<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/abc" -->
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>
<channel>
	<title>Comments for CyberInsecure.com</title>
	<link>http://cyberinsecure.com</link>
	<description>Daily cyber threats and internet security news alerts</description>
	<pubDate>Sat, 05 Jul 2008 16:48:08 +0000</pubDate>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>Comment on Sony USA PlayStation Website SQL Injected And Redirects Visitors To Fake Anti-Virus Scam by Greg Martin</title>
		<link>http://cyberinsecure.com/sony-usa-playstation-website-sql-injected-and-redirects-visitors-to-fake-anti-virus-scam/#comment-518</link>
		<dc:creator>Greg Martin</dc:creator>
		<pubDate>Wed, 02 Jul 2008 21:13:50 +0000</pubDate>
		<guid>http://cyberinsecure.com/sony-usa-playstation-website-sql-injected-and-redirects-visitors-to-fake-anti-virus-scam/#comment-518</guid>
		<description>If you are infected by these SQL Injection attacks, please address this immediately as your website could be infecting people with this garbage too...
 
http://infosec20.blogspot.com</description>
		<content:encoded><![CDATA[<p>If you are infected by these SQL Injection attacks, please address this immediately as your website could be infecting people with this garbage too&#8230;</p>
<p><a href="http://infosec20.blogspot.com" rel="nofollow">http://infosec20.blogspot.com</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Malware Spam Reporting Bogus Beijing Earthquake Targets Olympic Games Fans by CyberInsecure</title>
		<link>http://cyberinsecure.com/new-malware-spam-reporting-bogus-beijing-earthquake-targets-olympic-games-fans/#comment-507</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Tue, 24 Jun 2008 13:41:16 +0000</pubDate>
		<guid>http://cyberinsecure.com/new-malware-spam-reporting-bogus-beijing-earthquake-targets-olympic-games-fans/#comment-507</guid>
		<description>If it was indeed an email that infected your PC, do not use the internet for surfing until you scan your system and clean the virus. Otherwise, you might lose some, if not all, of your online accounts passwords.

Scan and clean your system as soon as possible, with more than just one anti-virus.</description>
		<content:encoded><![CDATA[<p>If it was indeed an email that infected your PC, do not use the internet for surfing until you scan your system and clean the virus. Otherwise, you might lose some, if not all, of your online accounts passwords.</p>
<p>Scan and clean your system as soon as possible, with more than just one anti-virus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Malware Spam Reporting Bogus Beijing Earthquake Targets Olympic Games Fans by oswald</title>
		<link>http://cyberinsecure.com/new-malware-spam-reporting-bogus-beijing-earthquake-targets-olympic-games-fans/#comment-506</link>
		<dc:creator>oswald</dc:creator>
		<pubDate>Tue, 24 Jun 2008 12:56:40 +0000</pubDate>
		<guid>http://cyberinsecure.com/new-malware-spam-reporting-bogus-beijing-earthquake-targets-olympic-games-fans/#comment-506</guid>
		<description>I just opened a flippen e-mail about the CHINESE EARTQUAKE.Is it at all harmful to my computer or internet banking fasilities? If so, what should I do?</description>
		<content:encoded><![CDATA[<p>I just opened a flippen e-mail about the CHINESE EARTQUAKE.Is it at all harmful to my computer or internet banking fasilities? If so, what should I do?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Social Networks Information Sharing Flaw Exposes Private MySpace Users Photos by CyberInsecure</title>
		<link>http://cyberinsecure.com/social-networks-information-sharing-exposes-private-myspace-photos-due-to-a-privacy-flaw/#comment-500</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Fri, 20 Jun 2008 00:03:29 +0000</pubDate>
		<guid>http://cyberinsecure.com/social-networks-information-sharing-exposes-private-myspace-photos-due-to-a-privacy-flaw/#comment-500</guid>
		<description>Again, this method does not work anymore.

