<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress.com" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

<channel>
	<title>exploits &amp;laquo; WordPress.com Tag Feed</title>
	<link>http://en.wordpress.com/tag/exploits/</link>
	<description>Feed of posts on WordPress.com tagged "exploits"</description>
	<pubDate>Wed, 19 Jun 2013 00:14:43 +0000</pubDate>

	<generator>http://en.wordpress.com/tags/</generator>
	<language>en</language>

<item>
<title><![CDATA[She Poses]]></title>
<link>http://thetexpatstarling.wordpress.com/2013/04/11/she-poses/</link>
<pubDate>Thu, 11 Apr 2013 16:04:39 +0000</pubDate>
<dc:creator>texpatstarling</dc:creator>
<guid>http://thetexpatstarling.wordpress.com/2013/04/11/she-poses/</guid>
<description><![CDATA[Who&#8217;s a pretty baby? You are! Yes, you are. Meet Dylan &#8211; three months new. She was compl]]></description>
<content:encoded><![CDATA[Who&#8217;s a pretty baby? You are! Yes, you are. Meet Dylan &#8211; three months new. She was compl]]></content:encoded>
</item>
<item>
<title><![CDATA[The Shodan Search Engine IS a Bit Scary]]></title>
<link>http://advocatesstudio.com/2013/04/09/the-shodan-search-engine-is-a-bit-scary/</link>
<pubDate>Tue, 09 Apr 2013 18:54:37 +0000</pubDate>
<dc:creator>Martha Sperry</dc:creator>
<guid>http://advocatesstudio.com/2013/04/09/the-shodan-search-engine-is-a-bit-scary/</guid>
<description><![CDATA[But it may be indicative of the lurking loss of privacy and security we seem to freely exchange for]]></description>
<content:encoded><![CDATA[<p><a href="http://advocatesstudio.files.wordpress.com/2013/04/shodan_logo.png"><img class="alignnone size-full wp-image-5646" alt="Shodan_logo" src="http://advocatesstudio.files.wordpress.com/2013/04/shodan_logo.png?w=192&#038;h=57" width="192" height="57" /></a> <a href="http://advocatesstudio.files.wordpress.com/2013/04/shodan-computer-search-engine.png"><br />
</a></p>
<p>But it may be indicative of the lurking loss of privacy and security we seem to freely exchange for the convenience of connectivity.</p>
<p>There are search engines out there specializing in all sorts of online information. I have highlighted some here, for example search tools that delve into the deep web. <a href="http://shodanhq.com">Shodan</a> is different. Shodan searches for devices connected to the Web. Like servers. Printers. Routers. Webcams. Security cameras. Control systems for water parks. Really? Yup, really. And it can see what is secured out there and what is unsecured. From a <a href="http://money.cnn.com/2013/04/08/technology/security/shodan/index.html">CNN Money article</a> that ran the rounds yesterday:</p>
<blockquote><p>A quick search for &#8220;default password&#8221; reveals countless printers, servers and system control devices that use &#8220;admin&#8221; as their user name and &#8220;1234&#8243; as their password. Many more connected systems require no credentials at all &#8212; all you need is a Web browser to connect to them.</p></blockquote>
<p>Search parameters include location by city or county, latitude or longitude. Or search by hostname, operating system or IP address. It also allows you to export your search results by XML, so you can take it with you, with the IP and physical location associated with the result. And, if you don&#8217;t want to do the heavy lifting, let some other <del>hackers</del> users do the work for you with shared searches.</p>
<p><a href="http://advocatesstudio.files.wordpress.com/2013/04/shodan-computer-search-engine.png"><img class="aligncenter size-large wp-image-5647" alt="SHODAN   Computer Search Engine" src="http://advocatesstudio.files.wordpress.com/2013/04/shodan-computer-search-engine.png?w=593&#038;h=983" width="593" height="983" /></a></p>
<p>Even scarier, use Shodan Exploits to search for known vulnerabilities and exploits lurking out there.</p>
<p>I can hear you now &#8211; &#8220;Oh.Em.Gee. How long has this been out there?&#8221; Three years. When you search one of their shared searches for, say, video web servers, you will see results from 2010 forward. Shodan is celebrating its three year anniversary with a decent flurry of press activity. Great. Now more <del>hackers</del> users will know about this means of tapping stuff.</p>
<p>I totally understand that being fore-warned is to be fore-armed, and that the principle purpose of this is to enhance security rather than shake up that fragile concept, but my pessimistic self can&#8217;t help but consider all the nefarious uses such a tool could promote. It is all great if device owners take heed and actually start securing these devices. FWIW, SHODAN (Sentient Hyper-Optimized Data Access Network) apparently is a name used for a fictional AI antagonist in the cyberpunk action role-playing video games System Shock and System Shock 2. Take from that what you may/will.</p>
<p>Shodan invites you to register using your social logins, but I had no problem running some searches without registering. Check it out. And be chilled.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacks and Scripts for Path of Exile]]></title>
<link>http://poehack.wordpress.com/2013/04/09/hacks-and-scripts-for-path-of-exile/</link>
<pubDate>Tue, 09 Apr 2013 16:36:38 +0000</pubDate>
<dc:creator>guildwars2freebot</dc:creator>
<guid>http://poehack.wordpress.com/2013/04/09/hacks-and-scripts-for-path-of-exile/</guid>
<description><![CDATA[There are many ways to make your game play in Path of Exile a lot easier: Auto hotkey scripts, bots,]]></description>
<content:encoded><![CDATA[<p>There are many ways to make your game play in Path of Exile a lot easier: Auto hotkey scripts, bots, auto potion bots, auto looting, auto selling and lots of other functions that very simple and easy to use programs can do for you. On HackerBot.net you will find a section dedicated to PoE hacks, bots and the sharing of those and the knowledge that goes with owning and using these kinds of workarounds.</p>
<p>If you are interested in contributing or downloading these tools to help you to be one of the best players in all of Path of Exile, then join our community now and start sharing and leeching our software and be the best player you can be today.</p>
<p><a href="http://hackerbot.net/path-of-exile-poe">Path of Exile &#8211; PoE Hacks on HackerBot</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Guild Wars 2 bots &amp; hacks]]></title>
<link>http://guildwars2freebot.wordpress.com/2013/04/09/guild-wars-2-bots-hacks/</link>
<pubDate>Tue, 09 Apr 2013 16:30:36 +0000</pubDate>
<dc:creator>guildwars2freebot</dc:creator>
<guid>http://guildwars2freebot.wordpress.com/2013/04/09/guild-wars-2-bots-hacks/</guid>
<description><![CDATA[If you are in desperate need of a way to get more gold, experience and crafting materials in Guild W]]></description>
<content:encoded><![CDATA[<p>If you are in desperate need of a way to get more gold, experience and crafting materials in Guild Wars 2, then you should check our our Guild Wars 2 section on Hackerbot.net.</p>
