<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Security</title><link>http://security.tipsdr.com/</link><description>Security news, and notes, from security at Tipsdr and from all corners of the Internet. Get continuous protection for your PC with Windows Live OneCare Download the free trial.Free Performance scanWindows SupportRemote Desktop Access</description><generator>Tumblr (security)</generator><item><title>Neighbor indicted in MySpace suicide case</title><description>&lt;a href="http://www.topix.net/tech/computer-security/2008/05/neighbor-indicted-in-myspace-suicide-case?fromrss=1"&gt;Neighbor indicted in MySpace suicide case&lt;/a&gt;: &lt;p class="lede_quote"&gt;“They exploited a young girl’s weaknesses”&lt;/p&gt; &lt;p&gt; After Missouri prosecutors said they couldn’t find grounds for charges in the case of a 13-year-old who killed herself after being bullied online, there…&lt;/p&gt;</description><link>http://security.tipsdr.com/post/35001723</link><guid>http://security.tipsdr.com/post/35001723</guid><pubDate>Fri, 16 May 2008 05:02:13 -0400</pubDate></item><item><title>'Hacker shuts down government computers'</title><description>&lt;a href="http://www.topix.net/tech/computer-security/2008/05/hacker-shuts-down-government-computers?fromrss=1"&gt;'Hacker shuts down government computers'&lt;/a&gt;: &lt;p class="lede_quote"&gt;“We believe it may have occurred”&lt;/p&gt; &lt;p&gt; Royal Darwin Hospital … a hacker allegedly took down servers for hospitals, a prison and a supreme court / Amy Brabin AN EXPERT hacker allegedly shut down the…&lt;/p&gt;</description><link>http://security.tipsdr.com/post/34982910</link><guid>http://security.tipsdr.com/post/34982910</guid><pubDate>Fri, 16 May 2008 00:48:29 -0400</pubDate></item><item><title>Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</title><description>&lt;a href="http://www.topix.net/tech/computer-security/2008/05/re-re-re-apache-server-html-injection-and-utf-7-xss-vulnerability?fromrss=1"&gt;Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability&lt;/a&gt;: &lt;p class="lede_quote"&gt;“As all ISO, UTF-8 and related charsets were 7-bit clean, it’s clear that Microsoft err’ed on the side of accepting UTF-7 charset for automatic detection in violation of RFC 2616.”&lt;/p&gt; &lt;p&gt; Hello, Please…&lt;/p&gt;</description><link>http://security.tipsdr.com/post/34956567</link><guid>http://security.tipsdr.com/post/34956567</guid><pubDate>Thu, 15 May 2008 19:31:34 -0400</pubDate></item><item><title>ZDI-08-025: Symantec Altiris Deployment Solution Domain Credential Disclosure Vulnerability</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0177.html"&gt;ZDI-08-025: Symantec Altiris Deployment Solution Domain Credential Disclosure Vulnerability&lt;/a&gt;: ZDI-08-025: Symantec Altiris Deployment Solution Domain Credential Disclosure Vulnerability May 15, 2008 — Affected Vendors: Symantec — Affected Products: Symantec Altiris Deployment Solution —…</description><link>http://security.tipsdr.com/post/34952347</link><guid>http://security.tipsdr.com/post/34952347</guid><pubDate>Thu, 15 May 2008 18:46:47 -0400</pubDate></item><item><title>ZDI-08-024: Symantec Altiris Deployment Solution SQL Injection Vulnerability</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0176.html"&gt;ZDI-08-024: Symantec Altiris Deployment Solution SQL Injection Vulnerability&lt;/a&gt;: ZDI-08-024: Symantec Altiris Deployment Solution SQL Injection Vulnerability May 15, 2008 — Affected Vendors: Symantec — Affected Products: Symantec Altiris Deployment Solution — TippingPoint(TM)…</description><link>http://security.tipsdr.com/post/34952348</link><guid>http://security.tipsdr.com/post/34952348</guid><pubDate>Thu, 15 May 2008 18:46:47 -0400</pubDate></item><item><title>SunShop Version 3.5.1 Remote Blind Sql Injection</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0175.html"&gt;SunShop Version 3.5.1 Remote Blind Sql Injection&lt;/a&gt;: #!