<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments for The GANSEC Security Weblog</title>
	<atom:link href="http://gansec.com/blog/?feed=comments-rss2" rel="self" type="application/rss+xml" />
	<link>http://gansec.com/blog</link>
	<description>The official Weblog of Georgia Network Security Consulting, LLC.</description>
	<lastBuildDate>Thu, 09 Feb 2012 02:51:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Comment on Trendnet home security cam flaw exposes video feeds on net by Trendnet</title>
		<link>http://gansec.com/blog/?p=429&#038;cpage=1#comment-9821</link>
		<dc:creator>Trendnet</dc:creator>
		<pubDate>Thu, 09 Feb 2012 02:51:08 +0000</pubDate>
		<guid isPermaLink="false">http://gansec.com/blog/?p=429#comment-9821</guid>
		<description>TRENDnet has posted the resolution to the security breach on their IP cameras. You can check information on affected TRENDnet IP cameras at: http://www.trendnet.com/products/features.asp?featureid=52. You can download critical firmware along with detailed update instructions for the affected TRENDnet IP cameras at http://www.trendnet.com/downloads/.</description>
		<content:encoded><![CDATA[<p>TRENDnet has posted the resolution to the security breach on their IP cameras. You can check information on affected TRENDnet IP cameras at: <a href="http://www.trendnet.com/products/features.asp?featureid=52" rel="nofollow">http://www.trendnet.com/products/features.asp?featureid=52</a>. You can download critical firmware along with detailed update instructions for the affected TRENDnet IP cameras at <a href="http://www.trendnet.com/downloads/" rel="nofollow">http://www.trendnet.com/downloads/</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Verisign hacked several times in 2010, didn&#8217;t disclose until now by Verisign hacked several times in 2010, didn’t disclose until now &#124; Broadland Security</title>
		<link>http://gansec.com/blog/?p=424&#038;cpage=1#comment-9632</link>
		<dc:creator>Verisign hacked several times in 2010, didn’t disclose until now &#124; Broadland Security</dc:creator>
		<pubDate>Sat, 04 Feb 2012 00:01:40 +0000</pubDate>
		<guid isPermaLink="false">http://gansec.com/blog/?p=424#comment-9632</guid>
		<description>[...] post: Verisign hacked several times in 2010, didn’t disclose until now Share on beboBlog this!Bookmark on DeliciousDigg this postShare on dzoneRecommend on FacebookShare [...]</description>
		<content:encoded><![CDATA[<p>[...] post: Verisign hacked several times in 2010, didn’t disclose until now Share on beboBlog this!Bookmark on DeliciousDigg this postShare on dzoneRecommend on FacebookShare [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Honda&#8217;s Customer Database breached &#8211; millions of email addresses and VIN numbers leaked by Japanese Automaker Honda Data Breach Affects 4.9 Million Customers &#124; Alertsec Xpress Data Security Blog</title>
		<link>http://gansec.com/blog/?p=312&#038;cpage=1#comment-1520</link>
		<dc:creator>Japanese Automaker Honda Data Breach Affects 4.9 Million Customers &#124; Alertsec Xpress Data Security Blog</dc:creator>
		<pubDate>Thu, 06 Jan 2011 16:36:26 +0000</pubDate>
		<guid isPermaLink="false">http://gansec.com/blog/?p=312#comment-1520</guid>
		<description>[...] Honda&#8217;s Customer Database breached &#8211; millions of email addresses and VIN numbers leaked (gansec.com) [...]</description>
		<content:encoded><![CDATA[<p>[...] Honda&#8217;s Customer Database breached &#8211; millions of email addresses and VIN numbers leaked (gansec.com) [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Fake AV variant out there, Norton/Symantec/Microsoft do NOT DETECT IT by Sven Olensky</title>
		<link>http://gansec.com/blog/?p=275&#038;cpage=1#comment-754</link>
		<dc:creator>Sven Olensky</dc:creator>
		<pubDate>Tue, 09 Nov 2010 16:25:54 +0000</pubDate>
		<guid isPermaLink="false">http://gansec.com/blog/?p=275#comment-754</guid>
		<description>It seems to be connecting to the Chinese site and just pull up a &#039;checkout&#039; page.

Sorry, I don&#039;t distribute viruses so I can&#039;t send it to you.</description>
		<content:encoded><![CDATA[<p>It seems to be connecting to the Chinese site and just pull up a &#8216;checkout&#8217; page.</p>
<p>Sorry, I don&#8217;t distribute viruses so I can&#8217;t send it to you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Fake AV variant out there, Norton/Symantec/Microsoft do NOT DETECT IT by Jared</title>
		<link>http://gansec.com/blog/?p=275&#038;cpage=1#comment-719</link>
		<dc:creator>Jared</dc:creator>
		<pubDate>Tue, 02 Nov 2010 21:53:51 +0000</pubDate>
		<guid isPermaLink="false">http://gansec.com/blog/?p=275#comment-719</guid>
		<description>I recently encountered this thing as well. It&#039;s a new iteration of the ThinkPoint scam. Another idea, since I no longer have the files to play with (in hindsight, I should have kept them), I&#039;m wondering if it sets up an HTTP server (nginx) after looking at the activity logs.

