<?xml version="1.0" encoding="UTF-8"?>
<rss version="0.92">
<channel>
	<title>Roy Firestein</title>
	<link>http://royfirestein.com</link>
	<description>Security Feeds</description>
	<lastBuildDate>Mon, 26 Jul 2010 02:53:01 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	
	<item>
		<title>I know who your name, where you work, and live (Safari v4 &amp; v5)</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Right at the moment a Safari user visits a website, even if they’ve never been there before or entered any personal information, a malicious website can uncover their first name, last name, work place, city, state, and email address. Safari v4 &#38; v5, with a combined [...]]]></description>
		<link>http://royfirestein.com/i-know-who-your-name-where-you-work-and-live-safari-v4-v5/</link>
			</item>
	<item>
		<title>In a cyber-war, we fight for economic well-being</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Earlier this month NPR’s Planet Money podcast had a session entitled, “A War Between States And Corporations,” where they interviewed Ian Bremmer (President, Eurasia Group). Mr. Bremmer is the author of The End of the Free Market: Who Wins the War Between States and Corporations? Near [...]]]></description>
		<link>http://royfirestein.com/in-a-cyber-war-we-fight-for-economic-well-being/</link>
			</item>
	<item>
		<title>You Don&#8217;t Want ISPs to Innovate</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
ISPs are trying to persuade the FCC not to impose basic rules on them, saying it will crush innovation. But when it comes to the tubes to your house, you don&#8217;t want their kind of &#8220;innovation.&#8221;






]]></description>
		<link>http://royfirestein.com/you-dont-want-isps-to-innovate-3/</link>
			</item>
	<item>
		<title>You Don&#8217;t Want ISPs to Innovate</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
ISPs are trying to persuade the FCC not to impose basic rules on them, saying it will crush innovation. But when it comes to the tubes to your house, you don&#8217;t want their kind of &#8220;innovation.&#8221;









]]></description>
		<link>http://royfirestein.com/you-dont-want-isps-to-innovate-2/</link>
			</item>
	<item>
		<title>You Don&#8217;t Want ISPs to Innovate</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
ISPs are trying to persuade the FCC not to impose basic rules on them, saying it will crush innovation. But when it comes to the tubes to your house, you don&#8217;t want their kind of &#8220;innovation.&#8221;



]]></description>
		<link>http://royfirestein.com/you-dont-want-isps-to-innovate/</link>
			</item>
	<item>
		<title>Stephen Wolfram: Computing a theory of everything &#8211; Stephen Wolfram (2010)</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Stephen Wolfram, creator of Mathematica, talks about his quest to make all knowledge computational &#8212; able to be searched, processed and manipulated. His new search engine, Wolfram Alpha, has no lesser goal than to model and explain the physics underlying the universe.
]]></description>
		<link>http://royfirestein.com/stephen-wolfram-computing-a-theory-of-everything-stephen-wolfram-2010/</link>
			</item>
	<item>
		<title>TEDTalks : Stephen Wolfram: Computing a theory of everything &#8211; Stephen Wolfram (2010)</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Stephen Wolfram, creator of Mathematica, talks about his quest to make all knowledge computational &#8212; able to be searched, processed and manipulated. His new search engine, Wolfram Alpha, has no lesser goal than to model and explain the physics underlying the universe.
]]></description>
		<link>http://royfirestein.com/tedtalks-stephen-wolfram-computing-a-theory-of-everything-stephen-wolfram-2010/</link>
			</item>
	<item>
		<title>PINs and the burden on customers</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)

A survey by the Consumers’ Association shows that 10% of cardholders write down or share their PIN. This high proportion surely raises serious doubt about whether it’s fair for banks to claim that such people are “grossly negligent” even if the PIN is well disguised (for [...]]]></description>
		<link>http://royfirestein.com/pins-and-the-burden-on-customers/</link>
			</item>
	<item>
		<title>MalaRIA Malicious RIA Proxy</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
I got an email from Erlend Oftedal about a new tool he’s created called MalaRIA.  The tool uses weak crossdomain.xml and clientaccesspolicy.xml (so both Flash and Silverlight) to allow a piece of code that resides on his server to use the client’s machine as a [...]]]></description>
		<link>http://royfirestein.com/malaria-malicious-ria-proxy/</link>
			</item>
	<item>
		<title>AT&amp;T UTMS JS Injection</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
This isn’t exactly an exploit, but I’m sure after reading it, some people will feel like it is, or at minimum it might make people feel uncomfortable.  It appears when users connect through AT&#38;T UTMS wireless cards, the system man-in-the-middle’s the connection, and not only [...]]]></description>
		<link>http://royfirestein.com/att-utms-js-injection/</link>
			</item>
	<item>
		<title>Facebook Patents Social Feeds and I Patent XSS</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
In honor of the USPO’s decision to allow Facebook’s patent for social feeds I decided to patent XSS.  Please pay up.  You know who you are.  Thank you.
]]></description>
		<link>http://royfirestein.com/facebook-patents-social-feeds-and-i-patent-xss/</link>
			</item>
	<item>
		<title>HTC Desire ROM shoehorns HTC Sense and Flash 10.1 onto the Nexus One</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)

