<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Nenad Vijatov &#187; Security</title>
	<atom:link href="http://blog.vijatov.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.vijatov.com</link>
	<description>xor %ecx,%ecx</description>
	<lastBuildDate>Thu, 05 Aug 2010 23:14:55 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Ubuntu Pentest Edition</title>
		<link>http://blog.vijatov.com/2010/01/15/ubuntu-pentest-edition/</link>
		<comments>http://blog.vijatov.com/2010/01/15/ubuntu-pentest-edition/#comments</comments>
		<pubDate>Fri, 15 Jan 2010 11:41:00 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Pentest]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=116</guid>
		<description><![CDATA[netinfinity release Ubuntu Pentest Edition &#8230; &#8220;Ubuntu pentest edition is primarily designed as a complete system (everyday usage &#8211; office, internet etc..) and can be used in pentesting purposes, which is a big advantage because you do not need to have a dual boot or use a virtual machine to run the system for pentest.&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p>netinfinity release Ubuntu Pentest Edition &#8230;<br />
&#8220;Ubuntu pentest edition is primarily designed as a complete system (everyday usage &#8211; office, internet etc..) and can be used in pentesting purposes, which is a big advantage because you do not need to have a dual boot or use a virtual machine to run the system for pentest.&#8221;<br />
Try it &#8230; <a href="http://www.netinfinity.org/download/">link</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2010/01/15/ubuntu-pentest-edition/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sinergija 09</title>
		<link>http://blog.vijatov.com/2009/10/11/sinergija-09/</link>
		<comments>http://blog.vijatov.com/2009/10/11/sinergija-09/#comments</comments>
		<pubDate>Sun, 11 Oct 2009 20:57:11 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[BitLocker]]></category>
		<category><![CDATA[BitLocker to Go]]></category>
		<category><![CDATA[Sinergija 09]]></category>
		<category><![CDATA[Windows 7 Security]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=110</guid>
		<description><![CDATA[I will have a technical speak at Sinergija 09 about BitLocker &#038; BitLocker to Go in Windows 7. Title of presentation is Fighting stealers with BitLocker.]]></description>
			<content:encoded><![CDATA[<p>I will have a technical speak at <a href="http://www.mssinergija.net">Sinergija 09</a> about <a href="http://www.microsoft.com/windows/enterprise/products/windows-7/features.aspx#bitlocker">BitLocker &#038; BitLocker to Go in Windows 7</a>.<br />
Title of presentation is <a href="http://www.mssinergija.net/en/agenda_dyn.aspx"><em>Fighting stealers with BitLocke</em>r</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/10/11/sinergija-09/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Researcher Acknowledgments for Microsoft Online Services</title>
		<link>http://blog.vijatov.com/2009/09/01/security-researcher-acknowledgments-for-microsoft-online-services-4/</link>
		<comments>http://blog.vijatov.com/2009/09/01/security-researcher-acknowledgments-for-microsoft-online-services-4/#comments</comments>
		<pubDate>Tue, 01 Sep 2009 06:40:32 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Nenad Vijatov]]></category>
		<category><![CDATA[Researcher Acknowledgment]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=106</guid>
		<description><![CDATA[&#8230; for July and August. Thanks to Microsoft Security Response Center.]]></description>
			<content:encoded><![CDATA[<p>&#8230; for July and August.<br />
Thanks to <a href="http://blogs.technet.com/msrc/">Microsoft Security Response Center</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/09/01/security-researcher-acknowledgments-for-microsoft-online-services-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security Researcher Acknowledgment</title>
		<link>http://blog.vijatov.com/2009/07/16/security-researcher-acknowledgment/</link>
		<comments>http://blog.vijatov.com/2009/07/16/security-researcher-acknowledgment/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 13:18:23 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Nenad Vijatov]]></category>
