<?xml version="1.0" encoding="ISO-8859-1" ?>
<?xml-stylesheet type="text/xsl" href="/xsl/index.xsl"?>

<BODY>
<TITLE>
Welcome to the Hostsplus Security Information Center
</TITLE>
<MENU>
    <MENUOBJECT>

	<MENUTITLE>
		Vulnerability Info	
	</MENUTITLE>

	<MENUITEM>
		<menuurl>
			http://www.securityfocus.com
		</menuurl>
		<MENUBODY>
			Security Focus	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.osvdb.org
		</menuurl>
		<MENUBODY>
			OSVDB
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://nvd.nist.gov
		</menuurl>
		<MENUBODY>
			Nist NVD
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://cve.mitre.org
		</menuurl>
		<MENUBODY>
			Mitre
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://ciac.llnl.gov
		</menuurl>
		<MENUBODY>
			CIAC
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.cert.org
		</menuurl>
		<MENUBODY>
			CERT
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://iase.disa.mil
		</menuurl>
		<MENUBODY>
			ISAE
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Exploit Info	
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.milw0rm.com
		</menuurl>
		<MENUBODY>
			Milw0rm
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.packetstormsecurity.nl
		</menuurl>
		<MENUBODY>
			Packet Storm
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.elsenot.com
		</menuurl>
		<MENUBODY>
			Else Not
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Active Research Groups
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.shmoo.com
		</menuurl>
		<MENUBODY>
			The Shmoo Group
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.thc.org
		</menuurl>
		<MENUBODY>
			THC
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>
			http://www.phenoelit.de
		</menuurl>
		<MENUBODY>
			Phenoelit
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>

	<MENUTITLE>
		Commercial Groups
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.ngssoftware.com
		</menuurl>
		<MENUBODY>
			NGS
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.immunitysec.com
		</menuurl>
		<MENUBODY>
			Immunitysec
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.secunia.com
		</menuurl>
		<MENUBODY>
			Secunia
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.securiteam.com
		</menuurl>
		<MENUBODY>
			Securiteam
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://xforce.iss.net
		</menuurl>
		<MENUBODY>
			Xforce
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.idefense.com
		</menuurl>
		<MENUBODY>
			Idefense
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.eeye.com
		</menuurl>
		<MENUBODY>
			Eeye
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://www.2600.com
		</menuurl>
		<MENUBODY>
			2600
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Security Organizations
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.owasp.org
		</menuurl>
		<MENUBODY>
			OWASP
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.isc2.org
		</menuurl>
		<MENUBODY>
			ISC2
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.isecom.org
		</menuurl>
		<MENUBODY>
			ISECOM
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://www.sans.org
		</menuurl>
		<MENUBODY>
			SANS
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.infragard.com
		</menuurl>
		<MENUBODY>
			Infragard
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Methodologies	
	</MENUTITLE>

	<MENUITEM>
		<menuurl>
			http://www.osissg.org
		</menuurl>
		<MENUBODY>
			OISSG
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.isecom.org/
		</menuurl>
		<MENUBODY>
			ISECOM
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.osstmm.org
		</menuurl>
		<MENUBODY>
			OSSTMM
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>

	<MENUTITLE>
		Free "Auditing" Tools
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.nessus.org
		</menuurl>
		<MENUBODY>
			Nessus
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.insecure.org
		</menuurl>
		<MENUBODY>
			Nmap
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.cqure.net
		</menuurl>
		<MENUBODY>
			Cqure Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.sqlsecurity.com/DesktopDefault.aspx?tabid=26	
		</menuurl>
		<MENUBODY>
			MS SQL Utilities
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.cirt.net
		</menuurl>
		<MENUBODY>
			Nikto
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.sysinternals.com
		</menuurl>
		<MENUBODY>
			Sysinternals Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.bindview.com/services/razor/utilities/
		</menuurl>
		<MENUBODY>
			Bindview Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://thc.org/releases.php
		</menuurl>
		<MENUBODY>
			THC Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.metasploit.org
		</menuurl>
		<MENUBODY>
			Metasploit
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.parosproxy.org/
		</menuurl>
		<MENUBODY>
			Paros Proxy
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.portswigger.net/proxy/
		</menuurl>
		<MENUBODY>
			Burp Proxy
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://www.securityforest.com
		</menuurl>
		<MENUBODY>
			Exploit Tree
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.tank.net
		</menuurl>
		<MENUBODY>
			Spork
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://ettercap.sourceforge.net/
		</menuurl>
		<MENUBODY>
			Ettercap
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.cirt.net/code/nikto.shtml
		</menuurl>
		<MENUBODY>
			nikto
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://www.sensepost.com/research/wikto/
		</menuurl>
		<MENUBODY>
			wikto
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.nstalker.com/eng/products/nstealth/
		</menuurl>
		<MENUBODY>
			nStealth
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>
			http://www.foofus.net/fizzgig/fgdump/
		</menuurl>
		<MENUBODY>
			fgdump (Obtain MS Hashes)
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.off-by-one.net/misc/cachedump.html
		</menuurl>
		<MENUBODY>
			Cachedump (Obtain MS Hashes)
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://studenti.unina.it/~ncuomo/syskey/
		</menuurl>
		<MENUBODY>
			samdump2
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>
			http://www.ethereal.com/
		</menuurl>
		<MENUBODY>
			Ethereal
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.immunitysec.com/resources-freesoftware.shtml
		</menuurl>
		<MENUBODY>
			Free Immunitysec Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.foundstone.com/resources/freetools.htm
		</menuurl>
		<MENUBODY>
			Free Foundstone Tools
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.eeye.com/html/Research/Tools/index.html
		</menuurl>
		<MENUBODY>
			Free Eeye Tools
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://sectools.org/
		</menuurl>
		<MENUBODY>
			Sectools.org
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Free Virtualization Tools	
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.vmware.com/products/server/
		</menuurl>
		<MENUBODY>
			VMWare Server
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://bochs.sourceforge.net/
		</menuurl>
		<MENUBODY>
			Bochs
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://pearpc.sourceforge.net/
		</menuurl>
		<MENUBODY>
			PearPC	
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>	
			http://www.microsoft.com/windows/virtualpc/default.mspx
		</menuurl>
		<MENUBODY>
			MS Virtual PC
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Free Reverse Engineering/Debugging Tools	
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://directory.fsf.org/GNU/binutils.html
		</menuurl>
		<MENUBODY>
			binutils
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.gnu.org/software/gdb/
		</menuurl>
		<MENUBODY>
			GDB
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://directory.fsf.org/GNU/GUSS.html
		</menuurl>
		<MENUBODY>
			Guss
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.gnu.org/software/ddd/
		</menuurl>
		<MENUBODY>
			DDD
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.ollydbg.de/
		</menuurl>
		<MENUBODY>
			Ollydbg 
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://labs.idefense.com/labs-software.php
		</menuurl>
		<MENUBODY>
			iDefense Labs Tools
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://oss.coresecurity.com/projects/uhooker.htm
		</menuurl>
		<MENUBODY>
			CORE Tools
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Defaced Websites
	</MENUTITLE>


	<MENUITEM>
		<menuurl>
			http://www.zone-h.org/component/option,com_attacks/Itemid,43/
		</menuurl>
		<MENUBODY>
			Zone H
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Default Password Lists
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.cirt.net/cgi-bin/passwd.pl
		</menuurl>
		<MENUBODY>
			Cirt's Passwords
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.phenoelit.de/dpl/dpl.html
		</menuurl>
		<MENUBODY>
			Phenoelit's Passwords
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://www.petefinnigan.com/default/default_password_list.htm
		</menuurl>
		<MENUBODY>
			Pete Finnigan's Default Oracle Passwords
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.governmentsecurity.org/articles/DefaultLoginsandPasswordsforNetworkedDevices.php
		</menuurl>
		<MENUBODY>
			GovernmentSecurity.org
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://defaultpassword.com/
		</menuurl>
		<MENUBODY>
			defaultpassword.com
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.cyxla.com/passwords/passwords.html
		</menuurl>
		<MENUBODY>
			Cyxla's Password Database
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.e-tech.ca/017-Default_Passwords_ad.asp
		</menuurl>
		<MENUBODY>
			e-tech Default Passwords
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.uktsupport.co.uk/reference/biosp.htm
		</menuurl>
		<MENUBODY>
			Bios Passwords
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		Technical Conferences
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.defcon.org
		</menuurl>
		<MENUBODY>
			DefCon
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.blackhat.com
		</menuurl>
		<MENUBODY>
			Blackhat
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.cansecwest.com
		</menuurl>
		<MENUBODY>
			CanSecWest
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://toorcon.com
		</menuurl>
		<MENUBODY>
			Toorcon
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
		 	http://www.shmoocon.org/	
		</menuurl>
		<MENUBODY>
			ShmooCon
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://www.hopenumbersix.net/
		</menuurl>
		<MENUBODY>
			H.O.P.E.
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.ccc.de/calendar/2006/23c3?language=en
		</menuurl>
		<MENUBODY>
			Chaos Computer Congress
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://conference.hackinthebox.org/
		</menuurl>
		<MENUBODY>
			Hack in the Box
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>
    <MENUOBJECT>
	<MENUTITLE>
		CD Distros
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.remote-exploit.org/index.php/Auditor_main
		</menuurl>
		<MENUBODY>
			Auditor
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.knoppix.org
		</menuurl>
		<MENUBODY>
			Knoppix
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.whoppix.net/index.php/Tools
		</menuurl>
		<MENUBODY>
			Whoppix / Whax
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.remote-exploit.org/index.php/Main_Page
		</menuurl>
		<MENUBODY>
			BackTrack
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Wireless Tools
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.netstumbler.com
		</menuurl>
		<MENUBODY>
			Netstumbler
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://prismstumbler.sourceforge.net
		</menuurl>
		<MENUBODY>
			Prismstubler
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.kismetwireless.net
		</menuurl>
		<MENUBODY>
			Kismet
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://kismac.de/
		</menuurl>
		<MENUBODY>
			Kismac (For Macs)
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://airsnort.shmoo.com
		</menuurl>
		<MENUBODY>
			Airsnort
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://wepcrack.sourceforge.net
		</menuurl>
		<MENUBODY>
			WEPCrack
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.aircrack-ng.org/doku.php
		</menuurl>
		<MENUBODY>
			Aircrack-ng
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://csrc.nist.gov/publications/nistpubs/800-48/NIST_SP-48.pdf
		</menuurl>
		<MENUBODY>
			Wireless SP
		</MENUBODY>
	</MENUITEM>



	<MENUITEM>
		<menuurl>
			http://www.blackalchemy.to/project/fakeap/
		</menuurl>
		<MENUBODY>
			FakeAP
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.802.11mercenary.net/lorcon/
		</menuurl>
		<MENUBODY>
			Lorcon
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://theta44.org/karma/index.html
		</menuurl>
		<MENUBODY>
			Karma
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

    <MENUOBJECT>
	<MENUTITLE>
		Checklists / Hardening Guides
	</MENUTITLE>

	<MENUITEM>
		<menuurl>
			http://csrc.nist.gov
		</menuurl>
		<MENUBODY>
			NIST CSRC
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://checklists.nist.gov
		</menuurl>
		<MENUBODY>
			NIST Checklists
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.cisecurity.org
		</menuurl>
		<MENUBODY>
			Center for Internet Security
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.nsa.gov/snac/index.cfm?MenuID=scg10.3.1
		</menuurl>
		<MENUBODY>
			NSA Security Configuration Guides
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>

		<menuurl>
			http://otn.oracle.com/deploy/security/oracle9i/pdf/9i_checklist.pdf
		</menuurl>
		<MENUBODY>
			Oracle's 9i Checklist
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>

		<menuurl>
			http://www.petefinnigan.com/orasec.htm
		</menuurl>
		<MENUBODY>
			PF's Checklists
		</MENUBODY>

	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.microsoft.com/technet/archive/security/chklist/default.mspx
		</menuurl>
		<MENUBODY>
			Microsoft Checklists
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.openna.com/pdfs/Securing-Optimizing-Linux-The-Ultimate-Solution-v2.0.pdf
		</menuurl>
		<MENUBODY>
			Securing and Optimizing Linux
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		OS and Service Hardening Tools
        </MENUTITLE>


        <MENUITEM>
                <menuurl>
			http://www.sun.com/software/security/jass/	 
                </menuurl>
                <MENUBODY>
			Solaris - JASS
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>
			http://www.sun.com/service/serviceplans/software/patchmanagement/patchmanager.html
                </menuurl>
                <MENUBODY>
			Solaris - Patch Manager
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>
			http://www.bastille-linux.org/
                </menuurl>
                <MENUBODY>
			Linux - Bastille
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>
			http://www.microsoft.com/technet/security/tools/default.mspx#EZE
                </menuurl>
                <MENUBODY>
			Microsoft Security Tools
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>
   <MENUOBJECT>
	<MENUTITLE>
		Defunct Research Groups ?
	</MENUTITLE>
	<MENUITEM>
		<menuurl>
			http://www.attrition.org
		</menuurl>
		<MENUBODY>
			Attrition
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.w00w00.org
		</menuurl>
		<MENUBODY>
			w00w00
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://adm.freelsd.net/ADM/
		</menuurl>
		<MENUBODY>
			ADM
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.cultdeadcow.com
		</menuurl>
		<MENUBODY>
			CDC
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://en.wikipedia.org/wiki/TESO
		</menuurl>
		<MENUBODY>
			TESO	
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://en.wikipedia.org/wiki/Gobbles
		</menuurl>
		<MENUBODY>
			Gobbles	
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>


    <MENUOBJECT>
	<MENUTITLE>
		Professional Security Programs
	</MENUTITLE>

	<MENUITEM>
		<menuurl>
			http://corporate.visa.com/st/programs.jsp
		</menuurl>
		<MENUBODY>
		 	Visa Security Programs
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			https://sdp.mastercardintl.com/
		</menuurl>
		<MENUBODY>
		 	MasterCard Site Data Protection Program
		</MENUBODY>
	</MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
                Password Crackers/Auditors
        </MENUTITLE>


	<MENUITEM>
		<menuurl>
			http://www.insecure.org/stf/lc5-setup.exe
		</menuurl>
		<MENUBODY>
			LC5 
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.insecure.org/stf/lc5-crack.zip
		</menuurl>
		<MENUBODY>
			LC5 Keygen
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://www.oxid.it/cain.html
		</menuurl>
		<MENUBODY>
			Cain and Abel
		</MENUBODY>
	</MENUITEM>


	<MENUITEM>
		<menuurl>
			http://www.openwall.com/john/
		</menuurl>
		<MENUBODY>
			John the Ripper
		</MENUBODY>
	</MENUITEM>
	<MENUITEM>
		<menuurl>
			http://www.banquise.net/misc/patch-john.html
		</menuurl>
		<MENUBODY>
			John Bigpatch (For more hash types)
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://en.wikipedia.org/wiki/RainbowCrack
		</menuurl>
		<MENUBODY>
			RainbowCrack 
		</MENUBODY>
	</MENUITEM>

	<MENUITEM>
		<menuurl>
			http://rainbowtables.shmoo.com/
		</menuurl>
		<MENUBODY>
			Rainbow Tables
		</MENUBODY>
	</MENUITEM>
    </MENUOBJECT>


   <MENUOBJECT>
        <MENUTITLE>
                Open Source Intelligence
        </MENUTITLE>

        <MENUITEM>
                <menuurl>
                        http://johnny.ihackstuff.com/
                </menuurl>
                <MENUBODY>
                        Google Hacking
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
                        http://news.netcraft.com/
                </menuurl>
                <MENUBODY>
                        NetCraft
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
                        http://www.archive.org/
                </menuurl>
                <MENUBODY>
                        Way Back Machine
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>
                        http://www.domaintools.com
                </menuurl>
                <MENUBODY>
                        DomainTools
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>
                        http://whois.webhosting.info
                </menuurl>
                <MENUBODY>
                        Web Hosting dot info 
                </MENUBODY>
        </MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Compliance Resources
        </MENUTITLE>

        <MENUITEM>
                <menuurl>
			http://www.hhs.gov/ocr/hipaa/
                </menuurl>
                <MENUBODY>
                        HIPAA
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://www.aicpa.org/info/sarbanes_oxley_summary.htm
                </menuurl>
                <MENUBODY>
			SOX
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://banking.senate.gov/conf/
                </menuurl>
                <MENUBODY>
			FMA (GLBA)
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://csrc.nist.gov/sec-cert/
                </menuurl>
                <MENUBODY>
			FISMA
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://www.iso.org/iso/en/prods-services/popstds/informationsecurity.html
                </menuurl>
                <MENUBODY>
			ISO 17799
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://csrc.nist.gov/fasp/
                </menuurl>
                <MENUBODY>
			NIST FASP Resources
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp.html
                </menuurl>
                <MENUBODY>
			Visa PCI
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://www.sans.org/resources/policies/
                </menuurl>
                <MENUBODY>
			SANS Security Policies
                </MENUBODY>
        </MENUITEM>

    </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Email Lists
        </MENUTITLE>

        <MENUITEM>
                <menuurl>
			http://www.securityfocus.com/archive
                </menuurl>
                <MENUBODY>
			Security Focus E-mail Lists
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://lists.grok.org.uk/mailman/listinfo/full-disclosure
                </menuurl>
                <MENUBODY>
			Full Disclosure (Unmoderated)
                </MENUBODY>
        </MENUITEM>


        <MENUITEM>
                <menuurl>
			http://www.immunitysec.com/mailman/listinfo/dailydave
                </menuurl>
                <MENUBODY>
			Daily Dave
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>
			http://www.seclists.org
                </menuurl>
                <MENUBODY>
			Security List Archives
                </MENUBODY>
        </MENUITEM>


   </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		Defense / IDS
        </MENUTITLE>

        <MENUITEM>
                <menuurl>
			http://www.snort.org
                </menuurl>
                <MENUBODY>
			Snort
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://www.bleedingsnort.com
                </menuurl>
                <MENUBODY>
			"Bleeding Edge" Snort
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://acidlab.sourceforge.net/
                </menuurl>
                <MENUBODY>
			ACID Snort Interface
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>





