<?phpxml version="1.0" encoding="utf-8"?>
<rss version="2.0" 
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
>
<channel>
<title>Best of Security / Published News</title>
<link>http://bestofsecurity.net</link>
<description>Best of Security Portal  votes</description>
<pubDate>Fri, 29 Aug 2008 16:00:11 PDT</pubDate>
<language>en</language>
<item>
<title><![CDATA[When Spammers Kill You While You Sleep]]></title>
<link>http://bestofsecurity.net/blogs/When_Spammers_Kill_You_While_You_Sleep/</link>
<comments>http://bestofsecurity.net/blogs/When_Spammers_Kill_You_While_You_Sleep/</comments>
<pubDate>Fri, 29 Aug 2008 16:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/When_Spammers_Kill_You_While_You_Sleep/</guid>
<description><![CDATA[I must admit that I was puzzled for a second when I saw an email with a suicide note as subject line in my spam inbox. I wondered what product they might try to sell with that note or which drive-by download site might be hidden behind it. So, I opened it. The email was actually written like a real suicide note.<br/><br/>94 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Security Bugs Vs. Regular Bugs]]></title>
<link>http://bestofsecurity.net/blogs/Security_Bugs_Vs-_Regular_Bugs/</link>
<comments>http://bestofsecurity.net/blogs/Security_Bugs_Vs-_Regular_Bugs/</comments>
<pubDate>Fri, 29 Aug 2008 16:00:07 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Security_Bugs_Vs-_Regular_Bugs/</guid>
<description><![CDATA[There has been much debate recently that stems from discussions related to Linux kernel development, over whether or not security vulnerabilities should be treated differently than regular software bugs. This has meant there has been a slight departure from the exhausted &quot;full disclosure&quot; debate<br/><br/>200 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Do You Know Where Your Baby Is?]]></title>
<link>http://bestofsecurity.net/blogs/Do_You_Know_Where_Your_Baby_Is/</link>
<comments>http://bestofsecurity.net/blogs/Do_You_Know_Where_Your_Baby_Is/</comments>
<pubDate>Fri, 29 Aug 2008 16:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Do_You_Know_Where_Your_Baby_Is/</guid>
<description><![CDATA[Notice! The virus-spreading spammer doesn't have your baby but is claiming to. In recent emails observed by Symantec, malicious code is being spread by hoax emails claiming to have pictures of your hijacked [sic] baby. The Subject line makes the claim that someone has<br/><br/>52 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Comcast sets monthly bandwidth limit for customers]]></title>
<link>http://bestofsecurity.net/news/Comcast_sets_monthly_bandwidth_limit_for_customers/</link>
<comments>http://bestofsecurity.net/news/Comcast_sets_monthly_bandwidth_limit_for_customers/</comments>
<pubDate>Fri, 29 Aug 2008 13:00:19 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Comcast_sets_monthly_bandwidth_limit_for_customers/</guid>
<description><![CDATA[Comcast, the largest provider of cable-based broadband service in the U.S., will limit residential customers to 250GB of bandwidth a month beginning Oct. 1, the company announced late Thursday.<br/><br/>166 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[FBI Warns of Hit Man Scam Resurgence]]></title>
<link>http://bestofsecurity.net/blogs/FBI_Warns_of_Hit_Man_Scam_Resurgence/</link>
<comments>http://bestofsecurity.net/blogs/FBI_Warns_of_Hit_Man_Scam_Resurgence/</comments>
<pubDate>Fri, 29 Aug 2008 09:00:19 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/FBI_Warns_of_Hit_Man_Scam_Resurgence/</guid>
<description><![CDATA[The FBI is warning people not to be disturbed by an e-mail scam that threatens your life and orders you to pay up to avoid being the target of a hired hit man. The FBI said its Internet Crime Complaint Center continues to receive thousands of reports concerning the hit man e-mail scheme. The FBI notes that while the content of the missive has evolved since similar hit man scams first surfaced in late 20006,...Please click on the title to continue reading this entry.<br/><br/>158 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Cloned US ATM cards: Can they fool Brit self-service checkouts?]]></title>
<link>http://bestofsecurity.net/news/Cloned_US_ATM_cards_Can_they_fool_Brit_self-service_checkouts/</link>
<comments>http://bestofsecurity.net/news/Cloned_US_ATM_cards_Can_they_fool_Brit_self-service_checkouts/</comments>
<pubDate>Fri, 29 Aug 2008 09:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Cloned_US_ATM_cards_Can_they_fool_Brit_self-service_checkouts/</guid>
<description><![CDATA[Carder crooks say they canCybercrooks are targeting self-service checkout systems in UK supermarkets to cash-out compromised US credit and debit card accounts.…<br/><br/>112 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Novell eDirectory Multiple Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Novell_eDirectory_Multiple_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Novell_eDirectory_Multiple_Vulnerabilities/</comments>
<pubDate>Fri, 29 Aug 2008 08:00:35 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Novell_eDirectory_Multiple_Vulnerabilities/</guid>
<description><![CDATA[Multiple vulnerabilities have been reported in Novell eDirectory, where some have an unknown impact and others can be exploited by malicious people to conduct cross-site scripting attacks or to potentially compromise a vulnerable system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft p<br/><br/>125 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Blogn Cross-Site Scripting and Cross-Site Request Forgery]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Blogn_Cross-Site_Scripting_and_Cross-Site_Request_Forgery/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Blogn_Cross-Site_Scripting_and_Cross-Site_Request_Forgery/</comments>
<pubDate>Fri, 29 Aug 2008 08:00:29 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Blogn_Cross-Site_Scripting_and_Cross-Site_Request_Forgery/</guid>
<description><![CDATA[Two vulnerabilities have been reported in Blogn, which can be exploited by malicious people to conduct cross-site scripting and cross-site request forgery attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications <br/><br/>128 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Adium MSN SLP Message Integer Overflow Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Adium_MSN_SLP_Message_Integer_Overflow_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Adium_MSN_SLP_Message_Integer_Overflow_Vulnerabilities/</comments>
<pubDate>Fri, 29 Aug 2008 08:00:20 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Adium_MSN_SLP_Message_Integer_Overflow_Vulnerabilities/</guid>
<description><![CDATA[Some vulnerabilities have been reported in Adium, which potentially can be exploited by malicious people to compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser.<br/><br/>193 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] HP TCP/IP Services for OpenVMS Finger Format String Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_HP_TCPIP_Services_for_OpenVMS_Finger_Format_String_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_HP_TCPIP_Services_for_OpenVMS_Finger_Format_String_Vulnerability/</comments>
<pubDate>Fri, 29 Aug 2008 08:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_HP_TCPIP_Services_for_OpenVMS_Finger_Format_String_Vulnerability/</guid>
<description><![CDATA[Christer Öberg, Claes Nyberg, and James Tusini have reported a vulnerability in HP TCP/IP Services for OpenVMS, which potentially can be exploited by malicious people to compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in upda<br/><br/>137 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Caudium &quot;configvar&quot; Insecure Temporary Files]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Caudium_configvar_Insecure_Temporary_Files/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Caudium_configvar_Insecure_Temporary_Files/</comments>
<pubDate>Fri, 29 Aug 2008 08:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Caudium_configvar_Insecure_Temporary_Files/</guid>
<description><![CDATA[A security issue has been reported in Caudium, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through<br/><br/>105 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] dotProject SQL Injection and Cross-Site Scripting]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_dotProject_SQL_Injection_and_Cross-Site_Scripting/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_dotProject_SQL_Injection_and_Cross-Site_Scripting/</comments>
<pubDate>Fri, 29 Aug 2008 08:00:09 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_dotProject_SQL_Injection_and_Cross-Site_Scripting/</guid>
<description><![CDATA[C1c4Tr1Z has discovered some vulnerabilities in dotProject, which can be exploited by malicious users to conduct SQL injection attacks, and by malicious people to conduct cross-site scripting attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in u<br/><br/>89 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Secunia Weekly Summary - Issue: 2008-35]]></title>
<link>http://bestofsecurity.net/news/ISN_Secunia_Weekly_Summary_-_Issue_2008-35/</link>
<comments>http://bestofsecurity.net/news/ISN_Secunia_Weekly_Summary_-_Issue_2008-35/</comments>
<pubDate>Fri, 29 Aug 2008 07:00:48 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Secunia_Weekly_Summary_-_Issue_2008-35/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Fri, 29 Aug 2008 05:07:57 -0500 (CDT)========================================================================                  The Secunia Weekly Advisory Summary                                          2008-08-21 - 2008-08-28                                               This week: 77 advisories                        ========================================================================Table of Contents:1................................................<br/><br/>130 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] British hacker Gary McKinnon in final appeal to Home Secretary over extradition]]></title>
<link>http://bestofsecurity.net/news/ISN_British_hacker_Gary_McKinnon_in_final_appeal_to_Home_Secretary_over_extradition/</link>
<comments>http://bestofsecurity.net/news/ISN_British_hacker_Gary_McKinnon_in_final_appeal_to_Home_Secretary_over_extradition/</comments>
<pubDate>Fri, 29 Aug 2008 07:00:33 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_British_hacker_Gary_McKinnon_in_final_appeal_to_Home_Secretary_over_extradition/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Fri, 29 Aug 2008 05:07:41 -0500 (CDT)http://business.timesonline.co.uk/tol/business/law/article4628575.eceBy David BrownThe TimesAugust 29, 2008A UFO enthusiast who hacked into top-secret US military computers appealed to the Home Secretary yesterday to stop his extradition after losing a legal appeal.Gary McKinnon is due to be extradited to the United States within two weeks and could face a sentence of up to 80 years in a maximum-security prison if found <br/><br/>114 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Common usernames get more spam]]></title>
<link>http://bestofsecurity.net/news/Common_usernames_get_more_spam/</link>
<comments>http://bestofsecurity.net/news/Common_usernames_get_more_spam/</comments>
<pubDate>Fri, 29 Aug 2008 07:00:10 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Common_usernames_get_more_spam/</guid>
<description><![CDATA[Time to evolve, aardvarksThe use by spammers of dictionary attacks means those whose email address begins with a less common first character are liable to get less spam.…<br/><br/>147 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Cross-site hacks and the art of self defence]]></title>
<link>http://bestofsecurity.net/news/Cross-site_hacks_and_the_art_of_self_defence/</link>
<comments>http://bestofsecurity.net/news/Cross-site_hacks_and_the_art_of_self_defence/</comments>
<pubDate>Fri, 29 Aug 2008 07:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Cross-site_hacks_and_the_art_of_self_defence/</guid>
