<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The ProStructure Blog &#187; Advisories</title>
	<atom:link href="http://www.prostructure.com/blog/category/advisories/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.prostructure.com/blog</link>
	<description>A blog about high-end IT Infrastructure and Security</description>
	<lastBuildDate>Thu, 22 Sep 2011 19:41:01 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.3</generator>
		<item>
		<title>One Policy to Enforce for Android Phones Connecting to Your Corporate Wifi</title>
		<link>http://www.prostructure.com/blog/2011/06/23/one-policy-to-enforce-for-android-phones-connecting-to-your-corporate-wifi/</link>
		<comments>http://www.prostructure.com/blog/2011/06/23/one-policy-to-enforce-for-android-phones-connecting-to-your-corporate-wifi/#comments</comments>
		<pubDate>Thu, 23 Jun 2011 19:41:14 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Enterprise IT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[Wifi]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=153</guid>
		<description><![CDATA[As reported by blogger Donovan Colbert on TechRepublic, Android devices automatically synchronize settings from your phone to Google servers so that when you log in from other devices, your settings travel with you.  This is very convenient for users, but if those users have signed into your corporate wifi, the synchronized data may include your [...]]]></description>
			<content:encoded><![CDATA[<p>As reported by blogger <a href="http://tek.io/mCn3II" target="_blank">Donovan Colbert on TechRepublic</a>, Android devices automatically synchronize settings from your phone to Google servers so that when you log in from other devices, your settings travel with you.  This is very convenient for users, but if those users have signed into your corporate wifi, the synchronized data may include your corporate WPA2 key.  This is an obvious risk to the privacy of your corporate wifi network.</p>
<p>Businesses with wifi networks should have policies in place that state under what conditions, if any, smart phones are allowed to connect to its network.  It would be wise to include a specific reference to disabling the &#8220;Backup my data&#8221; setting, usually found in the Settings/Privacy menu on Android phones.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/06/23/one-policy-to-enforce-for-android-phones-connecting-to-your-corporate-wifi/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HP System Management Homepage Security Advisory</title>
		<link>http://www.prostructure.com/blog/2011/05/05/hp-system-management-homepage-security-advisory/</link>
		<comments>http://www.prostructure.com/blog/2011/05/05/hp-system-management-homepage-security-advisory/#comments</comments>
		<pubDate>Thu, 05 May 2011 17:58:18 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[Enterprise IT]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[HP System Management Homepage]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[SMH]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=145</guid>
		<description><![CDATA[NIST has announced a highly exploitable flaw in the HP System Management Homepage (SMH) that can allow unauthenticated users to attack the web application over the network to ultimately execute arbitrary code on the server. The flaw has been rated with a CVSS Base Score of 10, which means it is highly exploitable and has [...]]]></description>
			<content:encoded><![CDATA[<p>NIST has <a href="http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2011-1541" target="_blank">announced</a> a highly exploitable flaw in the HP System Management Homepage (SMH) that can allow unauthenticated users to attack the web application over the network to ultimately execute arbitrary code on the server.  The flaw has been rated with a CVSS Base Score of 10, which means it is highly exploitable and has a potentially severe impact if exploited.</p>
<p>All administrators using this tool to manage HP hardware over the network should upgrade HP SMH to the <a href="http://h18013.www1.hp.com/products/servers/management/agents/index.html" target="_blank">latest version</a> in which the flaw has been resolved.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2011/05/05/hp-system-management-homepage-security-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Critical PDF Vulnerabilities in Blackberry Enterprise Server</title>
		<link>http://www.prostructure.com/blog/2009/01/13/critical-pdf-vulnerabilities-in-blackberry-enterprise-server/</link>
		<comments>http://www.prostructure.com/blog/2009/01/13/critical-pdf-vulnerabilities-in-blackberry-enterprise-server/#comments</comments>
		<pubDate>Tue, 13 Jan 2009 22:01:39 +0000</pubDate>