		<category><![CDATA[Researcher Acknowledgment]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=104</guid>
		<description><![CDATA[&#8230; for June 2009. http://technet.microsoft.com/en-us/security/cc308589.aspx]]></description>
			<content:encoded><![CDATA[<p>&#8230; for June 2009.</p>
<p><a href="http://technet.microsoft.com/en-us/security/cc308589.aspx">http://technet.microsoft.com/en-us/security/cc308589.aspx</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/07/16/security-researcher-acknowledgment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>NetFlow Analyzer 7 Cross-Site Scripting Vulnerabilities</title>
		<link>http://blog.vijatov.com/2009/07/16/netflow-analyzer-7-cross-site-scripting-vulnerabilities/</link>
		<comments>http://blog.vijatov.com/2009/07/16/netflow-analyzer-7-cross-site-scripting-vulnerabilities/#comments</comments>
		<pubDate>Thu, 16 Jul 2009 13:14:01 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/2009/07/16/netflow-analyzer-7-cross-site-scripting-vulnerabilities/</guid>
		<description><![CDATA[I’ve discovered some XSS vulnerabilities in NetFlow Analyzer 7. Link to Secunia SA.]]></description>
			<content:encoded><![CDATA[<p>I’ve discovered some XSS vulnerabilities in NetFlow Analyzer 7.</p>
<p>Link to <a href="http://secunia.com/advisories/35105/">Secunia SA</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/07/16/netflow-analyzer-7-cross-site-scripting-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PSCS VPOP3 Email Server Cross-Site Scripting Vulnerabilities</title>
		<link>http://blog.vijatov.com/2009/03/25/pscs-vpop3-email-server-cross-site-scripting-vulnerabilities/</link>
		<comments>http://blog.vijatov.com/2009/03/25/pscs-vpop3-email-server-cross-site-scripting-vulnerabilities/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 18:24:44 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Web Application Security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=64</guid>
		<description><![CDATA[I&#8217;ve discovered new XSS vulnerabilities in PSCS VPOP3 Enterprise Email server, exactly on Web Mail interface. Vulnerability version is 2.6.0j. Vendor is informed but isn&#8217;t published fix for this vulnerabilities yet, so for solution use a proxy or IPS to filter malicious characters. Secunia confirmed and published this vulnerability.]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve discovered new XSS vulnerabilities in PSCS VPOP3 Enterprise Email server, exactly on Web Mail interface. Vulnerability version is 2.6.0j. Vendor is informed but isn&#8217;t published fix for this vulnerabilities yet, so for solution use a proxy or IPS to filter malicious characters.</p>
<p><a href="http://secunia.com/advisories/34270/" target="_blank">Secunia</a> confirmed and published this vulnerability.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/03/25/pscs-vpop3-email-server-cross-site-scripting-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Pwn2Own 2009</title>
		<link>http://blog.vijatov.com/2009/03/22/pwn2own-2009/</link>
		<comments>http://blog.vijatov.com/2009/03/22/pwn2own-2009/#comments</comments>
		<pubDate>Sat, 21 Mar 2009 23:11:07 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=62</guid>
		<description><![CDATA[This years Pwn2Own uncover 4 new never seen before critical vulnerabilities affecting the IE8, Safari and FireFox. More about this contest you can read at DVLabs Blog.]]></description>
			<content:encoded><![CDATA[<p>This years <a href="http://cansecwest.com/post/2009-03-18-01:00:00.PWN2OWN_Final_Rules" target="_blank">Pwn2Own</a> uncover 4 new never seen before critical vulnerabilities affecting the IE8, Safari and FireFox.<br />
More about this contest you can read at <a href="http://dvlabs.tippingpoint.com/blog" target="_blank">DVLabs Blog</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/03/22/pwn2own-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Analysis of Conficker</title>
		<link>http://blog.vijatov.com/2009/03/10/analysis-of-conficker/</link>
		<comments>http://blog.vijatov.com/2009/03/10/analysis-of-conficker/#comments</comments>
		<pubDate>Tue, 10 Mar 2009 12:02:45 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Conficker]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=60</guid>
