<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.9.1" -->
<rss version="0.92">
<channel>
	<title>Accuvant Insight</title>
	<link>http://insight.accuvant.com</link>
	<description>Security Strategy Expertly Executed</description>
	<lastBuildDate>Mon, 08 Mar 2010 22:04:50 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Recent Encryption Research Demystified</title>
		<description><![CDATA[Last week, NetworkWorld published an article  under the headline “RSA 1024-bit private key encryption cracked.”  RSA encryption was one of the first widely-used asymmetric key algorithms, meaning it used two keys, one public and one private.  A message encrypted with the public key couldn’t be decrypted without the private key, the idea being that your [...]]]></description>
		<link>http://insight.accuvant.com/encryption/recent-encryption-research-demystified/</link>
			</item>
	<item>
		<title>Patch Production &amp; Responsible Disclosure – Follow On to WSJ Post</title>
		<description><![CDATA[A recent article published on the Wall Street Journal online declares a “Broad New Hacking Attack” involving the ‘new’ malware threat, Zeus or zbot.  This threat is far from new, however, neither the malware nor the phenomenon.  In April of 2008, RSA issued an advisory about the threat.  It is simply another dashboard exploiting a [...]]]></description>
		<link>http://insight.accuvant.com/vuln/patch-production-responsible-disclosure-%e2%80%93-follow-on-to-wsj-post/</link>
			</item>
	<item>
		<title>Mitigate Risk, Prevent Attacks &#8211; Response to WSJ Article from 2/18</title>
		<description><![CDATA[Yesterday, the Wall Street Journal published an article by Siobhan Gorman about hackers in Europe and China who successfully broke into computers at 2,500 companies and agencies over the last 18 months. The hackers used various techniques to infiltrate the corporate networks, including malware, phishing, email attachments, false virus patches and botnets.
A client of ours [...]]]></description>
		<link>http://insight.accuvant.com/strategy/131/</link>
			</item>
	<item>
		<title>Simplifying Hacks with the Oracle Data Pump Package</title>
		<description><![CDATA[The latest Oracle vulnerability announcement at the Black Hat DC 2010 conference by security researcher, David Litchfield of NGS Software, could possibly prove troublesome for Oracle 11g users.
The potential impact of this set of vulnerabilities could be devastating to an enterprise that has sensitive data contained in databases, and allows low level privileged users access [...]]]></description>
		<link>http://insight.accuvant.com/database/hacks-oracle-data-pump/</link>
			</item>
	<item>
		<title>Testing Web App CAPTCHA controls</title>
		<description><![CDATA[CAPTCHA (&#8220;Completely Automated Public Turing test to tell Computers and Humans Apart&#8221;) is a type of challenge-response test used by many web applications to ensure that the response is not generated by a computer. CAPTCHA implementations are often vulnerable to various kinds of attacks even if the generated CAPTCHA is unbreakable.
I&#8217;ve had a few questions [...]]]></description>
		<link>http://insight.accuvant.com/appsec/testing-web-app-captcha-controls/</link>
			</item>
	<item>
		<title>Accuvant Launches Accuvant Labs at BlackHat USA Conference</title>
		<description><![CDATA[Today, during the 2009 BlackHat conference in Las Vegas, Accuvant officially announced the addition of a research and development division to its security assessment practice, which is now called Accuvant Labs. This is significant for several reasons. First, security research experts Alex Wheeler and Ryan Smith, who most recently were recently credited with discovering Microsoft’s [...]]]></description>
		<link>http://insight.accuvant.com/news/accuvant-launches-accuvant-labs-at-blackhat-usa-conference/</link>
			</item>
	<item>
		<title>Creating a Solid Security Program</title>
		<description><![CDATA[A successful security program is not run like a dictatorship but rather like a partnership, one of the team, all fighting for a common cause. In order to have a successful security program within an organization everyone has to be involved and support it.]]></description>
		<link>http://insight.accuvant.com/strategy/creating-a-solid-security-program/</link>
			</item>
	<item>
		<title>Most Common Internal Vulnerabilities Found</title>
		<description><![CDATA[You can patch OSes all you want and scan your network with just about any general vulnerability scanner but you've left out one very important step - password policy enforcement beyond just domain accounts.]]></description>
		<link>http://insight.accuvant.com/vuln/most-common-internal-vulnerabilities-found/</link>
			</item>
	<item>
		<title>SCTP Linux Kernel Vulnerability Assessment and Reproduction</title>
		<description><![CDATA[Overview:
The blog post here makes statements about a vulnerability in the Linux kernel handling of SCTP data. The primary point of the post is to show how a vulnerability that was once thought to be of a relative low risk was incorrectly assessed and it can provide a 3rd party remote access to a server [...]]]></description>
		<link>http://insight.accuvant.com/appsec/sctp-linux-kernel-vulnerability-assessment-and-reproduction/</link>
			</item>
	<item>
		<title>Accuvant speaks at Blackhat Europe</title>
		<description><![CDATA[So the week before last Neel Mehta of Google, Alex Wheeler of TippingPoint, Dave Bonvillain of Accuvant, and myself made our way to Amsterdam to speak at Blackhat Europe. The topic of our talk was &#8216;Cutting thru the Hype: An Analysis of Application Security Testing Methodologies&#8217; (Dave&#8217;s name)&#8230; we were going to speak about all [...]]]></description>
		<link>http://insight.accuvant.com/con/accuvant-speaks-at-blackhat-europe/</link>
			</item>
</channel>
</rss>
