<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; Security</title>
	<atom:link href="http://praetorianprefect.com/archives/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 19 Jan 2012 03:59:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>iPhone 4 Ordering and Session Switching</title>
		<link>http://praetorianprefect.com/archives/2010/06/iphone-4-ordering-and-session-switching/</link>
		<comments>http://praetorianprefect.com/archives/2010/06/iphone-4-ordering-and-session-switching/#comments</comments>
		<pubDate>Tue, 15 Jun 2010 21:18:19 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[AT&T]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4215</guid>
		<description><![CDATA[Upon logging into AT&#38;T online to place an order for the new iPhone, some users are reporting that another user's information is coming up including billing information, call history, and so forth.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/06/iphone-4-ordering-and-session-switching/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>May&#8217;s Patch Tuesday</title>
		<link>http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/</link>
		<comments>http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/#comments</comments>
		<pubDate>Tue, 11 May 2010 22:46:23 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[patch tuesday]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3915</guid>
		<description><![CDATA[
After a busy April patch month, May&#8217;s patch Tuesday proves to be much quieter with two updates released by Microsoft. Although deemed critical, read the details below to see how your environment may or may not be affected.

Microsoft Updates



ID: MS10-030
Title: Vulnerability in Outlook Express and Windows Mail Could Allow Remote Code Execution 
Microsoft Severity: Critical

Summary: [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/05/mays-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>First Patch Tuesday of 2010</title>
		<link>http://praetorianprefect.com/archives/2010/01/first-patch-tuesday-of-2010/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/first-patch-tuesday-of-2010/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 23:08:10 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2947</guid>
		<description><![CDATA[We begin a new year and arrive at the first patch Tuesday of the decade. The news and spread of malware related to Adobe Reader continues to gain momentum and the information security community believes that this year will produce more exploits using Reader. I will include both the Microsoft and Adobe updates in these [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/first-patch-tuesday-of-2010/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Regular or Decaf? Tool launched to combat COFEE</title>
		<link>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/#comments</comments>
		<pubDate>Tue, 15 Dec 2009 01:21:34 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Forensics]]></category>
		<category><![CDATA[Incident Response]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[anti-forensics]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[decaf]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2250</guid>
		<description><![CDATA[

About a month ago, there was much news about the release of COFEE into the torrent wild. I even gave my two cents about the much hyped forensics toolkit which is provided to law enforcement for the purposes of easily capturing volatile data from personal computers during evidence collection. A tool to counter COFEE, aptly [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/regular-or-decaf-tool-launched-to-combat-cofee/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Six Bulletins in Last Patch Tuesday of 2009</title>
		<link>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 19:39:55 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2088</guid>
		<description><![CDATA[Today marks the last Microsoft patch Tuesday of 2009, and Microsoft has released patches to six bulletins:




MS09-071 &#8211; Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)
MS09-074 &#8211; Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183) 
MS09-072 &#8211; Cumulative Security Update for Internet Explorer (976325) 
MS09-069 &#8211; Vulnerability in Local [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Disabling Javascript on Adobe Acrobat</title>
		<link>http://praetorianprefect.com/archives/2009/12/disabling-javascript-on-adobe-acrobat/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/disabling-javascript-on-adobe-acrobat/#comments</comments>
		<pubDate>Wed, 02 Dec 2009 02:20:45 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[pdf]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2840</guid>
		<description><![CDATA[For many users, PDF's are simply a mechanism for providing documents to read. Given the spate of vulnerabilities identified in Acrobat and Reader in 2009, and the likely promise of more in 2010, we are releasing by request this general instruction for disabling Javascript in Adobe Acrobat. An advisable approach, depending on your usage of these products, may be to disable Javascript and only re-enable when performing an activity with a PDF that requires Javascript be enabled, such as with an eForm.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/disabling-javascript-on-adobe-acrobat/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>From Promiscuous to Port Scanning with Powershell</title>
		<link>http://praetorianprefect.com/archives/2009/11/from-promiscuous-to-port-scanning-with-powershell/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/from-promiscuous-to-port-scanning-with-powershell/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 19:04:15 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Administration]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[portscan]]></category>
		<category><![CDATA[powershell]]></category>
		<category><![CDATA[scripting]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1924</guid>
		<description><![CDATA[

