<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
	xmlns:media="http://search.yahoo.com/mrss/"
>

<channel>
	<title>Calculated Decision</title>
	<atom:link href="http://www.calculateddecision.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.calculateddecision.com</link>
	<description>Security, Software Development and Information Systems</description>
	<pubDate>Sun, 07 Sep 2008 04:39:14 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6</generator>
	<language>en</language>
		<!-- podcast_generator="podPress/8.8" -->
		<copyright>&#xA9; </copyright>
		<managingEditor>anthonytowry@calculateddecision.com ()</managingEditor>
		<webMaster>anthonytowry@calculateddecision.com()</webMaster>
		<category></category>
		<ttl>1440</ttl>
		<itunes:keywords></itunes:keywords>
		<itunes:subtitle></itunes:subtitle>
		<itunes:summary>Security, Software Development and Information Systems</itunes:summary>
		<itunes:author></itunes:author>
		<itunes:category text="Society &amp; Culture"/>
		<itunes:owner>
			<itunes:name></itunes:name>
			<itunes:email>anthonytowry@calculateddecision.com</itunes:email>
		</itunes:owner>
		<itunes:block>No</itunes:block>
		<itunes:explicit>no</itunes:explicit>
		<itunes:image href="http://www.calculateddecision.com/images/projects/podcast/PodcastLogoSM.jpg" />
		<image>
			<url>http://www.calculateddecision.com/images/projects/podcast/PodcastLogoSM.jpg</url>
			<title>Calculated Decision</title>
			<link>http://www.calculateddecision.com</link>
			<width>144</width>
			<height>144</height>
		</image>
		<item>
		<title>New ProCheckUp ValidateRequest Bypass</title>
		<link>http://www.calculateddecision.com/2008/09/06/new-procheckup-validaterequest-bypass/</link>
		<comments>http://www.calculateddecision.com/2008/09/06/new-procheckup-validaterequest-bypass/#comments</comments>
		<pubDate>Sun, 07 Sep 2008 04:39:14 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Web development]]></category>

		<category><![CDATA[ASP.NET]]></category>

		<category><![CDATA[xss]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=233</guid>
		<description><![CDATA[ProCheckUp has just published a new ValidateRequest XSS bypass paper.  I unfortunately have not had time to verify the information in the paper, but everything I've read appears to be in line with information Micheal Eddington had published earlier this year.
Microsoft has some interesting goodies (patches) coming out this next Tuesday regarding .Net, IE and [...]]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/09/06/new-procheckup-validaterequest-bypass/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Samurai Web Test Framework 0.1</title>
		<link>http://www.calculateddecision.com/2008/09/02/samurai-web-test-framework-01/</link>
		<comments>http://www.calculateddecision.com/2008/09/02/samurai-web-test-framework-01/#comments</comments>
		<pubDate>Wed, 03 Sep 2008 02:43:27 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[Web development]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[livecd]]></category>

		<category><![CDATA[web testing]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=229</guid>
		<description><![CDATA[Samurai WTF is a liveCD aimed at web application hacking/testing.  I haven't tried it yet, and from the version number it looks like it's still in it's infancy, but I thought it might deserve one more inward facing link.
Check it out at: SourceForge
]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/09/02/samurai-web-test-framework-01/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Altering the Mac OS X Login Access Window Text</title>
		<link>http://www.calculateddecision.com/2008/08/29/altering-the-mac-os-x-login-access-window-text/</link>
		<comments>http://www.calculateddecision.com/2008/08/29/altering-the-mac-os-x-login-access-window-text/#comments</comments>
		<pubDate>Sat, 30 Aug 2008 03:55:02 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Operating Systems]]></category>

		<category><![CDATA[OS X]]></category>

		<category><![CDATA[Policy]]></category>

		<category><![CDATA[Usage]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=218</guid>
		<description><![CDATA[ At July's DC405 0hm hit on the need for organizations to repeatedly hit users with terms of service, usage and warnings to further their case in the event of a compromise.
Recently I've been reading through the OS X hardening guide and found this quick little nugget.  Here is how it's done in OS X [...]]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/08/29/altering-the-mac-os-x-login-access-window-text/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Summary on the State of Nmap</title>
		<link>http://www.calculateddecision.com/2008/08/28/summary-on-the-state-of-nmap/</link>
		<comments>http://www.calculateddecision.com/2008/08/28/summary-on-the-state-of-nmap/#comments</comments>
		<pubDate>Fri, 29 Aug 2008 02:25:46 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[nmap]]></category>

		<category><![CDATA[scanning]]></category>

		<category><![CDATA[tools]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=216</guid>
		<description><![CDATA[Daniel Miessler has put together an excellent summary highlighting notable features of nmap.  Some of these features were shown off in Fyodor's recent Defcon and Blackhat talks on scanning the internet.
Daniel is nice enough to provide the reader with easy (read copy/paste) instructions on getting the svn and building this version of this essential tool.  [...]]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/08/28/summary-on-the-state-of-nmap/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Android Security Team Says Hi</title>
		<link>http://www.calculateddecision.com/2008/08/21/android-security-team-says-hi/</link>
		<comments>http://www.calculateddecision.com/2008/08/21/android-security-team-says-hi/#comments</comments>
		<pubDate>Fri, 22 Aug 2008 01:43:39 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Programming]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[android]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[handset]]></category>