<p>HackerBot is a community of cheaters, coders and hackers that are working together to share knowledge and exploits to use in our favorite MMOs and other online and offline games.</p>
<p><a href="http://hackerbot.net/guild-wars-2-gw2">Visit our Guild Wars 2 bots and hacks section</a> now.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[The Elder Scrolls Online]]></title>
<link>http://hackerbotnet.wordpress.com/2013/04/08/the-elder-scrolls-online/</link>
<pubDate>Mon, 08 Apr 2013 12:26:58 +0000</pubDate>
<dc:creator>hackerbotnet</dc:creator>
<guid>http://hackerbotnet.wordpress.com/2013/04/08/the-elder-scrolls-online/</guid>
<description><![CDATA[Looking for Cheats to use in TESO? HackerBot.net has a whole section dedicated to posting and downlo]]></description>
<content:encoded><![CDATA[<p>Looking for Cheats to use in TESO? HackerBot.net has a whole section dedicated to posting and downloading hacks and bots to use in The Elder Scrolls Online and also sharing information on how to use exploits and other means of getting around the rules. If you are a talented coder, are in possession of working scripts or simply want to download some working hacks, then sign up to our forum and be a part of our very active and attractive game hacking community.</p>
<p><a href="http://hackerbot.net/the-elder-scrolls-online-teso">The Elder Scrolls Online Hacks and Bots section on HackerBot.net</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[90 Seconds on The Verge: Daft Punk, Apple exploits, and T-Mobile]]></title>
<link>http://techtunesslap.wordpress.com/2013/03/31/90-seconds-on-the-verge-daft-punk-apple-exploits-and-t-mobile/</link>
<pubDate>Sun, 31 Mar 2013 11:09:28 +0000</pubDate>
<dc:creator>f410767</dc:creator>
<guid>http://techtunesslap.wordpress.com/2013/03/31/90-seconds-on-the-verge-daft-punk-apple-exploits-and-t-mobile/</guid>
<description><![CDATA[AppId is over the quota AppId is over the quota By Ross Miller on March 25, 2013 06:17 pm @ohnorosco]]></description>
<content:encoded><![CDATA[<p>AppId is over the quota<br />
AppId is over the quota<br />
 By Ross Miller on March 25, 2013 06:17 pm @ohnorosco </P><P>Don&#8217;t miss any stories Follow The Verge</EM></P>Follow <IMG alt="Ross 90 Seconds" src="http://techtunesslap.files.wordpress.com/2013/03/wpid-nsv000130000still002largevergemediumlandscape.jpg" width="640" height="360"> <P>Remote Area Medical. Royal Academy of Music. Restaurant Association of Maryland. Rolling Airframe Missile. Reverse Annuity Mortgage. Read and Modify. Royal Australian Mint. Royal Arch Mason. Responsibility Assignment Matrix. Radar Absorbent Material. Relative Atomic Mass. Rectangular Approximation Method. Risk Assessment Matrix. Rechargeable Alkaline Manganese. Right Attacking Midfielder. Rochester Academy of Medicine. Richmond Art Museum. Regional Accounting Manager. Ross A. Miller.</P><P><B>Stories of the day:</B></P><P><B>Thanks for watching — you&#8217;re basically our favorite person. Watch more 90 Seconds on The Verge at 90so.tv, on iTunes, and on YouTube!</B></P><P>Today&#8217;s 90 Seconds on The Verge was written by Ross Miller. All production magic is credited to John Lagomarsino.</P><ASIDE class="column grid_4 c-contain border-l2 rightcol">All</P></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[A peek inside the EgyPack Web malware exploitation kit]]></title>
<link>http://blog.webroot.com/2013/03/29/a-peek-inside-the-egypack-web-malware-exploitation-kit/</link>
<pubDate>Fri, 29 Mar 2013 07:00:26 +0000</pubDate>
<dc:creator>ddanchev</dc:creator>
<guid>http://blog.webroot.com/2013/03/29/a-peek-inside-the-egypack-web-malware-exploitation-kit/</guid>
<description><![CDATA[By Dancho Danchev On a daily basis we process multiple malicious campaigns that, in 95%+ of cases, r]]></description>
<content:encoded><![CDATA[By Dancho Danchev On a daily basis we process multiple malicious campaigns that, in 95%+ of cases, r]]></content:encoded>
</item>
<item>
<title><![CDATA[Today's Scrip-Bit   27 March 2013   Daniel 11:32]]></title>
<link>http://randyobrien50.wordpress.com/2013/03/27/todays-scrip-bit-27-march-2013-daniel-1132/</link>
<pubDate>Wed, 27 Mar 2013 10:19:30 +0000</pubDate>
<dc:creator>randyobrien50</dc:creator>
<guid>http://randyobrien50.wordpress.com/2013/03/27/todays-scrip-bit-27-march-2013-daniel-1132/</guid>
<description><![CDATA[Daniel 11:32.     And such as do wickedly against the covenant shall he corrupt by flatteries: but t]]></description>
<content:encoded><![CDATA[<p><strong><span style="font-family:Times New Roman;font-size:medium;"><span style="font-size:x-large;"><span style="text-decoration:underline;"><span style="font-family:Tahoma;">Daniel 11:32.</span></span><span style="font-family:Tahoma;"> </span></span><span style="font-size:small;">    </span><span style="font-family:Tahoma;font-size:medium;">And such as do wickedly against the covenant shall he corrupt by flatteries: but the people that do know their God shall be strong and do exploits. </span></span></strong></p>
<div>
<div dir="ltr">
<div dir="ltr"><strong><span style="font-family:Times New Roman;">Oh Friends, at last, at long last, we had a day yesterday akin to, that bore some resemblance to spring! Now it was still a tad nippy with a noticeable wind blowing, but you could feel the difference in the atmosphere. I can&#8217;t think of a suitable analogy at the moment, but it&#8217;s like one of those things you can&#8217;t exactly put your hands or mind on, however you just know, you can feel the difference in your spirit. The sunshine was decent, people were walking around in shirtsleeves, and there was even water running in the drains from the thawing of the snow. Wow! And all God&#8217;s people in the northern climes gave out a joyous shout of, &#8216;Glory Hallelujah! Spring is here at last! Thank You Lord!&#8217; Yeh mih people, rejuvenation of the earth up north is just around the corner; wet earth, green grass, blooming flowers, budding green leaves, singing birds, buzzing bees, lots of flora and fauna, all for real. And isn&#8217;t it wonderful that it&#8217;s all happening just when our souls and spirits are also being rejuvenated by a sacrificed Christ, who will winter in the grave for three days, from this Friday, Good Friday, then is going to rise majestically, like spring time, on this Sunday, Easter Sunday, to proclaim new life for the faithful for all eternity? It sure is! Oh Friends, I get so emotional when I think about it all, that I just have to keep reminding us of the wonderful and ever-LOVING God that we serve and worship. What other supposed deity has ever come close to the standards of our Holy Trinity eh? NONE my brethren, NONE! And NONE will ever come close, because our Godhead is the ONE AND ONLY TRUE GOD IN EXISTENCE! And all God&#8217;s children sang out loud and clear: &#8216;Praise the Lord, for He is indeed a wonderful God, worthy to be served and praised!&#8217; And in this Holy Week of 2013 Friends, we need to buckle down, to get real serious about the work Christ has called us to do. As our Bit so rightly declares: &#8216;And such as do wickedly against the covenant shall he corrupt (pollute) by flatteries: but the people that do know their God shall be strong and do exploits (take action).