<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss'><id>tag:blogger.com,1999:blog-23998881</id><updated>2009-09-08T09:18:53.209+02:00</updated><title type='text'>siculezza</title><subtitle type='html'></subtitle><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/default.asp'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default?start-index=26&amp;max-results=25'/><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://www.siculezza.it/blog/atom.xml'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>40</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-23998881.post-1563041279212043651</id><published>2009-09-08T09:17:00.000+02:00</published><updated>2009-09-08T09:18:53.220+02:00</updated><title type='text'>Microsoft Security Developer Starter Kit</title><content type='html'>The &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=0fcba3c7-bc30-47b0-a2f8-2e702720998a&amp;amp;displaylang=en"&gt;Microsoft SDL - Developer Starter Kit&lt;/a&gt; provides a compliation of baseline developer security training materials on the following core Microsoft Security Development Lifecycle (SDL) topics: &lt;div&gt;a) secure design principles; &lt;/div&gt;&lt;div&gt;b) secure implementation principles; &lt;/div&gt;&lt;div&gt;c) secure verification principles; &lt;/div&gt;&lt;div&gt;d) SQL injection; &lt;/div&gt;&lt;div&gt;e) cross-site scripting; &lt;/div&gt;&lt;div&gt;f) code analysis; &lt;/div&gt;&lt;div&gt;g)banned application programming interfaces (APIs); &lt;/div&gt;&lt;div&gt;h) buffer overflows; &lt;/div&gt;&lt;div&gt;i) source code annotation language; &lt;/div&gt;&lt;div&gt;j) security code review; &lt;/div&gt;&lt;div&gt;k) compiler defenses; &lt;/div&gt;&lt;div&gt;l) fuzz testing; &lt;/div&gt;&lt;div&gt;m) Microsoft SDL threat modeling principles; and &lt;/div&gt;&lt;div&gt;n) the Microsoft SDL threat modeling tool. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Each set of guidance contains Microsoft Office PowerPoint slides, speaker notes, train-the-trainer audio files, and sample comprehension questions. All materials have limited formatting so that you can leverage the content to achieve broader, enhanced adoption of Microsoft SDL principles in your development organization.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-1563041279212043651?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/1563041279212043651'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/1563041279212043651'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2009/09/microsoft-security-developer-starter.asp' title='Microsoft Security Developer Starter Kit'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-2176979459038329242</id><published>2008-08-19T15:50:00.002+02:00</published><updated>2009-04-16T22:41:14.694+02:00</updated><title type='text'>Developer Highway Code (free ebook)</title><content type='html'>To build software that meets your security objectives, you must integrate security activities into your software development lifecycle. &lt;a href="http://msdn.microsoft.com/en-gb/security/aa473878.aspx"&gt;This handbook&lt;/a&gt; captures and summarises the key security engineering activities that should be an integral part of your software development processes.&lt;br /&gt;These security engineering activities have been developed by Microsoft &lt;em&gt;patterns &amp;amp; practices&lt;/em&gt; to build on, refine and extend core lifecycle activities with a set of security-specific activities. These include identifying security objectives, applying design guidelines for security, threat modelling, security architecture and design reviews, security code reviews and security deployment reviews.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-2176979459038329242?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2176979459038329242'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2176979459038329242'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2008/08/developer-highway-code-free-ebook.asp' title='Developer Highway Code (free ebook)'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-2263809702750484026</id><published>2008-07-19T02:40:00.001+02:00</published><updated>2008-07-19T02:40:42.980+02:00</updated><title type='text'>How Cybercriminals Steal Money</title><content type='html'>&lt;object width="425" height="344"&gt;&lt;param name="movie" value="http://www.youtube.com/v/jC6Q1uCnbMo&amp;hl=en"&gt;&lt;/param&gt;&lt;param name="wmode" value="transparent"&gt;&lt;/param&gt;&lt;embed src="http://www.youtube.com/v/jC6Q1uCnbMo&amp;hl=en" type="application/x-shockwave-flash" wmode="transparent" width="425" height="344"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-2263809702750484026?