<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
>

<channel>
	<title>SecuraBit &#187; vmware</title>
	<atom:link href="http://www.securabit.com/tag/vmware/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securabit.com</link>
	<description>SecuraBit Before It Bytes!</description>
	<lastBuildDate>Mon, 26 Jul 2010 04:33:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
<!-- podcast_generator="Blubrry PowerPress/1.0.9" mode="advanced" entry="normal" -->
	<itunes:summary>This is a Computer Security podcast brought to you by the guys at SecuraBit.com.  Please visit our web site at http://www.securabit.com or send questions/comments to feedback@securabit.com

Thanks for listening!</itunes:summary>
	<itunes:author>SecuraBit</itunes:author>
	<itunes:explicit>no</itunes:explicit>
	<itunes:image href="http://staging.securabit.com/itunessecurabit.jpg" />
	<itunes:owner>
		<itunes:name>SecuraBit</itunes:name>
		<itunes:email>feedback@securabit.com</itunes:email>
	</itunes:owner>
	<managingEditor>feedback@securabit.com (SecuraBit)</managingEditor>
	<copyright>SecuraBit LLC</copyright>
	<itunes:subtitle>SecuraBit Before It Bytes!</itunes:subtitle>
	<itunes:keywords>security, forensics, hacking, infosec, securabit, podcast, sans, drinking, beer</itunes:keywords>
	<image>
		<title>SecuraBit &#187; vmware</title>
		<url>http://securabit.com/securabitrsssmall.jpg</url>
		<link>http://www.securabit.com</link>
	</image>
	<itunes:category text="Technology">
		<itunes:category text="Tech News" />
		<itunes:category text="Software How-To" />
	</itunes:category>
		<item>
		<title>Vulnerability Roundup</title>
		<link>http://www.securabit.com/2010/03/15/vulnerability-roundup-8/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=vulnerability-roundup-8</link>
		<comments>http://www.securabit.com/2010/03/15/vulnerability-roundup-8/#comments</comments>
		<pubDate>Mon, 15 Mar 2010 12:02:42 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[Guest Blogs]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[BIND]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[openssl]]></category>
		<category><![CDATA[php]]></category>
		<category><![CDATA[typo3]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://www.securabit.com/?p=1327</guid>
		<description><![CDATA[Well, it isn&#8217;t Patch Tuesday yet, but that doesn&#8217;t mean there isn&#8217;t Microsoft news.  A new 0-day has been found which exploits the help system in IE and older versions of windows (2000, XP, 2003).  I&#8217;ve included a few links with information about the vulnerability and mitigation steps.  It appears a patch for this (and [...]]]></description>
			<content:encoded><![CDATA[<p>Well, it isn&#8217;t Patch Tuesday yet, but that doesn&#8217;t mean there isn&#8217;t  Microsoft news.  A new 0-day has been found which exploits the help  system in IE and older versions of windows (2000, XP, 2003).  I&#8217;ve  included a few links with information about the vulnerability and  mitigation steps.  It appears a patch for this (and other known  vulnerabilities) will not be included in the Microsoft release on  Tuesday, which will include two bulletins, one for Office, and one for  windows, which cover 8 vulnerabilities in total.</p>
<p>Cisco has also  released three advisories for vulnerabilities in three of their  products.  Patches are now available for the Unified Communications  Manager, Digital Media Manager and the Digital Media Player Remote  display.</p>
<p>An interesting hardware/software vulnerability has been  released for OpenSSL which could allow an attacker to deduce at least  parts of the private key.  The technique used to exploit this weakness  doesn&#8217;t seem very practical for attacking a full size system, but could  be practical against embedded devices.</p>
<p>A new release of the TYPO3  Core CMS system has been released to cover a few vulnerabilities (XSS,  information disclosure).  Other Open Source projects, PHP and BIND have  also been updated with security fixes.</p>
<p>The Zero Day Initiative also  has some upcoming advisories for Apple&#8217;s Safari browser, which may mean  updates from Apple.  The ZDI has rated these as &#8220;High&#8221; severity.</p>
<p>Last,  but never least, VMWare has released and advisory for some of their  products, which includes another large list of CVEs covered.  These  updates include a long list of third party updates for packages in ESX.</p>
<ul>
<li>Microsoft: <a href="http://www.sans.org/newsletters/risk/display.php?v=9&amp;i=10#widely4">IE Help Code Execution Vulnerability</a></li>
<li>Microsoft: <a href="http://blogs.technet.com/srd/archive/2010/03/01/help-keypress-vulnerability-in-vbscript-enabling-remote-code-execution.aspx">IE Help Code Execution Vulnerability (MS Security Research  and Defense blog)</a></li>
<li>Microsoft: <a href="http://blogs.technet.com/msrc/archive/2010/03/04/march-2010-bulletin-release-advance-notification.aspx">March 2010 Patch Tuesday Advanced Notification</a></li>
<li>Microsoft: <a href="http://www.h-online.com/security/news/item/Several-known-vulnerabilities-to-remain-unpatched-on-forthcoming-Microsoft-patch-day-947191.html">Several known vulnerabilities to remain unpatched on forthcoming  Microsoft patch day</a></li>
<li>Cisco: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b924.shtml">Unified Communications Manager Denial of Service Vulnerabilities</a></li>
<li>Cisco: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b923.shtml">Multiple Vulnerabilities in Cisco Digital Media Manager</a></li>
