<?xml version="1.0" encoding="ISO-8859-1" ?>
	<rss version="2.0">
        	<channel>
                	<title>Security Scraper Feeds</title>
                        <link>http://www.securityscraper.com/</link>
                        <description>The security feed that doesn't loose an appetite.</description>
                        <language>en-us</language>
		<item>
                        <title>Microsoft Security Advisory (981374): Vulnerability in Internet Explorer Could Allow Remote Code Execution - 3/10/2010</title>
                        <link>http://www.securityscraper.com/index.php?item=378428</link>
                        <description>Revision Note: V1.1 (March 10, 2010): Restated the mitigation concerning the e-mail vector. Added a new workaround for disabling the peer factory class in iepeers.dll. Advisory Summary:Microsoft is investigating new, public reports of a vulnerability in Internet Explorer 6 and Internet Explorer 7. Our investigation has shown that the latest version of the browser, Internet Explorer 8, is not affected. The main impact of the vulnerability is remote code execution. This advisory contains information about which versions of Internet Explorer are vulnerable as well as workarounds and mitigations for this issue.</description>
                </item><item>
                        <title>Expert says Chinese government likely behind massive cyberattacks</title>
                        <link>http://www.securityscraper.com/index.php?item=378427</link>
                        <description>The Chinese government is likely behind recent cyberattacks on U.S. government Web sites and on U.S. companies in an apparent effort to quash criticism of the government there, an expert on U.S. and Chinese relations said Wednesday.</description>
                </item><item>
                        <title>Cisco, Microsoft certifications increase high-tech salaries</title>
                        <link>http://www.securityscraper.com/index.php?item=378426</link>
                        <description>For high-tech workers, it pays to be certified, according to research conducted by Dice Learning that shows 10 IT certifications stand out for delivering higher salaries.</description>
                </item><item>
                        <title>Google still tops, but Bing inches ahead in search market</title>
                        <link>http://www.securityscraper.com/index.php?item=378425</link>
                        <description>Microsoft in recent months has slowly boosted its share of the search business, but still remains far behind a so-far unbeatable foe in its battle with Google. Hitwise, an online traffic monitor, today reported that Google last month remained firmly at the head of the search pack while its rival's well regarded Microsoft Bing product gradually picks up a little traction.</description>
                </item><item>
                        <title>CA to buy Nimsoft</title>
                        <link>http://www.securityscraper.com/index.php?item=378424</link>
                        <description>CA said Wednesday it has signed a deal to buy IT performance monitoring vendor Nimsoft for $350 million. The acquisition, which is scheduled to close this month, will strengthen CA's hand in IT management software for what it calls "emerging enterprises," companies with annual revenues between $300 million and $2 billion.[ Stay ahead of the key tech business news with InfoWorld's Today's Headlines: First Look newsletter. ]</description>
                </item><item>
                        <title>50MHz to 100Mhz scope conversion</title>
                        <link>http://www.securityscraper.com/index.php?item=378423</link>
                        <description>
[Ross] is the proud owner of a 50 MHz Rigol DS1052E oscilloscope. He&amp;#8217;d like to have the 100 MHz version but the $400 difference in price puts it out of his reach. After some extensive poking around on the PCB and pouring over datasheets, he managed to reverse engineer the design and upgrade to a [...]</description>
                </item><item>
                        <title>Coffee powered Car-puccino</title>
                        <link>http://www.securityscraper.com/index.php?item=378422</link>
                        <description>
We can only imagine how amazing this coffee burning car smells at it speeds down the highway at a maximum of 60mph. Don&amp;#8217;t jump out of your seat so quick to get your own, while the idea sounds fantastic, the mileage will bring you back to earth rather quick. At 3 miles per kilo of [...]</description>
                </item><item>
                        <title>Suing Over Patents Is An Act Of Desperation</title>
                        <link>http://www.securityscraper.com/index.php?item=378421</link>
                        <description>From DailyTech
March 10, 2010 - said by Jason Mick :Apple Tried to Bully Sun With Lawsuit Threats in 2003

Faced with the growing threat of the Android army of smartphones to its best-selling iPhone, Apple unleashed a litany of litigation to try to stop sales of the phones.  Google is too powerful to attack head on, so instead Apple is trying to pick off the hardware makers, starting with HTC, makers of the Hero, MyTouch, and Nexus One.  There are a lot of questions over whether Apple's barking up the wrong tree, however, given how broad and vague its patents seem.

Jonathan I. Schwartz, former CEO of Sun Microsystems, sounded off in a blog in which he recalls a similar incident in which Apple CEO Steven P. Jobs threatened to sue his company.  

The event occurred back in 2003. Sun Microsystems had just unveiled "Project Looking Glass", a prototype Linux desktop with a rich 3D graphical desktop environment &amp;#150; Apple wasn't happy about that.

Jobs contact Schwartz, warning that the Linux project was "stepping all over Apple&amp;#146;s IP" and that if they put it out on the market, "I&amp;#146;ll just sue you."

However, Schwartz was wily and knew how to fight back.  He had helped found Lighthouse Design, which made software for the short-lived NeXTSTEP operating system, which was acquired by Apple with the purchase of NeXT in 1996.  A Lighthouse NeXT product, Concurrency (presentation software -- think PowerPoint), looked eerily similar to Apple's recently unveiled Keynote.

So Schwartz fired back at Jobs, "Steve, I was just watching your last presentation, and Keynote looks identical to Concurrence &amp;#150; do you own that IP?  And last I checked, MacOS is now built on Unix. I think Sun has a few OS patents, too."

