<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; featured</title>
	<atom:link href="http://praetorianprefect.com/archives/category/featured/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Mon, 11 Feb 2013 03:39:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>The &#8220;Aurora&#8221; IE Exploit Used Against Google in Action</title>
		<link>http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/#comments</comments>
		<pubDate>Sat, 16 Jan 2010 00:42:41 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Remote Exploit]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[post-wide]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3065</guid>
		<description><![CDATA[The <a href="http://www.computerworld.com/s/article/9144844/Hackers_used_IE_zero_day_not_PDF_in_China_Google_attacks?source=toc">big news</a> hit earlier this week, the attack vector that allowed bad actors presumably from China into the networks of Google, Juniper, Adobe, and some 30 other firms was an Internet Explorer zero day, a use after free vulnerability on an invalid pointer reference affecting IE 6, 7, and 8 but only used in IE 6 according to Microsoft.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/feed/</wfw:commentRss>
		<slash:comments>77</slash:comments>
		</item>
		<item>
		<title>Baidu.com the Latest Victim of Iranian CyberArmy</title>
		<link>http://praetorianprefect.com/archives/2010/01/baidu-com-the-latest-victim-of-iranian-cyberarmy/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/baidu-com-the-latest-victim-of-iranian-cyberarmy/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 03:11:23 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Web Site Defacement]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[post-wide]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2920</guid>
		<description><![CDATA[A group called the Iranian Cyber Army has, fresh off the heels of their <a href="http://praetorianprefect.com/archives/2009/12/we-shall-strike-if-the-leader-orders-twitter-struck-by-iranian-cyber-army/">DNS attack on Twitter</a> last month, hijacked the domain of Chinese search engine Baidu.com.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/baidu-com-the-latest-victim-of-iranian-cyberarmy/feed/</wfw:commentRss>
		<slash:comments>24</slash:comments>
		</item>
		<item>
		<title>JUNOS (Juniper) Flaw Exposes Core Routers to Kernel Crash</title>
		<link>http://praetorianprefect.com/archives/2010/01/junos-juniper-flaw-exposes-core-routers-to-kernal-crash/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/junos-juniper-flaw-exposes-core-routers-to-kernal-crash/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 22:23:17 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Remote Exploit]]></category>
		<category><![CDATA[core routers]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[tcp]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2812</guid>
		<description><![CDATA[A report has been received from Juniper at 4:25pm under bulletin PSN-2010-01-623 that a crafted malformed TCP field option in the TCP header of a packet will cause the JUNOS kernel to core (crash).]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/junos-juniper-flaw-exposes-core-routers-to-kernal-crash/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Forensics: Beverages Aside, A Look at Incident Response Tools</title>
		<link>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 00:57:57 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[decaf]]></category>
		<category><![CDATA[FTK]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2333</guid>
		<description><![CDATA[In November, Microsoft's forensics tool called COFEE (Computer Online Forensic Evidence Extractor) was leaked on torrents for download. The news coverage was <a href="http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/">much hype about nothing</a>, as many free tools already out there exceed COFEE in features and functionality.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Pentagon Web Site Vulnerabilities Identified</title>
		<link>http://praetorianprefect.com/archives/2009/12/pentagon-web-pwned/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/pentagon-web-pwned/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 01:12:55 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Cross Site Scripting]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[pentagon]]></category>
		<category><![CDATA[Romania]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2047</guid>
		<description><![CDATA[A Romanian hacker has on December 6th identified input validation deficiencies in URL parameter handling leading to security vulnerabilities on a section of the official site of the Pentagon, <a href="http://pentagon.afis.osd.mil">http://pentagon.afis.osd.mil</a>, the headquarters of the U.S. Department of Defense. The hacker who identifies himself as Ne0h has posted images of the vulnerabilities, which are still active at the time of this blog post, <a href="http://ne0h.baywords.com/2009/12/06/pentagon/">on his blog</a>.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/pentagon-web-pwned/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>The Perfect Crime, the perfect alibi: My Facebook Status</title>