   <MENUOBJECT>
        <MENUTITLE>
		Load Testing / Denial of Service Info
        </MENUTITLE>
        <MENUITEM>
                <menuurl>
			http://staff.washington.edu/dittrich/misc/ddos/
                </menuurl>
                <MENUBODY>
			DDOS Info
                </MENUBODY>
        </MENUITEM>

   </MENUOBJECT>

   <MENUOBJECT>
        <MENUTITLE>
		IDS Testing/Tuning Tools
        </MENUTITLE>

        <MENUITEM>
                <menuurl>
			ftp://ftp.st.ryuAkoku.ac.jp/pub/security/tool/snot/
                </menuurl>
                <MENUBODY>
			Snot
                </MENUBODY>
        </MENUITEM>

        <MENUITEM>
                <menuurl>
			http://securityfocus.com/data/tools/stick.tgz
                </menuurl>
                <MENUBODY>
			Stick
                </MENUBODY>
        </MENUITEM>

   </MENUOBJECT>
   <MENUOBJECT>
        <MENUTITLE>
		Firewall Ruleset Testing Tools
        </MENUTITLE>

        <MENUITEM>
                <menuurl>
			http://www.packetfactory.net/projects/firewalk/	
                </menuurl>
                <MENUBODY>
			Firewalk
                </MENUBODY>
        </MENUITEM>
        <MENUITEM>
                <menuurl>
			http://dev.inversepath.com/trac/ftester			
                </menuurl>
                <MENUBODY>
			FTester
                </MENUBODY>
        </MENUITEM>
   </MENUOBJECT>
</MENU>
<MSG>
    <MSGARTICLE>
	<MSGTITLE>
Welcome to the HostsPlus Security Information Center.
	</MSGTITLE>
	<MSGBODY>
This is a portal site created by HostsPlus to enable our clients and other interested parties to learn more about Information Security.
	</MSGBODY>
    </MSGARTICLE>
</MSG>
>rss version="2.0">
>channel>
    >title>Bugtraq>/title>
    >link>http://seclists.org/#bugtraq>/link>
    >description>The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!>/description>
  >item>
    >title>ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/79>/link>
    >description>&lt;p&gt;Posted by ZDI Disclosures on Mar 09&lt;/p&gt;ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability&lt;br&gt;
required to...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>[security bulletin] HPSBMA02489 SSRT090065 rev.1 - HP Performance Insight , Remote Execution of Arbitrary Commands>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/78>/link>
    >description>&lt;p&gt;Posted by security-alert on Mar 09&lt;/p&gt;SUPPORT COMMUNICATION - SECURITY BULLETIN&lt;br&gt;
Source: Hewlett-Packard Company, HP Software Security Response...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>[SECURITY] [DSA 2008-1] New typo3-src packages fix several vulnerabilities>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/77>/link>
    >description>&lt;p&gt;Posted by Moritz Muehlenhoff on Mar 09&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
Problem type   : local/remote...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>IBM ENOVIA SmarTeam v5 Cross Site Scripting Vulnerability>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/76>/link>
    >description>&lt;p&gt;Posted by lament on Mar 09&lt;/p&gt;=========================================&lt;br&gt;
driving...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy Provides Security Bypass>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/75>/link>
    >description>&lt;p&gt;Posted by Sabahattin Gucukoglu on Mar 09&lt;/p&gt;Do you have firmware information on which products it affects.&lt;br&gt;
think was true for Airport...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>SQL injection vulnerability in wILD CMS>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/74>/link>
    >description>&lt;p&gt;Posted by Maciej Gojny on Mar 09&lt;/p&gt;# Title: [SQL injection vulnerability in wILD CMS]&lt;br&gt;
# Name: wILD CMS...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Croogo CMS 1.2 Cross Site Scripting Vulnerabilities>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/73>/link>
    >description>&lt;p&gt;Posted by Paulino Calderon on Mar 09&lt;/p&gt;Croogo CMS 1.2 Cross Site Scripting Vulnerabilities&lt;br&gt;
  BACKGROUND...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>[ MDVSA-2010:057 ] apache>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/72>/link>
    >description>&lt;p&gt;Posted by security on Mar 08&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
           Enterprise Server 5.0...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: phpinfo() XSS Vulnerability>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/71>/link>
    >description>&lt;p&gt;Posted by Salvatore Fresta aka Drosophila on Mar 08&lt;/p&gt;I tested it with php 5.1.6 and 5.2.6 and seems not work. The&lt;br&gt;
/phpinfo.php?+%3CScRipT%3Ealert(0111001101100101011000110111010101110010011010010111010001111001);%3C/sCrIpT%3E+&lt;br&gt;>/description>
  >/item>
  >item>
    >title>[USN-907-1] gnome-screensaver vulnerabilities>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/70>/link>
    >description>&lt;p&gt;Posted by Marc Deslauriers on Mar 08&lt;/p&gt;===========================================================&lt;br&gt;
The problem can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>rPSA-2010-0014-1 mysql mysql-bench mysql-server>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/69>/link>
    >description>&lt;p&gt;Posted by rPath Update Announcements on Mar 08&lt;/p&gt;rPath Security Advisory: 2010-0014-1&lt;br&gt;
    mysql-bench=conary.rpath.com...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>rPSA-2010-0013-1 gzip>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/68>/link>
    >description>&lt;p&gt;Posted by rPath Update Announcements on Mar 08&lt;/p&gt;rPath Security Advisory: 2010-0013-1&lt;br&gt;
rPath Issue Tracking System:...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>rPSA-2010-0012-1 postgresql postgresql-contrib postgresql-server>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/67>/link>
    >description>&lt;p&gt;Posted by rPath Update Announcements on Mar 08&lt;/p&gt;rPath Security Advisory: 2010-0012-1&lt;br&gt;
    postgresql=conary.rpath.com () rpl:2/8.3.9-0.1-1...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>rPSA-2010-0011-1 gnome-ssh-askpass openssh openssh-client openssh-server>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/66>/link>
    >description>&lt;p&gt;Posted by rPath Update Announcements on Mar 08&lt;/p&gt;rPath Security Advisory: 2010-0011-1&lt;br&gt;
    openssh=conary.rpath.com () rpl:1/5.3p1-0.3-1...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>ZoneAlarm Security Circumvention>/title>
    >link>http://seclists.org/bugtraq/2010/Mar/65>/link>
    >description>&lt;p&gt;Posted by Andrew Barkley on Mar 08&lt;/p&gt;Hi,&lt;br&gt;
Certain vendors (including ZoneAlarm) implement...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Daily Dave>/title>
    >link>http://seclists.org/#dailydave>/link>
    >description>This technical discussion list covers vulnerability research, exploit development, and security events/gossip.  It was started by &lt;a href=&quot;http://www.immunitysec.com/&quot;&gt;ImmunitySec&lt;/a&gt; founder Dave Aitel and many security luminaries participate.  Many posts simply advertise Immunity products, but you can&#39;t really fault Dave for being self-promotional on a list named DailyDave.>/description>
  >item>
    >title>Re: Mike Bailey's Flash presentation is good.>/title>
    >link>http://seclists.org/dailydave/2010/q1/80>/link>
    >description>&lt;p&gt;Posted by Florian Weimer on Mar 09&lt;/p&gt;Bugs in web application frameworks are typically not fixed in the&lt;br&gt;
that makes scanners not entirely useless.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Mike Bailey's Flash presentation is good.>/title>
    >link>http://seclists.org/dailydave/2010/q1/79>/link>
    >description>&lt;p&gt;Posted by dave on Mar 09&lt;/p&gt;People in the web application security space are often more into&lt;br&gt;
But web application hacking can be as complex as a CLOUDBURST style...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Does anyone have video of this?>/title>
    >link>http://seclists.org/dailydave/2010/q1/78>/link>
    >description>&lt;p&gt;Posted by Nate Lawson on Mar 04&lt;/p&gt;I'm not sure why you're so excited about this. This panel is up every&lt;br&gt;
As for the NSA, crypto is such...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Perforce>/title>
    >link>http://seclists.org/dailydave/2010/q1/77>/link>
    >description>&lt;p&gt;Posted by Intevydis on Mar 04&lt;/p&gt;Hi,&lt;br&gt;
to trigger send the following data to port &amp;quot;...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Does anyone have video of this?>/title>
    >link>http://seclists.org/dailydave/2010/q1/76>/link>
    >description>&lt;p&gt;Posted by Dave Aitel on Mar 04&lt;/p&gt;Btw, for those who missed it:&lt;br&gt;
-dave&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Does anyone have video of this?>/title>
    >link>http://seclists.org/dailydave/2010/q1/75>/link>
    >description>&lt;p&gt;Posted by Dave Aitel on Mar 02&lt;/p&gt;NSA, cryptoexperts jab at RSA Conference Cryptographers' Panel&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1407881,00.html&quot;&gt;http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1407881,00.html&lt;/a&gt;&lt;br&gt;>/description>
  >/item>
  >item>
    >title>FIRST 2010!>/title>
    >link>http://seclists.org/dailydave/2010/q1/74>/link>
    >description>&lt;p&gt;Posted by dave on Mar 02&lt;/p&gt;I'm giving a keynote at FIRST 2010. As you might imagine, FIRST is an&lt;br&gt;
Incident response happens when your secure...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Month of PHP Security 2010 - CALL FOR PAPERS>/title>
    >link>http://seclists.org/dailydave/2010/q1/73>/link>
    >description>&lt;p&gt;Posted by Stefan Esser on Feb 27&lt;/p&gt;Month of PHP Security 2010 - CALL FOR PAPERS&lt;br&gt;
The intention of...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>dnsmap v0.30 + embedded devices discovery trick>/title>
    >link>http://seclists.org/dailydave/2010/q1/72>/link>
    >description>&lt;p&gt;Posted by Adrian P. on Feb 25&lt;/p&gt;Hello folks,&lt;br&gt;
ranges,...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: XSS in viewstate>/title>
    >link>http://seclists.org/dailydave/2010/q1/71>/link>
    >description>&lt;p&gt;Posted by Nicolas RUFF on Feb 21&lt;/p&gt;        Hello,&lt;br&gt;
serialization logic (but it...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: XSS in viewstate>/title>
    >link>http://seclists.org/dailydave/2010/q1/70>/link>
    >description>&lt;p&gt;Posted by David Byrne on Feb 19&lt;/p&gt;We usually see MAC protection turned off on at least one page during an&lt;br&gt;
Chris Weber wrote:&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: XSS in viewstate>/title>
    >link>http://seclists.org/dailydave/2010/q1/69>/link>
    >description>&lt;p&gt;Posted by David Byrne on Feb 19&lt;/p&gt;In our original advisory, we did comment that Microsoft hinted at this vulnerability in a rather buried document &lt;br&gt;
first time (as far as we know) that the .Net framework was demonstrated to be vulnerable to XSS through the...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: XSS in viewstate>/title>
    >link>http://seclists.org/dailydave/2010/q1/68>/link>
    >description>&lt;p&gt;Posted by dave on Feb 19&lt;/p&gt;We usually see MAC protection turned off on at least one page during an&lt;br&gt;
Chris Weber wrote:&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: XSS in viewstate>/title>
    >link>http://seclists.org/dailydave/2010/q1/67>/link>
    >description>&lt;p&gt;Posted by David Byrne on Feb 19&lt;/p&gt;&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.hacking-lab.com/misc/downloads/ViewState_Afames.pdf&quot;&gt;http://www.hacking-lab.com/misc/downloads/ViewState_Afames.pdf&lt;/a&gt;&lt;br&gt;
-dave&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: XSS in viewstate>/title>
    >link>http://seclists.org/dailydave/2010/q1/66>/link>
    >description>&lt;p&gt;Posted by Raw Data on Feb 19&lt;/p&gt;Hi Dave,&lt;br&gt;
MAC is managed internally...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Firewall Wizards>/title>
    >link>http://seclists.org/#firewall-wizards>/link>
    >description>Tips and tricks for firewall administrators>/description>
  >item>
    >title>Call for papers: ISP-10, Orlando, USA, July 2010>/title>
    >link>http://seclists.org/firewall-wizards/2010/Feb/6>/link>
    >description>&lt;p&gt;Posted by James Heralds on Feb 22&lt;/p&gt;It would be highly appreciated if you could share this announcement with&lt;br&gt;
be held during 12-14 of July 2010...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Inline 2 port POE Firewall>/title>
    >link>http://seclists.org/firewall-wizards/2010/Feb/5>/link>
    >description>&lt;p&gt;Posted by bruces on Feb 16&lt;/p&gt;What about the RouterBoard 433 series boards. Three NICs and POE,  &lt;br&gt;
Quoting Kerry Milestone &amp;lt;km4 () sanger ac uk&amp;gt;:&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Inline 2 port POE Firewall>/title>
    >link>http://seclists.org/firewall-wizards/2010/Feb/4>/link>
    >description>&lt;p&gt;Posted by Kerry Milestone on Feb 16&lt;/p&gt;Hello,&lt;br&gt;
fairly cheap price - rather than have to...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Login straight to priv mode in PIX with TACACS server>/title>
    >link>http://seclists.org/firewall-wizards/2010/Feb/3>/link>
    >description>&lt;p&gt;Posted by John Morrison on Feb 12&lt;/p&gt;Michel,&lt;br&gt;
cannot contact the TACACS+ server is to remove the network cables.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Login straight to priv mode in PIX with TACACS server>/title>
    >link>http://seclists.org/firewall-wizards/2010/Feb/2>/link>
    >description>&lt;p&gt;Posted by Michel Ferreira on Feb 11&lt;/p&gt;Hi,&lt;br&gt;
command if I need console access I still will be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Draft paper submission deadline is extended: ISP-10>/title>
    >link>http://seclists.org/firewall-wizards/2010/Feb/1>/link>
    >description>&lt;p&gt;Posted by James Heralds on Feb 05&lt;/p&gt;Draft paper submission deadline is extended: ISP-10&lt;br&gt;
The conference will be held at the same time and location where...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Hackito Ergo Sum 2010 - Call For Paper	- HES2010 CFP>/title>
    >link>http://seclists.org/firewall-wizards/2010/Feb/0>/link>
    >description>&lt;p&gt;Posted by endrazine on Feb 04&lt;/p&gt;Hackito Ergo Sum 2010 - Call For Paper - HES2010 CFP&lt;br&gt;
The goal of this...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Is it possible to control access between clients on same LAN with a firewall?>/title>
    >link>http://seclists.org/firewall-wizards/2010/Jan/37>/link>
    >description>&lt;p&gt;Posted by pkc_mls on Jan 28&lt;/p&gt;William Fitzgerald a écrit :&lt;br&gt;
on the LAN.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Is it possible to control access between clients on same LAN with a firewall?>/title>
    >link>http://seclists.org/firewall-wizards/2010/Jan/36>/link>
    >description>&lt;p&gt;Posted by Paul D. Robertson on Jan 27&lt;/p&gt;I'm going to give you the non-firewall, imperfect but quick and easy &lt;br&gt;
the &amp;quot;internal&amp;quot; network on the router....&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Is it possible to control access between clients on same LAN with a firewall?>/title>
    >link>http://seclists.org/firewall-wizards/2010/Jan/35>/link>
    >description>&lt;p&gt;Posted by William Fitzgerald on Jan 27&lt;/p&gt;Hi everyone,&lt;br&gt;
Pete.LeMay wrote:&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Is it possible to control access between clients on	same LAN with a firewall?>/title>
    >link>http://seclists.org/firewall-wizards/2010/Jan/34>/link>
    >description>&lt;p&gt;Posted by Will Brickles on Jan 27&lt;/p&gt;Using DD-WRT, what comes to mind immediately is to put your devices into separate VLANs and then use iptables to &lt;br&gt;
Using other (much more...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Is it possible to control access between clients on	same LAN with a firewall?>/title>
    >link>http://seclists.org/firewall-wizards/2010/Jan/33>/link>
    >description>&lt;p&gt;Posted by K K on Jan 27&lt;/p&gt;Yes.&lt;br&gt;
Kevin&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Is it possible to control access between clients on	same LAN with a firewall?>/title>
    >link>http://seclists.org/firewall-wizards/2010/Jan/32>/link>
    >description>&lt;p&gt;Posted by Paul Melson on Jan 26&lt;/p&gt;With DD-WRT you can assign a different VLAN to each interface of the&lt;br&gt;
connected to that switch from each...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Is it possible to control access between clients on	same LAN with a firewall?>/title>
    >link>http://seclists.org/firewall-wizards/2010/Jan/31>/link>
    >description>&lt;p&gt;Posted by Mark on Jan 26&lt;/p&gt;Will:&lt;br&gt;
firewall filter the traffic, in essence you would be creating a...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Is it possible to control access between clients on	same LAN with a firewall?>/title>
    >link>http://seclists.org/firewall-wizards/2010/Jan/30>/link>
    >description>&lt;p&gt;Posted by Eric Gearhart on Jan 26&lt;/p&gt;You sound like you might already know this, but I may as well&lt;br&gt;
separate...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>IDS Focus>/title>
    >link>http://seclists.org/#focus-ids>/link>
    >description>Technical discussion about Intrusion Detection Systems.  You can also read the archives of a &lt;A HREF=&quot;http://seclists.org/ids/&quot;&gt;previous IDS list&lt;/A&gt;>/description>
  >item>
    >title>Call for Papers: EC2ND 2010>/title>
    >link>http://seclists.org/focus-ids/2010/Mar/0>/link>
    >description>&lt;p&gt;Posted by Konrad Rieck on Mar 08&lt;/p&gt;Dear Colleagues,&lt;br&gt;
       6th European Conference on Computer...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Announcing xtractr (on pcapr)>/title>
    >link>http://seclists.org/focus-ids/2010/Feb/1>/link>
    >description>&lt;p&gt;Posted by kowsik on Feb 22&lt;/p&gt;We are happy to announce xtractr, a collaborative cloud app for&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.pcapr.net/&quot;&gt;http://www.pcapr.net/&lt;/a&gt;...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>CFP: Workshop on the Analysis of System Logs>/title>
    >link>http://seclists.org/focus-ids/2010/Feb/0>/link>
    >description>&lt;p&gt;Posted by Kathryn Mohror on Feb 05&lt;/p&gt;        Workshop on the Analysis of System Logs (WASL) 2010&lt;br&gt;
           AUTHOR...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Full Disclosure>/title>
    >link>http://seclists.org/#fulldisclosure>/link>
    >description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.>/description>
  >item>
    >title>[SECURITY] [DSA 2009-1] New tdiary packages fix	cross-site scripting>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/182>/link>