desperate mom: There are much easier ways (keylogging) if you have a local access to the PC. Since you are a mom, you can also practice your parental rights and openly demand to see what the "teen" is doing on myspace, "or else..." (even better, no hacking involved).</description>
		<content:encoded><![CDATA[<p>Again, this method does not work anymore.</p>
<p>desperate mom: There are much easier ways (keylogging) if you have a local access to the PC. Since you are a mom, you can also practice your parental rights and openly demand to see what the &#8220;teen&#8221; is doing on myspace, &#8220;or else&#8230;&#8221; (even better, no hacking involved).</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Social Networks Information Sharing Flaw Exposes Private MySpace Users Photos by keleigh</title>
		<link>http://cyberinsecure.com/social-networks-information-sharing-exposes-private-myspace-photos-due-to-a-privacy-flaw/#comment-499</link>
		<dc:creator>keleigh</dc:creator>
		<pubDate>Thu, 19 Jun 2008 22:40:33 +0000</pubDate>
		<guid>http://cyberinsecure.com/social-networks-information-sharing-exposes-private-myspace-photos-due-to-a-privacy-flaw/#comment-499</guid>
		<description>I am trying to access my teens myspace that is private, is there anyway?  I tried the suggestion above with the yahoo and widgets, and myspace didn't come up in the search.

