<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>EnableSecurity</title>
	<atom:link href="http://enablesecurity.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://enablesecurity.com</link>
	<description>Security Consultancy, Research and Development</description>
	<pubDate>Wed, 07 Jan 2009 13:38:17 +0000</pubDate>
	<generator>http://wordpress.org/?v=MU</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
		<url>http://www.gravatar.com/blavatar/277c71575ac661f2e6c6c304e5db39a3?s=96&#038;d=http://s.wordpress.com/i/buttonw-com.png</url>
		<title>EnableSecurity</title>
		<link>http://enablesecurity.com</link>
	</image>
			<item>
		<title>VOIPPACK now available!</title>
		<link>http://enablesecurity.com/2009/01/05/voippack-now-available/</link>
		<comments>http://enablesecurity.com/2009/01/05/voippack-now-available/#comments</comments>
		<pubDate>Mon, 05 Jan 2009 17:09:27 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[Site news]]></category>

		<category><![CDATA[sipvicious]]></category>

		<category><![CDATA[voice over ip]]></category>

		<category><![CDATA[voip security]]></category>

		<category><![CDATA[voippack]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=207</guid>
		<description><![CDATA[EnableSecurity VOIPPACK is finally out! We would like to thank everyone who made this possible. VOIPPACK can be purchased from our reseller Immunity in the US or directly for the rest of the world.
More information about pricing and video demonstrations can be found in the product page.

&#160;&#160;&#160;&#160;&#160;&#160;     ]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong><a href="http://enablesecurity.com/products/enablesecurity-voippack/">EnableSecurity VOIPPACK</a> is finally out!</strong> We would like to thank everyone who made this possible. VOIPPACK can be purchased from <a href="http://www.immunityinc.com/products-enablesecurity.shtml">our reseller Immunity</a> in the US or directly for the rest of the world.</p>
<p>More information about pricing and video demonstrations can be found in the <a href="http://enablesecurity.com/products/enablesecurity-voippack/">product page</a>.</p>
<p><img src="http://enablesecurity.files.wordpress.com/2008/12/voippack.jpg?w=400&amp;h=310" alt="http://enablesecurity.files.wordpress.com/2008/12/voippack.jpg?w=400&amp;h=310" /></p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/207/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=207&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2009/01/05/voippack-now-available/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>

		<media:content url="http://enablesecurity.files.wordpress.com/2008/12/voippack.jpg?w=400&#38;h=310" medium="image">
			<media:title type="html">http://enablesecurity.files.wordpress.com/2008/12/voippack.jpg?w=400&#38;h=310</media:title>
		</media:content>
	</item>
		<item>
		<title>Cross Site Scripting on your non-sensitive website?</title>
		<link>http://enablesecurity.com/2008/12/17/cross-site-scripting-on-your-non-sensitive-website/</link>
		<comments>http://enablesecurity.com/2008/12/17/cross-site-scripting-on-your-non-sensitive-website/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 18:37:06 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[rant]]></category>

