<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
 <title>SecuriTeam</title>
 <link>http://www.securiteam.com</link>
 <description>Welcome to the SecuriTeam RSS Feed - sponsored by Beyond Security. Know Your Vulnerabilities! Visit BeyondSecurity.com for your web site, network and code security audit and scanning needs.</description>
 <language>en</language>
 <copyright>Copyright 1998-2010, SecuriTeam.com</copyright>
 <image>
  <title>SecuriTeam.com</title>
  <url>http://www.securiteam.com/beyond-logo-small.png</url>
  <link>http://www.securiteam.com</link>
 </image>

 <item>
  <title>LedgerSMB Multiple Vulnerabilities</title>
  <link>http://www.securiteam.com/securitynews/5EP3H1P0AU.html</link>
  <description><![CDATA[It has been brought to our attention that a number of security vulnerabilities have been noted in SQL-Ledger.  Several of these affect earlier versions of LedgerSMB, and three hotfixes have been released for problems that continue to affect the LedgerSMB codebase.]]></description>
  <content:encoded><![CDATA[It has been brought to our attention that a number of security vulnerabilities have been noted in SQL-Ledger.  Several of these affect earlier versions of LedgerSMB, and three hotfixes have been released for problems that continue to affect the LedgerSMB codebase. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securitynews/5EP3H1P0AU.html</guid>
  <pubDate>Tue, 26 Jan 2010 01:24 GMT</pubDate>
 </item>

 <item>
  <title>Kaspersky Lab Multiple Products Local Privilege Escalation Vulnerability</title>
  <link>http://www.securiteam.com/securitynews/5RP2W150AC.html</link>
  <description><![CDATA[Insecure permissions have been detected in the multiple Kaspersky Lab antivirus products.]]></description>
  <content:encoded><![CDATA[Insecure permissions have been detected in the multiple Kaspersky Lab antivirus products. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securitynews/5RP2W150AC.html</guid>
  <pubDate>Mon, 04 Jan 2010 19:26 GMT</pubDate>
 </item>

 <item>
  <title>Piwik Cookie Unserialize Vulnerability</title>
  <link>http://www.securiteam.com/securitynews/6H00B0AQAS.html</link>
  <description><![CDATA[Piwik unserializes() user input which allows an attacker to send a carefully crafted cookie that when unserialized utilizes Piwik's classes to upload arbitrary files or execute arbitrary PHP code.]]></description>
  <content:encoded><![CDATA[Piwik unserializes() user input which allows an attacker to send a carefully crafted cookie that when unserialized utilizes Piwik's classes to upload arbitrary files or execute arbitrary PHP code. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securitynews/6H00B0AQAS.html</guid>
  <pubDate>Fri, 11 Dec 2009 19:42 GMT</pubDate>
 </item>

 <item>
  <title>Invision Power Board SQL PHP File Inclusion and SQL Injection</title>
  <link>http://www.securiteam.com/securitynews/6T0022AQAC.html</link>
  <description><![CDATA[Invision Power Board has a PHP file inclusion vulnerability that is trivial to exploit with a web browser and a known location of a php file residing on the target system. Authorisation is not required. The SQL injection vulnerability is somewhat tricky to exploit as there are quite a few restrictions that make creating a successful sql attack vector difficult. Nevertheless a crafty attacker might issue a series of requests that might allow him to gain some information about the target system or even read files from the disk depending on permissions granted to the db account that is used by the forum.]]></description>
  <content:encoded><![CDATA[Invision Power Board has a PHP file inclusion vulnerability that is trivial to exploit with a web browser and a known location of a php file residing on the target system. Authorisation is not required. The SQL injection vulnerability is somewhat tricky to exploit as there are quite a few restrictions that make creating a successful sql attack vector difficult. Nevertheless a crafty attacker might issue a series of requests that might allow him to gain some information about the target system or even read files from the disk depending on permissions granted to the db account that is used by the forum. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securitynews/6T0022AQAC.html</guid>
  <pubDate>Tue, 08 Dec 2009 23:49 GMT</pubDate>
 </item>

 <item>
  <title>U.S. Defense Information Systems Agency (DISA) Unix Security Readiness Review (SRR) Vulnerability</title>
  <link>http://www.securiteam.com/securitynews/6E00420QAS.html</link>
  <description><![CDATA[The U.S. Defense Information Systems Agency (DISA) publishes Security Readiness Review scripts (SRRs) to ensure systems and software meet security baselines required by the Department of Defense.  Unprivileged local users can obtain root access on Unix systems where the DISA SRR scripts are run.]]></description>
  <content:encoded><![CDATA[The U.S. Defense Information Systems Agency (DISA) publishes Security Readiness Review scripts (SRRs) to ensure systems and software meet security baselines required by the Department of Defense.  Unprivileged local users can obtain root access on Unix systems where the DISA SRR scripts are run. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securitynews/6E00420QAS.html</guid>
  <pubDate>Mon, 07 Dec 2009 23:22 GMT</pubDate>
 </item>

