<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>...........und der Admin hyperventilierte&#187; , &#8230;&#8230;&#8230;..und der Admin hyperventilierte</title>
	<atom:link href="http://www.malin-easy.de/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.malin-easy.de</link>
	<description>Security is not an option...</description>
	<lastBuildDate>Wed, 22 Sep 2010 22:24:23 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=abc</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Neuer Personalausweis&#8230; noch nicht da, aber jetzt schon geknackt!!!</title>
		<link>http://www.malin-easy.de/2010/09/23/neuer-personalausweis-noch-nicht-da-aber-jetzt-schon-geknackt/</link>
		<comments>http://www.malin-easy.de/2010/09/23/neuer-personalausweis-noch-nicht-da-aber-jetzt-schon-geknackt/#comments</comments>
		<pubDate>Wed, 22 Sep 2010 22:16:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[1 november]]></category>
		<category><![CDATA[deutschland]]></category>
		<category><![CDATA[personalausweis]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=305</guid>
		<description><![CDATA[Der digitale Personalausweis wird in Deutschland am 1. November 2010 eingeführt. Er ist so groß wie eine Scheckkarte und enthält neben Name, Geburtsdatum und Anschrift weitere persönliche Daten. Die Regierung lobt die Nutzungsmöglichkeiten bis hin zum Online-Einkauf.



Sie sind nur noch so groß wie Scheckkarten; auf einem Funkchip werden die Personendaten samt einem digitalen Foto zusätzlich [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/09/23/neuer-personalausweis-noch-nicht-da-aber-jetzt-schon-geknackt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Metasploit add exploit module for quicktime backdoor</title>
		<link>http://www.malin-easy.de/2010/08/31/metasploit-add-exploit-module-for-quicktime-backdoor/</link>
		<comments>http://www.malin-easy.de/2010/08/31/metasploit-add-exploit-module-for-quicktime-backdoor/#comments</comments>
		<pubDate>Tue, 31 Aug 2010 09:48:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[quicktime backdoor]]></category>
		<category><![CDATA[Schwachstelle]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=303</guid>
		<description><![CDATA[
Quelle: 
http://www.metasploit.com/redmine/projects/framework/repository/revisions/10192?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+metasploit%2Fdevelopment+(Metasploit+Development)

Metasploit Framework ist um einen weiteren Exploit reicher. 
This module exploits a memory trust issue in Apple QuickTime 7.6.7.
When processing a specially-crafted HTML page, the QuickTime ActiveX
control will treat a supplied parameter as a trusted pointer. It
will then use it as a COM-type pUnknown and lead to arbitrary code
execution. This exploit utilizes a combination [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/08/31/metasploit-add-exploit-module-for-quicktime-backdoor/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DLL Hijacking in Windows und haufenweise installierter Programme&#8230; is it a bug or is it a feature ;-)</title>
		<link>http://www.malin-easy.de/2010/08/29/dll-hijacking-in-windows-und-haufenweise-installierter-programme-is-it-a-bug-or-is-it-a-feature/</link>
		<comments>http://www.malin-easy.de/2010/08/29/dll-hijacking-in-windows-und-haufenweise-installierter-programme-is-it-a-bug-or-is-it-a-feature/#comments</comments>
		<pubDate>Sun, 29 Aug 2010 14:38:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=300</guid>
		<description><![CDATA[Microsoft bestätigte die Existenz dieser Sicherheitslücke am 23. August 2010 in Ihrem Security Advisory.

Gut, beleuchten wir das Problem einmal genauer. Nicht Windows allein stellt das Problem dar, sondern unzählige installierte Programme, die einen unsicheren Weg nutzen, um DLL-Dateien während ihrer Laufzeit dynamisch zu laden.
Eine offizielle Liste aller betroffenen Programme existiert derzeitig noch nicht. Jedoch lässt [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/08/29/dll-hijacking-in-windows-und-haufenweise-installierter-programme-is-it-a-bug-or-is-it-a-feature/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>DLL-Hijacking prof of concept&#8230;</title>
		<link>http://www.malin-easy.de/2010/08/27/dll-hijacking-prof-of-concept/</link>
		<comments>http://www.malin-easy.de/2010/08/27/dll-hijacking-prof-of-concept/#comments</comments>
		<pubDate>Fri, 27 Aug 2010 14:20:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Allgemein]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=301</guid>
		<description><![CDATA[Auf Grund des Posts über exploiting DLL hijacking von hdm, mal schnell den Exploit selbst ausprobiert&#8230; Windows XP Sp3 clean install ist das &#8220;Opfer.