Want some of that colorful, homescreen-juggling, Android 2.1 Sense UI that HTC has prepped for the HTC Desire? Well, the previously promised hacked ROM is ready for your Nexus One&#8217;s consumption. It&#8217;s in alpha right now, so install at your own risk, and does indeed support [...]]]></description>
		<link>http://royfirestein.com/htc-desire-rom-shoehorns-htc-sense-and-flash-10-1-onto-the-nexus-one/</link>
			</item>
	<item>
		<title>HTC Desire ROM shoehorns HTC Sense and Flash 10.1 onto the Nexus One</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)

Want some of that colorful, homescreen-juggling, Android 2.1 Sense UI that HTC has prepped for the HTC Desire? Well, the previously promised hacked ROM is ready for your Nexus One&#8217;s consumption. It&#8217;s in alpha right now, so install at your own risk, and does indeed support [...]]]></description>
		<link>http://royfirestein.com/htc-desire-rom-shoehorns-htc-sense-and-flash-10-1-onto-the-nexus-one/</link>
			</item>
	<item>
		<title>PRC Cyber Capabilities Study</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
A report prepared by Northrop Grumman on Chinese capability to wage information warfare offers some valuable insights into the nature of professional and national security cyber-attack teams.
REPORT ON CHINESE CYBER WARFARE &#38; ESPIONAGE &#8211; [uscc.gov]
“Capability of the People’s Republic of China to  Conduct Cyber Warfare [...]]]></description>
		<link>http://royfirestein.com/prc-cyber-capabilities-study/</link>
			</item>
	<item>
		<title>Quickpost: Quasi-Tautologies &amp; SQL-Injection</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)

Last OWASP/ISSA Belgian chapter meeting was the location of an interesting discussion. For a full report of the meeting, read Xavier’s excellent blogpost.
Many SQL-injection techniques rely on tautologies: adding an expression that is always true to the where-clause of a select statement. Like OR 1=1. 1=1 [...]]]></description>
		<link>http://royfirestein.com/quickpost-quasi-tautologies-sql-injection/</link>
			</item>
	<item>
		<title>Physicists Prove Teleportation of Energy Is Possible</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)


Over five years ago, scientists succeeded in teleporting  information. Unfortunately, the advance failed to bring us any closer to the Star Trek future we all dream of. Now, researchers in Japan have used the same principles to prove that energy can be teleported in the [...]]]></description>
		<link>http://royfirestein.com/physicists-prove-teleportation-of-energy-is-possible/</link>
			</item>
	<item>
		<title>Chip and PIN is broken</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
There should be a 9-minute film on Newsnight tonight (10:30pm, BBC Two) showing some research by Steven Murdoch, Saar Drimer, Mike Bond and me. We demonstrate a middleperson attack on EMV which lets criminals use stolen chip and PIN cards without knowing the PIN.
Our technical paper [...]]]></description>
		<link>http://royfirestein.com/chip-and-pin-is-broken/</link>
			</item>
	<item>
		<title>TEDTalks : Derek Sivers: Weird, or just different? &#8211; Derek Sivers (2009)</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
&#8220;There&#8217;s a flip side to everything,&#8221; the saying goes, and in 2 minutes, Derek Sivers shows this is true in a few ways you might not expect.
]]></description>
		<link>http://royfirestein.com/tedtalks-derek-sivers-weird-or-just-different-derek-sivers-2009/</link>
			</item>
	<item>
		<title>For the First Time, Researchers Find Longevity Gene That Helps Determine Lifespan</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)

Come on, you apes! You wanna live forever?
Humanity&#8217;s search for the secrets to immortality has inspired Ray Kurzweil&#8217;s Singularity vision and DARPA&#8217;s hunt for ageless synthetic beings. Now scientists have discovered a single gene that appears to control how quickly individuals will biologically age, The Telegraph [...]]]></description>
		<link>http://royfirestein.com/for-the-first-time-researchers-find-longevity-gene-that-helps-determine-lifespan/</link>
			</item>
	<item>
		<title>Marijuana Research Offers New Hope For Male Birth Control Pill</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)


