<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/atom10full.xsl" type="text/xsl" media="screen"?><?xml-stylesheet href="http://feeds.feedburner.com/~d/styles/itemcontent.css" type="text/css" media="screen"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>CGISecurity - Website and Application Security News</title>
    
    <link rel="alternate" type="text/html" href="http://www.cgisecurity.net/" />
    <id>tag:typepad.com,2003:weblog-1694854</id>
    <updated>2008-11-19T10:28:12-08:00</updated>
    <subtitle>All things related to website, database, SDL, and application security since 2000.
</subtitle>
    <generator uri="http://www.cgisecurity.com/">CGISecurity</generator>
    <link rel="self" href="http://feeds.feedburner.com/typepad/1216429516s8517/news" type="application/atom+xml" /><entry>
        <title>Automated security testing &amp; its limitations</title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/458676888/automated-secur.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/automated-secur.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58739412</id>
        <published>2008-11-19T10:28:12-08:00</published>
        <updated>2008-11-19T10:28:20-08:00</updated>
        <summary>"The team I work in uses both automated scanners, along with a few humans testing (minimum of 2)… A good tester should know the weaknesses of the automated testers.. The problem with automated testers, is, simply put, they are not human. That is they will not have intuition that a given...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Reviews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Security Tools" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/automated-secur.html</feedburner:origLink></entry>
    <entry>
        <title>Metasploit Framework 3.2 Released</title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/458621274/metasploit-fram.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/metasploit-fram.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58736718</id>
        <published>2008-11-19T09:33:14-08:00</published>
        <updated>2008-11-19T09:34:43-08:00</updated>
        <summary>"Contact: H D Moore FOR IMMEDIATE RELEASE Email: hdm[at]metasploit.com Austin, Texas, November 19th, 2008 -- The Metasploit Projectannounced today the free, world-wide availability of version 3.2 oftheir exploit development and attack framework. The latest versionis provided under a true open source software license (BSD) and is backed by a community-based development...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Security Tools" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/metasploit-fram.html</feedburner:origLink></entry>
    <entry>
        <title>Microsoft to offer free Antivirus</title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/458598305/microsoft-to-of.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/microsoft-to-of.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58735642</id>
        <published>2008-11-19T09:11:06-08:00</published>
        <updated>2008-11-19T09:11:16-08:00</updated>
        <summary>"Microsoft on Tuesday said it plans to kill off its Windows Live OneCare subscription security service in favor of a free offering that will feature a core of essential anti-malware tools while excluding peripheral services, such as PC tune up programs, found in OneCare. The move could help the software maker...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vendors" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Worms" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/microsoft-to-of.html</feedburner:origLink></entry>
    <entry>
        <title>Understanding How to Use the Microsoft's Exploitability Index</title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/457433927/understanding-h.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/understanding-h.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58677488</id>
        <published>2008-11-18T09:58:47-08:00</published>
        <updated>2008-11-18T09:58:55-08:00</updated>
        <summary>"On Oct. 14, 2008, Microsoft added another piece of information to the bulletin summary to better help customers with their risk assessment process: the Exploitability Index. This section is a brief overview to explain how customers can integrate the Exploitability Index with the Severity Rating system into their own risk assessment...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Defense" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="SDL" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vendors" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/understanding-h.html</feedburner:origLink></entry>
    <entry>
        <title>Integrity-178B Secure OS Gets Highest NSA Rating, Goes Commercial </title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/457395726/integrity-178b.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/integrity-178b.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58675712</id>
        <published>2008-11-18T09:22:35-08:00</published>
        <updated>2008-11-18T09:22:43-08:00</updated>
        <summary>"An operating system used in military fighter planes has raised the bar for system security as a new commercial offering, after receiving the highest security rating by a National Security Agency (NSA)-run certification program. Green Hills Software announced that its Integrity-178B operating system was certified as EAL6+ and that the company...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Defense" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/integrity-178b.html</feedburner:origLink></entry>
    <entry>
        <title>MS explains 7-year patch delay</title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/456250285/ms-explains-7-y.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/ms-explains-7-y.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58616494</id>
        <published>2008-11-17T10:03:57-08:00</published>
        <updated>2008-11-17T10:04:21-08:00</updated>
        <summary>"Microsoft has explained why it took seven years to patch a known vulnerability. Fixing the bug earlier would have taken out network applications and potential exploits alike, it explained. Security bulletin MS08-068 fixed a flaw in the SMB (Server Message Block) component of Windows, first demonstrated by Sir Dystic of Cult...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vendors" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/ms-explains-7-y.html</feedburner:origLink></entry>
    <entry>
        <title>Firefox 3.0.4 Released to address multiple security flaws</title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/452044976/firefox-304-rel.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/firefox-304-rel.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58470230</id>
        <published>2008-11-13T10:11:34-08:00</published>
        <updated>2008-11-13T12:43:30-08:00</updated>
        <summary>A handful of security vulnerabilities have been fixed in the latest version of firefox. Fixed in Firefox 3.0.4 MFSA 2008-58 Parsing error in E4X default namespaceMFSA 2008-57 -moz-binding property bypasses security checks on codebase principalsMFSA 2008-56 nsXMLHttpRequest::NotifyEventListeners() same-origin violationMFSA 2008-55 Crash and remote code execution in nsFrameManagerMFSA 2008-54 Buffer overflow in...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Browsers" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/firefox-304-rel.html</feedburner:origLink></entry>
    <entry>
        <title>.NET Framework rootkits - backdoors inside your framework </title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/452000021/net-framework-r.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/net-framework-r.html" thr:count="5" thr:updated="2008-11-14T13:04:27-08:00" />
        <id>tag:typepad.com,2003:post-58466132</id>
        <published>2008-11-13T09:24:51-08:00</published>
        <updated>2008-11-14T13:20:00-08:00</updated>
        <summary>"The paper introduces a new method that enables an attacker to change the.NET language, and to hide malicious code inside its core. It covers various ways to develop rootkits for the .NET framework, sothat every EXE/DLL that runs on a modified Framework will behavedifferently than what it's supposed to do. Code...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Research" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/net-framework-r.html</feedburner:origLink></entry>
    <entry>
        <title>DNS inventor blames wrangling for insecure interweb</title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/451083100/dns-inventor-bl.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/dns-inventor-bl.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58419950</id>
        <published>2008-11-12T12:33:50-08:00</published>
        <updated>2008-11-12T12:33:57-08:00</updated>
        <summary>"DNSSec (Domain Name System Security Extension), which uses digital signatures to guard against forged requests, offers a means of making internet naming systems more secure. But even 15 years after the standard was developed its adoption remains low. Mockapetris blames problems in making the technology easy to deploy, delays in developing...</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/dns-inventor-bl.html</feedburner:origLink></entry>
    <entry>
        <title>Visa Card Features Buttons and Screen to Generate CCV Dynamically</title>
        <link rel="alternate" type="text/html" href="http://feeds.feedburner.com/~r/typepad/1216429516s8517/news/~3/450934703/visa-card-featu.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.net/2008/11/visa-card-featu.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-58412412</id>
        <published>2008-11-12T09:51:07-08:00</published>
        <updated>2008-11-12T12:46:22-08:00</updated>
        <summary>A co worker sent me this link yesterday afternoon. "Using what appears to be Visa's mutant hybrid of a credit card and a pocket calculator, users can enter their PIN into the card itself and have a security code generated on the fly. The method can stop thieves in two ways....</summary>
        <author>
            <name>Robert</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Research" />
        
        


    <feedburner:origLink>http://www.cgisecurity.net/2008/11/visa-card-featu.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 --><!-- nhm:from_kauri -->