<description><![CDATA[The new browser warsHackers can force your browser to send requests to any site they want. It's not even hard - all they have to do is get you to view an email or a web page.…<br/><br/>89 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] IBM WebSphere Application Server for z/OS HTTP Server mod_proxy_ftp Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_IBM_WebSphere_Application_Server_for_zOS_HTTP_Server_mod_proxy_ftp_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_IBM_WebSphere_Application_Server_for_zOS_HTTP_Server_mod_proxy_ftp_Vulnerability/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:41 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_IBM_WebSphere_Application_Server_for_zOS_HTTP_Server_mod_proxy_ftp_Vulnerability/</guid>
<description><![CDATA[IBM has acknowledged a vulnerability in IBM WebSphere Application Server for z/OS, which can be exploited by malicious people to conduct cross-site scripting attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applicatio<br/><br/>75 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Red Hat update for libtiff]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_libtiff-1/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_libtiff-1/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:39 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_libtiff-1/</guid>
<description><![CDATA[Red Hat has issued an update for libtiff. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updat<br/><br/>148 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Red Hat update for libtiff]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_libtiff/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_libtiff/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:37 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_libtiff/</guid>
<description><![CDATA[Red Hat has issued an update for libtiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating y<br/><br/>139 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Slackware update for amarok]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Slackware_update_for_amarok/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Slackware_update_for_amarok/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:31 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Slackware_update_for_amarok/</guid>
<description><![CDATA[Slackware has issued an update for amarok. This fixes a security issue, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and ap<br/><br/>129 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] phpMyRealty &quot;price_max&quot; SQL Injection Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_phpMyRealty_price_max_SQL_Injection_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_phpMyRealty_price_max_SQL_Injection_Vulnerability/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:29 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_phpMyRealty_price_max_SQL_Injection_Vulnerability/</guid>
<description><![CDATA[~!Dok_tOR!~ has reported a vulnerability in phpMyRealty, which can be exploited by malicious people to conduct SQL injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. N<br/><br/>51 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[4/5] Novell Forum TCL Command Injection Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/45_Novell_Forum_TCL_Command_Injection_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/45_Novell_Forum_TCL_Command_Injection_Vulnerability/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:25 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/45_Novell_Forum_TCL_Command_Injection_Vulnerability/</guid>
<description><![CDATA[A vulnerability has been reported in Novell Forum, which can be exploited by malicious people to to compromise a vulnerable system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No <br/><br/>133 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[1/5] Sun Solaris Kernel Covert Channel Security Bypass]]></title>
<link>http://bestofsecurity.net/vulnerabilities/15_Sun_Solaris_Kernel_Covert_Channel_Security_Bypass/</link>
<comments>http://bestofsecurity.net/vulnerabilities/15_Sun_Solaris_Kernel_Covert_Channel_Security_Bypass/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:23 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/15_Sun_Solaris_Kernel_Covert_Channel_Security_Bypass/</guid>
<description><![CDATA[A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to bypass certain security restrictions.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your brow<br/><br/>97 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[4/5] Acoustica Mixcraft &quot;.mx4&quot; File Processing Buffer Overflow]]></title>
<link>http://bestofsecurity.net/vulnerabilities/45_Acoustica_Mixcraft_-mx4_File_Processing_Buffer_Overflow/</link>
<comments>http://bestofsecurity.net/vulnerabilities/45_Acoustica_Mixcraft_-mx4_File_Processing_Buffer_Overflow/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:20 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/45_Acoustica_Mixcraft_-mx4_File_Processing_Buffer_Overflow/</guid>
<description><![CDATA[Koshi has discovered a vulnerability in Acoustica Mixcraft, which can be exploited by malicious people to compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. N<br/><br/>98 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[1/5] geo-* Insecure Temporary Files]]></title>
<link>http://bestofsecurity.net/vulnerabilities/15_geo-_Insecure_Temporary_Files/</link>
<comments>http://bestofsecurity.net/vulnerabilities/15_geo-_Insecure_Temporary_Files/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:16 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/15_geo-_Insecure_Temporary_Files/</guid>
<description><![CDATA[Some security issues have been reported in geo-*, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs thro<br/><br/>177 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[1/5] GpsDrive &quot;geo-code&quot; Insecure Temporary Files]]></title>
<link>http://bestofsecurity.net/vulnerabilities/15_GpsDrive_geo-code_Insecure_Temporary_Files/</link>
<comments>http://bestofsecurity.net/vulnerabilities/15_GpsDrive_geo-code_Insecure_Temporary_Files/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/15_GpsDrive_geo-code_Insecure_Temporary_Files/</guid>
<description><![CDATA[A security issue has been reported in GpsDrive, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs throug<br/><br/>130 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Fog of attack clouds Best Western hack]]></title>
<link>http://bestofsecurity.net/news/Fog_of_attack_clouds_Best_Western_hack/</link>
<comments>http://bestofsecurity.net/news/Fog_of_attack_clouds_Best_Western_hack/</comments>
<pubDate>Fri, 29 Aug 2008 05:00:06 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Fog_of_attack_clouds_Best_Western_hack/</guid>
<description><![CDATA[Are you local? Really?Analysis Conflicting claims by Best Western and Glasgow's Sunday Herald over the scope of a recent security breach have been put under the microscope by security watchers. The paper claims that eight million records were potentially exposed, while the hotel insists only ten records were accessed.…<br/><br/>151 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[4/5] Ultra Office ActiveX Control Multiple Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/45_Ultra_Office_ActiveX_Control_Multiple_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/45_Ultra_Office_ActiveX_Control_Multiple_Vulnerabilities/</comments>
<pubDate>Fri, 29 Aug 2008 02:00:07 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/45_Ultra_Office_ActiveX_Control_Multiple_Vulnerabilities/</guid>
<description><![CDATA[shinnai has reported some vulnerabilities in Ultra Office Control, which can be exploited by malicious people to compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs throug<br/><br/>188 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Apple promises September fix for iPhone security flaw]]></title>
<link>http://bestofsecurity.net/news/Apple_promises_September_fix_for_iPhone_security_flaw/</link>
<comments>http://bestofsecurity.net/news/Apple_promises_September_fix_for_iPhone_security_flaw/</comments>
<pubDate>Thu, 28 Aug 2008 21:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Apple_promises_September_fix_for_iPhone_security_flaw/</guid>
<description><![CDATA[A recently discovered security flaw that would allow access to a locked iPhone will be fixed next month, Apple said on Thursday.<br/><br/>123 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Accused British Hacker Gary McKinnon Loses Appeal to Block Extradition]]></title>
<link>http://bestofsecurity.net/news/Accused_British_Hacker_Gary_McKinnon_Loses_Appeal_to_Block_Extradition/</link>
<comments>http://bestofsecurity.net/news/Accused_British_Hacker_Gary_McKinnon_Loses_Appeal_to_Block_Extradition/</comments>
<pubDate>Thu, 28 Aug 2008 19:00:39 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Accused_British_Hacker_Gary_McKinnon_Loses_Appeal_to_Block_Extradition/</guid>
<description><![CDATA[A British man accused of hacking into U.S. military computers lost a major court battle today and could be extradited to the United States within weeks. Gary McKinnon is alleged to have illegally accessed computers belonging to the Pentagon, NASA and the U.S. Army and Navy in 2001 and 2002. McKinnon lost his appeal today to the European Court of Human Rights to block his extradition.   -  A British man accused by the United States of  quot;the biggest military hack of all time quot; lost an appeal on Thurs<br/><br/>74 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[iPhone Security Flaw Exposes Private Data]]></title>
<link>http://bestofsecurity.net/news/iPhone_Security_Flaw_Exposes_Private_Data/</link>
<comments>http://bestofsecurity.net/news/iPhone_Security_Flaw_Exposes_Private_Data/</comments>
<pubDate>Thu, 28 Aug 2008 19:00:24 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/iPhone_Security_Flaw_Exposes_Private_Data/</guid>
<description><![CDATA[A security flaw in the Apple iPhone allows unauthorized users to gain easy access to private contacts and e-mails even when the device is locked, but the company said a fix is on the way. Popular technology blog Gizmodo and an online forum run by the Mac Rumors site showed that it took only three taps to gain access to locked iPhones, which run the latest 2.02 Apple iPhone software. A spokeswoman said in an e-mail that Apple was aware of the problem and was readying a software update to fix it. In the mean<br/><br/>103 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Internet Explorer 8 Beta 2 Privacy Features Win User Support]]></title>
<link>http://bestofsecurity.net/news/Internet_Explorer_8_Beta_2_Privacy_Features_Win_User_Support/</link>
<comments>http://bestofsecurity.net/news/Internet_Explorer_8_Beta_2_Privacy_Features_Win_User_Support/</comments>
<pubDate>Thu, 28 Aug 2008 19:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Internet_Explorer_8_Beta_2_Privacy_Features_Win_User_Support/</guid>
<description><![CDATA[Microsoft Internet Explorer 8 Beta 2 includes a number of security and privacy features that allow it to keep pace with competing browsers such as Firefox and Safari. Many users of Internet Explorer seem to appreciate Microsoft's privacy protections, which are designed to protect users' browsing information. The most talked-about features are InPrivate Browsing and InPrivate Blocking.   -  Much has been made of the new security features in MicrosoftInternet Explorer 8 Beta 2. As users and testers bang on t<br/><br/>194 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Report Slams U.S. Host as Major Source of Badware]]></title>
<link>http://bestofsecurity.net/blogs/Report_Slams_U-S-_Host_as_Major_Source_of_Badware/</link>
<comments>http://bestofsecurity.net/blogs/Report_Slams_U-S-_Host_as_Major_Source_of_Badware/</comments>
<pubDate>Thu, 28 Aug 2008 17:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/Report_Slams_U-S-_Host_as_Major_Source_of_Badware/</guid>
<description><![CDATA[Last week, I examined a series of Web services that make profiting from cyber crime a point-and-click exercise that even the most novice hackers can master. Today, I'd like to highlight the activities of Atrivo, a Concord, Calif., based network provider that hosts some of these services. Several noted security researchers are releasing a report today that stems from many months of investigating malicious activity emanating from Atrivo's customers. Security experts say that Atrivo, also...Please click on th<br/><br/>151 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Nortel uses USB drive to secure remote work]]></title>