Zusätzlich noch einige File-Extensions hinzugefügt, diese lassen sich beliebig auf weitere angreifbare Programme erweitern.
( group management ) .grp
( Digital ID File ) .p7c
( vCards ) .vcf
( address book files) .wab
Durch diese Vorgaben [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/08/27/dll-hijacking-prof-of-concept/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Metasploit add exploit module for cve-2010-08040</title>
		<link>http://www.malin-easy.de/2010/08/23/metasploit-add-exploit-module-for-cve-2010-08040/</link>
		<comments>http://www.malin-easy.de/2010/08/23/metasploit-add-exploit-module-for-cve-2010-08040/#comments</comments>
		<pubDate>Mon, 23 Aug 2010 06:29:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[cve-2010-08040]]></category>
		<category><![CDATA[Schwachstelle]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=298</guid>
		<description><![CDATA[
Quelle: 
http://www.metasploit.com/redmine/projects/framework/repository/revisions/10092?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+metasploit%2Fdevelopment+(Metasploit+Development)

Metasploit Framework ist um einen weiteren Exploit reicher.
This module exploits a vulnerability in Java Runtime Environment
that allows an untrusted method to run in a privileged context. The
vulnerability affects version 6 prior to update 19 and version 5
prior to update 23.
References:
http://cve.mitre.org/cgi-bin/cvename.cgi?name=2010-0840
http://www.osvdb.org/63483
http://slightlyrandombrokenthoughts.blogspot.com/2010/04/java-trusted-method-
chaining-cve-2010.html

]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/08/23/metasploit-add-exploit-module-for-cve-2010-08040/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Metasploit add exploit module for sonicwall aventail activex format string</title>
		<link>http://www.malin-easy.de/2010/08/20/metasploit-add-exploit-module-for-sonicwall-aventail-activex-format-string/</link>
		<comments>http://www.malin-easy.de/2010/08/20/metasploit-add-exploit-module-for-sonicwall-aventail-activex-format-string/#comments</comments>
		<pubDate>Fri, 20 Aug 2010 06:20:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Metasploit]]></category>
		<category><![CDATA[Schwachstelle]]></category>
		<category><![CDATA[sonicwall aventail activex format string]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=296</guid>
		<description><![CDATA[
Quelle:
http://www.metasploit.com/redmine/projects/framework/repository/revisions/10069?utm_source=feedburner&#038;utm_medium=feed&#038;utm_campaign=Feed%3A+metasploit%2Fdevelopment+(Metasploit+Development)

This module exploits a format string vulnerability within version
10.0.4.x and 10.5.1 of the SonicWALL Aventail SSL-VPN Endpoint
Interrogator/Installer ActiveX control (epi.dll). By calling the
&#8216;AuthCredential&#8217; method with a specially crafted Unicode format
string, an attacker can cause memory corruption and execute
arbitrary code. Unfortunately, it does not appear to be possible to
indirectly re-use existing stack data for more reliable
exploitation. [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/08/20/metasploit-add-exploit-module-for-sonicwall-aventail-activex-format-string/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2010.07.06 Gesammelte Werke :-)</title>
		<link>http://www.malin-easy.de/2010/07/06/2010-07-06-gesammelte-werke/</link>
		<comments>http://www.malin-easy.de/2010/07/06/2010-07-06-gesammelte-werke/#comments</comments>
		<pubDate>Tue, 06 Jul 2010 12:23:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Schwachstellen]]></category>
		<category><![CDATA[Schwachstelle]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=294</guid>
		<description><![CDATA[
Pre Multi-Vendor Shopping Malls SQL Injection Vulnerability
&#38; Auth Bypass Vulnerabilty.
http://www.exploit-db.com/exploits/14245

Lyrics V3 Engine SQL Injection Vulnerability
http://www.exploit-db.com/exploits/14244
BS Events Directory (articlesdetails.php) SQL Injection
Vulnerability Proof of Concept
http://www.exploit-db.com/exploits/14243
BS Classifieds Ads (articlesdetails.php) SQL Injection
Vulnerability Proof of Concept
http://www.exploit-db.com/exploits/14242
BS Business Directory (articlesdetails.php) SQL Injection
Vulnerability Proof of Concept
http://www.exploit-db.com/exploits/14241
BS Auto Classifieds (info.php) SQL Injection Vulnerability
Proof of Concept
http://www.exploit-db.com/exploits/14240
Auto Dealer &#60;= SQL Injection Vulnerability Proof of Concept
http://www.exploit-db.com/exploits/14239
BS [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/07/06/2010-07-06-gesammelte-werke/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Die interessantesten Artikel der ersten Woche Juli</title>
		<link>http://www.malin-easy.de/2010/07/05/die-interessantesten-artikel-der-ersten-woche-juli/</link>
		<comments>http://www.malin-easy.de/2010/07/05/die-interessantesten-artikel-der-ersten-woche-juli/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 10:38:09 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[Artikel]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=290</guid>
		<description><![CDATA[Events

