<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>SecuriTeam.com</title>
<link>http://www.securiteam.com</link>
<description>Beyond Security will help you expose your security holes and will show you what the bad guys already know about your hosts and network. Use our Automated Scanning service to perform a full security audit of your site, and find the latest security news and tools on Beyond Security's SecuriTeam web site.</description>
<language>en-us</language>
<copyright>Copyright 1998-2006, SecuriTeam.com</copyright>
<managingEditor>rss@securiteam.com</managingEditor>
<webMaster>rss@securiteam.com</webMaster>

<image>
<title>SecuriTeam.com</title>
<url>http://www.securiteam.com/beyond-logo-small.png</url>
<link>http://www.securiteam.com</link>
</image>

<item>
<title>Cisco BBSM Captive Portal Cross-site Scripting</title>
<link>http://www.securiteam.com/securitynews/5CP0E15OAA.html</link>
<description>A non-persistent XSS vulnerability is present within the AccessCodeStart.asp page. A malicious user may leverage this to possibly gain access client information in captive portal/hotspot locations using this software.</description>
<category>Security News</category>
<guid isPermaLink="true">http://www.securiteam.com/securitynews/5CP0E15OAA.html</guid>
<pubDate>Wed, 14 May 2008 21:39 GMT</pubDate>
</item>

<item>
<title>Cisco Unified Communications Manager Denial of Service Vulnerabilities</title>
<link>http://www.securiteam.com/securitynews/5BP0D15OAU.html</link>
<description>Cisco Unified Communications Manager, formerly Cisco CallManager, contains multiple denial of service (DoS) vulnerabilities that may cause an interruption in voice services, if exploited. These vulnerabilities were discovered internally by Cisco. The following Cisco Unified Communications Manager services are affected:</description>
<category>Security News</category>
<guid isPermaLink="true">http://www.securiteam.com/securitynews/5BP0D15OAU.html</guid>
<pubDate>Wed, 14 May 2008 20:49 GMT</pubDate>
</item>

<item>
<title>Novell eDirectory Unauthenticated Access to SOAP Interface</title>
<link>http://www.securiteam.com/securitynews/5XP0E0KOAU.html</link>
<description>The Novell eDirectory's eMBox utility is vulnerable to unauthenticated attacks.  Successful exploit of this vulnerability could result in DoS or access to local files.</description>
<category>Security News</category>
<guid isPermaLink="true">http://www.securiteam.com/securitynews/5XP0E0KOAU.html</guid>
<pubDate>Mon, 12 May 2008 19:41 GMT</pubDate>
</item>

<item>
<title>Call of Duty Denial of Service</title>
<link>http://www.securiteam.com/securitynews/5WP0D0KOAA.html</link>
<description>Call of Duty 4 (CoD4) is "the most recent and played game of the homonym series created by &lt;A HREF="http://www.infinityward.com">Infinity Ward&lt;/A> with over 15000 internet servers". A vulnerability in the CoD game allows remote attackers to cause the game to crash by sending it malform data.</description>
<category>Security News</category>
<guid isPermaLink="true">http://www.securiteam.com/securitynews/5WP0D0KOAA.html</guid>
<pubDate>Mon, 12 May 2008 19:38 GMT</pubDate>
</item>

<item>
<title>Wonderware SuiteLink Denial of Service Vulnerability</title>
<link>http://www.securiteam.com/securitynews/5GP0320OAA.html</link>
<description>WonderWare is supplier of industrial automation and information software solutions. According to the company's website [1]: "one third of the world's plants run Wonderware software solutions. Having sold more than 500,000 software licenses in over 100,000 plants worldwide, Wonderware has customers in virtually every global industry - including Oil &amp; Gas, Food &amp; Beverage, Utilities, Pharmaceuticals, Electronics, Metals, Automotive and more".</description>
<category>Security News</category>
<guid isPermaLink="true">http://www.securiteam.com/securitynews/5GP0320OAA.html</guid>
<pubDate>Wed, 07 May 2008 09:02 GMT</pubDate>
</item>

<item>
<title>SSL Capable NetCat</title>
<link>http://www.securiteam.com/tools/5RP0O20O0U.html</link>
<category>Tools</category>
<guid isPermaLink="true">http://www.securiteam.com/tools/5RP0O20O0U.html</guid>
<pubDate>Sun, 27 Apr 2008 12:33 GMT</pubDate>
</item>

<item>
<title>ProxyStrike - Active Web Application Proxy</title>
<link>http://www.securiteam.com/tools/5WP092KO0E.html</link>
<category>Tools</category>
<guid isPermaLink="true">http://www.securiteam.com/tools/5WP092KO0E.html</guid>
<pubDate>Wed, 09 Apr 2008 16:13 GMT</pubDate>
</item>