<link>http://bestofsecurity.net/news/Nortel_uses_USB_drive_to_secure_remote_work/</link>
<comments>http://bestofsecurity.net/news/Nortel_uses_USB_drive_to_secure_remote_work/</comments>
<pubDate>Thu, 28 Aug 2008 13:00:16 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Nortel_uses_USB_drive_to_secure_remote_work/</guid>
<description><![CDATA[Nortel hopes to tackle the security of remote work with an &amp;quot;office on a stick,&amp;quot; a USB drive that can link an employee&amp;#39;s PC with a corporate VPN and keep all the information from a session encrypted.<br/><br/>177 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[European court won't stop U.K. hacker's extradition to U.S.]]></title>
<link>http://bestofsecurity.net/news/European_court_wont_stop_U-K-_hackers_extradition_to_U-S-/</link>
<comments>http://bestofsecurity.net/news/European_court_wont_stop_U-K-_hackers_extradition_to_U-S-/</comments>
<pubDate>Thu, 28 Aug 2008 13:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/European_court_wont_stop_U-K-_hackers_extradition_to_U-S-/</guid>
<description><![CDATA[The European Court of Human Rights has refused U.K. hacker Gary McKinnon&amp;#39;s appeal against demands for his extradition to the U.S.<br/><br/>98 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[McAfee SiteAdvisor sued over 'spyware' tag]]></title>
<link>http://bestofsecurity.net/news/McAfee_SiteAdvisor_sued_over_spyware_tag/</link>
<comments>http://bestofsecurity.net/news/McAfee_SiteAdvisor_sued_over_spyware_tag/</comments>
<pubDate>Thu, 28 Aug 2008 13:00:04 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/McAfee_SiteAdvisor_sued_over_spyware_tag/</guid>
<description><![CDATA[If 7Search wins, you loseIn a case that could tie the hands of companies trying to protect their customers from internet threats, a website owner with past ties to a notorious piece of spyware has filed a lawsuit claiming it is being unfairly maligned by warnings from McAfee that the site poses a risk to its customers.…<br/><br/>143 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Quick Poll &quot;id&quot; SQL Injection Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Quick_Poll_id_SQL_Injection_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Quick_Poll_id_SQL_Injection_Vulnerability/</comments>
<pubDate>Thu, 28 Aug 2008 08:00:20 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Quick_Poll_id_SQL_Injection_Vulnerability/</guid>
<description><![CDATA[Hussin X has reported a vulnerability in Quick Poll, which can be exploited by malicious people to conduct SQL injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No in<br/><br/>199 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] R &quot;javareconf&quot; Insecure Temporary Files]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_R_javareconf_Insecure_Temporary_Files/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_R_javareconf_Insecure_Temporary_Files/</comments>
<pubDate>Thu, 28 Aug 2008 08:00:18 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_R_javareconf_Insecure_Temporary_Files/</guid>
<description><![CDATA[A security issue has been reported in R, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your <br/><br/>68 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Citadel &quot;migrate_aliases.sh&quot; Insecure Temporary Files]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Citadel_migrate_aliases-sh_Insecure_Temporary_Files/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Citadel_migrate_aliases-sh_Insecure_Temporary_Files/</comments>
<pubDate>Thu, 28 Aug 2008 08:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Citadel_migrate_aliases-sh_Insecure_Temporary_Files/</guid>
<description><![CDATA[A security issue has been discovered in Citadel, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs throu<br/><br/>79 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[1/5] Ampache &quot;gather-messages.sh&quot; Insecure Temporary Files]]></title>
<link>http://bestofsecurity.net/vulnerabilities/15_Ampache_gather-messages-sh_Insecure_Temporary_Files/</link>
<comments>http://bestofsecurity.net/vulnerabilities/15_Ampache_gather-messages-sh_Insecure_Temporary_Files/</comments>
<pubDate>Thu, 28 Aug 2008 08:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/15_Ampache_gather-messages-sh_Insecure_Temporary_Files/</guid>
<description><![CDATA[A security issue has been reported in Ampache, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through<br/><br/>187 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Honeyd &quot;test.sh&quot; Insecure Temporary Files]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Honeyd_test-sh_Insecure_Temporary_Files/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Honeyd_test-sh_Insecure_Temporary_Files/</comments>
<pubDate>Thu, 28 Aug 2008 08:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Honeyd_test-sh_Insecure_Temporary_Files/</guid>
<description><![CDATA[A security issue has been reported in Honeyd, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through <br/><br/>79 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[1/5] Tiger &quot;genmsgidx&quot; Insecure Temporary Files]]></title>
<link>http://bestofsecurity.net/vulnerabilities/15_Tiger_genmsgidx_Insecure_Temporary_Files/</link>
<comments>http://bestofsecurity.net/vulnerabilities/15_Tiger_genmsgidx_Insecure_Temporary_Files/</comments>
<pubDate>Thu, 28 Aug 2008 08:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/15_Tiger_genmsgidx_Insecure_Temporary_Files/</guid>
<description><![CDATA[A security issue has been reported in Tiger, which can be exploited by malicious, local users to perform certain actions with escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through y<br/><br/>83 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] HP-UX update for Apache]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_HP-UX_update_for_Apache-1/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_HP-UX_update_for_Apache-1/</comments>
<pubDate>Thu, 28 Aug 2008 08:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_HP-UX_update_for_Apache-1/</guid>
<description><![CDATA[HP has issued an update for Apache. This fixes a vulnerability, which potentially can be exploited by malicious people to cause a DoS (Denial of Service).Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs th<br/><br/>174 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Taiwan busts hacking ring]]></title>
<link>http://bestofsecurity.net/news/ISN_Taiwan_busts_hacking_ring/</link>
<comments>http://bestofsecurity.net/news/ISN_Taiwan_busts_hacking_ring/</comments>
<pubDate>Thu, 28 Aug 2008 07:00:57 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Taiwan_busts_hacking_ring/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Thu, 28 Aug 2008 00:33:55 -0500 (CDT)http://www.theinquirer.net/gb/inquirer/news/2008/08/27/taiwan-busts-hacking-ringBy Egan OrionThe Inquirer27 August 2008INSPECTOR KNACKER of the Taiwan yard has swooped down on a ring of cyber-thiefs who had been targeting government and corporate data stores.The six individuals arrested allegedly had attacked various government agencies, state-run companies, telecom corporations and a television shopping network.Investig<br/><br/>65 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Security hole opens up password protected iPhones]]></title>
<link>http://bestofsecurity.net/news/ISN_Security_hole_opens_up_password_protected_iPhones/</link>
<comments>http://bestofsecurity.net/news/ISN_Security_hole_opens_up_password_protected_iPhones/</comments>
<pubDate>Thu, 28 Aug 2008 07:00:52 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Security_hole_opens_up_password_protected_iPhones/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Thu, 28 Aug 2008 00:34:06 -0500 (CDT)http://news.cnet.com/8301-1009_3-10027479-83.htmlBy Elinor MillsSecurityCNET NewsAugust 27, 2008A serious security hole in the latest iPhone software exposes e-mail, text, and voice messages to whoever gets a hold of the device despite it being password-protected.Basically, clicking emergency call and double-clicking the &amp;quot;home&amp;quot; button brings up the favorites on iPhone 2.0.2, which opens up the address book, the<br/><br/>133 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Revealed: The Internet's Biggest Security Hole]]></title>
<link>http://bestofsecurity.net/news/ISN_Revealed_The_Internets_Biggest_Security_Hole/</link>
<comments>http://bestofsecurity.net/news/ISN_Revealed_The_Internets_Biggest_Security_Hole/</comments>
<pubDate>Thu, 28 Aug 2008 07:00:47 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Revealed_The_Internets_Biggest_Security_Hole/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Thu, 28 Aug 2008 00:34:28 -0500 (CDT)http://blog.wired.com/27bstroke6/2008/08/revealed-the-in.htmlBy Kim Zetter Threat LevelWired.comAugust 26, 2008Two security researchers have demonstrated a new technique to stealthily intercept internet traffic on a scale previously presumed to be unavailable to anyone outside of intelligence agencies like the National Security Agency.The tactic exploits the internet routing protocol BGP (Border Gateway Protocol) to let <br/><br/>86 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Ubuntu gets major security fix]]></title>
<link>http://bestofsecurity.net/news/ISN_Ubuntu_gets_major_security_fix/</link>
<comments>http://bestofsecurity.net/news/ISN_Ubuntu_gets_major_security_fix/</comments>
<pubDate>Thu, 28 Aug 2008 07:00:42 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Ubuntu_gets_major_security_fix/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Thu, 28 Aug 2008 00:34:17 -0500 (CDT)http://www.vnunet.com/vnunet/news/2224707/ubuntu-gets-major-security-fixBy Shaun Nichols in San Franciscovnunet.com26 Aug 2008Ubuntu users are being advised to update their systems after the release of a patch for the operating system's Linux kernel.The open-source group sent out an advisory to users warning that, if left unpatched, the flaws could allow an attacker execute malicious code or cause a denial of service err<br/><br/>62 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] MIT Lincoln Laboratory software aims to thwart cyber hackers]]></title>
<link>http://bestofsecurity.net/news/ISN_MIT_Lincoln_Laboratory_software_aims_to_thwart_cyber_hackers/</link>
<comments>http://bestofsecurity.net/news/ISN_MIT_Lincoln_Laboratory_software_aims_to_thwart_cyber_hackers/</comments>
<pubDate>Thu, 28 Aug 2008 07:00:29 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_MIT_Lincoln_Laboratory_software_aims_to_thwart_cyber_hackers/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Thu, 28 Aug 2008 00:33:45 -0500 (CDT)http://web.mit.edu/newsoffice/2008/security-0827.htmlMIT NewsAugust 27, 2008In response to the chronic cyber threat of hackers, MIT Lincoln Laboratory researchers are developing a software tool to identify the most vulnerable points in a computer network. The tool aims to make it possible for system administrators to focus on parts of a network that are most prone to attack, instead of securing all parts of the network.U<br/><br/>119 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Red Hat Directory Server Denial of Service Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Red_Hat_Directory_Server_Denial_of_Service_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Red_Hat_Directory_Server_Denial_of_Service_Vulnerabilities/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:29 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Red_Hat_Directory_Server_Denial_of_Service_Vulnerabilities/</guid>
<description><![CDATA[Some vulnerabilities have been reported in Red Hat Directory Server, which can be exploited by malicious people to cause a DoS (Denial of Service).Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through y<br/><br/>185 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Red Hat update for tomcat]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_tomcat/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_tomcat/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:27 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_tomcat/</guid>