		<category><![CDATA[american express]]></category>

		<category><![CDATA[cross site scripting]]></category>

		<category><![CDATA[fixing xss]]></category>

		<category><![CDATA[vulnerability prioritization]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=196</guid>
		<description><![CDATA[This article first appeared in EnableSecurity newsletter 0&#215;0001. Subscribe to the newsletter by sending an email to newsletter@enablesecurity.com.
It is often easy to calculate risk incorrectly. This may be due to lack of information or because one is not looking at the big picture. One particular topic that came up a month or so was prioritizing [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><em>This article first appeared in EnableSecurity newsletter 0&#215;0001. Subscribe to the newsletter by sending an email to <a href="mailto:newsletter@enablesecurity.com">newsletter@enablesecurity.com</a>.</em></p>
<p>It is often easy to calculate risk incorrectly. This may be due to lack of information or because one is not looking at the big picture. One particular topic that came up a month or so was prioritizing XSS on a main website which has no sensitive information, only informational content. The sensitive information is available on a different site to which the main website links. In many cases, such sites are not considered worth fixing within a reasonable time and tend to stay vulnerable because other tasks of higher priority come up. That is, until one of the following scenarios happens:</p>
<ul>
<li>Blackhat SEOs target your site to help <a href="http://www.cgisecurity.com/2008/03/10" target="_blank">increase their google ranking</a></li>
<li>No better or worse phishing attack than having your website include a form asking for a username and password which are sent to a <a href="http://tinyurl.com/2uge9s" target="_blank">Taiwanese webserver</a>. This especially applies if your service is a target of phishers.</li>
<li>Displaying of fake articles and press releases on your website, or redirection to malicious executables making it appear that your legit site is sending malware.</li>
<li>The media catches on and publishes details of the vulnerability - this is what just happened to <a href="http://go.theregister.com/news/http://www.theregister.co.uk/2008/12/16/american_express_website_bug/" target="_blank">American Express in the past days</a>.</li>
</ul>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/196/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/196/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/196/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=196&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/12/17/cross-site-scripting-on-your-non-sensitive-website/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>Demonstration of sipautohack</title>
		<link>http://enablesecurity.com/2008/12/17/demontration-of-sipautohack/</link>
		<comments>http://enablesecurity.com/2008/12/17/demontration-of-sipautohack/#comments</comments>
		<pubDate>Wed, 17 Dec 2008 09:34:35 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[Site news]]></category>

		<category><![CDATA[sipautohack]]></category>

		<category><![CDATA[voippack]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=191</guid>
		<description><![CDATA[Note: we are no longer accepting beta testing requests for VOIPPACK. Thanks for everyone who contributed to the beta testing!
VOIPPACK is nearing release stage - stay tuned.
For the high definition (HD) version of this video visit this page.


	
	
	
	


&#160;&#160;&#160;&#160;&#160;&#160;     ]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><strong>Note: we are no longer accepting beta testing requests for VOIPPACK. Thanks for everyone who contributed to the beta testing!</strong></p>
<p>VOIPPACK is nearing release stage - stay tuned.<br />
For the high definition (HD) version of this video visit <a href="http://vimeo.com/2524735" target="_blank">this page</a>.</p>
<p><span style='text-align:center; display: block;'>
<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.vimeo.com/moogaloop.swf?clip_id=2524735&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA">
	<param name="quality" value="best" />
	<param name="allowfullscreen" value="true" />
	<param name="scale" value="showAll" />
	<param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=2524735&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA" />
</object>
</span></p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/191/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/191/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/191/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=191&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/12/17/demontration-of-sipautohack/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>Would you like to try the beta of VoIPPack?</title>
		<link>http://enablesecurity.com/2008/12/11/would-you-like-to-try-the-beta-of-voippack/</link>
		<comments>http://enablesecurity.com/2008/12/11/would-you-like-to-try-the-beta-of-voippack/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 14:51:44 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[Site news]]></category>

