<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DarkFiber Consulting - IT Managed Services &#187; Exploit</title>
	<atom:link href="http://www.darkfiberla.com/tag/exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darkfiberla.com</link>
	<description>DarkFiber Consulting offers managed services for the SMB market. Some of the services we offer include network administration, server management, desktop support, smartphone and blackbery configuration, voip, and asterisk based pbx phone systems.</description>
	<lastBuildDate>Wed, 23 Jun 2010 18:43:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>SSL and TLS Vulnerable to Man-in-the-middle Attacks</title>
		<link>http://www.darkfiberla.com/security-alerts/ssl-and-tls-vulnerable-to-man-in-the-middle-attacks/</link>
		<comments>http://www.darkfiberla.com/security-alerts/ssl-and-tls-vulnerable-to-man-in-the-middle-attacks/#comments</comments>
		<pubDate>Thu, 10 Dec 2009 18:49:43 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Application Protocol]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Man In The Middle Attack]]></category>
		<category><![CDATA[Protocol Stream]]></category>
		<category><![CDATA[Protocols]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/ssl-and-tls-vulnerable-to-man-in-the-middle-attacks/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of reports of publicly available exploit code for a vulnerability within the SSL and TLS protocols. Reports indicate that exploitation of this vulnerability may allow an attacker to conduct a man-in-the-middle attack, allowing an attacker to inject plaintext into the beginning of the application protocol stream. DarkFiber Consulting encourages OpenSSL users [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of reports of publicly available exploit code for a vulnerability within the SSL and TLS protocols. Reports indicate that exploitation of this vulnerability may allow an attacker to conduct a man-in-the-middle attack, allowing an attacker to inject plaintext into the beginning of the application protocol stream.</p>
<p>DarkFiber Consulting encourages OpenSSL users and administrators to review the <a href="http://www.openssl.org/source/" target="_self">OpenSSL 0.9.8l</a> release and apply any updates.</p>
<p>DarkFiber Consulting has not received any reports of active exploitation and will continue to provide additional information as it becomes available.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/application-protocol/" title="Application Protocol" rel="tag">Application Protocol</a>, <a href="http://www.darkfiberla.com/tag/attacker/" title="Attacker" rel="tag">Attacker</a>, <a href="http://www.darkfiberla.com/tag/exploit/" title="Exploit" rel="tag">Exploit</a>, <a href="http://www.darkfiberla.com/tag/man-in-the-middle-attack/" title="Man In The Middle Attack" rel="tag">Man In The Middle Attack</a>, <a href="http://www.darkfiberla.com/tag/protocol-stream/" title="Protocol Stream" rel="tag">Protocol Stream</a>, <a href="http://www.darkfiberla.com/tag/protocols/" title="Protocols" rel="tag">Protocols</a>, <a href="http://www.darkfiberla.com/tag/vulnerability/" title="Vulnerability" rel="tag">Vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/ssl-and-tls-vulnerable-to-man-in-the-middle-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Releases Fix It for SMB Vulnerability</title>
		<link>http://www.darkfiberla.com/security-alerts/microsoft-releases-fix-it-for-smb-vulnerability/</link>
		<comments>http://www.darkfiberla.com/security-alerts/microsoft-releases-fix-it-for-smb-vulnerability/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 10:06:53 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Addresses]]></category>
		<category><![CDATA[Arbitrary Code]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Knowledge Base Article]]></category>
		<category><![CDATA[Message Block]]></category>
		<category><![CDATA[Metasploit Framework]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Knowledge Base]]></category>
		<category><![CDATA[Microsoft Knowledge Base Article]]></category>
		<category><![CDATA[Microsoft Releases Security Advisory]]></category>
