<?xml version="1.0" encoding="utf-8"?>
<rss version="0.92">
<channel>
<title>SecuObs.com</title>
<link>http://www.secuobs.com</link>
<description>Observatoire de la securite Internet</description>
<language>fr</language>
<webMaster>webmaster@secuobs.com</webMaster>
 <item><title>Metasploit-ation for the Nation</title><description>2011-05-18 22:43:29 - Rapid7 Network Security Blog : In a couple of weeks, our very own  Mubix  AKA Rob Fuller to those who don t live their life with an   sign permanently attached to their name  will be offering Metasploit-ation for the Nation Unlike that phrase   which I just made up   Mubix will actually be talking sense as he walks penetration    </description><link>http://www.secuobs.com/revue/news/305718.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/305718.shtml</guid></item>
<item><title>Rapid7  First ASV having its employees qualified as per the new PCI requirements</title><description>Secuobs.com : 2011-05-17 23:26:01 - Rapid7 Network Security Blog - Rapid7 is one of the 152 worldwide vendors approved by PCIco  the compliance body  to perform PCI scans of merchants and service providers external infrastructures To be considered ASV  Approved Scanning Vendor , a company must pass an annual test consisting in a scan of a specific vulnerable infrastructures  Lab  controlled by independent laboratories on behalf    </description><link>http://www.secuobs.com/revue/news/305467.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/305467.shtml</guid></item>
<item><title>May Patch Tuesday</title><description>Secuobs.com : 2011-05-11 21:31:24 - Rapid7 Network Security Blog - So yesterday was Patch Tuesday, and following a mammoth April, it was a pretty quiet one, with only 2 vulnerabilities reported, and only one of those given the most severe rating of  critical  That said, of course any vulnerability reported should be investigated and understood, and particularly those rated critical This month the critical vulnerability    </description><link>http://www.secuobs.com/revue/news/304166.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/304166.shtml</guid></item>
<item><title>PCI Newsletter  2   Payment processing terminology and workflow</title><description>Secuobs.com : 2011-05-11 15:31:37 - Rapid7 Network Security Blog - Hi Everyone, This is our second PCI 30 sec newsletter One cannot move through the PCI ecosystem without basic understandings of the payment processing terminology and workflow So let s have a look behind the scene The payment processing terminology In a nutshell, the payment transaction could be depicted as follow  We have cardholders that make    </description><link>http://www.secuobs.com/revue/news/304071.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/304071.shtml</guid></item>
<item><title>Rapid7 production presents The PCI 30 sec newsletters</title><description>Secuobs.com : 2011-05-11 14:41:40 - Rapid7 Network Security Blog -  Hello everyone from Belgium  the chip, beer and chocolate place but also the place without government since 1 year  I thought it could be useful if I distribute this newsletter on a regular basis I called it  The PCI 30 sec newsletter  because It should not take you more than 30 sec to digest Didier    </description><link>http://www.secuobs.com/revue/news/304062.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/304062.shtml</guid></item>
<item><title>PCI 30 Sec Newsletter  1   PCI, what are you talking about </title><description>Secuobs.com : 2011-05-11 14:41:40 - Rapid7 Network Security Blog - What is PCI  PCI stands for  Payment Card Industry denoting the debit, credit, pre-paid, e-purse, ATM and POS  Point of Sale  terminal and associated businesses But PCI is specifically referring to the Payment Card Industry Security Standards Council, a council formed by  MasterCard Visa American Express Discover JCB The PCI Council develops and maintains  so    </description><link>http://www.secuobs.com/revue/news/304061.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/304061.shtml</guid></item>
<item><title>And the Award goes to  US </title><description>Secuobs.com : 2011-05-09 19:45:21 - Rapid7 Network Security Blog - Recently we ve really been feeling the love from the good people Boston Business Journal  BBJ  and I wanted to take a moment to share this love and say a big thank you   It started a couple of weeks ago when the BBJ published this article on its Pacesetters for 2011, positioning Rapid7 as the    </description><link>http://www.secuobs.com/revue/news/303583.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/303583.shtml</guid></item>
<item><title>Metasploit Pro 37  Better, Faster, Stronger</title><description>Secuobs.com : 2011-05-04 21:20:52 - Rapid7 Network Security Blog - Over the last two months the Rapid7 team has been hard at work rewiring the database and session management components of the Metasploit Framework, Metasploit Express, and Metasploit Pro products These changes make the Metasploit platform faster, more reliable, and able to scale to hundreds of concurrent sessions and thousands of target hosts We are    </description><link>http://www.secuobs.com/revue/news/302635.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/302635.shtml</guid></item>
<item><title>Advice for Sony PSN users</title><description>Secuobs.com : 2011-04-29 02:12:10 - Rapid7 Network Security Blog - Unless you ve been living in cave during the past week, you will likely have heard that Sony s PlayStation Network  PSN  was breached last week The much-reported immediate impact for PSN users has been that the network has been unavailable for use since April 21st 2011 It seems likely though that there will be a greater    </description><link>http://www.secuobs.com/revue/news/301521.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/301521.shtml</guid></item>
<item><title>Metasploit T-shirt design contest  And the winner is </title><description>Secuobs.com : 2011-04-26 21:46:09 - Rapid7 Network Security Blog - You have voted in large numbers   and the results are out  design  36 is the winner of the Metasploit T-shirt design contest Danny Chrastil submitted the winning design, featuring the Metasploit logo consisting of code from the payload osx ppc shell_reverse_tcp The back shows the Metasploit splash screen cow, our legendary creature of mystery and superstition    </description><link>http://www.secuobs.com/revue/news/300907.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/300907.shtml</guid></item>
<item><title>April Patch Tuesday Round-Up</title><description>Secuobs.com : 2011-04-15 17:11:00 - Rapid7 Network Security Blog - This week s Patch Tuesday was pretty significant, with a record-tying 17 bulletins that patch a record 64 vulnerabilities, 15 more than the previous largest-ever set in October 2010 As usual, the Rapid7 team was all over it, monitoring the threat and trying to help out where possible This month s bulletin addresses vulnerabilities across Microsoft Windows, Microsoft Office,    </description><link>http://www.secuobs.com/revue/news/298711.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/298711.shtml</guid></item>
<item><title>Who will you be wearing  Vote for the new Metasploit T-shirt </title><description>Secuobs.com : 2011-04-13 23:09:59 - Rapid7 Network Security Blog - Wow   87 entries for our T-Shirt competition in one week We were very impressed with both quantity and quality of the entries we received for designing the new Metasploit T-shirt, which will be featured in the new Metasploit store Now, it s your turn  again  We need you to vote for your favorite shirt Starting    </description><link>http://www.secuobs.com/revue/news/298269.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/298269.shtml</guid></item>
