<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Ruan Müller</title>
	<atom:link href="http://ruanmuller.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ruanmuller.com</link>
	<description>Willing and not afraid to challenge the status quo.</description>
	<lastBuildDate>Mon, 15 Feb 2010 19:41:25 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>University of Cambridge discovers Chip and PIN verification &#8220;wedge&#8221; vulnerability</title>
		<link>http://ruanmuller.com/2010/02/15/university-of-cambridge-discovers-chip-and-pin-verification-wedge-vulnerability/</link>
		<comments>http://ruanmuller.com/2010/02/15/university-of-cambridge-discovers-chip-and-pin-verification-wedge-vulnerability/#comments</comments>
		<pubDate>Mon, 15 Feb 2010 19:41:25 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[Chip and PIN]]></category>
		<category><![CDATA[Man in the middle]]></category>
		<category><![CDATA[MITM]]></category>
		<category><![CDATA[terminal]]></category>
		<category><![CDATA[University of Cambridge]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=345</guid>
		<description><![CDATA[Students at the University of Cambridge have discovered a new flaw that is compromised by using a MITM attack that deceives a terminal in to thinking that a card&#8217;s PIN is correct irregardless of what number is provided for the PIN.
The attack uses an electronic device as a &#8220;man-in-the-middle&#8221; in order to prevent the PIN [...]]]></description>
			<content:encoded><![CDATA[<p>Students at the University of Cambridge have discovered a new flaw that is compromised by using a MITM attack that deceives a terminal in to thinking that a card&#8217;s PIN is correct irregardless of what number is provided for the PIN.</p>
<blockquote><p>The attack uses an electronic device as a &#8220;man-in-the-middle&#8221; in order to prevent the PIN verification message from getting to the card, and to always respond that the PIN is correct. Thus, the terminal thinks that the PIN was entered correctly, and the card assumes that a signature was used to authenticate the transaction.</p>
<p>&#8220;We think this is one of the biggest flaws that we&#8217;ve uncovered &#8211; that has ever been uncovered &#8211; against payment systems, and I&#8217;ve been in this business for 25 years,&#8221; said Professor Ross Anderson from the school&#8217;s Computer Laboratory.</p></blockquote>
<p>More details are available at the <a href="http://www.cl.cam.ac.uk/research/security/banking/nopin/" target="_blank">University of Cambridgde Computer Laboratory Security Group</a> website.</p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2010/02/15/university-of-cambridge-discovers-chip-and-pin-verification-wedge-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The EU and UK Have Less Open Wireless WiFi Broadband Hotspots Than USA</title>
		<link>http://ruanmuller.com/2010/01/08/the-eu-and-uk-have-less-open-wireless-wifi-broadband-hotspots-than-usa/</link>
		<comments>http://ruanmuller.com/2010/01/08/the-eu-and-uk-have-less-open-wireless-wifi-broadband-hotspots-than-usa/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 19:43:26 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[europe]]></category>
		<category><![CDATA[hotspot]]></category>
		<category><![CDATA[unlocked]]></category>
		<category><![CDATA[usa]]></category>
		<category><![CDATA[wefi]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=342</guid>
		<description><![CDATA[From ISPreview:
WeFi, a free wireless Wi-Fi broadband Hotspot locator website with a database of 47,000,000 access points around the world, has revealed that 40% of Hotspots in the USA are unlocked and do not require a security password. This compares with 25% in Europe.
