<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-3832621951001364942</atom:id><lastBuildDate>Tue, 20 Jul 2010 13:48:58 +0000</lastBuildDate><title>Secdev - Thierry Zoller</title><description>Where facts are few, experts are many.</description><link>http://blog.zoller.lu/</link><managingEditor>noreply@blogger.com (Thierry Zoller)</managingEditor><generator>Blogger</generator><openSearch:totalResults>140</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/ThierryZoller" /><feedburner:info uri="thierryzoller" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><feedburner:emailServiceId>ThierryZoller</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-3121983137680607621</guid><pubDate>Sun, 18 Jul 2010 13:14:00 +0000</pubDate><atom:updated>2010-07-18T16:37:06.295+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">0day</category><title>CVE-2010-2568 - LNK Code execution - Proof of concept (Update)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/Uk9OAOexbe0/cve-2010-2568-lnk-code-execution-proof.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



&amp;nbsp;Ivanlef0u released a POC for the exploit used in targeted attacks :http://ivanlef0u.nibbles.fr/repo/suckme.rar 


More...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Uk9OAOexbe0:uqWe8qm69EE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Uk9OAOexbe0:uqWe8qm69EE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Uk9OAOexbe0:uqWe8qm69EE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Uk9OAOexbe0:uqWe8qm69EE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Uk9OAOexbe0:uqWe8qm69EE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=Uk9OAOexbe0:uqWe8qm69EE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=Uk9OAOexbe0:uqWe8qm69EE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/Uk9OAOexbe0" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/07/cve-2010-2568-lnk-code-execution-proof.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-1244288826689830303</guid><pubDate>Fri, 16 Jul 2010 17:47:00 +0000</pubDate><atom:updated>2010-07-16T20:08:54.130+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Misc</category><title>You got pwned - The song</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/pZroJITmMQM/you-got-pwned-song.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates







I am pretty confident this song  will win the pwnie award this year :





Credit Drraid - Download :...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=pZroJITmMQM:17paokZVFsU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=pZroJITmMQM:17paokZVFsU:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=pZroJITmMQM:17paokZVFsU:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=pZroJITmMQM:17paokZVFsU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=pZroJITmMQM:17paokZVFsU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=pZroJITmMQM:17paokZVFsU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=pZroJITmMQM:17paokZVFsU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/pZroJITmMQM" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/07/you-got-pwned-song.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-8140928368275053101</guid><pubDate>Wed, 17 Mar 2010 17:09:00 +0000</pubDate><atom:updated>2010-04-03T17:36:51.787+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Misc</category><title>Top 10 Vulnerability Researcher 2009</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/5gyTe0EHW6M/top-10-vulnerability-researcher-2009.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/S6EKj8tQXqI/AAAAAAAAAL4/GrHk9nkNns8/s72-c/top10.png" height="72" width="72" /><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





Thanks @edisoar for the hint: IBM ISS collected information about the researches that discovered and published most...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=5gyTe0EHW6M:upWyf2d2MZ8:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=5gyTe0EHW6M:upWyf2d2MZ8:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=5gyTe0EHW6M:upWyf2d2MZ8:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=5gyTe0EHW6M:upWyf2d2MZ8:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=5gyTe0EHW6M:upWyf2d2MZ8:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=5gyTe0EHW6M:upWyf2d2MZ8:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=5gyTe0EHW6M:upWyf2d2MZ8:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/5gyTe0EHW6M" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/03/top-10-vulnerability-researcher-2009.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-1995332981951683579</guid><pubDate>Tue, 02 Mar 2010 17:07:00 +0000</pubDate><atom:updated>2010-03-02T18:11:47.190+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Misc</category><title>Videos of IDF Nominees in "Excellence in Visual Art"</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/147soO2kELM/indie-games.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





The Independant Games Festival is taking place right now, the Indie games [1] below have been nominated in the category...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=147soO2kELM:19l4l8Q_ZeI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=147soO2kELM:19l4l8Q_ZeI:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=147soO2kELM:19l4l8Q_ZeI:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=147soO2kELM:19l4l8Q_ZeI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=147soO2kELM:19l4l8Q_ZeI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=147soO2kELM:19l4l8Q_ZeI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=147soO2kELM:19l4l8Q_ZeI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/147soO2kELM" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/03/indie-games.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-271148901599299049</guid><pubDate>Thu, 18 Feb 2010 15:23:00 +0000</pubDate><atom:updated>2010-02-18T16:23:53.040+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tool</category><title>New Paper: SSL/TLS Hardening and Compatibility report 2010</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/qk9Cm_DK22g/new-paper-ssltls-hardening-and.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



