<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ESISS</title>
	<atom:link href="http://www.esiss.ac.uk/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.esiss.ac.uk</link>
	<description>EMMAN Shared Information Security Service</description>
	<lastBuildDate>Thu, 26 Jan 2012 17:11:41 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>PcAnywhere users at increased security risk</title>
		<link>https://www.esiss.ac.uk/general/pcanywhere-users-at-increased-security-risk/</link>
		<comments>https://www.esiss.ac.uk/general/pcanywhere-users-at-increased-security-risk/#comments</comments>
		<pubDate>Thu, 26 Jan 2012 10:17:03 +0000</pubDate>
		<dc:creator>Mohamed Imran</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2358</guid>
		<description><![CDATA[Following reports of the PcAnywhere product source code stolen, its parent company Symantec have released a security advisory stating user of version 12.0, 12.1 and 12.5 are at an &#8216;increased risk&#8217; and also includes recommendations on how to potentially mitigate the risks. This advisory can be found here and the security recommendations document is available [...]]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/pcanywhere-users-at-increased-security-risk/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Linux local root exploit</title>
		<link>https://www.esiss.ac.uk/general/linux-local-root-exploit-2/</link>
		<comments>https://www.esiss.ac.uk/general/linux-local-root-exploit-2/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 12:01:30 +0000</pubDate>
		<dc:creator>paulwhitton</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2350</guid>
		<description><![CDATA[Code has been released which exploits a vulnerability in linux kernel version >=2.6.39 which can give a local user root level access. The code exploits the following vulnerability, announced on the 18th January 2012. CVE-2012-0056 kernel: proc: /proc//mem mem_write insufficient permission checking Details of the exploit and full write up can be found here: http://blog.zx2c4.com/749]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/linux-local-root-exploit-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Screen locking programs on Xorg 1.11</title>
		<link>https://www.esiss.ac.uk/general/screen-locking-programs-on-xorg-1-11/</link>
		<comments>https://www.esiss.ac.uk/general/screen-locking-programs-on-xorg-1-11/#comments</comments>
		<pubDate>Thu, 19 Jan 2012 20:19:50 +0000</pubDate>
		<dc:creator>paulwhitton</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2340</guid>
		<description><![CDATA[A vulnerability has been found for all versions of xorg 1.11 whereby anyone can unlock a locked screen by pressing ctrl,alt and the * key from the number pad. We have tested this on a few systems and can confirm that revisions of xorg 1.11.x do seem to be vulnerable. The original report can be [...]]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/screen-locking-programs-on-xorg-1-11/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Scams targeting domain name registrants</title>
		<link>https://www.esiss.ac.uk/general/scams-targeting-domain-name-registrants/</link>
		<comments>https://www.esiss.ac.uk/general/scams-targeting-domain-name-registrants/#comments</comments>
		<pubDate>Tue, 17 Jan 2012 12:08:28 +0000</pubDate>
		<dc:creator>paulwhitton</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2318</guid>
		<description><![CDATA[Knowthenet.org.uk are reporting about a scam targeting domain name registrants. In the scam, registrants are contacted by telephone, by someone claiming to have 3rd party ownership of the registrant’s domain. They then make a demand for money or they will sell the domain on. Be aware of unsolicited calls regarding your domain names and if [...]]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/scams-targeting-domain-name-registrants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Adobe Flash &#8211; 0 day vulnerabilities</title>
		<link>https://www.esiss.ac.uk/general/adobe-flash-0-day-vulnerabilities/</link>
		<comments>https://www.esiss.ac.uk/general/adobe-flash-0-day-vulnerabilities/#comments</comments>
		<pubDate>Fri, 09 Dec 2011 10:21:24 +0000</pubDate>
		<dc:creator>Mohamed Imran</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2294</guid>
		<description><![CDATA[Two zero day vulnerabilities affecting Adobe flash have been reported which could be exploited to compromise a users machine. The version affected are &#60; 11.1.102.55 and has been classified as highly critical. The vulnerability can be exploited using specially crafted .swf fils so it is advisable not to browse flash content from untrusted websites. Further information [...]]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/adobe-flash-0-day-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zero Day Vulnerability in Adobe Reader/Acrobat</title>