Jobs was quiet and never threatened Schwartz about the product again.

He notes that Jobs isn't the only litigation bully in the tech industry, though.  He recalls an exchange in a later meeting with former Microsoft CEO Bill Gates and current CEO Steve Ballmer, about OpenOffice, a popular Sun product.  In th</description>
                </item><item>
                        <title>0017004: Data Buffer Size Exceeded!</title>
                        <link>http://www.securityscraper.com/index.php?item=378420</link>
                        <description>All of our phone calls have been fading in and out almost like the person on the other end is going through a tunnel.  It sounds like a cell phone call being disrupted.  

This is causing a lot of issues within our company with leads not hearing us talk and we are having to repeat ourselves numerous times.

Other error messages are showing within our system that have not shown before.  I have attached the error log below.  

Need help ASAP!</description>
                </item><item>
                        <title>A day of IDS (Snort) event data</title>
                        <link>http://www.securityscraper.com/index.php?item=378419</link>
                        <description></description>
                </item><item>
                        <title>Sun VirtualBox DoS</title>
                        <link>http://www.securityscraper.com/index.php?item=378418</link>
                        <description> Applications: xVM VirtualBox 1.6, xVM VirtualBox 2.0, xVM VirtualBox 2.1, xVM VirtualBox 2.2 (11.03.2010)</description>
                </item><item>
                        <title>kvm multiple security vulnerabilities</title>
                        <link>http://www.securityscraper.com/index.php?item=378417</link>
                        <description>DoS, privilege escalation. Applications: kvm 72 (11.03.2010)</description>
                </item><item>
                        <title>Microsoft Excel multiple security vulnerabilities, updated since 10.03.2010</title>
                        <link>http://www.securityscraper.com/index.php?item=378416</link>
                        <description>Multiple buffer overflows, memory corruptions, code execution. Applications: Office XP, Office 2003, Office 2004 for Mac, Office 2007, Office 2008 for Mac (11.03.2010)</description>
                </item><item>
                        <title>Web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)</title>
                        <link>http://www.securityscraper.com/index.php?item=378415</link>
                        <description>PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc. Applications: WordPress 2.9, Kandidat CMS 1.3, Chaton 1.5, tdiary 2.2, Employee Timeclock 0.99 (11.03.2010)</description>
                </item><item>
                        <title>XNView buffer overflow</title>
                        <link>http://www.securityscraper.com/index.php?item=378414</link>
                        <description>Integer overflow on DICOM images parsing leading to buffer overflow. Applications: XnView 1.97 (11.03.2010)</description>
                </item><item>
                        <title>[ MDVSA-2010:059 ] virtualbox</title>
                        <link>http://www.securityscraper.com/index.php?item=378413</link>
                        <description>Posted by security on Mar 10 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2010:059
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : virtualbox
 Date    : March 10, 2010
 Affected: 2008.0, 2009.0, 2009.1, 2010.0
 _______________________________________________________________________

 Problem Description:

 A...</description>
                </item><item>
                        <title>[USN-908-1] Apache vulnerabilities</title>
                        <link>http://www.securityscraper.com/index.php?item=378412</link>
                        <description>Posted by Marc Deslauriers on Mar 10===========================================================
Ubuntu Security Notice USN-908-1             March 10, 2010
apache2 vulnerabilities
CVE-2010-0408, CVE-2010-0434
===========================================================

A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 8.04 LTS
Ubuntu 8.10
Ubuntu 9.04
Ubuntu 9.10

This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and...</description>
                </item><item>
                        <title>Re: GeoIPgen version 0.4 released -	country-to-IPs generator</title>
                        <link>http://www.securityscraper.com/index.php?item=378411</link>
                        <description>Posted by Adrian P on Mar 10Neat project, and a research topic I've been interested in for several
years. However, it's not the first time that the MaxMind GeoLite
database has been used to generate lists of IP blocks for a given
country (country2ip, rather than ip2country).

October 2007:
http://www.gnucitizen.org/blog/strategic-hacking-geoip/
http://www.gnucitizen.org/static/blog/2007/10/country2ip.ppt</description>
                </item><item>
                        <title>Multiple vulnerabilities in SUPERAntiSpyware and	Super Ad Blocker</title>
                        <link>http://www.securityscraper.com/index.php?item=378410</link>
                        <description>Posted by Luka Milkovic on Mar 10 Title:                              Multiple vulnerabilities in
SUPERAntiSpyware and Super Ad Blocker
 Date of Discovery:         2 Feb 2010
 Contact Date:                4 Feb 2010
 Release Date:                10 Mar 2010
 Author:                          Luka Milkovic
 Mail:                              milkovic.luka at gmail.com
 Software Link:               SUPERAntiSpyware -
http://www.superantispyware.com/index.html...</description>
                </item><item>
                        <title>Re: GeoIPgen version 0.4 released -	country-to-IPs generator</title>
                        <link>http://www.securityscraper.com/index.php?item=378409</link>
                        <description>Posted by Kurt Buff on Mar 10See also:

http://xkcd.com/195/

Though I don't know where he got his data...

