<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Glider &#187; CGI Security</title>
	<atom:link href="http://www.theglider.org/archives/category/news/cgi-security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.theglider.org</link>
	<description>Life is a game, are you playing?</description>
	<lastBuildDate>Thu, 09 Feb 2012 10:04:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Safari RSS Reader Vulnerability</title>
		<link>http://www.theglider.org/archives/7628</link>
		<comments>http://www.theglider.org/archives/7628#comments</comments>
		<pubDate>Wed, 14 Jan 2009 18:02:22 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[In 2006 I gave a talk at blackhat on the risks of RSS vulnerabilities. It appears Safari has a flaw in its RSS reader as outlined by Brian Mastenbrook."The original version of this page contained a simple workaround for this issue which I believed would protect users against this problem. I...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7628/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oracle Releases Critical Patch Update With 41 Fixes</title>
		<link>http://www.theglider.org/archives/7531</link>
		<comments>http://www.theglider.org/archives/7531#comments</comments>
		<pubDate>Tue, 13 Jan 2009 23:15:25 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA["Oracle delivered 41 security fixes to its customers in its first critical patch update (CPU) of the year. Among those fixes are patches for serious flaws affecting Oracle WebLogic Server and Windows versions of Oracle Secure Backup. According to Oracle, a vulnerability in the WebLogic Server plugins for Apache, Sun and...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7531/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Patch Tuesday: MS09-001</title>
		<link>http://www.theglider.org/archives/7532</link>
		<comments>http://www.theglider.org/archives/7532#comments</comments>
		<pubDate>Tue, 13 Jan 2009 19:03:33 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Microsoft has just published MS09-001 . This update addresses an SMB flaw. "Vulnerabilities in SMB Could Allow Remote Code Execution (958687) This security update resolves several privately reported vulnerabilities in Microsoft Server Message Block (SMB) Protocol. The vulnerabilities could allow remote code execution on affected systems. An attacker who successfully exploited...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7532/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HTTPS-only mode added to Chrome Browser</title>
		<link>http://www.theglider.org/archives/7426</link>
		<comments>http://www.theglider.org/archives/7426#comments</comments>
		<pubDate>Mon, 12 Jan 2009 23:47:37 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Google has added a HTTPS browsing feature to chrome.From the changelog"A new HTTPS-only browsing mode. Add --force-https to your Google Chrome shortcut, and it will only load HTTPS sites. Sites with SSL certificate errors will not load. " Release Notes 2.0.156.1 http://dev.chromium.org/getting-involved/dev-channel/release-notes/releasenotes201561Very cool.]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7426/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gary McKinnon confesses to escape extradition to USA</title>
		<link>http://www.theglider.org/archives/7402</link>
		<comments>http://www.theglider.org/archives/7402#comments</comments>
		<pubDate>Mon, 12 Jan 2009 17:27:10 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA["COMPUTER hacker Gary McKinnon has signed a formal confession in a last-ditch attempt to avoid his extradition to the US, his family have confirmed.Former Highgate Wood School pupil Mr McKinnon, 42, is currently awaiting extradition after being accused of causing $700,000 worth of damage when he allegedly hacked into US security...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7402/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CWE &amp; SANS TOP 25 Most Dangerous Programming Errors</title>
		<link>http://www.theglider.org/archives/7403</link>
		<comments>http://www.theglider.org/archives/7403#comments</comments>
		<pubDate>Mon, 12 Jan 2009 17:06:36 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA["Most of the vulnerabilities that hackers exploit to attack Web sites and corporate servers are usually the result of common and well-understood programming errors. A list of 25 of the most serious such coding errors is scheduled to be released later today by a group of 30 high-profile organizations, including Microsoft,...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7403/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers deface Army and Nato sites</title>
		<link>http://www.theglider.org/archives/7288</link>
		<comments>http://www.theglider.org/archives/7288#comments</comments>
		<pubDate>Sat, 10 Jan 2009 00:43:09 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA["Hackers have taken down two high-profile targets as they continue their ongoing Web attacks in support of Palestine, defacing Web sites run by the U.S. Army and the North Atlantic Treaty Organization (NATO).The attacks on Thursday took down the Web sites for The United States Army Military District of Washington and...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7288/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New DNSSEC Bind Flaw Patched</title>
		<link>http://www.theglider.org/archives/7289</link>
		<comments>http://www.theglider.org/archives/7289#comments</comments>
		<pubDate>Sat, 10 Jan 2009 00:39:07 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA["Security researcher Dan Kaminsky made headlines last year when he discovered a critical DNS flaw. If left unpatched it could have crippled vast parts of the Internet. As 2009 starts up, a new DNS (define) flaw has emerged, but the severity of the threat is less pronounced. ISC (Internet Systems Consortium)...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7289/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oracle to issue 41 patches on January 13th</title>
		<link>http://www.theglider.org/archives/7272</link>
		<comments>http://www.theglider.org/archives/7272#comments</comments>
		<pubDate>Fri, 09 Jan 2009 21:05:25 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA["Next Tuesday (13 January) promises to be a busy day for hard-pressed sys admins. Although Microsoft's regular monthly Patch Tuesday update promises only one bulletin, a critical fix for Windows1, Oracle's quarterly batch weighs in at 41 fixes. The updates fix vulnerabilities across "hundreds of Oracle products", an alert from Oracle...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7272/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Suck at Information Security</title>
		<link>http://www.theglider.org/archives/7206</link>
		<comments>http://www.theglider.org/archives/7206#comments</comments>
		<pubDate>Fri, 09 Jan 2009 17:11:59 +0000</pubDate>
		<dc:creator>CGI</dc:creator>
				<category><![CDATA[CGI Security]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Lenny Zeltser from dshield has posted an amusing list of ways to suck at information security broken upin the following categories.- Security Policy and Compliance- Security Tools- Risk Management- Security Practices- Password ManagementHere's a snippet"Security Tools Deploy a security product out of the box without tuning it. Tune the IDS to...]]></description>
		<wfw:commentRss>http://www.theglider.org/archives/7206/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