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2263809702750484026'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2263809702750484026'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2008/07/how-cybercriminals-steal-money.asp' title='How Cybercriminals Steal Money'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-2247474744451440077</id><published>2008-07-02T21:44:00.003+02:00</published><updated>2008-07-02T21:49:18.589+02:00</updated><title type='text'>ratproxy</title><content type='html'>&lt;a href="http://code.google.com/p/ratproxy/"&gt;Ratproxy&lt;/a&gt; is a semi-automated, largely passive web application security audit tool, optimized for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-initiated traffic in complex web 2.0 environments.&lt;br /&gt;Detects and prioritizes broad classes of security problems, such as dynamic cross-site trust model considerations, script inclusion issues, content serving problems, insufficient XSRF and XSS defenses, and much more.&lt;br /&gt;Ratproxy is currently believed to support Linux, FreeBSD, MacOS X, and Windows (Cygwin) environments.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-2247474744451440077?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2247474744451440077'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2247474744451440077'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2008/07/ratproxy.asp' title='ratproxy'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-6192300477792356936</id><published>2008-06-09T20:10:00.001+02:00</published><updated>2008-06-09T20:12:28.054+02:00</updated><title type='text'>Microsoft Security Compliance Management toolkit</title><content type='html'>&lt;p&gt;In today’s IT environment, the ability to comply with regulations and industry standards, such as the Sarbanes Oxley Act, is a source of deep concern for many organizations. In addition, organizations need to manage risks resulting from emerging threats and changing conditions within their IT infrastructures. As a result, organizations need sound methods that they can count on to understand the state of the security settings in their IT infrastructures, assess the compliance of a security baseline, and demonstrate that compliance requirements have been met.&lt;/p&gt; &lt;p&gt;To help organizations address these challenges, Microsoft has created the &lt;a href="http://technet.microsoft.com/en-us/library/cc677002.aspx"&gt;Security Compliance Management toolkit&lt;/a&gt;. The toolkit provides best practices from Microsoft about how to plan, deploy, and monitor a security baseline. In addition, the toolkit provides remediation recommendations to address security baseline issues. The toolkit also offers a proven method that your organization can use to effectively monitor the compliance state of recommended security baselines for Windows Vista®, Windows® XP Service Pack 2 (SP2), and Windows Server® 2003 SP2.&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-6192300477792356936?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/6192300477792356936'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/6192300477792356936'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2008/06/microsoft-security-compliance.asp' title='Microsoft Security Compliance Management toolkit'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-6783816677761095531</id><published>2008-04-23T15:32:00.001+02:00</published><updated>2008-04-23T15:32:02.418+02:00</updated><title type='text'>Microsoft Security Intelligence Report</title><content type='html'>&lt;div xmlns='http://www.w3.org/1999/xhtml'&gt;Questa edizione del &lt;a href='http://www.microsoft.com/downloads/details.aspx?displaylang=it&amp;amp;FamilyID=bcc879db-9fe6-4331-b231-e274ea8fc804'&gt;Microsoft Security Intelligence Report&lt;/a&gt; è focalizzata sui risultati ottenuti nella seconda metà del 2007 (da luglio a dicembre) e si fonda sui dati pubblicati nelle precedenti versioni del report. Utilizzando i dati derivati da oltre 450 milioni di utenti Windows e alcuni dei servizi online più attivi della rete, il report fornisce una prospettiva approfondita sulle tendenze nel campo delle vulnerabilità del software e nel panorama del software dannoso e indesiderato, oltre che un aggiornamento sulle tendenze degli exploit che sfruttano le vulnerabilità del software. L’ambito di questa quarta edizione del report è cresciuto per includere un focus sulla privacy e le segnalazioni di violazioni della protezione, e una panoramica sul lavoro di Microsoft in collaborazione con le forze dell’ordine in ogni parte del mondo, a supporto della lotta contro i criminali della rete.&lt;br/&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-6783816677761095531?