Kurt</description>
                </item><item>
                        <title>Re: New Internet Explorer code-execution</title>
                        <link>http://www.securityscraper.com/index.php?item=378408</link>
                        <description>Posted by Moshe Ben Abu on Mar 10Metasploit exploit module now available:
http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/

On Wed, Mar 10, 2010 at 8:29 PM, Pradip Sharma &amp;lt;sharma.pradip () gmail com&amp;gt;wrote:</description>
                </item><item>
                        <title>[ MDVSA-2010:060 ] squid</title>
                        <link>http://www.securityscraper.com/index.php?item=378407</link>
                        <description>Posted by security on Mar 10 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2010:060
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : squid
 Date    : March 10, 2010
 Affected: 2008.0, 2009.0, 2009.1, 2010.0, Corporate 4.0,
           Enterprise Server 5.0...</description>
                </item><item>
                        <title>Re: Help hardening router</title>
                        <link>http://www.securityscraper.com/index.php?item=378406</link>
                        <description>Posted by doug schmidt on Mar 10http://www.cymru.com/Documents/secure-ios-template.html

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a...</description>
                </item><item>
                        <title>Re: Reporting SSH abuse</title>
                        <link>http://www.securityscraper.com/index.php?item=378405</link>
                        <description>Posted by Liquid on Mar 10Dan Pilcheck wrote:

Dan,

Honestly thats more than enough. I've had client sites that were doing 
the same and the notifications were more than ample to at least look 
into it. A nice note to the person should work, we had a couple in the 
past where the admin was a complete jerk in letting us know. So 
personally I'd recommend a screenshot of a log and perhaps just listing 
the IP and what its hammering against. (ssh in this case). Hope this...</description>
                </item><item>
                        <title>RE: Reporting SSH abuse</title>
                        <link>http://www.securityscraper.com/index.php?item=378404</link>
                        <description>Posted by Dan Lynch on Mar 10I could swear I once read an &amp;quot;authoritative&amp;quot; source doc on this subject, maybe an RFC (Site Security Handbook?), or 
something from CERT. But I can't seem to dig it up. Anyone?

Here's what I did find:

Going to the Source: Reporting Security Incidents to ISPs (2002)
http://www.securityfocus.com/infocus/1555

And a most-excellent write up &amp;quot;Composing abuse reports&amp;quot; (2007)
http://blog.anta.net/2007/04/18/composing-abuse-reports/...</description>
                </item><item>
                        <title>Re: Help hardening router</title>
                        <link>http://www.securityscraper.com/index.php?item=378403</link>
                        <description>Posted by Dave LaDuke on Mar 10Thanks for telling him, I had planned to have some fun later.

--------------------------------------------------
From: &amp;quot;Curt Shaffer&amp;quot; &amp;lt;cshaffer () gmail com&amp;gt;
Sent: Tuesday, March 09, 2010 1:49 AM
To: &amp;lt;mzcohen2682 () aim com&amp;gt;
Cc: &amp;lt;security-basics () securityfocus com&amp;gt;
Subject: Re: Help hardening router

------------------------------------------------------------------------
Securing Apache Web Server with thawte...</description>
                </item><item>
                        <title>Noted cryptographer on SSL, encryption and cloud computing</title>
                        <link>http://www.securityscraper.com/index.php?item=378402</link>
                        <description>Cryptographer, Taher Elgamal of Axway Inc., the inventor and initial driving force behind SSL, explains how applications may be better adapted to defend against attacks.

</description>
                </item><item>
                        <title>Linux Arpeggiators, Part 1</title>
                        <link>http://www.securityscraper.com/index.php?item=378401</link>
                        <description>
    
            
                            
        


In my last article I looked at performance loopers for Linux. This week I begin a 2-part review of similar applications called arpeggiators. 
 more>>


   </description>
                </item><item>
                        <title>Clientless SSL VPN vulnerability and Web browser protection</title>
                        <link>http://www.securityscraper.com/index.php?item=378400</link>
                        <description>In a recent US-CERT advisory, clientless SSL VPN vulnerabilities were listed as posing serious threats to Web browser security. In this tip, learn possible actions to take for Web browser protection.

</description>
                </item><item>
                        <title>Considering two-factor authentication? Do cost, risk analysis</title>
                        <link>http://www.securityscraper.com/index.php?item=378399</link>
                        <description>One-time passwords and other technologies are effective protection, but midmarket companies have to consider the expense and management overhead.

</description>
                </item><item>
                        <title>Enterprise data management: Prevent data loss and insider threats</title>
                        <link>http://www.securityscraper.com/index.php?item=378398</link>
                        <description>While DLP technologies are becoming more advanced, some organizations still struggle with how to prevent data loss. In this tip, learn how insider threats can present some serious security issues, and how to overcome those threats.

</description>
                </item><item>
                        <title>Scapy tutorial: How to use Scapy to test Snort rules</title>
                        <link>http://www.securityscraper.com/index.php?item=378397</link>
                        <description>When creating Snort rules, it's often difficult to test them before they go live. In this Scapy tutorial, Judy Novak explains how to use Scapy, a tool that simplifies packet crafting, to test new Snort rules.

</description>
                </item><item>
                        <title>Microsoft, Adobe Bringing Flash Support to Windows Phone 7 Series</title>
                        <link>http://www.securityscraper.com/index.php?item=378396</link>
                        <description>Microsoft and Adobe are working to port Flash Player 10.1 to Internet Explorer Mobile on the Windows Phone 7 Series, according to an Adobe executive, which would allow devices running Microsofts upcoming smartphone operating system to play rich content on a variety of Websites. Reports from February had suggested that Flash would not be supported on the first generation of Windows Phone 7 Series devices. Microsoft's hardware partners, including Hewlett-Packard, have been emphasizing their Adobe Flash support as a differentiator between their mobile products and those produced by Apple, such as the iPad and iPhone.   -  Microsoft and Adobe are apparently working together to ensure
that Windows Phone 7 Series supports Flash Player 10.1, according to a blog
posting by an Adobe executive. Enabling that support could possibly counter
February reports that the first generation of Microsofts new smartphone
operating ...


