<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-3832621951001364942</atom:id><lastBuildDate>Wed, 23 May 2012 14:33:15 +0000</lastBuildDate><category>Whitepaper</category><category>Hardware hacking</category><category>Vulnerabilties</category><category>0day</category><category>Advisory</category><category>Omron 3S4YR-MVFW Card reader</category><category>Misc</category><category>How-to</category><category>Bluetooth</category><category>About</category><category>Rants from Thierry</category><category>Lectures</category><category>Vulnerability disclosure Policy</category><category>zero day</category><category>Tool</category><category>BTcrack</category><title>Musings on  Information Security</title><description>_     Where facts are few, experts are many</description><link>http://blog.zoller.lu/</link><managingEditor>noreply@blogger.com (Thierry Zoller)</managingEditor><generator>Blogger</generator><openSearch:totalResults>153</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/ThierryZoller" /><feedburner:info uri="thierryzoller" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>ThierryZoller</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-8848427690374817996</guid><pubDate>Thu, 17 May 2012 11:23:00 +0000</pubDate><atom:updated>2012-05-17T13:27:12.624+02:00</atom:updated><title>Updates and Notable comments :</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/LF0CjUs5kT4/updated-posts-and-notable-updates.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-bgX5PhXBxoA/T7Tej5fEJcI/AAAAAAAAAWY/eJlFlwHHEas/s72-c/exploit.png" height="72" width="72" /><thr:total>0</thr:total><description>Updated Posts :


The Post "Attacker Classes and Pyramid " has been updated to the third iteration. The post was updated in terms of coherency but I also added my OWASP BENELUX presentation entitled...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=LF0CjUs5kT4:CMetY_AF0ys:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=LF0CjUs5kT4:CMetY_AF0ys:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=LF0CjUs5kT4:CMetY_AF0ys:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=LF0CjUs5kT4:CMetY_AF0ys:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=LF0CjUs5kT4:CMetY_AF0ys:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=LF0CjUs5kT4:CMetY_AF0ys:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=LF0CjUs5kT4:CMetY_AF0ys:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/LF0CjUs5kT4" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2012/05/updated-posts-and-notable-updates.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-5536191032653560194</guid><pubDate>Sat, 05 May 2012 13:47:00 +0000</pubDate><atom:updated>2012-05-07T21:38:56.452+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Misc</category><title>PCI Compliance, Security in isolated System and Parking Tellers (2nd)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/aHI-1zsORLE/pci-compliance-security-in-isolated.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-5AGJ8RxwEhA/T6ggXIHdS8I/AAAAAAAAAVw/OwZaXV_R1ak/s72-c/cc_masked.png" height="72" width="72" /><thr:total>1</thr:total><description>Following up on my blog post a few months ago entitled "PCI compliance, Security in isolated systems and Parking Tellers Part 1" - I took a brief look the other day at another Ticket issued by a...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=aHI-1zsORLE:p7tYx86xeG8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=aHI-1zsORLE:p7tYx86xeG8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=aHI-1zsORLE:p7tYx86xeG8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=aHI-1zsORLE:p7tYx86xeG8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=aHI-1zsORLE:p7tYx86xeG8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=aHI-1zsORLE:p7tYx86xeG8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=aHI-1zsORLE:p7tYx86xeG8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/aHI-1zsORLE" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2012/05/pci-compliance-security-in-isolated.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-3537530159258704742</guid><pubDate>Sat, 24 Mar 2012 13:51:00 +0000</pubDate><atom:updated>2012-03-24T15:09:15.554+01:00</atom:updated><title>CVSS - Common Vulnerability Scoring System - a critique [ Part1 ]</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/8KUdP2NQDV8/cvss-common-vulnerability-scoring.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-ff9MRpYgixI/T23ApSPJv1I/AAAAAAAAATE/ATdlKcLYAzE/s72-c/CVSS-model-temp.jpg" height="72" width="72" /><thr:total>4</thr:total><description>Ever since I started my career in information security I was both interested and&amp;nbsp;intrigued by metrics applied to vulnerabilities (or metrics in general for that matter). CVSS...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=8KUdP2NQDV8:yfZ1ynxmh1I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=8KUdP2NQDV8:yfZ1ynxmh1I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=8KUdP2NQDV8:yfZ1ynxmh1I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=8KUdP2NQDV8:yfZ1ynxmh1I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=8KUdP2NQDV8:yfZ1ynxmh1I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=8KUdP2NQDV8:yfZ1ynxmh1I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=8KUdP2NQDV8:yfZ1ynxmh1I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/8KUdP2NQDV8" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2012/03/cvss-common-vulnerability-scoring.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-7314969346455474057</guid><pubDate>Tue, 27 Dec 2011 15:02:00 +0000</pubDate><atom:updated>2011-12-27T16:09:45.422+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tool</category><title>"SSL Audit" - Updated release (SSL/TLS Scanner)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/40A547UPkuM/ssl-audit-updated-released-ssltls.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-wEtM9J9q31E/Tvnc7CWv6oI/AAAAAAAAASc/VToPKwObotY/s72-c/sslaudit_screenshot.png" height="72" width="72" /><thr:total>0</thr:total><description>Preamble :