<item>
<title>McGrew Security RAM Dumper</title>
<link>http://www.securiteam.com/tools/5CP020UNPA.html</link>
<category>Tools</category>
<guid isPermaLink="true">http://www.securiteam.com/tools/5CP020UNPA.html</guid>
<pubDate>Mon, 03 Mar 2008 15:04 GMT</pubDate>
</item>

<item>
<title>Creddump - Extracts Credentials from Windows Registry Hives</title>
<link>http://www.securiteam.com/tools/5IP0P1FNFE.html</link>
<category>Tools</category>
<guid isPermaLink="true">http://www.securiteam.com/tools/5IP0P1FNFE.html</guid>
<pubDate>Mon, 25 Feb 2008 19:31 GMT</pubDate>
</item>

<item>
<title>w3af - Web Application Attack and Audit Framework</title>
<link>http://www.securiteam.com/tools/5ZP0G1FNFM.html</link>
<category>Tools</category>
<guid isPermaLink="true">http://www.securiteam.com/tools/5ZP0G1FNFM.html</guid>
<pubDate>Fri, 15 Feb 2008 09:02 GMT</pubDate>
</item>

<item>
<title>Multiple Vendor rdesktop Vulnerabilities</title>
<link>http://www.securiteam.com/unixfocus/5HP0420OAW.html</link>
<description>&lt;A HREF="http://www.rdesktop.org/">rdesktop&lt;/A> is "an open source client that speaks the Remote Desktop Protocol (RDP). This allows Unix-based users to login to Windows Terminal Servers". Multiple vulnerabilities have been found in the rdesktop client, these vulnerabilities could be used to cause the program to execute arbitrary code.</description>
<category>Unix Focus</category>
<guid isPermaLink="true">http://www.securiteam.com/unixfocus/5HP0420OAW.html</guid>
<pubDate>Wed, 07 May 2008 15:16 GMT</pubDate>
</item>

<item>
<title>PHP GENERATE_SEED() Weak Random Number Seed Vulnerability</title>
<link>http://www.securiteam.com/unixfocus/5FP0220OAE.html</link>
<description>"&lt;A HREF="http://www.php.net">PHP&lt;/A> is a widely-used general-purpose scripting language that is especially suited for Web development and can be embedded into HTML." Weak random number seed might lead to security problems in PHP applications using random numbers.</description>
<category>Unix Focus</category>
<guid isPermaLink="true">http://www.securiteam.com/unixfocus/5FP0220OAE.html</guid>
<pubDate>Wed, 07 May 2008 07:48 GMT</pubDate>
</item>

<item>
<title>PHP Multibyte Shell Command Escaping Bypass Vulnerability</title>
<link>http://www.securiteam.com/unixfocus/5EP0120OAI.html</link>
<description>"PHP is a widely-used general-purpose scripting language that is especially suited for Web development and can be embedded into HTML." Several PHP shell locales with support for east asian variable width encodings allow bypassing PHP's shell command escaping functions, safe_mode and disable_functions.</description>
<category>Unix Focus</category>
<guid isPermaLink="true">http://www.securiteam.com/unixfocus/5EP0120OAI.html</guid>
<pubDate>Wed, 07 May 2008 07:45 GMT</pubDate>
</item>

<item>
<title>SugarCRM Community Edition Local File Disclosure Vulnerability</title>
<link>http://www.securiteam.com/unixfocus/5WP0V00O0Y.html</link>
<description>SugarCRM Community Edition is vulnerable to local file contents disclosure This vulnerability can be exploited by a malicious user to disclose potentially sensitive information. The flaw is caused due to a lack of input filtering in the SugarCRM RSS module, which can be exploited to disclose the content of local files.</description>
<category>Unix Focus</category>
<guid isPermaLink="true">http://www.securiteam.com/unixfocus/5WP0V00O0Y.html</guid>
<pubDate>Wed, 30 Apr 2008 14:01 GMT</pubDate>
</item>

<item>
<title>Wordpress Cookie Integrity Protection Vulnerability</title>
<link>http://www.securiteam.com/unixfocus/5FP0L2AO0W.html</link>
<description>An attacker, who is able to register a specially crafted username on a Wordpress 2.5 installation, is able to generate authentication cookies for other chosen accounts.</description>
<category>Unix Focus</category>
<guid isPermaLink="true">http://www.securiteam.com/unixfocus/5FP0L2AO0W.html</guid>
<pubDate>Mon, 28 Apr 2008 14:31 GMT</pubDate>
</item>