Copied from the post over at G-SEC:

At last. What started as an "I need an overview of best  practise in SSL/TLS configuration"...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qk9Cm_DK22g:uWBJOEi0qlc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qk9Cm_DK22g:uWBJOEi0qlc:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qk9Cm_DK22g:uWBJOEi0qlc:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qk9Cm_DK22g:uWBJOEi0qlc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qk9Cm_DK22g:uWBJOEi0qlc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qk9Cm_DK22g:uWBJOEi0qlc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qk9Cm_DK22g:uWBJOEi0qlc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/qk9Cm_DK22g" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/02/new-paper-ssltls-hardening-and.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-8778919106074909177</guid><pubDate>Wed, 17 Feb 2010 09:22:00 +0000</pubDate><atom:updated>2010-02-17T10:22:05.567+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tool</category><title>SSL/TLS Audit - New tool</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/idSURMn-hJI/ssltls-audit-new-tool.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/S3LRqNGwiuI/AAAAAAAAAK8/zr1cNq5xCIc/s72-c/ssl_scanner.png" height="72" width="72" /><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



Developed as part of G-SEC's investigation into the "Secure SSL/TLS configuration Report 2010" (to be published) we developed this...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=idSURMn-hJI:2cI0yJElmYM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=idSURMn-hJI:2cI0yJElmYM:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=idSURMn-hJI:2cI0yJElmYM:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=idSURMn-hJI:2cI0yJElmYM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=idSURMn-hJI:2cI0yJElmYM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=idSURMn-hJI:2cI0yJElmYM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=idSURMn-hJI:2cI0yJElmYM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/idSURMn-hJI" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2010/02/ssltls-audit-new-tool.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-2558977687474191270</guid><pubDate>Wed, 18 Nov 2009 14:16:00 +0000</pubDate><atom:updated>2009-11-30T15:19:29.989+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Whitepaper</category><title>TLS / SSLv3 renegotiation vulnerability explained - NEW update</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/ZIG1jgvIjVs/tls-sslv3-renegotiation-vulnerability.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>2</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



I updated the whitepaper "TLS / SSLv3 vulnerability explained" :



Updated 18.11.2009 : Added SMTP over TLS attack scenario, added...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZIG1jgvIjVs:beNHYvgiZOw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZIG1jgvIjVs:beNHYvgiZOw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZIG1jgvIjVs:beNHYvgiZOw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZIG1jgvIjVs:beNHYvgiZOw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZIG1jgvIjVs:beNHYvgiZOw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=ZIG1jgvIjVs:beNHYvgiZOw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=ZIG1jgvIjVs:beNHYvgiZOw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/ZIG1jgvIjVs" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-2610698277055879433</guid><pubDate>Thu, 05 Nov 2009 13:12:00 +0000</pubDate><atom:updated>2009-11-12T22:50:26.242+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">zero day</category><title>New SSLv3 / TLS  vulnerability - MITM attacks possible</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/CPzTDbkY2fg/new-sslv3-tls-vulnerability-mitm.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>2</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





In order to allow me to update in a more convenient manner, the latest updates will be added to the G-SEC blog only. Once the...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=CPzTDbkY2fg:iM3glkIBGXs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=CPzTDbkY2fg:iM3glkIBGXs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=CPzTDbkY2fg:iM3glkIBGXs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=CPzTDbkY2fg:iM3glkIBGXs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=CPzTDbkY2fg:iM3glkIBGXs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=CPzTDbkY2fg:iM3glkIBGXs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=CPzTDbkY2fg:iM3glkIBGXs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/CPzTDbkY2fg" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/11/new-sslv3-tls-vulnerability-mitm.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-1088495485975213547</guid><pubDate>Tue, 13 Oct 2009 14:59:00 +0000</pubDate><atom:updated>2009-10-14T14:23:04.565+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Computer Associates multiple products - RCE</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/w7Wazo267cU/computer-associates-multiple-products.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/StSWPLTcUzI/AAAAAAAAAKQ/i4VHfJPvqoQ/s72-c/pwned+by+av.jpg" height="72" width="72" /><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





