<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The Sealckers Press ~ http://infosec.sealckers.org/</title>
	<atom:link href="http://infosec.sealckers.org/feed" rel="self" type="application/rss+xml" />
	<link>http://infosec.sealckers.org</link>
	<description>Information and Internet Security - Full disclosure.</description>
	<lastBuildDate>Tue, 09 Mar 2010 23:41:38 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Microsoft Office Excel &gt; DbOrParamQry Record Parsing Vulnerability</title>
		<link>http://infosec.sealckers.org/press/20100903/microsoft-office-excel-dborparamqry-record-parsing-vulnerability.html</link>
		<comments>http://infosec.sealckers.org/press/20100903/microsoft-office-excel-dborparamqry-record-parsing-vulnerability.html#comments</comments>
		<pubDate>Mon, 08 Mar 2010 23:29:41 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Infosecurity]]></category>
		<category><![CDATA[PoC]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[coresecurity]]></category>
		<category><![CDATA[CVE-2010-0264]]></category>
		<category><![CDATA[DbOrParamQry]]></category>
		<category><![CDATA[excel 2002]]></category>
		<category><![CDATA[microsoft office excel]]></category>
		<category><![CDATA[query]]></category>
		<category><![CDATA[Record Parsing Vulnerability]]></category>
		<category><![CDATA[RPV]]></category>
		<category><![CDATA[sp3]]></category>
		<category><![CDATA[xp]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=711</guid>
		<description><![CDATA[Microsoft Office Excel > DbOrParamQry Record Parsing Vulnerability
Damian Frizza from Core Security Technologies discovered a memory corruption occurs on Microsoft Office Excel 2002 when parsing a .XLS file with a malformed DbOrParamQry record. This vulnerability could be used by a remote attacker to execute arbitrary code in the context of the currently logged on user, [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20100903/microsoft-office-excel-dborparamqry-record-parsing-vulnerability.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IE v.6,7,8 RCE &amp;&amp; stack overflow in winhlp32 process (Windows XP SP3)</title>
		<link>http://infosec.sealckers.org/press/20102502/windows-xp-sp3-ie78-rce-via-stack-overflow-in-winhlp32-process.html</link>
		<comments>http://infosec.sealckers.org/press/20102502/windows-xp-sp3-ie78-rce-via-stack-overflow-in-winhlp32-process.html#comments</comments>
		<pubDate>Thu, 25 Feb 2010 15:31:04 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Infosecurity]]></category>
		<category><![CDATA[PoC]]></category>
		<category><![CDATA[6]]></category>
		<category><![CDATA[7]]></category>
		<category><![CDATA[8]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[helpfile]]></category>
		<category><![CDATA[ie rce]]></category>
		<category><![CDATA[remote]]></category>
		<category><![CDATA[samba]]></category>
		<category><![CDATA[stack overflow]]></category>
		<category><![CDATA[vb]]></category>
		<category><![CDATA[winhlp32]]></category>
		<category><![CDATA[xp sp3]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=705</guid>
		<description><![CDATA[Introduction:
This vulnerability regards to invoke winhlp32.exe,the Microsoft Windows Help File viewer, from Internet Explorer 6,7,8  using VBScript. Passing malicious .HLP file to winhlp32 could allow remote attacker to run arbitrary command.
Additionally, there is a stack overflow vulnerability in winhlp32.exe. 
Proof of Concept:
To trigger vulnerability some user interaction is needed. Victim has to press F1 [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20102502/windows-xp-sp3-ie78-rce-via-stack-overflow-in-winhlp32-process.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google Buzz CSRF Vulnerabilities</title>
		<link>http://infosec.sealckers.org/press/20101202/google-buzz-csrf-vulnerabilities.html</link>
		<comments>http://infosec.sealckers.org/press/20101202/google-buzz-csrf-vulnerabilities.html#comments</comments>
		<pubDate>Fri, 12 Feb 2010 14:45:53 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Infosecurity]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[advisory]]></category>
		<category><![CDATA[buzz]]></category>
		<category><![CDATA[cross site request forgery]]></category>
		<category><![CDATA[csrf]]></category>
		<category><![CDATA[full disclosure]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[persistent]]></category>
		<category><![CDATA[secunia]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=698</guid>
		<description><![CDATA[Google Buzz CSRF Vulnerabilities
Google Buzz is a new way to start conversations about the things you find interesting, provided by Google Inc.
