<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Report Security Flaws</title>
	<atom:link href="http://reportsecurityflaws.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://reportsecurityflaws.wordpress.com</link>
	<description>Just another WordPress.com weblog</description>
	<lastBuildDate>Sat, 05 Sep 2009 05:47:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='reportsecurityflaws.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Report Security Flaws</title>
		<link>http://reportsecurityflaws.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://reportsecurityflaws.wordpress.com/osd.xml" title="Report Security Flaws" />
	<atom:link rel='hub' href='http://reportsecurityflaws.wordpress.com/?pushpress=hub'/>
		<item>
		<title>Apache&#8217;s incident report sets a disclosure standard</title>
		<link>http://reportsecurityflaws.wordpress.com/2009/09/05/apaches-incident-report-sets-a-disclosure-standard/</link>
		<comments>http://reportsecurityflaws.wordpress.com/2009/09/05/apaches-incident-report-sets-a-disclosure-standard/#comments</comments>
		<pubDate>Sat, 05 Sep 2009 05:47:29 +0000</pubDate>
		<dc:creator>reportsecurityflaws</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[apache]]></category>
		<category><![CDATA[disclosure]]></category>

		<guid isPermaLink="false">http://reportsecurityflaws.wordpress.com/?p=13</guid>
		<description><![CDATA[Apache Software Foundation's Infrastructure Team established a beacon in the disclosure darkness...<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reportsecurityflaws.wordpress.com&amp;blog=9205036&amp;post=13&amp;subd=reportsecurityflaws&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Incidents happen. What you do about it is critical. Not prone to sticking their heads in the sand, the Apache Software Foundation&#8217;s <a href="https://blogs.apache.org/infra/" target="_blank">Infrastructure Team</a> established a <a href="https://blogs.apache.org/infra/entry/apache_org_downtime_report" target="_blank">beacon</a> in the disclosure darkness. With unmatched transparency, while discussing a late August breach at Apachecon.con, the team indicated that &#8220;attackers fully compromised this machine, including gaining root privileges, and destroyed most of the logs, making it difficult for us to confirm the details of everything that happened on the machine.&#8221;</p>
<p>The report provides details on what happened, what worked, what didn&#8217;t work, and what changes they are making. Examples include:</p>
<ul>
<li>&#8220;The method by which most of our public facing websites are deployed to our production servers will also change, becoming a much more automated process. We hope to have switched over to a <a href="https://svn.apache.org/repos/infra/infrastructure/trunk/projects/svnpubsub/svnpubsub.py">SvnSubPub</a> / <a href="https://svn.apache.org/repos/infra/infrastructure/trunk/projects/svnpubsub/svnwcsub.py">SvnWcSub</a> based system within the next few weeks.&#8221;</li>
<li>&#8220;We will re-implement measures such as IP banning after several failed logins, on all machines.&#8221;</li>
</ul>
<p>See open disclosure and incident reporting at its finest at <a href="https://blogs.apache.org/infra/" target="_blank">https://blogs.apache.org/infra/</a>. Nicely done, Apache.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reportsecurityflaws.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reportsecurityflaws.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reportsecurityflaws.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reportsecurityflaws.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reportsecurityflaws.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reportsecurityflaws.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reportsecurityflaws.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reportsecurityflaws.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reportsecurityflaws.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reportsecurityflaws.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reportsecurityflaws.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reportsecurityflaws.wordpress.com/13/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reportsecurityflaws.wordpress.com/13/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reportsecurityflaws.wordpress.com/13/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reportsecurityflaws.wordpress.com&amp;blog=9205036&amp;post=13&amp;subd=reportsecurityflaws&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://reportsecurityflaws.wordpress.com/2009/09/05/apaches-incident-report-sets-a-disclosure-standard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b59d924c3cfc0682cdcdb96fab7cd11f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reportsecurityflaws</media:title>
		</media:content>
	</item>
		<item>
		<title>Ameriprise fails to respond appropriately</title>
		<link>http://reportsecurityflaws.wordpress.com/2009/08/27/ameriprise-fails-to-respond-appropriately/</link>
		<comments>http://reportsecurityflaws.wordpress.com/2009/08/27/ameriprise-fails-to-respond-appropriately/#comments</comments>
		<pubDate>Thu, 27 Aug 2009 20:55:07 +0000</pubDate>
		<dc:creator>reportsecurityflaws</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://reportsecurityflaws.wordpress.com/?p=7</guid>
		<description><![CDATA[Russ McRee, co-founder of ReportSecurityFlaws.com went public this week with a security disclosure about a vulnerability in Ameriprise Financial&#8217;s site for much of this year. Russ spoke with Dan Goodin of TheRegisterUK news site about the flaw. Until just a few days ago when Russ brought these flaws to the attention of the security press, [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reportsecurityflaws.wordpress.com&amp;blog=9205036&amp;post=7&amp;subd=reportsecurityflaws&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Russ McRee, co-founder of ReportSecurityFlaws.com went public this week with a security disclosure about a vulnerability in Ameriprise Financial&#8217;s site for much of this year. Russ spoke with Dan Goodin of TheRegisterUK news site about the flaw.</p>
<p>Until just a few days ago when Russ brought these flaws to the attention of the security press, Ameriprise did not reply to any of the warnings that he&#8217;d sent.</p>