		<link>http://praetorianprefect.com/archives/2009/11/the-perfect-crime-the-perfect-alibi-my-facebook-status/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/the-perfect-crime-the-perfect-alibi-my-facebook-status/#comments</comments>
		<pubDate>Thu, 12 Nov 2009 13:44:22 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Law]]></category>
		<category><![CDATA[facebook]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[I fought the law]]></category>
		<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[WTF]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1618</guid>
		<description><![CDATA[The NY Times brings us the story of Rodney Bradford. He&#8217;s the 19 year old Brooklyn man whose lawyer, Robert Reuland, invoked one of the first known &#8220;Facebook alibis&#8221; in his defense of the 19 year old Bradford on what were a second set of robbery charges he was facing. Since the Facebook defense is [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/the-perfect-crime-the-perfect-alibi-my-facebook-status/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>More COFEE Please, on Second Thought&#8230;</title>
		<link>http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 17:24:49 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[hype]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/</guid>
		<description><![CDATA[The forensics tool provided to law enforcement officials created by Microsoft called COFEE&#160; (Computer Online Forensic Evidence Extractor) has been leaked on torrents last week, and this has caused quite a bit of excitement.&#160; Let’s see if the big deal is warranted.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
		</item>
		<item>
		<title>OSSEC: Agentless&#8230;It&#8217;s good, but not good enough</title>
		<link>http://praetorianprefect.com/archives/2009/11/ossec-agentless-its-good-but-not-good-enough/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/ossec-agentless-its-good-but-not-good-enough/#comments</comments>
		<pubDate>Fri, 06 Nov 2009 00:22:49 +0000</pubDate>
		<dc:creator>Jeremy Rossi</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[agentless]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[openbsd]]></category>
		<category><![CDATA[ossec]]></category>
		<category><![CDATA[post-wide]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1475</guid>
		<description><![CDATA[In working with OSSEC agentless for some time now I have come across some limitations in the implementation that I felt needed to be addressed.  As OSSEC agentless is designed to preform <code>syscheck</code> functions on remote hosts, more general features are hard (if not impossible) to write into a script. This post will demonstrate an alternative for adding additional features to the OSSEC standard build.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/ossec-agentless-its-good-but-not-good-enough/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Barack Obama Donations Site was Hacked…err, no it wasn’t.</title>
		<link>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 02:45:53 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[politics]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1170</guid>
		<description><![CDATA[This morning a security researcher identified that he was able to carry out a successful SQL Injection attack against donate.barackobama.com, the official campaign donation site of current President Barack Obama, and gain access to credentials such as user names and passwords for persons who have donated to the Obama campaign, as well as administrative user credentials. On his blog he goes on to postulate the further attack possibilities with admin access such as web site defacement, uploading phpshells, and so forth. The problem is that the researcher Unu didn’t find an SQL injection site on donate.barackobama.com, he found one on a <a href="http://www.roosevelt.edu/calendars/calendar.asp">calendar application</a> at Roosevelt University. In the process of finding out how that would be possible, a real web site vulnerability on the Obama web site reveals itself.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Are Borderless Networks Possible?</title>
		<link>http://praetorianprefect.com/archives/2009/10/borderless-networks-yeah-but-wheres-my-border/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/borderless-networks-yeah-but-wheres-my-border/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 19:27:33 +0000</pubDate>
		<dc:creator>Jeremy Rossi</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[borderless networks]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=980</guid>
		<description><![CDATA[I attended SC World Congress in New York this week and a keynote from Cisco caught my attention: Securing the Cloud: Building the Borderless Network. I became fixated on the words used over and over by Joel McFarland. Borderless this, borderless that, borderless everything. This campaign started to bother me as this was a security [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/borderless-networks-yeah-but-wheres-my-border/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Adobe to release critical update on patch Tuesday</title>