   </description>
                </item><item>
                        <title>LG Holding Google Close in Bid for the Top</title>
                        <link>http://www.securityscraper.com/index.php?item=378395</link>
                        <description>LGs intention to be a top-two smartphone contender by 2012 appears to largely involve Google. Reportedly, half the phones it plans to release this year will run Android, and LG could benefit, too, from Googles new enterprise-geared Apps Marketplace.   -  LG Electronics plan to gain double-digit market share in the global mobile handset market by 2012 appears to figure largely on hitching its cart to the Google Android mobile operating system.
  
On March 10, LG officials introduced the Android-running LG-KH5200 in South Korea, and after being vagu...


     </description>
                </item><item>
                        <title>IT Spending in 2010 Will Rise Slightly: Ovum</title>
                        <link>http://www.securityscraper.com/index.php?item=378394</link>
                        <description>There will be an uptick in IT spending in 2010, but those budgets that do grow will increase by only 1 to 5 percent, according to Ovum. The bulk of CIOs in an Ovum survey said they expect their budgets to remain flat after the recession-ravaged 2009.   -  Dont expect IT spending to increase too much in 2010, according to research firm Ovum.
There will be some uptick in IT budgets for the year, but only in the 1 to 5 percent range, Ovum analysts said in a report March 9.
In fact, most enterprises will see no change in their IT spending, a survey of ...


     </description>
                </item><item>
                        <title>Twitter Fights Phishing, Malware With Link Scanning Service</title>
                        <link>http://www.securityscraper.com/index.php?item=378393</link>
                        <description>Twitter has announced it will begin scanning links posted by users to thwart phishing attacks and the spread of malware on the site.   -  Twitter has announced plans to route all links through a scanner in a bid to boost security and weed out malicious activity.
    
  The move follows a partnership announced in November between URL shortening service Bit.ly and security companies VeriSign, Websense and Sophos.
    
By routing al...


      </description>
                </item><item>
                        <title>Apple, Other Smartphone Makers Hit With Infringement Suits</title>
                        <link>http://www.securityscraper.com/index.php?item=378392</link>
                        <description>A little known company called SmartPhone Technologies files lawsuits against Apple, AT T, Research in Motion, Samsung, Sanyo, LG and Motorola for violating patents owned by the company.   -  The smartphone patent lawsuit derby continues with a company named
SmartPhone Technologies LLC suing Apple, AT amp;T, RIM (Research in
Motion), Samsung, Sanyo, LG and Motorola for violating patents owned by
the company. Filed in the U.S. District Court in the Eastern District
of Texas, SmartPhon...


     </description>
                </item><item>
                        <title>IT Managers Seeking -- and Getting -- More Help to Control Far-flung Assets</title>
                        <link>http://www.securityscraper.com/index.php?item=378391</link>
                        <description>The No. 1 most talked-about product genre at Data Center World 2010 is data center management software. Avocent, Aperture, AccessIT, BMC, EMC, Dell, Methode, nLyte, Aptare, Modius, Rackwise -- those are just some of the companies coming to the fore with interesting products and services.   -  NASHVILLE, Tenn. -- At Data Center World 2010 here in Music City, it's all about control.

We're talking control of data center footprints, carbon emissions, power consumption, equipment cooling, budgets, personnel, and myriad other things. Oh, yes: Control of the data itself also comes into this ...


     </description>
                </item><item>
                        <title>Twitter Fights Phishing, Malware With Link Scanning Service</title>
                        <link>http://www.securityscraper.com/index.php?item=378390</link>
                        <description>Twitter has announced it will begin scanning links posted by users to thwart phishing attacks and the spread of malware on the site.   -  Twitter has announced plans to route all links through a scanner in a bid to boost security and weed out malicious activity.
    
  The move follows a partnership announced in November between URL shortening service Bit.ly and security companies VeriSign, Websense and Sophos.
    
By routing al...


   
</description>
                </item><item>
                        <title>Troj/PDFJs-IL</title>
                        <link>http://www.securityscraper.com/index.php?item=378389</link>
                        <description></description>
                </item><item>
                        <title>Troj/DwnLdr-ICB</title>
                        <link>http://www.securityscraper.com/index.php?item=378388</link>
                        <description></description>
                </item><item>
                        <title>Troj/Drop-EV</title>
                        <link>http://www.securityscraper.com/index.php?item=378387</link>
                        <description></description>
                </item><item>
                        <title>Troj/Dloadr-CYS</title>
                        <link>http://www.securityscraper.com/index.php?item=378386</link>
                        <description></description>
                </item><item>
                        <title>Mal/Keylog-G</title>
                        <link>http://www.securityscraper.com/index.php?item=378385</link>
                        <description></description>
                </item><item>
                        <title>Mal/IRCBot-N</title>
                        <link>http://www.securityscraper.com/index.php?item=378384</link>
                        <description></description>
                </item><item>
                        <title>Turn a Hoodie into an Improvised Laptop Bag [Clever Uses]</title>
                        <link>http://www.securityscraper.com/index.php?item=378383</link>
                        <description>
										
					
						
											
									
				If you like getting the most use out of your possessions as possible, this guide will help you turn a hooded sweatshirt into a laptop bag, baby carrier, and more.				More&amp;nbsp;&amp;raquo;
				
