<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>IT Security Top Headlines &#187; news</title>
	<atom:link href="http://www.pinolobu.com/security/category/news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.pinolobu.com/security</link>
	<description>interesting news and opinions about IT security</description>
	<pubDate>Sun, 15 Jun 2008 07:16:33 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
	<language>en</language>
			<item>
		<title>It&#8217;s time to move from Wordpress to Movable Type: more secure?</title>
		<link>http://www.pinolobu.com/security/2008/06/15/its-time-to-move-from-wordpress-to-movable-type-more-secure/</link>
		<comments>http://www.pinolobu.com/security/2008/06/15/its-time-to-move-from-wordpress-to-movable-type-more-secure/#comments</comments>
		<pubDate>Sun, 15 Jun 2008 07:16:33 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[moveable type]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/06/15/its-time-to-move-from-wordpress-to-movable-type-more-secure/</guid>
		<description><![CDATA[According to the Department of Homeland Security, since 2005, MT has only had 10 reported security vulnerabilities, as compared to Wordpress&#8217; 100+
Full story
]]></description>
			<content:encoded><![CDATA[<p>According to the Department of Homeland Security, since 2005, MT has only had 10 reported security vulnerabilities, as compared to Wordpress&#8217; 100+</p>
<p><a href="http://www.movabletype.com/blog/2008/06/movable-type-a-history-of-secu.html">Full story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/06/15/its-time-to-move-from-wordpress-to-movable-type-more-secure/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Wordpress vulnerabilities result in mass blog cracks</title>
		<link>http://www.pinolobu.com/security/2008/06/15/wordpress-vulnerabilities-result-in-mass-blog-cracks/</link>
		<comments>http://www.pinolobu.com/security/2008/06/15/wordpress-vulnerabilities-result-in-mass-blog-cracks/#comments</comments>
		<pubDate>Sun, 15 Jun 2008 07:13:21 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[wordpress]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/06/15/wordpress-vulnerabilities-result-in-mass-blog-cracks/</guid>
		<description><![CDATA[Wordpress is arguably the most popular blogging platform. Hence, it&#8217;s a give that it has become a popular target for blackhat hackers. 
The intentions are usually search-engine optimization (SEO) of other sites the bad guys control, as well as traffic-redirection and more. 
And recently there were many automated attacks which exploited recently discovered security vulnerabilities [...]]]></description>
			<content:encoded><![CDATA[<p>Wordpress is arguably the most popular blogging platform. Hence, it&#8217;s a give that it has become a popular target for blackhat hackers. </p>
<p>The intentions are usually search-engine optimization (SEO) of other sites the bad guys control, as well as traffic-redirection and more. </p>
<p>And recently there were many automated attacks which exploited recently discovered security vulnerabilities in Wordpress.</p>
<p>Most damning, while usually Wordpress was able to keep up, in the past few days &#8220;new exploits have appeared that nobody seems to have answers for.&#8221;</p>
<p><a href="http://www.techcrunch.com/2008/06/11/my-blog-was-hacked-is-yours-next-huge-wordpress-security-issues/">Full story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/06/15/wordpress-vulnerabilities-result-in-mass-blog-cracks/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Was the Malaysian Prime Minister Office website defaced or not?</title>
		<link>http://www.pinolobu.com/security/2008/06/06/was-the-malaysian-prime-minister-office-website-defaced-or-not/</link>
		<comments>http://www.pinolobu.com/security/2008/06/06/was-the-malaysian-prime-minister-office-website-defaced-or-not/#comments</comments>
		<pubDate>Fri, 06 Jun 2008 13:02:36 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[hacker]]></category>

