<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Recognize-Security &#187; Security News</title>
	<atom:link href="http://www.rec-sec.com/category/security-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rec-sec.com</link>
	<description>a non-profit information security web site authored by Moshe Ben Abu (Trancer), focusing on vulnerability research, exploit development (mainly for the Metasploit Framework), web application security, information security and hacking news from around the world.</description>
	<lastBuildDate>Sun, 14 Mar 2010 17:44:35 +0000</lastBuildDate>
	<generator>http://www.rec-sec.com</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<cloud domain='www.rec-sec.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" />
			<item>
		<title>Microsoft Security Intelligence Report volume 7</title>
		<link>http://www.rec-sec.com/2009/11/02/microsoft-security-intelligence-report-volume-7/</link>
		<comments>http://www.rec-sec.com/2009/11/02/microsoft-security-intelligence-report-volume-7/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 16:59:42 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=848</guid>
		<description><![CDATA[The Microsoft Security Intelligence Report volume 7 (January through July 2009) released.
As usual in the Security Intelligence Report, Microsoft summarize the state of security and cyber-crime of the Internet, their products vulnerabilities and exploitation in-the-wild for the first half of 2009.
Microsoft Security Intelligence Report volume 7.
]]></description>
			<content:encoded><![CDATA[<p>The Microsoft Security Intelligence Report volume 7 (January through July 2009) released.<br />
As usual in the Security Intelligence Report, Microsoft summarize the state of security and cyber-crime of the Internet, their products vulnerabilities and exploitation in-the-wild for the first half of 2009.<br />
<a href="http://www.microsoft.com/security/portal/sir.aspx" title="Microsoft Malware Protection Center - Security Intelligence Report">Microsoft Security Intelligence Report volume 7</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/11/02/microsoft-security-intelligence-report-volume-7/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rapid7 Acquires the Metasploit Project</title>
		<link>http://www.rec-sec.com/2009/11/01/rapid7-acquires-metasploit/</link>
		<comments>http://www.rec-sec.com/2009/11/01/rapid7-acquires-metasploit/#comments</comments>
		<pubDate>Sun, 01 Nov 2009 05:16:55 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=833</guid>
		<description><![CDATA[Hello readers. If you didn&#8217;t heard about it already, on October 21st, 2009, the hackers favorite exploitation framework &#8211; the Metasploit Project was acquired by Rapid7, a vulnerability management, compliance, and penetration testing company. Yep, a commercial company.
The Metasploit Project creator, HD Moore, and one of the developers, Egypt, now got a full time job [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="Rapid7 and Metasploit" width="301" height="113" class="right" src="images/rapid7_metasploit.png" />Hello readers. If you didn&#8217;t heard about it already, on October 21st, 2009, the hackers favorite exploitation framework &#8211; <a href="http://www.metasploit.com/" title="The Metasploit Project">the Metasploit Project</a> was acquired by <a href="http://www.rapid7.com/" title="Rapid7">Rapid7</a>, a vulnerability management, compliance, and penetration testing company. Yep, a commercial company.</p>
<p>The Metasploit Project creator, HD Moore, and one of the developers, Egypt, now got a full time job working on and developing the Metasploit Project. HD in the position of Chief Architect of Metasploit and Egypt as a core developer of Metasploit at Rapid7. </p>
<p>If you read this blog often you probably noticed that I&#8217;m a big supporter of the Metasploit Project. I use it on a daily basis, preforming penetration tests and exploit development while at work or at home for fun. As you may guess, my feelings about the acquisition are mixed. On one side this is a good thing, this is a big step for the Metasploit Project. Now it&#8217;ll grow and develop faster and rapidly and us, the users, will get a better, faster, more advanced and less buggy program, and I believe we&#8217;ll start seeing faster release cycles. But on the other side, now the Metasploit Project which was a free, open source, community driven project, is managed by a commercial company. I think the worst case scenario will be if Rapid7 decide to make Metasploit a commercial product, which will be a sad thing. This won&#8217;t be the first time it&#8217;ll happen to a good security product. The best example here is the <a href="http://www.nessus.org/" title="Tenable Network Security">Nessus vulnerability scanner</a> which was acquired by Tenable Network Security back in 2005.</p>
