<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="Tiki CMS/Groupware via FeedCreator 1.7.2.1" -->
<?xml-stylesheet href="http://www.gotroot.com/lib/rss/rss-style.css" type="text/css"?>
<?xml-stylesheet href="http://www.gotroot.com/lib/rss/rss20.xsl" type="text/xsl"?>
<rss version="2.0">
    <channel>
        <title>Got Root Articles</title>
        <description></description>
        <link>http://www.gotroot.com//tiki-articles_rss.php?ver=2</link>
        <lastBuildDate>Wed, 16 May 2012 20:53:05 +0100</lastBuildDate>
        <generator>Tiki CMS/Groupware via FeedCreator 1.7.2.1</generator>
        <image>
            <url>http://www.gotroot.com/img/tiki/tikilogo.png</url>
            <title>Got Root</title>
            <link>http://www.gotroot.com//Welcome</link>
            <description><![CDATA[Feed provided by Got Root. Click to visit.]]></description>
        </image>
        <language>en-us</language>
        <managingEditor>gotroot.com</managingEditor>
        <webMaster>gotroot.com</webMaster>
        <item>
            <title>ASL Lite 1.0</title>
            <link>http://www.gotroot.com/article293-ASL-Lite-1-0</link>
            <description><![CDATA[<p>ASL Lite is a new lightweight rule updater project designed specifically as an ASL rule downloader for custom apache environments, control panel software like cpanel and directadmin, or non-apache/mixed web server implementations. ASL Lite supports a guided dialog similar to the standard asl configuration, that allows for the definition of custom commands for restarting web services, location of configuration files, and use via cron.
</p>
]]></description>
            <pubDate>Tue, 09 Feb 2010 00:00:00 +0100</pubDate>
        </item>
        <item>
            <title>Atomic Secured Linux 2.2.3 Released </title>
            <link>http://www.gotroot.com/article294-Atomic-Secured-Linux-2-2-3-Released</link>
            <description><![CDATA[<p>We are proud to announce the latest release for our flagship Atomic Secured Linux product, the latest in unified threat management systems.  Atomic Secured Linux(tm) is an out-of-the-box Unified Security Suite for Linux(tm) systems designed to protect your servers against both known and unknown threats. It is distributed through a subscription yum channel ensuring that ASL is always kept up to date.
</p>
]]></description>
            <pubDate>Mon, 01 Feb 2010 01:00:00 +0100</pubDate>
        </item>
        <item>
            <title>Atomic Secured Linux 2.2.2 Released</title>
            <link>http://www.gotroot.com/article292-Atomic-Secured-Linux-2-2-2-Released</link>
            <description><![CDATA[<p>Atomicorp is proud to announce the release of version 2.2.2 of Atomic Secured Linux.
Our full service security suite for Linux based systems.
</p>
]]></description>
            <pubDate>Thu, 07 Jan 2010 14:00:00 +0100</pubDate>
        </item>
        <item>
            <title>Atomic Secured Linux 2.2.1 Released</title>
            <link>http://www.gotroot.com/article291-Atomic-Secured-Linux-2-2-1-Released</link>
            <description><![CDATA[<p>We are proud to announce the release of <a class="wiki external"  href="http://www.atomicorp.com" rel="external">Atomic Secured Linux 2.2.1</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> the latest version of our cutting-edge Unified Security solution for servers.
</p>
]]></description>
            <pubDate>Sun, 13 Sep 2009 06:47:00 +0100</pubDate>
        </item>
        <item>
            <title>Follow the status of the Real Time rules on twitter</title>
            <link>http://www.gotroot.com/article290-Follow-the-status-of-the-Real-Time-rules-on-twitter</link>
            <description><![CDATA[<p>We've setup a twitter feed for our subversion system.  When we put out new rules you'll get a tweet.  You can follow us here:
</p>