		<category><![CDATA[voippack]]></category>

		<category><![CDATA[canvas]]></category>

		<category><![CDATA[sipautohack]]></category>

		<guid isPermaLink="false">http://enablesecurity.com/?p=180</guid>
		<description><![CDATA[VoIPPack adds VoIP capabilities to Immunity CANVAS. For more information about VoIPPack take a look at the product page. We are currently running a private beta so send us an email to apply as a beta tester.
The following is a taster showing sipautohack scanning a target network, identifying PBX server, enumerating the extensions intelligently and [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://enablesecurity.com/products/enablesecurity-voippack/">VoIPPack</a> adds VoIP capabilities to <a href="http://www.immunitysec.com/products-canvas.shtml" target="_blank">Immunity CANVAS</a>. For more information about VoIPPack take a look at <a href="http://enablesecurity.com/products/enablesecurity-voippack">the product page</a>. We are currently running a private beta so <a href="mailto:voippackbeta@enablesecurity.com">send us an email to apply as a beta tester</a>.</p>
<p>The following is a taster showing sipautohack scanning a target network, identifying PBX server, enumerating the extensions intelligently and finally cracking the password for each extension on the PBX. More demos <a href="http://enablesecurity.com/products/enablesecurity-voippack">here</a>.</p>
<p><span style='text-align:center; display: block;'>
<object type="application/x-shockwave-flash" width="400" height="300" data="http://www.vimeo.com/moogaloop.swf?clip_id=2426478&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA">
	<param name="quality" value="best" />
	<param name="allowfullscreen" value="true" />
	<param name="scale" value="showAll" />
	<param name="movie" value="http://www.vimeo.com/moogaloop.swf?clip_id=2426478&amp;server=www.vimeo.com&amp;fullscreen=1&amp;show_title=1&amp;show_byline=0&amp;show_portrait=0&amp;color=01AAEA" />
</object>
</span></p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/180/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/180/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/180/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/180/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/180/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/180/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/180/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/180/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/180/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/180/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=180&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/12/11/would-you-like-to-try-the-beta-of-voippack/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>
	</item>
		<item>
		<title>(IN)SECURE Magazine and other updates</title>
		<link>http://enablesecurity.com/2008/12/02/insecure-magazine-and-other-updates/</link>
		<comments>http://enablesecurity.com/2008/12/02/insecure-magazine-and-other-updates/#comments</comments>
		<pubDate>Tue, 02 Dec 2008 00:21:50 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[Research]]></category>

		<category><![CDATA[Site news]]></category>

		<category><![CDATA[acunetix]]></category>

		<category><![CDATA[h2hc]]></category>

		<category><![CDATA[insecure magazine]]></category>

		<category><![CDATA[insecuremag]]></category>

		<category><![CDATA[malta information security]]></category>

		<category><![CDATA[maltainforsec]]></category>

		<category><![CDATA[sandro gauci]]></category>

		<category><![CDATA[waf]]></category>

		<category><![CDATA[web application firewall]]></category>

		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=123</guid>
		<description><![CDATA[This is an update of what&#8217;s been happening on this end:

Issue 19 of (IN)SECURE Magazine is out, and with it you&#8217;ll find a report on RSA Europe 2008 and an article called &#8220;How security can hurt us&#8221; by yours truly. The magazine has a number of high quality articles and is  freely available from the [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>This is an update of what&#8217;s been happening on this end:<a href="http://enablesecurity.files.wordpress.com/2008/12/snapshot-2008-12-01-10-16-301.jpg"><img class="alignright size-full wp-image-125" title="snapshot-2008-12-01-10-16-301" src="http://enablesecurity.files.wordpress.com/2008/12/snapshot-2008-12-01-10-16-301.jpg?w=183&#038;h=259" alt="snapshot-2008-12-01-10-16-301" width="183" height="259" /></a></p>
<ul>
<li>Issue 19 of (IN)SECURE Magazine is out, and with it you&#8217;ll find a report on RSA Europe 2008 and an article called &#8220;How security can hurt us&#8221; by yours truly. The magazine has a number of high quality articles and is  freely available from <a href="http://www.net-security.org/insecuremag.php" target="_blank">the main website</a>.</li>
<li>Upcoming research: Vulnerabilities and tools related to Web Application Firewalls. Wendel Guglielmetti Henrique combined his and my research and presented it at H2HC. The presentation was called <a href="http://www.h2hc.com.br/palestrantes.html#SandroGauci" target="_blank">&#8220;Playing with Web Application Firewalls&#8221;</a>. Additionally, I presented my research at a local ISACA chapter. This research is still in its initial stage but is already showing significant results. Will be putting a separate post on this.</li>
<li>The <a href="http://www.acunetix.com/blog/" target="_blank">blog at Acunetix</a> now features posts by <a href="http://www.acunetix.com/blog/author/sandrogauci/" target="_blank">yours truly</a> on (you guessed it) Web Application Security.</li>
<li>If you are based in <a href="http://enablesecurity.com/malta">Malta</a>, then you might be interested in the <a href="http://www.linkedin.com/e/gis/1378047" target="_blank">Malta Infosec linkedin group</a> that will be organizing some informal events &#8220;real soon&#8221;. The blog is at <a href="http://maltainfosec.org/" target="_blank">Maltainfosec.org</a>.</li>
</ul>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/123/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/123/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/123/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=123&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/12/02/insecure-magazine-and-other-updates/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>