During my research on TLS/SSL Compatibility across different Operation Systems and Browsers I created supporting tools for myself and later decided to release them for the public....&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=40A547UPkuM:Ei5khlNALqU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=40A547UPkuM:Ei5khlNALqU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=40A547UPkuM:Ei5khlNALqU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=40A547UPkuM:Ei5khlNALqU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=40A547UPkuM:Ei5khlNALqU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=40A547UPkuM:Ei5khlNALqU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=40A547UPkuM:Ei5khlNALqU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/40A547UPkuM" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/12/ssl-audit-updated-released-ssltls.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-2463497595311468403</guid><pubDate>Fri, 23 Dec 2011 12:19:00 +0000</pubDate><atom:updated>2011-12-23T14:00:00.431+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Whitepaper</category><title>Final - SSL/TLS renegotiation explained (CVE-2009-3555)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/SPMFeQtDntE/final-ssltls-renegotiation-explained.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Final release for my paper explaining the different attack vectors and impacts for (CVE-2009-3555) "TLS / SSL renegotiation vulnerability".


Added comments and corrections by Alun Jones (Who I...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SPMFeQtDntE:Dmw5puGGqMM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SPMFeQtDntE:Dmw5puGGqMM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SPMFeQtDntE:Dmw5puGGqMM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SPMFeQtDntE:Dmw5puGGqMM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SPMFeQtDntE:Dmw5puGGqMM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SPMFeQtDntE:Dmw5puGGqMM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SPMFeQtDntE:Dmw5puGGqMM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/SPMFeQtDntE" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/12/final-ssltls-renegotiation-explained.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-6481594316151050236</guid><pubDate>Tue, 06 Dec 2011 19:13:00 +0000</pubDate><atom:updated>2012-05-07T21:42:52.873+02:00</atom:updated><title>PCI compliance, Security in isolated systems and Parking Tellers (Part1)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/PVJdzrnO6mQ/pci-compliance-security-in-isolated.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-hshVF4Ayhig/Tt5pUM829eI/AAAAAAAAASI/6QSN2hfFI1U/s72-c/quittung.png" height="72" width="72" /><thr:total>6</thr:total><description>A colleague of mine spotted the below while we were doing our expenses - The photograph below shows two separate receipts from two parking buildings that are not far away from each other in central...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=PVJdzrnO6mQ:DyjVV8RHR1A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=PVJdzrnO6mQ:DyjVV8RHR1A:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=PVJdzrnO6mQ:DyjVV8RHR1A:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=PVJdzrnO6mQ:DyjVV8RHR1A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=PVJdzrnO6mQ:DyjVV8RHR1A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=PVJdzrnO6mQ:DyjVV8RHR1A:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=PVJdzrnO6mQ:DyjVV8RHR1A:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/PVJdzrnO6mQ" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/12/pci-compliance-security-in-isolated.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-1150969640359588852</guid><pubDate>Tue, 01 Nov 2011 12:57:00 +0000</pubDate><atom:updated>2011-11-01T14:47:52.139+01:00</atom:updated><title>Blog cleanup</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/QRum0TeKmec/blog-cleanup_01.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>As some regulars might have noticed I restructed this blog a bit trying to get rid of some clutter. At the same time I updated a few specific pages I wanted to point out :