The male birth control pill has lingered for years tantalizingly just out of reach, in the realm where rumor meets science. Recently developed hormonal and mechanical contraceptives never found an audience, serving only to highlight the absence of a male pill. Now, an examination of how [...]]]></description>
		<link>http://royfirestein.com/marijuana-research-offers-new-hope-for-male-birth-control-pill/</link>
			</item>
	<item>
		<title>The Quest to Read the Human Mind</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)

If a few very smart neuroscientists are right, with enough number crunching and a powerful brain scanner, science can pluck pictures-and maybe one day even thoughts- directly from your brain 
It&#8217;s after dark on a warm Monday night in April, and I&#8217;m lying face-up in a [...]]]></description>
		<link>http://royfirestein.com/the-quest-to-read-the-human-mind/</link>
			</item>
	<item>
		<title>Vulnerability in TLS/SSL Could Allow Spoofing, (Wed, Feb 10th)</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Microsoft released a bulletin yesterday about a potential problem in TLS/SSL that could allow spoofing. From their bulletin:
Microsoft is investigating public reports of a vulnerability in the Transport Layer Security (TLS) and Secure Sockets Layer (SSL) protocols. At this time, Microsoft is not aware of any [...]]]></description>
		<link>http://royfirestein.com/vulnerability-in-tlsssl-could-allow-spoofing-wed-feb-10th/</link>
			</item>
	<item>
		<title>Appeals Court Backs EFF Push for Telecom Lobbying Documents Disclosure</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
San Francisco &#8211; Today a federal appeals court rejected a government claim of &#8220;lobbyist privacy&#8221; to hide the identities of individuals who pressured Congress to grant immunity to telecommunications companies that participated in the government&#8217;s warrantless electronic surveillance of millions of ordinary Americans. As the court [...]]]></description>
		<link>http://royfirestein.com/appeals-court-backs-eff-push-for-telecom-lobbying-documents-disclosure/</link>
			</item>
	<item>
		<title>Terrorists Prohibited from Using iTunes</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
The iTunes Store Terms and Conditions prohibits it: Notice, as I read this clause not only are terrorists &#8212; or at least those on terrorist watch lists &#8212; prohibited from using iTunes to manufacture WMD, they are also prohibited from even downloading and using iTunes. So [...]]]></description>
		<link>http://royfirestein.com/terrorists-prohibited-from-using-itunes/</link>
			</item>
	<item>
		<title>The Real Hustler</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Paul Wilson, my esteemed coauthor on that paper on the psychology of scam victims that is currently attracting quite a bit of attention, has just started an entertaining and instructive new blog, The Real Hustler. If you liked our paper, you’ll probably enjoy Paul’s blog.
Well worth [...]]]></description>
		<link>http://royfirestein.com/the-real-hustler/</link>
			</item>
	<item>
		<title>Beer is a rich source of silicon and may help prevent osteoporosis</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Shared by  Roy

I&#8217;ll drink for that!
A new study suggests that beer is a significant source of dietary silicon, a key ingredient for increasing bone mineral density. Beers containing high levels of malted barley and hops are richest in silicon.
]]></description>
		<link>http://royfirestein.com/beer-is-a-rich-source-of-silicon-and-may-help-prevent-osteoporosis/</link>
			</item>
	<item>
		<title>SS-2010-003.txt</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
A vulnerability exists in the Microsoft SMB client which allows an attacker to trigger a kernel pool memory corruption by sending a specific &#8216;Negotiate Protocol&#8217; response.
]]></description>
		<link>http://royfirestein.com/ss-2010-003-txt/</link>
			</item>
	<item>
		<title>2009-09-Part-of-Nature.png</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Shared by  Elton Carvalho

Gostei das partes que falam sobrecusto de extração versus valor de substituição e juros X reservas da natureza.

]]></description>
		<link>http://royfirestein.com/2009-09-part-of-nature-png/</link>
			</item>
	<item>
		<title>Researchers penetrate last bastion of Windows security</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
With a little help from Adobe
Security researchers have defeated vulnerability protections baked into the latest versions of Internet Explorer, demonstrating that it&#8217;s possible to poke holes in a safety net that&#8217;s widely relied on to keep end users safe from drive-by exploits.…