<p>I hope the fate of the Metasploit Project won&#8217;t be the same as Nessus. HD Moore stated on the Metasploit blog that the project will remain free and open source. So, if that&#8217;s the case and long as the Metasploit Project will stay that way I think the users should be happy about it. I will continue to support the Metasploit Project and develop exploits and other modules for it and contribute in every way I can.<br />
I guess all there&#8217;s left to say is congratulations to HD Moore and Egypt for the acquisition, keep on rocking. </p>
<p>References:<br />
<strong>&gt;&gt;</strong> <a href="http://blog.metasploit.com/2009/10/metasploit-rising.html" title="Metasploit: Metasploit Rising">Metasploit Rising</a> &#8211; HD Moore write about the acquisition on the Metasploit blog.<br />
<strong>&gt;&gt;</strong> <a href="http://www.rapid7.com/metasploit-announcement.jsp" title="Metasploit Acquisition FAQ | Rapid7">Rapid7 Acquires Metasploit</a> &#8211; The Metasploit acquisition by Rapid7 <abbr title="Chief Executive Officer">CEO</abbr>.<br />
<strong>&gt;&gt;</strong> <a href="http://www.metasploit.com/home/faq" title="The Metasploit Project - Rapid7 Acquisition FAQ">Rapid7 Acquisition <abbr title="Frequently Asked Questions">FAQ</abbr></a> &#8211; Questions and answers about the acquisition.<br />
<strong>&gt;&gt;</strong> <a href="http://blogs.zdnet.com/security/?p=4708" title="Metasploit + Rapid7 shakes up pen-test landscape | Zero Day | ZDNet.com">Metasploit + Rapid7 shakes up pen-test landscape</a> &#8211; Ryan Naraine write about the penetration testing market changes followed by the acquisition.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/11/01/rapid7-acquires-metasploit/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Digital Whisper #2 released</title>
		<link>http://www.rec-sec.com/2009/10/31/digitalwhisper-2-released/</link>
		<comments>http://www.rec-sec.com/2009/10/31/digitalwhisper-2-released/#comments</comments>
		<pubDate>Sat, 31 Oct 2009 21:59:26 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=829</guid>
		<description><![CDATA[Hello readers. Digital Whisper, the Israeli security\hacking\programming web magazine is out with a second issue.
This month issue features the following articles:

SSL &#038; Trasport Layer Security Protocol by cp77fk4r
Manual Unpacking by Zerith
Virus Loading Techniques by cp77fk4r
RFID Hacking by cp77fk4r
Port Knocking by cp77fk4r
Kerberos v5 Protocol by cp77fk4r
DNS Cache Poisoning by cp77fk4r

You can download it here &#8211; Digital [...]]]></description>
			<content:encoded><![CDATA[<p>Hello readers. <a href="http://www.digitalwhisper.co.il/" title="Digital Whisper - Technologic papers">Digital Whisper</a>, the Israeli security\hacking\programming web magazine is out with a second issue.<br />
This month issue features the following articles:</p>
<ul>
<li><abbr title="Secure Sockets Layer">SSL</abbr> &#038; Trasport Layer Security Protocol by cp77fk4r</li>
<li>Manual Unpacking by Zerith</li>
<li>Virus Loading Techniques by cp77fk4r</li>
<li><abbr title="Radio-Frequency Identification">RFID</abbr> Hacking by cp77fk4r</li>
<li>Port Knocking by cp77fk4r</li>
<li>Kerberos v5 Protocol by cp77fk4r</li>
<li><abbr title="Domain Name System">DNS</abbr> Cache Poisoning by cp77fk4r</li>
</ul>
<p>You can download it here &#8211; <a href="http://www.digitalwhisper.co.il/issue2" title="Digital Whisper issue 2">Digital Whisper issue #2</a>.</p>
<p>Have a great reading.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/10/31/digitalwhisper-2-released/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Why Bezeq Int SafeNet Service is Useless</title>
		<link>http://www.rec-sec.com/2009/10/16/bezeq-int-safenet-sucks/</link>
		<comments>http://www.rec-sec.com/2009/10/16/bezeq-int-safenet-sucks/#comments</comments>