<li>Cisco: <a href="http://www.cisco.com/en/US/products/products_security_advisory09186a0080b1b925.shtml">Digital Media Player Remote Display Unauthorized Content  Injection Vulnerability</a></li>
<li>OpenSSL: <a href="http://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/">Private key disclosure vulnerability</a></li>
<li>TYPO3: <a href="http://www.h-online.com/security/news/item/Security-update-for-TYPO3-released-940683.html">Security update released</a></li>
<li>ISC: <a href="http://www.isc.org/files/release-notes/962.html">BIND 9.6.2 released</a></li>
<li>PHP: <a href="http://www.php.net/ChangeLog-5.php#5.2.13">PHP 5.2.13 released</a></li>
<li>Safari: <a href="http://threatpost.com/en_us/blogs/hacker-report-high-risk-flaws-safari-browser-030110">Flaws in Safari Browser</a></li>
<li>VMWare: <a href="http://lists.vmware.com/pipermail/security-announce/2010/000082.html">Multiple ESX Service Console and vMA third party  updates</a></li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.securabit.com/2010/03/15/vulnerability-roundup-8/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Vulnerability Roundup</title>
		<link>http://www.securabit.com/2010/01/13/vulnerability-roundup/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=vulnerability-roundup</link>
		<comments>http://www.securabit.com/2010/01/13/vulnerability-roundup/#comments</comments>
		<pubDate>Wed, 13 Jan 2010 16:30:39 +0000</pubDate>
		<dc:creator>david</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[android]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[oracle]]></category>
		<category><![CDATA[phishing]]></category>
		<category><![CDATA[PowerDNS]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.securabit.com/?p=1108</guid>
		<description><![CDATA[Here are some of the more interesting vulnerabilities or patches from this week. As this is our first roundup, some of these are a little older than a week, but noteworthy nonetheless. This week we have a light Patch Tuesday from Microsoft, but Adobe picks up the slack with patches for a server product, Acrobat [...]]]></description>
			<content:encoded><![CDATA[<p>Here are some of the more interesting vulnerabilities or patches from this week.  As this is our first roundup, some of these are a little older than a week, but noteworthy nonetheless.  This week we have a light Patch Tuesday from Microsoft, but Adobe picks up the slack with patches for a server product, Acrobat and Reader.  Network equipment also makes an appearance on both the enterprise and consumer level, with what appears to be a simple DoS for Juniper products and an authentication bypass for D-Link routers.   To round things out there are PowerDNS and VMWare, and news from the Android camp, reminding us that as consumers move to new places, attackers will follow.</p>
<ul>
<li>Microsoft Patch Tuesday: <a href="http://blogs.technet.com/srd/archive/2010/01/12/ms10-001-font-file-decompression-vulnerability.aspx">OpenType Font file decompression vulnerability</a></li>
<li>Adobe: <a href="http://www.adobe.com/support/security/bulletins/apsb09-18.html">Security update for Flash Media Server</a></li>
<li>Adobe: <a href="http://www.adobe.com/support/security/bulletins/apsb10-02.html">Security updates for Reader and Acrobat</a></li>
<li>Oracle: <a href="http://isc.sans.org/diary.html?storyid=7960">Oracle Critical Patch Update (CPU)</a> &#8211; 24 vulns, 3 with no authentication required</li>
<li>MacOS X: <a href="http://isc.sans.org/diary.html?storyid=7942">PoC for MacOS X 10.5/10.6 vulnerability</a></li>
<li>VMWare: <a href="http://lists.vmware.com/pipermail/security-announce/2010/000075.html">Multiple updates for ESX</a></li>
<li>Juniper Networks: <a href="http://osvdb.org/show/osvdb/61538">JUNOS Malformed TCP Packet DoS</a></li>
<li>D-Link (Multiple Routers): <a href="http://www.sourcesec.com/2010/01/09/d-link-routers-one-hack-to-own-them-all/">HNAP Protocol Security Bypass Vulnerability</a></li>
<li>PowerDNS: <a href="http://osvdb.org/show/osvdb/61602">PowerDNS Recurser Buffer Overflow Vulnerability</a></li>
<li>Motorola Droid: <a href="http://www.techcrunch.com/2010/01/11/verizon-droid-security-bug/">Screen Lock bypass</a></li>
</ul>
<p>Another interesting story, also from the Android family is about a piece of malware which made its way into the Android Marketplace, specifically a fake mobile banking application which was designed to harvest login credentials.  More coverage can be found at <a href="http://isc.sans.org/diary.html?storyid=7936">SANS</a>.</p>
<p>Blog post by:  David Shpritz</p>
]]></content:encoded>
			<wfw:commentRss>http://www.securabit.com/2010/01/13/vulnerability-roundup/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>SecuraBit Episode 12</title>
		<link>http://www.securabit.com/2008/10/13/securabit-episode-12/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=securabit-episode-12</link>
		<comments>http://www.securabit.com/2008/10/13/securabit-episode-12/#comments</comments>
		<pubDate>Mon, 13 Oct 2008 15:21:29 +0000</pubDate>
		<dc:creator>Chris</dc:creator>
				<category><![CDATA[SecuraBits]]></category>
		<category><![CDATA[Show Releases]]></category>
		<category><![CDATA[bullshit]]></category>
		<category><![CDATA[cracking]]></category>
		<category><![CDATA[episodes]]></category>
		<category><![CDATA[failbus]]></category>
		<category><![CDATA[fios]]></category>
		<category><![CDATA[securabit]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[vista]]></category>
		<category><![CDATA[vmware]]></category>