<p><a class="wiki external"  href="http://twitter.com/atomicorp/" rel="external">GotRoot/Atomicorp Real Time Rules Twitter Feed</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" />
</p>
]]></description>
            <pubDate>Sun, 21 Jun 2009 19:49:00 +0100</pubDate>
        </item>
        <item>
            <title>Stop Rogue devices on your network for free</title>
            <link>http://www.gotroot.com/article289-Stop-Rogue-devices-on-your-network-for-free</link>
            <description><![CDATA[<p>Rogue devices, like unauthorized hosts or rogue APs got you down?  Here are several free and powerful solutions to detect, stop and even quarantine rogue devices on your network.
</p>
]]></description>
            <pubDate>Thu, 09 Apr 2009 22:24:00 +0100</pubDate>
        </item>
        <item>
            <title>Standalone modsecurity rules updater available</title>
            <link>http://www.gotroot.com/article288-Standalone-modsecurity-rules-updater-available</link>
            <description><![CDATA[<p>ASL customers already have this built into ASL, but for those running the rules without ASL we have developed a stand alone rule updater/downloader:
</p>

<p><a class="wiki external"  href="http://www.atomicorp.com/installers/rule-updater.sh" rel="external">Automatic Rule Updater</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fwww.atomicorp.com%2Finstallers%2Frule-updater.sh">(cache)</a>
</p>

<p>And the config file for the same:
</p>

<p><a class="wiki external"  href="http://www.atomicorp.com/installers/asl-updater.conf" rel="external">Automatic Rule Updater Config file</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fwww.atomicorp.com%2Finstallers%2Fasl-updater.conf">(cache)</a>
</p>

<p>Installation instructions are available here:
</p>

<p><a class="wiki external"  href="http://www.atomicorp.com/wiki/index.php/Atomic_ModSecurity_Rules" rel="external">Installation Instructions</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fwww.atomicorp.com%2Fwiki%2Findex.php%2FAtomic_ModSecurity_Rules">(cache)</a>
</p>
]]></description>
            <pubDate>Tue, 07 Apr 2009 18:29:00 +0100</pubDate>
        </item>
        <item>
            <title>MD5 weakness Proof of Concept</title>
            <link>http://www.gotroot.com/article287-MD5-weakness-Proof-of-Concept</link>
            <description><![CDATA[<p><a class="wiki external"  href="http://en.wikipedia.org/wiki/MD5" rel="external">MD5</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fen.wikipedia.org%2Fwiki%2FMD5">(cache)</a> weaknesses have been known for some time now and security researchers have been recommending against its use for a few years, while predicting that a realistic attack was just around the corner.  Research was published today that demonstrates that realistic attacks are possible now.  The research deals with a proof of concept collision attack to create fake CA certificate using MD5.  The researchers state that a knowledgeable attacker can fake a valid signature on a CA certificate, thereby making it possible to hijack the PKI used to sign SSL certs by pretending to be a valid CA.  The researchers website <a class="wiki external"  href="http://www.win.tue.nl/hashclash/rogue-ca/" rel="external">MD5 considered harmful today</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fwww.win.tue.nl%2Fhashclash%2Frogue-ca%2F">(cache)</a> has the details.  In short, nothing important should use MD5 anymore.
</p>
]]></description>
            <pubDate>Tue, 30 Dec 2008 18:45:00 +0100</pubDate>
        </item>
        <item>
            <title>BotHunting tool</title>
            <link>http://www.gotroot.com/article286-BotHunting-tool</link>
            <description><![CDATA[<p>For those that are not familiar with it, SRI has a great project called BotHunter<a href="tiki-editpage.php?page=BotHunter" title="Create page: BotHunter" class="wiki wikinew">?</a>.  Its a snort derivative using special rules and some SRI code to detect bots on your network and to anonymously share data with the BotHunter<a href="tiki-editpage.php?page=BotHunter" title="Create page: BotHunter" class="wiki wikinew">?</a> folks.  The installer is top notch and we really like what the project is doing.  Check it out yourself at <a class="wiki external"  href="http://www.bothunter.net">http://www.bothunter.net<img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /></a>
</p>