    >description>&lt;p&gt;Posted by Steffen Joeris on Mar 10&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
Problem type...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Vulnerabilities in Hydra Engine>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/181>/link>
    >description>&lt;p&gt;Posted by MustLive on Mar 10&lt;/p&gt;Hello Full-Disclosure!&lt;br&gt;
30.01.2010 - disclosed at my site....&lt;br&gt;>/description>
  >/item>
  >item>
    >title>iDefense Security Advisory 03.09.10: Microsoft Excel MDXTUPLE Record Heap Overflow Vulnerability>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/180>/link>
    >description>&lt;p&gt;Posted by iDefense Labs on Mar 10&lt;/p&gt;iDefense Security Advisory 03.09.10&lt;br&gt;
Corp.'s Excel could allow an attacker to execute...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>iDefense Security Advisory 03.09.10: Microsoft Excel MDXSET Record Heap Overflow Vulnerability>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/179>/link>
    >description>&lt;p&gt;Posted by iDefense Labs on Mar 10&lt;/p&gt;iDefense Security Advisory 03.09.10&lt;br&gt;
Corp.'s Excel could allow an attacker to execute...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>iDefense Security Advisory 03.09.10: Microsoft Excel FNGROUPNAME Record Uninitialized Memory Vulnerability>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/178>/link>
    >description>&lt;p&gt;Posted by iDefense Labs on Mar 09&lt;/p&gt;iDefense Security Advisory 03.09.10&lt;br&gt;
Microsoft Corp.'s Excel could allow an attacker to...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>iDefense Security Advisory 03.09.10: Microsoft Excel Sheet Object Type Confusion Vulnerability>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/177>/link>
    >description>&lt;p&gt;Posted by iDefense Labs on Mar 09&lt;/p&gt;iDefense Security Advisory 03.09.10&lt;br&gt;
Corp.'s Excel could allow an attacker to execute...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Ubisoft DDoS>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/176>/link>
    >description>&lt;p&gt;Posted by Rohit Patnaik on Mar 09&lt;/p&gt;Well, we don't know exactly how the servers were configured.  There might&lt;br&gt;
millions...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Ubisoft DDoS>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/175>/link>
    >description>&lt;p&gt;Posted by Jan Schejbal on Mar 09&lt;/p&gt;Am 09.03.2010 21:11, schrieb James Matthews:&lt;br&gt;
Jan&lt;br&gt;>/description>
  >/item>
  >item>
    >title>CORE-2009-1103: Microsoft Office Excel DbOrParamQry Record Parsing Vulnerability>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/174>/link>
    >description>&lt;p&gt;Posted by CORE Security Technologies Advisories on Mar 09&lt;/p&gt;      Core Security Technologies - CoreLabs Advisory&lt;br&gt;
Vendors contacted: Microsoft...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>CORE-2009-0813: Windows Movie Maker and Microsoft Producer IsValidWMToolsStream() Heap Overflow>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/173>/link>
    >description>&lt;p&gt;Posted by CORE Security Technologies Advisories on Mar 09&lt;/p&gt;      Core Security Technologies - CoreLabs Advisory&lt;br&gt;
Date of last update:...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Ubisoft DDoS>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/172>/link>
    >description>&lt;p&gt;Posted by Christian Sciberras on Mar 09&lt;/p&gt;Perhaps Cisco xt 5650a?&lt;br&gt;
Cheers.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>[ MDVSA-2010:058 ] php>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/171>/link>
    >description>&lt;p&gt;Posted by security on Mar 09&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
           Enterprise Server 5.0...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Ubisoft DDoS>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/170>/link>
    >description>&lt;p&gt;Posted by James Matthews on Mar 09&lt;/p&gt;I don't see why they didn't just block the attack. It must be more then&lt;br&gt;
this.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>ZDI-10-026: Hewlett-Packard OVPI helpmanager Servlet Remote Code Execution Vulnerability>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/169>/link>
    >description>&lt;p&gt;Posted by ZDI Disclosures on Mar 09&lt;/p&gt;ZDI-10-026: Hewlett-Packard OVPI helpmanager Servlet Remote Code Execution Vulnerability&lt;br&gt;
vulnerability by Digital Vaccine protection filter ID...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability>/title>
    >link>http://seclists.org/fulldisclosure/2010/Mar/168>/link>
    >description>&lt;p&gt;Posted by ZDI Disclosures on Mar 09&lt;/p&gt;ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability&lt;br&gt;
required to...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Honeypots>/title>
    >link>http://seclists.org/#honeypots>/link>
    >description>Discussions about tracking attackers by setting up decoy honeypots or entire &lt;A HREF=&quot;http://www.honeynet.org&quot;&gt;honeynet&lt;/A&gt; networks.>/description>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/13>/link>
    >description>&lt;p&gt;Posted by Jason Ross on Mar 03&lt;/p&gt;But it would have the advantage of allowing you to capture further&lt;br&gt;
traffic for analysis through whatever tools you choose.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/12>/link>
    >description>&lt;p&gt;Posted by Alexandre Dulaunoy on Mar 03&lt;/p&gt;We have used various techniques to make DNS honeypots. But there is&lt;br&gt;
information by doing and...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/11>/link>
    >description>&lt;p&gt;Posted by Brent Huston on Mar 03&lt;/p&gt;Likely nothing today, most malware isn't smart enough to figure that out.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/10>/link>
    >description>&lt;p&gt;Posted by Jason Lewis on Mar 03&lt;/p&gt;Slightly related, I was wondering what might happen if I made every&lt;br&gt;
query to the honeypot resolve back to the honeypot?&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/9>/link>
    >description>&lt;p&gt;Posted by Brent Huston on Mar 03&lt;/p&gt;One of the tactics our clients use is that they stand up one of our HoneyPoint Agents on a decoy box and then send all &lt;br&gt;
Let me know if that helps!&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/8>/link>
    >description>&lt;p&gt;Posted by chr1x on Mar 02&lt;/p&gt;This post looks pretty interesting!&lt;br&gt;
open possible...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/7>/link>
    >description>&lt;p&gt;Posted by Jason Lewis on Mar 02&lt;/p&gt;I just figured I'd setup something to log access and see what shows&lt;br&gt;
up.  I wasn't planning on directing traffic to the system.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/6>/link>
    >description>&lt;p&gt;Posted by Jason Lewis on Mar 02&lt;/p&gt;Cool, this is the kind of thing I was thinking of doing.  I was hoping&lt;br&gt;
Thanks.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/5>/link>
    >description>&lt;p&gt;Posted by Jason Ross on Mar 02&lt;/p&gt;There's quite a lot of (bad and good) bots &amp;quot;out there&amp;quot; looking for DNS&lt;br&gt;
will collect a fair amount of queries.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/4>/link>
    >description>&lt;p&gt;Posted by Valdis . Kletnieks on Mar 02&lt;/p&gt;On Tue, 02 Mar 2010 15:00:43 EST, Jason Lewis said:&lt;br&gt;
and hope that works?&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/3>/link>
    >description>&lt;p&gt;Posted by Jason Ross on Mar 02&lt;/p&gt;Below is how I've got BIND set up in Debian Linux for a similar purpose.&lt;br&gt;
Cheers,&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/2>/link>
    >description>&lt;p&gt;Posted by Tillmann Werner on Mar 02&lt;/p&gt;Jason,&lt;br&gt;
Tillmann&lt;br&gt;>/description>
  >/item>
  >item>
    >title>DNS honeypots?>/title>
    >link>http://seclists.org/honeypots/2010/q1/1>/link>
    >description>&lt;p&gt;Posted by Jason Lewis on Mar 02&lt;/p&gt;Anyone have any pointers to dns honeypots or maybe just BIND&lt;br&gt;
actually executing them?&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Honeynet Project Forensic Challenge 2010/2 - browsers under attack>/title>
    >link>http://seclists.org/honeypots/2010/q1/0>/link>
    >description>&lt;p&gt;Posted by christian . seifert on Feb 27&lt;/p&gt;The Honeynet Project has revived an successful program from the past: The Honeynet Project Forensic Challenge 2010. The &lt;br&gt;
individuals and organizations not only learn about threats, but also learn how to...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Incidents>/title>
    >link>http://seclists.org/#incidents>/link>
    >description>Lightly moderated list for dicussing actual security incidents (unexplained probes, breakins, etc).  Topics include information about new rootkits, backdoors, trojans, virii, and worms.>/description>
>/channel>
>/rss>
>rss version="2.0">
>channel>
>title>[ISN] InfoSec News Mailing List>/title>
>link>http://www.infosecnews.org/mailman/listinfo/isn>/link>
>description>InfoSecNews>/description>
>item>
>title>Thailand approves extradition of credit card hack suspect>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018851.html>/link>
>description>InfoSec News: Thailand approves extradition of credit card hack suspect: http://www.theregister.co.uk/2010/03/08/thailand_extradites_hacking_suspect/
Malaysian man suspected of participating in credit card thefts of more  [...]>/description>
>/item>
>item>
>title>RSA: Cybersecurity A Joint Fed, Industry Effort>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018850.html>/link>
>description>InfoSec News: RSA: Cybersecurity A Joint Fed, Industry Effort: http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=223200125
last week, laying out their plans for government cybersecurity,  [...]>/description>
>/item>
>item>
>title>Cybersecurity program has serious defects, GAO says>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018849.html>/link>
>description>InfoSec News: Cybersecurity program has serious defects, GAO says: http://gcn.com/articles/2010/03/08/cnci-assessment-030810.aspx
>/description>
>/item>
>item>
>title>Ford Motor Rolls Out New Security Features To Prevent Car-Hacking>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018848.html>/link>
>description>InfoSec News: Ford Motor Rolls Out New Security Features To Prevent Car-Hacking: http://www.darkreading.com/vulnerability_management/security/client/showArticle.jhtml?articleID=223200163
>/description>
>/item>
>item>
>title>Backdoor found in Energizer Duo USB battery charger>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018847.html>/link>
>description>InfoSec News: Backdoor found in Energizer Duo USB battery charger: http://news.cnet.com/8301-27080_3-10465429-245.html
>/description>
>/item>
>item>
>title>FDIC: Hackers took more than $120M in three months>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018846.html>/link>
>description>InfoSec News: FDIC: Hackers took more than $120M in three months: http://www.computerworld.com/s/article/9167598/FDIC_Hackers_took_more_than_120M_in_three_months?taxonomyId=17
$25 million in the third quarter of 2009, according to the U.S. [...]>/description>
>/item>
>item>
>title>Tokyo's Cyber Emergency Centre at the vanguard of hacking defence>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018845.html>/link>
>description>InfoSec News: Tokyo's Cyber Emergency Centre at the vanguard of hacking defence: http://technology.timesonline.co.uk/tol/news/tech_and_web/article7053320.ece
world keeps a running log of global cyber-attacks. Bloodcurdling names  [...]>/description>
>/item>
>item>
>title>The Corporate Side of Snooping>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018844.html>/link>
>description>InfoSec News: The Corporate Side of Snooping: http://www.nytimes.com/2010/03/07/business/07shelf.html
are constantly being spun by the same gang of politicians and lobbyists  [...]>/description>
>/item>
>item>
>title>Microsoft's tax-for-hacks 'horrible' idea, say security experts>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018843.html>/link>
>description>InfoSec News: Microsoft's tax-for-hacks 'horrible' idea, say security experts: http://www.computerworld.com/s/article/9166458/Microsoft_s_tax_for_hacks_horrible_idea_say_security_experts?taxonomyId=17
>/description>
>/item>
>item>
>title>Facebook founder Mark Zuckerberg 'hacked into emails of rivals and journalists'>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018842.html>/link>
>description>InfoSec News: Facebook founder Mark Zuckerberg 'hacked into emails of rivals and journalists': http://www.dailymail.co.uk/news/worldnews/article-1255888/Facebook-founder-Mark-Zuckerberg-hacked-emails-rivals-journalists.html
email accounts of rivals and journalists. [...]>/description>
>/item>
>item>
>title>Westin Bonaventure Los Angeles latest victim of hotel hackers>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018841.html>/link>
>description>InfoSec News: Westin Bonaventure Los Angeles latest victim of hotel hackers: http://content.usatoday.com/communities/hotelcheckin/post/2010/03/hackers-breach-westin-bonaventure-los-angeles-networks-cybercriminal/1
You may have to monitor your credit card statements - and even place a  [...]>/description>
>/item>
>item>
>title>Linux Advisory Watch: March 6th, 2010>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018840.html>/link>
>description>InfoSec News: Linux Advisory Watch: March 6th, 2010: +----------------------------------------------------------------------+
|                                                                      | [...]>/description>
>/item>
>item>
>title>At RSA, Some Security Pros Don't Practice What They Preach>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018839.html>/link>
>description>InfoSec News: At RSA, Some Security Pros Don't Practice What They Preach: http://www.darkreading.com/vulnerability_management/security/encryption/showArticle.jhtml?articleID=223101624
wireless users at one of the industry's biggest security conferences  [...]>/description>
>/item>
>item>
>title>Iowa Homeland Security Web site "compromised">/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018838.html>/link>
>description>InfoSec News: Iowa Homeland Security Web site "compromised": http://www.desmoinesregister.com/article/20100304/NEWS/100304002/1001/Iowa-Homeland-Security-Web-site-compromised
has been &amp;quot;compromised,&amp;quot; a state official said today. [...]>/description>
>/item>
>item>
>title>Nation's cybersecurity suffers from a lack of information sharing>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018837.html>/link>
>description>InfoSec News: Nation's cybersecurity suffers from a lack of information sharing: Forwarded from: Richard Forno &amp;lt;rforno (at) infowarrior.org&amp;gt;
>/description>
>/item>
>item>
>title>New BlackEnergy Trojan Targeting Russian, Ukrainian Banks>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018836.html>/link>
>description>InfoSec News: New BlackEnergy Trojan Targeting Russian, Ukrainian Banks: http://www.darkreading.com/security/vulnerabilities/showArticle.jhtml?articleID=223101487
more sophisticated version of the infamous BlackEnergy Trojan associated  [...]>/description>
>/item>
>item>
>title>White House Cyber Czar: 'There Is No Cyberwar'>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018835.html>/link>
>description>InfoSec News: White House Cyber Czar: 'There Is No Cyberwar': http://www.wired.com/threatlevel/2010/03/schmidt-cyberwar/
has a short answer for the drumbeat of rhetoric claiming the United  [...]>/description>
>/item>
>item>
>title>Heartland Aftershocks: Still at Risk?>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018834.html>/link>
>description>InfoSec News: Heartland Aftershocks: Still at Risk?: http://www.bankinfosecurity.com/articles.php?art_id=2264
reveal that as many as 5,000 of its customers were at risk because of  [...]>/description>
>/item>
>item>
>title>Secunia Weekly Summary - Issue: 2010-09>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018833.html>/link>
>description>InfoSec News: Secunia Weekly Summary - Issue: 2010-09: ========================================================================
 [...]>/description>
>/item>
>item>
>title>FBI Director: Hackers have corrupted valuable data>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018832.html>/link>
>description>InfoSec News: FBI Director: Hackers have corrupted valuable data: http://www.computerworld.com/s/article/9166378/FBI_Director_Hackers_have_corrupted_valuable_data?taxonomyId=17
>/description>
>/item>
>item>
>title>'Severe' OpenSSL vuln busts public key crypto>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018831.html>/link>
>description>InfoSec News: 'Severe' OpenSSL vuln busts public key crypto: http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/
the world's most widely used software encryption package that allows  [...]>/description>
>/item>
>item>
>title>Heartland Breach: Colorado Bank Reports New Fraud>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018830.html>/link>
>description>InfoSec News: Heartland Breach: Colorado Bank Reports New Fraud: http://www.bankinfosecurity.com/articles.php?art_id=2259
customers were at risk because of new fraudulent transactions tied to  [...]>/description>
>/item>
>item>
>title>Shands notifies 12,500 patients that data at risk>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018829.html>/link>
>description>InfoSec News: Shands notifies 12,500 patients that data at risk: http://www.gainesville.com/article/20100302/ARTICLES/3021003/1002
containing their medical information was stolen in January. [...]>/description>
>/item>
>item>
>title>Nation's cybersecurity suffers from a lack of information sharing>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018828.html>/link>
>description>InfoSec News: Nation's cybersecurity suffers from a lack of information sharing: http://fcw.com/articles/2010/03/03/cybersecurity-policy.aspx
>/description>
>/item>
>item>
>title>Tracing attack source key to cybersecurity strategy, Chertoff says>/title>
>link>http://www.infosecnews.org/pipermail/isn/2010-March/018827.html>/link>
>description>InfoSec News: Tracing attack source key to cybersecurity strategy, Chertoff says: http://www.computerworld.com/s/article/9165638/Tracing_attack_source_key_to_cybersecurity_strategy_Chertoff_says?taxonomyId=17
>/description>
>/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>MS Sec Notification>/title>
    >link>http://seclists.org/#microsoft>/link>
    >description>Beware that MS often uses these security bulletins as marketing propaganda to downplay serious vulnerabilities in their products -- note how most have a prominent and often-misleading &quot;mitigating factors&quot; section.>/description>
  >item>
    >title>Microsoft Security Bulletin Major Revisions>/title>
    >link>http://seclists.org/microsoft/2010/q1/6>/link>
