<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; featured</title>
	<atom:link href="http://praetorianprefect.com/archives/tag/featured/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Mon, 11 Feb 2013 03:39:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Anonymous Releases Very Unanonymous Press Release</title>
		<link>http://praetorianprefect.com/archives/2010/12/anonymous-releases-very-unanonymous-press-release/</link>
		<comments>http://praetorianprefect.com/archives/2010/12/anonymous-releases-very-unanonymous-press-release/#comments</comments>
		<pubDate>Sat, 11 Dec 2010 03:21:56 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Funny]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[Anonymous]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[post-wide]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4799</guid>
		<description><![CDATA[Today, December 10th, Anonymous, an Internet gathering, released a press release which you can read below. In it, a description is provided of what Anonymous is about, what Operation Payback is, and where the media is getting it wrong. Also in it, its author forgot to remove his name in the pdf's Meta information.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/12/anonymous-releases-very-unanonymous-press-release/feed/</wfw:commentRss>
		<slash:comments>32</slash:comments>
		</item>
		<item>
		<title>Paypal Sender Country XSS</title>
		<link>http://praetorianprefect.com/archives/2010/10/paypal-sender-country-xss/</link>
		<comments>http://praetorianprefect.com/archives/2010/10/paypal-sender-country-xss/#comments</comments>
		<pubDate>Wed, 06 Oct 2010 20:37:02 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Cross Site Scripting]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[paypal]]></category>
		<category><![CDATA[post-wide]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4653</guid>
		<description><![CDATA[A new XSS vulnerability was identified on Paypal.com earlier today, found by d3v1l and disclosed on both <a href="http://security-sh3ll.blogspot.com/2010/10/paypal-xss-vulnerability.html">Security-Shell</a> and <a href="http://www.xssed.com/mirror/69602/">XSSed</a>. The problem is with the parameter sender_country in a transaction called nvpsm.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/10/paypal-sender-country-xss/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Turning an ATM into a Slot Machine</title>
		<link>http://praetorianprefect.com/archives/2010/07/turning-an-atm-into-a-slot-machine/</link>
		<comments>http://praetorianprefect.com/archives/2010/07/turning-an-atm-into-a-slot-machine/#comments</comments>
		<pubDate>Wed, 28 Jul 2010 23:50:13 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[atm]]></category>
		<category><![CDATA[blackhat]]></category>
		<category><![CDATA[featured]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4600</guid>
		<description><![CDATA[In a talk originally slated for last year before it was muffled by Juniper based on the concerns of "an affected ATM vendor", Jack demonstrates what he calls jackpotting an ATM.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/07/turning-an-atm-into-a-slot-machine/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
		</item>
		<item>
		<title>Persistent XSS on Twitter.com</title>
		<link>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/</link>
		<comments>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/#comments</comments>
		<pubDate>Thu, 24 Jun 2010 08:32:11 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Social Networking]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[post-wide]]></category>
		<category><![CDATA[twitter]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=4423</guid>
		<description><![CDATA[Twitter user 0wn3d_5ys has demonstrated a persistent cross site scripting (XSS) vulnerability he found on  June 21st using his own Twitter account (visit at your own risk) that appears to be due to a lack of input validation of the application name field when accepting new requests for Twitter applications.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/06/persistent-xss-on-twitter-com/feed/</wfw:commentRss>
		<slash:comments>15</slash:comments>
		</item>
		<item>
		<title>The &#8220;Aurora&#8221; IE Exploit Used Against Google in Action</title>
		<link>http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/#comments</comments>
		<pubDate>Sat, 16 Jan 2010 00:42:41 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Remote Exploit]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[metasploit]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[post-wide]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3065</guid>
		<description><![CDATA[The <a href="http://www.computerworld.com/s/article/9144844/Hackers_used_IE_zero_day_not_PDF_in_China_Google_attacks?source=toc">big news</a> hit earlier this week, the attack vector that allowed bad actors presumably from China into the networks of Google, Juniper, Adobe, and some 30 other firms was an Internet Explorer zero day, a use after free vulnerability on an invalid pointer reference affecting IE 6, 7, and 8 but only used in IE 6 according to Microsoft.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/the-aurora-ie-exploit-in-action/feed/</wfw:commentRss>
		<slash:comments>77</slash:comments>
		</item>
		<item>
		<title>Scareware Purveyors, Spammers, and Crooks Take Advantage of Haiti Earthquake</title>
		<link>http://praetorianprefect.com/archives/2010/01/scareware-purveyors-spammers-and-crooks-take-advantage-of-haiti-earthquake/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/scareware-purveyors-spammers-and-crooks-take-advantage-of-haiti-earthquake/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 00:28:27 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Scareware]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[natural disaster]]></category>
