<?xml version="1.0" encoding="UTF-8"?> <rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" ><channel><title>Enterprise Security Update &#187; Web Vulnerability</title> <atom:link href="http://www.lexansystems.com/blog/category/web-vulnerability/feed/" rel="self" type="application/rss+xml" /><link>http://www.lexansystems.com/blog</link> <description>Bulletproof your network!</description> <lastBuildDate>Thu, 03 Mar 2011 07:47:23 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.2</generator> <atom:link rel='hub' href='http://www.lexansystems.com/blog/?pushpress=hub'/> <item><title>Twitter still vulnerable to cross site scripting attacks</title><link>http://www.lexansystems.com/blog/web-vulnerability/twitter-still-vulnerable-to-cross-site-scripting-attacks/</link> <comments>http://www.lexansystems.com/blog/web-vulnerability/twitter-still-vulnerable-to-cross-site-scripting-attacks/#comments</comments> <pubDate>Fri, 28 Aug 2009 02:55:17 +0000</pubDate> <dc:creator>Christopher</dc:creator> <category><![CDATA[Web Vulnerability]]></category><guid isPermaLink="false">http://www.lexansystems.com/blog/?p=201</guid> <description><![CDATA[James Slater found a cross-site-scripting vulnerability on Twitter.com which Twitter claims is now fixed.  According to James, it is not fixed.  The vulnerability allows malicious JavaScript to be embedded with user tweets.   This can result in user accounts being compromised and the owner can loose control of their account. The vulnerability comes down to Twitter&#8217;s [...]]]></description> <wfw:commentRss>http://www.lexansystems.com/blog/web-vulnerability/twitter-still-vulnerable-to-cross-site-scripting-attacks/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>IIS vulnerability spreads like a forest fire</title><link>http://www.lexansystems.com/blog/malware/iis-vulnerability-spreads-like-a-forest-fire/</link> <comments>http://www.lexansystems.com/blog/malware/iis-vulnerability-spreads-like-a-forest-fire/#comments</comments> <pubDate>Thu, 24 Apr 2008 19:45:03 +0000</pubDate> <dc:creator>Christopher</dc:creator> <category><![CDATA[CyberCrime]]></category> <category><![CDATA[Emerging Threats]]></category> <category><![CDATA[Information Security]]></category> <category><![CDATA[Malware]]></category> <category><![CDATA[Security Breach]]></category> <category><![CDATA[Web Defacement]]></category> <category><![CDATA[Web Vulnerability]]></category> <category><![CDATA[hack]]></category> <category><![CDATA[hackers]]></category> <category><![CDATA[IIS]]></category> <category><![CDATA[Vulnerability]]></category> <category><![CDATA[website defacement]]></category><guid isPermaLink="false">http://www.lexansystems.com/blog/?p=50</guid> <description><![CDATA[Almost 300,000 web sites hosted with Internet Information Services are infected with a new malicious malware according to PandaLabs. By injecting SQL code in all pages hosted on the same IIS server, this vulnerability allows hackers to inject SQL code and redirect the visitor to a malicious site. The malicious page scans the visitors machine [...]]]></description> <wfw:commentRss>http://www.lexansystems.com/blog/malware/iis-vulnerability-spreads-like-a-forest-fire/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>Alexa Top 100 Domains compromised</title><link>http://www.lexansystems.com/blog/malware/alexa-top-100-domains-compromised/</link> <comments>http://www.lexansystems.com/blog/malware/alexa-top-100-domains-compromised/#comments</comments> <pubDate>Thu, 28 Feb 2008 19:11:47 +0000</pubDate> <dc:creator>Christopher</dc:creator> <category><![CDATA[CyberCrime]]></category> <category><![CDATA[Information Security]]></category> <category><![CDATA[Malware]]></category> <category><![CDATA[Web Defacement]]></category> <category><![CDATA[Web Vulnerability]]></category><guid isPermaLink="false">http://www.lexansystems.com/blog/2008/02/28/alexa-top-100-domains-compromised/</guid> <description><![CDATA[While Finjan was researching a server hosting a new version of NeoSploit crimeware toolkit, a database of over 8,000 ftp accounts was uncovered. 10% of Alexa&#8217;s top 100 domains login username &#38; password are in the database. A majority of the accounts originate in the United States. Also uncovered was a trading application that rates [...]]]></description> <wfw:commentRss>http://www.lexansystems.com/blog/malware/alexa-top-100-domains-compromised/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>95% of Information Security breaches are from known vulnerabilities and misconfigurations</title><link>http://www.lexansystems.com/blog/web-vulnerability/95-of-information-security-breaches-are-from-known-vulnerabilities-and-misconfigurations/</link> <comments>http://www.lexansystems.com/blog/web-vulnerability/95-of-information-security-breaches-are-from-known-vulnerabilities-and-misconfigurations/#comments</comments> <pubDate>Sun, 28 Oct 2007 16:00:45 +0000</pubDate> <dc:creator>Christopher</dc:creator> <category><![CDATA[Information Security]]></category> <category><![CDATA[Security Breach]]></category> <category><![CDATA[Web Vulnerability]]></category><guid isPermaLink="false">http://www.lexansystems.com/blog/2007/10/28/95-of-information-security-breaches-are-from-known-vulnerabilities-and-misconfigurations/</guid> <description><![CDATA[It’s a shocking but true statement. But then if the vulnerabilities and misconfigurations are known, why are steps not taken to correct them? Well, the answer lies in the question itself. The vulnerabilities are known but which ones exist in your system&#8217;s network need to be identified.  The first step towards protection against security breaches [...]]]></description> <wfw:commentRss>http://www.lexansystems.com/blog/web-vulnerability/95-of-information-security-breaches-are-from-known-vulnerabilities-and-misconfigurations/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> <item><title>United Nations website hacked</title><link>http://www.lexansystems.com/blog/web-defacement/united-nations-website-hacked/</link> <comments>http://www.lexansystems.com/blog/web-defacement/united-nations-website-hacked/#comments</comments> <pubDate>Tue, 14 Aug 2007 02:57:08 +0000</pubDate> <dc:creator>Christopher</dc:creator> <category><![CDATA[PCI Compliance]]></category> <category><![CDATA[Web Defacement]]></category> <category><![CDATA[Web Vulnerability]]></category><guid isPermaLink="false">http://www.lexansystems.com/blog/2007/08/13/united-nations-website-hacked/</guid> <description><![CDATA[August 12th, 2007 the United Nations website (www.un.org) was defaced in an attempt to CyberProtest &#8220;Ysrail&#8221; and &#8220;USA&#8221; citing &#8220;peace for ever&#8221;. This message appeared on pages generally reserved for quotes and speeches from the secretary general Ban Ki-moon as well as on other well know websites. The hackers website states the CyberProtect&#8217;s objective, &#8220;that [...]]]></description> <wfw:commentRss>http://www.lexansystems.com/blog/web-defacement/united-nations-website-hacked/feed/</wfw:commentRss> <slash:comments>0</slash:comments> </item> </channel> </rss>
<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Minified using disk: basic
Page Caching using disk: enhanced (User agent is rejected)

Served from: www.lexansystems.com @ 2012-05-18 11:26:42 -->