I released another advisory today, the affected products are from Computer Associates who I'd like to thank for the cooperation...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=w7Wazo267cU:O2NntFIJVZo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=w7Wazo267cU:O2NntFIJVZo:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=w7Wazo267cU:O2NntFIJVZo:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=w7Wazo267cU:O2NntFIJVZo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=w7Wazo267cU:O2NntFIJVZo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=w7Wazo267cU:O2NntFIJVZo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=w7Wazo267cU:O2NntFIJVZo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/w7Wazo267cU" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/10/computer-associates-multiple-products.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-1941041156923876650</guid><pubDate>Sat, 12 Sep 2009 13:38:00 +0000</pubDate><atom:updated>2009-09-12T15:40:26.587+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Rants from Thierry</category><title>Derren Brown guessed the lottery numbers - afterwards</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/P5ZfJlus6aA/derren-brown-guessed-lottery-numbers.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>1</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



Derren Brown, the NLP master and magician &amp;nbsp;"predicted" the Lotterie numbers Live on TV and promised to tell on Friday how he...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=P5ZfJlus6aA:JGizbezrlrE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=P5ZfJlus6aA:JGizbezrlrE:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=P5ZfJlus6aA:JGizbezrlrE:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=P5ZfJlus6aA:JGizbezrlrE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=P5ZfJlus6aA:JGizbezrlrE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=P5ZfJlus6aA:JGizbezrlrE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=P5ZfJlus6aA:JGizbezrlrE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/P5ZfJlus6aA" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/09/derren-brown-guessed-lottery-numbers.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-3271155934380542097</guid><pubDate>Fri, 11 Sep 2009 15:31:00 +0000</pubDate><atom:updated>2009-10-26T17:59:20.732+01:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Rants from Thierry</category><title>You get what you pay for</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/SdJxYBIRzbk/you-get-what-you-pay-for.html</link><author>noreply@blogger.com (Thierry Zoller)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/SqpsH79fbuI/AAAAAAAAAJw/Ia9rkRSv3Hs/s72-c/lanc1.png" height="72" width="72" /><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



On a more non-technical note, I stumbled across this offer from a "renowed luxemburgish recruitment agency." I am not sure what part...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SdJxYBIRzbk:BelmvNfxQ2I:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SdJxYBIRzbk:BelmvNfxQ2I:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SdJxYBIRzbk:BelmvNfxQ2I:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SdJxYBIRzbk:BelmvNfxQ2I:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SdJxYBIRzbk:BelmvNfxQ2I:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=SdJxYBIRzbk:BelmvNfxQ2I:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=SdJxYBIRzbk:BelmvNfxQ2I:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/SdJxYBIRzbk" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/09/you-get-what-you-pay-for.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-6597355145516755319</guid><pubDate>Wed, 02 Sep 2009 11:46:00 +0000</pubDate><atom:updated>2009-09-02T13:48:52.206+02:00</atom:updated><title>IIS 5&amp;6 FTP vulnerability - information and tools (KB975191)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/87uKXJDHJ_A/iis-5-ftp-vulnerability-information-and.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates


I wrote a small summary and facts about the recent IIS5&amp;6 FTP 0day, note that te vulnerable part of the code can be reached without...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=87uKXJDHJ_A:-GalkjpC1go:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=87uKXJDHJ_A:-GalkjpC1go:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=87uKXJDHJ_A:-GalkjpC1go:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=87uKXJDHJ_A:-GalkjpC1go:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=87uKXJDHJ_A:-GalkjpC1go:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=87uKXJDHJ_A:-GalkjpC1go:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=87uKXJDHJ_A:-GalkjpC1go:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/87uKXJDHJ_A" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/09/iis-5-ftp-vulnerability-information-and.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-4893435542854152245</guid><pubDate>Thu, 30 Jul 2009 22:47:00 +0000</pubDate><atom:updated>2009-07-31T00:47:59.882+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Tool</category><title>New advances in Office malware analysis</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/XFW_Wxpv6-E/new-advances-in-office-malware-analysis.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





