<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>GeekTimeLinux &#187; Security</title>
	<atom:link href="http://geektimelinux.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://geektimelinux.com</link>
	<description>All Things Linux</description>
	<lastBuildDate>Thu, 01 Oct 2009 18:53:07 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Off the wire:  Wi-fi security system is &#8216;broken&#8217;</title>
		<link>http://geektimelinux.com/2007/10/19/off-the-wire-wi-fi-security-system-is-broken/</link>
		<comments>http://geektimelinux.com/2007/10/19/off-the-wire-wi-fi-security-system-is-broken/#comments</comments>
		<pubDate>Sat, 20 Oct 2007 04:06:37 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[wifi]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/19/off-the-wire-wi-fi-security-system-is-broken/</guid>
		<description><![CDATA[(Via Help Net Security &#8211; News.)
More holes have been picked in the security measure designed to protect the privacy and data of wi-fi users.
]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://feeds.feedburner.com/~r/HelpNetSecurity/~3/172134586/news.php">Help Net Security &#8211; News</a>.)</p>
<p>More holes have been picked in the security measure designed to protect the privacy and data of wi-fi users.</p>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/19/off-the-wire-wi-fi-security-system-is-broken/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Debian Security Advisory &#8211; New Linux 2.6.18 packages fix several &#8230; &#8211; Help Net Security</title>
		<link>http://geektimelinux.com/2007/10/13/debian-security-advisory-new-linux-2618-packages-fix-several-help-net-security/</link>
		<comments>http://geektimelinux.com/2007/10/13/debian-security-advisory-new-linux-2618-packages-fix-several-help-net-security/#comments</comments>
		<pubDate>Sat, 13 Oct 2007 13:39:39 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Distributions]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/14/debian-security-advisory-new-linux-2618-packages-fix-several-help-net-security/</guid>
		<description><![CDATA[(Via linux news &#8211; Google News.)




Debian Security Advisory &#8211; New Linux 2.6.18 packages  fix several &#8230;Help Net Security,&#160;Croatia&#160;- 35 minutes agoThis vulnerability is relevant to the Debian amd64 port as well as users of the i386 port who run the amd64 linux-image flavour. &#8230;



]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://news.google.com/news/url?sa=T&#038;ct=us/3-0&#038;fd=R&#038;url=http://www.net-security.org/advisory.php%3Fid%3D8013&#038;cid=1122127573&#038;ei=uBoSR539MJ6sao2wzYYO">linux news &#8211; Google News</a>.)</p>
<p>
<table border=0 width= valign=top cellpadding=2 cellspacing=7>
<tr>
<td valign=top class=j>
<div class=lh><a href="http://news.google.com/news/url?sa=T&#038;ct=us/3-0&#038;fd=R&#038;url=http://www.net-security.org/advisory.php%3Fid%3D8013&#038;cid=1122127573&#038;ei=uBoSR539MJ6sao2wzYYO">Debian Security Advisory &#8211; New <b>Linux</b> 2.6.18 packages  fix several <b>&#8230;</b></a><br /><font size=-1><font color=#6f6f6f>Help Net Security,&nbsp;Croatia&nbsp;-</font> <nobr>35 minutes ago</nobr></font><br /><font size=-1>This vulnerability is relevant to the Debian amd64 port as well as users of the i386 port who run the amd64 <b>linux</b>-image flavour. <b>&#8230;</b></font></div>
</td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/13/debian-security-advisory-new-linux-2618-packages-fix-several-help-net-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gentoo Linux Security Advisory &#8211; DenyHosts: Denial of Service &#8230; &#8211; Help Net Security</title>
		<link>http://geektimelinux.com/2007/10/13/gentoo-linux-security-advisory-denyhosts-denial-of-service-help-net-security/</link>
		<comments>http://geektimelinux.com/2007/10/13/gentoo-linux-security-advisory-denyhosts-denial-of-service-help-net-security/#comments</comments>
		<pubDate>Sat, 13 Oct 2007 13:39:22 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Distributions]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/14/gentoo-linux-security-advisory-denyhosts-denial-of-service-help-net-security/</guid>
		<description><![CDATA[(Via linux news &#8211; Google News.)