Thank you
desperate mom</description>
		<content:encoded><![CDATA[<p>I am trying to access my teens myspace that is private, is there anyway?  I tried the suggestion above with the yahoo and widgets, and myspace didn&#8217;t come up in the search.</p>
<p>Thank you<br />
desperate mom</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Credit Cards Data Stolen In 1st Source Bank Intrusion by John Franks</title>
		<link>http://cyberinsecure.com/credit-cards-data-stolen-in-1st-source-bank-intrusion/#comment-493</link>
		<dc:creator>John Franks</dc:creator>
		<pubDate>Sat, 14 Jun 2008 15:39:01 +0000</pubDate>
		<guid>http://cyberinsecure.com/credit-cards-data-stolen-in-1st-source-bank-intrusion/#comment-493</guid>
		<description>Why does this keep happening? There is a defined eCulture called The Business-Technology Weave that helps to influence employee behaviour as regards security, use and integrity of data. This is particularly relevant: &lt;em&gt;***spam - link removed***&lt;/em&gt; . Some good stuff here too: &lt;em&gt;***spam - link removed***&lt;/em&gt; . We use this book at work - I wouldn't recommend it if it wasn't making a tremendous difference.  Frankly, I would like my bank and any institution that handles MY personal data to read it - before it's too late!  Given all of these data thefts, it's only a matter of time before any specific person experiences a real headache - something worse than losing your wallet, for example.  Can't we get proactive about this??</description>
		<content:encoded><![CDATA[<p>Why does this keep happening? There is a defined eCulture called The Business-Technology Weave that helps to influence employee behaviour as regards security, use and integrity of data. This is particularly relevant: <em>***spam - link removed***</em> . Some good stuff here too: <em>***spam - link removed***</em> . We use this book at work - I wouldn&#8217;t recommend it if it wasn&#8217;t making a tremendous difference.  Frankly, I would like my bank and any institution that handles MY personal data to read it - before it&#8217;s too late!  Given all of these data thefts, it&#8217;s only a matter of time before any specific person experiences a real headache - something worse than losing your wallet, for example.  Can&#8217;t we get proactive about this??</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WordPress Multiple SQL Injection Vulnerabilities by CyberInsecure</title>
		<link>http://cyberinsecure.com/wordpress-multiple-sql-injection-vulnerabilities/#comment-491</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Thu, 12 Jun 2008 11:43:08 +0000</pubDate>
		<guid>http://cyberinsecure.com/wordpress-multiple-sql-injection-vulnerabilities/#comment-491</guid>
		<description>The issue was fixed in WP 2.5.1.</description>
		<content:encoded><![CDATA[<p>The issue was fixed in WP 2.5.1.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on WordPress Multiple SQL Injection Vulnerabilities by peter sysko</title>
		<link>http://cyberinsecure.com/wordpress-multiple-sql-injection-vulnerabilities/#comment-489</link>
		<dc:creator>peter sysko</dc:creator>
		<pubDate>Thu, 12 Jun 2008 02:43:34 +0000</pubDate>
		<guid>http://cyberinsecure.com/wordpress-multiple-sql-injection-vulnerabilities/#comment-489</guid>
		<description>pleast visit http://www.php.net/manual/en/function.mysql-real-escape-string.php
 to view best practice to prevent sql injections in php/mysql.. if wordpress does not use mysql_real_escape_string correctly or at all, this could be a serious issue for hundreds of thousands of wordpress installations! i'm staing notified to see if anyone else comments here.</description>
		<content:encoded><![CDATA[<p>pleast visit <a href="http://www.php.net/manual/en/function.mysql-real-escape-string.php" rel="nofollow">http://www.php.net/manual/en/function.mysql-real-escape-string.php</a><br />
 to view best practice to prevent sql injections in php/mysql.. if wordpress does not use mysql_real_escape_string correctly or at all, this could be a serious issue for hundreds of thousands of wordpress installations! i&#8217;m staing notified to see if anyone else comments here.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Social Networks Information Sharing Flaw Exposes Private MySpace Users Photos by CyberInsecure</title>
		<link>http://cyberinsecure.com/social-networks-information-sharing-exposes-private-myspace-photos-due-to-a-privacy-flaw/#comment-479</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Tue, 10 Jun 2008 07:08:26 +0000</pubDate>
		<guid>http://cyberinsecure.com/social-networks-information-sharing-exposes-private-myspace-photos-due-to-a-privacy-flaw/#comment-479</guid>
		<description>According to some users reports, the Myspace widget has been removed and it does not work anymore.</description>
		<content:encoded><![CDATA[<p>According to some users reports, the Myspace widget has been removed and it does not work anymore.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Social Networks Information Sharing Flaw Exposes Private MySpace Users Photos by Mike</title>
		<link>http://cyberinsecure.com/social-networks-information-sharing-exposes-private-myspace-photos-due-to-a-privacy-flaw/#comment-478</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Tue, 10 Jun 2008 06:17:52 +0000</pubDate>
		<guid>http://cyberinsecure.com/social-networks-information-sharing-exposes-private-myspace-photos-due-to-a-privacy-flaw/#comment-478</guid>
		<description>Has this been fixed?</description>
		<content:encoded><![CDATA[<p>Has this been fixed?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Stolen Database Being Used To Spam Stickam Users by Doug Asker</title>
		<link>http://cyberinsecure.com/stolen-database-being-used-to-spam-stickam-users/#comment-476</link>
		<dc:creator>Doug Asker</dc:creator>
		<pubDate>Mon, 09 Jun 2008 01:21:34 +0000</pubDate>
		<guid>http://cyberinsecure.com/stolen-database-being-used-to-spam-stickam-users/#comment-476</guid>
		<description>It seems that the social networking movement will be stopped in its tracks if people loose confidence in those who store their data. Social networking companies need good and effective spam bots but also, and more importantly, human intervention. Faceparty in the UK had recently had to kill their chat rooms because of abuse. Effective moderation will just have to be seen as a cost of doing business in this space!

-Doug Asker</description>
		<content:encoded><![CDATA[<p>It seems that the social networking movement will be stopped in its tracks if people loose confidence in those who store their data. Social networking companies need good and effective spam bots but also, and more importantly, human intervention. Faceparty in the UK had recently had to kill their chat rooms because of abuse. Effective moderation will just have to be seen as a cost of doing business in this space!</p>
<p>-Doug Asker</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hacked Comcast.net Leaves Users Without Email Access by CyberInsecure</title>
		<link>http://cyberinsecure.com/hacked-comcastnet-leaves-users-without-email-access/#comment-438</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Fri, 30 May 2008 09:56:00 +0000</pubDate>
		<guid>http://cyberinsecure.com/hacked-comcastnet-leaves-users-without-email-access/#comment-438</guid>
		<description>According to DSLReports forums, the outage is still going on, for 24 hours already.