Vulnerability...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=QRum0TeKmec:PP3gEakBsXA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=QRum0TeKmec:PP3gEakBsXA:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=QRum0TeKmec:PP3gEakBsXA:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=QRum0TeKmec:PP3gEakBsXA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=QRum0TeKmec:PP3gEakBsXA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=QRum0TeKmec:PP3gEakBsXA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=QRum0TeKmec:PP3gEakBsXA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/QRum0TeKmec" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/11/blog-cleanup_01.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-8294795631782082724</guid><pubDate>Wed, 26 Oct 2011 18:41:00 +0000</pubDate><atom:updated>2011-10-26T21:13:45.861+02:00</atom:updated><title>THC SSL DoS - vs - Per Design</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/ZOBgjNFBXvA/thc-ssl-dos-vs-per-design.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>1</thr:total><description>Since this is a rather old topic with both sides having valid points I will keep this post short and sweet. I have had no time to measure of investigate in depth and I don't think I will find...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZOBgjNFBXvA:Iljenku6un4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZOBgjNFBXvA:Iljenku6un4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZOBgjNFBXvA:Iljenku6un4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZOBgjNFBXvA:Iljenku6un4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZOBgjNFBXvA:Iljenku6un4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZOBgjNFBXvA:Iljenku6un4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZOBgjNFBXvA:Iljenku6un4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/ZOBgjNFBXvA" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/10/thc-ssl-dos-vs-per-design.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-5621727569677144142</guid><pubDate>Tue, 18 Oct 2011 18:20:00 +0000</pubDate><atom:updated>2012-05-17T13:12:13.336+02:00</atom:updated><title>Attacker Classes and Pyramid (Version 3)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/LIoHUHR2NfY/attacker-classes-and-pyramid-version-1.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/-nfFCb7SQkyE/T7TaBKdsgHI/AAAAAAAAAV8/ZISLX3VtE1Q/s72-c/attacker_pyramid_attacker_class.png" height="72" width="72" /><thr:total>1</thr:total><description>This is a living blog post I will update whenever I have time and new ideas.



TOC 


Introduction
Updates
Attacker Classes
Attacker Pyramid
Q&amp;amp;A

Introduction

The other day I was brainstorming...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=LIoHUHR2NfY:h6Q25JzuTek:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=LIoHUHR2NfY:h6Q25JzuTek:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=LIoHUHR2NfY:h6Q25JzuTek:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=LIoHUHR2NfY:h6Q25JzuTek:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=LIoHUHR2NfY:h6Q25JzuTek:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=LIoHUHR2NfY:h6Q25JzuTek:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=LIoHUHR2NfY:h6Q25JzuTek:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/LIoHUHR2NfY" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/10/attacker-classes-and-pyramid-version-1.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-7096697410885773442</guid><pubDate>Mon, 26 Sep 2011 14:18:00 +0000</pubDate><atom:updated>2011-10-01T21:01:34.749+02:00</atom:updated><title>The BEAST summary - TLS, CBC, Countermeasures (Update 4)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/Mvqv5fDWooc/beast-summary-tls-cbc-countermeasures.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-DKzv733c-xU/ToCBwDmahUI/AAAAAAAAAQA/hzyW_XDU97E/s72-c/aaaaa2.png" height="72" width="72" /><thr:total>1</thr:total><description>Lots of good information floating on the internet on the Proof of Concept (dubbed 'BEAST) against TLS 1.0 by Juliano Rizzo and Thai Duong at the Ekoparty. 




