<?xml version="1.0" encoding="gb2312"?>
<rss version="2.0">
<channel>
<title><![CDATA[Sowhat的blog]]></title>
        <image>
        <title>http://hi.baidu.com</title>
        <link>http://hi.baidu.com</link>
        <url>http://img.baidu.com/img/logo-hi.gif</url>
        </image>
<description><![CDATA[本blog所有内容仅代表作者个人.]]></description>
<link>http://hi.baidu.com/secway</link>
<language>zh-cn</language>
<generator>www.baidu.com</generator>
<ttl>5</ttl>


<item>
        <title><![CDATA[NIST新增网际安全职能 (Cybersecurity Coordination and Awareness Act)]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/86c5c78f987135e4f01f362f.html]]></link>
        <description><![CDATA[
		
		<p>美国众议院科学与技术委员会今天通过一项新的<a target="_blank" href="http://science.house.gov/legislation/leg_highlights_detail.aspx?NewsID=2674">法案</a>,增加了NIST在网际安全(cybersecurity)方面的职能.</p>
<p>根据此法案, NIST将负责指定一个计划来协调政府和国际组织间在开发新的网际安全标准方面的合作.</p>
<p>同时, NIST也将于政府机构, 业界和学术界共同合作, 对网际安全风险和最佳实践等, 进行公众教育</p>
<p><a target="_blank" href="http://www.nist.gov/">NIST</a>-美国国家标准技术研究院（National In</p> <a href="http://hi.baidu.com/secway/blog/item/86c5c78f987135e4f01f362f.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Cybersecurity">Cybersecurity</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/86c5c78f987135e4f01f362f.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-10  09:56</pubDate>
        <category><![CDATA[Cybersecurity]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/86c5c78f987135e4f01f362f.html</guid>
</item>

<item>
        <title><![CDATA[早期搞笑CVE]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/a8df22dada3b99d1b7fd4872.html]]></link>
        <description><![CDATA[
		
		<p><a target="_blank" href="http://blog.osvdb.org/2009/11/09/what-i-learned-from-early-cve-entries">OSVDB的人</a>从以前的老CVE里面翻出来几个比较有意思的. 尤其现在回过头来,看10年前的CVE,</p>
<p>早期CVE是通过投票来决定是否收录某一个漏洞.</p>
<p>可以点开具体看看: 倒数第2个就比较搞</p>
<p><a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=1999-0345">http://cve.mitre.org/cgi-bin/cvename.cgi?name=1999-0345</a> - CVE contributors can be stumped</p>
<p></p> <a href="http://hi.baidu.com/secway/blog/item/a8df22dada3b99d1b7fd4872.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/a8df22dada3b99d1b7fd4872.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-10  08:26</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/a8df22dada3b99d1b7fd4872.html</guid>
</item>

<item>
        <title><![CDATA[TLS/SSL3.0漏洞最新进展 - OpenSSL补丁]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/2fb4d70f36106ce7aa645775.html]]></link>
        <description><![CDATA[
		
		<p>昨天报道的<a target="_blank" href="http://hi.baidu.com/secway/blog/item/e5f405c6bd075a119c163d6a.html">TLS中间人攻击</a>, 今天OpenSSL已经有了补丁, 速度挺快.</p>
<p>不过这个补丁并不是从协议上修补了漏洞,而只是默认情况下关闭了renegotiation.</p>
<p>使用OPENSSL的用户, 可以去其官网升级了: <a href="http://www.openssl.org/source/">http://www.openssl.org/source/</a></p>
<p>不过如同牛人们(<a target="_blank" href="http://blogs.iss.net/archive/sslmitmiscsrf.html">Tom Cross@ISS</a>, </p> <a href="http://hi.baidu.com/secway/blog/item/2fb4d70f36106ce7aa645775.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/2fb4d70f36106ce7aa645775.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-07  07:27</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/2fb4d70f36106ce7aa645775.html</guid>
</item>

<item>
        <title><![CDATA[Facebook平台开发人员安全指南]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/2cf54e6d961626f142169470.html]]></link>
        <description><![CDATA[
		