		<pubDate>Fri, 16 Oct 2009 18:37:08 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=781</guid>
		<description><![CDATA[Hello readers. In this post I&#8217;d like to talk about Bezeq International SafeNet service. Bezeq Int is the most common ISP in Israel and like most of the ISP&#8217;s out there, Bezeq Int offer their customers a security service called SafeNet, which they recommend users to buy so they could surf the web in a [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="Bezeq International" width="204" height="93" class="left" src="images/bezeqint.png" />Hello readers. In this post I&#8217;d like to talk about Bezeq International SafeNet service. Bezeq Int is the most common <abbr title="Internet Service Provider">ISP</abbr> in Israel and like most of the <abbr title="Internet Service Provider">ISP</abbr>&#8217;s out there, Bezeq Int offer their customers a security service called SafeNet, which they recommend users to buy so they could surf the web in a safer manner.</p>
<p>As stated on <a href="http://www.bezeqint.net/SafeNet.html" title="Bezeq International - SafeNet">Bezeq Int SafeNet page</a> (and <a href="http://www.bezeqint.net/Page.aspx?cc=010101020101" title="Bezeq International - SafeNet details">details</a>), this service cost 13.90 <abbr title="Israeli New Shekel">NIS</abbr> a month and should be some kind of content filtering system, providing users protection from Malware (viruses, worms, trojan horses, spyware), <abbr title="Hyper Text Markup Language">HTML</abbr> exploits, malicious Activ-X and JAVA code, Fishing web sites and more (note I deliberately misspelled the definitions, that&#8217;s how it&#8217;s wrote on the SafeNet service specification page).</p>
<p>Well, after running a series of tests I can surly say Bezeq Int SafeNet service provide non of these protections what so ever. In fact, it doesn&#8217;t provide any sort of active protection. The only protection SafeNet service provides is blocking supposedly malicious web sites using an out-of-date domain names blacklist.</p>
<p>For example, trying to access <a href="http://www.packetstormsecurity.org/" title="packet storm">Packet Storm Security</a> web site will result in a redirection to a Bezeq Int domain, displaying this SafeNet message:<br />
<a href="images/screenshots/safenet.png" title="Bezeq Int SafeNet message" rel="lightbox"><img width="387" height="326" style="border-width:0" src="images/screenshots/safenet.png" alt="Bezeq Int SafeNet message" /></a><br />
<small>Click to enlarge.</small></p>
<p>The SafeNet service blacklist doesn&#8217;t include <a href="http://milw0rm.com/" title="milw0rm - exploits : vulnerabilities : videos : papers : shellcode">milw0rm</a> and other hacking related web sites. I even ran test against active Malware serving pages, Phishing web sites and rouge Anti-Virus sites, non of which have been blocked by Bezeq Int SafeNet service.</p>
<p>Furthermore, the SafeNet service domain blacklist function can be bypassed rather easily. It is possible to access blacklisted domains using their <abbr title="Internet Protocol">IP</abbr> addresses:<br />
<a href="images/screenshots/packetstorm.png" title="Packet Storm Security" rel="lightbox"><img width="387" height="326" style="border-width:0" src="images/screenshots/packetstorm.png" alt="Packet Storm Security" /></a><br />
<small>Click to enlarge.</small></p>
<p>In conclusion, Bezeq Int SafeNat service provide users no affective protection against any kind of threat and Bezeq Int doesn&#8217;t provide their customers any of the promised functions stated on the SafeNet service specification.<br />
In my opinion, Bezeq Int SafeNet service is a total rip-off and if you are registered to it I recommend you&#8217;d cancel the service immediately.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/10/16/bezeq-int-safenet-sucks/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Digital Whisper #1 released</title>
		<link>http://www.rec-sec.com/2009/09/30/digitalwhisper-1-released/</link>
		<comments>http://www.rec-sec.com/2009/09/30/digitalwhisper-1-released/#comments</comments>
		<pubDate>Wed, 30 Sep 2009 21:36:17 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=774</guid>
		<description><![CDATA[Hello there, Digital Whisper is a new Israeli security\hacking\programming web magazine founded by Afik Castiel (cp77fk4r) and Nir Adar (UnderWarrior), written in Hebrew.