			



</description>
                </item><item>
                        <title>HTML5 vs. Flash: HTML5 Isn't Always Better [Flash]</title>
                        <link>http://www.securityscraper.com/index.php?item=378382</link>
                        <description>
										
					
						
											
									
				Flash has taken quite a beating lately by everyone from Apple (no Flash on iPad or iPhones) to YouTube (transitioning to HTML5 video) to users sick of security exploits and sluggish browsers. Everyone's looking the silver bullet that kills Flash, but is HTML5 it?				More&amp;nbsp;&amp;raquo;
				
			

</description>
                </item><item>
                        <title>Keep Your Daily Momentum Going With a 10/15 Split [Work]</title>
                        <link>http://www.securityscraper.com/index.php?item=378381</link>
                        <description>
										
					
						
											
									
				One of the toughest aspects of staying productive is overcoming the ups and downs of motivation. Spending 10 minutes getting organized in the morning, then 15 minutes again in the evening, can help even out your daily go-get-'em energy.				More&amp;nbsp;&amp;raquo;
				
			



</description>
                </item><item>
                        <title>Kiwi Monitors Your Running Apps, Performs Actions Based on Their Status [Downloads]</title>
                        <link>http://www.securityscraper.com/index.php?item=378380</link>
                        <description>
										
					
						
											
									
				Windows: Kiwi is a free utility that monitors any application and springs into action when that application meets any user-defined criteria within a set of basic rules&amp;mdash;like restarting an application or email you when it's memory use exceeds a pre-defined level.				More&amp;nbsp;&amp;raquo;
				
			

</description>
                </item><item>
                        <title>Set Google Calendar Alerts to Gentle Reminder Mode for Less Intrusive Reminders [Google Calendar]</title>
                        <link>http://www.securityscraper.com/index.php?item=378379</link>
                        <description>
										
					
						
											
									
				If you like calendar reminders but you'd like them a little less in-your-face, you can enable gentle reminders in Google Calendar to replace the reminder pop up.				More&amp;nbsp;&amp;raquo;
				
			

</description>
                </item><item>
                        <title>How to Skip Commercials in Windows 7 Media Center [Windows Media Center]</title>
                        <link>http://www.securityscraper.com/index.php?item=378378</link>
                        <description>
										
					
						
											
									
				If you use Windows 7 Media Center to record TV, you'd probably prefer skipping commercials. After all, a big reason you record programs is to avoid commercials, right? Here's a fairly simple and free way to start skipping commercials in no time.				More&amp;nbsp;&amp;raquo;
				
			


</description>
                </item><item>
                        <title>Google Reader Play Lets You Sit Back and Watch Popular Reader Items [Google Reader]</title>
                        <link>http://www.securityscraper.com/index.php?item=378377</link>
                        <description>
										
					
						
											
									
				Google Reader Play is a new Reader feature that plays a slideshow of cool items from around the web based on the stories you star. It's like a 10-foot viewing experience for your newsreader.				More&amp;nbsp;&amp;raquo;
				
			

</description>
                </item><item>
                        <title>Social networking risks, benefits for enterprises weighed by RSA panel</title>
                        <link>http://www.securityscraper.com/index.php?item=378376</link>
                        <description>Social networking risks to enterprises may be outweighed by the benefits, but experts at the 2010 RSA Conference say infrastructure providers must improve security.

</description>
                </item><item>
                        <title>IBM z/OS 1.12: New features, improvements explained</title>
                        <link>http://www.securityscraper.com/index.php?item=378375</link>
                        <description>The latest version of IBM's mainframe OS, z/OS 1.12, includes improvements to EAV support, significant security enhancements, and new Predictive Failure Analysis and Run Time Diagnostics features.

</description>
                </item><item>
                        <title>Database Security Fundamentals: Patching</title>
                        <link>http://www.securityscraper.com/index.php?item=378374</link>
                        <description>Patching is a critical security operation for databases like any other application. The vast majority of security concerns and logic flaws within the database will be addressed by the database vendor. While the security &amp;amp; IT communities are made aware of critical security flaws in databases, and may even understand the exploit, the details of the fix are never made public [unless you are using an open source database]. That means the vendor is your only option for fixes and workarounds. Most of you will not be monitoring CVE notifications or performing pen tests on new versions of the database when they are released. Even if you have the in house expertise do so, you do not have the time to conduct serious investigation. Database vendors have dedicated security teams to analyze attacks against the database, and small firms must leverage the vendor's expertise.  

Project Quant for Patch Management was designed to break down patch management into essential, discreet functions, and assign cost based metrics to each task to provide a quantitative measurement to the patch management process. In order to achieve that goal, we needed to define a patch management process &amp;#160;on which to build the metrics model. For database patch management, you could choose to follow that process and feel confident that you have all relevant aspects of patching a database system. However, that process is far more encompassing and too much information for a series on database security fundamentals.    

As this series is designed more at the small and mid-market practitioner, who as a general rule lacks the time and tools necessary for more thorough processes, we are going to avoid the same depth of coverage major enterprises require. I am going to follow that basic Quant model, but suggest a subset of the process defined in the original Project Quant series. Further, I am not going to assume that you have any resources in place</description>
                </item><item>
                        <title>Nose Biometrics</title>
                        <link>http://www.securityscraper.com/index.php?item=378373</link>
                        <description>Really: Since they are hard to conceal, the study says, noses would work well for identification in covert surveillance. The researchers say noses have been overlooked in the growing field of biometrics, studies into ways of identifying distinguishing traits in people. "Noses are prominent facial features and yet their use as a biometric has been largely unexplored," said the University...