<item>
<title>Vulnerability in Microsoft Publisher Allows Code Execution (MS08-027)</title>
<link>http://www.securiteam.com/windowsntfocus/5ZP0B15OAI.html</link>
<description>This security update resolves a privately reported vulnerability in Microsoft Publisher that could allow remote code execution if a user opens a specially crafted Publisher file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</description>
<category>Windows NT</category>
<guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/5ZP0B15OAI.html</guid>
<pubDate>Wed, 14 May 2008 12:04 GMT</pubDate>
</item>

<item>
<title>Microsoft Word CSS Processing Memory Corruption Vulnerability</title>
<link>http://www.securiteam.com/windowsntfocus/5AP0C15OAO.html</link>
<description>Microsoft Word is a word processing application that is distributed with Microsoft Office. Cascading Style Sheets (CSS) is a stylesheet language used to describe the presentation of a document written in a markup language. Remote exploitation of a memory corruption vulnerability in Microsoft Corp.'s Word could allow attackers to execute arbitrary code with the privileges of the logged in user.</description>
<category>Windows NT</category>
<guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/5AP0C15OAO.html</guid>
<pubDate>Wed, 14 May 2008 11:48 GMT</pubDate>
</item>

<item>
<title>Vulnerabilities in Microsoft Word Allows Code Execution (MS08-026)</title>
<link>http://www.securiteam.com/windowsntfocus/5FP0C0UOAC.html</link>
<description>This security update resolves several privately reported vulnerabilities in Microsoft Word that could allow remote code execution if a user opens a specially crafted Word file. An attacker who successfully exploited these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.</description>
<category>Windows NT</category>
<guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/5FP0C0UOAC.html</guid>
<pubDate>Tue, 13 May 2008 21:02 GMT</pubDate>
</item>

<item>
<title>Microsoft Windows I2O Filter Utility Driver (i2omgmt.sys) Local Privilege Escalation Vulnerability</title>
<link>http://www.securiteam.com/windowsntfocus/5EP0B0UOAO.html</link>
<description>Intelligent Input/Output (&lt;A HREF="http://en.wikipedia.org/wiki/I2O">I2O&lt;/A>) is "a defunct computer input/output (I/O) specification. i2omgmt.sys is a Windows driver for the I2O Utility Filter". Local exploitation of an input validation vulnerability within version 5.1.2600.2180 of i2omgmt.sys, as included with Microsoft Corp's Windows XP operating system, could allow an attacker to execute arbitrary code in the context of the kernel.</description>
<category>Windows NT</category>
<guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/5EP0B0UOAO.html</guid>
<pubDate>Tue, 13 May 2008 08:41 GMT</pubDate>
</item>

<item>
<title>Novell eDirectory DoS via HTTP Headers</title>
<link>http://www.securiteam.com/windowsntfocus/5VP0C0KOAG.html</link>
<description>A vulnerability in Novell's eDirectory allows Connection: HTTP headers to be used to cause dhost.exe to consume 100% of a CPU.  Multiple requests submitted can comsume time on all CPUs.</description>
<category>Windows NT</category>
<guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/5VP0C0KOAG.html</guid>
<pubDate>Mon, 12 May 2008 19:33 GMT</pubDate>
</item>

<item>
<title>Intel Centrino 2200BG Wireless Driver Probe Overflow</title>
<link>http://www.securiteam.com/exploits/5FP0N0AO0M.html</link>
<description>A vulnerability in Intel Centrino 220BG Wireless driver allows remote attackers via a malformed beacon packet to cause the driver to overflow an internal buffer which in turn can be used to execute arbitrary code. The following exploit code can be used to test the vulnerability.</description>
<category>Exploit</category>
<guid isPermaLink="true">http://www.securiteam.com/exploits/5FP0N0AO0M.html</guid>
<pubDate>Mon, 21 Apr 2008 19:51 GMT</pubDate>
</item>

<item>
<title>SCO UnixWare pkgadd Local Root (Exploit)</title>
<link>http://www.securiteam.com/exploits/5ZP081PO0C.html</link>
<description>A vulnerability in SCO UnixWare's pkgadd command line program allows local attackers to gain elevated privileges.</description>
<category>Exploit</category>
<guid isPermaLink="true">http://www.securiteam.com/exploits/5ZP081PO0C.html</guid>
<pubDate>Sun, 06 Apr 2008 09:21 GMT</pubDate>
</item>

<item>
<title>SCO UnixWare Reliant HA Local Root (Exploit)</title>
<link>http://www.securiteam.com/exploits/5YP071PO0W.html</link>
<description>A vulnerability in SCO UnixWare's Reliant HA program allows local attackers to overflow an internal buffer in the program causing it to execute arbitrary code.</description>
<category>Exploit</category>
<guid isPermaLink="true">http://www.securiteam.com/exploits/5YP071PO0W.html</guid>
<pubDate>Sun, 06 Apr 2008 09:20 GMT</pubDate>
</item>

