<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Unixbox Security Engineers &#187; Security Advisor</title>
	<atom:link href="http://unixbox.org/?feed=rss2&#038;author=3" rel="self" type="application/rss+xml" />
	<link>http://unixbox.org</link>
	<description>Ethical Hacking</description>
	<lastBuildDate>Thu, 17 Jun 2010 21:07:54 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Using Social Media to advance our attack.</title>
		<link>http://unixbox.org/?p=124</link>
		<comments>http://unixbox.org/?p=124#comments</comments>
		<pubDate>Fri, 04 Sep 2009 06:48:36 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/?p=124</guid>
		<description><![CDATA[We were asked to check the integrity of a larger financial firm located in Canada. We had a couple of meetings about where the important information was most vulnerable.  After great debate, we decided that the HR department would be our target. They held a lot of SSN and PMI information. As a team we [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=124</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Craigslist Phishing attack</title>
		<link>http://unixbox.org/?p=122</link>
		<comments>http://unixbox.org/?p=122#comments</comments>
		<pubDate>Tue, 25 Aug 2009 22:49:12 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/?p=122</guid>
		<description><![CDATA[What a great attack!  Well done.
During our regular  update and verification of all Craigslist accounts we have not been able to  verify your account information. Either your information has changed or it is  incomplete.
Please login to your account and update your Craigslist account  information:
http://user-accounts-craigslist.org/account.verification/user.account.html
Failure to verify your account may result in [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=122</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cenzic Detects a PHP Restriction Bypass Vulnerability &amp; Updates 3 Other SmartAttacks</title>
		<link>http://unixbox.org/?p=120</link>
		<comments>http://unixbox.org/?p=120#comments</comments>
		<pubDate>Sun, 23 Aug 2009 06:01:35 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/?p=120</guid>
		<description><![CDATA[



Weekly product update – Cenzic detects a PHP Restriction Bypass Vulnerability and enhances 3 SmartAttacks



As of August 21, 2009 Cenzic now detects a PHP &#8216;mail.log&#8217; Configuration Option &#8216;open_basedir&#8217; Restriction Bypass Vulnerability (Bugtraq ID 36007).  PHP is prone to a &#8216;open_basedir&#8217; restriction-bypass vulnerability due to a design error.  Successful exploits could allow an attacker to write [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=120</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hacking Oracle will soon get easier</title>
		<link>http://unixbox.org/?p=118</link>
		<comments>http://unixbox.org/?p=118#comments</comments>
		<pubDate>Sun, 16 Aug 2009 04:03:56 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/?p=118</guid>
		<description><![CDATA[Hackers will soon gain a powerful new tool for breaking into Oracle Corp&#8217;s database, the top-selling business software used by companies to store electronic information.
Security experts have developed an easy-to-use, automated software tool that can remotely break into Oracle databases over the Internet to simulate attacks on computer systems, but cybercrooks can use it for [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=118</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers Use Twitter to Control Botnet</title>
		<link>http://unixbox.org/?p=116</link>
		<comments>http://unixbox.org/?p=116#comments</comments>
		<pubDate>Sat, 15 Aug 2009 05:37:13 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/?p=116</guid>
		<description><![CDATA[Hackers are now using Twitter to send coded update messages to computers they’ve previously infected with rogue code, according to a report from net monitoring firm Arbor Networks.
This looks to be the first reported case of hackers using the popular micro-messaging company to control botnets, which are assemblages of infected PCs that can be directed [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=116</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Password Advice</title>
		<link>http://unixbox.org/?p=112</link>
		<comments>http://unixbox.org/?p=112#comments</comments>
		<pubDate>Thu, 13 Aug 2009 02:44:38 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/?p=112</guid>
		<description><![CDATA[Password Advice
Here&#8217;s some complicated advice on securing passwords that &#8212; I&#8217;ll bet &#8212; no one follows.


DO use a password manager such as those reviewed by Scott Dunn in his Sept. 18, 2008,  Insider Tips column. Although Scott focused on free programs, I really like CallPod&#8217;s Keeper, a $15 utility that comes in Windows, Mac, [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=112</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Businesses Vulnerable to Botnets</title>
		<link>http://unixbox.org/?p=79</link>
		<comments>http://unixbox.org/?p=79#comments</comments>
		<pubDate>Fri, 07 Aug 2009 04:15:48 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/wordpress/?p=79</guid>
		<description><![CDATA[Ten to 25 percent of broadband networks are likely infected by bots, and bots cause 90 percent of spam, according to the Messaging Anti-Abuse Working Group (MAAWG), a coalition of security companies, bandwidth providers, and other interested parties.
MAAWG has issued a report on the problem as well as advice for IT managers, titled &#8220;Messaging Anti-Abuse [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=79</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Security Risks</title>
		<link>http://unixbox.org/?p=78</link>
		<comments>http://unixbox.org/?p=78#comments</comments>
		<pubDate>Fri, 07 Aug 2009 04:12:51 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/wordpress/?p=78</guid>
		<description><![CDATA[Network administrators are besieged today with a growing list of security risks, and analysts warn that too often they get caught up in battling one or two vulnerabilities and remain blind to a league of others.
&#8220;There are so many risks to deal with, it&#8217;s an overwhelming job,&#8221; says Dan Woolley, a vice president at Reston, [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=78</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Policies &#8211; Not Yet As Common As You&#8217;d Think</title>
		<link>http://unixbox.org/?p=76</link>
		<comments>http://unixbox.org/?p=76#comments</comments>
		<pubDate>Fri, 07 Aug 2009 04:10:13 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/wordpress/?p=76</guid>
		<description><![CDATA[Formal security policies are less commonplace in enterprise environments than many people might think. Why are some organizations still dragging their feet, and what might help give security administrators a boost?
In a worldwide study of more than 1,000 IT executives last year, Computer Sciences Corp. (CSC) discovered that 46 percent do not have a formal [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=76</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Unixbox Security Engineers</title>
		<link>http://unixbox.org/?p=60</link>
		<comments>http://unixbox.org/?p=60#comments</comments>
		<pubDate>Thu, 06 Aug 2009 22:38:33 +0000</pubDate>
		<dc:creator>Security Advisor</dc:creator>
				<category><![CDATA[Security Updates]]></category>

		<guid isPermaLink="false">http://unixbox.org/wordpress/?p=60</guid>
		<description><![CDATA[Big corporate layoffs are creating a nightmare of security risks as IT workers scramble to close down network connections and plug up dangerous holes as employees are walked out the door.
For companies like bankrupt energy trader Enron Corp. and now financially embarrassed WorldCom Inc., laying off thousands of employees means there simply may be too [...]]]></description>
		<wfw:commentRss>http://unixbox.org/?feed=rss2&amp;p=60</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