 <item>
  <title>Netifera - Modular Open Source Platform for Security Tools</title>
  <link>http://www.securiteam.com/tools/5QP0B0KQUE.html</link>
  <description><![CDATA[]]></description>
  <content:encoded><![CDATA[ <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/tools/5QP0B0KQUE.html</guid>
  <pubDate>Sun, 12 Apr 2009 14:01 GMT</pubDate>
 </item>

 <item>
  <title>WarVOX -  Tools for Exploring, Classifying, and Auditing Telephone Systems</title>
  <link>http://www.securiteam.com/tools/5RP012KQKA.html</link>
  <description><![CDATA[]]></description>
  <content:encoded><![CDATA[ <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/tools/5RP012KQKA.html</guid>
  <pubDate>Mon, 09 Mar 2009 08:59 GMT</pubDate>
 </item>

 <item>
  <title>Webshag - Web Server Audit Tool</title>
  <link>http://www.securiteam.com/tools/5QP0L0UQAI.html</link>
  <description><![CDATA[]]></description>
  <content:encoded><![CDATA[ <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/tools/5QP0L0UQAI.html</guid>
  <pubDate>Mon, 23 Feb 2009 17:28 GMT</pubDate>
 </item>

 <item>
  <title>Browser Fuzzer</title>
  <link>http://www.securiteam.com/tools/5OP0L00Q0Y.html</link>
  <description><![CDATA[]]></description>
  <content:encoded><![CDATA[ <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/tools/5OP0L00Q0Y.html</guid>
  <pubDate>Tue, 20 Jan 2009 14:01 GMT</pubDate>
 </item>

 <item>
  <title>FSpy - Linux Filesystem Activity Monitoring</title>
  <link>http://www.securiteam.com/tools/6D00V0ANFY.html</link>
  <description><![CDATA[]]></description>
  <content:encoded><![CDATA[ <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/tools/6D00V0ANFY.html</guid>
  <pubDate>Wed, 31 Dec 2008 12:04 GMT</pubDate>
 </item>

 <item>
  <title>Publique! CMS and SQL Injection Vulnerabilities</title>
  <link>http://www.securiteam.com/unixfocus/5FP3I1P0AO.html</link>
  <description><![CDATA[A remotely exploitable vulnerability was found in the framework core component. Exploitation of this bug does not require authentication and will lead to remotely exposed potentially sensitive information from the Publique! database. Particularly, an attacker can extract usernames and passwords needed to authenticate to the administrative interface and gain full control of the web site and (depending on certain conditions) the server itself.]]></description>
  <content:encoded><![CDATA[A remotely exploitable vulnerability was found in the framework core component. Exploitation of this bug does not require authentication and will lead to remotely exposed potentially sensitive information from the Publique! database. Particularly, an attacker can extract usernames and passwords needed to authenticate to the administrative interface and gain full control of the web site and (depending on certain conditions) the server itself. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/unixfocus/5FP3I1P0AO.html</guid>
  <pubDate>Tue, 26 Jan 2010 01:44 GMT</pubDate>
 </item>

 <item>
  <title>Files2Links F2L-3000 SQL Injection Vulnerability</title>
  <link>http://www.securiteam.com/unixfocus/5DP3G1P0AA.html</link>
  <description><![CDATA[The login page of the F2L-3000 version 4.0.0 is vulnerable to SQL Injection. Exploitation of the vulnerability may allow attackers to bypass authentication and access sensitive information stored on the device.]]></description>
  <content:encoded><![CDATA[The login page of the F2L-3000 version 4.0.0 is vulnerable to SQL Injection. Exploitation of the vulnerability may allow attackers to bypass authentication and access sensitive information stored on the device. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/unixfocus/5DP3G1P0AA.html</guid>
  <pubDate>Tue, 26 Jan 2010 00:27 GMT</pubDate>
 </item>