&#8217; That comes from Daniel&#8217;s prophecy, re the scholars: &#8216;an amazing summary of about two hundred years of the history of the wars between Egypt and Syria that took place during the fourth through the second centuries B.C, All of these prophecies, however, were written by Daniel in the sixth century B.C.&#8217; That&#8217;s at least a couple hundred years before the wars actually begun, solidifying the Good Book and its contents as a vehicle, a testimony of awesome truth! However Friends, we are also experiencing hard and troubled times, Life&#8217;s not getting any easier, in fact it&#8217;s getting more difficult day by day as we trundle along in our evil, ungodly ways. And it&#8217;s getting even shorter for those of us moving up the ladder of age. That means, if we want to leave a mark in this world, to make a difference as is required of us, then my brethren, we have to get serious and get our action going NOW! Tomorrow will be too late! The believers in Christ have to transform themselves into followers, meaning DO as Christ desires, not merely talk about it. Oh Friends, I don&#8217;t know how to truly galvanize us Christians to action nuh, but I know that we do need to become much more action oriented than we currently are. We need to begin seriously fighting back against the evil powers, both physical and spiritual, that are currently controlling our world. I know that saying it and doing it are two different things, and the doing is much harder. But then we need to remember that we&#8217;re indwelt by the Holy Spirit of the Most High God Jehovah, Creator of the universe and all therein, which means that we have the most powerful force in the universe right in our own backyard, so to speak. And don&#8217;t forget the scripture that so rightly and reassuringly tells us that &#8216;greater is he that is in you, than he that is in the world.&#8217; (1 John 4:4b) And that&#8217;s gospel truth Friends: Jesus is indeed greater than Beelzebub! So we have no real excuse for our tardiness or inaction in moving the LOVE Revolution along, because the scripture also tells us: &#8216;For God hath not given us the spirit of fear; but of power, and of LOVE, and of a sound mind.&#8217; (2 Tim.1:7) So what are we waiting for to rise up and take back what rightfully belongs to our God eh my people? It only needs our willingness now to do it. Obviously it won&#8217;t be easy, because Lucifer and his evil cronies won&#8217;t give up their ill-gotten gains without a serious fight. But as I&#8217;ve just pointed out, we have all the tools to take it away, we just need to unite, be of the same mind, have one true purpose. And unfortunately, until we seriously make a move towards Christian unity, Lucifer and his buddies will remain enthroned, continuing the successful strategy of dividing and conquering us. Oh my brethren, today I&#8217;m calling on all true believers in Christ to become followers, to unite as He desires us to do, then to get some serious action going, so we can ignite a flame over the whole world and thus ensure the success of the LOVE Revolution that our God requires us to instigate and WIN! And what better time to do it than this Easter Season, the most important time in the history of our Church, when Christ defeated death, Lucifer and the grave, and rose to glory, taking us with Him. Oh my people, Jesus requires us now to step up to the plate and fight a strong, steadfast and faithful fight, like He did in His time here on earth, and is now doing on our behalf in heaven. Please, let&#8217;s not disappoint Him and allow all His sacrifice to go to waste. I pray that today we&#8217;ll all hear this message, ponder it sincerely in our hearts, minds and souls, then rise up as one and retake our Father&#8217;s inheritance. In Jesus&#8217; Name, I pray. Much LOVE!&#8230;true unity, real LOVE and much action&#8230;are the necessary ingredients&#8230;for the success of Jesus&#8217; LOVE Revolution&#8230;</span></strong></div>
<div dir="ltr"><strong> </strong></div>
</div>
</div>
]]></content:encoded>
</item>
<item>
<title><![CDATA['Terminated Wire Transfer Notification/ACH File ID" themed malicious campaigns lead to Black Hole Exploit Kit]]></title>
<link>http://blog.webroot.com/2013/03/27/terminated-wire-transfer-notificationach-file-id-themed-malicious-campaigns-lead-to-black-hole-exploit-kit/</link>
<pubDate>Wed, 27 Mar 2013 07:00:44 +0000</pubDate>
<dc:creator>ddanchev</dc:creator>
<guid>http://blog.webroot.com/2013/03/27/terminated-wire-transfer-notificationach-file-id-themed-malicious-campaigns-lead-to-black-hole-exploit-kit/</guid>
<description><![CDATA[By Dancho Danchev A couple of days ago our sensors picked up two separate malicious email campaigns,]]></description>
<content:encoded><![CDATA[By Dancho Danchev A couple of days ago our sensors picked up two separate malicious email campaigns,]]></content:encoded>
</item>
<item>
<title><![CDATA[Malicious 'BBC Daily Email' Cyprus bailout themed emails lead to Black Hole Exploit Kit]]></title>
<link>http://blog.webroot.com/2013/03/25/malicious-bbc-daily-email-cyprus-bailout-themed-emails-lead-to-black-hole-exploit-kit/</link>
<pubDate>Mon, 25 Mar 2013 07:00:39 +0000</pubDate>
<dc:creator>ddanchev</dc:creator>
<guid>http://blog.webroot.com/2013/03/25/malicious-bbc-daily-email-cyprus-bailout-themed-emails-lead-to-black-hole-exploit-kit/</guid>
<description><![CDATA[By Dancho Danchev Cybercriminals are currently spamvertising tens of thousands of malicious emails i]]></description>
<content:encoded><![CDATA[By Dancho Danchev Cybercriminals are currently spamvertising tens of thousands of malicious emails i]]></content:encoded>
</item>
<item>
<title><![CDATA[#Bank Information #Security: The Evolving Threat From Insiders]]></title>
<link>http://adlerlaw.wordpress.com/2013/03/24/bank-information-security-the-evolving-threat-from-insiders/</link>
<pubDate>Sun, 24 Mar 2013 12:40:08 +0000</pubDate>
<dc:creator>David</dc:creator>
<guid>http://adlerlaw.wordpress.com/2013/03/24/bank-information-security-the-evolving-threat-from-insiders/</guid>
<description><![CDATA[VIDEO: The Evolving Insider Threat- Dawn Cappelli, Randy Trzeciak of CMU&#8217;s Insider Threat Cent]]></description>
<content:encoded><![CDATA[<p>VIDEO: <strong>The Evolving Insider Threat</strong>- Dawn Cappelli, Randy Trzeciak of CMU&#8217;s Insider Threat Center</p>
<p>This <a href="http://www.bankinfosecurity.com/evolving-insider-threat-a-5548">video from RSA Conference 2013</a> discusses:</p>
<ul>
<li>Who typically commits insider crimes &#8211; and how;</li>
<li>How employees are being victimized from outside;</li>
<li>Why our critical infrastructure is at heightened risk.</li>
</ul>
