<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; Vulnerability</title>
	<atom:link href="http://praetorianprefect.com/archives/category/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Thu, 19 Jan 2012 03:59:33 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Turning an ATM into a Slot Machine</title>
		<link>http://praetorianprefect.com/archives/2010/07/turning-an-atm-into-a-slot-machine/</link>
		<comments>http://praetorianprefect.com/archives/2010/07/turning-an-atm-into-a-slot-machine/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 23:50:13 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[atm]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[featured]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4600</guid>
		<description><![CDATA[In a talk originally slated for last year before it was muffled by Juniper based on the concerns of "an affected ATM vendor", Jack demonstrates what he calls jackpotting an ATM.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/07/turning-an-atm-into-a-slot-machine/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Microsoft&#8217;s Google Attack Patch?</title>
		<link>http://praetorianprefect.com/archives/2010/02/microsofts-google-attack-patch/</link>
		<comments>http://praetorianprefect.com/archives/2010/02/microsofts-google-attack-patch/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 04:18:26 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Funny]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Patch Management]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3421</guid>
		<description><![CDATA[Noted journalist and friend of the blog <a href="http://twitter.com/georgevhulme">George V. Hulme</a> shared the picture below from CNBC, perhaps the most amusing way seen thus far of describing the patch for the '<a href="http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/">Aurora bug</a>' that famously affected Google late last year.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/02/microsofts-google-attack-patch/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Adobe util.printd Zero Day</title>
		<link>http://praetorianprefect.com/archives/2009/12/adobe-util-printd-zero-day/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/adobe-util-printd-zero-day/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 21:02:21 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2427</guid>
		<description><![CDATA[A critical vulnerability was discovered early this week in Adobe Reader and Acrobat versions 9.2 and earlier which could allow attackers to gain control of the affected system, not even a week after Adobe <a href="http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/">released a critical update</a> for its Flash Player on patch Tuesday last week. The attack uses a weakness in a function called util.printd along with a heap spray implemented with Javascript to attempt to inject shell code.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/adobe-util-printd-zero-day/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Six Bulletins in Last Patch Tuesday of 2009</title>
		<link>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 19:39:55 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[Administration]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[ie]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[patch]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[updates]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2088</guid>
		<description><![CDATA[Today marks the last Microsoft patch Tuesday of 2009, and Microsoft has released patches to six bulletins:




MS09-071 &#8211; Vulnerabilities in Internet Authentication Service Could Allow Remote Code Execution (974318)
MS09-074 &#8211; Vulnerability in Microsoft Office Project Could Allow Remote Code Execution (967183) 
MS09-072 &#8211; Cumulative Security Update for Internet Explorer (976325) 
MS09-069 &#8211; Vulnerability in Local [...]]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/six-bulletins-in-last-patch-tuesday-of-2009/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Barack Obama Donations Site was Hacked…err, no it wasn’t.</title>
		<link>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 02:45:53 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[politics]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1170</guid>
		<description><![CDATA[This morning a security researcher identified that he was able to carry out a successful SQL Injection attack against donate.barackobama.com, the official campaign donation site of current President Barack Obama, and gain access to credentials such as user names and passwords for persons who have donated to the Obama campaign, as well as administrative user credentials. On his blog he goes on to postulate the further attack possibilities with admin access such as web site defacement, uploading phpshells, and so forth. The problem is that the researcher Unu didn’t find an SQL injection site on donate.barackobama.com, he found one on a <a href="http://www.roosevelt.edu/calendars/calendar.asp">calendar application</a> at Roosevelt University. In the process of finding out how that would be possible, a real web site vulnerability on the Obama web site reveals itself.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
		<item>
		<title>Microsoft Video ActiveX Control Vulnerability</title>
		<link>http://praetorianprefect.com/archives/2009/07/microsoft-video-activex-control-vulnerability/</link>
		<comments>http://praetorianprefect.com/archives/2009/07/microsoft-video-activex-control-vulnerability/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 06:04:23 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=319</guid>
		<description><![CDATA[Microsoft is recommending setting the kill bit for an ActiveX control object, MPEG2TuneRequest, to avoid an in the wild zero day exploit that allows for remote code execution when a web site containing the exploit is browsed by a user with Internet Explorer.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/07/microsoft-video-activex-control-vulnerability/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

