<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: flaws]]></title>
    <link>http://securityratty.com/tag/flaws</link>
    <description></description>
    <pubDate>Thu, 30 Oct 2008 01:35:17 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Online Finance Flaw: TIAA-CREF XSS & Potential CSRF]]></title>
      <link>http://securityratty.com/article/5978268eaad37c626521f5473142a03e</link>
      <guid>http://securityratty.com/article/5978268eaad37c626521f5473142a03e</guid>
      <description><![CDATA[Before discussing a TIAA-CREF security flaw, allow me to clarify my &quot;terms of engagement
Prior to offering analysis of any security flaws in online financial services, be assured I have engaged the...]]></description>
      <content:encoded><![CDATA[Before discussing a <a href="http://www.tiaa-cref.org/" target="_blank">TIAA-CREF</a> security flaw, allow me to clarify my "terms of engagement". <br />Prior to offering analysis of any security flaws in online financial services, be assured I have engaged the service provider and offered what I believe to a reasonable amount of time to remedy this issue. Specifically, a minimum of two weeks and three unique contact attempts are made. Should the vendor offer a timeline in which the issue will be resolved, so long as it is not months or years, I will wait until they are ready to deploy the fix, then discuss the vulnerability. If I am not in receipt of a reply other than generic customer service replies, I will follow the two week standard, then discuss the issue.<br /><br />TIAA-CREF, or the Teachers Insurance and Annuity Association - College Retirement Equities Fund, is a respected, widely utilized provider of numerous financial products and services. The TIAA-CREF site is ranked <a href="http://www.alexa.com/search?q=tiaa-cref.org" target="_blank">26,148</a> on <a href="http://www.alexa.com" target="_blank">Alexa.com</a> at the time of this writing.<br /><br />I'll first direct you to the TIAA-CREF <a href="http://www.tiaa-cref.org/about/inside/topics/security.html" target="_blank">Security</a> page, where they discuss the expected elements like identity theft, spoofing, tips, and my favorite, phishing.<br />Here's where the trouble begins. Obviously, most phishing occurs when some miscreant creates a fake page and attempts to lure victims via email. <br /><span style="font-weight:bold;">The severity of phishing risks are greatly increased by the introduction of a cross-site scripting (<a href="http://en.wikipedia.org/wiki/Cross-site_scripting" target+"_blank">XSS</a>) vulnerability in a site that is of high value to phishing attackers.</span> <br />With such a vulnerability available, the prospect of success for a phisher are much higher given that the malicious URL they would craft could include the actual target domain, rather than a faked misrepresentation. A simple script insertion at the vulnerable variable would then allow the attacker to redirect victims to a maliciously crafted logon page in the context of the vulnerable site.<br />Sad side note: when you search <span style="font-style:italic;">security</span> at the TIAA-CREF site, the above mentioned Security page is not returned in the results as I write this. <br />However, the resulting search URL serves as the starting point for our discussion of the flaw:<br /><span style="font-style:italic;">http://www.tiaa-cref.org/explore/portlets/search.jsp?query=security&strtfrm=1&totpresults=75&srchtype=4&sc=1&frmsite=0</span><br />The vast majority of non-search input variables on the TIAA-CREF site offer reasonable XSS protections, likely a blacklist method that redirects you to the following language when common XSS strings are noted, particularly where it counts at logon pages.<br /><span style="font-weight:bold;">Due to the presence of characters known to be used in Cross Site Scripting attacks, access is forbidden. This web site does not allow Urls which might include embedded HTML tags.<span style="font-style:italic;"></span></span> <br />Unfortunately, this methodology was not deployed globally, and thus the following online finance flaw.<br />All input variables used in TIAA-CREF's search.jsp script are vulnerable to XSS.<br />Utilized by an attacker, this could have a much more significant impact on TIAA-CREF customers who fall victim to a now more convincing social engineering effort.<br />Here's the site before script insertion:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_kVOWaY1TAF0/STb14rWuuOI/AAAAAAAAAFk/ydVDLZjjwNI/s1600-h/tiaa-cref-before.