Thanks, Keith, for bringing this to our attention.</description>
		<content:encoded><![CDATA[<p>According to DSLReports forums, the outage is still going on, for 24 hours already.</p>
<p>Thanks, Keith, for bringing this to our attention.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Hacked Comcast.net Leaves Users Without Email Access by Brandon Cosio</title>
		<link>http://cyberinsecure.com/hacked-comcastnet-leaves-users-without-email-access/#comment-437</link>
		<dc:creator>Brandon Cosio</dc:creator>
		<pubDate>Fri, 30 May 2008 04:46:23 +0000</pubDate>
		<guid>http://cyberinsecure.com/hacked-comcastnet-leaves-users-without-email-access/#comment-437</guid>
		<description>Honestly, do hackers have a freakin life or do they spend their whole day sitting at a computer trying to f*** up peoples lives. How am I supposed to know i I got the job at Best Buy. Hackers need to get a life and needto get laid!</description>
		<content:encoded><![CDATA[<p>Honestly, do hackers have a freakin life or do they spend their whole day sitting at a computer trying to f*** up peoples lives. How am I supposed to know i I got the job at Best Buy. Hackers need to get a life and needto get laid!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Adobe Flash Vulnerability Exploited In Latest Mass SQL Injection Attack by CyberInsecure</title>
		<link>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-435</link>
		<dc:creator>CyberInsecure</dc:creator>
		<pubDate>Thu, 29 May 2008 20:20:37 +0000</pubDate>
		<guid>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-435</guid>
		<description>Updated. Thanks Zach Stepek, JD, Steve and Corey.</description>
		<content:encoded><![CDATA[<p>Updated. Thanks Zach Stepek, JD, Steve and Corey.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Adobe Flash Vulnerability Exploited In Latest Mass SQL Injection Attack by Corey</title>
		<link>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-434</link>
		<dc:creator>Corey</dc:creator>
		<pubDate>Thu, 29 May 2008 19:38:11 +0000</pubDate>
		<guid>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-434</guid>
		<description>Correction... the latest Flash player is immune from this vulnerability 9.0.124. Just fyi.</description>
		<content:encoded><![CDATA[<p>Correction&#8230; the latest Flash player is immune from this vulnerability 9.0.124. Just fyi.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Adobe Flash Vulnerability Exploited In Latest Mass SQL Injection Attack by Steve</title>
		<link>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-433</link>
		<dc:creator>Steve</dc:creator>
		<pubDate>Thu, 29 May 2008 19:35:59 +0000</pubDate>
		<guid>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-433</guid>
		<description>My contacts in Adobe say this is not true.</description>
		<content:encoded><![CDATA[<p>My contacts in Adobe say this is not true.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Adobe Flash Vulnerability Exploited In Latest Mass SQL Injection Attack by Zach Stepek</title>
		<link>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-432</link>
		<dc:creator>Zach Stepek</dc:creator>
		<pubDate>Thu, 29 May 2008 19:35:28 +0000</pubDate>
		<guid>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-432</guid>
		<description>The information listed here is incorrect. Check the appropriate security websites and Adobe's website to see the full details. This issue was addressed in the last Flash Player update.</description>
		<content:encoded><![CDATA[<p>The information listed here is incorrect. Check the appropriate security websites and Adobe&#8217;s website to see the full details. This issue was addressed in the last Flash Player update.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on New Adobe Flash Vulnerability Exploited In Latest Mass SQL Injection Attack by John Dowdell</title>
		<link>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-431</link>
		<dc:creator>John Dowdell</dc:creator>
		<pubDate>Thu, 29 May 2008 19:31:15 +0000</pubDate>
		<guid>http://cyberinsecure.com/new-adobe-flash-vulnerability-exploited-in-latest-mass-sql-injection-attack/#comment-431</guid>
		<description>&lt;em&gt;"At this moment there is no known patch available from Adobe, and no known workaround."&lt;/em&gt;

uhm, if you just use the current version, then you're protected from those Chinese hackers who followed Mark Dowd's blueprint.
http://blogs.adobe.com/psirt