<item><title>Be a superhero  Design the new Metasploit swag</title><description>Secuobs.com : 2011-04-05 20:17:34 - Rapid7 Network Security Blog - Don t know what to wear for the next BlackHat conference  Afraid of going naked to B-Sides  We are too, so we decided to do something about it We re getting ready to launch our own Metasploit designer clothes   and you re the designer  To start off our Metasploit swag store, we d like you to design a    </description><link>http://www.secuobs.com/revue/news/296407.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/296407.shtml</guid></item>
<item><title>Learn, download   contribute  the new Metasploit website</title><description>Secuobs.com : 2011-04-01 06:45:06 - Rapid7 Network Security Blog - Today, we relaunched the Metasploitcom site We hope you ll find it as awesome as we do The new site not only has updated looks, we ve also rewritten much of its content and put it on a shiny new server to make it faster We mainly focused on three aspects  learn, download   contribute  Learn      </description><link>http://www.secuobs.com/revue/news/295581.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/295581.shtml</guid></item>
<item><title>Join me for the PCI SC Magazine eConference this Tuesday March 22, 2011</title><description>Secuobs.com : 2011-03-21 19:31:53 - Rapid7 Network Security Blog - Hi, Don t miss the PCI SC Magazine eConference tomorrow March 22, 2011 I will talk about the PCI Compliance versus Security perspective and share my view on the following   Is PCI a Compliance or Security Program  When  22 March 2011 1pm EDT Where  https eventsunisfaircom indexjsp code SCW seid 3262 eid 474 Fee  Free Abstract  This 3-letter acronym has significantly impacted the security    </description><link>http://www.secuobs.com/revue/news/293102.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/293102.shtml</guid></item>
<item><title>Empowering Security Professionals</title><description>Secuobs.com : 2011-03-16 15:09:42 - Rapid7 Network Security Blog - Over the last few years I ve been focused on empowering security professionals through my work with DojoSec and DojoCon I ve had the pleasure of serving tons of people with the success of many of my community efforts To be honest, I m surprise how many people have been informed and inspired by the projects I ve been    </description><link>http://www.secuobs.com/revue/news/292011.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/292011.shtml</guid></item>
<item><title>March Patch Tuesday Roundup</title><description>Secuobs.com : 2011-03-15 04:07:11 - Rapid7 Network Security Blog - Since Microsoft is on this new staggered pattern of releases, we can expect a feast or famine every other month so get used to it Depending on what side of the desk you sit on you can adjust the context With that being said, this month s release brought us 3 patches addressing 4 vulnerabilities I think    </description><link>http://www.secuobs.com/revue/news/291605.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/291605.shtml</guid></item>
<item><title>Metasploit version 36 delivers enhanced command-line options and PCI reports</title><description>Secuobs.com : 2011-03-07 15:24:05 - Rapid7 Network Security Blog - All Metasploit editions are seeing an update to version 36 today, including an enhanced command-line feature set for increased proficiency and detailed PCI reports with pass fail information for a comprehensive view of compliance posture with PCI regulations Here s an overview of what s new  Metasploit Pro Console   Only available in Metasploit Pro, this console is    </description><link>http://www.secuobs.com/revue/news/289861.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/289861.shtml</guid></item>
<item><title>Dual Core s Metasploit Track  Free Download </title><description>Secuobs.com : 2011-02-24 18:36:39 - Rapid7 Network Security Blog - We got a ton of requests to let you know when the new Dual Core Metasploit track  msf mastering success   failure  would be available for download Dual Core had given the track a debut at the Rapid7 Skye High party at Ruby Skye in San Francisco as part of the RSA Conference  view the    </description><link>http://www.secuobs.com/revue/news/287473.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/287473.shtml</guid></item>
<item><title>Don t get blinded by the Flash </title><description>Secuobs.com : 2011-02-22 16:00:39 - Rapid7 Network Security Blog - Flash has become a de-facto standard for Web applications, yet most vulnerability management solutions don t do a very good job verifying Flash content This is surprising, especially since 98pourcents of workstations have the Adobe Flash player installed, according to an Adobe study The Flash player itself can contain unpatched vulnerabilities, which most scanners already detect    </description><link>http://www.secuobs.com/revue/news/286852.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/286852.shtml</guid></item>
<item><title>Rapid7 sponsors 7 Boston high schools for the 2011 Cyber Foundations Competition</title><description>Secuobs.com : 2011-02-19 01:28:16 - Rapid7 Network Security Blog - Rapid7 is looking to sponsor students at seven high schools in the Boston Metro area to participate in the 2011 Cyber Foundations Competition This is your chance to make sure your local high school s students can participate in this great learning experience   for free  The sponsorship is our way of giving back to the    </description><link>http://www.secuobs.com/revue/news/286349.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/286349.shtml</guid></item>
<item><title>Rapid7 s high flying RSA party</title><description>Secuobs.com : 2011-02-18 23:33:16 - Rapid7 Network Security Blog - Thanks to all of you who attended our party at Ruby Skye on Wednesday We were overwhelmed by how many RSA delegates showed up  The club holds close to a thousand people, and we were operating at capacity for most of the night Apologies if you had to wait in line for a few minutes     </description><link>http://www.secuobs.com/revue/news/286321.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/286321.shtml</guid></item>
<item><title>Dual Core puts the Rap back into Rapid7</title><description>Secuobs.com : 2011-02-18 05:41:18 - Rapid7 Network Security Blog - As we re all recovering from the epic RSA Rapid7 party at Ruby Skye last night, I wanted to thank Dual Core for the debut performance of  mastering success and failure   msf  featuring the Metasploit Framework Awesome track   the room went nuts  Here s a video of the full performance The msf track starts at    </description><link>http://www.secuobs.com/revue/news/286136.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/286136.shtml</guid></item>
<item><title>February Patch Tuesday Roundup</title><description>Secuobs.com : 2011-02-11 22:03:22 - Rapid7 Network Security Blog - I think we all knew this was coming January s release was just too light This month Microsoft released 12 updates which address 22 vulnerabilities There were 3 critical updates this release and 9 important fixes The honorable mention would have to go to the CSS recursive import fix MS11-003 - CVE-2010-3971- This issue effects the way    </description><link>http://www.secuobs.com/revue/news/284713.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/284713.shtml</guid></item>
<item><title>Oh IANA, don t you pwn for me</title><description>Secuobs.com : 2011-01-26 19:51:19 - Rapid7 Network Security Blog - So there I was An uneventful Sunday morning watching the Colbert Report on my DVR when a commercial for Overstockcom flashed on my screen Overstock was touting their newest site address  oco Easy for customers to get to  Frustrating for whoever owned ocom I thought this was a great idea on their part a site address    </description><link>http://www.secuobs.com/revue/news/280954.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/280954.shtml</guid></item>
<item><title>Last year s journey and the road ahead</title><description>Secuobs.com : 2011-01-19 16:07:32 - Rapid7 Network Security Blog - During the holiday season of the past weeks, I reflected a lot on the past with my loved ones At the same time, I couldn t help thinking about the Rapid7 journey so far and the exciting path before us I thought I d share some of this with you 2010 was an explosive year for Rapid7    </description><link>http://www.secuobs.com/revue/news/279233.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/279233.shtml</guid></item>
