<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-11073050</id><updated>2011-06-20T23:55:32.039-07:00</updated><title type='text'>IT Security Portal</title><subtitle type='html'>Information Security aims to study the countermeasures to information threats and embraces a range of technologies such as Cryptography, Computer Security, Intrusion Detection, Security Management, Forensics, and many more issues that will be posted in this blog.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://secure-net.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default?start-index=101&amp;max-results=100'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>263</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-11073050.post-27182424400466292</id><published>2008-10-14T22:25:00.001-07:00</published><updated>2008-10-14T22:25:30.964-07:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-27182424400466292?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/27182424400466292'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/27182424400466292'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2008/10/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-3060519959820154542</id><published>2008-09-14T22:46:00.000-07:00</published><updated>2008-09-14T22:47:56.080-07:00</updated><title type='text'>Microsoft Security Bulletin Major Revisions</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-3060519959820154542?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/3060519959820154542'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/3060519959820154542'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2008/09/microsoft-security-bulletin-major.html' title='Microsoft Security Bulletin Major Revisions'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-6812170073783112020</id><published>2008-06-12T23:18:00.001-07:00</published><updated>2008-06-12T23:18:24.588-07:00</updated><title type='text'>Microsoft has released their monthly security bulletins for June, fixing vulnerabilities in various Microsoft products</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-6812170073783112020?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6812170073783112020'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6812170073783112020'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2008/06/microsoft-has-released-their-monthly.html' title='Microsoft has released their monthly security bulletins for June, fixing vulnerabilities in various Microsoft products'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-1123090177174176521</id><published>2008-05-13T22:52:00.000-07:00</published><updated>2008-05-13T22:53:40.083-07:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>&lt;div align="justify"&gt;Microsoft has released updates to remedy critical vulnerabilities in&lt;br /&gt;Microsoft Windows and Office for Windows and Mac.&lt;br /&gt;Updates for Microsoft Windows and Office are available on the&lt;br /&gt;Microsoft Update site. &lt;/div&gt;&lt;div align="justify"&gt;Office for Mac users should go to the Mactopia&lt;br /&gt;website to obtain updates. &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-1123090177174176521?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/1123090177174176521'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/1123090177174176521'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2008/05/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-8137199182852061279</id><published>2008-03-12T02:57:00.000-07:00</published><updated>2008-03-12T02:59:34.177-07:00</updated><title type='text'>Microsoft Excel -- ZERO-DAY exploit - PATCH AVAILABLE NOW - targeted attacks exploiting unspecified error in the handling of Excel files</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-8137199182852061279?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/8137199182852061279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/8137199182852061279'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2008/03/microsoft-excel-zero-day-exploit-patch.html' title='Microsoft Excel -- ZERO-DAY exploit - PATCH AVAILABLE NOW - targeted attacks exploiting unspecified error in the handling of Excel files'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-8796462653026085773</id><published>2008-02-19T00:30:00.000-08:00</published><updated>2008-02-19T00:32:12.734-08:00</updated><title type='text'>Some vulnerabilities and weaknesses have been fixed in the latest</title><content type='html'>&lt;div align="justify"&gt;Some vulnerabilities and weaknesses have been fixed in the latest version of Mozilla Firefox, which can be exploited by malicious people to disclose sensitive information, bypass certain security restrictions, conduct spoofing attacks, or to compromise a user's system.&lt;br /&gt;Various errors have been fixed in Firefox's browser engine and Javascript engine, which can be exploited to cause a memory corruption and allow the execution of arbitrary code.&lt;br /&gt;A weakness due to a design error within the focus handling and which can potentially be exploited to trick a user into uploading arbitrary files has also been fixed.&lt;br /&gt;An error in the handling of images when a user leaves a page, which uses "designMode" frames, can be exploited to disclose the user's navigation history, forward navigation information, and to cause a memory corruption. Successful exploitation of this vulnerability may allow execution of arbitrary code.&lt;br /&gt;A design error related to timer-enabled dialogs can be exploited to trick a user into unintentionally confirming a security dialog.&lt;br /&gt;A problem in Firefox, which follows "302" redirects for stylesheets and allows reading the target URL via "element.sheet.href", can potentially be exploited to disclose sensitive URL parameters.&lt;br /&gt;The vulnerabilities are reported in versions prior to 2.0.0.12. Users&lt;br /&gt;are advised to download the updated version immediately.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-8796462653026085773?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/8796462653026085773'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/8796462653026085773'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2008/02/some-vulnerabilities-and-weaknesses.html' title='Some vulnerabilities and weaknesses have been fixed in the latest'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-7566210609995833899</id><published>2008-02-19T00:26:00.000-08:00</published><updated>2008-02-19T00:28:01.066-08:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>Vulnerabilities in Microsoft Windows and Office could allow an attacker to gain control of your computer.&lt;br /&gt;Updates for Microsoft Windows are available on the Microsoft Update site. We also recommend enabling Automatic Updates.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-7566210609995833899?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7566210609995833899'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7566210609995833899'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2008/02/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-8773548499757841662</id><published>2008-01-08T22:52:00.000-08:00</published><updated>2008-01-08T22:54:00.175-08:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>Microsoft has released updates to remedy vulnerabilities in Microsoft Windows.&lt;br /&gt;&lt;br /&gt;Updates for Microsoft Windows are available on the Microsoft Update site. &lt;br /&gt;We also recommend enabling Automatic Updates.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-8773548499757841662?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/8773548499757841662'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/8773548499757841662'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2008/01/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-6136259659316092117</id><published>2007-12-26T23:48:00.001-08:00</published><updated>2008-11-13T01:14:07.871-08:00</updated><title type='text'>Merry Christmas and a prosperous New Year !!!!</title><content type='html'>&lt;a href="http://1.bp.blogspot.com/_FDLkKY8kALQ/R3NZBvM5gNI/AAAAAAAAAAM/hg8xOnFqdFk/s1600-h/Merry+Christmas+a+a+Happy+New+Year.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5148556685399916754" style="DISPLAY: block; MARGIN: 0px auto 10px; CURSOR: hand; TEXT-ALIGN: center" alt="" src="http://1.bp.blogspot.com/_FDLkKY8kALQ/R3NZBvM5gNI/AAAAAAAAAAM/hg8xOnFqdFk/s320/Merry+Christmas+a+a+Happy+New+Year.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-6136259659316092117?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6136259659316092117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6136259659316092117'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/12/merry-christmas-and-prosperous-new-year.html' title='Merry Christmas and a prosperous New Year !!!!'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_FDLkKY8kALQ/R3NZBvM5gNI/AAAAAAAAAAM/hg8xOnFqdFk/s72-c/Merry+Christmas+a+a+Happy+New+Year.jpg' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-7920867629985843622</id><published>2007-12-14T03:48:00.000-08:00</published><updated>2007-12-14T03:49:20.418-08:00</updated><title type='text'>Microsoft released its last batch of Security Bulletins for the year</title><content type='html'>&lt;div style="text-align: justify;"&gt;Seven Security Bulletins were released, with one Extremely Critical advisory, two Highly Critical advisories, two Moderately Critical advisories, and two Less Critical advisories.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-7920867629985843622?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7920867629985843622'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7920867629985843622'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/12/microsoft-released-its-last-batch-of.html' title='Microsoft released its last batch of Security Bulletins for the year'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-2864081252753688779</id><published>2007-11-14T05:31:00.000-08:00</published><updated>2007-11-14T05:37:15.263-08:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>A vulnerability in Microsoft Windows may allow an attacker to access&lt;br /&gt;your computer, install and run malicious software on your computer, or&lt;br /&gt;cause it to crash.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-2864081252753688779?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/2864081252753688779'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/2864081252753688779'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/11/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-6968464035383713116</id><published>2007-10-28T23:37:00.001-07:00</published><updated>2007-10-28T23:37:54.171-07:00</updated><title type='text'>Some vulnerabilities and a weakness have been reported in Mozilla Firefox</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-6968464035383713116?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6968464035383713116'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6968464035383713116'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/10/some-vulnerabilities-and-weakness-have.html' title='Some vulnerabilities and a weakness have been reported in Mozilla Firefox'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-4270381833550820740</id><published>2007-10-28T23:36:00.001-07:00</published><updated>2007-10-28T23:36:28.410-07:00</updated><title type='text'>Microsoft issues 3 critical security updates patching several vulnerabilities</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-4270381833550820740?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/4270381833550820740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/4270381833550820740'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/10/microsoft-issues-3-critical-security.html' title='Microsoft issues 3 critical security updates patching several vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-4041009415271502996</id><published>2007-10-28T23:34:00.000-07:00</published><updated>2007-10-28T23:35:55.967-07:00</updated><title type='text'>Sun updates for command execution and information disclosure vulnerabilities in Java</title><content type='html'>The Java Runtime Enviornment software contains multiple vulnerabilities that could allow:&lt;br /&gt;multiple unspecified errors in Java Runtime Environment, may allow an untrusted Java Web Start application or Java applet to move or copy arbitrary files on the system, tricking a user into dragging and dropping a file from an applet to a desktop application that has the proper permissions.&lt;br /&gt;unspecified errors in Java Web Start, which could allow an untrusted application to determine the location of the Java Web Start cache, or read and write local files that are accessible to the user running the untrusted application.&lt;br /&gt;unspecified errors in the Java Runtime Environment, which could be exploited by a malicious appleta applet or by using Java APIs to establish network connections to certain services on machines other than the originating host.&lt;br /&gt;The vulnerabilities are reported in the following versions:&lt;br /&gt;JDK and JRE 6 Update 2 and earlier&lt;br /&gt;JDK and JRE 5.0 Update 12 and earlier&lt;br /&gt;SDK and JRE 1.4.2_15 and earlier&lt;br /&gt;SDK and JRE 1.3.1_20 and earlier&lt;br /&gt;OPERATING SYSTEMS Regardless if you run the above programs under :&lt;br /&gt;Windows 2000, XP, Vista,&lt;br /&gt;Windows 2003 Server the vulnerabilities apply! Remember, most PCs have this software installed since many webpages require Java to allow the user a good surfer experience.&lt;br /&gt;IMPORTANT Java Runtime Environment must be removed from a PC before the update/later released is installed ==&gt; see section OTHER ACTIONS below on how to do it - fast and easy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-4041009415271502996?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/4041009415271502996'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/4041009415271502996'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/10/sun-updates-for-command-execution-and.html' title='Sun updates for command execution and information disclosure vulnerabilities in Java'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-7695681972957803745</id><published>2007-10-28T23:32:00.000-07:00</published><updated>2007-10-28T23:34:06.038-07:00</updated><title type='text'>Malicious PDF files being spammed out in volume</title><content type='html'>These PDF files exploit a recent vulnerability. When such PDF files are viewed on vulnerable machines, they get infected.