<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Hero &#187; Chat</title>
	<atom:link href="http://sechero.com/tag/chat/feed/" rel="self" type="application/rss+xml" />
	<link>http://sechero.com</link>
	<description>If it's about security, you heard it here first</description>
	<lastBuildDate>Mon, 12 Jul 2010 23:27:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th)</title>
		<link>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/</link>
		<comments>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/#comments</comments>
		<pubDate>Fri, 29 May 2009 18:42:56 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Botnet]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Virus]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th) School is over or about to be over for many kids. With that comes many families whose parents work and kids will be left at home to relax and enjoy their summer vacation. This means alot of free time and an internet out [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://isc.sans.org/diary.php?storyid=6490&amp;rss">Its summer&#8230;Do you know what your kids are doing?, (Fri, May 29th)</a></h1>
</p>
<p>School is over or about to be over for many kids. With that comes many families whose parents work and kids will be left at home to relax and enjoy their summer vacation. This means alot of free time and an internet out there just waiting to be explored. Everyone is aware of the need to keep your kids safe while on the internet. But in some cases, there is a need to keep the internet and others safe from your kids. Let me explain that last comment. Kids with too much time on their hands get into trouble. You hear about it all the time on the news with kids getting into trouble with things such as vandalism, stealing,etc. What about kids getting into trouble on the internet?<br /> Do a google search on the phrase teenage hacker and see what comes up. Kids are curious and learn fast. The internet can become a playground for them to explore and test out cool new programs and tools they find on the internet or write themselves. Chat rooms are available where kids can learn many things from others and want to try them for themselves. They can also get pulled into the wrong crowd on the internet and get in way over their heads fast. They may not even see anything wrong with it, its just computers after all.<br /> Most of the filtering technology today focuses on web traffic. What are your kids looking at on the web. That is a good thing, but there are many other ports and protocols available and nothing watching them. Would you know if your child was running a botnet? Stealing credit card numbers? Hacking into websites? Its not a game and there are real consequences to it, even sometimes when the intent may have been to do good.Here are some recent examples:<br /> Nineteen-year-old  Dmitriy Guzner from New Jersey was part of an underground hacking group named  &#8216;Anonymous&#8217; that targeted the church with several attacks. He could face ten  years in prison on computer hacking charges and is due to be sentenced on August  24. <a href="http://www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br" title="http://www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br" target="_blank">www.securecomputing.net.au/News/144850,teenage-hacker-pleads-guilty-to-church-of-scientology-cyber-attacks.aspx<br</a> /></p>
<p></p>
<p> Twitter has announced a review into four worm attacks on the site as a teenage hacker admits he could be jailed for his role in the stunt. <a href="http://news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br" title="http://news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br" target="_blank">news.sky.com/skynews/Home/Technology/Twitter-Worm-Attack-Biz-Stone-Announces-Review-As-Teenage-Hacker-Michael-Mooney-Speaks-Out/Article/200904215261579<br</a> /> A teenage hacker whose campaign to expose holes in Internet security sparked an FBI investigation was being sentenced in court today. <a href="http://www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br" title="http://www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br" target="_blank">www.independent.co.uk/news/business/news/teenage-hacker-to-be-sentenced-for-internet-crusade-676871.html<br</a> /> <br /> As parents, we need to also talk to our kids about the other dangers that are on the internet. Dangers such as hacking, virus making, botnet creation, stealing, etc. You may think your child is doing nothing but sitting on a computer playing. But keep in mind that computer on the internet is a portal to a whole nother world.