]]></description>
            <pubDate>Mon, 22 Dec 2008 00:00:00 +0100</pubDate>
        </item>
        <item>
            <title>ASL 2.0 Final Released</title>
            <link>http://www.gotroot.com/article285-ASL-2-0-Final-Released</link>
            <description><![CDATA[<p><a class="wiki" href="http://www.progllc.com" target='_blank'>Prometheus Group</a> is proud to announce the release of Atomic Secured Linux 2.0, the latest version of our cutting-edge Unified Security solution for servers.
</p>
]]></description>
            <pubDate>Mon, 07 Jul 2008 16:06:00 +0100</pubDate>
        </item>
        <item>
            <title>Virtual Patch for Hidden Text Exploit</title>
            <link>http://www.gotroot.com/article284-Virtual-Patch-for-Hidden-Text-Exploit</link>
            <description><![CDATA[<p><a class="wiki external"  href="http://isc.sans.org/diary.html?storyid=4327" rel="external">SANS ISC</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fisc.sans.org%2Fdiary.html%3Fstoryid%3D4327">(cache)</a> brings us a <a class="wiki external"  href="http://www.techsideup.com/wordpress-hack-inserts-hidden-text/" rel="external">report</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fwww.techsideup.com%2Fwordpress-hack-inserts-hidden-text%2F">(cache)</a> of a new method spammers are using to put links into blogs using hidden text.  We don't consider this a <a title="How to securely run WordPress and how to prevent comment spam with WordPress" href="WordPress" class="wiki ">WordPress</a> vuln, but rather a class of problems revolving around hidden test.  This is very reminiscent of the iframe attacks using hidden iframes.  In the spirit of making the world a nicer place, we're publishing Modsec rules to protect against this problem.  You can download the rules from <a class="wiki"  href="http://www.gotroot.com/patches/hidden_spam_patch.txt" rel="">here</a>.  Right now its one rule, but as we discover other ways to protect against this we'll update the file.  If you are running ASL or have a subscription to the real time rules, this is included in the latest update automatically.
</p>
]]></description>
            <pubDate>Thu, 24 Apr 2008 22:00:00 +0100</pubDate>
        </item>
        <item>
            <title>Free Modsecurity 2.5 rules released</title>
            <link>http://www.gotroot.com/article283-Free-Modsecurity-2-5-rules-released</link>
            <description><![CDATA[<p>We've been providing 2.5 signatures and rules to our ASL customers for over a year, and are proud to announce the availability of these rules through the GotRoot<a href="tiki-editpage.php?page=GotRoot" title="Create page: GotRoot" class="wiki wikinew">?</a> lab website.  The free rules are delayed 30 days.  Want the rules in real time?  Well <a class="wiki external"  href="http://www.progllc.com/products/buy-now/prodbuyasl.html" rel="external">sign up now!</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" />  Its only $99.95 a year for a real time subscription to the  most comprehensive and widely used WAF rules on the Internet!
</p>
]]></description>
            <pubDate>Tue, 18 Mar 2008 00:00:00 +0100</pubDate>
        </item>
        <item>
            <title>ASL 2.0 final beta out</title>
            <link>http://www.gotroot.com/article282-ASL-2-0-final-beta-out</link>
            <description><![CDATA[<p>We've been been working like mad men on ASL (especially Scott), and we're at the final Beta.  2.0 final is just around the corner.  The GUI is slick, tons of new security features,  vulnerability scanner, built in support portal and more.  Check it out on the <a class="wiki external"  href="http://www.atomicrocketturtle.com/Joomla/content/view/137/34/" rel="external">ASL website</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" />.
</p>
]]></description>
            <pubDate>Tue, 05 Feb 2008 01:18:00 +0100</pubDate>
        </item>
        <item>
            <title>Site move complete</title>
            <link>http://www.gotroot.com/article281-Site-move-complete</link>
            <description><![CDATA[<p>For anyone that had problems logging into their accounts, I do apologize for the delay fixing the site.  The problem was very very very convulted.  Ah the joys of moving boxes, upgrading PHP, MYSQL and Javascript.  Logins should be working again for everyone.
</p>
]]></description>
            <pubDate>Tue, 05 Feb 2008 00:47:00 +0100</pubDate>
        </item>
        <item>
            <title>Virtual Patching talk at SANS CDI</title>
            <link>http://www.gotroot.com/article280-Virtual-Patching-talk-at-SANS-CDI</link>
            <description><![CDATA[<p>Ryan Barnett and I will be giving a talk on Virtual Patching at SANS CDI 2007.  Our talk is on December 14th, from 7:30PM to 8:30PM.  Drop by and join us, and after please join us for beers and friendly banter.
</p>