		<media:content url="http://enablesecurity.files.wordpress.com/2008/12/snapshot-2008-12-01-10-16-301.jpg" medium="image">
			<media:title type="html">snapshot-2008-12-01-10-16-301</media:title>
		</media:content>
	</item>
		<item>
		<title>At RSA Europe 2008 - Talks of interest</title>
		<link>http://enablesecurity.com/2008/10/27/at-rsa-europe-2008-talks-of-interest/</link>
		<comments>http://enablesecurity.com/2008/10/27/at-rsa-europe-2008-talks-of-interest/#comments</comments>
		<pubDate>Mon, 27 Oct 2008 10:39:12 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[Site news]]></category>

		<category><![CDATA[london security]]></category>

		<category><![CDATA[rsa europe]]></category>

		<category><![CDATA[rsa europe 2008]]></category>

		<category><![CDATA[security conference]]></category>

		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=87</guid>
		<description><![CDATA[Currently at RSA Europe in London and the Keynote is about to start. While we&#8217;re being given a Discovery Channel styled lecture on Alan Turing, I&#8217;ve been marking the sessions that have a potential of being interesting. Marked the following:

Security Remodelling - Benjamin Jun
Locking the Back Door: New Backdoor Threats in Application Security by Chris [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>Currently at RSA Europe in London and the Keynote is about to start. While we&#8217;re being given a Discovery Channel styled lecture on Alan Turing, I&#8217;ve been marking the sessions that have a potential of being interesting. Marked the following:</p>
<ul>
<li>Security Remodelling - Benjamin Jun</li>
<li>Locking the Back Door: New Backdoor Threats in Application Security by Chris Wysopal</li>
<li>A dialogue with ENISA</li>
<li>VoIP Threats and Countermeasures by David Endler (conflicts with the talk  by Chris Wysopal)</li>
<li>Evolving threat landscape: Do we have to trade off browser functionality for security and privacy? Craig Spiezle (Microsoft)</li>
<li>Security Testing in Web 2.0 World by Billy Hoffman</li>
<li>SQL Smuggling by Avi Douglen</li>
<li>Regular expressions as a basis for Security Products are dead by Steve Moyle</li>
<li>Blinded by Flash: Widespread security risks flash developers don&#8217;t see by Prajakta Jagdale</li>
<li>Mobile Banking and Identity Theft: Can your phone protect your identity? Patrick Bedwell</li>
</ul>
<p>Then there&#8217;s quite a few &#8220;special interest groups&#8221; that look intriguing as well.</p>
<p>Meanwhile Arthur W. Coviello of RSA is talking about why the way we do security fails, and suggesting a <em>better</em> approach. Talk about Information Risk Management Stategy, and picking on regulations and compliance.</p>
<p>I&#8217;ll be posting live updates on <a href="http://www.twitter.com/sandrogauci" target="_blank">twitter.com/sandrogauci</a>. If any visitors are around, feel free to send me a <a href="http://enablesecurity.com/contact">msg</a>.</p>
<p style="text-align:center;"><a href="http://enablesecurity.files.wordpress.com/2008/10/rsa-europe1.jpg"><img class="aligncenter size-full wp-image-86" title="rsa-europe1" src="http://enablesecurity.files.wordpress.com/2008/10/rsa-europe1.jpg?w=231&#038;h=79" alt="" width="231" height="79" /></a></p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/87/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/87/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/87/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=87&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/10/27/at-rsa-europe-2008-talks-of-interest/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>

		<media:content url="http://enablesecurity.files.wordpress.com/2008/10/rsa-europe1.jpg" medium="image">
			<media:title type="html">rsa-europe1</media:title>
		</media:content>
	</item>
		<item>
		<title>Does your software check for updates? You might be in trouble</title>
		<link>http://enablesecurity.com/2008/10/13/does-your-software-check-for-updates-you-might-be-in-trouble/</link>
		<comments>http://enablesecurity.com/2008/10/13/does-your-software-check-for-updates-you-might-be-in-trouble/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 10:42:20 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[rant]]></category>