http://blog.g-sec.lu/2009/07/new-advances-in-officeexcelpowerpoint.html



Dear Anti virus vendors,

Your clients are getting...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=XFW_Wxpv6-E:j7FDdXdppO0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=XFW_Wxpv6-E:j7FDdXdppO0:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=XFW_Wxpv6-E:j7FDdXdppO0:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=XFW_Wxpv6-E:j7FDdXdppO0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=XFW_Wxpv6-E:j7FDdXdppO0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=XFW_Wxpv6-E:j7FDdXdppO0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=XFW_Wxpv6-E:j7FDdXdppO0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/XFW_Wxpv6-E" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/07/new-advances-in-office-malware-analysis.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-425549520738558571</guid><pubDate>Wed, 15 Jul 2009 18:18:00 +0000</pubDate><atom:updated>2009-07-15T20:20:04.919+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Advisory : One bug to rule them all -  Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3....</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/7MPYQ6wv17U/advisory-one-bug-to-rule-them-all.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>1</thr:total><description>Subscribe to the RSS feed in case you are interested in updates [GSEC-TZO-44-2009] One bug to rule them all -  Firefox, IE, Safari,Opera, Chrome,Seamonkey,iPhone,iPod,Wii,PS3....
&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=7MPYQ6wv17U:ZetBXZXBsX4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=7MPYQ6wv17U:ZetBXZXBsX4:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=7MPYQ6wv17U:ZetBXZXBsX4:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=7MPYQ6wv17U:ZetBXZXBsX4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=7MPYQ6wv17U:ZetBXZXBsX4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=7MPYQ6wv17U:ZetBXZXBsX4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=7MPYQ6wv17U:ZetBXZXBsX4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/7MPYQ6wv17U" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/07/advisory-one-bug-to-rule-them-all.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-2537581673785741654</guid><pubDate>Tue, 14 Jul 2009 16:43:00 +0000</pubDate><atom:updated>2009-07-14T19:34:00.556+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">0day</category><title>0pen0wn.c - Shellcode "dissasembled"</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/MgiEReG7100/0pen0wnc-shellcode-dissasembled.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>12</thr:total><description>Subscribe to the RSS feed in case you are interested in updates
Rumor had it that the anti-sec group was using a OpenSSH 0day, str0ke today linked to an URL that supposedly has the exploit code to...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=MgiEReG7100:ijrD1L_TUqw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=MgiEReG7100:ijrD1L_TUqw:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=MgiEReG7100:ijrD1L_TUqw:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=MgiEReG7100:ijrD1L_TUqw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=MgiEReG7100:ijrD1L_TUqw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=MgiEReG7100:ijrD1L_TUqw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=MgiEReG7100:ijrD1L_TUqw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/MgiEReG7100" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/07/0pen0wnc-shellcode-dissasembled.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-976623824217076757</guid><pubDate>Tue, 16 Jun 2009 10:57:00 +0000</pubDate><atom:updated>2009-06-18T15:58:38.511+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Advisories - FPROT,Clamav</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/1BWRovxpda4/advisories-fprot.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates

[TZO-33-2009] FPROT generic bypass (TAR)[TZO-40-2009] Clamav generic bypass (RAR,ZIP,CAB)[TZO-34-2009] FPROT generic bypass...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=1BWRovxpda4:LJUAX_W0xVk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=1BWRovxpda4:LJUAX_W0xVk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=1BWRovxpda4:LJUAX_W0xVk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=1BWRovxpda4:LJUAX_W0xVk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=1BWRovxpda4:LJUAX_W0xVk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=1BWRovxpda4:LJUAX_W0xVk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=1BWRovxpda4:LJUAX_W0xVk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/1BWRovxpda4" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/06/advisories-fprot.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-434933733584643786</guid><pubDate>Tue, 09 Jun 2009 13:03:00 +0000</pubDate><atom:updated>2009-06-18T15:30:05.849+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Advisories:  Apple, F-prot, Norman,Ikarus, Kaspersky</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/B5pG0xn1W5o/advisory-kaspersky.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates
[TZO-30-2009] Kaspersky generic PDF evasion (update: Kaspersky got in touch)
[TZO-31-2009] Ikarus generic evasion...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=B5pG0xn1W5o:Xdy_Jq-amCg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=B5pG0xn1W5o:Xdy_Jq-amCg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=B5pG0xn1W5o:Xdy_Jq-amCg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=B5pG0xn1W5o:Xdy_Jq-amCg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=B5pG0xn1W5o:Xdy_Jq-amCg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=B5pG0xn1W5o:Xdy_Jq-amCg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=B5pG0xn1W5o:Xdy_Jq-amCg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/B5pG0xn1W5o" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/06/advisory-kaspersky.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-8817005177239712549</guid><pubDate>Sun, 31 May 2009 08:45:00 +0000</pubDate><atom:updated>2009-06-14T21:35:10.174+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Correlated list of advisories</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/OqsF-zWDxEU/correlated-list-of-advisories.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates.

