5] Interview with Dan Guido at SOURCE Boston 2012 – Part 2

[0x6] What is Data Integrity? Learn How to Ensure Database Data Integrity via Checks, Tests, & Best Practices

[0x7] Weekly News Roundup

[0x8] Interview with Dan Guido at SOURCE Boston 2012 – Part I

[0x9] Data Mining A Mountain of Zero Day Vulnerabilities – Webinar Q&A

[0xA] Cybersecurity Risks in Public Companies Infographic

Black Hat Announcements

Black Hat Digital Self Defense. Black Hat provides cutting edge content in the information and computer security field. Keep up to date with Black Hat presentations, announcements, and free content.

[0x1] Black Hat USA 2010 Training: Pentesting with Backtrack by Offensive Security

[0x2] Black Hat USA 2010 Training: Application Security: For Hackers and Developers

[0x3] Black Hat USA 2010 Training: Assaulting IPS

[0x4] Free Black Hat March Webcast - Pen Testing the Web with Firefox by Michael Schearer ("theprez98")

[0x5] Black Hat USA 2010 Registration Now Open!

[0x6] Black Hat USA 2010 Call for Papers Closes May 1

[0x7] Black Hat Europe 2010 Call for Papers Closes March 1

[0x8] Feb 18 Webcast

[0x9] Black Hat DC 2010 - News - Security chip that does encryption in PCs hacked

[0xA] Black Hat DC Keynote

ZDNet | Zero Day Blog RSS

[0x1] The Pirate Bay returns, Anonymous hater takes credit for DDoS

[0x2] Wikileaks has been under DDoS attack for the last three days

[0x3] Apple releases QuickTime 7.7.2 for Windows, fixes 17 flaws

[0x4] Anonymous denies it is behind The Pirate Bay DDoS attack

[0x5] The Pirate Bay hit with massive DDoS attack

[0x6] Android malware families nearly quadruple from 2011 to 2012

[0x7] Google Chrome 19 is out

[0x8] Wikipedia: If you see ads on our site, you have malware

[0x9] Avira Antivirus update cripples millions of Windows PCs

[0xA] Adobe about-face: Photoshop, Illustrator patches will be free

Physical Security

[0x1] DHS cybersecurity official leaves more questions than answers

[0x2] McAfee-Intel eye critical infrastructure protection

[0x3] Infosec experts speak out on natural gas pipeline attacks

[0x4] ICS-CERT alert: Natural gas pipelines under attack

[0x5] Need to report TSA abuse? There's an app for that!

[0x6] TSA or Secret Service: Which is worse?

[0x7] I was wrong about the TSA

[0x8] Apparent cyberattack hits Iranian oil facility

[0x9] #SOURCEBoston: Geer warns against 'all or nothing' approach to critical infrastructure and the Internet

[0xA] #TSA over-reaching, caught on video

Post Politics: Breaking Politics News, Political Analysis & More - The Washington Post

Post Politics from The Washington Post is the source for political news headlines, in-depth politics coverage and political opinion, plus breaking news on the Obama administration and White House, Congress, the Supreme Court, elections and more.

[0x1] The missing issue in the presidential campaign

[0x2] At Camp David, world leaders agree on more spending to boost Europe’s economy

[0x3] Hakeem Jeffries: Brooklyn’s Barack Obama?

[0x4] Sunday Talk Shows (5/19/12): Chicago NATO Summit, Paul Ryan, Meet the Press, Face the Nation, GPS and more

[0x5] Obama campaign working to counter new voter ID laws

[0x6] Conservative groups outspending liberal counterparts 4 to 1 on congressional races

[0x7] Mitt Romney’s claim that 100,000 auto jobs have been lost under Obama

[0x8] Scott Brown raising money off Elizabeth Warren Native American questions

[0x9] Birtherism isn’t dead

[0xA] Wisconsin recall slipping away from Democrats

Andy ITGuy - Information Security Blog

A voice of reason in a world of FUD

[0x1] Dealing with a business that doesn’t want you.

[0x2] Cudos to Apple

[0x3] Making A Change

[0x4] No place for dishonesty

[0x5] Book Review: America the Vulnerable

[0x6] SC Magazine Debate

[0x7] Breaking out of compliance management (part 1)

[0x8] Risk Management or Compliance Management

[0x9] OK Mr. Jobs…. You win

[0xA] Focus.com Security Awareness Roundtable

Boaz Gelbord

A look at information security management, spending in the security industry, and everything along the way.

[0x1] Comodo, RSA, and Security Priorities

[0x2] Security Scoreboard - Join the Conversation

[0x3] iPad and the Illusion of Privacy

[0x4] Napera selling security at the Google Apps Marketplace

[0x5] Flash Security Under the Microscope

[0x6] Google Secure Search and Security Overkill

[0x7] Facebook and Security Minimalism

[0x8] Application Security Underfunded

[0x9] Security Scoreboard is Live!

[0xA] Mass Security Regulation Gets Tech Priorities Wrong

Oracle Security Alerts

Security Alerts Issued by Oracle

[0x1] Oracle Security Alert for CVE-2012-1675

[0x2] Oracle Critical Patch Update (CPU) Advisory - April 2012

[0x3] Oracle Java SE Critical Patch Update Advisory - February 2012

[0x4] Oracle Security Alert for CVE-2011-5035

[0x5] Oracle Critical Patch Update (CPU) Advisory - January 2012

[0x6] Oracle Critical Patch Update (CPU) Advisory - October 2011

[0x7] Oracle Security Alert for CVE-2011-3192

[0x8] Oracle Critical Patch Update (CPU) Advisory - July 2011

[0x9] Oracle Java SE Critical Patch Update Advisory - June 2011

[0xA] Oracle Critical Patch Update (CPU) - April 2011

CSOONLINE.com - Security Industry

[0x1] Thwarted by security at enterprises, cyber criminals target SMBs

[0x2] Companies slow to react to mobile security threat

[0x3] Let's not bicker and argue about who killed who

[0x4] How to sneak into a security conference

[0x5] RSA Conference 2012: Stress and burnout in infosec careers

[0x6] RSA Conference 2012 sneak peek: cloud, big data, and mobile

[0x7] Industry on Cybersecurity Act of 2012: Not so fast

[0x8] SOPA, PIPA, Anonymous: Can I have a little hope?

[0x9] Managing information security during an innovation void

[0xA] Open Data Center Alliance working on cloud usage models

Fortinet Security Blog

The latest news and information about Fortinet products and services for Real Time Network Protection.

[0x1] Partnerships Vital In Cybercrime Crackdowns

[0x2] Security Week In Review, May 7-11

[0x3] Securing Your Virtual Environment: A Lowdown

[0x4] Microsoft, Adobe Issue One-Two Punch With May Security Updates

[0x5] Security Week In Review, April 30-May 5

[0x6] Okay, You’ve Got Malware–Now What?

[0x7] The Cybersecurity Bill Alphabet Soup: A Guide

[0x8] Security Week In Review, April 23-27

[0x9] Are Today’s Teens, Tomorrow’s Cybercriminals?

[0xA] Advanced Persistent Threats: A Breakdown

Bugtraq

The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!

[0x1] New Open Source Web Application Vulnerability Scanner Available

[0x2] SEC Consult SA-20120518 :: Memory overwrite vulnerability in libwpd (OpenOffice.org) - CVE-2012-2149

[0x3] H2HC Brazil 9th Edition - Call for Papers

[0x4] Re: [oss-security] CVE Request: Planeshift buffer overflow

[0x5] Re: [oss-security] CVE Request: Planeshift buffer overflow

[0x6] [SECURITY] [DSA 2475-1] openssl security update

[0x7] [security bulletin] HPSBOV02780 SSRT100766 rev.1 - HP OpenVMS ACMELOGIN, Local Unauthorized

[0x8] Re: [oss-security] CVE Request: Planeshift buffer overflow

[0x9] [SECURITY] [DSA 2474-1] ikiwiki security update

[0xA] DDIVRT-2012-44 Epicor Returns Management SOAP-Based Blind SQL Injection

lkml.org

lkml.org - the realtime linux kernel mailinglist archive

[0x1] Re: [PATCH 08/10] Use __kernel_ulong_t in struct msqid64_ds

[0x2] [PATCH] x86/mce: Fix check for processor context when machine chec ...

[0x3] [PATCH] net/ipv4: replace simple_strtoul with kstrtoul

[0x4] [PATCH] net/ipv4/ipconfig: neaten __setup placement

[0x5] Re: [PATCH 08/10] Use __kernel_ulong_t in struct msqid64_ds

[0x6] Re: Plumbers: Tweaking scheduler policy micro-conf RFP

[0x7] Re: Plumbers: Tweaking scheduler policy micro-conf RFP

[0x8] Re: [PATCH] regulator: core: use correct device for device supply ...

[0x9] Re: Plumbers: Tweaking scheduler policy micro-conf RFP

[0xA] Re: [PATCH] USB CDC-Ether - Add ZTE WWAN matches before generic Et ...

Network World on Spam

The latest spam and anti-spam news and analysis from NetworkWorld.com

[0x1] Feds draw a bead on Russian behind Mega-D botnet

[0x2] Ransomware Attack Resurfaces to Hold Files Hostage

[0x3] Adobe Reader X Makes PDF Files Safer

[0x4] McAfee Reports Malware at All-Time High

[0x5] PayPal Users Beware of Holiday Phishing Scam

[0x6] Phishing Attack Targets Merchant Accounts

[0x7] Secure a PC, Website From Firesheep Session Hijacking

[0x8] Is Microsoft Crossing the Line With Security Essentials

[0x9] In-Depth Look at Boonana Malware

[0xA] Phishing Scam Targets United States Military Members

CSOONLINE.com - Security Awareness

[0x1] Ten commandments for effective security training

[0x2] Cloud providers need to step up on security, say analysts

[0x3] Making the case for preventing workplace violence

[0x4] Is your definition of security holding you back?

[0x5] Three reasons why asking risky questions reduces risk

[0x6] Tide turns against SOPA, but it's not dead yet

[0x7] Managing information security during an innovation void

[0x8] 4 spear-phishing hooks for the holidays

[0x9] How your signature can propel your security career

[0xA] 9 secrets of getting stuff done in a big company

Techworld.com security

Latest IT articles from Techworld's security channel

[0x1] Metropolitan Police get rapid mobile phone analysis system

[0x2] Metropolitan Police gets rapid smartphone analysis system

[0x3] Java and Flash vulnerabilities being exploited by cyber spies

[0x4] Cybercriminals honing Android malware skills in Russia

[0x5] Hackers behind Flashback click fraud campaign haven't been paid

[0x6] Security services among top employers IT students want to work for

[0x7] UK now a top ten nation for hacking traffic, logs show

[0x8] Anonymous hater claims responsibility for Pirate Bay DDoS attack

[0x9] UK man jailed for hacking a private Facebook account

[0xA] HP, CSC and EMC open cybersecurity research centre in Berlin

Hacking Evolution

Another Hackers' Ranting Space

[0x1] Cyber Dawn: Libya

[0x2] Kill all Chrome/Chromium renderer and plugin processes on Linux

[0x3] Sagittarius: PHP Code Obfuscater

[0x4] Your Time Is Almost Up

[0x5] SHRED: Usability Vs. Philosophy

[0x6] Resolved: Facebook Unsubscribe All

[0x7] SCAF And The Revolution

[0x8] Egypt’s Constitution Referendum

[0x9] libgcrypt C++ Wrapper

[0xA] C++ trick or treat

Leadership 101

Enhancing Global Leadership from the Inside-Out.

[0x1] Leadership Transferability...

[0x2] Growing Your Seeds... Part III

[0x3] Growing Your Seeds... Part II

[0x4] Growing Your Seeds...

[0x5] Your People... Part III

[0x6] Your People... Part II

[0x7] Your People...

[0x8] Building That Institution... Part III

[0x9] Building That Institution... Part II

[0xA] Building That Institution...

Wilders Security Forums

This is a Computer Security discussion forum.

[0x1] Is it ok to disable V-sync on a Laptop/LCD

[0x2] Intermittant problems with HTTPS with 5.2x

[0x3] Google in bed with CIA + NWO = Fact

[0x4] Returnil not booting-paid version

[0x5] Is it possible to install Android over iOS on an iPad 2?

[0x6] still getting the eset error message popping up

[0x7] How to transfer /save contents of Sandbox (all files)

[0x8] ClamAV defs updates 19 May 2012

[0x9] McAfee Daily defs updates 5/19/2012

[0xA] New to ESET

Internet Security News - SecurityProNews

Breaking news and top stories from the world of Internet security.

[0x1] Facebook Becomes A Favorite Target Of Phishers

[0x2] Google Goes After Impersonator Scammers

[0x3] Senate Uncovers Online Credit Card Tricks

[0x4] McAfee: Cyberwarfare A Big Threat

[0x5] ICSA Labs Finds Flaws In New Security Products

[0x6] Nigeria Announces Early Results Of Anti-Scammer Initiative

[0x7] MessageLabs Names Most- (And Least-) Spammed States

[0x8] Enormous Malware Archive Creates Stir

[0x9] Avsim Hacker (Maybe) Brought Before Cops

[0xA] Email Password Hackers Present Real Threat

Learning Solaris 10

Check out the Zones F.A.Q. !

[0x1] CentOS 3.9 running in an lx branded zone

[0x2] OpenSolaris & Sun Secure Global desktop

[0x3] Opensolaris & wifi Broadcom BCM4312 on Dell Vostro 1710

[0x4] Security Advantages of the Solaris Zones Software

[0x5] Understanding the Security Capabilities of Solaris Zones Software

[0x6] New blueprint over the M-Series servers configuration

[0x7] Sun Forums: A Sun Java System Web Server 7.0 Reference Deployment

[0x8] Network virtualization in Solaris : project Crossbow

[0x9] Setting Up OpenDS 1.0.0 as a Naming Service

[0xA] Sun Fire X4500 as a Media Server for Symantec Veritas NetBackup 6.5

SecuraBit

Before It Bytes!

[0x1] SecuraBit Episode 104: Cackalacky Goodness!

[0x2] SecuraBit Episode 103: Pockets full of Ownsies

[0x3] SecuraBit Episode 102: The Last Train

[0x4] RichSec April Monthly Meeting

[0x5] RVASec: Richmond VA’s first Security Conference!

[0x6] SecuraBit Gh0st PenLab Closed Beta!

[0x7] SecuraBit Episode 101: The Survey Says!

[0x8] SecuraBit Episode 100: Double Header with WPS and Forensics!

[0x9] Episode 100 Tonight!!

[0xA] SecuraBit Episode 99: 99 Bottles of Pwn on the Wall!

CSOONLINE.com - Malware/Cybercrime

[0x1] Cyber warfare in sights at government training conference

[0x2] Will voluntary cyber threat sharing plan cast doubt over CISPA?

[0x3] Android hackers honing skills in Russia

[0x4] Cyber spies exploiting Java, Flash flaws

[0x5] Wikipedia warns users about malware injecting ads into its pages

[0x6] New Zeus malware scam promises rebates, security

[0x7] 10 hacks that made headlines

[0x8] Thwarted by security at enterprises, cyber criminals target SMBs

[0x9] Kaspersky denies it's working with Apple on Mac security

[0xA] Public vs. private cyberattack responsibility debate heats up

Securitas Operandi™

Incorporating security and risk into everyday thought.

[0x1] Risk assessment the key to budgeting security resources

[0x2] Cloud based solutions bring disaster recovery within reach of small business

[0x3] Why the security war will never be won

[0x4] Cloud service providers and the U.S. PATRIOT Act

[0x5] Block Javascript in Adobe Acrobat

[0x6] Why Disaster Recovery Requires a Plan

[0x7] What does a network scanner bring to the company?

[0x8] Demystifying UTM and NGF

[0x9] Threats

[0xA] Healthy Skepticism Required When Using Online Storage

Syrinx Technologies Podcasts

Interviews with local, regional and international technology experts on various topics.

[0x1] Application Development in a Web 2.0 World

[0x2] Ingredients for a Successful Disaster Recovery Plan

[0x3] Security & Web Facing Applications

[0x4] Different Approaches to SSO

[0x5] Story as Brand

[0x6] Effective Network Management Strategies

[0x7] HIPAA Privacy and Security

[0x8] What’s Wrong with the Federal, State and Local Budget Process

[0x9] Business Continuity Planning

[0xA] Identity Federation and Compliance

Exploit Files ≈ Packet Storm

Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers

[0x1] Vanilla 2.0.18.4 Cross Site Scripting

[0x2] Vanilla Latest Comment 1.1 Cross Site Scripting

[0x3] Vanilla About Me 1.1.1 Cross Site Scripting

[0x4] Oracle Weblogic Apache Connector POST Request Buffer Overflow

[0x5] Squiggle 1.7 SVG Browser Java Code Execution

[0x6] PHP 5.4 Win32 Code Execution

[0x7] HP VSA Command Execution

[0x8] SkinCrafter 3.0 Buffer Overflow

[0x9] Cryptographp Local File Inclusion / HTTP Response Splitting

[0xA] Division 6 IT SQL Injection / Cross Site Scripting

Tony Bradley

Technology in Plain English

[0x1] How to Avoid Rogue Security Software

[0x2] What’s a Rogue – And Why Do You Need to Know?

[0x3] Top 10 Ways Computer Security Will Improve in 2010 (Not!)

[0x4] The Year in Malware–A 2009 Review

[0x5] Taking Steps to Protect the Network on Cyber Monday

[0x6] November 2009

[0x7] White Paper: Panda Cloud Protection

[0x8] Facebook and Twitter Phishing Attacks

[0x9] Become a Fan, Win a 1Tb ioSafe Drive

[0xA] Record-Setting Patch Tuesday from Microsoft and Adobe

CSOONLINE.com - Global Security

[0x1] Will voluntary cyber threat sharing plan cast doubt over CISPA?

[0x2] Public vs. private cyberattack responsibility debate heats up

[0x3] Does 'stand your cyberground' stand a chance?

[0x4] APT in action: The Heartland breach

[0x5] Naming names in APT

[0x6] Getting stuff done: Public vs private sector edition

[0x7] Defense against dark arts: Your multidisciplinary security quiz

[0x8] Bad new world: Cyber risk and the future of our nation

[0x9] 5 secrets to building a great security team

[0xA] Lessons in security leadership: David Komendat

Deb Shinder's Blog

Deb Shinder is MS SECURITY. An Enterprise Security MVP, she has the “inside story” on all topics related to securing Microsoft networks, from the server all the way down to the network-connected smart phone. Her blog will address Microsoft’s security products and technologies including those built into the operating system (access controls and permissions, EFS, BitLocker, etc.), network security technologies (Active Directory, IPsec, DirectAccess, etc.) and separate security products (ISA Server/TMG, IAG, ILM and the Forefront family of client and server security products and services). This blog focuses on how network administrators and network security specialists can create a multi-layered security strategy, develop sound security policies, and build a strong line of defense around the network to prevent both internal and external attack.

[0x1] Would a .secure top-level domain make the Internet safer?

[0x2] Chrome 19 fixes 20 security flaws

[0x3] Adobe changes mind about free security fixes

[0x4] Hosting providers losing half of capacity to bots

[0x5] IT security professional failing on risk strategies

[0x6] APT attackers using booby-trapped RTF docs

[0x7] Is the Cloud the solution to SMB security woes?

[0x8] Antivirus update gone seriously wrong

[0x9] Free BlackHat Webinar: Making Life Difficult for Malware

[0xA] Ten ways to secure a Windows file server

SANS Internet Storm Center, InfoCON: green

[0x1] PHP 5.4 Remote Exploit PoC in the wild, (Sat, May 19th)

[0x2] ZTE Score M Android Phone backdoor, (Fri, May 18th)

[0x3] ISC StormCast for Friday, May 18th 2012 http://isc.sans.edu/podcastdetail.html?id=2545, (Fri, May 18th)

[0x4] ISC Feature of the Week: Tools->Information Gathering, (Thu, May 17th)

[0x5] New IPv6 Video: IPv6 Router Advertisements https://isc.sans.edu/ipv6videos, (Thu, May 17th)

[0x6] Do Firewalls make sense?, (Thu, May 17th)

[0x7] ISC StormCast for Thursday, May 17th 2012 http://isc.sans.edu/podcastdetail.html?id=2542, (Thu, May 17th)

[0x8] Reserved IP Address Space Reminder, (Wed, May 16th)

[0x9] Avira Antivirus false positives http://forum.avira.com/wbb/index.php?page=Thread&threadID=144875, (Wed, May 16th)

[0xA] New Version of Google Chrome released (19.0.1084.46) , (Wed, May 16th)

Room362.com RSS Feed

Blog

[0x1] phDays in Moscow

[0x2] How to Win CCDC - Slides

[0x3] Who is on your dream team red team?

[0x4] Developing the LNK Metasploit post module with Mona

[0x5] MS08_068 + MS10_046 = FUN UNTIL 2018

[0x6] A @textfiles approach at gathering the world's DNS - Slides

[0x7] (UAC) User Assisted Compromise

[0x8] Hak5 Segment Sneak Peak

[0x9] Shared Links

[0xA] Hash Types for John the Ripper

SearchSecurity: Threat Monitor

Tactical advice on defending against current threats, including viruses, worms, spyware and bots.

[0x1] Securely implement and configure SSL to ward off SSL vulnerabilities

[0x2] How to prevent a WPS flaw from damaging enterprise wireless security

[0x3] DoS attack responses demand better business continuity plans

[0x4] Web-facing applications: Mitigating likely Web application threats

[0x5] Securing the SIEM system: Control access, prioritize availability

[0x6] How to ensure data security by spotting enterprise security weaknesses

[0x7] Carrier IQ software: A big risk to enterprise mobile security?

[0x8] Duqu malware advice: Should enterprises worry about the Duqu Trojan?

[0x9] How to implement an enterprise threat assessment methodology

[0xA] Malware on a Mac: How to implement a Mac antimalware program

OVAL News

OVAL news headlines for the latest compatible products, data and schema updates, upcoming conferences, new Web site features, OVAL in the news, etc.

[0x1] Positive Technologies Posts OVAL Adoption Questionnaire to Become Official OVAL Adopter

[0x2] Positive Technologies Makes Declaration to Adopt OVAL

[0x3] Positive Technologies Now Listed on "Other Repositories" Page

[0x4] Registration Now Open for Security Automation Developer Days 2012 on July 9-13

[0x5] OVAL Interpreter Updated to Version 5.10.1.2

[0x6] OVAL Board Holds Teleconference Meeting

[0x7] OVAL Language "Sandbox" Now Available

[0x8] Draft of OVAL Language UNIX Component Data Model Specification Now Available

[0x9] OVAL Repository Announces Top Contributors Awards for Q1-2012

[0xA] New OVAL Board Member

CSOONLINE.com - Identity Management

[0x1] Symplified eases move to cloud with identity, access management

[0x2] Who should be at the root of protecting the nation's healthcare data?

[0x3] Trust me!

[0x4] Managing the unmanageable

[0x5] How the Red Cross found its ID management groove

[0x6] Watching the watchers

[0x7] 10 identity management metrics that matter

[0x8] Digitized medical records are easy prey, but all is not lost

[0x9] Automating and securing file transfers: key issues

[0xA] Leverage government innovation to reduce the risks of Web 2.0 identity management

dropsafe

network security, unix and bicycles

[0x1] GET SPOCK UP HERE! # #pratchett meets #trek

[0x2] Vodka Martini: Vodka, Vermouth, Olive; Vodka Gibson: use an Onion; Vodka Muffett: use Pickled Garlic

[0x3] Botching the Bomb | Foreign Affairs

[0x4] What I think is wrong with #VRM – HT @nzn @glynmoody @windley @dsearls @adriana872

[0x5] “JESUS also suffered from GOVERNMENT CUTS” # should have gone on strike, then.

[0x6] Dinner: poached goose egg on warm baguette, french butter; vodka martini.

[0x7] Just in case anyone thinks that Internet trolls and timewasters are a new phenomenon…

[0x8] Express.co.uk :: We’re the new naughty novelists # La Express reports on the British #CottageErotica industry

[0x9] Law banning insulting language ‘is strangling free speech’ – Telegraph

[0xA] #India blocks #Pastebin? Great way to kill off the tech boom in #Bangalore, guys #whoohoo #IndiaTechSuicide

InformationWeek - All Stories And Blogs

InformationWeek

[0x1] Sailing Mystery Unsolved: Court Declares Jim Gray Dead

[0x2] Oh, Facebook, Why Can't I Quit You?

[0x3] New FBI Surveillance Backdoors? 6 Key Points

[0x4] Twitter Adds Do Not Track Capability

[0x5] Nokia Burning Cash, But AT&T Has Hope

[0x6] Facebook's History: From Dorm To IPO Darling

[0x7] Samsung Racks Up 9M Galaxy S III Preorders

[0x8] InformationWeek's RSS Feed is brought to you by

[0x9] Salesforce.com Reports Torrid Q1 Growth, Slams SAP

[0xA] HP Layoffs Signal Punishing Fall

The Hacker Academy

[0x1] Search Engine Hacking- A Students Perspective

[0x2] FOCA – Reconnaissance Complete

[0x3] Reporting: The Difference Between Good and Great Penetration Testers

[0x4] Network Intelligence- A students perspective

[0x5] Business Intelligence- A Students Perspective

[0x6] Professional Penetration Testing

[0x7] The Mind Of A Hacker- A Students Perspective

[0x8] Security Fundamentals- A Students Perspective

[0x9] The Hacker Academy from a student’s perspective- The set up

[0xA] Special THA Panel Discussion Webinar: Vulnerability Research Reporting

Security University 2011 Class Schedule

2011 Security University Classes

[0x1] CISSP® Prep/The Official SU CISSP® Prep Class

[0x2] Q/EH® Qualified/ Ethical Hacker Class - Enroll Now!

[0x3] Q/SA® Qualified/ Security Analyst Penetration Tester Certification w/ Q/PTL® License - Enroll Now!

[0x4] Q/FE® Qualified/ Forensic Expert - Enroll Now!

[0x5] Q/ND® Qualified/ Network Defender - Enroll Now!

[0x6] Q/NSP® Qualified/ Network Security Policy Admin and SOA Security Oriented Architect - Enroll Now!