<p>Even if you are an employer using standard commercial verification measures, you should be cautious about misuse of any information by employees, managers and contractors. Accordingly, you should be careful with training and education and not on only newly-hired employees. Further, plan on how login credential and access to sensitive information will be handled and/or turned over when training or when terminating, suspending, withholding pay, lowering pay, or taking any other adverse action against an employee.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Latest Java update patches 50 holes, including critical zero-day flaw]]></title>
<link>http://newiphonegeeks.wordpress.com/2013/03/21/latest-java-update-patches-50-holes-including-critical-zero-day-flaw/</link>
<pubDate>Thu, 21 Mar 2013 15:00:16 +0000</pubDate>
<dc:creator>newiphonegeeks</dc:creator>
<guid>http://newiphonegeeks.wordpress.com/2013/03/21/latest-java-update-patches-50-holes-including-critical-zero-day-flaw/</guid>
<description><![CDATA[Oracle was convinced to issue an update for its Java plugin two weeks early this month in order to s]]></description>
<content:encoded><![CDATA[<p style="font-size:14px;">
<p><img src="http://newiphonegeeks.files.wordpress.com/2013/03/java_logo11.jpg?w=457" alt="Java - logo" width="457" /></p>
</p>
<p style="font-size:14px;">Oracle was convinced to issue an update for its Java plugin two weeks early this month in order to squash a few critical bugs that resulted in a torrent of bad press. Everyone from security bloggers to the federal government had warned the general public against using Java after it was discovered that the exploit was being targeted in the wild. Apple blocked Java via OS X&#8217;s Xprotect, and Mozilla and Google both flipped the switch on their browsers to blacklist the plug-in.</p>
<p style="font-size:14px;">According to security researcher Brian Krebs, the most critical fix in the most recent Java update addresses an issue in Oracle&#8217;s new trust mechanism. The initial change made it so that Java requested authorization from end users whenever unsigned, untrusted code was encountered. While it was an excellent step in the right direction in terms of improving the overall security of Java, it was also very easy to circumvent.</p>
<p style="font-size:14px;">In total, the Java update takes care of 50 security flaws. Unsurprisingly, Oracle is recommending that all users update as soon as possible due to the severe risk posed by surfing with a vulnerable version.</p>
<p style="font-size:14px;">If you&#8217;ve still got Java installed on your system, keep your eyes peeled for an update notification. If you&#8217;d rather not wait for Oracle&#8217;s updater to answer the call, just head over to the Java download page and grab the latest version. Mac users will be relieved to know that the new release matches Xprotect&#8217;s minimum version expectation &#8212; and that means no more terminal hacking is required just so you can play Minecraft.</p>
<p style="font-size:14px;">One more thing: just make sure the update you&#8217;re installing is a legitimate one, not some craftily-designed malware.</p>
<p style="font-size:14px;">More reading: How to disable Java on everything</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake 'CNN Breaking News Alerts' themed emails lead to Black Hole Exploit Kit]]></title>
<link>http://blog.webroot.com/2013/03/21/fake-cnn-breaking-news-alerts-themed-emails-lead-to-black-hole-exploit-kit/</link>
<pubDate>Thu, 21 Mar 2013 07:00:05 +0000</pubDate>
<dc:creator>ddanchev</dc:creator>
<guid>http://blog.webroot.com/2013/03/21/fake-cnn-breaking-news-alerts-themed-emails-lead-to-black-hole-exploit-kit/</guid>
<description><![CDATA[By Dancho Danchev Cybercriminals are currently mass mailing tens of thousands malicious &#8216;CNN B]]></description>
<content:encoded><![CDATA[By Dancho Danchev Cybercriminals are currently mass mailing tens of thousands malicious &#8216;CNN B]]></content:encoded>
</item>
<item>
<title><![CDATA[Queen Anne Nightstand]]></title>
<link>http://thetexpatstarling.wordpress.com/2013/03/21/queen-anne-nightstand/</link>
<pubDate>Thu, 21 Mar 2013 04:37:20 +0000</pubDate>
<dc:creator>texpatstarling</dc:creator>
<guid>http://thetexpatstarling.wordpress.com/2013/03/21/queen-anne-nightstand/</guid>
<description><![CDATA[I&#8217;ve lost Photoshop. I had no idea how crippling it would be for me. I haven&#8217;t posted be]]></description>
<content:encoded><![CDATA[I&#8217;ve lost Photoshop. I had no idea how crippling it would be for me. I haven&#8217;t posted be]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacking for Beginners- Top Website Hacks]]></title>
<link>http://decisionstats.com/2013/03/20/hacking-for-beginners-top-website-hacks/</link>
<pubDate>Wed, 20 Mar 2013 07:12:52 +0000</pubDate>
<dc:creator>Ajay Ohri</dc:creator>
<guid>http://decisionstats.com/2013/03/20/hacking-for-beginners-top-website-hacks/</guid>
<description><![CDATA[I really liked this 2002 presentation on Website Hacks at blackhat.com/presentations/bh-asia-02/bh-a]]></description>
<content:encoded><![CDATA[<p>I really liked this 2002 presentation on Website Hacks at <cite>blackhat.com/presentations/bh-asia-02/bh-asia-02-shah.pdf</cite> . It explains in a easy manner some common fundamentals in hacking websites. Take time to go through this- its a good example of how hacking tutorials need to be created if you want to expand the number of motivated hackers.</p>
<iframe src='http://www.slideshare.net/slideshow/embed_code/17398674' width='476' height='390' scrolling='no'></iframe>
<p>However a more recent list of hacks is here-</p>
<p><a href="https://blog.whitehatsec.com/top-ten-web-hacking-techniques-of-2012/" rel="nofollow">https://blog.whitehatsec.com/top-ten-web-hacking-techniques-of-2012/</a></p>
<h2><strong>The Top Ten</strong></h2>
<ol>
<li><strong><a href="https://docs.google.com/presentation/d/11eBmGiHbYcHR9gL5nDyZChu_-lCa2GizeuOfaLU2HOU/edit?pli=1#slide=id.g1d134dff_1_222">CRIME</a> (<a href="http://en.wikipedia.org/wiki/CRIME_%28security_exploit%29">1</a>, <a href="http://arstechnica.com/security/2012/09/crime-hijacks-https-sessions/">2</a>, <a href="http://www.imperialviolet.org/2012/09/21/crime.html">3</a> <a href="http://threatpost.com/en_us/blogs/new-attack-uses-ssltls-information-leak-hijack-https-sessions-090512">4</a>) by <em><a href="https://twitter.com/julianor">Juliano Rizzo</a> and <a href="https://twitter.com/thaidn">Thai Duong</a></em></strong></li>
<li><a href="http://media.blackhat.com/bh-us-12/Briefings/Polyakov/BH_US_12_Polyakov_SSRF_Business_WP.pdf">Pwning via SSRF (memcached, php-fastcgi, etc)</a> (<a href="http://www.slideshare.net/d0znpp/ssrf-attacks-and-sockets-smorgasbord-of-vulnerabilities">2</a>, <a href="http://erpscan.com/press-center/blog/ssrf-via-ws-adressing/">3</a>, <a href="https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2002-1484">4</a>, <a href="http://t.co/ExfnaQf9n0">5</a>)</li>
<li><a href="http://blog.kotowicz.net/2012/02/intro-to-chrome-addons-hacking.html">Chrome addon hacking</a> (<a href="http://blog.kotowicz.net/2012/02/chrome-addons-hacking-want-xss-on.html">2</a>, <a href="http://blog.kotowicz.net/2012/03/chrome-addons-hacking-bye-bye-adblock.html">3</a>, <a href="http://blog.kotowicz.net/2012/07/xss-chef-chrome-extension-exploitation.html">4</a>, <a href="http://blog.kotowicz.net/2012/09/owning-system-through-chrome-extension.html">5</a>)</li>
