<?xml version="1.0" encoding="UTF-8"?><!-- generator="WordPress/2.6" -->
<rss version="0.92">
<channel>
	<title>Infosec Pals</title>
	<link>http://infosecpals.com/blog</link>
	<description>Collective blog on Infosec, technology and gadgets!</description>
	<lastBuildDate>Tue, 27 Oct 2009 03:44:57 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>Open Source Alternatives to PGP Desktop/SDA</title>
		<description><![CDATA[PGP Desktop products (Pro/Home) provide a neat set of features for all your email encryption, file and disk encryption needs in one nice package but for a price. However there are open source alternatives that offer similar features, which are more than enough for home and small business users. PGP Desktop offers great set of [...]]]></description>
		<link>http://infosecpals.com/blog/2008/open-source-alternatives-to-pgp-desktopsda</link>
			</item>
	<item>
		<title>Polymorphic ECMAScript Generator!</title>
		<description><![CDATA[JavaScript (in cyrptic speak ECMAScript) worms are becoming increasingly common, so are advances in anti-detection. Heard of polymorphic (code changing) viruses the same concept has been observed in recent worms as well. Detecting polymorphic code is difficult and Gareth Heyes has a nice article on why it is a challenge in javascript. To prove his [...]]]></description>
		<link>http://infosecpals.com/blog/2008/polymorphic-ecmascript-generator</link>
			</item>
	<item>
		<title>Adobe AIR Security</title>
		<description><![CDATA[Adobe recently launch of AIR, previously know as Apollo, a cross-platform framework to deploy flash style applications to the desktop and web. The new applications are called RIA&#8217;s - Rich Internet Applications. Every time there is a new web offering it is subject to security evaluations by many curious minds, AIR will be no exception. [...]]]></description>
		<link>http://infosecpals.com/blog/2008/adobe-air-security</link>
			</item>
	<item>
		<title>Stealing Encrypted Data !</title>
		<description><![CDATA[The Center for Information Technology policy group at Princeton university published a finding in which they showed how simple it is to break “Encrypted Hard drives” using cold boot attack.
This attack as described in the paper is very simple and can be performed by an average guy.  The attacks exploit the DRAM remanence effects [...]]]></description>
		<link>http://infosecpals.com/blog/2008/stealing-encrypted-data</link>
			</item>
	<item>
		<title>UMA FemtoCell Security Concerns</title>
		<description><![CDATA[Recently completed a write up on Unlicenced Mobile Access (UMA) and FemtoCell Security Concerns. It&#8217;s available online under the articles section, check it out.
]]></description>
		<link>http://infosecpals.com/blog/2008/uma-femtocell-security-concerns</link>
			</item>
	<item>
		<title>Quick and Dirty Fuzzing</title>
		<description><![CDATA[I&#8217;m a bit late into the fuzzing game, and recently I was thrown to do few short projects that involved third-party server components.  Though tools like sulley and spike produces good results, especially since you can fuzz in depth with several test cases, but if you are short on time and haven&#8217;t had a [...]]]></description>
		<link>http://infosecpals.com/blog/2008/quick-and-dirty-fuzzing</link>
			</item>
	<item>
		<title>Top VoIP Vulnerabilities in 2008</title>
		<description><![CDATA[Sipera recently announced its list of Top 5 VoIP Vulnerabilities in 2007. A similar more detailed list was also released &#8220;Top 9 VoIP Threats And Vulnerabilities&#8221; by CMP Channel. Sipera has provided some input to the article so they are essentially the same list with a few more thrown in to make the list Top [...]]]></description>
		<link>http://infosecpals.com/blog/2008/top-voip-vulnerabilities-in-2008</link>
			</item>
	<item>
		<title>Phishing the Phishers</title>
		<description><![CDATA[DIY Phishing kits make it easier for even novice fraudsters to setup phishing sites. These point and click tools have a few variables that need to be configured and a phisher is all set to send spam emails hoping unsuspecting users will follow to their fake financial sites. Some phishing sites also use malware installers [...]]]></description>
		<link>http://infosecpals.com/blog/2008/phishing-the-phishers</link>
			</item>
	<item>
		<title>Secure DLP = endpoint + network</title>
		<description><![CDATA[Data leakage concerns have hit all time highs in 2007, a recent survey shows 71% of people fear a remote worker will lose their PII. Enterprises where quick to explorer Data Leakage Protection/Data Loss Prevention (DLP) products since 2003, however the software solutions where still being perfected then. These products seem to be have matured [...]]]></description>
		<link>http://infosecpals.com/blog/2008/secure-dlp</link>
			</item>
	<item>
		<title>OllyDbg as a TCP Proxy with Uhooker</title>
		<description><![CDATA[Greetings to one and all&#8230;I&#8217;m back after a fantastic vacation to India.  I was trying to look at interesting things to research about and I bumped across Hernan Ochoa&#8217;s blog and an interesting OllyDbg plugin called UHooker (i.e., Universal Hooker).  The UHooker is basically a plugin that can allow testers to hook into [...]]]></description>
		<link>http://infosecpals.com/blog/2008/ollydbg-as-a-tcp-proxy-with-uhooker</link>
			</item>
</channel>
</rss>