		<category><![CDATA[Microsoft Security Advisory]]></category>
		<category><![CDATA[System Administrators]]></category>
		<category><![CDATA[Tool]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/microsoft-releases-fix-it-for-smb-vulnerability/</guid>
		<description><![CDATA[Microsoft has released Microsoft Knowledge Base Article 975497 to address a previously reported vulnerability in Microsoft Sever Message Block (SMB). This vulnerability may allow an attacker to execute arbitrary code or cause a denial-of-service condition. DarkFiber Consulting encourages users and administrators to review Microsoft Knowledge Base Article 975497 and Microsoft Security Advisory 975497 and apply [...]]]></description>
			<content:encoded><![CDATA[<p>Microsoft has released Microsoft Knowledge Base <a href="http://support.microsoft.com/kb/975497" target="_self">Article 975497</a> to address a previously reported vulnerability in Microsoft Sever Message Block (SMB). This vulnerability may allow an attacker to execute arbitrary code or cause a denial-of-service condition.</p>
<p>DarkFiber Consulting encourages users and administrators to review Microsoft Knowledge Base <a href="http://support.microsoft.com/kb/975497" target="_self">Article 975497</a> and Microsoft Security <a href="http://www.microsoft.com/technet/security/advisory/975497.mspx" target="_self">Advisory 975497</a> and apply the Fix it tool or workarounds. Microsoft Knowledge Base Article 975497 addresses the vulnerability that was previously reported in the &#8220;<a href="http://www.DarkFiber Consulting.gov/current/#microsoft_releases_security_advisory_975497" target="_self">Microsoft Releases Security Advisory 975497</a>&#8221; Current Activity entry.</p>
<p>DarkFiber Consulting is aware that exploit code for this vulnerability has been made publicly available as part of the Metasploit Framework. Users and system administrators are strongly encouraged to apply the <a href="http://support.microsoft.com/kb/975497">Microsoft Fix</a> it solution or other workarounds until a patch is released.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/addresses/" title="Addresses" rel="tag">Addresses</a>, <a href="http://www.darkfiberla.com/tag/arbitrary-code/" title="Arbitrary Code" rel="tag">Arbitrary Code</a>, <a href="http://www.darkfiberla.com/tag/attacker/" title="Attacker" rel="tag">Attacker</a>, <a href="http://www.darkfiberla.com/tag/denial-of-service/" title="Denial Of Service" rel="tag">Denial Of Service</a>, <a href="http://www.darkfiberla.com/tag/exploit/" title="Exploit" rel="tag">Exploit</a>, <a href="http://www.darkfiberla.com/tag/knowledge-base-article/" title="Knowledge Base Article" rel="tag">Knowledge Base Article</a>, <a href="http://www.darkfiberla.com/tag/message-block/" title="Message Block" rel="tag">Message Block</a>, <a href="http://www.darkfiberla.com/tag/metasploit-framework/" title="Metasploit Framework" rel="tag">Metasploit Framework</a>, <a href="http://www.darkfiberla.com/tag/microsoft/" title="Microsoft" rel="tag">Microsoft</a>, <a href="http://www.darkfiberla.com/tag/microsoft-knowledge-base/" title="Microsoft Knowledge Base" rel="tag">Microsoft Knowledge Base</a>, <a href="http://www.darkfiberla.com/tag/microsoft-knowledge-base-article/" title="Microsoft Knowledge Base Article" rel="tag">Microsoft Knowledge Base Article</a>, <a href="http://www.darkfiberla.com/tag/microsoft-releases-security-advisory/" title="Microsoft Releases Security Advisory" rel="tag">Microsoft Releases Security Advisory</a>, <a href="http://www.darkfiberla.com/tag/microsoft-security-advisory/" title="Microsoft Security Advisory" rel="tag">Microsoft Security Advisory</a>, <a href="http://www.darkfiberla.com/tag/system-administrators/" title="System Administrators" rel="tag">System Administrators</a>, <a href="http://www.darkfiberla.com/tag/tool/" title="Tool" rel="tag">Tool</a>, <a href="http://www.darkfiberla.com/tag/vulnerability/" title="Vulnerability" rel="tag">Vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/microsoft-releases-fix-it-for-smb-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>U.S. Federal Reserve Fraudulent Email Scam</title>
