<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>The HP Security Laboratory</title><link>http://www.communities.hp.com/securitysoftware/blogs/spilabs/default.aspx</link><description /><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP1 (Build: 31106.3070)</generator><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" href="http://feeds.feedburner.com/TheSpiLaboratory" type="application/rss+xml" /><item><title>News of Michael Jackson's death blazes across the web--what if it were a hoax?</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/kMiTGZGYCjQ/information-speed-mj-s-death-blasts-across-the-web.aspx</link><pubDate>Fri, 26 Jun 2009 17:59:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:90442</guid><dc:creator>Chris Sullo</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=90442</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/26/information-speed-mj-s-death-blasts-across-the-web.aspx#comments</comments><description>Over at the SEOmozBlog , Danny Dover has a really interesting post about how, and how fast, the news of Michael Jackson&amp;#39;s death travelled across the web. I won&amp;#39;t go through it here, but it&amp;#39;s a fascinating read. Less than an hour after the...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/26/information-speed-mj-s-death-blasts-across-the-web.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=90442" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kMiTGZGYCjQ:ZjCt2eDZJA0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kMiTGZGYCjQ:ZjCt2eDZJA0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=kMiTGZGYCjQ:ZjCt2eDZJA0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kMiTGZGYCjQ:ZjCt2eDZJA0:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kMiTGZGYCjQ:ZjCt2eDZJA0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=kMiTGZGYCjQ:ZjCt2eDZJA0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kMiTGZGYCjQ:ZjCt2eDZJA0:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/kMiTGZGYCjQ" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/malware/default.aspx">malware</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/phishing/default.aspx">phishing</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/26/information-speed-mj-s-death-blasts-across-the-web.aspx</feedburner:origLink></item><item><title>Uncharted Territories: the personal-corporate-social-web-mashup</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/DzouAA5pkGg/uncharted-territories-the-personal-corporate-social-web-mashup.aspx</link><pubDate>Wed, 24 Jun 2009 15:19:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:90144</guid><dc:creator>Chris Sullo</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=90144</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/24/uncharted-territories-the-personal-corporate-social-web-mashup.aspx#comments</comments><description>Corporate web communications have grown from simple web pages to massive and complex applications. The security department has mostly kept up and maintained a secure perimeter&amp;mdash;even when that perimeter included outsourced and vendor systems. Contracts...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/24/uncharted-territories-the-personal-corporate-social-web-mashup.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=90144" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=DzouAA5pkGg:Z4LR1K0Ob1o:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=DzouAA5pkGg:Z4LR1K0Ob1o:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=DzouAA5pkGg:Z4LR1K0Ob1o:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=DzouAA5pkGg:Z4LR1K0Ob1o:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=DzouAA5pkGg:Z4LR1K0Ob1o:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=DzouAA5pkGg:Z4LR1K0Ob1o:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=DzouAA5pkGg:Z4LR1K0Ob1o:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/DzouAA5pkGg" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/hacked/default.aspx">hacked</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/policy/default.aspx">policy</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/web+application+security/default.aspx">web application security</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/24/uncharted-territories-the-personal-corporate-social-web-mashup.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 6/08/09 - 6/23/09</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/-DFQDpy7SUA/top-five-web-application-vulnerabilities-6-08-09-6-23-09.aspx</link><pubDate>Tue, 23 Jun 2009 19:04:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:90044</guid><dc:creator>mark.painter</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=90044</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/23/top-five-web-application-vulnerabilities-6-08-09-6-23-09.aspx#comments</comments><description>1) F5 Networks FirePass SSL VPN Unspecified Cross-Site Scripting Vulnerability F5 Networks FirePass SSL VPN is susceptible to a Cross-Site Scripting vulnerability. If successful, Cross-Site Scripting can be exploited to manipulate or steal cookies, create...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/23/top-five-web-application-vulnerabilities-6-08-09-6-23-09.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=90044" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=-DFQDpy7SUA:-4NWO5pA7oo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=-DFQDpy7SUA:-4NWO5pA7oo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=-DFQDpy7SUA:-4NWO5pA7oo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=-DFQDpy7SUA:-4NWO5pA7oo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=-DFQDpy7SUA:-4NWO5pA7oo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=-DFQDpy7SUA:-4NWO5pA7oo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=-DFQDpy7SUA:-4NWO5pA7oo:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/-DFQDpy7SUA" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/information+disclosure/default.aspx">information disclosure</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Apache+Tomcat/default.aspx">Apache Tomcat</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/FireStats/default.aspx">FireStats</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/F5+Networks+FirePass+SSL+VPN/default.aspx">F5 Networks FirePass SSL VPN</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site++scripting/default.aspx">cross-site  scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/ModSecurity/default.aspx">ModSecurity</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/remote+file+include/default.aspx">remote file include</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/23/top-five-web-application-vulnerabilities-6-08-09-6-23-09.aspx</feedburner:origLink></item><item><title>Hello darknets, my old friend...