Do you still have these files?</description>
		<content:encoded><![CDATA[<p>I recently encountered this thing as well. It&#8217;s a new iteration of the ThinkPoint scam. Another idea, since I no longer have the files to play with (in hindsight, I should have kept them), I&#8217;m wondering if it sets up an HTTP server (nginx) after looking at the activity logs.</p>
<p>Do you still have these files?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Immature Security Researchers Mad at Microsoft, Release 0-Day Exploits by Sven Olensky</title>
		<link>http://gansec.com/blog/?p=228&#038;cpage=1#comment-120</link>
		<dc:creator>Sven Olensky</dc:creator>
		<pubDate>Fri, 23 Jul 2010 14:11:07 +0000</pubDate>
		<guid isPermaLink="false">http://gansec.com/blog/?p=228#comment-120</guid>
		<description>Michael, it doesn&#039;t bother me that vendors are being put under the gun to fix some issue that others find -- in that respect, I am all for slapping them with the exploit as soon as it is found. However, my concern is the user base that has vulnerable software installed. If an exploit is released and there is no fix in sight from the vendor, then the people who have to deal with the infections/attacks/etc are the users that run that vulnerable software. The users are going to be the victims, not the vendors.</description>
		<content:encoded><![CDATA[<p>Michael, it doesn&#8217;t bother me that vendors are being put under the gun to fix some issue that others find &#8212; in that respect, I am all for slapping them with the exploit as soon as it is found. However, my concern is the user base that has vulnerable software installed. If an exploit is released and there is no fix in sight from the vendor, then the people who have to deal with the infections/attacks/etc are the users that run that vulnerable software. The users are going to be the victims, not the vendors.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Immature Security Researchers Mad at Microsoft, Release 0-Day Exploits by Michael</title>
		<link>http://gansec.com/blog/?p=228&#038;cpage=1#comment-119</link>
		<dc:creator>Michael</dc:creator>
		<pubDate>Fri, 23 Jul 2010 13:57:13 +0000</pubDate>
		<guid isPermaLink="false">http://gansec.com/blog/?p=228#comment-119</guid>
		<description>Why do so many people find this shocking.  There is no reason at all to give software vendors any notice before publishing an exploit, it simply a common nicety in our field.  Personally I think exploits should be published the day they are found.  Software vendors make a decision based on money and time when publishing code, why should security researchers factor that into their disclosure notices.  All too often I have heard from software companies that that security fix will take too long, we&#039;ll release it &#039;as is&#039; and add a bug to the tracker so we fix by next release.</description>
		<content:encoded><![CDATA[<p>Why do so many people find this shocking.  There is no reason at all to give software vendors any notice before publishing an exploit, it simply a common nicety in our field.  Personally I think exploits should be published the day they are found.  Software vendors make a decision based on money and time when publishing code, why should security researchers factor that into their disclosure notices.  All too often I have heard from software companies that that security fix will take too long, we&#8217;ll release it &#8216;as is&#8217; and add a bug to the tracker so we fix by next release.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Mass infection of web sites running IIS with ASP by Guard against SQL injection attacks: protect your database &#171; The GANSEC Security Weblog</title>
		<link>http://gansec.com/blog/?p=194&#038;cpage=1#comment-13</link>
		<dc:creator>Guard against SQL injection attacks: protect your database &#171; The GANSEC Security Weblog</dc:creator>
		<pubDate>Wed, 09 Jun 2010 18:50:34 +0000</pubDate>
		<guid isPermaLink="false">http://gansec.com/blog/?p=194#comment-13</guid>
		<description>[...] Mass infection of web sites running IIS with ASP [...]</description>
		<content:encoded><![CDATA[<p>[...] Mass infection of web sites running IIS with ASP [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on How to secure your Smartphone (Blackberry, iPhone, Windows Mobile-based phones) by If Your Password Is 123456, Just Make It HackMe &#124; TechNexus.info</title>
		<link>http://gansec.com/blog/?p=113&#038;cpage=1#comment-10</link>
		<dc:creator>If Your Password Is 123456, Just Make It HackMe &#124; TechNexus.info</dc:creator>
		<pubDate>Thu, 21 Jan 2010 23:58:28 +0000</pubDate>
		<guid isPermaLink="false">http://gansecblogger.wordpress.com/?p=113#comment-10</guid>
		<description>[...] How to secure your Smartphone (Blackberry, iPhone, Windows Mobile &#8230; [...]</description>
		<content:encoded><![CDATA[<p>[...] How to secure your Smartphone (Blackberry, iPhone, Windows Mobile &#8230; [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New serious Windows / ActiveX exploit &#8211; Workaround available by Critical: Microsoft patches coming out Tuesday to fix ActiveX vulnerabilities, new vulnerability in MS Office &#171; The GANSEC Security Weblog</title>
		<link>http://gansec.com/blog/?p=62&#038;cpage=1#comment-9</link>
		<dc:creator>Critical: Microsoft patches coming out Tuesday to fix ActiveX vulnerabilities, new vulnerability in MS Office &#171; The GANSEC Security Weblog</dc:creator>
		<pubDate>Mon, 13 Jul 2009 17:53:20 +0000</pubDate>
		<guid isPermaLink="false">http://gansecblogger.wordpress.com/?p=62#comment-9</guid>
		<description>[...] in Advisories, hacks, patches.  Tags: Microsoft-Worm, patches, advisory, microsoft trackback  I mentioned this last week, and Microsoft is planning to patch it tomorrow (Tuesday), from what I read. Stay alert and patch [...]</description>
		<content:encoded><![CDATA[<p>[...] in Advisories, hacks, patches.  Tags: Microsoft-Worm, patches, advisory, microsoft trackback  I mentioned this last week, and Microsoft is planning to patch it tomorrow (Tuesday), from what I read. Stay alert and patch [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