<li><a href="http://blog.ptsecurity.com/2012/08/not-so-random-numbers-take-two.html">Bruteforce of PHPSESSID</a></li>
<li><a href="https://superevr.com/blog/2012/blended-threats-and-javascript/">Blended Threats and JavaScript</a></li>
<li><a href="http://www.riyazwalikar.com/2012/11/cross-site-port-attacks-xspa-part-1.html">Cross-Site Port Attacks</a></li>
<li><a href="http://securitymusings.com/article/3159/how-a-platform-using-html5-can-affect-the-security-of-your-website">Permanent backdooring of HTML5 client-side application</a></li>
<li><a href="http://gursevkalra.blogspot.com/2012/03/captcha-re-riding-attack.html">CAPTCHA Re-Riding Attack</a></li>
<li><a href="http://seckb.yehg.net/2012/06/xss-gaining-access-to-httponly-cookie.html">XSS: Gaining access to HttpOnly Cookie in 2012</a></li>
<li><a href="http://www.mcafee.com/us/resources/white-papers/foundstone/wp-pentesters-guide-to-hacking-odata.pdf">Attacking OData: HTTP Verb Tunneling, Navigation Properties for Additional Data Access, System Query Options ($select)</a></li>
</ol>
<h3>Honorable Mention</h3>
<p>11. <a href="https://github.com/FireFart/WordpressPingbackPortScanner">Using WordPress as a intranet and internet port scanner</a></p>
<p>12. <a href="http://www.quotium.com/research/advisories/XSS-NetRequestValidation.php">.Net Cross Site Scripting – Request Validation Bypassing (</a><a href="http://www.floyd.ch/?p=462">1</a>)</p>
<p>13. <a href="http://suriya.me/me-and-facebook-a-cautionary-tale/">Bruteforcing/Abusing search functions with no-rate checks to collect data</a></p>
<p>14. <a href="http://labs.neohapsis.com/2012/11/14/browser-event-hijacking/">Browser Event Hijacking</a> (<a href="http://arstechnica.com/security/2012/12/how-script-kiddies-can-hijack-your-browser-to-steal-your-password/">2</a>, <a href="http://h43z.blogspot.com/2012/11/whats-real-and-whats-not.html">3</a>)</p>
<p>But a more widely used ranking method for Website Hacking is here. Note it is a more formal but probably a more recent document than the pdf above. If only it could be made into an easier to read tutorial, it would greatly improve website exploit security strength.</p>
<p><a href="https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project" target="_blank">https://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project</a></p>
<p>The Release Candidate for the OWASP Top 10 for 2013 is now available here: <a href="http://owasptop10.googlecode.com/files/OWASP%20Top%2010%20-%202013%20-%20RC1.pdf" rel="nofollow">OWASP Top 10 &#8211; 2013 &#8211; Release Candidate</a></p>
<p>The OWASP Top 10 &#8211; 2013 Release Candidate includes the following changes as compared to the 2010 edition:</p>
<ul>
<li>A1 Injection</li>
<li>A2 Broken Authentication and Session Management (was formerly A3)</li>
<li>A3 Cross-Site Scripting (XSS) (was formerly A2)</li>
<li>A4 Insecure Direct Object References</li>
<li>A5 Security Misconfiguration (was formerly A6)</li>
<li>A6 Sensitive Data Exposure (merged from former A7 Insecure Cryptographic Storage and former A9 Insufficient Transport Layer Protection)</li>
<li>A7 Missing Function Level Access Control (renamed/broadened from former A8 Failure to Restrict URL Access)</li>
<li>A8 Cross-Site Request Forgery (CSRF) (was formerly A5)</li>
<li>A9 Using Known Vulnerable Components (new but was part of former A6 – Security Misconfiguration)</li>
<li>A10 Unvalidated Redirects and Forwards</li>
</ul>
<iframe src='http://www.slideshare.net/slideshow/embed_code/17398868' width='476' height='390' scrolling='no'></iframe>
<p>&#8212;<br />
Once again, I am presenting this as an example of how lucid documentation can help spread technological awareness to people affected by technical ignorance and lacking the savvy and chops for self-learning. If you need better cyber security, you need better documentation and tutorials on hacking for improving the quantity and quality of the pool of available hackers and bringing in young blood to enhance your cyber security edge.</p>
		<div id="geo-post-10984" class="geo geo-post" style="display: none">
			<span class="latitude">28.635308</span>
			<span class="longitude">77.224960</span>
		</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anonymity on the Internet]]></title>
<link>http://thaiguy5.wordpress.com/2013/03/18/anonymity-on-the-internet/</link>
<pubDate>Mon, 18 Mar 2013 12:59:42 +0000</pubDate>
<dc:creator>thaiguy5</dc:creator>
<guid>http://thaiguy5.wordpress.com/2013/03/18/anonymity-on-the-internet/</guid>
<description><![CDATA[In my opinion, to be anonymous on the Internet, being an &#8220;intermediate level techie&#8221;, is]]></description>
<content:encoded><![CDATA[<p>In my opinion, to be anonymous on the Internet, being an &#8220;intermediate level techie&#8221;, is using proxies and virtual private networks to hide their IP, which in turn protects their real identity and works better at preventing hackers and agents from spying on you or tracking you. This doesn&#8217;t prevent that 100%, but it works unless you use your real information on a social network such as Facebook and/or Twitter. </p>
<p>People want to be anonymous on the internet to prevent &#8220;Tracking Cookies&#8221; from identifying your real location, so they use proxies, which sends your internet browsing to a proxy server which relays that information to the world wide web, using the proxy servers IP instead of yours. Proxy servers are located all over the world, you can be in Canada and use a proxy server in France, so tracking cookies and website administrators will think you are from France, not Canada. This is a good way, although wrong, to avoid IP Bans on websites, allowing you to create more accounts and avoid the consequences of bans. If you use proxies halfway across the world, the connection is going to be significantly slower than without one, by up to 0.5 seconds, but if you really want to be anonymous, you should be patient. Professional or experienced hackers (both white and black hats (good and bad)) will ALWAYS be anonymous on the internet to avoid detection and avoid being traced, by using proxies, or even multiple proxies. Although the FBI and government agencies can eventually track down your real location if you&#8217;re doing something illegal, getting through proxies using packet sniffers (take encrypted data going through a connection and decrypting it) and the likes. So you&#8217;re rarely completely safe.</p>
<p>Virtual Private Networks, or VPNs, are similar to proxies in a way and are sometimes used alongside proxies to create an even more secure and anonymous network or browsing experience. It is usually slower when the two are combined because you are relaying information across two networks; a VPN and a proxy server. The farther they are located from each other, the slower the connection is going to be. Same with proxies, intermediate and experienced hackers will use both at the same time, but often use private rather than public proxies and virtual servers, setting up their own or using &#8220;underground&#8221; proxies which are well hidden from the public eye.</p>
