<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">

<link rel="self" type="application/atom+xml"
href="http://www.security-net.biz/blog/feed.php"/>

<title>Security Net Feed</title>
<link href="http://security-net.biz/blog/"/>
<updated>2010-02-17T17:02:28Z</updated>
<author>
<name>Ivan Markovic</name>
</author>
<id>urn:uuid:1268166738</id>

<entry>
    <title>Telekom, Huawei, CSRF</title>
    <link href="http://security-net.biz/wsw/index.php?p=200&amp;bl=325"/>
    <author>
    <name>Ivan Markovic</name>
    </author>
    <id>tag:www.security-net.biz,2010-02-17:/325</id>
    <updated>2010-02-17T17:02:28Z</updated>
    <summary type="html">Vecina Telekom ADSL modema je ranjiva na CSRF napade, ovim putem mozemo izmeniti vitalna podesavanja i ugroziti korisnike na vise nacina.&lt;br /&gt;&lt;br /&gt;Linkovi:&lt;br /&gt;&lt;br /&gt;- &lt;a target=&quot;_blank&quot; href=&quot;http://netsec.rs/18/huawei-hg510-multiple-vulnerabilities/493/&quot;&gt;http://netsec.rs/18/huawei-hg510-multiple-vulnerabilities/493/&lt;/a&gt;&lt;br /&gt;- &lt;a target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/38261/info&quot;&gt;http://www.securityfocus.com/bid/38261/info&lt;/a&gt;&lt;br /&gt;- &lt;a target=&quot;_blank&quot; href=&quot;http://www.elitesecurity.org/t391845-Telekom-ADSL-amp-Huawei-CSRF-Auth-Bypass-DoS&quot;&gt;http://www.elitesecurity.org/t391845-Telekom-ADSL-amp-Huawei-CSRF-Auth-Bypass-DoS&lt;/a&gt;&lt;br /&gt;- &lt;a href=&quot;http://en.wikipedia.org/wiki/Cross-site_request_forgery&quot; target=&quot;_blank&quot;&gt;http://en.wikipedia.org/wiki/Cross-site_request_forgery&lt;/a&gt;</summary>
  </entry>
<entry>
    <title>Banka Intesa: Gde je nas web sajt ?</title>
    <link href="http://security-net.biz/wsw/index.php?p=200&amp;bl=324"/>
    <author>
    <name>Ivan Markovic</name>
    </author>
    <id>tag:www.security-net.biz,2010-02-13:/324</id>
    <updated>2010-02-13T19:02:59Z</updated>
    <summary type="html">Domen je istekao:&lt;br /&gt;&lt;br /&gt;---------------------------------------------&lt;br /&gt;Expiration Date: 2011-11-25&lt;br /&gt;Creation Date: 2005-11-25&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Last Update Date: 2010-02-12&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Name Servers:&lt;br /&gt;ns1.pendingrenewaldeletion.com&lt;br /&gt;ns2.pendingrenewaldeletion.com&lt;br /&gt;---------------------------------------------&lt;br /&gt;&lt;br /&gt;Diskusija:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.devprotalk.com/t8440-istekao-domen-banke-intesa.html&quot; target=&quot;_blank&quot;&gt;http://www.devprotalk.com/t8440-istekao-domen-banke-intesa.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;I da li je potrebno da napomenem koliko je ova neodgovornost opasna po korisnike ?&lt;/span&gt;</summary>
  </entry>
<entry>
    <title>schneier / google / hacking / cn</title>
    <link href="http://security-net.biz/wsw/index.php?p=200&amp;bl=323"/>
    <author>
    <name>Ivan Markovic</name>
    </author>
    <id>tag:www.security-net.biz,2010-01-25:/323</id>
    <updated>2010-01-25T01:01:33Z</updated>