Case Study: WhatsUp keeps Legoland [...]]]></description>
		<link>http://royfirestein.com/researchers-penetrate-last-bastion-of-windows-security/</link>
			</item>
	<item>
		<title>Hackers Disrupt European CO₂ Market</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
In recent weeks, various cybercrime attacks have disrupted the computer systems that allow nations to manage their national greenhouse-gas emissions quotas and their possession of carbon assets according to international agreements (the Kyoto Protocol and the European system). One quota is the right to emit the equivalent of [...]]]></description>
		<link>http://royfirestein.com/hackers-disrupt-european-co%e2%82%82-market/</link>
			</item>
	<item>
		<title>The Web won’t be safe, let alone secure, unless we break it</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
There are several security issues affecting all major Web browsers that have remained unaddressed for years (probably because the bad guys haven’t leveraged them aggressively enough, but the potential is there). The problem is that the only known ways to fix these issues (adequately) is to [...]]]></description>
		<link>http://royfirestein.com/the-web-won%e2%80%99t-be-safe-let-alone-secure-unless-we-break-it/</link>
			</item>
	<item>
		<title>Download of the day: GNU/Linux Advanced Administration PDF Book</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)

The Free Technology Academy (FTA) has released excellent book called &#8220;The GNU/Linux operating system&#8221;, the main contents are related with system administration.  You will learn how to install and configure several computer services, and how to optimise and synchronise the resources using GNU/Linux.
Read more: Download [...]]]></description>
		<link>http://royfirestein.com/download-of-the-day-gnulinux-advanced-administration-pdf-book/</link>
			</item>
	<item>
		<title>@RSnake ’s RFI List in Burp Suite</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
First of all, get Robert @RSnake Hansen’s RFI list here:
http://ha.ckers.org/blog/20100129/large-list-of-rfis-1000/
it’s a great list, but as soon as I saw it, I was like.. hmm.. how can I use that? Well, being that I am a Burp fan, I parsed the .dat with the following line:

cat rfi-locations.dat [...]]]></description>
		<link>http://royfirestein.com/rsnake-%e2%80%99s-rfi-list-in-burp-suite/</link>
			</item>
	<item>
		<title>Facebook Rewrites PHP Runtime For Speed</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
VonGuard writes &#8220;Facebook has gotten fed up with the speed of PHP. The company has been working on a skunkworks project to rewrite the PHP runtime, and on Tuesday of this week, they will be announcing the availability of their new PHP runtime as an open [...]]]></description>
		<link>http://royfirestein.com/facebook-rewrites-php-runtime-for-speed/</link>
			</item>
	<item>
		<title>iPad v. A Rock</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
This speaks for itself. Thanks to Phil Santoro for creating it and sending it us (a play on the iphone v. rock joke).



    


]]></description>
		<link>http://royfirestein.com/ipad-v-a-rock/</link>
			</item>
	<item>
		<title>It’s the little things (Part One)</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
For forensic analysts, the .lnk shortcut file and the thumbprint cache are invaluable sources with Windows devices to provide details about missing data.
Individuals wanting to hide their activities may flush their browser cache, Temp files, use, and even wipe the drive free space. However, they may [...]]]></description>
		<link>http://royfirestein.com/it%e2%80%99s-the-little-things-part-one/</link>
			</item>
	<item>
		<title>Scientists grow solar cell components in tobacco plants</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
(PhysOrg.com) &#8212; Over billions of years, plants have evolved very efficient sunlight-collecting systems. Now, scientists are trying to harness the finely tuned systems in tobacco plants in order to use them as the building blocks of solar cells. Scientists predict that the technique could lead to [...]]]></description>
		<link>http://royfirestein.com/scientists-grow-solar-cell-components-in-tobacco-plants/</link>
			</item>
	<item>
		<title>NIF Moves 5.9 Million Degrees Closer To Fusion Power</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)