<p>When it comes to being anonymous on the internet, proxies and VPNs help you in protecting your identity to some extent. Excuse me if I missed anything, I&#8217;m brushing over the basics of online anonymity.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA['ADP Package Delivery Notification' themed emails lead to Black Hole Exploit Kit]]></title>
<link>http://blog.webroot.com/2013/03/18/adp-package-delivery-notification-themed-emails-lead-to-black-hole-exploit-kit/</link>
<pubDate>Mon, 18 Mar 2013 07:00:13 +0000</pubDate>
<dc:creator>ddanchev</dc:creator>
<guid>http://blog.webroot.com/2013/03/18/adp-package-delivery-notification-themed-emails-lead-to-black-hole-exploit-kit/</guid>
<description><![CDATA[By Dancho Danchev A currently ongoing malicious email campaign is impersonating ADP in an attempt to]]></description>
<content:encoded><![CDATA[By Dancho Danchev A currently ongoing malicious email campaign is impersonating ADP in an attempt to]]></content:encoded>
</item>
<item>
<title><![CDATA[William Carey is Calling and Speaking]]></title>
<link>http://inspiration4generations.wordpress.com/2013/03/17/william-carey-is-calling-and-speaking/</link>
<pubDate>Sun, 17 Mar 2013 19:45:29 +0000</pubDate>
<dc:creator>princeprolific</dc:creator>
<guid>http://inspiration4generations.wordpress.com/2013/03/17/william-carey-is-calling-and-speaking/</guid>
<description><![CDATA[William Carey, a man, ordinary Used to do the extra-ordinary Made a living as shoe maker Brought lif]]></description>
<content:encoded><![CDATA[<p><a href="http://inspiration4generations.files.wordpress.com/2013/03/william-carrey.jpg"><img class="aligncenter size-medium wp-image-3654" alt="william carrey" src="http://inspiration4generations.files.wordpress.com/2013/03/william-carrey.jpg?w=300&#038;h=196" width="300" height="196" /></a></p>
<h1 style="text-align:center;"><span style="color:#000000;">William Carey, a man, ordinary</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Used to do the extra-ordinary</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Made a living as shoe maker</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Brought life to the dead as a preacher.</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;"> </span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Expect great things from a great God</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Expect good things from a good God</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Your faith will reap a great reward</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Your expectation will bring manifestation.</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;"> </span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Attempt great things for your God</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Be bold, just do it; stand on His word .</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Believe on the truth you have heard</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">And it shall surely come to pass.</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;"> </span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">William left his comfort zone</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Did not mind standing lone</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Believed His God- the Holy One.</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Had a passion for missions as a dream.</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;"> </span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Inspired many to fulfil vision</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Encouraged many to take on the baton</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Run their race; fulfil commission</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Stand until their work is done.</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;"> </span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">‘Attempt great things for God</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;">Expect Great things from God.’</span></h1>
<h1 style="text-align:center;"><span style="color:#000000;"> </span></h1>
<p><span style="color:#800080;">&#8230;but the people who know their God shall be strong, and carry out <i>great exploits.</i></span></p>
<p><span style="color:#800080;">Dan11:32</span></p>
<blockquote><p>&#160;</p>
<p><span style="color:#000000;"><b>William Carey</b> (17 August 1761 – 9 June 1834) was an <a title="English people" href="http://en.wikipedia.org/wiki/English_people"><span style="color:#000000;">English</span></a> <a title="Baptist" href="http://en.wikipedia.org/wiki/Baptist"><span style="color:#000000;">Baptist</span></a> <a title="Missionary" href="http://en.wikipedia.org/wiki/Missionary"><span style="color:#000000;">missionary</span></a> and a <a title="Particular Baptist" href="http://en.wikipedia.org/wiki/Particular_Baptist"><span style="color:#000000;">Particular Baptist</span></a> minister, known as the &#8220;<b>father of modern missions</b>.&#8221;<sup><a href="http://en.wikipedia.org/wiki/William_Carey_(missionary)#cite_note-1"><span style="color:#000000;">[1]</span></a></sup> Carey was one of the founders of the <a title="Baptist Missionary Society" href="http://en.wikipedia.org/wiki/Baptist_Missionary_Society"><span style="color:#000000;">Baptist Missionary Society</span></a>.</span></p>
<p><span style="color:#000000;">As a missionary in the <a title="Denmark" href="http://en.wikipedia.org/wiki/Denmark"><span style="color:#000000;">Danish</span></a> colony, <a title="Serampore" href="http://en.wikipedia.org/wiki/Serampore"><span style="color:#000000;">Serampore</span></a>, <a title="India" href="http://en.wikipedia.org/wiki/India"><span style="color:#000000;">India</span></a>, he translated the <a title="Bible" href="http://en.wikipedia.org/wiki/Bible"><span style="color:#000000;">Bible</span></a> into <a title="Bengali language" href="http://en.wikipedia.org/wiki/Bengali_language"><span style="color:#000000;">Bengali</span></a>, <a title="Sanskrit" href="http://en.wikipedia.org/wiki/Sanskrit"><span style="color:#000000;">Sanskrit</span></a>, and numerous other languages and dialects.</span></p>
<p><span style="color:#000000;">He possessed a natural gift for language, teaching himself <a title="Latin" href="http://en.wikipedia.org/wiki/Latin"><span style="color:#000000;">Latin</span></a></span></p>
<p><span style="color:#000000;">While apprenticed to Nichols, he also taught himself <a title="Greek language" href="http://en.wikipedia.org/wiki/Greek_language"><span style="color:#000000;">Greek</span></a> with the help of a local villager who had a college education</span></p>