[0x7] Q/AAP® Qualified Access, Authentication and PKI Professional - Enroll Now!

[0x8] CWNA™/CWSP™ Boot Camp - Enroll Now!

[0x9] Q/WAD® Qualified/ Wireless Analyst and Defender - Enroll Now!

[0xA] Q/SSE® Qualified/ Software Security Expert Cert. - Enroll Now!

Network Security Podcast

[0x1] The Network Security Podcast, Episode 277

[0x2] The Network Security Podcast, Episode 276

[0x3] Network Security Podcast, Episode 275

[0x4] Network Security Podcast, Episode 272v2

[0x5] Network Security Podcast, Episode 274

[0x6] Network Security Podcast. Episode 273

[0x7] Third times a charm?

[0x8] Network Security Podcast, Episode 272

[0x9] Network Security Podcast, Episode 271

[0xA] Network Security Podcast, Episode 270

The RISKS Forum

Peter G. Neumann moderates this regular digest of current events which demonstrate risks to the public in computers and related systems. Security risks are often discussed.

[0x1] Risks Digest 26.84

[0x2] Risks Digest 26.83

[0x3] Risks Digest 26.82

[0x4] Risks Digest 26.81

[0x5] Risks Digest 26.80

[0x6] Risks Digest 26.79

[0x7] Risks Digest 26.78

[0x8] Risks Digest 26.77

[0x9] Risks Digest 26.76

[0xA] Risks Digest 26.75

SecTechno

Information Security Blog

[0x1] Infosec Weekly Round-up May 07 – 13 , 2012

[0x2] New Release for the WiFi Pineapple Hotspot

[0x3] USB Safeguard Utility to Encrypt and Protect USB Data

[0x4] Infosec Weekly Roundup April 30 – May 6, 2012

[0x5] Try App Whitelisting to Mitigate Malware

[0x6] AVG Describes the Blackhole Kit as Most Active Threat on the Web

[0x7] Infosec Weekly Round-up April 23 – 29 , 2012

[0x8] Fake Email Trick aims to Redirect Users to Malicious websites

[0x9] App Permission Watcher Android Tool to Display Application Security Level

[0xA] Malware Hits the Iranian Oil Terminal

CSOONLINE.com - Data Protection

[0x1] IT students aim for the security services

[0x2] BlackBerry 7 gets security approval from government

[0x3] US firms over-reliant on firewalls to defend against DDoS attacks

[0x4] Anonymous Takes Aim at Indian Government

[0x5] Doctors warned not to use social media with patients

[0x6] HP, CSC and EMC open cybersecurity research centre

[0x7] The Pirate Bay suffers DDoS attack

[0x8] Paging Mr. Phelps: This SSD will self-destruct....

[0x9] UK man jailed for Facebook hack

[0xA] Hospital system pursues identity-management Holy Grail

Security Database

[0x1] Security-Database is now CWE Compatible !

[0x2] Security-Database is now CVE Compatible !

[0x3] Security-Database update is database by adding ExploitDB

[0x4] New Vendors integration HP & VMware

[0x5] Officially OVAL Adopter

[0x6] New vDNA WebService : CVSS v2 Calculator

[0x7] Security-Database OVAL Repository Update

[0x8] Security-Database vDNA API Documentation

[0x9] Security-Database is proud to bring you this new service : vDNA

[0xA] Complemento v0.7.6 - Collection of Tools

Securelist / Glossary

[0x1] Kaspersky Security Network (KSN)

[0x2] Toolkit

[0x3] ITW (In-the-Wild) samples

[0x4] Crimeware

[0x5] Keylogger

[0x6] World Wide Web

[0x7] WildList

[0x8] WiFi

[0x9] Whitelist

[0xA] Web browser

Juniper

Juniper RSS Feed

[0x1] Juniper’s New Network Platform Architecture

[0x2] Signature Update #2137

[0x3] The old wall is crumbling

[0x4] Signature Update #2136

[0x5] Signature Update #2135

[0x6] Signature Update #2134

[0x7] Quick Facts about vGW Antivirus and IDS

[0x8] IBM, Juniper, and open data center architectures – our shared view

[0x9] Signature Update #2133

[0xA] Juniper Supports Open Source Cloud Computing

(IN)SECURE Magazine Notifications RSS

Notifications of new (IN)SECURE Magazine issues.

[0x1] (IN)SECURE Magazine special issue: RSA Conference 2012

[0x2] (IN)SECURE Magazine Issue 33

[0x3] (IN)SECURE Magazine Issue 32

[0x4] (IN)SECURE Magazine Issue 31

[0x5] (IN)SECURE Magazine Issue 30

[0x6] (IN)SECURE Magazine Issue 29

[0x7] (IN)SECURE Magazine Issue 28

[0x8] (IN)SECURE Magazine Issue 27

[0x9] (IN)SECURE Magazine Issue 26

[0xA] (IN)SECURE Magazine Issue 25

Techworld.com operating-systems

Latest IT articles from Techworld's operating-systems channel

[0x1] How to delete linked calendar entries in Android

[0x2] How delete linked calendar entries in Android

[0x3] Developers, busy with Ice Cream Sandwich, not holding back for Android 5

[0x4] Apple updates Mac OS X 10.8 Mountain Lion Developer Preview

[0x5] Firefox on Windows RT 'probably not worth it'

[0x6] Firefox on Window RT 'probably not worth it'

[0x7] Microsoft battles PC bloat with new Signature tune-up

[0x8] Ubuntu Business Desktop Remix gets 12.04 'Precise Pangolin' update

[0x9] Android 5.0 'Jelly Bean' autumn launch will be on Google devices first

[0xA] Windows 8 to offer enhanced multi-screen working

2600: The Hacker Quarterly

Off The Hook and Off The Wall

[0x1] Off The Hook show for May 16, 2012

[0x2] Off The Wall show for May 15, 2012

[0x3] HELP US COMPILE THE 2013 HACKER CALENDAR

[0x4] SPRING ISSUE OF 2600 RELEASED

[0x5] VOLUME 1 OF 2600 NOW ONLINE - DRM FREE - IN KINDLE, NOOK, AND PDF FORMATS

[0x6] HOPE TICKET SALES TO BENEFIT ELECTRONIC FRONTIER FOUNDATION

[0x7] RICHARD O'DWYER STORY TO BE FEATURED ON 'OFF THE HOOK'

[0x8] THE YES MEN ON 'OFF THE HOOK' TONIGHT

[0x9] RADIO ARCHIVE NOTES

[0xA] THE YES MEN TO KEYNOTE AT HOPE NUMBER NINE

SOURCE Conference Blog

Boston - Seattle - Barcelona

[0x1] SOURCE Boston 2012 News!

[0x2] The SOURCE Barcelona Apartment Experience

[0x3] links for 2011-08-08

[0x4] When In Rome (Or When At Caesars…)

[0x5] Call For Papers on Software Static Analysis

[0x6] THE Security Problem is Scale

[0x7] “We Don’t Sell It? Then It’s Not Important”

[0x8] Mobile Security – Users Just Don’t Care

[0x9] SOURCE Seattle, ho!

[0xA] Possible PlayStation Network Attack Vectors

Electronic Frontiers Australia

Representing Internet users concerned with on-line freedoms and rights

[0x1] EFA supports mandatory data breach notification

[0x2] EFA congratulates iiNet on its historic High Court victory

[0x3] Federal Court decision highlights need for flexible right of fair use in Copyright Act

[0x4] Planned US anti-piracy laws a draconian mess

[0x5] Melbourne event: War on the Internet

[0x6] In principle support of R18+ rating for video games

[0x7] New domain names on the way

[0x8] EFA News

[0x9] Conroy: Filter alive and kicking

[0xA] EFA Welcomes R18+ games guidelines

Hacked Gadgets - DIY Tech Blog

Many articles about hacking gadgets. Examples of extreme technology. DIY projects describing how to build electronic projects. Fun top 5 and top 10 lists.

[0x1] Constant Current Dummy Load Project

[0x2] Name the Thing Contest – 204

[0x3] Heavylift Hexacopter Build

[0x4] Light Trikes at the Bay Area Maker Faire

[0x5] WiiCube

[0x6] DIY Sous-Vide Cooker

[0x7] Open Hardware High Resolution 3D Printer

[0x8] Robot Motor Control

[0x9] Alan Parekh Interview on EEWeb

[0xA] Self Balancing Robot using the Microchip dspic33f

PacketWars

Attack. Defend. Survive.

[0x1] 2012 Resolutions

[0x2] PacketWars Innagural Battle In Germany 2011

[0x3] Heading To The Heidelberg

[0x4] See the Action

[0x5] PacketWars Confirmed At Troopers11

[0x6] Online News: Help Net Security

[0x7] Day-Con IV Content Added to Flickr [THX FLO]

[0x8] And the winner is…

[0x9] Tornado Warning: Cyber Storm III

[0xA] Day-Con IV Promo Video

Episteme: Belief. Knowledge. Wisdom

[0x1] How to Quickly Create New Habits in Your Life

[0x2] Matching and Mirroring (or: Cybernetic Issues in NLP)

[0x3] My Newest Experiment – The Kindle Book

[0x4] Maturity and Business

[0x5] What is it to be Mature?

[0x6] A Branding MAD Lib

[0x7] Suppressing Dissent

[0x8] Byron (and influence through the media)

[0x9] Influence and Failing Kindergarten

[0xA] Return-to-Barry-White Human Exploitation

Voice+Data RSS Feed

Aggregate RSS Feed

[0x1] Preparing your network infrastructure for UC collaboration and video deployment

[0x2] Schneider Electric StruxureWare Data Centre Operation Suite v7.1 DCIM software

[0x3] BitCloud gains VMWare Enterprise Partner status

[0x4] Allied Telesis AT-8100 Series switches

[0x5] Monitoring the effects of high bandwidth videoconferencing on the network

[0x6] Eaton enclosure power distribution units (ePDU)

[0x7] How to mitigate damage from a distributed denial of service (DDoS) attack

[0x8] IEI Technology Icefire Mobile Clinic Assistant compact tablet PC

[0x9] Medibank’s Dave Buckmaster on the importance of IT uptime

[0xA] Ruckus WLAN powers 600 clients at Google’s Think Mobile 2011 event

Layer 7 Technologies

Layer 7 Technologies markets a family of XML appliances and software to secure, simplify and scale Web services.

[0x1] New Article - Layer 7 Expands into Dutch Market with ION-IP Partnership - ChannelWeb

[0x2] New Press Release - Working Opportunity Fund makes follow on investment in Layer 7 Technologies (February 2, 2009)

[0x3] New Award - 2009 Ready to Rocket List - Rocketbuilders

[0x4] Watch VP Marketing & Alliances, Dimitri Sirota, interviewed by Sys-Con.TV at JavaOne Conference in June, 2008.

[0x5] New Press Release - SOA Consortium Releases New Podcast from K. Scott Morrison, Layer 7 Technologies, on How to Fail at SOA (August 18, 2008)

[0x6] New Press Release - Layer 7 Joins SOA Consortium as Silver Sponsor (June 30, 2008)

[0x7] New Article - Layer 7 Nominated for SYS-CON's "SOA World Magazine Readers' Choice Awards": The SecureSpan XML Networking Gateway Nominated for "Best Security Solution" - SOA World

[0x8] New Press Release - Layer 7 Technologies Enhances Field Collaboration for SOA Through HP ISV Marketplace Referral Program (June 18, 2008)

[0x9] New Article - Layer 7 to Provide Security and Operational Governance for Sun Java CAPS - eBizQ

[0xA] New Press Release - Layer 7 Technologies to Provide Security and Operational Governance for Sun Java CAPS (June 9, 2008)

Dr Anton Chuvakin Blog PERSONAL Blog

LogChat: Andrew Hay and Anton Chuvakin talk about logging, log management and related topics

[0x1] Links for 2012-05-18 [del.icio.us]

[0x2] Book Review: “Security De-Engineering: Solving the Problems in Information Risk Management” by Ian Tibble

[0x3] Links for 2012-05-17 [del.icio.us]

[0x4] Links for 2012-05-08 [del.icio.us]

[0x5] Monthly Blog Round-Up – April 2012

[0x6] Links for 2012-04-30 [del.icio.us]

[0x7] Metricon 7 Call for Papers

[0x8] Links for 2012-04-22 [del.icio.us]

[0x9] Links for 2012-04-04 [del.icio.us]

[0xA] Monthly Blog Round-Up – March 2012

[0x1] Spam in April 2012: Junk Mail Gathers Pace in the US

[0x2] Kaspersky Lab and InfoWatch Become Independent from Each Other

[0x3] Kaspersky Lab Officially Opens its South East Europe Office

[0x4] Spam in Q1 2012: A Marathon of Holidays

[0x5] Kaspersky Lab Congratulates Scuderia Ferrari on Success at the Spanish Grand Prix

[0x6] Number of the Week: 55% of Mobile Devices Using Unprotected Wi-Fi Networks

[0x7] Kaspersky Lab Reached Partnership Agreement with Venustech

[0x8] Kaspersky Lab Announces the Winners of Its Annual Student Conference

[0x9] Cyber Threats in April 2012: Mac OS X Malware & Mass-Exploitation; New Spam Campaigns

[0xA] Kaspersky Endpoint Security 8 for Windows Tops Corporate Solutions in VB100 Test

Daily Dave

This technical discussion list covers vulnerability research, exploit development, and security events/gossip. It was started by ImmunitySec founder Dave Aitel and many security luminaries participate. Many posts simply advertise Immunity products, but you can't really fault Dave for being self-promotional on a list named DailyDave.

[0x1] Howard Schmidt

[0x2] Ten years.

[0x3] New INFILTRATE 2012 Movie is up! With surprise introduction by Halvar!

[0x4] Re: Mobile Phone Security Survey

[0x5] Mobile Phone Security Survey

[0x6] With a real team, it's not about the numbers

[0x7] 72 hours

[0x8] Spooked at RSA 2012

[0x9] What's happening at SyScan'12 Singapore

[0xA] Save yourself 20% by tweeting

2600: The Hacker Quarterly

Off The Hook and Off The Wall

[0x1] Off The Hook show for May 16, 2012

[0x2] Off The Wall show for May 15, 2012

[0x3] HELP US COMPILE THE 2013 HACKER CALENDAR

[0x4] SPRING ISSUE OF 2600 RELEASED

[0x5] VOLUME 1 OF 2600 NOW ONLINE - DRM FREE - IN KINDLE, NOOK, AND PDF FORMATS

[0x6] HOPE TICKET SALES TO BENEFIT ELECTRONIC FRONTIER FOUNDATION

[0x7] RICHARD O'DWYER STORY TO BE FEATURED ON 'OFF THE HOOK'

[0x8] THE YES MEN ON 'OFF THE HOOK' TONIGHT

[0x9] RADIO ARCHIVE NOTES

[0xA] THE YES MEN TO KEYNOTE AT HOPE NUMBER NINE

Episteme: Belief. Knowledge. Wisdom

[0x1] How to Quickly Create New Habits in Your Life

[0x2] Matching and Mirroring (or: Cybernetic Issues in NLP)

[0x3] My Newest Experiment – The Kindle Book

[0x4] Maturity and Business

[0x5] What is it to be Mature?

[0x6] A Branding MAD Lib

[0x7] Suppressing Dissent

[0x8] Byron (and influence through the media)

[0x9] Influence and Failing Kindergarten

[0xA] Return-to-Barry-White Human Exploitation

Naked Security - Sophos

News, opinion, advice and research on computer security threats from Sophos

[0x1] State of Utah outlines mistakes made allowing theft of 780K records

[0x2] Should jailbreaking gaming consoles, mobile phones and tablets be legalized?

[0x3] Cyber romance scams cost US victims $50 million in 2011

[0x4] Backups are good - but don't forget to check your backups work [VIDEO]

[0x5] Call of Duty Trojan horse creator ends up in jail, after drunken college raid

[0x6] British hacker jailed for one year for breaking into Facebook account

[0x7] SSCC 90 - A walk around Interop 2012 with John Shier

[0x8] Technical paper - Fake anti-virus: The journey from Trojan to a persistent threat

[0x9] Free Sophos Anti-Virus app for your Android

[0xA] Fake anti-virus disguises used by Android malware

The Falcon's View

Mental meanderings of an infosec obsessive...

[0x1] Key Challenge: Estimating Loss in the Public Sector

[0x2] Epidemiological Thinking: A New Info Risk Mgmt Trend?

[0x3] SIRAcon Wrap-up

[0x4] Is the US Government Making Security Worse?

[0x5] Where's Ben? (May 2012 Edition)

[0x6] InfoSec vs. Fast Food Nation

[0x7] Book Review: The Alexandria Project by Andrew Updegrove

[0x8] The Inevitable Devolution of Standards Into Compliance Regimes

[0x9] Registration is Open for Inaugural SIRAcon

[0xA] #RSAC 2012: Concluding Thoughts

Exploit KB

exploit ~#

[0x1] Windows 7 Fake Access Point With Alfa AWUS036H

[0x2] Setup a Fake Access Point With BackTrack5

[0x3] Resolver

[0x4] Wophcrack – Ophcrack web interface

[0x5] New home for exploit.co.il

[0x6] ScreenSpy – New Meterpreter Script Review

[0x7] Meterpreter Script – Windows Service Creator

[0x8] Installing USB-B2K Telbox On UBUNTU 10.04 64 Bit

[0x9] Exploit KB Vulnerable Web App

[0xA] Patching and Compiling Cowpatty UBUNTU 10.04

The Falcon's View

Mental meanderings of an infosec obsessive...

[0x1] Upgrade+Migration Update

[0x2] FYI: Pending Site Upgrade+Migration

[0x3] Email Platform Migration

[0x4] AppSec DC 2010 Video Posted

[0x5] Survivability Rather Than Security Metrics

[0x6] RSA 2011: In Summary

[0x7] RSA 2011: Meet Federated Networks

[0x8] RSA 2011: Imation Expands Offerings

[0x9] RSA 2011: (dis)Innovation Sandbox

[0xA] Forget SmartGrid, Micro-Generation Is the Future

XSSed syndication

You are welcome to syndicate and share xssed.com contents

[0x1] F-Secure, McAfee and Symantec websites again XSSed

[0x2] Happy New Year 2012!

[0x3] Not surprisingly, McAfee websites are susceptible to XSS attacks

[0x4] Secure Amazon Seller Central password reset page XSSed

[0x5] EV SSL-secured live PayPal site vulnerable to XSS

[0x6] Persistent XSS bug discovered on eBay

[0x7] More American Express sites vulnerable to XSS and open redirects

[0x8] Cross-site scripting hole in American Express site using EV SSL

[0x9] Amazon hit by persistent XSS vulnerability

[0xA] MasterCard and Visa sites bitten by XSS bugs

Free Network / Communications Magazines and Downloads from bestsecuritytips.tradepub.com

Free publications about networking and communication technologies and management.

[0x1] Session Hijacking: How to Protect your Customers and your Corporate Data

[0x2] How to Unlock the ROI of Your Marketing with Analytics

[0x3] MissionCritical Communications

[0x4] The Changing Requirements of WAN Optimization

[0x5] Accelerating Data Migration with WAN Optimization

[0x6] Accelerating Cloud Performance with WAN Optimization

[0x7] Assessing ROI for Mobile Acceleration Clients

[0x8] The GNU/Linux Advanced Administration

[0x9] Cisco Secure Mobility Solution

[0xA] Six Tips for Choosing a UTM Solution

Securelist / Blog

[0x1] We Need More Than Jelly Bean

[0x2] Carolina Dieckmann, Brazilian cybercrime legislation and la “Viveza criolla”

[0x3] Public points of data loss

[0x4] Is ‘SexyDefense’ The Future of Anti-Espionage?

[0x5] Update to "DNSChanger - Cleaning Up 4 Million Infected Hosts"

[0x6] OS X Mass Exploitation - Why Now?

[0x7] SOURCE Boston Security Conference and Training 2012 Day 2 - Dan Geer Keynote, Android Modding and Cloud Security

[0x8] New Spam campaign on Twitter Leads to Rogue AV

[0x9] SOURCE Boston Security Conference and Training 2012 - Hacktivism, Duqu and Building Successful Security Programs

[0xA] New Version of OSX.SabPub & Confirmed Mac APT attacks

LinuxSecurity.com: Debian Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] Debian: 2475-1: openssl: integer underflow

[0x4] Debian: 2474-1: ikiwiki: cross-site scripting

[0x5] Debian: 2473-1: openoffice.org: buffer overflow

[0x6] Debian: 2472-1: gridengine: privilege escalation

[0x7] Debian: 2457-2: iceweasel / icedove: Multiple vulnerabilities

[0x8] Debian: 2471-1: ffmpeg: Multiple vulnerabilities

[0x9] Debian: 2670-1: wordpress: Multiple vulnerabilities

[0xA] Debian: 2469-1: linux-2.6: privilege escalation/denial

The Hacker's Choice - Freeworld News

News around The Hacker's Choice including releases, papers, exploits and other activities

[0x1] Hydra v6.5 is now available!

[0x2] Hydra v6.4 is now available with module enhancements and ...

[0x3] THC T-Shirts for 2011 can now be ordered.

[0x4] Get the new thc-ipv6 v1.6 release - lots of cool new tool...

[0x5] Hydra v6.3 is available with new oracle and smtp-enum mod...

[0x6] Amap v5.4 is now available which fixes an IPv6 bug introd...

[0x7] Amap v5.3 is now available.

[0x8] Hydra v6.2 is available with a new password bruteforcing ...

[0x9] Join the THC t-shirt design contest!

[0xA] Hydra v6.1 is available with SSHv1 support, a few fixes a...

LinuxSecurity.com: Ubuntu Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] Ubuntu: 1445-1: Linux kernel vulnerabilities

[0x4] Ubuntu: 1445-1: Linux kernel vulnerabilities

[0x5] Ubuntu: 1444-1: BackupPC vulnerability

[0x6] Ubuntu: 1443-1: Update Manager vulnerabilities

[0x7] Ubuntu: 1442-1: Sudo vulnerability

[0x8] Ubuntu: 1440-1: Linux kernel (Natty backport) vulnerabilities

[0x9] Ubuntu: 1432-1: Linux kernel vulnerabilities

[0xA] Ubuntu: 1439-1: Horizon vulnerabilities

Hackers Center Blogs

[0x1] Not Another Penetration testing course

[0x2] Data Related to Kneber Botnet breach recovered by Netwitness

[0x3] Building security into business processes

[0x4] Spy Eye tool kit goes after Zeus botnet

[0x5] Black Hat: Researcher claims hack of chip used to secure computers, smartcards

[0x6] China steals Google's data

[0x7] PortSwigger.net - web application security

[0x8] eLearnSecurity : Breaking into system is no more enough

[0x9] NIST releases Security Content Automation Protocol for FISMA

[0xA] A zero-day flaw in the TLS and SSL protocols, which are commonly used to encrypt web pages, has been made public.

MITRE Career News

The MITRE Career News feed offers stories about working at MITRE, from our popular Employee Spotlight features, to useful information about upcoming recruiting events and more.

[0x1] MITRE Engineer Has a Passion for Aviation and Travel

[0x2] HR Recruiter Scouts Students to Take on the Country's Top Technical Challenges

[0x3] MITRE's Systems Engineering Pays Off for Civil Agencies

[0x4] Engineer's Early Fascination with Geography and Language Evident in MITRE's Georeferencing Toolkit

[0x5] From Communications to Cybersecurity, Enhancing National Security through Technology

[0x6] A New Era for IT Acquisition

[0x7] Serving MITRE and his Country

[0x8] Empowering Nurses with Advanced Technology

[0x9] MITRE Named to Glassdoor.com's 50 Best Places to Work List

[0xA] A Career in Aviation Technical Leadership

Penetration Testing

While this list is intended for "professionals", participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.

[0x1] Securing Citrix

[0x2] Re: Question of Likelihood

[0x3] sslcaudit 1.0 released

[0x4] Re: Question of Likelihood

[0x5] Question of Likelihood

[0x6] t2'12: Call for Papers 2012 (Helsinki / Finland)

[0x7] A survey on web application attacks

[0x8] Announce: Italian Hacker Game Cracca al Tesoro - Crack A Treasure

[0x9] nullcon Delhi 2012 Call for Paper/Call for Event

[0xA] xSQL Scanner 1.6 - Released

The Hacker Diaries

Ethical Hacking, Security Tools, and all things Cyber Security

[0x1] Sony Security Breach

[0x2] How Can You Protect Against Future Epsilon-Like Breaches?

[0x3] Healthcare & Security: A Hacker’s Perspective

[0x4] Best Offensive Security Tools Survey 2010

[0x5] Inside the Mind of a Hacker

[0x6] Hacktivists change the Global Warming Debate

[0x7] Protecting from Identity Theft? A good Start

[0x8] Social Security number code cracked, study claims

[0x9] Pink Floyd star David Gilmour joins fight to halt extradition to US of hacker Gary McKinnon

[0xA] The Myth of the Virus Free Mac

blog ntic de revolunet

Blog des Nouvelles Technologies de l'Information et de la Communication

[0x1] Le point sur ExtJs 4

[0x2] Revolunet réalise l’application de E-coffrefort.fr

[0x3] Revolunet réalise le magazine digital BellesDemeures.com

[0x4] Présentation de documents en direct

[0x5] Recrute développeur PHP

[0x6] Django internationalisation made easy with i18n

[0x7] Google apps tips

[0x8] Recrutement développeur PHP sur Paris

[0x9] Symbian : l’open source comme ultime recours ?