<description><![CDATA[Red Hat has issued an update for tomcat. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks, bypass certain security restrictions, or disclose sensitive information.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches <br/><br/>113 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Mono Sys.Web HTTP Header Injection Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Mono_Sys-Web_HTTP_Header_Injection_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Mono_Sys-Web_HTTP_Header_Injection_Vulnerability/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:25 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Mono_Sys-Web_HTTP_Header_Injection_Vulnerability/</guid>
<description><![CDATA[Juraj Skripsky has reported a vulnerability in Mono, which can be exploited by malicious people to conduct HTTP header injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browse<br/><br/>112 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Red Hat update for adminutil]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Red_Hat_update_for_adminutil/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Red_Hat_update_for_adminutil/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:23 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Red_Hat_update_for_adminutil/</guid>
<description><![CDATA[Red Hat has issued an update for adminutil. This fixes some vulnerabilities, which can be exploited by malicious people to conduct cross-site scripting attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * R<br/><br/>113 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Red Hat Directory Server Multiple Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_Directory_Server_Multiple_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_Directory_Server_Multiple_Vulnerabilities/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:21 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_Directory_Server_Multiple_Vulnerabilities/</guid>
<description><![CDATA[Some vulnerabilities have been reported in Red Hat Directory Server, which can be exploited by malicious people to conduct cross-site scripting attacks, cause a DoS (Denial of Service), and potentially compromise a vulnerable system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patch<br/><br/>56 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] CMME Multiple Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_CMME_Multiple_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_CMME_Multiple_Vulnerabilities/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:20 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_CMME_Multiple_Vulnerabilities/</guid>
<description><![CDATA[SirGod has discovered some vulnerabilities and a security issue in CMME (Content Management Made Easy), which can be exploited by malicious people to conduct cross-site scripting attacks and disclose sensitive information.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are appl<br/><br/>75 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Red Hat update for openoffice.org]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_openoffice-org/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_openoffice-org/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_openoffice-org/</guid>
<description><![CDATA[Red Hat has issued an update for openoffice.org. This fixes a vulnerability, which potentially can be exploited by malicious people to compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications *<br/><br/>139 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] OpenOffice &quot;rtl_allocateMemory()&quot; Truncation Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_OpenOffice_rtl_allocateMemory_Truncation_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_OpenOffice_rtl_allocateMemory_Truncation_Vulnerability/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_OpenOffice_rtl_allocateMemory_Truncation_Vulnerability/</guid>
<description><![CDATA[A vulnerability has been reported in OpenOffice, which potentially can be exploited by malicious people to compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. <br/><br/>153 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[French train tickets go USB]]></title>
<link>http://bestofsecurity.net/news/French_train_tickets_go_USB/</link>
<comments>http://bestofsecurity.net/news/French_train_tickets_go_USB/</comments>
<pubDate>Thu, 28 Aug 2008 05:00:04 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/French_train_tickets_go_USB/</guid>
<description><![CDATA[We don't need no stinkin' ISO7816The French National Railway Company is trialling contactless tickets with USB connections, replacing the ubiquitous ISO7816 for online top-ups and data storage.…<br/><br/>71 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[McKinnon heads for the last chance saloon]]></title>
<link>http://bestofsecurity.net/news/McKinnon_heads_for_the_last_chance_saloon/</link>
<comments>http://bestofsecurity.net/news/McKinnon_heads_for_the_last_chance_saloon/</comments>
<pubDate>Thu, 28 Aug 2008 03:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/McKinnon_heads_for_the_last_chance_saloon/</guid>
<description><![CDATA[Pentagon hacker's final appealAccused Pentagon hacker Gary McKinnon is approaching his own D-Day, with his fate due to be sealed in the European Court of Human Rights in Strasbourg.…<br/><br/>64 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[5/5] JustSystems Ichitaro Products Unspecified Code Execution Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/55_JustSystems_Ichitaro_Products_Unspecified_Code_Execution_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/55_JustSystems_Ichitaro_Products_Unspecified_Code_Execution_Vulnerability/</comments>
<pubDate>Thu, 28 Aug 2008 01:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/55_JustSystems_Ichitaro_Products_Unspecified_Code_Execution_Vulnerability/</guid>
<description><![CDATA[A vulnerability has been reported in JustSystems Ichitaro products, which can be exploited by malicious people to compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your br<br/><br/>123 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[4/5] Ubuntu update for yelp]]></title>
<link>http://bestofsecurity.net/vulnerabilities/45_Ubuntu_update_for_yelp/</link>
<comments>http://bestofsecurity.net/vulnerabilities/45_Ubuntu_update_for_yelp/</comments>
<pubDate>Thu, 28 Aug 2008 01:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/45_Ubuntu_update_for_yelp/</guid>
<description><![CDATA[Ubuntu has issued an update for yelp. This fixes a vulnerability, which can be exploited by malicious people to compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your brow<br/><br/>135 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Private Browsing and the Enterprise]]></title>
<link>http://bestofsecurity.net/news/Private_Browsing_and_the_Enterprise/</link>
<comments>http://bestofsecurity.net/news/Private_Browsing_and_the_Enterprise/</comments>
<pubDate>Wed, 27 Aug 2008 19:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Private_Browsing_and_the_Enterprise/</guid>
<description><![CDATA[In an enterprise, privacy is good in moderation. But new hyperprivacy features need IT's control.   -  The rumors were right: Internet Explorer 8 will have new privacy features akin to those in Apple Safari. What role should they play in the enterprise?InPrivate Browsing ( quot;Private Browsing quot; was already taken by Apple) lets the user control whether or not IE saves potentially privacy-rel...   <br/><br/>145 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Apple iPhone Passcode Bypass Made Public]]></title>
<link>http://bestofsecurity.net/news/Apple_iPhone_Passcode_Bypass_Made_Public/</link>
<comments>http://bestofsecurity.net/news/Apple_iPhone_Passcode_Bypass_Made_Public/</comments>
<pubDate>Wed, 27 Aug 2008 19:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Apple_iPhone_Passcode_Bypass_Made_Public/</guid>
<description><![CDATA[The passcode feature on the latest version of Apple's iPhone can be bypassed in a few simple steps. Apple issued a fix for the issue when it released iPhone v1.1.3 back in January. While iPhone users wait for another fix, information about an easy workaround has been made available.   -  The passcode feature on the latest version of  Apples iPhone can be bypassed, potentially allowing an unauthorized person  to access data on the device if it is lost or stolen. The issue was posted to a MacRumors.com discu<br/><br/>166 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[WhiteHat Report Finds Web Site Security Vulnerabilities Persist]]></title>
<link>http://bestofsecurity.net/news/WhiteHat_Report_Finds_Web_Site_Security_Vulnerabilities_Persist/</link>
<comments>http://bestofsecurity.net/news/WhiteHat_Report_Finds_Web_Site_Security_Vulnerabilities_Persist/</comments>
<pubDate>Wed, 27 Aug 2008 19:00:10 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/WhiteHat_Report_Finds_Web_Site_Security_Vulnerabilities_Persist/</guid>
<description><![CDATA[WhiteHat Security's latest report on Web site security shows cross-site scripting remains the most common Web site vulnerability. But cross-site forgery requests also made WhiteHat's list of top 10 Web site security flaws. On a positive note, the majority of the vulnerabilities discovered by WhiteHat were remediated.   -  WhiteHat Security's latest report on Web site vulnerabilities has found theInternet in slightly better shape emphasis on slightly.In the fifth installment of the  quot;WhiteHat Website Se<br/><br/>139 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hackers resort to 'sick' kidnap spam]]></title>
<link>http://bestofsecurity.net/news/Hackers_resort_to_sick_kidnap_spam/</link>
<comments>http://bestofsecurity.net/news/Hackers_resort_to_sick_kidnap_spam/</comments>
<pubDate>Wed, 27 Aug 2008 17:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Hackers_resort_to_sick_kidnap_spam/</guid>
<description><![CDATA[Hackers are claiming they have kidnapped children in a bid to infect PCs with a Trojan Horse virus, says Sophos.<br/><br/>91 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Hijacking huge chunks of the internet - a new How To]]></title>
<link>http://bestofsecurity.net/news/Hijacking_huge_chunks_of_the_internet_-_a_new_How_To/</link>
<comments>http://bestofsecurity.net/news/Hijacking_huge_chunks_of_the_internet_-_a_new_How_To/</comments>
<pubDate>Wed, 27 Aug 2008 15:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Hijacking_huge_chunks_of_the_internet_-_a_new_How_To/</guid>
<description><![CDATA[It's easy. Those tubes are bustedMore evidence that the intertubes are fundamentally broken has been served up by Wired.com in an article laying out a technique to surreptitiously hijack huge chunks of the internet and monitor or even modify unencrypted traffic before it reaches its intended destination.…<br/><br/>155 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Locked iPhones can be unlocked without a password]]></title>
<link>http://bestofsecurity.net/news/Locked_iPhones_can_be_unlocked_without_a_password/</link>
<comments>http://bestofsecurity.net/news/Locked_iPhones_can_be_unlocked_without_a_password/</comments>
<pubDate>Wed, 27 Aug 2008 13:00:26 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Locked_iPhones_can_be_unlocked_without_a_password/</guid>
<description><![CDATA[Private information stored in Apple&amp;#39;s iPhone and protected by a lock code can be accessed by anyone with just a few button presses.<br/><br/>180 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] HP Enterprise Discovery Unspecified Privilege Escalation]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_HP_Enterprise_Discovery_Unspecified_Privilege_Escalation/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_HP_Enterprise_Discovery_Unspecified_Privilege_Escalation/</comments>
<pubDate>Wed, 27 Aug 2008 10:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_HP_Enterprise_Discovery_Unspecified_Privilege_Escalation/</guid>