<item><title>w3af  Better, Stronger, Faster</title><description>Secuobs.com : 2011-01-18 21:15:48 - Rapid7 Network Security Blog - Since our latest release back in November, the w3af team has focused on making the framework better, stronger and faster By downloading this release you ll be able to enjoy new vulnerability checks, more stable code and a about 15pourcents performance boost in the overall speed of your scan Here s what s new  Now using bloom filters    </description><link>http://www.secuobs.com/revue/news/279031.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/279031.shtml</guid></item>
<item><title>January Patch Tuesday Roundup</title><description>Secuobs.com : 2011-01-13 20:58:23 - Rapid7 Network Security Blog - So I know we all were hoping to see a fix for some of this Windows Graphic Rendering Engine nastiness but no go For now, you ll need to resort to the good ol  FixIt option or if you wanna get your hands dirty, you can modify the ACL on shimgvwdll directly Either way, if you re running    </description><link>http://www.secuobs.com/revue/news/278063.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/278063.shtml</guid></item>
<item><title>Become invisible to anti-virus protection</title><description>Secuobs.com : 2011-01-06 17:13:09 - Rapid7 Network Security Blog - Wouldn t it be fantastic to be invisible for a day  Walk straight into a bank vault in the morning, be a fly on the wall in the Oval Office for lunch, and spend an evening in your favorite movie star s house Well, now you can   with Metasploit  We tested our Metasploit invisibility cloak on    </description><link>http://www.secuobs.com/revue/news/276291.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/276291.shtml</guid></item>
<item><title>How to set up a pentesting lab</title><description>Secuobs.com : 2011-01-05 17:19:23 - Rapid7 Network Security Blog - One of my biggest challenges in learning how to pentest was finding systems to test against I heard that using your neighbors network is  frowned upon , and hanging out in a Starbucks and pwning your fellow coffee drinkers on the public wifi raises the occasional eyebrow So what do I do  Build a test environment    </description><link>http://www.secuobs.com/revue/news/276020.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/276020.shtml</guid></item>
<item><title>Chinese agencies double cyber attacks on Germany</title><description>Secuobs.com : 2011-01-04 21:09:36 - Rapid7 Network Security Blog -  Prost Neujahr  That s what we say for  Happy New Year  in Germany, where I just spent a few days with my family to relax and get away from work A futile attempt, since the Bundesamt für Verfassungsschutz  Federal Office for the Protection of the Constitution, or BfV for short  decided to publish new statistics about    </description><link>http://www.secuobs.com/revue/news/275770.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/275770.shtml</guid></item>
<item><title>Plunderous Informative Pirates</title><description>Secuobs.com : 2010-12-30 05:49:57 - Rapid7 Network Security Blog - Gawker got owned Bad The resulting data breach resulted in some pretty entertaining fallout  a hacker gang took down a website purely on perceived arrogance and self-worth of the target, millions of accounts wound up compromised all across the web NPR and other outlets wound up trying to tell us for like the 10th time    </description><link>http://www.secuobs.com/revue/news/274837.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/274837.shtml</guid></item>
<item><title>December Patch Tuesday Roundup</title><description>Secuobs.com : 2010-12-23 01:28:10 - Rapid7 Network Security Blog - So what can I say that hasn t already been said about this month s Patch Tuesday release Microsoft never ceases to amaze, finishing the year with another 17 bulletins for 40 vulnerabilities this release This month marks the end of a record-breaking year for bulletins and another month of what appears to be an upward trajectory of    </description><link>http://www.secuobs.com/revue/news/273712.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/273712.shtml</guid></item>
<item><title>Four holiday tips to protect against identity theft</title><description>Secuobs.com : 2010-12-22 16:36:24 - Rapid7 Network Security Blog - As you re doing your last-minute online holiday shopping, here are my top four holiday tips to protect you from identity theft  Never pick a password based on any word found in a dictionary Choose a different password for each Web site or service If you notice any strange behavior, change your password immediately Use a virtual credit card number    </description><link>http://www.secuobs.com/revue/news/273608.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/273608.shtml</guid></item>
<item><title>The Next Security Frontier  Virtualization</title><description>Secuobs.com : 2010-12-22 01:32:35 - Rapid7 Network Security Blog - Most pundits agree that virtualization is taking the industry by storm Leading analyst group IDC is projecting that more than 70pourcents of all server workloads installed on new shipments are expected to reside in a virtual machine by 2014 With organizations lining up left and right to climb on the virtualization bandwagon, the security aspect    </description><link>http://www.secuobs.com/revue/news/273464.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/273464.shtml</guid></item>
<item><title>Rapid7 scam busters  Using social engineering to train your users about phishing attacks</title><description>Secuobs.com : 2010-12-20 16:05:36 - Rapid7 Network Security Blog - With the holidays approaching, many people are looking for gift ideas and deals Holiday season is also hunting season for malicious hackers who send out gift idea and deal phishing emails How do you protect your employees from divulging their personal and even corporate passwords to an attacker  It s hard to combat phishing with technology Training    </description><link>http://www.secuobs.com/revue/news/273091.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/273091.shtml</guid></item>
<item><title>Cisco IOS Penetration Testing with Metasploit</title><description>Secuobs.com : 2010-12-17 19:29:57 - Rapid7 Network Security Blog - The Metasploit Framework and the commercial Metasploit products have always provided features for assessing the security of network devices With the latest release, we took this a step further and focused on accelerating the penetration testing process for Cisco IOS devices While the individual modules and supporting libraries were added to the open source framework,    </description><link>http://www.secuobs.com/revue/news/272648.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/272648.shtml</guid></item>
<item><title>Offensive Security   Backtrack Linux   Metasploit Pro</title><description>Secuobs.com : 2010-12-16 17:38:47 - Rapid7 Network Security Blog - This week the guys over at Offensive Security officially added Metasploit Pro to their curriculum for the class Pentration Testing with Backtrack For those not familiar with it, BackTrack is a Linux distribution that includes a lot of tools for penetration testing Since 2006, it has been downloaded three million times and has become the    </description><link>http://www.secuobs.com/revue/news/272274.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/272274.shtml</guid></item>
<item><title>Sesame open  Auditing password security with Metasploit 351</title><description>Secuobs.com : 2010-12-15 21:17:42 - Rapid7 Network Security Blog - Secret passwords don t only get you into Aladdin s cave or the tree house, but also into corporate networks and bank accounts Yet, they are one of the weakest ways to protect access Sure, there are better ways to secure access, such as smart cards or one-time password tokens, but these are still far from being    </description><link>http://www.secuobs.com/revue/news/272054.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/272054.shtml</guid></item>