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/6783816677761095531'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/6783816677761095531'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2008/04/microsoft-security-intelligence-report.asp' title='Microsoft Security Intelligence Report'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-8119210232274392707</id><published>2008-02-19T10:55:00.000+01:00</published><updated>2008-02-19T10:57:02.944+01:00</updated><title type='text'>Microsoft Security Assessment Tool 3.5</title><content type='html'>Il &lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyId=6D79DF9C-C6D1-4E8F-8000-0BE72B430212&amp;displaylang=it"&gt;Microsoft Security Assessment Tool 3.5&lt;/a&gt; è la versione aggiornata dell’originale Microsoft Security Risk Self-Assessment Tool (MSRSAT), rilasciato nel 2004, e del Microsoft Security Assessment Tool 2.0 rilasciato nel 2006. Le minacce alla sicurezza dei sistemi hanno subito una forte evoluzione da allora. Per questo, la versione attuale include nuove domande e risposte per offrire agli utilizzatori di MSAT uno strumento completo che favorisca la comprensione del panorama di riferimento delle minacce alla sicurezza cui l’organizzazione è esposta.&lt;br /&gt;&lt;br /&gt;Il tool adotta un approccio olistico che permette di valutare il livello di sicurezza dell’organizzazione esaminandola dal punto di vista delle persone, dei processi e delle tecnologie. I risultati vengono poi confrontati con delle guide di riferimento e con suggerimenti per la mitigazione del rischio fornendo anche collegamenti e informazioni ad approfondimenti per singolo settore di industria.&lt;br /&gt;Queste risorse possono essere di aiuto nell’identificare strumenti e metodi specifici che possano cambiare l’approccio alla sicurezza dell’ambiente IT.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-8119210232274392707?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/8119210232274392707'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/8119210232274392707'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2008/02/microsoft-security-assessment-tool-35.asp' title='Microsoft Security Assessment Tool 3.5'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-7509275671550453422</id><published>2008-02-12T00:09:00.000+01:00</published><updated>2008-02-12T00:22:10.515+01:00</updated><title type='text'>All Your iFrame Are Point to Us</title><content type='html'>&lt;div style="margin: 12px 0px; font-family: arial; color: #333333; background: #ffffff; border: solid 4px #e5e5e5; width: 100%; clear: left;"&gt;&lt;div class="CM_CTB_Content_Wrap" style="margin: 0px; padding: 0px;background-color: #ffffff;"&gt;&lt;div style="border-bottom: solid 1px #dcdcdc; white-space: nowrap; margin-bottom: 8px; background-color: #eeeeee ;background-image: url(http://clipmarks.com/images/source-bg.gif); background-repeat: repeat-x; height: 24px; line-height: 24px; vertical-align: middle; padding-bottom: 4px; color: #666666; font-size: 10px;" &gt;&lt;a href="http://clipmarks.com/clip-to-blog/" title="clipmarks' clip-to-blog"&gt;&lt;img src="http://content.clipmarks.com/blog_embed/275dc5fd-4ea2-4334-bc32-3b48214fdfcb/53AD66A6-819E-45A9-A782-0F1E64E784E9/" alt="" width="19" height="19" border="0" style="vertical-align: middle; margin: 0px 4px; display: inline; border: none; float:none;" /&gt;&lt;/a&gt;clipped from &lt;a title="http://googleonlinesecurity.blogspot.com/2008/02/all-your-iframe-are-point-to-us.html" href="http://googleonlinesecurity.blogspot.com/2008/02/all-your-iframe-are-point-to-us.html" style="font-size: 11px;"&gt;googleonlinesecurity.blogspot.com&lt;/a&gt;&lt;/div&gt;&lt;blockquote style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;" cite="http://googleonlinesecurity.blogspot.com/2008/02/all-your-iframe-are-point-to-us.html"&gt;&lt;DIV&gt;It has been over a year and a half since we started to identify web pages that infect vulnerable hosts via &lt;I&gt;drive-by downloads&lt;/I&gt;, i.e. web pages that attempt to exploit their visitors by installing and running malware automatically.  During that time we have investigated billions of URLs and found more than three million unique URLs on over 180,000 web sites automatically installing malware.  During the course of our research, we have investigated not only the prevalence of drive-by downloads but also how users are being exposed to malware and how it is being distributed.   Our research paper is currently under peer review, but we are making a &lt;A href="http://research.google.com/archive/provos-2008a.pdf"&gt;technical report [PDF]&lt;/A&gt; available now.  