		<dc:creator>Amber Pham</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[BES]]></category>
		<category><![CDATA[Blackberry]]></category>
		<category><![CDATA[bulletin]]></category>
		<category><![CDATA[RIM]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=41</guid>
		<description><![CDATA[Research in Motion has just released security bulletin KB17118 that announces a new set of vulnerabilities in the Blackberry Attachment Service that runs on Blackberry Enterprise Server (BES). According to Blackberry, “these vulnerabilities could enable a malicious individual to send an email message containing a specially crafted PDF file, which when opened for viewing on [...]]]></description>
			<content:encoded><![CDATA[<p>Research in Motion has just released security bulletin <a href="http://www.blackberry.com/btsc/search.do?cmd=displayKC&amp;docType=kc&amp;externalId=KB17118" target="_blank">KB17118</a> that announces a new set of vulnerabilities in the Blackberry Attachment Service that runs on Blackberry Enterprise Server (BES).  According to Blackberry, “these vulnerabilities could enable a malicious individual to send an email message containing a specially crafted PDF file, which when opened for viewing on a BlackBerry smartphone, could cause memory corruption and possibly lead to arbitrary code execution on the computer that hosts the BlackBerry Attachment Service.”</p>
<p>It is strongly recommended that you read bulletin KB17118, then download and install the patch, called Service Pack 6 Interim Security Software Update 2, from <a href="http://www.blackberry.com/go/serverdownloads" target="_blank">http://www.blackberry.com/go/serverdownloads</a>.   The security bulletin also offers a workaround that reduces the functionality of BES but protects the server from exploits of the Attachment Service vulnerabilities.</p>
<p>The affected versions of the server software are BlackBerry Enterprise Server software version 4.1 Service Pack 3 (4.1.3) through 4.1 Service Pack 6 (4.1.6), including the latest maintenance release.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2009/01/13/critical-pdf-vulnerabilities-in-blackberry-enterprise-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Heads Up!  Big vulnerabilities in Cisco PIX, VMware and Mac OSX</title>
		<link>http://www.prostructure.com/blog/2008/06/09/heads-up-big-vulnerabilities-in-cisco-pix-vmware-and-mac-osx/</link>
		<comments>http://www.prostructure.com/blog/2008/06/09/heads-up-big-vulnerabilities-in-cisco-pix-vmware-and-mac-osx/#comments</comments>
		<pubDate>Mon, 09 Jun 2008 16:41:43 +0000</pubDate>
		<dc:creator>Irving Popovetsky</dc:creator>
				<category><![CDATA[Advisories]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[mac]]></category>
		<category><![CDATA[os x]]></category>
		<category><![CDATA[pix]]></category>
		<category><![CDATA[vmware]]></category>
		<category><![CDATA[vulnerabilities]]></category>

		<guid isPermaLink="false">http://www.prostructure.com/blog/?p=6</guid>
		<description><![CDATA[Last week, quite a few major vulnerabilities were discovered in some of our customer&#8217;s favorite products, namely: VMWare (all products, from ESX Server all the way down to VMware Player) Cisco PIX and ASA (versions 7.1, 7.2, 8.0 and 8.1) Mac OS X (Both Server and Client editions, 10.4 and 10.5 are affected) Quite a [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, quite a few major vulnerabilities were discovered in some of our customer&#8217;s favorite products, namely: <strong></strong></p>
<ul>
<li><strong>VMWare </strong>(all products, from ESX Server all the way down to VMware Player)</li>
<li><strong>Cisco PIX and ASA </strong>(versions 7.1, 7.2, 8.0 and 8.1)</li>
<li><strong>Mac OS X </strong>(Both Server and Client editions, 10.4 and 10.5 are affected)</li>
</ul>
<p>Quite a few of these vulnerabilities are remotely exploitable and especially dangerous on the PIX and unprotected OSX and VMware installations.   VMware also looks like it may have a  local &#8220;VM breakout&#8221; bug or two, watch out for these.   We strongly recommend getting these products updated as soon as possible.</p>
<p>For more information and relevant links, check out the <a title="US Cyber Security Bulletin SB08-161" href="http://www.us-cert.gov/cas/bulletins/SB08-161.html" target="_blank">US-CERT <span class="cas_alert_info">Cyber Security Bulletin SB08-161</span></a>.  Search for the product you&#8217;re running on this page.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.prostructure.com/blog/2008/06/09/heads-up-big-vulnerabilities-in-cisco-pix-vmware-and-mac-osx/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
<!-- WP Super Cache is installed but broken. The path to wp-cache-phase1.php in wp-content/advanced-cache.php must be fixed! -->