 <item>
  <title>HP-UX Running Apache Data Injection and DoS Vulnerability</title>
  <link>http://www.securiteam.com/unixfocus/5QP2V150AO.html</link>
  <description><![CDATA[A potential security vulnerability has been identified with HP-UX running Apache v2.0.59.12 and earlier. The vulnerability could be exploited remotely to inject unauthorized data or to create a Denial of Service (DoS).]]></description>
  <content:encoded><![CDATA[A potential security vulnerability has been identified with HP-UX running Apache v2.0.59.12 and earlier. The vulnerability could be exploited remotely to inject unauthorized data or to create a Denial of Service (DoS). <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/unixfocus/5QP2V150AO.html</guid>
  <pubDate>Mon, 04 Jan 2010 19:20 GMT</pubDate>
 </item>

 <item>
  <title>MIT krb5 KDC denial of service in cross-realm referral processing</title>
  <link>http://www.securiteam.com/unixfocus/5MP2W0K0AK.html</link>
  <description><![CDATA[An unauthenticated remote attacker could cause the KDC to crash due to a null pointer dereference.  Legitimate requests can also cause this crash to occur.]]></description>
  <content:encoded><![CDATA[An unauthenticated remote attacker could cause the KDC to crash due to a null pointer dereference.  Legitimate requests can also cause this crash to occur. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/unixfocus/5MP2W0K0AK.html</guid>
  <pubDate>Sat, 02 Jan 2010 18:51 GMT</pubDate>
 </item>

 <item>
  <title>AproxEngine Multiple Vulnerabilities</title>
  <link>http://www.securiteam.com/unixfocus/5BP2V0A0AG.html</link>
  <description><![CDATA[Vulnerabilities have been discovered in AproxEngine, which can be exploited by malicious users to manipulate certain data, conduct spoofing, SQL injection, and script insertion attacks and by malicious people to conduct SQL injection and script insertion attacks.]]></description>
  <content:encoded><![CDATA[Vulnerabilities have been discovered in AproxEngine, which can be exploited by malicious users to manipulate certain data, conduct spoofing, SQL injection, and script insertion attacks and by malicious people to conduct SQL injection and script insertion attacks. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/unixfocus/5BP2V0A0AG.html</guid>
  <pubDate>Fri, 01 Jan 2010 23:38 GMT</pubDate>
 </item>

 <item>
  <title>Microsoft Indeo Codec Memory Corruption Vulnerability</title>
  <link>http://www.securiteam.com/windowsntfocus/6S00D00QAW.html</link>
  <description><![CDATA[The Indeo codec on systems running Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow code to run on users systems when opening specially crafted content.]]></description>
  <content:encoded><![CDATA[The Indeo codec on systems running Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow code to run on users systems when opening specially crafted content. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/6S00D00QAW.html</guid>
  <pubDate>Thu, 10 Dec 2009 03:07 GMT</pubDate>
 </item>

 <item>
  <title>HP DDMI Execution of Arbitrary Code</title>
  <link>http://www.securiteam.com/windowsntfocus/6T00C2AQ0Y.html</link>
  <description><![CDATA[A potential security vulnerability has been identified with HP Discovery & Dependency Mapping Inventory (DDMI) running on Windows. The vulnerability could be exploited remotely by an authorized user to execute arbitrary code.]]></description>
  <content:encoded><![CDATA[A potential security vulnerability has been identified with HP Discovery & Dependency Mapping Inventory (DDMI) running on Windows. The vulnerability could be exploited remotely by an authorized user to execute arbitrary code. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/6T00C2AQ0Y.html</guid>
  <pubDate>Wed, 18 Nov 2009 19:18 GMT</pubDate>
 </item>

 <item>
  <title>Microsoft Windows License Logging Service Heap Corruption Vulnerability</title>
  <link>http://www.securiteam.com/windowsntfocus/6M00D0UQ0W.html</link>
  <description><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. Authentication is not required on certain configurations to exploit this vulnerability.]]></description>
  <content:encoded><![CDATA[This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. Authentication is not required on certain configurations to exploit this vulnerability. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/6M00D0UQ0W.html</guid>
  <pubDate>Fri, 13 Nov 2009 20:16 GMT</pubDate>
 </item>

 <item>
  <title>Microsoft Office Excel Code Execution Vulnerabilities</title>
  <link>http://www.securiteam.com/windowsntfocus/6K00B0UQ0K.html</link>
  <description><![CDATA[Attackers using specially crafted XLS files can execute arbitrary code via memory corruptions, invalid index, and invalid pointer errors.]]></description>
  <content:encoded><![CDATA[Attackers using specially crafted XLS files can execute arbitrary code via memory corruptions, invalid index, and invalid pointer errors. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/6K00B0UQ0K.html</guid>
  <pubDate>Fri, 13 Nov 2009 19:41 GMT</pubDate>
 </item>