<p>URL: <a href="http://isc.sans.org/diary.php?storyid=6490&amp;rss">http://isc.sans.org/diary.php?storyid=6490&amp;rss</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/its-summerdo-you-know-what-your-kids-are-doing-fri-may-29th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adium 1.4 beta brings Twitter support and other goodies</title>
		<link>http://sechero.com/adium-14-beta-brings-twitter-support-and-other-goodies/</link>
		<comments>http://sechero.com/adium-14-beta-brings-twitter-support-and-other-goodies/#comments</comments>
		<pubDate>Tue, 19 May 2009 01:31:25 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://sechero.com/adium-14-beta-brings-twitter-support-and-other-goodies/</guid>
		<description><![CDATA[Adium 1.4 beta brings Twitter support and other goodies Our favorite multi-service messaging client, Adium has issued two awesome updates. For OS X 10.4 Tiger users, or users who just want to use the most &#8220;stable&#8221; Adium release, the team has released Adium 1.3.4. This version boasts and updated core library and an updated Facebook [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31353">Adium 1.4 beta brings Twitter support and other goodies</a></h1>
</p>
<p>Our favorite multi-service messaging client, Adium has issued two awesome updates. For OS X 10.4 Tiger users, or users who just want to use the most &#8220;stable&#8221; Adium release, the team has released Adium 1.3.4. This version boasts and updated core library and an updated Facebook chat plugin. The Adium blog states that this will likely be the last update for OS X 10.4 Tiger users.</p>
<p>If you&#8217;re running OS X 10.5 Leopard and you want to get a taste of some new Adium features, the first beta of Adium 1.4 is also now available. The big news with Adium 1.4 is Twitter support!  In addition to Twitter, Adium 1.4 also supports IRC, enhanced group messaging (independent styles and whatnot) and a slew of other improvements and enhancements.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31353">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31353</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/adium-14-beta-brings-twitter-support-and-other-goodies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The New York Times Twitter Account Hijacked</title>
		<link>http://sechero.com/the-new-york-times-twitter-account-hijacked/</link>
		<comments>http://sechero.com/the-new-york-times-twitter-account-hijacked/#comments</comments>
		<pubDate>Mon, 18 May 2009 01:01:11 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://sechero.com/the-new-york-times-twitter-account-hijacked/</guid>
		<description><![CDATA[The New York Times Twitter Account Hijacked The Moment, a popular fashion blog belonging to the New York Times, had its Twitter account commandeered by cyber-crooks. Following the incident, more than half a million users of the micro-blogging platform received adult-oriented spam. A message reading, &#8220;Everyone visit tinyurl.com/[removed] for 100% FREE webcam girls/guys doing anything [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31332">The New York Times Twitter Account Hijacked</a></h1>
</p>
<p>The Moment, a popular fashion blog belonging to the New York Times, had its Twitter account commandeered by cyber-crooks. Following the incident, more than half a million users of the micro-blogging platform received adult-oriented spam.</p>
<p>A message reading, &#8220;Everyone visit <a href="http://tinyurl.com/" title="http://tinyurl.com/" target="_blank">tinyurl.com/</a>[removed] for 100% FREE webcam girls/guys doing anything you ask them in the chat, I love it personally,&#8221; baffled The Moment&#8217;s Twitter followers on Thursday.</p>
<p>The security breach was confirmed a couple of hours later, after the real owners regained control of the compromised account. &#8220;In case that spam wasn&#8217;t obvious enough ˇX Yes, we were hacked! What a lousy way to thank our half million followers. Sorry everybody!&#8221; they wrote.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31332">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31332</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/the-new-york-times-twitter-account-hijacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Mac OS X iChat Disabled SSL Connection Information Disclosure Vulnerability</title>
		<link>http://sechero.com/apple-mac-os-x-ichat-disabled-ssl-connection-information-disclosure-vulnerability/</link>
		<comments>http://sechero.com/apple-mac-os-x-ichat-disabled-ssl-connection-information-disclosure-vulnerability/#comments</comments>