		<category><![CDATA[malaysia]]></category>

		<category><![CDATA[price increase]]></category>

		<category><![CDATA[prime minister]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/06/06/was-the-malaysian-prime-minister-office-website-defaced-or-not/</guid>
		<description><![CDATA[The PM announced price hikes in petrol and diesel prices on 4th of June 2008. As a result, by the next day the website of the Prime Minister&#8217;s Office was apparently defaced by disgruntled person(s).
Upon closer inspection however, it seems to be a remote file inclusion attack, taking advantage of a Lotus Domino vulnerability, on [...]]]></description>
			<content:encoded><![CDATA[<p>The PM announced price hikes in petrol and diesel prices on 4th of June 2008. As a result, <a href="http://www.skthew.com/2008/06/05/price-hike-pmos-website-hacked/">by the next day <a href="http://www.pmo.gov.my">the website of the Prime Minister&#8217;s Office</a> was apparently defaced</a> by disgruntled person(s).</p>
<p>Upon closer inspection however, it seems to be <a href="http://kormmandos.wordpress.com/2008/06/05/did-malaysia-pmo-website-get-hacked/">a remote file inclusion attack</a>, taking advantage of a Lotus Domino vulnerability, on which platform the website is running, meaning the attacker was not able to execute commands on the server, else it would have been worse.</p>
<p>As of now though, if you still follow the &#8220;<a href="http://www.pmo.gov.my/website/webdbase.nsf/w_4?openForm&#038;url=http://www.geocities.com/nmapx/manifesto.txt">hacked link</a>&#8221; it will not be accessible anymore.</p>
<p>Quite interesting: the &#8220;<a href="http://www.geocities.com/nmapx/manifesto.txt">manifesto</a>&#8221; seems to have been modified since then, to include the following text:</p>
<p>A special officer to Datuk Seri Abdullah Ahmad Badawi confirmed the incident and said it was an &#8220;<a href="http://www.nst.com.my/Current_News/NST/Friday/Frontpage/2260134/Article">unsuccessful hacking attempt</a>&#8220;. &#8220;What happened is that someone copied the URL (the site&#8217;s address) and cloned it to make it look like the real site. Special Officer? There is nothing special about you just the same as the rest of those lazy adminz. UBAH GAYA HIDUP &#8230; Lancau ahh</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/06/06/was-the-malaysian-prime-minister-office-website-defaced-or-not/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Burglars stole laptop, laptop struck back, burglars got arrested</title>
		<link>http://www.pinolobu.com/security/2008/05/13/burglars-stole-laptop-laptop-struck-back-burglars-got-arrested/</link>
		<comments>http://www.pinolobu.com/security/2008/05/13/burglars-stole-laptop-laptop-struck-back-burglars-got-arrested/#comments</comments>
		<pubDate>Tue, 13 May 2008 13:42:35 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[Frias]]></category>

		<category><![CDATA[macintosh]]></category>

		<category><![CDATA[Shahikian]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/05/13/burglars-stole-laptop-laptop-struck-back-burglars-got-arrested/</guid>
		<description><![CDATA[It&#8217;s a Mac. Does Windows machines have such features?
Full story
]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s a Mac. Does Windows machines have such features?</p>
<p><a href="http://www.nytimes.com/2008/05/10/nyregion/10laptop.html?_r=2&#038;bl&#038;ex=1210737600&#038;en=949dc013156ba36c&#038;ei=5087%0A&#038;oref=slogin&#038;oref=slogin">Full story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/05/13/burglars-stole-laptop-laptop-struck-back-burglars-got-arrested/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Security flaw turns Gmail into open-relay server</title>
		<link>http://www.pinolobu.com/security/2008/05/11/security-flaw-turns-gmail-into-open-relay-server/</link>
		<comments>http://www.pinolobu.com/security/2008/05/11/security-flaw-turns-gmail-into-open-relay-server/#comments</comments>
		<pubDate>Sun, 11 May 2008 07:20:28 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[gmail]]></category>

		<category><![CDATA[google]]></category>

		<category><![CDATA[Man-in-the-middle attack]]></category>

		<category><![CDATA[open relay]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/05/11/security-flaw-turns-gmail-into-open-relay-server/</guid>
		<description><![CDATA[A recently-discovered flaw in Gmail is capable of turning Google&#8217;s e-mail service into a highly effective spam machine. According to the Information Security Research Team (INSERT), Gmail is susceptible to a man-in-the-middle attack that allows a spammer to send thousands of bulk e-mails through Google&#8217;s SMTP service without fear of detection. This attack bypasses both [...]]]></description>
			<content:encoded><![CDATA[<p>A recently-discovered flaw in Gmail is capable of turning Google&#8217;s e-mail service into a highly effective spam machine. According to the Information Security Research Team (INSERT), Gmail is susceptible to a man-in-the-middle attack that allows a spammer to send thousands of bulk e-mails through Google&#8217;s SMTP service without fear of detection. This attack bypasses both Google&#8217;s identity fraud protection mechanisms and the current 500-address limit on bulk e-mail.</p>
<p><a href="http://arstechnica.com/news.ars/post/20080510-security-flaw-turns-gmail-into-open-relay-server.html">Full story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/05/11/security-flaw-turns-gmail-into-open-relay-server/feed/</wfw:commentRss>
		</item>
		<item>
		<title>High street chains will be the next victims of cyber terrorism</title>
		<link>http://www.pinolobu.com/security/2008/04/26/high-street-chains-will-be-the-next-victims-of-cyber-terrorism/</link>
		<comments>http://www.pinolobu.com/security/2008/04/26/high-street-chains-will-be-the-next-victims-of-cyber-terrorism/#comments</comments>
		<pubDate>Fri, 25 Apr 2008 20:00:20 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[hacked]]></category>