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 166px;" src="http://1.bp.blogspot.com/_kVOWaY1TAF0/STb14rWuuOI/AAAAAAAAAFk/ydVDLZjjwNI/s320/tiaa-cref-before.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5275674367570655458" /></a><br /><br />Here's the site after script insertion:<br /><br /><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_kVOWaY1TAF0/STb2X3oLzeI/AAAAAAAAAFs/FBGmafHFZ2o/s1600-h/tiaa-cref-after.png" target="_blank"><img style="cursor:pointer; cursor:hand;width: 320px; height: 198px;" src="http://3.bp.blogspot.com/_kVOWaY1TAF0/STb2X3oLzeI/AAAAAAAAAFs/FBGmafHFZ2o/s320/tiaa-cref-after.png" border="0" alt=""id="BLOGGER_PHOTO_ID_5275674903441034722" /></a><br /><br />Further, certain parts of the site, including the <a href="https://www.account3000.com/tiaacref/TFALogin.asp" target="_blnak">Trust Company</a> logon page, show potential signs of cross-site request forgery (<a href="http://en.wikipedia.org/wiki/Cross-site_request_forgery" target="_blank">CSRF</a>) in that they accept updates via GET or allow submittal with the referrer stripped.<br /><br />Lessons learned:<br />1) Don't assume all is well even though a site may offer examples of how attentive they are to security.<br />2) Never log on to an online financial service offering (or anything else for that matter) via a link sent to you in an email. Period.<br />3) Take all steps at your disposal to ensure you are logging in to and transacting with the actual site you intended to utilize. Don't depend on security badges and SSL certificates as your sole means of confirmation.<br />4) If you note something of concern at a site you utilize, advise them immediately and demand repair or clarification until you're satisfied. <br /><br />Please feel free to send <a href="http://www.tiaa-cref.org/about/contact/index.html?tc_lnk=toputlity" target="_blank">feedback</a> to TIAA-CREF as I have per my "terms of engagement" above. Hopefully they'll resolve this issue soon, on behalf of customers in their care.<br /><br />Up next in our series, two of the top five banks mentioned in Javelin Strategy & Research's <span style="font-style:italic;">Banking Identity Safety Scorecard</span> are vulnerable to similar issues.<br /><br /><a href="http://del.icio.us/post?url=http://holisticinfosec.blogspot.com/2008/12/online-finance-flaw-tiaa-cref-xss.html&title=Online%20Finance%20Flaw:%20TIAA-CREF%20XSS%20&%20Potential%20CSRF " title="Online Finance Flaw: TIAA-CREF XSS & Potential CSRF ">del.icio.us</a> | <a href="http://digg.com/submit?phase=2&amp;url=http://holisticinfosec.blogspot.com/2008/12/online-finance-flaw-tiaa-cref-xss.html" title="Online Finance Flaw: TIAA-CREF XSS & Potential CSRF ">digg</a> | <a href="http://slashdot.org/submit.pl?url=http://holisticinfosec.blogspot.com/2008/12/online-finance-flaw-tiaa-cref-xss.html">Submit to Slashdot</a>]]></content:encoded>
      <pubDate>Wed, 03 Dec 2008 06:42:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/tiaa-cref">tiaa-cref</category>
      <category domain="http://securityratty.com/tag/site">site</category>
      <category domain="http://securityratty.com/tag/cross-site">cross-site</category>
      <category domain="http://securityratty.com/tag/tiaa-cref site">tiaa-cref site</category>
      <category domain="http://securityratty.com/tag/tiaa-cref security flaw">tiaa-cref security flaw</category>
      <category domain="http://securityratty.com/tag/flaw">flaw</category>
      <category domain="http://securityratty.com/tag/tiaa-cref security page">tiaa-cref security page</category>
      <category domain="http://securityratty.com/tag/security page">security page</category>
      <category domain="http://securityratty.com/tag/cross site">cross site</category>
      <source url="http://holisticinfosec.blogspot.com/2008/12/online-finance-flaw-tiaa-cref-xss.html">Online Finance Flaw: TIAA-CREF XSS &amp; Potential CSRF</source>
    </item>
    <item>
      <title><![CDATA[Online Finance Flaws: An Awareness Campaign]]></title>
      <link>http://securityratty.com/article/1aabc5edbe215010d8c71b5aa4aa7551</link>
      <guid>http://securityratty.com/article/1aabc5edbe215010d8c71b5aa4aa7551</guid>
      <description><![CDATA[Here begins a series regarding web application security inadequacies in online financial service offerings. The services to be discussed will include banks, credit unions, credit card companies, and...]]></description>