		<description><![CDATA[Guys from the SRI International were made really good analysis on the currently most active Virus/Worm, Conficker, also known as Downup, Downadup and Kido. Analysis can be found at http://mtc.sri.com/Conficker/.]]></description>
			<content:encoded><![CDATA[<p>Guys from the <a href="http://www.sri.com/" target="_blank">SRI International</a> were made really good analysis on the currently most active Virus/Worm, <a href="http://en.wikipedia.org/wiki/Conficker" target="_blank">Conficker</a>, also known as Downup, Downadup and Kido.</p>
<p>Analysis can be found at <a href="http://mtc.sri.com/Conficker/" target="_blank">http://mtc.sri.com/Conficker/</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/03/10/analysis-of-conficker/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ESET Remote Administrator Script Insertion Vulnerability</title>
		<link>http://blog.vijatov.com/2009/02/05/eset-remote-administrator-script-insertion-vulnerability/</link>
		<comments>http://blog.vijatov.com/2009/02/05/eset-remote-administrator-script-insertion-vulnerability/#comments</comments>
		<pubDate>Thu, 05 Feb 2009 16:01:17 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[ESET]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=51</guid>
		<description><![CDATA[Me and Ivan Markovic found vulnerability in ESET&#8217;s NOD32 Remote Administrator Server. Vulnerability is reported in version 3.x  and potentially can be exploited to compromise a user&#8217;s system. For successful attack you need Administrator account at NOD32 RAS to create a malicious report. Administrators and Read-only users are both affected if open malicious report. Secunia [...]]]></description>
			<content:encoded><![CDATA[<p>Me and <a href="http://www.security-net.biz/" target="_blank">Ivan Markovic</a> found vulnerability in ESET&#8217;s NOD32 Remote Administrator Server. Vulnerability is reported in version 3.x  and potentially can be exploited to compromise a user&#8217;s system. For successful attack you need Administrator account at NOD32 RAS to create a malicious report. Administrators and Read-only users are both affected if open malicious report.</p>
<p><a href="http://secunia.com/advisories/33805/" target="_blank">Secunia</a> confirmed this vulnerability.</p>
<p>Here is <a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0548" target="_blank">CVE ID: 2009-0548</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/02/05/eset-remote-administrator-script-insertion-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PSCS VPOP3 Email Server Script Insertion Vulnerability</title>
		<link>http://blog.vijatov.com/2009/02/02/pscs-vpop3-email-server-script-insertion-vulnerability/</link>
		<comments>http://blog.vijatov.com/2009/02/02/pscs-vpop3-email-server-script-insertion-vulnerability/#comments</comments>
		<pubDate>Mon, 02 Feb 2009 17:00:17 +0000</pubDate>
		<dc:creator>Nenad Vijatov</dc:creator>
				<category><![CDATA[Research]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Windows Security]]></category>
		<category><![CDATA[XSS]]></category>

		<guid isPermaLink="false">http://blog.vijatov.com/?p=49</guid>
		<description><![CDATA[I found vulnerability in VPOP3 Email server which allows script insertion. Vulnerability is discovered in the version 2.6.0h. Although the vendor release the patch (implemented some filters), vulnerability still exists in the new version 2.6.0i. Patch don&#8217;t completely fix the vulnerability. Secunia confirmed vulnerability.]]></description>
			<content:encoded><![CDATA[<p>I found vulnerability in VPOP3 Email server which allows script insertion.<br />
Vulnerability is discovered in the version 2.6.0h. Although the vendor release the patch (implemented some filters), vulnerability still exists in the new version 2.6.0i. Patch don&#8217;t completely fix the vulnerability.</p>
<p><a href="http://secunia.com/advisories/33571/" target="_blank">Secunia</a> confirmed vulnerability.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vijatov.com/2009/02/02/pscs-vpop3-email-server-script-insertion-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