		<link>http://www.darkfiberla.com/security-alerts/us-federal-reserve-fraudulent-email-scam/</link>
		<comments>http://www.darkfiberla.com/security-alerts/us-federal-reserve-fraudulent-email-scam/#comments</comments>
		<pubDate>Fri, 14 Nov 2008 00:04:48 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Caution]]></category>
		<category><![CDATA[Email Information]]></category>
		<category><![CDATA[Email Messages]]></category>
		<category><![CDATA[Email Scam]]></category>
		<category><![CDATA[Email Scams]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Federal Reserve]]></category>
		<category><![CDATA[Malicious Code]]></category>
		<category><![CDATA[Malicious Website]]></category>
		<category><![CDATA[Phishing Attacks]]></category>
		<category><![CDATA[Phishing Scam]]></category>
		<category><![CDATA[Social Engineering]]></category>
		<category><![CDATA[Untrusted]]></category>
		<category><![CDATA[Virus Signatures]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/us-federal-reserve-fraudulent-email-scam/</guid>
		<description><![CDATA[DarkFiber Consulting is aware of public reports of a fraudulent email scam circulating via messages that falsely appear to be from the U.S. Federal Reserve. These email messages contain information about a phishing scam and links for users to follow to obtain additional information about the scam. If a user follows the links, they will [...]]]></description>
			<content:encoded><![CDATA[<p>DarkFiber Consulting is aware of <a href="http://blog.trendmicro.com/bogus-federal-reserve-sites-deliver-pdf-exploit/" target="_self">public reports</a> of a fraudulent email scam circulating via messages that falsely appear to be from the U.S. Federal Reserve. These email messages contain information about a phishing scam and links for users to follow to obtain additional information about the scam. If a user follows the links, they will be redirected to a malicious website where a PDF exploit is used to install malicious code on the affected system.</p>
<p>DarkFiber Consulting encourages users to do the following to help mitigate the risks:
<ul>
<li>Do not follow unsolicited links.</li>
<li>Use caution when visiting untrusted websites.</li>
<li>Install antivirus software and keep the virus signatures up to date.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/reading_room/emailscams_0905.pdf" target="_self">Recognizing and Avoiding Email Scams</a> (pdf) document for more information on avoiding email scams.</li>
<li>Refer to the <a href="http://www.DarkFiber Consulting.gov/cas/tips/ST04-014.html" target="_self">Avoiding Social Engineering and Phishing Attacks</a> document for more information on social engineering attacks.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/caution/" title="Caution" rel="tag">Caution</a>, <a href="http://www.darkfiberla.com/tag/email-information/" title="Email Information" rel="tag">Email Information</a>, <a href="http://www.darkfiberla.com/tag/email-messages/" title="Email Messages" rel="tag">Email Messages</a>, <a href="http://www.darkfiberla.com/tag/email-scam/" title="Email Scam" rel="tag">Email Scam</a>, <a href="http://www.darkfiberla.com/tag/email-scams/" title="Email Scams" rel="tag">Email Scams</a>, <a href="http://www.darkfiberla.com/tag/exploit/" title="Exploit" rel="tag">Exploit</a>, <a href="http://www.darkfiberla.com/tag/federal-reserve/" title="Federal Reserve" rel="tag">Federal Reserve</a>, <a href="http://www.darkfiberla.com/tag/malicious-code/" title="Malicious Code" rel="tag">Malicious Code</a>, <a href="http://www.darkfiberla.com/tag/malicious-website/" title="Malicious Website" rel="tag">Malicious Website</a>, <a href="http://www.darkfiberla.com/tag/phishing-attacks/" title="Phishing Attacks" rel="tag">Phishing Attacks</a>, <a href="http://www.darkfiberla.com/tag/phishing-scam/" title="Phishing Scam" rel="tag">Phishing Scam</a>, <a href="http://www.darkfiberla.com/tag/social-engineering/" title="Social Engineering" rel="tag">Social Engineering</a>, <a href="http://www.darkfiberla.com/tag/untrusted/" title="Untrusted" rel="tag">Untrusted</a>, <a href="http://www.darkfiberla.com/tag/virus-signatures/" title="Virus Signatures" rel="tag">Virus Signatures</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/us-federal-reserve-fraudulent-email-scam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Microsoft Updates Security Advisory 951306</title>