		<pubDate>Thu, 14 May 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/apple-mac-os-x-ichat-disabled-ssl-connection-information-disclosure-vulnerability/</guid>
		<description><![CDATA[Vuln: Apple Mac OS X iChat Disabled SSL Connection Information Disclosure Vulnerability Apple Mac OS X iChat Disabled SSL Connection Information Disclosure Vulnerability URL: http://www.securityfocus.com/bid/34973]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/bid/34973">Vuln: Apple Mac OS X iChat Disabled SSL Connection Information Disclosure Vulnerability</a></h1>
</p>
<p>Apple Mac OS X iChat Disabled SSL Connection Information Disclosure Vulnerability
<p>URL: <a href="http://www.securityfocus.com/bid/34973">http://www.securityfocus.com/bid/34973</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/apple-mac-os-x-ichat-disabled-ssl-connection-information-disclosure-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple delivers jumbo security update for Mac OS X</title>
		<link>http://sechero.com/apple-delivers-jumbo-security-update-for-mac-os-x/</link>
		<comments>http://sechero.com/apple-delivers-jumbo-security-update-for-mac-os-x/#comments</comments>
		<pubDate>Wed, 13 May 2009 03:35:13 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://sechero.com/apple-delivers-jumbo-security-update-for-mac-os-x/</guid>
		<description><![CDATA[Apple delivers jumbo security update for Mac OS X Apple Inc. today patched 67 vulnerabilities in Mac OS X, including two bugs that researchers used in March to walk off with $5,000 each in a noted hacking contest. Tuesday&#8217;s update was the largest for Apple since March 2008. &#8220;For Apple, updates this size are now [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31273">Apple delivers jumbo security update for Mac OS X</a></h1>
</p>
<p>Apple Inc. today patched 67 vulnerabilities in Mac OS X, including two bugs that researchers used in March to walk off with $5,000 each in a noted hacking contest.</p>
<p>Tuesday&#8217;s update was the largest for Apple since March 2008. &#8220;For Apple, updates this size are now becoming the norm,&#8221; said Andrew Storms, director of security operations at nCircle Network Security.</p>
<p>Security Update 2009-002, which was bundled with the upgrade for Leopard to Mac OS X 10.5.7, and available separately for users of Tiger, plugged holes in BIND, CoreGraphics, Disk Images, Flash Player, iChat, Kerberos, QuickDraw Manager, Safari, Spotlight, WebKit and other bits and pieces of the operating system.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31273">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31273</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/apple-delivers-jumbo-security-update-for-mac-os-x/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple patches and updates, (Tue, May 12th)</title>
		<link>http://sechero.com/apple-patches-and-updates-tue-may-12th/</link>
		<comments>http://sechero.com/apple-patches-and-updates-tue-may-12th/#comments</comments>
		<pubDate>Tue, 12 May 2009 23:07:09 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Apple patches and updates, (Tue, May 12th) Apple released patches today: Apple OS X 10.5.7 update / Security update 2009-002 10.5.7 is an update of the operating system (much like a service pack in the windows world) and contains functionality as well as security updates. The security content of this update is: Apache: CVE-2008-2939, CVE-2008-0456 [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://isc.sans.org/diary.php?storyid=6382&amp;rss">Apple patches and updates, (Tue, May 12th)</a></h1>
</p>
<p>Apple released patches today:</p>
<p>     Apple OS X 10.5.7 update / Security update 2009-002<br />     10.5.7 is an update of the operating system (much like a service pack in the windows world) and contains functionality as well as security updates.<br />     The security content of this update is:</p>
<p>         Apache: CVE-2008-2939, CVE-2008-0456<br />         ATS: CVE-2009-0154<br />         BIND (update to 9.3.6-P1 or 9.4.2-P1): CVE-2009-0025<br />         CFNetwork: CVE-2009-0144, CVE-2009-0157<br />         CoreGraphics: CVE-2009-0155, CVE-2009-0146, CVE-2009-0147, CVE-2009-0165<br />         Cscope: CVE-2009-0148<br />         CUPS: CVE-2009-0164<br />         Disk Images: CVE-2009-0150, CVE-2009-0149<br />         Enscript (update to 1.6.4): CVE-2004-1184, CVE-2004-1185, CVE-2004-1186, CVE-2008-3863<br />         Flash Player plug-in (update to 10.0.22.87 or 9.0.159.0): CVE-2009-0519, CVE-2009-0520, CVE-2009-0114<br />         Help Viewer: CVE-2009-0942, CVE-2009-0943<br />         iChat: CVE-2009-0152<br />         International Components for Unicode: CVE-2009-0153<br />         IPSec:CVE-2008-3651, CVE-2008-3652<br />         Kerberos: CVE-2009-0845, CVE-2009-0846, CVE-2009-0847, CVE-2009-0844<br />         Kernel: CVE-2008-1517<br />         Launch Services: CVE-2009-0156<br />         libxml: CVE-2008-3529<br />         Net-SNMP: CVE-2008-4309<br />         Network Time: CVE-2009-0021, CVE-2009-0159<br />         Networking: CVE-2008-3530<br />         OpenSSL: CVE-2008-5077<br />         PHP: CVE-2008-3659, CVE-2008-2829, CVE-2008-3660, CVE-2008-2666, CVE-2008-2371, CVE-2008-2665, CVE-2008-3658, CVE-2008-5557 (upgrade to 5.2.8)<br />         QuickDraw Manager: CVE-2009-0160, CVE-2009-0010<br />         Ruby (a.o. update to 1.8.6-p287): CVE-2008-3443, CVE-2008-3655, CVE-2008-3656, CVE-2008-3657, CVE-2008-3790, CVE-2009-0161<br />         Safari: CVE-2009-0162<br />         Spotlight: CVE-2009-0944<br />         system_cmds<br />         telnet: CVE-2009-0158<br />         WebKit: CVE-2009-0945<br />         X11 (a.o. updates to FreeType 2.3.8, libpng 1.2.35): CVE-2006-0747, CVE-2007-2754, CVE-2008-2383, CVE-2008-1382, CVE-2009-0040, CVE-2009-0946</p>
<p>     as always, this update is all or nothing, o no mixing and matching of what you need more urgently than other.</p>
<p>     Safari 4 beta</p>
<p>         libxml: CVE-2008-3529<br />         Safari: CVE-2009-0162<br />         WebKit: CVE-2009-0945</p>
<p>     Safari 3.2.3</p>
<p>         libxml: CVE-2008-3529<br />         Safari: CVE-2009-0162<br />         WebKit: CVE-2009-0945</p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/apple-patches-and-updates-tue-may-12th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MataChat &#8216;input.php&#8217; Multiple Cross Site Scripting Vulnerabilities</title>
		<link>http://sechero.com/matachat-inputphp-multiple-cross-site-scripting-vulnerabilities/</link>
		<comments>http://sechero.com/matachat-inputphp-multiple-cross-site-scripting-vulnerabilities/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[Vuln: MataChat &#8216;input.php&#8217; Multiple Cross Site Scripting Vulnerabilities MataChat &#8216;input.php&#8217; Multiple Cross Site Scripting Vulnerabilities URL: http://www.securityfocus.com/bid/34722]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/bid/34722">Vuln: MataChat &#8216;input.php&#8217; Multiple Cross Site Scripting Vulnerabilities</a></h1>
</p>
<p>MataChat &#8216;input.php&#8217; Multiple Cross Site Scripting Vulnerabilities
<p>URL: <a href="http://www.securityfocus.com/bid/34722">http://www.securityfocus.com/bid/34722</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/matachat-inputphp-multiple-cross-site-scripting-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>MataChat Cross-Site Scripting Vulnerabilities</title>
		<link>http://sechero.com/matachat-cross-site-scripting-vulnerabilities/</link>
		<comments>http://sechero.com/matachat-cross-site-scripting-vulnerabilities/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 15:50:01 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[MataChat Cross-Site Scripting Vulnerabilities &#60;!&#8211; Envelope-to: email@address Delivery-date: Mon, 27 Apr 2009 16:41:03 +0100 Received: from outgoing.securityfocus.com ([205.206.231.27] helo=outgoing3.securityfocus.com) by lt.network5.net with esmtp (Exim 4.43) id 1LySx5-00086L-0W for email@address; Mon, 27 Apr 2009 16:41:03 +0100 Received: from lists2.securityfocus.com (lists2.securityfocus.com [205.206.231.20]) by outgoing3.securityfocus.com (Postfix) with QMQP id F0AC2236F2D; Mon, 27 Apr 2009 09:05:50 -0600 (MDT) Mailing-List: [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://lists.rootsecure.net/?p=view&amp;l=bugtraq&amp;m=85359">MataChat Cross-Site Scripting Vulnerabilities</a></h1>
</p>
<p>&lt;!&#8211; Envelope-to: email@address Delivery-date: Mon, 27 Apr 2009 16:41:03 +0100 Received: from <a href="http://outgoing.securityfocus.com" title="http://outgoing.securityfocus.com" target="_blank">outgoing.securityfocus.com</a> ([205.206.231.27] helo=outgoing3.securityfocus.com) 	by <a href="http://lt.network5.net" title="http://lt.network5.net" target="_blank">lt.network5.net</a> with esmtp (Exim 4.43) 	id 1LySx5-00086L-0W 	for email@address; Mon, 27 Apr 2009 16:41:03 +0100 Received: from <a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> (<a href="http://lists2.securityfocus.com" title="http://lists2.securityfocus.com" target="_blank">lists2.securityfocus.com</a> [205.206.231.20]) 	by <a href="http://outgoing3.securityfocus.com" title="http://outgoing3.securityfocus.com" target="_blank">outgoing3.securityfocus.com</a> (Postfix) with