With the need for a cheap and abundant alternative to fossils fuels more important than ever before, the field of fusion energy is getting hotter. Really, really hot. 6 million degrees hot. Yes, the National Ignition Facility, the Department of Energy&#8217;s pet fusion project, has finally [...]]]></description>
		<link>http://royfirestein.com/nif-moves-5-9-million-degrees-closer-to-fusion-power/</link>
			</item>
	<item>
		<title>Parallel Algorithm Leads To Crypto Breakthrough</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Hugh Pickens writes &#8220;Dr. Dobbs reports that a cracking algorithm using brute force methods can analyze the entire DES 56-bit keyspace with a throughput of over 280 billion keys per second, the highest-known benchmark speeds for 56-bit DES decryption and can accomplish a key recovery that [...]]]></description>
		<link>http://royfirestein.com/parallel-algorithm-leads-to-crypto-breakthrough/</link>
			</item>
	<item>
		<title>DAVID THORNE KILLS IT AGAIN – THE BLOCKBUSTER SAGA..</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
If you don’t know who David Thorne is, I’ll remind you – he is the genius that gave you the “spider drawing” email mayhem. Then there was the “Party in Apartment 3” escapade and the “design me a logo” piece of genius.
But he didn’t stop there [...]]]></description>
		<link>http://royfirestein.com/david-thorne-kills-it-again-%e2%80%93-the-blockbuster-saga/</link>
			</item>
	<item>
		<title>Look Beyond the Exploit</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
The post One Exploit Should Not Ruin Your Day by Dino Dai Zovi made me think:
Finally, the larger problem is that it only took one exploit to compromise these organizations.  One exploit should never ruin you day. [sic]
No, that is wrong.  The larger problem [...]]]></description>
		<link>http://royfirestein.com/look-beyond-the-exploit/</link>
			</item>
	<item>
		<title>Links</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
ToolsDavid Kovar has written a tool, in Python, to parse the NTFS $MFT, called analyzeMFT.  The tool can be downloaded from this site.  I&#8217;ve been using Mark Menz&#8217;s MFTRipper to parse this data, and having other tools to do this sort of thing available [...]]]></description>
		<link>http://royfirestein.com/links/</link>
			</item>
	<item>
		<title>Obama&#8217;s budget slashes moon mission, new rockets</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
NASA&#8217;s plans to return astronauts to the moon are dead. So are the rockets being designed to take them there &#8212; that is, if President Barack Obama gets his way.
]]></description>
		<link>http://royfirestein.com/obamas-budget-slashes-moon-mission-new-rockets/</link>
			</item>
	<item>
		<title>A Primer on Information Theory and Privacy</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
If we ask whether a fact about a person identifies that person, it turns out that the answer isn&#8217;t simply yes or no.  If all I know about a person is their ZIP code, I don&#8217;t know who they are.  If all I know [...]]]></description>
		<link>http://royfirestein.com/a-primer-on-information-theory-and-privacy/</link>
			</item>
	<item>
		<title>2009 Blog Rewind: The Three-Way Handshake is a Lie!</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
As I close out my look at some of the most influential posts published here in 2009 I conclude with a post that garnered widespread industry recognition and sparked many discussions, Tod Beardsley&#8217;s &#8220;TCP Portals: The Handshake&#8217;s A Lie&#8220;. The post, only published a month ago, [...]]]></description>
		<link>http://royfirestein.com/2009-blog-rewind-the-three-way-handshake-is-a-lie/</link>
			</item>
	<item>
		<title>Top Ten Web Hacking Techniques of 2009 (Official)</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Every year the Web security community produces dozens of new hacking techniques documented in white papers, blog posts, magazine articles, mailing list emails, etc. Not to be confused with individual vulnerability instances brandishing CVE numbers, nor intrusions / incidents, but actual new methods of Web attack. [...]]]></description>
		<link>http://royfirestein.com/top-ten-web-hacking-techniques-of-2009-official/</link>
			</item>
	<item>
		<title>RockYou Hacked. Some 30 million passwords in the wild [Security]</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
RockYou, a service that offers applications like slideshows, games, layouts and more for social networking sites like Facebook, MySpace or Orkut that of the network’s users seem to love so much was recently hacked and the service’s entire database of 30+ million data sets exposed. This [...]]]></description>
		<link>http://royfirestein.com/rockyou-hacked-some-30-million-passwords-in-the-wild-security/</link>
			</item>
	<item>
		<title>Bothunter 1.5 Released!</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
One of my favorite projects has a new significant release. Bothunter is an auto9mated bot finding tool. It uses the Emerging Threats signature base, but has a LOT more under the hood. I highly recommend it, we write a lot of signatures based on new threats [...]]]></description>
		<link>http://royfirestein.com/bothunter-1-5-released/</link>
			</item>
	<item>
		<title>The wrong way to determine the size of a buffer</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)

A colleague of mine showed me some code from a back-end
program on a web server.
Fortunately, the company that wrote this is out of business.
Or at least I hope they&#8217;re out of business!


size = 16384;
while (size &#38;&#38; IsBadReadPtr(buffer, size)) {
    size--;
}


]]></description>
		<link>http://royfirestein.com/the-wrong-way-to-determine-the-size-of-a-buffer/</link>
			</item>
	<item>
		<title>mswinnt-pwn.txt</title>
		<description><![CDATA[pulled from Google Reader (click on title for original post)
Microsoft Windows suffers from an user mode to ring 0 escalation vulnerability.
]]></description>
		<link>http://royfirestein.com/mswinnt-pwn-txt/</link>
			</item>
</channel>
</rss>