<p>Part of the Ameriprise site contained cross-site scripting hazards that made it possible for phishing attackers to insert malicious content into browser sessions, and possibly steal session cookies used to authenticate customer accounts.</p>
<p>Ameriprise, like most sites, does not have an easy method to contact a security aware staff member to alert the company of a potential security hazard. Russ discovered a similar <a href="http://holisticinfosec.blogspot.com/2008/12/online-finance-flaw-american-express.html" target="_blank">flaw</a> on an American Express site late last year; a flaw that was similarly ignored by the American Express customer service department.</p>
<p>Ameriprise repaired its site less than two hours after being notified by TheRegister.uk of the flaw.</p>
<p>Read the <a href="http://www.theregister.co.uk/2009/08/20/ameriprise_website_vulnerabilities/" target="_blank">story</a> at El Reg.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reportsecurityflaws.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reportsecurityflaws.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reportsecurityflaws.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reportsecurityflaws.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reportsecurityflaws.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reportsecurityflaws.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reportsecurityflaws.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reportsecurityflaws.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reportsecurityflaws.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reportsecurityflaws.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reportsecurityflaws.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reportsecurityflaws.wordpress.com/7/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reportsecurityflaws.wordpress.com/7/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reportsecurityflaws.wordpress.com/7/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reportsecurityflaws.wordpress.com&amp;blog=9205036&amp;post=7&amp;subd=reportsecurityflaws&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://reportsecurityflaws.wordpress.com/2009/08/27/ameriprise-fails-to-respond-appropriately/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b59d924c3cfc0682cdcdb96fab7cd11f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reportsecurityflaws</media:title>
		</media:content>
	</item>
		<item>
		<title>Welcome to Report Security Flaws</title>
		<link>http://reportsecurityflaws.wordpress.com/2009/08/27/welcome-to-report-security-flaws/</link>
		<comments>http://reportsecurityflaws.wordpress.com/2009/08/27/welcome-to-report-security-flaws/#comments</comments>
		<pubDate>Thu, 27 Aug 2009 20:54:14 +0000</pubDate>
		<dc:creator>reportsecurityflaws</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://reportsecurityflaws.wordpress.com/?p=5</guid>
		<description><![CDATA[Report Security Flaws exists to increase awareness and responsiveness in Internet vendors and web site operators when they receive security-related disclosures. It is our hope that all vendors/operators maintain an email alias that exists for the sole purpose of receiving disclosure notices from parties reporting noted security flaws on the vendor/operator&#8217;s web site. Further, said [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reportsecurityflaws.wordpress.com&amp;blog=9205036&amp;post=5&amp;subd=reportsecurityflaws&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Report Security Flaws exists to increase awareness and responsiveness in Internet vendors and web site operators when they receive security-related disclosures.<br />
It is our hope that all vendors/operators maintain an email alias that exists for the sole purpose of receiving disclosure notices from parties reporting noted security flaws on the vendor/operator&#8217;s web site.</p>
<p>Further, said email alias should be monitored by individuals with an understanding of web application security issues and business logic flaws, while maintaining a close working relationship with the site developers and operations engineers. This relationship should allow for the quick escalation of reported issues for mitigation and remediation.<br />
Examples of such email alias might include:<br />
security@domain.com<br />
websecurity@domain.com<br />
webreports@domain.com</p>
<p>Too often vendors and web site operators fail to manage the proper intake and escalation of reported security flaws, leading to lapses in web application security for days, weeks, and even months.</p>
<p>Report Security Flaws will provide resources and guidance for vendors and site operators facing such challenges, with the hope of improving internet security posture for vendor/operators and consumers alike.</p>
<p>Report Security Flaws is a joint effort maintained by:<br />
Ira Victor, Data Security Podcast<br />
Russ McRee, HolisticInfoSec.org</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/reportsecurityflaws.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/reportsecurityflaws.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/reportsecurityflaws.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/reportsecurityflaws.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/reportsecurityflaws.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/reportsecurityflaws.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/reportsecurityflaws.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/reportsecurityflaws.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/reportsecurityflaws.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/reportsecurityflaws.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/reportsecurityflaws.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/reportsecurityflaws.wordpress.com/5/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/reportsecurityflaws.wordpress.com/5/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/reportsecurityflaws.wordpress.com/5/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=reportsecurityflaws.wordpress.com&amp;blog=9205036&amp;post=5&amp;subd=reportsecurityflaws&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://reportsecurityflaws.wordpress.com/2009/08/27/welcome-to-report-security-flaws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/b59d924c3cfc0682cdcdb96fab7cd11f?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">reportsecurityflaws</media:title>
		</media:content>
	</item>
	</channel>
</rss>
