<?xml version="1.0" encoding="iso-8859-1"?><!-- Copyright (C) 2001-2009 - Developer Shed, LLC. -->
<rss version="2.0">
<channel>
<title>Security - RSS Feeds</title>
<link>http://www.devshed.com</link>
<description>Security - RSS Feeds</description>
<language>en-us</language>
<lastBuildDate>Thu, 26 Nov 2009 06:32:19 -0500</lastBuildDate>
<pubDate>Thu, 26 Nov 2009 06:32:19 -0500</pubDate>
<item><title>Critical Microsoft Visual Studio Security Patch Tuesday</title>
<pubDate>Sat, 25 Jul 2009 00:06:48 -0400</pubDate>
<link>http://www.devshed.com/c/a/Security/Critical-Microsoft-Visual-Studio-Security-Patch-Tuesday-0723209/?kc=rss</link>
<description>
<![CDATA[Microsoft is releasing a security patch for Visual Studio and another  moderate  rated patch for IE for almost all versions.  The patches are must-haves for developers that use Visual Studio and any internet explorer users.<br/>   -  Here comes another critical patch from Microsoft.   What it fixes is anyone's guess, but it affects almost all versions of Windows and .NET Visual Studio back to 2003.   Developers are encouraged to register their guess, but make your guesses after you apply the patch.
Speculation is that the Inter...]]></description>
<guid>http://www.devshed.com/c/a/Security/Critical-Microsoft-Visual-Studio-Security-Patch-Tuesday-0723209/?kc=rss</guid>
</item>
<item><title>US Faces Tech Security Expert Deficit</title>
<pubDate>Thu, 23 Jul 2009 01:14:08 -0400</pubDate>
<link>http://www.devshed.com/c/a/Security/US-Faces-Tech-Security-Expert-Deficit-10294/?kc=rss</link>
<description>
<![CDATA[Recent attacks against the United States IT security infrastructure has officials worried that, over the next decade, qualified cyber-security personnel will be at a premium; and a shortage.  The question is: how does the USA plan to lure and keep top tech talent to secure and protect the national information infrastructure?<br/>   -  There's a definite digital-divide starting, but it's not between the rich and the poor; it's between the IT Security expert haves and have-nots...and it's spreading from private companies all the way to the US Government.
Recent studies of the country's top IT management shows that a whopping 35%+ ...]]></description>
<guid>http://www.devshed.com/c/a/Security/US-Faces-Tech-Security-Expert-Deficit-10294/?kc=rss</guid>
</item>
<item><title>LAN Reconnaissance</title>
<pubDate>Thu, 13 Nov 2008 09:00:46 -0500</pubDate>
<link>http://www.devshed.com/c/a/Security/LAN-Reconnaissance/?kc=rss</link>
<description>
<![CDATA[If you're trying to keep your LAN secure, sometimes it helps to think like a cracker. This article shows you how to scout out a LAN, and how malicious hackers get around security. It is excerpted from chapter four of Security Power Tools, written by Bryan Burns et. al. (O'Reilly, 2007; ISBN: 0596009631). Copyright © 2007 O'Reilly Media, Inc. All rights reserved. Used with permission from the publisher. Available from booksellers or direct from O'Reilly Media.<br/>   -  This chapter covers LAN reconnaissance; specifically, it covers capturing packets and scoping out the LAN environment using ettercap-ng, p0f, and dsniff. When investigating a LAN, your goals can sometimes be at odds with each other. Are you trying to be quick? Is stealth a factor? Sometimes going fo...]]></description>
<guid>http://www.devshed.com/c/a/Security/LAN-Reconnaissance/?kc=rss</guid>
</item>
<item><title>An Epilogue to Cryptography</title>
<pubDate>Mon, 30 Jul 2007 09:00:47 -0400</pubDate>
<link>http://www.devshed.com/c/a/Security/An-Epilogue-to-Cryptography/?kc=rss</link>
<description>
<![CDATA[This is the last part of a three-part series covering encryption and decryption, with a focus on the algorithms used. If you have missed either the first or second part, I encourage you to check them out before reading this part.<br/>   -  Throughout this multi-part series we examined the coding of few individual encryption and decryption  algorithms. Please keep in mind that none of them were ultimately secure. With the quantum leaps that technologies  and computer resources have made  nowadays, their decryption would be quite easy e...]]></description>
<guid>http://www.devshed.com/c/a/Security/An-Epilogue-to-Cryptography/?kc=rss</guid>
</item>
<item><title>A Sequel to Cryptography</title>
<pubDate>Tue, 24 Jul 2007 09:00:48 -0400</pubDate>
<link>http://www.devshed.com/c/a/Security/A-Sequel-to-Cryptography/?kc=rss</link>
<description>
<![CDATA[This is the second part of a series covering cryptography algorithms. If by any chance you have missed its first part, I urge you to check it out right now. It is called  quot;An Introduction to Cryptography. quot; In order to understand this article, it is crucial to grasp the concepts explained in that part.<br/>   -  I have promised that in this article I will continue showing you real-world encryption algorithms and more specifically  that we are going to XOR. Throughout this part we will find out what exactly is XOR, how to implement it into an encryption algorithm, and ultimately a few techniques for breaking...]]></description>