		<category><![CDATA[search engine poisoning]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=3024</guid>
		<description><![CDATA[Bad actors have taken advantage by engaging in search engine poisoning including taking over existing web sites, using techniques that boost search ranking, and installing malicious software using scareware tactics on user’s PC’s. They also set up fake donation web sites. Finally, they employ Spam e-mail, Twitter messages, and related electronic communication methods in order to direct users to these web sites.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/scareware-purveyors-spammers-and-crooks-take-advantage-of-haiti-earthquake/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Baidu.com the Latest Victim of Iranian CyberArmy</title>
		<link>http://praetorianprefect.com/archives/2010/01/baidu-com-the-latest-victim-of-iranian-cyberarmy/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/baidu-com-the-latest-victim-of-iranian-cyberarmy/#comments</comments>
		<pubDate>Tue, 12 Jan 2010 03:11:23 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Web Site Defacement]]></category>
		<category><![CDATA[defacement]]></category>
		<category><![CDATA[Hacktivism]]></category>
		<category><![CDATA[post-wide]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2920</guid>
		<description><![CDATA[A group called the Iranian Cyber Army has, fresh off the heels of their <a href="http://praetorianprefect.com/archives/2009/12/we-shall-strike-if-the-leader-orders-twitter-struck-by-iranian-cyber-army/">DNS attack on Twitter</a> last month, hijacked the domain of Chinese search engine Baidu.com.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/baidu-com-the-latest-victim-of-iranian-cyberarmy/feed/</wfw:commentRss>
		<slash:comments>24</slash:comments>
		</item>
		<item>
		<title>JUNOS (Juniper) Flaw Exposes Core Routers to Kernel Crash</title>
		<link>http://praetorianprefect.com/archives/2010/01/junos-juniper-flaw-exposes-core-routers-to-kernal-crash/</link>
		<comments>http://praetorianprefect.com/archives/2010/01/junos-juniper-flaw-exposes-core-routers-to-kernal-crash/#comments</comments>
		<pubDate>Wed, 06 Jan 2010 22:23:17 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Remote Exploit]]></category>
		<category><![CDATA[core routers]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[tcp]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2812</guid>
		<description><![CDATA[A report has been received from Juniper at 4:25pm under bulletin PSN-2010-01-623 that a crafted malformed TCP field option in the TCP header of a packet will cause the JUNOS kernel to core (crash).]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2010/01/junos-juniper-flaw-exposes-core-routers-to-kernal-crash/feed/</wfw:commentRss>
		<slash:comments>20</slash:comments>
		</item>
		<item>
		<title>Forensics: Beverages Aside, A Look at Incident Response Tools</title>
		<link>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/#comments</comments>
		<pubDate>Wed, 16 Dec 2009 00:57:57 +0000</pubDate>
		<dc:creator>MJP</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[cofee]]></category>
		<category><![CDATA[decaf]]></category>
		<category><![CDATA[FTK]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2333</guid>
		<description><![CDATA[In November, Microsoft's forensics tool called COFEE (Computer Online Forensic Evidence Extractor) was leaked on torrents for download. The news coverage was <a href="http://praetorianprefect.com/archives/2009/11/more-cofee-please-on-second-thought/">much hype about nothing</a>, as many free tools already out there exceed COFEE in features and functionality.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/forensics-beverages-aside-a-look-at-incident-response-tools/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>Pentagon Web Site Vulnerabilities Identified</title>
		<link>http://praetorianprefect.com/archives/2009/12/pentagon-web-pwned/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/pentagon-web-pwned/#comments</comments>
		<pubDate>Tue, 08 Dec 2009 01:12:55 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Cross Site Scripting]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[pentagon]]></category>
		<category><![CDATA[Romania]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=2047</guid>
		<description><![CDATA[A Romanian hacker has on December 6th identified input validation deficiencies in URL parameter handling leading to security vulnerabilities on a section of the official site of the Pentagon, <a href="http://pentagon.afis.osd.mil">http://pentagon.afis.osd.mil</a>, the headquarters of the U.S. Department of Defense. The hacker who identifies himself as Ne0h has posted images of the vulnerabilities, which are still active at the time of this blog post, <a href="http://ne0h.baywords.com/2009/12/06/pentagon/">on his blog</a>.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/pentagon-web-pwned/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Microsoft Video ActiveX Control Vulnerability</title>
		<link>http://praetorianprefect.com/archives/2009/07/microsoft-video-activex-control-vulnerability/</link>
		<comments>http://praetorianprefect.com/archives/2009/07/microsoft-video-activex-control-vulnerability/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 06:04:23 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[ActiveX]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[featured]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=319</guid>
		<description><![CDATA[Microsoft is recommending setting the kill bit for an ActiveX control object, MPEG2TuneRequest, to avoid an in the wild zero day exploit that allows for remote code execution when a web site containing the exploit is browsed by a user with Internet Explorer.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/07/microsoft-video-activex-control-vulnerability/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
	</channel>
</rss>