[0xA] Appels illimités vers le Maroc

Microsoft Security Content: Comprehensive Edition

Microsoft Security Content: Comprehensive Edition

[0x1] MS12-034 - Critical : Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578) - Version: 1.1

[0x2] MS12-035 - Critical : Vulnerabilities in .NET Framework Could Allow Remote Code Execution (2693777) - Version: 2.0

[0x3] Summary for May 2012 - Version: 2.0

[0x4] MS11-100 - Critical : Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420) - Version: 1.4

[0x5] MS12-032 - Important : Vulnerability in TCP/IP Could Allow Elevation of Privilege (2688338) - Version: 1.1

[0x6] MS12-030 - Important : Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2663830) - Version: 1.1

[0x7] MS12-029 - Critical : Vulnerability in Microsoft Word Could Allow Remote Code Execution (2680352) - Version: 1.1

[0x8] Microsoft Security Advisory (2695962): Update Rollup for ActiveX Kill Bits - Version: 1.0

[0x9] MS12-033 - Important : Vulnerability in Windows Partition Manager Could Allow Elevation of Privilege (2690533) - Version: 1.0

[0xA] MS12-031 - Important : Vulnerability in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2597981) - Version: 1.0

LinuxSecurity.com: EnGarde_Secure_Linux Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] EnGarde Secure Community Release Notes 3.0.10

[0x4] EnGarde Secure Community 3.0.8 Release Notes

[0x5] EnGarde Secure Community 3.0.7 Release Notes

[0x6] EnGarde Secure Community 3.0.6 Release Notes

[0x7] EnGarde Secure Community 3.0.5 Release Notes

[0x8] EnGarde Secure Community 3.0.4 Release Notes

[0x9] EnGarde Secure Community 3.0.3 Release Notes

[0xA] EnGarde Secure Community 3.0.2 Release Notes

ZDI: Upcoming Advisories

Upcoming Advisories

[0x1] ZDI-CAN-1547: Microsoft

[0x2] ZDI-CAN-1531: Microsoft

[0x3] ZDI-CAN-1529: EMC

[0x4] ZDI-CAN-1528: WebKit.Org

[0x5] ZDI-CAN-1527: Novell

[0x6] ZDI-CAN-1526: Microsoft

[0x7] ZDI-CAN-1525: Microsoft

[0x8] ZDI-CAN-1524: Microsoft

[0x9] ZDI-CAN-1523: Microsoft

[0xA] ZDI-CAN-1520: Microsoft

LinuxSecurity.com: Red_Hat Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] Red Hat: 2012:0571-01: kernel: Moderate Advisory

[0x4] Red Hat: 2012:0670-01: kernel-rt: Important Advisory

[0x5] Red Hat: 2012:0570-01: php: Critical Advisory

[0x6] Red Hat: 2012:0568-01: php: Critical Advisory

[0x7] Red Hat: 2012:0569-01: php53: Critical Advisory

[0x8] Red Hat: 2012:0546-01: php: Critical Advisory

[0x9] Red Hat: 2012:0544-01: ImageMagick: Moderate Advisory

[0xA] Red Hat: 2012:0545-01: ImageMagick: Moderate Advisory

Symantec Security Response Podcasts

Listen online, download to your computer, or subscribe and get the latest information automatically.

[0x1] Intelligence Report Podcast – November 2011

[0x2] Intelligence Report Podcast – October 2011

[0x3] Intelligence Report Podcast – August 2011

[0x4] Symantec Report Finds Cyber Threats Skyrocket in Volume and Sophistication

[0x5] Symantec Appliance Strategy: Messaging Gateway & Web Gateway

[0x6] Update from Symantec Security Technology & Response

[0x7] Search Engine Poisoning

[0x8] Symantec Security Response Profile: Zulfikar Ramzan

[0x9] ISTR XIV - Phishing and Spam in the Economic Downturn

[0xA] ISTR XIV - Financially Motivated Malicious Code Development

cryptography on SWiK

[0x1] Stream-Cipher-Test-Algorithm-1

[0x2] cryptoolinux

[0x3] del.icio.us/popular/cryptography

[0x4] password

[0x5] mosref

[0x6] MatrixSSL - embedded SSL for devices

[0x7] Cryptonit

[0x8] turbid

[0x9] cryptlib

[0xA] Galois Field Arithmetic Library

www.derkeiler.com: Pen-Test

Pen-Test

[0x1] Securing Citrix

[0x2] sslcaudit 1.0 released

[0x3] Question of Likelihood

[0x4] t212: Call for Papers 2012 (Helsinki / Finland)

[0x5] A survey on web application attacks

[0x6] Announce: Italian Hacker Game Cracca al Tesoro - Crack A Treasure

[0x7] nullcon Delhi 2012 Call for Paper/Call for Event

[0x8] xSQL Scanner 1.6 - Released

[0x9] [Tool update] VoIP Hopper 2.04 released

[0xA] Anti-fingerprinting techniques

Department of Homeland Security News

Department of Homeland Security News

[0x1] Readout of Secretary Napolitano's Visit to Germany: Day 2

[0x2] Readout Of Secretary Napolitano's Visit To Germany

[0x3] Written testimony of the Federal Emergency Management Agency U.S. Fire Administration for a House Committee on Science, Space, and Technology hearing titled “Working for a Fire Safe America: Examining United States Fire Administration Priorities”

[0x4] Written testimony of the U.S. Immigration and Customs Enforcement for a House Ways and Means Subcommittee on Trade hearing titled “Supporting Economic Growth and Job Creation through Customs Trade Modernization, Facilitation, and Enforcement”

[0x5] Written testimony of the U.S. Customs and Border Protection for a House Homeland Security Subcommittee on Oversight, Investigations, and Management hearing titled “Department of Homeland Security: An Examination of Ethical Standards”

[0x6] Written testimony of the Transportation Security Administration for a House Homeland Security Subcommittee on Oversight, Investigations, and Management hearing titled “Department of Homeland Security: An Examination of Ethical Standards”

[0x7] Written testimony of the U.S. Immigration and Customs Enforcement for a House Homeland Security Subcommittee on Oversight, Investigations, and Management hearing titled “Department of Homeland Security: An Examination of Ethical Standards”

[0x8] Written testimony of the U.S. Customs and Border Protection for a House Ways and Means Subcommittee on Trade hearing titled “Supporting Economic Growth and Job Creation through Customs Trade Modernization, Facilitation, and Enforcement”

[0x9] Written testimony of the U.S. Coast Guard for a Senate Commerce, Science, and Transportation Subcommittee on Oceans, Atmosphere, Fisheries, and Coast Guard hearing titled “Stemming the Tide: The U.S. Response to Tsunami Generated Marine Debris”

[0xA] Remarks by Secretary Janet Napolitano at the U.S. Coast Guard Academy Commencement

US-CERT Current Activity

The US-CERT Current Activity web page is a regularly updated summary of the most frequent, high-impact types of security incidents currently being reported to the US-CERT.

[0x1] Apple Releases QuickTime 7.7.2

[0x2] Google Releases Google Chrome 19

[0x3] Apple Releases Flashback Malware Security Updates

[0x4] Apple Releases Multiple Security Updates

[0x5] Adobe Releases Security Bulletins for Multiple Products

[0x6] Apple Releases iOS 5.1.1

[0x7] Microsoft Releases May Security Bulletin

[0x8] Microsoft Releases Advanced Notification for May Security Bulletin

[0x9] Adobe Releases Security Advisory for Adobe Flash Player

[0xA] Google Releases Chrome 18.0.1025.168

National Security

National Security

[0x1] Missile Defense A Divisive Topic At NATO Summit

[0x2] An Afghan Shoots, A Marine Dies, Mistrust Grows

[0x3] Why The U.S. Is Aggressively Targeting Yemen

[0x4] Are U.S. Troops In Australia A Hedge Against China?

[0x5] Why Do Terrorists So Often Go For Planes?

[0x6] Military Looks To Redefine PTSD, Without Stigma

[0x7] U.S. Military Mission: Pushing Afghans To Take Lead

[0x8] Cybersecurity Firms Ditch Defense, Learn To 'Hunt'

[0x9] House To Vote On GOP Bill Framed As Guns Vs. Butter

[0xA] Bomb Plot: Secrets Didn't Stay Secret For Long

CERIAS Combined Feed

News and Blog posts from CERIAS. This feed does not include our events calendar (http://www.cerias.purdue.edu/feeds/events)

[0x1] Spafford Wins Award for Outstanding Career Achievement

[0x2] Keynote: Howard Schmidt (Keynote Summary)

[0x3] Security Fireside Chat (Summary)

[0x4] Panel #3: Securing Mobile Devices (Panel Summary)

[0x5] Panel #2: Big Data Analytics (Panel Summary)

[0x6] Panel #1: Securing SCADA Systems (Panel Summary)

[0x7] Opening Keynote: Arthur W. Coviello, Jr. (Keynote Summary)

[0x8] CERIAS Annual Awards Announced

[0x9] An Interesting Opportunity

[0xA] Putting to Rest RSA Key Security Worries

Techworld.com networking

Latest IT articles from Techworld's networking channel

[0x1] Fibre broadband to be rolled out to 90% o rural Rutland by BT

[0x2] Japanese researchers break record for Terahertz Wi-Fi transmission

[0x3] Angry Birds tops corporate mobile blacklist, Facebook, YouTube follow

[0x4] Compuware brings APM to cloud and Big Data applications

[0x5] From packet inspectors to WAN optimisers, network add-ons are all the rage

[0x6] Verizon to offer 100G links, make optical networks more resilient

[0x7] IP network run over xylophones by California researchers

[0x8] Wi-Fi-Blocking wallpaper keeps your signal in and intruders out

[0x9] Virtualise the rest of the data centre, VMware recommends at Interop

[0xA] Small cells could raise big problems for mobile operators

Here you'll find observations, anecdotes, and analysis from our experienced staff of reporters and editors, with links to stories, surveys and other content that appear on InformationWeek.com, TechWeb.com, and many other points on the Web. We welcome discussion, and invite you to share your opinions and thoughts. Please participate with us!

[0x1] Are There Too Many Storage Solutions?

[0x2] Smartphone Adoption Higher In Europe

[0x3] Solid State Storage Can Save You Money

[0x4] Smartphone Option Overload Confuses Consumers

[0x5] InformationWeek's RSS Feed is brought to you by

[0x6] Google Has Lost Control Of Android Fragmentation

[0x7] RIM Investors Give Thumbs Down On New CEO

[0x8] Windows Phone Predicted To Overtake iOS By 2015

[0x9] Solid State Disk's True Cost

[0xA] Can Nokia Crack The Verizon Nut?

CSOONLINE.com - Emergency Preparedness

[0x1] 4 critical trends in IT business continuity

[0x2] Operation Global Blackout: Real danger or irrelevant?

[0x3] Severe space weather: How big a threat?

[0x4] Does my company need business continuity software?

[0x5] Lieberman: Cybersecurity Act of 2012 will help us protect critical infrastructure

[0x6] Security at the scene of the crime

[0x7] Government engineers actively plan for cyberwar

[0x8] Experts advise caution, information sharing in wake of alleged utility attacks

[0x9] Will 2012 REALLY be the year of the cyberwar?

[0xA] Smartphones, social media tied into ELERTS emergency system

StalkR's Blog

Blog of a security enthusiast

[0x1] USB rescue and secure boot disk

[0x2] YubiText and 3-factor password authentication

[0x3] YubiKey USB security token

[0x4] PPTP VPN and policy routing on user

[0x5] Going DNSSEC, Unbound and PowerDNS

[0x6] SSH/HTTP(S) multiplexing with sshttp

[0x7] Ghost in the Shellcode 2012 Teaser - Hackquest

[0x8] HSTS preloading, public key pinning and Chrome

[0x9] Twitter Archiver

[0xA] Hack in the Box Amsterdam 2011 CTF

OSF Data Loss - The Blotter

This feed contains the latest blotter articles posted to datalossdb.org.

[0x1] Identity Theft in the Matrix

[0x2] Ottawa phasing out SIN card to help avoid identify theft

[0x3] Northwestern Memorial employee charged with theft of patients' identities

[0x4] Schield creates ID victims website

[0x5] ID Theft, Online Fraud Rose Slightly In 2011

[0x6] 9 Alarming Statistics About Identity Theft

[0x7] Report: Children are fastest-growing identity theft victims

[0x8] Identity Theft Concerns Follow Security Breach

[0x9] I.D. grave robbers: Post-mortem identity theft

[0xA] Newark man charged with stealing $1.2M from mortgage lenders with stolen identity

Adventures in Security

Commentary, reviews, and tips relevant to anyone responsible for information security. Including how to build and manage a security program, editorials about the state of information security, and do's and don't's based on my 26 years of IT experience.

[0x1] Firefox Sync: Think Twice before Use

[0x2] Looks aren't everything...

[0x3] Google, wireless networks, and ethics...

[0x4] Twitter down... Why should you care?

[0x5] Give Facebook a break...

[0x6] Integrated Malware

[0x7] Patch, patch, patch... and then patch

[0x8] Media management must include printers

[0x9] So, who is liable for negligence?

[0xA] Security double-standards are still a bad idea

InformationWeek Security News

InformationWeek

[0x1] New FBI Surveillance Backdoors? 6 Key Points

[0x2] Twitter Adds Do Not Track Capability

[0x3] Facebook's History: From Dorm To IPO Darling

[0x4] Fake Google Chrome Installer Steals Banking Details

[0x5] Forensic Tool Grabs iPhone, iPad Data Remotely

[0x6] 6 Facebook Problems Need Fixing

[0x7] Zeus Malware Seeks Facebook Users' Debit Card Data

[0x8] InformationWeek's RSS Feed is brought to you by

[0x9] 5 Ways To Lose A Malicious Insider Lawsuit

[0xA] Google Chrome 19 Debuts, With 20 Bug Patches

Skypher

The blog for absolutely nothing!

[0x1] Web Development on a Chromebook (2)

[0x2] Web Development on a Chromebook

[0x3] Transformed polygons fractal rendering engine

[0x4] JavaScript 1K poptart cat

[0x5] JavaScript Mandelbrot fractal rendering engine

[0x6] Window Zoom Chrome Extension

[0x7] w32 speaking shellcode – Pwn in style

[0x8] Merry Christmas and a Happy New Year!

[0x9] JsSfx3.2 – JavaScript compression tool updated.

[0xA] JavaScript Perlin flames source

XSSed syndication

You are welcome to syndicate and share xssed.com contents

[0x1] www.120.li XSS

[0x2] www.shop.nsw.gov.au XSS

[0x3] au.msi.com XSS

[0x4] www.amazon.com XSS

[0x5] suivi.chronopost.fr XSS

[0x6] www.scientology.org XSS

[0x7] new.davidguetta.com XSS

[0x8] www.davidguetta.com XSS

[0x9] security.anti-abuse.com XSS

[0xA] www.manchesterproducts.com XSS

Technibble

Helping Computer Technicians Become Computer Business Owners

[0x1] 4 Ways Computer Repair Shops Can Profit from the Tablet Revolution

[0x2] Patch My PC – Mass Update Third Party Software Automatically

[0x3] How to Gain Computer Repair Customers Through Volunteer Work

[0x4] How To Create Effective Craigslist Ads For Your Computer Repair Business

[0x5] GSmartControl – Monitor and Test Hard Drive SMART Data

[0x6] 3 Ways to Get Computer Repair Customers Serious About Data Backup

[0x7] Mail Viewer – View Stand Alone Email Databases

[0x8] Bypass Windows Logons with the Utilman.exe Trick

[0x9] CloseTheDoor – Port Scanning and Information Tool

[0xA] Using an iPad in the Computer Repair Business

Security Tools News & Tips

Just another WordPress weblog

[0x1] Microsoft Security Essentials

[0x2] NSMXpress

[0x3] Korea to train 3,000 ‘cyber sheriffs’

[0x4] FortiClient standard edition

[0x5] 10 Solid Tips to Safeguard Your Facebook Privacy

[0x6] K9 Web Protection

[0x7] Check Point Power-1 Appliances

[0x8] Wordpress blogs hacked – Upgrade your Wordpress NOW!

[0x9] Cisco ASA 5500 Series Firewall

[0xA] (IN)SECURE Magazine Issue 22 is out

OSVDB Blog :

Everything Is Vulnerable

[0x1] We're Still Here - Update on OSVDB Project: Data and Exports

[0x2] Ferreting Out Unique Vulnerability Data in OSVDB

[0x3] Open Security Foundation Announces New Advisory Board

[0x4] Open Security Foundation Launches New Cloud Security Project

[0x5] March Update: Challenge: OSVDB Winter 2010 Fundraising Goal = done

[0x6] iDefense VCP as seen through OSVDB

[0x7] February Update: OSVDB Winter 2010 Fundraising Goal

[0x8] Time to.. Track More Data

[0x9] Open Security Foundation - Advisory Board - Call for Nominations

[0xA] Open Security Foundation - State of the Union 2010

The SMB Minute

The SMB Minute

[0x1] Great collection of different tools at grassrootssecurity

[0x2] Four Must-Have SMB Security Tools

[0x3] How to choose the right Firewall for Your SMB

[0x4] Fake Anti-Virus Progams

[0x5] Interview with Chirs Nickerson Part3

[0x6] Those Who Cannot Remember the Past are Condemned to Repeat it

[0x7] Your photos are NOT posted online

[0x8] More Phishing attempts

[0x9] Interview with Chris Nickerson Part 2, NOW with BETTER audio

[0xA] Interview with Chris Nickerson (part 1)

Kismet Wireless

Kismet development & Wireless security

[0x1] KisBee status

[0x2] Android hidden AP weirdness

[0x3] Android Kismet progress

[0x4] Kismet on Android

[0x5] Capturing raw 802.11 on android

[0x6] Reaver / WPS Brute Force IDS

[0x7] Shmoocon

[0x8] Drone wackiness

[0x9] Phy-Neutral changes to drones

[0xA] Kismet G+ page

CSOONLINE.com - Employee Protection

[0x1] Making the case for preventing workplace violence

[0x2] 10 tips for offsite meeting security

[0x3] World Trade Center security and progress

[0x4] Corporate security experts: Bin Laden death shouldn't impact business, travel plans

[0x5] Security stepped up around U.S. following Bin Laden news

[0x6] Travel security in the Middle East and North Africa

[0x7] What it's like to respond to a bomb threat

[0x8] What it's like...

[0x9] Executive protection: Why the private sector model is broken

[0xA] Artful security: Design elements that ensure security, but also emphasize style

ITWeb News Feed

Latest ICT news

[0x1] Apple stock breaks $300 for first time

[0x2] Sony delays Gran Turismo release

[0x3] MS deepens Facebook ties

[0x4] Media firms approached on Yahoo sale

[0x5] Doing more with less

[0x6] Bytes People Solutions honoured

[0x7] Virtualisation benefits SME market

[0x8] MCI adapts Adapt on Demand

[0x9] Intel reports $11bn revenue quarter

[0xA] Konica Minolta SA offers green toner

War on Error

One day they'll laugh at what we think is secure. Thankfully, we won't be there to hear them...

[0x1] Why Apple and Amazon should pay more tax

[0x2] Hackers spam Ticketweb users after email breach

[0x3] Microsoft offers access to anti-botnet system

[0x4] Comet has some explaining to do but so does Microsoft

[0x5] Hacker finds Lindsay Lohan Playboy pictures on P2P

[0x6] Dell dumps Streak tablet and cools on Android

[0x7] Windows 8 will struggle, analysts predict

[0x8] Gmail's offline mode rides again

[0x9] The crazy US patent system has turned Apple and Microsoft into trolls

[0xA] Apple and Microsoft, patent trolls. But is Google any better?

ZDI: Recent Press

Recent Press Hits

[0x1] Google offers $20,000 prize in annual hack-off

[0x2] Pwn2Own 2011: Google offering $20,000 for Chrome sandbox exploit

[0x3] Google Offers Bucks For Bugs In Its Web Applications

[0x4] How Microsoft ranks with the most tardy bug fixers

[0x5] HP TippingPoint gives deadline to vendors

[0x6] TippingPoint sets six-month deadline for flaw fixes

[0x7] HP's Zero Day Initiative Gives Vendors Patching Deadline

[0x8] Researchers Throw Down Vulnerability-Disclosure Gauntlet

[0x9] TippingPoint gives vendors six months to fix holes

[0xA] New vulnerability disclosure deadline puts pressure on tardy software vendors

xorl %eax, %eax

[0x1] CVE-2012-2369: pidgin-otr Log Message Format String

[0x2] Linux kernel DRM Intel i915 Multiple IOCTL Integer Overflows

[0x3] CVE-2012-1775: VLC MMS Support Stack Overflow

[0x4] Admin Mistakes: GNU, BSD TAR and POSIX Compatibility

[0x5] CVE-2012-2141: net-snmp Read out-of-bounds

[0x6] News: Phrack #68 Released!

[0x7] Hack Analysis (CVE-2010-0738)

[0x8] Book: The Tangled Web

[0x9] Knife: KA-BAR USMC #1217

[0xA] CVE-2011-4362: Lighttpd Remote Signedness Issue

ITWeb Internet

Latest ICT Internet news

[0x1] MS deepens Facebook ties

[0x2] Branded Internet presents wholesale dept

[0x3] X for expensive?

[0x4] Pilots get online training

[0x5] Low connectivity hinders e-business

[0x6] Sony intros classical music e-store

[0x7] MWEB Business expands uncapped services

[0x8] How will SA lower broadband cost?

[0x9] Amazon plans app store

[0xA] MWEB Business extends ADSL offerings

Murky

Tending to Geekiness

[0x1] London Prepares: Track World Cup -London – Day 1

[0x2] The Artist

[0x3] Links for 2012-02-09 [del.icio.us]

[0x4] Ukulele

[0x5] A Mini Christmas Marketing Suggestion

[0x6] Links for 2011-11-15 [del.icio.us]

[0x7] 7 billion and counting

[0x8] Rock Choir

[0x9] Les Misérables

[0xA] River Song

Martin McKeay's blog

[0x1] Hacking locks instead of computers

[0x2] Did she think this of the potential consequences?

[0x3] Escaping a virtual machine

[0x4] Certs: Added value or minimum requirement?

[0x5] The dubious effects of monitoring surfing habits

[0x6] Should your ISP protect you from yourself?

[0x7] Was the iPhone ready for prime time?

[0x8] Maynor isn't the Sell Out or LMH

[0x9] Infosec Sell Out outed, disappears

[0xA] VA employee tried to hide the damage

NYT > Cryptography

News about cryptography, including commentary and archival articles published in The New York Times.

[0x1] Britain’s GCHQ Uses Online Puzzle to Recruit Hackers

[0x2] How 18th-Century Copiale Cipher Was Cracked

[0x3] One-Time Pad Encryption Dates Back to Telegraph Codebook

[0x4] A Crack in the Code Kryptos Is Keeping

[0x5] Debate Over P vs. NP Proof Highlights Web Collaboration

[0x6] Universities Spar Over Disappearing Electronic Messages

[0x7] Goodbye, Passwords. You Aren’t a Good Defense.

[0x8] Adding Math to List of Security Threats

[0x9] Studios’ DVDs Face a Crack in Security

[0xA] A Cryptologist Takes a Crack at Deciphering DNA’s Deep Secrets

Hack a Day

Fresh hacks every day

[0x1] Making real-life portals with a Kinect

[0x2] DIY spring and plate reverb

[0x3] Geeks living off the grid are hard on batteries

[0x4] Building a color sensor using luminosity

[0x5] Reminder: SpaceX launch tomorrow. Watch it live!

[0x6] Conductive ink circuit experiments

[0x7] Scavenging from consumer electronics to make a flame-powered phone charger

[0x8] Adding kilometers to a radio meant only for meters

[0x9] Printing circuitry on a RepRap

[0xA] Teaching BeagleBone to play with LIDD displays

ZDI: Published Advisories

Published Advisories

[0x1] ZDI-12-074: Oracle Forms Recognition CroScPlt.dll ActiveX Control Remote Code Execution Vulnerabilty

[0x2] ZDI-12-073: Oracle WebCenter Forms Recognition Sssplt30.ocx ActiveX Control Remote Code Execution Vulnerabilty

[0x3] ZDI-12-072: Samba ReportEventW Heap Overflow Remote Code Execution Vulnerability

[0x4] ZDI-12-071: Samba ndr_ValidatePassword heap overflow Remote Code Execution Vulnerability

[0x5] ZDI-12-070: Samba lsa_LookupNames Heap Overflow Remote Code Execution Vulnerability

[0x6] ZDI-12-069: Samba SetInfoPolicy AuditEventsInfo Remote Code Execution Vulnerability

[0x7] ZDI-12-068: Samba GetAliasMembership SidArray Remote Code Execution Vulnerability

[0x8] ZDI-12-067: WebKit.org Webkit Array.Splice Remote Code Execution Vulnerability

[0x9] ZDI-12-066: Internet Explorer CTagFactory Use-After-Free Remote Code Execution Vulnerability

[0xA] ZDI-12-065: Microsoft Internet Explorer selectAll Use-After-Free Remote Code Execution Vulnerability

[H]ardOCP News/Article Feed

News/Article Feed for [H]ardOCP

[0x1] Rovio to Launch Racing-Themed 'Angry Birds Heikki'

[0x2] Supervolcano Drilling Plan Gets Go-Ahead

[0x3] Microsoft Publishes a History of the Windows Interface

[0x4] A Portable Scanner for Smartphones

[0x5] Useless Chainsaw Video of the Day

[0x6] 'Ring of Fire' Eclipse on Sunday

[0x7] Facebook Suit Over Subscriber Tracking Seeks $15 Billion

[0x8] Latest Windows 8 News Reveals Removal of Aero

[0x9] Epic Mickey 2 Gets Behind-the-Scenes Video

[0xA] Amazon's 10-Inch Kindle Fire Tablet Due in Q3

Twitter / ubuntu_security

Twitter updates from ubuntu_security / ubuntu_security.

[0x1] ubuntu_security: [USN-810-1] NSS vulnerabilities

[0x2] ubuntu_security: [USN-817-1] Thunderbird vulnerabilities

[0x3] ubuntu_security: [USN-813-2] Apache vulnerability

[0x4] ubuntu_security: [USN-824-1] PHP vulnerability

[0x5] ubuntu_security: [USN-816-1] fetchmail vulnerability

[0x6] ubuntu_security: [USN-810-1] NSS vulnerabilities

[0x7] ubuntu_security: [USN-817-1] Thunderbird vulnerabilities

[0x8] ubuntu_security: [USN-813-2] Apache vulnerability

[0x9] ubuntu_security: [USN-824-1] PHP vulnerability

[0xA] ubuntu_security: [USN-816-1] fetchmail vulnerability

GNUCITIZEN

Information Security Think tank

[0x1] Well Websecurify Runs on The iPhone

[0x2] Stuxnet

[0x3] Having fun with BeEF, the browser exploitation framework

[0x4] ColdFusion directory traversal FAQ (CVE-2010-2861)

[0x5] 1ST European Edition of HITB Coming Up!

