<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Secure San Diego &#187; Exploits</title>
	<atom:link href="http://www.securesandiego.com/category/exploits/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securesandiego.com</link>
	<description>A little about InfoSec from San Diego</description>
	<lastBuildDate>Wed, 13 Oct 2010 14:23:46 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Forgot to Mention</title>
		<link>http://www.securesandiego.com/2009/11/forgot-to-mention/</link>
		<comments>http://www.securesandiego.com/2009/11/forgot-to-mention/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 06:09:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Misc Security]]></category>
		<category><![CDATA[Vulnerability Management]]></category>
		<category><![CDATA[Pen Test]]></category>
		<category><![CDATA[Vulnerabilites]]></category>

		<guid isPermaLink="false">http://www.securesandiego.com/?p=107</guid>
		<description><![CDATA[MetaSploit 3.3 hit the streets today. Release notes here http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_33 And download location here http://www.metasploit.com/framework/download]]></description>
			<content:encoded><![CDATA[<p>MetaSploit 3.3 hit the streets today.</p>
<p>Release notes <a href="http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_33" target="_blank">here</a> <a href="http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_33" target="_blank">http://www.metasploit.com/redmine/projects/framework/wiki/Release_Notes_33</a></p>
<p>And download location here http://www.metasploit.com/framework/download</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securesandiego.com/2009/11/forgot-to-mention/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>RIM + PDF = Exploit me</title>
		<link>http://www.securesandiego.com/2009/05/rim-pdf-exploit-me/</link>
		<comments>http://www.securesandiego.com/2009/05/rim-pdf-exploit-me/#comments</comments>
		<pubDate>Fri, 29 May 2009 16:39:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Vulnerabilites]]></category>

		<guid isPermaLink="false">http://www.securesandiego.com/?p=80</guid>
		<description><![CDATA[Earlier this week RIM, the makers of BlackBerry, released a new vulnerability that scores rather high on the CVSS scale. In case you are not familar with CVSS this score is rather high. It is recommeded that you either patch or apply the workaround as outlined in the RIM advisory.]]></description>
			<content:encoded><![CDATA[<p>Earlier this week RIM, the makers of BlackBerry, <a title="The vuln Here" href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB18327" target="_blank">released a new vulnerability</a> that scores rather high on the <a title="To read More on CVSS" href="http://nvd.nist.gov/cvss.cfm" target="_blank">CVSS</a> scale. In case you are not familar with CVSS this score is rather high.</p>
<p>It is recommeded that you either patch or apply the workaround as outlined in the RIM advisory.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securesandiego.com/2009/05/rim-pdf-exploit-me/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Tuesday &#8211; Fail</title>
		<link>http://www.securesandiego.com/2008/12/patch-tuesday-fail/</link>
		<comments>http://www.securesandiego.com/2008/12/patch-tuesday-fail/#comments</comments>
		<pubDate>Thu, 11 Dec 2008 08:30:50 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.securesandiego.com/?p=72</guid>
		<description><![CDATA[This week contained the proverbial MSFT patch Tuesday, this set of patches contained 8 advisories patching items from Internet Explorer, MS Office Components, Windows Explorer, etc.. So in all this was a pretty heavy Black Tuesday for MSFT. The Fail As MSFT was releasing their patches another group of people were releasing their own little [...]]]></description>
			<content:encoded><![CDATA[<p>This week contained the proverbial <a href="http://blogs.technet.com/msrc/archive/2008/12/09/december-2008-monthly-bulletin-release.aspx" target="_blank">MSFT patch Tuesday</a>, this set of patches contained 8 advisories patching items from Internet Explorer, MS Office Components, Windows Explorer, etc.. So in all this was a pretty heavy Black Tuesday for MSFT.</p>
<p><strong>The Fail</strong></p>
<p>As MSFT was releasing their patches another group of people were releasing their own little bug. On Tuesday morning as the patches from MSFT were being released several online publications starting reporting a new IE 0day exploit in the wild. All the publicity started <a href="http://www.pcworld.com/article/155190/new_web_attack_exploits_unpatched_ie_flaw.html" target="_blank">here at PC World</a> and from there it just rolls down hill.</p>
<blockquote><p>The flaw was made public in Chinese language discussion forums two days ago by a security group called the Knownsec team. In tests, it worked on IE 7 running on Windows XP, Service Pack 2.</p></blockquote>
<p>Since the initial report out of PC World the news starts to spiral out of other media outlets. However nothing  good gets published until HD Moore does some really good analysis on the exploit over at the <a href="http://www.breakingpointsystems.com/community/blog/patch-tuesdays-and-drive-by-sundays" target="_blank">Breaking Point Security blog</a>.</p>
<p><strong>Defenses</strong></p>
<ol>
<li>Start off by switching browsers to FireFox. <a href="http://www.mozilla.com/en-US/firefox/?from=getfirefox" target="_blank">You can get it here.</a></li>
<li>Enable DEP on your system,</li>
</ol>
<p>Until MSFT releases a patch for this I would recommend switching to another browser.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securesandiego.com/2008/12/patch-tuesday-fail/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS &#8211; Hacker Techniques, Exploits and Incident Handling</title>
		<link>http://www.securesandiego.com/2008/11/sans-hacker-techniques-exploits-and-incident-handling/</link>
		<comments>http://www.securesandiego.com/2008/11/sans-hacker-techniques-exploits-and-incident-handling/#comments</comments>
		<pubDate>Wed, 12 Nov 2008 20:19:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Monitoring]]></category>
		<category><![CDATA[Training]]></category>
		<category><![CDATA[SANS]]></category>