This blog post will be continuously...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Mvqv5fDWooc:k2o9WhWb3Y8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Mvqv5fDWooc:k2o9WhWb3Y8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Mvqv5fDWooc:k2o9WhWb3Y8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Mvqv5fDWooc:k2o9WhWb3Y8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Mvqv5fDWooc:k2o9WhWb3Y8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Mvqv5fDWooc:k2o9WhWb3Y8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Mvqv5fDWooc:k2o9WhWb3Y8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/Mvqv5fDWooc" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/09/beast-summary-tls-cbc-countermeasures.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-4293378804439286873</guid><pubDate>Tue, 20 Sep 2011 15:21:00 +0000</pubDate><atom:updated>2011-09-25T17:33:20.260+02:00</atom:updated><title>TLS/SSL hardening and compatibility Report 2011</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/Eo4LpJM9MZE/tlsssl-hardening-and-compatibility.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/-WRP9DFtnDyw/Tn9JsHDiAvI/AAAAAAAAAPk/knGPXb1xO2k/s72-c/aaaaa2.png" height="72" width="72" /><thr:total>0</thr:total><description>This is a cross post from the G-SEC blog



My professional and private commitments made it difficult to maintain a healthy blogging style, I am trying to get back to some blogging on a more regular...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Eo4LpJM9MZE:gO7f-VvjGio:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Eo4LpJM9MZE:gO7f-VvjGio:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Eo4LpJM9MZE:gO7f-VvjGio:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Eo4LpJM9MZE:gO7f-VvjGio:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Eo4LpJM9MZE:gO7f-VvjGio:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Eo4LpJM9MZE:gO7f-VvjGio:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Eo4LpJM9MZE:gO7f-VvjGio:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/Eo4LpJM9MZE" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/09/tlsssl-hardening-and-compatibility.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-231612040921714654</guid><pubDate>Tue, 23 Aug 2011 18:47:00 +0000</pubDate><atom:updated>2011-09-24T17:24:05.164+02:00</atom:updated><title>What did PHP crypt() and Alzheimer have in common ?</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/PsKLpyLTtmU/what-does-php-crypt-and-alzheimer-had.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>I stumbled across this weird PHP bug in the crypt() implementation (version&amp;nbsp;5.3.7RC5) [1]
The bug reporter states that :


"If crypt() is executed with MD5 salts, the return value consists of...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=PsKLpyLTtmU:xkNH91GEhck:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=PsKLpyLTtmU:xkNH91GEhck:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=PsKLpyLTtmU:xkNH91GEhck:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=PsKLpyLTtmU:xkNH91GEhck:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=PsKLpyLTtmU:xkNH91GEhck:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=PsKLpyLTtmU:xkNH91GEhck:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=PsKLpyLTtmU:xkNH91GEhck:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/PsKLpyLTtmU" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/08/what-does-php-crypt-and-alzheimer-had.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-4147813315997820284</guid><pubDate>Mon, 01 Aug 2011 20:20:00 +0000</pubDate><atom:updated>2011-11-01T13:56:13.268+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">How-to</category><category domain="http://www.blogger.com/atom/ns#">About</category><category domain="http://www.blogger.com/atom/ns#">Lectures</category><category domain="http://www.blogger.com/atom/ns#">Misc</category><title>Tools, Whitepapers, Talks</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/Zl3UNvxhQQM/tools-whitepapers-talks.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://img.youtube.com/vi/jxp-iohRdjY/default.jpg" height="72" width="72" /><thr:total>0</thr:total><description>Talks / Lectures


During my career I had the opportunity to present my thoughts and views on Information Security to numerous people and organizations, below is a list of conferences I had the...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Zl3UNvxhQQM:UFE0CLDpucw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Zl3UNvxhQQM:UFE0CLDpucw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Zl3UNvxhQQM:UFE0CLDpucw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Zl3UNvxhQQM:UFE0CLDpucw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Zl3UNvxhQQM:UFE0CLDpucw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Zl3UNvxhQQM:UFE0CLDpucw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Zl3UNvxhQQM:UFE0CLDpucw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/Zl3UNvxhQQM" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2011/08/tools-whitepapers-talks.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-4220293074585707444</guid><pubDate>Sun, 22 Aug 2010 21:33:00 +0000</pubDate><atom:updated>2011-09-24T17:51:31.234+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">0day</category><title>CVE-2010-x+n - Loadlibrary/Getprocaddress roars its evil head in 2010</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/C6gVneAPWbY/cve-2010-xn-loadlibrarygetprocaddress.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_LApW097P-0I/THGVpjhPktI/AAAAAAAAAMA/nGCcvsdZ9Io/s72-c/dll.png" height="72" width="72" /><thr:total>2</thr:total><description>Subscribe to the RSS feed in case you are interested in updates