QMQP 	id F0AC2236F2D; Mon, 27 Apr 2009 09:05:50 -0600 (MDT) Mailing-List: contact <a href="mailto:bugtraq-help@securityfocus.com;" title="mailto:bugtraq-help@securityfocus.com;">bugtraq-help@securityfocus.com;</a> run by ezmlm Precedence: bulk List-Id: &lt;bugtraq.list-id.securityfocus.com&gt; List-Post: &lt;mailto:bugtraq@securityfocus.com&gt; List-Help: &lt;mailto:bugtraq-help@securityfocus.com&gt; List-Unsubscribe: &lt;mailto:bugtraq-unsubscribe@securityfocus.com&gt; List-Subscribe: &lt;mailto:bugtraq-subscribe@securityfocus.com&gt; Delivered-To: mailing list <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Delivered-To: moderator for <a href="mailto:bugtraq@securityfocus.com" title="mailto:bugtraq@securityfocus.com">bugtraq@securityfocus.com</a> Received: (qmail 5976 invoked from network); 25 Apr 2009 05:53:34 -0000 Message-ID: &lt;20090425055840.29668.qmail@securityfocus.com&gt; Content-Type: text/plain Content-Disposition: inline MIME-Version: 1.0 X-Mailer: MIME-tools 5.411 (Entity 5.404) Content-Transfer-Encoding: quoted-printable X-IMAPbase: 1176125385 8893 Status: O X-UID: 8892 Content-Length: 2925 X-Keywords:                                                                                                    </p>
<p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/matachat-cross-site-scripting-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>4Chan Takes Over The Time 100</title>
		<link>http://sechero.com/4chan-takes-over-the-time-100/</link>
		<comments>http://sechero.com/4chan-takes-over-the-time-100/#comments</comments>
		<pubDate>Thu, 23 Apr 2009 07:19:16 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://sechero.com/4chan-takes-over-the-time-100/</guid>
		<description><![CDATA[4Chan Takes Over The Time 100 Look closely at Time magazine&#8217;s online voting results so far for the Time 100 and you will see at the top someone called moot (aka 21-year-old Christopher Poole), the founder of 4chan, the notorious online bulletin board where hackers like to hang out. Not only did moot&#8217;s followers manage [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31002">4Chan Takes Over The Time 100</a></h1>
</p>
<p>Look closely at Time magazine&#8217;s online voting results so far for the Time 100 and you will see at the top someone called moot (aka 21-year-old Christopher Poole), the founder of 4chan, the notorious online bulletin board where hackers like to hang out. Not only did moot&#8217;s followers manage to get his name to the top of the Time 100 reader&#8217;s list, they also manipulated the next 20 spots. If you take the first letter of each name, it spells out the cryptic message, &#8220;Marblecake, also the game.&#8221; (See image below). Update: According to a tip, marblecake was also the name of the chatroom &#8220;where Project Chanology was born (4chan&#8217;s war against Scientology).&#8221;</p>
<p>It turns out the results were hacked with an auto-voting program spread on 4chan. (For details of the hack, read this post). What does it mean? Marblecake is a sophomoric sexual reference, which is in keeping with the spirit of 4chan, which also claims to be where Rickrolling and Lolcats got their start.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31002">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=31002</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/4chan-takes-over-the-time-100/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Denial of Service</title>
		<link>http://sechero.com/denial-of-service-5/</link>
		<comments>http://sechero.com/denial-of-service-5/#comments</comments>
		<pubDate>Mon, 06 Apr 2009 21:20:36 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Bugtraq]]></category>
		<category><![CDATA[Chat]]></category>

		<guid isPermaLink="false">http://sechero.com/denial-of-service-5/</guid>
		<description><![CDATA[Bugtraq: [ GLSA 200904-04 ] WeeChat: Denial of Service [ GLSA 200904-04 ] WeeChat: Denial of Service URL: http://www.securityfocus.com/archive/1/502479]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/archive/1/502479">Bugtraq: [ GLSA 200904-04 ] WeeChat: Denial of Service</a></h1>
</p>
<p>[ GLSA 200904-04 ] WeeChat: Denial of Service
<p>URL: <a href="http://www.securityfocus.com/archive/1/502479">http://www.securityfocus.com/archive/1/502479</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/denial-of-service-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Denial of Service</title>
		<link>http://sechero.com/denial-of-service-4/</link>
		<comments>http://sechero.com/denial-of-service-4/#comments</comments>