</description>
                </item><item>
                        <title> Basic security measures do wonders</title>
                        <link>http://www.securityscraper.com/index.php?item=378372</link>
                        <description>Deep down inside, we all wish for a unique solution that will protect our machine or our network completely forever and ever, preferably one that can be activated with a simple flick of a switch and t...</description>
                </item><item>
                        <title> Most malicious websites are hosted in the US</title>
                        <link>http://www.securityscraper.com/index.php?item=378371</link>
                        <description>AVG Technologies unveiled the results of a research study which shows that  contrary to popular opinion  most malicious websites are hosted on US servers and not in other countries like China.
 
 Th...</description>
                </item><item>
                        <title>Top free troubleshooting tools for Windows</title>
                        <link>http://www.securityscraper.com/index.php?item=378370</link>
                        <description>These seven handy tools help you diagnose and cure a wide range of Windows ills, and they're all free for the downloading</description>
                </item><item>
                        <title>OCZ introduces an SSD for under $100</title>
                        <link>http://www.securityscraper.com/index.php?item=378369</link>
                        <description>OCZ today announced a new line of more affordable solid state drives called the Onyx series, which will begin with a sub-$100 model.</description>
                </item><item>
                        <title>Google, Italian Culture Ministry sign book digitization pact</title>
                        <link>http://www.securityscraper.com/index.php?item=378368</link>
                        <description>Google and the Italian Culture Ministry have signed an agreement for the digitization of books held in Italy's two main national libraries, the first such pact between the U.S. company and a national government, the two sides announced Wednesday.</description>
                </item><item>
                        <title>RIM silent on data outages in North America, UK</title>
                        <link>http://www.securityscraper.com/index.php?item=378367</link>
                        <description>Some BlackBerry users in North America and the United Kingdom said they experienced data outages earlier this week on Wi-Fi-equipped BlackBerries when not connected to Wi-Fi.</description>
                </item><item>
                        <title>Only 21% of Twitter members are active, report says</title>
                        <link>http://www.securityscraper.com/index.php?item=378366</link>
                        <description>A study by Barracuda Networks found that most Twitter members are still inactive members, though the analysis does find some increased activity at the microblogging service.</description>
                </item><item>
                        <title>Google Apps store seeks cloud collaboration boost</title>
                        <link>http://www.securityscraper.com/index.php?item=378365</link>
                        <description>Google's new Apps Marketplace could give a significant boost to Web-based communication and collaboration software for businesses by creating a wide-ranging yet integrated virtual suite of heterogeneous cloud applications.</description>
                </item><item>
                        <title>Hackers exploit latest IE zero-day with drive-by attacks</title>
                        <link>http://www.securityscraper.com/index.php?item=378364</link>
                        <description>Hackers are exploiting the just-disclosed unpatched bug in Internet Explorer (IE) to launch drive-by attacks from malicious Web sites, security researchers said today.</description>
                </item><item>
                        <title>Intel shows first six-core desktop processor</title>
                        <link>http://www.securityscraper.com/index.php?item=378363</link>
                        <description>Intel Corp. showed its first six-core processor for desktops, the Core i7-980X Extreme Edition, which will go into workstations and PCs targeted at gamers.</description>
                </item><item>
                        <title>#51927: Mapping for MySQL's latin1 character set in .NET connector</title>
                        <link>http://www.securityscraper.com/index.php?item=378362</link>
                        <description>Bug ID: 51927Submitted by: Anita NovelloCategory: Connector/NetStatus: OpenAssigned to: Tonci GrginSeverity: 3OS: Microsoft WindowsVersion: 6.x</description>
                </item><item>
                        <title>#51929: Unnecessary Sync Updates</title>
                        <link>http://www.securityscraper.com/index.php?item=378361</link>
                        <description>Bug ID: 51929Submitted by: Martin PirringerCategory: MySQL Workbench: ModelingStatus: OpenSeverity: 3OS: Microsoft Windows (7)Version: 5.2.16</description>
                </item><item>
                        <title>#51930: MySQL not optimizing query on two part (char,int) index</title>
                        <link>http://www.securityscraper.com/index.php?item=378360</link>
                        <description>Bug ID: 51930Submitted by: Scott NeborCategory: Server: OptimizerStatus: OpenSeverity: 5OS: Linux (Ubuntu 8.04)Version: 5.1.44 - compiled from source</description>
                </item><item>
                        <title>#51931: external component threw an error while attempting to manage import/export</title>
                        <link>http://www.securityscraper.com/index.php?item=378359</link>
                        <description>Bug ID: 51931Submitted by: Thomas LyleCategory: Connector/ODBCStatus: OpenSeverity: 1OS: Mac OS X (7 32 bit)Version: 5.2.16 rev 5249</description>
                </item><item>
                        <title>#51932: ndbd keep crashing</title>
                        <link>http://www.securityscraper.com/index.php?item=378358</link>
                        <description>Bug ID: 51932Submitted by: Rob TousainCategory: Server: ClusterStatus: OpenSeverity: 1OS: Linux (RedHat)Version:  mysql-5.1.30 ndb-6.3.20-GA</description>
                </item><item>
                        <title>#51933: catastrophic memory</title>
                        <link>http://www.securityscraper.com/index.php?item=378357</link>
                        <description>Bug ID: 51933Submitted by: daniel raineCategory: MySQL Workbench: ModelingStatus: OpenSeverity: 2OS: AnyVersion: 5.2.16 OSS beta rev. 5249</description>
                </item><item>
                        <title>#51934: System.AccessViolationException</title>
                        <link>http://www.securityscraper.com/index.php?item=378356</link>
                        <description>Bug ID: 51934Submitted by: Alexandre Scheffer Quintela  Category: MySQL Workbench: ModelingStatus: OpenSeverity: 3OS: Microsoft Windows (winxpsp3)Version: 5.2.16</description>
                </item><item>
                        <title>RE: [WEB SECURITY] Question &amp; Answer guide for web application security testing</title>
                        <link>http://www.securityscraper.com/index.php?item=378355</link>
                        <description></description>
                </item><item>
                        <title>RE: [WEB SECURITY] Question &amp; Answer guide for web application security testing</title>
                        <link>http://www.securityscraper.com/index.php?item=378354</link>
                        <description></description>
                </item><item>
                        <title>Re: [WEB SECURITY] Question &amp; Answer guide for web application security testing</title>
                        <link>http://www.securityscraper.com/index.php?item=378353</link>
                        <description></description>
                </item><item>
                        <title>Samba < 3.3.12 / 3.4.7 / 3.5.1 Security Bypass Vulnerability</title>
                        <link>http://www.securityscraper.com/index.php?item=378352</link>
                        <description>
Synopsis :The remote Samba server is vulnerable to a security bypass attack.According to its banner, the version of Samba Server on the remote host is potentially affected by a security bypass vulnerability.  A flaw exists that causes all smbd processes to inherit CAP_DAC_OVERRIDE capabilities, allowing all file system access to be allowed even when permissions should have denied access.  For your information, the observed version of Samba is:%LCVSS Base Score : 6.4CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N
See also :