    >description>&lt;p&gt;Posted by Microsoft on Mar 09&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Summary for March 2010>/title>
    >link>http://seclists.org/microsoft/2010/q1/5>/link>
    >description>&lt;p&gt;Posted by Microsoft on Mar 09&lt;/p&gt;********************************************************************&lt;br&gt;
With...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Summary for February 2010>/title>
    >link>http://seclists.org/microsoft/2010/q1/4>/link>
    >description>&lt;p&gt;Posted by Microsoft on Feb 09&lt;/p&gt;********************************************************************&lt;br&gt;
February 2010 can be found at...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Summary for January 2010>/title>
    >link>http://seclists.org/microsoft/2010/q1/3>/link>
    >description>&lt;p&gt;Posted by Microsoft on Jan 21&lt;/p&gt;********************************************************************&lt;br&gt;
January 2010 can be found at...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Major Revision>/title>
    >link>http://seclists.org/microsoft/2010/q1/2>/link>
    >description>&lt;p&gt;Posted by Microsoft on Jan 14&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Summary for January 2010>/title>
    >link>http://seclists.org/microsoft/2010/q1/1>/link>
    >description>&lt;p&gt;Posted by Microsoft on Jan 12&lt;/p&gt;********************************************************************&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx&quot;&gt;http://www.microsoft.com/technet/security/bulletin/ms10-jan.mspx&lt;/a&gt;....&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Re-Release>/title>
    >link>http://seclists.org/microsoft/2010/q1/0>/link>
    >description>&lt;p&gt;Posted by Microsoft on Jan 12&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Major Revisions>/title>
    >link>http://seclists.org/microsoft/2009/q4/9>/link>
    >description>&lt;p&gt;Posted by Microsoft on Dec 08&lt;/p&gt;********************************************************************&lt;br&gt;
* MS08-037 - Important...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Summary for December 2009>/title>
    >link>http://seclists.org/microsoft/2009/q4/8>/link>
    >description>&lt;p&gt;Posted by Microsoft on Dec 08&lt;/p&gt;********************************************************************&lt;br&gt;
December 2009 can be found at...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Major Revisions>/title>
    >link>http://seclists.org/microsoft/2009/q4/7>/link>
    >description>&lt;p&gt;Posted by Microsoft on Nov 24&lt;/p&gt;********************************************************************&lt;br&gt;
* MS08-076 - Important...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Major Revisions>/title>
    >link>http://seclists.org/microsoft/2009/q4/6>/link>
    >description>&lt;p&gt;Posted by Microsoft on Nov 10&lt;/p&gt;********************************************************************&lt;br&gt;
*...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Summary for November 2009>/title>
    >link>http://seclists.org/microsoft/2009/q4/5>/link>
    >description>&lt;p&gt;Posted by Microsoft on Nov 10&lt;/p&gt;********************************************************************&lt;br&gt;
November 2009 can be found at...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Advance Notification for November 2009>/title>
    >link>http://seclists.org/microsoft/2009/q4/4>/link>
    >description>&lt;p&gt;Posted by Microsoft on Nov 05&lt;/p&gt;********************************************************************&lt;br&gt;
Notification for November 2009 can be found...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Major Revisions>/title>
    >link>http://seclists.org/microsoft/2009/q4/3>/link>
    >description>&lt;p&gt;Posted by Microsoft on Nov 03&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Microsoft Security Bulletin Major Revisions>/title>
    >link>http://seclists.org/microsoft/2009/q4/2>/link>
    >description>&lt;p&gt;Posted by Microsoft on Oct 28&lt;/p&gt;********************************************************************&lt;br&gt;
 -...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
                 >title>NANOG@merit.edu>/title>
                >link>http://www.merit.edu/mail.archives/nanog/index.html>/link>
                >description>Latest posts to NANOG Mailing List>/description>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06295.html>/link>
		>description>Gregory Hicks (03/10/10)>/description>
	>/item>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06294.html>/link>
		>description>Mikael Abrahamsson (03/10/10)>/description>
	>/item>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06293.html>/link>
		>description>David Conrad (03/10/10)>/description>
	>/item>
	>item>
		>title>RE: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06292.html>/link>
		>description>Arjan van der Oest (03/10/10)>/description>
	>/item>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06291.html>/link>
		>description>Paul Ferguson (03/10/10)>/description>
	>/item>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06290.html>/link>
		>description>David Conrad (03/10/10)>/description>
	>/item>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06289.html>/link>
		>description>Robert Enger - NANOG (03/10/10)>/description>
	>/item>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06288.html>/link>
		>description>Mark (03/10/10)>/description>
	>/item>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06287.html>/link>
		>description>Rubens Kuhl (03/10/10)>/description>
	>/item>
	>item>
		>title>Re: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06286.html>/link>
		>description>Mikael Abrahamsson (03/10/10)>/description>
	>/item>
	>item>
		>title>RE: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06285.html>/link>
		>description>Crooks, Sam (03/09/10)>/description>
	>/item>
	>item>
		>title>Re: T1 aggregation and data center gatew>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06284.html>/link>
		>description>Larry Sheldon (03/09/10)>/description>
	>/item>
	>item>
		>title>Re: T1 aggregation and data center gatew>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06283.html>/link>
		>description>Michael K. Smith (03/09/10)>/description>
	>/item>
	>item>
		>title>Re: T1 aggregation and data center gatew>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06282.html>/link>
		>description>John Peach (03/09/10)>/description>
	>/item>
	>item>
		>title>RE: CRS-3>/title>
		>link>http://www.merit.edu/mail.archives/nanog/msg06281.html>/link>
		>description>George Bonser (03/09/10)>/description>
	>/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
                 >title>netsec@merit.edu>/title>
                >link>http://www.merit.edu/mail.archives/netsec/index.html>/link>
                >description>Latest posts to netsec mailing list>/description>
	>item>
		>title>SANS NewsBites Vol. 12 Num. 19 : $120 Mi>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03525.html>/link>
		>description>The SANS Institute (03/09/10)>/description>
	>/item>
	>item>
		>title>FW: [ISN] FDIC: Hackers took more than $>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03524.html>/link>
		>description>Howell, Paul (03/09/10)>/description>
	>/item>
	>item>
		>title>HTC Phones Pre-installed With Mariposa B>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03523.html>/link>
		>description>Howell, Paul (03/09/10)>/description>
	>/item>
	>item>
		>title>Ford Motor Rolls Out New Security Featur>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03522.html>/link>
		>description>Howell, Paul (03/09/10)>/description>
	>/item>
	>item>
		>title>What's in a Name?>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03521.html>/link>
		>description>Howell, Paul (03/09/10)>/description>
	>/item>
	>item>
		>title>FW: US-CERT Cyber Security Bulletin SB10>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03520.html>/link>
		>description>Howell, Paul (03/08/10)>/description>
	>/item>
	>item>
		>title>SANS NewsBites Vol. 12 Num. 18 : Source>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03519.html>/link>
		>description>The SANS Institute (03/05/10)>/description>
	>/item>
	>item>
		>title>The Myth of iPhone App Piracy>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03518.html>/link>
		>description>Howell, Paul (03/03/10)>/description>
	>/item>
	>item>
		>title>The Comprehensive National Cybersecurity>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03517.html>/link>
		>description>Howell, Paul (03/03/10)>/description>
	>/item>
	>item>
		>title>SANS NewsBites Vol. 12 Num. 17 : Obama A>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03516.html>/link>
		>description>The SANS Institute (03/02/10)>/description>
	>/item>
	>item>
		>title>Microsoft Windows 7/Vista Advanced Foren>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03515.html>/link>
		>description>Howell, Paul (03/02/10)>/description>
	>/item>
	>item>
		>title>Good Practices Guide for Deploying DNSSE>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03514.html>/link>
		>description>Howell, Paul (03/02/10)>/description>
	>/item>
	>item>
		>title>FW: US-CERT Cyber Security Bulletin SB10>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03513.html>/link>
		>description>Howell, Paul (03/02/10)>/description>
	>/item>
	>item>
		>title>FW: [ISN] United Airlines Caught in Twit>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03512.html>/link>
		>description>Howell, Paul (02/28/10)>/description>
	>/item>
	>item>
		>title>SANS NewsBites Vol. 12 Num. 16 : State o>/title>
		>link>http://www.merit.edu/mail.archives/netsec/msg03511.html>/link>
		>description>The SANS Institute (02/26/10)>/description>
	>/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
  >title>      SANS ISC SecNewsFeed>/title>
  >link>       http://isc.sans.org>/link>
  >description>>![CDATA[]]>>/description>
             >image>
               >title>SANS ISC SecNewsFeed>/title>
               >url>http://isc.sans.org/images/status.gif>/url>
               >link>http://isc.sans.org>/link>
             >/image>
  >item>
    >title>Update for Apache 2.2 web server closes various security holes (Heise Security News)>/title>
    >link>http://rss.feedsportal.com/c/32569/f/491736/s/96d2e1a/l/0L0Sh0Eonline0N0Csecurity0Cnews0Citem0CUpdate0Efor0EApache0E20E20Eweb0Eserver0Ecloses0Evarious0Esecurity0Eholes0E949780A0Bhtml0Cfrom0Crss/story01.htm>/link>
  >/item>
  >item>
    >title>Travelers file complaints over TSA body scanners (NetworkWorld Security)>/title>
    >link>http://www.networkworld.com/news/2010/030910-travelers-file-complaints-over-tsa.html>/link>
  >/item>
  >item>
    >title>Vodafone ships Mariposa-infected HTC Magic (The Register)>/title>
    >link>http://go.theregister.com/feed/www.theregister.co.uk/2010/03/09/vodafone_mariposa/>/link>
  >/item>
  >item>
    >title>Energizer Malware, (Tue, Mar 9th) (InternetStormCenter)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8386&amp;rss>/link>
  >/item>
  >item>
    >title>CVE-2010-0433 (openssl) (Natl. Vulnerability Database)>/title>
    >link>http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2010-0433>/link>
  >/item>
  >item>
    >title>Vuln: TYPO3 Core Multiple Remote Security Vulnerabilities (SecurityFocus Vulnerabilities)>/title>
    >link>http://www.securityfocus.com/bid/38366>/link>
  >/item>
  >item>
    >title>Panda Discovers Malware on HTC Magic Phone     (PC World) (Yahoo Security)>/title>
    >link>http://us.rd.yahoo.com/dailynews/rss/security/*http://news.yahoo.com/s/pcworld/20100309/tc_pcworld/pandadiscoversmalwareonhtcmagicphone>/link>
  >/item>
  >item>
    >title>SA10-068A: Microsoft Updates for Multiple Vulnerabilities (US-Cert Alerts)>/title>
    >link>http://www.us-cert.gov/cas/alerts/SA10-068A.html>/link>
  >/item>
  >item>
    >title>TA10-068A: Microsoft Updates for Multiple Vulnerabilities (US-CERT Techalerts)>/title>
    >link>http://www.us-cert.gov/cas/techalerts/TA10-068A.html>/link>
  >/item>
  >item>
    >title>Guide to Microsoft Police Forensic Services (Schneier blog)>/title>
    >link>http://www.schneier.com/blog/archives/2010/03/guide_to_micros.html>/link>
  >/item>
  >item>
    >title>MS10-017 - Important: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150) (Microsoft)>/title>
    >link>http://www.microsoft.com/technet/security/bulletin/ms10-017.mspx?pubDate=2010-03-09>/link>
  >/item>
  >item>
    >title>Identifying Load Balancers in Penetration Testing (SANS Reading Room)>/title>
    >link>http://www.sans.org/reading_room/whitepapers/testing/rss/identifying_load_balancers_in_penetration_testing_33313>/link>
  >/item>
  >item>
    >title>Botnets, malware and capturing cybercriminals (SearchSecurity.com) (Yahoo News)>/title>
    >link>http://us.rd.yahoo.com/dailynews/rss/search/%22Internet+Storm+Center%22/SIG=12srf5fl4/*http%3A//searchsecurity.techtarget.com/video/0,297151,sid14_gci1415235,00.html?track=sy160>/link>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
>title>SecurityFocus News>/title>
>link>http://www.securityfocus.com>/link>
>description>
>/description>
>image> 
>title>SecurityFocus>/title> 
>url>http://www.securityfocus.com/rss/SFLogo_v1.gif>/url> 
>link>http://www.securityfocus.com>/link> 
>/image>
>item>
>title>News: Twitter attacker had proper credentials>/title>
>link>http://www.securityfocus.com/news/11569?ref=rss>/link>
>description>Twitter attacker had proper credentials>/description>
>/item>
>item>
>title>News: PhotoDNA scans images for child abuse>/title>
>link>http://www.securityfocus.com/news/11570?ref=rss>/link>
>description>PhotoDNA scans images for child abuse>/description>
>/item>
>item>
>title>News: Conficker data highlights infected networks>/title>
>link>http://www.securityfocus.com/news/11568?ref=rss>/link>
>description>>![CDATA[ Conficker data highlights infected networks>br/>>br/>
]]>>/description>
>/item>
>item>
>title>News: Popular apps need better patching, says report>/title>
>link>http://www.securityfocus.com/news/11560?ref=rss>/link>
>description>Popular apps need better patching, says report>/description>
>/item>
>item>
>title>Brief: Google offers bounty on browser bugs>/title>
>link>http://www.securityfocus.com/brief/1067?ref=rss>/link>
>description>Google offers bounty on browser bugs>/description>
>/item>
>item>
>title>Brief: Cyberattacks from U.S. &quot;greatest concern&quot;>/title>
>link>http://www.securityfocus.com/brief/1066?ref=rss>/link>
>description>>![CDATA[ Cyberattacks from U.S. &quot;greatest concern&quot;>br/>>br/>
]]>>/description>
>/item>
>item>
>title>Brief: Microsoft patches as fraudsters target IE flaw>/title>
>link>http://www.securityfocus.com/brief/1065?ref=rss>/link>
>description>Microsoft patches as fraudsters target IE flaw>/description>
>/item>
>item>
>title>Brief: Attack on IE 0-day refined by researchers>/title>
>link>http://www.securityfocus.com/brief/1064?ref=rss>/link>
>description>Attack on IE 0-day refined by researchers>/description>
>/item>
>item>
>title>News: Monster botnet held 800,000 people's details>/title>
>link>http://www.securityfocus.com/news/11580?ref=rss>/link>
>description>>![CDATA[ Monster botnet held 800,000 people's details>br/>>br/>
]]>>/description>
>/item>
>item>
>title>News: Google: 'no timetable' on China talks>/title>
>link>http://www.securityfocus.com/news/11581?ref=rss>/link>
>description>Google: 'no timetable' on China talks>/description>
>/item>
>item>
>title>News: Latvian hacker tweets hard on banking whistle>/title>
>link>http://www.securityfocus.com/news/11577?ref=rss>/link>
>description>Latvian hacker tweets hard on banking whistle>/description>
>/item>
>item>
>title>News: MS uses court order to take out Waledac botnet>/title>
>link>http://www.securityfocus.com/news/11578?ref=rss>/link>
>description>>![CDATA[ MS uses court order to take out Waledac botnet>br/>>br/>
]]>>/description>
>/item>
>item>
>title>Infocus: Enterprise Intrusion Analysis, Part One>/title>
>link>http://www.securityfocus.com/infocus/1904?ref=rss>/link>
>description>Enterprise Intrusion Analysis, Part One>/description>
>/item>
>item>
>title>Infocus: Responding to a Brute Force SSH Attack>/title>
>link>http://www.securityfocus.com/infocus/1903?ref=rss>/link>
>description>Responding to a Brute Force SSH Attack>/description>
>/item>
>item>
>title>Infocus: Data Recovery on Linux and &lt;i&gt;ext3&lt;/i&gt;>/title>
>link>http://www.securityfocus.com/infocus/1902?ref=rss>/link>
>description>>![CDATA[ Data Recovery on Linux and &lt;i&gt;ext3&lt;/i&gt;>br/>>br/>
]]>>/description>
>/item>
>item>
>title>Infocus: WiMax: Just Another Security Challenge?>/title>
>link>http://www.securityfocus.com/infocus/1901?ref=rss>/link>
>description>WiMax: Just Another Security Challenge?>/description>
>/item>
>item>
>title>Gunter Ollmann: Time to Squish SQL Injection>/title>
>link>http://www.securityfocus.com/columnists/505?ref=rss>/link>
>description>Time to Squish SQL Injection>/description>
>/item>
>item>
>title>Mark Rasch: Lazy Workers May Be Deemed Hackers>/title>
>link>http://www.securityfocus.com/columnists/504?ref=rss>/link>
>description>>![CDATA[ Lazy Workers May Be Deemed Hackers>br/>>br/>
]]>>/description>
>/item>
>item>
>title>Adam O'Donnell: The Scale of Security>/title>
>link>http://www.securityfocus.com/columnists/503?ref=rss>/link>
>description>The Scale of Security>/description>
>/item>
>item>
>title>Mark Rasch: Hacker-Tool Law Still Does Little>/title>
>link>http://www.securityfocus.com/columnists/502?ref=rss>/link>
>description>Hacker-Tool Law Still Does Little>/description>
>/item>
>item>
>title>More rss feeds from SecurityFocus>/title>
>link>http://www.securityfocus.com/rss/index.shtml>/link>
>description>News, Infocus, Columns, Vulnerabilities, Bugtraq ...>/description>
>/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Nmap Development>/title>
    >link>http://seclists.org/#nmap-dev>/link>
    >description>Unmoderated technical development forum for debating ideas, patches, and suggestions regarding proposed changes to &lt;A HREF=&quot;http://nmap.org&quot;&gt;Nmap&lt;/A&gt; and related projects.>/description>
  >item>
    >title>Re: zenmap doesn't scan my user mode linux image>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/842>/link>
    >description>&lt;p&gt;Posted by Toralf Förster on Mar 10&lt;/p&gt;David Fifield wrote at 17:41:12&lt;br&gt;
the protocols of sendmail, courier, apache, cups and friends).&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: More nsock socket_count_write_dec assert() failures>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/841>/link>
    >description>&lt;p&gt;Posted by David Fifield on Mar 09&lt;/p&gt;I worked off-list with Brandon on this problem, and I think we have it&lt;br&gt;
However, when handle_write_result was called agains as a result of...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: NMAP XML output too verbose>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/840>/link>
    >description>&lt;p&gt;Posted by Duarte Silva on Mar 09&lt;/p&gt;Knowing that I'm fairly new in the area of contributing to nmap, but&lt;br&gt;