		<p>Facebook<a target="_blank" href="http://is.gd/4Odsu">发布</a>了一个安全指南, 以指导Facebook平台上的开发人员, 主要是参考OWASP和Microsoft的资源.</p>
<p><a href="http://wiki.developers.facebook.com/index.php/Platform_Security">http://wiki.developers.facebook.com/index.php/Platform_Security</a></p>
<p> </p>
<li class="toclevel-1"><a href="http://wiki.developers.facebook.com/index.php/Platform_Security#Facebook_Platform_Security_Features"><span class="tocnumber">1</span> </a></li> <a href="http://hi.baidu.com/secway/blog/item/2cf54e6d961626f142169470.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Security">Security</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/2cf54e6d961626f142169470.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-06  08:01</pubDate>
        <category><![CDATA[Security]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/2cf54e6d961626f142169470.html</guid>
</item>

<item>
        <title><![CDATA[新的TLS/SSL3.0中间人攻击已公布 - TLS renegotiation attack]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/e5f405c6bd075a119c163d6a.html]]></link>
        <description><![CDATA[
		
		<p>刚刚有研究人员公布了一种针对TLS/SSL的中间人攻击, 该攻击</p>
<p>1. exploitable (可操作性比较强)</p>
<p>2. 目前还没有解决方案, 等待各厂商出补丁.</p>
<p>3. 受影响的上层协议包括HTTPS,IMAP, SIP等等.</p>
<p> </p>
<p><a target="_blank" href="http://www.educatedguesswork.org/2009/11/understanding_the_tls_renegoti.html">有人举了下面这个例子</a>来帮助大家理解此洞</p>
<p><font color="#0b5394">E.g., the attacker would send: </font></p>
 <a href="http://hi.baidu.com/secway/blog/item/e5f405c6bd075a119c163d6a.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/e5f405c6bd075a119c163d6a.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-06  07:28</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/e5f405c6bd075a119c163d6a.html</guid>
</item>

<item>
        <title><![CDATA[非法获取出售公民个人信息将获罪]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/e999a258f4eaff8b800a181f.html]]></link>
        <description><![CDATA[
		
		<p>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;  <a target="_blank" href="http://www.ahsz.tv/Article/ShowArticle.asp?ArticleID=8347">非法获取出售公民个人信息将获罪 </a><br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</p> <a href="http://hi.baidu.com/secway/blog/item/e999a258f4eaff8b800a181f.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Cybersecurity">Cybersecurity</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/e999a258f4eaff8b800a181f.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-05  15:39</pubDate>
        <category><![CDATA[Cybersecurity]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/e999a258f4eaff8b800a181f.html</guid>
</item>

<item>
        <title><![CDATA[火星科技有限公司]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/46e1f18be72e3ad9fd1f1032.html]]></link>
        <description><![CDATA[
		
		<p><em>twitter上不去,就在这微博一篇.</em></p>
<p>还真有这么个公司,而且跟安全还沾点边</p>
<p>火星科技<a target="_blank" href="http://www.marstor.com.cn/special.php?id=7">大事记</a></p>
<p>2008-07-01:成立天津<strong>火星科技有限公司</strong>，作为北京亚细亚存储、备份和容灾研发基地<br>
2009-03：与华苑产业园区合作建立存储技术测试和实验室<br>
2009-09：拥有全部自主知识产权的国产企业级<strong>跨平台备份软件产业化项目获得国家发改委450万元资金支持<br>
</strong> </p> 
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Misc">Misc</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/46e1f18be72e3ad9fd1f1032.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-05  08:45</pubDate>
        <category><![CDATA[Misc]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/46e1f18be72e3ad9fd1f1032.html</guid>
</item>

<item>
        <title><![CDATA[360周鸿袆：明年安全软件要么免费要么退出市场!]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/7de1223de4bacbe43d6d9730.html]]></link>
        <description><![CDATA[
		
		<p><a target="_blank" href="http://tech.163.com/09/1103/16/5N7638N000093ST8.html"><font color="#1e50a2">网易科技</font>讯</a> 11月3日消息，互联网大会第二天，360安全卫士董事长周鸿袆在接受<font color="#000000">网易</font>科技专访时表示，360安全卫士采用免费模式并非是市场搅局者，他大胆断言，<font color="#ff0000">明年所有的安全软件要么就免费，要么就退出市场。</font></p>
<p><font color="#000000">周鸿祎</font>还透露，目前很多杀毒软件实际上是谋取暴利：&ldquo;其实每年研发的钱就那么多，收集点病毒就</p> <a href="http://hi.baidu.com/secway/blog/item/7de1223de4bacbe43d6d9730.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Security">Security</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/7de1223de4bacbe43d6d9730.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-05  08:39</pubDate>
        <category><![CDATA[Security]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/7de1223de4bacbe43d6d9730.html</guid>
</item>