      <content:encoded><![CDATA[Here begins a series regarding web application security inadequacies in online financial service offerings. The services to be discussed will include banks, credit unions, credit card companies, and others. As the economy struggles profoundly, and much of the blame points at the financial sector, I believe it important to point out the false sense of security so many brand-name financial services wrongly instill in their customers.<br />Often this sense of security is coupled with a typical "security badge" provider, helping drive conversions rather than security, as we will also legitimize how often the badge providers miss the mark on their promises.<br />Accountability in loan making decisions and practices might have prevented the sub-prime market collapse and the subsequent credit crunch that has hogtied our economy. <br />Accountability with regard to web application security while providing online financial services is now all the more important as <a href="http://securitywatch.eweek.com/exploits_and_attacks/as_economy_dives_underground_thrives.html" target="_blank">cybercrime</a> will continue to increase at a pace proportionate to economic woes.<br />Each post relevant to this campaign will include Online Finance Flaw in its title for tracking purposes. <br />Look forward to surprising flaws in financial services brands you'll recognize.<br />Perhaps, the more attention we draw to services that should place security above all else, the more likely it is they'll commit to improving their security posture.<br />Feel free to comment or contribute; we'll begin in a day or two.]]></content:encoded>
      <pubDate>Sat, 29 Nov 2008 19:08:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/web application security">web application security</category>
      <category domain="http://securityratty.com/tag/financial services brands">financial services brands</category>
      <category domain="http://securityratty.com/tag/security badge">security badge</category>
      <category domain="http://securityratty.com/tag/services">services</category>
      <category domain="http://securityratty.com/tag/security posture">security posture</category>
      <category domain="http://securityratty.com/tag/online financial services">online financial services</category>
      <category domain="http://securityratty.com/tag/economy">economy</category>
      <category domain="http://securityratty.com/tag/economy struggles profoundly">economy struggles profoundly</category>
      <source url="http://holisticinfosec.blogspot.com/2008/11/online-finance-flaws-awareness-campaign_29.html">Online Finance Flaws: An Awareness Campaign</source>
    </item>
    <item>
      <title><![CDATA[Microsoft: First exploit ratings show success]]></title>
      <link>http://securityratty.com/article/dffc7515c546b02b5835629983298e8c</link>
      <guid>http://securityratty.com/article/dffc7515c546b02b5835629983298e8c</guid>
      <description><![CDATA[Microsoft was eight for 20 in its first predictions of how exploitable the flaws in its software would be. But that was good enough for the company to claim...]]></description>
      <content:encoded><![CDATA[Microsoft was eight for 20 in its first predictions of how exploitable the flaws in its software would be. But that was good enough for the company to claim success.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:677335ca695d8dab7c18daa3b9354977:d1UL7LceTDW%2F0EozAMVJPzDry11oJVWQC49nNTsT6MVXDkjYcHOSlGNmOqz9cLdKy%2BV0TNzkj5Kq'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:b7e3c8117a11c0df75f3a07dce98a666:i5B8UCWRWH4lgIvfnHanuptZLpepIjHmOC5I%2BOIDfusUqQK7xtoJh9DzBLx9zZpCaLe76tZohRoXoQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:982e134d1a2d4bd9e7edc5db9a2f7f80:pvM3N%2Bd8YaFUJvFhFxcpE7aDbsmvFYTziDQyKBmPSY%2F2%2FR7JBgMrS5vroPYlyT76e9uDTctZHmXnWQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:bb03914e8ddad04911bbb3cc210e266a:zKMz80LZtdhMGeMp5Brde6yI0GsA53vKsKK4AopL%2BFPBo8dPftH7%2BfwjnykmsGZp4ze0IrF4ntbwQA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=55d8b06ec75e5b6ec9677f92803b6d3e" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=55d8b06ec75e5b6ec9677f92803b6d3e" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Mon, 17 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/claim success">claim success</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/software">software</category>
      <category domain="http://securityratty.com/tag/predictions">predictions</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/company">company</category>
      <category domain="http://securityratty.com/tag/exploitable">exploitable</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=55d8b06ec75e5b6ec9677f92803b6d3e">Microsoft: First exploit ratings show success</source>
    </item>