The problem of XML having hosts that...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: NMAP XML output too verbose>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/839>/link>
    >description>&lt;p&gt;Posted by Ron on Mar 09&lt;/p&gt;One of the most common questions we see in #nmap on Freenode is, &amp;quot;how an I find every host with port xx open?&amp;quot; -- I &lt;br&gt;
think your proposed modification to --open will make that a far easier question to answer. Sounds good to me!&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: New Nmap options for IDS interaction>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/838>/link>
    >description>&lt;p&gt;Posted by Theo Dzierzbicki on Mar 09&lt;/p&gt;Hello again,&lt;br&gt;
the sendOK() function. This function happens to be a different...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: NMAP XML output too verbose>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/837>/link>
    >description>&lt;p&gt;Posted by Fyodor on Mar 09&lt;/p&gt;Hi Kevin.  I talked this over with David Fifield today and we have a&lt;br&gt;
normally read the XML...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: a few usability problems and how to scan very fast a large network>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/836>/link>
    >description>&lt;p&gt;Posted by Farkas Levente on Mar 09&lt;/p&gt;local arp table usually don't contains all apr info on the lan:-(&lt;br&gt;
Nmap done: 65536 IP addresses...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: a few usability problems and how to scan very fast a large network>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/835>/link>
    >description>&lt;p&gt;Posted by Brandon Enright on Mar 09&lt;/p&gt;The best way would be to look at your ARP tables.  With Nmap though,&lt;br&gt;
Well if you tell Nmap to scan an IP and it...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>RE: [BULK]  Re: new Win install fails beyond localhost>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/834>/link>
    >description>&lt;p&gt;Posted by Norris Carden on Mar 09&lt;/p&gt;BTW, the same install package is working fine on my XP desktop.&lt;br&gt;
--------------- Timing report...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: new Win install fails beyond localhost>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/833>/link>
    >description>&lt;p&gt;Posted by David Fifield on Mar 09&lt;/p&gt;Thanks, can you also do&lt;br&gt;
David Fifield&lt;br&gt;>/description>
  >/item>
  >item>
    >title>RE: new Win install fails beyond localhost>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/832>/link>
    >description>&lt;p&gt;Posted by Norris Carden on Mar 09&lt;/p&gt;Results as requested... thanks for pointing out these options.. &lt;br&gt;
lo0...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>a few usability problems and how to scan very fast a large network>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/831>/link>
    >description>&lt;p&gt;Posted by Farkas Levente on Mar 09&lt;/p&gt;hi,&lt;br&gt;
- normal output is not very easy to parse....&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: zenmap doesn't scan my user mode linux image>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/830>/link>
    >description>&lt;p&gt;Posted by David Fifield on Mar 09&lt;/p&gt;It would be very helpful if you could retest with version 5.00 to&lt;br&gt;
David Fifield&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: new Win install fails beyond localhost>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/829>/link>
    >description>&lt;p&gt;Posted by David Fifield on Mar 09&lt;/p&gt;Can you scan hosts outside your local network, like scanme.nmap.org?&lt;br&gt;
David Fifield&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: zenmap doesn't scan my user mode linux image>/title>
    >link>http://seclists.org/nmap-dev/2010/q1/828>/link>
    >description>&lt;p&gt;Posted by Toralf Förster on Mar 09&lt;/p&gt;David Fifield wrote at 18:49:00&lt;br&gt;
Starting Nmap 5.21 (...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Nmap Hackers>/title>
    >link>http://seclists.org/#nmap-hackers>/link>
    >description>Moderated list for the most important new releases and announcements regarding the &lt;A HREF=&quot;http://nmap.org&quot;&gt;Nmap Security Scanner&lt;/A&gt; and related projects. We recommend that all Nmap users &lt;a href=&quot;http://cgi.insecure.org/mailman/listinfo/nmap-hackers&quot;&gt;subscribe&lt;/a&gt;.>/description>
  >item>
    >title>Nmap 5.21 released>/title>
    >link>http://seclists.org/nmap-hackers/2010/2>/link>
    >description>&lt;p&gt;Posted by Fyodor on Jan 27&lt;/p&gt;Hello everyone.  I'm pleased to release Nmap 5.21, which contains zero&lt;br&gt;
development projects.  If you want to know...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Lots of Nmap News>/title>
    >link>http://seclists.org/nmap-hackers/2010/1>/link>
    >description>&lt;p&gt;Posted by Fyodor on Jan 22&lt;/p&gt;Hi folks.  I'm happy to report that the 5.20 release went well.  But&lt;br&gt;
If you're running from a build of the latest SVN checkout, you...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Nmap 5.20 Released>/title>
    >link>http://seclists.org/nmap-hackers/2010/0>/link>
    >description>&lt;p&gt;Posted by Fyodor on Jan 20&lt;/p&gt;Happy new year, everyone.  I'm happy to announce Nmap 5.20--our first&lt;br&gt;
The...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Nmap 5.00 Released!>/title>
    >link>http://seclists.org/nmap-hackers/2009/3>/link>
    >description>&lt;p&gt;Posted by Fyodor on Jul 16&lt;/p&gt;Hello everyone.  I'm delighted to announce the release of Nmap 5.00!&lt;br&gt;
1) The new Ncat tool aims to be your Swiss Army Knife...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Nmap news: stable release candidate 4.90RC1, SoC team,	and new translations>/title>
    >link>http://seclists.org/nmap-hackers/2009/2>/link>
    >description>&lt;p&gt;Posted by Fyodor on Jun 26&lt;/p&gt;Hi Folks.  I'm pleased to announce some exciting Nmap news:&lt;br&gt;
Please test it out, and let us know if you find any problems...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Nmap 4.85BETA6 now avail w/Conficker detection>/title>
    >link>http://seclists.org/nmap-hackers/2009/1>/link>
    >description>&lt;p&gt;Posted by Fyodor on Apr 01&lt;/p&gt;Hi Folks!  In case you missed all the news reports yesterday, a couple&lt;br&gt;
millions of infections, and this massive botnet...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Nmap News: 4.84BETA4 release, Nmap book news, Summer of Code, Twitter,	etc.>/title>
    >link>http://seclists.org/nmap-hackers/2009/0>/link>
    >description>&lt;p&gt;Posted by Fyodor on Mar 27&lt;/p&gt;Hello everyone.  We've seen 848 messages on nmap-dev this year, but&lt;br&gt;
4.85BETA4 release,...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Penetration Testing>/title>
    >link>http://seclists.org/#pen-test>/link>
    >description>While this list is intended for &quot;professionals&quot;, participants frequenly disclose techniques and strategies that would be useful to anyone with a practical interest in security and network auditing.>/description>
  >item>
    >title>Re: Case studies books>/title>
    >link>http://seclists.org/pen-test/2010/Mar/45>/link>
    >description>&lt;p&gt;Posted by David Glosser on Mar 09&lt;/p&gt;not a book, no idea how real, but  fun to watch&lt;br&gt;
and CEPT certs require a full practical examination in order to become...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Evaluating pentesters>/title>
    >link>http://seclists.org/pen-test/2010/Mar/44>/link>
    >description>&lt;p&gt;Posted by Shohn Trojacek on Mar 09&lt;/p&gt;Tony,&lt;br&gt;
actual response at...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Professional Scrpt Kiddies vs Real Talent>/title>
    >link>http://seclists.org/pen-test/2010/Mar/43>/link>
    >description>&lt;p&gt;Posted by Omar Herrera on Mar 09&lt;/p&gt;Hi Adriel,&lt;br&gt;
We got scientists and experts that claim to know the...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Evaluating pentesters>/title>
    >link>http://seclists.org/pen-test/2010/Mar/42>/link>
    >description>&lt;p&gt;Posted by Jason Ross on Mar 09&lt;/p&gt;In theory, there is; see &lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityscoreboard.com&quot;&gt;http://securityscoreboard.com&lt;/a&gt;&lt;br&gt;
a helpful resource IMO. Specifically, it provides a very nice...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Evaluating pentesters>/title>
    >link>http://seclists.org/pen-test/2010/Mar/41>/link>
    >description>&lt;p&gt;Posted by aceinyaface on Mar 09&lt;/p&gt;Hey Tony,&lt;br&gt;
Prove to peers and potential employers without a doubt that...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Professional Scrpt Kiddies vs Real Talent>/title>
    >link>http://seclists.org/pen-test/2010/Mar/40>/link>
    >description>&lt;p&gt;Posted by Vikram Dhillon on Mar 09&lt;/p&gt;Thanks for that awesome email, I suppose you are right that in most cases the script kiddies are just being an &lt;br&gt;
advent of linux however, things have changed a lot, the code is open so its harder to make it...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Professional Scrpt Kiddies vs Real Talent>/title>
    >link>http://seclists.org/pen-test/2010/Mar/39>/link>
    >description>&lt;p&gt;Posted by Adriel T. Desautels on Mar 09&lt;/p&gt;Comments embedded below:&lt;br&gt;
What does...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Professional Scrpt Kiddies vs Real Talent>/title>
    >link>http://seclists.org/pen-test/2010/Mar/38>/link>
    >description>&lt;p&gt;Posted by Adriel T. Desautels on Mar 09&lt;/p&gt;Hi Wim, my comments are embedded below.&lt;br&gt;
I love HD, so do the people on our team, but I'm not sure that I'd go so far as...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: proposed pen-test>/title>
    >link>http://seclists.org/pen-test/2010/Mar/37>/link>
    >description>&lt;p&gt;Posted by Shohn Trojacek on Mar 08&lt;/p&gt;I haven't thought this very far through, but wanted to comment that&lt;br&gt;
I'd probably spend...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Professional Scrpt Kiddies vs Real Talent>/title>
    >link>http://seclists.org/pen-test/2010/Mar/36>/link>
    >description>&lt;p&gt;Posted by Wim Remes on Mar 08&lt;/p&gt;while I understand what triggered this post and/or e-mail, it is barely scratching the surface.  Infosec is so much &lt;br&gt;
very open and interactive community (no, not by stepping in the...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: proposed pen-test>/title>
    >link>http://seclists.org/pen-test/2010/Mar/35>/link>
    >description>&lt;p&gt;Posted by Terry Cutler on Mar 08&lt;/p&gt;Hey John, I'm actually reproducing the Hack that was done on Google&lt;br&gt;
Linkedin invitations....&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Evaluating pentesters>/title>
    >link>http://seclists.org/pen-test/2010/Mar/34>/link>
    >description>&lt;p&gt;Posted by Andre Gironda on Mar 08&lt;/p&gt;Is there some kind of capital planning, budgeting, or decision-making&lt;br&gt;
Ok....&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Evaluating pentesters>/title>
    >link>http://seclists.org/pen-test/2010/Mar/33>/link>
    >description>&lt;p&gt;Posted by David Glosser on Mar 08&lt;/p&gt;I would assume that a PCI  Approved Scanning Vendor (ASV) would also&lt;br&gt;
Prove to...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: proposed pen-test>/title>
    >link>http://seclists.org/pen-test/2010/Mar/32>/link>
    >description>&lt;p&gt;Posted by krymson on Mar 08&lt;/p&gt;If you have access to the mailboxes of the department, could you just slip them in with some prepared wear-and-tear on &lt;br&gt;
out, or give them to a student or friend or...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Evaluating pentesters>/title>
    >link>http://seclists.org/pen-test/2010/Mar/31>/link>
    >description>&lt;p&gt;Posted by Tracy Reed on Mar 08&lt;/p&gt;On Fri, Mar 05, 2010 at 07:01:33PM -0500, Tony Turner spake thusly:&lt;br&gt;
merchants who...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
  >title>digg.com: Stories / Popular>/title>
  >description>digg.com: Stories / Popular>/description>
  >link>http://digg.com/>/link>
   >title>You can't hurry love...>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/4QUJKWtSqWg/You_can_t_hurry_love_2>/link>
   >description>You can't hurry love. No, you'll just have to wait. Just trust in a good time. No matter how long it takes. by Phil Collins
&lt;a href="http://feedads.g.doubleclick.net/~at/R6Mhp_C-nFeKJatJ7d2JV2wbSAU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/R6Mhp_C-nFeKJatJ7d2JV2wbSAU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/4QUJKWtSqWg" height="1" width="1"/&gt;>/description>
  >item>
   >title>Science Trips Out on Music in The Heart Is a Drum Machine>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/beYetHzMg70/Science_Trips_Out_on_Music_in_The_Heart_Is_a_Drum_Machine>/link>
   >description>What is music? It’s a simple question, but it leads director Christopher Pomerenke in many complicated artistic and scientific directions in his documentary The Heart Is a Drum Machine, out Tuesday on DVD.
&lt;a href="http://feedads.g.doubleclick.net/~at/LYbiKVB8A1PqmyzAg5Tldh60nqQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/LYbiKVB8A1PqmyzAg5Tldh60nqQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/beYetHzMg70" height="1" width="1"/&gt;>/description>
  >item>
   >title>10 Forgotten Hollywood Stars who are Still Sexy>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/dGnrQ1y20jI/10_Forgotten_Hollywood_Stars_who_are_Still_Sexy>/link>
   >description>Not only does the young brigade add to the sex appeal in the movie arena, there is a long list of forgotten Hollywood stars which still give competition to their younger counterparts.Beauty never goes out of fashion and same goes for some of the stars who have lost their glory but not their glamour!
&lt;a href="http://feedads.g.doubleclick.net/~at/FvLz0iCA-ebXXFmcWcxBraViXq8/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/FvLz0iCA-ebXXFmcWcxBraViXq8/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/dGnrQ1y20jI" height="1" width="1"/&gt;>/description>
  >item>
   >title>The Machines Have Become Self-Aware (pic)>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/2rRXFN2j7mA/The_Machines_Have_Become_Self_Aware_pic>/link>
   >description>*****
&lt;a href="http://feedads.g.doubleclick.net/~at/Vca5bWL8QB_EyVXMJ6ayYUUhGzQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/Vca5bWL8QB_EyVXMJ6ayYUUhGzQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/2rRXFN2j7mA" height="1" width="1"/&gt;>/description>
  >item>
   >title>Facing Pot Charges, Man Claims Marijuana is His Religion>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/DF_xI6HEVG8/Facing_Pot_Charges_Man_Claims_Marijuana_is_His_Religion>/link>
   >description>More specifically, he's a member of both the Church of Universal Sacraments and The Hawaii Cannabis Ministry, aka the THC Ministry, and he uses marijuana in the practice of his religion.
&lt;a href="http://feedads.g.doubleclick.net/~at/lzA4ZkKvXFlQ6_LOIy7F-se821k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/lzA4ZkKvXFlQ6_LOIy7F-se821k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/DF_xI6HEVG8" height="1" width="1"/&gt;>/description>
  >item>
   >title>"Cove" Movie Assails Dolphin Hunt, Gets Oscar Boost>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/1bEL1UjWMq0/Cove_Movie_Assails_Dolphin_Hunt_Gets_Oscar_Boost>/link>
   >description>National Geographic With its 2010 Oscar win for best documentary, the movie The Cove has reignited debate over annual dolphin hunts in Taiji, Japan. This now sheds a whole new story &amp; light on the murderous Dolphin Hunt, it's not............................
&lt;a href="http://feedads.g.doubleclick.net/~at/M5BoYMCHKsYeUGIM7yxkgfq68Xg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/M5BoYMCHKsYeUGIM7yxkgfq68Xg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/1bEL1UjWMq0" height="1" width="1"/&gt;>/description>
  >item>
   >title>Did Microsoft Leave the Social Media Space?>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/jVJkOdyaX0s/Did_Microsoft_Leave_the_Social_Media_Space>/link>
   >description>Microsoft on its part is not in talks. People feel the software giant has run away from this space and is a big time failure. But wait a min. If you think, MS has actually left the space you are wrong.
&lt;a href="http://feedads.g.doubleclick.net/~at/Ng-Dk9HOzra7kgjo8ZNafzlFG_c/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/Ng-Dk9HOzra7kgjo8ZNafzlFG_c/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/jVJkOdyaX0s" height="1" width="1"/&gt;>/description>
  >item>
   >title>Magical Street Graffiti – 35 Breathtaking Illusions!!>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/IoFqQ48acKg/Magical_Street_Graffiti_n_35_Breathtaking_Illusions>/link>
   >description>Graffiti, by nature, is a very controversial subject as it represents a type of art which is mostly unauthorized and one that is in contrast to traditional forms of artwork. The ever growing street culture and graffiti are mostly provocative, appealing, bold and audacious.
&lt;a href="http://feedads.g.doubleclick.net/~at/gnRUs3kBG37j8dAL_RBRd1sqZxU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/gnRUs3kBG37j8dAL_RBRd1sqZxU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/IoFqQ48acKg" height="1" width="1"/&gt;>/description>
  >item>
   >title>Pot Meet Kettle: Greenpeace Data Centers Dirty as Facebook's>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/WxS81MoRxE8/Pot_Meet_Kettle_Greenpeace_Data_Centers_Dirty_as_Facebook_s>/link>
   >description>After calling out the social network for using electricity generated with coal for its new green data center, it turns out that at least some of Greenpeace's servers are powered by coal as well as nuclear power.
&lt;a href="http://feedads.g.doubleclick.net/~at/AmBFkL8WAXLXWemwbgr1OG7eqKA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/AmBFkL8WAXLXWemwbgr1OG7eqKA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/WxS81MoRxE8" height="1" width="1"/&gt;>/description>
  >item>
   >title>Vitamin D Crucial To Activating Immune Defenses>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/senFJS9ar2E/Vitamin_D_Crucial_To_Activating_Immune_Defenses>/link>
   >description>Scientists at the University of Copenhagen have discovered that Vitamin D is crucial to activating our immune defenses and that without sufficient intake of the vitamin, the killer cells of the immune system - T cells - will not be able to react to and fight off serious infections in the body.
&lt;a href="http://feedads.g.doubleclick.net/~at/_2XovTRKu5WowIyCQ9RMZUXbmWs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/_2XovTRKu5WowIyCQ9RMZUXbmWs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/senFJS9ar2E" height="1" width="1"/&gt;>/description>
