<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
	<title>softsecurity.com This day highlights</title>
	<link>http://www.softsecurity.com</link>
	<description>This day highlights</description>
	<language />
	<copyright />
	<pubDate>Thu, 28 Aug 2008 13:30:41 GMT</pubDate>
	<lastBuildDate>Thu, 28 Aug 2008 13:30:41 GMT</lastBuildDate>
	<category />
	<image />
	
	<item>
		<title>French train tickets go USB</title>
		<link>http://softsecurity.com/news_D3002_high.html</link>
		<description>We don't need no stinkin' ISO7816
The French National Railway Company is trialling contactless tickets with USB connections, replacing the ubiquitous ISO7816 for online top-ups and data storage.&amp;hellip;</description>
		<pubDate>Thu, 28 Aug 2008 10:51:04 GMT</pubDate>
	</item>
	<item>
		<title>McKinnon heads for the last chance saloon</title>
		<link>http://softsecurity.com/news_D3001_high.html</link>
		<description>Pentagon hacker's final appeal
Accused Pentagon hacker Gary McKinnon is approaching his own D-Day, with his fate due to be sealed in the European Court of Human Rights in Strasbourg.&amp;hellip;</description>
		<pubDate>Thu, 28 Aug 2008 09:52:00 GMT</pubDate>
	</item>
	<item>
		<title>Rootkit evolution</title>
		<link>http://softsecurity.com/news_D3000_high.html</link>
		<description>This article is the third in a series devoted to the evolution of viruses and anti-virus solutions</description>
		<pubDate>Thu, 28 Aug 2008 06:00:00 GMT</pubDate>
	</item>
	<item>
		<title>Security World:  SSH key-based attacks</title>
		<link>http://softsecurity.com/news_D2997_high.html</link>
		<description>US-CERT is aware of active attacks against Linux-based computing infrastructures using compromised SSH keys. The attack appears to initially use stolen SSH keys to gain access to a system, and then us...</description>
		<pubDate>Thu, 28 Aug 2008 04:40:32 GMT</pubDate>
	</item>
	<item>
		<title>Security World:  A third of IT staff snoop at confidential data</title>
		<link>http://softsecurity.com/news_D2998_high.html</link>
		<description>Exercise extreme caution when it comes to dismissing employees with knowledge of your IT systems. Cyber-Ark's annual survey around Trust, Security &amp; Passwords focused on 300 IT security professional...</description>
		<pubDate>Thu, 28 Aug 2008 04:30:11 GMT</pubDate>
	</item>
	<item>
		<title>Off the wire:  Use and manipulate tcsh shell variables for fun and profit</title>
		<link>http://softsecurity.com/news_D2982_high.html</link>
		<description>Tcsh is one of the most popular UNIX shells. Learn how you can use tcsh shell variables to make your work easier and how to take advantage of tcsh's advanced security features.</description>
		<pubDate>Thu, 28 Aug 2008 04:26:39 GMT</pubDate>
	</item>
	<item>
		<title>Off the wire:  Deploying enterprise software securely</title>
		<link>http://softsecurity.com/news_D2983_high.html</link>
		<description>This laundry list of security requirements is a lot to think about for every application deployment, but vigilance in this area can drastically improve an organizations security posture. The requirem...</description>
		<pubDate>Thu, 28 Aug 2008 03:57:46 GMT</pubDate>
	</item>
	<item>
		<title>Virus Center:  More malware blocked in July 2008 than in the whole of 2007</title>
		<link>http://softsecurity.com/news_D2984_high.html</link>
		<description>In its Global Threat Report ScanSafe reported that the total number of Web-based malware blocks has increased by 87 per cent in July 2008 compared to the previous month. Specifically, the first two we...</description>
		<pubDate>Thu, 28 Aug 2008 03:48:30 GMT</pubDate>
	</item>
	<item>
		<title>Security World:  Panda Security launches its 2009 antivirus products</title>
		<link>http://softsecurity.com/news_D2985_high.html</link>
		<description>Panda Security has launched its 2009 range of antivirus solutions for the consumer sector. The product line-up comprises Panda Antivirus Pro 2009, Panda Internet Security 2009 and Panda Global Protect...</description>
		<pubDate>Thu, 28 Aug 2008 03:43:01 GMT</pubDate>
	</item>
	<item>
		<title>Gaping hole opened in Internet's trust-based BGP protocol</title>
		<link>http://softsecurity.com/news_D2999_high.html</link>
