<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Vorlon's Blog &#187; security</title>
	<atom:link href="http://blog.vorlons.info/archives/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.vorlons.info</link>
	<description>Science, Life, Computers, ... who knows what will end up in here...</description>
	<lastBuildDate>Mon, 12 Oct 2009 15:35:11 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/>		<item>
		<title>Network Security Breaches at NASA</title>
		<link>http://blog.vorlons.info/archives/2008/12/05/243/</link>
		<comments>http://blog.vorlons.info/archives/2008/12/05/243/#comments</comments>
		<pubDate>Fri, 05 Dec 2008 13:08:24 +0000</pubDate>
		<dc:creator>vorlon</dc:creator>
				<category><![CDATA[English]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Science]]></category>
		<category><![CDATA[NASA]]></category>
		<category><![CDATA[ROSAT]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.vorlons.info/?p=243</guid>
		<description><![CDATA[Bruce Schneier points to an article at BusinessWeek about repeated attacks on the NASA networks and successful intrusions. The article also mentions a possible connection of the problem of ROSAT pointing too close to the sun in September 1998 to such attacks.
]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.schneier.com/blog/archives/2008/12/cyberattacks_ag.html">Bruce Schneier</a> points to <a href="http://www.businessweek.com/print/magazine/content/08_48/b4110072404167.htm">an article at BusinessWeek</a> about repeated attacks on the NASA networks and successful intrusions. The article also mentions a possible connection of the problem of ROSAT <a href="http://www.mpe.mpg.de/xray/wave/rosat/mission/rosat_news/news66.txt">pointing too close to the sun</a> in September 1998 to such attacks.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vorlons.info/archives/2008/12/05/243/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Serious DNS vulnerabilities &#8211; update for bind available</title>
		<link>http://blog.vorlons.info/archives/2008/07/09/174/</link>
		<comments>http://blog.vorlons.info/archives/2008/07/09/174/#comments</comments>
		<pubDate>Wed, 09 Jul 2008 09:24:28 +0000</pubDate>
		<dc:creator>vorlon</dc:creator>
				<category><![CDATA[Computer stuff]]></category>
		<category><![CDATA[English]]></category>
		<category><![CDATA[Gentoo]]></category>
		<category><![CDATA[DNS]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://blog.vorlons.info/?p=174</guid>
		<description><![CDATA[In the light of yesterday&#8217;s large coordinated release of DNS related updates to various products, I would like to point you to the updated bind packages in the portage tree.

net-dns/bind-9.4.2_p1 is currently being marked stable on all supported architectures
net-dns/bind-9.5.0_p1 has been committed with unstable keywords

Nameservers should be updated quite soon, since this issue should be [...]]]></description>
			<content:encoded><![CDATA[<p>In the light of yesterday&#8217;s large coordinated release of DNS related updates to various products, I would like to point you to the updated bind packages in the portage tree.</p>
<ul>
<li>net-dns/bind-9.4.2_p1 is currently being marked stable on all supported architectures</li>
<li>net-dns/bind-9.5.0_p1 has been committed with unstable keywords</li>
</ul>
<p>Nameservers should be updated quite soon, since this issue should be considered serious.</p>
<p>A GLSA will be published after all security architectures have marked the affected package stable. The progress can be followed in bug <a title="bug #231201" href="https://bugs.gentoo.org/show_bug.cgi?id=231201" target="_blank">#231201</a>.</p>
<p>For more information have a look at the following links and the references therein:</p>
<ul>
<li><a title="VU #800113" href="http://www.kb.cert.org/vuls/id/800113" target="_blank">US-CERT Vulnerability Note VU#800113</a></li>
<li><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447" target="_blank">CVE-2008-1447</a></li>
<li><a href="http://www.isc.org/sw/bind/forgery-resilience.php" target="_blank">ISC info</a></li>
</ul>
<p>Also note that if you are restricting the used outgoing ports of your nameserver by a firewall for example, this policy should be revisited.</p>
<p><em>Update 2008-07-11:<br />
</em><a title="GLSA 200807-08" href="http://www.gentoo.org/security/en/glsa/glsa-200807-08.xml" target="_blank">GLSA 200807-08</a> has just been released to address this issue.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vorlons.info/archives/2008/07/09/174/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Chipkarte der Uni Göttingen unsicher!?</title>
		<link>http://blog.vorlons.info/archives/2008/03/30/168/</link>
		<comments>http://blog.vorlons.info/archives/2008/03/30/168/#comments</comments>
		<pubDate>Sun, 30 Mar 2008 16:42:39 +0000</pubDate>
		<dc:creator>vorlon</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Göttingen]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[university]]></category>

		<guid isPermaLink="false">http://blog.vorlons.info/archives/2008/03/30/168/</guid>
		<description><![CDATA[Ich hatte noch keine Zeit mir das genauer anzugucken, aber es sieht so aus als wurde die Verschlüsselung eines RFID-Chips geknackt, welcher auch auf den Chipkarten der Uni Göttingen verwendung findet. Diese wiederum wird u.a. zum Bezahlen in der Mensa oder auch als Zutrittsberechtigung in verschiedenen Fakultäten verwendet
via cpunk
UPDATE:
Mehr zum Knacken der Verschlüsselung gibt es [...]]]></description>
			<content:encoded><![CDATA[<p>Ich hatte noch keine Zeit mir das genauer anzugucken, aber es sieht so aus als wurde die Verschlüsselung eines RFID-Chips geknackt, welcher auch auf den Chipkarten der Uni Göttingen verwendung findet. Diese wiederum wird u.a. zum Bezahlen in der Mensa oder auch als Zutrittsberechtigung in verschiedenen Fakultäten verwendet</p>
<p>via <a href="http://cpunk.de/archives/2008/03/28/index.html#e2008-03-28T17_17_24.txt">cpunk</a></p>
<p>UPDATE:</p>
<p>Mehr zum Knacken der Verschlüsselung gibt es auf der Seite von <a href="http://www.cs.virginia.edu/~kn5f/">Karsten Nohl</a> und in <a href="http://events.ccc.de/congress/2007/Fahrplan/events/2378.en.html">diesem Vortrag</a> vom 24C3.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.vorlons.info/archives/2008/03/30/168/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>
