<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; MJP</title>
	<atom:link href="http://praetorianprefect.com/archives/author/simonprice/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Fri, 16 Mar 2012 05:46:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>May&#8217;s Patch Tuesday</title>
		<link>http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/</link>
		<comments>http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/#comments</comments>
		<pubDate>Tue, 11 May 2010 22:46:23 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3915</guid>
		<description><![CDATA[After a busy April patch month, May&#8217;s patch Tuesday proves to be much quieter with two updates released by Microsoft. Although deemed critical, read the details below to see how your environment may or may not be affected. Microsoft Updates ID: MS10-030 Title: Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>WinPE 3.0 &amp; Forensics</title>
		<link>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/</link>
		<comments>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/#comments</comments>
		<pubDate>Mon, 12 Apr 2010 22:46:49 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[post-wide]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3608</guid>
		<description><![CDATA[It is a common task for an investigator to boot a machine using bootable media in the form of DVD or USB and there are countless options available. This tutorial is not intended to replace your favorite Helix CD or preferred method, but you may find this analysis interesting if you are a Windows expert performing a forensics analysis.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/04/winpe-3-0-forensics/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
		</item>
		<item>
		<title>Microsoft IE 6 &amp; 7 Zero-day (Aside)</title>
		<link>http://praetorianprefect.com/archives/2010/03/microsoft-ie-6-7-zero-day-aside/</link>
		<comments>http://praetorianprefect.com/archives/2010/03/microsoft-ie-6-7-zero-day-aside/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 22:00:45 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3489</guid>
		<description><![CDATA[A blog post on the MSRC web site warned of a new zero-day in Internet Explorer versions 6 and 7 running on Windows XP, Windows 2000, or Windows 2003. The post references Security Advisory (981374), and at this time there aren&#8217;t many details about the vulnerability other than what MS has stated in the advisory. [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/03/microsoft-ie-6-7-zero-day-aside/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>March&#8217;s Patch Tuesday</title>
		<link>http://praetorianprefect.com/archives/2010/03/3473/</link>
		<comments>http://praetorianprefect.com/archives/2010/03/3473/#comments</comments>
		<pubDate>Tue, 09 Mar 2010 20:38:40 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[excel]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[office]]></category>
		<category><![CDATA[office for mac]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[updates]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3473</guid>
		<description><![CDATA[<a href="http://praetorianprefect.com/wp-content/uploads/2010/03/msft_logo.jpg"><img src="http://praetorianprefect.com/wp-content/uploads/2010/03/msft_logo.jpg" alt="msft_logo" title="msft_logo" width="150" height="150" class="alignleft size-full wp-image-3484" /></a>

Today is patch Tuesday for March 2010, and Microsoft has released two security bulletins for this round of updates, neither of which are deemed critical. The second bulletin addresses seven different vulnerabilities across various versions of Microsoft Office Excel.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/03/3473/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Press F1 for Help, pwned.</title>
		<link>http://praetorianprefect.com/archives/2010/03/press-f1-for-help-pwned/</link>
		<comments>http://praetorianprefect.com/archives/2010/03/press-f1-for-help-pwned/#comments</comments>
		<pubDate>Tue, 02 Mar 2010 17:39:54 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Remote Exploit]]></category>
		<category><![CDATA[help system]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[winhlp32]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3444</guid>
		<description><![CDATA[Microsoft published security advisory 981169 yesterday in response to the zero day vulnerability reported a few days prior. The vulnerability is in the help system and can be triggered by luring an Internet Explorer user into pressing the F1 key. Windows 2000, Windows XP SP2 &#38; SP3, and Windows 2003 SP2 with Internet Explorer 7 [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/03/press-f1-for-help-pwned/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>February&#8217;s Patch Tuesday</title>
		<link>http://praetorianprefect.com/archives/2010/02/februarys-patch-tuesday/</link>
		<comments>http://praetorianprefect.com/archives/2010/02/februarys-patch-tuesday/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 22:56:29 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Patch Management]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[Remote Exploit]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3305</guid>
		<description><![CDATA[Today is patch Tuesday for February 2010, and it marks a fairly busy patch cycle for Microsoft, who released thirteen updates today. In late January, there was an out-of-band release for two critical patches, in response to the high profile issue around the Internet Explorer Aurora exploit. This makes a total of fifteen total patches between since January's patch Tuesday.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/02/februarys-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Microsoft Posts Advanced Notification for Out of Band Patch</title>
		<link>http://praetorianprefect.com/archives/2010/01/microsoft-posts-advanced-notification-for-out-of-band-patch/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/microsoft-posts-advanced-notification-for-out-of-band-patch/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 00:31:43 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3145</guid>
		<description><![CDATA[Microsoft has published the advanced notification for an unscheduled patch update release to occur tomorrow, outside of the normal patch Tuesday cycle. The update is for an Internet Explorer vulnerability reported to be a vector for the Aurora exploit which was used to attack Google and several other companies. The last time Microsoft released an [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/microsoft-posts-advanced-notification-for-out-of-band-patch/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Using Group Policy to Disable JavaScript in Adobe PDF Files</title>