  >item>
   >title>Greedo The Bounty Hunter - Intergalactic Loser (Videos)>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/_hY6X6yVlnw/Greedo_The_Bounty_Hunter_Intergalactic_Loser_Videos>/link>
   >description>Greedo is everything a bounty hunter shouldn't be.
&lt;a href="http://feedads.g.doubleclick.net/~at/6p9U3DWtwcvaT7HcPi3aHTyd5hU/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/6p9U3DWtwcvaT7HcPi3aHTyd5hU/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/_hY6X6yVlnw" height="1" width="1"/&gt;>/description>
  >item>
   >title>Authorities Move Against Sushi Bar for Serving Whale Meat>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/xCGnNC3fOa0/Authorities_Move_Against_Sushi_Bar_for_Serving_Whale_Meat>/link>
   >description>Investigation by The Cove filmmaker Charles Hambleton leads to allegations that a sushi hotspot has been serving whale meat.
&lt;a href="http://feedads.g.doubleclick.net/~at/bTOWgXtlDGjaOqWz_Jr2KvLOXLE/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/bTOWgXtlDGjaOqWz_Jr2KvLOXLE/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/xCGnNC3fOa0" height="1" width="1"/&gt;>/description>
  >item>
   >title>Swedes extend warm embrace to 'cuddle party' movement>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/ZbuApcFYZI4/Swedes_extend_warm_embrace_to_cuddle_party_movement>/link>
   >description>Swedes are often partial to picking up on trends from "over there", with the latest offering a new way to socialize American-style - introducing... the "cuddle party".
&lt;a href="http://feedads.g.doubleclick.net/~at/KK4J0Ir3lee76SZoJEqgCOL-rmY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/KK4J0Ir3lee76SZoJEqgCOL-rmY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/ZbuApcFYZI4" height="1" width="1"/&gt;>/description>
  >item>
   >title>Insulators Made Into Conductors>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/mj2J1bYwGRE/Insulators_Made_Into_Conductors>/link>
   >description>Most polymers -- materials made of long, chain-like molecules -- are very good insulators for both heat and electricity. But scientists have now found a way to transform the most widely used polymer, polyethylene, into a material that conducts heat just as well as most metals, yet remains an electrical insulator...
&lt;a href="http://feedads.g.doubleclick.net/~at/2lMlYuaFqI0qv1P-aFQk8QGxGKs/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/2lMlYuaFqI0qv1P-aFQk8QGxGKs/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/mj2J1bYwGRE" height="1" width="1"/&gt;>/description>
  >item>
   >title>Two-fingered push-ups world record attempt >/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/HgC7H2i7V8I/Two_fingered_push_ups_world_record_attempt>/link>
   >description>A judge watches Mohammed Ali Zinhom do 46 push-ups in 49 seconds on just two fingers.
&lt;a href="http://feedads.g.doubleclick.net/~at/O3fHf-ptv2iRa5gqAxU9gQkdckw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/O3fHf-ptv2iRa5gqAxU9gQkdckw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/HgC7H2i7V8I" height="1" width="1"/&gt;>/description>
  >item>
   >title>Five Alternative Uses for a Twinkie (Pics)>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/_UaoTB9F45I/Five_Alternative_Uses_for_a_Twinkie_Pics>/link>
   >description>The original uses being, of course, the clogging of major arteries and the causing of orgasms in your mouth. There's the "Twinkie stuffed hot dog" and yes, the vegan Twinkie. Delicious.
&lt;a href="http://feedads.g.doubleclick.net/~at/8Asyj9oUf8CYFlcxvDsYCacLESY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/8Asyj9oUf8CYFlcxvDsYCacLESY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/_UaoTB9F45I" height="1" width="1"/&gt;>/description>
  >item>
   >title>7 Muslims arrested in Ireland over plot to kill cartoonist>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/R7MEVgm4ugA/7_Muslims_arrested_in_Ireland_over_plot_to_kill_cartoonist>/link>
   >description>Seven Muslims were arrested in Ireland today over an alleged plot to assassinate a Swedish cartoonist who depicted the Prophet Mohammed with the body of a dog.
&lt;a href="http://feedads.g.doubleclick.net/~at/ouPoYaolQ2GdY63ZaI2IdtzoBWg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/ouPoYaolQ2GdY63ZaI2IdtzoBWg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/R7MEVgm4ugA" height="1" width="1"/&gt;>/description>
  >item>
   >title>Bottled Wind Could Be as Constant as Coal>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/Ou-mZnU0EJY/Bottled_Wind_Could_Be_as_Constant_as_Coal>/link>
   >description>Wind power has made incredible inroads into the U.S. energy system thanks to big, efficient machines standing hundreds of feet tall.  But the future of wind power may be underground.
&lt;a href="http://feedads.g.doubleclick.net/~at/mjvSMNYhw5Dk4OZOvZHAgzndaMY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/mjvSMNYhw5Dk4OZOvZHAgzndaMY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/Ou-mZnU0EJY" height="1" width="1"/&gt;>/description>
  >item>
   >title>Obama Using 'Bounty Hunters' for Health Care Fraud >/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/LPySDrOQ8xM/Obama_Using_Bounty_Hunters_for_Health_Care_Fraud>/link>
   >description>President Barack Obama said Tuesday he'll bring in high-tech bounty hunters to help root out health care fraud, grabbing a populist idea with bipartisan backing in his final push to overhaul the system.
&lt;a href="http://feedads.g.doubleclick.net/~at/T0CWnecb8G7SxD-yW7U4OeJzTIY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/T0CWnecb8G7SxD-yW7U4OeJzTIY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/LPySDrOQ8xM" height="1" width="1"/&gt;>/description>
  >item>
   >title>When Goods Get Traded, Who Pays for the CO2?>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/w0NmgCyZo2Y/When_Goods_Get_Traded_Who_Pays_for_the_CO2>/link>
   >description>The carbon equation isn't as straightforward as we might think. Scientists find that rich nations are essentially outsourcing some of their carbon emissions to developing nations through global trade
&lt;a href="http://feedads.g.doubleclick.net/~at/gUjp_nHbzxvQDwp6HIR_tWZP9Po/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/gUjp_nHbzxvQDwp6HIR_tWZP9Po/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/w0NmgCyZo2Y" height="1" width="1"/&gt;>/description>
  >item>
   >title>"Valley of the Neptunes" Surprises Jimi Hendrix Skeptics>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/QamgfRNaS3M/Valley_of_the_Neptunes_Surprises_Jimi_Hendrix_Skeptics>/link>
   >description>In the span of his brief career, Jimi Hendrix only produced three albums.Now comes Valleys of the Neptunes, a collection of recordings from the final days of The Jimi Hendrix Experience. Music critics have been reluctant to embrace the album because so many of his posthumous releases have been throwaways. However, this effort is turning heads.
&lt;a href="http://feedads.g.doubleclick.net/~at/M-o4BhgQT6pQVZc3qxnTob3SaFA/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/M-o4BhgQT6pQVZc3qxnTob3SaFA/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/QamgfRNaS3M" height="1" width="1"/&gt;>/description>
  >item>
   >title>The Secret Of A Long &amp; Happy Sex Life? Be Healthy &amp; Be A Man>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/TObVCdSxAG0/The_Secret_Of_A_Long_Happy_Sex_Life_Be_Healthy_Be_A_Man>/link>
   >description>Men and women are living longer than ever before, but are they still having sex? Yes, say researchers in the US, but how often, and how enjoyable it is depends partly on their gender and partly on their state of health.
&lt;a href="http://feedads.g.doubleclick.net/~at/SOKQsGNSMW6dVbDrC1DWa46Uw9g/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/SOKQsGNSMW6dVbDrC1DWa46Uw9g/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/TObVCdSxAG0" height="1" width="1"/&gt;>/description>
  >item>
   >title>CBS Will Broadcast Men's Hoops Final Four Games in 3D>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/T32nFpq-1Co/CBS_Will_Broadcast_Men_s_Hoops_Final_Four_Games_in_3D>/link>
   >description>CBS Sports will show the semifinals and championship game of the NCAA men's basketball tournament in 3D, marking the network's first foray into 3D TV. The network has struck a deal with Cinedigm Digital Cinema Corp. to show the Final Four games in 100 movie theaters nationwide, with pricing yet to be established.
&lt;a href="http://feedads.g.doubleclick.net/~at/42LRhoswLjPbTtuRtbbgsLWSRCg/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/42LRhoswLjPbTtuRtbbgsLWSRCg/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/T32nFpq-1Co" height="1" width="1"/&gt;>/description>
  >item>
   >title>Will Lunar Hole Become First Settlement on the Moon?>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/Quxi_89preM/Will_Lunar_Hole_Become_First_Settlement_on_the_Moon>/link>
   >description>An international team of scientists has discovered an enormous hole that may well become the base for a moon colony. The lunar “lava tube” is not a new find, but the lava sheet that protects it and appears not to be prone to collapse, makes it different from all the others.
&lt;a href="http://feedads.g.doubleclick.net/~at/hcd0n8BQaRIDfdlaRa8bkxgyqb4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/hcd0n8BQaRIDfdlaRa8bkxgyqb4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/Quxi_89preM" height="1" width="1"/&gt;>/description>
  >item>
   >title>Sony Signs All 6 Major Studios for HD Movies on PlayStation>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/ZTbrBRtpRSY/Sony_Signs_All_6_Major_Studios_for_HD_Movies_on_PlayStation>/link>
   >description>Well, it looks like Sony has a little treat for PS3 users now that they're able to turn their consoles back on -- it's just announced that it has signed up all six major studios to deliver HD movies on the PlayStation Network (the first company to do so, as Sony is happy to point out). That includes 20th Century Fox, Walt Disney Pictures... MORE!
&lt;a href="http://feedads.g.doubleclick.net/~at/Ls_zQphMJwZ1rQ4iOlbcxJDKffo/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/Ls_zQphMJwZ1rQ4iOlbcxJDKffo/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/ZTbrBRtpRSY" height="1" width="1"/&gt;>/description>
  >item>
   >title>Star Trek: The Next Generation of Fandom >/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/DaJgLI9S1MU/Star_Trek_The_Next_Generation_of_Fandom>/link>
   >description>From the fantastic to the ridiculous, here are 10 of the most interesting expressions of Star Trek fanaticism.
&lt;a href="http://feedads.g.doubleclick.net/~at/OM9E62Qx4KNKH9Jr3Su14Ed6HAM/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/OM9E62Qx4KNKH9Jr3Su14Ed6HAM/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/DaJgLI9S1MU" height="1" width="1"/&gt;>/description>
  >item>
   >title>Finally see an actual Giant Squid>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/1f7abxvlMLM/Finally_see_an_actual_Giant_Squid>/link>
   >description>Controversial anatomist Gunther von Hagens has stuffed the monstrous pair of squid with silicone for preservation. A new technique preserves the squid in a life like form.
&lt;a href="http://feedads.g.doubleclick.net/~at/09VuFZveL0wCEXkGU8KV-lbaZQY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/09VuFZveL0wCEXkGU8KV-lbaZQY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/1f7abxvlMLM" height="1" width="1"/&gt;>/description>
  >item>
   >title>DR Congo ring may be giant 'impact crater'>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/52aRDZk5a2Y/DR_Congo_ring_may_be_giant_impact_crater>/link>
   >description>Deforestation has revealed what could be a giant impact crater in Central Africa, scientists say. The 36-46km-wide feature, identified in DR Congo, may be one of the largest such structures discovered in the last decade.
&lt;a href="http://feedads.g.doubleclick.net/~at/BzURkMBeX761LvEQKjMjJPfthRY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/BzURkMBeX761LvEQKjMjJPfthRY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/52aRDZk5a2Y" height="1" width="1"/&gt;>/description>
  >item>
   >title>Physicists Find Way To See Through Opaque Materials>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/brHkz_HPGOI/Physicists_Find_Way_To_See_Through_Opaque_Materials>/link>
   >description>New experiments show that it's possible to focus light through opaque materials and detect objects hidden behind them, provided you know enough about the material.
&lt;a href="http://feedads.g.doubleclick.net/~at/xuRGEasA1y-DdIJSq1q7xOo4-44/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/xuRGEasA1y-DdIJSq1q7xOo4-44/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/brHkz_HPGOI" height="1" width="1"/&gt;>/description>
  >item>
   >title>Real-life 'Bridezilla' starts crazy brawl inside bridal shop>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/eCxmAtLk6Gg/Real_life_Bridezilla_starts_crazy_brawl_inside_bridal_shop>/link>
   >description>If the guy goes through with this marriage, they both deserve to be miserable for the rest of their lives....
&lt;a href="http://feedads.g.doubleclick.net/~at/I0ZeOFF6xecd4xVkYNJMoEAb75k/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/I0ZeOFF6xecd4xVkYNJMoEAb75k/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/eCxmAtLk6Gg" height="1" width="1"/&gt;>/description>
  >item>
   >title>Adderall Is Baseball's New Drug Problem, Says Doc>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/4DsCeYiaWZc/Adderall_Is_Baseball_s_New_Drug_Problem_Says_Doc>/link>
   >description>A major league baseball player’s bitter divorce has lifted the lid on the sport’s new drug problem – players abusing the drug Adderall.
&lt;a href="http://feedads.g.doubleclick.net/~at/BVKwUbVksZavs4dj-_J33eswyq4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/BVKwUbVksZavs4dj-_J33eswyq4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/4DsCeYiaWZc" height="1" width="1"/&gt;>/description>
  >item>
   >title>2004-2008 Toyota Prius Recall Will Reshape Accelerator Pedal>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/29XnPMNTQ6M/2004_2008_Toyota_Prius_Recall_Will_Reshape_Accelerator_Pedal>/link>
   >description>Owners of Toyota's iconic Prius hybrid model who thought they'd escaped the rash of Toyota recalls need to think again. The company is working on a fix to reshape accelerator pedals so that they cannot be trapped by floor mats, and will issue details within weeks.
&lt;a href="http://feedads.g.doubleclick.net/~at/uH4uLs7T73BE8k6fvcdOlNiBb_Y/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/uH4uLs7T73BE8k6fvcdOlNiBb_Y/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/29XnPMNTQ6M" height="1" width="1"/&gt;>/description>
  >item>
   >title>A gallery of the worst tattoos EVER.>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/cNTPV4Vrgbg/A_gallery_of_the_worst_tattoos_EVER>/link>
   >description>The first thing that comes to mind is absolute stupidity.
&lt;a href="http://feedads.g.doubleclick.net/~at/thgkLjSRuS4l8Cf4QiDsEET3-wQ/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/thgkLjSRuS4l8Cf4QiDsEET3-wQ/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/cNTPV4Vrgbg" height="1" width="1"/&gt;>/description>
  >item>
   >title>America's Cheapest Hooker Charges $5 and a Jawbreaker >/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/-sY6KxUB_20/America_s_Cheapest_Hooker_Charges_5_and_a_Jawbreaker>/link>
   >description>Yes, she solicited an undercover Cincinnati cop, and all she wanted was5 bucks and a large clump of candy.
&lt;a href="http://feedads.g.doubleclick.net/~at/sff3WYNpGXbKAZL8MPz0PgnM3Aw/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/sff3WYNpGXbKAZL8MPz0PgnM3Aw/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/-sY6KxUB_20" height="1" width="1"/&gt;>/description>
  >item>
   >title>1969 LSD induced IHOP Commercial>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/uphooEACZJs/1969_LSD_induced_IHOP_Commercial>/link>
   >description>Turn on, tune in, drop out. This commercial made me feel like I was tripping.
&lt;a href="http://feedads.g.doubleclick.net/~at/kcNNHj24J26w2vUaOc1VQAHFa0A/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/kcNNHj24J26w2vUaOc1VQAHFa0A/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/uphooEACZJs" height="1" width="1"/&gt;>/description>
  >item>
   >title>Nokia Files Patent for Self-Charging Phone>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/Me-2mrQ6gMo/Nokia_Files_Patent_for_Self_Charging_Phone>/link>
   >description>Kinetically powered cell phones have been relegated to futuristic concepts..or have they? Nokia files a patent that could lead to the first real piezoelectric mobile phone.
&lt;a href="http://feedads.g.doubleclick.net/~at/BYBg6ddULhnwqj17VHQaI7wk0oI/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/BYBg6ddULhnwqj17VHQaI7wk0oI/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/Me-2mrQ6gMo" height="1" width="1"/&gt;>/description>
  >item>
   >title>Apple's Long History of Lousy First Reviews>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/XXDKQio1Gg8/Apple_s_Long_History_of_Lousy_First_Reviews>/link>
   >description>Though the iPad has drawn some harsh reviews, it's hardly the first Apple product to get trashed (at first). A look back at 25 years of "flops"
&lt;a href="http://feedads.g.doubleclick.net/~at/bC94IQa8Y7G7UHnmDc0UacogQu4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/bC94IQa8Y7G7UHnmDc0UacogQu4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/XXDKQio1Gg8" height="1" width="1"/&gt;>/description>
  >item>
   >title>Moms Iron Daughters' Breasts in Mutilation Practice>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/h7_w2QO83Yo/Moms_Iron_Daughters_Breasts_in_Mutilation_Practice>/link>
   >description>Though not publicly acknowledged, many pubescent girls in the West African country of Cameroon are subjected to the practice of breast ironing, which involves massaging a child's growing breasts with an object like a stone, hammer or spatula that has been heated over coals, until the breasts actually disappear. The practice of breast ironing is...
&lt;a href="http://feedads.g.doubleclick.net/~at/n4HBNiK2Q6rE1X9hG4LWOjLQAFY/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/n4HBNiK2Q6rE1X9hG4LWOjLQAFY/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/h7_w2QO83Yo" height="1" width="1"/&gt;>/description>
  >item>
   >title>Hourly Wage Earners Are Happier Than Salaried Workers>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/iblSRj0_Puc/Hourly_Wage_Earners_Are_Happier_Than_Salaried_Workers>/link>
   >description>The relationship between money and happiness is stronger for people paid hourly because they're more often reminded of how much they earn, according to researchers at Stanford University and the University of Toronto. That lets workers more easily measure their value, which in turn increases happiness.
&lt;a href="http://feedads.g.doubleclick.net/~at/14jLuKt7W0weGa477vMjf7ycuew/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/14jLuKt7W0weGa477vMjf7ycuew/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/iblSRj0_Puc" height="1" width="1"/&gt;>/description>
