<?xml version="1.0" encoding="utf-8"?>

<rdf:RDF
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:cc="http://web.resource.org/cc/"
  xmlns="http://purl.org/rss/1.0/">

<channel rdf:about="http://www.cgisecurity.com/">
<title>CGISecurity - Website and Application Security News</title>
<link>http://www.cgisecurity.net/</link>
<image>http://images.cgisecurity.com/i/rss.gif</image>
<description>All things related to website, database, SDL, and application security since 2000.
</description>
<dc:language>en-US</dc:language>
<dc:creator></dc:creator>
<dc:date>2008-12-01T14:27:16-08:00</dc:date>
<admin:generatorAgent rdf:resource="http://www.typepad.com/" />


<items>
<rdf:Seq><rdf:li rdf:resource="http://www.cgisecurity.net/2008/12/insecure-magazine-19-released.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/12/college-students-rig-victoria-secret-online-contest.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/12/manipulating-google-flu-trends-to-perform-cyber-warfare.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/inside-safari-32s-antiphishing-features.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/oracle-forensics-part-7-using-the-oracle-system-change-number-in-forensic-investigations.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/article-what-the-nsa-thinks-of-net-20-security.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/automated-secur.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/metasploit-fram.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/microsoft-to-of.html" />
<rdf:li rdf:resource="http://www.cgisecurity.net/2008/11/understanding-h.html" />
</rdf:Seq>
</items>

</channel>

<item rdf:about="http://www.cgisecurity.net/2008/12/insecure-magazine-19-released.html">
<title>Insecure Magazine #19 Released</title>
<link>http://www.cgisecurity.net/2008/12/insecure-magazine-19-released.html</link>
<description>In this issue. The future of AV: looking for the good while stopping the bad Eight holes in Windows login controls Extended validation and online security: EV SSL gets the green light Interview with Giles Hogben, an expert on identity and authentication technologies working at ENISA Web filtering in a Web...</description>


<dc:creator>Robert</dc:creator>
<dc:date>2008-12-01T14:27:16-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/12/college-students-rig-victoria-secret-online-contest.html">
<title>College students rig Victoria Secret online contest</title>
<link>http://www.cgisecurity.net/2008/12/college-students-rig-victoria-secret-online-contest.html</link>
<description>&quot;At Drexel University and a handful of other colleges, students created computer scripts to sway the contest—an online vote to nominate a university to receive its own clothing line—in their campuses’ favor. Tim Plunkett, a junior at Drexel, created a script that could cast 1,500 votes per second, according to The...</description>

<dc:subject>Funny</dc:subject>
<dc:subject>Incidents</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-12-01T13:36:05-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/12/manipulating-google-flu-trends-to-perform-cyber-warfare.html">
<title>Manipulating Google Flu Trends to perform cyber warfare?</title>
<link>http://www.cgisecurity.net/2008/12/manipulating-google-flu-trends-to-perform-cyber-warfare.html</link>
<description>I came across an interesting post at freedom-to-tinker discussing the impacts of google&#39;s flu monitoring program.&quot;My concern today is whether Flu Trends can be manipulated. The system makes inferences from how people search, but people can change their search behavior. What if a person or a small group set out to...</description>

<dc:subject>Off Topic</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-12-01T13:24:48-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/inside-safari-32s-antiphishing-features.html">
<title>Inside Safari 3.2’s anti-phishing features</title>
<link>http://www.cgisecurity.net/2008/11/inside-safari-32s-antiphishing-features.html</link>
<description>An article over at macworld discusses the anti phishing features in the new safari.&quot;The release of Safari 3.2 on November 13 displayed Apple’s penchant for cryptic release notes, as the company describes all three versions as featuring “protection from fraudulent phishing Web sites.” Let&#39;s decode that for you: Safari 3.2 offers...</description>