 <item>
  <title>Microsoft SharePoint 2007 ASP.NET Source Code Disclosure</title>
  <link>http://www.securiteam.com/windowsntfocus/6W0040UQ0W.html</link>
  <description><![CDATA[It was found that the download facility of Microsoft SharePoint Team Services can be abused to reveal the source code of ASP.NET files.]]></description>
  <content:encoded><![CDATA[It was found that the download facility of Microsoft SharePoint Team Services can be abused to reveal the source code of ASP.NET files. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/windowsntfocus/6W0040UQ0W.html</guid>
  <pubDate>Tue, 03 Nov 2009 01:51 GMT</pubDate>
 </item>

 <item>
  <title>Trango Broadband Wireless Rogue SU Authentication Bug</title>
  <link>http://www.securiteam.com/exploits/5LP2V0K0AG.html</link>
  <description><![CDATA[Currently there is a flaw in the authentication mechanism of these radios which, if an attacker knows some details, can allow interception of ethernet packets broadcast from the Access Point to the Subscriber Unit and potentially allows injection into the communication from the Subscriber Unit to the Access Point.]]></description>
  <content:encoded><![CDATA[Currently there is a flaw in the authentication mechanism of these radios which, if an attacker knows some details, can allow interception of ethernet packets broadcast from the Access Point to the Subscriber Unit and potentially allows injection into the communication from the Subscriber Unit to the Access Point. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/exploits/5LP2V0K0AG.html</guid>
  <pubDate>Sat, 02 Jan 2010 18:40 GMT</pubDate>
 </item>

 <item>
  <title>Exposing HMS HICP Protocol and Intellicom NetBiterConfig.exe Remote Buffer Overflow</title>
  <link>http://www.securiteam.com/exploits/5CP2W0A0AU.html</link>
  <description><![CDATA[SCADA weaknesses created by HICP Protocol and NetBiter WebSCADA.]]></description>
  <content:encoded><![CDATA[SCADA weaknesses created by HICP Protocol and NetBiter WebSCADA. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/exploits/5CP2W0A0AU.html</guid>
  <pubDate>Fri, 01 Jan 2010 23:52 GMT</pubDate>
 </item>

 <item>
  <title>Family Connections Multiple Remote Vulnerabilities</title>
  <link>http://www.securiteam.com/exploits/6U00D20QAQ.html</link>
  <description><![CDATA[Many fields are not properly sanitised and some checks can be bypassed.]]></description>
  <content:encoded><![CDATA[Many fields are not properly sanitised and some checks can be bypassed. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/exploits/6U00D20QAQ.html</guid>
  <pubDate>Thu, 17 Dec 2009 23:16 GMT</pubDate>
 </item>

 <item>
  <title>VideoCache vccleaner Root Vulnerability</title>
  <link>http://www.securiteam.com/exploits/6T00C20QAY.html</link>
  <description><![CDATA[VideoCache is a Squid URL rewriter plugin written in Python for bandwidth optimization while browsing video sharing websites. Version 1.9.2 allows a user with the privileges of the Squid proxy server to append semi-arbitrary data to arbitrary files with root privileges, upon the administrator's execution of the 'vccleaner' utility.]]></description>
  <content:encoded><![CDATA[VideoCache is a Squid URL rewriter plugin written in Python for bandwidth optimization while browsing video sharing websites. Version 1.9.2 allows a user with the privileges of the Squid proxy server to append semi-arbitrary data to arbitrary files with root privileges, upon the administrator's execution of the 'vccleaner' utility. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/exploits/6T00C20QAY.html</guid>
  <pubDate>Thu, 17 Dec 2009 23:07 GMT</pubDate>
 </item>

 <item>
  <title>QuickHeal Antivirus 2010 Local Privilege Escalation</title>
  <link>http://www.securiteam.com/exploits/6S00B20QAQ.html</link>
  <description><![CDATA[All files under the install folder have Full control for BUILTIN\users and can be replace with malicious files.]]></description>
  <content:encoded><![CDATA[All files under the install folder have Full control for BUILTIN\users and can be replace with malicious files. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/exploits/6S00B20QAQ.html</guid>
  <pubDate>Thu, 17 Dec 2009 22:57 GMT</pubDate>
 </item>