Although our technical report contains a lot more detail, we present some high-level findings here:&lt;/DIV&gt;&lt;/blockquote&gt;&lt;div style="height: 2px; font-size: 2px; background: #dcdcdc; border-bottom: solid 1px #f5f5f5; margin: 2px 4px;"&gt;&lt;/div&gt;&lt;blockquote style="text-align: left; padding: 0px 8px; margin: 4px 0px 8px 0px; background: transparent; border: none;" cite="http://googleonlinesecurity.blogspot.com/2008/02/all-your-iframe-are-point-to-us.html"&gt;&lt;div align="center"&gt;&lt;img src="http://content7.clipmarks.com/blog_cache/googleonlinesecurity.blogspot.com/img/A7A8595D-BF2B-45FF-9907-AFD7DB1493ED" alt="" /&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div style="margin: 0px 6px 6px 4px;"&gt;&lt;table style="font-size: 11px;border-spacing: 0px;padding: 0px;" cellpadding="0" cellspacing="0" width="100%"&gt;&lt;tr&gt;&lt;td style="background:transparent;border-width:0px;padding:0px;"&gt;&amp;nbsp;&lt;/td&gt;&lt;td align="right" style="background:transparent;border-width:0px;padding:0px;width:107px" width="107"&gt;&lt;a href="http://clipmarks.com/share/53AD66A6-819E-45A9-A782-0F1E64E784E9/blog/" title="blog or email this clip"&gt;&lt;img src="http://content8.clipmarks.com/images/c2b-foot.png" border="0" alt="blog it" width="107" height="17" style="border-width:0px;padding:0px;margin:0px;" /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-7509275671550453422?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7509275671550453422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7509275671550453422'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2008/02/all-your-iframe-are-point-to-us.asp' title='All Your iFrame Are Point to Us'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-8136555692640646533</id><published>2008-01-04T19:20:00.000+01:00</published><updated>2008-01-04T19:22:19.275+01:00</updated><title type='text'>Firewall?</title><content type='html'>&lt;img src="http://www.siculezza.it/blog/uploaded_images/kurios119-797215.jpg" alt="" border="0" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-8136555692640646533?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/8136555692640646533'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/8136555692640646533'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2008/01/firewall.asp' title='Firewall?'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-7472298571236235883</id><published>2007-10-24T16:43:00.000+02:00</published><updated>2007-10-24T16:45:19.371+02:00</updated><title type='text'>XSSDetect Public Beta now Available</title><content type='html'>&lt;a href="http://www.microsoft.com/downloads/details.aspx?FamilyID=19a9e348-bdb9-45b3-a1b7-44ccdcb7cfbe&amp;amp;displaylang=en"&gt;XSSDetect&lt;/a&gt; runs as a Visual Studio plug-in and can detect potential XSS issues in managed code.&lt;br /&gt;&lt;span&gt;XSSDetect is a static code analysis tool that helps identify Cross-Site Scripting security flaws found within Web applications. It is able to scan compiled managed assemblies (C#, Visual Basic .NET, J#) and analyze dataflow paths from sources of user-controlled input to vulnerable outputs. It also detects whether proper encoding or filtering has been applied to the data and will ignore such "sanitized" paths.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-7472298571236235883?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7472298571236235883'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7472298571236235883'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/10/xssdetect-public-beta-now-available.asp' title='XSSDetect Public Beta now Available'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-7513579265566926933</id><published>2007-10-18T22:41:00.000+02:00</published><updated>2007-10-18T22:43:13.713+02:00</updated><title type='text'>Guida ai rischi connessi alle violazioni del copyright</title><content type='html'>La Federazione contro la Pirateria Musicale (FPM) ha annunciato oggi  l'invio ai responsabili delle strutture informatiche delle università italiane ed altre istituzioni accademiche collegate, di &lt;a href="http://www.fpm-antipiracy.it/dettaglio_documento.asp?id=876&amp;idtipo_documento=3"&gt;una guida informativa&lt;/a&gt; realizzata per evidenziare i possibili rischi che i sistemi informativi accademici possono incorrere con l'utilizzo di applicazioni o siti di web potenzialmente pericolosi da parte di studenti, dipendenti o utilizzatori estemporanei delle tecnologie rese disponibili all'interno degli atenei. Ad esempio, tramite l’accesso a reti p2p, si possono esporre le reti informatiche ad infezioni da parte di virus, spyware, malware e soprattutto  si possono violare dati riservati e materiale protetto da copyright.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-7513579265566926933?