/usr/bin/perl -w use LWP::UserAgent; # scripts : SunShop Version 3.5.1 Remote Blind Sql Injection # scripts site : # Discovered # By : irvian # site : # email : irvian.infoatgmail.com print…</description><link>http://security.tipsdr.com/post/34936611</link><guid>http://security.tipsdr.com/post/34936611</guid><pubDate>Thu, 15 May 2008 15:29:56 -0400</pubDate></item><item><title>Legal victory against spammers as MySpace wins record payout of USD 234 million, Sophos reports</title><description>&lt;a href="http://www.topix.net/tech/computer-security/2008/05/legal-victory-against-spammers-as-myspace-wins-record-payout-of-usd-234-million-sophos-reports?fromrss=1"&gt;Legal victory against spammers as MySpace wins record payout of USD 234 million, Sophos reports&lt;/a&gt;: &lt;p class="lede_quote"&gt;“In the war against spam it is right that large companies should have a heavy stick like this to hit the spammers with”&lt;/p&gt; &lt;p&gt; IT security and control firm Sophos has applauded a legal judgment that has…&lt;/p&gt;</description><link>http://security.tipsdr.com/post/34934940</link><guid>http://security.tipsdr.com/post/34934940</guid><pubDate>Thu, 15 May 2008 15:09:58 -0400</pubDate></item><item><title>RE: Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilities (UNCLASSIFIED)</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0174.html"&gt;RE: Cisco Security Advisory: Cisco Unified Presence Denial of Service Vulnerabilities (UNCLASSIFIED)&lt;/a&gt;: Classification: UNCLASSIFIED Caveats: NONE Please advise Theresa Original Message From: nobodyatcisco.com] On Behalf Of Cisco Systems Product Security Incident Response Team Sent: Wednesday, May 14,…</description><link>http://security.tipsdr.com/post/34923859</link><guid>http://security.tipsdr.com/post/34923859</guid><pubDate>Thu, 15 May 2008 13:23:36 -0400</pubDate></item><item><title>Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0173.html"&gt;Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability&lt;/a&gt;: Setting the HTTP response header: Content-Type: text/html; charset=iso-8859-1 or adding the tag:  or even both - still does not deter IE from scanning the contents and interpreting them as UTF-7 when…</description><link>http://security.tipsdr.com/post/34923860</link><guid>http://security.tipsdr.com/post/34923860</guid><pubDate>Thu, 15 May 2008 13:23:36 -0400</pubDate></item><item><title>EBay seller pleads guilty to software piracy charges</title><description>&lt;a href="http://www.infoworld.com/cgi-bin/redirect?source=rss&amp;url=http://www.infoworld.com/article/08/05/15/EBay-seller-pleads-guilty-to-software-piracy-charges_1.html"&gt;EBay seller pleads guilty to software piracy charges&lt;/a&gt;: A 23-year-old Oregon man has pleaded guilty to charges that he used identity theft to set up bogus accounts on eBay, where he sold counterfeit software with a retail value of more than $1 million,…</description><link>http://security.tipsdr.com/post/34922081</link><guid>http://security.tipsdr.com/post/34922081</guid><pubDate>Thu, 15 May 2008 13:02:57 -0400</pubDate></item><item><title>EU raises privacy issue for Google Street View</title><description>&lt;a href="http://www.infoworld.com/cgi-bin/redirect?source=rss&amp;url=http://www.infoworld.com/article/08/05/15/EU-raises-privacy-issue-for-Google-Street-View_1.html"&gt;EU raises privacy issue for Google Street View&lt;/a&gt;: Europe’s data protection supervisor, Peter Hustinx, urged Google Thursday to respect local privacy rules  as it prepares to launch its Street View function this side of the Atlantic.</description><link>http://security.tipsdr.com/post/34922082</link><guid>http://security.tipsdr.com/post/34922082</guid><pubDate>Thu, 15 May 2008 13:02:57 -0400</pubDate></item><item><title>Verizon snares $678 million federal network contract</title><description>&lt;a href="http://www.infoworld.com/cgi-bin/redirect?source=rss&amp;url=http://www.infoworld.com/article/08/05/15/Verizon-snares-678-million-federal-contract_1.html"&gt;Verizon snares $678 million federal network contract&lt;/a&gt;: Verizon Business has captured one of the largest federal network deals of 2008: a 10-year contract to provide managed network and security services to the U.S. Department of Homeland Security that is…</description><link>http://security.tipsdr.com/post/34922083</link><guid>http://security.tipsdr.com/post/34922083</guid><pubDate>Thu, 15 May 2008 13:02:57 -0400</pubDate></item><item><title>Non-tech criminals can now rent-a-botnet</title><description>&lt;a href="http://www.infoworld.com/cgi-bin/redirect?source=rss&amp;url=http://www.infoworld.com/article/08/05/15/Non-tech-criminals-can-now-rent-a-botnet_1.html"&gt;Non-tech criminals can now rent-a-botnet&lt;/a&gt;: Online fraudsters that aren’t highly skilled in the arts of cybercrime can now rent a service that offers an all-in-one hosting server with a built-in Zeus Trojan administration panel and infecting…</description><link>http://security.tipsdr.com/post/34922084</link><guid>http://security.tipsdr.com/post/34922084</guid><pubDate>Thu, 15 May 2008 13:02:57 -0400</pubDate></item><item><title>Kostenloses