<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>blafra</title>
	<atom:link href="http://www.blafra.com/wordpress/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://www.blafra.com/wordpress</link>
	<description>a place to spew</description>
	<lastBuildDate>Fri, 12 Sep 2008 17:42:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>4th Annual IT Security Automation Conference</title>
		<link>http://www.blafra.com/wordpress/?p=26</link>
		<comments>http://www.blafra.com/wordpress/?p=26#comments</comments>
		<pubDate>Fri, 12 Sep 2008 17:42:06 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[plugs]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=26</guid>
		<description><![CDATA[The 4th Annual IT Security Automation Conference is around the corner; September 22nd &#8211; 25th. If you&#8217;re in the Maryland areas and have $95 to drop it should be worth it. Myself and a couple others from CIS will be there so let us know if you plan on attending. ]]></description>
			<content:encoded><![CDATA[<p>The <a href="http://nvd.nist.gov/scapconf2008.cfm">4th Annual IT Security Automation Conference</a> is around the corner; September 22nd &#8211; 25th. If you&#8217;re in the Maryland areas and have $95 to drop it should be worth it. Myself and a couple others from <a href="http://cisecurity.org">CIS</a> will be there so let us know if you plan on attending. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=26</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Peach 2 at BA-CON 2008</title>
		<link>http://www.blafra.com/wordpress/?p=25</link>
		<comments>http://www.blafra.com/wordpress/?p=25#comments</comments>
		<pubDate>Fri, 12 Sep 2008 17:29:07 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[fuzz]]></category>
		<category><![CDATA[plugs]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=25</guid>
		<description><![CDATA[The Blackhat Vegas classes went really well &#8211; minus a couple hiccups with the DVDs Mike and I will be traveling to Argentina for BA-CON where we&#8217;re putting on another two day class of fuzzing with Peach. If you&#8217;re going to be in Buenos Aires at the end of September drop us an email.  ]]></description>
			<content:encoded><![CDATA[<p>The Blackhat Vegas classes went really well &#8211; minus a couple hiccups with the DVDs <img src='http://www.blafra.com/wordpress/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p><a href="http://phed.org">Mike</a> and I will be traveling to Argentina for BA-CON where we&#8217;re putting on another <a href="http://ba-con.com.ar/dojopeach.html" target="_blank">two day class of fuzzing with Peach</a>. If you&#8217;re going to be in Buenos Aires at the end of September drop us an email.</p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=25</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Baking Cool Exploits</title>
		<link>http://www.blafra.com/wordpress/?p=24</link>
		<comments>http://www.blafra.com/wordpress/?p=24#comments</comments>
		<pubDate>Thu, 17 Apr 2008 01:48:00 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=24</guid>
		<description><![CDATA[Take one part vanilla memory corruption bug. Add three parts ActionScript Virtual Machine KungFoo. Beat. Alot. Bake at 98.6 degrees. Let cool and serve. Go here for the coolest exploit I&#8217;ve seen since this one.]]></description>
			<content:encoded><![CDATA[<p>Take one part vanilla memory corruption bug. Add three parts ActionScript Virtual Machine KungFoo. Beat. Alot. Bake at 98.6 degrees. Let cool and serve.</p>
<p>Go <a href="http://documents.iss.net/whitepapers/IBM_X-Force_WP_final.pdf">here</a> for the coolest exploit I&#8217;ve seen since this <a href="http://uninformed.org/?v=4&amp;a=5&amp;t=pdf">one</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=24</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>More on IE, File Type Detection, and file(1).</title>
		<link>http://www.blafra.com/wordpress/?p=22</link>
		<comments>http://www.blafra.com/wordpress/?p=22#comments</comments>
		<pubDate>Wed, 09 Apr 2008 22:00:54 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=22</guid>