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7513579265566926933'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7513579265566926933'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/10/guida-ai-rischi-connessi-alle.asp' title='Guida ai rischi connessi alle violazioni del copyright'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-7418525628231642721</id><published>2007-10-06T13:55:00.000+02:00</published><updated>2007-10-06T14:01:39.551+02:00</updated><title type='text'>hakin9: Metasploit 3.0 Autopwn</title><content type='html'>&lt;a href="http://hakin9.org/it/haking/issues/10_2007.html"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://www.siculezza.it/blog/uploaded_images/3858930394700c288a7eca-749019.jpg" alt="" border="0" /&gt;&lt;/a&gt;Il nostro Daniele Costa ha realizzato un nuovo articolo per la rivista &lt;a href="http://hakin9.org/it/haking/issues/10_2007.html"&gt;hakin9&lt;/a&gt;, questo mese potete trovare "Metasploit 3.0 Autopwn"; tema di questo articolo è una dettagliata analisi del framework Metasploit, una piattaforma di sviluppo, completamente gratuita, per la creazione di tool dedicati al mondo della security ed in particolare alla creazione ed esecuzione di exploit.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-7418525628231642721?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7418525628231642721'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7418525628231642721'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/10/hakin9-metasploit-30-autopwn.asp' title='hakin9: Metasploit 3.0 Autopwn'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-4568261768240218350</id><published>2007-08-28T18:12:00.000+02:00</published><updated>2007-08-28T18:17:44.875+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='virus'/><title type='text'>infected or not?</title><content type='html'>&lt;a href="http://www.infectedornot.com/italy/"&gt;Un semplice controllo via browser&lt;/a&gt; (realizzato da Panda), permette di sapere velocemente se il nostro PC è stato infettato dai più diffusi malware.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-4568261768240218350?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/4568261768240218350'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/4568261768240218350'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/08/infected-or-not.asp' title='infected or not?'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-1185161133183296023</id><published>2007-08-11T19:44:00.001+02:00</published><updated>2007-08-11T19:58:54.055+02:00</updated><title type='text'>Vulnerabilità XSS in Blogger</title><content type='html'>Durante alcuni esperimenti condotti negli ultimi giorni ho scoperto che la piattaforma  Blogger soffre di una vulnerabilità XSS.&lt;br /&gt;&lt;br /&gt;In pratica chiunque abbia la possibilità di postare su un blog tramite l'interfaccia di Blogger può iniettare codice javascript come ad esempio il semplice :&lt;br /&gt;&lt;br /&gt;[script]alert(document.cookie)[/script] (sostituite le '[' con '&lt;;')   Ho notato in particolare che se il blog è ospitato su blogspot.com il codice viene eseguito ma i cookie non vengono mostrati...mentre se si inietta il codice su un blog ospitato all'interno di un sito web come, per esempio, quello di Siculezza.it i cookie vengono visualizzati correttamente...probabilmente ciò dipende da una diversa configurazione del web server.  Per una POC della vulnerabilità visitate questo sito:   &lt;a href="http://pocasiculezza.blogspot.com/"&gt;http://pocasiculezza.blogspot.com&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Oppure guardate attentatmente il prossimo paragrafo&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;script src="http://ha.ckers.org/xss.js"&gt;&lt;/script&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-1185161133183296023?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/1185161133183296023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/1185161133183296023'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/08/vulnerabilit-xss-in-blogger.asp' title='Vulnerabilità XSS in Blogger'/><author><name>Daniele Costa</name><uri>http://www.blogger.com/profile/01844194383683646109</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='12083513272950381194'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-2136343737761647233</id><published>2007-08-10T10:20:00.000+02:00</published><updated>2007-08-10T10:21:24.367+02:00</updated><title type='text'>Anche Banco di Sicilia entra nel phishing nazionale</title><content type='html'>Si arricchisce di un nuovo l’ ormai corposa lista degli obiettivi del phishing nazionale, grazie ad un e-mail rilevata quest’oggi ai danni dell’istituto di credito  Banco di Sicilia. Nonostante la novità i phisher hanno voluto utilizzare come messaggio di posta elettrica la medesima comunicazione già impiegata per CartaSi, Maestro e successivamente anche per Banca Intesa e Banca di Roma.