		<category><![CDATA[hacker]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[high street chains]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/04/26/high-street-chains-will-be-the-next-victims-of-cyber-terrorism/</guid>
		<description><![CDATA[High street chains will be the next victims of cyber terrorism, some of the world&#8217;s elite hackers have warned.
They claim it is only a &#8220;matter of time&#8221; before the likes of Tesco and Marks &#038; Spencer are targeted.
Criminals could use the kind of tactics which crippled Estonia&#8217;s government and some firms last year, they warned.
The [...]]]></description>
			<content:encoded><![CDATA[<p>High street chains will be the next victims of cyber terrorism, some of the world&#8217;s elite hackers have warned.</p>
<p>They claim it is only a &#8220;matter of time&#8221; before the likes of Tesco and Marks &#038; Spencer are targeted.</p>
<p>Criminals could use the kind of tactics which crippled Estonia&#8217;s government and some firms last year, they warned.</p>
<p>The experts were members of the infamous &#8220;Hackers Panel&#8221; which convened in London this week at the InfoSecurity Europe conference.</p>
<p>The panel includes penetration testers and so-called &#8220;white hat&#8221; hackers, who help companies tighten up their digital security by searching for flaws in their defences.</p>
<p>Previous panellists include Gary McKinnon, known as Solo, alleged by the US government to have hacked into dozens of US Army, Navy, Air Force, and Department of Defense computers.</p>
<p>The &#8220;hackers&#8221; usually remain anonymous, &#8220;for security reasons&#8221;, but this year&#8217;s panellists agreed to break cover.<br />
<a href="http://news.bbc.co.uk/2/hi/technology/7366995.stm"><br />
Full story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/04/26/high-street-chains-will-be-the-next-victims-of-cyber-terrorism/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Hackers are still exploiting 10 year old web vulnerabilities</title>
		<link>http://www.pinolobu.com/security/2008/04/14/hackers-are-still-exploiting-10-year-old-web-vulnerabilities/</link>
		<comments>http://www.pinolobu.com/security/2008/04/14/hackers-are-still-exploiting-10-year-old-web-vulnerabilities/#comments</comments>
		<pubDate>Mon, 14 Apr 2008 13:22:56 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[web vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/04/14/hackers-are-still-exploiting-10-year-old-web-vulnerabilities/</guid>
		<description><![CDATA[Web designers making very old mistakes are letting malicious hackers hijack visitors to their sites, say experts. Many of the loopholes left in the code created for websites have been known about for almost a decade say the security researchers. The poor practices are proving very attractive to hi-tech criminals looking for a ready source [...]]]></description>
			<content:encoded><![CDATA[<p>Web designers making very old mistakes are letting malicious hackers hijack visitors to their sites, say experts. Many of the loopholes left in the code created for websites have been known about for almost a decade say the security researchers. The poor practices are proving very attractive to hi-tech criminals looking for a ready source of victims. According to Symantec the number of sites vulnerable in this way almost doubled during the last half of 2007.</p>
<p><a href="http://news.bbc.co.uk/2/hi/technology/7345990.stm">Full story</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/04/14/hackers-are-still-exploiting-10-year-old-web-vulnerabilities/feed/</wfw:commentRss>
		</item>
		<item>
		<title>There are now more than 1 million computer viruses</title>
		<link>http://www.pinolobu.com/security/2008/04/10/there-are-now-more-than-1-million-computer-viruses/</link>
		<comments>http://www.pinolobu.com/security/2008/04/10/there-are-now-more-than-1-million-computer-viruses/#comments</comments>
		<pubDate>Thu, 10 Apr 2008 13:54:05 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[viruses]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/04/10/there-are-now-more-than-1-million-computer-viruses/</guid>
		<description><![CDATA[Yes, that number includes all malicious software: viruses, worms and trojans.
That&#8217;s what security firm Symantec Corp said in the latest edition of its bi-annual Internet Security Threat Report. The company added that most of these were created in the past year.
Full article
]]></description>
			<content:encoded><![CDATA[<p>Yes, that number includes all malicious software: viruses, worms and trojans.</p>
<p>That&#8217;s what security firm Symantec Corp said in t<a href="http://www.symantec.com/business/theme.jsp?themeid=threatreport">he latest edition of its bi-annual Internet Security Threat Report</a>. The company added that most of these were created in the past year.</p>
<p><a href="http://news.bbc.co.uk/2/hi/technology/7340315.stm">Full article</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/04/10/there-are-now-more-than-1-million-computer-viruses/feed/</wfw:commentRss>
		</item>
		<item>
		<title>US homeland security chief says cyber risk &#8220;equals 9/11 impact&#8221;</title>
		<link>http://www.pinolobu.com/security/2008/04/09/us-homeland-security-chief-says-cyber-risk-equals-911-impact/</link>
		<comments>http://www.pinolobu.com/security/2008/04/09/us-homeland-security-chief-says-cyber-risk-equals-911-impact/#comments</comments>
		<pubDate>Wed, 09 Apr 2008 14:11:38 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[Michael Chertoff]]></category>