Linkmanagementscript SQL Injection Vulnerabilities</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0170.html"&gt;Kostenloses Linkmanagementscript SQL Injection Vulnerabilities&lt;/a&gt;: # # # …::::Kostenloses Linkmanagementscript SQL Injection Vulnerabilities ::::… # Virangar Security Team &lt;a href="http://www.virangar.net"&gt;www.virangar.net&lt;/a&gt; Discoverd By :virangar security team(hadihadi) special tnx…</description><link>http://security.tipsdr.com/post/34917543</link><guid>http://security.tipsdr.com/post/34917543</guid><pubDate>Thu, 15 May 2008 12:20:08 -0400</pubDate></item><item><title>Debian generated SSH-Keys working exploit</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0171.html"&gt;Debian generated SSH-Keys working exploit&lt;/a&gt;: Hi Securityfocus, the debian openssl issue leads that there are only 65.536 possible ssh keys generated, cause the only entropy is the pid of the process generating the key. …</description><link>http://security.tipsdr.com/post/34917540</link><guid>http://security.tipsdr.com/post/34917540</guid><pubDate>Thu, 15 May 2008 12:20:07 -0400</pubDate></item><item><title>Aruba Mobility Controller TACACS User Authentication and Cross Site Scripting Vulnerabilities (Aruba Advisory ID: AID-051408)</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0172.html"&gt;Aruba Mobility Controller TACACS User Authentication and Cross Site Scripting Vulnerabilities (Aruba Advisory ID: AID-051408)&lt;/a&gt;: Aruba Networks Security Advisory Title: Aruba Mobility Controller TACACS User Authentication and Cross Site Scripting Vulnerabilities Aruba Advisory ID: AID-051408 Revision: 1.0 For Public Release on…</description><link>http://security.tipsdr.com/post/34917538</link><guid>http://security.tipsdr.com/post/34917538</guid><pubDate>Thu, 15 May 2008 12:20:06 -0400</pubDate></item><item><title>Phishing botnet expands by hacking legit sites</title><description>&lt;a href="http://www.topix.net/tech/computer-security/2008/05/phishing-botnet-expands-by-hacking-legit-sites?fromrss=1"&gt;Phishing botnet expands by hacking legit sites&lt;/a&gt;: &lt;p class="lede_quote"&gt;“The tool does not spread on its own but relies on the Asprox botnet to propagate to new hosts”&lt;/p&gt; &lt;p&gt; A botnet is now using a SQL-injection attack tool designed to hack legitimate Web sites, a move…&lt;/p&gt;</description><link>http://security.tipsdr.com/post/34908558</link><guid>http://security.tipsdr.com/post/34908558</guid><pubDate>Thu, 15 May 2008 10:56:28 -0400</pubDate></item><item><title>Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability</title><description>&lt;a href="http://www.seclists.org/lists/bugtraq/2008/May/0169.html"&gt;Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability&lt;/a&gt;: Hello, Please try to understand what we did here. You might be right in here: “As all ISO, UTF-8 and related charsets were 7-bit clean, it’s clear that Microsoft err’ed on the side of accepting UTF-7…</description><link>http://security.tipsdr.com/post/34903897</link><guid>http://security.tipsdr.com/post/34903897</guid><pubDate>Thu, 15 May 2008 10:12:31 -0400</pubDate></item><item><title>Colonel suggests using hackers' tool against them</title><description>&lt;a href="http://www.topix.net/tech/computer-security/2008/05/colonel-suggests-using-hackers-tool-against-them?fromrss=1"&gt;Colonel suggests using hackers' tool against them&lt;/a&gt;: &lt;p class="lede_quote"&gt;“To me it’s a silly solution to a problem that has much simpler solutions”&lt;/p&gt; &lt;p&gt; By JORDAN ROBERTSON Thursday, May 15, 2008 Hackers often harness the combined power of thousands of virus-infected…&lt;/p&gt;</description><link>http://security.tipsdr.com/post/34886194</link><guid>http://security.tipsdr.com/post/34886194</guid><pubDate>Thu, 15 May 2008 06:43:12 -0400</pubDate></item><item><title>Hacker writes rootkit for Cisco's routers</title><description>&lt;a href="http://www.topix.net/tech/computer-security/2008/05/hacker-writes-rootkit-for-ciscos-routers?fromrss=1"&gt;Hacker writes rootkit for Cisco's routers&lt;/a&gt;: &lt;p class="lede_quote"&gt;“We’re still in the process of putting the whole presentation together, and we also need to work with Cisco before we talk to anybody”&lt;/p&gt; &lt;p&gt; A security researcher has developed malicious rootkit…&lt;/p&gt;</description><link>http://security.tipsdr.com/post/34867474</link><guid>http://security.tipsdr.com/post/34867474</guid><pubDate>Thu, 15 May 2008 02:30:22 -0400</pubDate></item></channel></rss>