<item>
        <title><![CDATA[str0ke@milw0rm过世了?]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/a1315b34d23393315bb5f5ab.html]]></link>
        <description><![CDATA[
		
		<p>四个月之前, <a target="_blank" href="http://hi.baidu.com/secway/blog/item/18393c4a362f002a09f7efd4.html">milw0rm关闭了一次</a>, 最后发现是str0ke逗大家玩的.</p>
<p>这次<a target="_blank" href="http://www.milw0rm.com/">milw0rm</a>连续有将近两个月没有更新了, 也看到很多人在打听milw0rm怎么了.</p>
<p>刚才看到有朋友在群里转贴的下面这个blog, 说str0ke因为心脏问题, 今天早上过世了. 留下妻子一个人带4个小孩.</p>
<p>今天不是愚人节, 但还是希望这个消息是假的.</p>
<p>虽然没跟str0ke见过面, 但是几年前好像</p> <a href="http://hi.baidu.com/secway/blog/item/a1315b34d23393315bb5f5ab.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Security">Security</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/a1315b34d23393315bb5f5ab.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-04  16:03</pubDate>
        <category><![CDATA[Security]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/a1315b34d23393315bb5f5ab.html</guid>
</item>

<item>
        <title><![CDATA[[最新报告]Microsoft Security Intelligence Report volume 7]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/ff99ca01d0357a09738da5a8.html]]></link>
        <description><![CDATA[
		
		<p>Microsoft今天发布了针对09年上半年的报告: Microsoft Security Intelligence Report volume 7.</p>
<p>有几个数据比较有意思:</p>
<p><span><span><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/secway/pic/item/cc1a3990266824a3a977a4d2.jpg"><br>
</span>在VISTA上被搞最多的前10大漏洞中, 天朝民众独享其中5个, 同时还与国际友人分享了其余5个!</span></p>
<p> </p>
<p></p> <a href="http://hi.baidu.com/secway/blog/item/ff99ca01d0357a09738da5a8.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Report">Report</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/ff99ca01d0357a09738da5a8.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-03  08:10</pubDate>
        <category><![CDATA[Report]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/ff99ca01d0357a09738da5a8.html</guid>
</item>

<item>
        <title><![CDATA[turbodiff - Coresecurity]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/a079f635c5e86d1b90ef393f.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<p>继<a target="_blank" href="http://www.zynamics.com/index.php?page=bindiff">Sabre Bindiff</a>, <a target="_blank" href="http://hi.baidu.com/tombkeeper/blog/item/084e92cb836a08f853664f2f.html">Nsfocus bindiff</a>和<a target="_blank" href="http://hi.baidu.com/secway/blog/item/41b32ddf7e52061648540361.html">Patchdiff2</a>之后, 又来一个bindiff工具,免费的Turbodiff.</p>
<p></p> <a href="http://hi.baidu.com/secway/blog/item/a079f635c5e86d1b90ef393f.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/a079f635c5e86d1b90ef393f.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-02  10:19</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/a079f635c5e86d1b90ef393f.html</guid>
</item>

<item>
        <title><![CDATA[中国信息安全漏洞库（China Information Security Vulnerability Database，简称CNVD)]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/2c99c1b7db788bfe30add164.html]]></link>
        <description><![CDATA[
		
		<p>又来一个新的库, 中国信息安全漏洞库（China Information Security Vulnerability Database，简称CNVD)</p>
<p>跟前两天测评中心的<a target="_blank" href="http://hi.baidu.com/secway/blog/item/10237fd7b894f4d7a144dfb9.html">国家漏洞库</a>还不一样.</p>
<p>详情参见: <a target="_blank" href="http://tech.qq.com/a/20091022/000160.htm">20余家企业共建国家信息安全漏洞共享平台</a></p>
<p style="text-indent: 2em"><strong>国家信息安全漏洞共享平台共建成员单位如下：</strong></p>
<p style="text-indent: 2em"></p> <a href="http://hi.baidu.com/secway/blog/item/2c99c1b7db788bfe30add164.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/2c99c1b7db788bfe30add164.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-01  13:29</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/2c99c1b7db788bfe30add164.html</guid>
</item>

