<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Technology for Mortals &#187; Security news</title>
	<atom:link href="http://www.formortals.com/category/news/security-news/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.formortals.com</link>
	<description>Because technology isn&#039;t just for geeks</description>
	<lastBuildDate>Thu, 27 Oct 2011 06:16:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.3</generator>
		<item>
		<title>Temporary workaround for Windows SMBv2 zero-day</title>
		<link>http://www.formortals.com/temporary-workaround-for-windows-smbv2-zero-day/</link>
		<comments>http://www.formortals.com/temporary-workaround-for-windows-smbv2-zero-day/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 09:58:05 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>
		<category><![CDATA[Windows Server 2008]]></category>
		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=827</guid>
		<description><![CDATA[The Windows SMBv2 zero-day vulnerability (disclosed vulnerability with no software fix) appears to be more dangerous than initially thought.  The vulnerability does not affect the Release to Manufacturing (RTM) version of Windows 7 or Windows Server 2008 R2, but it does affects Windows Vista and Windows Server 2008.  The danger is no longer just a [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/temporary-workaround-for-windows-smbv2-zero-day/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>Voting machines hacked, votes stolen in POC attack</title>
		<link>http://www.formortals.com/voting-machines-hacked-votes-stolen-in-poc-attack/</link>
		<comments>http://www.formortals.com/voting-machines-hacked-votes-stolen-in-poc-attack/#comments</comments>
		<pubDate>Thu, 13 Aug 2009 04:02:36 +0000</pubDate>
		<dc:creator>Justin James</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=717</guid>
		<description><![CDATA[Researches at the University of California, San Diego, have used a new programming technique to hack a voting machine. What is really scary about this attack, is that the researchers did not need the source code or other unlikely insider information to do it. All they needed was the information that someone would have by [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/voting-machines-hacked-votes-stolen-in-poc-attack/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
		</item>
		<item>
		<title>Temporary fix for unauthorized WordPress password reset</title>
		<link>http://www.formortals.com/temporary-fix-for-unauthorized-wordpress-password-reset/</link>
		<comments>http://www.formortals.com/temporary-fix-for-unauthorized-wordpress-password-reset/#comments</comments>
		<pubDate>Wed, 12 Aug 2009 07:11:45 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>
		<category><![CDATA[WordPress]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=709</guid>
		<description><![CDATA[There is a serious exploit against WordPress out in the wild that allows an attacker to reset your password.  It works on every version of WordPress and there is no official patch yet which is pretty scary.  There is a temporary workaround and it appears that WordPress.com has already applied this workaround.  This workaround can [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/temporary-fix-for-unauthorized-wordpress-password-reset/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>90% of you run an insecure version of flash</title>
		<link>http://www.formortals.com/90-of-you-run-an-insecure-version-of-flash/</link>
		<comments>http://www.formortals.com/90-of-you-run-an-insecure-version-of-flash/#comments</comments>
		<pubDate>Fri, 07 Aug 2009 00:00:33 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[Adobe]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=690</guid>
		<description><![CDATA[Last Friday, a new version of Adobe Flash came out which patched the most recent critical flaws in Flash Player. Yet because the update process isn&#8217;t automatic, most of you have not updated your Flash Player in your web browser. The fact that Adobe makes the manual update process a pain to use and forces [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/90-of-you-run-an-insecure-version-of-flash/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
		</item>
		<item>
		<title>Mozilla patches SSL, Microsoft CryptoAPI still exposed</title>
		<link>http://www.formortals.com/mozilla-patches-ssl-microsoft-cryptoapi-still-exposed/</link>
		<comments>http://www.formortals.com/mozilla-patches-ssl-microsoft-cryptoapi-still-exposed/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 21:21:10 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[BlackHat]]></category>
		<category><![CDATA[DEFCON]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=684</guid>
		<description><![CDATA[Mozilla has patched a very critical flaw in Firefox that allows attackers to pose as a legitimate Firefox update server and implant harmful code into a victim’s computer. Firefox 3.0.13 and 3.5.2 are no longer vulnerable to this attack and the update should automatically run. It would be prudent to check it manually under the Firefox [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/mozilla-patches-ssl-microsoft-cryptoapi-still-exposed/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SSL exploit turns Firefox into malware distributor</title>