  >item>
   >title>Cisco's New Router To Delivers 322 Terabits per Second>/title>
   >link>http://feeds.digg.com/~r/digg/popular/~3/iaJ_IFwavNI/Cisco_s_New_Router_To_Delivers_322_Terabits_per_Second>/link>
   >description>Cisco Systems, has announced the launch of a super-fast and effeciency-focused router technology which will be at the heart of "the next generation of the Internet".
&lt;a href="http://feedads.g.doubleclick.net/~at/C9hvOWYqYhzsVf-tLTA3RSp12Q4/1/da"&gt;&lt;img src="http://feedads.g.doubleclick.net/~at/C9hvOWYqYhzsVf-tLTA3RSp12Q4/1/di" border="0" ismap="true"&gt;&lt;/img&gt;&lt;/a&gt;&lt;/p&gt;&lt;img src="http://feeds.feedburner.com/~r/digg/popular/~4/iaJ_IFwavNI" height="1" width="1"/&gt;>/description>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>The RISKS Forum>/title>
    >link>http://seclists.org/#risks>/link>
    >description>Peter G. Neumann moderates this regular digest of current events which demonstrate risks to the public in computers and related systems.  Security risks are often discussed.>/description>
  >item>
    >title>Risks Digest 25.95>/title>
    >link>http://seclists.org/risks/2010/q1/6>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Feb 28&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Sunday 28 February 2010  Volume 25 : Issue 95&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.94>/title>
    >link>http://seclists.org/risks/2010/q1/5>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Feb 14&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Sunday 14 February 2010  Volume 25 : Issue 94&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.93>/title>
    >link>http://seclists.org/risks/2010/q1/4>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Jan 29&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Friday 29 January 2010  Volume 25 : Issue 93&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.92>/title>
    >link>http://seclists.org/risks/2010/q1/3>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Jan 26&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 26 January 2010  Volume 25 : Issue 92&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.91>/title>
    >link>http://seclists.org/risks/2010/q1/2>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Jan 19&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 19 January 2010  Volume 25 : Issue 91&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.90>/title>
    >link>http://seclists.org/risks/2010/q1/1>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Jan 08&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Friday 8 January 2010  Volume 25 : Issue 90&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.89>/title>
    >link>http://seclists.org/risks/2010/q1/0>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Jan 07&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Thursday 7 January 2010  Volume 25 : Issue 89&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.88>/title>
    >link>http://seclists.org/risks/2009/q4/8>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Dec 26&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Saturday 26 December 2009  Volume 25 : Issue 88&lt;br&gt;
The current issue can...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.87>/title>
    >link>http://seclists.org/risks/2009/q4/7>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Dec 15&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 15 December 2009  Volume 25 : Issue 87&lt;br&gt;
The current issue can...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.86>/title>
    >link>http://seclists.org/risks/2009/q4/6>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Dec 14&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Monday 14 December 2009  Volume 25 : Issue 86&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.85>/title>
    >link>http://seclists.org/risks/2009/q4/5>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Nov 28&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Saturday 28 November 2009  Volume 25 : Issue 85&lt;br&gt;
The current issue can...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.84>/title>
    >link>http://seclists.org/risks/2009/q4/4>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Nov 25&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Weds 25 November 2009  Volume 25 : Issue 84&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.83>/title>
    >link>http://seclists.org/risks/2009/q4/3>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Nov 06&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Friday 6 November 2009  Volume 25 : Issue 83&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.82>/title>
    >link>http://seclists.org/risks/2009/q4/2>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Oct 20&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Tuesday 20 October 2009  Volume 25 : Issue 82&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Risks Digest 25.81>/title>
    >link>http://seclists.org/risks/2009/q4/1>/link>
    >description>&lt;p&gt;Posted by RISKS List Owner on Oct 12&lt;/p&gt;RISKS-LIST: Risks-Forum Digest  Monday 12 October 2009  Volume 25 : Issue 81&lt;br&gt;
The current issue can be...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
  >title>      SANS Internet Storm Center, InfoCON: green>/title>
  >link>       http://isc.sans.org>/link>
  >description>>![CDATA[]]>>/description>
             >image>
               >title>SANS Internet Storm Center, InfoCON: green>/title>
               >url>http://isc.sans.org/images/status.gif>/url>
               >link>http://isc.sans.org>/link>
             >/image>
  >item>
    >title>Infocon: green>/title>
    >link>http://isc.sans.org/diary.html?rss>/link>
    >description>>![CDATA[What's My Firewall Telling Me? (Part 4)]]>>/description>
  >/item>
  >item>
    >title>What's My Firewall Telling Me? (Part 4), (Wed, Mar 10th)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8395&amp;rss>/link>
    >description>>![CDATA[Theres been a lot of discussion about the recent stories on parsing firewall logs - Mar ...(more)... ]]>>/description>
  >/item>
  >item>
    >title>
Microsoft Security Advisory 981374 - Remote Code Execution Vulnerability for IE6 and IE7, (Wed, Mar 10th)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8398&amp;rss>/link>
    >description>>![CDATA[Several readers have pointed us towards this advisory. This Microsoft advisory outlines a vuln ...(more)... ]]>>/description>
  >/item>
  >item>
    >title>
March 2010 - Microsoft Patch Tuesday Diary, (Tue, Mar 9th)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8392&amp;rss>/link>
    >description>>![CDATA[
    ...(more)... ]]>>/description>
  >/item>
  >item>
    >title>
Samurai WTF 0.8, (Mon, Mar 8th)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8377&amp;rss>/link>
    >description>>![CDATA[A new version of the Samurai WTF (Web Testing Framework) distribution, version 0.8, has been r ...(more)... ]]>>/description>
  >/item>
  >item>
    >title>
Vodafone Android Phone: Complete with Mariposa Malware, (Tue, Mar 9th)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8389&amp;rss>/link>
    >description>>![CDATA[Panda Security has a post up on one of their employees buying a brand new Android phone from Vodafon ...(more)... ]]>>/description>
  >/item>
  >item>
    >title>
Energizer Malware, (Tue, Mar 9th)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8386&amp;rss>/link>
    >description>>![CDATA[We received several emails today about the US-CERTanalysis of Trojan horse software found in a ...(more)... ]]>>/description>
  >/item>
  >item>
    >title>
SEO poisoning on TV show, (Mon, Mar 8th)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8383&amp;rss>/link>
    >description>>![CDATA[An ISCreader, thanks Paul, notified us about a new SEO(Search Engine Optimization) ...(more)... ]]>>/description>
  >/item>
  >item>
    >title>
Microsoft announced two important bulletins (fixing multiple vulns. affecting Windows and Office) for tomorrow: http://www.microsoft.com/technet/security/Bulletin/MS10-mar.mspx, (Mon, Mar 8th)>/title>
    >link>http://isc.sans.org/diary.html?storyid=8380&amp;rss>/link>
    >description>>![CDATA[ ...(more)... ]]>>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
>title>Nessus.org Plugins>/title>
>link>http://www.nessus.org/scripts.php>/link>
>description>All the newest security checks for the Nessus scanner>/description>
>image about="http://www.nessus.org/images/RssLogo.jpg">
>title>Nessus Plugins>/title>
>url>http://www.nessus.org/images/RssLogo.jpg>/url>
>link>http://www.nessus.org/>/link>
>/image>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45021">
>title>MS10-017: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (980150)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45021>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45020">
>title>MS10-016: Vulnerability in Windows Movie Maker Could Allow Remote Code Execution (975561)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45020>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45019">
>title>SpamAssassin Milter Plugin 'mlfi_envrcpt()' Remote Arbitrary Command Injection>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45019>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45018">
>title>Symantec IM Manager KeyView OLE Parsing Integer Overflow (SYM10-006)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45018>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45017">
>title>Symantec IM Manager Detection>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45017>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45016">
>title>USN907-1 : gnome-screensaver vulnerabilities>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45016>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45015">
>title>SuSE Security Update:  Security update for sudo (sudo-6891)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45015>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45014">
>title>SuSE Security Update:  sudo (2010-03-01)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45014>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45013">
>title>SuSE 11.2 Security Update:  sudo (2010-03-01)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45013>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45012">
>title>SuSE 11.1 Security Update:  sudo (2010-03-01)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45012>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45011">
>title>SuSE 11.0 Security Update:  sudo (2010-03-01)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45011>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45010">
>title>SuSE 11.0 Security Update:  kernel (2010-03-01)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45010>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45009">
>title>FreeBSD : drupal -- multiple vulnerabilities (5230)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45009>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45008">
>title>[DSA2008] DSA-2008-1 typo3-src>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45008>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45007">
>title>SSA-2010-067-01 httpd >/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45007>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45006">
>title>Energizer DUO USB Battery Charger Software Backdoor (credentialed check)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45006>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45005">
>title>Arugizer Backdoor>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45005>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45004">
>title>Apache 2.2 &lt; 2.2.15 Multiple Vulnerabilities>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45004>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45003">
>title>SuSE Security Update:  Security update for netpbm (libnetpbm-6851)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45003>/link>
>/item>
>item about="http://www.nessus.org/plugins/index.php?view=single&amp;id=45002">
>title>SuSE Security Update:  libnetpbm-devel (2010-02-16)>/title>
>description>>![CDATA[Synopsis :>br />
]]>>/description>
>link>http://www.nessus.org/plugins/index.php?view=single&amp;id=45002>/link>
>/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
 >title>SecuriTeam>/title>
 >link>http://www.securiteam.com>/link>
 >description>Welcome to the SecuriTeam RSS Feed - sponsored by Beyond Security. Know Your Vulnerabilities! Visit BeyondSecurity.com for your web site, network and code security audit and scanning needs.>/description>
 >image>
  >title>SecuriTeam.com>/title>
  >url>http://www.securiteam.com/beyond-logo-small.png>/url>
  >link>http://www.securiteam.com>/link>
 >/image>
 >item>
  >title>LedgerSMB Multiple Vulnerabilities>/title>
  >link>http://www.securiteam.com/securitynews/5EP3H1P0AU.html>/link>
  >description>>![CDATA[It has been brought to our attention that a number of security vulnerabilities have been noted in SQL-Ledger.  Several of these affect earlier versions of LedgerSMB, and three hotfixes have been released for problems that continue to affect the LedgerSMB codebase.]]>>/description>
 >/item>
 >item>
  >title>Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability>/title>
  >link>http://www.securiteam.com/securitynews/5RP2W150AC.html>/link>
  >description>>![CDATA[Insecure permissions have been detected in the multiple Kaspersky Lab antivirus products.]]>>/description>
 >/item>
 >item>
  >title>Piwik Cookie Unserialize Vulnerability>/title>
  >link>http://www.securiteam.com/securitynews/6H00B0AQAS.html>/link>
  >description>>![CDATA[Piwik unserializes() user input which allows an attacker to send a carefully crafted cookie that when unserialized utilizes Piwik's classes to upload arbitrary files or execute arbitrary PHP code.]]>>/description>
 >/item>
 >item>
  >title>Invision Power Board SQL PHP File Inclusion and SQL Injection>/title>
  >link>http://www.securiteam.com/securitynews/6T0022AQAC.html>/link>
  >description>>![CDATA[Invision Power Board has a PHP file inclusion vulnerability that is trivial to exploit with a web browser and a known location of a php file residing on the target system. Authorisation is not required. The SQL injection vulnerability is somewhat tricky to exploit as there are quite a few restrictions that make creating a successful sql attack vector difficult. Nevertheless a crafty attacker might issue a series of requests that might allow him to gain some information about the target system or even read files from the disk depending on permissions granted to the db account that is used by the forum.]]>>/description>
 >/item>
 >item>
  >title>U.S. Defense Information Systems Agency (DISA) Unix Security Readiness Review (SRR) Vulnerability>/title>
  >link>http://www.securiteam.com/securitynews/6E00420QAS.html>/link>
  >description>>![CDATA[The U.S. Defense Information Systems Agency (DISA) publishes Security Readiness Review scripts (SRRs) to ensure systems and software meet security baselines required by the Department of Defense.  Unprivileged local users can obtain root access on Unix systems where the DISA SRR scripts are run.]]>>/description>
 >/item>
 >item>
  >title>Netifera - Modular Open Source Platform for Security Tools>/title>
  >link>http://www.securiteam.com/tools/5QP0B0KQUE.html>/link>
  >description>>![CDATA[]]>>/description>
 >/item>
 >item>
  >title>WarVOX -  Tools for Exploring, Classifying, and Auditing Telephone Systems>/title>
  >link>http://www.securiteam.com/tools/5RP012KQKA.html>/link>
  >description>>![CDATA[]]>>/description>
 >/item>
 >item>
  >title>Webshag - Web Server Audit Tool>/title>
  >link>http://www.securiteam.com/tools/5QP0L0UQAI.html>/link>
  >description>>![CDATA[]]>>/description>
 >/item>
 >item>
  >title>Browser Fuzzer>/title>
  >link>http://www.securiteam.com/tools/5OP0L00Q0Y.html>/link>
  >description>>![CDATA[]]>>/description>
 >/item>
 >item>
  >title>FSpy - Linux Filesystem Activity Monitoring>/title>
  >link>http://www.securiteam.com/tools/6D00V0ANFY.html>/link>
  >description>>![CDATA[]]>>/description>
 >/item>
 >item>
  >title>Publique! CMS and SQL Injection Vulnerabilities>/title>
  >link>http://www.securiteam.com/unixfocus/5FP3I1P0AO.html>/link>
  >description>>![CDATA[A remotely exploitable vulnerability was found in the framework core component. Exploitation of this bug does not require authentication and will lead to remotely exposed potentially sensitive information from the Publique! database. Particularly, an attacker can extract usernames and passwords needed to authenticate to the administrative interface and gain full control of the web site and (depending on certain conditions) the server itself.]]>>/description>
 >/item>
 >item>
  >title>Files2Links F2L-3000 SQL Injection Vulnerability>/title>
  >link>http://www.securiteam.com/unixfocus/5DP3G1P0AA.html>/link>
  >description>>![CDATA[The login page of the F2L-3000 version 4.0.0 is vulnerable to SQL Injection. Exploitation of the vulnerability may allow attackers to bypass authentication and access sensitive information stored on the device.]]>>/description>
 >/item>
 >item>
  >title>HP-UX Running Apache Data Injection and DoS Vulnerability>/title>
  >link>http://www.securiteam.com/unixfocus/5QP2V150AO.html>/link>
  >description>>![CDATA[A potential security vulnerability has been identified with HP-UX running Apache v2.0.59.12 and earlier. The vulnerability could be exploited remotely to inject unauthorized data or to create a Denial of Service (DoS).]]>>/description>
 >/item>
 >item>
  >title>MIT krb5 KDC denial of service in cross-realm referral processing>/title>
  >link>http://www.securiteam.com/unixfocus/5MP2W0K0AK.html>/link>
  >description>>![CDATA[An unauthenticated remote attacker could cause the KDC to crash due to a null pointer dereference.  Legitimate requests can also cause this crash to occur.]]>>/description>
 >/item>
 >item>
  >title>AproxEngine Multiple Vulnerabilities>/title>
  >link>http://www.securiteam.com/unixfocus/5BP2V0A0AG.html>/link>
  >description>>![CDATA[Vulnerabilities have been discovered in AproxEngine, which can be exploited by malicious users to manipulate certain data, conduct spoofing, SQL injection, and script insertion attacks and by malicious people to conduct SQL injection and script insertion attacks.]]>>/description>
 >/item>
 >item>
  >title>Microsoft Indeo Codec Memory Corruption Vulnerability>/title>
  >link>http://www.securiteam.com/windowsntfocus/6S00D00QAW.html>/link>
  >description>>![CDATA[The Indeo codec on systems running Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow code to run on users systems when opening specially crafted content.]]>>/description>
 >/item>
 >item>
  >title>HP DDMI Execution of Arbitrary Code>/title>
  >link>http://www.securiteam.com/windowsntfocus/6T00C2AQ0Y.html>/link>
  >description>>![CDATA[A potential security vulnerability has been identified with HP Discovery & Dependency Mapping Inventory (DDMI) running on Windows. The vulnerability could be exploited remotely by an authorized user to execute arbitrary code.]]>>/description>