<description><![CDATA[A vulnerability has been reported in HP Enterprise Discovery, which can be exploited by malicious users to gain escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. N<br/><br/>190 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[White House Imposes New Security Mandate for Federal Agencies]]></title>
<link>http://bestofsecurity.net/blogs/White_House_Imposes_New_Security_Mandate_for_Federal_Agencies/</link>
<comments>http://bestofsecurity.net/blogs/White_House_Imposes_New_Security_Mandate_for_Federal_Agencies/</comments>
<pubDate>Wed, 27 Aug 2008 09:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/White_House_Imposes_New_Security_Mandate_for_Federal_Agencies/</guid>
<description><![CDATA[The Bush administration has ordered all federal agencies to adopt new measures to shore up the security of government Web sites, setting a January 2009 deadline for implementing the changes across all dot-gov domains. Agencies will be required to roll out domain name system security extensions (DNSSEC), a set of security add-ons for the domain name system. DNS is a fundamental piece of the Internet infrastructure that acts as a kind of distributed Internet phone...Please click on the title to continue read<br/><br/>198 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Sharity Unspecified Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Sharity_Unspecified_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Sharity_Unspecified_Vulnerability/</comments>
<pubDate>Wed, 27 Aug 2008 07:01:18 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Sharity_Unspecified_Vulnerability/</guid>
<description><![CDATA[A vulnerability with an unknown impact has been reported in Sharity.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.<br/><br/>80 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] KM Scanner File Utility Multiple Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_KM_Scanner_File_Utility_Multiple_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_KM_Scanner_File_Utility_Multiple_Vulnerabilities/</comments>
<pubDate>Wed, 27 Aug 2008 07:01:16 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_KM_Scanner_File_Utility_Multiple_Vulnerabilities/</guid>
<description><![CDATA[Seth Fogie has reported some vulnerabilities in KM Scanner File Utility, which can be exploited by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, and compromise a vulnerable system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are a<br/><br/>101 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] IBM DB2 CLR Stored Procedures Unspecified Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_IBM_DB2_CLR_Stored_Procedures_Unspecified_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_IBM_DB2_CLR_Stored_Procedures_Unspecified_Vulnerability/</comments>
<pubDate>Wed, 27 Aug 2008 07:01:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_IBM_DB2_CLR_Stored_Procedures_Unspecified_Vulnerability/</guid>
<description><![CDATA[A vulnerability with an unknown impact has been reported in IBM DB2.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No installation or download is required.<br/><br/>121 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] IBM Lotus Quickr Multiple Cross-Site Scripting Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_IBM_Lotus_Quickr_Multiple_Cross-Site_Scripting_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_IBM_Lotus_Quickr_Multiple_Cross-Site_Scripting_Vulnerabilities/</comments>
<pubDate>Wed, 27 Aug 2008 07:01:07 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_IBM_Lotus_Quickr_Multiple_Cross-Site_Scripting_Vulnerabilities/</guid>
<description><![CDATA[Some vulnerabilities have been reported in IBM Lotus Quickr, which can be exploited by malicious people to conduct cross-site scripting attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your<br/><br/>106 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] K-Rate Premium Multiple Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_K-Rate_Premium_Multiple_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_K-Rate_Premium_Multiple_Vulnerabilities/</comments>
<pubDate>Wed, 27 Aug 2008 07:01:04 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_K-Rate_Premium_Multiple_Vulnerabilities/</guid>
<description><![CDATA[Corwin has discovered some vulnerabilities in K-Rate Premium, which can be exploited by malicious users to compromise a vulnerable system, and by malicious people and users to conduct script insertion and SQL injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are<br/><br/>138 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] DriveCrypt Plus Pack Password Disclosure Security Issue]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_DriveCrypt_Plus_Pack_Password_Disclosure_Security_Issue/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_DriveCrypt_Plus_Pack_Password_Disclosure_Security_Issue/</comments>
<pubDate>Wed, 27 Aug 2008 07:01:02 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_DriveCrypt_Plus_Pack_Password_Disclosure_Security_Issue/</guid>
<description><![CDATA[A security issue has been discovered in DriveCrypt Plus Pack, which can be exploited by malicious, local users to disclose sensitive information.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through you<br/><br/>87 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Xoops PopnupBlog Module &quot;index.php&quot; Cross-Site Scripting]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Xoops_PopnupBlog_Module_index-php_Cross-Site_Scripting/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Xoops_PopnupBlog_Module_index-php_Cross-Site_Scripting/</comments>
<pubDate>Wed, 27 Aug 2008 07:00:59 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Xoops_PopnupBlog_Module_index-php_Cross-Site_Scripting/</guid>
<description><![CDATA[Lostmon has discovered two vulnerabilities in the PopnupBlog module for Xoops, which can be exploited by malicious people to conduct cross-site scripting attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications *<br/><br/>96 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] A New Breed Of Hackers Tracks Online Acts of War]]></title>
<link>http://bestofsecurity.net/news/ISN_A_New_Breed_Of_Hackers_Tracks_Online_Acts_of_War/</link>
<comments>http://bestofsecurity.net/news/ISN_A_New_Breed_Of_Hackers_Tracks_Online_Acts_of_War/</comments>
<pubDate>Wed, 27 Aug 2008 07:00:55 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_A_New_Breed_Of_Hackers_Tracks_Online_Acts_of_War/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Wed, 27 Aug 2008 00:28:36 -0500 (CDT)http://www.washingtonpost.com/wp-dyn/content/article/2008/08/26/AR2008082603128.htmlBy Kim HartWashington Post Staff WriterAugust 27, 2008; TORONTO -- Here in the Citizen Lab at the University of Toronto, a new breed of hackers is conducting digital espionage.They are among a growing number of investigators who monitor how traffic is routed through countries, where Web sites are blocked and why it's all happening. Now th<br/><br/>110 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] US data breaches booming in '08]]></title>
<link>http://bestofsecurity.net/news/ISN_US_data_breaches_booming_in_08/</link>
<comments>http://bestofsecurity.net/news/ISN_US_data_breaches_booming_in_08/</comments>
<pubDate>Wed, 27 Aug 2008 07:00:50 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_US_data_breaches_booming_in_08/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Wed, 27 Aug 2008 00:28:27 -0500 (CDT)http://www.theregister.co.uk/2008/08/27/itrc_data_breaches_2008_beat_2007/By Austin Modine The Register27th August 2008The number of personal information leaks reported in the US this year have already exceeded the total amount in all of 2007, San Diego-based Identity Theft Resource Center said today.With four months left in 2008, the firm found that 449 US businesses and government agencies have thus far reported lost o<br/><br/>172 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] PacSec 2008 CFP (Deadline Sept. 1, Conference Nov. 12/13) and BA-Con 2008 Speakers (Sept. 30/ Oct. 1)]]></title>
<link>http://bestofsecurity.net/news/ISN_PacSec_2008_CFP_Deadline_Sept-_1_Conference_Nov-_1213_and_BA-Con_2008_Speakers_Sept-_30_Oct-_1/</link>
<comments>http://bestofsecurity.net/news/ISN_PacSec_2008_CFP_Deadline_Sept-_1_Conference_Nov-_1213_and_BA-Con_2008_Speakers_Sept-_30_Oct-_1/</comments>
<pubDate>Wed, 27 Aug 2008 07:00:47 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_PacSec_2008_CFP_Deadline_Sept-_1_Conference_Nov-_1213_and_BA-Con_2008_Speakers_Sept-_30_Oct-_1/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Wed, 27 Aug 2008 00:29:12 -0500 (CDT)Forwarded from: Dragos Ruiu &amp;lt;dr (at) kyx.net&amp;gt;Spanish url: http://ba-con.com.ar/speakers.html?language=esSpeaker list and Dojos for BA-Con, September 30, October 1st.(all presentations in both Spanish and English)  Presentations:  WPA/WPA2: how long is it gonna make it - Cdric Blancher &amp;amp; Simon   Marchal, EADS &amp;amp; SGDN  Security Concerns of Firmware Updates (SPI System BIOS and Embedded    Controller) - Sun Bin<br/><br/>72 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Attackers Targeting Linux Infrastructures With Rootkit to Steal SSH Keys]]></title>
<link>http://bestofsecurity.net/news/ISN_Attackers_Targeting_Linux_Infrastructures_With_Rootkit_to_Steal_SSH_Keys/</link>
<comments>http://bestofsecurity.net/news/ISN_Attackers_Targeting_Linux_Infrastructures_With_Rootkit_to_Steal_SSH_Keys/</comments>
<pubDate>Wed, 27 Aug 2008 07:00:41 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Attackers_Targeting_Linux_Infrastructures_With_Rootkit_to_Steal_SSH_Keys/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Wed, 27 Aug 2008 00:28:14 -0500 (CDT)http://www.eweek.com/c/a/Security/Attackers-Targeting-Linux-Infrastructures-With-Rootkit-to-Steal-SSH-Keys/By Brian PrinceeWEEK.com2008-08-26 U.S.-CERT is warning of attacks targeting Linux-based infrastructures using compromised SSH keys. After access is gained to the system, local kernel exploits are used to gain root access. A rootkit is then installed to steal more SSH keys. The attack could be related to a flaw affe<br/><br/>77 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Fatah hackers breach Hamas website]]></title>
<link>http://bestofsecurity.net/news/ISN_Fatah_hackers_breach_Hamas_website/</link>
<comments>http://bestofsecurity.net/news/ISN_Fatah_hackers_breach_Hamas_website/</comments>
<pubDate>Wed, 27 Aug 2008 07:00:38 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Fatah_hackers_breach_Hamas_website/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Wed, 27 Aug 2008 00:28:47 -0500 (CDT)http://www.ynetnews.com/articles/0,7340,L-3588203,00.htmlBy Roee Nahmias08.26.08Israel NewsFatah hackers brought down Tuesday a website belonging to Izz al-Din al-Qassam, Hamas' military wing, precisely two months after the site was breached by the Israeli Fanat Al Radical group.&amp;quot;Don't say this is the work of the intelligence services. This is only Fatah youth and the hackers of Palestine,&amp;quot; said a message plant<br/><br/>149 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Virus Infects Space Station Laptops (Again)]]></title>
<link>http://bestofsecurity.net/news/ISN_Virus_Infects_Space_Station_Laptops_Again/</link>
<comments>http://bestofsecurity.net/news/ISN_Virus_Infects_Space_Station_Laptops_Again/</comments>
<pubDate>Wed, 27 Aug 2008 07:00:35 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Virus_Infects_Space_Station_Laptops_Again/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Wed, 27 Aug 2008 00:28:03 -0500 (CDT)http://blog.wired.com/27bstroke6/2008/08/virus-infects-s.htmlBy Ryan Singel Threat LevelWired.comAugust 26, 2008 Viruses intended to steal passwords and send them to a remote server infected laptops in the International Space Station in July, NASA confirmed Tuesday.And according to NASA, this wasn't the first infection.&amp;quot;This is not the first time we have had a worm or a virus,&amp;quot; NASA spokesman Kelly Humphries sa<br/><br/>181 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Needham schools say system was breached]]></title>
<link>http://bestofsecurity.net/news/ISN_Needham_schools_say_system_was_breached/</link>
<comments>http://bestofsecurity.net/news/ISN_Needham_schools_say_system_was_breached/</comments>