		<pubDate>Sat, 04 Apr 2009 17:22:54 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Linux]]></category>

		<guid isPermaLink="false">http://sechero.com/denial-of-service-4/</guid>
		<description><![CDATA[[ GLSA 200904-04 ] WeeChat: Denial of Service Posted by Tobias Heinlein on Apr 04 &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - Gentoo Linux Security Advisory [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://seclists.org/fulldisclosure/2009/Apr/0040.html">[ GLSA 200904-04 ] WeeChat: Denial of Service</a></h1>
</p>
<p>Posted by Tobias Heinlein on Apr 04
</p>
<p>
<p> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br /> Gentoo Linux Security Advisory                           GLSA 200904-04 <br /> &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - &#8211; - <br />&#8230;
<p>URL: <a href="http://seclists.org/fulldisclosure/2009/Apr/0040.html">http://seclists.org/fulldisclosure/2009/Apr/0040.html</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/denial-of-service-4/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Major Chinese Game (Duowan) Spoofed Web Site Serving Trojan Ranked Top in Baidu</title>
		<link>http://sechero.com/major-chinese-game-duowan-spoofed-web-site-serving-trojan-ranked-top-in-baidu/</link>
		<comments>http://sechero.com/major-chinese-game-duowan-spoofed-web-site-serving-trojan-ranked-top-in-baidu/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 19:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Fake]]></category>
		<category><![CDATA[Lab]]></category>
		<category><![CDATA[Trojan]]></category>

		<guid isPermaLink="false">http://sechero.com/major-chinese-game-duowan-spoofed-web-site-serving-trojan-ranked-top-in-baidu/</guid>
		<description><![CDATA[Malicious Web Site / Malicious Code: SEO Poisoning: Major Chinese Game (Duowan) Spoofed Web Site Serving Trojan Ranked Top in Baidu WebsenseÂ® Security Labsâ„˘ ThreatSeekerâ„˘ Network has discovered that a download site supplying free audio chat software to users under Duowan.com has been SEO poisoned with the intention of directing visitors to a malicious site. [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://securitylabs.websense.com/content/Alerts/3328.aspx">Malicious Web Site / Malicious Code: SEO Poisoning: Major Chinese Game (Duowan) Spoofed Web Site Serving Trojan Ranked Top in Baidu</a></h1>
</p>
<p>
<p>WebsenseÂ® Security Labsâ„˘ ThreatSeekerâ„˘ Network has discovered that a download site supplying free audio chat software to users under <a href="http://Duowan.com" title="http://Duowan.com" target="_blank">Duowan.com</a> has been SEO poisoned with the intention of directing visitors to a malicious site.</p>
<p>Duowan.com is a large Chinese Internet game community which has an Alexa traffic rank of 448. If you search for YY in <a href="http://Baidu.com" title="http://Baidu.com" target="_blank">Baidu.com</a>, the malicious site which is masquerading as the <a href="http://Duowan.com" title="http://Duowan.com" target="_blank">Duowan.com</a> download site appears as the first result.</p>
<p>The search result in <a href="http://Baidu.com" title="http://Baidu.com" target="_blank">Baidu.com</a>:<br /> 
<p>The fake site:&nbsp;<br /> 
<p>This is the offical site: </p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/major-chinese-game-duowan-spoofed-web-site-serving-trojan-ranked-top-in-baidu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Macs lacking in security</title>
		<link>http://sechero.com/macs-lacking-in-security/</link>
		<comments>http://sechero.com/macs-lacking-in-security/#comments</comments>
		<pubDate>Thu, 26 Mar 2009 00:38:54 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://sechero.com/macs-lacking-in-security/</guid>
		<description><![CDATA[Charlie Miller: Macs lacking in security Youˇ¦ve probably seen the headlines: ˇ§Pwn2Own 2008: MacBook Air hacked in 2 minutesˇ¨ or ˇ§Pwn2Own 2009: Safari/MacBook falls in seconds.ˇ¨ But thereˇ¦s a story behind every headline and who better to get the story from than Charlie Miller, the man behind the headlines? We had the opportunity to chat [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=30634">Charlie Miller: Macs lacking in security</a></h1>
</p>
<p>Youˇ¦ve probably seen the headlines: ˇ§Pwn2Own 2008: MacBook Air hacked in 2 minutesˇ¨ or ˇ§Pwn2Own 2009: Safari/MacBook falls in seconds.ˇ¨ But thereˇ¦s a story behind every headline and who better to get the story from than Charlie Miller, the man behind the headlines? We had the opportunity to chat with Charlie after his back-to-back successes in demonstrating zero-day exploits affecting the Mac.
