<?xml version="1.0"?><!-- RSS generated by Radio UserLand v8.0.8 on Mon, 03 Mar 2003 19:43:50 GMT --><rss version="2.0">	<channel>		<title>Marc Barrot: security</title>		<link>http://radio.weblogs.com/0104487/categories/security/</link>		<description>SITE SECURITY ISSUES</description>		<copyright>Copyright 2003 Marc Barrot</copyright>		<lastBuildDate>Mon, 03 Mar 2003 19:43:50 GMT</lastBuildDate>		<docs>http://backend.userland.com/rss</docs>		<generator>Radio UserLand v8.0.8</generator>		<managingEditor>mbarrot@dig.fr</managingEditor>		<webMaster>mbarrot@dig.fr</webMaster>		<category domain="http://www.weblogs.com/rssUpdates/changes.xml">rssUpdates</category> 		<skipHours>			<hour>2</hour>			<hour>3</hour>			<hour>0</hour>			<hour>5</hour>			<hour>6</hour>			<hour>4</hour>			<hour>1</hour>			<hour>7</hour>			</skipHours>		<cloud domain="radio.xmlstoragesystem.com" port="80" path="/RPC2" registerProcedure="xmlStorageSystem.rssPleaseNotify" protocol="xml-rpc"/>		<ttl>60</ttl>		<item>			<title>Sendmail Security Alert</title>			<link>http://radio.weblogs.com/0104487/categories/security/2003/03/03.html#a558</link>			<description>Received another security notice from RedHat this afternoon:&lt;blockquote&gt;During a code audit of Sendmail by ISS, a critical vulnerability was uncovered that affects unpatched versions of Sendmail prior to version8.12.8.  A remote attacker can send a carefully crafted email messagewhich, when processed by sendmail, causes arbitrary code to beexecuted as root.&lt;/blockquote&gt;&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2003/03/03.html#a558&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2003/03/03.html#a558</guid>			<pubDate>Mon, 03 Mar 2003 18:13:00 GMT</pubDate>			</item>		<item>			<title>Vulnerability In Redhat&apos;s glibc</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/10/04.html#a412</link>			<description>From the latest &lt;a href=&quot;https://rhn.redhat.com/network/errata/errata_details.pxt?eid=1218&quot;&gt;RHN alert&lt;/a&gt;: ... A read buffer overflow vulnerability exists in the glibc resolver code in versions of glibc up to and including 2.2.5.  The vulnerability is triggered by DNS packets larger than 1024 bytes and can cause applications to crash.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/10/04.html#a412&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/10/04.html#a412</guid>			<pubDate>Fri, 04 Oct 2002 17:38:04 GMT</pubDate>			</item>		<item>			<title>Securing Linux: Why It&apos;s Worthwhile and Achievable</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/10/04.html#a410</link>			<description>&lt;a href=&quot;http://www.oreillynet.com/pub/a/onlamp/2002/10/03/securinglinux.html&quot;&gt;Michael Bauer&lt;/a&gt;, author of &lt;i&gt;Building Secure Servers with Linux&lt;/i&gt;, explains some of the reasons why it&apos;s both possible and worthwhile to secure Linux for use as an Internet server platform. [an &lt;a href=&quot;http://www.oreillynet.com/&quot;&gt;O&apos;Reilly Network Article&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/10/04.html#a410</guid>			<pubDate>Fri, 04 Oct 2002 16:17:22 GMT</pubDate>			<source url="http://www.oreillynet.com/cs/xml/query/q/295?x-ver=1.0">O&apos;Reilly Network Articles</source>			</item>		<item>			<title>A Visit To Amanda</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/09/25.html#a369</link>			<description>&lt;a href=&quot;http://www.oreillynet.com/pub/a/network/2002/09/24/essentialsysadmin.html&quot;&gt;&amp;AElig;leen Frisch&lt;/a&gt;: Top Five Open Source Packages for System Administrators - Number 5 [in &lt;a href=&quot;http://www.oreillynet.com/pub/a/network/newsletters/20020924.html&quot;&gt;O&apos;Reilly Network&apos;s Newsletter&lt;/a&gt;].</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/09/25.html#a369</guid>			<pubDate>Wed, 25 Sep 2002 19:35:24 GMT</pubDate>			</item>		<item>			<title>Site Logging And Monitoring</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/09/06.html#a295</link>			<description>Thanks to &lt;a href=&quot;http://weblog.infoworld.com/udell/2002/09/06.html#a401&quot;&gt;Jon Udell&lt;/a&gt; for reminding me what &quot;slam&quot; stands for :-)&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/09/06.html#a295&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/09/06.html#a295</guid>			<pubDate>Fri, 06 Sep 2002 17:22:34 GMT</pubDate>			</item>		<item>			<link>http://radio.weblogs.com/0104487/categories/security/2002/08/03.html#a271</link>			<description>&lt;a href=&quot;http://www.whiterabbits.com/MacNetJournal/2002/08/02.html#a1880&quot;&gt;Apple releases Security Update 2002-08-02&lt;/a&gt;.