<p><span style="color:#000000;">Dorothy Carey had seven children, five sons and two daughters; both girls died in infancy, as well as their son Peter, who died at the age of 5. Old himself died soon afterward, and Carey took over his business, during which time he taught himself <a title="Hebrew language" href="http://en.wikipedia.org/wiki/Hebrew_language"><span style="color:#000000;">Hebrew</span></a>, <a title="Italian language" href="http://en.wikipedia.org/wiki/Italian_language"><span style="color:#000000;">Italian</span></a>, <a title="Dutch language" href="http://en.wikipedia.org/wiki/Dutch_language"><span style="color:#000000;">Dutch</span></a>, and <a title="French language" href="http://en.wikipedia.org/wiki/French_language"><span style="color:#000000;">French</span></a>, often reading while working on his shoes.</span></p>
<p><span style="color:#000000;">Dorothy Carey died in 1807. Due to her debilitating mental breakdown, she had long since ceased to be an able member of the mission, and her condition was an additional burden to it. John Marshman wrote how Carey worked away on his studies and translations, &#8220;…while an insane wife, frequently wrought up to a state of most distressing excitement, was in the next room…&#8221;.</span></p>
<p><span style="color:#000000;">Later that same year Carey made the following entry in his diary: “Tuesday, Dec. 8, 1807. This evening Mrs. Carey died of the fever under which she has languished some time. Her death was a very easy one; but there was no appearance of returning reason, nor any thing that could cast a dawn of hope or light on her state.”<sup><a href="http://en.wikipedia.org/wiki/William_Carey_(missionary)#cite_note-5"><span style="color:#000000;">[5]</span></a></sup></span></p>
<p><span style="color:#000000;">Several friends and colleagues had urged William to commit Dorothy to an asylum. But he recoiled at the thought of the treatment she might receive in such a place and took the responsibility to keep her within the family home, even though the children were exposed to her rages</span></p></blockquote>
<p>&#160;</p>
<p>&#160;</p>
<p><a href="http://en.wikipedia.org/wiki/William_Carey_(missionary)">http://en.wikipedia.org/wiki/William_Carey_(missionary)</a></p>
<p>&#160;</p>
<p>©Fenny West2013</p>
<p><a href="http://wp.me/p1eApa-Nh">http://wp.me/p1eApa-Nh</a></p>
<p><a href="http://inspiration4generations.wordpress.com/2013/01/03/in-this-brand-new-year-2/">http://inspiration4generations.wordpress.com/2013/01/03/in-this-brand-new-year-2/</a></p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybercriminals resume spamvertising 'Re: Fwd: Wire Transfer' themed emails, serve client-side exploits and malware]]></title>
<link>http://blog.webroot.com/2013/03/15/cybercriminals-resume-spamvertising-re-fwd-wire-transfer-themed-emails-serve-client-side-exploits-and-malware/</link>
<pubDate>Fri, 15 Mar 2013 07:00:13 +0000</pubDate>
<dc:creator>ddanchev</dc:creator>
<guid>http://blog.webroot.com/2013/03/15/cybercriminals-resume-spamvertising-re-fwd-wire-transfer-themed-emails-serve-client-side-exploits-and-malware/</guid>
<description><![CDATA[By Dancho Danchev Over the last couple of days, a cybercricriminal/gang of cybercriminals that we]]></description>
<content:encoded><![CDATA[By Dancho Danchev Over the last couple of days, a cybercricriminal/gang of cybercriminals that we]]></content:encoded>
</item>
<item>
<title><![CDATA[Spamvertised BBB 'Your Accreditation Terminated" themed emails lead to Black Hole Exploit Kit]]></title>
<link>http://blog.webroot.com/2013/03/13/spamvertised-bbb-your-accreditation-terminated-themed-emails-lead-to-black-hole-exploit-kit/</link>
<pubDate>Wed, 13 Mar 2013 07:00:01 +0000</pubDate>
<dc:creator>ddanchev</dc:creator>
<guid>http://blog.webroot.com/2013/03/13/spamvertised-bbb-your-accreditation-terminated-themed-emails-lead-to-black-hole-exploit-kit/</guid>
<description><![CDATA[By Dancho Danchev Over the past week, a cybercriminal/gang of cybercriminals whose activities we]]></description>
<content:encoded><![CDATA[By Dancho Danchev Over the past week, a cybercriminal/gang of cybercriminals whose activities we]]></content:encoded>
</item>
<item>
<title><![CDATA[New Owners of rotmghack.com (HackerBot.net)]]></title>
<link>http://rotmgdupe.wordpress.com/2013/03/11/new-owners-of-rotmghack-com-hackerbot-net/</link>
<pubDate>Mon, 11 Mar 2013 19:56:22 +0000</pubDate>
<dc:creator>realmofthemadgodhack</dc:creator>
<guid>http://rotmgdupe.wordpress.com/2013/03/11/new-owners-of-rotmghack-com-hackerbot-net/</guid>
<description><![CDATA[So we have bought the old scammer site and turned it into a sub-part of our legit hacking forum wher]]></description>
<content:encoded><![CDATA[<p>So we have bought the old scammer site and turned it into a sub-part of our legit hacking forum where all you guys can help each other out in love and get an advantage playing your favorite mmos and pc, flasch games.</p>
<p>We will be hosting forums for all kind of games to hack.</p>
<p>So join up with us to share your hacks, cheats and bots with our members and download the latest hacks for your favorite games.</p>
<p>Also visit our new <a href="http://hackerbotnet.wordpress.com/">Game Hacking Blog</a> and subscribe to us on <a href="https://twitter.com/hackerbotnet">Twitter</a>.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Game Hacks, Bots and other Cheats]]></title>
<link>http://hackerbotnet.wordpress.com/2013/03/11/game-hacks-bots-and-other-cheats/</link>
<pubDate>Mon, 11 Mar 2013 17:39:05 +0000</pubDate>
<dc:creator>hackerbotnet</dc:creator>
<guid>http://hackerbotnet.wordpress.com/2013/03/11/game-hacks-bots-and-other-cheats/</guid>
<description><![CDATA[If you are looking for game hacking software like hacks, cheats and other trainers, or if you need h]]></description>
<content:encoded><![CDATA[<p>If you are looking for game hacking software like hacks, cheats and other trainers, or if you need hacking tutorials and help with cheating in your favorite pc games, mmos or browser games, then you should check out hackerbot.net.</p>
<p>We are a devoted community of game hackers, trying to help each other and our users to get better results playing their favorite games.</p>
<p>See you soon on <a href="http://hackerbot.net/">HackerBot.net</a></p>
<p>For news on other game hacks, <a href="http://howtohackit.wordpress.com/">go here</a>.</p>
]]></content:encoded>
</item>
<item>
<title><![CDATA[Commercial Steam 'information harvester/mass group inviter' could lead to targeted fraudulent campaigns]]></title>
<link>http://blog.webroot.com/2013/03/11/commercial-steam-information-harvestermass-group-inviter-could-lead-to-targeted-fraudulent-campaigns/</link>
<pubDate>Mon, 11 Mar 2013 07:00:34 +0000</pubDate>
<dc:creator>ddanchev</dc:creator>
<guid>http://blog.webroot.com/2013/03/11/commercial-steam-information-harvestermass-group-inviter-could-lead-to-targeted-fraudulent-campaigns/</guid>
<description><![CDATA[By Dancho Danchev Despite the fact that the one-to-many type of malicious campaign continues dominat]]></description>
<content:encoded><![CDATA[By Dancho Danchev Despite the fact that the one-to-many type of malicious campaign continues dominat]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenX Hacking ~ 173.241.250.2]]></title>