		<link>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 15:03:50 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[reader]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=882</guid>
		<description><![CDATA[A new zero-day vulnerability in Adobe Reader and Acrobat 9.1.3 has been identified by Chia-Ching Fang and the Taiwanese Information and Communication Security Technology Service Center that allows an attacker to remotely execute arbitrary code. The attack is seeded by providing via e-mail or download a specially crafted PDF file which in current examples will then drop a malware executable as well as an unaffected pdf file.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Operation Phish Phry</title>
		<link>http://praetorianprefect.com/archives/2009/10/operation-phish-phry/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/operation-phish-phry/#comments</comments>
		<pubDate>Wed, 07 Oct 2009 11:43:07 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Phishing]]></category>
		<category><![CDATA[banks]]></category>
		<category><![CDATA[FBI]]></category>
		<category><![CDATA[money mule]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=792</guid>
		<description><![CDATA[A phish phry is a social gathering, and early Wednesday the FBI, US Attorney’s Office, the LA Electronic Crimes Task Force, and Egyptian authorities started working towards arranging the largest gathering of suspects indicted in connection with a single phishing scam to date.  Dubbed “Operation Phish Phry”, this two year inter-agency inter-country investigation is rounding up 100 suspects including 53 from North Carolina, Las Vegas, and Los Angeles as well as 47 in Egypt accused of stealing more than a million dollars from two U.S. banks.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/operation-phish-phry/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>2008 Server to the Core</title>
		<link>http://praetorianprefect.com/archives/2009/09/2008-server-to-the-core/</link>
		<comments>http://praetorianprefect.com/archives/2009/09/2008-server-to-the-core/#comments</comments>
		<pubDate>Wed, 23 Sep 2009 21:47:06 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[active directory]]></category>
		<category><![CDATA[cli]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[scripting]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[windows 2008]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=398</guid>
		<description><![CDATA[One of my favorite websites in the days of Windows 2000 Server was a project from a group of system managers from the Department of Electrical Engineering at the Swiss Federal Institute of Technology; it was titled “Real Men Don&#8217;t Click”, and it was dedicated to accomplishing tasks solely using the command line interface (CLI). [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/09/2008-server-to-the-core/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Wolverine&#8217;s nemesis: Data Leakage</title>
		<link>http://praetorianprefect.com/archives/2009/05/wolverines-nemesis-data-leakage/</link>
		<comments>http://praetorianprefect.com/archives/2009/05/wolverines-nemesis-data-leakage/#comments</comments>
		<pubDate>Fri, 01 May 2009 05:44:33 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Data Leak Prevention]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[copyright]]></category>
		<category><![CDATA[piracy]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=114</guid>
		<description><![CDATA[As widely reported, the major motion picture opening today, X-Men Origins: Wolverine, was leaked on March 31st to major BitTorrent trackers and within twenty four hours had been downloaded some 75,000 times and to date more then 1mm. If the average movie ticket price is $7.18, then that&#8217;s potentially $7mm or more in lost revenue [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/05/wolverines-nemesis-data-leakage/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Now I will believe that there are unicorns&#8230;</title>
		<link>http://praetorianprefect.com/archives/2009/04/now-i-will-believe-that-there-are-unicorns/</link>
		<comments>http://praetorianprefect.com/archives/2009/04/now-i-will-believe-that-there-are-unicorns/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 04:17:59 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Web Site Defacement]]></category>
		<category><![CDATA[espn]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=13</guid>
		<description><![CDATA[Anyone who looked at ESPN online today (04/27/09) may find themselves agreeing with Mr. Shakespeare. Starting a little after 4pm EST you may have noticed a spike in chatter on Twitter related to <a href="http://www.espn.com">ESPN.com</a>.  A high profile web site defacement occurred on the sports news web site where the <a href="http://www.cornify.com">Cornify script</a> was invoked by a Javascript using keystokes known as the <a href="http://en.wikipedia.org/wiki/Konami_code">Konami code</a>.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/04/now-i-will-believe-that-there-are-unicorns/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>