After Acrossecurity, published an interesting vulnerability and HDmoore appears to have stumbled on the same issue, I decided to...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=C6gVneAPWbY:saWf6CnQF8k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=C6gVneAPWbY:saWf6CnQF8k:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=C6gVneAPWbY:saWf6CnQF8k:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=C6gVneAPWbY:saWf6CnQF8k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=C6gVneAPWbY:saWf6CnQF8k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=C6gVneAPWbY:saWf6CnQF8k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=C6gVneAPWbY:saWf6CnQF8k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/C6gVneAPWbY" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/08/cve-2010-xn-loadlibrarygetprocaddress.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-3121983137680607621</guid><pubDate>Sun, 18 Jul 2010 13:14:00 +0000</pubDate><atom:updated>2010-07-18T16:37:06.295+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">0day</category><title>CVE-2010-2568 - LNK Code execution - Proof of concept (Update)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/Uk9OAOexbe0/cve-2010-2568-lnk-code-execution-proof.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



&amp;nbsp;Ivanlef0u released a POC for the exploit used in targeted attacks :http://ivanlef0u.nibbles.fr/repo/suckme.rar 


More...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Uk9OAOexbe0:uqWe8qm69EE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Uk9OAOexbe0:uqWe8qm69EE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Uk9OAOexbe0:uqWe8qm69EE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Uk9OAOexbe0:uqWe8qm69EE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Uk9OAOexbe0:uqWe8qm69EE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Uk9OAOexbe0:uqWe8qm69EE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Uk9OAOexbe0:uqWe8qm69EE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/Uk9OAOexbe0" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/07/cve-2010-2568-lnk-code-execution-proof.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-8140928368275053101</guid><pubDate>Wed, 17 Mar 2010 17:09:00 +0000</pubDate><atom:updated>2010-04-03T17:36:51.787+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Misc</category><title>Top 10 Vulnerability Researcher 2009</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/5gyTe0EHW6M/top-10-vulnerability-researcher-2009.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/S6EKj8tQXqI/AAAAAAAAAL4/GrHk9nkNns8/s72-c/top10.png" height="72" width="72" /><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





Thanks @edisoar for the hint: IBM ISS collected information about the researches that discovered and published most...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=5gyTe0EHW6M:upWyf2d2MZ8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=5gyTe0EHW6M:upWyf2d2MZ8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=5gyTe0EHW6M:upWyf2d2MZ8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=5gyTe0EHW6M:upWyf2d2MZ8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=5gyTe0EHW6M:upWyf2d2MZ8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=5gyTe0EHW6M:upWyf2d2MZ8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=5gyTe0EHW6M:upWyf2d2MZ8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/5gyTe0EHW6M" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/03/top-10-vulnerability-researcher-2009.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-1995332981951683579</guid><pubDate>Tue, 02 Mar 2010 17:07:00 +0000</pubDate><atom:updated>2010-03-02T18:11:47.190+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Misc</category><title>Videos of IDF Nominees in "Excellence in Visual Art"</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/147soO2kELM/indie-games.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





The Independant Games Festival is taking place right now, the Indie games [1] below have been nominated in the category...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=147soO2kELM:19l4l8Q_ZeI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=147soO2kELM:19l4l8Q_ZeI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=147soO2kELM:19l4l8Q_ZeI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=147soO2kELM:19l4l8Q_ZeI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=147soO2kELM:19l4l8Q_ZeI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=147soO2kELM:19l4l8Q_ZeI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=147soO2kELM:19l4l8Q_ZeI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/147soO2kELM" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/03/indie-games.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-271148901599299049</guid><pubDate>Thu, 18 Feb 2010 15:23:00 +0000</pubDate><atom:updated>2010-02-18T16:23:53.040+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tool</category><title>New Paper: SSL/TLS Hardening and Compatibility report 2010</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/qk9Cm_DK22g/new-paper-ssltls-hardening-and.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