		<link>http://www.darkfiberla.com/security-alerts/microsoft-updates-security-advisory-951306/</link>
		<comments>http://www.darkfiberla.com/security-alerts/microsoft-updates-security-advisory-951306/#comments</comments>
		<pubDate>Tue, 14 Oct 2008 17:53:48 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[April]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Microsoft Security Response Center]]></category>
		<category><![CDATA[Microsoft Updates]]></category>
		<category><![CDATA[Microsoft Windows]]></category>
		<category><![CDATA[Msrc]]></category>
		<category><![CDATA[Privileges]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Response Center]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/microsoft-updates-security-advisory-951306/</guid>
		<description><![CDATA[In April 2008, Microsoft released Security Advisory 951306 to alert users of a vulnerability in Microsoft Windows. This vulnerability may allow local users, or users who can legitimately run code in the context of IIS or SQL Server, to operate with elevated privileges. Recently, Microsoft Security Response Center (MSRC) posted several blog entries indicating that [...]]]></description>
			<content:encoded><![CDATA[<p>In April 2008, Microsoft released <a href="http://www.microsoft.com/technet/security/advisory/951306.mspx" target="_self">Security Advisory 951306</a> to alert users of a vulnerability in Microsoft Windows. This vulnerability may allow local users, or users who can legitimately run code in the context of IIS or SQL Server, to operate with elevated privileges. Recently, Microsoft Security Response Center (MSRC) posted several blog entries indicating that the Security Advisory was updated to reflect the availability of public exploit code. A patch or update is not available to correct this issue.</p>
<p>DarkFiber Consulting encourages users and administrators to do the following to help mitigate the risks:
<ul>
<li>Review the updated <a href="http://www.microsoft.com/technet/security/advisory/951306.mspx" target="_self">Security Advisory 951306</a> and apply the suggested workarounds.</li>
<li>Review the MSRC blog entries from <a href="http://blogs.technet.com/msrc/archive/2008/10/09/update-1-microsoft-security-advisory-951306.aspx" target="_self">October 9, 2008</a> and <a href="http://blogs.technet.com/msrc/archive/2008/10/13/questions-about-microsoft-security-advisory-951306.aspx" target="_self">October 13, 2008</a>.</li>
</ul>

	Tags: <a href="http://www.darkfiberla.com/tag/april/" title="April" rel="tag">April</a>, <a href="http://www.darkfiberla.com/tag/exploit/" title="Exploit" rel="tag">Exploit</a>, <a href="http://www.darkfiberla.com/tag/microsoft/" title="Microsoft" rel="tag">Microsoft</a>, <a href="http://www.darkfiberla.com/tag/microsoft-security-response-center/" title="Microsoft Security Response Center" rel="tag">Microsoft Security Response Center</a>, <a href="http://www.darkfiberla.com/tag/microsoft-updates/" title="Microsoft Updates" rel="tag">Microsoft Updates</a>, <a href="http://www.darkfiberla.com/tag/microsoft-windows/" title="Microsoft Windows" rel="tag">Microsoft Windows</a>, <a href="http://www.darkfiberla.com/tag/msrc/" title="Msrc" rel="tag">Msrc</a>, <a href="http://www.darkfiberla.com/tag/privileges/" title="Privileges" rel="tag">Privileges</a>, <a href="http://www.darkfiberla.com/tag/security-advisory/" title="Security Advisory" rel="tag">Security Advisory</a>, <a href="http://www.darkfiberla.com/tag/security-response-center/" title="Security Response Center" rel="tag">Security Response Center</a>, <a href="http://www.darkfiberla.com/tag/vulnerability/" title="Vulnerability" rel="tag">Vulnerability</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/microsoft-updates-security-advisory-951306/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Oracle Releases Security Advisory for WebLogic Plug-in Vulnerability</title>
		<link>http://www.darkfiberla.com/security-alerts/oracle-releases-security-advisory-for-weblogic-plug-in-vulnerability/</link>
