<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>QuietMove &#187; Blog</title>
	<atom:link href="http://www.quietmove.com/category/blog/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.quietmove.com</link>
	<description>Penetration Testing : Web Application Security : IT Audit : PCI DSS Developer Training</description>
	<lastBuildDate>Mon, 01 Mar 2010 09:34:51 +0000</lastBuildDate>
	
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Microsoft makes its four core SDL Training classes available to the public</title>
		<link>http://www.quietmove.com/2010/03/microsoft-makes-its-four-core-sdl-training-classes-available-to-the-public/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2010/03/microsoft-makes-its-four-core-sdl-training-classes-available-to-the-public/#comments</comments>
		<pubDate>Mon, 01 Mar 2010 09:33:40 +0000</pubDate>
		<dc:creator>qmadmin</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[microsoft]]></category>
		<category><![CDATA[sdl]]></category>
		<category><![CDATA[web application security]]></category>

		<guid isPermaLink="false">http://www.quietmove.com/?p=936</guid>
		<description><![CDATA[Microsoft makes its four core SDL Training classes available to the public: Introduction to the Microsoft Security Development Lifecycle (SDL); Introduction to Microsoft Threat Modeling; Basics of Secure Design, Development, and Test; Privacy for Software Development.
You can download all the SDL materials and accompanying tools from the Microsoft site.
Tools are categorized by phase of the [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2010/03/microsoft-makes-its-four-core-sdl-training-classes-available-to-the-public/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PCI-DSS Compliance and Third Party Custom Application Vendors</title>
		<link>http://www.quietmove.com/2009/08/pci-dss-compliance-and-custom-third-party-application-vendors/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2009/08/pci-dss-compliance-and-custom-third-party-application-vendors/#comments</comments>
		<pubDate>Sat, 22 Aug 2009 18:41:17 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.quietmove.com/?p=922</guid>
		<description><![CDATA[We have been performing many interesting PCI DSS compliance projects, recently, assisting organizations in identifying their  security and compliance gaps, creating remediation project plans, and assisting  in communication with the acquiring bank that process their credit card transactions, often ghost-writing correspondence.
One of the most interesting things to come up recently has been the response from [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2009/08/pci-dss-compliance-and-custom-third-party-application-vendors/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Insider Threat: AMEX DBA steals Credit Card data</title>
		<link>http://www.quietmove.com/2009/07/insider-threat-amex-dba-steals-credit-card-data/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2009/07/insider-threat-amex-dba-steals-credit-card-data/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 19:14:39 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.quietmove.com/?p=860</guid>
		<description><![CDATA[A DBA at American Express in Phoenix used his access to steal credit card numbers and PINs, encoded the card numbers onto blank cards, and used them to make purchases.
AMEX was hit by a long-standing database security management problem &#8211; how do you log the DBA&#8217;s activities, when the logs are stored in tables the [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2009/07/insider-threat-amex-dba-steals-credit-card-data/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rumors of new OpenSSH exploit in the wild, for older versions</title>
		<link>http://www.quietmove.com/2009/07/rumors-of-new-openssh-exploit-in-the-wild-for-older-versions/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2009/07/rumors-of-new-openssh-exploit-in-the-wild-for-older-versions/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 16:58:52 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[0day]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://www.quietmove.com/?p=858</guid>
		<description><![CDATA[http://www.theregister.co.uk/2009/07/08/openssh_exploit_rumour/
http://secer.org/hacktools/0day-openssh-remote-exploit.html
We first heard these rumors a couple days ago, but sat on it because there was no evidence at the time, and no one is served by the release of fake exploit reports.
The very latest versions of OpenSSH are apparently immune &#8211; this makes us think of a few posibilities:

Denial of Service condition from years [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2009/07/rumors-of-new-openssh-exploit-in-the-wild-for-older-versions/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cyber Warfare Trends for 2010: Network Attacks are the 21st Century&#8217;s Longbow</title>
		<link>http://www.quietmove.com/2009/07/cyber-warfare-trends-for-2010-network-attacks-are-the-21st-centurys-longbow/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2009/07/cyber-warfare-trends-for-2010-network-attacks-are-the-21st-centurys-longbow/#comments</comments>
		<pubDate>Wed, 08 Jul 2009 09:29:36 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.quietmove.com/?p=852</guid>
		<description><![CDATA[In the history or warfare, the ability to deliver powerful attacks from a distance has often been the deciding factors of conflicts. The prehistoric spear thrower  begat the javelin, spear, longbow, cannon, rifle, intercontinental ballistic missile, and most recently&#8230; the remote exploit.
Reuters reports:
SEOUL (Reuters) &#8211; South Korean authorities issued a cyber security warning on Wednesday [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2009/07/cyber-warfare-trends-for-2010-network-attacks-are-the-21st-centurys-longbow/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Poor Man&#8217;s Web Application Firewall (WAF) with Apache mod_rewrite</title>
		<link>http://www.quietmove.com/2009/07/poor-mans-web-application-firewall-waf-with-apache-mod_rewrite/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2009/07/poor-mans-web-application-firewall-waf-with-apache-mod_rewrite/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 18:30:31 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.quietmove.com/?p=830</guid>
		<description><![CDATA[mod_rewrite can be used to protect against many types of XSS, XSRF, injection, HTTP verb abuse, referer link spam, image hijacking, and other things.
Here are a few articles with samples and examples of ways to use Apache mod_rewrite and .htaccess files to protect yourself.
http://perishablepress.com/press/2009/02/03/eight-ways-to-blacklist-with-apaches-mod_rewrite/
http://www.askapache.com/htaccess/mod_rewrite-tips-and-tricks.htm
http://www.askapache.com/htaccess/mod_rewrite-variables-cheatsheet.html
Of course there is always mod_security in addition to a range of [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2009/07/poor-mans-web-application-firewall-waf-with-apache-mod_rewrite/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>TorrentReactor Breach Used To Attack Users, Tip: How To Detect You&#8217;ve Been Hacked</title>
		<link>http://www.quietmove.com/2009/07/torrentreactor-breach-used-to-attack-users-tip-how-to-detect-youve-been-hacked/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2009/07/torrentreactor-breach-used-to-attack-users-tip-how-to-detect-youve-been-hacked/#comments</comments>
		<pubDate>Thu, 02 Jul 2009 21:16:24 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://quietmove.com/?p=760</guid>
		<description><![CDATA[In a nutshell &#8211; A recent trend in botnet/malware herder attacks is that are looking for new &#8211; and old &#8211; ways to accomplish the main purpose of including javascript malware on legitimate sites, often using traditional hacking methods.
Emphasis in the quote below is mine. Similar to the reports of FTP hacking recently, where attackers [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2009/07/torrentreactor-breach-used-to-attack-users-tip-how-to-detect-youve-been-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Follow QuietMove on Twitter</title>
		<link>http://www.quietmove.com/2009/07/follow-quietmove-on-twitter/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2009/07/follow-quietmove-on-twitter/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 05:10:16 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[#hack]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#owasp #pci]]></category>
		<category><![CDATA[#pcidss]]></category>
		<category><![CDATA[#webappsec]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[quietmove]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[twitter]]></category>

		<guid isPermaLink="false">http://quietmove.com/?p=758</guid>
		<description><![CDATA[We&#8217;re now posting the freshest, most relevant Information Security news to Twitter.
If you follow the &#8220;Security twit&#8221; hashtags #infosec, #security, #hack, #pci, #pcidss, and #webappsec, no doubt you&#8217;ve seen some of our posting.
Follow us, and we&#8217;ll follow you back!
http://twitter.com/quietmove


No related posts.


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2009/07/follow-quietmove-on-twitter/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web App Security: Comparing and contrasting Black Box, White Box, Fault Injection, and SCA</title>
		<link>http://www.quietmove.com/2007/06/web-app-security-comparing-and-contrasting-black-box-white-box-fault-injection-and-sca/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2007/06/web-app-security-comparing-and-contrasting-black-box-white-box-fault-injection-and-sca/#comments</comments>
		<pubDate>Thu, 14 Jun 2007 00:58:41 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.quietmove.com/blog/web-app-security-comparing-and-contrasting-black-box-white-box-fault-injection-and-sca/</guid>
		<description><![CDATA[This article is based on a talk I gave at the Phoenix OWASP chapter on May 10th.My intention is to summarize the methods used to assess the security of web applications, identify what they are good and not so good at finding, and outline their varying strengths and weaknesses.  If you’ll indulge me, I’d [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2007/06/web-app-security-comparing-and-contrasting-black-box-white-box-fault-injection-and-sca/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Hackers from India Indicted for Online Brokerage Intrusion Scheme</title>
		<link>http://www.quietmove.com/2007/03/hackers-from-india-indicted-for-online-brokerage-intrusion-scheme/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.quietmove.com/2007/03/hackers-from-india-indicted-for-online-brokerage-intrusion-scheme/#comments</comments>
		<pubDate>Sat, 17 Mar 2007 17:24:24 +0000</pubDate>
		<dc:creator>QuietMove</dc:creator>
				<category><![CDATA[Blog]]></category>

		<guid isPermaLink="false">http://www.quietmove.com/blog/hackers-from-india-indicted-for-online-brokerage-intrusion-scheme/</guid>
		<description><![CDATA[From http://www.infozine.com/news/stories/op/storiesView/sid/21633/
A few snippets from the article:
 &#8220;A federal grand jury in Omaha, Neb., has indicted three individuals on charges of conspiracy, fraud and aggravated identity theft stemming from a high-tech, international fraud scheme designed to hijack online brokerage accounts for profit&#8230;&#8221;
&#8220;As part of this ongoing investigation, at least 60 customers and nine brokerage firms [...]


No related posts.]]></description>
		<wfw:commentRss>http://www.quietmove.com/2007/03/hackers-from-india-indicted-for-online-brokerage-intrusion-scheme/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