Copied from the post over at G-SEC:

At last. What started as an "I need an overview of best  practise in SSL/TLS configuration"...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qk9Cm_DK22g:uWBJOEi0qlc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qk9Cm_DK22g:uWBJOEi0qlc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qk9Cm_DK22g:uWBJOEi0qlc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qk9Cm_DK22g:uWBJOEi0qlc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qk9Cm_DK22g:uWBJOEi0qlc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qk9Cm_DK22g:uWBJOEi0qlc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qk9Cm_DK22g:uWBJOEi0qlc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/qk9Cm_DK22g" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/02/new-paper-ssltls-hardening-and.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-8778919106074909177</guid><pubDate>Wed, 17 Feb 2010 09:22:00 +0000</pubDate><atom:updated>2010-02-17T10:22:05.567+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tool</category><title>SSL/TLS Audit - New tool</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/idSURMn-hJI/ssltls-audit-new-tool.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/S3LRqNGwiuI/AAAAAAAAAK8/zr1cNq5xCIc/s72-c/ssl_scanner.png" height="72" width="72" /><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



Developed as part of G-SEC's investigation into the "Secure SSL/TLS configuration Report 2010" (to be published) we developed this...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=idSURMn-hJI:2cI0yJElmYM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=idSURMn-hJI:2cI0yJElmYM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=idSURMn-hJI:2cI0yJElmYM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=idSURMn-hJI:2cI0yJElmYM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=idSURMn-hJI:2cI0yJElmYM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=idSURMn-hJI:2cI0yJElmYM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=idSURMn-hJI:2cI0yJElmYM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/idSURMn-hJI" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/02/ssltls-audit-new-tool.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-2558977687474191270</guid><pubDate>Wed, 18 Nov 2009 14:16:00 +0000</pubDate><atom:updated>2009-11-30T15:19:29.989+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Whitepaper</category><title>TLS / SSLv3 renegotiation vulnerability explained - NEW update</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/ZIG1jgvIjVs/tls-sslv3-renegotiation-vulnerability.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>2</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



I updated the whitepaper "TLS / SSLv3 vulnerability explained" :



Updated 18.11.2009 : Added SMTP over TLS attack scenario, added...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZIG1jgvIjVs:beNHYvgiZOw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZIG1jgvIjVs:beNHYvgiZOw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZIG1jgvIjVs:beNHYvgiZOw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZIG1jgvIjVs:beNHYvgiZOw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZIG1jgvIjVs:beNHYvgiZOw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZIG1jgvIjVs:beNHYvgiZOw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZIG1jgvIjVs:beNHYvgiZOw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/ZIG1jgvIjVs" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-2610698277055879433</guid><pubDate>Thu, 05 Nov 2009 13:12:00 +0000</pubDate><atom:updated>2009-11-12T22:50:26.242+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">zero day</category><title>New SSLv3 / TLS  vulnerability - MITM attacks possible</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/CPzTDbkY2fg/new-sslv3-tls-vulnerability-mitm.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>2</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





In order to allow me to update in a more convenient manner, the latest updates will be added to the G-SEC blog only. Once the...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=CPzTDbkY2fg:iM3glkIBGXs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=CPzTDbkY2fg:iM3glkIBGXs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=CPzTDbkY2fg:iM3glkIBGXs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=CPzTDbkY2fg:iM3glkIBGXs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=CPzTDbkY2fg:iM3glkIBGXs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=CPzTDbkY2fg:iM3glkIBGXs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=CPzTDbkY2fg:iM3glkIBGXs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/CPzTDbkY2fg" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/11/new-sslv3-tls-vulnerability-mitm.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-1088495485975213547</guid><pubDate>Tue, 13 Oct 2009 14:59:00 +0000</pubDate><atom:updated>2009-10-14T14:23:04.565+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Computer Associates multiple products - RCE</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/w7Wazo267cU/computer-associates-multiple-products.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/StSWPLTcUzI/AAAAAAAAAKQ/i4VHfJPvqoQ/s72-c/pwned+by+av.jpg" height="72" width="72" /><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