		<category><![CDATA[digital signing]]></category>

		<category><![CDATA[evilgrade]]></category>

		<category><![CDATA[insecure updates]]></category>

		<category><![CDATA[signed updates]]></category>

		<category><![CDATA[update vulnerabilities]]></category>

		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=77</guid>
		<description><![CDATA[Note: this article originally appeared on EnableSecurity Newsletter #0&#215;0001. To subscribe send an email to newsletter@enablesecurity.com. 
Most contemporary software attempts to perform automated updates for  one thing or another. Maybe it&#8217;s a patch for the software itself, or simply a list of additional files that are required for day to day operations. Security software such [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><em><strong>Note</strong>: this article originally appeared on EnableSecurity Newsletter #0&#215;0001. To subscribe send an email to <a href="mailto:newsletter@enablesecurity.com">newsletter@enablesecurity.com</a>. </em></p>
<p>Most contemporary software attempts to perform automated updates for  one thing or another. Maybe it&#8217;s a patch for the software itself, or simply a list of additional files that are required for day to day operations. Security software such as Antivirus software needs to be  automatically updated if it wants to protect against the latest threats instantly. Although of these updates do not have any sort of precautions for man in the middle attacks, no one seemed to care until the past few months.</p>
<p style="text-align:center;"><a href="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-13-12-46-21.jpg"><img class="size-full wp-image-81 aligncenter" title="snapshot-2008-10-13-12-46-21" src="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-13-12-46-21.jpg?w=420&#038;h=201" alt="" width="420" height="201" /></a></p>
<p>It is only the latest <a href="http://www.doxpara.com" target="_blank">DNS cache poisoning flaw</a> that made researchers and security folks tick and start realizing that the upcoming patch might not be what it seems. Then <a href="http://www.infobyte.com.ar/down/isr-evilgrade-Readme.txt" target="_blank">Evilgrade</a> came out. This software is an exploitation framework which allows penetration testers to demonstrate upgrade related flaws in the following software:</p>
<ul>
<li>Java plugin</li>
<li>Winzip</li>
<li>Winamp</li>
<li>MacOS</li>
<li>OpenOffices</li>
<li>iTunes</li>
<li>Linkedin Toolbar</li>
</ul>
<p>Meanwhile security advisories keep coming out identifying new software which is vulnerable to this attack:</p>
<ul>
<li><a href="http://www.securityfocus.com/archive/1/496389" target="_blank">InstallShield Update Agent - Remote &#8220;Rule Script&#8221; Code Execution Vulnerability</a></li>
<li><a href="http://seclists.org/fulldisclosure/2008/Aug/0302.html" target="_blank">PartyGaming PartyPoker Malicious Update Vulnerability</a></li>
</ul>
<p>I&#8217;m sure that this is only the tip of the iceberg and there is more to come.</p>
<p>Automated updates can be a life saver, and certain products cannot do without them (like Antivirus software). However (security) updates in particular should not be introducing this kind of security issue!</p>
<p>If you&#8217;re a software vendor you have a responsibility to make sure that your automated updates are signed and verified in a secure manner <a rel="nofollow" href="http://seclists.org/fulldisclosure/2008/Aug/0302.html" target="_blank"></a></p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/77/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/77/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/77/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=77&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/10/13/does-your-software-check-for-updates-you-might-be-in-trouble/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>

		<media:content url="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-13-12-46-21.jpg" medium="image">
			<media:title type="html">snapshot-2008-10-13-12-46-21</media:title>
		</media:content>
	</item>
		<item>
		<title>Apple Mail.app security advisory</title>
		<link>http://enablesecurity.com/2008/10/03/apple-mailapp-security-advisory/</link>
		<comments>http://enablesecurity.com/2008/10/03/apple-mailapp-security-advisory/#comments</comments>
		<pubDate>Fri, 03 Oct 2008 15:04:58 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[Research]]></category>