It&#8217;s been a while since my last post regarding Powershell which showed how to scan hosts for network interfaces in promiscuous mode. This time around, we’ll scan for some well known ports in our Active Directory to see who has a local IIS or SQL Express running on their machine. I know what you’re thinking. [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/from-promiscuous-to-port-scanning-with-powershell/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>OSSEC: Agentless scripts</title>
		<link>http://praetorianprefect.com/archives/2009/11/ossec-agentless-scripts/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/ossec-agentless-scripts/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 23:57:47 +0000</pubDate>
		<dc:creator>Jeremy Rossi</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[agentless]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[openbsd]]></category>
		<category><![CDATA[ossec]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1419</guid>
		<description><![CDATA[In my last OSSEC post "<a href="/archives/2009/11/ossec-agentless-to-save-the-day/">OSSEC: Agentless to save the day</a>" I went over how to setup agentless monitoring using the built in scripts.  With this post I am going to get into the details of how to modify the OSSEC supplied scripts to do your bidding.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/ossec-agentless-scripts/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>OSSEC: Agentless to save the day</title>
		<link>http://praetorianprefect.com/archives/2009/11/ossec-agentless-to-save-the-day/</link>
		<comments>http://praetorianprefect.com/archives/2009/11/ossec-agentless-to-save-the-day/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 23:04:21 +0000</pubDate>
		<dc:creator>Jeremy Rossi</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Tools]]></category>
		<category><![CDATA[agentless]]></category>
		<category><![CDATA[hids]]></category>
		<category><![CDATA[lids]]></category>
		<category><![CDATA[ossec]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1395</guid>
		<description><![CDATA[OSSEC is a Host Intrusion detection system (HIDS) in name, but in reality it is far more.  It's able to look for rootkits, monitor logs (LIDS), and even actively respond to defined events.  While all these features are great the unsung hero is agentless monitoring.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/11/ossec-agentless-to-save-the-day/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Replace watch.swf with warp.swf on YouTube</title>
		<link>http://praetorianprefect.com/archives/2009/10/replace-watch-swf-with-warp-swf-on-youtube/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/replace-watch-swf-with-warp-swf-on-youtube/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 07:13:42 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Asides]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[youtube]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1218</guid>
		<description><![CDATA[If you replace watch.swf with warp.swf in a url on youtube, a new application shows up that dynamically opens up new nodes of related videos. Its both interesting and bizarre, anda  good way to burn five minutes: <a href="http://www.youtube.com/warp.swf?v=oHg5SJYRHA0">Youtube Warp</a>.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/replace-watch-swf-with-warp-swf-on-youtube/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The Barack Obama Donations Site was Hacked…err, no it wasn’t.</title>
		<link>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 02:45:53 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[politics]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1170</guid>
		<description><![CDATA[This morning a security researcher identified that he was able to carry out a successful SQL Injection attack against donate.barackobama.com, the official campaign donation site of current President Barack Obama, and gain access to credentials such as user names and passwords for persons who have donated to the Obama campaign, as well as administrative user credentials. On his blog he goes on to postulate the further attack possibilities with admin access such as web site defacement, uploading phpshells, and so forth. The problem is that the researcher Unu didn’t find an SQL injection site on donate.barackobama.com, he found one on a <a href="http://www.roosevelt.edu/calendars/calendar.asp">calendar application</a> at Roosevelt University. In the process of finding out how that would be possible, a real web site vulnerability on the Obama web site reveals itself.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Where is your BES Policy?</title>
		<link>http://praetorianprefect.com/archives/2009/10/where-is-your-bes-policy/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/where-is-your-bes-policy/#comments</comments>
		<pubDate>Mon, 26 Oct 2009 16:23:52 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Data Leak Prevention]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[BES]]></category>
		<category><![CDATA[blackberry]]></category>
		<category><![CDATA[exchange]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[mobile]]></category>
		<category><![CDATA[passwords]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1139</guid>
		<description><![CDATA[Several months ago, users of a wireless carrier in the United Arab Emirates (UAE) were sent an SMS message to their Blackberry devices instructing them to install a software patch that would resolve recent network trouble they’ve been experiencing. The patch turned out to be spyware (Etisalat.A[MA]) and would intercept the user’s email, sending the [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/where-is-your-bes-policy/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Are Borderless Networks Possible?</title>
		<link>http://praetorianprefect.com/archives/2009/10/borderless-networks-yeah-but-wheres-my-border/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/borderless-networks-yeah-but-wheres-my-border/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 19:27:33 +0000</pubDate>
		<dc:creator>Jeremy Rossi</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[borderless networks]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[policy]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=980</guid>
		<description><![CDATA[I attended SC World Congress in New York this week and a keynote from Cisco caught my attention: Securing the Cloud: Building the Borderless Network.  I became fixated on the words used over and over by Joel McFarland. Borderless this, borderless that, borderless everything.  This campaign started to bother me as this was [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/borderless-networks-yeah-but-wheres-my-border/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Adobe to release critical update on patch Tuesday</title>
		<link>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/#comments</comments>
		<pubDate>Fri, 09 Oct 2009 15:03:50 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[reader]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=882</guid>
		<description><![CDATA[A new zero-day vulnerability in Adobe Reader and Acrobat 9.1.3 has been identified by Chia-Ching Fang and the Taiwanese Information and Communication Security Technology Service Center that allows an attacker to remotely execute arbitrary code. The attack is seeded by providing via e-mail or download a specially crafted PDF file which in current examples will then drop a malware executable as well as an unaffected pdf file.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/adobe-to-release-critical-update-on-patch-tuesday/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Colbert&#8217;s Human DDOS</title>
		<link>http://praetorianprefect.com/archives/2009/10/colberts-human-ddos/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/colberts-human-ddos/#comments</comments>
		<pubDate>Thu, 08 Oct 2009 06:37:29 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[ddos]]></category>
		<category><![CDATA[wiki]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=857</guid>
		<description><![CDATA[Stephen Colbert launched an impromptu human distributed denial of service (DDOS) by instructing his viewers, or the Colbert Nation, to make edits to the collaborative wiki encyclopedia Conservapedia. Specifically he wants to be added as a character in the Conservapedia translated version of the bible, an ongoing crowd sourcing project of the web site.


  [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/colberts-human-ddos/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