Gentoo Linux Security Advisory &#8211; DenyHosts: Denial of Service &#8230;Help Net Security,&#160;Croatia&#160;- 34 minutes agoSecurity is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users machines is of utmost importance to us. &#8230;



]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://news.google.com/news/url?sa=T&#038;ct=us/4-0&#038;fd=R&#038;url=http://www.net-security.org/advisory.php%3Fid%3D8011&#038;cid=0&#038;ei=uBoSR539MJ6sao2wzYYO">linux news &#8211; Google News</a>.)</p>
<p>
<table border=0 width= valign=top cellpadding=2 cellspacing=7>
<tr>
<td valign=top class=j>
<div class=lh><a href="http://news.google.com/news/url?sa=T&#038;ct=us/4-0&#038;fd=R&#038;url=http://www.net-security.org/advisory.php%3Fid%3D8011&#038;cid=0&#038;ei=uBoSR539MJ6sao2wzYYO">Gentoo <b>Linux</b> Security Advisory &#8211; DenyHosts: Denial of Service <b>&#8230;</b></a><br /><font size=-1><font color=#6f6f6f>Help Net Security,&nbsp;Croatia&nbsp;-</font> <nobr>34 minutes ago</nobr></font><br /><font size=-1>Security is a primary focus of Gentoo <b>Linux</b> and ensuring the confidentiality and security of our users machines is of utmost importance to us. <b>&#8230;</b></font></div>
</td>
</tr>
</table>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/13/gentoo-linux-security-advisory-denyhosts-denial-of-service-help-net-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Insecure by Default</title>
		<link>http://geektimelinux.com/2007/10/11/insecure-by-default/</link>
		<comments>http://geektimelinux.com/2007/10/11/insecure-by-default/#comments</comments>
		<pubDate>Thu, 11 Oct 2007 23:10:10 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/11/insecure-by-default/</guid>
		<description><![CDATA[(Via LXer Linux News.)
Guess what, I can walk up to your Ubuntu, PCLinuxOS, Debian, etc desktop installation and take complete control over it without needing a single password. Thats right, root access simply by sitting down at your computer. Why is it nearly every single distro by default leaves this gaping security hole open?
]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://lxer.com/module/newswire/ext_link.php?rid=93953">LXer Linux News</a>.)</p>
<p>Guess what, I can walk up to your Ubuntu, PCLinuxOS, Debian, etc desktop installation and take complete control over it without needing a single password. Thats right, root access simply by sitting down at your computer. Why is it nearly every single distro by default leaves this gaping security hole open?</p>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/11/insecure-by-default/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Off the wire:  Secure your webserver using SSL and TinyCA</title>
		<link>http://geektimelinux.com/2007/10/10/off-the-wire-secure-your-webserver-using-ssl-and-tinyca/</link>
		<comments>http://geektimelinux.com/2007/10/10/off-the-wire-secure-your-webserver-using-ssl-and-tinyca/#comments</comments>
		<pubDate>Wed, 10 Oct 2007 11:23:46 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/10/off-the-wire-secure-your-webserver-using-ssl-and-tinyca/</guid>
		<description><![CDATA[(Via Help Net Security.)
SSL is especially suited for HTTP since it can provide some protection even if only one side of the communication is authenticated.
]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://feeds.feedburner.com/~r/HelpNetSecurity/~3/167810722/news.php">Help Net Security</a>.)</p>
<p>SSL is especially suited for HTTP since it can provide some protection even if only one side of the communication is authenticated.</p>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/10/off-the-wire-secure-your-webserver-using-ssl-and-tinyca/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ubuntu:  xen-3.0 vulnerability</title>
		<link>http://geektimelinux.com/2007/10/09/ubuntu-xen-30-vulnerability/</link>
		<comments>http://geektimelinux.com/2007/10/09/ubuntu-xen-30-vulnerability/#comments</comments>
		<pubDate>Tue, 09 Oct 2007 23:12:10 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Distributions]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/09/ubuntu-xen-30-vulnerability/</guid>
		<description><![CDATA[(Via LinuxSecurity.com &#8211; Security Advisories.)
LinuxSecurity.com: Joris van Rantwijk discovered that the Xen host did not correctly validate the contents of a Xen guests&#8217;s grug.conf file.  Xen guest root users could exploit this to run arbitrary commands on the host when the guest system was rebooted.