[0x6] Hacking Linksys IP Cameras (pt 6)

[0x7] Dnsmap v0.30 is now out!

[0x8] Old-school Remote Command Exec Vulnerabilities on Avaya Intuity

[0x9] Skydive

[0xA] Free Web Application Security Testing Tool

CSOONLINE.com - Identity Theft Prevention

[0x1] U.S. seeking to build international unity around cyberdefense for industrial control systems

[0x2] FBI issues warning on hotel Internet connections

[0x3] Financial malware tricks users with claims of free credit card fraud insurance

[0x4] How to fight back against privacy pirates

[0x5] Hackers blackmail Belgian bank with threats to publish customer data

[0x6] Dutch court temporarily frees 17-year-old KPN hacking suspect

[0x7] Russia-speaking cybercriminals earned $4.5 billion in 2011, researchers estimate

[0x8] Identity theft: When millions of dead people apply for credit cards

[0x9] Sophos takes down partner portal after signs of hacking

[0xA] Ice IX malware tricks Facebook users into exposing credit card details, says Trusteer

The Ethical Hacker Network RSS News Feed

Most Recent Additions to The Ethical Hacker Network, the best, single source of educational content for forensics, pen testing and incident response. Hacker Challenges with prizes, free monthly giveaways, tutorials, articles, forums, certification info and more.

[0x1] April 2012 Free Giveaway Winners of eLearnSecurity Training

[0x2] May 2012 Free Giveaway Sponsor - iSWAT by FishNet Security

[0x3] Course Review: Penetration Testing Professional v2 by eLearnSecurity

[0x4] Bringing the Unsexy Back: The Process of Selling SE Penetration Tests

[0x5] Book Review: Metasploit – The Penetration Tester's Guide

[0x6] March 2012 Free Giveaway Winner of Training Camp Prize

[0x7] Book Review: The Tangled Web

[0x8] Scam Your Clients for Their Own Good

[0x9] February 2012 Free Giveaway Winner - Global Knowledge

[0xA] Building Information Security Professionals

DVLabs: Blogs

Recent Blog Posts

[0x1] Thank you Aaron

[0x2] Announcing the IDA Toolbag

[0x3] MindshaRE: Another Approach To Tracking ReadFile

[0x4] Pwn2Own Challenges: Heapsprays are for the 99%

[0x5] Pwn2Own 2012 and Google Pwnium

[0x6] MindshaRE: Python Syntax Coloring in IDA

[0x7] MindshaRE: Yo Dawg, I heard you like reversing...

[0x8] MindshaRE: Adding Cross References via IDAPython

[0x9] MindshaRE: IDAception

[0xA] Pwn2Own Pre-Game

Remove reviews

Pipes Output

[0x1] Relaxed JSON parsing

[0x2] Updating the root certificates for Java

[0x3] Vagrant and VirtualBox on Windows

[0x4] Another friend blogging

[0x5] Using Jython from Maven

[0x6] How to post high-quality videos to Google Video

[0x7] Integrating Maven with Ivy

[0x8] Upgrading the Options (GlobeTrotter) GI515m

[0x9] Getting the most out of your audio recording with Audacity

[0xA] More videos

Hak5 - Technolust since 2005

Trust Your Technolust

[0x1] Hak 1113 – Persistent SSH tunnels for Windows and Linux, Local vs Remote forwards and more

[0x2] Hak5 1112 – Relay two firewalled devices through a persistent SSH proxy

[0x3] Hak5 1111 – Roll your own Secure Cloud Storage with SSHFS – Secure Shell File System

[0x4] Hak5 1110 – SSH Public Key Fingerprints, Windows SSH Servers and Linux Key Pair Exchange

[0x5] Hak5 1109 – Proxies, Linux SSH Servers, Windows Clients & Public Keys

[0x6] The New iPad – Shannon’s Review

[0x7] SF Bay Area Party – Celebrate Season 11 Episode 11!!!!1111

[0x8] Hak5 1108 – Hak5 Special: Proxies – Part 1

[0x9] Hak5 1107 – Block Facebook Tracking, Interactive Process Automation, plus NetCat and Ngrep tricks

[0xA] Hak5 1106 – How To Setup Two Factor Authentication in Backtrack Linux

Latest Alerts From Websense Security Labs

This is the Alert Rss Feed from Websense Security Labs

[0x1] None: Please update your RSS readers and bookmarks, the Security Labs blog has moved!

[0x2] Malicious Web Site / Malicious Code: New Zbot campaign comes in a PDF

[0x3] Malicious Web Site / Malicious Code: Fake Apple App Store Malicious Spam

[0x4] Malicious Web Site / Malicious Code: Skype Toolbar for Outlook Scam

[0x5] Malicious Web Site / Malicious Code: Searching for Corey Haim Leads to Rogue AV

[0x6] Malicious Web Site / Malicious Code: BBS of Sougou Compromised

[0x7] Malicious Web Site / Malicious Code: Blackhat SEO turns to PDF with Chile and Hawaii disasters

[0x8] Malicious Web Site / Malicious Code: Searching For Joannie Rochette Leads To Rogue AV

[0x9] Malicious Web Site / Malicious Code: Bloom Box Black SEO

[0xA] Malicious Web Site / Malicious Code: Microsoft's Ninemsn Australia Web Site Compromised

CSOONLINE.com - Data Privacy

[0x1] Wireless tech makes health care security a 'major concern'

[0x2] Thwarted by security at enterprises, cyber criminals target SMBs

[0x3] Facebook proposes more changes to privacy policy

[0x4] Sides dig in as FBI warns of 'going dark' in online era

[0x5] California moves to stop employers demanding Facebook passwords

[0x6] U.S. seeking to build international unity around cyberdefense for industrial control systems

[0x7] Myspace Settles FTC Privacy Investigation, Submits to 20 Years of Checks

[0x8] Data privacy concerns put citizens off online contact with government

[0x9] Myspace settles FTC privacy complaint

[0xA] Windows 8 privacy worry overblown, says Microsoft analyst

LinuxSecurity.com: Fedora Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] Fedora 10 ruby-1.8.6.368-2.fc10

[0x4] Fedora 12 moodle-1.9.7-1.fc12

[0x5] Fedora 12 ntp-4.2.4p8-1.fc12

[0x6] Fedora 10 moodle-1.9.7-1.fc10

[0x7] Fedora 12 kernel-2.6.31.6-166.fc12

[0x8] Fedora 10 httpd-2.2.14-1.fc10

[0x9] Fedora 12 nss-util-3.12.5-1.fc12.1

[0xA] Fedora 10 rubygem-actionpack-2.1.1-5.fc10

Cisco Security Responses

Cisco Security Responses (the 40 most recent responses)

[0x1] Attention: New Cisco Security Response RSS Feed Locations

[0x2] Infected Cisco Information Packet and Warranty CDs

[0x3] Cisco IOS Software Denial of Service Vulnerabilities

[0x4] Rootkits on Cisco IOS Devices

[0x5] Cisco IPSec VPN Implementation Group Name Enumeration Vulnerability

[0x6] Multiple Vulnerabilities in Cisco Unified Videoconferencing Products

[0x7] Cisco Unified MeetingPlace XSS Vulnerability

[0x8] Cisco Unified MeetingPlace XSS Vulnerability (November 2007)

[0x9] Cisco IronPort Desktop Flag Plug-in for Outlook Information Disclosure

[0xA] Unmatched Request Discloses Client Internal IP Address

Securelist / Alerts

[0x1] Trojan-Ransom.Win32.Gpcode.ax

[0x2] Email-Worm.Win32.VBMania

[0x3] Net-Worm.Win32.Kido

[0x4] Virus.Win32.Gpcode.ak

[0x5] Email-Worm.Win32.Warezov.nf

[0x6] Email-Worm.Win32.Warezov.mx

[0x7] Email-Worm.Win32.Warezov.ms

[0x8] Email-Worm.Win32.Zhelatin

[0x9] Email-Worm.Win32.Zhelatin.u

[0xA] Email-Worm.Win32.Zhelatin.r

HSC Security Portal

Hackers Center Security Portal is one of the most complete, updated and visited Securty portals on the net. We offer Security Blogs, Exploits, Texts, Tools

[0x1] Scrubyt 0.4

[0x2] Sahi V3

[0x3] UrlParams 2.2.0

[0x4] TemperIE

[0x5] Nikto 2

[0x6] hcraft 1.0.0

[0x7] MSNPawn 1.1

[0x8] httprint

[0x9] DIRB

[0xA] WebInject 1.4

Executive Spotlight Podcasts

Listen online, download to your computer, or subscribe and get the latest information automatically.

[0x1] Executive Spotlight Podcast: County of York, Pennsylvania

[0x2] Executive Spotlight Podcast: IT Transformation at Missouri’s Laclede Gas Company

[0x3] Executive Spotlight Podcast: IT from the CFO's Point of View

[0x4] Executive Spotlight Podcast: IT Security and Privacy at New Jersey’s Barnabas Health

[0x5] Executive Spotlight Podcast: Italian National Cancer Institute

[0x6] Executive Spotlight Podcast: Great Eastern Life Assurance Malaysia

[0x7] Executive Spotlight Podcast: University Hospitals of Leuven

[0x8] Executive Spotlight Podcast: Lotus Renault GP

[0x9] Executive Spotlight Podcast: Deloitte U.K.

[0xA] Executive Spotlight Podcast: Thai Airways International

Shellcodes - Shell-Storm.org

Last shellcodes

[0x1] Linux/x86-64 - Execute /bin/sh - 27 bytes

[0x2] Linux/x86 - [setreuid()] -> [/sbin/iptables -F] -> [exit(0)] - 76 bytes

[0x3] Linux/x86 - nc -lvve/bin/sh -p13377 - 62 bytes

[0x4] NetBSD/x86 - kill all processes shellcode - 23 bytes

[0x5] Windows - xp sp2 PEB ISbeingdebugged shellcode - 56 bytes

[0x6] Linux/x86-64 - add user with passwd - 189 bytes

[0x7] Linux/x86 - Search php,html writable files and add your code - 380+ bytes

[0x8] Linux/x86 - setuid(0)+setgid(0)+add user iph without password to /etc/passwd - 124 bytes

[0x9] Linux/mips - reboot() - 32 bytes

[0xA] Linux/mips - connect back shellcode (port 0x7a69) - 168 bytes

CSOONLINE.com - Metrics/Budgets

[0x1] Case study: What's the business case for GRC?

[0x2] Small company, big security challenges

[0x3] Getting stuff done: Public vs private sector edition

[0x4] 9 secrets of getting stuff done in a big company

[0x5] Survey finds dangerous gap in prevention

[0x6] Case study: Security on a shoestring budget

[0x7] Hey, CSOs: Suck it up and accept budget cuts

[0x8] 10 identity management metrics that matter

[0x9] 2011 State of the CSO

[0xA] Making the ROI case for GRC platforms

TechRadar: All latest news feeds

TechRadar UK latest feeds

[0x1] Raspberry Pi 14-megapixel camera module unveiled

[0x2] Amazon Kindle Fire 10.1-inch tablet coming in Q3?

[0x3] Government blasted for 'cosy' relationship with Google

[0x4] SpaceX launch aborted after last minute engine glitch

[0x5] Tutorial: How to control a PC with your Android phone

[0x6] Review Roundup: This week's hottest reviews on TechRadar

[0x7] GameStop launches mobile service through AT&T for unlocked devices

[0x8] Acer announces new Ivy Bridge travel laptop

[0x9] Facebook finishes first day of trading down $4 (£2.50) from early high

[0xA] Students buy a PC, get a free Xbox 360 from Microsoft

[ISN] InfoSec News Mailing List

InfoSecNews

[0x1] Advance Announcement: 2011 ACM Cloud Computing Security Workshop (CCSW) is back !

[0x2] Unfollowed: How a (Possible) Social Network Spy Came Undone

[0x3] US-Russian dictionary defines cyber war, other concepts

[0x4] ICANN taps DefCon founder for top security spot

[0x5] Teacher Passwords Stolen, Grades Hacked At 3 Seattle High Schools

[0x6] [ACM CCS'11] Reminder: Deadline Approaching (May 6, 2011)

[0x7] Cyberespionage: US finds FBI agents in elite unit lack necessary skills

[0x8] Experts dissect hacker attacks during cybersecurity forum at Hagerstown Community College

[0x9] Are we talking "cyber war" like the Bush admin talked WMDs?

[0xA] Oracle hedging its vulnerability reports?

ZDNET Video

[0x1] The Value of Social Media Data

[0x2] SAP announces startup fund, HANA upgrade program

[0x3] Broadcom CEO touts tech to target precise location indoors

[0x4] Ignition West: How to make money in mobile apps

[0x5] Salesforce's Rypple puts a social spin on performance reviews

[0x6] Game on for Apple's newest iPad

[0x7] Apple launches latest iPad with 4G

[0x8] Apple announces next-gen Apple TV

[0x9] In battling cyberattacks, public-private partnerships the best weapons?

[0xA] Symantec CEO: Companies must avoid 'lockdown'

CSOONLINE.com - Investigations/Forensics

[0x1] Sides dig in as FBI warns of 'going dark' in online era

[0x2] How online black markets work

[0x3] There's no 911 for cybercrime. If there were, would you call?

[0x4] How to fight check fraud

[0x5] Eight online banking scammers arrested in Russia

[0x6] News International security chief arrested in phone hacking case

[0x7] Case study: Surveillance technology for investigations and crowd control

[0x8] Symantec Releases Faster Next-Gen NetBackup, Backup Exec Software

[0x9] Three steps to properly protect your personal data

[0xA] Security at the scene of the crime

Security Leadership

[0x1] Howard Schmidt went the distance

[0x2] #FFSec: Security pros to follow on Twitter, May 18

[0x3] Alan Paller on cutting through the bull

[0x4] ISSA-LA's Security Summit IV is tomorrow

[0x5] Is The Time Right To Spread Your Risk?

[0x6] 'Apocalypse Now' meets #infosec

[0x7] #FFSec: Security pros to follow on Twitter, May 11

[0x8] Leadership coach will keynote ISSA-LA event

[0x9] Live from Hollywood: An #infosec meeting of the minds

[0xA] Things security vendors send me

Hungry Hacker

The Hungry Hacker's Explanation of Everything

[0x1] Our DSL Modem was overheating…

[0x2] Review: Logitech G330 Headset

[0x3] FreeBSD on Linode

[0x4] Buggy Digital Volume Controls

[0x5] Fixing an Office Chair

[0x6] Buying a little more time from my Microsoft Optical Mouse

[0x7] lspci for Windows… Sort of…

[0x8] Super-caching with TimThumb

[0x9] Low-pressure Spyder with Pure Energy Regulator

[0xA] UPnP-IGD on FreeBSD with PF

Zone-H.org Defacements

Latest defacements published by Zone-H.org

[0x1] http://russwed.se

[0x2] http://gbuzzsource.com/bca.html

[0x3] http://www.ihlaw.kr

[0x4] http://banyaninfotech.com/wp-content/themes/GameFusion/x.php

[0x5] http://everythingkw.com/htc.html

[0x6] http://syncsoft.org/htc.html

[0x7] http://fanconexion.com

[0x8] http://www.mdsports.com.au/htc.html

[0x9] http://sudelsur.com

[0xA] http://risejapan-menuett.com

CNET News - Security & Privacy

[0x1] FBI 'looking at' law making Web sites wiretap-ready, director says

[0x2] Facebook sued for $15 billion over alleged privacy infractions

[0x3] Caught snooping: U.K. government staffers

[0x4] Socialcam closes hole that enabled accidental sharing

[0x5] Pirate Bay, WikiLeaks fight off crippling attacks

[0x6] U.S. cybersecurity chief Howard Schmidt retiring

[0x7] Twitter announces support for Do Not Track

[0x8] Friday debut of SF bar-cams stirs sour reception

[0x9] Euclid downplays privacy concerns about Wi-Fi tracking

[0xA] Flashback makers missed out on their payday, Symantec says

phed.org

the rantings of michael eddington

[0x1] Changes to Fuzzing Strategies in Peach 2.3.8

[0x2] Peach Training @ CanSecWest 2011

[0x3] Using Code Coverage to Select Fuzzing Sample Files

[0x4] Using .NET Assemblies with Peach 2

[0x5] Looking forward to Peach 3

[0x6] Fuzzing SQL Stored Procedures

[0x7] Changing Defaults for Data Elements

[0x8] Fuzzing Shared Libraries

[0x9] Peach Dojo @ CanSecWest 2009

[0xA] Still Alive!

Declan McCullagh's Politech

Politech is the oldest Internet resource devoted to politics and technology. Launched in 1994, the Politech mailing list and then the web site has chronicled the growing intersection of law, culture, technology, politics, and law. Edited by Declan McCullagh.

[0x1] Politicians push for mandatory data retention laws, bipartisanly

[0x2] Who'd make the most technology-friendly president? Discuss.

[0x3] Judge rules defendant can't be forced to divulge PGP passphrase

[0x4] ITU botnet paper published in draft form, comments requested

[0x5] David Burt and his Filtering Facts Web site are back

[0x6] FTC Internet advertising summit in Washington this week

[0x7] Hamline University student suspended after pro-gun rights email

[0x8] MIT student picking up friend at airport nearly shot, charged with "infernal machine" crime

[0x9] Paul Levy: Politicians, infomercial kings try to stifle anonymous Internet speech

[0xA] Colorado sheriff creates roadblock so private firm can demand DNA blood samples

CSOONLINE.com - Loss Prevention

[0x1] Will your next car steal itself?

[0x2] There's no 911 for cybercrime. If there were, would you call?

[0x3] How to sneak into a security conference

[0x4] Patent trolls in our midst

[0x5] 10 tips for offsite meeting security

[0x6] Security at the scene of the crime

[0x7] 4 steps retailers can take to combat flash robs

[0x8] Most fraud is an inside job, says survey

[0x9] Theft, shrink rates rise globally

[0xA] World Trade Center security and progress

It's a shampoo world anyway

...la lausige Leben, revisited

[0x1] The grand Hillbilly Bank Robbery

[0x2] NoScript now includes LocalRodeo-like functionality

[0x3] OWASP Germany Conference

[0x4] LocalRodeo (beta) for Firefox 3

[0x5] Travel ahead

[0x6] DeepSec 2007 Roundup

[0x7] Why I do not like taint tracking

[0x8] DNS rebinding at CCS'07

[0x9] CfP: NordSec 2007 - The 12th Nordic Workshop on Secure IT Systems

[0xA] 2nd Rule: You do blog about Bar Camp

Crypto-Gram Security Podcast

Security: Bruce Schneier's monthly Crypto-Gram Newsletter (read by Dan Henage)

[0x1] Crypto-Gram 15 Mar 2012

[0x2] Crypto-Gram 15 Feb 2012

[0x3] Crypto-Gram 15 Jan 2012

[0x4] Crypto-Gram 15 Dec 2011

[0x5] Crypto-Gram 15 Nov 2011

[0x6] Crypto-Gram 15 Oct 2011

[0x7] Crypto-Gram 15 Sep 2011

[0x8] Crypto-Gram 15 Aug 2011

[0x9] Crypto-Gram 15 Jul 2011

[0xA] Crypto-Gram 15 Jun 2011

Hackers For Charity

Hackers For Charity

[0x1] Loko Village Fire Relief.. Thank you.

[0x2] Ivan’s run for HFC!

[0x3] Begging Again…

[0x4]

[0x5] HFC Supporter Running in Marathon Des Sables in Morocco!

[0x6] Fire relief days 17-20

[0x7] Fire relief day 15 saturday

[0x8] Fire relief day 14

[0x9] Thursday

[0xA] Wednesday

Liquidmatrix Security Digest

Bringing Fire To The Village: Your Source For Computer, Network & Information Security News

[0x1] #FreeByron is no more, long live #ByronIsFree (UPDATED) (UPDATED AGAIN)

[0x2] VMWare Vulnerability Security Advisory

[0x3] Stupid Human Tricks: Security Job Interviews

[0x4] You Lose America. CISPA Passes 248-168

[0x5] Onion Browser For iOS Private Browsing

[0x6] EU Parliament To Turn Over Passenger Data To US

[0x7] Iran Says It’s Building A Drone Aircraft Copy

[0x8] Aviva Fires 1,300 Via Email…By Accident

[0x9] Mercedes Adds Remote Updates

[0xA] Link: Apple holds the master decryption key when it comes to iCloud security, privacy

Computerworld Blogs

[0x1] Peeking under the hood of Chrome browser reveals cpu hog

[0x2] Motorola updates its Android 4.0 upgrade plan -- and it isn't all good news

[0x3] Workforce IT program: A model for debt-free college education

[0x4] Microsoft says Windows Phone beats the iPhone in China

[0x5] Apple TV: exec says it's coming 'soon'

[0x6] Just trying to maintain that tech high-priesthood

[0x7] Huge HP layoff: Whitman to decimate troops

[0x8] Expect Windows 8 PCs to be pre-loaded with bloatware

[0x9] Apple, the iPhone, and the future of healthcare

[0xA] What could be simpler?

Rational Survivability

Hoff's Ramblings about Information Survivability, Information Centricity, Risk Management and Disruptive Innovation.

[0x1] Overlays: Wasting Away Again In Abstractionville…

[0x2] Tin Foil Hats: On BBQ Brisket & Security Purists…

[0x3] Incomplete Thought: Will the Public Cloud Create a Generation Of Network Stupid?

[0x4] Security As A Service: “The Cloud” & Why It’s a Net Security Win

[0x5] SEO Twitter: The Emotion of Self-Promotion…

[0x6] March 16, 2012: @Beaker’s Tweets O’ the Week…

[0x7] A Funny Thing Happened On My Way To Malware Removal…

[0x8] Why Steeling Your Security Is Less Stainless and More Irony…

[0x9] You Know What’s Dead? Security…

[0xA] Hoff’s RSA 2012 Schedule: My Talks, Panels, Seminars & Such

contagio

malware dump

[0x1] See you in two weeks

[0x2] May 3 - CVE-2012-0779 World Uyghur Congress Invitation.doc

[0x3] 019 Speech.doc MacOS_X/MS09-027.A -exploit for MS Word on Snow Leopard OSX

[0x4] Xpaj -MBR rootkit sample - sample

[0x5] Operation Cleanup Japan (OCJP) by 0Day.jp May 3

[0x6] CVE-2012-0158 - South China Sea, Insider Information and other samples and analysis

[0x7] DarkMegi rootkit - sample (distributed via Blackhole)

[0x8] Java OSX CVE-2012-0507, CVE-2011-3544 and Flashback.35/J sample

[0x9] OSX/Flashback.K sample + Mac OS malware study set (30+ older samples)

[0xA] OSX Flashback URLs, Domains, etc

SecDocs Feed

Latest security documents RSS feed

[0x1] [Video] r0ket

[0x2] [Video] Building and Giving Away: Motivations

[0x3] [Slides] r0ket

[0x4] [Slides] Building and Giving Away: Motivations

[0x5] [Video] The blackbox in your phone

[0x6] [Slides] The blackbox in your phone

[0x7] [Video] Space Federation

[0x8] [Video] Transition Telecom

[0x9] [Video] Stuff you don't see - every day

[0xA] [Slides] Stuff you don't see - every day

MSDN Blogs

via RSS Feed & Other Development Resources

[0x1] Progress on CodePlex pull requests

[0x2] Progress on CodePlex pull requests

[0x3] Progress on CodePlex pull requests

[0x4] Progress on CodePlex pull requests

[0x5] Rejoignez le mouvement de libération des données publiques en créant votre site Open Data en quelques clics !

[0x6] Getting an App in the Windows Store: What, Why, and How

[0x7] CloudTip #14-How do I get SQL Profiler info from SQL Azure?

[0x8] CloudTip #14-How do I get SQL Profiler info from SQL Azure?

[0x9] How to get a registration code for the Windows Store

[0xA] Six0Run Scores Big with Windows Azure

NoScript Updates

Recent stable releases from noscript.net

[0x1] NoScript 2.4.1

[0x2] NoScript 2.4

[0x3] NoScript 2.3.9

[0x4] NoScript 2.3.8

[0x5] NoScript 2.3.7

[0x6] NoScript 2.3.6

[0x7] NoScript 2.3.5

[0x8] NoScript 2.3.4

[0x9] NoScript 2.3.3

[0xA] NoScript 2.3.2

TraverseCode.com

Malware Research Blog

[0x1] Analysis of *Document* Stealer Trojan Developed in Perl

[0x2] |From: PDF@Exploit| |To: Zeus@Trojan| |Subject: Steals Bank Credentials|

[0x3] Don’t press F1 key in Windows XP

[0x4] Traversing a ‘DLL’: Financial Crimeware (Banker)

[0x5] Orkut Phishing using Blogspot account

[0x6] Social Engineering – Fake TwitterIM Download

[0x7] Scam Mail targeting Indian users “Tax Refund Online Form”

[0x8] Chase Bank Phishing scam Mail

[0x9] Traversing a Financial Crimeware which uses Proxy Technique

[0xA] 1st Rogue Mail in 2010

Business Continuity

[0x1] CISOs Must Act As The Glue Between BC, DR And Security

[0x2] Business Continuity Standards Don’t Matter -- But They Should

[0x3] Communication And Coordination Should Be The Cornerstone Of Your BC Plan

[0x4] Workarounds without data?

[0x5] More evidence critical infrastructure is a train wreck waiting to happen

[0x6] SECURITY WISDOM WATCH: SOPA-PIPA edition

[0x7] Key Sessions at CISO Executive Summit 2011

[0x8] Securing Mobile Data at the Application Layer

[0x9] Security Metrics and the Balanced Scorecard

[0xA] The Dark Side of Collaboration

CSOONLINE.com - Federated Identity

[0x1] Leverage government innovation to reduce the risks of Web 2.0 identity management

[0x2] SaaS, Security and the Cloud: It's All About the Contract

[0x3] Social Networking a Tool for More Secure Identity Management? No Joke!

[0x4] News Flash: Data Debauchery That Happens in Vegas Doesn't Stay There

[0x5] Why Security Pros Hate Microsoft SharePoint (and What to Do About It)

[0x6] Federated ID: An Idea Whose Time Never Came?