<p>URL: <a href="http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=30634">http://www.hackinthebox.org/index.php?name=News&amp;file=article&amp;sid=30634</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/macs-lacking-in-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ontario Court Orders Website To Disclose Identity of Anonymous Posters</title>
		<link>http://sechero.com/ontario-court-orders-website-to-disclose-identity-of-anonymous-posters/</link>
		<comments>http://sechero.com/ontario-court-orders-website-to-disclose-identity-of-anonymous-posters/#comments</comments>
		<pubDate>Wed, 25 Mar 2009 10:51:05 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[Disclosure]]></category>
		<category><![CDATA[Email]]></category>
		<category><![CDATA[Mail]]></category>
		<category><![CDATA[PHP]]></category>

		<guid isPermaLink="false">http://sechero.com/ontario-court-orders-website-to-disclose-identity-of-anonymous-posters/</guid>
		<description><![CDATA[Ontario Court Orders Website To Disclose Identity of Anonymous Posters An Ontario court has ordered (pdf) the owners of the FreeDominion.ca to disclose all personal information on eight anonymous posters to the chat site. The required information includes email and IP addresses. The case arises from a lawsuit launched by Richard Warman, the anti-hate fighter, [...]]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.pogowasright.org/article.php?story=20090325065105842">Ontario Court Orders Website To Disclose Identity of Anonymous Posters</a></h1>
</p>
<p>
<p>An Ontario court has <a href="http://www.freedominion.com.pa/images/motion_decision.pdf">ordered</a> (pdf) the owners of the FreeDominion.ca to disclose all personal information on eight anonymous posters to the chat site.  The required information includes email and IP addresses.  The case arises from a lawsuit launched by Richard Warman, the anti-hate fighter, against the site and the posters.  The court focused heavily on the Ontario Rules of Civil Procedure, which contain a strong duty of disclosure on litigants.</p>
<p>Source &#8211; <a href="http://www.michaelgeist.ca/content/blogsection/0/125/" target="_blank"> Michael Geist </a></p>
<p><a href="http://reddit.com/submit?url=http://www.pogowasright.org/article.php?story=20090325065105842" target="_new">Reddit It</a>Â |Â <a href="http://digg.com/submit?phase=2&amp;url=http://www.pogowasright.org/article.php?story=20090325065105842" target="_new">Digg This</a>Â |Â <a href="http://del.icio.us/post?url=http://www.pogowasright.org/article.php?story=20090325065105842" target="_new">Add to <a href="http://del.icio.us" title="http://del.icio.us" target="_blank">del.icio.us</a></a></p>
<p>URL: <a href="http://www.pogowasright.org/article.php?story=20090325065105842">http://www.pogowasright.org/article.php?story=20090325065105842</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/ontario-court-orders-website-to-disclose-identity-of-anonymous-posters/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHPizabi &#8216;modules/chat/dac.php&#8217; Local File Include Vulnerability</title>
		<link>http://sechero.com/phpizabi-moduleschatdacphp-local-file-include-vulnerability/</link>
		<comments>http://sechero.com/phpizabi-moduleschatdacphp-local-file-include-vulnerability/#comments</comments>
		<pubDate>Tue, 24 Mar 2009 00:00:00 +0000</pubDate>
		<dc:creator>invalid string</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Chat]]></category>
		<category><![CDATA[PHP]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://sechero.com/phpizabi-moduleschatdacphp-local-file-include-vulnerability/</guid>
		<description><![CDATA[Vuln: PHPizabi &#8216;modules/chat/dac.php&#8217; Local File Include Vulnerability PHPizabi &#8216;modules/chat/dac.php&#8217; Local File Include Vulnerability URL: http://www.securityfocus.com/bid/34213]]></description>
			<content:encoded><![CDATA[</p>
<p>
<h1><a href="http://www.securityfocus.com/bid/34213">Vuln: PHPizabi &#8216;modules/chat/dac.php&#8217; Local File Include Vulnerability</a></h1>
</p>
<p>PHPizabi &#8216;modules/chat/dac.php&#8217; Local File Include Vulnerability
<p>URL: <a href="http://www.securityfocus.com/bid/34213">http://www.securityfocus.com/bid/34213</a></p>
</p></p>
]]></content:encoded>
			<wfw:commentRss>http://sechero.com/phpizabi-moduleschatdacphp-local-file-include-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