&lt;br /&gt;An unknown party has been sending out tens of thousands of mails with Subject-lines like:&lt;br /&gt;Your credit report&lt;br /&gt;Personal Financial Statement&lt;br /&gt;Your Credit File&lt;br /&gt;Balance Report&lt;br /&gt;The mails contain no mail body, only an attachment called "report.pdf". When opened, the PDF file uses the CVE-2007-5020 vulnerability via Acrobat Reader and IE7 and downloads further malware from a server in Malaysia. The target of the malware seems to be to create a botnet of infected machines to be used for further malicious activity.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-7695681972957803745?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7695681972957803745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7695681972957803745'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/10/malicious-pdf-files-being-spammed-out.html' title='Malicious PDF files being spammed out in volume'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-7292353868366134228</id><published>2007-10-10T06:34:00.000-07:00</published><updated>2007-10-10T06:35:45.744-07:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-7292353868366134228?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7292353868366134228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7292353868366134228'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/10/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-7730530429372813969</id><published>2007-09-13T00:18:00.000-07:00</published><updated>2007-09-13T00:19:59.566-07:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>Vulnerabilities in Microsoft Windows Windows and MSN Messenger could allow an attacker to gain control of your computer.&lt;br /&gt;Updates for Microsoft Windows are available on the Microsoft Update site. We also recommend enabling Automatic Updates.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-7730530429372813969?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7730530429372813969'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7730530429372813969'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/09/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-8677016288603877825</id><published>2007-08-15T22:00:00.000-07:00</published><updated>2007-08-15T22:01:58.514-07:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>Microsoft has released updates that address critical vulnerabilities in Microsoft Windows, Internet Explorer, Windows Media Player, Office, Office for Mac, XML Core Services, Visual Basic, Virtual PC, and Virtual Server.&lt;br /&gt;Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.&lt;br /&gt;Apply updates from Microsoft.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-8677016288603877825?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/8677016288603877825'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/8677016288603877825'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/08/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-7732362931319662871</id><published>2007-08-09T22:08:00.000-07:00</published><updated>2007-08-09T22:09:00.134-07:00</updated><title type='text'>Cisco released several security advisories this week for various products</title><content type='html'>&lt;div align="justify"&gt;Cisco IOS and IOS XR are reportedly affected by a vulnerability that can be exploited to disclose sensitive information or cause a Denial of Service. The problem is due to an error when processing Ipv6 packets with a Type 0 routing header. Sending a specially crafted packet may lead to disclosure of a number of bytes of packet buffer memory, or to crash the device.&lt;br /&gt;This vulnerability affects Cisco IOS 12.x and Cisco IOS XR 3.x products. Vendor patches have been released for some, but not all, affected devices.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-7732362931319662871?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7732362931319662871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7732362931319662871'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/08/cisco-released-several-security.html' title='Cisco released several security advisories this week for various products'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-1270255618638023231</id><published>2007-08-02T22:18:00.000-07:00</published><updated>2007-08-02T22:26:08.418-07:00</updated><title type='text'>Mozilla released Firefox 2.0.0.6</title><content type='html'>&lt;div style="text-align: justify;"&gt;The first is a vulnerability caused by an error in the handling of "about:blank" pages loaded by chrome in an addon. This can be exploited to execute script code under chrome privileges by e.g.&lt;br /&gt;clicking on a link opened in an "about:blank" window created and  populated in a certain ways by an addon.&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-1270255618638023231?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/1270255618638023231'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/1270255618638023231'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/08/mozilla-released-firefox-2006.html' title='Mozilla released Firefox 2.0.0.6'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-6844973115943625206</id><published>2007-07-10T22:26:00.000-07:00</published><updated>2007-07-10T22:28:38.488-07:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>Microsoft has released updates to remedy vulnerabilities in Microsoft Windows and Office.&lt;br /&gt;To obtain these updates, visit the Microsoft Update web site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-6844973115943625206?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6844973115943625206'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6844973115943625206'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/07/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-4796608936804423057</id><published>2007-06-12T22:47:00.000-07:00</published><updated>2007-06-12T22:51:15.072-07:00</updated><title type='text'>Microsoft Updates for Multiple Vulnerabilities</title><content type='html'>Vulnerabilities in Microsoft Windows, Internet Explorer, and Office&lt;br /&gt;could allow an attacker to gain control of your computer.&lt;br /&gt;MS07-031 - Vulnerability in the Windows Schannel Security Package Could Allow Remote Code Execution&lt;br /&gt;MS07-033 - Cumulative Security Update for Internet Explorer&lt;br /&gt;MS07-034 - Cumulative Security Update for Outlook Express and Windows Mail&lt;br /&gt;MS07-035 - Vulnerability in Win32 API Could Allow Remote Code Execution&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-4796608936804423057?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/4796608936804423057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/4796608936804423057'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/06/microsoft-updates-for-multiple.html' title='Microsoft Updates for Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-6957475853261829038</id><published>2007-06-07T04:03:00.000-07:00</published><updated>2007-06-07T04:14:42.511-07:00</updated><title type='text'>Yahoo Messenger - TWO zero-day - buffer overflow security issue in an ActiveX control AND one vulnerability that affects the viewer ywcvwr.dll</title><content type='html'>&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-6957475853261829038?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6957475853261829038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6957475853261829038'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/06/yahoo-messenger-two-zero-day-buffer.html' title='Yahoo Messenger - TWO zero-day - buffer overflow security issue in an ActiveX control AND one vulnerability that affects the viewer ywcvwr.dll'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-1488236454053668567</id><published>2007-03-05T02:47:00.000-08:00</published><updated>2007-03-05T02:49:21.237-08:00</updated><title type='text'>Mozilla Firefox, Sea Monkey and Thunderbird - multiple security vulnerabilities</title><content type='html'>The vulnerabilities could be exploited by attackers to take complete control of an affected system or bypass security restrictions.&lt;br /&gt;You need to upgrade your software as follows:&lt;br /&gt;Downloading latest version of Firefox 2.0.0.2&lt;br /&gt;Downloading latest version of SeaMonkey 1.1&lt;br /&gt;Downloading latest version of Thunderbird 1.5.0.9&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-1488236454053668567?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/1488236454053668567'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/1488236454053668567'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/03/mozilla-firefox-sea-monkey-and.html' title='Mozilla Firefox, Sea Monkey and Thunderbird - multiple security vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-7917410498830849364</id><published>2007-02-13T22:25:00.000-08:00</published><updated>2007-02-13T22:28:09.662-08:00</updated><title type='text'>Microsoft issues 12 security updates</title><content type='html'>CRITICAL&lt;br /&gt;2 for Windows;&lt;br /&gt;2 for Office;&lt;br /&gt;1 for Live OneCare, Antigen, Windows Defender, and Forefront&lt;br /&gt;1 for Windows, Internet Explorer&lt;br /&gt;IMPORTANT&lt;br /&gt;1 for Windows and Visual Studio;&lt;br /&gt;1 for Windows and Office;&lt;br /&gt;1 for Step-by-Step Interactive Training;&lt;br /&gt;2 for Windows&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-7917410498830849364?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7917410498830849364'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7917410498830849364'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/02/microsoft-issues-12-security-updates.html' title='Microsoft issues 12 security updates'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-6544372638484700696</id><published>2007-02-12T04:05:00.000-08:00</published><updated>2007-01-09T22:53:03.670-08:00</updated><title type='text'>DDoSers bombard Military root server</title><content type='html'>At least three DNS root servers, including one maintained by the US Department of Defense, were flooded with data for about 12 hours in an attack that was notable more for its audacity than any noticeable degradation of internet traffic.&lt;br /&gt;The DOD's G server was among those sustaining the most damage, according to an analysis of the machine's unanswered queries. The L server, maintained by ICANN, and the WIDE Project's M server, located in multiple locations, were also hit in attacks that started a little after midnight GMT on Tuesday.&lt;br /&gt;There were reports that F and I servers also faced increased traffic, but those attacks appeared to be short-lived. They appeared to affect certain top-level-domains, including .org.&lt;br /&gt;SANS said it was aware of root server attacks but is still wading through data before issuing a report. It encouraged people with logs, or other information relating to the attacks to send it to SANS officials.&lt;br /&gt;It was unclear where the attacks originated, since the perpetrators disguised the origination of the packet flood, according to the Associated Press. There was some speculation they may have come out of Korea.&lt;br /&gt;SOURCE: The Register&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-6544372638484700696?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6544372638484700696'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6544372638484700696'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/02/ddosers-bombard-military-root-server.html' title='DDoSers bombard Military root server'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-6993826075666360751</id><published>2007-01-09T22:49:00.000-08:00</published><updated>2007-01-09T22:53:02.829-08:00</updated><title type='text'>3 critical security bulletins from Microsoft</title><content type='html'>Microsoft Security Bulletins were issued today&lt;br /&gt;1 Microsoft Security Bulletin affecting Microsoft Windows - Internet Explorer - Critical&lt;br /&gt;1 Microsoft Security Bulletin affecting Microsoft Office - Excel - Critical&lt;br /&gt;1 Microsoft Security Bulletin affecting Microsoft Office - Outlook - Critical&lt;br /&gt;1 Microsoft Security Bulletin affecting Microsoft Office 2003 Brazilian Portuguese Grammar Checker Vulnerability - Important&lt;br /&gt;&lt;br /&gt;The critical vulnerabilities affect the following: operating systems:&lt;br /&gt;Microsoft Windows 2000/XP/2003/Server 2003/software&lt;br /&gt;Microsoft Office 2000/XP/2003&lt;br /&gt;Microsoft Works Suite 2004/2005&lt;br /&gt;Apple Mac&lt;br /&gt;Microsoft Office 2004 for Mac&lt;br /&gt;Microsoft Office v. X for Mac&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-6993826075666360751?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6993826075666360751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6993826075666360751'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/01/3-critical-security-bulletins-from.html' title='3 critical security bulletins from Microsoft'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-7771143783375017909</id><published>2007-01-04T04:33:00.000-08:00</published><updated>2007-01-04T04:37:38.892-08:00</updated><title type='text'>Adobe Acrobat Reader - cross-site scripting vulnerability</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:arial;color:#000000;"&gt;The &lt;/span&gt;&lt;a title="http://cytrap.org/RiskIT/mod/glossary/view.php?id=" mode="entry&amp;amp;hook=" href="http://cytrap.org/RiskIT/mod/glossary/view.php?id=2&amp;mode=entry&amp;amp;hook=4" target="_blank"&gt;&lt;span style="font-family:arial;color:#000000;"&gt;vulnerability&lt;/span&gt;&lt;/a&gt;&lt;span style="font-family:arial;color:#000000;"&gt; could be exploited by attackers by getting javascript executed by simply having it appended to the PDF's URL. Input passed to a hosted PDF file is not properly sanitised by the browser plug-in before being returned to users.&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:Arial;"&gt;Systems Affected: Adobe Acrobat Reader version 7.0.8 and prior &lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;Solution: Upgrade to &lt;a href="http://www.adobe.com/products/acrobat/readstep2.html"&gt;Adobe Reader version 8.0.0  &lt;/a&gt;&lt;/div&gt;&lt;div align="justify"&gt;SOURCE: &lt;a title="http://cytrap.eu/" href="http://cytrap.eu/"&gt;CyTRAP Labs&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-7771143783375017909?