<?xml version="1.0" encoding="utf-8" ?>
<rss version="2.0">
<channel>
<title>Ivan Markovic - Security Net</title>
<link>http://www.security-net.biz/wsw/index.php?p=200</link>
<description>RSS feed Security Net</description>
<language>sr</language>
<ttl>15</ttl>

<item>
	<title>Telekom, Huawei, CSRF</title>
	<link>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=325</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=325</guid>
	<description>Vecina Telekom ADSL modema je ranjiva na CSRF napade, ovim putem mozemo izmeniti vitalna podesavanja i ugroziti korisnike na vise nacina.&lt;br /&gt;&lt;br /&gt;Linkovi:&lt;br /&gt;&lt;br /&gt;- &lt;a target=&quot;_blank&quot; href=&quot;http://netsec.rs/18/huawei-hg510-multiple-vulnerabilities/493/&quot;&gt;http://netsec.rs/18/huawei-hg510-multiple-vulnerabilities/493/&lt;/a&gt;&lt;br /&gt;- &lt;a target=&quot;_blank&quot; href=&quot;http://www.securityfocus.com/bid/38261/info&quot;&gt;http://www.securityfocus.com/bid/38261/info&lt;/a&gt;&lt;br /&gt;- &lt;a target=&quot;_blank&quot; href=&quot;http://www.elitesecurity.org/t391845-Telekom-ADSL-amp-Huawei-CSRF-Auth-Bypass-DoS&quot;&gt;http://www.elitesecurity.org/t391845-Telekom-ADSL-amp-Huawei-CSRF-Auth-Bypass-DoS&lt;/a&gt;&lt;br /&gt;- &lt;a href=&quot;http://en.wikipedia.org/wiki/Cross-site_request_forgery&quot; target=&quot;_blank&quot;&gt;http://en.wikipedia.org/wiki/Cross-site_request_forgery&lt;/a&gt;</description>
	<pubDate>Wed, 17 Feb 2010 05:39:28 +0100</pubDate>
</item>

<item>
	<title>Banka Intesa: Gde je nas web sajt ?</title>
	<link>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=324</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=324</guid>
	<description>Domen je istekao:&lt;br /&gt;&lt;br /&gt;---------------------------------------------&lt;br /&gt;Expiration Date: 2011-11-25&lt;br /&gt;Creation Date: 2005-11-25&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Last Update Date: 2010-02-12&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Name Servers:&lt;br /&gt;ns1.pendingrenewaldeletion.com&lt;br /&gt;ns2.pendingrenewaldeletion.com&lt;br /&gt;---------------------------------------------&lt;br /&gt;&lt;br /&gt;Diskusija:&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;http://www.devprotalk.com/t8440-istekao-domen-banke-intesa.html&quot; target=&quot;_blank&quot;&gt;http://www.devprotalk.com/t8440-istekao-domen-banke-intesa.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;I da li je potrebno da napomenem koliko je ova neodgovornost opasna po korisnike ?&lt;/span&gt;</description>
	<pubDate>Sat, 13 Feb 2010 07:10:59 +0100</pubDate>
</item>

<item>
	<title>schneier / google / hacking / cn</title>
	<link>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=323</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=323</guid>
	<description>&amp;quot;In order to comply with government search warrants on user data, &lt;span style=&quot;font-weight: bold;&quot;&gt;Google&lt;/span&gt; created a &lt;span style=&quot;font-weight: bold;&quot;&gt;backdoor&lt;/span&gt; access system into &lt;span style=&quot;font-weight: bold;&quot;&gt;Gmail &lt;/span&gt;accounts. This feature is what the &lt;span style=&quot;font-weight: bold;&quot;&gt;Chinese hackers&lt;/span&gt; exploited to gain access.&amp;quot;&lt;br /&gt;&lt;br /&gt;&lt;a target=&quot;_blank&quot; href=&quot;http://www.cnn.com/2010/OPINION/01/23/schneier.google.hacking/&quot;&gt;http://www.cnn.com/2010/OPINION/01/23/schneier.google.hacking/&lt;/a&gt;</description>
	<pubDate>Mon, 25 Jan 2010 01:19:33 +0100</pubDate>
</item>

<item>
	<title>phpAV &amp; PHP.ini Security Info</title>
	<link>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=322</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=322</guid>
	<description>Drago mi je da se na nasim prostorima sve cesce pojavljuju osobe zainteresovane za bezbednost, i zato zelim da pohvalim i ohrabrim iste da nastave sa svojim radom! &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Milos Zivanovic&lt;/span&gt; je napisao odlican PHP skript koji moze brzo i efikasno da otkrije maliciozne fajlove na vasim web serverima. Skript ima opcije pretrazivanja direktorijuma za poznatim opasnim skriptama kao i opciju pretrazivanja izvornog koda za potencijalno opasnim funkcijama.&lt;br /&gt;&lt;br /&gt;Skript mozete skinuti ovde: &lt;a target=&quot;_blank&quot; href=&quot;http://www.packetstormsecurity.org/web/phpav-1.1.txt&quot;&gt;http://www.packetstormsecurity.org/web/phpav-1.1.txt&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;Milos Djuric&lt;/span&gt; je nasao inspiraciju u skriptu koji sam napisao davno a koji prikazuje obavestanja o potencijalno opasnim podesavanjima PHP-a. Skript je unapredjen a veoma zanimljiva opcija je i prikazivanje podesavanja u odnosu na tip okruzenja (Debug/Production).&lt;br /&gt;&lt;br /&gt;Skript mozete skinuti ovde:&lt;a href=&quot;http://www.elitesecurity.org/t382114-PHP-ini-Security-info-pitanja-podesavanju-php-ini&quot; target=&quot;_blank&quot;&gt; http://www.elitesecurity.org/t382114-PHP-ini-Security-info-pitanja-podesavanju-php-ini&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Ukoliko imate neku ideju a vezana je za razvoj &amp;quot;security&amp;quot; alata, slobodno me kontaktirajte rado cu Vam izaci u susret ;)</description>
	<pubDate>Sat, 09 Jan 2010 09:53:23 +0100</pubDate>
</item>

<item>
	<title>Zanimljivosti iz sveta bezbednosti</title>
	<link>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=321</link>
	<guid>http://www.security-net.biz/wsw/index.php?p=200&amp;bl=321</guid>
	<description>U poslednje vreme ne stizem da pisem na svom blogu o svim zanimljivim stvarima u vezi bezbednosti, ali zato mogu da podelim zanimljive linkove ;)&lt;br /&gt;&lt;br /&gt;- &lt;a href=&quot;http://securityretentive.blogspot.com/2009/12/best-security-improvements-in-2009.html&quot; target=&quot;_blank&quot;&gt;Best Security Improvements in 2009?&lt;/a&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.theregister.co.uk/2009/12/25/microsoft_iis_semicolon_bug/&quot; target=&quot;_blank&quot;&gt;Microsoft IIS vuln leaves users open to remote attack&lt;/a&gt;&lt;br /&gt;- &lt;a href=&quot;http://www.owasp.org/index.php/Securing_tomcat&quot; target=&quot;_blank&quot;&gt;Securing tomcat&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;</description>
	<pubDate>Tue, 29 Dec 2009 09:48:58 +0100</pubDate>
</item>

</channel>
</rss>