According to WeFi’s data, a traveler would find a higher percentage of [...]]]></description>
			<content:encoded><![CDATA[<p>From ISPreview:</p>
<blockquote><p><a href="http://www.wefi.com/" target="_blank">WeFi</a>, a free wireless Wi-Fi broadband Hotspot locator website with a database of 47,000,000 access points around the world, has revealed that 40% of Hotspots in the USA are unlocked and do not require a security password. This compares with 25% in Europe.</p>
<p>According to WeFi’s data, a traveler would find a higher percentage of open hotspots in countries such as Thailand, Israel, Brazil, Argentina and the Bahamas as compared with both the US and Europe. Across the world, approximately 30% of recorded Wi-Fi access points are unlocked, while some 70% are locked</p></blockquote>
<p>Full Article: <a href="http://www.ispreview.co.uk/story/2010/01/08/usa-home-to-more-open-wireless-wifi-broadband-hotspots-than-eu-and-uk.html" target="_blank">ISPreview</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2010/01/08/the-eu-and-uk-have-less-open-wireless-wifi-broadband-hotspots-than-usa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scientists Demonstrate New Lightweight Rootkit Protection Method</title>
		<link>http://ruanmuller.com/2009/11/14/scientists-demonstrate-new-lightweight-rootkit-protection-method/</link>
		<comments>http://ruanmuller.com/2009/11/14/scientists-demonstrate-new-lightweight-rootkit-protection-method/#comments</comments>
		<pubDate>Sat, 14 Nov 2009 21:33:03 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[hypervisor]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[rootkit]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=338</guid>
		<description><![CDATA[Scientists are set to unveil a lightweight system they say makes an operating system significantly more resistant to rootkits without degrading its performance. The hypervisor-based system is dubbed HookSafe, and it works by relocating kernel hooks in a guest OS to a dedicated page-aligned memory space that&#8217;s tightly locked down. The team installed HookSafe on [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p><em>Scientists are set to unveil a lightweight system they say makes an operating system significantly more resistant to rootkits without degrading its performance. The hypervisor-based system is dubbed HookSafe, and it works by relocating kernel hooks in a guest OS to a dedicated page-aligned memory space that&#8217;s tightly locked down. The team installed HookSafe on a machine running Ubuntu 8.04, and found the system successfully prevented nine real-world rootkits targeting that platform from installing or hiding themselves. The program was able to achieve that protection with only a 6 percent reduction in performance benchmarks.</em></p></blockquote>
<p>Via: <a href="http://www.theregister.co.uk/2009/11/11/hooksafe_rootkit_protection/" target="_blank">The Register</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/11/14/scientists-demonstrate-new-lightweight-rootkit-protection-method/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenBSD 4.6 Released</title>
		<link>http://ruanmuller.com/2009/10/20/openbsd-4-6-released/</link>
		<comments>http://ruanmuller.com/2009/10/20/openbsd-4-6-released/#comments</comments>
		<pubDate>Tue, 20 Oct 2009 23:12:59 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[openbsd]]></category>
		<category><![CDATA[openssh]]></category>
		<category><![CDATA[Operating System]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=331</guid>
		<description><![CDATA[The release of OpenBSD 4.6 was released on Sunday. Highlights of the new release include:

Simplified installation process.
Improved documentation and man pages.
New versions of packages in ports (package management system). Over 5800 packages in total.
Hardware driver updates: sensors, chipsets, video devices etc. New drivers, functionality and reliability updates.
Network stack updates: stricter default settings. Wired interfaces are [...]]]></description>
			<content:encoded><![CDATA[<p><em>The release of <a href="http://www.openbsd.org/plus46.html">OpenBSD 4.6</a> was released on Sunday. Highlights of the new release include:<a href="http://www.openbsd.org/donations.html"></a></em></p>
<ul>
<li>Simplified installation process.</li>
<li>Improved documentation and man pages.</li>
<li>New versions of packages in ports (package management system). Over 5800 packages in total.</li>
<li>Hardware driver updates: sensors, chipsets, video devices etc. New drivers, functionality and reliability updates.</li>
<li>Network stack updates: stricter default settings. Wired interfaces are now preferred over wireless ones.</li>
<li>Firewall changes: enabled by default, stricter checking of package formats.</li>
<li>Routing daemon updates: mainly BGP daemon updates, fixes few bugs.</li>
<li>New more secure smtpd (mail server).New OpenSSH released (5.3).</li>
</ul>
<p><em>Grab a <a href="http://www.openbsd.org/orders.html">CD set</a> or <a href="http://www.openbsd.org/ftp.html">download</a> from a mirror, and please <a href="http://www.openbsd.org/donations.html">support</a> the project</em></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/10/20/openbsd-4-6-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Employees within business and government organizations are the fastest-growing threat</title>
		<link>http://ruanmuller.com/2009/09/30/employees-within-business-and-government-organizations-are-the-fastest-growing-threat/</link>
		<comments>http://ruanmuller.com/2009/09/30/employees-within-business-and-government-organizations-are-the-fastest-growing-threat/#comments</comments>
		<pubDate>Thu, 01 Oct 2009 04:29:29 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[canada]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=321</guid>
		<description><![CDATA[A joint study conducted by TELUS and the Rotman School of Management at the University of Toronto surveyed more than 600 Canadian IT security professionals on Canadian IT security practices this year.