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/08/03.html#a271&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/08/03.html#a271</guid>			<pubDate>Sat, 03 Aug 2002 16:04:54 GMT</pubDate>			<source url="http://www.whiterabbits.com/MacNetJournal/rss.xml">Mac Net Journal</source>			</item>		<item>			<title>Apache mod_ssl and openSSH Update For MacOS X</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/06/28.html#a203</link>			<description>I&apos;ve just installed the Security Update, July 2002 edition on my MacOS X machines after reading this&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/06/28.html#a203&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/06/28.html#a203</guid>			<pubDate>Sat, 29 Jun 2002 04:29:45 GMT</pubDate>			<source url="http://www.whiterabbits.com/MacNetJournal/rss.xml">Mac Net Journal</source>			</item>		<item>			<title>So Long, And Thanks For All The Passwords</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/06/13.html#a182</link>			<description>This catchy phrase is printed on the cool openBSD t-shirt I got at the expo.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/06/13.html#a182&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/06/13.html#a182</guid>			<pubDate>Fri, 14 Jun 2002 04:02:38 GMT</pubDate>			</item>		<item>			<title>Honeypots and Honeynets</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/06/13.html#a181</link>			<description>[img] in &lt;a href=&quot;http://www.usenix.org/events/usenix02/tutorials/tutwed.html#w3&quot;&gt;Yesterday&apos;s tutorial&lt;/a&gt;, Marcus Ranum presented the latest data on the cracker population, as gathered by the &lt;a href=&quot;http://project.honeynet.org/&quot;&gt;honeynet group&lt;/a&gt;, and, while talking way too fast for a presentation, made a good case for honeypots as tools for intrusion detection.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/06/13.html#a181&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/06/13.html#a181</guid>			<pubDate>Thu, 13 Jun 2002 22:47:11 GMT</pubDate>			</item>		<item>			<title>Mail Sending Mistakes</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/06/13.html#a180</link>			<description>A follow up on David Blank-Edelman &lt;a href=&quot;http://radio.weblogs.com/0104487/2002/06/11.html#a176&quot;&gt;Perl for System Administration&lt;/a&gt; tutorial on Tuesday.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/06/13.html#a180&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/06/13.html#a180</guid>			<pubDate>Thu, 13 Jun 2002 22:14:43 GMT</pubDate>			</item>		<item>			<title>Monitoring Security</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/06/11.html#a174</link>			<description>Here our some ground rules when using SNMP and client server tools to monitor systems and network devices&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/06/11.html#a174&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/06/11.html#a174</guid>			<pubDate>Tue, 11 Jun 2002 16:02:38 GMT</pubDate>			</item>		<item>			<title>Host Resources MIB</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/06/10.html#a168</link>			<description>&lt;a href=&quot;http://www.snmp.com/IETF-RFC-MIRROR/rfc1514.txt&quot;&gt;RFC 1514&lt;/a&gt; defines a Management Information Base for host systems.