I released another advisory today, the affected products are from Computer Associates who I'd like to thank for the cooperation...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=w7Wazo267cU:O2NntFIJVZo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=w7Wazo267cU:O2NntFIJVZo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=w7Wazo267cU:O2NntFIJVZo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=w7Wazo267cU:O2NntFIJVZo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=w7Wazo267cU:O2NntFIJVZo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=w7Wazo267cU:O2NntFIJVZo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=w7Wazo267cU:O2NntFIJVZo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/w7Wazo267cU" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/10/computer-associates-multiple-products.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-1941041156923876650</guid><pubDate>Sat, 12 Sep 2009 13:38:00 +0000</pubDate><atom:updated>2009-09-12T15:40:26.587+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Rants from Thierry</category><title>Derren Brown guessed the lottery numbers - afterwards</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/P5ZfJlus6aA/derren-brown-guessed-lottery-numbers.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>1</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



Derren Brown, the NLP master and magician &amp;nbsp;"predicted" the Lotterie numbers Live on TV and promised to tell on Friday how he...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=P5ZfJlus6aA:JGizbezrlrE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=P5ZfJlus6aA:JGizbezrlrE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=P5ZfJlus6aA:JGizbezrlrE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=P5ZfJlus6aA:JGizbezrlrE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=P5ZfJlus6aA:JGizbezrlrE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=P5ZfJlus6aA:JGizbezrlrE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=P5ZfJlus6aA:JGizbezrlrE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/P5ZfJlus6aA" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/09/derren-brown-guessed-lottery-numbers.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-3271155934380542097</guid><pubDate>Fri, 11 Sep 2009 15:31:00 +0000</pubDate><atom:updated>2009-10-26T17:59:20.732+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Rants from Thierry</category><title>You get what you pay for</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/SdJxYBIRzbk/you-get-what-you-pay-for.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/SqpsH79fbuI/AAAAAAAAAJw/Ia9rkRSv3Hs/s72-c/lanc1.png" height="72" width="72" /><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



On a more non-technical note, I stumbled across this offer from a "renowed luxemburgish recruitment agency." I am not sure what part...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SdJxYBIRzbk:BelmvNfxQ2I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SdJxYBIRzbk:BelmvNfxQ2I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SdJxYBIRzbk:BelmvNfxQ2I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SdJxYBIRzbk:BelmvNfxQ2I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SdJxYBIRzbk:BelmvNfxQ2I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SdJxYBIRzbk:BelmvNfxQ2I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SdJxYBIRzbk:BelmvNfxQ2I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/SdJxYBIRzbk" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/09/you-get-what-you-pay-for.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-6597355145516755319</guid><pubDate>Wed, 02 Sep 2009 11:46:00 +0000</pubDate><atom:updated>2009-09-02T13:48:52.206+02:00</atom:updated><title>IIS 5&amp;6 FTP vulnerability - information and tools (KB975191)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/87uKXJDHJ_A/iis-5-ftp-vulnerability-information-and.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates


I wrote a small summary and facts about the recent IIS5&amp;6 FTP 0day, note that te vulnerable part of the code can be reached without...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=87uKXJDHJ_A:-GalkjpC1go:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=87uKXJDHJ_A:-GalkjpC1go:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=87uKXJDHJ_A:-GalkjpC1go:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=87uKXJDHJ_A:-GalkjpC1go:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=87uKXJDHJ_A:-GalkjpC1go:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=87uKXJDHJ_A:-GalkjpC1go:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=87uKXJDHJ_A:-GalkjpC1go:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/87uKXJDHJ_A" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/09/iis-5-ftp-vulnerability-information-and.html</feedburner:origLink></item></channel></rss>