[0x7] Identity Management: Implementation Dos and Dont's

[0x8] Identity Management: Critical Components

[0x9] An Introduction to Identity Management

[0xA] Strong Authentication for Online Banking: Success Factors

Http server Vulnerabilities in World Laboratory of Bugtraq 2 (CVEMAP)

Http server Vulnerabilities - CXSecurity WLB2CVEMAP Database

[0x1] CVE-2012-0883: envvars (aka envvars-std) in the Apache ...

[0x2] CVE-2012-1181: fcgid_spawn_ctl.c in the mod_fcgid modul...

[0x3] CVE-2012-0053: protocol.c in the Apache HTTP Server 2.2...

[0x4] CVE-2012-0031: scoreboard.c in the Apache HTTP Server 2...

[0x5] CVE-2012-0021: The log_cookie function in mod_log_confi...

[0x6] CVE-2011-4415: The ap_pregsub function in server/util.c...

[0x7] CVE-2011-4317: The mod_proxy module in the Apache HTTP ...

[0x8] CVE-2011-3639: The mod_proxy module in the Apache HTTP ...

[0x9] CVE-2011-3607: Integer overflow in the ap_pregsub funct...

[0xA] CVE-2011-3368: The mod_proxy module in the Apache HTTP ...

eWEEK Security

News, reviews and commentary on technology security and data, application and network integrity, anti-virus and more.

[0x1] Is Network Solutions Snatching Domain Names?

[0x2] Reforming the DisGrace Period

[0x3] Critical TCP/IP Worm Hole Dings Windows Vista

[0x4] RSA Lays Off Security, Sales Staff

[0x5] Phishing at the Top Level

[0x6] Spam on the Run: Notorious Spammer on the Lam

[0x7] Microsoft: Critical Vista Patch Coming

[0x8] Code Testing Tools Could Be Acquisition Targets in '08

[0x9] More Bad Drivers on the Information Superhighway

[0xA] Passenger Hacks NYC Taxi Computer System

PandaLabs Blog

Everything you need to know about Internet threats

[0x1] Where is the lulz now?

[0x2] Michael Jackson catalogue stole from Sony. More to come?

[0x3] Bot shopping with my wife

[0x4] PandaLabs Annual Report – 2011

[0x5] Katy Perry and Russell Brand baits to spread a new Facebook worm

[0x6] Sex, lies and Twitter

[0x7] Megaupload and the cybercrime fight

[0x8] The Rise of the Ransomware

[0x9] 2012 Security Trends

[0xA] Could targeted attacks be avoided?

Splunk Blogs

[0x1] Splunk = Customer Satisfaction

[0x2] Analytics Staffing for Big Data: A Perspective

[0x3] Dallas Splunk Users Group – June 12th @ 6:00p CST

[0x4] #SplunkGovt Twitter Chat: A Sneak Peak at What We’ll Explore at SplunkLIVE! Washington, D.C.

[0x5] Doing More With What You Have

[0x6] That happened: episode 9

[0x7] Quantifying the Benefits of Splunk with SSDs

[0x8] Identifying Phishing Sites in Your Events

[0x9] I invested in a shiny new tool/technology…

[0xA] That happened: episode 8

CSOONLINE.com - Physical Security

[0x1] Commercial enterprises are putting our critical infrastructure at risk

[0x2] The future of SCADA-control security

[0x3] Making the case for preventing workplace violence

[0x4] Case study: Surveillance technology for investigations and crowd control

[0x5] A clear-eyed look at APT

[0x6] CSO's Ultimate Guide to Social Engineering

[0x7] Network Security Isolationism must die

[0x8] 10 tips for offsite meeting security

[0x9] Security at the scene of the crime

[0xA] FAQ: What You Should Know About Illinois Water-District SCADA Breach

CERIAS Blog

[0x1] Keynote: Howard Schmidt (Keynote Summary)

[0x2] Security Fireside Chat (Summary)

[0x3] Panel #3: Securing Mobile Devices (Panel Summary)

[0x4] Panel #2: Big Data Analytics (Panel Summary)

[0x5] Panel #1: Securing SCADA Systems (Panel Summary)

[0x6] Opening Keynote: Arthur W. Coviello, Jr. (Keynote Summary)

[0x7] An Interesting Opportunity

[0x8] Gene Schultz, R. I. P.

[0x9] More than passive defense

[0xA] Bullies, Pirates and Lulz

XSSed syndication

You are welcome to syndicate and share xssed.com contents

[0x1] www.120.li XSS

[0x2] www.shop.nsw.gov.au XSS

[0x3] au.msi.com XSS

[0x4] www.amazon.com XSS

[0x5] suivi.chronopost.fr XSS

[0x6] www.scientology.org XSS

[0x7] new.davidguetta.com XSS

[0x8] www.davidguetta.com XSS

[0x9] www.shacombank.com.hk XSS

[0xA] games.ru.msn.com XSS

The Web Application Security Consortium / FrontPage

The Web Application Security Consortium (WASC) is an international group of experts, industry practitioners, and organizational representatives who produce open source and widely agreed upon best-practice security standards for the World Wide Web.

[0x1] Robert Auger edited FrontPage

[0x2] Robert Auger edited FrontPage

[0x3] Robert Auger edited FrontPage

[0x4] Robert Auger edited FrontPage

[0x5] Robert Auger edited FrontPage

[0x6] Robert Auger edited FrontPage

[0x7] Robert Auger edited FrontPage

[0x8] Robert Auger edited FrontPage

[0x9] Robert Auger edited FrontPage

[0xA] Robert Auger edited FrontPage

ITWeb Computing

Latest ICT Computing news

[0x1] Sony delays Gran Turismo release

[0x2] MS calls for student innovators

[0x3] Data centres get innovative

[0x4] Sony Ericsson pioneers green phone

[0x5] Fujitsu offers USB zero client

[0x6] Grade 11 wins Computer Olympiad

[0x7] Intel powers local youth

[0x8] Best-case cloud computing years away

[0x9] Desktop virtualisation demand surges

[0xA] Czech operators support mobile payment

HBH News Feed

HellBoundHackers RSS Feed

[0x1] Iran confirms cyberattacks against oil facilities

[0x2] Google boosts Web bug bounties to $20,000

[0x3] Mac Flashback malware

[0x4] Will it Take a Law to Protect Online Privacy?

[0x5] Microsoft leads seizure of Zeus cybercrime servers

[0x6] Hackers Publish Exploit for Wormable RDP Hole

[0x7] US charges members of Anonymous

[0x8] New Mac malware exploits Java bugs

[0x9] Iran cuts off Web sites

[0xA] HBH v2 Update

Government Technology

[0x1] Government Technology - January 2009

[0x2] Government Technology - December 2008

[0x3] Government Technology - December 2008

[0x4] Government Technology - November 2008

[0x5] Government Technology - November 2008

[0x6] Government Technology - October 2008

[0x7] Government Technology - October 2008

[0x8] Government Technology - September 2008

[0x9] Government Technology - September 2008

[0xA] Government Technology - August 2008

The TSA Blog

Terrorists Evolve. Threats Evolve. Security Must Stay Ahead. You Play A Part.

[0x1] This blog has moved

[0x2] Traveling With Airbags

[0x3] Advanced Imaging Technology Off To a Great Start

[0x4] Response to: TSA to Download Your iTunes?

[0x5] Federal Air Marshals on Flight 663

[0x6] Traveling with E-readers, Netbooks, and Other Small Gadgets (Including the iPad)

[0x7] Advanced Imaging Technology - Yes, It's Worth It

[0x8] Helping Wounded Warriors

[0x9] Advanced Imaging Technology: "Radiation Risk Tiny"

[0xA] Live Aviation Security Chat with Secretary Napolitano on Facebook 3/9/10

Smart Security by Dharmesh M Mehta

An Application Security Blog

[0x1] What do you say? Yes / No / Don't Care

[0x2] 7 UID bogus centers shut down

[0x3] Mobile Apps Security – Are you worried?

[0x4] Simple Autocomplete

[0x5] Past few months

[0x6] OTP adoption from India to the US?

[0x7] Getting Hands Dirty with Ettercap Tool

[0x8] About the 'Rugged' Initiative

[0x9] Plenty of (IN)Secure Broadband Routers

[0xA] Mumbai to Host India’s First e-Crime Forum

SriniCenthala

Welcome ! You come to the right place for datawarehouse , Business Intelligence BI , Extraction Transformation and Loading ETL Process , Decision Support System (DSS) and OLTP System Design , Data Modeler , Data Architect who has extensive experience in building Very Large Systems. Project Management process PMI Process and PMP Certification. Provide help to any one who wants to know about PMO Office setup & also handling any IT Projects.

[0x1] Wish You Happy New Year 2011 !

[0x2] Study in India: www.eduhelp.in

[0x3] Stay Agile & Succeed - Pairworks - Agile Project Management Tool On-Demand

[0x4] PureApp.com - Monitor & Control Continues Integration On-Demand

[0x5] "There are times brick hits your head!"..."Do not lose your faith on what you love to do!"

[0x6] Agile Project Management Tool - www.PairWorks.com

[0x7] Planning for "eServicePlace LinkedIn Application"

[0x8] New Launch of Datamartist

[0x9] eServicePlace.com How it works

[0xA] New Services Market Place , so What for you?

CSOONLINE.com - Strategic Planning/ERM

[0x1] Case study: What's the business case for GRC?

[0x2] Managing information security during an innovation void

[0x3] Tactics versus strategy

[0x4] What are your risk managers thinking about?

[0x5] How your signature can propel your security career

[0x6] 9 secrets of getting stuff done in a big company

[0x7] How to have real risk management

[0x8] Laggard to leader: What it takes to get there

[0x9] 5 secrets to building a great security team

[0xA] 2011 State of the CSO

PenTestIT

Your source for Information Security Related information!

[0x1] GAME: Keeper of the Grove

[0x2] Revelo: The Javascript Deobfuscator!

[0x3] ClubHACK Magazine May 2012!

[0x4] Quarks PwDump: The Windows Credentials Extractor!

[0x5] Orion Browser Dumper: Advance browser forensic tool

[0x6] UPDATE: Microsoft EMET v3!

[0x7] UPDATE: Ophcrack LiveCD 3.4.0!

[0x8] File Repair: Tool to repair and recover corrupted popular files

[0x9] Sslcaudit: Perform Security Audits of SSL/TLS Clients!

[0xA] UPDATE: Mutillidae 2.1.19!

StoneBlog.stonesoft.com

Share knowledge about StoneGate

[0x1] Security Right-Sizing

[0x2] How A2Cloud helps Mobile Device Management

[0x3] What Should You Takeaway from the Global Payments, Inc. Breach?

[0x4] Stonesoft SSL VPN 1.5.100: BYOD at your service

[0x5] Stonesoft 5.4 – Other Enhancements

[0x6] Security Issues in IPv6 Transition (Guest Post from Brian Monkman, ICSA Labs)

[0x7] Stonesoft 5.4 – LEEF Forwarding/Reception Support

[0x8] An Update on Stonesoft’s IPv6 Readiness

[0x9] 7 ways to love the A2Cloud

[0xA] Stonesoft 5.4 – Inspection Improvements

Will Hack For SUSHI

Hacking and Defending Wireless

[0x1] Things I Wish Amazon.com Didn’t Tell Me

[0x2] The Changing Wireless Attack Landscape

[0x3] Pen Test Perfect Storm 6: We Love Cisco!

[0x4] ISACA Review: Hacking Exposed Wireless 2nd Edition

[0x5] Packet Capture Payload Assessment

[0x6] GIAC GAWN Ethical Hacking Wireless Testing Aid

[0x7] Reflections on “hole196″

[0x8] Evading IPS/IDS with TCP Checksum Forgery

[0x9] FaceTime Protocol Analysis

[0xA] WiMAX Network Scanning Work-in-Progress

Mu Dynamics Blog

[0x1] Spirent acquisition of Mu Dynamics marries heavyweight load-bearing, barrage-level security testing | Security Bistro http://bit.ly/IoitP5

[0x2] Why Cloud is Bad for Startups

[0x3] NoOps, ShmoOps and Somebody Else’s Problem

[0x4] Adding New Relic Analytics to Blitz

[0x5] Security Advisories MU-201202-01 and MU-201202-02 for GnuTLS and Libtasn1

[0x6] blitz.io: Using Redis Transactions with CouchDB

[0x7] How to win in the age of cyber war

[0x8] Validating Application Detection Signatures

[0x9] Dear Angry Nerds, meet Blitz the Bird Thrower

[0xA] 4 full bars but no buzz?… start doing DPI

Securelist / Descriptions

[0x1] Porn-Tool.Win32.StripDance.d

[0x2] Hoax.HTML.OdKlas.a

[0x3] Hoax.HTML.Agent.i

[0x4] not-a-virus:AdWare.Win32.Sushi.a

[0x5] Trojan-Clicker.JS.Agent.op

[0x6] Trojan.JS.Redirector.os

[0x7] Trojan.JS.Fraud.ba

[0x8] not-a-virus:AdWare.Win32.WhiteSmoke.a

[0x9] Trojan-GameThief.Win32.Nilage.ipj

[0xA] Trojan-Downloader.JS.Agent.ftu

Site Home

[0x1] Blog Post: 次の世代の信頼できるコンピューティング

[0x2] Blog Post: Top 10 Wiki Ninjas: Richard Mueller (Directory Services Development MVP) helps maintain TechNet Wiki

[0x3] Blog Post: Jordan Crook and Matt Burns from TechCrunch Probe Hackers for Info About Hackathon

[0x4] Blog Post: Known Issues for Upgrading Active Directory to Windows Server 2008R2 from Windows 2003

[0x5] Blog Post: SharePoint - remoting PS

[0x6] Blog Post: [Dongclee의 2012년 5월 세 번째 포스팅] Windows Server 2012 Series 10 : 무거운 CRL(Certificate Revocation List)을 버리고, 날렵한 OCSP(Online Certificate Status Protocol)을 사용합시다

[0x7] Blog Post: Aggiornamenti di sicurezza tramite Common Vulnerability Reporting Framework

[0x8] Blog Post: The Windows 8 User Experience Gets Explained

[0x9] Blog Post: TechCrunch Hackaton Starts Today: Get Updates about Microsoft BizSpark Startups

[0xA] Blog Post: 30 Days of Windows Phone App Development Tips – Week Three

Uninformed Journal

Informative information for the uninformed

[0x1] Using dual-mappings to evade automated unpackers

[0x2] Analyzing local privilege escalations in win32k

[0x3] Exploiting Tomorrow's Internet Today: Penetration testing with IPv6

[0x4] Can you find me now? Unlocking the Verizon Wireless xv6800 (HTC Titan) GPS

[0x5] An Objective Analysis of the Lockdown Protection System for Battle.net

[0x6] ActiveX - Active Exploitation

[0x7] Context-keyed Payload Encoding

[0x8] Improving Software Security Analysis using Exploitation Properties

[0x9] Real-time Steganography with RTP

[0xA] PatchGuard Reloaded: A Brief Analysis of PatchGuard Version 3

PenTester Scripting

[0x1] discovery:ssl_tests

[0x2] authors:jason_haddix

[0x3] discovery

[0x4] mapping

[0x5] mapping:nmap_open_port_stats - created

[0x6] exploitation

[0x7] exploitation:p0wnpr0xy - created

[0x8] mapping:userpass - created

[0x9] exploitation:sqlinjector - created

[0xA] exploitation:get_to_post - created

Latest MITRE News

The MITRE Corporation is a not–for–profit organization chartered to work in the public interest. As a national resource, we apply our expertise in systems engineering, information technology, operational concepts, and enterprise modernization to address our sponsors' critical needs.

[0x1] MITRE Celebrates Move to New Building in Shiloh, Ill.

[0x2] MITRE Announces Leadership Appointments

[0x3] CWE Compatibility Certificates Awarded

[0x4] MITRE Employees Honored at Black Engineer of the Year STEM Conference

[0x5] MITRE CEO Alfred Grasso Named to Federal 100 List

[0x6] MITRE Engineers Use Positive Deviance Approach to Identify and Advance Successful Practices in Systems Engineering

[0x7] MITRE's Lillian Zarrelli Ryals Named Board Chair of Women in Aerospace

[0x8] MITRE Named to Glassdoor.com's 50 Best Places to Work List

[0x9] Conclusion of First MITRE Challenge Brings New Way to Fast–Track Ideas

[0xA] Service–Oriented Architecture for e–Government Conference Spotlights Composable Services

Paul Golding - International Technology Consultant

Product and Technology Visionary

[0x1] 7 Databases in 7 Weeks – a valuable book

[0x2] Building an Ideas Culture – Is it a Good Idea?

[0x3] Innovators are us…

[0x4] Art.com

[0x5] O2 UK

[0x6] Navteq

[0x7] Vision Mobile

[0x8] McLaren Applied Technologies

[0x9] Acision

[0xA] Naspers

Virtual Shadows has MOVED!

[0x1] Virtual Shadows is MOVING!

[0x2] Hacking programmable road signs

[0x3] David Lacey likes my book!

[0x4] Censoring your blog

[0x5] Book launch on Monday Central London

[0x6] ouch ....

[0x7] Achieving miracles when times are tough

[0x8] The book arrived on Tuesday

[0x9] Your iPhone as a wind instrument!

[0xA] China's Net Nannies have been busy

iSecur1ty - Arab Security Community

مجتمع عربي للهاكر الأخلاقي وخبراء الحماية يركّز على مفهوم اختبار الاختراق وجديد أخبار الحماية والثغرات, شروحات فيديو ومقالات أمنيّة.

[0x1] فيديو : هجمات browser_autopwn بأستخدام SET

[0x2] فيديو : أختبار أختراق الحسابات داخل الشبكه

[0x3] فيديو : أختبار الأختراق بصيغه Doc

[0x4] فيديو : أختبار الأختراق بصيغه jar

[0x5] للمرة الاولي في مصر ورشة عمل وملتقى مهندسي أمن المعلومات بالمعهد المصرفي المصري

[0x6] فيديو : شرح هجمات multi_attack بأستخدام SET

[0x7] فيديو : برنامح logwatch

[0x8] فيديو : شرح أداه Beef

[0x9] مؤتمر كات سكوب

[0xA] فيديو : شرح أداه zap proxy

SearchSecurity: Security Wire Daily News

The latest information security news on IT threats, vulnerabilities and market trends from the award-winning SearchSecurity.com.

[0x1] Praise, criticism for retiring cybersecurity coordinator Howard Schmidt

[0x2] PCI Council urges P2P encryption for mobile payments

[0x3] Steve Lipner on the Microsoft SDL, critical infrastructure protection

[0x4] Android security model doing best to enable mobile malware spread

[0x5] Gartner report: UTM market on the upswing, expert says

[0x6] BeyondTrust acquires eEye Digital Security for vulnerability management

[0x7] May 2012 Patch Tuesday: Microsoft fixes Duqu Trojan ghost code

[0x8] Gary McGraw: Eliminating badware addresses malware problem

[0x9] Adobe pushes patch for actively exploited Flash Player vulnerability

[0xA] Microsoft program breach led to early RDP vulnerability exploit

Security-Shell

Hacking and Security tools . News and Views for the World ®

[0x1] Web Application Penetration testing with Google Chrome Browser

[0x2] Updates: Autoruns v 11.3, LiveKd v 5.2 and Strings v 2.5

[0x3] WebVulScan - Web Application Vulnerability Scanner

[0x4] sqlcake v.1.1 Released

[0x5] MS12-032 - Vulnerability in TCP/IP Could Allow Elevation of Privilege

[0x6] Vulnerability Assessment - Information Assurance Tools Report

[0x7] SQLSentinel v.0.1

[0x8] Updates: NotMyFault, Process Monitor v3.01 and TestLimit v 5.2

[0x9] RAFT - Response Analysis and Further Testing Tool

[0xA] Blackbox DOM-based XSS Scanner

Panda Research Blog

Leading the way in proactive malware detection

[0x1] Q2 2011 Test Results of Security Suites

[0x2] Tis the comparative season

[0x3] Microsoft’s 6-year long open door to malware

[0x4] Panda Antivirus Command Line Scanner 9.5.1.2

[0x5] AV-Test.org 2010 Test Results

[0x6] Microsoft just doesn’t get it…. Security is about diversity

[0x7] Dear Microsoft: Please Stop Pushing Potentially Unwanted Software Through Windows Update

[0x8] Virus Bulletin 2010

[0x9] AV-Comparatives Performance Test 2010

[0xA] PC Security Labs July 2010 Test Results

Dr Anton Chuvakin Blog PERSONAL Blog

LogChat: Andrew Hay and Anton Chuvakin talk about logging, log management and related topics

[0x1] Links for 2012-05-18 [del.icio.us]

[0x2] Book Review: “Security De-Engineering: Solving the Problems in Information Risk Management” by Ian Tibble

[0x3] Links for 2012-05-17 [del.icio.us]

[0x4] Links for 2012-05-08 [del.icio.us]

[0x5] Monthly Blog Round-Up – April 2012

[0x6] Links for 2012-04-30 [del.icio.us]

[0x7] Metricon 7 Call for Papers

[0x8] Links for 2012-04-22 [del.icio.us]

[0x9] Links for 2012-04-04 [del.icio.us]

[0xA] Monthly Blog Round-Up – March 2012

ARN Security

ARN Security

[0x1] Twitter jumps on Do Not Track bandwagon

[0x2] Windows 8 security: What's new

[0x3] Download the Insider Threat Deep Dive Report

[0x4] Imperva appoints DNA as second Australian distributor

[0x5] Anonymous Takes Aim at Indian Government

[0x6] iPhone, iPad become apple of cyber criminals' eye

[0x7] Windows 8: Microsoft tries to rein in crapware

[0x8] Social media bring business, but add security quagmire

[0x9] Paging Mr. Phelps: This SSD will self-destruct....

[0xA] Smartphone security is heading for 'apocalypse'

CSOONLINE.com - Video Surveillance

[0x1] Will Obama preside over the coming of Big Brother?

[0x2] There's no 911 for cybercrime. If there were, would you call?

[0x3] Case study: Surveillance technology for investigations and crowd control

[0x4] 10 tips for offsite meeting security

[0x5] Security at the scene of the crime

[0x6] U.S. border security strategy faces budget woes

[0x7] Video surveillance: The march to megapixel IP cameras continues

[0x8] World Trade Center security and progress

[0x9] The 2nd annual CSO holiday gift guide

[0xA] TSA and the freedom thing: We're the problem

LinuxSecurity.com: OpenBSD Advisories

The central voice for Linux and Open Source security news.

[0x1] Study: Spammers use e-mail ID to gain legitimacy

[0x2] Password guessing with Medusa 2.0

[0x3] OpenBSD: kernel heap overflow in IPsec

[0x4] OpenBSD: login_radius security flaw

[0x5] OpenBSD: Xpm security fix

[0x6] OpenBSD: zlib reliabilty fix

[0x7] OpenBSD: cvs Multiple vulnerabilities

[0x8] OpenBSD: cvs Heap overflow vulnerability

[0x9] OpenBSD: procfs Incorrect bounds checking vulnerability

[0xA] OpenBSD: cvs Pathname validation vulnerabilities

Networking/Security Forums

Security Forums Dot Com :: Share Your Knowledge

[0x1] Connecting Storage Arrays and Server

[0x2] Virus damaged computer

[0x3] What's the deal w/ StopZilla...???

[0x4] USB audio problem

[0x5] Vacation Tracking Software

[0x6] Browser Lags or stalls

[0x7] Learning from Windows to Linux

[0x8] dual ISP routers

[0x9] Dhcp

[0xA] ip not resolving

Techworld.com networking

Latest IT articles from Techworld's networking channel

[0x1] Fibre broadband to be rolled out to 90% o rural Rutland by BT

[0x2] Japanese researchers break record for Terahertz Wi-Fi transmission

[0x3] Angry Birds tops corporate mobile blacklist, Facebook, YouTube follow

[0x4] Compuware brings APM to cloud and Big Data applications

[0x5] From packet inspectors to WAN optimisers, network add-ons are all the rage

[0x6] Verizon to offer 100G links, make optical networks more resilient

[0x7] IP network run over xylophones by California researchers

[0x8] Wi-Fi-Blocking wallpaper keeps your signal in and intruders out

[0x9] Virtualise the rest of the data centre, VMware recommends at Interop

[0xA] Small cells could raise big problems for mobile operators

lkml.org :

lkml.org - the realtime linux kernel mailinglist archive

[0x1] Re: [RFC/RFT 5/5] p54spi: Load firmware from work queue and not fr ...

[0x2] Re: [RFC/RFT] p54spi: Convert driver to use asynchronous firmware ...

[0x3] Re: Incorrect uses of get_driver()/put_driver()

[0x4] Re: Incorrect uses of get_driver()/put_driver()

[0x5] Re: Incorrect uses of get_driver()/put_driver()

[0x6] Re: loading firmware while usermodehelper disabled.

[0x7] Re: loading firmware while usermodehelper disabled.

[0x8] Re: loading firmware while usermodehelper disabled.

[0x9] Huge amount of randomness with cuse and "urandompar"

[0xA] Re: [PATCH] drivers/ssb/driver_chipcommon_pmu.c: uninitilized warning

SANS Information Security Reading Room

Last 25 Computer Security Papers added to the Reading Room

[0x1] SANSFIRE 2011

[0x2] Risk Assessment of Social Media

[0x3] Shedding Light on Security Incidents Using Network Flows

[0x4] In-house Penetration Testing for PCI DSS

[0x5] A Regular Expression Search Primer for Forensic Analysts

[0x6] Diskless Cluster Computing: Security Benefit of oneSIS and Git

[0x7] Detailed Analysis Of Sykipot (Smartcard Proxy Variant)

[0x8] Remote Access Point/IDS

[0x9] Post Exploitation using Metasploit pivot & port forward

[0xA] A Complete Guide on IPv6 Attack and Defense

Rational Survivability

PLEASE NOTE: I HAVE PERMANENTLY MOVED MY BLOG TO http://www.rationalsurvivability.com/blog <-- All these posts/comments have been moved there and all new posts since May 2009 appear there.

[0x1] IMPORTANT REMINDER: My Blog and RSS Feed Have Moved To http://www.rationalsurvivability.com/blog

[0x2] IMPORTANT REMINDER: My Blog and RSS Feed Have Moved

[0x3] IMPORTANT: Moving My Blog & RSS Feed

[0x4] BeanSec! Wednesday, March 18, 2009 - 6PM to ?