		<category><![CDATA[security]]></category>

		<category><![CDATA[advisory]]></category>

		<category><![CDATA[apple]]></category>

		<category><![CDATA[mail.app]]></category>

		<category><![CDATA[privacy]]></category>

		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=69</guid>
		<description><![CDATA[The newsletter issued yesterday included an advisory on Mail.app&#8217;s insecure storage of S/MIME on the email server. The main problem is that people making use of S/MIME expect encryption to protect them from a snooping mail server, and the default &#8220;store drafts on mail server&#8221; option does not respect this.
At this stage Apple did not [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-03-17-10-16.jpg"><img class="size-full wp-image-71 alignright" title="snapshot-2008-10-03-17-10-16" src="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-03-17-10-16.jpg?w=160&#038;h=143" alt="" width="160" height="143" /></a>The newsletter issued yesterday included <a href="http://resources.enablesecurity.com/advisories/apple-mailapp-smime.txt" target="_blank">an advisory</a> on Mail.app&#8217;s insecure storage of S/MIME on the email server. The main problem is that people making use of S/MIME expect encryption to protect them from a snooping mail server, and the default &#8220;store drafts on mail server&#8221; option does not respect this.</p>
<p>At this stage Apple did not release anything to address this issue because it <em>might</em> require architectural changes. I understand that - however publishing a solution to this issue does not have to consist of a patch. This is why I&#8217;m publishing the advisory and the below solutions, so that clients that are concerned about this can mitigate.</p>
<p>If you would like to stick to Mail.app:</p>
<ul>
<li>Go to the Preferences and select the account from the accounts tab</li>
<li>Select the &#8220;Mailbox behaviors&#8221; tab</li>
<li>Uncheck the option &#8220;Store draft messages on the server&#8221;</li>
</ul>
<p>Otherwise some <a href="http://www.mozilla.com/thunderbird/" target="_blank">other email clients</a> are not vulnerable because they encrypt the drafts emails before they are sent to server.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/69/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/69/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/69/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=69&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/10/03/apple-mailapp-security-advisory/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>

		<media:content url="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-03-17-10-16.jpg" medium="image">
			<media:title type="html">snapshot-2008-10-03-17-10-16</media:title>
		</media:content>
	</item>
		<item>
		<title>EnableSecurity Newsletter 0&#215;0001</title>
		<link>http://enablesecurity.com/2008/10/03/enablesecurity-newsletter-0x0001/</link>
		<comments>http://enablesecurity.com/2008/10/03/enablesecurity-newsletter-0x0001/#comments</comments>
		<pubDate>Fri, 03 Oct 2008 14:17:33 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[Site news]]></category>

		<category><![CDATA[enablesecurity newsletter]]></category>

		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=66</guid>
		<description><![CDATA[The first issue of the newsletter is out! Included the articles of interest:

Upcoming EnableSecurity projects
Events: RSA Europe 2008
New advisory: Apple&#8217;s Mail.app stores your S/MIME encrypted emails in clear text
Surf Jack updates and what is Surf Jack anyway?
Cross Site Scripting on your non-sensitive website?
Your magnetic stripe credit card is going away
Does your software check for updates? [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p>The first issue of the newsletter is out! Included the articles of interest:</p>
<ul>
<li>Upcoming EnableSecurity projects</li>
<li>Events: RSA Europe 2008</li>
<li>New advisory: Apple&#8217;s Mail.app stores your S/MIME encrypted emails in clear text</li>
<li>Surf Jack updates and what is Surf Jack anyway?</li>
<li>Cross Site Scripting on your non-sensitive website?</li>
<li>Your magnetic stripe credit card is going away</li>
<li>Does your software check for updates? You might be in trouble&#8230;</li>
<li>Selected Security news</li>
</ul>
<p style="text-align:center;"><a href="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-03-15-47-51.jpg"><img class="size-full wp-image-67 aligncenter" title="snapshot-2008-10-03-15-47-51" src="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-03-15-47-51.jpg?w=427&#038;h=456" alt="" width="427" height="456" /></a></p>
<p>Some of these articles will eventually find their way to this blog or other locations. Others will remain exclusive to the newsletter.</p>
<p>To get access to the newsletter simply send me an email to <a href="mailto:newsletter@enablesecurity.com">newsletter@enablesecurity.com</a>.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/66/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/66/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/66/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=66&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/10/03/enablesecurity-newsletter-0x0001/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>

