<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Praetorian Prefect &#187; politics</title>
	<atom:link href="http://praetorianprefect.com/archives/tag/politics/feed/" rel="self" type="application/rss+xml" />
	<link>http://praetorianprefect.com</link>
	<description>Information security, a little slower...a little deeper</description>
	<lastBuildDate>Fri, 16 Mar 2012 05:46:23 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Unu Cracks a Wall Street Journal Conference Site, Not WSJ.com</title>
		<link>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/</link>
		<comments>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/#comments</comments>
		<pubDate>Fri, 04 Dec 2009 10:41:35 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[politics]]></category>
		<category><![CDATA[vendors]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1966</guid>
		<description><![CDATA[Unu did identify a Wall Street Journal branded web site that is vulnerable to SQL Injection attacks. But the site is not WSJ.com, is not on the same servers WSJ.com is on, is not a site hosted by Dow Jones-Teleratel but rather a conference site hosted by a WSJ vendor called MAP Digital, Inc..]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/12/unu-cracks-a-wall-street-journal-conference-site-not-wsj-com/feed/</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>The Barack Obama Donations Site was Hacked…err, no it wasn’t.</title>
		<link>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/</link>
		<comments>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/#comments</comments>
		<pubDate>Tue, 27 Oct 2009 02:45:53 +0000</pubDate>
		<dc:creator>Prefect</dc:creator>
				<category><![CDATA[featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[politics]]></category>

		<guid isPermaLink="false">http://praetorianprefect.com/?p=1170</guid>
		<description><![CDATA[This morning a security researcher identified that he was able to carry out a successful SQL Injection attack against donate.barackobama.com, the official campaign donation site of current President Barack Obama, and gain access to credentials such as user names and passwords for persons who have donated to the Obama campaign, as well as administrative user credentials. On his blog he goes on to postulate the further attack possibilities with admin access such as web site defacement, uploading phpshells, and so forth. The problem is that the researcher Unu didn’t find an SQL injection site on donate.barackobama.com, he found one on a <a href="http://www.roosevelt.edu/calendars/calendar.asp">calendar application</a> at Roosevelt University. In the process of finding out how that would be possible, a real web site vulnerability on the Obama web site reveals itself.]]></description>
		<wfw:commentRss>http://praetorianprefect.com/archives/2009/10/the-barack-obama-donations-site-was-hacked%e2%80%a6err-no-it-wasn%e2%80%99t/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
		</item>
	</channel>
</rss>