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7771143783375017909'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/7771143783375017909'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/01/adobe-acrobat-reader-cross-site.html' title='Adobe Acrobat Reader - cross-site scripting vulnerability'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-853198533919648963</id><published>2007-01-02T02:26:00.000-08:00</published><updated>2007-01-02T02:27:46.103-08:00</updated><title type='text'>SEASON'S GREETINGS</title><content type='html'>&lt;strong&gt;&lt;span style="color:#ff0000;"&gt;BEST WISHES FOR A HAPPY NEW YEAR!!!&lt;/span&gt;&lt;/strong&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-853198533919648963?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/853198533919648963'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/853198533919648963'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2007/01/seasons-greetings.html' title='SEASON&apos;S GREETINGS'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-325975843525538259</id><published>2006-12-21T02:04:00.000-08:00</published><updated>2006-12-21T02:05:52.238-08:00</updated><title type='text'>Yahoo IM Vulnerability</title><content type='html'>Yahoo! reported a vulnerability in its instant messaging client for versions obtained prior to November 2, 2006. The vulnerability is caused by an unspecified error in Yahoo! Messenger's ActiveX control, which potentially can be exploited by malicious people to compromise a user's system.&lt;br /&gt;Users are advised to upgrade to the latest version of Yahoo! Messenger.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-325975843525538259?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/325975843525538259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/325975843525538259'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/12/yahoo-im-vulnerability.html' title='Yahoo IM Vulnerability'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-2416309732130629082</id><published>2006-12-20T22:44:00.000-08:00</published><updated>2006-12-20T22:47:00.095-08:00</updated><title type='text'>Mozilla Addresses Multiple Vulnerabilities</title><content type='html'>Mozilla Firefox, Thunderbird, and derived products contain several vulnerabilities. By taking advantage of one or more of these vulnerabilities, an attacker may be able to take control of your computer.&lt;br /&gt;Upgrade to the latest versions of Firefox, Thunderbird, and SeaMonkey. Mozilla has released Firefox 1.5.0.9, Firefox 2.0.0.1, Thunderbird 1.5.0.9 and SeaMonkey 1.0.7 to correct these&lt;br /&gt;problems. Mozilla Firefox, Thunderbird, and SeaMonkey automatically check for updates by default.&lt;br /&gt;Security updates for Firefox 1.5 are scheduled to end in April 2007. According to Mozilla: Firefox 1.5.0.x will be maintained with security and stability updates until April 24, 2007. All users are strongly encouraged to upgrade to Firefox 2.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-2416309732130629082?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/2416309732130629082'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/2416309732130629082'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/12/mozilla-addresses-multiple.html' title='Mozilla Addresses Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-6253765451631399409</id><published>2006-12-14T00:43:00.000-08:00</published><updated>2006-12-14T00:49:20.404-08:00</updated><title type='text'>Microsoft Security Bulletin Summary for December 2006</title><content type='html'>Critical Security Bulletins&lt;br /&gt;MS06-072 - Cumulative Security Update for Internet Explorer -&lt;br /&gt;MS06-073 - Vulnerability in Visual Studio 2005            &lt;br /&gt;MS06-078 - Vulnerability in Windows Media Format&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-6253765451631399409?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://go.microsoft.com/fwlink/?LinkId=79710' title='Microsoft Security Bulletin Summary for December 2006'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6253765451631399409'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/6253765451631399409'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/12/microsoft-security-bulletin-summary-for.html' title='Microsoft Security Bulletin Summary for December 2006'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-1408055972893339881</id><published>2006-11-15T05:45:00.000-08:00</published><updated>2006-11-15T05:47:44.169-08:00</updated><title type='text'>Microsoft Security Updates for Windows, Internet Explorer, and Adobe Flash</title><content type='html'>&lt;div align="justify"&gt;Vulnerabilities in Microsoft Windows, Internet Explorer, and Adobe Flash may allow an attacker to access your computer, install and run malicious software on your computer, or cause it to crash. An attacker could exploit these vulnerabilities by using specially crafted network traffic, or by convincing you to view a speciallycrafted web site or HTML email message.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-1408055972893339881?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/1408055972893339881'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/1408055972893339881'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/11/microsoft-security-updates-for-windows.html' title='Microsoft Security Updates for Windows, Internet Explorer, and Adobe Flash'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-116175898222928057</id><published>2006-10-24T23:48:00.000-07:00</published><updated>2006-11-15T00:13:49.439-08:00</updated><title type='text'>Firefox 2.0 Out a Day Early</title><content type='html'>The final version of Mozilla's Firefox 2.0 web browser was available on the company's FTP servers on Monday, October 23, a day before its scheduled official release.  The public launch page is not yet up.  A preview version of the browser, Release Candidate 3, was posted for download on October 16.  The release follows close on the heels of that of Microsoft's Internet Explorer (IE) 7. Firefox 2.0 has integrated anti-phishing controls as well as RSS and XML feed viewing capabilities.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-116175898222928057?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/116175898222928057'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/116175898222928057'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/10/firefox-20-out-day-early.html' title='Firefox 2.0 Out a Day Early'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-116115336185738677</id><published>2006-10-17T23:34:00.000-07:00</published><updated>2006-11-15T00:13:49.329-08:00</updated><title type='text'>Flash MP3 Players Given as Prizes in Japan Infected with Trojan</title><content type='html'>As many as 10,000 people in Japan received Flash MP3 players as prizes from McDonalds, but they came with an unexpected extra bit of software: a variant of the QQpass spyware Trojan horse program.  The players were preloaded with ten songs and the malware. If the devices were connected to Windows PCs, passwords and other sensitive data could potentially be exposed to attackers. It is likely that a machine used to load the content was infected with the malware. McDonalds Japan has apologized, established a helpline to facilitate the recall of the infected MPs players and posted directions for cleansing infected PCs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-116115336185738677?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/116115336185738677'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/116115336185738677'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/10/flash-mp3-players-given-as-prizes-in.html' title='Flash MP3 Players Given as Prizes in Japan Infected with Trojan'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-116055234019024035</id><published>2006-10-11T00:33:00.000-07:00</published><updated>2006-11-15T00:13:49.225-08:00</updated><title type='text'>Microsoft Updates for Vulnerabilities in Windows, Office, and Internet Explorer</title><content type='html'>Microsoft has provided updates to remedy these vulnerabilities. To obtain these updates, visit the Microsoft Update web site. &lt;br /&gt;Microsoft Office 2000 users must visit the Microsoft Office Update web site to get the appropriate updates.&lt;br /&gt;Apple Mac OS X users should obtain updates from the Mactopia web site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-116055234019024035?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/116055234019024035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/116055234019024035'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/10/microsoft-updates-for-vulnerabilities.html' title='Microsoft Updates for Vulnerabilities in Windows, Office, and Internet Explorer'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115934141311439282</id><published>2006-09-27T00:13:00.000-07:00</published><updated>2006-11-15T00:13:49.106-08:00</updated><title type='text'>Microsoft Internet Explorer VML Buffer Overflow</title><content type='html'>Microsoft Internet Explorer (IE) fails to properly handle Vector Markup Language (VML) tags. This creates a buffer overflow vulnerability that could allow a remote attacker to execute arbitrary code.&lt;br /&gt;Microsoft Internet Explorer contains a stack buffer overflow in code that handles VML. More information is available in Vulnerability Note VU#416092, Microsoft Security Advisory (925568), and Microsoft Security Bulletin MS06-055.&lt;br /&gt;By convincing a user to open a specially crafted HTML document, such as a web page or HTML email message, a remote attacker could execute arbitrary code with the privileges of the user running IE.&lt;br /&gt;Apply update from Microsoft&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115934141311439282?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115934141311439282'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115934141311439282'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/microsoft-internet-explorer-vml-buffer.html' title='Microsoft Internet Explorer VML Buffer Overflow'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115873637508150300</id><published>2006-09-20T00:11:00.000-07:00</published><updated>2006-11-15T00:13:49.016-08:00</updated><title type='text'>Mozilla Releases Firefox 1.5.0.7 to Address Seven Flaws</title><content type='html'>Mozilla released Firefox 1.5.0.7, addressing seven vulnerabilities in earlier versions of the browser. Four are rated critical, two are rated moderate and one is rated low.  The flaws could allow cross-site scripting, spoofing and man-in-the-middle attacks.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115873637508150300?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115873637508150300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115873637508150300'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/mozilla-releases-firefox-1507-to.html' title='Mozilla Releases Firefox 1.5.0.7 to Address Seven Flaws'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115873620568638065</id><published>2006-09-20T00:07:00.000-07:00</published><updated>2006-11-15T00:13:48.909-08:00</updated><title type='text'>Serious ActiveX Vulnerability in IE 5.01 and 6.0</title><content type='html'>Microsoft is investigating reports of a flaw in the Microsoft DirectAnimation Path ActiveX Control in Internet Explorer (IE) that could be exploited to allow remote code execution.  Proof-of-concept code has been published, but there are no reports of active attacks that exploit this flaw.  Microsoft recommends that until a fix is released, users disable ActiveX and active scripting controls.  The vulnerability affects IE versions 5.01 and 6.0.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115873620568638065?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115873620568638065'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115873620568638065'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/serious-activex-vulnerability-in-ie.html' title='Serious ActiveX Vulnerability in IE 5.01 and 6.0'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115813447331129240</id><published>2006-09-13T00:59:00.000-07:00</published><updated>2006-11-15T00:13:48.794-08:00</updated><title type='text'>Microsoft Windows and Publisher Vulnerabilities</title><content type='html'>Microsoft has released updates that address critical vulnerabilities in Microsoft Windows and Microsoft Publisher. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.&lt;br /&gt;Microsoft has provided updates for these vulnerabilities in the September 2006 Security Bulletins. The security bulletins describe any known issues related to the updates. Note any known issues described in the bulletins and test for any potentially adverse affects in your environment.&lt;br /&gt;Updates for Microsoft Windows and Microsoft Office XP and later are available on the Microsoft Update site. Microsoft Office 2000 updates are available on the Microsoft Office Update site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115813447331129240?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115813447331129240'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115813447331129240'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/microsoft-windows-and-publisher.html' title='Microsoft Windows and Publisher Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115813431476135526</id><published>2006-09-13T00:58:00.000-07:00</published><updated>2006-11-15T00:13:48.656-08:00</updated><title type='text'>Malicious Files on Samsung Web Site</title><content type='html'>Last week, Samsung Electronics' US web site was hosting a Trojan horse program capable of logging keystrokes and disabling antivirus software.&lt;br /&gt;Users had to be tricked into downloading the code onto their computers; there is no evidence of an exploit that downloaded the malware without user interaction.  The malicious files appear to have been removed from the site.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115813431476135526?