<guid>http://www.devshed.com/c/a/Security/A-Sequel-to-Cryptography/?kc=rss</guid>
</item>
<item><title>An Introduction to Cryptography</title>
<pubDate>Mon, 23 Jul 2007 09:00:47 -0400</pubDate>
<link>http://www.devshed.com/c/a/Security/An-Introduction-to-Cryptography/?kc=rss</link>
<description>
<![CDATA[In the last few decades the science and study of cryptography has earned an outstanding reputation due to its insane applicability and efficiency. Cryptography is the science of message secrecy. Its importance is easily explicable -- it is used everywhere: online purchasing, secured money transfers, cellular phones, broadcast of TV channels, emails, confidential data, and so forth.  Our life would be quite different without cryptography.<br/>   -  This is the first article of a multi-part series. It serves the purpose of introducing you to  cryptography. I cannot promise an easy ride through this journey, but it will be a comprehensible and amazing one. As much as we'll get into this, we'll realize how complex cryptography can be. But that sh...]]></description>
<guid>http://www.devshed.com/c/a/Security/An-Introduction-to-Cryptography/?kc=rss</guid>
</item>
<item><title>Security Overview</title>
<pubDate>Thu, 30 Jun 2005 09:00:00 -0400</pubDate>
<link>http://www.devshed.com/c/a/Security/Security-Overview/?kc=rss</link>
<description>
<![CDATA[When we talk about “security” we know what we want, but describing it and making it happen can be different matters altogether. Network security has a natural conflict with network connectivity. The more an autonomous system opens itself up, the more risk it takes on. This, in turn, requires that more effort be applied to security enforcement tasks. This article is chapter eight of the book, Cisco: A Beginner's Guide, third edition, by Anthony Velte and Toby Velte (McGraw-Hill/Osborne, 2004, ISBN: 0072256354).<br/>   -  The concept of network security may seem somewhat of a moving target or several moving targets. When we talk about “security” we know what we want, but describing it and making it happen can be different matters altogether. Network security has a natural conflict with network connectivity. The more ...]]></description>
<guid>http://www.devshed.com/c/a/Security/Security-Overview/?kc=rss</guid>
</item>
<item><title>Network Security Assessment</title>
<pubDate>Thu, 19 May 2005 09:00:01 -0400</pubDate>
<link>http://www.devshed.com/c/a/Security/Network-Security-Assessment/?kc=rss</link>
<description>
<![CDATA[If you want to run a business with  a website, security must be high on 
your list of important matters to get right up front. In this article, you will 
learn about Internet-based network security assessment and penetration testing, 
which can help you determine your website's risk of being successfully attacked 
-- and what to do to fix any problems. It is taken from chapter one of the 
book Network Security Assessment by Chris McNab 
(O'Reilly, 2004; ISBN: 059600611X).<br/>   -  This chapter discusses at a high level the rationale behind Internet-based network security assessment and penetration testing. To retain complete control over your networks and data, you must take a proactive approach to security, an approach that starts with assessment to identify and categorize y...]]></description>
<guid>http://www.devshed.com/c/a/Security/Network-Security-Assessment/?kc=rss</guid>
</item>
<item><title>Firewalls</title>
<pubDate>Wed, 30 Mar 2005 09:00:01 -0500</pubDate>
<link>http://www.devshed.com/c/a/Security/Firewalls/?kc=rss</link>
<description>
<![CDATA[If you have ever wondered how to configure and run a secure open source firewall, look no further.  This book excerpt is from chapter three of Open Source Security Tools by Tony Howlett, ISBN 0321194438, copyright 2004. All rights reserved. It is reprinted with permission from Addison-Wesley Professional.<br/>   -  So now that you have a fairly secure operating system and know a few basic tricks, lets get into using some more complex security tools. This chapter describes how to configure and run a secure open source firewall. If you already have a firewall, you may still want to read this chapter if you need ...]]></description>
<guid>http://www.devshed.com/c/a/Security/Firewalls/?kc=rss</guid>
</item>
<item><title>What’s behind the curtain? Part II</title>
<pubDate>Mon, 28 Feb 2005 09:00:01 -0500</pubDate>
<link>http://www.devshed.com/c/a/Security/Whats-behind-the-curtain-Part-II/?kc=rss</link>
<description>
<![CDATA[In this second of a three-part series covering threats to computer security, we focus on attacks that are more specifically directed against a particular person or company.<br/>   -  Internet usage entails many risks. You surf the Internet to do your work and 
you end up with a system with degraded performance and an unexpected behavior. 
Congratulations! No, you did not win the lottery; you have just been hacked! 

