<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>gHacks technology news &#187; vulnerabilities</title>
	<atom:link href="http://www.ghacks.net/tag/vulnerabilities/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ghacks.net</link>
	<description>A technology blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description>
	<lastBuildDate>Tue, 24 Nov 2009 09:43:13 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Patch Tuesday December 08</title>
		<link>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/</link>
		<comments>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/#comments</comments>
		<pubDate>Wed, 10 Dec 2008 21:06:27 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[microsoft patchday]]></category>
		<category><![CDATA[microsoft patches]]></category>
		<category><![CDATA[patch tuesday]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<category><![CDATA[windows patches]]></category>
		<category><![CDATA[windows security]]></category>
		<category><![CDATA[windows-update]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/?p=8835</guid>
		<description><![CDATA[Microsoft released another batch of patches using their regular schedule. A total of eight security bulletins have been published that contain descriptions of security vulnerabilities of which six have been classified as critical and two as important.
The easiest way to install the patches is by downloading and installing the security patches at Windows Update which [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft released another batch of patches using their regular schedule. A total of eight security bulletins have been published that contain descriptions of security vulnerabilities of which six have been classified as critical and two as important.</p>
<p>The easiest way to install the patches is by downloading and installing the security patches at <a href="http://www.update.microsoft.com">Windows Update</a> which provides access to all security updates even for users who run a non legit version of Windows.</p>
<p>Microsoft did also release a new version of the Windows Malicious Software Removal Tool which is now able to detect two new families of malware (Win32/FakeXPA and Win32/Yektel)</p>
<p><span id="more-8835"></span>
<ul>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-070.mspx">MS08-070</a>: Vulnerabilities in Visual Basic 6.0 Runtime Extended Files (ActiveX Controls) Could Allow Remote Code Execution (932349) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-071.mspx">MS08-071</a>: Vulnerabilities in GDI Could Allow Remote Code Execution (956802) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-072.mspx">MS08-072</a>: Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (957173) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-073.mspx">MS08-073</a>: Cumulative Security Update for Internet Explorer (958215) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-074.mspx">MS08-074</a>: Vulnerabilities in Microsoft Office Excel Could Allow Remote Code Execution (959070) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-075.mspx">MS08-075</a>: Vulnerabilities in Windows Search Could Allow Remote Code Execution (959349) which is rated &#8220;Critical&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-076.mspx">MS08-076</a>: Vulnerabilities in Windows Media Components Could Allow Remote Code Execution (959807) which is rated &#8220;Important&#8221;</li>
<li><a href="http://www.microsoft.com/technet/security/Bulletin/MS08-077.mspx">MS08-077</a>: Vulnerability in Microsoft Office SharePoint Server Could Cause Elevation of Privilege (957175) which is rated &#8220;Important&#8221;</li>
</ul>
<p>Windows users should install the updates as soon as possible to secure their computer system.</p>

	Tags: <a href="http://www.ghacks.net/tag/microsoft-patchday/" title="microsoft patchday" rel="tag">microsoft patchday</a>, <a href="http://www.ghacks.net/tag/microsoft-patches/" title="microsoft patches" rel="tag">microsoft patches</a>, <a href="http://www.ghacks.net/tag/patch-tuesday/" title="patch tuesday" rel="tag">patch tuesday</a>, <a href="http://www.ghacks.net/tag/vulnerabilities/" title="vulnerabilities" rel="tag">vulnerabilities</a>, <a href="http://www.ghacks.net/tag/windows-patches/" title="windows patches" rel="tag">windows patches</a>, <a href="http://www.ghacks.net/tag/windows-security/" title="windows security" rel="tag">windows security</a>, <a href="http://www.ghacks.net/tag/windows-update/" title="windows-update" rel="tag">windows-update</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2009/11/11/microsoft-security-updates-november-2009/" title="Microsoft Security Updates November 2009 (November 11, 2009)">Microsoft Security Updates November 2009</a> (2)</li>
	<li><a href="http://www.ghacks.net/2009/06/10/microsoft-security-patches-for-june-2009/" title="Microsoft Security Patches for June 2009 (June 10, 2009)">Microsoft Security Patches for June 2009</a> (12)</li>
	<li><a href="http://www.ghacks.net/2008/04/08/microsoft-security-patches-april-2008/" title="Microsoft Security Patches April 2008 (April 8, 2008)">Microsoft Security Patches April 2008</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/11/12/microsoft-patch-tuesday-november-08/" title="Microsoft Patch Tuesday November 08 (November 12, 2008)">Microsoft Patch Tuesday November 08</a> (0)</li>
	<li><a href="http://www.ghacks.net/2009/04/15/microsoft-security-updates-april-2009/" title="Microsoft Security Updates April 2009 (April 15, 2009)">Microsoft Security Updates April 2009</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2008/12/10/microsoft-patch-tuesday-december-08/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Five common Web application vulnerabilities</title>
		<link>http://www.ghacks.net/2006/05/03/five-common-web-application-vulnerabilities/</link>
		<comments>http://www.ghacks.net/2006/05/03/five-common-web-application-vulnerabilities/#comments</comments>
		<pubDate>Wed, 03 May 2006 15:52:28 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2006/05/03/five-common-web-application-vulnerabilities/</guid>
		<description><![CDATA[The article "Five common Web application vulnerabilities" lists and explains five common attack forms and presents an example how this vulnerability could have been exploited. The explanation is clearly aimed at people who do not have dealt with such vulnerabilities before, seems to be a great way to start and getting informed.]]></description>
			<content:encoded><![CDATA[<p>The article &#8220;<a target="_blank" href="http://www.securityfocus.com/infocus/1864">Five common Web application vulnerabilities</a>&#8221; lists and explains five common attack forms and presents an example how this vulnerability could have been exploited. The explanation is clearly aimed at people who do not have dealt with such vulnerabilities before, seems to be a great way to start and getting informed.<br />
The five attacks in question are:</p>
<p><span class="body"></p>
<ol>
<li>Remote code execution</li>
<li>SQL injection</li>
<li>Format string vulnerabilities</li>
<li>Cross Site Scripting (XSS)</li>
<li>Username enumeration</li>
</ol>
<p><span id="more-463"></span><br />
</span>Another great feature of this article is the reference section beneath each attack form which provides you with more indepth information about the subject. Again, a great way to get started.<br />
<span class="body" /></p>
<p><span class="body" /></p>