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115813431476135526'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115813431476135526'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/malicious-files-on-samsung-web-site.html' title='Malicious Files on Samsung Web Site'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115813423765209431</id><published>2006-09-13T00:55:00.000-07:00</published><updated>2006-11-15T00:13:48.543-08:00</updated><title type='text'>Credit Card Companies Update PCI</title><content type='html'>The five major credit card companies, American Express, Discover Financial Services, JCB, MasterCard Worldwide and Visa International, have formed the Payment Card Industry Security Standards Council, marking the first time all have agreed on a common framework for payment card security. Their first order of business was to update the current PCI Data Security Standard by providing instructions for implementing the requirements and clarifying the language, for instance, replacing vague terms, such as "regularly," with specifics, such as "annually" or "quarterly."  The council's goal is "to enhance payment account security by fostering broad adoption of the PCI Data Security Standard."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115813423765209431?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115813423765209431'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115813423765209431'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/credit-card-companies-update-pci.html' title='Credit Card Companies Update PCI'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115813400035593417</id><published>2006-09-13T00:51:00.000-07:00</published><updated>2006-11-15T00:13:48.444-08:00</updated><title type='text'>Critical vulnerabilities have been identified in Flash Player that could allow an attacker who successfully exploits these vulnerabilities to take con</title><content type='html'>Systems Affected    &lt;br /&gt;Macromedia Flash Player - Version 8.0.24.0 and earlier, &lt;br /&gt;Browsers affected - Firefox, Mozilla, Netscape, Opera, Internet Explorer and CompuServe - using Macromedia Flash Player&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115813400035593417?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115813400035593417'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115813400035593417'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/critical-vulnerabilities-have-been.html' title='Critical vulnerabilities have been identified in Flash Player that could allow an attacker who successfully exploits these vulnerabilities to take con'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115804535815440927</id><published>2006-09-12T00:14:00.000-07:00</published><updated>2006-11-15T00:13:48.327-08:00</updated><title type='text'>Vulnerability in Word Could Allow Remote Code Execution</title><content type='html'>Microsoft is investigating new public reports of limited “zero-day” attacks using a vulnerability in Microsoft Word 2000. In order for this attack to be carried out, a user must first open a malicious Word file attached to an e-mail or otherwise provided to them by an attacker.&lt;br /&gt;As a best practice, users should always exercise extreme caution when opening unsolicited attachments from both known and unknown sources.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115804535815440927?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115804535815440927'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115804535815440927'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/vulnerability-in-word-could-allow.html' title='Vulnerability in Word Could Allow Remote Code Execution'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115735135756478903</id><published>2006-09-03T23:28:00.000-07:00</published><updated>2006-11-15T00:13:48.213-08:00</updated><title type='text'>Mobile Devices Hold On to Old Data</title><content type='html'>Following the directions that come with mobile devices, such as phones and PDAs, to remove data before selling or recycling them is not enough to ensure the next person who holds the device will not be able to see your private information.  Data can still be retrieved from phones that have been reset.  A security software company that purchased 10 used smartphones and PDAs on eBay found sensitive, personally identifiable information on nearly all of them.  The company plans to return all the phones to their original owners and has kept all the data it retrieved from the phones on a computer not connected to its corporate network.&lt;br /&gt;Some companies have provided stronger data wiping functions in their newer devices.&lt;br /&gt;SOURCE: SANS&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115735135756478903?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115735135756478903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115735135756478903'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/09/mobile-devices-hold-on-to-old-data.html' title='Mobile Devices Hold On to Old Data'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115703058321334476</id><published>2006-08-31T06:22:00.000-07:00</published><updated>2006-11-15T00:13:48.081-08:00</updated><title type='text'>Microsoft Tries Again on Internet Explorer Patch</title><content type='html'>Microsoft released a corrected cumulative security patch for Internet Explorer because its first patch created a vulnerability.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115703058321334476?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115703058321334476'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115703058321334476'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/08/microsoft-tries-again-on-internet.html' title='Microsoft Tries Again on Internet Explorer Patch'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115703052225042594</id><published>2006-08-31T06:20:00.000-07:00</published><updated>2006-11-15T00:13:47.958-08:00</updated><title type='text'>Cisco Warns of Flaw in Firewall Products</title><content type='html'>An alert from Cisco Systems Inc. describes an unintentional password modification vulnerability in multiple firewall products that could be exploited to change passwords without user interaction and allow "unauthorized users ... to gain access to a device that has been reloaded after passwords in its startup configuration have been changed.&lt;br /&gt;Authorized users can be locked out and lose the ability to manage the affected device."  The flaw affects Cisco PIX 500 Series Security Appliances, Cisco ASA 5500 Series Adaptive Security Appliances and Firewall Service Module (FWSM) for Cisco Catalyst 6500 switches and Cisco 7600 Series Routers running affected versions of the software.&lt;br /&gt;Cisco has issued software to address this vulnerability.  A second alert from Cisco describes a pair of flaws in Cisco VPN 3000 series concentrators with FTP file management enabled that could be exploited to execute some FTP commands and delete files.  Cisco has issued free software to address these two flaws and also made workarounds available.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115703052225042594?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115703052225042594'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115703052225042594'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/08/cisco-warns-of-flaw-in-firewall.html' title='Cisco Warns of Flaw in Firewall Products'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115510592217204978</id><published>2006-08-08T23:43:00.000-07:00</published><updated>2006-11-15T00:13:47.853-08:00</updated><title type='text'>Microsoft Patch Disclosure - August 2006</title><content type='html'>Critical&lt;br /&gt;MS06-040 - Vulnerability in Server Service Could Allow Remote Code Execution&lt;br /&gt;MS06-041 - Vulnerability in DNS Resolution Could Allow Remote Code Execution&lt;br /&gt;MS06-042 - Cumulative Security Update for Internet Explorer&lt;br /&gt;MS06-043 - Vulnerability in Microsoft Windows Could Allow Remote Code Execution&lt;br /&gt;MS06-044 - Vulnerability in Microsoft Management Console Could Allow Remote Code Execution&lt;br /&gt;MS06-046 - Vulnerability in HTML Help Could Allow Remote Code Execution&lt;br /&gt;MS06-047 - Vulnerability in Microsoft Visual Basic for Applications Could Allow Remote Code Execution&lt;br /&gt;MS06-048 - Vulnerabilities in Microsoft Office Could Allow Remote Code Execution&lt;br /&gt;MS06-051 - Vulnerability in Windows Kernel Could Result in Remote Code Execution&lt;br /&gt;Moderate&lt;br /&gt;MS06-045 - Vulnerability in Windows Explorer Could Allow Remote Code Execution&lt;br /&gt;MS06-049 - Vulnerability in Windows Kernel Could Result in Elevation of Privilege&lt;br /&gt;MS06-050 - Vulnerabilities in Microsoft Windows Hyperlink Object Library Could Allow Remote Code Execution&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115510592217204978?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='related' href='http://www.microsoft.com/technet/security/bulletin/' title='Microsoft Patch Disclosure - August 2006'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115510592217204978'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115510592217204978'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/08/microsoft-patch-disclosure-august-2006.html' title='Microsoft Patch Disclosure - August 2006'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115441435604929029</id><published>2006-07-31T23:37:00.000-07:00</published><updated>2006-11-15T00:13:47.721-08:00</updated><title type='text'>Mozilla Releases Firefox Update</title><content type='html'>On July 26, Mozilla released an update for its Firefox web browser, Firefox 1.5.0.5, to remedy a dozen flaws, seven of which are rated "critical."  Mozilla has issued advisories for each of the vulnerabilities.  The critical flaws include crashes with evidence of memory corruption, a privilege escalation flaw, JavaScript engine vulnerabilities and a memory corruption flaw in the way simultaneous XPCOM events are handled.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115441435604929029?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115441435604929029'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115441435604929029'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/07/mozilla-releases-firefox-update.html' title='Mozilla Releases Firefox Update'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115398939238826390</id><published>2006-07-27T01:35:00.000-07:00</published><updated>2006-11-15T00:13:47.599-08:00</updated><title type='text'>Zero-Day PowerPoint Flaw Already Being Exploited</title><content type='html'>Microsoft is investigating reports of a zero-day vulnerability in PowerPoint.  Users' machines would become infected only if they are tricked into opening a maliciously crafted PowerPoint document.  Attacks exploiting the flaw have already been detected; a PowerPoint attachment to spam has been found to contain the PPDDropper.b Trojan horse program, which places a backdoor called Bifrozse.e on infected computers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115398939238826390?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115398939238826390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115398939238826390'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/07/zero-day-powerpoint-flaw-already-being.html' title='Zero-Day PowerPoint Flaw Already Being Exploited'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115398930500386602</id><published>2006-07-27T01:32:00.000-07:00</published><updated>2006-11-15T00:13:47.447-08:00</updated><title type='text'>State Dept. Acknowledges Attacks on Systems</title><content type='html'>The US State Department says it is working with Carnegie Mellon University's Computer Emergency Response Team and the FBI on the investigation into cyber attacks that targeted US embassies in the East Asia-Pacific region and State Department headquarters in Washington DC.&lt;br /&gt;The systems attacked were unclassified and an initial investigation indicates "no compromise of sensitive US government information."  A department spokesperson said the attacks were not the result of problems with computer security policies.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115398930500386602?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115398930500386602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115398930500386602'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/07/state-dept-acknowledges-attacks-on.html' title='State Dept. Acknowledges Attacks on Systems'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115398612539218941</id><published>2006-07-27T00:36:00.000-07:00</published><updated>2006-11-15T00:13:47.328-08:00</updated><title type='text'>Fake Google Web Site Hides Trojan Horse</title><content type='html'>A fake Google Tool Bar can turn victims' machines into zombies if it is downloaded.  E-mails direct users to the Web site that perfectly mimics the real Google download page where the victim is offered the fake tool.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115398612539218941?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115398612539218941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115398612539218941'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/07/fake-google-web-site-hides-trojan.html' title='Fake Google Web Site Hides Trojan Horse'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115392216886481744</id><published>2006-07-26T06:52:00.000-07:00</published><updated>2006-11-15T00:13:47.149-08:00</updated><title type='text'>Microsoft Security Bulletins for July 2006</title><content type='html'>Vulnerability in Server Service Could Allow Remote Code Execution (917159)&lt;br /&gt;This update resolves two vulnerabilities in the Server service, the most serious of which could allow remote code execution.&lt;br /&gt; &lt;br /&gt;Vulnerability in DHCP Client Service Could Allow Remote Code Execution (914388)&lt;br /&gt;This update resolves a vulnerability in the DHCP Client service that could allow remote code execution.&lt;br /&gt; &lt;br /&gt;Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (917285)&lt;br /&gt;&lt;br /&gt;Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (917284)&lt;br /&gt;This update resolves two vulnerabilities in Office, the most serious of which could allow remote code execution.&lt;br /&gt;&lt;br /&gt;Vulnerabilities in Microsoft Office Filters Could Allow Remote Code Execution (915384)&lt;br /&gt;This update resolves two vulnerabilities in Office, the most serious of which could allow remote code execution.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115392216886481744?