The economic downturn has increased the risk organizations:
“The threat environment worsens because when the economy goes into a downturn, job losses mount, and as [...]]]></description>
			<content:encoded><![CDATA[<p>A joint study conducted by TELUS and the Rotman School of Management at the University of Toronto surveyed more than 600 Canadian IT security professionals on Canadian IT security practices this year.</p>
<p>The economic downturn has increased the risk organizations:</p>
<blockquote><p>“The threat environment worsens because when the economy goes into a downturn, job losses mount, and as people leave the organization many often take data with them,” Mr. Hejazi said.</p>
<p>About 33 per cent of reported security breaches this year came from within companies, and unauthorized access by employees represented the fastest-growing threat area, according to TELUS Security Labs managing director and study co-author Alan LeFort.</p>
<p>Last year, about 17 per cent of Canadian organizations reported so-called “insider breaches.” This year, that number has more than doubled to 36 per cent.</p></blockquote>
<p>The complete article can be read at <a href="http://www.theglobeandmail.com/news/technology/it-security-breaches-soar-in-2009/article1305011/" target="_blank">The Globe and Mail</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/09/30/employees-within-business-and-government-organizations-are-the-fastest-growing-threat/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SANS Report: 60% Of All Attacks Hit Web Applications, Most in the U.S.</title>
		<link>http://ruanmuller.com/2009/09/15/sans-report-60-of-all-attacks-hit-web-applications-most-in-the-u-s/</link>
		<comments>http://ruanmuller.com/2009/09/15/sans-report-60-of-all-attacks-hit-web-applications-most-in-the-u-s/#comments</comments>
		<pubDate>Tue, 15 Sep 2009 17:41:35 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Development]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[patching]]></category>
		<category><![CDATA[vulnerability scanning]]></category>
		<category><![CDATA[web applications]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=315</guid>
		<description><![CDATA[Most organizations are focusing their patching efforts and vulnerability scanning on the operating system &#8212; but 60 percent of the total number of attacks occur on Web applications, and many attacks are aimed at third-party applications such as Microsoft Office, and Adobe Flash and other tools, according to actual attack data gathered for the report. [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p><span>Most organizations are focusing their patching efforts and vulnerability scanning on the operating system &#8212; but 60 percent of the total number of attacks occur on Web applications, and many attacks are aimed at third-party applications such as Microsoft Office, and Adobe Flash and other tools, according to actual attack data gathered for the report. Meanwhile, enterprises are taking twice as long to patch their applications than to patch their operating systems, the report says. </span></p></blockquote>
<p>More at <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=220000401">darkREADING</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/09/15/sans-report-60-of-all-attacks-hit-web-applications-most-in-the-u-s/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sun presents plans for a security accelerator chip to offload encryption</title>
		<link>http://ruanmuller.com/2009/08/26/sun-presents-plans-for-a-security-accelerator-chip-to-offload-encryption/</link>
		<comments>http://ruanmuller.com/2009/08/26/sun-presents-plans-for-a-security-accelerator-chip-to-offload-encryption/#comments</comments>
		<pubDate>Wed, 26 Aug 2009 23:37:42 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Data Centers]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[coprocessor]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Rainbow Falls]]></category>
		<category><![CDATA[Sun]]></category>
		<category><![CDATA[T2]]></category>
		<category><![CDATA[Ultrasparc]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=309</guid>
		<description><![CDATA[Sun Microsystems&#8217; product plans are up in the air pending its acquisition by Oracle, but the company&#8217;s chip engineers continue to present new designs in the hope they&#8217;ll see the light of day. At the Hot Chips conference at Stanford University on Tuesday, Sun presented plans for a security accelerator chip that it said would [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Sun Microsystems&#8217; product plans are up in the air pending its acquisition by Oracle, but the company&#8217;s chip engineers continue to present new designs in the hope they&#8217;ll see the light of day. At the Hot Chips conference at Stanford University on Tuesday, Sun presented plans for a security accelerator chip that it said would reduce encryption costs for applications such as VoIP calls and online banking Web sites. The chip, known as a coprocessor, will be included on the same silicon as Rainbow Falls, the code name for the follow-on to Sun&#8217;s multithreaded Ultrasparc T2 processor.</p></blockquote>
<p>Via: <a href="http://www.osnews.com/story/22063/Sun_Plans_On-Chip_Security_Boost_for_UltraSPARC" target="_blank">OSNews</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/08/26/sun-presents-plans-for-a-security-accelerator-chip-to-offload-encryption/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New DoS Vulnerability Affects All Versions of BIND 9</title>