&lt;br /&gt;La comparsa quest’oggi come obiettivo di Banco di Sicilia e nella giornata di ieri del gruppo bancario Banco Popolare rappresenta una pericola tendenza dei phisher i quali a quanto pare non si limitano come in passato a concentrare la loro azione verso determinati istituti di credito, ma cercano nuovi obiettivi, i quali potrebbero rivelarsi particolarmente fruttuosi, dato che le nuove potenziali vittime potrebbero essere impreparate o totalmente ignare al pericolo phishing.&lt;br /&gt;&lt;br /&gt;Fonte: &lt;a href="http://www.anti-phishing.it/news/articoli/news.09082007.php"&gt;anti-phishing.it&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-2136343737761647233?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2136343737761647233'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2136343737761647233'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/08/anche-banco-di-sicilia-entra-nel.asp' title='Anche Banco di Sicilia entra nel phishing nazionale'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-8570067591105969806</id><published>2007-07-16T00:51:00.000+02:00</published><updated>2007-07-16T00:54:27.830+02:00</updated><title type='text'>26 ARRESTS IN ITALY FOR ASSOCIATION TO COMMIT OFFENCES OF PHISHING</title><content type='html'>The Provincial Command of the Military Financial Police (Guardia di Finanza) of Milan executed 26 Arrests Warrants for the people belonging to two criminal associations. These two criminal associations were connected through and made up of Italian and Foreign citizens, who were responsible of a series of deceptions of hundreds of users taking advantage of Home Banking Services, through techniques better known as phishing.&lt;br /&gt;The operation, called “PHISH &amp; CHIP“, allowed the Judicial Authorities to identify 18 Italian citizens and 8 foreign citizens from Eastern Europe, regularly living in our Country, who took advantage of the Home Banking Services’ personal access codes of the clients of “Poste Italiane” (holders of on-line bank accounts or PostePay Cards). The access codes were illegally wormed out through the answers given to the e-mails apparently sent by their Credit Institutions.&lt;br /&gt;(Fonte: &lt;a href="http://www.castlecops.com/article-6810-nested-0-0.html"&gt;CastleCops&lt;/a&gt;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-8570067591105969806?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/8570067591105969806'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/8570067591105969806'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/07/26-arrests-in-italy-for-association-to.asp' title='26 ARRESTS IN ITALY FOR ASSOCIATION TO COMMIT OFFENCES OF PHISHING'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-7412742064679136047</id><published>2007-05-28T22:03:00.000+02:00</published><updated>2007-05-28T22:09:56.549+02:00</updated><title type='text'>Libro: Computer Forensics</title><content type='html'>&lt;a href="http://www.apogeonline.com/libri/88-503-2593-2/scheda"&gt;Computer Forensics&lt;/a&gt;: scritto a quattro mani da &lt;a href="http://forensicsbypila.blogspot.com/"&gt;Andrea Ghirardini&lt;/a&gt; (esperto di indagini forensi nel "mondo elettronico") e da Gabriele Faggioli (legale specializzato negli aspetti giuridici degli illeciti digitali), questo libro descrive l’applicazione di un metodo investigativo scientifico al mondo digitale per ricavare elementi, informazioni, prove da portare in sede processuale.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-7412742064679136047?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7412742064679136047'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7412742064679136047'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/05/libro-computer-forensics.asp' title='Libro: Computer Forensics'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-7189977756719605176</id><published>2007-05-23T22:56:00.000+02:00</published><updated>2007-05-23T22:57:07.415+02:00</updated><title type='text'>hakin9: Web Penetration Test</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://www.iteam5.net/blog/uploaded_images/8246330704654020710d31-752632.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://www.iteam5.net/blog/uploaded_images/8246330704654020710d31-752624.jpg" alt="" border="0" /&gt;&lt;/a&gt;Il nostro Daniele Costa guadagna la copertina e lo spazio dedicato al primo e più importante articolo sulla rivista &lt;a href="http://hakin9.org/it/haking/issues/5_2007.html"&gt;hakin9&lt;/a&gt; di questo mese.&lt;br /&gt;L'articolo di 8 pagine, dal titolo "&lt;span style="font-style: italic;"&gt;Web Penetration Test - Guida allo sfruttamento di un remote code exploit&lt;/span&gt;", tratta uno dei maggiori pericoli per i server presenti in rete, lo sfruttamento improprio di vulnerabilità legate alle applicazioni web basate su tecnologie di scripting come il PHP, il PERL oppure ancora l'ASP.