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115392216886481744'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115392216886481744'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/07/microsoft-security-bulletins-for-july.html' title='Microsoft Security Bulletins for July 2006'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115147820710558246</id><published>2006-06-28T00:01:00.000-07:00</published><updated>2006-11-15T00:13:47.034-08:00</updated><title type='text'>Buffer Overflow Flaw in Opera Browser</title><content type='html'>A buffer overflow flaw that occurs when the Opera web browser processes JPEG mages could allow remote code execution.  The problem is known to exist in Opera v.8.54 and possibly in earlier versions as well. Users are urged to upgrade to Opera 9.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115147820710558246?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115147820710558246'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115147820710558246'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/06/buffer-overflow-flaw-in-opera-browser.html' title='Buffer Overflow Flaw in Opera Browser'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115069887467168173</id><published>2006-06-18T23:33:00.000-07:00</published><updated>2006-11-15T00:13:46.864-08:00</updated><title type='text'>Exploits for Microsoft Flaws Circulating</title><content type='html'>Within a day after Microsoft's monthly security update, proof-of-concept exploits for at least five of the vulnerabilities addressed have been detected. Microsoft's June security release included twelve bulletins that addressed 21 vulnerabilities in Windows, Microsoft Office and Microsoft Exchange; eight of the bulletins received severity ratings of "critical." Some of the exploits are for flaws that had been disclosed prior to the security updates, but at least two are for flaws that were not known before the updates were released.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115069887467168173?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115069887467168173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115069887467168173'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/06/exploits-for-microsoft-flaws.html' title='Exploits for Microsoft Flaws Circulating'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115026778385603602</id><published>2006-06-13T23:48:00.000-07:00</published><updated>2006-11-15T00:13:46.730-08:00</updated><title type='text'>JS-Yamanner Worm Affects Yahoo! Mail Users</title><content type='html'>The JS-Yamanner worm collects the addresses it finds on Yahoo! Mail contact lists to spread itself; it also sends the addresses back to a remote server.  The "from" field is spoofed to make the email appear to come from av3@yahoo.com.  It spreads when users open email sent by the worm.  The vulnerability allows script embedded in HTML email to run within users' browsers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115026778385603602?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115026778385603602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115026778385603602'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/06/js-yamanner-worm-affects-yahoo-mail.html' title='JS-Yamanner Worm Affects Yahoo! Mail Users'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-115026725486157125</id><published>2006-06-13T23:39:00.000-07:00</published><updated>2006-11-15T00:13:46.603-08:00</updated><title type='text'>Microsoft Windows, Internet Explorer, Media Player, Word, and PowerPoint Vulnerabilities</title><content type='html'>Microsoft has provided an update to remedy these vulnerabilities. To obtain the update, visit the Microsoft Update web site. We also recommend enabling Automatic Updates or click &lt;a href="http://www.microsoft.com/technet/security/bulletin/ms06-jun.mspx"&gt;here&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-115026725486157125?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115026725486157125'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/115026725486157125'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/06/microsoft-windows-internet-explorer.html' title='Microsoft Windows, Internet Explorer, Media Player, Word, and PowerPoint Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114949079109701398</id><published>2006-06-04T23:57:00.000-07:00</published><updated>2006-11-15T00:13:46.446-08:00</updated><title type='text'>Mozilla Products Contain Multiple Vulnerabilities</title><content type='html'>The Firefox web browser and Thunderbird email application contain several vulnerabilities. By taking advantage of one or more of these vulnerabilities, an attacker may be able to take control of your computer.&lt;br /&gt;Solution&lt;br /&gt;Upgrade to the latest versions of Firefox and Thunberbird. Mozilla has released an updated version of Firefox and Thunberbird to corrrect these problems.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114949079109701398?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114949079109701398'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114949079109701398'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/06/mozilla-products-contain-multiple.html' title='Mozilla Products Contain Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114949060365637885</id><published>2006-06-04T23:55:00.000-07:00</published><updated>2006-11-15T00:13:46.286-08:00</updated><title type='text'>EU Court Overturns Passenger Data Agreement with US</title><content type='html'>European Court of Justice said an EU/US agreement to transfer sensitive personal data about EU airline passengers did not have an "appropriate legal basis" and invalidated the agreement. "The court ruled that because the information contained in passenger records is collected by airlines for their own commercial use, the European Union could not legally agree to provide that data to US authorities ..." US authorities had wanted EU airlines to provide them with 34 pieces of data about each traveler on board planes headed for the US and threatened hefty fines and lengthy security checks if the request was not met. The European Court of Justice has given the EU until September 30 to develop an alternative solution.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114949060365637885?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114949060365637885'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114949060365637885'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/06/eu-court-overturns-passenger-data.html' title='EU Court Overturns Passenger Data Agreement with US'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114863933585649239</id><published>2006-05-26T03:28:00.000-07:00</published><updated>2006-11-15T00:13:46.001-08:00</updated><title type='text'>Cisco Security Advisory: Windows VPN Client Local Privilege Escalation Vulnerability</title><content type='html'>The Cisco VPN Client for Windows is affected by a local privilege escalation vulnerability that allows non-privileged users to gain administrative privileges.&lt;br /&gt;A user needs to authenticate and start an interactive Windows session to be able to exploit this vulnerability.&lt;br /&gt;Cisco has made free software available to address this vulnerability for affected customers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114863933585649239?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114863933585649239'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114863933585649239'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/05/cisco-security-advisory-windows-vpn.html' title='Cisco Security Advisory: Windows VPN Client Local Privilege Escalation Vulnerability'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114838153445721538</id><published>2006-05-23T03:50:00.000-07:00</published><updated>2006-11-15T00:13:45.867-08:00</updated><title type='text'>Exploits Circulating for Zero Day Flaw in Microsoft Word</title><content type='html'>This exploit code has been targeting individuals through email messages with a malicious Microsoft Word attachment. The messages appear to come from someone within the individual's own organization, and simply opening the Word file causes the system to be exploited.&lt;br /&gt;Successful exploitation of this flaw would lead to the attacker gaining full rights in the context of the exploited user. As an example, if an exploited system was being run under Administrator privileges, then the attacker would gain Administrator privileges for that machine and be able to execute code, delete or edit files or change configuration settings.&lt;br /&gt;It should be noted that these attacks are currently extremely targeted. Across various organizations only a small handful of systems have been attacked. These emails were at least somewhat hand-crafted for the people targeted for attack. Administrative privileges are required for the exploit code to operate properly, although administrative privileges are not required for the security vulnerability itself.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114838153445721538?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114838153445721538'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114838153445721538'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/05/exploits-circulating-for-zero-day-flaw.html' title='Exploits Circulating for Zero Day Flaw in Microsoft Word'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114828304637634002</id><published>2006-05-22T00:29:00.000-07:00</published><updated>2006-11-15T00:13:45.703-08:00</updated><title type='text'>Google Fraud: Botnets Used to Steal Money From Google Advertisers</title><content type='html'>The SANS Internet Storm Center (ISC) has released evidence showing botnets are being used to defraud advertisers using Google Adword, a pay-per-click advertising system. Advertisers pay Google for each click; Google in turn pays a substantial amount of that revenue to publishers who run banners for the advertisers. Unscrupulous publishers work with the botmasters to generate high volumes of clicks and ultimately revenue. The botmasters get a share of this as well. ISC uncovered evidence of a botnet with 115 bots, each of which was clicking on sites up to 15 times a day, keeping them under the detection system's radar.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114828304637634002?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114828304637634002'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114828304637634002'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/05/google-fraud-botnets-used-to-steal.html' title='Google Fraud: Botnets Used to Steal Money From Google Advertisers'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114725245396954460</id><published>2006-05-10T02:12:00.000-07:00</published><updated>2006-11-15T00:13:45.539-08:00</updated><title type='text'>Microsoft Releases Patches on Patch Tuesday</title><content type='html'>On Tuesday, May 9, Microsoft released three security bulletins that address vulnerabilities in Microsoft Windows and Microsoft Exchange.  At least two of the flaws have been given a "critical" rating;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114725245396954460?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114725245396954460'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114725245396954460'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/05/microsoft-releases-patches-on-patch.html' title='Microsoft Releases Patches on Patch Tuesday'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114655382877742425</id><published>2006-05-02T00:09:00.000-07:00</published><updated>2006-11-15T00:13:45.389-08:00</updated><title type='text'>Symantec Warns of Flaws in Scan Engine</title><content type='html'>Symantec is encouraging its Scan Engine customers to upgrade from version 5.0 to version 5.1 following the disclosure of three vulnerabilities. The first vulnerability is due to the fact that Symantec Scan Engine does not properly authenticate web-based user logins; this flaw could be exploited to control the Scan Engine server.&lt;br /&gt;The second flaw involves a static private DSA key for SSL communications and could be exploited by a man-in-the-middle attack. The third flaw allows unauthenticated remote users to download files located under the Scan Engine installation directory.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114655382877742425?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114655382877742425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114655382877742425'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/05/symantec-warns-of-flaws-in-scan-engine.html' title='Symantec Warns of Flaws in Scan Engine'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114655377007485829</id><published>2006-05-02T00:02:00.000-07:00</published><updated>2006-11-15T00:13:45.263-08:00</updated><title type='text'>Cisco Issues Fixes for Multiple Flaws</title><content type='html'>Cisco Systems has issued patches for several vulnerabilities in a number of its products, including CiscoWorks Wireless LAN Solution Engine (WLSE), Hosting Solution Engine, User Registration Tool, Ethernet Subscriber Solution Engine and CiscoWorks 2000 Service Management Solution.  Cisco did not issue patches for the last two products as they have been discontinued and are no longer supported. &lt;br /&gt;In addition, Cisco issued an advisory for a cross-site scripting flaw in WLSE running software earlier than version 2.13.  Another advisory addresses a Multi Protocol Label Switching (MPLS)-related flaw on the Cisco IOS XR modular operating platform that could be exploited to cause a denial-of-service condition.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114655377007485829?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114655377007485829'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114655377007485829'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/05/cisco-issues-fixes-for-multiple-flaws.html' title='Cisco Issues Fixes for Multiple Flaws'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114551907325679177</id><published>2006-04-20T00:40:00.000-07:00</published><updated>2006-11-15T00:13:45.105-08:00</updated><title type='text'>Oracle Products Contain Multiple Vulnerabilities</title><content type='html'>Oracle has released Critical Patch Update - April 2006. This update addresses more than thirty vulnerabilities in different Oracle products and components.