		<description>New details on an old bug could bring the BGP protocol's vulnerability back into the spotlight, some ten years after it was first reported. This particular problem is considered by experts to be at least as bad as last month's  well-publicized DNS, but in this case, there's no ready-made solution.  &lt;a href=&quot;http://arstechnica.com/news.ars/post/20080827-inherent-security-flaw-poses-risk-to-internet-users.html&quot;&gt;Read More...&lt;/a&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/arstechnica/security/~4/376678111&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Thu, 28 Aug 2008 01:20:00 GMT</pubDate>
	</item>
	<item>
		<title>Passcode exploit (and fix) found for locked iPhones</title>
		<link>http://softsecurity.com/news_D2994_high.html</link>
		<description>Think your iPhone is safe if it's locked? Think again. An exploit has made the rounds today, allowing anyone to gain access to your personal info on a locked iPhone very easily. Luckily, there's also an easy way to prevent it, although Apple should patch the hole ASAP.&lt;a href=&quot;http://arstechnica.com/journals/apple.ars/2008/08/27/passcode-exploit-and-fix-found-for-locked-iphones&quot;&gt;Read More...&lt;/a&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/arstechnica/security/~4/376539447&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 27 Aug 2008 21:51:00 GMT</pubDate>
	</item>
	<item>
		<title>Report: Popular Web Attacks Go Stealth</title>
		<link>http://softsecurity.com/news_D2981_high.html</link>
		<description>Attackers are increasingly using encoding to sneak their SQL injection, cross-site scripting attacks past Web security</description>
		<pubDate>Wed, 27 Aug 2008 21:45:00 GMT</pubDate>
	</item>
	<item>
		<title>MSN Norway serving Flash exploits through malvertising</title>
		<link>http://softsecurity.com/news_D2990_high.html</link>
		<description>Morten Krakvik from the Norwegian Honeynet Project is reporting that MSN Norway is among the latest victims of malvertising, a practice where a bogus advertising provider tricks leading portals into accepting advertisements from its network, which often end up redirecting to live exploit URLs. The recent wave of malvertising that also targeted Digg, MSNBC and [...]&lt;br style=&quot;clear: both;&quot;/&gt;
  &lt;img alt=&quot;&quot; style=&quot;border: 0; height:1px; width:1px;&quot; border=&quot;0&quot; src=&quot;http://www.pheedo.com/img.phdo?i=fe3b0a7403b3bf922000f0ad625f9446&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;
&lt;img src=&quot;http://www.pheedo.com/feeds/tracker.php?i=fe3b0a7403b3bf922000f0ad625f9446&quot; style=&quot;display: none;&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; alt=&quot;&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/376547732&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 27 Aug 2008 21:44:02 GMT</pubDate>
	</item>
	<item>
		<title>Hijacking huge chunks of the internet - a new How To</title>
		<link>http://softsecurity.com/news_D2980_high.html</link>
		<description>It's easy. Those tubes are busted
More evidence that the intertubes are fundamentally broken has been served up by Wired.com in an article laying out a technique to surreptitiously hijack huge chunks of the internet and monitor or even modify unencrypted traffic before it reaches its intended destination.&amp;hellip;</description>
		<pubDate>Wed, 27 Aug 2008 21:16:50 GMT</pubDate>
	</item>
	<item>
		<title>Microsoft Offers Details on Privacy Features in IE8</title>
		<link>http://softsecurity.com/news_D2979_high.html</link>
		<description>New browser will allow user to better control access to surfing history, cookies</description>
		<pubDate>Wed, 27 Aug 2008 20:46:00 GMT</pubDate>
	</item>
	<item>
		<title>Web to get more social as OAuth is sanctioned for use </title>
		<link>http://softsecurity.com/news_D2995_high.html</link>
		<description>A promising new protocol for securely and easily transferring data between websites is now ready for prime time. All contributors, including Google and Yahoo, have signed a covenant not to sue over OAuth implementations, freeing it for use by virtually anyone.&lt;a href=&quot;http://arstechnica.com/news.ars/post/20080827-web-to-get-more-social-as-oauth-is-sanctioned-for-use.html&quot;&gt;Read More...&lt;/a&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/arstechnica/security/~4/376431608&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 27 Aug 2008 19:01:00 GMT</pubDate>
	</item>
	<item>
		<title>Off the wire:  Whitepaper - Open source security myths dispelled</title>