HiTB News
HiTB Konferenz in Dubaï and Kuala Lumpur

Hack in the Box Day #1 Wrap Up – rootshell.be
Hack in the Box Day #2 Wrap Up – rootshell.be





Notes from OWASP Bay Area Security Summit – michael-coates.blogspot.com
Interessantes zu dynamischen Identifikation und Quarantänte von schädlichen Scripten&#8230;
Hacking the Next Hope Badge – travisgoodspeed.blogspot.com
MSP430 port of the OpenBeacon firmware.

Resources:

Comparing web application [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/07/05/die-interessantesten-artikel-der-ersten-woche-juli/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2010.07.05 Gesammelte Werke :-)</title>
		<link>http://www.malin-easy.de/2010/07/05/2010-07-05-gesammelte-werke/</link>
		<comments>http://www.malin-easy.de/2010/07/05/2010-07-05-gesammelte-werke/#comments</comments>
		<pubDate>Mon, 05 Jul 2010 09:49:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Schwachstellen]]></category>
		<category><![CDATA[Schwachstelle]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=291</guid>
		<description><![CDATA[
SasCam 2.7 ActiveX Head Buffer Overflow
http://www.exploit-db.com/exploits/14215 

bbPress 1.0.2 [CSRF ] change admin password
http://www.exploit-db.com/exploits/14214 
Joomla Component Sef (com_sef) &#8211; LFI Vulnerability
http://www.exploit-db.com/exploits/14213 
Joomla NijnaMonials Component (com_ninjamonials) Blind SQL Injection Vulnerability
http://www.exploit-db.com/exploits/14211 
Joomla Front-edit Address Book Component (com_addressbook) Blind SQL Injection Vulnerability
http://www.exploit-db.com/exploits/14210 
Joomla Front-End Article Manager System Upload Vulnerability
http://www.exploit-db.com/exploits/14209 
Sandbox v2.0.2 Local FIle Inclusion Vulnerability
http://www.exploit-db.com/exploits/14208 
Joomla Phoca Gallery Component [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/07/05/2010-07-05-gesammelte-werke/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>2010.07.02 Gesammelte Werke :-)</title>
		<link>http://www.malin-easy.de/2010/07/02/2010-07-02-gesammelte-werke/</link>
		<comments>http://www.malin-easy.de/2010/07/02/2010-07-02-gesammelte-werke/#comments</comments>
		<pubDate>Fri, 02 Jul 2010 08:50:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Schwachstellen]]></category>
		<category><![CDATA[Schwachstelle]]></category>

		<guid isPermaLink="false">http://www.malin-easy.de/?p=288</guid>
		<description><![CDATA[
MooreAdvice (productlist.asp) SQL injection Vulnerable
http://www.exploit-db.com/exploits/14169 

VGM Forbin (article.asp) SQL injection Vulnerable
http://www.exploit-db.com/exploits/14168 
Docmint =&#62; 2.1 XSS&#124;HTML&#124;URL Injection/Redirecting Vulnerability
http://www.exploit-db.com/exploits/14167 
Bit Weaver v2.7 Local File Inclusion Vulnerability
http://www.exploit-db.com/exploits/14166 
iScripts EasyBiller Cross Site Scripting Vulnerabilities
http://www.exploit-db.com/exploits/14165 
iScripts CyberMatch 1.0 Blind SQL Injection Vulnerability
http://www.exploit-db.com/exploits/14164 
iScripts ReserveLogic 1.0 SQL Injection Vulnerability
http://www.exploit-db.com/exploits/14163 
iScripts EasySnaps 2.0 Multiple SQL Injection Vulnerabilities
http://www.exploit-db.com/exploits/14162 
Joomla Component Remository (com_remository) LFI
http://www.exploit-db.com/exploits/14161 [...]]]></description>
		<wfw:commentRss>http://www.malin-easy.de/2010/07/02/2010-07-02-gesammelte-werke/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