</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/ViPAP2Qv0x0/hello-darknets-my-old-friend.aspx</link><pubDate>Wed, 17 Jun 2009 18:31:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89944</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89944</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/17/hello-darknets-my-old-friend.aspx#comments</comments><description>Billy Hoffman and Matt Wood of the HP Web Security Research Group are generating serious heat with their upcoming BlackHat USA presentation which will detail their browser-based darknet. Articles on Dark Reading, Forbes.com, and Slashdot are just the...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/17/hello-darknets-my-old-friend.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89944" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ViPAP2Qv0x0:XbIgRZ-QV4E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ViPAP2Qv0x0:XbIgRZ-QV4E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=ViPAP2Qv0x0:XbIgRZ-QV4E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ViPAP2Qv0x0:XbIgRZ-QV4E:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ViPAP2Qv0x0:XbIgRZ-QV4E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=ViPAP2Qv0x0:XbIgRZ-QV4E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ViPAP2Qv0x0:XbIgRZ-QV4E:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/ViPAP2Qv0x0" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/blackhat+usa/default.aspx">blackhat usa</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/darknet/default.aspx">darknet</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/17/hello-darknets-my-old-friend.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities  5/26/09 - 6/07/09</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/ZBpwyF48FUk/top-five-web-application-vulnerabilities-5-26-09-6-07-09.aspx</link><pubDate>Mon, 08 Jun 2009 19:06:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89811</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89811</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/08/top-five-web-application-vulnerabilities-5-26-09-6-07-09.aspx#comments</comments><description>1) Sun Java System Web Server Reverse Proxy Plug-in Cross-Site Scripting Vulnerability Sun Java System Web Server is susceptible to a Cross-Site Scripting vulnerability. If successful, Cross-Site Scripting can be exploited to manipulate or steal cookies...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/08/top-five-web-application-vulnerabilities-5-26-09-6-07-09.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89811" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZBpwyF48FUk:VZXo5sWfChg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZBpwyF48FUk:VZXo5sWfChg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=ZBpwyF48FUk:VZXo5sWfChg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZBpwyF48FUk:VZXo5sWfChg:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZBpwyF48FUk:VZXo5sWfChg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=ZBpwyF48FUk:VZXo5sWfChg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=ZBpwyF48FUk:VZXo5sWfChg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/ZBpwyF48FUk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/SQL+Injection/default.aspx">SQL Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site+scripting/default.aspx">cross-site scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/PHP-Nuke/default.aspx">PHP-Nuke</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/IBM+FileNet+Content+Manager/default.aspx">IBM FileNet Content Manager</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Sun+Java+System+Web+Server/default.aspx">Sun Java System Web Server</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Apache+Tomcat/default.aspx">Apache Tomcat</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/phpBugTracker/default.aspx">phpBugTracker</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/08/top-five-web-application-vulnerabilities-5-26-09-6-07-09.aspx</feedburner:origLink></item><item><title>Talking Headers: Part 3: The Fun</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/kaspPtToU_k/talking-headers-part-3-the-fun.aspx</link><pubDate>Mon, 08 Jun 2009 12:29:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89807</guid><dc:creator>Chris Sullo</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89807</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/08/talking-headers-part-3-the-fun.aspx#comments</comments><description>In Part 1 of the series on interesting headers, I talked about leaking hostnames. In Part 2 , it was PHP errors. In Part 3 I bring you... the funny stuff. Not funny, like how Mark Mcgwire&amp;#39;s rookie card is now $5 on ebay compared to the hundreds it...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/08/talking-headers-part-3-the-fun.