	Tags: <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/vulnerabilities/" title="vulnerabilities" rel="tag">vulnerabilities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/04/18/scurn-security-vulnerability-search-engine/" title="Scurn &#8211; Security Vulnerability Search Engine (April 18, 2006)">Scurn &#8211; Security Vulnerability Search Engine</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/yahoo-marks-dangerous-search-results/" title="Yahoo marks dangerous search results (May 7, 2008)">Yahoo marks dangerous search results</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/08/11/wordpress-remote-admin-password-reset-vulnerability/" title="Wordpress Remote Admin Password Reset Vulnerability (August 11, 2009)">Wordpress Remote Admin Password Reset Vulnerability</a> (13)</li>
	<li><a href="http://www.ghacks.net/2006/07/22/wireless-hotspot-hacks/" title="Wireless Hotspot Hacks (July 22, 2006)">Wireless Hotspot Hacks</a> (1)</li>
	<li><a href="http://www.ghacks.net/2006/03/12/windows-worms-door-cleaner/" title="Windows Worms Door Cleaner (March 12, 2006)">Windows Worms Door Cleaner</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2006/05/03/five-common-web-application-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scurn &#8211; Security Vulnerability Search Engine</title>
		<link>http://www.ghacks.net/2006/04/18/scurn-security-vulnerability-search-engine/</link>
		<comments>http://www.ghacks.net/2006/04/18/scurn-security-vulnerability-search-engine/#comments</comments>
		<pubDate>Tue, 18 Apr 2006 07:17:19 +0000</pubDate>
		<dc:creator>Martin</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[scurn]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.ghacks.net/2006/04/18/scurn-security-vulnerability-search-engine/</guid>
		<description><![CDATA[Cirt.net provides an easy and fast way to search many sites that post security vulnerabilites. The search engine uses the databases of the following sites: Bugtraq, CVE, ISS, OSVDB, Secunia, Snort, Nessus, Packetstorm, Security Tracker, Bugtraq Mailing List and Full-Disclosure Mailing List. The latest security vulnerabilites are reported to those sites and you are able to check them all with this search engine. ]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.cirt.net/scurn/" target="_blank">Cirt.net</a> provides an easy and fast way to search many sites that post security vulnerabilites. The search engine uses the databases of the following sites: Bugtraq, CVE, ISS, OSVDB, Secunia, Snort, Nessus, Packetstorm, Security Tracker, Bugtraq Mailing List and Full-Disclosure Mailing List. The latest security vulnerabilites are reported to those sites and you are able to check them all with this search engine.</p>
<p>This is great for everyone who works with more than one of those sites, get ready to save some time. It´s also a great way for website owners to stay up to date and secure their websites by knowing and fixing the latest publically known vulnerabilities.</p>
<p><span id="more-418"></span></p>

	Tags: <a href="http://www.ghacks.net/tag/scurn/" title="scurn" rel="tag">scurn</a>, <a href="http://www.ghacks.net/tag/security/" title="Security" rel="tag">Security</a>, <a href="http://www.ghacks.net/tag/vulnerabilities/" title="vulnerabilities" rel="tag">vulnerabilities</a><br />

	<h4>Related posts</h4>
	<ul class="st-related-posts">
	<li><a href="http://www.ghacks.net/2006/05/03/five-common-web-application-vulnerabilities/" title="Five common Web application vulnerabilities (May 3, 2006)">Five common Web application vulnerabilities</a> (0)</li>
	<li><a href="http://www.ghacks.net/2008/05/07/yahoo-marks-dangerous-search-results/" title="Yahoo marks dangerous search results (May 7, 2008)">Yahoo marks dangerous search results</a> (4)</li>
	<li><a href="http://www.ghacks.net/2009/08/11/wordpress-remote-admin-password-reset-vulnerability/" title="Wordpress Remote Admin Password Reset Vulnerability (August 11, 2009)">Wordpress Remote Admin Password Reset Vulnerability</a> (13)</li>
	<li><a href="http://www.ghacks.net/2006/07/22/wireless-hotspot-hacks/" title="Wireless Hotspot Hacks (July 22, 2006)">Wireless Hotspot Hacks</a> (1)</li>
	<li><a href="http://www.ghacks.net/2006/03/12/windows-worms-door-cleaner/" title="Windows Worms Door Cleaner (March 12, 2006)">Windows Worms Door Cleaner</a> (2)</li>
</ul>

]]></content:encoded>
			<wfw:commentRss>http://www.ghacks.net/2006/04/18/scurn-security-vulnerability-search-engine/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