]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://www.linuxsecurity.com/content/view/129965?rdf">LinuxSecurity.com &#8211; Security Advisories</a>.)</p>
<p><b>LinuxSecurity.com</b>: Joris van Rantwijk discovered that the Xen host did not correctly validate the contents of a Xen guests&#8217;s grug.conf file.  Xen guest root users could exploit this to run arbitrary commands on the host when the guest system was rebooted.</p>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/09/ubuntu-xen-30-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Debian: New gforge packages fix cross-site scripting</title>
		<link>http://geektimelinux.com/2007/10/07/debian-new-gforge-packages-fix-cross-site-scripting/</link>
		<comments>http://geektimelinux.com/2007/10/07/debian-new-gforge-packages-fix-cross-site-scripting/#comments</comments>
		<pubDate>Sun, 07 Oct 2007 14:51:09 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/07/debian-new-gforge-packages-fix-cross-site-scripting/</guid>
		<description><![CDATA[(Via LinuxSecurity.com &#8211; Security Advisories.)
LinuxSecurity.com: It was discovered that a cross site scripting vulnerability in GForge, a collaborative development tool, allows remote attackers to inject arbitrary web script or HTML in the context of a logged in user&#8217;s session.
]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://www.linuxsecurity.com/content/view/129890?rdf">LinuxSecurity.com &#8211; Security Advisories</a>.)</p>
<p><b>LinuxSecurity.com</b>: It was discovered that a cross site scripting vulnerability in GForge, a collaborative development tool, allows remote attackers to inject arbitrary web script or HTML in the context of a logged in user&#8217;s session.</p>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/07/debian-new-gforge-packages-fix-cross-site-scripting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mandriva: Updated openssl packages fix vulnerabilities</title>
		<link>http://geektimelinux.com/2007/10/07/mandriva-updated-openssl-packages-fix-vulnerabilities/</link>
		<comments>http://geektimelinux.com/2007/10/07/mandriva-updated-openssl-packages-fix-vulnerabilities/#comments</comments>
		<pubDate>Sun, 07 Oct 2007 14:50:53 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/07/mandriva-updated-openssl-packages-fix-vulnerabilities/</guid>
		<description><![CDATA[(Via LinuxSecurity.com &#8211; Security Advisories.)
LinuxSecurity.com:  A flaw in how OpenSSL performed Montgomery multiplications was discovered %that could allow a local attacker to reconstruct RSA private keys by examining another user&#8217;s OpenSSL processes (CVE-2007-3108).
]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://www.linuxsecurity.com/content/view/129892?rdf">LinuxSecurity.com &#8211; Security Advisories</a>.)</p>
<p><b>LinuxSecurity.com</b>:  A flaw in how OpenSSL performed Montgomery multiplications was discovered %that could allow a local attacker to reconstruct RSA private keys by examining another user&#8217;s OpenSSL processes (CVE-2007-3108).</p>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/07/mandriva-updated-openssl-packages-fix-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ubuntu:  OpenOffice.org vulnerability</title>
		<link>http://geektimelinux.com/2007/10/07/ubuntu-openofficeorg-vulnerability/</link>
		<comments>http://geektimelinux.com/2007/10/07/ubuntu-openofficeorg-vulnerability/#comments</comments>
		<pubDate>Sun, 07 Oct 2007 14:50:32 +0000</pubDate>
		<dc:creator>tony</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://geektimelinux.com/2007/10/07/ubuntu-openofficeorg-vulnerability/</guid>
		<description><![CDATA[(Via LinuxSecurity.com &#8211; Security Advisories.)
LinuxSecurity.com: An integer overflow was discovered in the TIFF handling code in OpenOffice. If a user were tricked into loading a malicious TIFF image, a remote attacker  could execute arbitrary code with user privileges.
]]></description>
			<content:encoded><![CDATA[<p>(Via <a href="http://www.linuxsecurity.com/content/view/129891?rdf">LinuxSecurity.com &#8211; Security Advisories</a>.)</p>
<p><b>LinuxSecurity.com</b>: An integer overflow was discovered in the TIFF handling code in OpenOffice. If a user were tricked into loading a malicious TIFF image, a remote attacker  could execute arbitrary code with user privileges.</p>
]]></content:encoded>
			<wfw:commentRss>http://geektimelinux.com/2007/10/07/ubuntu-openofficeorg-vulnerability/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