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89807" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kaspPtToU_k:KOjyIg9sKaE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kaspPtToU_k:KOjyIg9sKaE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=kaspPtToU_k:KOjyIg9sKaE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kaspPtToU_k:KOjyIg9sKaE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kaspPtToU_k:KOjyIg9sKaE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=kaspPtToU_k:KOjyIg9sKaE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=kaspPtToU_k:KOjyIg9sKaE:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/kaspPtToU_k" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Research/default.aspx">Research</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/HTTP/default.aspx">HTTP</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Headers/default.aspx">Headers</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/humor/default.aspx">humor</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/08/talking-headers-part-3-the-fun.aspx</feedburner:origLink></item><item><title>Schneier on security in the age of cloud computing</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/k9NpkcHO-vk/schneier-on-security-in-the-age-of-cloud-computing.aspx</link><pubDate>Thu, 04 Jun 2009 16:03:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89779</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89779</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/04/schneier-on-security-in-the-age-of-cloud-computing.aspx#comments</comments><description>Bruce Schneier offers a great perspective on why security is even more important in the age of cloud computing. As the expression goes, three can keep a secret if two of them are dead. In a nutshell, cloud computing forces you to increase the number of...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/04/schneier-on-security-in-the-age-of-cloud-computing.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89779" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=k9NpkcHO-vk:KN8CXLDAETI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=k9NpkcHO-vk:KN8CXLDAETI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=k9NpkcHO-vk:KN8CXLDAETI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=k9NpkcHO-vk:KN8CXLDAETI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=k9NpkcHO-vk:KN8CXLDAETI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=k9NpkcHO-vk:KN8CXLDAETI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=k9NpkcHO-vk:KN8CXLDAETI:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/k9NpkcHO-vk" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cloud+computing/default.aspx">cloud computing</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/bruce+schneier/default.aspx">bruce schneier</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/04/schneier-on-security-in-the-age-of-cloud-computing.aspx</feedburner:origLink></item><item><title>Talking Headers: Part 2</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/o_5btLvgebc/talking-headers-part-2.aspx</link><pubDate>Wed, 03 Jun 2009 13:30:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89729</guid><dc:creator>Chris Sullo</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89729</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/03/talking-headers-part-2.aspx#comments</comments><description>While my rookie Mark McGwire cards aren&amp;#39;t appreciating at all, my header collection is. Check these actual headers out: php warning: Unknown(): Unable to load dynamic library &amp;#39;/usr/local/lib/php/extensions/no-debug-non-zts-20020429/mysql.so&amp;#39;...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/03/talking-headers-part-2.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89729" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=o_5btLvgebc:KwGbogyIVUQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=o_5btLvgebc:KwGbogyIVUQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=o_5btLvgebc:KwGbogyIVUQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=o_5btLvgebc:KwGbogyIVUQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=o_5btLvgebc:KwGbogyIVUQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=o_5btLvgebc:KwGbogyIVUQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=o_5btLvgebc:KwGbogyIVUQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/o_5btLvgebc" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Research/default.aspx">Research</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/HTTP/default.aspx">HTTP</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Headers/default.aspx">Headers</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/PHP/default.aspx">PHP</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/03/talking-headers-part-2.aspx</feedburner:origLink></item><item><title>Hacking has evolved</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/UH0OpLpP-Mc/hacking-has-evolved.aspx</link><pubDate>Tue, 02 Jun 2009 14:22:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89725</guid><dc:creator>mark.painter</dc:creator><slash:comments>1</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89725</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/02/hacking-has-evolved.aspx#comments</comments><description>This is a great article about the value of a hacked PC to an attacker. While this focuses on personal PCs, all of these reasons can also apply to compromised web servers. Remember, web hacking has evolved. Script kiddies began by defacing web sites and...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/02/hacking-has-evolved.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89725" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=UH0OpLpP-Mc:nfAzHiVlLHA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=UH0OpLpP-Mc:nfAzHiVlLHA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=UH0OpLpP-Mc:nfAzHiVlLHA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=UH0OpLpP-Mc:nfAzHiVlLHA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=UH0OpLpP-Mc:nfAzHiVlLHA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=UH0OpLpP-Mc:nfAzHiVlLHA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=UH0OpLpP-Mc:nfAzHiVlLHA:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/UH0OpLpP-Mc" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/web+application+security/default.aspx">web application security</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/hackers/default.aspx">hackers</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/06/02/hacking-has-evolved.aspx</feedburner:origLink></item><item><title>Instant High Score!