&lt;br /&gt;&lt;br /&gt;Complimenti!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-7189977756719605176?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7189977756719605176'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7189977756719605176'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/05/hakin9-web-penetration-test.asp' title='hakin9: Web Penetration Test'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-2468899236524311096</id><published>2007-05-23T22:43:00.000+02:00</published><updated>2007-05-23T22:46:19.915+02:00</updated><title type='text'>Google Online Security Blog</title><content type='html'>Anche Google si dota di un blog sulla sicurezza informatica; il &lt;a href="http://googleonlinesecurity.blogspot.com/"&gt;Google Online Security Blog&lt;/a&gt; inizia con un post dal titolo "Introducing Google's online security efforts" a cura di Panayiotis Mavrommatis e Niels Provos dell'Anti-Malware Team.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-2468899236524311096?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2468899236524311096'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/2468899236524311096'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/05/google-online-security-blog.asp' title='Google Online Security Blog'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-551269233635955288</id><published>2007-05-21T22:36:00.000+02:00</published><updated>2007-05-21T22:37:56.513+02:00</updated><title type='text'>Libro: Cross Site Scripting Attacks</title><content type='html'>&lt;span class="Catalog_Desc"&gt;&lt;a href="http://www.syngress.com/catalog/?pid=4360"&gt; Cross Site Scripting Attacks&lt;/a&gt; starts by defining the terms and laying out the ground work. It assumes that the reader is familiar with basic web programming (HTML) and JavaScript. First it discusses the concepts, methodology, and technology that makes XSS a valid concern. It then moves into the various types of XSS attacks, how they are implemented, used, and abused. After XSS is thoroughly explored, the next part provides examples of XSS malware and demonstrates real cases where XSS is a dangerous risk that exposes internet users to remote access, sensitive data theft, and monetary losses. Finally, the book closes by examining the ways developers can avoid XSS vulnerabilities in their web applications, and how users can avoid becoming a victim. The audience is web developers, security practitioners, and managers.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-551269233635955288?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/551269233635955288'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/551269233635955288'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/05/libro-cross-site-scripting-attacks.asp' title='Libro: Cross Site Scripting Attacks'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-7930237771408940041</id><published>2007-05-14T00:28:00.000+02:00</published><updated>2007-05-14T00:31:24.571+02:00</updated><title type='text'>The Ghost in the Browser: Analysis of Web-based Malware</title><content type='html'>From &lt;a href="HotBots%20%2707"&gt;HotBots '07&lt;/a&gt;, First Workshop on Hot Topics in Understanding Botnets:&lt;br /&gt;&lt;a href="http://www.usenix.org/events/hotbots07/tech/full_papers/provos/provos.pdf"&gt;The Ghost in the Browser: Analysis of Web-based Malware&lt;/a&gt;&lt;br /&gt;Niels Provos, Dean McNamee, Panayiotis Mavrommatis, Ke Wang, and Nagendra Modadugu&lt;br /&gt;Google, Inc.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-7930237771408940041?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7930237771408940041'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/7930237771408940041'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/05/ghost-in-browser-analysis-of-web-based.asp' title='The Ghost in the Browser: Analysis of Web-based Malware'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-3818731831740896604</id><published>2007-05-09T11:03:00.000+02:00</published><updated>2007-05-09T11:06:12.423+02:00</updated><title type='text'>Network Monitor 3.1 Beta Has Released</title><content type='html'>The NM3.1 Beta is available on &lt;a href="http://connect.Microsoft.com"&gt;http://connect.Microsoft.com&lt;/a&gt; and simmering with new features for you to test. What's New in Network Monitor 3.1:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Wireless (802.11) capturing and monitor mode on Vista - With supported hardware, (Native WIFI), you can now trace wireless management packets. You can scan all channels or a subset of the ones your wireless NIC supports. You can also focus in on one specific channel.