&lt;br /&gt;The Critical Patch Update provides information about affected components, access and authorization required, and the impact of the vulnerabilities on data confidentiality, integrity, and availability.&lt;br /&gt;According to Oracle, none of the vulnerabilities corrected in the Oracle Critical Patch Update affect Oracle Database Client-only installations.&lt;br /&gt;The Oracle Database, Oracle Application Server, Oracle Enterprise Manager Grid Control, Oracle Collaboration Suite, JD Edwards EnterpriseOne and OneWorld Tools, and PeopleSoft Enterprise Portal Applications patches in the Updates are cumulative; each successive. Critical Patch Update contains the fixes from the previous Critical Patch Updates.&lt;br /&gt;Oracle E-Business Suite and Applications patches are not cumulative, so E-Business Suite and Applications customers should refer to previous Critical Patch Updates to identify previous fixes they wish to apply.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114551907325679177?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114551907325679177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114551907325679177'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/04/oracle-products-contain-multiple.html' title='Oracle Products Contain Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114543336125115579</id><published>2006-04-19T00:36:00.000-07:00</published><updated>2006-11-15T00:13:44.940-08:00</updated><title type='text'>Mozilla Releases Firefox Updates</title><content type='html'>Mozilla has released an updated version of its Firefox browser, Firefox 1.5.0.2, which includes support for Mac OS X running on Intel processors. Mozilla says the update is a "stability and security" release because it includes fixes for critical security flaws as well as other problems. Mozilla also released fixes for flaws in older versions of Firefox and in the Sea Monkey browser suite. Some of the Firefox flaws could be exploited by simply tricking users into viewing maliciously crafted web pages.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114543336125115579?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114543336125115579'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114543336125115579'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/04/mozilla-releases-firefox-updates.html' title='Mozilla Releases Firefox Updates'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114482707423216652</id><published>2006-04-12T00:29:00.000-07:00</published><updated>2006-11-15T00:13:44.816-08:00</updated><title type='text'>Microsoft has released updates that address critical vulnerabilities in Windows and Internet Explorer.</title><content type='html'>Microsoft has released updates that address critical vulnerabilities in Microsoft Windows and Internet Explorer. Exploitation of these vulnerabilities could allow a remote, unauthenticated attacker to execute arbitrary code or cause a denial of service on a vulnerable system.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114482707423216652?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114482707423216652'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114482707423216652'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/04/microsoft-has-released-updates-that.html' title='Microsoft has released updates that address critical vulnerabilities in Windows and Internet Explorer.'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114422138181117824</id><published>2006-04-05T00:15:00.000-07:00</published><updated>2006-11-15T00:13:44.671-08:00</updated><title type='text'>Microsoft Extends Support for Older Version of MBSA</title><content type='html'>In a bow to customer pressure, Microsoft has extended support for the Microsoft Baseline Security Analyzer (MBSA) version 1.2 indefinitely.&lt;br /&gt;Microsoft initially said it would end support for the tool on March 31, 2006, but feedback from customers made it clear that to discontinue support "would create a gap in security update detection for Microsoft products." MBSA is a free tool that scans computers for vulnerabilities with available Microsoft patches. MBSA 2.0, released in July 2005, fails to detect the need for patches in certain Microsoft products.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114422138181117824?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114422138181117824'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114422138181117824'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/04/microsoft-extends-support-for-older.html' title='Microsoft Extends Support for Older Version of MBSA'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114421928160178745</id><published>2006-04-04T23:40:00.000-07:00</published><updated>2006-11-15T00:13:44.525-08:00</updated><title type='text'>Attackers Hone IE TextRange() Exploit</title><content type='html'>A "new generation" of exploit code that takes advantage of the TextRange() vulnerability in Microsoft's Internet Explorer (IE) has been posted to the Internet. When the older exploits attempted to install keystroke loggers on vulnerable machines, they froze browsers for noticeable periods of time, allowing users to shut down their computers and avoid being infected with the malware. The new exploit is faster and employs techniques to evade antivirus signatures.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114421928160178745?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114421928160178745'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114421928160178745'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/04/attackers-hone-ie-textrange-exploit.html' title='Attackers Hone IE TextRange() Exploit'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114421882256267436</id><published>2006-04-04T23:32:00.000-07:00</published><updated>2006-11-15T00:13:44.384-08:00</updated><title type='text'>Zero-Day IE Flaw Exposes Holes in Microsoft's Security Patch Process</title><content type='html'>Cyber criminals are now using spam in an attempt to spread malware that exploits an unpatched critical vulnerability in Microsoft's Internet Explorer (IE). The spam tries to lure people to maliciously crafted web sites; the sites download software that captures bank account log-in data onto victims' computers and transmits them to the thieves.&lt;br /&gt;Microsoft encourages users to disable active scripting pending the availability of a legitimate patch. The emergence of zero-day vulnerabilities illuminates problems with Microsoft's monthly security releases. An executive with a company that released a third-party patch for the flaw says he understands Microsoft's need to test, but that Microsoft should also provide some sort of faster protection for the interim, perhaps a "beta" patch.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114421882256267436?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114421882256267436'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114421882256267436'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/04/zero-day-ie-flaw-exposes-holes-in.html' title='Zero-Day IE Flaw Exposes Holes in Microsoft&apos;s Security Patch Process'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114370347961713764</id><published>2006-03-29T23:21:00.000-08:00</published><updated>2006-11-15T00:13:44.190-08:00</updated><title type='text'>Web Sites Exploiting IE Flaw; Microsoft Working On Fix</title><content type='html'>There are reports that web sites are already exploiting the Internet Explorer TextRange () flaw to install spyware on vulnerable computers.&lt;br /&gt;As of Monday morning, more than 200 such sites have been detected.  The flaw exists in IE 6 and IE 7 beta 2; this marks the third IE vulnerability disclosed in one week.  Microsoft is developing a fix.&lt;br /&gt;Users are advised to disable Active Scripting in IE.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114370347961713764?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114370347961713764'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114370347961713764'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/03/web-sites-exploiting-ie-flaw-microsoft.html' title='Web Sites Exploiting IE Flaw; Microsoft Working On Fix'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114240936437566776</id><published>2006-03-14T23:55:00.000-08:00</published><updated>2006-11-15T00:13:44.069-08:00</updated><title type='text'>Windows Media Player Patches Pose Problems</title><content type='html'>Microsoft has issued an advisory warning that three previously released patches for Windows Media Player 10 can be problematic.  WMP users who have installed the patches may experience trouble seeking, rewinding and fast-forwarding files. One of the patches was released in February in MS06-005 and was deemed a "critical" fix.  The other two patches in question were released in October 2005. Microsoft suggests two workarounds.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114240936437566776?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114240936437566776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114240936437566776'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/03/windows-media-player-patches-pose.html' title='Windows Media Player Patches Pose Problems'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114240930866031137</id><published>2006-03-14T23:54:00.000-08:00</published><updated>2006-11-15T00:13:43.941-08:00</updated><title type='text'>Microsoft March Security Update Includes Critical Microsoft Office Fix</title><content type='html'>In Microsoft's monthly security update two security bulletins will describe fixes; one addresses a "critical" flaw in Microsoft Office.&lt;br /&gt;The second bulletin will address flaws in Windows and has an "important"&lt;br /&gt;rating. Microsoft will release the bulletins on Tuesday, March 14 along with an updated version of Windows' malicious software removal tool and one non-security, high-priority update.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114240930866031137?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114240930866031137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114240930866031137'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/03/microsoft-march-security-update.html' title='Microsoft March Security Update Includes Critical Microsoft Office Fix'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114240918045105565</id><published>2006-03-14T23:52:00.000-08:00</published><updated>2006-11-15T00:13:43.797-08:00</updated><title type='text'>Citibank Acknowledges ATM Network Penetrated</title><content type='html'>Citibank acknowledged last week that attackers infiltrated its ATM network in Canada, Russia and the United Kingdom, and stole a block of PINs (personal identification numbers). Sophisticated hackers use the PINs to create counterfeit cards and steal money.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114240918045105565?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114240918045105565'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114240918045105565'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/03/citibank-acknowledges-atm-network.html' title='Citibank Acknowledges ATM Network Penetrated'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114173972202628268</id><published>2006-03-07T05:54:00.000-08:00</published><updated>2006-11-15T00:13:43.598-08:00</updated><title type='text'>DDoS Attackers Turn to High Profile Blogs</title><content type='html'>High profile blogs have been targeted by distributed denial of service&lt;br /&gt;(DDoS) attacks in recent weeks.  Some speculate that the attackers are broadening their range of targets, which until now has included on line betting sites and online games to include profitable and politically focused blogs.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114173972202628268?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114173972202628268'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114173972202628268'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/03/ddos-attackers-turn-to-high-profile.html' title='DDoS Attackers Turn to High Profile Blogs'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114173962928686390</id><published>2006-03-07T05:53:00.000-08:00</published><updated>2006-11-15T00:13:43.442-08:00</updated><title type='text'>Apple Security Update Addresses 20 Flaws, Including Safari Hole</title><content type='html'>Apple has released Security Update 2006-001, which fixes 20 flaws in Mac OS X, including vulnerabilities that could be exploited to install malware through the Safari web browser.  Apple has issued updates for OS X v10.3.9, OS X Server v10.3.9, OS X v10.4.5 and OS X Server v10.4.5.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114173962928686390?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114173962928686390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114173962928686390'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/03/apple-security-update-addresses-20.html' title='Apple Security Update Addresses 20 Flaws, Including Safari Hole'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114102994645535117</id><published>2006-02-27T00:45:00.000-08:00</published><updated>2006-11-15T00:13:43.330-08:00</updated><title type='text'>eDonkey Server Shut Down</title><content type='html'>Police raids in Belgium and Switzerland have shut down Razorback2, believed to be one of the largest index servers on the eDonkey file sharing network.  The servers held an index of an estimated 170 million pirated files, according to RIAA. The server's owner was arrested in Switzerland; equipment was seized in Belgium.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114102994645535117?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114102994645535117'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114102994645535117'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/edonkey-server-shut-down.html' title='eDonkey Server Shut Down'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114068262806643423</id><published>2006-02-23T00:11:00.000-08:00</published><updated>2006-11-15T00:13:43.195-08:00</updated><title type='text'>Apple Mac OS X Safari Command Execution Vulnerability</title><content type='html'>Apple Safari is a web browser that comes with Apple Mac OS X. Safari contains a vulnerability that could allow an attacker to run malicious programs on your computer.