		<media:content url="http://enablesecurity.files.wordpress.com/2008/10/snapshot-2008-10-03-15-47-51.jpg" medium="image">
			<media:title type="html">snapshot-2008-10-03-15-47-51</media:title>
		</media:content>
	</item>
		<item>
		<title>(IN)SECURE Magazine Issue 18</title>
		<link>http://enablesecurity.com/2008/09/30/insecure-magazine-issue-18/</link>
		<comments>http://enablesecurity.com/2008/09/30/insecure-magazine-issue-18/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 03:40:27 +0000</pubDate>
		<dc:creator>Sandro</dc:creator>
		
		<category><![CDATA[Site news]]></category>

		<category><![CDATA[bgp security]]></category>

		<category><![CDATA[dns poisoning]]></category>

		<category><![CDATA[dns security]]></category>

		<category><![CDATA[insecure magazine]]></category>

		<category><![CDATA[insecuremag]]></category>

		<category><![CDATA[security assumptions]]></category>

		<category><![CDATA[snmp security]]></category>

		<category><![CDATA[snmp v3]]></category>

		<guid isPermaLink="false">http://enablesecurity.wordpress.com/?p=63</guid>
		<description><![CDATA[The latest issue of the free digital security publication is out and includes some thought provoking articles:

Browser security: bolt it on, then build it in by Jeremiah Grossman
Windows driver vulnerabilities: the METHOD_NEITHER odyssey by Anibal Sacco
Insecurities in privacy protection software by Shrikant Raman
Compliance does not equal security but it&#8217;s a good start by Jack Danahy

This [...]]]></description>
			<content:encoded><![CDATA[<div class='snap_preview'><br /><p><a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-18.pdf" target="_blank"><img class="size-full wp-image-64 alignright" title="insecuremag18" src="http://enablesecurity.files.wordpress.com/2008/09/snapshot-2008-09-30-05-08-03.jpg?w=188&#038;h=264" alt="" width="188" height="264" /></a>The <a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-18.pdf" target="_blank">latest issue</a> of the free digital security publication is out and includes some thought provoking articles:</p>
<ul>
<li>Browser security: bolt it on, then build it in by Jeremiah Grossman</li>
<li>Windows driver vulnerabilities: the METHOD_NEITHER odyssey by Anibal Sacco</li>
<li>Insecurities in privacy protection software by Shrikant Raman</li>
<li>Compliance does not equal security but it&#8217;s a good start by Jack Danahy</li>
</ul>
<p>This issue also includes my column which talks about why the latest happenings in the security industry should shake us to our senses. The idea is that we need to realize that some of the Internet technologies that we rely on have fundamental flaws.</p>
<p>Here&#8217;s a <a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-18.pdf" target="_blank">download link</a>.</p>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/enablesecurity.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/enablesecurity.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/enablesecurity.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/enablesecurity.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/enablesecurity.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/enablesecurity.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/enablesecurity.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/enablesecurity.wordpress.com/63/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/enablesecurity.wordpress.com/63/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/enablesecurity.wordpress.com/63/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=enablesecurity.com&blog=3438158&post=63&subd=enablesecurity&ref=&feed=1" /></div>]]></content:encoded>
			<wfw:commentRss>http://enablesecurity.com/2008/09/30/insecure-magazine-issue-18/feed/</wfw:commentRss>
	
		<media:content url="http://www.gravatar.com/avatar/192a78d487076b95fb3562ad601a1535?s=96&#38;d=identicon" medium="image">
			<media:title type="html">sandro</media:title>
		</media:content>

		<media:content url="http://enablesecurity.files.wordpress.com/2008/09/snapshot-2008-09-30-05-08-03.jpg" medium="image">
			<media:title type="html">insecuremag18</media:title>
		</media:content>
	</item>
	</channel>
</rss>