&lt;/li&gt;&lt;li&gt;RAS tracing support on Vista - Now you can trace your RAS connections so you can see the traffic inside your VPN tunnel. Previously this was only available with XP.&lt;/li&gt;&lt;li&gt;Right click add to filter - Now there's an easier way to discover how to create filters. Right click in the frame details data element or a column field in the frame summary and select add to filter.&lt;/li&gt;&lt;li&gt;Microsoft Update enabled - Now you will be prompted when new updates exist. NM3.1 will occasionally check for a new version and notify you when one is available.&lt;/li&gt;&lt;li&gt;New public parsers - These include ip1394, ipcp, ipv6cp, madcap, pppoE, soap, ssdp, winsrpl, as well as improvements in the previously shipped parsers.&lt;/li&gt;&lt;li&gt;...&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-3818731831740896604?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/3818731831740896604'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/3818731831740896604'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/05/network-monitor-31-beta-has-released.asp' title='Network Monitor 3.1 Beta Has Released'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-4919744466418179803</id><published>2007-05-05T19:23:00.000+02:00</published><updated>2007-05-05T19:29:05.968+02:00</updated><title type='text'>virus dal dischetto alla penna USB</title><content type='html'>Il primo computer virus che ho visto (ed eliminato..) è stato &lt;a href="http://www.research.ibm.com/antivirus/SciPapers/Chess/PCCOMVIR/note204.html#Header_8"&gt;Stoned&lt;/a&gt; nel 1989; si diffondeva attraverso il boot sector dei floppy disk (allora da 5 pollici ed un quarto!), se ti beccavi il virus appariva la frase "your PC is now stoned" ed il computer si bloccava...&lt;br /&gt;Adesso Sophos ci avverte dei rischi connessi ad una nuova famiglia di worm che si diffonde &lt;a href="http://www.sophos.com/pressoffice/news/articles/2007/05/usbstick.html"&gt;attraverso le memory stick USB&lt;/a&gt;... uno schema di spreading che si ripete...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-4919744466418179803?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/4919744466418179803'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/4919744466418179803'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/05/virus-dal-dischetto-alla-penna-usb.asp' title='virus dal dischetto alla penna USB'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-8811565468114157319</id><published>2007-04-15T16:20:00.000+02:00</published><updated>2007-05-08T16:22:14.842+02:00</updated><title type='text'>Security link di aprile</title><content type='html'>&lt;ul&gt;&lt;li&gt;&lt;h4 class="desc"&gt;&lt;a href="http://firegpg.tuxfamily.org/index.php?page=home" rel="nofollow"&gt;FireGPG - use GPG easily in Firefox !&lt;/a&gt;&lt;/h4&gt;&lt;/li&gt;&lt;li&gt;&lt;h4 class="desc"&gt;&lt;a href="http://stopbadware.org/" rel="nofollow"&gt;StopBadware.org&lt;/a&gt;&lt;/h4&gt;&lt;/li&gt;&lt;li&gt;&lt;h4 class="desc"&gt;&lt;a href="http://blogs.zdnet.com/storage/?p=129" rel="nofollow"&gt;» How to REALLY erase a hard drive | Storage Bits | ZDNet.com&lt;/a&gt;&lt;/h4&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-8811565468114157319?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/8811565468114157319'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/8811565468114157319'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/04/security-link-di-aprile.asp' title='Security link di aprile'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry><entry><id>tag:blogger.com,1999:blog-23998881.post-6119259368787499962</id><published>2007-03-26T22:10:00.000+02:00</published><updated>2007-03-29T13:48:21.137+02:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='libri'/><title type='text'>Libro: Sicurezza informatica - di Salvatore Aranzulla</title><content type='html'>&lt;a href="http://www.fag.it/scheda.aspx?ID=21685"&gt;&lt;img src="http://www.siculezza.it/blog/uploaded_images/mylibropiccolo-743794.jpg" alt="" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/23998881-6119259368787499962?l=www.siculezza.it%2Fblog%2Fdefault.asp'/&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/6119259368787499962'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/23998881/posts/default/6119259368787499962'/><link rel='alternate' type='text/html' href='http://www.siculezza.it/blog/2007/03/libro-sicurezza-informatica-di.asp' title='Libro: Sicurezza informatica - di Salvatore Aranzulla'/><author><name>Francesco Passantino</name><uri>http://www.blogger.com/profile/01059427494664972545</uri><email>noreply@blogger.com</email><gd:extendedProperty xmlns:gd='http://schemas.google.com/g/2005' name='OpenSocialUserId' value='03119937490217887264'/></author></entry></feed>