<dc:subject>Browsers</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-25T10:43:46-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/oracle-forensics-part-7-using-the-oracle-system-change-number-in-forensic-investigations.html">
<title>Oracle Forensics Part 7: Using the Oracle System Change Number in Forensic Investigations</title>
<link>http://www.cgisecurity.net/2008/11/oracle-forensics-part-7-using-the-oracle-system-change-number-in-forensic-investigations.html</link>
<description>David Litchfield has published a new tool and paper on forensics on Oracle Databases. From his email to the Websecurity mailing list.&quot;I&#39;ve just posted a new tool and paper for Oracle forensics. The tool, orablock, allows a forensic investigator to dump data from a &quot;cold&quot; Oracle data file - i.e. there&#39;s...</description>

<dc:subject>Articles</dc:subject>
<dc:subject>Forensics</dc:subject>
<dc:subject>Research</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-25T09:36:57-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/article-what-the-nsa-thinks-of-net-20-security.html">
<title>Article: What the NSA thinks of .NET 2.0 Security</title>
<link>http://www.cgisecurity.net/2008/11/article-what-the-nsa-thinks-of-net-20-security.html</link>
<description>Romain Guacher to the SC-L mailing list that the NSA has published a massive 298 page unclassified document on .NET 2.0 security. From the introduction.&quot;The purpose of this document is to inform administrators responsible for systems andnetwork security about the configurable security features available in the .NET Framework.To place some of...</description>

<dc:subject>Articles</dc:subject>
<dc:subject>Defense</dc:subject>
<dc:subject>Development</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-24T09:15:30-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/automated-secur.html">
<title>Automated security testing &amp; its limitations</title>
<link>http://www.cgisecurity.net/2008/11/automated-secur.html</link>
<description>&quot;The team I work in uses both automated scanners, along with a few humans testing (minimum of 2)… A good tester should know the weaknesses of the automated testers.. The problem with automated testers, is, simply put, they are not human. That is they will not have intuition that a given...</description>

<dc:subject>Reviews</dc:subject>
<dc:subject>Security Tools</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-19T10:28:12-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/metasploit-fram.html">
<title>Metasploit Framework 3.2 Released</title>
<link>http://www.cgisecurity.net/2008/11/metasploit-fram.html</link>
<description>&quot;Contact: H D Moore FOR IMMEDIATE RELEASE Email: hdm[at]metasploit.com Austin, Texas, November 19th, 2008 -- The Metasploit Projectannounced today the free, world-wide availability of version 3.2 oftheir exploit development and attack framework. The latest versionis provided under a true open source software license (BSD) and is backed by a community-based development...</description>

<dc:subject>Security Tools</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-19T09:33:14-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/microsoft-to-of.html">
<title>Microsoft to offer free Antivirus</title>
<link>http://www.cgisecurity.net/2008/11/microsoft-to-of.html</link>
<description>&quot;Microsoft on Tuesday said it plans to kill off its Windows Live OneCare subscription security service in favor of a free offering that will feature a core of essential anti-malware tools while excluding peripheral services, such as PC tune up programs, found in OneCare. The move could help the software maker...</description>

<dc:subject>IndustryNews</dc:subject>
<dc:subject>Vendors</dc:subject>
<dc:subject>Worms</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-19T09:11:06-08:00</dc:date>
</item>
<item rdf:about="http://www.cgisecurity.net/2008/11/understanding-h.html">
<title>Understanding How to Use the Microsoft&#39;s Exploitability Index</title>
<link>http://www.cgisecurity.net/2008/11/understanding-h.html</link>
<description>&quot;On Oct. 14, 2008, Microsoft added another piece of information to the bulletin summary to better help customers with their risk assessment process: the Exploitability Index. This section is a brief overview to explain how customers can integrate the Exploitability Index with the Severity Rating system into their own risk assessment...</description>

<dc:subject>Defense</dc:subject>
<dc:subject>SDL</dc:subject>
<dc:subject>Vendors</dc:subject>

<dc:creator>Robert</dc:creator>
<dc:date>2008-11-18T09:58:47-08:00</dc:date>
</item>


</rdf:RDF>
<!-- ph=1 -->
<!-- nhm:from_kauri -->