<pubDate>Wed, 27 Aug 2008 07:00:29 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Needham_schools_say_system_was_breached/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Wed, 27 Aug 2008 00:28:57 -0500 (CDT)http://www.boston.com/news/education/k_12/articles/2008/08/26/needham_schools_say_system_was_breached/By Peter SchwormGlobe Staff August 26, 2008 A junior at Needham High School posted students' schedules and identification numbers and teachers' classroom rosters on his Facebook account after hacking into an online student information system, school officials said yesterday.In an e-mail sent yesterday morning to high sch<br/><br/>181 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Microsoft dishes dirt on IE8 'pr0n mode']]></title>
<link>http://bestofsecurity.net/news/Microsoft_dishes_dirt_on_IE8_pr0n_mode/</link>
<comments>http://bestofsecurity.net/news/Microsoft_dishes_dirt_on_IE8_pr0n_mode/</comments>
<pubDate>Wed, 27 Aug 2008 05:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Microsoft_dishes_dirt_on_IE8_pr0n_mode/</guid>
<description><![CDATA['Off the record' browsing is goMicrosoft has outlined the new privacy tools available in its forthcoming browser Internet Explorer 8 (IE8).…<br/><br/>182 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[4/5] AWStats Totals Cross-site Scripting and PHP Code Execution]]></title>
<link>http://bestofsecurity.net/vulnerabilities/45_AWStats_Totals_Cross-site_Scripting_and_PHP_Code_Execution/</link>
<comments>http://bestofsecurity.net/vulnerabilities/45_AWStats_Totals_Cross-site_Scripting_and_PHP_Code_Execution/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:39 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/45_AWStats_Totals_Cross-site_Scripting_and_PHP_Code_Execution/</guid>
<description><![CDATA[Emory University has reported some vulnerabilities in AWStats Totals, which can be exploited by malicious people to conduct cross-site scripting attacks or to compromise a vulnerable system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating yo<br/><br/>111 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Kolifa.net Download Script &quot;id&quot; SQL Injection Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Kolifa-net_Download_Script_id_SQL_Injection_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Kolifa-net_Download_Script_id_SQL_Injection_Vulnerability/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:37 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Kolifa-net_Download_Script_id_SQL_Injection_Vulnerability/</guid>
<description><![CDATA[Kacak has reported a vulnerability in Kolifa.net Download Script, which can be exploited by malicious people to conduct SQL injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your b<br/><br/>182 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Red Hat update for kernel]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_kernel/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_kernel/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:34 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_kernel/</guid>
<description><![CDATA[Red Hat has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, disclose potentially sensitive information, cause a DoS (Denial of Service), and potentially gain escalated privileges, and by malicious people to cause a DoS.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspec<br/><br/>156 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Million Pixel Ad Script &quot;id_cat&quot; SQL Injection]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Million_Pixel_Ad_Script_id_cat_SQL_Injection/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Million_Pixel_Ad_Script_id_cat_SQL_Injection/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:30 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Million_Pixel_Ad_Script_id_cat_SQL_Injection/</guid>
<description><![CDATA[Hussin X has reported a vulnerability in Million Pixel Ad Script (Million Pixel Script), which can be exploited by malicious people to conduct SQL injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and application<br/><br/>114 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Debian update for tiff]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Debian_update_for_tiff/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Debian_update_for_tiff/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:23 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Debian_update_for_tiff/</guid>
<description><![CDATA[Debian has issued an update for tiff. This fixes a vulnerability, which can be exploited by malicious people to cause a DoS (Denial of Service) or to potentially compromise a user's system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating you<br/><br/>167 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Red Hat update for ipsec-tools]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_ipsec-tools/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_ipsec-tools/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Red_Hat_update_for_ipsec-tools/</guid>
<description><![CDATA[Red Hat has issued an update for ipsec-tools. This fixes two vulnerabilities, which can be exploited by malicious users and malicious people to cause a DoS (Denial of Service).Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and <br/><br/>92 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] BitlBee Account Recreation Security Issue]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_BitlBee_Account_Recreation_Security_Issue/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_BitlBee_Account_Recreation_Security_Issue/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_BitlBee_Account_Recreation_Security_Issue/</guid>
<description><![CDATA[A security issue has been reported in BitlBee, which can be exploited by malicious people to bypass certain security restrictions and hijack accounts.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs throug<br/><br/>154 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Smart Survey &quot;sid&quot; Cross-Site Scripting Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Smart_Survey_sid_Cross-Site_Scripting_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Smart_Survey_sid_Cross-Site_Scripting_Vulnerability/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:10 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Smart_Survey_sid_Cross-Site_Scripting_Vulnerability/</guid>
<description><![CDATA[Bug Researchers Group has reported a vulnerability in Smart Survey, which can be exploited by malicious people to conduct cross-site scripting attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs throu<br/><br/>137 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[1/5] Sun Solaris NFS RPC Zones Denial of Service]]></title>
<link>http://bestofsecurity.net/vulnerabilities/15_Sun_Solaris_NFS_RPC_Zones_Denial_of_Service/</link>
<comments>http://bestofsecurity.net/vulnerabilities/15_Sun_Solaris_NFS_RPC_Zones_Denial_of_Service/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/15_Sun_Solaris_NFS_RPC_Zones_Denial_of_Service/</guid>
<description><![CDATA[A vulnerability has been reported in Sun Solaris, which can be exploited by malicious, local users to cause a DoS (Denial of Service).Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. <br/><br/>108 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] webEdition CMS &quot;we_objectID&quot; SQL Injection Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_webEdition_CMS_we_objectID_SQL_Injection_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_webEdition_CMS_we_objectID_SQL_Injection_Vulnerability/</comments>
<pubDate>Wed, 27 Aug 2008 04:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_webEdition_CMS_we_objectID_SQL_Injection_Vulnerability/</guid>
<description><![CDATA[Lidloses_Auge has reported a vulnerability in webEdition CMS, which can be exploited by malicious people to conduct SQL injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your brows<br/><br/>168 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[PCI-DSS Version 1.2 - Changes Forthcoming]]></title>
<link>http://bestofsecurity.net/blogs/PCI-DSS_Version_1-2_-_Changes_Forthcoming/</link>
<comments>http://bestofsecurity.net/blogs/PCI-DSS_Version_1-2_-_Changes_Forthcoming/</comments>
<pubDate>Wed, 27 Aug 2008 00:00:04 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/PCI-DSS_Version_1-2_-_Changes_Forthcoming/</guid>
<description><![CDATA[The PCI Security Standards Council has released a summary of changes and clarifications for version 1.2 of the PCI-DSS standard, which is scheduled for release on October 1, 2008. In an effort to combat the growing problem of card theft, the Payment Card Industry Data Security Standard has been established to ensure that through the use of imposed regulations, compromises of customer card data will not be easily possible.<br/><br/>143 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[A recent spam worm analysis]]></title>
<link>http://bestofsecurity.net/blogs/A_recent_spam_worm_analysis/</link>
<comments>http://bestofsecurity.net/blogs/A_recent_spam_worm_analysis/</comments>
<pubDate>Tue, 26 Aug 2008 21:00:15 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>blogs</category>
<guid>http://bestofsecurity.net/blogs/A_recent_spam_worm_analysis/</guid>
<description><![CDATA[Here in the Labs, we've recently discovered a new spam worm spreading. It is usually sent with spam that tries to deceive users into clicking a malicious URL contained in the message. Once clicked, the URL redirects users to malicious Web sites that result in an ActiveX Object error. The intention of this error is to&amp;nbsp;manipulate&amp;nbsp;users to download files infected with a virus. <br/><br/>89 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Four quick tips for choosing an IM security product]]></title>
<link>http://bestofsecurity.net/news/Four_quick_tips_for_choosing_an_IM_security_product/</link>
<comments>http://bestofsecurity.net/news/Four_quick_tips_for_choosing_an_IM_security_product/</comments>
<pubDate>Tue, 26 Aug 2008 21:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Four_quick_tips_for_choosing_an_IM_security_product/</guid>
<description><![CDATA[Instant messaging (IM) has become an increasingly useful business tool for modern corporations. Data from a Forrester Research survey suggests that 71 percent of businesses will invest in real-time messaging this year.<br/><br/>98 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[MessageLabs Buys Image Analysis Vendor for E-Mail Security]]></title>
<link>http://bestofsecurity.net/news/MessageLabs_Buys_Image_Analysis_Vendor_for_E-Mail_Security/</link>
<comments>http://bestofsecurity.net/news/MessageLabs_Buys_Image_Analysis_Vendor_for_E-Mail_Security/</comments>
<pubDate>Tue, 26 Aug 2008 19:00:31 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/MessageLabs_Buys_Image_Analysis_Vendor_for_E-Mail_Security/</guid>
<description><![CDATA[MessageLabs has purchased a provider of image analysis technology to improve its e-mail security offerings. The company says technology from Fortium ICA will help secure e-mail by preventing unauthorized images from entering or leaving enterprise networks.   -  MessageLabs has acquired United Kingdom-based Fortium ICA Limited in a bid to broaden its ability to enforce e-mail security policies  using image composition analysis. The acquisition, made for an undisclosed sum, is intended to strengthen MessageL<br/><br/>144 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Laptop Sold on eBay Exposes 1M Royal Bank of Scotland (RBS), American Express and NatWest Customers]]></title>
<link>http://bestofsecurity.net/news/Laptop_Sold_on_eBay_Exposes_1M_Royal_Bank_of_Scotland_RBS_American_Express_and_NatWest_Customers/</link>
<comments>http://bestofsecurity.net/news/Laptop_Sold_on_eBay_Exposes_1M_Royal_Bank_of_Scotland_RBS_American_Express_and_NatWest_Customers/</comments>
<pubDate>Tue, 26 Aug 2008 19:00:27 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Laptop_Sold_on_eBay_Exposes_1M_Royal_Bank_of_Scotland_RBS_American_Express_and_NatWest_Customers/</guid>
