<?xml version="1.0" encoding="utf-8"?>

<rdf:RDF
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:cc="http://web.resource.org/cc/"
  xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.cgisecurity.com/">
<title>CGISecurity - Website and Application Security News</title>
<link>http://www.cgisecurity.net/</link>
<image>http://images.cgisecurity.com/i/rss.gif</image>
<description>All things related to website, database, SDL, and application security since 2000.
</description>
<dc:language>en-US</dc:language>
<dc:creator></dc:creator>
<dc:date>2008-11-19T10:28:12-08:00</dc:date>
<admin:generatorAgent rdf:resource="http://www.typepad.com/" />


<items>
<rdf:Seq><rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/automated-secur.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/metasploit-fram.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/microsoft-to-of.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/understanding-h.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/integrity-178b.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/ms-explains-7-y.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/firefox-304-rel.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/net-framework-r.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/dns-inventor-bl.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/visa-card-featu.html" />
</rdf:Seq>
</items>

</channel>

<item rdf:about="http://www.cgisecurity.net/2008/11/automated-secur.html">
<title>Automated security testing &amp; its limitations</title>
<link>http://www.cgisecurity.net/2008/11/automated-secur.html</link>
<description>&quot;The team I work in uses both automated scanners, along with a few humans testing (minimum of 2)… A good tester should know the weaknesses of the automated testers.. The problem with automated testers, is, simply put, they are not human. That is they will not have intuition that a given...</description>

<dc:subject>Reviews</dc:subject>
<dc:subject>Security Tools</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-19T10:28:12-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/metasploit-fram.html">
<title>Metasploit Framework 3.2 Released</title>
<link>http://www.cgisecurity.net/2008/11/metasploit-fram.html</link>
<description>&quot;Contact: H D Moore FOR IMMEDIATE RELEASE Email: hdm[at]metasploit.com Austin, Texas, November 19th, 2008 -- The Metasploit Projectannounced today the free, world-wide availability of version 3.2 oftheir exploit development and attack framework. The latest versionis provided under a true open source software license (BSD) and is backed by a community-based development...</description>

<dc:subject>Security Tools</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-19T09:33:14-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/microsoft-to-of.html">
<title>Microsoft to offer free Antivirus</title>
<link>http://www.cgisecurity.net/2008/11/microsoft-to-of.html</link>
<description>&quot;Microsoft on Tuesday said it plans to kill off its Windows Live OneCare subscription security service in favor of a free offering that will feature a core of essential anti-malware tools while excluding peripheral services, such as PC tune up programs, found in OneCare. The move could help the software maker...</description>

<dc:subject>IndustryNews</dc:subject>
<dc:subject>Vendors</dc:subject>
<dc:subject>Worms</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-19T09:11:06-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/understanding-h.html">
<title>Understanding How to Use the Microsoft&#39;s Exploitability Index</title>
<link>http://www.cgisecurity.net/2008/11/understanding-h.html</link>
<description>&quot;On Oct. 14, 2008, Microsoft added another piece of information to the bulletin summary to better help customers with their risk assessment process: the Exploitability Index. This section is a brief overview to explain how customers can integrate the Exploitability Index with the Severity Rating system into their own risk assessment...</description>

<dc:subject>Defense</dc:subject>
<dc:subject>SDL</dc:subject>
<dc:subject>Vendors</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-18T09:58:47-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/integrity-178b.html">
<title>Integrity-178B Secure OS Gets Highest NSA Rating, Goes Commercial </title>
<link>http://www.cgisecurity.net/2008/11/integrity-178b.html</link>
<description>&quot;An operating system used in military fighter planes has raised the bar for system security as a new commercial offering, after receiving the highest security rating by a National Security Agency (NSA)-run certification program. Green Hills Software announced that its Integrity-178B operating system was certified as EAL6+ and that the company...</description>

<dc:subject>Defense</dc:subject>
<dc:subject>IndustryNews</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-18T09:22:35-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/ms-explains-7-y.html">
<title>MS explains 7-year patch delay</title>
<link>http://www.cgisecurity.net/2008/11/ms-explains-7-y.html</link>
<description>&quot;Microsoft has explained why it took seven years to patch a known vulnerability. Fixing the bug earlier would have taken out network applications and potential exploits alike, it explained. Security bulletin MS08-068 fixed a flaw in the SMB (Server Message Block) component of Windows, first demonstrated by Sir Dystic of Cult...</description>

<dc:subject>IndustryNews</dc:subject>
<dc:subject>Vendors</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-17T10:03:57-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/firefox-304-rel.html">
<title>Firefox 3.0.4 Released to address multiple security flaws</title>
<link>http://www.cgisecurity.net/2008/11/firefox-304-rel.html</link>
<description>A handful of security vulnerabilities have been fixed in the latest version of firefox. Fixed in Firefox 3.0.4 MFSA 2008-58 Parsing error in E4X default namespaceMFSA 2008-57 -moz-binding property bypasses security checks on codebase principalsMFSA 2008-56 nsXMLHttpRequest::NotifyEventListeners() same-origin violationMFSA 2008-55 Crash and remote code execution in nsFrameManagerMFSA 2008-54 Buffer overflow in...</description>

<dc:subject>Browsers</dc:subject>
<dc:subject>IndustryNews</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-13T10:11:34-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/net-framework-r.html">
<title>.NET Framework rootkits - backdoors inside your framework </title>
<link>http://www.cgisecurity.net/2008/11/net-framework-r.html</link>
<description>&quot;The paper introduces a new method that enables an attacker to change the.NET language, and to hide malicious code inside its core. It covers various ways to develop rootkits for the .NET framework, sothat every EXE/DLL that runs on a modified Framework will behavedifferently than what it&#39;s supposed to do. Code...</description>

<dc:subject>Research</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-13T09:24:51-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/dns-inventor-bl.html">
<title>DNS inventor blames wrangling for insecure interweb</title>
<link>http://www.cgisecurity.net/2008/11/dns-inventor-bl.html</link>
<description>&quot;DNSSec (Domain Name System Security Extension), which uses digital signatures to guard against forged requests, offers a means of making internet naming systems more secure. But even 15 years after the standard was developed its adoption remains low. Mockapetris blames problems in making the technology easy to deploy, delays in developing...</description>

<dc:subject>IndustryNews</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-12T12:33:50-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/visa-card-featu.html">
<title>Visa Card Features Buttons and Screen to Generate CCV Dynamically</title>
<link>http://www.cgisecurity.net/2008/11/visa-card-featu.html</link>
<description>A co worker sent me this link yesterday afternoon. &quot;Using what appears to be Visa&#39;s mutant hybrid of a credit card and a pocket calculator, users can enter their PIN into the card itself and have a security code generated on the fly. The method can stop thieves in two ways....</description>

<dc:subject>IndustryNews</dc:subject>
<dc:subject>Research</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-12T09:51:07-08:00</dc:date>
</item>


</rdf:RDF>
<!-- ph=1 -->
<!-- nhm:from_kauri -->