Their first issue is out today, you can grab a copy here &#8211; Digital Whisper issue #1. This issue features the following articles:

Windows Privilege Escalation by cp77fk4r
Manual Packing by HLL
Introduction to Artificial Intelligence [...]]]></description>
			<content:encoded><![CDATA[<p>Hello there, <a href="http://www.digitalwhisper.co.il/" title="Digital Whisper - Technologic papers">Digital Whisper</a> is a new Israeli security\hacking\programming web magazine founded by Afik Castiel (cp77fk4r) and Nir Adar (UnderWarrior), written in Hebrew.<br />
Their first issue is out today, you can grab a copy here &#8211; <a href="http://www.digitalwhisper.co.il/issue1" title="Digital Whisper issue 1">Digital Whisper issue #1</a>. This issue features the following articles:</p>
<ul>
<li>Windows Privilege Escalation by cp77fk4r</li>
<li>Manual Packing by HLL</li>
<li>Introduction to Artificial Intelligence by UnderWarrior</li>
<li>Lock Picking by cp77fk4r</li>
<li>WEP Encryption by Hertzel Levi</li>
<li>Introduction to Recursion in C by UnderWarrior</li>
<li>HTTP Attacks &#8211; Response Splitting by cp77fk4r</li>
</ul>
<p>If anyone is willing to contribute, submit an article or give a feedback, contact Digital Whisper crew here &#8211; editor[AT]digitalwhisper.co.il</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/09/30/digitalwhisper-1-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Phrack #66 released</title>
		<link>http://www.rec-sec.com/2009/06/11/phrack-66/</link>
		<comments>http://www.rec-sec.com/2009/06/11/phrack-66/#comments</comments>
		<pubDate>Thu, 11 Jun 2009 11:08:20 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=674</guid>
		<description><![CDATA[Phrack magazine is out with a fresh issue. You can grab a copy on Phrack site.
]]></description>
			<content:encoded><![CDATA[<p>Phrack magazine is out with a fresh issue. You can grab a copy on <a href="http://www.phrack.com/issues.html?issue=66" title="Phrack Magazine - issue 66">Phrack site</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/06/11/phrack-66/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Verizon Data Breach Investigations Report 2009</title>
		<link>http://www.rec-sec.com/2009/04/30/verizon-data-breach-investigations-report-2009/</link>
		<comments>http://www.rec-sec.com/2009/04/30/verizon-data-breach-investigations-report-2009/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 17:21:48 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=436</guid>
		<description><![CDATA[The Verizon Data Breach Investigations Report for 2009 released few days ago.
The report summarize the state of cyber-crime for 2008, covering sources of data breaches, threats and attack vectors, who and what kind of data are getting compromised.
Interesting reading and a great source for statistics.
Verizon Data Breach Investigations Report 2009.
]]></description>
			<content:encoded><![CDATA[<p>The Verizon Data Breach Investigations Report for 2009 released few days ago.<br />
The report summarize the state of cyber-crime for 2008, covering sources of data breaches, threats and attack vectors, who and what kind of data are getting compromised.<br />
Interesting reading and a great source for statistics.<br />
<a href="http://www.verizonbusiness.com/resources/security/reports/2009_databreach_rp.pdf" title="Verizon Data Breach Investigations Report 2009">Verizon Data Breach Investigations Report 2009</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/04/30/verizon-data-breach-investigations-report-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Security Intelligence Report volume 6</title>
		<link>http://www.rec-sec.com/2009/04/09/ms-security-intelligence-report-vol6/</link>
		<comments>http://www.rec-sec.com/2009/04/09/ms-security-intelligence-report-vol6/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 16:16:13 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=340</guid>
		<description><![CDATA[The Microsoft Security Intelligence Report volume 6 (July through December 2008) released.
The report summarize security and exploit trends, the internet cyber-crime state and Microsoft products vulnerabilities and exploitation in-the-wild for the second half of 2008.
I find the report very interesting and I strongly recommend reading it.
Microsoft Security Intelligence Report volume 6.