		<link>http://softsecurity.com/news_D2986_high.html</link>
		<description>Dispel the five major myths surrounding Open Source Security and gain the tools necessary to make a truly informed decision for your IT organization.</description>
		<pubDate>Wed, 27 Aug 2008 18:48:42 GMT</pubDate>
	</item>
	<item>
		<title>Security World:  BT enhances security monitoring service</title>
		<link>http://softsecurity.com/news_D2987_high.html</link>
		<description>BT announced the enhancement of its global Event Monitoring and Correlation service to further defend enterprise networks against the growing threat of malicious botnet attacks. Using new proprietary ...</description>
		<pubDate>Wed, 27 Aug 2008 18:46:39 GMT</pubDate>
	</item>
	<item>
		<title>Taiwan busts hacking ring, 50 million personal records compromised</title>
		<link>http://softsecurity.com/news_D2991_high.html</link>
		<description>Taiwan&amp;#8217;s Criminal Investigation Bureau (CIB) has successfully tracked down and arrested six people in what the CIB believes to be the biggest personal data breach in Taiwan to date. Apparently, the group also managed to obtain personal data on Taiwan&amp;#8217;s current and former presidents :
&amp;#8220;The suspects are believed to have stolen more than 50 million [...]&lt;br style=&quot;clear: both;&quot;/&gt;
  &lt;img alt=&quot;&quot; style=&quot;border: 0; height:1px; width:1px;&quot; border=&quot;0&quot; src=&quot;http://www.pheedo.com/img.phdo?i=ba6b53a293a4a64df0a36429698d0a8f&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;
&lt;img src=&quot;http://www.pheedo.com/feeds/tracker.php?i=ba6b53a293a4a64df0a36429698d0a8f&quot; style=&quot;display: none;&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; alt=&quot;&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/376418519&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 27 Aug 2008 18:45:01 GMT</pubDate>
	</item>
	<item>
		<title>Windows Live Hotmail to sign in up to 70 percent faster</title>
		<link>http://softsecurity.com/news_D2996_high.html</link>
		<description>Details on the next version of Windows Live Hotmail have emerged thanks to a new promotional website. The Windows Live Hotmail blog hasn't said anything official, though, and has just posted more phishing warnings.&lt;a href=&quot;http://arstechnica.com/journals/microsoft.ars/2008/08/27/windows-live-hotmail-to-sign-in-up-to-70-percent-faster&quot;&gt;Read More...&lt;/a&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/arstechnica/security/~4/376384343&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 27 Aug 2008 18:09:00 GMT</pubDate>
	</item>
	<item>
		<title>Intel ships BIOS fix for Rutkowska&acute;s Black Hat flaw</title>
		<link>http://softsecurity.com/news_D2992_high.html</link>
		<description>Intel has shipped a BIOS update with a fix for a privilege escalation vulnerability that was used by rootkit researcher Joanna Rutkowska to bluepill the Xen hypervisor.
The vulnerability was discussed by Rutkowska at the Black Hat briefings earlier this month but details on the exploit were withheld until Intel could release its patch.
That patch is [...]&lt;br style=&quot;clear: both;&quot;/&gt;
      &lt;a href=&quot;http://www.pheedo.com/click.phdo?s=b842a57607d02e1726351cc166d50041&quot;&gt;&lt;img alt=&quot;&quot; style=&quot;border: 0;&quot; border=&quot;0&quot; src=&quot;http://www.pheedo.com/img.phdo?s=b842a57607d02e1726351cc166d50041&quot;/&gt;&lt;/a&gt;
  &lt;img src=&quot;http://www.pheedo.com/feeds/tracker.php?i=b842a57607d02e1726351cc166d50041&quot; style=&quot;display: none;&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; alt=&quot;&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/376292562&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 27 Aug 2008 15:52:45 GMT</pubDate>
	</item>
	<item>
		<title>Security World:  Wireless DTCP content protection specification</title>
		<link>http://softsecurity.com/news_D2975_high.html</link>
		<description>The Digital Transmission Licensing Administrator (DTLA) has approved and published a new supplement to the Digital Transmission Content Protection (DTCP) Specification for the use of WirelessHD. The r...</description>
		<pubDate>Wed, 27 Aug 2008 13:35:46 GMT</pubDate>
	</item>
	<item>
		<title>iPhone passcode lock rendered useless</title>
		<link>http://softsecurity.com/news_D2993_high.html</link>
		<description>Do not trust that passcode lock on Apple&amp;#8217;s iPhone.