		<comments>http://www.darkfiberla.com/security-alerts/oracle-releases-security-advisory-for-weblogic-plug-in-vulnerability/#comments</comments>
		<pubDate>Wed, 30 Jul 2008 04:23:16 +0000</pubDate>
		<dc:creator>DarkFiber Consulting</dc:creator>
				<category><![CDATA[Security Alerts]]></category>
		<category><![CDATA[Address]]></category>
		<category><![CDATA[Apache]]></category>
		<category><![CDATA[Attacker]]></category>
		<category><![CDATA[Confidentiality]]></category>
		<category><![CDATA[Denial Of Service]]></category>
		<category><![CDATA[Exploit]]></category>
		<category><![CDATA[Integrity]]></category>
		<category><![CDATA[Oracle]]></category>
		<category><![CDATA[Oracle Security]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Server Applications]]></category>
		<category><![CDATA[Vulnerability]]></category>
		<category><![CDATA[Weblogic]]></category>
		<category><![CDATA[Workarounds]]></category>

		<guid isPermaLink="false">http://www.darkfiberla.com/security-alerts/oracle-releases-security-advisory-for-weblogic-plug-in-vulnerability/</guid>
		<description><![CDATA[Oracle has released a Security Advisory to address a vulnerability in the WebLogic plug-in for Apache. Exploitation of this vulnerability may allow a remote, unauthenticated attacker to compromise the confidentiality or integrity of WebLogic Server applications or cause a denial-of-service condition. The advisory indicates that exploit code for this vulnerability is publicly available. DarkFiber Consulting [...]]]></description>
			<content:encoded><![CDATA[<p>Oracle has released a <a href="https://support.bea.com/application_content/product_portlets/securityadvisories/2793.html" target="_self">Security Advisory</a> to address a vulnerability in the WebLogic plug-in for Apache. Exploitation of this vulnerability may allow a remote, unauthenticated attacker to compromise the confidentiality or integrity of WebLogic Server applications or cause a denial-of-service condition. The advisory indicates that exploit code for this vulnerability is publicly available.</p>
<p>DarkFiber Consulting encourages users to review the <a href="https://support.bea.com/application_content/product_portlets/securityadvisories/2793.html" target="_self">Oracle Security Advisory</a> and implement the workarounds listed in the document to help mitigate the risks. At this time, a patch or update is not available.</p>
<p>DarkFiber Consulting will provide additional information as it becomes available.</p>

	Tags: <a href="http://www.darkfiberla.com/tag/address/" title="Address" rel="tag">Address</a>, <a href="http://www.darkfiberla.com/tag/apache/" title="Apache" rel="tag">Apache</a>, <a href="http://www.darkfiberla.com/tag/attacker/" title="Attacker" rel="tag">Attacker</a>, <a href="http://www.darkfiberla.com/tag/confidentiality/" title="Confidentiality" rel="tag">Confidentiality</a>, <a href="http://www.darkfiberla.com/tag/denial-of-service/" title="Denial Of Service" rel="tag">Denial Of Service</a>, <a href="http://www.darkfiberla.com/tag/exploit/" title="Exploit" rel="tag">Exploit</a>, <a href="http://www.darkfiberla.com/tag/integrity/" title="Integrity" rel="tag">Integrity</a>, <a href="http://www.darkfiberla.com/tag/oracle/" title="Oracle" rel="tag">Oracle</a>, <a href="http://www.darkfiberla.com/tag/oracle-security/" title="Oracle Security" rel="tag">Oracle Security</a>, <a href="http://www.darkfiberla.com/tag/security-advisory/" title="Security Advisory" rel="tag">Security Advisory</a>, <a href="http://www.darkfiberla.com/tag/server-applications/" title="Server Applications" rel="tag">Server Applications</a>, <a href="http://www.darkfiberla.com/tag/vulnerability/" title="Vulnerability" rel="tag">Vulnerability</a>, <a href="http://www.darkfiberla.com/tag/weblogic/" title="Weblogic" rel="tag">Weblogic</a>, <a href="http://www.darkfiberla.com/tag/workarounds/" title="Workarounds" rel="tag">Workarounds</a><br />
]]></content:encoded>
			<wfw:commentRss>http://www.darkfiberla.com/security-alerts/oracle-releases-security-advisory-for-weblogic-plug-in-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