    <item>
      <title><![CDATA[Apple plays catch-up, ads anti-fraud safeguard to Safari]]></title>
      <link>http://securityratty.com/article/949c25cc922a5535dd873e46a0e7d378</link>
      <guid>http://securityratty.com/article/949c25cc922a5535dd873e46a0e7d378</guid>
      <description><![CDATA[In an update to its Safari Web browser, Apple on Thursday patched several security flaws and added anti-phishing protection -- making it the last major browser to receive the feature that blocks known...]]></description>
      <content:encoded><![CDATA[In an update to its Safari Web browser, Apple on Thursday patched several security flaws and added anti-phishing protection -- making it the last major browser to receive the feature that blocks known identity-stealing sites.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:a81f524bd87796a718dc935f96bf64b0:aSLzi9e0JNzXSvY%2Bu9Uu8Tjtpg%2F4VbUZU9as2mAYqkph%2FaWDgX%2Fg6ZJ88MzCtOlxyUmJrbM5R1%2BC'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:d8058c83a09391fc4a875abd9273c2d8:Ove5%2FRPNbN39Bq7RW42e86yXw8B3yA2Lmd0kYc0RNiZJ0qUxXiSDKVYB%2BiVnGo25Wi%2B%2BmSFFjWtwXQ%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:214c44e436c54d95e2ce19b25f6330a5:VU3q1pVu8lQRivyhKfuFEEeIp6oe7xEg%2FGcKB7WpSGHxaNbUzGZvcATtWxKd2FFoM%2Budcc0CCW2dIQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:0dc6c5d43e324af14a12a7a2b45a2503:13wLNFM%2BYtZruwJ7RAnLKf9A0uh96L%2BKy67UBuEOBm969rJuTqDb%2B%2Fyod1adK6BW%2BH10Um%2Bk7tAuaw%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=c57d1d9341b46aa89dfe1a3a5f949aeb" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=c57d1d9341b46aa89dfe1a3a5f949aeb" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Fri, 14 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/safari web browser">safari web browser</category>
      <category domain="http://securityratty.com/tag/apple">apple</category>
      <category domain="http://securityratty.com/tag/major browser">major browser</category>
      <category domain="http://securityratty.com/tag/security flaws">security flaws</category>
      <category domain="http://securityratty.com/tag/protection">protection</category>
      <category domain="http://securityratty.com/tag/sites">sites</category>
      <category domain="http://securityratty.com/tag/blocks">blocks</category>
      <category domain="http://securityratty.com/tag/receive">receive</category>
      <category domain="http://securityratty.com/tag/feature">feature</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=c57d1d9341b46aa89dfe1a3a5f949aeb">Apple plays catch-up, ads anti-fraud safeguard to Safari</source>
    </item>
    <item>
      <title><![CDATA[Mozilla fixes 11 new flaws in Firefox, six critical]]></title>
      <link>http://securityratty.com/article/a18a8c554ba3730c699f5a2b2577779a</link>
      <guid>http://securityratty.com/article/a18a8c554ba3730c699f5a2b2577779a</guid>
      <description><![CDATA[Mozilla has patched 11 vulnerabilities in Firefox 3.0 -- and 12 bugs in the older Firefox 2.0 -- that could be used to compromise computers and steal...]]></description>
      <content:encoded><![CDATA[Mozilla has patched 11 vulnerabilities in Firefox 3.0 -- and 12 bugs in the older Firefox 2.0 -- that could be used to compromise computers and steal information.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:cf08f0c5563137391e24cab21121a0f3:q4vS%2F5edGIT6mK7SxbS6QsaqEeeFvWygLlcmb%2FNasNtpjFZikFyCDXJeIFqr4zmxS%2Bh%2B7kUL4lGs'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5a8abb23899446eaa11b8249ab3985c3:YbwTxC3XCHLL1M9Uu40UUZxVLGh3xz6dwRrWBcZ0tItQc6WCrAwzvCMhhBeN83ksZ4YUm0I5as8EqA%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:728522c00fb4071725c9756f19f8af5a:1%2B3QbCv0CQsFJ4kgUcMO%2Fq4e955S67vpEKxlC1Vg1x6zkz88qITWQJZZez2xffZWpztlAo8YGxO%2FBQ%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:5e91ad34ddcb53436e071e23365ac6c8:xIPHmGY0aHpihGq2KTHZuqPz5XK71SzkG7DmPnbTYsli5Ee35AtdRWo7g917Hvv0xbB3OH1h3G8lhA%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=1ac6ad125b130743917577d9026d0635" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=1ac6ad125b130743917577d9026d0635" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 13 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firefox">firefox</category>
      <category domain="http://securityratty.com/tag/compromise computers">compromise computers</category>
      <category domain="http://securityratty.com/tag/mozilla">mozilla</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/bugs">bugs</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=1ac6ad125b130743917577d9026d0635">Mozilla fixes 11 new flaws in Firefox, six critical</source>
