<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Daily Dave</title>
    <link>http://seclists.org/#dailydave</link>
    <atom:link href="http://seclists.org/rss/dailydave.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>This technical discussion list covers vulnerability research, exploit development, and security events/gossip.  It was started by &lt;a href=&quot;http://www.immunitysec.com/&quot;&gt;ImmunitySec&lt;/a&gt; founder Dave Aitel and many security luminaries participate.  Many posts simply advertise Immunity products, but you can&#39;t really fault Dave for being self-promotional on a list named DailyDave.</description>
    <pubDate>Fri, 06 Nov 2009 02:00:04 GMT</pubDate>
    <lastBuildDate>Fri, 06 Nov 2009 02:00:04 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>MITM Attack on Smartphones whitepaper</title>
    <link>http://seclists.org/dailydave/2009/q4/39</link>
    <description>&lt;p&gt;Posted by Mayank Aggarwal on Nov 05&lt;/p&gt;SMobile has released a detailed report on research indicating that smartphone users are just as susceptible to &lt;br&gt;
man-in-the-middle (MITM) attacks as PC users. This report details the results of attempts to produce MITM attacks to &lt;br&gt;
determine whether it is possible to intercept SSL encrypted communications between various smartphone devices and &lt;br&gt;
servers. Of the devices that were tested, each of the major smartphone operating systems appeared to lack...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 01:54:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/39</guid>
  </item>


  <item>
    <title>Re: PrevX and other projects</title>
    <link>http://seclists.org/dailydave/2009/q4/38</link>
    <description>&lt;p&gt;Posted by Shane Macaulay on Oct 30&lt;/p&gt;The chart on their main page would be a lot more compelling if they had&lt;br&gt;
conversely applied whatever method they used to collect that information.&lt;br&gt;
&lt;br&gt;
&amp;quot;&amp;quot;&amp;quot;&amp;quot;These statistics are provided to show that all vendors miss threats&lt;br&gt;
and cannot be interpreted to compare the effectiveness of one product to&lt;br&gt;
another.&amp;quot;&amp;quot;&amp;quot;&amp;quot;&amp;quot;&lt;br&gt;
&lt;br&gt;
That seems to indicate they would show us their failure rate when&lt;br&gt;
compared to these vendors?  And...&lt;br&gt;</description>
    <pubDate>Fri, 30 Oct 2009 12:06:38 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/38</guid>
  </item>


  <item>
    <title>PrevX and other projects</title>
    <link>http://seclists.org/dailydave/2009/q4/37</link>
    <description>&lt;p&gt;Posted by dave on Oct 28&lt;/p&gt;So you can read one Immunity deliverable linked here:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.prevx.com/&quot;&gt;http://www.prevx.com/&lt;/a&gt; (look for &amp;quot;Independent Review&amp;quot;).&lt;br&gt;
&lt;br&gt;
Likewise, if you have wondered where all the Immunity Debugger scripts&lt;br&gt;
ran off to, they were on the old Immunity Forum. We ripped the old forum&lt;br&gt;
content out of the old database and imported into the new hotness, so&lt;br&gt;
you can seem them all here:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://forum.immunityinc.com/&quot;&gt;https://forum.immunityinc.com/&lt;/a&gt;. I don't think Google spiders HTTPS sites&lt;br&gt;
for some reason...&lt;br&gt;</description>
    <pubDate>Wed, 28 Oct 2009 18:24:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/37</guid>
  </item>


