<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-34288918</id><updated>2011-04-21T16:48:03.898-07:00</updated><title type='text'>The Front Line Warrior</title><subtitle type='html'>The view from the front line of the information security wars.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://thefrontlinewarrior.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34288918/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://thefrontlinewarrior.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>William Bell</name><uri>http://www.blogger.com/profile/17864550254159686884</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-34288918.post-115827086886547059</id><published>2006-09-14T14:45:00.000-07:00</published><updated>2006-09-14T14:54:28.990-07:00</updated><title type='text'></title><content type='html'>&lt;span style="font-weight: bold;"&gt;More Fun with ActiveX&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Today brings us yet another ActiveX COM vulnerability, this bug is deemed "extremely criticial" by Secunia.com and pretty much everyone else.&lt;br /&gt;&lt;br /&gt;The bug hunter was kind enough to submit a POC along with his disclosure.&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;Here is the link to the&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt; &lt;a href="http://www.xsec.org/index.php?module=releases&amp;act=view&amp;amp;type=2&amp;id=20"&gt;POC&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;I have tested the code against IE 6 SP2 installed on a fully patched XP SP2 and it is vulnerable. Symantec catches the shell code in the POC and labels the dumped content as a "Trojan Horse". This of course can be easily bypassed with a proper payload.&lt;br /&gt;&lt;br /&gt;I hope MS is well on their way to a Critical Patch push, else we could all be in for some fun.&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34288918-115827086886547059?l=thefrontlinewarrior.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thefrontlinewarrior.blogspot.com/feeds/115827086886547059/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34288918&amp;postID=115827086886547059' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34288918/posts/default/115827086886547059'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34288918/posts/default/115827086886547059'/><link rel='alternate' type='text/html' href='http://thefrontlinewarrior.blogspot.com/2006/09/more-fun-with-activex-today-brings-us.html' title=''/><author><name>William Bell</name><uri>http://www.blogger.com/profile/17864550254159686884</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34288918.post-115816243973572037</id><published>2006-09-13T08:41:00.000-07:00</published><updated>2006-09-13T08:49:11.223-07:00</updated><title type='text'></title><content type='html'>So if you have been living under a rock for the last two days, on vacation, or otherwise completely out of the loop, RSA Signature Forgery has been the hot topic. The Matasano Team has been covering it, with the help of Nate Lawson from Cryptography Research.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.matasano.com/log/486/rsa-signature-forgery-explained-with-nate-lawson-part-i/"&gt;Part 1 - New Attack&lt;/a&gt;&lt;br /&gt;&lt;a href="http://www.matasano.com/log/487/rsa-signature-forgery-explained-with-nate-lawson-part-ii/"&gt;Part 2 - Public Key Difficulties&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This is the first two parts of what the team is calling an N part series, hopefully&lt;br /&gt;&lt;br /&gt;N = ( Dead Horse ) - 1&lt;br /&gt;&lt;br /&gt;Thanks to the Matasano Team and Nate for providing the in depth coverage.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34288918-115816243973572037?l=thefrontlinewarrior.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thefrontlinewarrior.blogspot.com/feeds/115816243973572037/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34288918&amp;postID=115816243973572037' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34288918/posts/default/115816243973572037'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34288918/posts/default/115816243973572037'/><link rel='alternate' type='text/html' href='http://thefrontlinewarrior.blogspot.com/2006/09/so-if-you-have-been-living-under-rock.html' title=''/><author><name>William Bell</name><uri>http://www.blogger.com/profile/17864550254159686884</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-34288918.post-115808315995588358</id><published>2006-09-12T10:41:00.000-07:00</published><updated>2006-09-13T08:24:35.346-07:00</updated><title type='text'></title><content type='html'>PCI Standards Updated to v 1.1&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.pcisecuritystandards.org/tech/supporting_documents.htm"&gt;PCI DSS v 1.1 Documentation&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;With the formation of the PCI Security Standards Council, comes the latest release of the PCI Data Security Standard.&lt;br /&gt;&lt;br /&gt;Highlights include requirements for application code reviews, improved log retention, and improved physical security.&lt;br /&gt;&lt;br /&gt;The PCI Security Council is making a valiant attempt to keep its standard on the cutting edge, with clear and concise requirements and no legalese that is rampant in most compliance documents.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/34288918-115808315995588358?l=thefrontlinewarrior.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://thefrontlinewarrior.blogspot.com/feeds/115808315995588358/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=34288918&amp;postID=115808315995588358' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/34288918/posts/default/115808315995588358'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/34288918/posts/default/115808315995588358'/><link rel='alternate' type='text/html' href='http://thefrontlinewarrior.blogspot.com/2006/09/pci-standards-updated-to-v-1.html' title=''/><author><name>William Bell</name><uri>http://www.blogger.com/profile/17864550254159686884</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