</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/06/10.html#a168</guid>			<pubDate>Mon, 10 Jun 2002 16:26:22 GMT</pubDate>			</item>		<item>			<title>Live From Usenix Tutorial Sessions</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/06/10.html#a167</link>			<description>The wireless connection just came up in our meeting room. I&apos;m currently attending John Sellens&apos; &lt;a href=&quot;http://www.usenix.org/events/usenix02/tutorials/tutmon.html#m4&quot;&gt;System  And Network Monitoring&lt;/a&gt; tutorial&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/06/10.html#a167&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/06/10.html#a167</guid>			<pubDate>Mon, 10 Jun 2002 18:56:09 GMT</pubDate>			</item>		<item>			<title>PHP Security Revisited</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/18.html#a102</link>			<description>Catching up on Martin Heller&apos;s &lt;a href=&quot;http://www.byte.com/documents/s=7042/byt1017074924088/0325_heller.html&quot;&gt;PHP Revisited&lt;/a&gt; column on Byte.com, I&apos;ve just realised I am responsible for a site with public Internet exposure and PHP 4.1.1 for Windows&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/18.html#a102&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/18.html#a102</guid>			<pubDate>Thu, 18 Apr 2002 15:14:10 GMT</pubDate>			</item>		<item>			<title>Office X Combined Updater 10.0.3</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/17.html#a100</link>			<description>Today is update day on &quot;slam&quot;.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/17.html#a100&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/17.html#a100</guid>			<pubDate>Wed, 17 Apr 2002 23:31:56 GMT</pubDate>			</item>		<item>			<title>MacOS X 10.1.4 Upgrade</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/17.html#a99</link>			<description>Apple does slightly better than Microsoft in their system update description:&lt;blockquote&gt;Security Update:-- BSD-based TCP/IP connections now check and block broadcast or multicast IP destination addresses.&lt;/blockquote&gt;Among other things, version 10.1&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/17.html#a99&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/17.html#a99</guid>			<pubDate>Wed, 17 Apr 2002 23:08:29 GMT</pubDate>			</item>		<item>			<title>Internet Explorer 5.1.4 Update</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/17.html#a98</link>			<description>Microsoft really needs to work on their update descriptions, especially when security issues are involved.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/17.html#a98&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/17.html#a98</guid>			<pubDate>Wed, 17 Apr 2002 23:01:29 GMT</pubDate>			</item>		<item>			<title>SOAP::Lite Updated</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/16.html#a94</link>			<description>Good news while checking my email this morning, Paul Kulchenko &apos;s notice that a new 0.55 version of &lt;a href=&quot;http://soaplite.com/&quot;&gt;SOAP::Lite&lt;/a&gt; is available for download, both in &lt;a href=&quot;http://soaplite.com/download/SOAP-Lite-latest.tar.gz&quot;&gt;Unix&lt;/a&gt;&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/16.html#a94&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/16.html#a94</guid>			<pubDate>Tue, 16 Apr 2002 13:52:18 GMT</pubDate>			</item>		<item>			<title>Securing SOAP::Lite - Addendum</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/11.html#a84</link>			<description>In my far from expert opinion, securing the open() call in HTTP::Daemon::ClientConn::sendfile would make for a more secure SOAP::Lite module.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/11.html#a84&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/11.html#a84</guid>			<pubDate>Thu, 11 Apr 2002 20:35:07 GMT</pubDate>			</item>		<item>			<title>SOAP::Lite::Paul_Strikes_Back()</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/10.html#a81</link>			<description>&lt;a href=&quot;http://scriptingnews.userland.com/backissues/2002/04/10#l44ae805e6a476d195830f9f8eb3a02ab&quot;&gt;Dave&lt;/a&gt; directed my attention to Paul Kulchenko&apos;s answer to the full package name traversal &lt;a href=&quot;http://www.phrack.com/show.php?p=58&amp;amp;a=9&quot;&gt;explo&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/10.html#a81&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/10.html#a81</guid>			<pubDate>Thu, 11 Apr 2002 01:09:51 GMT</pubDate>			</item>		<item>			<title>SOAP::Lite Exploit - continued</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/10.html#a80</link>			<description>&lt;a href=&quot;http://radio.weblogs.com/0100887/2002/04/09.html#a184&quot;&gt;[img] &lt;/a&gt;I