The feature, which lets users set a four-digit pincode to limit access to the device, can be easily bypassed with a few finger taps on the iPhone to give an intruder access to sensitive information.
Here are a few steps to reproduce this vulnerability (requires physical access to [...]&lt;br style=&quot;clear: both;&quot;/&gt;
  &lt;img alt=&quot;&quot; style=&quot;border: 0; height:1px; width:1px;&quot; border=&quot;0&quot; src=&quot;http://www.pheedo.com/img.phdo?i=b924e7bcfada68c6423e2bf7606fd177&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;
&lt;img src=&quot;http://www.pheedo.com/feeds/tracker.php?i=b924e7bcfada68c6423e2bf7606fd177&quot; style=&quot;display: none;&quot; border=&quot;0&quot; height=&quot;1&quot; width=&quot;1&quot; alt=&quot;&quot;/&gt;&lt;img src=&quot;http://feeds.feedburner.com/~r/zdnet/security/~4/376187983&quot; height=&quot;1&quot; width=&quot;1&quot;/&gt;</description>
		<pubDate>Wed, 27 Aug 2008 13:19:34 GMT</pubDate>
	</item>
	<item>
		<title>Article:  Application Security Matters: Deploying Enterprise Software Securely</title>
		<link>http://softsecurity.com/news_D2974_high.html</link>
		<description>One of the most interesting aspects of being an information security consultant is the exposure to an enormous variety of industries and organizations. From health care to governments, nonprofits to s...</description>
		<pubDate>Wed, 27 Aug 2008 12:08:48 GMT</pubDate>
	</item>
	<item>
		<title>Microsoft dishes dirt on IE8 'pr0n mode'</title>
		<link>http://softsecurity.com/news_D2977_high.html</link>
		<description>'Off the record' browsing is go
Microsoft has outlined the new privacy tools available in its forthcoming browser Internet Explorer 8 (IE8).&amp;hellip;</description>
		<pubDate>Wed, 27 Aug 2008 10:58:32 GMT</pubDate>
	</item>
	<item>
		<title>iPhone passwords not worth the paper they're written on</title>
		<link>http://softsecurity.com/news_D2976_high.html</link>
		<description>Push two keys to bypass password
iPhones protected by a password aren't actually protected at all, as just by pressing a few keys a miscreant can access all the phone's functions without needing the password at all.&amp;hellip;</description>
		<pubDate>Wed, 27 Aug 2008 10:42:39 GMT</pubDate>
	</item>
	<item>
		<title>Security World:  HNS Book giveaway: "The Best of 2600 - A Hacker Odyssey"</title>
		<link>http://softsecurity.com/news_D2960_high.html</link>
		<description>We are giving one of our readers a copy of &quot;The Best of 2600 - A Hacker Odyssey&quot;.
 
 Since 1984, the quarterly magazine 2600 has provided fascinating articles for readers who are curious about technol...</description>
		<pubDate>Wed, 27 Aug 2008 02:15:17 GMT</pubDate>
	</item>
	<item>
		<title>Off the wire:  Most organizations fail to stop interior network threats</title>
		<link>http://softsecurity.com/news_D2961_high.html</link>
		<description>A survey by Opine Consulting revealed nearly half of the IT professionals who responded had endpoints connecting to their corporate networks without their knowledge. Yet compared to other security iss...</description>
		<pubDate>Wed, 27 Aug 2008 01:25:47 GMT</pubDate>
	</item>
	<item>
		<title>US data breaches booming in '08</title>
		<link>http://softsecurity.com/news_D2971_high.html</link>
		<description>Have you seen my identity?
The number of personal information leaks reported in the US this year have already exceeded the total amount in all of 2007, San Diego-based Identity Theft Resource Center said today.&amp;hellip;</description>
		<pubDate>Wed, 27 Aug 2008 00:22:41 GMT</pubDate>
	</item>
	<item>
		<title>CERT: Linux servers under 'Phalanx' attack</title>
		<link>http://softsecurity.com/news_D2972_high.html</link>
		<description>Stolen keys unlock back door
Attacks in the wild are under way against Linux systems with compromised SSH keys, the US Computer Emergency Readiness Team is warning.&amp;hellip;</description>
		<pubDate>Wed, 27 Aug 2008 00:13:09 GMT</pubDate>
	</item>
</channel>
</rss>