 <item>
  <title>Why Silent Updates Boost Security</title>
  <link>http://www.securiteam.com/securityreviews/5NP0E00R5A.html</link>
  <description><![CDATA[Thomas Duebendorfer Google Switzerland GmbH and Stefan Frei Communication Systems Group, ETH Zurich, Switzerland looked into the performance of Web browser update mechanisms. The analysis of anonymized Google Web server logs allowed us to compare and rank the update strategies deployed by Google Chrome, Mozilla Firefox, Apple Safari, and Opera.]]></description>
  <content:encoded><![CDATA[Thomas Duebendorfer Google Switzerland GmbH and Stefan Frei Communication Systems Group, ETH Zurich, Switzerland looked into the performance of Web browser update mechanisms. The analysis of anonymized Google Web server logs allowed us to compare and rank the update strategies deployed by Google Chrome, Mozilla Firefox, Apple Safari, and Opera. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securityreviews/5NP0E00R5A.html</guid>
  <pubDate>Sun, 10 May 2009 18:35 GMT</pubDate>
 </item>

 <item>
  <title>PDF Silent HTTP Form Repurposing Attacks</title>
  <link>http://www.securiteam.com/securityreviews/5MP0D00R5G.html</link>
  <description><![CDATA[This paper sheds light on a modified approach to triggering web attacks through JavaScript protocol handler in the context of opening a PDF in a browser.]]></description>
  <content:encoded><![CDATA[This paper sheds light on a modified approach to triggering web attacks through JavaScript protocol handler in the context of opening a PDF in a browser. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securityreviews/5MP0D00R5G.html</guid>
  <pubDate>Sun, 10 May 2009 18:29 GMT</pubDate>
 </item>

 <item>
  <title>Frame Pointer Overwrite Demonstration (Linux)</title>
  <link>http://www.securiteam.com/securityreviews/6M0010UNFQ.html</link>
  <description><![CDATA[This paper assumes you have read the proper background information and/or technical details about the above subject. If not, please do so, because this read does not include key concepts but instead technical exploitation examples. That being said, enjoy. Knowledge is power.]]></description>
  <content:encoded><![CDATA[This paper assumes you have read the proper background information and/or technical details about the above subject. If not, please do so, because this read does not include key concepts but instead technical exploitation examples. That being said, enjoy. Knowledge is power. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securityreviews/6M0010UNFQ.html</guid>
  <pubDate>Wed, 03 Dec 2008 16:24 GMT</pubDate>
 </item>

 <item>
  <title>Format String Exploitation Demonstration (Linux)</title>
  <link>http://www.securiteam.com/securityreviews/6E0030KNFO.html</link>
  <description><![CDATA[This paper assumes you have read the proper background information and/or technical details about the above subject. If not, please do so, because this read does not include key concepts but instead technical exploitation examples. That being said, enjoy. Knowledge is power.]]></description>
  <content:encoded><![CDATA[This paper assumes you have read the proper background information and/or technical details about the above subject. If not, please do so, because this read does not include key concepts but instead technical exploitation examples. That being said, enjoy. Knowledge is power. <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securityreviews/6E0030KNFO.html</guid>
  <pubDate>Tue, 02 Dec 2008 16:22 GMT</pubDate>
 </item>

 <item>
  <title>Hacking SOHO Routers</title>
  <link>http://www.securiteam.com/securityreviews/6D00C0KN5S.html</link>
  <description><![CDATA[The purpose of this paper is to outline the security measures being taken by vendors to prevent such attacks in their home routing products, what those security measures accomplish, and where they fall short. We will use existing network tools to examine common vulnerabilities in a range of popular devices and demonstrate weaknesses in the security of those devices; additionally,  we will examine common trends in security measures that have been duplicated across vendors, and examine how those trends help and hinder the security of their devices. In particular, we will examine the following home routers, which are some of the latest offerings from their respective vendors at the time of this writing:&nbsp;* Linksys WRT160N]]></description>
  <content:encoded><![CDATA[The purpose of this paper is to outline the security measures being taken by vendors to prevent such attacks in their home routing products, what those security measures accomplish, and where they fall short. We will use existing network tools to examine common vulnerabilities in a range of popular devices and demonstrate weaknesses in the security of those devices; additionally,  we will examine common trends in security measures that have been duplicated across vendors, and examine how those trends help and hinder the security of their devices. In particular, we will examine the following home routers, which are some of the latest offerings from their respective vendors at the time of this writing:&nbsp;* Linksys WRT160N <p>-</p><p>Make your website safer. Use external <a href="http://www.beyondsecurity.com/penetration-testing.html">penetration testing</a> service. First report ready in one hour!</p>]]></content:encoded>
  <category></category>
  <guid isPermaLink="true">http://www.securiteam.com/securityreviews/6D00C0KN5S.html</guid>
  <pubDate>Wed, 12 Nov 2008 17:54 GMT</pubDate>
 </item>

 </channel>
</rss>