		<guid isPermaLink="false">http://www.securesandiego.com/?p=52</guid>
		<description><![CDATA[Reminder to anyone that reads here. I will be teaching the above course here in San Diego starting December 9th. You can get event details here http://www.sans.org/mentor/details.php?nid=15064 and to register go here https://www.sans.org/registration/register.php?conferenceid=15064 Summary of the course. This course addresses the latest cutting-edge insidious attack vectors and the oldie-but-goodie attacks that are still so prevalent, [...]]]></description>
			<content:encoded><![CDATA[<p>Reminder to anyone that reads here. I will be teaching the above course here in San Diego starting December 9th. You can get event details here <a href="http://www.sans.org/mentor/details.php?nid=15064" target="_blank">http://www.sans.org/mentor/details.php?nid=15064</a> and to register go here <a href="https://www.sans.org/registration/register.php?conferenceid=15064" target="_blank">https://www.sans.org/registration/register.php?conferenceid=15064</a></p>
<p>Summary of the course.</p>
<blockquote><p>This course addresses the latest cutting-edge insidious attack vectors and the oldie-but-goodie attacks that are still so prevalent, and everything in between. Instead of merely teaching a few hack-attack tricks, this course includes a time-tested, step-by-step process for responding to computer incidents, a detailed description of how attackers undermine systems so you can prepare, detect, and respond to them, and a hands-on workshop for discovering holes before the bad guys do. Additionally, the course explores the legal issues associated with responding to computer attacks, including employee monitoring, working with law enforcement, and handling evidence.</p></blockquote>
<p>I hope to see you there.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securesandiego.com/2008/11/sans-hacker-techniques-exploits-and-incident-handling/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Patch Or Die</title>
		<link>http://www.securesandiego.com/2008/10/patch-or-die/</link>
		<comments>http://www.securesandiego.com/2008/10/patch-or-die/#comments</comments>
		<pubDate>Fri, 24 Oct 2008 06:06:48 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Vulnerabilities]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Vulnerabilites]]></category>

		<guid isPermaLink="false">http://www.securesandiego.com/?p=36</guid>
		<description><![CDATA[Caught your eye on that one. It seems there is a new vulnerability/exploit out there that MSFT so &#8220;bad&#8221; that they have resleased an out of band patch. How bad is it, well let&#8217;s just say you should patch all your windows system ASAP. I am not going to analyze this patch again, as many [...]]]></description>
			<content:encoded><![CDATA[<p>Caught your eye on that one. It seems there is a new vulnerability/exploit out there that MSFT so &#8220;bad&#8221; that they have resleased an out of band patch. How bad is it, well let&#8217;s just say you should patch all your windows system ASAP. I am not going to analyze this patch again, as many others have done so already.</p>
<p>Just 2 words for you &#8211; PATCH IT</p>
<p>As of 11:00 PM PST there is a known working Exploit in the wild in the form of a worm.</p>
<p>Read all about this in teh links below.</p>
<p><a href="http://www.microsoft.com/technet/security/Bulletin/ms08-067.mspx" target="_blank">Microsoft Patch Notification</a></p>
<p><a href="http://blogs.technet.com/msrc/archive/2008/10/23/ms08-067-released.aspx" target="_blank">Microsoft TechNet Blog entry</a></p>
<p><a href="http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx" target="_blank">Microsoft TechNet Blog Entry more about</a></p>
<p><a href="http://isc.sans.org/diary.html?storyid=5227" target="_blank">The normal SANS Stuff</a></p>
<p>Exploit information links below</p>
<p><a href="http://blog.threatexpert.com/2008/10/gimmiva-exploits-zero-day-vulnerability.html" target="_blank">Good blog entry on the worm/exploit</a> &#8211; ThreatExpert</p>
<p><a href="http://www.teamfurry.com/wordpress/2008/10/24/new-worm-on-the-loose/" target="_blank">Another Good Entry</a> &#8211; Team Furry</p>
<p>Comment as you see fit.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securesandiego.com/2008/10/patch-or-die/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