http://us1.samba.org/samba/security/CVE-2010-078.html

Solution :

Upgrade to Samba 3.3.12, 3.4.7, 3.5.1

Risk factor :

MEDIUMReferences:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0728
Copyright Tenable Network Security Inc. 2010</description>
                </item><item>
                        <title>Bugtraq: Secunia Research: XnView DICOM Parsing Integer Overflow Vulnerability</title>
                        <link>http://www.securityscraper.com/index.php?item=378351</link>
                        <description> Secunia Research: XnView DICOM Parsing Integer Overflow Vulnerability </description>
                </item><item>
                        <title>Vuln: Microsoft Excel EntExU2 Record Remote Code Execution Vulnerability</title>
                        <link>http://www.securityscraper.com/index.php?item=378350</link>
                        <description> Microsoft Excel EntExU2 Record Remote Code Execution Vulnerability </description>
                </item><item>
                        <title>Google-China resolution coming 'soon,' says CEO</title>
                        <link>http://www.securityscraper.com/index.php?item=378349</link>
                        <description>Talks between Google and Chinese government are ongoing, Google's Eric Schmidt says Wednesday, and he expects the matter to be resolved sooner rather than later.</description>
                </item><item>
                        <title>Online industry unites against Digital Economy Bill</title>
                        <link>http://www.securityscraper.com/index.php?item=378348</link>
                        <description>Google, Yahoo, eBay, Facebook, Orange, Talk Talk and BT have singed an open letter  to the Financial Times condemning a bill in parliament that they say “threatens freedom of speech and the open internet”.</description>
                </item><item>
                        <title>Counterfeit card fraud drops by half in the UK</title>
                        <link>http://www.securityscraper.com/index.php?item=378347</link>
                        <description>Fraud losses due to counterfeit payment cards fell by half in 2009 from the year prior in the U.K., but online banking losses continued to rise, according to new banking industry figures released Wednesday.</description>
                </item><item>
                        <title>Scareware will be most costly security scam of 2010</title>
                        <link>http://www.securityscraper.com/index.php?item=378346</link>
                        <description>Scareware or fake antivirus programs that encourage web users to part with their hard-earned cash and download hoax security software, is likely to be the most costly scam of 2010, says McAfee.</description>
                </item><item>
                        <title>Reader exploit prompts Adobe update alert</title>
                        <link>http://www.securityscraper.com/index.php?item=378345</link>
                        <description>Users of Adobe PDF Reader should check they are running the latest version of the software after the discovery of an exploit that takes advantage of a serious flaw patched only two weeks ago.</description>
                </item><item>
                        <title>Cyberattacks raise e-banking security fears</title>
                        <link>http://www.securityscraper.com/index.php?item=378344</link>
                        <description>Increasing cyberattacks against the online bank accounts of small and mid-size businesses has prompted growing calls for improved online banking security.</description>
                </item><item>
                        <title>Facebook, Google slam amendment to Digital Economy Bill</title>
                        <link>http://www.securityscraper.com/index.php?item=378343</link>
                        <description>Google, Facebook and eBay are among the tech giants that have slammed the government's plans to tackle internet piracy, claiming it will "threaten freedom of speech".</description>
                </item><item>
                        <title>British hopeless at backing up PCs</title>
                        <link>http://www.securityscraper.com/index.php?item=378342</link>
                        <description>Europeans differ in their approach to PC backup, a new survey has found. The Germans do it efficiently, the French with enthusiasm, while the British sometimes have trouble taking it seriously at all.</description>
                </item><item>
                        <title>Create your own unique icons</title>
                        <link>http://www.securityscraper.com/index.php?item=378341</link>
                        <description>Icons have come a long way in the past decade, evolving from tiny, pixelated pictures into glossy, gorgeous artwork. Adding a custom icon to an application, document, or folder has evolved, too. You no longer need to use special utilities to build icons at tiny sizes; instead, you can take just about any photo or illustration and convert it into an icon.</description>
                </item><item>
                        <title>Bike Directions Added to Google Maps</title>
                        <link>http://www.securityscraper.com/index.php?item=378340</link>
                        <description>Google on Wednesday launched bicycle directions for Google Maps making it easier for cyclists to plan routes in 150 U.S. cities including Boston, Chicago, Los Angeles, New York, San Francisco, Portland and Washington, DC. You can use Google Maps to find cycling-specific directions in urban areas, and by default Google Maps will plan your route to avoid steep hills whenever possible. The new maps feature can also be used as a map layer to get an overall sense of cycling accessibility in a particular city.</description>
                </item><item>
                        <title>Facebook, Twitter Ready Location-Based Features</title>