[0x5] How To Be PCI Compliant in the Cloud...

[0x6] On the Overcast Podcast with Geva Perry and James Urquhart

[0x7] More On Clouds & Botnets: MeatClouds, CloudFlux, LeapFrog, EDoS and More!

[0x8] Source Boston - Video Interviews of Security Rockstars...

[0x9] Oh Noes: We Can't Monitor/Protect Against Intra-VM Traffic!

[0xA] Sun vs. Cisco? I'm Getting My Popcorn...

Identity Theft Blog

Welcome to the most progressive identity theft blog which includes hundreds of original identity theft articles written by Henry Bagdasarian.

[0x1] May 11, Electronic Pick Pocketing

[0x2] May 2, Spoofed Email Spams

[0x3] Apr 29, Fraud Training

[0x4] Apr 22, Email Spoofing

[0x5] Apr 18, Trusted Cyberspace Identity Strategy

[0x6] Apr 9, Identity Force Service Review

[0x7] Apr 1, Address Change Fraud

[0x8] Mar 13, Fraud Alerts

[0x9] Mar 5, Identity Theft Prevention Program

[0xA] Feb 28, Bad Business Reputation

DEF CON 18 [Audio] Speeches from the Hacker Convention.

DEF CON 18 [Audio] Speeches from the Hacker Convention.

[0x1] A.P. Delchi - Physical Security : You're Doing It Wrong!

[0x2] Adam Pridgen & Matt Wollenweber - Toolsmithing an IDA Bridge, Case Study for Building a Reverse Engineering Tool

[0x3] Adrian Crenshaw - Programmable HID USB Keystroke Dongle: Using the Teensy as a Pen Testing Device

[0x4] Ki-Chan Ahn & Dong-Joo Ha - Malware Migrating to Gaming Consoles: Embedded Devices, an Antivirus-Free Safe Hideout For Malware

[0x5] Andrew Kongs & Dr. Gerald Kane - Training the Next Generation of Hardware Hackers -- Teaching Computer Organization and Assembly Language Hands-On with Embedded Systems

[0x6] Anthony Lai, Jake Appelbaum & Jon Oberheide - The Power of Chinese Security

[0x7] Anthony Lineberry, David Luke Richardson & Tim Wyatt - These Aren't the Permissions You're Looking For

[0x8] Barrett Weisshaar & Garret Picchioni - The Night The Lights Went Out In Vegas: Demystifying Smartmeter Networks

[0x9] Barnaby Jack - Jackpotting Automated Teller Machines Redux

[0xA] Blake Self & bitemytaco - Hacking DOCSIS For Fun and Profit

Gremwell blogs

[0x1] Release of sslcaudit 1.0

[0x2] Does your test system support SSLv2?

[0x3] Release of sslcaudit v1.0 RC1

[0x4] Yet Another Portscanner (in Python)

[0x5] We Are Hiring

[0x6] MagicTree 1.1 Released

[0x7] Installing Arachni from Source on Ubuntu 11.04 (Natty)

[0x8] NeXpose XML - A Rant

[0x9] MagicTree Forum

[0xA] A tool to search for serialized Java objects in a binary stream

OVAL Repository Latest Updates

This feed provides information about the latest updates to the OVAL Repository, including new OVAL definitions; definitions that have changed status (e.g., from Draft to Interim or Interim to Accepted); and definitions that have been modified is posted here. Each update to the OVAL Repository will also update this feed. The OVAL Repository is updated as edits and additions are completed. It is possible for this feed to be updated several times per day, but updates rarely occure more often than once per day.

[0x1] Definition oval:org.mitre.oval:def:8595 has been added to the OVAL Repository.

[0x2] Definition oval:org.mitre.oval:def:844 has been added to the OVAL Repository.

[0x3] Definition oval:org.mitre.oval:def:7709 has been added to the OVAL Repository.

[0x4] Definition oval:org.mitre.oval:def:7517 has been added to the OVAL Repository.

[0x5] Definition oval:org.mitre.oval:def:7438 has been added to the OVAL Repository.

[0x6] Definition oval:org.mitre.oval:def:7436 has been added to the OVAL Repository.

[0x7] Definition oval:org.mitre.oval:def:7397 has been added to the OVAL Repository.

[0x8] Definition oval:org.mitre.oval:def:7224 has been added to the OVAL Repository.

[0x9] Definition oval:org.mitre.oval:def:7214 has been added to the OVAL Repository.

[0xA] Definition oval:org.mitre.oval:def:7182 has been added to the OVAL Repository.

GFI Labs blog

A blog about activities, products and ideas at GFI (formerly Sunbelt Software), one of the leading developers of security software to protect against spyware, spam and other threats.

[0x1] Tumblr Dating Game? No Me Gusta.

[0x2] Malware Poses as Rainmeter Skins on deviantART

[0x3] The Diablo No-No.

[0x4] New Twitter Spam Run Leads to Android Rogue AV

[0x5] VIPRE® Report for April: Be Careful When Browsing Social Networking Sites

[0x6] Mass Trollface Spam hits Tumblr

[0x7] Is Your System DNS Changer-free?

[0x8] Surveys and “Pinterest Invites” Lurk on Google Play

[0x9] First GFI Partners’ Conference in the Philippines Held in Manila

[0xA] OpFake Goes Undercover as GTA3 10th Anniversary Edition

The Geek Stuff

Guides, HowTos and Tips for Technology Geeks

[0x1] UNIX / Linux Processes: C fork() Function

[0x2] How to Calculate IP Header Checksum (With an Example)

[0x3] How to Encrypt Your Bash Shell Script on Linux Using SHC

[0x4] Intro to DOCSIS Architecture, CM CMTS Protocol for Cable Modems

[0x5] Ettercap Tutorial: DNS Spoofing & ARP Poisoning Examples

[0x6] Linux Traceroute Command Examples

[0x7] How to Install Apache 2.4.2 from Source on CentOS 6.2 with SSL

[0x8] IP Routing: Linux Route Flags (U – Up, G – Gateway, H – Host)

[0x9] How to Use C Mutex Lock Examples for Linux Thread Synchronization

[0xA] Top 7 Ubuntu Desktop Backup Software

C-skills

A blog dedicated to software and network trickery.

[0x1] Android phones wanted

[0x2] more sshttp trickery

[0x3] lophttpd news

[0x4] libusi++ comeback

[0x5] contribs

[0x6] removing #ifdef's where possible

[0x7] github pwnage

[0x8] systemd CVE-2012-0871 trickery

[0x9] Prepackaged lophttpd for Android

[0xA] lophttpd running on android

StormSecurity

IT Security Research and Services

[0x1] My PhD Thesis

[0x2] From Windows thumbnails vulnerability to remote shell

[0x3] Red Teaming Usage for Assessing Information Security

[0x4] New version of ddosim – DDOS simulator

[0x5] Backward disassembler for ROP exploitation

[0x6] Guide For Designing Cyber Security Exercises

[0x7] GROUP_CONCAT() for Oracle blind SQL injection

[0x8] Check if your email account has been exposed!

[0x9] SqlBit – a new blind SQL injection exploiter

[0xA] Application Layer DDoS Simulator

US-CERT Bulletins

US-CERT Bulletins provide bi-weekly summaries of security issues and new vulnerabilities. They also provide patches, workarounds, and other actions to help mitigate risk.

[0x1] SB12-135: Vulnerability Summary for the Week of May 7, 2012

[0x2] SB12-128: Vulnerability Summary for the Week of April 30, 2012

[0x3] SB12-121: Vulnerability Summary for the Week of April 23, 2012

[0x4] SB12-114: Vulnerability Summary for the Week of April 16, 2012

[0x5] SB12-107: Vulnerability Summary for the Week of April 9, 2012

[0x6] SB12-093: Vulnerability Summary for the Week of March 26, 2012

[0x7] SB12-086: Vulnerability Summary for the Week of March 19, 2012

[0x8] SB12-079: Vulnerability Summary for the Week of March 12, 2012

[0x9] SB12-072: Vulnerability Summary for the Week of March 5, 2012

[0xA] SB12-065: Vulnerability Summary for the Week of February 27, 2012

CSOONLINE.com - IT Audit

[0x1] Compliance isn't security, but companies still pretend it is, according to survey

[0x2] Law firms see big money in healthcare breach cases

[0x3] 12 tips for implementing GRC

[0x4] The in-depth guide to data destruction

[0x5] Nation's nuclear power watchdog comes up short on FISMA compliance

[0x6] Small company, big security challenges

[0x7] Cisco CSO on self-defending networks: The marketing's dead, the goal's alive

[0x8] Forget new threats: It's the old-school attacks that keep getting you

[0x9] Healthcare security needs a booster shot

[0xA] Mac OS X Lion: Losing its security pride

CSOONLINE.com - Pandemic Preparedness

[0x1] BC/DR spending not a top budget priority

[0x2] CSO's ultimate guide to business continuity and disaster recovery

[0x3] Lack of Telework Preparedness Puts Business Continuity in Danger?

[0x4] Gartner Joins GAO in Raising Flu Network Congestion Fears

[0x5] Most Businesses READY for Flu Pandemic?

[0x6] Swine Flu Near You? IPhone App Will Let You Know

[0x7] A Swine Flu (H1N1) Business Continuity Planning Guide

[0x8] Swine Flu: Watching the Southern Hemisphere for Signs of H1N1 Havoc

[0x9] WHO Declares Swine flu a Pandemic. Now What?

[0xA] Swine Flu: A Wake-up Call for Emergency Planners

Cisco Security Notices

Cisco Security Notices (the 40 most recent notices )

[0x1] Cisco IPSec VPN Implementation Group Name Enumeration Vulnerability

[0x2] Crafted DNS Packet Can Cause Denial Of Service

[0x3] Cisco IPsec VPN Implementation Group Password Usage Vulnerability

[0x4] Response to BugTraq - Cisco Clean Access Agent (Perfigo) Bypass

[0x5] CSS SSL Authentication Bypass

[0x6] ZOTOB and WORM_RBOT.CBQ Mitigation Recommendations

[0x7] Response to Full-Disclosure - Potential Denial of Service Bug in Cisco Pix Firewall IOS 6.2.2 and 6.3.(3.102)

[0x8] Cisco 802.1x Voice-Enabled Interfaces Allow Anonymous Voice VLAN Access

[0x9] Vulnerability in a Variant of the TCP Timestamps Option

[0xA] W32.BLASTER Worm Mitigation Recommendations

BetaNews

Technology News and Analysis

[0x1] IT embraces bring your own device in corporate deployment, despite risks

[0x2] iPhone meets its match

[0x3] Facebook's IPO is a jackpot for some, despite dark shadow of mobile

[0x4] Now in beta, ESET Smart Security 6 and NOD32 Antivirus 6

[0x5] LastPass Wallet secures your iPad and iPhone information

[0x6] Turns text files into 3D-animated ebooks

[0x7] Will you make Mark Zuckerberg rich?

[0x8] Comcast ditches data caps, but charges heavy users overage fees

[0x9] Windows Phone reaches for the bottom

[0xA] Trackerbird launches, lets you collect user analytics in your .NET apps

CSOONLINE.com - Other

[0x1] Age-appropriate parenting tools for the concerned security professional

[0x2] Resumption of the crypto wars?

[0x3] PCI 2.0 reviewed

[0x4] How to do a hotel room security check

[0x5] Schneier: Eavesdropping on 'smart homes'

[0x6] "The biggest and worst deal in security history"

[0x7] Passwords in the wild: the future

[0x8] Website vulnerability analysis: fast, cheap, good - pick 2

[0x9] Riggins: FAIR and vulnerabilities

[0xA] Bejtlich: Dell needs a PSIRT

blog.fon.com

wifi for everyone

[0x1] We’re Celebrating 6 Million Hotspots!

[0x2] Save on Roaming and Overage Charges with WiFi

[0x3] The Importance of WiFi in Retail Locations

[0x4] WiFi: Now in a Quarter of the World’s Households

[0x5] What is EAP-SIM?

[0x6] SFR Renews Partnership with Fon

[0x7] The Future of WiFi Connection: 802.11u

[0x8] The Evolution of WiFi

[0x9] Help Fon Win the People’s Choice Award!

[0xA] Fon Partners With Netia to Create Largest WiFi Community in Poland

My Security Planet

My Security Planet

[0x1] Schneier on Security: Friday Squid Blogging: Squid Scalp Massager

[0x2] Zero in a bit: Weekly News Roundup

[0x3] Schneier on Security: Kip Hawley Reviews Liars and Outliers

[0x4] Zero in a bit: Privacy and Confidentiality on the Eve of the Facebook IPO

[0x5] Mozilla Webdev: An Introduction to persona.org

[0x6] Watchfire Application Security Insider: Enhancing Web Application Security Testing with IBM Security AppScan Glass Box

[0x7] Schneier on Security: Cybersecurity at the Doctor's Office

[0x8] Zero in a bit: Interview with Dan Guido at SOURCE Boston 2012 – Part 3

[0x9] Schneier on Security: Rules for Radicals

[0xA] extern blog SensePost; : A closer look into the RSA SecureID software token

OStatic blogs

[0x1] Diminutive Android PCs Are Selling for Under $75

[0x2] An Open Source Arsenal for Photographers

[0x3] Mandriva Returning to Community

[0x4] NASA Reportedly Pulls OpenStack Development

[0x5] Android Rules the Smartphone Market, and Samsung Rides the Wave

[0x6] Chrome 19 Adds Tab Features, Moves Toward Business-Class Security

[0x7] Google's Android Plan: Are Surprises In Store?

[0x8] ROSALabs Releases New Distribution

[0x9] Which CMS System Is Right for You? Take a Test Drive

[0xA] Red Hat Enterprise Linux Hits 10-Year Anniversary

Wireless LAN Security Blog - AirTight Networks

[0x1] AirTight BYOD Survey – Only Two weeks left

[0x2] Smart Mobile Devices — “Stress Test” for the WIPS of the Future

[0x3] 1 Minute Survey: BYOD – Love it/Hate it?

[0x4] Don’t let BYOD turn into “BYOR” in your network

[0x5] BYOD and WPA2 – not made for each other

[0x6] Even at Shmoocon, Security Can’t Be Taken for Granted

[0x7] A tale of the two WLAN controllers, do we need to be chasing our tail for the WLAN security?

[0x8] AirTight SpectraGuard Products Achieve FIPS 140-2 and DISA UC APL Certification

[0x9] NRF: See AirTight’s unique cloud-based Secure Wi-Fi and captive portal for distributed retail

[0xA] Skyjacking attack – then Cisco, now Aruba?

BlogInfoSec.com

An Information Security Magazine in a Blog Format

[0x1] Supply Chain Risk Management and Catastrophes

[0x2] The (Sorry) State of Application Security

[0x3] TEOTWAWKI … Take 2

[0x4] InfoSec is Ritualistic, Not Innovative … It’s a SIN!

[0x5] Storing Books against Digital Disaster

[0x6] InfoSec Defenders are “Losers” per RSA

[0x7] Review and Critique of Generally Accepted Privacy Principles — Part 4

[0x8] Review and Critique of Generally Accepted Privacy Principles — Part 3

[0x9] Is Software Disposal a Security Issue?

[0xA] Review and Critique of Generally Accepted Privacy Principles — Part 2

PortSwigger Web Security Blog

[0x1] Burp is voted #1 web scanner

[0x2] Breaking encrypted data using Burp

[0x3] It's a biggie

[0x4] MDSec online training labs

[0x5] The fame of Peter Wiener

[0x6] Burp Suite Free Edition v1.4 released

[0x7] Web App Hacker's Handbook 2nd Edition - Preview

[0x8] Burp v1.4 beta now available

[0x9] Burp v1.4 preview - Session handling: putting it all together

[0xA] Burp v1.4 preview - Macros

tanasi.it

Alessandro `jekil` Tanasi blog

[0x1] Cinema: Salt

[0x2] Cinema: Inception

[0x3] Server RPS da Ovh.it e il lungo buio

[0x4] Cosa e` il bunga bunga?

[0x5] Ereditarieta` in Ruby on Rails

[0x6] Cinema: A-Team

[0x7] End Summer Camp

[0x8] Lol: Java sara` il futuro?

[0x9] Router Alice: trovate le password!

[0xA] Cinema: Alice in Wonderland

Optimal Security

the Lumension Blog

[0x1] Safe Social Media in 3 Steps

[0x2] Closing the Antivirus Protection Gap

[0x3] DNSChanger Trojan: Not All Doom and Gloom

[0x4] A Bit of May Madness from Microsoft for May 2012 Patch Tuesday

[0x5] Checkmark Compliance Will Get You Nowhere But Hacked

[0x6] Why Go Corporate? Choices in How to Earn The Big Bucks

[0x7] A Look at April’s State of Cyber Security

[0x8] Security vs. Operations

[0x9] Is Apple the New Adobe?

[0xA] Security and Operations: Back to the Basics

SecurityInfoWatch Forums - Discussions for the Security Professional

Security discussion forums on topics of security management, policies, guard services, loss prevention, homeland security, alarm systems, network video, security jobs

[0x1] Cruzin the Avenue

[0x2] Another 419 scam

[0x3] Stock Market

[0x4] Ridiculous WalMart Lawsuit

[0x5] Shoulder Mic

[0x6] Druggies Targeting "Open House" Properties

[0x7] Caught red handed - trutv special

[0x8] Donna Summer

[0x9] A couple of useful topics from IT-Security world

[0xA] Steel Defender - Body Armor

Microsoft news from Network World

Breaking Microsoft news and analysis from NetworkWorld.com

[0x1] An OS for the home and cool Kickstarter projects

[0x2] Microsoft tunes up Windows 8 multi-screen

[0x3] Microsoft cloud survey: Security, cost both a deterrent and an attraction

[0x4] Windows 8 Update: Firefox, Chrome cry foul over Windows 8 ARM

[0x5] Bing will tap Facebook, Twitter in answering queries

[0x6] HP, F5 partner to speed delivery of cloud apps

[0x7] Microsoft announces 7 bulletins for May 2012 Patch Tuesday, closes book on MAPP data leak

[0x8] Remember Windows Live? Forget it.

[0x9] VMware takes on Dropbox, Google Drive, Microsoft SkyDrive

[0xA] Is Google Drive ready for prime time?

Twitter / amrittsering

Twitter updates from Amrit Williams / amrittsering.

[0x1] amrittsering: @VanessaAlvarez1 Thanks!

[0x2] amrittsering: thanks bro @nemawilliams and @daya10 (btw - congrats on the twins - WOW!!!!)

[0x3] amrittsering: RT @Daya10: “@nemawilliams: a happy birthday to my brother @amrittsering love you bro!” Happy Birthday to my cousin!!!!

[0x4] amrittsering: Board-game themed movies (Clue, Battleship, operation A.K.A. Saw) not complete until Hungry, Hungry Hippo - RiverHorse 2 is released

[0x5] amrittsering: From rests to beauty salons, we're in reality show hell; 3 shows featuring pawn stores & 2 on fish tanks - fish tanks wtf? #blamesocialmedia

[0x6] amrittsering: Keeping up with the Romneys: Indiana man arrested with 4 kids strapped to car hood http://t.co/EgKFJdSB

[0x7] amrittsering: rt @JGamblin Watching a movie by myself for the first time ever <-- glad your independence is able to make this delicate leap forward ;-)

[0x8] amrittsering: @georgevhulme @csoandy It's only a bubble once it actually bursts...then, and only then is it an actual bubble, until then its just an orb

[0x9] amrittsering: Dania Suarez, Columbian "escort" responding to the new US policy to use chaperones to "chaperone" SS agents "yes, we give volume discounts"

[0xA] amrittsering: As much as I appreciate the craftsmanship of the S63, imagine its really hard to NOT look like an Albanian sex trafficker while driving one

GlobalSecurity.org

Reliable Security Information from GlobalSecurity.org.

[0x1] Combined Force Seizes Opium Cache

[0x2] CLR-37 deploys to Afghanistan

[0x3] Pakistan PM says NATO summit's invitation unconditional

[0x4] Air Force vice chief nominated to be next USAFE commander

[0x5] Locklear: Pacom's Priorities Reflect New Strategic Guidance

[0x6] U.S. Congress to debate sale of F-16 fighters to Taiwan

[0x7] Russia Floats Out Large Landing Ship

[0x8] Russian Paras Fire 'Green Beret' Weapons in U.S.

[0x9] Ammunition Depot Fire in Far East Injures One

[0xA] DOD News Briefing with George Little from the Pentagon

Insanely Low-Level

An Arkon Blog

[0x1] Appfront

[0x2] Kernel Exploits

[0x3] IsDebuggerPresent – When To Attach a Debugger

[0x4] isX64 Gem

[0x5] Finding Kernel32 Base Address Shellcode

[0x6] Private Symbols Look Up by Binary Signatures

[0x7] diStorm Goes on Diet

[0x8] Binary Hooking Problems

[0x9] Executing .PYC Files in Python

[0xA] JavaScript Once Again

msnbc.com: Security

Msnbc.com is a leader in breaking news and original journalism.

[0x1] ZTE confirms security hole in US phone

[0x2] Is it illegal to record and post noisy neighbors having sex?

[0x3] Anonymous attacks Indian government websites

[0x4] We may not trust Facebook, but we don't quit it either, shows poll

[0x5] Banking Trojan poses as Google Chrome installer

[0x6] Drunken hacker jailed for selling gamers' info

[0x7] 5 ways criminals use Facebook

[0x8] Apple QuickTime update fixes 17 security glitches

[0x9] Google fixes 18 Chrome glitches, enables tab syncing

[0xA] Apple issues security updates for Leopard users

Security - RSS Feed

Security news - RSS Feed

[0x1] Facebook Class Action Lawsuit Seeks $15 Billion for Privacy Violations

[0x2] Cyber-Threats Pose Challenges for NATO Summit in Chicago

[0x3] Microsoft Holds Security Development Conference

[0x4] Twitter Joins Google, Apple, Microsoft, Others in 'Do Not Track Effort'

[0x5] Facebook, Gmail, Hotmail, Yahoo Users Hit by Zeus Debit Card Scam

[0x6] Google Patches 20 Chrome 19 Security Vulnerabilities, Adds Tab-Syncing

[0x7] Attackers Hit Human Rights, Foreign Policy Websites With Drive-By Exploits

[0x8] Apple Protects OS X 10.5 Leopard From Flashback Malware

[0x9] Apple Security Updates Targets Mac OS X Leopard, Flashback Trojan

[0xA] California Woman Gets 5-Year Prison Term in Phishing Conviction

Daniel's Blog

Information security, scuba diving and some other things I am interested in...

[0x1] Travel safe!

[0x2] “I can’t get no satisfaction” from the ATO

[0x3] !Me encanta Colombia!

[0x4] That “flip” thing

[0x5] MBAs and GMAT

[0x6] Where should you buy it? Try Mustafa*!

[0x7] Bondi got flipped!

[0x8] Are you aware of the new business models which are now available on the web?

[0x9] Hello Merlion!

[0xA] Movember video!

ThinkGeek :: Clearance Products

Stuff for Smart Masses - Clearance Items

[0x1] Laboratory Beaker Mug

[0x2] Bandits - Elastic Organizers

[0x3] Sand Puff Geometric Set

[0x4] Electronic Firefly in a Jar

[0x5] Portal 2 Life-Size Inflatable Sentry Turret

[0x6] Screaming Monkey Slingshot

[0x7] Electronic Bubble Wrap Keychain

[0x8] The Cubicle Doorbell

[0x9] USB Grenade Flash Drive

[0xA] Samurai Confidential

Observations from a Tech Architect: Enterprise Implementation Issues & Solutions

Enterprise Technology Architect Craig Borysowich shares the challenges and achievements of enterprise solution design and implementation.

[0x1] Microsoft’s MDT and the reality about ACT.

[0x2] Project Work Plans

[0x3] Managed Hosting Services - Mandatory Requirement: Two-Way Platform Assurance

[0x4] Project Initiation Reports

[0x5] Quick Windows 7 Migration Survey - respond by Apr30 for a chance to win $100!!

[0x6] Integration Implementation Plans

[0x7] The Current Situation & Requirements Report

[0x8] The Systems Integration Master Plan

[0x9] Long Range Systems Plan Document

[0xA] Project Management Lite: Impacts of 4GL on Estimating

Business:Security Articles from EzineArticles.com

EzineArticles.com is Trusted By Millions as The Source For Quality Original Articles

[0x1] Employee Theft: Stop This Business Killer!

[0x2] 5 Ways Sensor Tags Protect Your Business

[0x3] 10 Ways to Protect Yourself and Your Business From Fraud

[0x4] How to Protect Your Business From Fraud and Identity Theft

[0x5] Keeping Your Business Safe From Theft

[0x6] Strengthening Security by Using Commercial Locks

[0x7] Advantage Of Picking A Local Locksmith

[0x8] The Importance of Hiring Professional Guards for Your Construction Security

[0x9] Understanding High Security Fencing And The Commonest Users

[0xA] The Importance Of Pack Security Fences And Choosing The Right Materials

dropsafe

network security, unix and bicycles

[0x1] GET SPOCK UP HERE! # #pratchett meets #trek

[0x2] Vodka Martini: Vodka, Vermouth, Olive; Vodka Gibson: use an Onion; Vodka Muffett: use Pickled Garlic

[0x3] Botching the Bomb | Foreign Affairs

[0x4] What I think is wrong with #VRM – HT @nzn @glynmoody @windley @dsearls @adriana872

[0x5] “JESUS also suffered from GOVERNMENT CUTS” # should have gone on strike, then.

[0x6] Dinner: poached goose egg on warm baguette, french butter; vodka martini.