took time this afternoon to read the SOAP::Lite exploit &amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/10.html#a80&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/10.html#a80</guid>			<pubDate>Wed, 10 Apr 2002 22:36:05 GMT</pubDate>			</item>		<item>			<title>SOAP::Lite Vulnerability Issue</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/09.html#a76</link>			<description>I don&apos;t have time to check this exploit, but if the issue described below is verified, Perl web services are in a world of hurt :&lt;blockquote&gt;IlyaM writes &quot;About four months ago there was Phrack article named RPC without borders which describes quite &amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/09.html#a76&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/09.html#a76</guid>			<pubDate>Tue, 09 Apr 2002 18:00:50 GMT</pubDate>			</item>		<item>			<title>MacOS X security update includes openSSH 3.1</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/04/05.html#a69</link>			<description>&lt;blockquote&gt;&lt;a href=&quot;http://www.macnn.com/news.php?id=13512&quot;&gt;Apple Security Update released for Mac OS X&lt;/a&gt;.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/04/05.html#a69&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/04/05.html#a69</guid>			<pubDate>Fri, 05 Apr 2002 14:35:15 GMT</pubDate>			<source url="http://www.whiterabbits.com/MacNetJournal/rss.xml">Mac Net Journal</source>			</item>		<item>			<title>Aqua interface to syslog.conf</title>			<link>http://radio.weblogs.com/0104487/categories/security/2002/03/13.html#a33</link>			<description>&lt;blockquote&gt;&lt;a href=&quot;http://www.trafalgargroup.net/sysloggenx/sysloggenx.sit&quot;&gt;Syslog Gen X 1.0&lt;/a&gt;.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/03/13.html#a33&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/03/13.html#a33</guid>			<pubDate>Wed, 13 Mar 2002 11:39:01 GMT</pubDate>			<source url="http://radio.weblogs.com/0102230/staplerFeeds/VersionTracker.xml">Version Tracker</source>			</item>		<item>			<title>Race condition in GNU FileUtils</title>			<link>http://www.net-security.org/text/bugs/1015937490,2085,.shtml</link>			<description>&lt;blockquote&gt;Race condition in various utilities from fileutils GNU package may cause root user to delete the whole filesystem.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/03/12.html#a27&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/03/12.html#a27</guid>			<pubDate>Tue, 12 Mar 2002 18:04:30 GMT</pubDate>			</item>		<item>			<title>Updated RedHat 7.2 rpms</title>			<link></link>			<description>A number of important updates to RedHat Linux 7.2 were released between last Friday and today:binutils  vs.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/03/11.html#a25&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/03/11.html#a25</guid>			<pubDate>Tue, 12 Mar 2002 00:25:06 GMT</pubDate>			</item>		<item>			<link>http://radio.weblogs.com/0104487/categories/security/2002/03/08.html#a14</link>			<description>&lt;b&gt;OpenSSH Alert !&lt;/b&gt;&lt;blockquote&gt;&lt;a href=&quot;http://www.linuxsecurity.com/articles/cryptography_article-4565.html&quot;&gt;LinuxSecurity&lt;/a&gt;: &quot;A bug exists in the channel code of OpenSSH versions 2.0 - 3.0.2 Users with an existing user account can abuse this bu&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/03/08.html#a14&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/03/08.html#a14</guid>			<pubDate>Fri, 08 Mar 2002 15:06:49 GMT</pubDate>			</item>		<item>			<link>http://radio.weblogs.com/0104487/categories/security/2002/03/07.html#a10</link>			<description>&lt;b&gt;Network sniffers are always bad news&lt;/b&gt;&lt;blockquote&gt;&lt;a href=&quot;http://www.linuxjournal.com/article.php?sid=5869&quot;&gt;SwitchSniff&lt;/a&gt;.&amp;nbsp;[&lt;a href=&quot;http://radio.weblogs.com/0104487/2002/03/07.html#a10&quot; target=&quot;_blank&quot;&gt;read more&lt;/a&gt;]</description>			<guid>http://radio.weblogs.com/0104487/categories/security/2002/03/07.html#a10</guid>			<pubDate>Thu, 07 Mar 2002 21:05:11 GMT</pubDate>			<source url="http://www.linuxjournal.com/news.rss">Linux Journal</source>			</item>		</channel>	</rss>