                        <link>http://www.securityscraper.com/index.php?item=378339</link>
                        <description>Facebook and Twitter are preparing to flip the switch on features that will allow you to share your location with your friends at any time. Facebook is reportedly revving up to introduce the feature, while Twitter is ready to enable the changes on its site any moment now.</description>
                </item><item>
                        <title>Apple iPhone app fine print hurts developers</title>
                        <link>http://www.securityscraper.com/index.php?item=378338</link>
                        <description>iPad and iPhone developers beware. Apple reserves the right to kill an app at any time with no reason, and Apple's liability in any circumstance is limited to $50.</description>
                </item><item>
                        <title>What Are the Most Overrated Security Technologies?</title>
                        <link>http://www.securityscraper.com/index.php?item=378337</link>
                        <description>Which security technologies are IT shops putting too much faith in? Some readers weigh in.</description>
                </item><item>
                        <title>Trillian Astra</title>
                        <link>http://www.securityscraper.com/index.php?item=378336</link>
                        <description>Trillian Astra (Free version and 30-day trial of $25 Pro as one download), the latest communications program from Cerulean Studios, can pull together a wide variety of instant messenger accounts and Web services like Facebook and Twitter. But it goes a bit far with the information it wants to publicly share.</description>
                </item><item>
                        <title>Google adds Street View 'edit location' function</title>
                        <link>http://www.securityscraper.com/index.php?item=378335</link>
                        <description>Google is giving web users the ability to edit the locations of businesses that appear in its Street View service.</description>
                </item><item>
                        <title>Hackers aren't as sneaky as you think</title>
                        <link>http://www.securityscraper.com/index.php?item=378334</link>
                        <description>LinuxSecurity.com: Two weeks ago, I essentially claimed that nearly every company I know is hacked -- and in many cases, thoroughly hacked. Although there's a bit of hyperbole in that statement, it isn't that far from reality. That statement, however, has led some readers to believe detecting hackers and preventing attacks is impossible. Nothing could be further from the truth.</description>
                </item><item>
                        <title>Reader exploit prompts Adobe update alert</title>
                        <link>http://www.securityscraper.com/index.php?item=378333</link>
                        <description>Users of Adobe PDF Reader should check they are running the latest version of the software after the discovery of an exploit that takes advantage of a serious flaw patched only three weeks ago.</description>
                </item><item>
                        <title>Rental and Real Estate Scams</title>
                        <link>http://www.securityscraper.com/index.php?item=378332</link>
                        <description></description>
                </item><item>
                        <title>Noisy Super 8</title>
                        <link>http://www.securityscraper.com/index.php?item=378331</link>
                        <description>

	
	
	
	
	


[Matt Kemp] remade this super 8 film camera into a synthesizer. Inside you&amp;#8217;ll find a light sensor pointed through the lens. This way, zooming, focusing, and pointing the lens elsewhere will change the sound. He also refit the original controls to monkey with the output. Turn your speakers up when you watch this, your co-workers [...]</description>
                </item><item>
                        <title>Jeri makes integrated circuits</title>
                        <link>http://www.securityscraper.com/index.php?item=378330</link>
                        <description>
[Jeri Ellsworth] made this silicon inverter at home, by hand. It took her two years to get the process figured out and achieve something we didn&amp;#8217;t think was possible. The complexity of manufacture, and the wide range of tools and materials needed seem insurmountable but she did it anyway. Her home chip fab Flickr set [...]</description>
                </item><item>
                        <title>Select Your Web Browser(s)</title>
                        <link>http://www.securityscraper.com/index.php?item=378329</link>
                        <description> 			 			I wasn't sure I'd see this Browser Choice update:I set my computer's Regional Options for the United States even though it's physically located in Finland (I'm an American after all).Regional settings might trump my IP address, I thought&amp;hellip; but it seems not. I manually ran Microsoft Update and was provided access to KB976002. Cool.If you're located outside of Europe and are wondering what's this is all about, read this from the BBC.Microsoft is offering alternative browser options to European Windows users to settle an anti-trust lawsuit. The update component points users to browserchoice.eu &amp;mdash; from where they can select from 12 different web browsers.On a somewhat not completely unrelated note: Microsoft Security Advisory (981374) was published yesterday."Microsoft is investigating new, public reports of a vulnerability in Internet Explorer 6 and Internet Explorer 7."The vulnerability could allow for remote code execution.Once again, that browser choice link is browserchoice.eu. Send it to your friends and family.Signing off,Sean 			 On 10/03/10 At 05:00 PM</description>
                </item></channel>
                        </rss>