I took some time to correlate and collect the attributed VDB IDs to them :

2009
[TZO-01-2009] Multiple Avira Antivir Denial of...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=OqsF-zWDxEU:PH774qPOg2g:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=OqsF-zWDxEU:PH774qPOg2g:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=OqsF-zWDxEU:PH774qPOg2g:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=OqsF-zWDxEU:PH774qPOg2g:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=OqsF-zWDxEU:PH774qPOg2g:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=OqsF-zWDxEU:PH774qPOg2g:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=OqsF-zWDxEU:PH774qPOg2g:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/OqsF-zWDxEU" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/05/correlated-list-of-advisories.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-4826087642817064939</guid><pubDate>Thu, 28 May 2009 00:19:00 +0000</pubDate><atom:updated>2009-05-31T21:26:44.388+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Advisory - Firefox Denial of service (Keygen)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/h8o_ZQJF-WM/advisory-firefox-denial-of-service.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>[TZO 27-2009] Firefox Denial of Service (Keygen)
I have received interesting and mixed feedback from posting the above "bug".
First I'd like to clarify that  a vulnerability is measured by the impact...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=h8o_ZQJF-WM:drTUIDtHSTk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=h8o_ZQJF-WM:drTUIDtHSTk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=h8o_ZQJF-WM:drTUIDtHSTk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=h8o_ZQJF-WM:drTUIDtHSTk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=h8o_ZQJF-WM:drTUIDtHSTk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=h8o_ZQJF-WM:drTUIDtHSTk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=h8o_ZQJF-WM:drTUIDtHSTk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/h8o_ZQJF-WM" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/05/advisory-firefox-denial-of-service.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-7724374954701651534</guid><pubDate>Tue, 26 May 2009 19:02:00 +0000</pubDate><atom:updated>2009-05-26T22:27:17.989+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Rants from Thierry</category><title>About the different risk ratings of Anti-virus bypasses</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/qOYdYs9chcI/about-different-scoresrisk-ratings-of.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>As you may or may not know, I reported quite some Anti-virus bypasses and evasions lately. Most of them have been categorised and rated by vulnerability database maintainers, such as NIST, Secunia,...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qOYdYs9chcI:8YUrUllaz2E:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qOYdYs9chcI:8YUrUllaz2E:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qOYdYs9chcI:8YUrUllaz2E:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qOYdYs9chcI:8YUrUllaz2E:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qOYdYs9chcI:8YUrUllaz2E:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=qOYdYs9chcI:8YUrUllaz2E:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=qOYdYs9chcI:8YUrUllaz2E:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/qOYdYs9chcI" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/05/about-different-scoresrisk-ratings-of.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-101518994561059931</guid><pubDate>Tue, 26 May 2009 11:57:00 +0000</pubDate><atom:updated>2009-05-26T20:42:10.132+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Advisories - Firefox DoS (unclamped loop)</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/KSjAwy1KnhQ/advisories-firefox-dos-unclamped-loop.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>[TZO-26-2009] Firefox DoS (unclamped loop) forced disclosure


&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=KSjAwy1KnhQ:E7oNKbjLHYY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=KSjAwy1KnhQ:E7oNKbjLHYY:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=KSjAwy1KnhQ:E7oNKbjLHYY:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=KSjAwy1KnhQ:E7oNKbjLHYY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=KSjAwy1KnhQ:E7oNKbjLHYY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=KSjAwy1KnhQ:E7oNKbjLHYY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=KSjAwy1KnhQ:E7oNKbjLHYY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/KSjAwy1KnhQ" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/05/advisories-firefox-dos-unclamped-loop.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-2256356275119201697</guid><pubDate>Mon, 25 May 2009 20:00:00 +0000</pubDate><atom:updated>2009-05-25T22:15:51.686+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>IIS 5 / IIS 5.1 / IIS 6 Webdav unicode - the bug that won't die ?</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/gL5GbdxIkE4/iis-6-webdav-unicode-bug-that-wont-die.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>This is just in : As it appears the IIS 5 / IIS 5.1 / IIS 6 Webdav unicode bug also allows to bypass IP/Domain filters if any are in place. Whoops. So in summary :