[0x7] Just in case anyone thinks that Internet trolls and timewasters are a new phenomenon…

[0x8] Express.co.uk :: We’re the new naughty novelists # La Express reports on the British #CottageErotica industry

[0x9] Law banning insulting language ‘is strangling free speech’ – Telegraph

[0xA] #India blocks #Pastebin? Great way to kill off the tech boom in #Bangalore, guys #whoohoo #IndiaTechSuicide

Search Engine Watch - Latest

Latest News

[0x1] 6 Tools to Manage Your Twitter Followers

[0x2] 4 Ways to Rethink a Facebook Advertising Campaign

[0x3] For Better Facebook Engagement, Post on Topics Related To, But Not About, Your Brand [Study]

[0x4] Google Launches Knowledge Graph, 'First Step in Next Generation Search'

[0x5] Mobile Sites: Choosing an Implementation Process & Strategies

[0x6] Why Your SEO & Social Strategy Should Include Pinterest

[0x7] Google NSA Relationship Secrecy Continues Despite Courts Efforts

[0x8] Ford Retains Confidence in Facebook Ads as GM Quits

[0x9] Life After Google Penguin – Going Beyond the Name

[0xA] 7 Time-Saving Google Analytics Custom Reports

Files ≈ Packet Storm

Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers

[0x1] Vanilla 2.0.18.4 Cross Site Scripting

[0x2] Vanilla Latest Comment 1.1 Cross Site Scripting

[0x3] Vanilla About Me 1.1.1 Cross Site Scripting

[0x4] libssh2 C Library 1.4.2

[0x5] Oracle Weblogic Apache Connector POST Request Buffer Overflow

[0x6] Squiggle 1.7 SVG Browser Java Code Execution

[0x7] libwpd WPXContentListener::_closeTableRow() Memory Overwrite

[0x8] Hackers 2 Hackers 9 Call For Papers

[0x9] HP Security Bulletin HPSBOV02780 SSRT100766

[0xA] HP Security Bulletin HPSBUX02782 SSRT100844

IT.com.mk

[0x1] Графити артистот кој го ишара Facebook можеби тежи 500 милиони долари

[0x2] nVidia претстави „GPU виртуелни десктопи“ со кои планираат да го револуционираат гејмингот

[0x3] Стив Џобс работел на редизајн на новиот iPhone со екран од 4 инчи

[0x4] Facebook продава 420 милиони акции во цена од 38 долари

[0x5] Нарачани се 9 милиони нови Samsung Galaxy III уреди

[0x6] Twitter имплементира „Не ме следи“ опција

[0x7] Дигитални македонски телевизии од јуни 2013 година

[0x8] Дали Македонија е навистина меѓу четирите држави со најбрз развој на ИТ услуги во светот?

[0x9] Менаџирајте Facebook фан страни преку iPhone

[0xA] Google и оддаде признание на македонската заедница на корисници на слободен софтвер

HolisticInfoSec

The HolisticInfoSec.org blog includes follow-up on previously written articles and research, as well as research and rants. While the goal is promoting standards, simplicity, and efficiency in achieving holistic information security, we occasionally rally against industry shortcomings where necessary.

[0x1] toolsmith: Buster Sandbox Anayzer

[0x2] toolsmith: Log Parser Lizard

[0x3] MIR-ROR 2.0 released

[0x4] More Mayhem with Pwn Plug

[0x5] toolsmith: Pen Testing with Pwn Plug

[0x6] A Tribute to Tareq

[0x7] toolsmith: Splunk app - Windows Security Operation Center

[0x8] 2011 Toolsmith Tool of the Year: OWASP ZAP

[0x9] STOP SOPA!

[0xA] toolsmith: ZeroAccess analysis with OSForensics

Dr. Dobb's Security

Dr. Dobb's

[0x1] Wind River Introduces Safe Partitioning

[0x2] Evolving Your Current Processes and Infrastructure to Fulfill the Requirements of ISO 26262

[0x3] Apple Releases OS X Mountain Lion Developer Preview

[0x4] Compuware Updates Mainframe Workbench

[0x5] Bridging Git Over Open Source and Commercial

[0x6] OpenSSL Closes Security Hole Six Pack

[0x7] Former Hacker: Software Should Be More Secure

[0x8] The Best of 2011

[0x9] Top Security Threats for 2012

[0xA] Cast Software's Five Pillars of Application Integrity

Microsoft Security Blog

The official Microsoft blog for discussing industry and Microsoft security topics.

[0x1] Weekly Roundup: May 18, 2012 – Smartphone Security, Cyber Threat Trends and the Importance of Secure Development

[0x2] Operating System Infection Rates - Slight Change in the Trend

[0x3] Scareware: Don’t Let Scammers Scare You

[0x4] Trust in Computing Research : 5 : Consumerization of IT

[0x5] Weekly Roundup: May 4, 2012 – Think Before You Click

[0x6] Trust in Computing Research: 4 : Computing and the Internet (Demographic breakdown)

[0x7] Proliferation of Devices & Applications and Government & Cybersecurity – TwC Interactive Timeline Part 8

[0x8] Weekly Roundup: April 27, 2012 – Tracking the Security Trends: Data Integrity

[0x9] Hundreds of Pages of New Security Intelligence Now Available: Microsoft Security Intelligence Report Volume 12 Released

[0xA] Weekly Roundup: April 20, 2012 – Cybersecurity R&D Trends

Network Security Blog

Join me as I spend 30 minutes each week talking about the computer security issues facing us today. I discuss privacy, hacking, malware and the Payment Card Industry (PCI) Data Security Standards.

[0x1] Network Security Podcast, Episode 275

[0x2] Network Security Podcast, Episode 272 v2

[0x3] Something to think on from Source Boston

[0x4] Network Security Podcast, Episode 274

[0x5] This is why CISPA scares me

[0x6] Network Security Podcast, Episode 273

[0x7] Network Security Podcast, Episode 272

[0x8] Global Payment Systems delisted by Visa

[0x9] Network Security Podcast, Episode 271

[0xA] TSA blocks Schneier from testifying

SecuriTeam

Welcome to the SecuriTeam RSS Feed - sponsored by Beyond Security. Know Your Vulnerabilities! Visit BeyondSecurity.com for your web site, network and code security audit and scanning needs.

[0x1] RealNetworks RealPlayer RV10 Sample Height Parsing Code Execution Vulnerability

[0x2] RealNetworks RealPlayer IVR MLTI Chunk Length Parsing Code Execution Vulnerability

[0x3] RealNetworks RealPlayer RV30 Uninitialized Index Value Code Execution Vulnerability

[0x4] RealNetworks RealPlayer Invalid Codec Name Code Execution Vulnerability

[0x5] RealNetwork RealPlayer MPG Width Integer Underflow Code Execution Vulnerability

[0x6] Apache mod_rewrite Vulnerability PoC

[0x7] netsniff-ng - A Linux Network Analyzer and Networking Toolkit

[0x8] Simple Local File Inclusion Exploiter

[0x9] NiX A Linux Brute Forcer

[0xA] Nchop - A TCP Session Splicing Tool Used to Rvade Intrusion Detection Systems

Verizon Center - News

Keep up with the latest news surrounding Verizon Center. Managed and owned by Monumental Sports & Entertainment, Verizon Center is home to the NBA’s Washington Wizards, the WNBA’s Washington Mystics, the NHL’s Washington Capitals, and the Georgetown Hoyas Men’s Basketball teams. Located in the heart of Chinatown above the Gallery-Place Chinatown Metro stop, Verizon Center is only a few steps away from the White House and hosts more than 220 events and concerts each year.

[0x1] Andrea Bocelli U.S. Tour Kicks-Off Next Month - Dec 2 Show at Verizon Center

[0x2] Roger Waters "The Wall" Returns to North America in 2012 - Includes July 12 Show at Verizon Center

[0x3] Remarkable Rookie Class Highlights Harlem Globetrotters Arrival Into DC and Fairfax March 24-25

[0x4] 17th Annual BB&T Classic - Dec 4 at Verizon Center

[0x5] Hard Times Cafe Brings Local Fare to Verizon Center

[0x6] Monumental Report to Serve as Hyper-Local Online Community Platform

[0x7] KMART presents WWE Holiday Tour Dec 29

[0x8] Verizon Center Debuts Mobile App

[0x9] Cirque du Soleil - Quidam - Nov 16 through 20

[0xA] JAY-Z and Kanye West: Watch the Throne Tour Nov 3

CSOONLINE.com - PCI and Compliance

[0x1] PHI security demands leave life coach feeling doomed

[0x2] Compliance isn't security, but companies still pretend it is, according to survey

[0x3] Law firms see big money in healthcare breach cases

[0x4] Report: PHI security is MIA

[0x5] Amid breach fallout, Global Payments struggles with public message

[0x6] The PCI effect -- for better or worse -- following Global Payments breach

[0x7] Debriefing: Laws and orders (the quiz)

[0x8] 12 tips for implementing GRC

[0x9] Industry on Cybersecurity Act of 2012: Not so fast

[0xA] Lieberman: Cybersecurity Act of 2012 will help us protect critical infrastructure

SecManiac.com

Dave (ReL1K) Kennedy's Security Haven

[0x1] The Social-Engineer Toolkit (SET) v3.3 Codename “DerbyCon 2.0 Edition”

[0x2] BSIDES Cleveland !!!! July 13th 2012

[0x3] DerbyCon ticket sales THIS FRIDAY! 1PM EST

[0x4] The Social-Engineer Toolkit v3.2 codename “#FreeHugs” has been released.

[0x5] Building an HTTP shell with AES + Proxy Support in Python

[0x6] New tool release – “Egress Buster” – Find outbound ports

[0x7] Artillery 0.4 alpha has been released!

[0x8] The Social-Engineer Toolkit 3.1 Codename “User Awareness” has been released!

[0x9] The Social-Engineer Toolkit (SET) 3.0 “#WeThrowBaseBalls” has been released.

[0xA] Blackhat Training on The Social-Engineer Toolkit!

Cisco Security Advisories

Cisco Security Advisories (the 40 most recent advisories)

[0x1] Attention: New Cisco Security Advisory RSS Feed Locations

[0x2] Denial of Service Vulnerability in Cisco Video Surveillance IP Cameras

[0x3] Cisco Unified Contact Center Express Directory Traversal Vulnerability

[0x4] Cisco Unified Communications Manager Directory Traversal Vulnerability

[0x5] Buffer Overflow Vulnerabilities in the Cisco WebEx Player

[0x6] Cisco Security Agent Remote Code Execution Vulnerabilities

[0x7] Cisco Show and Share Security Vulnerabilities

[0x8] CiscoWorks Common Services Arbitrary Command Execution Vulnerability

[0x9] Cisco TelePresence Video Communication Server Cross-Site Scripting Vulnerability

[0xA] Cisco IOS Software Smart Install Remote Code Execution Vulnerability

CSOONLINE.com - Critical Infrastructure

[0x1] Cyber warfare in sights at government training conference

[0x2] The future of SCADA-control security

[0x3] Embedded system security much more dangerous, costly than traditional software vulnerabilities

[0x4] Threat intelligence: Why it's about sharing more data

[0x5] Making the case for preventing workplace violence

[0x6] Severe space weather: How big a threat?

[0x7] Industry on Cybersecurity Act of 2012: Not so fast

[0x8] Lieberman: Cybersecurity Act of 2012 will help us protect critical infrastructure

[0x9] Coverity and Wind River target development insecurity with new alliance

[0xA] Will Kim Jong Un be for cyberwarfare what his dad was for nukes?

hacklab.to

Toronto's hacker collective

[0x1] Overheard at Hacklab

[0x2] USB Microscope

[0x3] Hacklab Open House Party

[0x4] A Month of Workshops

[0x5] Soldering Workshop Tomorrow!

[0x6] Toronto RepRap Users Meetup #3 = Great Success!

[0x7] Toronto Haskell Users Meetup

[0x8] Quantified Hacklab (Part 1)

[0x9] Toronto RepRap User Group #3

[0xA] Gamfternoon Continues

شروحات الفيديو - iSecur1ty

مجتمع عربي للهاكر الأخلاقي وخبراء الحماية يركّز على مفهوم اختبار الاختراق وجديد أخبار الحماية والثغرات, شروحات فيديو ومقالات أمنيّة.

[0x1] فيديو : هجمات browser_autopwn بأستخدام SET

[0x2] فيديو : أختبار أختراق الحسابات داخل الشبكه

[0x3] فيديو : أختبار الأختراق بصيغه Doc

[0x4] فيديو : أختبار الأختراق بصيغه jar

[0x5] فيديو : شرح هجمات multi_attack بأستخدام SET

[0x6] فيديو : برنامح logwatch

[0x7] فيديو : شرح أداه Beef

[0x8] فيديو : شرح أداه zap proxy

[0x9] فيديو : أختبار أختراق Windows7 بإستخدام Metasploit

[0xA] فيديو : برنامج Joomscan

What's New

What's New at FIRST website

[0x1] Holistic risk management: perspectives from IT professionals

[0x2] FIRST Announces Call for Subjects for version 3 of the Common Vulnerability Scoring System (CVSS)

[0x3] FIRST Announces Call for Participants and Subjects for version 3 of the Common Vulnerability Scoring System (CVSS)

[0x4] The 24th Annual FIRST Conference, Malta focuses on the need for collaboration to combat new global security threats

[0x5] FIRST Times Newsletter - Winter 2012 Edition

[0x6] The Education Committee (EduC) Newsletter

[0x7] Welcome FIRST new teams!

[0x8] Call for Speaker Deadline Approaching!

[0x9] Registration for the London TC is underway!

[0xA] The 2012 Call for Speakers is officially open

Apple

[0x1] Games for the weekend: Fortress Under Siege

[0x2] RIM, Motorola propose truce in nano-SIM fight, plus 4 other Apple stories to read today

[0x3] A $5 app turns Android tablets into a second monitor for Mac or PC

[0x4] Verizon: You can keep unlimited — if you buy your own phone

[0x5] New U.S. iPad activations move inland

[0x6] A breakdown of iOS and Android profits, plus 4 other Apple stories to read today

[0x7] Survey says: Apple customer service a secret weapon

[0x8] Google launches Schemer app for the iPhone

[0x9] Steve Jobs to get the Sorkin treatment, plus 4 other Apple stories to read today

[0xA] This Sesame Street app will potty-train your kid

Help Net Security - News

Help Net Security - your homepage for all the information security news

[0x1] Twitter supports “Do Not Track” option

[0x2] Facebook IPO advanced fee scam hitting inboxes

[0x3] MacScan 2.9.3 with Google Chrome and SeaMonkey support released

[0x4] Hacker jailed for targeting Call of Duty gamers

[0x5] Worm targets Facebook users via PMs

[0x6] Review: LOK-IT Secure Flash Drive

[0x7] Spam with malicious attachments rising

[0x8] Password creation policies are the enemy of secure passphrases

[0x9] Malicious fake Android AV apps pushed onto users

[0xA] Secure data on Android devices with SecureZIP

Veracode Security Blog: Application security research, security trends and opinions

Application security testing, analysis, and metrics

[0x1] Weekly News Roundup

[0x2] Privacy and Confidentiality on the Eve of the Facebook IPO

[0x3] Interview with Dan Guido at SOURCE Boston 2012 – Part 3

[0x4] Veracode’s Chris Wysopal Appointed to Black Hat’s Content Review Panel

[0x5] Interview with Dan Guido at SOURCE Boston 2012 – Part 2

[0x6] What is Data Integrity? Learn How to Ensure Database Data Integrity via Checks, Tests, & Best Practices

[0x7] Weekly News Roundup

[0x8] Interview with Dan Guido at SOURCE Boston 2012 – Part I

[0x9] Data Mining A Mountain of Zero Day Vulnerabilities – Webinar Q&A

[0xA] Cybersecurity Risks in Public Companies Infographic

My Security Blog

Security Chronicles By Umesh Thota.
www.SecureBlog.net

[0x1] iPhoned..

[0x2] thats why.. lol…

[0x3] Panda Cloud Antivirus !!!

[0x4] BEST BROWSER (*FIREFOX) ADDONS!!!

[0x5] BORG!!! BOT!!! FIGHT!!!

[0x6] GUIDELINES FOR SAFE COMPUTING:

[0x7] K9 Web Protection - Free Internet Filtering and Parental Controls Software

[0x8] Must Have Security Solutions (for free)

[0x9] Goolag Scanner Released!

[0xA] Change DNS ? for a Safer, Faster Online Experience

SANS Internet Storm Center, InfoCON: green

[0x1] Infocon: green

[0x2] PHP 5.4 Remote Exploit PoC in the wild, (Sat, May 19th)

[0x3] ZTE Score M Android Phone backdoor, (Fri, May 18th)

[0x4] ISC StormCast for Friday, May 18th 2012 http://isc.sans.edu/podcastdetail.html?id=2545, (Fri, May 18th)

[0x5] ISC Feature of the Week: Tools->Information Gathering, (Thu, May 17th)

[0x6] New IPv6 Video: IPv6 Router Advertisements https://isc.sans.edu/ipv6videos, (Thu, May 17th)

[0x7] Do Firewalls make sense?, (Thu, May 17th)

[0x8] ISC StormCast for Thursday, May 17th 2012 http://isc.sans.edu/podcastdetail.html?id=2542, (Thu, May 17th)

[0x9] Reserved IP Address Space Reminder, (Wed, May 16th)

[0xA] Avira Antivirus false positives http://forum.avira.com/wbb/index.php?page=Thread&threadID=144875, (Wed, May 16th)

CSOONLINE.com - Security Leadership

[0x1] Disaster recovery is a success just waiting to happen

[0x2] How to start a business continuity program

[0x3] Ten commandments for effective security training

[0x4] Trust me!

[0x5] Making the case for preventing workplace violence

[0x6] Who should the CISO report to?

[0x7] Tangled web: Facebook, SEO, and black-hat tactics colliding (still)

[0x8] Was LulzSec bust part of a play against Julian Assange?

[0x9] A clear-eyed look at APT

[0xA] Rugged DevOps: In search of the defensible infrastructure

Infosec Island Latest Articles

Adrift in Threats? Come Ashore!

[0x1] SCADA Security: Consequences and Difficulty with Incentives

[0x2] Spring Cleaning Your PC

[0x3] Attribution: Inductive vs. Deductive Reasoning

[0x4] Companies Hit in Targeted Attacks

[0x5] Kaspersky Warns of Critical Infrastructure Vulnerabilities

[0x6] Have You Read the New Facebook Privacy Rules… Again??

[0x7] US Enhances Cybersecurity Collaboration with Australia

[0x8] Practice Linux Penetration Testing Skills with Metasploitable

[0x9] Air Force Command Realigns Cyberspace Capabilities

[0xA] Is Lord Sugar a Member of Anonymous?

SecurityFocus News

SecurityFocus is the most comprehensive and trusted source of security information on the Internet. We are a vendor-neutral site that provides objective, timely and comprehensive security information to all members of the security community, from end users, security hobbyists and network administrators to security consultants, IT Managers, CIOs and CSOs.

[0x1] News: Change in Focus

[0x2] News: Twitter attacker had proper credentials

[0x3] News: PhotoDNA scans images for child abuse

[0x4] News: Conficker data highlights infected networks

[0x5] Brief: Google offers bounty on browser bugs

[0x6] Brief: Cyberattacks from U.S. "greatest concern"

[0x7] Brief: Microsoft patches as fraudsters target IE flaw

[0x8] Brief: Attack on IE 0-day refined by researchers

[0x9] News: Monster botnet held 800,000 people's details

[0xA] News: Google: 'no timetable' on China talks

Help Net Security - News

Help Net Security - your homepage for all the information security news

[0x1] Twitter supports “Do Not Track” option

[0x2] Facebook IPO advanced fee scam hitting inboxes

[0x3] MacScan 2.9.3 with Google Chrome and SeaMonkey support released

[0x4] Hacker jailed for targeting Call of Duty gamers

[0x5] Worm targets Facebook users via PMs

[0x6] Review: LOK-IT Secure Flash Drive

[0x7] Spam with malicious attachments rising

[0x8] Password creation policies are the enemy of secure passphrases

[0x9] Malicious fake Android AV apps pushed onto users

[0xA] Secure data on Android devices with SecureZIP

Search Engine Watch Discussion Forums

Search Engine Watch Forums

[0x1] xsdfasxscafafg

[0x2] Free Directory

[0x3] No Follow code

[0x4] SEO for News Content

[0x5] When Title Tags are too similar

[0x6] No more Web Spam....

[0x7] The Over Optimization algo update - named webspam update - are you hit?

[0x8] How to show add-on domain as domain name in SERPs rather than subdomain?

[0x9] What's better for SEO: using a sub-domain or directory of a domain name?

[0xA] Adwords Keyword Type Modifications

PaulDotCom

[0x1] Hack Naked TV Episode 35

[0x2] Episode 288 with Cedric Blancher & Aaron Crawford Thursday 6pm ET

[0x3] Episode 287 with Dr. Anton Chuvakin & Daniel Martin at 6PM tonight

[0x4] Hack Naked TV Episode 34

[0x5] PaulDotCom Espanol Episode 12 - Efrain Torres

[0x6] PaulDotCom Security Weekly Episode 286 - Penetration Testing, Exploits, Poop for Wifi

[0x7] Hack Naked At Night - Episode 5 - Badges, Barcodes & Arduino

[0x8] Episode 286 with Core Security Technologies Tonight 6PM EDT

[0x9] Hack Naked TV Episode 33

[0xA] PaulDotCom Security Weekly Episode 285 - Nick Farr, Hacker Spaces, Hackers In Space

Full Disclosure

A lightly moderated high-traffic forum for disclosure of security information. Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. Unfortunately, most of the posts are worthless drivel, so finding the gems takes patience.

[0x1] [SECURITY] [DSA 2476-1] pidgin-otr security update

[0x2] Re: FW: Curso online - Profesional pentesting - Promocion ( 25% de descuento )

[0x3] FW: Curso online - Profesional pentesting - Promocion ( 25% de descuento )

[0x4] Re: Google Accounts Security Vulnerability

[0x5] Re: Google Accounts Security Vulnerability

[0x6] Re: Checking out backdoor shells

[0x7] Checking out backdoor shells

[0x8] Re: Google Accounts Security Vulnerability

[0x9] Re: Google Accounts Security Vulnerability

[0xA] H2HC Brazil 9th Edition - Call for Papers

Twitter / sans_isc

Twitter updates from SANS ISC / sans_isc.

[0x1] sans_isc: [Diary] PHP 5.4 Remote Exploit PoC in the wild, (Sat, May 19th): There is a remote exploit in the wild ... http://t.co/fhS5ni6B #sansisc

[0x2] sans_isc: @transvasive I fully agree. In particular these stupid "backdoors" have to stop.

[0x3] sans_isc: RT @lennyzeltser: 4 techniques attackers have used to run malicious code inside Microsoft Office documents: http://t.co/hqmvzkp4 #malware

[0x4] sans_isc: [Diary] ZTE Score M Android Phone backdoor, (Fri, May 18th): The ZTE Score M phone, apparently availabl... http://t.co/X1rQl1tE #sansisc

[0x5] sans_isc: [Diary] ISC StormCast for Friday, May 18th 2012 http://t.co/5hiQ0aR2, (Fri, M... http://t.co/CVbjxnW2 #sansisc

[0x6] sans_isc: [Diary] ISC Feature of the Week: Tools->Information Gathering, (Thu, May 17th): Overview One of the se... http://t.co/OcLrhaDu #sansisc

[0x7] sans_isc: [Diary] New IPv6 Video: IPv6 Router Advertisements https://t.co/GCPBTtXe, (Thu, May 17th): ..... http://t.co/gIokwDJb #sansisc

[0x8] sans_isc: [Diary] Do Firewalls make sense?, (Thu, May 17th): Once in a while, someone comes up with the idea that... http://t.co/lMYdjuZL #sansisc

[0x9] sans_isc: [Diary] ISC StormCast for Thursday, May 17th 2012 http://t.co/Ltdz3FDZ, (Thu,... http://t.co/xAEUdJg3 #sansisc

[0xA] sans_isc: [Diary] Avira Antivirus false positives http://t.co/GUqU2ccY... http://t.co/7rj9BjUu #sansisc

nixCraft

This is a Linux sys admin journal by Vivek about sys admin work, Linux tips & tricks, hacks, news and more.

[0x1] Linux debugfs Hack: Undelete Files

[0x2] Create Custom URL Shortener For WordPress Based Blog In a Five Minutes

[0x3] FAQ Updates: May/03/2012

[0x4] Linus Torvalds Wins Millennium Technology Prize

[0x5] 20 Examples: Make Sure Unix / Linux Configuration Files Are Free From Syntax Errors

[0x6] Is My Mac Computer Infected With The Flashback Trojan?

[0x7] HowTo: Wake Up Computers Using Linux Command [ Wake-on-LAN ( WOL ) ]

[0x8] FAQ Updates: April/03/2012

[0x9] Video: Who Writes Linux Kernel?

[0xA] Adobe Flash v11.2 and Above Will Only Be Available For Chrome Browser on Linux

Network World on Intrustion Detection and Prevention

The latest intrusion detection and prevention news and analysis from NetworkWorld.com.

[0x1] 10 hacks that made headlines

[0x2] Fortinet has highest catch rate in IPS testing

[0x3] Hackers blackmail Belgian bank with threats to publish customer data

[0x4] Most IT and security professionals see Anonymous as serious threat to their companies

[0x5] Sophos takes down partner portal after signs of hacking

[0x6] Reborn LulzSec claims hack of dating site for military personnel

[0x7] News International security chief arrested in phone hacking case

[0x8] Malware increasingly uses DNS as command and control channel to avoid detection, experts say

[0x9] Imperva: Companies should secure their websites before worrying about DDoS attacks from Anonymous

[0xA] WikiLeaks releases Stratfor emails possibly from December hack

Virtual Shadows

the privacy blog!

[0x1] Biometrics and Web Services

[0x2] There is innovation outside of academia!

[0x3] Back yet again

[0x4] No surprises……you are being hacked by your government!

[0x5] Santa hacked

[0x6] Patriots in the Cloud

[0x7] Security innovation

[0x8] Hack this as government spy

[0x9] Cyber attacks on critical infrastructure

[0xA] Proving you are secure over compliance

The Web Application Security Consortium

The Web Application Security Consortium (WASC) is an international group of experts, industry practitioners, and organizational representatives who produce open source and widely agreed upon best-practice security standards for the World Wide Web.