		<description><![CDATA[Yesterday, I created some files that would pass file(1) yet contained HTML to determine if IE would render them as HTML. The goal of this was to underscore that discrepancies between file type detection mechanisms, especially those found in a browser and web platform, may result in security issues. In this testing a pattern emerged; none of the files [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday, I created some files that would pass file(1) yet contained HTML to determine if IE would render them as HTML. The goal of this was to underscore that discrepancies between file type detection mechanisms, especially those found in a browser and web platform, may result in security issues. In this testing a pattern emerged; none of the files (PNG and JPEG) that contained upper ASCII characters rendered as HTML. The other  formats, void of upper ASCII, rendered as HTML. This got me supposing that IE&#8217;s content-sniffing may look for upper ASCII characters when deciding to consider data HTML or not. I thought about that again this morning and determined that my original thought was incorrect because I&#8217;ve seen IE render valid PDFs and BMPs as HTML. So something else is going on with PNG and JPEG. I probably won&#8217;t  look into that anytime soon as my initial goal in this research is to determine what I *can* do.</p>
<p>I did some more testing this moring by creating various files, including GIF and BMP, that contain upper ASCII, sent them with the appropriate image/(gif|bmp) content-type and each test resulted in rendered HTML. </p>
<p>The take away from this is:</p>
<ul>
<li> If you want to bypass a file(1) based file type detection mechanism and cause IE to render HTML all in one shot GIF, BMP, and PDF are valid options while JPEG and PNG appear otherwise. I&#8217;m certain there are heaps of other formats that will work as well.</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=22</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Content Ownership and Validating File Types</title>
		<link>http://www.blafra.com/wordpress/?p=21</link>
		<comments>http://www.blafra.com/wordpress/?p=21#comments</comments>
		<pubDate>Wed, 09 Apr 2008 02:47:05 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=21</guid>
		<description><![CDATA[I was referred to Billy (BK) Rios&#8217;s blog as an article there somewhat relates to research I conducted on how browsers react when faced with different combinations of content-types, dispositions, and data. This is where I became aware of the term &#8220;Content Ownership&#8221; &#8211; the concept is familiar but the pretty term was not. It&#8217;s pretty [...]]]></description>
			<content:encoded><![CDATA[<p>I was referred to <a href="http://xs-sniper.com/blog/2008/04/04/insecure-content-ownership/">Billy (BK) Rios&#8217;s blog </a>as an article there somewhat relates to <a href="http://www.blafra.com/wordpress/?p=11">research I conducted </a>on how browsers react when faced with different combinations of content-types, dispositions, and data. This is where I became aware of the term &#8220;Content Ownership&#8221; &#8211; the concept is familiar but the pretty term was not.</p>
<p>It&#8217;s pretty clear that taking ownership of other people&#8217;s content is risky business. Especially, given Internet Explorer&#8217;s willingness to render data as HTML despite the advertised Content-type. However, serving up other people&#8217;s content is often a requirement. Having that content look pretty is also a requirement. Flickr surely can&#8217;t send images with a Content-Disposition type of &#8216;attachment&#8217; without killing their user experience. We are left with a need for additional validation. So how do we do that? File extensions surely don&#8217;t work. Nor will anything else that originates from the user and makes claims about the content format. What about file(1) and magic(4)?</p>
<p>For those unfamiliar, magic(4) contains a grammar that is used by file(1) to determine a file type based on the file&#8217;s content. For example:</p>
<pre>blake@cecilia ~ $ file /bin/ls
/bin/ls: ELF 32-bit LSB shared object, Intel 80386, version 1 (SYSV), ...