  <item>
    <title>B. Aggressive. B. E. Aggressive. (or &quot;One 0day is	enough&quot;)</title>
    <link>http://seclists.org/dailydave/2009/q4/36</link>
    <description>&lt;p&gt;Posted by dave on Oct 27&lt;/p&gt;When you go into security consulting engagements with a new business&lt;br&gt;
unit you usually face a few questions from the developers and business&lt;br&gt;
owners. &amp;quot;What is it exactly that you're going to tell us?&amp;quot;&lt;br&gt;
&lt;br&gt;
We always answer this the same way: &amp;quot;Things that will surprise you.&amp;quot;&lt;br&gt;
&lt;br&gt;
Most developers have read a lot about security these days - they&lt;br&gt;
understand SQL Injection, Cross Site Scripting, access control, not to&lt;br&gt;
use their own...&lt;br&gt;</description>
    <pubDate>Tue, 27 Oct 2009 15:56:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/36</guid>
  </item>
  <item>
    <title>Last mile || InfoSys 2010 [ICAS, ICNS, INTENSIVE,	LMPCNA] March 7-13, 2010 - Cancun, Mexico</title>
    <link>http://seclists.org/dailydave/2009/q4/35</link>
    <description>&lt;p&gt;Posted by Jaime Lloret Mauri on Oct 26&lt;/p&gt;Last mile || InfoSys 2010 [ICAS, ICNS, INTENSIVE, LMPCNA] March 7-13, &lt;br&gt;
2010 - Cancun, Mexico&lt;br&gt;
&lt;br&gt;
INVITATION&lt;br&gt;
&lt;br&gt;
Note that we are entering the last few days of submission for the events &lt;br&gt;
collocated in Cancun, Mexico&lt;br&gt;
&lt;br&gt;
Please consider to contribute and encourage your team members and fellow &lt;br&gt;
scientists to contribute to the following federated events.&lt;br&gt;
&lt;br&gt;
The submission deadline has now been moved to November 1, 2009.&lt;br&gt;
&lt;br&gt;
Publisher: CPS ( see:...&lt;br&gt;</description>
    <pubDate>Tue, 27 Oct 2009 01:39:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/35</guid>
  </item>


  <item>
    <title>Re: Friday afternoon RAND fail. :&gt;</title>
    <link>http://seclists.org/dailydave/2009/q4/34</link>
    <description>&lt;p&gt;Posted by dave on Oct 26&lt;/p&gt;In related news, VulnDisco has Solaris 0day this month.&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;https://forum.immunityinc.com/board/thread/63/vulndisco/?page=1#post-63&quot;&gt;https://forum.immunityinc.com/board/thread/63/vulndisco/?page=1#post-63&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
One of the people who did peer review for that RAND paper emailed me.&lt;br&gt;
I'll leave what he said private though. I'm sure the author (Martin C.&lt;br&gt;
Libicki) has had enough people annoying him over it this morning. :&amp;gt;&lt;br&gt;
&lt;br&gt;
-dave&lt;br&gt;
&lt;br&gt;
Gunter Ollmann wrote:&lt;br&gt;
...&lt;br&gt;</description>
    <pubDate>Mon, 26 Oct 2009 16:37:40 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/34</guid>
  </item>


  <item>
    <title>Re: Friday afternoon RAND fail. :&gt;</title>
    <link>http://seclists.org/dailydave/2009/q4/33</link>
    <description>&lt;p&gt;Posted by Travis Carelock on Oct 23&lt;/p&gt;From Rand's new whitepaper on Cyberwarfare (pg. 73):&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.rand.org/pubs/monographs/2009/RAND_MG877.pdf&quot;&gt;http://www.rand.org/pubs/monographs/2009/RAND_MG877.pdf&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&amp;quot;&amp;quot;&amp;quot;&lt;br&gt;
      The following hints may be indicative. Private hackers are more&lt;br&gt;
likely to use techniques that have been circulating throughout the&lt;br&gt;
hacker community. While it is not impossible that they have managed&lt;br&gt;
to generate a novel exploit to take advantage of a hitherto unknown&lt;br&gt;
vulnerability, they are unlikely to have...&lt;br&gt;</description>
    <pubDate>Sat, 24 Oct 2009 03:45:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/33</guid>
  </item>