However, it is also quite vulnerable to persistent CSRF attacks when data is pulled from external data feeds.
Kristian Hermansen&#8216; proof-of-concept executes a denial of service against Google Buzz users for which the only recovery [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20101202/google-buzz-csrf-vulnerabilities.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Microsoft shocked : Local Kernel Privilege Escalation (0-day, 17y.old) + IE fixs.</title>
		<link>http://infosec.sealckers.org/press/20102301/microsoft-shocked-0day-kernel-and-ie-fixs.html</link>
		<comments>http://infosec.sealckers.org/press/20102301/microsoft-shocked-0day-kernel-and-ie-fixs.html#comments</comments>
		<pubDate>Sat, 23 Jan 2010 21:13:09 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Infosecurity]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[0-day]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[google vs china]]></category>
		<category><![CDATA[ie rce]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[windows kernel]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=692</guid>
		<description><![CDATA[Microsoft shocked : Local Privilege Escalation in Windows Kernel.
Do you remember Google vs China? Remember bugs that have allowed Chinese hackers to enter into Gmail accounts and access to confidential information?
Microsoft has confirmed a privilege-escalation vulnerability in the Windows kernel, one day after a Google engineer posted details of the flaw to the Full Disclosure [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20102301/microsoft-shocked-0day-kernel-and-ie-fixs.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Internet Explorer 6-7-8 =&gt; Remote Code Execution</title>
		<link>http://infosec.sealckers.org/press/20101901/internet-explorer-remote-code-execution.html</link>
		<comments>http://infosec.sealckers.org/press/20101901/internet-explorer-remote-code-execution.html#comments</comments>
		<pubDate>Tue, 19 Jan 2010 10:57:56 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[6.0]]></category>
		<category><![CDATA[7]]></category>
		<category><![CDATA[8]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[gmail]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[hackers]]></category>
		<category><![CDATA[internet explorer]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=689</guid>
		<description><![CDATA[Summary:
Microsoft is investigating reports of limited, targeted attacks against customers of Internet Explorer 6, using a vulnerability in Internet Explorer.
Affected:
Internet Explorer 5.01 Service Pack 4 on Microsoft Windows 2000 Service Pack 4 is not affected, and that Internet Explorer 6 Service Pack 1 on Microsoft Windows 2000 Service Pack 4, and Internet Explorer 6, Internet [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20101901/internet-explorer-remote-code-execution.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Save MySQL : The Petition</title>
		<link>http://infosec.sealckers.org/press/20101001/save-mysql-the-petition.html</link>
		<comments>http://infosec.sealckers.org/press/20101001/save-mysql-the-petition.html#comments</comments>
		<pubDate>Sun, 10 Jan 2010 15:16:53 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Stuffs]]></category>
		<category><![CDATA[Writing]]></category>
		<category><![CDATA[oracle]]></category>
		<category><![CDATA[petition]]></category>
		<category><![CDATA[save mysql]]></category>
		<category><![CDATA[sun]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=612</guid>
		<description><![CDATA[In April 2009, Oracle announced that it had agreed to acquire Sun. Since Sun had acquired MySQL the previous year, this would mean that Oracle, the market leader for closed source databases, would get to own MySQL, the most popular open source database.
If Oracle acquired MySQL on that basis, it would have as much control [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20101001/save-mysql-the-petition.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>XSS Revenge : eu2010.es HACKED</title>
		<link>http://infosec.sealckers.org/press/20100601/xss-revenge-eu2010-es-hacked.html</link>
		<comments>http://infosec.sealckers.org/press/20100601/xss-revenge-eu2010-es-hacked.html#comments</comments>
		<pubDate>Wed, 06 Jan 2010 15:23:56 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[Articles]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Writing]]></category>
		<category><![CDATA[eu2010.es]]></category>
		<category><![CDATA[hacked]]></category>
		<category><![CDATA[revenge]]></category>
		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=615</guid>
		<description><![CDATA[Political websites have been hacked over the past 24 hours to leave leaders with red faces.