&lt;br /&gt;Solution&lt;br /&gt;Turn off "Open safe files after downloading" feature&lt;br /&gt;To turn off "Open safe files after downloading" feature in Safari, first choose "Preferences" from the Safari menu. Next, uncheck the option "Open 'safe' files after downloading."&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114068262806643423?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114068262806643423'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114068262806643423'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/apple-mac-os-x-safari-command.html' title='Apple Mac OS X Safari Command Execution Vulnerability'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114059980464388691</id><published>2006-02-22T01:16:00.000-08:00</published><updated>2006-11-15T00:13:43.013-08:00</updated><title type='text'>Microsoft Decries iDefense's Offer of Cash for Critical Windows Holes</title><content type='html'>Microsoft has spoken out against iDefense's offer to pay US$10,000 to people who find and reveal to them critical vulnerabilities in Windows.&lt;br /&gt;According to a Microsoft spokesperson, the company "does not believe that offering compensation for vulnerability information is the best way [to] protect customers," and instead prefers that "researchers" ensure a fix is available from vendors before disclosing the details of a vulnerability.  iDefense says it believes their offer "promotes the concept of responsible disclosure."  iDefense Labs Michael Sutton said he finds it curious that Microsoft's Antivirus Reward Program offers US$250,000 for information leading to the arrest and conviction of malware writers, but is opposed to iDefense's program.  Peter Mell, who manages the National Vulnerability Database (NVD) at the National Institute of Standards and Technology (NIST), says iDefense's program could skew bug hunters' attention to certain vendors rather than helping improve security in the industry.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114059980464388691?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114059980464388691'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114059980464388691'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/microsoft-decries-idefenses-offer-of.html' title='Microsoft Decries iDefense&apos;s Offer of Cash for Critical Windows Holes'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114059975850265132</id><published>2006-02-22T00:47:00.000-08:00</published><updated>2006-11-15T00:13:42.810-08:00</updated><title type='text'>Google Files Formal Rejection of Government Request for Search Data</title><content type='html'>Google has filed court documents over the weekend with a federal judge in San Jose formally rejecting the US government's request for search data.  The documents say Google believes providing that information to the government would violate users' privacy and expose the company's trade secrets.  Google goes on to say that the information requested would not "accomplish what the government wanted."  The requests were made by the Department of Justice (DoJ) to demonstrate that voluntary regulation is not preventing minors from accessing inappropriate web content and appeal the injunction against a law that would impose penalties on web site operators who allow minors to view inappropriate material.  The American Civil Liberties Union (ACLU) has filed an amicus brief on behalf of Google.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114059975850265132?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114059975850265132'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114059975850265132'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/google-files-formal-rejection-of.html' title='Google Files Formal Rejection of Government Request for Search Data'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114018476555925767</id><published>2006-02-17T05:53:00.000-08:00</published><updated>2006-11-15T00:13:42.576-08:00</updated><title type='text'>Microsoft Patch Disclosure - February 2006</title><content type='html'>Critical&lt;br /&gt;MS06-004 - Cumulative Security Update for Internet Explorer&lt;br /&gt;MS06-005 - Vulnerability in Windows Media Player Could Allow Remote Code Execution&lt;br /&gt;Important&lt;br /&gt;MS06-006 - Vulnerability in Windows Media Player Plug-in with Non-Microsoft Internet Browsers Could Allow Remote Code Execution&lt;br /&gt;MS06-007 - Vulnerability in TCP/IP Could Allow Denial of Service&lt;br /&gt;MS06-008 - Vulnerability in Web Client Service Could Allow Remote Code Execution&lt;br /&gt;MS06-009 - Vulnerability in the Korean Input Method Editor Could Allow Elevation of Privilege&lt;br /&gt;MS06-010 - Vulnerability in PowerPoint 2000 Could Allow Information Disclosure&lt;br /&gt;&lt;br /&gt;http://www.microsoft.com/technet/security/bulletin/ms06-feb.mspx&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114018476555925767?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114018476555925767'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114018476555925767'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/microsoft-patch-disclosure-february.html' title='Microsoft Patch Disclosure - February 2006'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114018432930862754</id><published>2006-02-17T05:51:00.000-08:00</published><updated>2006-11-15T00:13:42.361-08:00</updated><title type='text'>Bluetooth Vulnerability Leaves Some Sony Ericsson Phones Susceptible</title><content type='html'>A vulnerability in several models of Sony Ericsson mobile phones could be remotely exploited to cause denial-of-service on the devices.  The flaw lies in an error in Bluetooth that does not properly handle malformed L2CAP (Logical Link Control and Adaptation Layer Protocols).&lt;br /&gt;Malformed code could crash the phones; when they are restarted, they would have normal functionality.  Users are advised to turn off the "discoverable mode" in their Bluetooth settings.  The flaw affects Sony Ericsson models K600i, V600i, W800i and T68i.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114018432930862754?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114018432930862754'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114018432930862754'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/bluetooth-vulnerability-leaves-some.html' title='Bluetooth Vulnerability Leaves Some Sony Ericsson Phones Susceptible'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114018425256159523</id><published>2006-02-17T05:49:00.000-08:00</published><updated>2006-11-15T00:13:42.180-08:00</updated><title type='text'>Microsoft Fixes Flaw that Misidentified Symantec Programs as Spyware</title><content type='html'>Microsoft has fixed a problem with a signature update to its Windows AntiSpyware program that erroneously identified two Symantec antivirus programs as spyware and recommended their removal.  The flaw lies in a signature update for Windows AntiSpyware Beta 1.  The program prompts users to remove registry keys and subkeys essential to the Symantec products.  The update that contains the problem is signature set 5805; the problem is fixed in a newly issued signature set, 5807.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114018425256159523?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114018425256159523'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114018425256159523'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/microsoft-fixes-flaw-that.html' title='Microsoft Fixes Flaw that Misidentified Symantec Programs as Spyware'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-114018389057083015</id><published>2006-02-17T05:42:00.000-08:00</published><updated>2006-11-15T00:13:41.952-08:00</updated><title type='text'>Sun Addresses Privilege Escalation Vulnerability in JRE</title><content type='html'>Sun Microsystems has released updated versions of its Java Runtime Environment (JRE) to address seven critical security flaws.  The flaws lie in problems with the "reflection" APIs and could be exploited with maliciously crafted applets to read and write files on hard drives of vulnerable systems and to execute programs.  Affected versions include JRE 1.3.1_16 and earlier, JRE 1.4.2_09 and earlier and JRE 5.0 Update 4 and earlier.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-114018389057083015?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114018389057083015'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/114018389057083015'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/sun-addresses-privilege-escalation.html' title='Sun Addresses Privilege Escalation Vulnerability in JRE'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113938672520205373</id><published>2006-02-08T00:15:00.000-08:00</published><updated>2006-11-15T00:13:41.542-08:00</updated><title type='text'>Multiple Vulnerabilities in Mozilla Products</title><content type='html'>Several vulnerabilities exist in the Mozilla web browser and derived products, the most serious of which could allow a remote attacker to execute arbitrary code on an affected system.&lt;br /&gt;Several vulnerabilities have been reported in the Mozilla web browser and derived products. &lt;br /&gt;The most severe impact of these vulnerabilities could allow a remote attacker to execute arbitrary code with the privileges of the user running the affected application. Other impacts include a denial of service or local information disclosure.&lt;br /&gt;Solution&lt;br /&gt;Upgrade to Mozilla Firefox 1.5.0.1 or SeaMonkey 1.0.&lt;br /&gt;For Mozilla-based products that have no updates available, users are strongly encouraged to disable JavaScript.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113938672520205373?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113938672520205373'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113938672520205373'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/multiple-vulnerabilities-in-mozilla.html' title='Multiple Vulnerabilities in Mozilla Products'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113938642625323331</id><published>2006-02-08T00:05:00.000-08:00</published><updated>2006-11-15T00:13:41.391-08:00</updated><title type='text'>Mobile Phone Tapping Affected Greek PM and Other Government Officials</title><content type='html'>The Greek government has acknowledged that several of the country's top officials, including Prime Minister Costas Karamanlis, "have had their mobile phones tapped for more than a year." The scheme involved installing spy software on the Vodaphone central system that diverted calls to hard to trace pay-as-you-go mobile phones. An investigation is underway, but authorities have not determined who is conducting the surveillance.  A total of approximately 100 phones belonging to Greek politicians are believed to be involved.  The taps reportedly started before the 2004 Athens Olympics and continued through March 2005, when the scheme was discovered.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113938642625323331?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113938642625323331'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113938642625323331'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/mobile-phone-tapping-affected-greek-pm.html' title='Mobile Phone Tapping Affected Greek PM and Other Government Officials'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113921693889195808</id><published>2006-02-06T01:08:00.000-08:00</published><updated>2006-11-15T00:13:41.285-08:00</updated><title type='text'>Flaws Found in IE 7 Beta 2</title><content type='html'>Within hours of Microsoft's release of the beta 2 preview of Internet Explorer (IE) 7, a flaw was found in the code that could crash the browser.  The flaw could potentially be exploited to execute arbitrary code on vulnerable machines, according to the person who discovered the flaw, though a posting on Microsoft's IE development blog refutes that claim.  Microsoft says that they are already developing a fix for the flaw.  There have also been reports of installation trouble related to certain anti-spyware and antivirus tools.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113921693889195808?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113921693889195808'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113921693889195808'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/flaws-found-in-ie-7-beta-2.html' title='Flaws Found in IE 7 Beta 2'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113921687586322720</id><published>2006-02-06T00:41:00.000-08:00</published><updated>2006-11-15T00:13:41.188-08:00</updated><title type='text'>Mozilla Releases Firefox 1.5.0.1</title><content type='html'>Mozilla is urging Firefox users to upgrade to Firefox version 1.5.0.1.&lt;br /&gt;The updated version of the browser addresses a number of security flaws including a denial-of-service vulnerability and several "stability"&lt;br /&gt;fixes that are aimed at repairing issues of the browser hindering system performance.  Firefox 1.5.0.1 is being pushed out as an automatic update; this is the first time Mozilla has used the automatic update feature for Firefox.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113921687586322720?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113921687586322720'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113921687586322720'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/mozilla-releases-firefox-1501.html' title='Mozilla Releases Firefox 1.5.0.1'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113896901587121584</id><published>2006-02-03T04:13:00.000-08:00</published><updated>2006-11-15T00:13:41.060-08:00</updated><title type='text'>ChoicePoint Settlement Imposes UD$15 Million Fine</title><content type='html'>The Federal Trade Commission (FTC) has unanimously approved a settlement with ChoicePoint which the identity verification service must pay fines of US$15 million, the largest civil penalty in US history.  US$10 million is an FTC fine, the additional US$5 million is designated for customer compensation.  Under the terms of the settlement, ChoicePoint must also undergo independent security audits every two years until 2026.  The FTC charged that ChoicePoint's "security processes and data handling violated privacy rights and federal laws."  The settlement also requires that ChoicePoint create "a comprehensive security program, and implement new procedures to ensure that only legitimate businesses obtain consumer reports."  