  <item>
    <title>Re: Friday afternoon RAND fail. :&gt;</title>
    <link>http://seclists.org/dailydave/2009/q4/32</link>
    <description>&lt;p&gt;Posted by Gunter Ollmann on Oct 23&lt;/p&gt;From Rand's new whitepaper on Cyberwarfare (pg. 73):&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.rand.org/pubs/monographs/2009/RAND_MG877.pdf&quot;&gt;http://www.rand.org/pubs/monographs/2009/RAND_MG877.pdf&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&amp;quot;&amp;quot;&amp;quot;&lt;br&gt;
      The following hints may be indicative. Private hackers are more&lt;br&gt;
likely to use techniques that have been circulating throughout the&lt;br&gt;
hacker community. While it is not impossible that they have managed&lt;br&gt;
to generate a novel exploit to take advantage of a hitherto unknown&lt;br&gt;
vulnerability, they are unlikely to have more...&lt;br&gt;</description>
    <pubDate>Fri, 23 Oct 2009 23:12:53 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/32</guid>
  </item>
  <item>
    <title>Friday afternoon RAND fail. :&gt;</title>
    <link>http://seclists.org/dailydave/2009/q4/31</link>
    <description>&lt;p&gt;Posted by dave on Oct 23&lt;/p&gt;From Rand's new whitepaper on Cyberwarfare (pg. 73):&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.rand.org/pubs/monographs/2009/RAND_MG877.pdf&quot;&gt;http://www.rand.org/pubs/monographs/2009/RAND_MG877.pdf&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&amp;quot;&amp;quot;&amp;quot;&lt;br&gt;
      The following hints may be indicative. Private hackers are more&lt;br&gt;
likely to use techniques that have been circulating throughout the&lt;br&gt;
hacker community. While it is not impossible that they have managed&lt;br&gt;
to generate a novel exploit to take advantage of a hitherto unknown&lt;br&gt;
vulnerability, they are unlikely to have more...&lt;br&gt;</description>
    <pubDate>Fri, 23 Oct 2009 21:18:16 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/31</guid>
  </item>
  <item>
    <title>Re: Exploits matter.</title>
    <link>http://seclists.org/dailydave/2009/q4/30</link>
    <description>&lt;p&gt;Posted by security curmudgeon on Oct 22&lt;/p&gt;Based on discussion from this thread and internal chat:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://blog.osvdb.org/2009/10/22/classification-exploit-status-overhaul#&quot;&gt;http://blog.osvdb.org/2009/10/22/classification-exploit-status-overhaul#&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Classification: Exploit Status Overhaul&lt;br&gt;
&lt;br&gt;
Posted by jericho 31 minutes ago&lt;br&gt;
OSVDB's classification system is designed to categorize certain attributes &lt;br&gt;
of a vulnerability. This facilitates custom searches by a specific &lt;br&gt;
attribute, helps researchers develop metrics and gives a better picture of &lt;br&gt;
the vulnerability...&lt;br&gt;</description>
    <pubDate>Fri, 23 Oct 2009 02:35:11 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/30</guid>
  </item>


  <item>
    <title>Re: Solvers!</title>
    <link>http://seclists.org/dailydave/2009/q4/29</link>
    <description>&lt;p&gt;Posted by nnp on Oct 22&lt;/p&gt;The architecture and design of the basic algorithm behind most solvers&lt;br&gt;
we use for input generation was first described in 1960 (the DPLL&lt;br&gt;
algorithm) so I think we're safe from the patent mongers there ;-) As&lt;br&gt;
for the logic-specific parts of the solvers, most are described in&lt;br&gt;
academic papers spanning the last 40 years so I presume that&lt;br&gt;
constitutes 'prior art'.&lt;br&gt;
&lt;br&gt;
I don't know of anybody working on designing or implementing the&lt;br&gt;
modern crop of SMT...&lt;br&gt;</description>
    <pubDate>Thu, 22 Oct 2009 13:24:10 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/29</guid>
  </item>
  <item>
    <title>Solvers!</title>
    <link>http://seclists.org/dailydave/2009/q4/28</link>
    <description>&lt;p&gt;Posted by dave on Oct 21&lt;/p&gt;I'm trying to get a django app built so I can demo some of our new tech,&lt;br&gt;
but it's slow going. In the meantime today's extra credit reading and&lt;br&gt;
viewing:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://seanhn.wordpress.com/&quot;&gt;http://seanhn.wordpress.com/&lt;/a&gt; (solver-&amp;gt;exploits blog and paper)&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://media.blackhat.com/bh-usa-06/video/2006_BlackHat_Vegas-V7-Halvar_Flake-Need_New_Tools.mp4&quot;&gt;http://media.blackhat.com/bh-usa-06/video/2006_BlackHat_Vegas-V7-Halvar_Flake-Need_New_Tools.mp4&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
That's probably Halvar's best talk - in it he chats about solving input&lt;br&gt;
crafting issues with large equation solvers (from 2006 so...&lt;br&gt;</description>
    <pubDate>Thu, 22 Oct 2009 02:06:58 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/28</guid>
  </item>