(The "injection" was to HTML pages, and shows how normal websites are not always protected from hackers inserting evil links into good pages. Those hacked sites just pointed to foreign servers hosting malformed SWF.)

jd/adobe</description>
		<content:encoded><![CDATA[<p><em>&#8220;At this moment there is no known patch available from Adobe, and no known workaround.&#8221;</em></p>
<p>uhm, if you just use the current version, then you&#8217;re protected from those Chinese hackers who followed Mark Dowd&#8217;s blueprint.<br />
<a href="http://blogs.adobe.com/psirt" rel="nofollow">http://blogs.adobe.com/psirt</a></p>
<p>(The &#8220;injection&#8221; was to HTML pages, and shows how normal websites are not always protected from hackers inserting evil links into good pages. Those hacked sites just pointed to foreign servers hosting malformed SWF.)</p>
<p>jd/adobe</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Yahoo Banner Ads Infecting Visitors With Malware by Sourced &#187; Sourced &#187; Windows Security Recommendations</title>
		<link>http://cyberinsecure.com/yahoo-banner-ads-infecting-visitors-with-malware/#comment-410</link>
		<dc:creator>Sourced &#187; Sourced &#187; Windows Security Recommendations</dc:creator>
		<pubDate>Sun, 25 May 2008 10:58:28 +0000</pubDate>
		<guid>http://cyberinsecure.com/yahoo-banner-ads-infecting-visitors-with-malware/#comment-410</guid>
		<description>[...] It&#8217;s not that my clients did anything wrong, most swear that the last healthy, operational session on the computer consisted of some simple email or an instant messenger session. And I believe them, especially since I noticed many victims of this little surge were using Yahoo email accounts. [...]</description>
		<content:encoded><![CDATA[<p>[&#8230;] It&#8217;s not that my clients did anything wrong, most swear that the last healthy, operational session on the computer consisted of some simple email or an instant messenger session. And I believe them, especially since I noticed many victims of this little surge were using Yahoo email accounts. [&#8230;]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Another SQL Injection Worm Making Rounds With 4000 Websites Infected by Dave</title>
		<link>http://cyberinsecure.com/another-sql-injection-worm-making-rounds-with-4000-websites-infected/#comment-340</link>
		<dc:creator>Dave</dc:creator>
		<pubDate>Tue, 13 May 2008 19:28:35 +0000</pubDate>
		<guid>http://cyberinsecure.com/another-sql-injection-worm-making-rounds-with-4000-websites-infected/#comment-340</guid>
		<description>The method of attack is a POST to an SQL database.  There are few if any scanners that detect the POST vulnerability if the code is GET protected. A manual review of any code having access to a database would be in order.  Search all files for the following string "request.querystring".  This string limits the SQL injection filtering to GETS and does not filter POSTS.  To fix the problem, remove ".querystring".  There may be other attack vectors but I have seen this one successful on sites scanned and found to be safe by several security scanners.</description>
		<content:encoded><![CDATA[<p>The method of attack is a POST to an SQL database.  There are few if any scanners that detect the POST vulnerability if the code is GET protected. A manual review of any code having access to a database would be in order.  Search all files for the following string &#8220;request.querystring&#8221;.  This string limits the SQL injection filtering to GETS and does not filter POSTS.  To fix the problem, remove &#8220;.querystring&#8221;.  There may be other attack vectors but I have seen this one successful on sites scanned and found to be safe by several security scanners.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