bypasses...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=gL5GbdxIkE4:Hldj5GRGiNs:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=gL5GbdxIkE4:Hldj5GRGiNs:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=gL5GbdxIkE4:Hldj5GRGiNs:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=gL5GbdxIkE4:Hldj5GRGiNs:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=gL5GbdxIkE4:Hldj5GRGiNs:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=gL5GbdxIkE4:Hldj5GRGiNs:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=gL5GbdxIkE4:Hldj5GRGiNs:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/gL5GbdxIkE4" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/05/iis-6-webdav-unicode-bug-that-wont-die.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-9058372870332518332</guid><pubDate>Sat, 23 May 2009 12:49:00 +0000</pubDate><atom:updated>2009-05-23T15:15:37.551+02:00</atom:updated><title>RSA and DSA - misconceptions and usefull information</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/zPP_J8zmRsc/rsa-and-dsa-misconceptions-and-usefull.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>This post is nothing new, for some it might be. At least I consider it important enough to re-publish this information for those fiddling with RSA / DSA and keys that were used to generate affected...&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=zPP_J8zmRsc:JcxQnszAgLg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=zPP_J8zmRsc:JcxQnszAgLg:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=zPP_J8zmRsc:JcxQnszAgLg:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=zPP_J8zmRsc:JcxQnszAgLg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=zPP_J8zmRsc:JcxQnszAgLg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=zPP_J8zmRsc:JcxQnszAgLg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=zPP_J8zmRsc:JcxQnszAgLg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/zPP_J8zmRsc" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/05/rsa-and-dsa-misconceptions-and-usefull.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-726749716478799759</guid><pubDate>Fri, 22 May 2009 13:36:00 +0000</pubDate><atom:updated>2009-05-23T00:15:03.515+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Advisories : Panda multiple evasions</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/eqeOAB3VoFs/advisories-panda.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>[TZO-24-2009] Panda generic evasion (CAB)[TZO-25-2009] Panda generic evasion (TAR)Why two advisories for one vendor? Read here.&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=eqeOAB3VoFs:a3g_xjYs9ak:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=eqeOAB3VoFs:a3g_xjYs9ak:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=eqeOAB3VoFs:a3g_xjYs9ak:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=eqeOAB3VoFs:a3g_xjYs9ak:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=eqeOAB3VoFs:a3g_xjYs9ak:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=eqeOAB3VoFs:a3g_xjYs9ak:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=eqeOAB3VoFs:a3g_xjYs9ak:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/eqeOAB3VoFs" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/05/advisories-panda.html</feedburner:origLink></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-3832621951001364942.post-6919933443917090537</guid><pubDate>Mon, 18 May 2009 15:12:00 +0000</pubDate><atom:updated>2009-05-18T17:59:31.439+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Advisory</category><title>Advisories - Avira, Bitdefender generic PDF evasion</title><link>http://feedproxy.google.com/~r/ThierryZoller/~3/3SWBeCL4VEA/advisories-avira-bitdefender-pdf.html</link><author>noreply@blogger.com (Thierry Zoller)</author><thr:total>0</thr:total><description>New advisories :
[TZO-22-2009] Avira Antivir generic evasion (PDF)
[TZO-23-2009] Bitdefender generic evasion (PDF)
FYI: Similar PDF evasions have been discovered in the wild by Didier Stevens&lt;br/&gt;
&lt;br/&gt;
Security news : http://blog.zoller.lu&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=3SWBeCL4VEA:5N69QUDx2rk:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=3SWBeCL4VEA:5N69QUDx2rk:gIN9vFwOqvQ"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=3SWBeCL4VEA:5N69QUDx2rk:gIN9vFwOqvQ" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=3SWBeCL4VEA:5N69QUDx2rk:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=3SWBeCL4VEA:5N69QUDx2rk:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/ThierryZoller?a=3SWBeCL4VEA:5N69QUDx2rk:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/ThierryZoller?i=3SWBeCL4VEA:5N69QUDx2rk:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/ThierryZoller/~4/3SWBeCL4VEA" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.zoller.lu/2009/05/advisories-avira-bitdefender-pdf.html</feedburner:origLink></item></channel></rss>