blake@cecilia ~ $ file /etc/passwd
/etc/passwd: ASCII text</pre>
<p><br/>At first glance, this seems like a viable options. However, as some simple testing will show, those utilizing file(1) and magic(4) to perform content-type validation are in for a surprise. </p>
<p>I was able to construct a GIF, PDF, Macromedia Flash (FLS), Macromedia Flash Video (FLV), and Compressed Macromedia Flash (CWS) files that satisfy file(1) yet render as HTML/JavaScript in Internet Explorer 7. It&#8217;s worth noting that I also attempted creating a simple JPEG and PNG in a similar manner but IE would not render them as HTML. I suspect this is due to the upper ASCII characters found within these files &#8211; more testing on that later. The implications of this are that if anyone is relying on file(1) or magic(3) for making content ownership decisions they may have a problems.</p>
<p>Below are the files I used for testing:</p>
<pre>JPEG:
0000h: FF D8 FF E0 00 10 4A 46 49 46 3C 68 74 6D 6C 3E  ......JFIF&lt;html&gt;
0010h: 3C 73 63 72 69 70 74 3E 61 6C 65 72 74 28 29 3B  &lt;script&gt;alert();
0020h: 3C 2F 73 63 72 69 70 74 3E 3C 2F 68 74 6D 6C 3E  &lt;/script&gt;&lt;/html&gt;</pre>
<pre>PDF:
0000h: 50 44 46 3C 68 74 6D 6C 3E 3C 73 63 72 69 70 74  PDF&lt;html&gt;&lt;script
0010h: 3E 61 6C 65 72 74 28 29 3B 3C 2F 73 63 72 69 70  &gt;alert();&lt;/scrip
0020h: 74 3E 3C 2F 68 74 6D 6C 3E                       t&gt;&lt;/html&gt;</pre>
<pre>FWS:
0000h: 46 57 53 3C 68 74 6D 6C 3E 3C 73 63 72 69 70 74  FWS&lt;html&gt;&lt;script
0010h: 3E 61 6C 65 72 74 28 29 3B 3C 2F 73 63 72 69 70  &gt;alert();&lt;/scrip
0020h: 74 3E 3C 2F 68 74 6D 6C 3E                       t&gt;&lt;/html&gt;</pre>
<pre>FLW:
0000h: 46 4C 56 3C 68 74 6D 6C 3E 3C 73 63 72 69 70 74  FLV&lt;html&gt;&lt;script
0010h: 3E 61 6C 65 72 74 28 29 3B 3C 2F 73 63 72 69 70  &gt;alert();&lt;/scrip
0020h: 74 3E 3C 2F 68 74 6D 6C 3E                       t&gt;&lt;/html&gt;</pre>
<pre>CWS:
0000h: 43 57 53 3C 68 74 6D 6C 3E 3C 73 63 72 69 70 74  CWS&lt;html&gt;&lt;script
0010h: 3E 61 6C 65 72 74 28 29 3B 3C 2F 73 63 72 69 70  &gt;alert();&lt;/scrip
0020h: 74 3E 3C 2F 68 74 6D 6C 3E                       t&gt;&lt;/html&gt;</pre>
<pre>PNG:
0000h: 89 50 4E 47 0D 0A 1A 0A 3C 68 74 6D 6C 3E 3C 73  .PNG....&lt;html&gt;&lt;s
0010h: 63 72 69 70 74 3E 61 6C 65 72 74 28 29 3B 3C 2F  cript&gt;alert();&lt;/
0020h: 73 63 72 69 70 74 3E 3C 2F 68 74 6D 6C 3E        script&gt;&lt;/html&gt;</pre>
<pre>GIF: 
0000h: 47 49 46 38 3C 68 74 6D 6C 3E 3C 73 63 72 69 70  GIF8&lt;html&gt;&lt;scrip
0010h: 74 3E 61 6C 65 72 74 28 29 3B 3C 2F 73 63 72 69  t&gt;alert();&lt;/scri
0020h: 70 74 3E 3C 2F 68 74 6D 6C 3E                    pt&gt;&lt;/html&gt;</pre>
<p><br/>and the file(1) output for these files:</p>
<pre>
blake@cecilia ~ $ for i in `ls`; do file $i;done
compressed_flash.cws: Macromedia Flash data (compressed), version 60
flash.fla: Macromedia Flash data, version 60
flashvideo.fla: Macromedia Flash Video
gif.gif: GIF image data 28020 x 15980
jpeg.jpg: JPEG image data, JFIF standard 104.116, thumbnail 99x114
pdf.pdf: Macintosh PDF File (data) : F&lt;html&gt;&lt;script&gt;alert();&lt;/script
png.png: PNG image data, 1668442480 x 1950245228, 101-bit</pre>
<p><br/>This brings up a bigger issue &#8211; the need for those writing browsers and those writing web platforms to agree on a standardized method for identifying content types. As we can see above, the differences in detection mechanisms will more than likely result in very real security implications.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=21</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft&#8217;s ASIRRA CAPTCHA/HIP project takes a jab</title>
		<link>http://www.blafra.com/wordpress/?p=20</link>
		<comments>http://www.blafra.com/wordpress/?p=20#comments</comments>
		<pubDate>Thu, 27 Mar 2008 05:21:43 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=20</guid>
		<description><![CDATA[Microsoft&#8217;s Research team created a pretty cool HIP (Human Interactive Proof) system, ASIRRA, which requires a user to select a set of images depicting all dogs or cats (supplied by PetFinder) to prove they are non-software. About a month ago, smart folks at the Palo Alto Research Center went Doogie Howser on this system and subsequently released a [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft&#8217;s Research team created a pretty cool HIP (Human Interactive Proof) system, <a href="http://research.microsoft.com/asirra/">ASIRRA</a>, which requires a user to select a set of images depicting all dogs or cats (supplied by PetFinder) to prove they are non-software. About a month ago, smart folks at the Palo Alto Research Center went Doogie Howser on this system and subsequently released a paper titled <a href="http://eprint.iacr.org/2008/126.pdf"><em>Maching Learning Attacks Against the ASIRRA CAPTCHA</em></a><em>. </em>Here&#8217;s a portion of the abstract:</p>