		<guid isPermaLink="false">http://securabit.com/?p=312</guid>
		<description><![CDATA[Securabit Episode 12

Anthony Gartner
Chris Mills
Chris Gerling

Chris G rides the <a href="http://www.failbus.com/">Failbus</a> with his FIOS connection

<a href="http://blogs.cioinsight.com/biztech30/content/it_careers/it_jobs_no_widespread_worry_2.html">IT Jobs: No "Widespread Worry"</a>

<a href="http://blog.wired.com/defense/2008/08/air-force-suspe.html">Air Force Cyber Command</a>

<a href="http://www.net-security.org/secworld.php?id=6616">Cracking one billion passwords per second with NVIDIA video car</a>d

BREAK

Chris G]]></description>
			<content:encoded><![CDATA[<p>Securabit Episode 12</p>
<p>Anthony Gartner<br />
Chris Mills<br />
Chris Gerling</p>
<p>Chris G rides the <a href="http://www.failbus.com/">Failbus</a> with his FIOS connection</p>
<p><a href="http://blogs.cioinsight.com/biztech30/content/it_careers/it_jobs_no_widespread_worry_2.html">IT Jobs: No &#8220;Widespread Worry&#8221;</a></p>
<p><a href="http://blog.wired.com/defense/2008/08/air-force-suspe.html">Air Force Cyber Command</a></p>
<p><a href="http://www.net-security.org/secworld.php?id=6616">Cracking one billion passwords per second with NVIDIA video car</a>d</p>
<p>BREAK</p>
<p>Chris G talks about running VM&#8217;s in Vista Ultimate 64 bit</p>
<p>The guys discuss home networking</p>
<p><a href="http://www.soekris.com/">Soekris Box</a><br />
<a href="http://www.netgate.com/product_info.php?products_id=312">Netgate m1n1wall firewall 3E 2D3<br />
</a><br />
<a href="http://www.foxbusiness.com/story/markets/industries/finance/aig-executives-blow--getting-bailout/">AIG Executives Blow $440,000 After Getting Bailout</a></p>
<p>Password Management Systems:</p>
<p><a href="http://passwordsafe.sourceforge.net/">Password Safe</a><br />
<a href="http://keepass.info/">KeePass</a><br />
<a href="http://www.fpx.de/fp/Software/Gorilla/">Password Gorilla</a> &#8211; Works on Mac OS X<br />
<a href="http://agilewebsolutions.com/products/1Password">1Password</a><br />
<a href="http://en.wikipedia.org/wiki/Apple_Keychain">Apple Keychain</a> &#8211; Nice, but not portable<br />
<a href="http://www.windmeadow.com/node/35">TrueCrypt on JungleDisk</a></p>
<p><a href="http://www.reuters.com/article/pressRelease/idUS182108+29-Sep-2008+BW20080929">New Nevada Law Requiring Businesses to Encrypt Emails with Customers</a></p>
<p><a href="http://news.zdnet.co.uk/itmanagement/0,1000000308,39217959,00.htm">France required to keep record all connections</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.securabit.com/2008/10/13/securabit-episode-12/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