    <summary type="html">&amp;quot;In order to comply with government search warrants on user data, &lt;span style=&quot;font-weight: bold;&quot;&gt;Google&lt;/span&gt; created a &lt;span style=&quot;font-weight: bold;&quot;&gt;backdoor&lt;/span&gt; access system into &lt;span style=&quot;font-weight: bold;&quot;&gt;Gmail &lt;/span&gt;accounts. This feature is what the &lt;span style=&quot;font-weight: bold;&quot;&gt;Chinese hackers&lt;/span&gt; exploited to gain access.&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.cnn.com/2010/OPINION/01/23/schneier.google.hacking/&quot;&gt;http://www.cnn.com/2010/OPINION/01/23/schneier.google.hacking/&lt;/a&gt;</summary>
  </entry>
<entry>
    <title>phpAV &amp; PHP.ini Security Info</title>
    <link href="http://security-net.biz/wsw/index.php?p=200&amp;bl=322"/>
    <author>
    <name>Ivan Markovic</name>
    </author>
    <id>tag:www.security-net.biz,2010-01-09:/322</id>
    <updated>2010-01-09T21:01:23Z</updated>
    <summary type="html">Drago mi je da se na nasim prostorima sve cesce pojavljuju osobe zainteresovane za bezbednost, i zato zelim da pohvalim i ohrabrim iste da nastave sa svojim radom! &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Milos Zivanovic&lt;/span&gt; je napisao odlican PHP skript koji moze brzo i efikasno da otkrije maliciozne fajlove na vasim web serverima. Skript ima opcije pretrazivanja direktorijuma za poznatim opasnim skriptama kao i opciju pretrazivanja izvornog koda za potencijalno opasnim funkcijama.&lt;br /&gt;&lt;br /&gt;Skript mozete skinuti ovde: &lt;a target=&quot;_blank&quot; href=&quot;http://www.packetstormsecurity.org/web/phpav-1.1.txt&quot;&gt;http://www.packetstormsecurity.org/web/phpav-1.1.txt&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Milos Djuric&lt;/span&gt; je nasao inspiraciju u skriptu koji sam napisao davno a koji prikazuje obavestanja o potencijalno opasnim podesavanjima PHP-a. Skript je unapredjen a veoma zanimljiva opcija je i prikazivanje podesavanja u odnosu na tip okruzenja (Debug/Production).&lt;br /&gt;&lt;br /&gt;Skript mozete skinuti ovde:&lt;a href=&quot;http://www.elitesecurity.org/t382114-PHP-ini-Security-info-pitanja-podesavanju-php-ini&quot; target=&quot;_blank&quot;&gt; http://www.elitesecurity.org/t382114-PHP-ini-Security-info-pitanja-podesavanju-php-ini&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ukoliko imate neku ideju a vezana je za razvoj &amp;quot;security&amp;quot; alata, slobodno me kontaktirajte rado cu Vam izaci u susret ;)</summary>
  </entry>
<entry>
    <title>Zanimljivosti iz sveta bezbednosti</title>
    <link href="http://security-net.biz/wsw/index.php?p=200&amp;bl=321"/>
    <author>
    <name>Ivan Markovic</name>
    </author>
    <id>tag:www.security-net.biz,2009-12-29:/321</id>
    <updated>2009-12-29T21:12:58Z</updated>
    <summary type="html">U poslednje vreme ne stizem da pisem na svom blogu o svim zanimljivim stvarima u vezi bezbednosti, ali zato mogu da podelim zanimljive linkove ;)&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://securityretentive.blogspot.com/2009/12/best-security-improvements-in-2009.html&quot; target=&quot;_blank&quot;&gt;Best Security Improvements in 2009?&lt;/a&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.theregister.co.uk/2009/12/25/microsoft_iis_semicolon_bug/&quot; target=&quot;_blank&quot;&gt;Microsoft IIS vuln leaves users open to remote attack&lt;/a&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.owasp.org/index.php/Securing_tomcat&quot; target=&quot;_blank&quot;&gt;Securing tomcat&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;</summary>
  </entry>
</feed>     