		<category><![CDATA[RSAConference]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/04/09/us-homeland-security-chief-says-cyber-risk-equals-911-impact/</guid>
		<description><![CDATA[On the 8th of April 2008, the BBC reported that the US homeland security chief has made a heartfelt plea to Silicon Valley workers to stand up and be counted in the fight to secure the cyber highway.
Michael Chertoff invoked the attacks of 9/11 as he sought to galvanise IT professionals and security experts.
He told [...]]]></description>
			<content:encoded><![CDATA[<p>On the 8th of April 2008, the BBC reported that the US homeland security chief has made a heartfelt plea to Silicon Valley workers to stand up and be counted in the fight to secure the cyber highway.</p>
<p>Michael Chertoff invoked the attacks of 9/11 as he sought to galvanise IT professionals and security experts.</p>
<p>He told the world&#8217;s biggest IT security conference that serious threats to cyberspace are on &#8220;a par this country tragically experienced on 9/11&#8243;.</p>
<p>Such attacks can hit financial bodies and a government&#8217;s powers, he said.</p>
<p><a href="http://news.bbc.co.uk/2/hi/technology/7335930.stm">Full version</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/04/09/us-homeland-security-chief-says-cyber-risk-equals-911-impact/feed/</wfw:commentRss>
		</item>
		<item>
		<title>The world&#8217;s largest information security industry conference and expo</title>
		<link>http://www.pinolobu.com/security/2008/04/09/the-worlds-largest-information-security-industry-conference-and-expo/</link>
		<comments>http://www.pinolobu.com/security/2008/04/09/the-worlds-largest-information-security-industry-conference-and-expo/#comments</comments>
		<pubDate>Wed, 09 Apr 2008 14:06:18 +0000</pubDate>
		<dc:creator>pinolobu</dc:creator>
		
		<category><![CDATA[news]]></category>

		<category><![CDATA[RSAConference]]></category>

		<guid isPermaLink="false">http://www.pinolobu.com/security/2008/04/09/the-worlds-largest-information-security-industry-conference-and-expo/</guid>
		<description><![CDATA[The RSAConference claims to be the most comprehensive forum in information security. 
The 2008 edition in the US claim to have 17,000 attendees from the industry’s best and brightest.
There are 19 class tracks and more than 220 sessions.
Keynote addresses from Microsoft, RSA, The Security Division of EMC, CA, VeriSign, Symantec, TippingPoint, Oracle, and IBM.
Many networking [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.rsaconference.com/">The RSAConference</a> claims to be the most comprehensive forum in information security. </p>
<p>The 2008 edition in the US claim to have 17,000 attendees from the industry’s best and brightest.</p>
<p>There are 19 class tracks and more than 220 sessions.</p>
<p>Keynote addresses from Microsoft, RSA, The Security Division of EMC, CA, VeriSign, Symantec, TippingPoint, Oracle, and IBM.</p>
<p>Many networking (the human sort) events such as the Peer2Peer Sessions, First-Time Attendee Orientation, Welcome Reception, and the annual RSA® Conference Codebreakers Bash.</p>
<p>More than 350 exhibitors.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.pinolobu.com/security/2008/04/09/the-worlds-largest-information-security-industry-conference-and-expo/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