<item>
        <title><![CDATA[NSA局长兼任美网络司令部司令]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/87c8242cd2cc2ee68a13995e.html]]></link>
        <description><![CDATA[
		
		<p>如<a target="_blank" href="http://hi.baidu.com/secway/blog/item/2fb4d70f96a9cce7ab64571c.html">此前</a>大家预期的一样,美国防部长盖茨推荐, 奥巴马终于任命了NSA局长兼任司令职务, 4颗星了.</p>
<p><span><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/secway/pic/item/538c2aee384f04d5b2fb9508.jpg"><br>
</span></p>
<p><a href="http://www.informationweek.com/news/government/security/showArticle.jhtml?articleID=220700278">http://www.informationweek.com/news/government/</a></p> <a href="http://hi.baidu.com/secway/blog/item/87c8242cd2cc2ee68a13995e.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Cybersecurity">Cybersecurity</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/87c8242cd2cc2ee68a13995e.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-01  08:39</pubDate>
        <category><![CDATA[Cybersecurity]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/87c8242cd2cc2ee68a13995e.html</guid>
</item>

<item>
        <title><![CDATA[美机构对中国军方网络战能力的研究报告]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/10237fd7979511d7a144dfb8.html]]></link>
        <description><![CDATA[
		
		<p>美国Northrop Grumman公司为US-China Economic and Security Review Commission做了一份我天朝军方网络战斗力的研究报告, 值得参考,借鉴,批判.</p>
<p>全文连接: <a href="http://www.uscc.gov/researchpapers/2009/NorthropGrumman_PRC_Cyber_Paper_FINAL_Approved%20Report_16Oct2009.pdf">http://www.uscc.gov/researchpapers/2009/NorthropGrumman_PRC_Cyber_Paper_FINAL_Approved%20Report_16Oct2009.pdf</a></p>
<p>88页,其中37页前后最精彩.</p>
<p>关键词: XFOCUS, NSFOCUS, VENUSTECH, 总参N部, 0day, PDF, WRI,各种黑x</p> <a href="http://hi.baidu.com/secway/blog/item/10237fd7979511d7a144dfb8.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Cybersecurity">Cybersecurity</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/10237fd7979511d7a144dfb8.html#comment">查看评论</a>]]></description>
        <pubDate>2009-11-01  00:06</pubDate>
        <category><![CDATA[Cybersecurity]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/10237fd7979511d7a144dfb8.html</guid>
</item>

<item>
        <title><![CDATA[ZDI关于漏洞市场内幕的介绍]]></title>
        <link><![CDATA[http://hi.baidu.com/secway/blog/item/b80a018b24573f18c8fc7a09.html]]></link>
        <description><![CDATA[
		
		<p> </p>
<p><a href="http://docs.google.com/present/view?id=dcc6wpsd_20ghbpjxcr">http://docs.google.com/present/view?id=dcc6wpsd_20ghbpjxcr</a></p>
<p>Pedram Amini<br>
pamini [at] tippingpoint</p>
<p>我选了几张比较有意思的,欢迎讨论</p>
<p>漏洞市场:</p>
<p><span><img class="blogimg" border="0" small="0" src="http://hiphotos.baidu.com/secway/pic/item/2cf54e6d48ea88d54316943f.jpg"></span></p>
<p><span>各家的价格:</span> (欢迎业内人士也列举一下国内的情况)</p>
<p></p> <a href="http://hi.baidu.com/secway/blog/item/b80a018b24573f18c8fc7a09.html">阅读全文</a>
		
		<br/><b>类别：</b><a href="http://hi.baidu.com/secway/blog/category/Vulnerability">Vulnerability</a>&nbsp;<a href="http://hi.baidu.com/secway/blog/item/b80a018b24573f18c8fc7a09.html#comment">查看评论</a>]]></description>
        <pubDate>2009-10-31  21:44</pubDate>
        <category><![CDATA[Vulnerability]]></category>
        <author><![CDATA[secway]]></author>
		<guid>http://hi.baidu.com/secway/blog/item/b80a018b24573f18c8fc7a09.html</guid>
</item>


</channel>
</rss>