<item><title>Mubix and Carnal0wnage join the Rapid7 family</title><description>Secuobs.com : 2010-12-14 16:14:54 - Rapid7 Network Security Blog - We re happy to welcome two new rock stars to our family  Rob Fuller aka mubix and Chris Gates aka carnal0wnage are joining our professional services team to conduct penetration tests for Rapid7 customers Rob has joins us from Applied Security, where he worked as a Network Attack Operator, a Penetration Tester for the Department of Defense,    </description><link>http://www.secuobs.com/revue/news/271550.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/271550.shtml</guid></item>
<item><title>Shock and awe with gawkercom  How to test if you have been breached</title><description>Secuobs.com : 2010-12-13 21:38:15 - Rapid7 Network Security Blog - This weekend, the Web and back-end database of Gawkercom was published on Pirate Bay If you had a personal email account registered at Gawker or one of their associated web sites, such as Engaged, you may have been breached This especially becomes a problem if you are using the same password across a number of    </description><link>http://www.secuobs.com/revue/news/271392.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/271392.shtml</guid></item>
<item><title>Setting up a test environment for VPN Pivoting with Metasploit Pro</title><description>Secuobs.com : 2010-12-02 00:26:00 - Rapid7 Network Security Blog - Penetration testing software only shows its true capabilities on actual engagements However, you cannot race a car before you ve ever sat in the driver s seat That s why in this article I d like to show you how to set up a test environment for VPN pivoting, a Metasploit Pro feature for intermediate and advanced users recently    </description><link>http://www.secuobs.com/revue/news/268727.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/268727.shtml</guid></item>
<item><title>The Big Easy</title><description>Secuobs.com : 2010-12-01 04:51:13 - Rapid7 Network Security Blog - People don t like to hire blackhats It s great because it speaks to so many levels of assumptions and interests me immensely because of it Arguably, the mentality speaks to a much lower level issue with the pervasive American ideal of perfectionism  but if I wanted to wax wasteful poetic on the irritating low-level sociological tendencies    </description><link>http://www.secuobs.com/revue/news/268470.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/268470.shtml</guid></item>
<item><title>Turning your world upside down  Metasploit ambigram tattoos</title><description>Secuobs.com : 2010-11-23 19:59:37 - Rapid7 Network Security Blog - You may remember Roy s Metasploit tattoo a few weeks ago, which prompted our Metasploit Pro tattoo competition We thought it was a cute idea, expecting a few fun pictures with felt pen tattoos or tattoo photo montages of of the Metasploit logo We weren t counting on Bill Swearingen from I-Hacked  aka hevnsnt on Twitter , who blew    </description><link>http://www.secuobs.com/revue/news/266977.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/266977.shtml</guid></item>
<item><title>Help your new sweethearts call home to Metasploit</title><description>Secuobs.com : 2010-11-12 21:01:14 - Rapid7 Network Security Blog - Life is full of disappointments  You spend a lot of time flirting with a cute new machine, convince it to accept your payload, and never get a call back   just because the big bad NAT is not letting your new sweetheart phone home That s why many of you broken hearted pentesters have asked us    </description><link>http://www.secuobs.com/revue/news/264517.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/264517.shtml</guid></item>
<item><title>November Patch Tuesday Roundup</title><description>Secuobs.com : 2010-11-11 19:33:23 - Rapid7 Network Security Blog - Microsoft s November Patch Tuesday was fairly light with only 3 security bulletins covering 11 vulnerabilities, only one bulletin, MS10-087, was rated critical The bulletin related to MS Office 2007 and Office 2010 vulnerability which could be exploited by a classic drive by type attack when a customer views a malicious RTF As Josh Abraham, Rapid7 security    </description><link>http://www.secuobs.com/revue/news/264252.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/264252.shtml</guid></item>
<item><title>How VPN pivoting creates an undetectable local network tap</title><description>Secuobs.com : 2010-11-08 21:12:21 - Rapid7 Network Security Blog - Let s assume your goal for an external penetration test is to pwn the domain controller Of course, the domain controller s IP address is not directly accessible from the Web, so how do you go about it  Seasoned pentesters already know the answer  they compromise a publicly accessible host and pivot to other machines and network    </description><link>http://www.secuobs.com/revue/news/263302.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/263302.shtml</guid></item>
<item><title>Open source on steroids  How we boosted w3af development</title><description>Secuobs.com : 2010-11-03 23:32:36 - Rapid7 Network Security Blog - I m thrilled to announce that we re releasing w3af version 10-rc4 and that it offers users many great new features But, I m even more excited to say that the release isn t the big news The major achievement is the story behind the release and the effort put in by our contributors, our core developer Javier Andalia,    </description><link>http://www.secuobs.com/revue/news/262247.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/262247.shtml</guid></item>
<item><title>We weren t joking when we said  tattoos </title><description>Secuobs.com : 2010-11-01 17:47:06 - Rapid7 Network Security Blog -  Be careful what we wish for  In 2006, HD Moore wrote a blog post about a redesign of the Metasploit Project, announcing that the new graphics  will be featured on tee shirts, posters, and tattoos over the coming year  Well, you guys took a little longer than we thought but we now have our first    </description><link>http://www.secuobs.com/revue/news/261513.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/261513.shtml</guid></item>
<item><title>Embrace the Chaos</title><description>Secuobs.com : 2010-10-26 03:52:27 - Rapid7 Network Security Blog - Something I never stop thinking about is who the power brokers of any given society are Think of it this way  if there was one group out there, toiling and working and doing all sorts of tasks, who decided one day to give the rest of the world the finger, just how hard would society    </description><link>http://www.secuobs.com/revue/news/259842.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/259842.shtml</guid></item>
<item><title>Metasploit anniversary marks world s most successful open source acquisition</title><description>Secuobs.com : 2010-10-20 19:50:05 - Rapid7 Network Security Blog - Exactly one year ago, Rapid7 acquired the Metasploit Project Many community members feared that this would be the end of Metasploit s open source era After all, many open source projects had been turned into commercial offerings at the cost of the community Most prominently our space, a widely used vulnerability scanner is no longer open    </description><link>http://www.secuobs.com/revue/news/258649.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/258649.shtml</guid></item>
<item><title>Take an earlier flight home with the new Metasploit Pro</title><description>Secuobs.com : 2010-10-19 21:03:39 - Rapid7 Network Security Blog - We love it, our beta testers loved it, and we trust you will as well  today we re introducing Metasploit Pro, our newest addition to the Metasploit family, made for penetration testers who need a bigger, and better, bag of tricks The feedback our beta testers has been fantastic, most people loved how easily they can conduct    </description><link>http://www.secuobs.com/revue/news/258313.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/258313.shtml</guid></item>