]]></description>
			<content:encoded><![CDATA[<p>The Microsoft Security Intelligence Report volume 6 (July through December 2008) released.<br />
The report summarize security and exploit trends, the internet cyber-crime state and Microsoft products vulnerabilities and exploitation in-the-wild for the second half of 2008.<br />
I find the report very interesting and I strongly recommend reading it.<br />
<a href="http://www.microsoft.com/security/portal/sir.aspx" title="Microsoft Malware Protection Center - Security Intelligence Report">Microsoft Security Intelligence Report volume 6</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/04/09/ms-security-intelligence-report-vol6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Israeli Hacking Convention 2009</title>
		<link>http://www.rec-sec.com/2009/04/09/israeli-hacking-convention-2009/</link>
		<comments>http://www.rec-sec.com/2009/04/09/israeli-hacking-convention-2009/#comments</comments>
		<pubDate>Thu, 09 Apr 2009 15:53:53 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=109</guid>
		<description><![CDATA[Since Y2Hack (2000) and Y2Hack4 (2004) there was no hacking convention held in Israel. That&#8217;s just sad because Israel is a small country and have a lot of great minds in the field, and I think having such an event at least once a year will contribute a lot to the Israeli hacking community and [...]]]></description>
			<content:encoded><![CDATA[<p>Since Y2Hack (2000) and Y2Hack4 (2004) there was no hacking convention held in Israel. That&#8217;s just sad because Israel is a small country and have a lot of great minds in the field, and I think having such an event at least once a year will contribute a lot to the Israeli hacking community and will take it few steps forward.<br />
This year, Thanks to the ambitiousness of <a href="http://www.linkedin.com/in/yanivmiron" title="Yaniv Miron - LinkedIn">Yaniv Miron</a>, we&#8217;ll get a hacking convention in Israel:</p>
<p><a href="http://www.ilhack.org/2009/" title="IL.Hack 2009 - Israeli Hacking Convention"><img alt="IL.Hack 2009 - Israeli Hacking Convention" width="475" height="70" style="border-width:0" src="images/ilhack2009banner.png" /></a></p>
<p>The convention will be held on 24/05/2009 at the American Zionist House in Tel Aviv and will include:</p>
<ul>
<li>Hacking lectures.</li>
<li>Information security lectures.</li>
<li>Hacking Wargames.</li>
<li>Book Crossing.</li>
<li>Pizzas!</li>
</ul>
<p>Go sign up! For further information check out <a href="http://www.ilhack.org/2009/" title="IL.Hack 2009 - כנס ההאקרים הישראלי">IL.Hack 2009</a> web site (Hebrew), or the <a href="http://www.ilhack.org/2009/?page_id=235" title="IL.Hack 2009 - Israeli Hacking Convention">IL.Hack 2009</a> English information page.<br />
You can also approve attendance at the <a href="http://www.facebook.com/event.php?eid=50392667942" title="Facebook | כנס האקינג ישראלי 2009">convention Facebook event</a>.</p>
<p>Note that more sponsors are needed, so if some of the readers can arrange something, please contact Yaniv Miron &#8211; info@ilhack.org.</p>
<p>Hope to see you there :-)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/04/09/israeli-hacking-convention-2009/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>No More Free Bugs</title>
		<link>http://www.rec-sec.com/2009/03/25/no-more-free-bugs/</link>
		<comments>http://www.rec-sec.com/2009/03/25/no-more-free-bugs/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 08:00:15 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.com/?p=281</guid>
		<description><![CDATA[Read the following argument by Dino A. Dai Zovi, Charlie Miller and Alex Sotirov &#8211; No More Free Bugs.
Basically, the argument states:

Security vulnerabilities have high value and finding them is hard work and cost a lot of money. And there&#8217;s a market out there for them.
Vendors relays on security researchers to choose the &#8220;responsible disclosure&#8221; [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="No More Free Bugs" width="300" height="181" class="right" src="images/nomorefreebugs.png" />Read the following argument by <a href="http://www.theta44.org/" title="Theta44 - Dino A. Dai Zovi">Dino A. Dai Zovi</a>, <a href="http://blogs.zdnet.com/security/?p=2941" title="Questions for Pwn2Own hacker Charlie Miller | Zero Day | ZDNet.com">Charlie Miller</a> and <a href="http://www.phreedom.org/" title="Security Research by Alexander Sotirov">Alex Sotirov</a> &#8211; <a href="http://blog.trailofbits.com/2009/03/22/no-more-free-bugs/" title="No More Free Bugs &laquo; &#8230;And You Will Know me by the Trail of Bits"><strong>No More Free Bugs</strong></a>.</p>