 >/item>
 >item>
  >title>Microsoft Windows License Logging Service Heap Corruption Vulnerability>/title>
  >link>http://www.securiteam.com/windowsntfocus/6M00D0UQ0W.html>/link>
  >description>>![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. Authentication is not required on certain configurations to exploit this vulnerability.]]>>/description>
 >/item>
 >item>
  >title>Microsoft Office Excel Code Execution Vulnerabilities>/title>
  >link>http://www.securiteam.com/windowsntfocus/6K00B0UQ0K.html>/link>
  >description>>![CDATA[Attackers using specially crafted XLS files can execute arbitrary code via memory corruptions, invalid index, and invalid pointer errors.]]>>/description>
 >/item>
 >item>
  >title>Microsoft SharePoint 2007 ASP.NET Source Code Disclosure>/title>
  >link>http://www.securiteam.com/windowsntfocus/6W0040UQ0W.html>/link>
  >description>>![CDATA[It was found that the download facility of Microsoft SharePoint Team Services can be abused to reveal the source code of ASP.NET files.]]>>/description>
 >/item>
 >item>
  >title>Trango Broadband Wireless Rogue SU Authentication Bug>/title>
  >link>http://www.securiteam.com/exploits/5LP2V0K0AG.html>/link>
  >description>>![CDATA[Currently there is a flaw in the authentication mechanism of these radios which, if an attacker knows some details, can allow interception of ethernet packets broadcast from the Access Point to the Subscriber Unit and potentially allows injection into the communication from the Subscriber Unit to the Access Point.]]>>/description>
 >/item>
 >item>
  >title>Exposing HMS HICP Protocol and Intellicom NetBiterConfig.exe Remote Buffer Overflow>/title>
  >link>http://www.securiteam.com/exploits/5CP2W0A0AU.html>/link>
  >description>>![CDATA[SCADA weaknesses created by HICP Protocol and NetBiter WebSCADA.]]>>/description>
 >/item>
 >item>
  >title>Family Connections Multiple Remote Vulnerabilities>/title>
  >link>http://www.securiteam.com/exploits/6U00D20QAQ.html>/link>
  >description>>![CDATA[Many fields are not properly sanitised and some checks can be bypassed.]]>>/description>
 >/item>
 >item>
  >title>VideoCache vccleaner Root Vulnerability>/title>
  >link>http://www.securiteam.com/exploits/6T00C20QAY.html>/link>
  >description>>![CDATA[VideoCache is a Squid URL rewriter plugin written in Python for bandwidth optimization while browsing video sharing websites. Version 1.9.2 allows a user with the privileges of the Squid proxy server to append semi-arbitrary data to arbitrary files with root privileges, upon the administrator's execution of the 'vccleaner' utility.]]>>/description>
 >/item>
 >item>
  >title>QuickHeal Antivirus 2010 Local Privilege Escalation>/title>
  >link>http://www.securiteam.com/exploits/6S00B20QAQ.html>/link>
  >description>>![CDATA[All files under the install folder have Full control for BUILTIN\users and can be replace with malicious files.]]>>/description>
 >/item>
 >item>
  >title>Why Silent Updates Boost Security>/title>
  >link>http://www.securiteam.com/securityreviews/5NP0E00R5A.html>/link>
  >description>>![CDATA[Thomas Duebendorfer Google Switzerland GmbH and Stefan Frei Communication Systems Group, ETH Zurich, Switzerland looked into the performance of Web browser update mechanisms. The analysis of anonymized Google Web server logs allowed us to compare and rank the update strategies deployed by Google Chrome, Mozilla Firefox, Apple Safari, and Opera.]]>>/description>
 >/item>
 >item>
  >title>PDF Silent HTTP Form Repurposing Attacks>/title>
  >link>http://www.securiteam.com/securityreviews/5MP0D00R5G.html>/link>
  >description>>![CDATA[This paper sheds light on a modified approach to triggering web attacks through JavaScript protocol handler in the context of opening a PDF in a browser.]]>>/description>
 >/item>
 >item>
  >title>Frame Pointer Overwrite Demonstration (Linux)>/title>
  >link>http://www.securiteam.com/securityreviews/6M0010UNFQ.html>/link>
  >description>>![CDATA[This paper assumes you have read the proper background information and/or technical details about the above subject. If not, please do so, because this read does not include key concepts but instead technical exploitation examples. That being said, enjoy. Knowledge is power.]]>>/description>
 >/item>
 >item>
  >title>Format String Exploitation Demonstration (Linux)>/title>
  >link>http://www.securiteam.com/securityreviews/6E0030KNFO.html>/link>
  >description>>![CDATA[This paper assumes you have read the proper background information and/or technical details about the above subject. If not, please do so, because this read does not include key concepts but instead technical exploitation examples. That being said, enjoy. Knowledge is power.]]>>/description>
 >/item>
 >item>
  >title>Hacking SOHO Routers>/title>
  >link>http://www.securiteam.com/securityreviews/6D00C0KN5S.html>/link>
  >description>>![CDATA[The purpose of this paper is to outline the security measures being taken by vendors to prevent such attacks in their home routing products, what those security measures accomplish, and where they fall short. We will use existing network tools to examine common vulnerabilities in a range of popular devices and demonstrate weaknesses in the security of those devices; additionally,  we will examine common trends in security measures that have been duplicated across vendors, and examine how those trends help and hinder the security of their devices. In particular, we will examine the following home routers, which are some of the latest offerings from their respective vendors at the time of this writing:&nbsp;* Linksys WRT160N]]>>/description>
 >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Security Basics>/title>
    >link>http://seclists.org/#basics>/link>
    >description>A high-volume list which permits people to ask &quot;stupid questions&quot; without being derided as &quot;n00bs&quot;.  I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.>/description>
  >item>
    >title>Reporting SSH abuse>/title>
    >link>http://seclists.org/basics/2010/Mar/44>/link>
    >description>&lt;p&gt;Posted by Dan Pilcheck on Mar 09&lt;/p&gt;Hello list,&lt;br&gt;
up with. I suppose there's not much else to...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Help hardening router>/title>
    >link>http://seclists.org/basics/2010/Mar/43>/link>
    >description>&lt;p&gt;Posted by Mike Hale on Mar 09&lt;/p&gt;Wouldn't you want to encrypt your passwords in 5?  Level 7 can be&lt;br&gt;
cracked in seconds online.&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Help hardening router>/title>
    >link>http://seclists.org/basics/2010/Mar/42>/link>
    >description>&lt;p&gt;Posted by Curt Shaffer on Mar 09&lt;/p&gt;Step one is to now change all of your passwords unless you put bogus hashes in there when you posted this. Otherwise, &lt;br&gt;
it benefits your...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Help hardening router>/title>
    >link>http://seclists.org/basics/2010/Mar/41>/link>
    >description>&lt;p&gt;Posted by Alex on Mar 09&lt;/p&gt;Hi you&lt;br&gt;
the...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>RE: Help hardening router>/title>
    >link>http://seclists.org/basics/2010/Mar/40>/link>
    >description>&lt;p&gt;Posted by Jatmoko, Arif (ID - Jakarta) on Mar 09&lt;/p&gt;If this is a Cisco Catalyst, that should be support SSH. Just enable SSH by entering the command :&lt;br&gt;
You should, at least learn some basic command or consults about configuring Catalyst IOS to someone has...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: securing a segment of a network>/title>
    >link>http://seclists.org/basics/2010/Mar/39>/link>
    >description>&lt;p&gt;Posted by krymson on Mar 09&lt;/p&gt;Would that be a primary concern about the current state of audits and checklists? Basically, there is a *lot* of effort &lt;br&gt;
applicatiions, shares and/or privileges. Splitting the network does not address this in any way, at best it...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>FW: Help hardening router>/title>
    >link>http://seclists.org/basics/2010/Mar/38>/link>
    >description>&lt;p&gt;Posted by Craig S. Wright on Mar 09&lt;/p&gt;ARGGG!&lt;br&gt;
        Nipper, (Network Infrastructure Parser)...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Help hardening router>/title>
    >link>http://seclists.org/basics/2010/Mar/37>/link>
    >description>&lt;p&gt;Posted by John Morrison on Mar 09&lt;/p&gt;Joe,&lt;br&gt;
Download and installed the latest...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Help hardening router>/title>
    >link>http://seclists.org/basics/2010/Mar/36>/link>
    >description>&lt;p&gt;Posted by David Goldsmith on Mar 09&lt;/p&gt;Did you change the various encrypted passwords before posting the&lt;br&gt;
be sure to fully...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: securing a segment of a network>/title>
    >link>http://seclists.org/basics/2010/Mar/35>/link>
    >description>&lt;p&gt;Posted by Adam Pal on Mar 08&lt;/p&gt;Hi Roger,&lt;br&gt;
&amp;quot;Keep the same, maintain the...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Help hardening router>/title>
    >link>http://seclists.org/basics/2010/Mar/34>/link>
    >description>&lt;p&gt;Posted by mzcohen2682 on Mar 08&lt;/p&gt;HI ALL !&lt;br&gt;
also in the endo of the access list they have a line saying:...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Re: securing a segment of a network>/title>
    >link>http://seclists.org/basics/2010/Mar/33>/link>
    >description>&lt;p&gt;Posted by Bovril1a on Mar 08&lt;/p&gt;Unless you are in a high security environment the requirement from your  auditors is an excellent example of why &lt;br&gt;
Before you EVER accept an audit finding it needs to meet a basic &amp;quot;Rule of...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: securing a segment of a network>/title>
    >link>http://seclists.org/basics/2010/Mar/32>/link>
    >description>&lt;p&gt;Posted by Roger D Vargas on Mar 08&lt;/p&gt;Adam Pal escribió:&lt;br&gt;
PCs in the network....&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: securing a segment of a network>/title>
    >link>http://seclists.org/basics/2010/Mar/31>/link>
    >description>&lt;p&gt;Posted by Adam Pal on Mar 08&lt;/p&gt;Hello Roger,&lt;br&gt;
RDV&amp;gt; ago I had physically split my network in 2, with 2 windows...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: [cansecwest] Advanced PHP Hacking>/title>
    >link>http://seclists.org/basics/2010/Mar/30>/link>
    >description>&lt;p&gt;Posted by Barbod Kiani on Mar 08&lt;/p&gt;Laurent:&lt;br&gt;
would be to have one of your...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
>link>http://seclists.org/#jobs>/link>
>description>A popular list for advertising or finding jobs in the security field.  Employers post openings and job seekers post resumes (run by SecurityFocus).  For privacy reasons, only the current year is archived.>/description>
>/channel>
>/rss>
>rss version="2.0">
>channel>
>link>http://seclists.org/#vuln-dev>/link>
>description>A moderated list for discussing possible security issues and devising exploits for them.>/description>
>/channel>
>/rss>
>rss version="2.0">
>channel>
>title>SecurityFocus Vulnerabilities>/title>
>link>http://www.securityfocus.com>/link>
>description>
>/description>
>image> 
>title>SecurityFocus>/title> 
>url>http://www.securityfocus.com/rss/SFLogo_v1.gif>/url> 
>link>http://www.securityfocus.com>/link> 
>/image>
>item>
>title>Vuln: RETIRED: Microsoft March 2010 Advance Notification Multiple Vulnerabilities>/title>
>link>http://www.securityfocus.com/bid/38540>/link>
>description>>![CDATA[ RETIRED: Microsoft March 2010 Advance Notification Multiple Vulnerabilities ]]>>/description>
>/item>
>item>
>title>Vuln: Microsoft Excel DbOrParamQry Record Remote Code Execution Vulnerability>/title>
>link>http://www.securityfocus.com/bid/38555>/link>
>description>>![CDATA[ Microsoft Excel DbOrParamQry Record Remote Code Execution Vulnerability ]]>>/description>
>/item>
>item>
>title>Vuln: Microsoft Windows Movie Maker and Producer '.mswmm' Buffer Overflow Vulnerability>/title>
>link>http://www.securityfocus.com/bid/38515>/link>
>description>>![CDATA[ Microsoft Windows Movie Maker and Producer '.mswmm' Buffer Overflow Vulnerability ]]>>/description>
>/item>
>item>
>title>Vuln: Microsoft Internet Explorer 'iepeers.dll' Remote Code Execution Vulnerability>/title>
>link>http://www.securityfocus.com/bid/38615>/link>
>description>>![CDATA[ Microsoft Internet Explorer 'iepeers.dll' Remote Code Execution Vulnerability ]]>>/description>
>/item>
>item>
>title>Bugtraq: ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability>/title>
>link>http://www.securityfocus.com/archive/1/509979>/link>
>description>>![CDATA[ ZDI-10-025: Microsoft Office Excel XLSX File Parsing Remote Code Execution Vulnerability ]]>>/description>
>/item>
>item>
>title>Bugtraq: SQL injection vulnerability in wILD CMS>/title>
>link>http://www.securityfocus.com/archive/1/509973>/link>
>description>>![CDATA[ SQL injection vulnerability in wILD CMS ]]>>/description>
>/item>
>item>
>title>Bugtraq: IBM ENOVIA SmarTeam v5 Cross Site Scripting Vulnerability>/title>
>link>http://www.securityfocus.com/archive/1/509975>/link>
>description>>![CDATA[ IBM ENOVIA SmarTeam v5 Cross Site Scripting Vulnerability ]]>>/description>
>/item>
>item>
>title>Bugtraq: [security bulletin] HPSBMA02489 SSRT090065 rev.1 - HP Performance Insight , Remote Execution of Arbitrary Commands>/title>
>link>http://www.securityfocus.com/archive/1/509977>/link>
>description>>![CDATA[ [security bulletin] HPSBMA02489 SSRT090065 rev.1 - HP Performance Insight , Remote Execution of Arbitrary Commands ]]>>/description>
>/item>
>item>
>title>More rss feeds from SecurityFocus>/title>
>link>http://www.securityfocus.com/rss/index.shtml>/link>
>description>News, Infocus, Columns, Vulnerabilities, Bugtraq ...>/description>
>/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>VulnWatch>/title>
    >link>http://seclists.org/#vulnwatch>/link>
    >description>A non-discussion, non-patch, all-vulnerability annoucement list supported and run by a community of volunteer moderators distributed around the world.>/description>
>/channel>
>/rss>
>rss version="2.0">
>channel>
    >title>Web App Security>/title>
    >link>http://seclists.org/#webappsec>/link>
    >description>Provides insights on the unique challenges which make web applications notoriously hard to secure, as well as attack methods including SQL injection, cross-site scripting (XSS), cross-site request forgery, and more.>/description>
  >item>
    >title>Re: Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/42>/link>
    >description>&lt;p&gt;Posted by Yu Qu on Mar 08&lt;/p&gt;Hi, Peine and others:&lt;br&gt;
Ministry of Education Key Lab for Intelligent...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>RE: [WEB SECURITY] Re: Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/41>/link>
    >description>&lt;p&gt;Posted by Calderon, Juan Carlos (GE, Corporate, consultant) on Mar 08&lt;/p&gt;Yeah, Steve's is just a nice approach, my experience is the same, you&lt;br&gt;
To:...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/40>/link>
    >description>&lt;p&gt;Posted by Morgan Reed on Mar 08&lt;/p&gt;Sounds like the right approach, though I'm not aware of any Java based CMS.&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: [WEB SECURITY] Re: Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/39>/link>
    >description>&lt;p&gt;Posted by Steve Pinkham on Mar 08&lt;/p&gt;Rogan Dawes wrote:&lt;br&gt;
 &amp;gt;...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Security BSides Austin - sponsors needed!>/title>
    >link>http://seclists.org/webappsec/2010/q1/38>/link>
    >description>&lt;p&gt;Posted by Benjamin Tomhave on Mar 08&lt;/p&gt;Hi folks,&lt;br&gt;
become officially...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/37>/link>
    >description>&lt;p&gt;Posted by Marc-André Laverdière on Mar 08&lt;/p&gt;You can have a try at Securibench. Some of the apps in there don't run without &lt;br&gt;
It's Finally Here - The Cenzic Website HealthCheck....&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/36>/link>
    >description>&lt;p&gt;Posted by Federico Maggi on Mar 08&lt;/p&gt;        OWASP's WebGoat Project has designed a non-trivial web application in Java, exactly for this purpose.&lt;br&gt;
--------------------------------------&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/35>/link>
    >description>&lt;p&gt;Posted by Kvetch on Mar 08&lt;/p&gt;Check out Daffodil CRM - &lt;a  rel=&quot;nofollow&quot; href=&quot;http://sourceforge.net/projects/daffodilcrm/&quot;&gt;http://sourceforge.net/projects/daffodilcrm/&lt;/a&gt;&lt;br&gt;
--------------------------------------&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/34>/link>
    >description>&lt;p&gt;Posted by Wagner Elias on Mar 08&lt;/p&gt;OWASP Broken Web App Project contains WebGoat an app vulnerable in Java.&lt;br&gt;
2010/3/8 Holger Peine &amp;lt;Holger.Peine () fh-hannover de&amp;gt;:&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Need a real Java web application with vulnerabilities>/title>
    >link>http://seclists.org/webappsec/2010/q1/33>/link>
    >description>&lt;p&gt;Posted by Holger Peine on Mar 08&lt;/p&gt;Hello,&lt;br&gt;
-...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>SamuraiWTF 0.8 released>/title>
    >link>http://seclists.org/webappsec/2010/q1/32>/link>
    >description>&lt;p&gt;Posted by Kevin Johnson on Mar 05&lt;/p&gt;Hi all,&lt;br&gt;
cell: 904.403.8024&lt;br&gt;>/description>
  >/item>
  >item>
    >title>removing version identifying attribution data>/title>
    >link>http://seclists.org/webappsec/2010/q1/31>/link>
    >description>&lt;p&gt;Posted by Robin Wood on Mar 04&lt;/p&gt;With a lot of open source web apps there is usually some kind of file&lt;br&gt;
rather not expose my clients to data leakage which I...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Vulnerabilities Animated Clips>/title>
    >link>http://seclists.org/webappsec/2010/q1/30>/link>
    >description>&lt;p&gt;Posted by Maty Siman on Mar 03&lt;/p&gt;One of the biggest challenges of the security community is to build true&lt;br&gt;
help developers understand a...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Advanced PHP Hacking>/title>
    >link>http://seclists.org/webappsec/2010/q1/29>/link>
    >description>&lt;p&gt;Posted by Laurent OUDOT at TEHTRI-Security on Mar 03&lt;/p&gt;Hi,&lt;br&gt;
deeper down to your...&lt;br&gt;>/description>
  >/item>
  >item>
    >title>Re: Cookie Secure Attribute - Clarification>/title>
    >link>http://seclists.org/webappsec/2010/q1/28>/link>
    >description>&lt;p&gt;Posted by 51l3n73y3s on Mar 01&lt;/p&gt;I would make the attribute as Secure and then also set the requireSSL of the &lt;br&gt;
This list is...&lt;br&gt;>/description>
  >/item>
>/channel>
>/rss>
>rss version="2.0">
>channel>
>/channel>
>/rss>
</BODY>