<item><title>October Patch Tuesday Roundup</title><description>Secuobs.com : 2010-10-15 00:40:02 - Rapid7 Network Security Blog - Although Microsoft s October patch covers 39 vulnerabilities, there are only 4 critical bulletins One of the vulnerabilities, covered by bulletin MS10-083, was reported to Microsoft by HD Moore back in 2006 Unfortunately, according to HD Moore, despite the long wait, the fix  does not completely solve the underlying vulnerability, but it does block the easiest    </description><link>http://www.secuobs.com/revue/news/257159.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/257159.shtml</guid></item>
<item><title>MS10-046  A rude awakening</title><description>Secuobs.com : 2010-09-24 20:14:52 - Rapid7 Network Security Blog - Unless you ve been living under a rock, you ve probably seen some chatter about the Stuxnet worm and the patch now known to the world as MS10-046 This out-of-band patch Microsoft released on Monday plugged a hole in the Windows shell component which handles lnk file parsing That bug allowed malware authors to piggyback their own    </description><link>http://www.secuobs.com/revue/news/251480.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/251480.shtml</guid></item>
<item><title>Black Hat Race To Root Results</title><description>Secuobs.com : 2010-09-24 20:14:52 - Rapid7 Network Security Blog - We had a good number of folks compete for prizes in the Race to Root competition at this year s Black Hat, so thanks to everyone who came by Three competitors came out on top Anders Hansen took first place  He ll be receiving both a ProxMark3  http proxmark3com  and a MAKInterface Magstripe Reader Writer  http wwwmakinterfacede index_ephp3 frompage makstusbephp3 , Haikon Krohn took    </description><link>http://www.secuobs.com/revue/news/251479.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/251479.shtml</guid></item>
<item><title>August Patch Tuesday Roundup</title><description>Secuobs.com : 2010-09-24 20:14:52 - Rapid7 Network Security Blog - Microsoft s patch this month, which consists of 14 bulletins that address 34 vulnerabilities, is the largest since October 2009 With the massive amount of work that lies ahead, it may help to prioritize your work Josh Abraham, Rapid7 Security Researcher, recommends that you pay particular attention to MS10-054 This vulnerability in the SMB protocol  is potentially    </description><link>http://www.secuobs.com/revue/news/251478.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/251478.shtml</guid></item>
<item><title>Metasploit Express crucial to win in South Florida ISSA Hack the Flag</title><description>Secuobs.com : 2010-09-24 20:14:52 - Rapid7 Network Security Blog - Last Saturday, our favorite South Florida hacker collective, HackMiami, took first place at the South Florida ISSA Hack the Flag contest in Fort Lauderdale, FL Seven teams participated, defending systems running a variety of off-the-shelf services such as HTTP, SSH, FTP, while attempting to take control of other teams  systems We think it s a useful    </description><link>http://www.secuobs.com/revue/news/251477.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/251477.shtml</guid></item>
<item><title>Application DLL Load Hijacking</title><description>Secuobs.com : 2010-09-24 20:14:52 - Rapid7 Network Security Blog - This post discusses the DLL loading vulnerabilities covered in the news last week For technical information about the flaw and how to test for it, please see the Metasploit Blog Last Thursday, Acros, a Slovenian security firm, published an advisory that identified what they call a  binary planting  flaw in iTunes Essentially, if you open a    </description><link>http://www.secuobs.com/revue/news/251476.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/251476.shtml</guid></item>
<item><title>September Patch Tuesday Roundup</title><description>Secuobs.com : 2010-09-24 20:14:52 - Rapid7 Network Security Blog - Microsoft s patch for September includes 4 Critical Bulletins and 5 Important Bulletins covering 11 vulnerabilities A couple vulnerabilities are worth noting including  MS10-064 a vulnerability in Microsoft Outlook allows for Remote Code Execution This is the classic drive-by malware in which the attacker sends a malicious email message to the victim Simply by opening the contents of    </description><link>http://www.secuobs.com/revue/news/251475.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/251475.shtml</guid></item>
<item><title>New VxWorks Vulnerabilities</title><description>Secuobs.com : 2010-08-02 09:32:34 - Rapid7 Network Security Blog - CERT plans to publish advisories for VU 362332 and VU 840249 today, both flaws in the VxWorks operating system VxWorks is used to power a wide range of devices, including everything from printers, to fibre-channel switches, and even spacecraft NeXpose users already have a check in place for VU 362332, while VU 840249 is a bit more complicated and    </description><link>http://www.secuobs.com/revue/news/245851.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/245851.shtml</guid></item>
<item><title>Better is not good enough</title><description>Secuobs.com : 2010-07-28 22:44:59 - Rapid7 Network Security Blog - In July 2009 I posted to the Rapid7 blog that the future is friendly In that post, I talked about how we, as vendors and service providers, have not fulfilled our promises to protect our customers, feed the community, and catalyze change I admitted that we need to be better, committed that we will be better, and announced to you that it starts now Now that we ve reached the end of July 2010, it seems like an appropriate time to reflect on that optimism, reflect on our commitment, and reflect on the state of our industry </description><link>http://www.secuobs.com/revue/news/244791.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/244791.shtml</guid></item>
<item><title>Cheer and Pwning in Las Vegas</title><description>Secuobs.com : 2010-07-23 01:24:43 - Rapid7 Network Security Blog - Rapid7 and the entire core Metasploit team are headed to Las Vegas next week for Black Hat USA, Security B-Sides, and Defcon 18 The full schedule of events is listed below, make sure you drop by Booth  64 at Black Hat to take a shot at the Race to Root contest, where the winners    </description><link>http://www.secuobs.com/revue/news/243049.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/243049.shtml</guid></item>
<item><title>Metasploit Express v341 Released </title><description>Secuobs.com : 2010-07-19 22:48:46 - Rapid7 Network Security Blog - Metasploit Express 341 was released on July 15th, 2010 This release adds 16 new exploits, an overhauled module browser, island-hopping support, brute force support for FTP and HTTPS, enhanced import and export functionality, and improvements to the online update system, including support for HTTP proxies This release fixes over 100 bugs    </description><link>http://www.secuobs.com/revue/news/241833.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/241833.shtml</guid></item>
<item><title>July Patch Tuesday Roundup</title><description>Secuobs.com : 2010-07-19 20:01:58 - Rapid7 Network Security Blog - The highlight of Microsoft s security bulletins is the fix for Microsoft s online help vulnerability  MS10-042  identified by Google security researcher, Tavis Ormandy, which could allow an attacker to take control of a computer by luring a computer user to a malicious Web site Also as Microsoft s July security bulletins also address vulnerabilities in Windows XP, Josh    </description><link>http://www.secuobs.com/revue/news/241787.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/241787.shtml</guid></item>