    </item>
    <item>
      <title><![CDATA[Mozilla fixes 11 new flaws in Firefox, six critical]]></title>
      <link>http://securityratty.com/article/2252473c0d17cce48f2fb9276bfd9515</link>
      <guid>http://securityratty.com/article/2252473c0d17cce48f2fb9276bfd9515</guid>
      <description><![CDATA[Mozilla on Wednesday patched 11 vulnerabilities in Firefox 3.0 -- and 12 bugs in the older Firefox 2.0 -- that could be used to compromise computers and steal...]]></description>
      <content:encoded><![CDATA[Mozilla on Wednesday patched 11 vulnerabilities in Firefox 3.0 -- and 12 bugs in the older Firefox 2.0 -- that could be used to compromise computers and steal information.]]></content:encoded>
      <pubDate>Wed, 12 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/firefox">firefox</category>
      <category domain="http://securityratty.com/tag/compromise computers">compromise computers</category>
      <category domain="http://securityratty.com/tag/mozilla">mozilla</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/wednesday">wednesday</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/bugs">bugs</category>
      <source url="http://www.networkworld.com/news/2008/111308-mozilla-fixes-11-new-flaws.html?fsrc=rss-security">Mozilla fixes 11 new flaws in Firefox, six critical</source>
    </item>
    <item>
      <title><![CDATA[Microsoft fixes critical Web bugs with security updates]]></title>
      <link>http://securityratty.com/article/32a9820a8a9fd3ab36d6dcb672eb9b52</link>
      <guid>http://securityratty.com/article/32a9820a8a9fd3ab36d6dcb672eb9b52</guid>
      <description><![CDATA[Microsoft released two security updates for its Windows operating system Tuesday to patch flaws that could give attackers new ways to install malicious software on a victim's...]]></description>
      <content:encoded><![CDATA[Microsoft released two security updates for its Windows operating system Tuesday to patch flaws that could give attackers new ways to install malicious software on a victim's computer.]]></content:encoded>
      <pubDate>Mon, 10 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/install malicious software">install malicious software</category>
      <category domain="http://securityratty.com/tag/microsoft">microsoft</category>
      <category domain="http://securityratty.com/tag/system tuesday">system tuesday</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/patch flaws">patch flaws</category>
      <category domain="http://securityratty.com/tag/attackers">attackers</category>
      <category domain="http://securityratty.com/tag/windows">windows</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/victim">victim</category>
      <source url="http://www.networkworld.com/news/2008/111108-microsoft-fixes-critical-web-bugs.html?fsrc=rss-security">Microsoft fixes critical Web bugs with security updates</source>
    </item>
    <item>
      <title><![CDATA[Adobe fixes 6 flaws in Flash]]></title>
      <link>http://securityratty.com/article/8e338676db24d29aac50f06e673b2772</link>
      <guid>http://securityratty.com/article/8e338676db24d29aac50f06e673b2772</guid>
      <description><![CDATA[For the second time in two days, Adobe Systems has issued a security update to fix multiple vulnerabilities in one of its most-popular programs, Flash...]]></description>
      <content:encoded><![CDATA[For the second time in two days, Adobe Systems has issued a security update to fix multiple vulnerabilities in one of its most-popular programs, Flash Player.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:00394360bb6d248cc9baea02213db9cf:%2FCZN4eJtNRh8ra3AViblz3BSiPyP46KIqFB51dvYjhppJCUCdqwQGBZma5uyvxoiX1QnUNGWlBjY'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:e1aac51b5c10f1eb477b03a83ba52292:VzTNpyZJPXddORCj0snMZSkIRJN4%2FawAoZYtGSoKiM2xFfxJ3WquPwbporhtxalyVfdB7u2wS3YRig%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:72ae93ea24b1029f7edf23b212c1399d:juC6MeQaCuBEW%2Bt4xQGzdPaRtALS%2B4os6omPXZY0jE9%2Bx%2BZipYuie948LtNpqSid%2Fg0ukftcfVA5XA%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:1f3f0b74bdad49a787d084f88ae975e6:dxfoGHh7UVdDmgvnImiHUSP7IBO4ZTm%2FKAzRBKsDpMrd%2BYOhkI%2BgW0vfOTOuPu6YryekUDTh7lrnUg%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=d728e0ef93ea8841799c41780e9a4747" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=d728e0ef93ea8841799c41780e9a4747" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Thu, 06 Nov 2008 02:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fix multiple vulnerabilities">fix multiple vulnerabilities</category>