<p>Basically, the argument states:</p>
<ul>
<li>Security vulnerabilities have high value and finding them is hard work and cost a lot of money. And there&#8217;s a market out there for them.</li>
<li>Vendors relays on security researchers to choose the &#8220;responsible disclosure&#8221; way and report bugs they find (for free).</li>
<li>Reporting security vulnerabilities is a risky business, legally and professionally.</li>
<li>Reporting security vulnerabilities without any legal agreements pretty much sucks.</li>
<li>Reporting security vulnerabilities for free &#8211; sucks too.</li>
</ul>
<p>In my opinion, vendors should have a pre-made agreement, written by the company <abbr title="Chief Security Officer">CSO</abbr>/security manager, backed up by the company <abbr title="Chief Executive Officer">CEO</abbr> and the company lawyer, for vulnerability disclosure and rewarding methods. Price can be calculated by the vulnerability severity and probability level (<a href="http://www.first.org/cvss/"><abbr title="Common Vulnerability Scoring System">CVSS</abbr></a> style) and the technical details and further work the security researcher provide. For example, the researcher wrote a <abbr title="Proof of Concept">PoC</abbr> exploit code &#8211; low value. Researcher wrote a reliable universal exploit code &#8211; high value.<br />
This way, security researchers will have more than enough reason to disclose vulnerabilities to vendors and get reward for it as it should be, instead of choosing other way (and in my opinion, the wrong way) to gain profit, either money or just fame.</p>
<p>The opinions about the &#8220;no more free bugs&#8221; argument around the world are mixed. Ross Thomas of SophosLabs thinks the security industry sunk in to a <a href="http://www.sophos.com/security/blog/2009/03/3680.html" title="SophosLabs blog - Heroes">new level of lameness</a>. Adam O&#8217;Donnell say there&#8217;s nothing to be excited about and <a href="http://blogs.zdnet.com/security/?p=2989" title="&quot;No more free bugs&quot;?  There never were any free bugs | Zero Day | ZDNet.com">there were never such a thing as free bugs</a>.</p>
<p>I think there is nothing new under the sun. Vendors won&#8217;t rush to make vulnerability disclosure rewarding agreements just because three top security researchers state the party is over and no bugs will be given away for free any more. Security researchers and bug hunters are still stuck with the dilemma of the actions to take after finding a bug &#8211; responsible disclosure, full disclosure, selling it to whoever are willing to pay or doing nothing with it.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2009/03/25/no-more-free-bugs/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Security News &#8211; May 07</title>
		<link>http://www.rec-sec.com/2007/06/05/security-news-may-07/</link>
		<comments>http://www.rec-sec.com/2007/06/05/security-news-may-07/#comments</comments>
		<pubDate>Tue, 05 Jun 2007 10:26:36 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.co.il/2007/06/05/security-news-may-07/</guid>
		<description><![CDATA[It&#8217;s been a long time since our last post.. what can we do?  jsz and I have been really busy this month and I hope we can make time to post here. I promise we&#8217;ll post a lot of interesting stuff soon.
Every month we&#8217;ll post the latest month security news highlights. So, here we [...]]]></description>
			<content:encoded><![CDATA[<p>It&#8217;s been a long time since our last post.. what can we do?  jsz and I have been really busy this month and I hope we can make time to post here. I promise we&#8217;ll post a lot of interesting stuff soon.<br />
Every month we&#8217;ll post the latest month security news highlights. So, here we go:</p>
<p><strong>Phrack Magazine #64</strong></p>
<blockquote><p>&#8220;As long as there is technology, there will be hackers. As long as there<br />
are hackers, there will be PHRACK magazine. We look forward to the next<br />
20 years&#8221;</p></blockquote>
<p>That&#8217;s how Phrack #63 Introduction ended. Phrack magazine is revived with a new staff calling them selfs <em>&#8220;The Circle of Lost Hackers&#8221;</em>. Phrack is (was?) the best online hacking magazine in the world and a lot of people say that it can never be revived. The new issue, although it doesn&#8217;t have the regular amount of technical articles in it, seems like a good start. But to determine rather Phrack will continue to be the best, true underground hacking magazine or not, only time will say&#8230;</p>