<item><title>NeXpose Runs on WinXP   alpha</title><description>Secuobs.com : 2010-07-05 15:21:40 - Rapid7 Network Security Blog - One of the most frequent feature requests we ve received here at Rapid7 from our community is a wider array of supported Windows platforms Thus far, our supported Windows platforms have been restricted to Windows Server, which clearly limits the relevance of NeXpose to many of our non-enterprise users For these platforms, we use the standard    </description><link>http://www.secuobs.com/revue/news/237708.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/237708.shtml</guid></item>
<item><title>Time for the June 2010 summary of the upcoming Microsoft Security Updates </title><description>Secuobs.com : 2010-06-09 07:16:35 - Rapid7 Network Security Blog - As summer comes upon us in the Northern hemisphere, June is again one of the heavier months for Microsoft For 2009, it was 10 Advisories, covering 31 Vulnerabilities For June 2010, Microsoft has announced 10 Advisories, with 34 Vulnerabilities covered For Windows, 2 Critical and 4 Important are listed For Office, 2 rated as Important Another    </description><link>http://www.secuobs.com/revue/news/229893.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/229893.shtml</guid></item>
<item><title>Rapid7 One of Boston s Hottest Companies</title><description>Secuobs.com : 2010-06-08 18:46:37 - Rapid7 Network Security Blog - A recent list of Boston s Hottest Companies brings together an interesting mix of private start-ups in the the digital content, social media, life sciences, technology and security verticals Rapid7 is included in the list of the hottest Boston companies that was selected out of more than 1,250 companies This is on the back of Rapid7  s    </description><link>http://www.secuobs.com/revue/news/229617.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/229617.shtml</guid></item>
<item><title>Recently joined Rapid7</title><description>Secuobs.com : 2010-06-02 17:24:05 - Rapid7 Network Security Blog - Hi, I m Didier Godart and I recently joined Rapid7 as Risk Product Manager I m a skilled Business Leader with 19 years experience in Information Security, Auditing and Risk management I ve been a key actor of the PCI Council from its early days I set the first security rules for Ecommerce security, co-authored the first versions of the    </description><link>http://www.secuobs.com/revue/news/227914.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/227914.shtml</guid></item>
<item><title>May Patch Tuesday Roundup</title><description>Secuobs.com : 2010-05-14 16:43:40 - Rapid7 Network Security Blog - Time for the May 2010 summary of the upcoming Microsoft Security Updates  2 Advisories, with 2 Vulnerabilities covered Both are rated as Critical The first one covering Outlook Express, Microsoft Mail, and Microsoft Live Mail on all Windows Operating Systems  sans Server Core and Server Core for Windows Server 2008 R2  and the second covering Microsoft Visual    </description><link>http://www.secuobs.com/revue/news/222204.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/222204.shtml</guid></item>
<item><title>April Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2010-04-13 23:20:22 - Rapid7 Network Security Blog - Time for this month s summary of the latest Microsoft Security updates   11 advisories, with 25 vulnerabilities covered 5 Critical  5 Important  1 Moderate This is the heaviest April update we ve seen  we generally see 5-8 updates in April and 25 vulnerabilities breaks the 2009 April record of 21 The SMB DoS issue is being addressed,    </description><link>http://www.secuobs.com/revue/news/211717.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/211717.shtml</guid></item>
<item><title>March Microsoft Out-Of-Band Patch Tuesday Roundup</title><description>Secuobs.com : 2010-03-30 23:45:58 - Rapid7 Network Security Blog - Brief summary of today s Out-Of-Band Microsoft Security update   1 Cumulative IE update, with 10 vulnerabilities covered While Out-Of-Band updates are not unheard of  this is the second one so far this year , 10 vulnerabilities covered is a lot Here s the breakdown  MS10-018  Rated Critical Cumulative update for Internet Explorer, covering 10 vulnerabilities  CVE-2010-0267  Uninitialized Memory Corruption  CVE-2010-0488    </description><link>http://www.secuobs.com/revue/news/207090.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/207090.shtml</guid></item>
<item><title>Visualizing Microsoft Security Bulletin Supersedence</title><description>Secuobs.com : 2010-03-26 02:35:31 - Rapid7 Network Security Blog - I ve always been a very visual person As a young child, I had an interesting ability to be able to subconsciously scan the landscape and immediately pick out things that were out of place On my way to work or otherwise driving around town, my eyes are scanning the passenger s, rear-view and driver s side mirrors    </description><link>http://www.secuobs.com/revue/news/205609.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/205609.shtml</guid></item>
<item><title>It Takes a Village To Raise the  PCI  Bar</title><description>Secuobs.com : 2010-03-19 00:57:15 - Rapid7 Network Security Blog - The new PCI ASV Program Guide is out, and the updates are much more significant than they appear   I had the pleasure of working on the ASV Task Force last year, pulled together by the PCI SSC to revamp the rules of engagement for ASV Services The experience was fantastic, working directly with the    </description><link>http://www.secuobs.com/revue/news/203170.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/203170.shtml</guid></item>
<item><title>New Massachusetts data privacy law sets aggressive standard to protect residents from identity theft</title><description>Secuobs.com : 2010-03-18 20:32:03 - Rapid7 Network Security Blog - Organizations nationwide are taking note of the newest state privacy law aimed at attacking the issue of identity theft head on The new Massachusetts data privacy law, also known as MA 201 CMR 17, applies to any organization anywhere in the world that  owns or licenses  personal information whether stored in electronic or paper form about    </description><link>http://www.secuobs.com/revue/news/203076.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/203076.shtml</guid></item>
<item><title>Creating your own vulnerability checks in NeXpose Community Edition</title><description>Secuobs.com : 2010-03-15 17:10:09 - Rapid7 Network Security Blog - Creating custom vulnerability checks in NeXpose </description><link>http://www.secuobs.com/revue/news/201721.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/201721.shtml</guid></item>
<item><title>New HIPAA security penalties hit healthcare services   business associates</title><description>Secuobs.com : 2010-03-13 02:41:45 - Rapid7 Network Security Blog - Healthcare Services and Health Plan Administrators are in the cross-hairs of federal regulators from the Department of Health and Human Services February 17th was the moment  the tipping point  because after that, the enforcement penalties found in the new Health Information Technology for Economic and Clinical Health Act, also known as the HITECH Act, came    </description><link>http://www.secuobs.com/revue/news/201298.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/201298.shtml</guid></item>
<item><title>March Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2010-03-10 04:50:20 - Rapid7 Network Security Blog - Time once again for this month s summary of the latest Microsoft Security updates   2 advisories, with 8 vulnerabilities covered This is the lightest March update since Microsoft skipped March altogether back in 2007 Here s the breakdown  MS10-016  Rated Important Potential Remote Code Execution in Windows Movie Maker, covering 1 vulnerability  CVE-2010-0265  Buffer Overflow in Movie Maker    </description><link>http://www.secuobs.com/revue/news/200106.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/200106.shtml</guid></item>