		<link>https://www.esiss.ac.uk/general/zero-day-vulnerability-in-adobe-reader/</link>
		<comments>https://www.esiss.ac.uk/general/zero-day-vulnerability-in-adobe-reader/#comments</comments>
		<pubDate>Tue, 06 Dec 2011 21:47:20 +0000</pubDate>
		<dc:creator>paulwhitton</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2266</guid>
		<description><![CDATA[Adobe have released a warning about a zero day vulnerability in adobe reader versions affected are: Adobe Reader X (10.1.1) and earlier versions for Windows and Macintosh Adobe Reader 9.4.6 and earlier 9.x versions for UNIX Adobe Acrobat X (10.1.1) and earlier versions for Windows and Macintosh. This is being actively exploited in the wild. [...]]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/zero-day-vulnerability-in-adobe-reader/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>BIND 9 resolver crash</title>
		<link>https://www.esiss.ac.uk/general/bind-9-resolver-crash/</link>
		<comments>https://www.esiss.ac.uk/general/bind-9-resolver-crash/#comments</comments>
		<pubDate>Wed, 16 Nov 2011 16:08:39 +0000</pubDate>
		<dc:creator>paulwhitton</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2247</guid>
		<description><![CDATA[ISC are reporting a serious problem in all versions of BIND 9 which perform recursive queries. From the ISC website: Organizations across the Internet are reporting crashes interrupting service on BIND 9 nameservers performing recursive queries. Affected servers crash after logging an error in query.c with the following message: &#8220;INSIST(! dns_rdataset_isassociated(sigrdataset))&#8221; Multiple versions are reported [...]]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/bind-9-resolver-crash/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Critical Alert- Microsoft Windows Remote Code Execution</title>
		<link>https://www.esiss.ac.uk/general/critical-alert-microsoft-windows-remote-code-execution/</link>
		<comments>https://www.esiss.ac.uk/general/critical-alert-microsoft-windows-remote-code-execution/#comments</comments>
		<pubDate>Wed, 09 Nov 2011 12:40:06 +0000</pubDate>
		<dc:creator>paulwhitton</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2236</guid>
		<description><![CDATA[MS11-083 Vulnerability in TCP/IP Could Allow Remote Code Execution (2588516) &#8211; Windows Vista, Windows Server 2008, Windows 7 (All versions) As part of yesterdays patch Tuesday Microsoft announced a critical vulnerability bulletin (Microsoft Level 2). The vulnerability could allow remote code execution if an attacker sends a continuous flow of specially crafted UDP packets to [...]]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/critical-alert-microsoft-windows-remote-code-execution/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oracle releases critical security updates &#8211; October 2011</title>
		<link>https://www.esiss.ac.uk/general/oracle-releases-critical-security-updates-october-2011/</link>
		<comments>https://www.esiss.ac.uk/general/oracle-releases-critical-security-updates-october-2011/#comments</comments>
		<pubDate>Wed, 19 Oct 2011 16:15:34 +0000</pubDate>
		<dc:creator>Mohamed Imran</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2233</guid>
		<description><![CDATA[Oracle have released an advisory which informs of several security updates released for their various products including a recent Java security update. The nature of some of the vulnerabilities described in this advisory are critical and should be treated with high priority. The advisory consists of  57 updates and further information can be found here: http://www.oracle.com/technetwork/topics/security/cpuoct2011-330135.html]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/oracle-releases-critical-security-updates-october-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache HTTP security advisory</title>
		<link>https://www.esiss.ac.uk/general/apache-http-security-advisory/</link>
		<comments>https://www.esiss.ac.uk/general/apache-http-security-advisory/#comments</comments>
		<pubDate>Thu, 06 Oct 2011 10:15:23 +0000</pubDate>
		<dc:creator>Mohamed Imran</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">https://www.esiss.ac.uk/?p=2218</guid>
		<description><![CDATA[Product: Apache HTTP Affected module: mod_proxy Affected versions: httpd 1.3 (all versions), 2.x (all versions) A security advisory released describes a vulnerability in the &#8216;ReWriteRule&#8217; and &#8216;ProxyPassMatch&#8217; directives in Apache which could lead to internal information disclosure. This functions in the mod_proxy module is used to configure a reverse proxy using pattern matching. Apache configuration [...]]]></description>
		<wfw:commentRss>https://www.esiss.ac.uk/general/apache-http-security-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