		<link>http://praetorianprefect.com/archives/2010/01/disable-acrobat-reader-pdf-in-the-enterprise/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/disable-acrobat-reader-pdf-in-the-enterprise/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 03:37:42 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[pdf]]></category>
		<category><![CDATA[tutorial]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2856</guid>
		<description><![CDATA[We have previously <a href="http://praetorianprefect.com/archives/2009/12/disabling-javascript-on-adobe-acrobat/">posted instructions</a> for users to disable JavaScript, giving them the option to enable it only when necessary. However, if you have made the decision to make this change across your enterprise or to a specific user base, this manual process is not practical. Therefore, a Group Policy Object is best to handle the task at hand.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/disable-acrobat-reader-pdf-in-the-enterprise/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>First Patch Tuesday of 2010</title>
		<link>http://praetorianprefect.com/archives/2010/01/first-patch-tuesday-of-2010/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/first-patch-tuesday-of-2010/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 23:08:10 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2947</guid>
		<description><![CDATA[We begin a new year and arrive at the first patch Tuesday of the decade. The news and spread of malware related to Adobe Reader continues to gain momentum and the information security community believes that this year will produce more exploits using Reader. I will include both the Microsoft and Adobe updates in these [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/first-patch-tuesday-of-2010/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SMB Bug won&#8217;t be patched in January</title>
		<link>http://praetorianprefect.com/archives/2010/01/smb-bug-wont-be-patched-in-january/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/smb-bug-wont-be-patched-in-january/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 18:07:44 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Asides]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2910</guid>
		<description><![CDATA[Microsoft announced in a blog post that the SMB bug which can crash Windows 7 and Server 2008 R2 will not be patched in January&#8217;s patch Tuesday. We have shown how this bug can cause a severe halt to the OS, however, Microsoft stated that they &#8220;are not aware of any active attacks using the [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/smb-bug-wont-be-patched-in-january/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe util.printd Zero Day</title>
		<link>http://praetorianprefect.com/archives/2009/12/adobe-util-printd-zero-day/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/adobe-util-printd-zero-day/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 21:02:21 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2427</guid>
		<description><![CDATA[A critical vulnerability was discovered early this week in Adobe Reader and Acrobat versions 9.2 and earlier which could allow attackers to gain control of the affected system, not even a week after Adobe <a href="http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/">released a critical update</a> for its Flash Player on patch Tuesday last week. The attack uses a weakness in a function called util.printd along with a heap spray implemented with Javascript to attempt to inject shell code.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/adobe-util-printd-zero-day/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Forensics: Beverages Aside, A Look at Incident Response Tools</title>
		<link>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 00:57:57 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[decaf]]></category>
		<category><![CDATA[FTK]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2333</guid>
		<description><![CDATA[In November, Microsoft's forensics tool called COFEE (Computer Online Forensic Evidence Extractor) was leaked on torrents for download. The news coverage was <a href="http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/">much hype about nothing</a>, as many free tools already out there exceed COFEE in features and functionality.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Regular or Decaf? Tool launched to combat COFEE</title>
		<link>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 01:21:34 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[anti-forensics]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[decaf]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2250</guid>
		<description><![CDATA[About a month ago, there was much news about the release of COFEE into the torrent wild. I even gave my two cents about the much hyped forensics toolkit which is provided to law enforcement for the purposes of easily capturing volatile data from personal computers during evidence collection. A tool to counter COFEE, aptly [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Six Bulletins in Last Patch Tuesday of 2009</title>
		<link>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 19:39:55 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2088</guid>
		<description><![CDATA[Today marks the last Microsoft patch Tuesday of 2009, and Microsoft has released patches to six bulletins: MS09-071 &#8211; Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318) MS09-074 &#8211; Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183) MS09-072 &#8211; Cumulative Security Update for Internet Explorer (976325) MS09-069 &#8211; Vulnerability [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>From Promiscuous to Port Scanning with Powershell</title>
		<link>http://praetorianprefect.com/archives/2009/11/from-promiscuous-to-port-scanning-with-powershell/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/from-promiscuous-to-port-scanning-with-powershell/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 19:04:15 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[portscan]]></category>
		<category><![CDATA[powershell]]></category>
		<category><![CDATA[scripting]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1924</guid>
		<description><![CDATA[It&#8217;s been a while since my last post regarding Powershell which showed how to scan hosts for network interfaces in promiscuous mode. This time around, we’ll scan for some well known ports in our Active Directory to see who has a local IIS or SQL Express running on their machine. I know what you’re thinking. [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/from-promiscuous-to-port-scanning-with-powershell/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