<p><font size="1" face="CMR9">Our classifier allows us to solve a 12-image ASIRRA challenge automatically with probability 10.3%. This probability of success is signicantly higher than the estimate given in [6] for machine vision attacks. The weakness we expose in the current implementation of ASIRRA does not mean that ASIRRA cannot be deployed securely. With appropriate safeguards, we believe that ASIRRA offers an appealing balance between usability and security. One contribution of this work is to inform the choice of safeguard parameters in ASIRRA deployments.</font></p>
<p>Big fat brains strapped to compilers is typically going to result in software capable of almost anything &#8211; including solving pretty sophisticated computer vision/imaging problems. Full disclosure &#8211; I don&#8217;t know jack about solving computer vision problems. I do, however, find myself reading more and more whitepapers, written by significantly smarter people than myself, about targeted software capable of breaking today&#8217;s most difficult graphical HIPs. This research is yet another example of how traditional graphical HIP systems are failing. Hopefully, it will become standard practice to integrate thresholds to protect sensitive site functionality and we&#8217;ll all be rid of CAPTCHAs.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=20</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Peach at CanSecWest</title>
		<link>http://www.blafra.com/wordpress/?p=19</link>
		<comments>http://www.blafra.com/wordpress/?p=19#comments</comments>
		<pubDate>Tue, 18 Mar 2008 14:17:45 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[fuzz]]></category>
		<category><![CDATA[plugs]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=19</guid>
		<description><![CDATA[Mike Eddington will be presenting on the Peach Fuzzing Platform at CanSecWest this March 26th &#8211; 28th.  In his presentation, Mike will be demonstrating some of the new capabilities added to Peach 2.0, including the state machine, data definition language, and PeachBuilder UI. Go here or here for more info.]]></description>
			<content:encoded><![CDATA[<p>Mike Eddington will be presenting on the Peach Fuzzing Platform at CanSecWest this March 26th &#8211; 28th.  In his presentation, Mike will be demonstrating some of the new capabilities added to Peach 2.0, including the state machine, data definition language, and PeachBuilder UI. Go <a href="http://cansecwest.com/index.html">here</a> or <a href="http://peachfuzz.sourceforge.net/">here </a>for more info.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=19</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Updates to areyouahuman.org</title>
		<link>http://www.blafra.com/wordpress/?p=18</link>
		<comments>http://www.blafra.com/wordpress/?p=18#comments</comments>
		<pubDate>Tue, 18 Mar 2008 01:54:19 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[plugs]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=18</guid>
		<description><![CDATA[There&#8217;s been some recent updates to areyouahuman.org. Chief among them are: It&#8217;s less ugly Graphical and SMS HIPs/CAPTCHAs are working (better) Example code in PHP, PERL, and C# for integrating with both APIs Items left to complete include: Complete threshold and blacklist funcationality Add APIKey functionality to support per-site customizations Feedback is definitely welcome.]]></description>
			<content:encoded><![CDATA[<p>There&#8217;s been some recent updates to <a href="http://areyouahuman.org">areyouahuman.org</a>. Chief among them are:</p>
<ul>
<li>It&#8217;s less ugly</li>
<li>Graphical and SMS HIPs/CAPTCHAs are working (better)</li>
<li>Example code in PHP, PERL, and C# for integrating with both APIs</li>
</ul>
<p>Items left to complete include:</p>
<ul>
<li>Complete threshold and blacklist funcationality</li>
<li>Add APIKey functionality to support per-site customizations</li>
</ul>
<p>Feedback is definitely welcome.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=18</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Browsers and MIME Types</title>
		<link>http://www.blafra.com/wordpress/?p=11</link>
		<comments>http://www.blafra.com/wordpress/?p=11#comments</comments>