  <item>
    <title>SOURCE Boston 2010 Call for Papers</title>
    <link>http://seclists.org/dailydave/2009/q4/27</link>
    <description>&lt;p&gt;Posted by Christien Rioux on Oct 19&lt;/p&gt;SOURCE Boston 2010 Call for Papers is Now Open!&lt;br&gt;
&lt;br&gt;
SOURCE Boston 2010&lt;br&gt;
April 21-23, 2010&lt;br&gt;
Seaport Hotel&lt;br&gt;
www.sourceconference.com&lt;br&gt;
&lt;br&gt;
SOURCE is the first and only conference combining advanced technology&lt;br&gt;
and security practices with the business of security. With thoughtful&lt;br&gt;
attention to detail and emphasis on high quality and compelling&lt;br&gt;
technical content, SOURCE is committed to delivering valuable&lt;br&gt;
information in a high energy and fun environment.&lt;br&gt;
&lt;br&gt;
SOURCE...&lt;br&gt;</description>
    <pubDate>Mon, 19 Oct 2009 18:15:40 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/27</guid>
  </item>
  <item>
    <title>CanSecWest 2010 CALL FOR PAPERS (deadline Nov 30,	conf. Mar22-26) and PacSec (Nov 4/5) Selections</title>
    <link>http://seclists.org/dailydave/2009/q4/26</link>
    <description>&lt;p&gt;Posted by Dragos Ruiu on Oct 19&lt;/p&gt;We extend our apologies if you are inconvenienced by multiple copies of this messages.&lt;br&gt;
&lt;br&gt;
We would like to announce the PacSec 2009 Paper Selections, and&lt;br&gt;
the opening of the 2010 CanSecWest Call For Papers. Given&lt;br&gt;
the proximity of the Winter Olympics in Vancouver one month&lt;br&gt;
before the conference, we would advise all planning to attend&lt;br&gt;
to make travel preparations well in advance for next year... &lt;br&gt;
&lt;br&gt;
PacSec 2009 Presentations&lt;br&gt;
&lt;br&gt;
Keynote Presentation...&lt;br&gt;</description>
    <pubDate>Mon, 19 Oct 2009 17:41:54 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/26</guid>
  </item>


  <item>
    <title>[NPA] Call for Papers: International Journal of Network	Protocols and Algorithms</title>
    <link>http://seclists.org/dailydave/2009/q4/25</link>
    <description>&lt;p&gt;Posted by Jaime Lloret_Mauri on Oct 10&lt;/p&gt;********************* Call for Papers for Vol 1, Issue 2 ********************* &lt;br&gt;
&lt;br&gt;
Network Protocols and Algorithms &lt;br&gt;
&lt;br&gt;
ISSN 1943-3581&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.macrothink.org/journal/index.php/npa/&quot;&gt;http://www.macrothink.org/journal/index.php/npa/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Network Protocols and Algorithms is a free online international journal, peer-reviewed and published by Macrothink &lt;br&gt;
Institute. It publishes papers focused on the design, development, manage, optimize or monitoring any type of network &lt;br&gt;
protocol, communication system,...&lt;br&gt;</description>
    <pubDate>Sat, 10 Oct 2009 23:13:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/dailydave/2009/q4/25</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