[0x1] Sherif Koussa edited Static Analysis Tool Evaluation Criteria Working

[0x2] Ryan Barnett edited Distributed Web Honeypots

[0x3] Ryan Barnett uploaded 200px-SpiderLabs_Logo_2011.png

[0x4] Robert Auger edited Clickjacking Working

[0x5] Robert Auger added Clickjacking Working

[0x6] Ryan Barnett edited Web-Hacking-Incident-Database

[0x7] Ryan Barnett edited Web-Hacking-Incident-Database

[0x8] Robert Auger edited Insufficient Data Protection Working

[0x9] Robert Auger edited Insufficient Data Protection Working

[0xA] Robert Auger edited Insufficient Data Protection Working

Data Management White Papers

Business Intelligence, Database, Data Warehouse, Knowledge Management, and Oracle White Papers

[0x1] Insiders' Guide to Evaluating Remote Control Software

[0x2] Automated Sales Order Processing for Order-to-Cash Performance with SAP(R) Solutions

[0x3] Closing the Order to Cash Performance Gap: Between Document Processes and SAP(R) Solutions

[0x4] Order-to-Cash Best Practices for Billing Documents - Automated Access and Delivery

[0x5] Automating Complete PO Document Packages for Procure-to-Pay Performance with SAP(R) Solutions

[0x6] The Learning Organization Goes Digital

[0x7] 10 Tips - IT Training Support

[0x8] How to Make Your IT Staff Smarter

[0x9] Improving Application Development with Digital Libraries

[0xA] Working Green with Digital Libraries - How it Can Help

Security Career/Staffing

[0x1] It can't always be about hugging and grabbing an ice cream cone

[0x2] #RSAC, #BSidesSF videos: Jack Daniel

[0x3] An Unexpected RSA Encounter

[0x4] Security - It’s Just a Job

[0x5] (ISC)2 Career Impact Survey says: Congratulations. You Kept Your Job

[0x6] Rewind And Replay For Web App Vulnerabilities

[0x7] Cyber Shafarat 2012: Cyber Warfare, OPSEC and Intelligence

[0x8] ShmooCon 2012 is this weekend. Boohoo

[0x9] Key Sessions at CISO Executive Summit 2011

[0xA] Blogging Cybersecurity: Looking Back at the Best, Worst and Most Surprising

honeyblog

A blog on honeypots, honeynets, and more...

[0x1] 2011 Honeynet Project Security Workshop Slides + Videos

[0x2] SysSec Workshop

[0x3] The Last Line of Defense - http://tllod.com

[0x4] Call for Papers: EC2ND'10

[0x5] Chaosradio Express #155

[0x6] Challenge 4 of the Forensic Challenge 2010 - VoIP

[0x7] "Is the Internet for Porn? An Insight Into the Online Adult Industry"

[0x8] USENIX LEET'10 & RAID 2010

[0x9] Technical Report: "Abusing Social Networks for Automated User Profiling"

[0xA] Twitter Spamdetector Service

Latest Secunia Blog Entries

Secunia collects, evaluates, verifies, and analyses vulnerability information.

[0x1] Secunia CSI commended @ SC Awards Europe 2012

[0x2] ARN: 10 commandments of Windows security

[0x3] Secunia CSI supports Microsoft CM 2012

[0x4] Forbes' Secunia PSI review: a “magic download”

[0x5] And now, presenting our next ResearchCast

[0x6] Secunia Achieves Record Growth – Again – and Brings US Expansion into Focus

[0x7] Secunia and MS-ISAC in New Partnership to Provide Vulnerability and Patch Management to US State and Local Governments

[0x8] Bank Info Security interviews Secunia’s CSO

[0x9] Coordinating Vulnerability Disclosures with Apple

[0xA] InfoWorld: Secunia pushes security patches without vendor consent

National Vulnerability Database

This feed contains the most recent fully analyzed CVE cyber vulnerabilities published within the National Vulnerability Database.

[0x1] CVE-2012-2319 (linux_kernel)

[0x2] CVE-2012-2123 (linux_kernel)

[0x3] CVE-2012-2121 (linux_kernel)

[0x4] CVE-2012-1601 (linux_kernel)

[0x5] CVE-2012-1179 (linux_kernel)

[0x6] CVE-2012-1146 (linux_kernel)

[0x7] CVE-2012-1097 (linux_kernel)

[0x8] CVE-2012-1090 (linux_kernel)

[0x9] CVE-2012-0879 (linux_kernel)

[0xA] CVE-2012-0207 (linux_kernel)

Threat Level

Privacy, Crime and Security Online

[0x1] The Ultimate Counterfeiter Isn’t a Crook—He’s an Artist

[0x2] Jamming Tripoli: Inside Moammar Gadhafi’s Secret Surveillance Network

[0x3] Top Handset Maker Confirms Backdoor in One of Its Models

[0x4] Feds Considering Allowing DVD-Encryption Cracking

[0x5] It’s Tinkerers v. Hollywood as Copyright Office Mulls New Jailbreaking Rules

[0x6] Comcast Suspends Data Cap Temporarily, Will Test New Overage Fees

[0x7] To Warrant or Not to Warrant? ACLU, Police Clash Over Cellphone Location Data

[0x8] Justice Dept. Defends Public’s Constitutional ‘Right to Record’ Cops

[0x9] ‘Dead Man Walking’ Tricks Airport Into Giving Him Top Security Job

[0xA] Banned PlayStation Hacker Sees Hope of Return in Jailbreaking Deliberations

GeekDad

Parents, Kids and the Stuff We Obsess About

[0x1] 30 Classic Games for Simple Outdoor Play (GeekDad Wayback Machine)

[0x2] A Different Way to Play Battleship (GeekDad Weekly Rewind)

[0x3] Top 20 Ways to Provoke a Geek Argument (GeekDad Wayback Machine)

[0x4] GeekDad HipTrax #88 (GeekDad Weekly Rewind)

[0x5] A Google-a-Day Puzzle for May 19

[0x6] All Aboard! This Week’s Tabletop Features Ticket to Ride

[0x7] 2001: A Space Odyssey Scene in LEGO as iPhone Dock

[0x8] A GeekDad’s First Maker Faire

[0x9] Schemer Glorious Game Giveaway Winners

[0xA] GeekDad and GeekMom at Maker Faire!

Exotic Liability

Exotic Liability

[0x1] Exotic Liability 84: FTW

[0x2] Exotic Liability 83: Oh yeah

[0x3] Exotic Liability 82 Holidays are Errata funz

[0x4] InfoSec Santa

[0x5] Exotic Liability 80: Unbreakable

[0x6] EL 79: ConGestion

[0x7] Episode 78: Con-dom

[0x8] Exotic Liability 77- Winehouse

[0x9] Exotic Liability 76 - Down the Rabbit Hole

[0xA] Exotic Liability 75: Major Marcus

Security Watch

[0x1] End of Year Security Reports, The Complete List

[0x2] GSM Security, 2011

[0x3] Ad Networks Drive-by Download attack

[0x4] Materials, SecTor 2010

[0x5] Google Hacking Database Reborn

[0x6] Reports, State of the Internet 2010, CA Threat Landscape

[0x7] Materials, VB2010 conference

[0x8] Reports, NSSLabs Consumer Anti-Malware Products Test Report Q3 2010

[0x9] Materials, HITB Malaysia, 2010

[0xA] Patching Days for Oracle, Java, and Microsoft

ITtoolbox Downloads

[0x1] Using WebSphere DataStage with IBM DataMirror Change Data Capture

[0x2] Extend and Reuse Existing Mainframe Functions Through SOA - Part 4 of the Roadmap To Reduce Webcast Series

[0x3] Consolidate Applications From Non-Strategic Platforms Onto z/OS - Part 3 of the Roadmap To Reduce Webcast Series

[0x4] Tech Talk:: Strategic Solutions To Help Solve Top Issues In The Data Center Today

[0x5] How Safe Is Your Network? - Analyst #1 Choice for Vulnerability Management - Free Trial

[0x6] Always be Open for Business

[0x7] Make Compliance Work for You

[0x8] Reduce Operational Costs By Up To 95% - Part 1 of the Roadmap To Reduce Webcast Series

[0x9] Increase productivity by up to 40% - Part 2 of the Roadmap To Reduce Webcast Series

[0xA] Database Trends and Applications Survey Results: The Freshest BI Data from the Journal of Enterprise Data Management

Command Line Kung Fu

This blog will include fun, useful, interesting, security related, non-security related, tips, and tricks associated with the command line. It will include OS X, Linux, and even Windows!

[0x1] Episode #165: What's the Frequency Kenneth?

[0x2] Episode #164: Exfiltration Nation

[0x3] Episode #163: Pilgrim's Progress

[0x4] Episode #162: Et Tu Bruteforce

[0x5] Episode #161: Cleaning up the Joint

[0x6] Episode #160: Plotting to Take Over the World

[0x7] Episode #159: Portalogical Exam

[0x8] Revisiting Episode #151: Readers' Revenge!

[0x9] Episode #158: The Old Switcheroo

[0xA] Episode #157: I Ain't No Fortunate One

MacRumors: Mac News and Rumors - Front Page

the mac news you care about

[0x1] ElcomSoft's Phone Forensics Software Offers Near Real-Time Access to iCloud Backups

[0x2] Apple in Talks to Open R&D Facility in Russia's Skolkovo Innovation Centre?

[0x3] Apple's Annual iTunes Festival in London Moves to September

[0x4] Steve Jobs 'Worked Closely' on Design of Next-Generation iPhone with Larger Display

[0x5] Screenwriter Aaron Sorkin Shares Some Thoughts About Steve Jobs Biopic, Woz Hired As Advisor

[0x6] Apple Board Member Mickey Drexler on Steve Jobs' iCar Dreams, Apple's Living Room Push

[0x7] Verizon Clarifies Discontinuation of Grandfathered Unlimited Data: Applies to New Subsidized Devices

[0x8] Apple Cutting Off Mac App Store Hotkey Apps as Sandboxing Requirement Goes Live on June 1? [Updated]

[0x9] Apple's Data Centers to Be Powered by 100% Renewable Energy

[0xA] Apple Receives Regulatory Approval for 20-Megawatt Solar Farm at North Carolina Data Center

BBC News - Technology

The latest stories from the Technology section of the BBC News web site.

[0x1] Facebook shares see modest debut

[0x2] Met Police to extract phone data

[0x3] Silicon trick for next-gen memory

[0x4] Twitter backs web privacy effort

[0x5] Anonymous attacks Indian websites

[0x6] Computer game for stroke patients

[0x7] Government to miss cookie cut-off

[0x8] China Mobile in talks with Apple

[0x9] Government may miss cloud targets

[0xA] Japan launches S Korea satellite

Well, I'm Back

Robert O'Callahan. Christian. Repatriate Kiwi. Mozilla hacker.

[0x1] Accelerated Scrolling In Firefox: Past, Present And Future

[0x2] Sad And Pathetic Machines

[0x3] Korea

[0x4] The Internet Experiment Has Failed

[0x5] Retrospective On Our Trip To Europe

[0x6] Wakaraanga Creek

[0x7] I'm Back

[0x8] Retro Movie Showcase

[0x9] Requiring Planet Mozilla Content To Be Mozilla-Project-Related

[0xA] Movie Overdose

Google Online Security Blog

The latest news and insights from Google on security and safety on the Internet.

[0x1] Spurring more vulnerability research through increased rewards

[0x2] An improved Google Authenticator app to celebrate millions of 2-step verification users

[0x3] Celebrating one year of web vulnerability research

[0x4] Android and Security

[0x5] Landing another blow against email phishing

[0x6] Tech tips that are Good to Know

[0x7] Expanding Safe Browsing Alerts to include malware distribution domains

[0x8] Reminder: Safe Browsing version 1 API turning down December 1

[0x9] Protecting data for the long term with forward secrecy

[0xA] Safe Browsing Alerts for Network Administrators is graduating from Labs

PandaLabs Blog

Everything you need to know about Internet threats

[0x1] Where is the lulz now?

[0x2] Michael Jackson catalogue stole from Sony. More to come?

[0x3] Bot shopping with my wife

[0x4] PandaLabs Annual Report – 2011

[0x5] Katy Perry and Russell Brand baits to spread a new Facebook worm

[0x6] Sex, lies and Twitter

[0x7] Megaupload and the cybercrime fight

[0x8] The Rise of the Ransomware

[0x9] 2012 Security Trends

[0xA] Could targeted attacks be avoided?

Latest Articles on Security

ZDNet UK's news and analysis for business leaders includes 10,464 articles on Security

[0x1] Privacy watchdog to chase big companies over cookie law

[0x2] UK Anonymous keeps up DDoS barrage on ICO

[0x3] McAfee teams with Intel on energy systems defence

[0x4] Researchers find backdoor on ZTE Android phones

[0x5] Apple releases Flashback tool for Mac OS X 10.5

[0x6] Irish watchdog: Facebook privacy still falls short

[0x7] Adobe changes course and patches Photoshop for free

[0x8] Adobe makes users pay to fix Photoshop flaw

[0x9] Seventeen-year-old arrested over TeamPoison attacks

[0xA] Tougher interception laws to reach Twitter

ASTALAVISTA Forum Feed

[0x1] Realchat

[0x2] Remember To Kill Your Php Scripts!

[0x3] Boobies

[0x4] Aiuto! Sono Nuovo!

[0x5] [Ask] Deface Technique ?

[0x6] Heaven Or Hell

[0x7] Top!

[0x8] Need Mw3 Pc Hacks

[0x9] Hi To All

[0xA] Brute Force Network Share?

Linus' blog

Eventually this might even contain some Torvalds family pictures.

[0x1] Glamorous pictures?

[0x2] Pearls before swine..

[0x3] Thank you for ...

[0x4] Early Halloween Guest

[0x5] "13744 supplied"

[0x6] Meanwhile, in Finland..

[0x7] A Pig Lover's Oath

[0x8] Silly grin

[0x9] Turst me, I know what I'm doing...

[0xA] Demons? Really?

CISSP | Information Security Training | CISSP Certification | CISSP Training - Shon Harris

CISSP Blog by Shon Harris - CISSP - Information Security Training - CISSP Certification - CISSP Training - Security Training - Logical Security - Shon Harris

[0x1] Cold Boot Attack

[0x2] Fuzzing Frameworks

[0x3] The Enigmatic Existence of X-Morphic Exploitation

[0x4] Smart Grid Security Overview

[0x5] Shortages in Federal Government’s Cyber security Work Force

[0x6] Data Loss Prevention: Best practices for protecting your most valuable asset

[0x7] Zeus Toolkit Gangs Staging Mass Attacks on Banking Applications

[0x8] Smartphone security: Risks and protection measures

[0x9] Making the Internet Safer: Online Resources for Parents and Children

[0xA] Interview with Shon Harris

Heorot.net

Learning and Managing Penetration Testing in Today's Chaotic World

[0x1] “Going-to-DefCon” Heorot.net Course Discounts

[0x2] Course Updates

[0x3] Interview on PaulDotCom

[0x4] “Best Of” Hakin9 Magazine

[0x5] Book On Sale Now!

[0x6] DefCon 17 Speech

[0x7] Book Deal Announced

[0x8] Hackerdemia Project

[0x9] IRC Chat and Webinars

[0xA] Hakin9 Magazine article

MySecured.com

Covering Mobile Phone Forensics, Information Security and Computer Security

[0x1] Push for cigarette-like warnings on mobiles in the USA

[0x2] Blackbox JTAG Reverse Engineering @ 26th Chaos Communication Congress

[0x3] Happy Holidays from MySecured.com

[0x4] Sexting and Mobile Phone Forensics

[0x5] NIST Releases a New Report within Mobile Forensic Reference Materials: A Methodology and Reification. NISTIR 7617.

[0x6] New NIST SIM Data Population Tool For Mobile Phone Forensics Uses

[0x7] Augmented Reality Projection Tracking System from Japan

[0x8] Android 2.0 Perview Video (On G1 from SDK)

[0x9] Wearable, Projector and Mobile Phone based Sixth Sense

[0xA] Real-Time Interactive Augmented Reality Billboard

Evil Routers

[0x1] IPv6 – It’s Not An Option

[0x2] Cisco ASA: “read-only file system”

[0x3] How To Upgrade Cisco ASA Software And ASDM

[0x4] Wireless Field Day 2

[0x5] How to Upgrade the License on a Cisco ASA

[0x6] HP Eliminates Premium Licenses; Existing Customers Shafted

[0x7] life# reload

[0x8] iou2net and IOUlive86 now available on Github

[0x9] IOU License Generator on Github

[0xA] Why Gigamon Scares The Crap Out of Me

Veracode in the News

Read the latest news about Veracode

[0x1] 1.12.12 DarkReading

[0x2] 1.9.12 Nextgov

[0x3] 1.5.12 SearchSecurity

[0x4] 1.5.12 CNET

[0x5] 1.3.12 eWeek

[0x6] 11.8.11 Financial Times

[0x7] 11.1.11 Financial Times

[0x8] 10.21.11 eWeek

[0x9] 10.19.11 TechNewsWorld

[0xA] 10.18.11 SD Times

Rational Survivability

Hoff's Ramblings about Information Survivability, Information Centricity, Risk Management and Disruptive Innovation.

[0x1] Overlays: Wasting Away Again In Abstractionville…

[0x2] Tin Foil Hats: On BBQ Brisket & Security Purists…

[0x3] Incomplete Thought: Will the Public Cloud Create a Generation Of Network Stupid?

[0x4] Security As A Service: “The Cloud” & Why It’s a Net Security Win

[0x5] SEO Twitter: The Emotion of Self-Promotion…

[0x6] March 16, 2012: @Beaker’s Tweets O’ the Week…

[0x7] A Funny Thing Happened On My Way To Malware Removal…

[0x8] Why Steeling Your Security Is Less Stainless and More Irony…

[0x9] You Know What’s Dead? Security…

[0xA] Hoff’s RSA 2012 Schedule: My Talks, Panels, Seminars & Such

SANS Internet Storm Center, InfoCON: green

[0x1] PHP 5.4 Remote Exploit PoC in the wild, (Sat, May 19th)

[0x2] ZTE Score M Android Phone backdoor, (Fri, May 18th)

[0x3] ISC StormCast for Friday, May 18th 2012 http://isc.sans.edu/podcastdetail.html?id=2545, (Fri, May 18th)

[0x4] ISC Feature of the Week: Tools->Information Gathering, (Thu, May 17th)

[0x5] New IPv6 Video: IPv6 Router Advertisements https://isc.sans.edu/ipv6videos, (Thu, May 17th)

[0x6] Do Firewalls make sense?, (Thu, May 17th)

[0x7] ISC StormCast for Thursday, May 17th 2012 http://isc.sans.edu/podcastdetail.html?id=2542, (Thu, May 17th)

[0x8] Reserved IP Address Space Reminder, (Wed, May 16th)

[0x9] Avira Antivirus false positives http://forum.avira.com/wbb/index.php?page=Thread&threadID=144875, (Wed, May 16th)

[0xA] New Version of Google Chrome released (19.0.1084.46) , (Wed, May 16th)

The new Security and Penetration Testing Community

A new Information and Penetration Testing Protal for all security and network professionals. The site include a number of whitehat hacking tools and documents like nmap,dsniff,etterkap,yersinia,cisco security.

[0x1] Advance Web Hacking

[0x2] Honeypot

[0x3] The Conflicker Worm

[0x4] Thoughts on Security of the Corporate documents

[0x5] Are Security Audits necessary ?

[0x6] RFID, its implications and how to defeat

[0x7] Assesing Risks

[0x8] FBI Raids: Pertinent or Paranoid?

[0x9] Protecting Children Online

[0xA] Sarbanes Oxley and IT

Suspekt...

A Blog About Code, Information Security, PHP And More

[0x1] Improving the ASLR of Mac OS X Snow Leopard

[0x2] Speaking at POC 2010 - ASLR for jailbroken iPhones

[0x3] Month of PHP Security 2010 has begun…

[0x4] SyScan-Workshop: Advanced PHP Auditing at Source and Bytecode Level

[0x5] MOPS CFP: Deadline Extension - April 18, 2010

[0x6] MOPS - Zend Webinar: Secure Application Development with the Zend Framework

[0x7] Zend Webinar: Sichere Applikationen auf Basis des Zend Frameworks

[0x8] Suhosin-Patch 0.9.9.1

[0x9] Month of PHP Security - Blog Post Drawing

[0xA] Patch breaks Suhosin Security Feature in Debian Unstable/Testing

Microsoft Security Bulletins

[0x1] MS12-034 - Critical : Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578) - Version: 1.1

[0x2] MS12-035 - Critical : Vulnerabilities in .NET Framework Could Allow Remote Code Execution (2693777) - Version: 2.0

[0x3] MS11-100 - Critical : Vulnerabilities in .NET Framework Could Allow Elevation of Privilege (2638420) - Version: 1.4

[0x4] MS12-032 - Important : Vulnerability in TCP/IP Could Allow Elevation of Privilege (2688338) - Version: 1.1

[0x5] MS12-030 - Important : Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2663830) - Version: 1.1

[0x6] MS12-029 - Critical : Vulnerability in Microsoft Word Could Allow Remote Code Execution (2680352) - Version: 1.1

[0x7] MS12-033 - Important : Vulnerability in Windows Partition Manager Could Allow Elevation of Privilege (2690533) - Version: 1.0

[0x8] MS12-031 - Important : Vulnerability in Microsoft Visio Viewer 2010 Could Allow Remote Code Execution (2597981) - Version: 1.0

[0x9] MS12-027 - Critical : Vulnerability in Windows Common Controls Could Allow Remote Code Execution (2664258) - Version: 2.0

[0xA] MS12-028 - Important : Vulnerability in Microsoft Office Could Allow Remote Code Execution (2639185) - Version: 1.1

Light Blue Touchpaper

Security Research, Computer Laboratory, University of Cambridge

[0x1] I’m from the Government and I’m here to help

[0x2] Three paper Thursday: Shamir x3 at Eurocrypt

[0x3] Scrambling for Safety 2012

[0x4] Three Paper Thursday: full disk encryption

[0x5] A one-line software patent – and a fix

[0x6] Risk and privacy in payment systems

[0x7] Call for nominations for PET Award 2012

[0x8] Three Paper Thursday: BGP and its security

[0x9] Job ad: post-doctoral researcher in security, operating systems, computer architecture

[0xA] Three Paper Thursday: Binary analysis and Security

PCI Security Standards Council Press Releases

PCI Security Standards Council latest Press Releases

[0x1] PCI Security Standards Council Provides Guidance to Merchants on Mobile Payment Acceptance Security

[0x2] PCI Security Standards Council Announces Qualified Integrators and Resellers Certification Program

[0x3] PCI Security Standards Council Announces Update to Point-to-point Encryption Program

[0x4] PCI Security Standards Council to Host First Ever Asia Pacific Meeting for Regional Stakeholders

[0x5] PCI Security Standards Council Opens Registration For 2012 Global Community Meetings

[0x6] PCI Security Standards Council Announces Pending Close to Feedback Period

[0x7] PCI Security Standards Council Continue Focus On Mobile Payment Acceptance Security

[0x8] PCI Security Standards Council Appoints Michael Mitchell As 2012 Chairperson

[0x9] PCI Security Standards Council Invites Payments Community to Input on PIN Transaction Security

[0xA] PCI Security Standards Council Announces Winners of Special Interest Group Elections

LWN.net comments

This feed contains the text of all comments posted to the LWN.net site.

[0x1] Fedora 17 release pushed back to May 29

[0x2] Deb -> Rpm?

[0x3] ZFS on Linux

[0x4] A scientific basis for Open Source Software

[0x5] Fedora 17 release pushed back to May 29

[0x6] A scientific basis for Open Source Software

[0x7] A scientific basis for Open Source Software

[0x8] Lotus Symphony code for OpenOffice coming soon

[0x9] X.Org: "A Wasteland of Unreviewedness" (Phoronix)

[0xA] Fedora 17 release pushed back to May 29

F-Secure Antivirus Research Weblog

Weblog of F-Secure Antivirus Research Team

[0x1] Video: Angry Birds Space Trojan & Drive-by Android

[0x2] Repost: Webinar: Making Life Difficult for Malware

[0x3] Recommended Listening: Danger In The Download

[0x4] Download: Mobile Threat Report, Q1 2012

[0x5] What's wrong with marketing software?

[0x6] Pirate Bay to Anonymous: Call Your Mom!

[0x7] Java Drive-by Generator

[0x8] Webinar: Making Life Difficult for Malware

[0x9] Terrorist Groups in the Online World

[0xA] Yet Another SQL Injection Attack

CSOONLINE.com - Supply Chain Security

[0x1] How to start a business continuity program

[0x2] Smart grid (in)securities

[0x3] Global telecom gets a lesson in business continuity

[0x4] Opinion: COAC is a security risk for the U.S.

[0x5] Supply Chain Security Threats: 5 Game-Changing Forces

[0x6] SLIDESHOW: Chemical Safety Training

[0x7] Chemical Spill Response: How Dow is Training Small Town America to Handle Hazmat Emergencies

[0x8] Swine Flu: How to Make Biz Continuity Plans

[0x9] UPDATED: Pandemic Preparedness Primer

[0xA] What New Air Cargo Security Rules Mean for Business

SecuraBit

A show for security professionals.

[0x1] SecuraBit Episode 104: Cackalacky Goodness!

[0x2] SecuraBit Episode 103: Pockets full of Ownsies

[0x3] SecuraBit Episode 102: The Last Train

[0x4] SecuraBit Episode 101: The Survey Says!

[0x5] SecuraBit Episode 100: Double Header with WPS and Forensics!

[0x6] SecuraBit Episode 99: 99 Bottles of Pwn on the Wall!

[0x7] SecuraBit Episode 98: Adapting to Our Internet!

[0x8] More details on the Pentesting Lab

[0x9] SecuraBit Episode 97: Ron Gula and Cyber Warfare!

[0xA] SecuraBit Episode 96: Year in Review!

The InfoSec Blog

System Integrity: Without Integrity you don't have Security

[0x1] If Customers Ask for More Choice, Don’t Listen

[0x2] An OP-ED by Richard Clarke on China

[0x3] Managing Software

[0x4] Surely compliance is binary?

[0x5] Social Engineering and sufficency of awareness training

[0x6] Orwell: a quarter of a century late

[0x7] About ISO 27001 Risk Statement and Controls

[0x8] The 19 most maddening security questions | Security – InfoWorld

[0x9] Please Realize That Piracy is a Service Problem.

[0xA] Upside and downside: How I hate Journalists