		<pubDate>Tue, 18 Mar 2008 01:46:40 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[security]]></category>
		<category><![CDATA[web]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=11</guid>
		<description><![CDATA[I recently finished up phase one of some research into how various browsers react when presented with HTML-like data along with contradictory Content-Types. The goal of this exercise was to identify instances when each browser would successfully render the data as HTML. I chose this goal because the implications, from a content host and consumer&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>I recently finished up phase one of some research into how various browsers react when presented with HTML-like data along with contradictory Content-Types. The goal of this exercise was to identify instances when each browser would successfully render the data as HTML. I chose this goal because the implications, from a content host and consumer&#8217;s perspective, are quite severe if delivered content is unexpectedly rendered by the browser. See also: XSS, CSRF, etc.</p>
<p>Here&#8217;s a quick overview of what was determined.  For the complete writeup, go <a target="_blank" href="http://www.leviathansecurity.com/pdf/Flirting%20with%20MIME%20Types.pdf">here</a>.</p>
<p>I tested current versions (as of this writing) of Internet Explorer, Opera, Safari, and FireFox all on the Windows platform.  I used 735 differerent content types which resulted in a total of <span style="font-size: 11pt; font-family: 'Calibri','sans-serif'">13158 tests. </span></p>
<ul>
<li><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'">Internet Explorer rendered HTML for 696 different Content-types in the Internet Zone.</span></li>
<li><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'">Opera rendered HTML for 14 different Content-types.</span></li>
<li><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'">FireFox rendered HTML for 8 different Content-types.</span></li>
<li><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'">Safari rendered HTML for 7 different Content-types.</span></li>
</ul>
<p><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'">Another interesting point, which is obvious once you say it outloud, is no test resulted in rendered HTML when the Content-Disposition type was set to &#8220;attachment&#8221;. Zero. This is good news for media sharing sites that typically host untrusted content. Hopefully, this will start to catch on a bit more.</span></p>
<p><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'"></span><span style="font-size: 11pt; font-family: 'Calibri','sans-serif'"></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=11</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Center for Internet Security &#8211; 16 Benchmarks in roughly 6 months :)</title>
		<link>http://www.blafra.com/wordpress/?p=17</link>
		<comments>http://www.blafra.com/wordpress/?p=17#comments</comments>
		<pubDate>Wed, 12 Mar 2008 14:49:31 +0000</pubDate>
		<dc:creator>Blake Frantz</dc:creator>
				<category><![CDATA[plugs]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.blafra.com/wordpress/?p=17</guid>
		<description><![CDATA[ The Center for Internet Security has been busy the last six months, releasing 16 updated and/or new security benchmarks. This includes: Windows Server 2003 (Domain Controller &#38; Member Server) Solaris 11, 10, and 8 HPUX Red Hat Linux Debian Linux Cisco IOS Cisco PIX, ASA, and FWSM CheckPoint Firewall Exchange Server 2007 Apache MySQL IIS 6,5 [...]]]></description>
			<content:encoded><![CDATA[<p> The <a href="http://cisecurity.org/" title="Center for Internet Security">Center for Internet Security</a> has been busy the last six months, releasing 16 updated and/or new security benchmarks. This includes:</p>
<ul>
<li>Windows Server 2003 (Domain Controller &amp; Member Server)</li>
<li>Solaris 11, 10, and 8</li>
<li>HPUX</li>
<li>Red Hat Linux</li>
<li>Debian Linux</li>
<li>Cisco IOS</li>
<li>Cisco PIX, ASA, and FWSM</li>
<li>CheckPoint Firewall</li>
<li>Exchange Server 2007</li>
<li>Apache</li>
<li>MySQL</li>
<li>IIS 6,5</li>
<li>OpenLDAP</li>
<li>Free Radius</li>
<li>VMWare ESX</li>
<li>General Virtual Machines</li>
</ul>
<p>Check em out, there&#8217;s a lot of good information in there. The benchmarks are free for the home user but a subscription is required if you plan on using them commercially.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.blafra.com/wordpress/?feed=rss2&amp;p=17</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

