<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/rss2full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><rss xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" version="2.0"><channel><title>G-SEC - Blog</title><link>http://blog.g-sec.lu/</link><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/g-sec" /><description>Where facts are few, experts are many.</description><language>en</language><managingEditor>noreply@blogger.com (Thierry Zoller)</managingEditor><lastBuildDate>Mon, 14 May 2012 12:06:45 PDT</lastBuildDate><generator>Blogger</generator><atom:id xmlns:atom="http://www.w3.org/2005/Atom">tag:blogger.com,1999:blog-6875971858454394582</atom:id><openSearch:totalResults xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">11</openSearch:totalResults><openSearch:startIndex xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">1</openSearch:startIndex><openSearch:itemsPerPage xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/">25</openSearch:itemsPerPage><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/rss+xml" href="http://feeds.feedburner.com/g-sec" /><feedburner:info uri="g-sec" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><geo:lat>6.13700</geo:lat><geo:long>50.01630</geo:long><feedburner:emailServiceId>g-sec</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><item><title>An Overview of the BEAST - TLS, CBC, countermeasures (Update 3)</title><link>http://feedproxy.google.com/~r/g-sec/~3/PW-2pW1YT5c/overview-of-beast-tls-cbc.html</link><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Mon, 26 Sep 2011 07:38:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-4280732858005542004</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-09-28T22:02:26.728+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/-DKzv733c-xU/ToCBwDmahUI/AAAAAAAAAQA/hzyW_XDU97E/s72-c/aaaaa2.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><description>Lots of good information floating on the internet on the Proof of Concept (dubbed 'BEAST) against TLS 1.0 by Juliano Rizzo and Thai Duong at the Ekoparty. This Post summaries the credible information...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/PW-2pW1YT5c" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2011/09/overview-of-beast-tls-cbc.html</feedburner:origLink></item><item><title>SSL/TLS Hardening and compatibility report 2011 (updated)</title><link>http://feedproxy.google.com/~r/g-sec/~3/FAWE9TrPSDQ/ssltls-hardening-and-compatibility.html</link><category>Whitepaper</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Tue, 20 Sep 2011 08:05:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-2208169947965430364</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2011-09-25T17:34:59.659+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/-Uv67DaU1a-c/Tn9J-LWFTKI/AAAAAAAAAPs/RJNgdyrUxXA/s72-c/aaaaa2.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





My professional and private commitments made it difficult to maintain a healthly blogging style, I am trying to get back to some...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/FAWE9TrPSDQ" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2011/09/ssltls-hardening-and-compatibility.html</feedburner:origLink></item><item><title>New Paper: SSL/TLS Hardening and Compatibility report 2010</title><link>http://feedproxy.google.com/~r/g-sec/~3/mv6kq6twUto/new-paper-ssltls-hardening-and.html</link><category>Whitepaper</category><category>Tool</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Thu, 18 Feb 2010 06:20:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-5090618459139771638</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2010-02-18T15:42:48.021+01:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



At last. What started as an "I need an overview of best practise in SSL/TLS configuration" type of idea, ended in a 3 month code,...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/mv6kq6twUto" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2010/02/new-paper-ssltls-hardening-and.html</feedburner:origLink></item><item><title>Harden SSL/TLS  - Tool release</title><link>http://feedproxy.google.com/~r/g-sec/~3/M0JI92J1uII/harden-ssltls-tool-release.html</link><category>Tool</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Tue, 16 Feb 2010 09:43:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-8110470940060474819</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2010-02-16T18:43:46.261+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_LApW097P-0I/S3rZNB1xHnI/AAAAAAAAALw/APsPIsGd0J0/s72-c/ssl_harden_f.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates

&amp;nbsp;“Harden SSL/TLS” allows hardening the SSL/TLS  settings of  Windows 2000,2003,2008,2008R2, XP,Vista,7. It allows locally and  ...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/M0JI92J1uII" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2010/02/harden-ssltls-tool-release.html</feedburner:origLink></item><item><title>SSL/TLS Audit (alpha) - Tool Release</title><link>http://feedproxy.google.com/~r/g-sec/~3/3iHDD71fFz8/ssltls-audit-alpha-tool-release.html</link><category>Tool</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Wed, 10 Feb 2010 07:33:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-8931305765972206288</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2010-02-10T16:55:30.228+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/S3LRqNGwiuI/AAAAAAAAAK8/zr1cNq5xCIc/s72-c/ssl_scanner.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><description>Subscribe to the RSS feed in case you are interested in updates
Developed as part of G-SEC's investigation into the "Secure SSL/TLS configuration Report 2010" (to be published) we developed this...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/3iHDD71fFz8" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2010/02/ssltls-audit-alpha-tool-release.html</feedburner:origLink></item><item><title>TLS / SSLv3 renegotiation vulnerability explained (Update #2)(</title><link>http://feedproxy.google.com/~r/g-sec/~3/D-aNw5V_CEU/tls-sslv3-renegotiation-vulnerability.html</link><category>Whitepaper</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Fri, 13 Nov 2009 03:52:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-1196369082456336674</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2009-12-09T21:26:59.721+01:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates



This paper explains the vulnerability for a broader audience and summarizes the information that is currently available. The...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/D-aNw5V_CEU" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2009/11/tls-sslv3-renegotiation-vulnerability.html</feedburner:origLink></item><item><title>SSLv3 / TLS Man in the Middle vulnerability - update #9</title><link>http://feedproxy.google.com/~r/g-sec/~3/giGZdVxgU0I/sslv3-tls-man-in-middle-vulnerability.html</link><category>Zero Day</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Thu, 05 Nov 2009 04:00:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-4823321018305808908</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2009-12-09T21:22:06.087+01:00</atom:updated><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">1</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





Updated 17:50 GMT+1 / 05.2009 - added Mitigation / Impact&amp;nbsp;
Updated 16:40 GMT+1 / 06.2009 - added IETF draft&amp;nbsp;
Updated...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/giGZdVxgU0I" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2009/11/sslv3-tls-man-in-middle-vulnerability.html</feedburner:origLink></item><item><title>Solving the HACK.LU 2009 reversing challenge like it's 1998</title><link>http://feedproxy.google.com/~r/g-sec/~3/-KZAcI1F6So/solving-hacklu-2009-reversing-challenge.html</link><category>Hack.lu</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Mon, 02 Nov 2009 12:15:00 PST</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-7392523790534714028</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2009-11-12T22:28:31.164+01:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://2.bp.blogspot.com/_LApW097P-0I/Su8piY-_slI/AAAAAAAAAKY/585WUKSj73Q/s72-c/crackme.exe.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">4</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





Here is quick overview of one possible way to solve the Hack.lu 2009 crackme&amp;nbsp; (reversing challenge) with the classical JZ/JNZ...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/-KZAcI1F6So" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2009/11/solving-hacklu-2009-reversing-challenge.html</feedburner:origLink></item><item><title>Advisory : Computer Associates multiple products - arbritary remote code execution</title><link>http://feedproxy.google.com/~r/g-sec/~3/_HQFDxCtM8E/computer-associates-multiple-products.html</link><category>Advisory</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Tue, 13 Oct 2009 07:46:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-3797049063907374708</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2009-10-15T18:34:59.989+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://3.bp.blogspot.com/_LApW097P-0I/StSQ03nZhBI/AAAAAAAAAKI/QQjmQ0uoxRQ/s72-c/pwned+by+av.jpg" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates





G-SEC released an advisory today that affects various Computer Associates products. The most interesting part is the multitude of...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/_HQFDxCtM8E" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2009/10/computer-associates-multiple-products.html</feedburner:origLink></item><item><title>IIS 5 &amp; IIS 6 &amp; IIS7 FTP vulnerability - information and tools (updated)</title><link>http://feedproxy.google.com/~r/g-sec/~3/mGYhT9R-yts/iis-5-iis-6-ftp-vulnerability.html</link><category>Zero Day</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Tue, 01 Sep 2009 05:06:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-2667318485100048149</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2009-09-07T15:20:50.531+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://1.bp.blogspot.com/_LApW097P-0I/Sp0Wjus3yhI/AAAAAAAAAJo/IQlx-TAPxks/s72-c/ftpWrite.gif" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><description>Subscribe to our RSS feed for regular updates

Renowed security researcher "Kingcope" published a recent zero day vulnerability (i.e no patch and unkown at the time of publication)  affecting...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/mGYhT9R-yts" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2009/09/iis-5-iis-6-ftp-vulnerability.html</feedburner:origLink></item><item><title>New advances in Office/Excel/Powerpoint Malware detection and analysis</title><link>http://feedproxy.google.com/~r/g-sec/~3/IXm98JqMdGs/new-advances-in-officeexcelpowerpoint.html</link><category>Tool</category><author>noreply@blogger.com (Thierry Zoller)</author><pubDate>Thu, 30 Jul 2009 15:20:00 PDT</pubDate><guid isPermaLink="false">tag:blogger.com,1999:blog-6875971858454394582.post-1901884639979337979</guid><atom:updated xmlns:atom="http://www.w3.org/2005/Atom">2009-08-01T03:38:43.992+02:00</atom:updated><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="http://4.bp.blogspot.com/_LApW097P-0I/SnH6NB4AjWI/AAAAAAAAAJQ/i2gc8ZeTNpo/s72-c/offviz.png" height="72" width="72" /><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><description>Subscribe to the RSS feed in case you are interested in updates

As you may or may not know there is massive client-side exploitation movement going on since last year (there has been before but on a...&lt;br/&gt;
&lt;br/&gt;
[[ This is a content summary only. Visit our blog for more ]]&lt;img src="http://feeds.feedburner.com/~r/g-sec/~4/IXm98JqMdGs" height="1" width="1"/&gt;</description><feedburner:origLink>http://blog.g-sec.lu/2009/07/new-advances-in-officeexcelpowerpoint.html</feedburner:origLink></item></channel></rss>