<ul>
<li><a href="http://phrack.org" title="Phrack Magazine">Phrack Magazine</a></li>
<li><a href="http://phrack.org/issues.html?issue=64" title="Phrack Magazine - Issue 64">Phrack #64</a></li>
</ul>
<p><strong>Uniformed vol.7</strong><br />
Three great articles on the latest vol of Uniformed:<br />
Reducing the Effective Entropy of GS Cookies, and a Memalyze &#8211; Dynamic Analysis of Memory Access Behavior in Software by skape.<br />
The last article by |)roid is about Mnemonic Password Formulas witch discuss easy and advanced ways for creating mnemonic passwords and its weaknesses.<br />
If you never heard of mnemonic passwords, I strongly suggest you read the following research &#8211; <a href="http://www.rec-sec.co.il/docs/Human_selection_of_mnemonic_phrase-based_passwords.pdf" title="Human selection of mnemonic phrase-based passwords">Human selection of mnemonic phrase-based passwords</a> (pdf).</p>
<ul>
<li><a href="http://www.uninformed.org" title="Uniformed">Uniformed</a></li>
<li><a href="http://www.uninformed.org/?v=7" title="Uniformed vol.7">Uniformed vol.7</a></li>
</ul>
<p><strong>the Month of ActiveX Bugs</strong><br />
May was announced to be the <a href="http://moaxb.blogspot.com/" title="MoAxB (the Month of ActiveX Bugs)">Month of ActiveX Bugs (<acronym title="Month of ActiveX Bugs">MoAxB</acronym>)</a>. You won&#8217;t find a lot of interesting vulnerabilities there.. most of them was found in 3rd party application.<br />
Last year H D Moore presented some fuzzing techniques that disclosed more then 100 bugs in Windows XP default ActiveX controls. Of course not all of the bugs are exploitable but the point is that finding ActiveX bugs it&#8217;s not that big of a deal.<br />
H D Moore also started the <em>Month of [somthing] Bugs</em> with the <a href="http://browserfun.blogspot.com/" title="Browser Fun - Browser bugs, tricks, and hacks">Month of Browser Bugs (<acronym title="Month of Browser Bugs">MoBB</acronym>)</a> back on June 2006. Followed by the <a href="http://projects.info-pull.com/mokb/" title="the Month of Kernel Bugs (MoKB) archive">Month of Kernel Bugs</a> (<a href="http://kernelfun.blogspot.com/" title="Kernel Fun - Kernel bugs and madness"><acronym title="Month of Kernel Bugs">MoKB</acronym></a>) on November and the <a href="http://projects.info-pull.com/moab/" title="the Month of Apple Bugs (MoAB)">Month of Apple Bugs</a> (<a href="http://applefun.blogspot.com/" title="Apple Fun"><acronym title="Month of Apple Bugs">MoAB</acronym></a>) on January this year, both by LMH.<br />
Later on, on March, Stefan Esser who retired from the <acronym title="PHP Hypertext Preprocessor">PHP</acronym> Security Response Team because of slow response time to security holes (one of many reasons. Read more at <a href="http://blog.php-security.org/archives/2006/12.html" title="Stefan Esser PHP Security Blog">Stefan&#8217;s blog</a>), announced the <a href="http://www.php-security.org/" title="the Month of PHP Bugs - formerly known as March">Month of <acronym title="PHP Hypertext Preprocessor">PHP</acronym> Bugs (<acronym title="Month of PHP Bugs">MoPB</acronym>)</a>, in which he disclosed a lot of serious security issues in <acronym title="PHP Hypertext Preprocessor">PHP</acronym> core along with some bonus bugs in Mod Security and the Zend Platform.<br />
On April, two weird dudes &#8211; Mondo Armando and M?¼staschio announced the <a href="http://momby.livejournal.com/" title="the Month of Myspace Bugs, Yuss! (MoMBY)">Month of Myspace Bugs, Yuss! (<acronym title="Month of Myspace Bugs">MoMBY</acronym>)</a> which mostly included <acronym title="Cross-Site Scripting">XSS</acronym> vulnerabilities, different <acronym title="HyperText Markup Language">HTML</acronym> Injections bugs and more, nothing fancy.<br />
This month is the <a href="http://websecurity.com.ua/category/moseb/" title="the Month of Search Engine Bugs">Month of Search Engine Bugs (<acronym title="Month of Search Engine Bugs">MOSEB</acronym>)</a> which we&#8217;ll sum up at the end of the month. </p>
<p><strong>Google Security Blog</strong><br />
Google launches a new, homemade security blog. Nothing much to see there for now except a paper regarding the dangerous in virtualizations. Very interesting subject, not so interesting paper (read with 90% caffeine in blood).</p>