<description><![CDATA[Personal details of more than 1 million customers of Royal Bank of Scotland, American Express and NatWest are found on a computer sold on auction site eBay. RBS said the information included historical data related to credit card applications and data from other banks, but would not disclose further details.The information was being held by archiving firm Graphic Data, which copies paperwork from some of Britain's biggest financial organisations and stores it digitally.   -  LONDON (Reuters) - Account hold<br/><br/>76 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Why Can't Google Stop Malware Ads on Adwords?]]></title>
<link>http://bestofsecurity.net/news/Why_Cant_Google_Stop_Malware_Ads_on_Adwords/</link>
<comments>http://bestofsecurity.net/news/Why_Cant_Google_Stop_Malware_Ads_on_Adwords/</comments>
<pubDate>Tue, 26 Aug 2008 19:00:23 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Why_Cant_Google_Stop_Malware_Ads_on_Adwords/</guid>
<description><![CDATA[There has recently been an unfettered flow of advertising for malicious software on Google's AdWords networks. How come Google can't stop the malware?   -  People make much of technical matters in security, but the most importantforce behind malware is social engineering, not some vulnerability or baddesign. The current hot malware is a textbook case of social engineering and anaggressive marketing campaign.You must have seen them by now: ads f...   <br/><br/>189 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Attackers Targeting Linux Infrastructures With Rootkit to Steal SSH Keys]]></title>
<link>http://bestofsecurity.net/news/Attackers_Targeting_Linux_Infrastructures_With_Rootkit_to_Steal_SSH_Keys/</link>
<comments>http://bestofsecurity.net/news/Attackers_Targeting_Linux_Infrastructures_With_Rootkit_to_Steal_SSH_Keys/</comments>
<pubDate>Tue, 26 Aug 2008 19:00:19 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Attackers_Targeting_Linux_Infrastructures_With_Rootkit_to_Steal_SSH_Keys/</guid>
<description><![CDATA[U.S.-CERT is warning of attacks targeting Linux-based infrastructures using compromised SSH keys. After access is gained to the system, local kernel exploits are used to gain root access. A rootkit is then installed to steal more SSH keys. The attack could be related to a flaw affecting Debian-based encryption keys discovered earlier this year.   -  Hackers are launching attacks against Linux-based computing infrastructures using compromised SSH keys and installing rootkits, according to a warning by the U<br/><br/>169 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[CERT: Linux servers under 'Phalanx' attack]]></title>
<link>http://bestofsecurity.net/news/CERT_Linux_servers_under_Phalanx_attack/</link>
<comments>http://bestofsecurity.net/news/CERT_Linux_servers_under_Phalanx_attack/</comments>
<pubDate>Tue, 26 Aug 2008 19:00:07 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/CERT_Linux_servers_under_Phalanx_attack/</guid>
<description><![CDATA[Stolen keys unlock back doorAttacks in the wild are under way against Linux systems with compromised SSH keys, the US Computer Emergency Readiness Team is warning.…<br/><br/>57 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[US data breaches booming in '08]]></title>
<link>http://bestofsecurity.net/news/US_data_breaches_booming_in_08/</link>
<comments>http://bestofsecurity.net/news/US_data_breaches_booming_in_08/</comments>
<pubDate>Tue, 26 Aug 2008 19:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/US_data_breaches_booming_in_08/</guid>
<description><![CDATA[Have you seen my identity?The number of personal information leaks reported in the US this year have already exceeded the total amount in all of 2007, San Diego-based Identity Theft Resource Center said today.…<br/><br/>180 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Update: U.S. border-crossing database raises concerns]]></title>
<link>http://bestofsecurity.net/news/Update_U-S-_border-crossing_database_raises_concerns/</link>
<comments>http://bestofsecurity.net/news/Update_U-S-_border-crossing_database_raises_concerns/</comments>
<pubDate>Tue, 26 Aug 2008 17:00:14 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Update_U-S-_border-crossing_database_raises_concerns/</guid>
<description><![CDATA[A plan by U.S. Customs and Border Protection (CBP) to collect personal information on every traveler coming into the country and keep that information in a database for 15 years could have huge privacy implications for U.S. residents, one privacy group said.<br/><br/>192 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Call out a phisher, get attacked by malware]]></title>
<link>http://bestofsecurity.net/news/Call_out_a_phisher_get_attacked_by_malware/</link>
<comments>http://bestofsecurity.net/news/Call_out_a_phisher_get_attacked_by_malware/</comments>
<pubDate>Tue, 26 Aug 2008 17:00:11 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Call_out_a_phisher_get_attacked_by_malware/</guid>
<description><![CDATA[Users tired of phishing attacks who retaliate by talking back are being targeted with exploits designed to hijack their computers, a security researcher said Tuesday.<br/><br/>171 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Houston, we have a virus]]></title>
<link>http://bestofsecurity.net/news/Houston_we_have_a_virus/</link>
<comments>http://bestofsecurity.net/news/Houston_we_have_a_virus/</comments>
<pubDate>Tue, 26 Aug 2008 17:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Houston_we_have_a_virus/</guid>
<description><![CDATA[Worm infects International Space Station laptopsA computer worm that ferrets out passwords managed to stow away on laptops aboard the International Space Station, NASA has confirmed. It is not the first time a NASA computer has become infected.…<br/><br/>134 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Scumbags punt Trojan with baby kidnap lure]]></title>
<link>http://bestofsecurity.net/news/Scumbags_punt_Trojan_with_baby_kidnap_lure/</link>
<comments>http://bestofsecurity.net/news/Scumbags_punt_Trojan_with_baby_kidnap_lure/</comments>
<pubDate>Tue, 26 Aug 2008 11:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Scumbags_punt_Trojan_with_baby_kidnap_lure/</guid>
<description><![CDATA[A new lowWith a sick email malware campaign, pond dwelling scumbags are claiming to have kidnapped the children of would-be targets of infection.…<br/><br/>62 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Crypto guru thinks outside the box with Cube attack]]></title>
<link>http://bestofsecurity.net/news/Crypto_guru_thinks_outside_the_box_with_Cube_attack/</link>
<comments>http://bestofsecurity.net/news/Crypto_guru_thinks_outside_the_box_with_Cube_attack/</comments>
<pubDate>Tue, 26 Aug 2008 11:00:03 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Crypto_guru_thinks_outside_the_box_with_Cube_attack/</guid>
<description><![CDATA[Stream ciphers easily split (maybe)Senior cryptologist Adi Shamir is developing a new attack for rooting out potential weaknesses in encryption ciphers, dubbed the Cube Attack.…<br/><br/>124 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Swimage Encore Hardcoded Password Information Disclosure]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Swimage_Encore_Hardcoded_Password_Information_Disclosure/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Swimage_Encore_Hardcoded_Password_Information_Disclosure/</comments>
<pubDate>Tue, 26 Aug 2008 09:00:27 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Swimage_Encore_Hardcoded_Password_Information_Disclosure/</guid>
<description><![CDATA[A security issue has been reported in Swimage Encore, which can be exploited by malicious, local users to disclose potentially sensitive information.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through<br/><br/>111 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] ezContents Multiple Local File Inclusion Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_ezContents_Multiple_Local_File_Inclusion_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_ezContents_Multiple_Local_File_Inclusion_Vulnerabilities/</comments>
<pubDate>Tue, 26 Aug 2008 09:00:24 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_ezContents_Multiple_Local_File_Inclusion_Vulnerabilities/</guid>
<description><![CDATA[Digital Security Research Group have discovered some vulnerabilities in ezContents, which can be exploited by malicious people to disclose sensitive information.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * <br/><br/>140 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] Pluck blog_include_react.php Local File Inclusion]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_Pluck_blog_include_react-php_Local_File_Inclusion/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_Pluck_blog_include_react-php_Local_File_Inclusion/</comments>
<pubDate>Tue, 26 Aug 2008 09:00:23 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_Pluck_blog_include_react-php_Local_File_Inclusion/</guid>
<description><![CDATA[Digital Security Research Group have reported two vulnerabilities in Pluck, which can be exploited by malicious people to disclose sensitive information.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs thr<br/><br/>100 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] BtitTracker / xbtit &quot;info_hash&quot; SQL Injection Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_BtitTracker__xbtit_info_hash_SQL_Injection_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_BtitTracker__xbtit_info_hash_SQL_Injection_Vulnerabilities/</comments>
<pubDate>Tue, 26 Aug 2008 09:00:20 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_BtitTracker__xbtit_info_hash_SQL_Injection_Vulnerabilities/</guid>
<description><![CDATA[InATeam has discovered a vulnerability in BtitTracker (BTI-Tracker) and xbtit, which can be exploited by malicious people to conduct SQL injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs t<br/><br/>130 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] NetBSD PPPoE Packet Processing Tag Length Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_NetBSD_PPPoE_Packet_Processing_Tag_Length_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_NetBSD_PPPoE_Packet_Processing_Tag_Length_Vulnerability/</comments>
<pubDate>Tue, 26 Aug 2008 09:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_NetBSD_PPPoE_Packet_Processing_Tag_Length_Vulnerability/</guid>
<description><![CDATA[A vulnerability has been reported in NetBSD, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applic<br/><br/>99 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] OpenVMS SMGSHR.EXE Buffer Overflow Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_OpenVMS_SMGSHR-EXE_Buffer_Overflow_Vulnerability/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_OpenVMS_SMGSHR-EXE_Buffer_Overflow_Vulnerability/</comments>
<pubDate>Tue, 26 Aug 2008 09:00:13 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_OpenVMS_SMGSHR-EXE_Buffer_Overflow_Vulnerability/</guid>
<description><![CDATA[A vulnerability has been reported in OpenVMS, which can be exploited by malicious, local users to gain escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. No install<br/><br/>161 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Minister warns of national grid hack threat]]></title>
<link>http://bestofsecurity.net/news/Minister_warns_of_national_grid_hack_threat/</link>
<comments>http://bestofsecurity.net/news/Minister_warns_of_national_grid_hack_threat/</comments>
<pubDate>Tue, 26 Aug 2008 09:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Minister_warns_of_national_grid_hack_threat/</guid>
<description><![CDATA[And theft of commercial secretsA UK government minister has warned that cyber-terrorists were attempting to take out the national grid.…<br/><br/>183 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Improved WinDBG opcode searching]]></title>
<link>http://bestofsecurity.net/tools/Improved_WinDBG_opcode_searching-1/</link>
<comments>http://bestofsecurity.net/tools/Improved_WinDBG_opcode_searching-1/</comments>
<pubDate>Tue, 26 Aug 2008 07:00:43 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>tools</category>
<guid>http://bestofsecurity.net/tools/Improved_WinDBG_opcode_searching-1/</guid>