</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/2NmX3SyrDP8/instant-high-score.aspx</link><pubDate>Fri, 29 May 2009 17:49:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89707</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89707</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/29/instant-high-score.aspx#comments</comments><description>One of our security researchers just happened to stumble across this interesting Highscores area of a free Flash skeet shooting game. Notice scores 6-10. Now I&amp;#39;m not saying he had anything to do with this. What I am saying is that if your query parameters...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/29/instant-high-score.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89707" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2NmX3SyrDP8:iYMDQV3WCPg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2NmX3SyrDP8:iYMDQV3WCPg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=2NmX3SyrDP8:iYMDQV3WCPg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2NmX3SyrDP8:iYMDQV3WCPg:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2NmX3SyrDP8:iYMDQV3WCPg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=2NmX3SyrDP8:iYMDQV3WCPg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=2NmX3SyrDP8:iYMDQV3WCPg:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/2NmX3SyrDP8" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/web+application+security/default.aspx">web application security</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/hackers/default.aspx">hackers</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/29/instant-high-score.aspx</feedburner:origLink></item><item><title>Talking Headers: Part 1</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/mb2FcOEdTAQ/what-do-your-headers-say-about-you.aspx</link><pubDate>Fri, 29 May 2009 14:58:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89705</guid><dc:creator>Chris Sullo</dc:creator><slash:comments>2</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89705</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/29/what-do-your-headers-say-about-you.aspx#comments</comments><description>Some people collect coins, DVDs or comic books. Others collect cars or Star Wars toys. Among other things, I like to collect HTTP headers. They take up a lot less space than cars, and can have a much higher return value than Mark McGwire&amp;#39;s rookie...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/29/what-do-your-headers-say-about-you.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89705" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=mb2FcOEdTAQ:t68NzEJSa1Y:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=mb2FcOEdTAQ:t68NzEJSa1Y:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=mb2FcOEdTAQ:t68NzEJSa1Y:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=mb2FcOEdTAQ:t68NzEJSa1Y:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=mb2FcOEdTAQ:t68NzEJSa1Y:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=mb2FcOEdTAQ:t68NzEJSa1Y:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=mb2FcOEdTAQ:t68NzEJSa1Y:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/mb2FcOEdTAQ" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Research/default.aspx">Research</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/HTTP/default.aspx">HTTP</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Headers/default.aspx">Headers</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/29/what-do-your-headers-say-about-you.aspx</feedburner:origLink></item><item><title>Social Insecurity</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/jWh0pGdwF_0/social-insecurity.aspx</link><pubDate>Thu, 28 May 2009 20:57:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89700</guid><dc:creator>todd.densmore</dc:creator><slash:comments>4</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89700</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/28/social-insecurity.aspx#comments</comments><description>Not too long ago, one could trust the big corporate names to run clean websites. You had to go surfing down some shady back alleys of the web to expose yourself to malware. Those were the na&amp;iuml;ve days of the pre-adolescent internet, when firewalls...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/28/social-insecurity.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89700" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=jWh0pGdwF_0:3jYRkm9tMao:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=jWh0pGdwF_0:3jYRkm9tMao:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=jWh0pGdwF_0:3jYRkm9tMao:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=jWh0pGdwF_0:3jYRkm9tMao:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=jWh0pGdwF_0:3jYRkm9tMao:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=jWh0pGdwF_0:3jYRkm9tMao:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=jWh0pGdwF_0:3jYRkm9tMao:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/jWh0pGdwF_0" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/malware/default.aspx">malware</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/social+networks/default.aspx">social networks</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/28/social-insecurity.aspx</feedburner:origLink></item><item><title>Top Five Web Application Vulnerabilities 5/12/09 - 5/25/09</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/vXgVUvf-JjE/top-five-web-application-vulnerabilities-5-12-09-5-25-09.aspx</link><pubDate>Wed, 27 May 2009 15:16:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89690</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89690</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/27/top-five-web-application-vulnerabilities-5-12-09-5-25-09.aspx#comments</comments><description>1) Novell GroupWise WebAccess Multiple Security Vulnerabilities Novell GroupWise WebAccess is susceptible to multiple vulnerabilities including Cross-Site Scripting and issues of security restriction bypass. Attackers who successfully exploit these vulnerabilities...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/27/top-five-web-application-vulnerabilities-5-12-09-5-25-09.