<ul>
<li><a href="http://googleonlinesecurity.blogspot.com/" title="Google Online Security Blog">Google Online Security Blog</a></li>
<li><a href="http://taviso.decsystem.org/virtsec.pdf" title="An Empirical Study into the Security Exposure to Hosts of Hostile Virtualized Environments">On virtualization paper</a> (pdf)</li>
</ul>
<p><strong><acronym title="Berkeley Software Distribution">BSD</acronym> Rootkits</strong><br />
<a href="http://www.thestackframe.org/" title="Joseph Kong - the Stack Frame">Joseph Kong</a> published his first book <a href="http://www.oreilly.com/catalog/1593271425/" title="Oreilly - Designing BSD Rootkits by Joseph Kong">Designing <acronym title="Berkeley Software Distribution">BSD</acronym> Rootkits</a>. I ordered a copy and I can&#8217;t wait to read it.<br />
I think it&#8217;s about time someone publish this kind of book, this subject suffers from a serious lack of resources on the web.<br />
Some of you might know Joseph from his article on Phrack #63 <a href="http://www.phrack.org/archives/63/p63-0x07_Games_With_Kernel_Memory_FreeBSD_Style.txt" title="Phrack 63: Games With Kernel Memory - FreeBSD Style">Games With Kernel Memory &#8211; Free<acronym title="Berkeley Software Distribution">BSD</acronym> Style</a>.<br />
Anyway, I&#8217;ll review the book when I finish reading it.</p>
<p>That&#8217;s it for now, have a great month!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2007/06/05/security-news-may-07/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>(IN)SECURE Magazine 11</title>
		<link>http://www.rec-sec.com/2007/05/08/insecure-magazine-11/</link>
		<comments>http://www.rec-sec.com/2007/05/08/insecure-magazine-11/#comments</comments>
		<pubDate>Mon, 07 May 2007 23:44:32 +0000</pubDate>
		<dc:creator>Trancer</dc:creator>
				<category><![CDATA[Security News]]></category>

		<guid isPermaLink="false">http://www.rec-sec.co.il/index.php/2007/05/08/insecure-magazine-11/</guid>
		<description><![CDATA[Issue 11 of (IN)SECURE Magazine released.
In this issue:

On the security of e-passports
Review: GFI LANguard Network Security Scanner 8
Critical steps to secure your virtualized environment
Interview with Howard Schmidt, President and CEO R &#38; H Security Consulting
Quantitative look at penetration testing
Integrating ISO 17799 into your Software Development Lifecycle
Public Key Infrastructure (PKI): dead or alive?
Interview with Christen Krogh, [...]]]></description>
			<content:encoded><![CDATA[<p><img alt="(IN)SECURE Magazine 11 cover" width="200" height="282" class="right" src="images/issue11.png" />Issue 11 of <a href="http://insecuremag.com/" title="(IN)SECURE Magazine site">(IN)SECURE Magazine</a> released.<br />
In this issue:</p>
<blockquote><ul>
<li>On the security of e-passports</li>
<li>Review: GFI LANguard Network Security Scanner 8</li>
<li>Critical steps to secure your virtualized environment</li>
<li>Interview with Howard Schmidt, President and <acronym title="Chief Executive Officer">CEO</acronym> R &amp; H Security Consulting</li>
<li>Quantitative look at penetration testing</li>
<li>Integrating <acronym title="International Standards Organization">ISO</acronym> 17799 into your Software Development Lifecycle</li>
<li>Public Key Infrastructure (<acronym title="Public Key Infrastructure">PKI</acronym>): dead or alive?</li>
<li>Interview with Christen Krogh, Opera Software&#8217;s Vice President of Engineering</li>
<li>Super ninja privacy techniques for web application developers</li>
<li>Security economics</li>
<li>iptables &#8211; an introduction to a robust firewall</li>
<li>Black Hat Briefings &#038; Training Europe 2007</li>
<li>Enforcing the network security policy with digital certificates</li>
</ul>
</blockquote>
<p>Very interesting stuff! Download (IN)SECURE <a href="http://www.net-security.org/dl/insecure/INSECURE-Mag-11.pdf" title="(IN)SECURE Magazine 11">issue 11</a>.</p>
<p>Also, you might want to check out this interview of <a href="http://jeremiahgrossman.blogspot.com/" title="Jeremiah Grossman's blog">Jeremiah Grossman</a> about Web Application Security:<br />
<object type="application/x-shockwave-flash" width="425" height="350" data="http://www.youtube.com/v/4FdVpCm9BTM"><param name="movie" value="http://www.youtube.com/v/4FdVpCm9BTM" /></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rec-sec.com/2007/05/08/insecure-magazine-11/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