		<link>http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/</link>
		<comments>http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 17:35:30 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[dns]]></category>
		<category><![CDATA[DOS]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=301</guid>
		<description><![CDATA[ISC is reporting that a new, remotely exploitable vulnerability has been found in all versions of BIND 9. A specially crafted dynamic update packet will make BIND die with an assertion error. There is an exploit in the wild and there are no access control workarounds. Red Hat claims that the exploit does not affect [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p><em>ISC is reporting that a new, remotely exploitable <a href="https://www.isc.org/node/474">vulnerability has been found in all versions of BIND 9</a>. A specially crafted dynamic update packet will make BIND die with an assertion error. There is an exploit in the wild and there are no access control workarounds. <a href="https://bugzilla.redhat.com/show_bug.cgi?id=514292">Red Hat claims</a> that the exploit does not affect BIND servers that do not allow dynamic updates, but the ISC post refutes that. This is a high-priority vulnerability and DNS operators will want to upgrade BIND to the latest patch level.</em></p></blockquote>
<p>Via: <a href="http://it.slashdot.org/story/09/07/29/0028231/New-DoS-Vulnerability-In-All-Versions-of-BIND-9">Slashdot</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/07/29/new-dos-vulnerability-affects-all-versions-of-bind-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nmap 5 Released</title>
		<link>http://ruanmuller.com/2009/07/20/nmap-5-released/</link>
		<comments>http://ruanmuller.com/2009/07/20/nmap-5-released/#comments</comments>
		<pubDate>Mon, 20 Jul 2009 19:08:02 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Open Source]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[audit]]></category>
		<category><![CDATA[insecure]]></category>
		<category><![CDATA[nmap]]></category>
		<category><![CDATA[NSE]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=297</guid>
		<description><![CDATA[Nmap Security Scanner version 5 has been released. Significant performance improvements were made, and many scripts have been added. Nmap can now log into Windows a system and perform local checks such as Conficker detection.
Announcement
Changes
Download
]]></description>
			<content:encoded><![CDATA[<p>Nmap Security Scanner version 5 has been released. Significant performance improvements were made, and many scripts have been added. Nmap can now log into Windows a system and perform local checks such as Conficker detection.</p>
<p><a href="http://seclists.org/nmap-hackers/2009/0003.html">Announcement</a><br />
<a href="http://nmap.org/5/#5changes">Changes</a><br />
<a href="http://nmap.org/download.html">Download</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/07/20/nmap-5-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PHP Interpreter Modified To Find XSS and Injection Holes, Automatically Generates Attacks</title>
		<link>http://ruanmuller.com/2009/06/19/php-interpreter-modified-to-find-xss-and-injection-holes-automatically-generates-attacks/</link>
		<comments>http://ruanmuller.com/2009/06/19/php-interpreter-modified-to-find-xss-and-injection-holes-automatically-generates-attacks/#comments</comments>
		<pubDate>Fri, 19 Jun 2009 22:46:23 +0000</pubDate>
		<dc:creator>Ruan</dc:creator>
				<category><![CDATA[Databases]]></category>
		<category><![CDATA[Programming]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[ardilla]]></category>
		<category><![CDATA[injection]]></category>
		<category><![CDATA[interpreter]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[sql]]></category>
		<category><![CDATA[xss]]></category>
		<category><![CDATA[xss2]]></category>

		<guid isPermaLink="false">http://ruanmuller.com/?p=292</guid>
		<description><![CDATA[Researchers have built a tool that automatically finds and exploits SQL injection and cross-site scripting vulnerabilities in Web applications.
The so-called Ardilla tool uses a technique developed by the researchers &#8212; MIT&#8217;s Adam Kiezun, the University of Washington&#8217;s Michael Ernst, Stanford&#8217;s Philip Guo, and Syracuse University&#8217;s Karthick Jayaraman &#8212; that creates inputs that pinpoint bugs in [...]]]></description>
			<content:encoded><![CDATA[<blockquote><p>Researchers have built a tool that automatically finds and exploits SQL injection and cross-site scripting vulnerabilities in Web applications.</p>
<p>The so-called Ardilla tool uses a technique developed by the researchers &#8212; MIT&#8217;s Adam Kiezun, the University of Washington&#8217;s Michael Ernst, Stanford&#8217;s Philip Guo, and Syracuse University&#8217;s Karthick Jayaraman &#8212; that creates inputs that pinpoint bugs in Web applications and then generates SQL injection and XSS attacks. Ardilla is for PHP-based Web apps. </p></blockquote>
<p>There is also a <a href="http://groups.csail.mit.edu/pag/ardilla/">table of results</a> from analysis done against several PHP web applications</p>
<p>Via: <a href="http://www.darkreading.com/security/app-security/showArticle.jhtml?articleID=218100143">darkREADING</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ruanmuller.com/2009/06/19/php-interpreter-modified-to-find-xss-and-injection-holes-automatically-generates-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