A report on BBC News said that visitors to Spain&#8217;s EU presidency website were greeted by an image of comedy character Mr Bean instead of the Spanish Prime Minister Jose Luis Rodriguez Zapatero.
The government said that the site &#8211; www.eu2010.es [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20100601/xss-revenge-eu2010-es-hacked.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Xmas is coming! Happy new year!</title>
		<link>http://infosec.sealckers.org/press/20091412/xmas-is-coming-happy-new-year.html</link>
		<comments>http://infosec.sealckers.org/press/20091412/xmas-is-coming-happy-new-year.html#comments</comments>
		<pubDate>Sun, 13 Dec 2009 22:10:17 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[Announcement]]></category>
		<category><![CDATA[Stuffs]]></category>
		<category><![CDATA[new year]]></category>
		<category><![CDATA[sealckers]]></category>
		<category><![CDATA[wishes]]></category>
		<category><![CDATA[xmas]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=588</guid>
		<description><![CDATA[Christmas is coming, and with this the New Year!  Wishes to all. 
We&#8217;ll see you soon.
~ nicola

]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20091412/xmas-is-coming-happy-new-year.html/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Windows 7 and Windows Server 2008 R2 Remote Kernel Crash Exploit</title>
		<link>http://infosec.sealckers.org/press/20091611/windows-7-and-windows-server-2008-r2-remote-kernel-crash-exploit.html</link>
		<comments>http://infosec.sealckers.org/press/20091611/windows-7-and-windows-server-2008-r2-remote-kernel-crash-exploit.html#comments</comments>
		<pubDate>Sun, 15 Nov 2009 23:54:55 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[Exploits]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Infosecurity]]></category>
		<category><![CDATA[PoC]]></category>
		<category><![CDATA[Webappsec]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[affected]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[ipv4]]></category>
		<category><![CDATA[ipv6]]></category>
		<category><![CDATA[link]]></category>
		<category><![CDATA[remote]]></category>
		<category><![CDATA[remote kernel crash]]></category>
		<category><![CDATA[smb]]></category>
		<category><![CDATA[sploit]]></category>
		<category><![CDATA[windows 7]]></category>
		<category><![CDATA[windows server 2008 r2]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=583</guid>
		<description><![CDATA[Windows 7 and Windows Server 2008 R2 Remote Kernel Crash Exploit
Windows 7 and Windows Server 2008 R2, with the very latest patches applied, are affected of this vulnerability.  A link to a server running this code could easily be embedded in a web page or email, pointing out to a poison host on the [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20091611/windows-7-and-windows-server-2008-r2-remote-kernel-crash-exploit.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Whitehouse.gov Mind Insecurity</title>
		<link>http://infosec.sealckers.org/press/20090411/whitehouse-gov-mind-insecurity.html</link>
		<comments>http://infosec.sealckers.org/press/20090411/whitehouse-gov-mind-insecurity.html#comments</comments>
		<pubDate>Wed, 04 Nov 2009 16:52:53 +0000</pubDate>
		<dc:creator>nicola</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Stuffs]]></category>
		<category><![CDATA[Webappsec]]></category>
		<category><![CDATA[Writing]]></category>
		<category><![CDATA[crazy]]></category>
		<category><![CDATA[down]]></category>
		<category><![CDATA[drupal]]></category>
		<category><![CDATA[failure]]></category>
		<category><![CDATA[insecurity]]></category>
		<category><![CDATA[usa]]></category>
		<category><![CDATA[whotehouse.gov]]></category>

		<guid isPermaLink="false">http://infosec.sealckers.org/?p=576</guid>
		<description><![CDATA[The incredible news is that Whitehouse has decided to go open source with the CMS system Drupal. It&#8217;s right, the crazy reality. &#8220;Ahaha&#8221; in this case, it&#8217;s right. I&#8217;m talking about the same Drupal that you all probably know.  Oh, yes, there are &#8220;only&#8221; pages and pages of vulnerabilities on PacketStorm, Milw0rm and OSVDB [...]]]></description>
		<wfw:commentRss>http://infosec.sealckers.org/press/20090411/whitehouse-gov-mind-insecurity.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