<description><![CDATA[Goaded by some coworkers about the opcode searching functionality of windbg prompted me to add a new option to jutsu today: searchOpcodeYou can search for sets of instructions in conjunction, it will assemble them, providing you the machine code, then search for the instructions in executable memory. Instructions are delimited by pipes. I plan to add some limited wildcard functionality in the near future as well.0:000&gt; !jutsu searchOpcode  pop ecx | pop ecx | ret[J] Searching for:&gt;  pop ecx &gt;  pop ecx &gt;  r<br/><br/>76 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Improved WinDBG opcode searching]]></title>
<link>http://bestofsecurity.net/tools/Improved_WinDBG_opcode_searching/</link>
<comments>http://bestofsecurity.net/tools/Improved_WinDBG_opcode_searching/</comments>
<pubDate>Tue, 26 Aug 2008 07:00:40 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>tools</category>
<guid>http://bestofsecurity.net/tools/Improved_WinDBG_opcode_searching/</guid>
<description><![CDATA[Goaded by some coworkers about the opcode searching functionality of windbg prompted me to add a new option to jutsu today: searchOpcodeYou can search for sets of instructions in conjunction, it will assemble them, providing you the machine code, then search for the instructions in executable memory. Instructions are delimited by pipes. I plan to add some limited wildcard functionality in the near future as well.0:000&gt; !jutsu searchOpcode  pop ecx | pop ecx | ret[J] Searching for:&gt;  pop ecx &gt;  pop ecx &gt;  r<br/><br/>86 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Red Hat hack prompts critical OpenSSH update]]></title>
<link>http://bestofsecurity.net/news/ISN_Red_Hat_hack_prompts_critical_OpenSSH_update/</link>
<comments>http://bestofsecurity.net/news/ISN_Red_Hat_hack_prompts_critical_OpenSSH_update/</comments>
<pubDate>Tue, 26 Aug 2008 07:00:32 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Red_Hat_hack_prompts_critical_OpenSSH_update/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Tue, 26 Aug 2008 04:31:36 -0500 (CDT)http://www.theregister.co.uk/2008/08/22/red_hat_systems_hacked/By John LeydenThe Register22nd August 2008Red Hat has warned that hackers were able to commandeer its systems and tamper with code - but said that since its content distribution was not hit, it is confident that polluted code has not served up to users.The first hint that something was wrong came last week when Fedora rebuilt its systems, a reconstruction tha<br/><br/>125 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Cybersecurity lacking in Africa, official says]]></title>
<link>http://bestofsecurity.net/news/ISN_Cybersecurity_lacking_in_Africa_official_says/</link>
<comments>http://bestofsecurity.net/news/ISN_Cybersecurity_lacking_in_Africa_official_says/</comments>
<pubDate>Tue, 26 Aug 2008 07:00:29 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Cybersecurity_lacking_in_Africa_official_says/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Tue, 26 Aug 2008 04:32:08 -0500 (CDT)http://www.networkworld.com/news/2008/082508-cybersecurity-lacking-in-africa-official.htmlBy Brenda Zulu IDG News Service 08/25/2008 Africa will not realize the benefits of IT without improvements in cybersecurity, the secretary general of the Common Market for Eastern and Southern Africa (COMESA) said today.Speaking at the International Telecommunication Union's (ITU's) regional Cybersecurity Forum being held here this <br/><br/>125 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Personal data of 1m bank customers found on secondhand computer sold on eBay for 35UKP]]></title>
<link>http://bestofsecurity.net/news/ISN_Personal_data_of_1m_bank_customers_found_on_secondhand_computer_sold_on_eBay_for_35UKP/</link>
<comments>http://bestofsecurity.net/news/ISN_Personal_data_of_1m_bank_customers_found_on_secondhand_computer_sold_on_eBay_for_35UKP/</comments>
<pubDate>Tue, 26 Aug 2008 07:00:25 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Personal_data_of_1m_bank_customers_found_on_secondhand_computer_sold_on_eBay_for_35UKP/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Tue, 26 Aug 2008 04:32:50 -0500 (CDT)http://www.dailymail.co.uk/news/article-1049121/Personal-data-1m-bank-customers-secondhand-sold-eBay-35.htmlBy Dan Newlingdailymail.co.uk25th August 2008Personal details of more than a million bank customers have been found on a computer sold on eBay.Highly- sensitive information on American Express, NatWest and Royal Bank of Scotland customers was stored on the machine's hard drive.It includes names, addresses, mobile p<br/><br/>163 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Thousands of cyber attacks each day on key utilities]]></title>
<link>http://bestofsecurity.net/news/ISN_Thousands_of_cyber_attacks_each_day_on_key_utilities/</link>
<comments>http://bestofsecurity.net/news/ISN_Thousands_of_cyber_attacks_each_day_on_key_utilities/</comments>
<pubDate>Tue, 26 Aug 2008 07:00:22 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Thousands_of_cyber_attacks_each_day_on_key_utilities/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Tue, 26 Aug 2008 04:31:55 -0500 (CDT)http://www.timesonline.co.uk/tol/news/uk/crime/article4592677.eceBy Jonathan Richards The TimesAugust 23, 2008Computer networks controlling electricity supplies, telecommunications and banking are being attacked thousands of times a day in a new cyberwar against Britain waged by criminals and terrorists - some of them backed by foreign states - the Government has said.Lord West of Spithead, the Security Minister, told Th<br/><br/>56 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[ISN] Public, private sectors at odds over cyber security]]></title>
<link>http://bestofsecurity.net/news/ISN_Public_private_sectors_at_odds_over_cyber_security/</link>
<comments>http://bestofsecurity.net/news/ISN_Public_private_sectors_at_odds_over_cyber_security/</comments>
<pubDate>Tue, 26 Aug 2008 07:00:17 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/ISN_Public_private_sectors_at_odds_over_cyber_security/</guid>
<description><![CDATA[From: InfoSec News &amp;lt;alerts_at_private&amp;gt;Date: Tue, 26 Aug 2008 04:32:23 -0500 (CDT)http://www.latimes.com/business/la-fi-security26-2008aug26,0,2021258.storyBy Joseph Menn, Los Angeles Times Staff WriterAugust 26, 2008Three very big and very different computer security breaches that have dominated recent headlines did more than show how badly the Internet needs major repairs. They also exposed the huge rift between corporate America and the federal government over who should fix it, cyber-security expe<br/><br/>115 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Accellion File Transfer Appliance &quot;forgot_password.html&quot; Cross-Site Scripting]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Accellion_File_Transfer_Appliance_forgot_password-html_Cross-Site_Scripting/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Accellion_File_Transfer_Appliance_forgot_password-html_Cross-Site_Scripting/</comments>
<pubDate>Tue, 26 Aug 2008 06:00:12 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Accellion_File_Transfer_Appliance_forgot_password-html_Cross-Site_Scripting/</guid>
<description><![CDATA[Eric BEAULIEU has reported a vulnerability in Accellion File Transfer Appliance, which can be exploited by malicious people to conduct cross-site scripting attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications<br/><br/>64 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] TIBCO Hawk Multiple Buffer Overflow Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_TIBCO_Hawk_Multiple_Buffer_Overflow_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_TIBCO_Hawk_Multiple_Buffer_Overflow_Vulnerabilities/</comments>
<pubDate>Tue, 26 Aug 2008 06:00:10 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_TIBCO_Hawk_Multiple_Buffer_Overflow_Vulnerabilities/</guid>
<description><![CDATA[Some vulnerabilities have been reported in multiple TIBCO products, which can be exploited by malicious people to disclose sensitive information, cause a DoS (Denial of Service), or to compromise a vulnerable system.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * <br/><br/>141 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] MiaCMS &quot;id&quot; SQL Injection Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_MiaCMS_id_SQL_Injection_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/35_MiaCMS_id_SQL_Injection_Vulnerabilities/</comments>
<pubDate>Tue, 26 Aug 2008 06:00:08 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/35_MiaCMS_id_SQL_Injection_Vulnerabilities/</guid>
<description><![CDATA[~!Dok_tOR!~ has discovered some vulnerabilities in MiaCMS, which can be exploited by malicious people to conduct SQL injection attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser.<br/><br/>167 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[1/5] Samba &quot;group_mapping.tdb&quot; Insecure Permissions Security Issue]]></title>
<link>http://bestofsecurity.net/vulnerabilities/15_Samba_group_mapping-tdb_Insecure_Permissions_Security_Issue/</link>
<comments>http://bestofsecurity.net/vulnerabilities/15_Samba_group_mapping-tdb_Insecure_Permissions_Security_Issue/</comments>
<pubDate>Tue, 26 Aug 2008 06:00:06 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/15_Samba_group_mapping-tdb_Insecure_Permissions_Security_Issue/</guid>
<description><![CDATA[A security issue has been reported in Samba, which can be exploited by malicious, local users to bypass certain security restrictions.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your browser. <br/><br/>104 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[Best Western plays down impact of hack attack]]></title>
<link>http://bestofsecurity.net/news/Best_Western_plays_down_impact_of_hack_attack/</link>
<comments>http://bestofsecurity.net/news/Best_Western_plays_down_impact_of_hack_attack/</comments>
<pubDate>Tue, 26 Aug 2008 05:00:05 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>news</category>
<guid>http://bestofsecurity.net/news/Best_Western_plays_down_impact_of_hack_attack/</guid>
<description><![CDATA[8 million records? Huh, more like 10Hotel chain Best Western has denied falling victim to a large-scale hacking attack.…<br/><br/>91 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] Ubuntu update for kernel]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_Ubuntu_update_for_kernel-3/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_Ubuntu_update_for_kernel-3/</comments>
<pubDate>Tue, 26 Aug 2008 03:00:22 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_Ubuntu_update_for_kernel-3/</guid>
<description><![CDATA[Ubuntu has issued an update for the kernel. This fixes some vulnerabilities, which can be exploited by malicious, local users to bypass certain security restrictions, cause a DoS (Denial of Service), and potentially gain escalated privileges.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Micros<br/><br/>146 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[2/5] AN Guestbook Cross-Site Scripting Vulnerabilities]]></title>
<link>http://bestofsecurity.net/vulnerabilities/25_AN_Guestbook_Cross-Site_Scripting_Vulnerabilities/</link>
<comments>http://bestofsecurity.net/vulnerabilities/25_AN_Guestbook_Cross-Site_Scripting_Vulnerabilities/</comments>
<pubDate>Tue, 26 Aug 2008 03:00:20 PDT</pubDate>
<dc:creator>Staff</dc:creator>
<category>vulnerabilities</category>
<guid>http://bestofsecurity.net/vulnerabilities/25_AN_Guestbook_Cross-Site_Scripting_Vulnerabilities/</guid>
<description><![CDATA[Some vulnerabilities have been reported in AN Guestbook, which can be exploited by malicious people to conduct cross-site scripting attacks.Be sure to check if your system is missing security updates or have insecure applications installed:http://secunia.com/software_inspector/Feature Overview - The Secunia Software Inspector: * Detects insecure versions of applications installed * Verifies that all Microsoft patches are applied * Assists you in updating your system and applications * Runs through your bro<br/><br/>179 Vote(s) ]]></description>
</item>

<item>
<title><![CDATA[[3/5] LibTIFF LZW Decoder Buffer Underflow Vulnerability]]></title>
<link>http://bestofsecurity.net/vulnerabilities/35_LibTIFF_LZW_Deco