ChoicePoint sold data to customers who lied about their credentials, according to FTC charges.  The US Securities and Exchange Commission (SEC) is looking into share trades made by ChoicePoint CEO Derek V. Smith and COO Doug Curling both of whom allegedly made considerable profits in the months following their knowledge of the security breach but before it became public.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113896901587121584?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113896901587121584'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113896901587121584'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/choicepoint-settlement-imposes-ud15.html' title='ChoicePoint Settlement Imposes UD$15 Million Fine'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113896871389796983</id><published>2006-02-03T04:07:00.000-08:00</published><updated>2006-11-15T00:13:40.911-08:00</updated><title type='text'>Winamp Playlist Buffer Overflow</title><content type='html'>Winamp 5.13 resolves a buffer overflow vulnerability in how playlist files are handled. &lt;br /&gt;Winamp fails to properly handle playlists with long computer names&lt;br /&gt;Winamp contains a buffer overflow vulnerability when processing a playlist that specifies a long computer name. This may allow a remote unauthenticated attacker to execute arbitrary code on a vulnerable system.&lt;br /&gt;By convincing a user to open a specially crafted playlist file, a remote unauthenticated attacker may be able to execute arbitrary code with the privileges of the user. Winamp may open a playlist file without any user interaction as the result of viewing a web page or other HTML document.&lt;br /&gt;The solution is to upgrade to Winamp 5.13.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113896871389796983?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113896871389796983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113896871389796983'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/02/winamp-playlist-buffer-overflow.html' title='Winamp Playlist Buffer Overflow'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113834874974311213</id><published>2006-01-26T23:57:00.000-08:00</published><updated>2006-11-15T00:13:40.768-08:00</updated><title type='text'>Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack</title><content type='html'>The Cisco VPN 3000 series concentrators are a family of purpose-built, remote access Virtual Private Network (VPN) platforms for data encryption and authentication.&lt;br /&gt;A malicious user may be able to send a crafted HTTP (Hypertext Transfer Protocol) packet to the concentrators which may cause the device to reload and drop user connections.&lt;br /&gt;Repeated exploitation of this vulnerability will create a sustained DoS (denial of service).&lt;br /&gt;Cisco has made free software available to address this vulnerability for affected customers.This advisory is posted at&lt;br /&gt;http://www.cisco.com/warp/public/707/cisco-sa-20060126-vpn.shtml&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113834874974311213?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113834874974311213'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113834874974311213'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/cisco-vpn-3000-concentrator-vulnerable.html' title='Cisco VPN 3000 Concentrator Vulnerable to Crafted HTTP Attack'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113817844325046593</id><published>2006-01-25T00:40:00.000-08:00</published><updated>2006-11-15T00:13:40.621-08:00</updated><title type='text'>Eight Arrested in Connection with Phishing Ring</title><content type='html'>Eight people have been arrested in Bulgaria on charges they are involved with a group responsible for sending a phishing email.  The group allegedly operated a number of phony Microsoft web sites; the phony email was sent with addresses spoofed to appear they came from Microsoft billing account management.  Recipients were asked to divulge credit card information that ring members allegedly used to buy goods and make wire transfers.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113817844325046593?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113817844325046593'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113817844325046593'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/eight-arrested-in-connection-with.html' title='Eight Arrested in Connection with Phishing Ring'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113817793235082561</id><published>2006-01-24T23:34:00.000-08:00</published><updated>2006-11-15T00:13:40.521-08:00</updated><title type='text'>Google Refusing to Comply with Government Request for Search Data</title><content type='html'>Google is resisting government requests for data on its search engine usage.  The two requests the government has made are for a random sample of 1 million web site addresses in its search engine index and for the text of all queries made on the search engine during a specific week.&lt;br /&gt;The government maintains it needs the records from Google to prepare its defense in a lawsuit brought by the American Civil Liberties Union. The lawsuit challenges the Child Online Protection Act (COPA) on the grounds that it violates the First Amendment. The government wants the information to help support its claim that COPA is stronger than Internet content filtering in efforts to prevent minors from accessing pornographic Internet content. &lt;br /&gt;Google believes the government's demand for information is overreaching. Other search engine operators, including Microsoft's MSN and Yahoo, have complied with the government's request for search data.  Both say no personal information was revealed.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113817793235082561?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113817793235082561'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113817793235082561'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/google-refusing-to-comply-with.html' title='Google Refusing to Comply with Government Request for Search Data'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113800228106633034</id><published>2006-01-22T23:44:00.000-08:00</published><updated>2006-11-15T00:13:40.410-08:00</updated><title type='text'>Windows XP SP3 Due Out in Second Half of 2007</title><content type='html'>&lt;div align="justify"&gt;Microsoft has set a tentative release date of the second half of 2007 for Windows XP Service Pack 3 (SP3) the professional and home editions.&lt;br /&gt;Windows XP SP2 was released in 2004. Microsoft reportedly pushed back the release date for XP SP3 to allow them to concentrate resources on Windows Vista, which is scheduled to be released later this year.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113800228106633034?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113800228106633034'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113800228106633034'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/windows-xp-sp3-due-out-in-second-half.html' title='Windows XP SP3 Due Out in Second Half of 2007'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113800222233499114</id><published>2006-01-22T23:40:00.000-08:00</published><updated>2006-11-15T00:13:40.302-08:00</updated><title type='text'>F-Secure Has Fixes Available for DoS and Code Execution Flaws</title><content type='html'>&lt;div align="justify"&gt;F-Secure has warned of several vulnerabilities in its products that could be exploited to cause denial-of-service or execute malicious code.&lt;br /&gt;One of the flaws is a boundary error in .zip archive handling that could allow the execution of arbitrary code; a problem with .rar and .zip archive processing scanning functionality could allow malware to escape detection. Attackers could exploit the vulnerabilities with specially crafted archives. The company has fixes available for the &lt;a href="http://www.f-secure.com/security/fsc-2006-1.shtml"&gt;flaws&lt;/a&gt;.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113800222233499114?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113800222233499114'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113800222233499114'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/f-secure-has-fixes-available-for-dos.html' title='F-Secure Has Fixes Available for DoS and Code Execution Flaws'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113765753012896783</id><published>2006-01-18T23:53:00.000-08:00</published><updated>2006-11-15T00:13:40.202-08:00</updated><title type='text'>Oracle Products Contain Multiple Vulnerabilities</title><content type='html'>&lt;div align="justify"&gt;Various Oracle products and components are affected by multiple vulnerabilities. The impacts of these vulnerabilities include remote execution of arbitrary code, information disclosure, and denial of service.&lt;/div&gt;&lt;div align="justify"&gt;Oracle has released Critical Patch Update - January 2006. This update addresses more than eighty vulnerabilities in different Oracle products and components.&lt;br /&gt;The Critical Patch Update provides information about affected components, access and authorization required, and the impact of the vulnerabilities on data confidentiality, integrity, and availability.&lt;br /&gt;According to Oracle, three of the vulnerabilities corrected un the Oracle Critical Patch Update for January 2006 affect Oracle Database Client-only installations.&lt;/div&gt;&lt;div align="justify"&gt;The impact of these vulnerabilities varies depending on the product, component, and configuration of the system. Potential consequences include the execution of arbitrary code or commands, information disclosure, and denial of service. Vulnerable components are likely to be available to attackers via remote networks and with limited or no prior authorization. An attacker who compromises an Oracle database may be able to gain access to sensitive information.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113765753012896783?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113765753012896783'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113765753012896783'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/oracle-products-contain-multiple.html' title='Oracle Products Contain Multiple Vulnerabilities'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113765720202927958</id><published>2006-01-18T23:50:00.000-08:00</published><updated>2006-11-15T00:13:40.100-08:00</updated><title type='text'>IOS Stack Group Bidding Protocol Crafted Packet DoS</title><content type='html'>&lt;div align="justify"&gt;The Cisco IOS Stack Group Bidding Protocol (SGBP) feature in certain versions of Cisco IOS software is vulnerable to a remotely-exploitable denial of service condition. Devices that do not support or have not enabled the SGBP protocol are not affected by this vulnerability.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113765720202927958?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113765720202927958'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113765720202927958'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/ios-stack-group-bidding-protocol.html' title='IOS Stack Group Bidding Protocol Crafted Packet DoS'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113765698469955864</id><published>2006-01-18T23:48:00.000-08:00</published><updated>2006-11-15T00:13:39.979-08:00</updated><title type='text'>Cisco Call Manager Denial of Service</title><content type='html'>&lt;div align="justify"&gt;Cisco CallManager (CCM) is the software-based call-processing component of the Cisco IP telephony solution which extends enterprise telephony features and functions to packet telephony network devices such as IP phones, media processing devices, voice-over-IP (VoIP) gateways, and multimedia applications. All Cisco CallManager versions are vulnerable to these Denial of Service (DoS) attacks, which may result in services being interrupted or servers rebooting.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113765698469955864?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113765698469955864'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113765698469955864'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/cisco-call-manager-denial-of-service.html' title='Cisco Call Manager Denial of Service'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-11073050.post-113759499988309383</id><published>2006-01-18T06:35:00.000-08:00</published><updated>2006-11-15T00:13:38.343-08:00</updated><title type='text'>Windows Wi-Fi Vulnerability</title><content type='html'>&lt;div align="justify"&gt;A flaw in a Windows XP and 2000 feature that automatically searches for Wi-Fi connections could be exploited to put vulnerable computers in peer-to-peer networks, potentially exposing the contents of their hard drives. When computers running these operating systems are turned on, they automatically search for a Wi-Fi connection; if none is found, they create an ad hoc connection to a local address using the SSID from the last successful connection and broadcast the SSID in an attempt to search for other computers to connect to. If an attacker is listening for this type of broadcast, he can create a network connection with the same SSID that would allow the machines to associate and give the attacker access to files on the user's PC. Users with firewalls are protected; users running Windows XP SP2 are not at risk. Users can protect their computers by disabling Wi-Fi when they are not using it.&lt;br /&gt;In addition, system administrators should block ports 135, 137, 138 and&lt;br /&gt;139 from accepting NetBIOS connections.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/11073050-113759499988309383?l=secure-net.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113759499988309383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/11073050/posts/default/113759499988309383'/><link rel='alternate' type='text/html' href='http://secure-net.blogspot.com/2006/01/windows-wi-fi-vulnerability.html' title='Windows Wi-Fi Vulnerability'/><author><name>Agapitos Chrysochoos</name><uri>http://www.blogger.com/profile/10797035022923084936</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='20' height='32' src='http://bp1.blogger.com/_FDLkKY8kALQ/R4W-ifM5gPI/AAAAAAAAAAY/G2mTffDJp6E/S220/achr.jpg'/></author></entry></feed>