<item><title>Introducing Exploit Exposure</title><description>Secuobs.com : 2010-02-23 17:10:04 - Rapid7 Network Security Blog - We just released a new version of NeXpose to all of our users that has a new technology we call Exploit Exposure   Exploit Exposure will now give you exploit information about a particular vulnerability Why is this important  The Rapid7 vulnerability database contains checks for over 12,000 vulnerabilities, and most organizations have a lot    </description><link>http://www.secuobs.com/revue/news/194667.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/194667.shtml</guid></item>
<item><title>February Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2010-02-10 04:14:24 - Rapid7 Network Security Blog - Time for this month s summary of the latest Microsoft Security updates   13 advisories, with 26 vulnerabilities covered This is the busiest February update ever Here s the breakdown  MS10-003  Rated Important Potential Remote Code Execution in Office XP and Office 2004 for Mac, covering 1 vulnerability  CVE-2010-0243  Buffer Overflow in MSODLL  This one replaces the MS09-062 GDI     </description><link>http://www.secuobs.com/revue/news/190322.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/190322.shtml</guid></item>
<item><title>February Microsoft Patch Tuesday Preview</title><description>Secuobs.com : 2010-02-05 00:03:28 - Rapid7 Network Security Blog - Sheldon here with a quick preview of next week s Microsoft Patch Tuesday updates   If you re on the customer side, you have a lot of patching to do starting next week If you re on the Security Research side, order some extra pizza and chill an extra case of Red Bull   this is going to    </description><link>http://www.secuobs.com/revue/news/188750.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/188750.shtml</guid></item>
<item><title>The True Value of  Free  in Vulnerability Management</title><description>Secuobs.com : 2010-01-22 19:03:06 - Rapid7 Network Security Blog - Yesterday proved to be another busy day for the security community with Microsoft s out of band security update for Internet Explorer We ve already blogged about the positive impact that Metasploit and the broader security community are having on increasing the awareness for major security issues Within 24 hours of the security update, we ve included coverage for    </description><link>http://www.secuobs.com/revue/news/184535.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/184535.shtml</guid></item>
<item><title>January Out of Band Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2010-01-21 21:53:06 - Rapid7 Network Security Blog - After a quiet Patch Tuesday last week with only one vulnerability announced, that calm has been followed by a bit of a storm Here is a quick summary of this month s summary of Microsoft s Out of Band Security update   1 updates, with 8 vulnerabilities covered Here s the breakdown  MS10-002  Rated Critical Potential Remote Code Execution,    </description><link>http://www.secuobs.com/revue/news/184174.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/184174.shtml</guid></item>
<item><title>The Story Behind NeXpose Community Edition</title><description>Secuobs.com : 2010-01-19 17:42:45 - Rapid7 Network Security Blog - Hi, I m the product manager here at Rapid7 and one of the many people behind the Community Edition I joined Rapid7 in July after spending my last eight years with Red Hat Before that, I worked at another open source software company Naturally, I have strong opinions on why open source and community-driven software is    </description><link>http://www.secuobs.com/revue/news/183142.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/183142.shtml</guid></item>
<item><title>January Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2010-01-12 22:28:24 - Rapid7 Network Security Blog - A new year, a new decade, and time once again for this month s summary of the latest Microsoft Security updates   actually, that s  update  1 update, with 1 vulnerability covered Here s the breakdown  MS10-001  Rated Critical Potential Remote Code Execution via integer overflow in LZCOMP Decompressor of the Embedded OpenType  EOT  Font Engine, covering 1 vulnerability  CVE-2010-0018    </description><link>http://www.secuobs.com/revue/news/180802.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/180802.shtml</guid></item>
<item><title>Metasploit PSEXEC scanner  via Perl </title><description>Secuobs.com : 2009-12-18 18:47:35 - Rapid7 Network Security Blog - Metasploit s pexec module is one of my favorite modules It does exactly what I need and it does it really well One thing I wish that Metasploit had, is a scanner version of the psexec exploit module So I decided to build my own with Perl Okay, assume we have the following networks  19216810 24, 19216820 24 etc    </description><link>http://www.secuobs.com/revue/news/173977.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/173977.shtml</guid></item>
<item><title>December Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2009-12-08 22:47:00 - Rapid7 Network Security Blog - Time once again for this month s summary of the latest Microsoft Security updates NeXpose  including the free NeXpose Community Edition  users will have coverage within 24 hours or less Metasploit already had a module for the IE exposure Here s the breakdown   6 updates, with 12 vulnerabilities covered Here s the breakdown  MS09-069  Rated Critical    </description><link>http://www.secuobs.com/revue/news/169831.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/169831.shtml</guid></item>
<item><title>NeXpose Community Edition Metasploit Integration  Responding to the Needs of Users</title><description>Secuobs.com : 2009-12-04 01:47:44 - Rapid7 Network Security Blog - When we released NeXpose Community Edition and Metasploit 331 two days ago, we received a lot of interest from members of the community As people have downloaded the new releases and started using them, we ve had a lot of great feedback Your response has been exceptionally positive and people are finding a lot of value    </description><link>http://www.secuobs.com/revue/news/168426.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/168426.shtml</guid></item>
<item><title>December Microsoft Patch Tuesday Preview</title><description>Secuobs.com : 2009-12-04 01:47:44 - Rapid7 Network Security Blog - Sheldon here with a preview of what s coming out in next week s Microsoft Patch Tuesday   6 updates in total, covering 12 vulnerabilities Windows, IE, and Office are affected Bulletin 1 affects all supported Windows versions, rated Important on most, Moderate on XP, and Critical on Server 2008 This will be the second highest priority    </description><link>http://www.secuobs.com/revue/news/168425.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/168425.shtml</guid></item>
<item><title>The Noisy Assembly</title><description>Secuobs.com : 2009-12-03 01:35:06 - Rapid7 Network Security Blog - Not like the exploits out on STS With straight-forward hints and straight-forward flow  Here is a program, which IDA shall show The feat I ve taken to find and assess Contained is a message to unsuppress Discovered by breaking the code  although I confess that is not all you must know, For you must have talent     </description><link>http://www.secuobs.com/revue/news/168005.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/168005.shtml</guid></item>
<item><title>Confidence, Integrity and Immediate Availability</title><description>Secuobs.com : 2009-12-01 23:15:06 - Rapid7 Network Security Blog - For those who have been wondering what we ve been up to, we are pleased to announce the immediate availability of NeXpose Community Edition Community Edition is an important part of our commitment to say what we mean and to do what we say we re going to do When we made the Metasploit announcement, there was much    </description><link>http://www.secuobs.com/revue/news/167468.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/167468.shtml</guid></item>