In the first part of “Whats behind the curtain” article I e...]]></description>
<guid>http://www.devshed.com/c/a/Security/Whats-behind-the-curtain-Part-II/?kc=rss</guid>
</item>
<item><title>What’s behind the curtain? Part I</title>
<pubDate>Mon, 21 Feb 2005 09:00:00 -0500</pubDate>
<link>http://www.devshed.com/c/a/Security/Whats-behind-the-curtain-Part-I/?kc=rss</link>
<description>
<![CDATA[It's no secret that any computer connected to the Internet faces a wide array of security threats. These days, however, a business needs to be connected to the Internet just to do business. What can you do? Keep reading to learn more about risks you take, and what you can do to protect yourself and your company.<br/>   -  Introduction
Everyone who uses the Internet has encountered at least one security violation. Sometimes these violations go unnoticed by the security-unaware user, and other times we may found out about them after they have caused severe damage to our information and systems. The best approach to so...]]></description>
<guid>http://www.devshed.com/c/a/Security/Whats-behind-the-curtain-Part-I/?kc=rss</guid>
</item>
<item><title>Vectors</title>
<pubDate>Wed, 02 Feb 2005 09:00:22 -0500</pubDate>
<link>http://www.devshed.com/c/a/Security/Vectors/?kc=rss</link>
<description>
<![CDATA[Many of us who use use security products on our computers religiously are bewildered to find that we still get infected with malware. How does this happen? No matter what we do, our computers are constantly in touch with the vectors that carry malicious software. Thomas Greene explains what this means, and what we can do about it.<br/>   -    
NO DOUBT MOST OF US can sympathize with this Register reader:
Hi Mr. Greene, I have just read your article on the severe Windows security hole and I still cannot for the life of me fathom ports there are so many! I have been on line now for two years and have had to reformat my hard drive so ma...]]></description>
<guid>http://www.devshed.com/c/a/Security/Vectors/?kc=rss</guid>
</item>
<item><title>PKI: Looking at the Risks</title>
<pubDate>Mon, 24 Jan 2005 09:00:23 -0500</pubDate>
<link>http://www.devshed.com/c/a/Security/PKI-Looking-at-the-Risks/?kc=rss</link>
<description>
<![CDATA[Public key infrastructure (PKI) is an excellent technology to help users certify that the people or companies they are corresponding with are who they say they are. It has proven itself invaluable in e-commerce among other areas. As with any technology, however, it is not without its own security risks. Eliana Stavrou discusses these risks, and ways to minimize them.<br/>   -  To be  fair to the readers, I believe that it is time to explain  the possible risks and threats associated with Public Key Infrastructure (PKI). Until now, I have given you a lot of information on how to use PKI. (Editor's note: see Eliana Stavrou's articles on ASP Free). Although PKI is considered...]]></description>
<guid>http://www.devshed.com/c/a/Security/PKI-Looking-at-the-Risks/?kc=rss</guid>
</item>
<item><title>A Quick Look at Cross Site Scripting</title>
<pubDate>Tue, 04 Jan 2005 09:00:30 -0500</pubDate>
<link>http://www.devshed.com/c/a/Security/A-Quick-Look-at-Cross-Site-Scripting/?kc=rss</link>
<description>
<![CDATA[We may not be able to completely bulletproof our websites, but we can at least try to anticipate possible attacks and secure against them. Here is one you might not have heard of: cross site scripting. With just a bit of JavaScript, a malicious attacker can use it to cause all sorts of problems. To find out more about what it is, and how to prevent your website from becoming a victim, keep reading.<br/>   -  Introduction
The question keeps  spinning in our minds, just like a ball bouncing deeply inside the brain: is our website really secure? Surely, thats a very tough topic to answer. But one thing is true in  all  cases: there are not any websites “completely” safe from attacks. Given the uncontrolle...]]></description>
<guid>http://www.devshed.com/c/a/Security/A-Quick-Look-at-Cross-Site-Scripting/?kc=rss</guid>
</item>
<item><title>PKI Architectures: How to Choose One</title>
<pubDate>Tue, 26 Oct 2004 09:00:02 -0400</pubDate>
<link>http://www.devshed.com/c/a/Security/PKI-Architectures-How-to-Choose-One/?kc=rss</link>
<description>
<![CDATA[In the Internets world of insecurities, many actions should be taken  to 
enhance the defense of each and every network. Many solutions exist that provide 
a level of security, none however being bulletproof. The best approach is to 
combine a variety of mechanisms that will supplement one another. In this 
article I will discuss a technology that is considered to be the new trend and a 
favored option among network implementers, that is Public Key Infrastructure 
(PKI).<br/>   -  Introduction
Deciding to implement a PKI architecture is not an easy task to do. There are many factors which must be taken into consideration if we want to benefit from PKI technology. 
Before moving into explaining various PKI architectures and the criterion we use to choose the one that best su...]]></description>
<guid>http://www.devshed.com/c/a/Security/PKI-Architectures-How-to-Choose-One/?kc=rss</guid>
</item>
</channel>
</rss>