		<link>http://www.formortals.com/ssl-exploit-turns-firefox-into-malware-distributor/</link>
		<comments>http://www.formortals.com/ssl-exploit-turns-firefox-into-malware-distributor/#comments</comments>
		<pubDate>Thu, 30 Jul 2009 15:40:37 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[BlackHat]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=648</guid>
		<description><![CDATA[Security researcher Moxie Marlinspike gave one of the more interesting and terrifying presentations at BlackHat 2009 in Las Vegas yesterday. Marlinspike demonstrated how the X.509 digital certificates used by Secure Socket Layer (SSL) to secure online communications such as eCommerce and online banking were was completely broken.  This allowed Marlinspike to pose as the Mozilla [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/ssl-exploit-turns-firefox-into-malware-distributor/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>ISPs have a duty to block malicious traffic</title>
		<link>http://www.formortals.com/isps-have-a-duty-to-block-malicious-traffic/</link>
		<comments>http://www.formortals.com/isps-have-a-duty-to-block-malicious-traffic/#comments</comments>
		<pubDate>Tue, 28 Jul 2009 14:50:18 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[AT&T]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Policy]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>
		<category><![CDATA[YouTube]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=634</guid>
		<description><![CDATA[Mass media and blogosphere hysteria ensued after several ISPs (including AT&#38;T) responded to customer complaints and blocked an IP address that was transmitting massive amounts of Denial of Service (DoS) traffic. For something as routine as and essential as blocking a malicious attack from a computer on the Internet, all hell broke loose late Sunday [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/isps-have-a-duty-to-block-malicious-traffic/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>F-Secure is mistaken regarding Windows 7 RC security &#8220;fail&#8221;</title>
		<link>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/</link>
		<comments>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/#comments</comments>
		<pubDate>Wed, 06 May 2009 07:05:00 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=180</guid>
		<description><![CDATA[F-Secure is getting some news coverage because one of their bloggers claim that they have identified a security failure in Windows 7 Release Candidate.  Their blogger Mikko writes that Windows 7 still hides file extensions which allows virus writers to easily trick users in to launching executable files that were disguised as ordinary document files.  [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/f-secure-is-mistaken-regarding-windows-7-rc-security-fail/feed/</wfw:commentRss>
		<slash:comments>18</slash:comments>
		</item>
		<item>
		<title>Download Office 2007 SP2, don&#8217;t use Windows Update</title>
		<link>http://www.formortals.com/download-office-2007-sp2-dont-use-windows-update/</link>
		<comments>http://www.formortals.com/download-office-2007-sp2-dont-use-windows-update/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 12:30:00 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[Microsoft software]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security news]]></category>
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=179</guid>
		<description><![CDATA[Update 4/30/2009 &#8211; Microsoft support helped me fix the problem using an internal script/utility called&#160;au_check_v78f.exe to clear out my update database which may have been corrupted. &#160;Hopefully, they will make this tool public. For anyone who has more than one computer running Office 2007 or if you may need to run the update on a [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/download-office-2007-sp2-dont-use-windows-update/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>HTTPS web hijacking goes from theory to practice</title>
		<link>http://www.formortals.com/https-web-hijacking-goes-from-theory-to-practice/</link>
		<comments>http://www.formortals.com/https-web-hijacking-goes-from-theory-to-practice/#comments</comments>
		<pubDate>Fri, 20 Feb 2009 04:40:00 +0000</pubDate>
		<dc:creator>George Ou</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Security news]]></category>

		<guid isPermaLink="false">http://www.formortals.com/?p=166</guid>
		<description><![CDATA[I&#8217;ve been privately talking about the theoretical dangers of HTTPS hacking with the developers of a major web browser since 2006 and earlier last month, I published my warnings about HTTPS web hacking along with a proposed solution.  A week later, Google partially implemented some of my recommendations in an early Alpha version of their [...]]]></description>
		<wfw:commentRss>http://www.formortals.com/https-web-hijacking-goes-from-theory-to-practice/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