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89690" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vXgVUvf-JjE:TYuRWklRgvQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vXgVUvf-JjE:TYuRWklRgvQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=vXgVUvf-JjE:TYuRWklRgvQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vXgVUvf-JjE:TYuRWklRgvQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vXgVUvf-JjE:TYuRWklRgvQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=vXgVUvf-JjE:TYuRWklRgvQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vXgVUvf-JjE:TYuRWklRgvQ:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/vXgVUvf-JjE" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/XSS/default.aspx">XSS</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/phpMyAdmin/default.aspx">phpMyAdmin</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/top+five+web+application+vulnerabilities/default.aspx">top five web application vulnerabilities</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/PHPCode+Injection/default.aspx">PHPCode Injection</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Sun+Java+System+Communications+Express/default.aspx">Sun Java System Communications Express</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Sun+Java+System+Portal+Server/default.aspx">Sun Java System Portal Server</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Novell+GroupWise+WebAccess/default.aspx">Novell GroupWise WebAccess</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/27/top-five-web-application-vulnerabilities-5-12-09-5-25-09.aspx</feedburner:origLink></item><item><title>The Internet is an unsafe place</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/RFrzGIrIbKA/the-internet-is-an-unsafe-place.aspx</link><pubDate>Fri, 22 May 2009 15:36:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89673</guid><dc:creator>mark.painter</dc:creator><slash:comments>0</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89673</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/22/the-internet-is-an-unsafe-place.aspx#comments</comments><description>Two recent studies have cast some light on the current state of web application security. How bad is it out there? Bad. 82% of web sites had either a Critical, High, or Urgent vulnerability within the past calendar year, with Cross-Site Scripting being...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/22/the-internet-is-an-unsafe-place.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89673" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=RFrzGIrIbKA:Lfrxao1nd3I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=RFrzGIrIbKA:Lfrxao1nd3I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=RFrzGIrIbKA:Lfrxao1nd3I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=RFrzGIrIbKA:Lfrxao1nd3I:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=RFrzGIrIbKA:Lfrxao1nd3I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=RFrzGIrIbKA:Lfrxao1nd3I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=RFrzGIrIbKA:Lfrxao1nd3I:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/RFrzGIrIbKA" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/hackers/default.aspx">hackers</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/cross-site+scripting/default.aspx">cross-site scripting</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Application+Management+Lifecycle/default.aspx">Application Management Lifecycle</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/ALM/default.aspx">ALM</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/22/the-internet-is-an-unsafe-place.aspx</feedburner:origLink></item><item><title>Microsoft's ClickOnce Firefox add-on</title><link>http://feedproxy.google.com/~r/TheSpiLaboratory/~3/vwQQAtLMLcs/the-sneaky-ms-clickonce-firefox-add-on.aspx</link><pubDate>Fri, 22 May 2009 14:35:00 GMT</pubDate><guid isPermaLink="false">94bda21f-7d63-4095-85de-7c2a68fb172c:89672</guid><dc:creator>Chris Sullo</dc:creator><slash:comments>7</slash:comments><wfw:commentRss>http://www.communities.hp.com/securitysoftware/blogs/spilabs/rsscomments.aspx?PostID=89672</wfw:commentRss><comments>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/22/the-sneaky-ms-clickonce-firefox-add-on.aspx#comments</comments><description>With Firefox, I just went to download a certain new version 2.0 web browser and and was surprised that after hitting the license accept button Firefox started up an installer, downloaded the application and installed it without any prompts or questions...(&lt;a href="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/22/the-sneaky-ms-clickonce-firefox-add-on.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://www.communities.hp.com/securitysoftware/aggbug.aspx?PostID=89672" width="1" height="1"&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vwQQAtLMLcs:a78090slCpk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vwQQAtLMLcs:a78090slCpk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=vwQQAtLMLcs:a78090slCpk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vwQQAtLMLcs:a78090slCpk:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vwQQAtLMLcs:a78090slCpk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?i=vwQQAtLMLcs:a78090slCpk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/TheSpiLaboratory?a=vwQQAtLMLcs:a78090slCpk:7Q72WNTAKBA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/TheSpiLaboratory?d=7Q72WNTAKBA" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/TheSpiLaboratory/~4/vwQQAtLMLcs" height="1" width="1"/&gt;</description><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/security/default.aspx">security</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Firefox/default.aspx">Firefox</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/Microsoft/default.aspx">Microsoft</category><category domain="http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/tags/browser/default.aspx">browser</category><feedburner:origLink>http://www.communities.hp.com/securitysoftware/blogs/spilabs/archive/2009/05/22/the-sneaky-ms-clickonce-firefox-add-on.aspx</feedburner:origLink></item></channel></rss>