<item><title>Metasploit v33 released </title><description>Secuobs.com : 2009-11-17 19:04:33 - Rapid7 Network Security Blog - HD Moore and the entire Metasploit team have released Metasploit v33  I m really excited to start using this new release as it provides tons of new features including  123 new exploits, 117 new auxiliary modules, support for Vista and Windows 7, improved stability of Meterpreter, all applicable exploits now have OSVDB references, Meterpreter with colors    </description><link>http://www.secuobs.com/revue/news/161700.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/161700.shtml</guid></item>
<item><title>MS09-065 and the Worrisome Web</title><description>Secuobs.com : 2009-11-11 23:02:46 - Rapid7 Network Security Blog - Yesterday was Patch Tuesday Unlike the month before, there were only a few bugs to be had  but like everyone else, MS09-065 particularly caught my attention For starters, MS09-065 is a kernel bug This is bad enough It s made much worse by the fact that the vulnerability goes all the way back to Windows 2000 and    </description><link>http://www.secuobs.com/revue/news/159956.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/159956.shtml</guid></item>
<item><title>November Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2009-11-10 22:04:47 - Rapid7 Network Security Blog - Time once again for this month s summary of the latest Microsoft Security updates   6 updates, with 15 vulnerabilities covered Here s the breakdown  MS09-063  Rated Critical Potential Remote Code Execution via Memory Corruption in Web Services on Devices API, covering 1 vulnerability  CVE-2009-2512 Important to note that this one only affects Windows Vista and Server 2008 Also    </description><link>http://www.secuobs.com/revue/news/159538.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/159538.shtml</guid></item>
<item><title>Scan softly and carry a big scope   PCI clarifies wireless guidelines</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - In an Information Supplement released by the PCI Security Standards Council, the requirements for securing Wireless Access Points just got a lot clearer The Special Interest Group  SIG  has completed the review of the Wireless guidelines within the DSS and is taking aim at clarifying requirements for managing wireless communications As has become the hallmark of    </description><link>http://www.secuobs.com/revue/news/152932.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152932.shtml</guid></item>
<item><title>Meet us at BlackHat and DEFCON</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - For those converging upon the BlackHat and DEFCON Conferences this week in Las Vegas, we d love to see you in one of the sessions We ll actually have a number of Rapid7 Security Experts speaking so feel free to stop by  Wednesday, July 29th 16 45   18 00 Unmasking You Presenters  Joshua  Jabra  Abraham   Robert  RSnake  Hansen Where  BlackHat, Las Vegas Schedule More    </description><link>http://www.secuobs.com/revue/news/152931.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152931.shtml</guid></item>
<item><title> Unmasking You  at BlackHat 09 and DefCon 17</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - Last week, I gave a presentation with Robert  RSnake  Hansen called  Unmasking You  at BlackHat 09 and DefCon 17 The slides and demos can be found at  http spl0itorg files talks defcon09  Originally, we were only scheduled to speak at DefCon, but due to a last minute change we spoke at both venues The backstory of how that occurred, is kind    </description><link>http://www.secuobs.com/revue/news/152930.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152930.shtml</guid></item>
<item><title> Unmasking You    Demos</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - This posting includes all of the demos that were presented during  Unmasking You  at BlackHat 09 and DEFCON 17 by Joshua  Jabra  Abraham and Robert  RSnake  Hansen Metasploit Autopwn  via BeEF  This is a module from the Browser Exploitation Framework  BeEF  to perform an iframe redirection to Metasploit Browser Autopwn or a Browser Exploit However, in this    </description><link>http://www.secuobs.com/revue/news/152929.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152929.shtml</guid></item>
<item><title>August Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - Sheldon here again, with a quick summary of this month s Microsoft Security updates   9 advisories, with 19 vulnerabilities covered Here s the breakdown  MS09-036  Rated Important Potential Denial of Service in ASPNET in Microsoft Vista and 2008, covering 1 vulnerability  CVE-2009-1536 Important to note that this vulnerability only affects systems where IIS 70 is installed and ASPNET    </description><link>http://www.secuobs.com/revue/news/152928.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152928.shtml</guid></item>
<item><title>Binary Obfuscation from the Top Down</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - Full disclosure, here  I love binary-related things I m an extremely low-level person If I get any higher level than C, chances are I m just being lazy Otherwise, I m completely immersed in the world of K R So any opportunity I get to peddle my wares in the world of binary I will gladly take What started this    </description><link>http://www.secuobs.com/revue/news/152927.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152927.shtml</guid></item>
<item><title>Once again, time for a quick summary of this month s Microsoft Security updates </title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - Five advisories, with eight vulnerabilities covered Here s the breakdown  MS09-045  Rated Critical Potential Remote Code Execution in JScript 51 on Microsoft Windows 2000 SP4, JScript 56 57 58 on all supported Windows versions except Windows 7 and Server 2008 R2, covering 1 vulnerability  CVE-2009-1920 Important to note that 58 is only affected if IE8 is installed and Server 2003 2008 are    </description><link>http://www.secuobs.com/revue/news/152926.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152926.shtml</guid></item>
<item><title>October Microsoft Patch Tuesday Preview</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - Wow, because the number of bulletins affecting the number of Windows versions is pretty staggering Windows is taking the most lumps this month Wow, because Windows7 makes its debut in the monthly dance with 5 updates  although only the IE update is critical  Wow, because Bulletin 13 alone affects the following products across the Microsoft universe  - Windows    </description><link>http://www.secuobs.com/revue/news/152925.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152925.shtml</guid></item>
<item><title>October Microsoft Patch Tuesday Roundup</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - Time for this month s summary of the latest Microsoft Security updates   13 advisories, with 34 vulnerabilities covered Here s the breakdown  MS09-050  Rated Critical Potential Remote Code Execution and Denial of Service in SMBv2, covering 3 vulnerabilities  CVE-2009-2526  Infinite Loop DoS , CVE-2009-2532  Command Value Remote Code Exec , and CVE-2009-3103  Negotiation Remote Code Exec  Important to note that    </description><link>http://www.secuobs.com/revue/news/152924.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152924.shtml</guid></item>
<item><title>Fearless, Certain and Without Doubt</title><description>Secuobs.com : 2009-10-22 07:08:12 - Rapid7 Network Security Blog - 111 days ago we announced in our inaugural blog post that the future is friendly It just got a lot friendlier That post was about making a fundamental difference in our space, bringing people together to drive change, and admitting that our industry has not been good enough In that post, Rapid7 made the commitment to    </description><link>http://www.secuobs.com/revue/news/152923.shtml</link><guid isPermaLink="false">http://www.secuobs.com/revue/news/152923.shtml</guid></item>
</channel>
</rss>
 
