<?xml version="1.0" encoding="UTF-8"?><!-- generator="Recognize-Security" -->
<rss version="0.92">
<channel>
	<title>Recognize-Security</title>
	<link>http://www.rec-sec.com</link>
	<description>a non-profit information security web site authored by Moshe Ben Abu (Trancer), focusing on vulnerability research, exploit development (mainly for the Metasploit Framework), web application security, information security and hacking news from around the world.</description>
	<lastBuildDate>Thu, 11 Mar 2010 13:48:09 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<atom:link rel="hub" href="http://pubsubhubbub.appspot.com" xmlns:atom="http://www.w3.org/2005/Atom" />
	<atom:link rel="hub" href="http://superfeedr.com/hubbub" xmlns:atom="http://www.w3.org/2005/Atom" />
	
	<item>
		<title>Microsoft Internet Explorer iepeers.dll use-after-free exploit (meta)</title>
		<description><![CDATA[A new Microsoft Internet Explorer 0day exploit has been found circulating in-the-wild. According to Microsoft, there are  targeted attacks attempting to use this vulnerability. Microsoft published a security advisory for this vulnerability here:
Microsoft Security Advisory (981374): Vulnerability in Internet Explorer Could Allow Remote Code Execution
The vulnerability is a use-after-free (invalid pointer reference) vulnerability within [...]]]></description>
		<link>http://www.rec-sec.com/2010/03/10/internet-explorer-iepeers-use-after-free-exploit/</link>
			</item>
	<item>
		<title>South River Technologies WebDrive Service Bad Security Descriptor Local Privilege Escalation exploit (meta)</title>
		<description><![CDATA[Here&#8217;s a local privilege escalation exploit I wrote, as a Metasploit Meterpreter script, for the South River Technologies WebDrive Service Bad Security Descriptor vulnerability. 
This vulnerability was discovered by bellick of the Nine:Situations:Group and the original advisory can be found on the Nine:Situations:Group web site &#8211; South River Technologies WebDrive Service Bad Security Descriptor Local [...]]]></description>
		<link>http://www.rec-sec.com/2010/01/26/srt-webdrive-privilege-escalation/</link>
			</item>
	<item>
		<title>AOL 9.5 Phobos.Playlist Import() Stack-based Buffer Overflow exploit (meta)</title>
		<description><![CDATA[Wrote a new Metaspoit exploit module for the AOL 9.5 Phobos.Playlist ActiveX control Import() stack-based buffer overflow vulnerability.
This module exploits a stack-based buffer overflow within Phobos.dll of AOL 9.5. By setting an overly long value to &#8216;Import()&#8217;, an attacker can overrun a buffer and execute arbitrary code.
This vulnerability was found by Hellcode Research and was [...]]]></description>
		<link>http://www.rec-sec.com/2010/01/25/aol-playlist-class-buffer-overflow/</link>
			</item>
	<item>
		<title>Peter Van Eeckhoutte&#8217;s Exploit Writing Tutorials</title>
		<description><![CDATA[Hello everyone. If your in to exploit development or new to this and want to learn how to do it, here&#8217;s a series of tutorials by Peter Van Eeckhoutte (a.k.a corelanc0d3r), which I strongly recommend, that will give you solid knowledge in exploit writing.
Today Peter published the latest edition to his exploit writing tutorials about [...]]]></description>
		<link>http://www.rec-sec.com/2010/01/22/corelanc0d3r-exploit-tutorials/</link>
			</item>
	<item>
		<title>Recognize-Security on Twitter</title>
		<description><![CDATA[Hello readers,
From now on you can follow Recognize-Security on Twitter!
Check it out &#8211; twitter.com/rec_sec
]]></description>
		<link>http://www.rec-sec.com/2010/01/21/recognize-security-on-twitter/</link>
			</item>
	<item>
		<title>cPanel HTTP Response Splitting Vulnerability</title>
		<description><![CDATA[Security Advisory for cPanel and WHM (WebHost Manager) versions 11.25.
Vulnerabilities found:

HTTP Response Splitting vulnerability
Open Redirection vulnerability

 cPanel HTTP Response Splitting Vulnerability &#8211; Security Advisory (PDF).
 cPanel HTTP Response Splitting Vulnerability &#8211; Security Advisory (TXT).
I&#8217;d like to point out the lame work of the cPanel Security Team on these vulnerabilities. Usually when I report a vulnerability, [...]]]></description>
		<link>http://www.rec-sec.com/2010/01/21/cpanel-http-response-splitting-vulnerability/</link>
			</item>
	<item>
		<title>Nmap 5.20 released</title>
		<description><![CDATA[A new version of Nmap Security Scanner released today which is the first stable release since 5.00 &#8211; Nmap 5.20.
This version got tons of improvements such as improved UDP scanning, new Nmap Scripting Engine scripts, updated OS and version detection and more.
Check out the Change log and announcement of Nmap 5.20.
Download Nmap 5.20.
]]></description>
		<link>http://www.rec-sec.com/2010/01/21/nmap-5-20-released/</link>
			</item>
	<item>
		<title>BackTrack Linux 4 released</title>
		<description><![CDATA[A new version for the penetration testers and security experts favorite Linux distrobution released &#8211; BackTrack Linux 4.
This version offers new tools, new kernel and tons of bug fixes. And, BackTrack Linux is no longer a part of remote-exploit.org, it got a new home at backtrack-linux.org.
I used the new version for the last couple of [...]]]></description>
		<link>http://www.rec-sec.com/2010/01/21/backtrack-linux-4-released/</link>
			</item>
	<item>
		<title>Metasploit Unleashed &#8211; Mastering the Framework</title>
		<description><![CDATA[Hello everyone,
I&#8217;d like to recommend a new and free online course brought to you by the great guys at Offensive Security, the creators of BackTrack Linux distribution.
Metasploit Unleashed &#8211; Mastering the Framework online course will give you a solid knowledge base to start working with the Metasploit Framework, from simple things such as lunching an [...]]]></description>
		<link>http://www.rec-sec.com/2009/12/17/metasploit-unleashed/</link>
			</item>
	<item>
		<title>Metasploit Framework 3.3 released</title>
		<description><![CDATA[The guys at Rapid7 and the Metasploit team announced the release of version 3.3 of the framework. The new version ships with tons of improvments, bug fixes, new featues, exploits and auxilary modules. I really recommend it. For the complete list of changes read the announcment post by HD Moore &#8211; Metasploit Framework 3.3 released!
You [...]]]></description>
		<link>http://www.rec-sec.com/2009/11/18/metasploit-framework-3-3/</link>
			</item>
	<item>
		<title>Microsoft Security Intelligence Report volume 7</title>
		<description><![CDATA[The Microsoft Security Intelligence Report volume 7 (January through July 2009) released.
As usual in the Security Intelligence Report, Microsoft summarize the state of security and cyber-crime of the Internet, their products vulnerabilities and exploitation in-the-wild for the first half of 2009.
Microsoft Security Intelligence Report volume 7.
]]></description>
		<link>http://www.rec-sec.com/2009/11/02/microsoft-security-intelligence-report-volume-7/</link>
			</item>
	<item>
		<title>Rapid7 Acquires the Metasploit Project</title>
		<description><![CDATA[Hello readers. If you didn&#8217;t heard about it already, on October 21st, 2009, the hackers favorite exploitation framework &#8211; the Metasploit Project was acquired by Rapid7, a vulnerability management, compliance, and penetration testing company. Yep, a commercial company.
The Metasploit Project creator, HD Moore, and one of the developers, Egypt, now got a full time job [...]]]></description>
		<link>http://www.rec-sec.com/2009/11/01/rapid7-acquires-metasploit/</link>
			</item>
	<item>
		<title>Digital Whisper #2 released</title>
		<description><![CDATA[Hello readers. Digital Whisper, the Israeli security\hacking\programming web magazine is out with a second issue.
This month issue features the following articles:

SSL &#038; Trasport Layer Security Protocol by cp77fk4r
Manual Unpacking by Zerith
Virus Loading Techniques by cp77fk4r
RFID Hacking by cp77fk4r
Port Knocking by cp77fk4r
Kerberos v5 Protocol by cp77fk4r
DNS Cache Poisoning by cp77fk4r

You can download it here &#8211; Digital [...]]]></description>
		<link>http://www.rec-sec.com/2009/10/31/digitalwhisper-2-released/</link>
			</item>
	<item>
		<title>Why Bezeq Int SafeNet Service is Useless</title>
		<description><![CDATA[Hello readers. In this post I&#8217;d like to talk about Bezeq International SafeNet service. Bezeq Int is the most common ISP in Israel and like most of the ISP&#8217;s out there, Bezeq Int offer their customers a security service called SafeNet, which they recommend users to buy so they could surf the web in a [...]]]></description>
		<link>http://www.rec-sec.com/2009/10/16/bezeq-int-safenet-sucks/</link>
			</item>
	<item>
		<title>HTTPDX h_handlepeer() Function Buffer Overflow exploit (meta)</title>
		<description><![CDATA[Hello readers, I wrote a new Metaspoit exploit module for the HTTPDX h_handlepeer() function stack-based buffer overflow vulnerability.
The vulnerability was found in HTTPDX HTTP/FTP server version 1.4 by Pankaj Kohli and the original exploit can be found on his website &#8211; httpdx 1.4 GET Request Remote Buffer Overflow Exploit (0day).
This module exploits a stack-based buffer [...]]]></description>
		<link>http://www.rec-sec.com/2009/10/16/httpdx-buffer-overflow-exploit/</link>
			</item>
</channel>
</rss>