<link>http://onlinethreatalerts.wordpress.com/2013/03/09/openx-hacking-173-241-250-2/</link>
<pubDate>Sat, 09 Mar 2013 17:27:11 +0000</pubDate>
<dc:creator>SFA Reporter</dc:creator>
<guid>http://onlinethreatalerts.wordpress.com/2013/03/09/openx-hacking-173-241-250-2/</guid>
<description><![CDATA[According to KerbsOnSecurity, Hackers are actively exploiting a dangerous security vulnerability in]]></description>
<content:encoded><![CDATA[According to KerbsOnSecurity, Hackers are actively exploiting a dangerous security vulnerability in]]></content:encoded>
</item>
<item>
<title><![CDATA[Pwn2Own (2013) Contest a Blast - FULL Results]]></title>
<link>http://secureconnexion.wordpress.com/2013/03/09/pwn2own-2013-contest-a-blast-full-results/</link>
<pubDate>Sat, 09 Mar 2013 11:13:06 +0000</pubDate>
<dc:creator>Jay Pfoutz</dc:creator>
<guid>http://secureconnexion.wordpress.com/2013/03/09/pwn2own-2013-contest-a-blast-full-results/</guid>
<description><![CDATA[CanSecWest is a conference, and 2013&#8242;s conference once again involved the Pwn2Own contest for]]></description>
<content:encoded><![CDATA[<p>CanSecWest is a conference, and 2013&#8242;s conference once again involved the Pwn2Own contest for hackers, an elite (1337) competition. The concept remained simple and will always that if you pwn a fully-patched browser running on a fully-patched laptop, you get to keep the laptop.</p>
<p>However, different rules applied this year. It involved successfully demonstrating the exploit, providing the sponsor (HP) the fully functioning exploit, and all details involved with the vulnerability used in the attack. If there were many vulnerabilities, multiple reports are needed, etc.</p>
<p>The work couldn&#8217;t be sold to anyone else, and proof of concept would belong to HP once sold. Basically, HP buys the winning exploits for own use. Their idea of reward money was the following:</p>
<ul>
<li>Google Chrome on Windows 7 = $100,000</li>
<li>IE10 on Windows 8 = $100,000 or IE9 on Windows 7 = $75,000.</li>
<li>Mozilla Firefox on Windows 7 = $60,000</li>
<li>Apple Safari on Mac OS X Mountain Lion = $65,000</li>
<li>Adobe Reader XI and Flash Player = $70,000</li>
<li>Oracle Java = $20,000</li>
</ul>
<p>It was assuredly a blast at the competition, no doubt about it.</p>
<h3>DAY ONE: Java, Chrome, IE10, and Firefox PWNED!!!</h3>
<p>(Where&#8217;s Safari, right? It survived!)</p>
<p>The idea behind each attack is the ability to browse to an untrusted website where you&#8217;re able to inject and run arbitrary code outside of the browsing environment.</p>
<p>Of course, one of the rules is: &#8220;A successful attack &#8230; must require little or no user interaction and must demonstrate code execution&#8230; If a sandbox is present, a full sandbox escape is required to win.&#8221;</p>
<p><a href="http://secureconnexion.files.wordpress.com/2013/03/ie-ff-chr.jpg"><img class="size-full wp-image-1149 alignright" alt="ie-ff-chr" src="http://secureconnexion.files.wordpress.com/2013/03/ie-ff-chr.jpg?w=249&#038;h=80" width="249" height="80" /></a>In addition to Chrome, Firefox, and IE10 being pwned, Java was pwned three times on the first day. Once by James Forshaw, Joshua Drake, and VUPEN Security. VUPEN Security also led a lot of the pack of issues by successfully exploiting IE10 and Firefox as well.</p>
<p>The only other exploit was by Nils &#38; Jon, where both successfully exploited Chrome.</p>
<p>The day after the first day of Pwn2Own, Mozilla and Google patched the exploits that were pushed out. Amazingly fast, Firefox <a href="http://www.mozilla.org/security/announce/2013/mfsa2013-29.html" target="_blank">went on</a> to version 19.0.2 (which you should&#8217;ve been updated automatically), and Chrome <a href="http://googlechromereleases.blogspot.dk/2013/03/stable-channel-update_7.html" target="_blank">went on</a> to version 25.0.1364.160 (effectively patching 10 vulnerabilities).</p>
<p>“We received the technical details on Wednesday evening and within less than 24 hours diagnosed the issue, built a patch, validated the fix and the resulting builds, and deployed the patch to users,” said Michael Coates, Mozilla’s director of security assurance, in a <a href="https://blog.mozilla.org/security/2013/03/07/mozilla-and-pwn2own-event/">Thursday blog</a>.</p>
<p>Microsoft has decided to wait until next week&#8217;s <a href="http://www.helpmyos.com/t325-microsoft-patches-every-2nd-tuesday-of-the-month" target="_blank">Patch Tuesday</a> run of updates to push out the fix for the Internet Explorer exploit on IE10.</p>
<h3>DAY TWO: Adobe Reader and Flash Player PWNED!!! Java PWNED AGAIN!!!</h3>
<p>The last day of Pwn2Own 2013 went with a BANG!<a href="http://secureconnexion.files.wordpress.com/2013/03/fl-ar-ja.jpg"><img class="size-full wp-image-1148 alignleft" alt="fl-ar-ja" src="http://secureconnexion.files.wordpress.com/2013/03/fl-ar-ja.jpg?w=149&#038;h=66" width="149" height="66" /></a></p>
<p>Flash Player&#8230;exploited by VUPEN Security (any surprise?). Adobe Reader PWNED by George Hotz. Java once again was exploited, this time proxied by Ben Murphy.</p>
<p>Who&#8217;re the overall prize winners?</p>
<ul>
<li>James Forshaw, Ben Murphy, and Joshua Drake for Java &#8211; each $20,000</li>
<li>VUPEN Security for IE10 + Firefox + Java + Flash &#8211; $250,000</li>
<li>Nils &#38; Jon for Google Chrome &#8211; $100,000</li>
<li>George Hotz for Adobe Reader &#8211; $70,000</li>
</ul>
<p>Of course, George Hotz is best known for jailbreaking the iPhone and PlayStation 3. He&#8217;s still in progress with a lawsuit with Sony over the issue for PS3.</p>
<p>It&#8217;s amazing to see that Java was PWNED 4 times in just two days, but is it any surprise <a title="New Java Update Available by Oracle, Sped Up Patching Process" href="http://secureconnexion.wordpress.com/2013/02/21/new-java-update-available-by-oracle-sped-up-patching-process/" target="_blank">based</a> on the <a title="Critical Java patch issued for 30 security holes" href="http://secureconnexion.wordpress.com/2012/10/17/critical-java-patch-for-30-sec-holes/" target="_blank">number</a> of <a title="Oracle FINALLY Releases Critical Security Update for Java 7" href="http://secureconnexion.wordpress.com/2013/01/14/oracle-finally-releases-critical-security-update-for-java-7/" target="_blank">vulnerabilities</a> Oracle has <a title="Serious Java Vulnerabilities Have Many Things in Common (mini-whitepaper)" href="http://secureconnexion.wordpress.com/2012/12/04/serious-java-vulnerabilities-have-many-things-in-common-mini-whitepaper/" target="_blank">dealt</a> with for <a title="Java Flaws Becoming Serious Issue" href="http://secureconnexion.wordpress.com/2012/07/26/java-flaws-becoming-serious-issue/" target="_blank">Java</a>?</p>
<p>Now in its eighth year, Pwn2Own contest had $480,000 in payouts, a record year. Amazing!</p>
<p>Got any vibe on this issue? Post comment below! <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
</item>

</channel>
</rss>