		<category><![CDATA[mobile]]></category>

		<category><![CDATA[Open Source]]></category>

		<category><![CDATA[phone]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=213</guid>
		<description><![CDATA[ The team working on the Android mobile platform project have recently published an introduction to Full Disclosure and other security outlets.  The team made a great move here toward encouraging hackers to responsibly disclose security issues.
The post mentions one item that many researchers value a great deal...transparency throughout the remediation process.  The guys and [...]]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/08/21/android-security-team-says-hi/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Dodging AV With Metasploit Payloads</title>
		<link>http://www.calculateddecision.com/2008/07/28/dodging-av-with-metasploit-payloads/</link>
		<comments>http://www.calculateddecision.com/2008/07/28/dodging-av-with-metasploit-payloads/#comments</comments>
		<pubDate>Tue, 29 Jul 2008 06:50:52 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Security]]></category>

		<category><![CDATA[antivirus]]></category>

		<category><![CDATA[malware]]></category>

		<category><![CDATA[Metasploit]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=197</guid>
		<description><![CDATA[I haven't been up to a lot lately.  I'm finishing out my term with my current employer, getting equipment ready for Las Vegas, and thinking about the viability of a few personal projects.
I have however found time to do a little reading.  Over at the SANS Reading Room there is a paper titled [...]]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/07/28/dodging-av-with-metasploit-payloads/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Geekonomics by David Rice</title>
		<link>http://www.calculateddecision.com/2008/07/25/geekonomics-by-david-rice/</link>
		<comments>http://www.calculateddecision.com/2008/07/25/geekonomics-by-david-rice/#comments</comments>
		<pubDate>Fri, 25 Jul 2008 22:05:08 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Books]]></category>

		<category><![CDATA[secure coding]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=192</guid>
		<description><![CDATA[
Geekonomics: The Real Cost of Insecure Software attempts to employ solid economic reasoning behind software defects that impact security.
Geekonomics was a finalist in the running for a prestigous Jolt Award, and not terribly expensive (coming in @ MSRP $30 and less than that most places), so I jumped on it.  The case for this [...]]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/07/25/geekonomics-by-david-rice/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DNS Flaw Details - Mirror</title>
		<link>http://www.calculateddecision.com/2008/07/23/dns-flaw-details-mirror/</link>
		<comments>http://www.calculateddecision.com/2008/07/23/dns-flaw-details-mirror/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 04:53:14 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<category><![CDATA[DNS]]></category>

		<category><![CDATA[exploit]]></category>

		<category><![CDATA[flaw]]></category>

		<category><![CDATA[hacking]]></category>

		<category><![CDATA[kaminsky]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=187</guid>
		<description><![CDATA[So, if you haven't seen the details for the DNS flaw you can take a look here: http://www.ri0tnet.net/dns.html
Check out the information leak of the year.  Oh, and patch those DNS servers.  WWDKD?
]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/07/23/dns-flaw-details-mirror/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Princeton Releases Encryption Key Extraction Tool</title>
		<link>http://www.calculateddecision.com/2008/07/23/key-extraction-tool/</link>
		<comments>http://www.calculateddecision.com/2008/07/23/key-extraction-tool/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 04:47:53 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Hardware]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[crypto]]></category>

		<category><![CDATA[direct memory access]]></category>

		<category><![CDATA[DMA]]></category>

		<category><![CDATA[key]]></category>

		<category><![CDATA[RAM]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=185</guid>
		<description><![CDATA[If you remember and I'm sure that you do, a while back some researchers at Princeton released a demonstration video of shaping encryption keys from frozen memory.  They proved that RAM may not be quite as volatile as everyone had previously assumed.  The tool they used is now public information.  Great, great...so the hell what.
Another [...]]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/07/23/key-extraction-tool/feed/</wfw:commentRss>
		</item>
		<item>
		<title>DC405 - July Meeting Recap</title>
		<link>http://www.calculateddecision.com/2008/07/23/dc405-july-meeting-recap/</link>
		<comments>http://www.calculateddecision.com/2008/07/23/dc405-july-meeting-recap/#comments</comments>
		<pubDate>Thu, 24 Jul 2008 04:10:17 +0000</pubDate>
		<dc:creator>Anthony Towry</dc:creator>
		
		<category><![CDATA[Community]]></category>

		<category><![CDATA[beer]]></category>

		<category><![CDATA[brewing]]></category>

		<category><![CDATA[dc405]]></category>

		<category><![CDATA[defcon]]></category>

		<guid isPermaLink="false">http://www.calculateddecision.com/?p=181</guid>
		<description><![CDATA[This past Friday the Defcon 405 group held the July edition of the monthly meeting.  This round featured 0hm as our headliner.  He presented a riveting talk on "Hardening Windows Server: Building a House out of Greased BBs".  I taped the presentation and as soon as I coordinate slides, will post the video.
I also handed [...]]]></description>
		<wfw:commentRss>http://www.calculateddecision.com/2008/07/23/dc405-july-meeting-recap/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