<item>
<title>SCO UnixWare Merge mcd Local Root (Exploit)</title>
<link>http://www.securiteam.com/exploits/5XP061PO0Y.html</link>
<description>A vulnerability in SCO UnixWare's Merge mcd command allows local attackers to gain elevated privileges by overflowing an internal buffer used by the program.</description>
<category>Exploit</category>
<guid isPermaLink="true">http://www.securiteam.com/exploits/5XP061PO0Y.html</guid>
<pubDate>Sun, 06 Apr 2008 09:18 GMT</pubDate>
</item>

<item>
<title>TFTP Server for Windows Buffer Overflow (Exploit)</title>
<link>http://www.securiteam.com/exploits/5UP0X0ANPE.html</link>
<description>Multithreaded &lt;A HREF="http://sourceforge.net/projects/tftp-server/">TFTP Server&lt;/A> for "PXEBOOT, Router image load, supports tsize, blksize, Interval and Server Port Ranges, Block Number Rollover for Large Files. Can be installed as Service/daemon. Single Port version also available. Freeware Software Download". A buffer overflow vulnerability has been discovered in the TFTP Server for Windows, this vulnerability allows remote attackers to cause the product to execute arbitrary code.</description>
<category>Exploit</category>
<guid isPermaLink="true">http://www.securiteam.com/exploits/5UP0X0ANPE.html</guid>
<pubDate>Mon, 31 Mar 2008 13:09 GMT</pubDate>
</item>

<item>
<title>Lateral SQL Injection: a New Class of Vulnerability in Oracle</title>
<link>http://www.securiteam.com/securityreviews/5QP0N20O0Y.html</link>
<description>A new class of vulnerabilities have been discovered in Oracle, these vulnerabilities can be exploited through the use of Oracle's ability to allow users to manipluate the way certain internal functions work.</description>
<category>Security Reviews</category>
<guid isPermaLink="true">http://www.securiteam.com/securityreviews/5QP0N20O0Y.html</guid>
<pubDate>Sun, 27 Apr 2008 14:27 GMT</pubDate>
</item>

<item>
<title>Microsoft Windows DNS Stub Resolver Cache Poisoning (MS08-020)</title>
<link>http://www.securiteam.com/securityreviews/5QP022KO1E.html</link>
<description>The Windows DNS stub resolver is a Windows service used by Windows desktop software to resolve DNS names into IP addresses. The DNS stub resolver forwards DNS queries to the DNS server configured for the workstation (or server) and returns the DNS server s response to the requesting software.</description>
<category>Security Reviews</category>
<guid isPermaLink="true">http://www.securiteam.com/securityreviews/5QP022KO1E.html</guid>
<pubDate>Wed, 09 Apr 2008 16:37 GMT</pubDate>
</item>

<item>
<title>Cold Boot Attacks on Disk Encryption</title>
<link>http://www.securiteam.com/securityreviews/5GP0N1FNFU.html</link>
<description>The below linked paper shows that disk encryption, the standard approach to protecting sensitive data on laptops, can be defeated by relatively simple methods. The paper also demonstrates the methods by using them to defeat three popular disk encryption products: BitLocker, which comes with Windows Vista; FileVault, which comes with MacOS X; and dm-crypt, which is used with Linux.</description>
<category>Security Reviews</category>
<guid isPermaLink="true">http://www.securiteam.com/securityreviews/5GP0N1FNFU.html</guid>
<pubDate>Mon, 25 Feb 2008 19:15 GMT</pubDate>
</item>

<item>
<title>OpenBSD DNS Cache Poisoning and Multiple O/S Predictable IP ID Vulnerability</title>
<link>http://www.securiteam.com/securityreviews/5PP0H0UNGW.html</link>
<description>A serious weakness has been discovered in OpenBSD's PRNG, which allows an attacker to predict the next transaction ID (typically up to 8-10 guesses) given a series of consecutive 12-15 transaction IDs.</description>
<category>Security Reviews</category>
<guid isPermaLink="true">http://www.securiteam.com/securityreviews/5PP0H0UNGW.html</guid>
<pubDate>Wed, 13 Feb 2008 12:03 GMT</pubDate>
</item>

<item>
<title>Exploiting WDM Audio Drivers</title>
<link>http://www.securiteam.com/securityreviews/5RP0120N5W.html</link>
<description>For those researchers who are interested in the driver security and also for driver writers, the paper "Exploiting WDM Audio Drivers" has been released.</description>
<category>Security Reviews</category>
<guid isPermaLink="true">http://www.securiteam.com/securityreviews/5RP0120N5W.html</guid>
<pubDate>Mon, 07 Jan 2008 18:55 GMT</pubDate>
</item>

</channel>
</rss>