      <category domain="http://securityratty.com/tag/flash player">flash player</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/most-popular programs">most-popular programs</category>
      <category domain="http://securityratty.com/tag/time">time</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/days">days</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=d728e0ef93ea8841799c41780e9a4747">Adobe fixes 6 flaws in Flash</source>
    </item>
    <item>
      <title><![CDATA[Ed Felten on e-voting: What can go wrong]]></title>
      <link>http://securityratty.com/article/95ab05eafbfa35d55bdaf6015fcff266</link>
      <guid>http://securityratty.com/article/95ab05eafbfa35d55bdaf6015fcff266</guid>
      <description><![CDATA[Voting machines of all stripes have remarkably similar flaws and though geographically scattered, inaccurate tallies of votes are not likely to flip a whole presidential election, there is a...]]></description>
      <content:encoded><![CDATA[Voting machines of all stripes have remarkably similar flaws and though geographically scattered, inaccurate tallies of votes are not likely to flip a whole presidential election, there is a "nightmare scenario" that could. Meanwhile on the state level, security issues have already popped up in the wake of various states' deployments of direct-recording electronic (DRE) voting machines.]]></content:encoded>
      <pubDate>Sun, 02 Nov 2008 21:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/remarkably similar flaws">remarkably similar flaws</category>
      <category domain="http://securityratty.com/tag/security issues">security issues</category>
      <category domain="http://securityratty.com/tag/nightmare scenario">nightmare scenario</category>
      <category domain="http://securityratty.com/tag/presidential election">presidential election</category>
      <category domain="http://securityratty.com/tag/machines">machines</category>
      <category domain="http://securityratty.com/tag/tallies">tallies</category>
      <category domain="http://securityratty.com/tag/flip">flip</category>
      <category domain="http://securityratty.com/tag/dre">dre</category>
      <category domain="http://securityratty.com/tag/deployments">deployments</category>
      <source url="http://www.networkworld.com/news/2008/110308-ed-felten-on-e-voting-what.html?fsrc=rss-security">Ed Felten on e-voting: What can go wrong</source>
    </item>
    <item>
      <title><![CDATA[Highly-critical Vulnerabilities Patched In OpenOffice Suite 2.4.2]]></title>
      <link>http://securityratty.com/article/4b05c997f625f4489628e471be845ab9</link>
      <guid>http://securityratty.com/article/4b05c997f625f4489628e471be845ab9</guid>
      <description><![CDATA[OpenOffice.org has released a new version of the open-source desktop productivity suite to patch highly-critical vulnerabilities that could expose users to arbitrary code execution attacks. The flaws,...]]></description>
      <content:encoded><![CDATA[OpenOffice.org has released a new version of the open-source desktop productivity suite to patch highly-critical vulnerabilities that could expose users to arbitrary code execution attacks.
The flaws, which affect all versions prior to OpenOffice.org 2.4.2, could be exploited via manipulated WMF and EMF files in StarOffice or StarSuite documents:
CVE-2008-2237: A security vulnerability with the way OpenOffice [...]]]></content:encoded>
      <pubDate>Thu, 30 Oct 2008 01:35:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/openoffice">openoffice</category>
      <category domain="http://securityratty.com/tag/patch highly-critical vulnerabilities">patch highly-critical vulnerabilities</category>
      <category domain="http://securityratty.com/tag/expose users">expose users</category>
      <category domain="http://securityratty.com/tag/security vulnerability">security vulnerability</category>
      <category domain="http://securityratty.com/tag/starsuite documents">starsuite documents</category>
      <category domain="http://securityratty.com/tag/org">org</category>
      <category domain="http://securityratty.com/tag/emf files">emf files</category>
      <category domain="http://securityratty.com/tag/versions prior">versions prior</category>
      <category domain="http://securityratty.com/tag/cve-2008-2237">cve-2008-2237</category>
      <source url="http://cyberinsecure.com/highly-critical-vulnerabilities-patched-in-openoffice-suite-242/">Highly-critical Vulnerabilities Patched In OpenOffice Suite 2.4.2</source>
    </item>
  </channel>
</rss>