<p>Heres a link to the official SANS CDI page:
</p>

<p><a class="wiki external"  href="https://www2.sans.org/cdi07/night.php?portal=821dc21b4842373211f7acb46edf6b96">https://www2.sans.org/cdi07/night.php?portal=821dc21b4842373211f7acb46edf6b96<img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /></a>
</p>
]]></description>
            <pubDate>Wed, 12 Dec 2007 23:58:00 +0100</pubDate>
        </item>
        <item>
            <title>Virtual Patching article with SANS</title>
            <link>http://www.gotroot.com/article279-Virtual-Patching-article-with-SANS</link>
            <description><![CDATA[<p>I recently put together a tips and advice article for Virtual Patching for <a class="wiki external"  href="http://www.sans.org" rel="external">SANS</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fwww.sans.org">(cache)</a>.  You can read it here <a class="wiki external"  href="http://www.sans.edu/resources/securitylab/virtual_patching_cdi.php" rel="external">Virtual Patching for Web Applications with ModSecurity</a><img border="0" class="externallink" src="img/icons/external_link.gif" alt=" (external link)" /> <a class="wikicache" target="_blank" href="tiki-view_cache.php?url=http%3A%2F%2Fwww.sans.edu%2Fresources%2Fsecuritylab%2Fvirtual_patching_cdi.php">(cache)</a>.  Technical Review of the article was by Ryan Barnett and GIAC Advisory Board, which I greatly appreciate.
</p>
]]></description>
            <pubDate>Wed, 12 Dec 2007 23:48:00 +0100</pubDate>
        </item>
        <item>
            <title>Filter out iframe attacks</title>
            <link>http://www.gotroot.com/article278-Filter-out-iframe-attacks</link>
            <description><![CDATA[<p>iframe attacks seem to be taking a hold with many vulnerable websites.  The problem obviously being vulnerable ap
plications, which we would all like to see fixed.  However, not everyone can be so lucky as to have either perfect applications, or perfect countermeasures against these vulnerabilities.  Enter output filtering.  We've put together a special set of rules for anyone running apache.  This will filter out all your iframe attacks.
</p>
]]></description>
            <pubDate>Sun, 02 Sep 2007 23:44:00 +0100</pubDate>
        </item>
        <item>
            <title>Modsecurity 2.0 compatible rules released</title>
            <link>http://www.gotroot.com/article277-Modsecurity-2-0-compatible-rules-released</link>
            <description><![CDATA[<p>2.0 compatible rules were released today.  Consider these beta quality rules until further testing is done.  Also, the format of the rules has changed considerably in 2.0, so if you want production quality we recommend you use the 1.9 rules with modsecurity 1.9.4.
</p>
]]></description>
            <pubDate>Sun, 22 Oct 2006 19:45:00 +0100</pubDate>
        </item>
        <item>
            <title>Incoming calls problems with Broadvoice and Asterisk</title>
            <link>http://www.gotroot.com/article276-Incoming-calls-problems-with-Broadvoice-and-Asterisk</link>
            <description><![CDATA[<p>Asterisk users of broadvoice may have noticed a problem with not recieving inbound calls today.  It appears that something changed in the way Broadvoice sends their SIP packets, but we have the solution:  Just make the following change to your extensions.conf file:
</p>

<p>Look for the extensions.conf context for your incoming calls, in our case, its [from-broadvoice], and add this line at the end of your context:
</p>

<p>exten => YOURPHONENUMBER,1,Goto(from-broadvoice,1,1)
</p>

<p>Make sure you change the "from-broadvoice" to the name of your incoming calls context.
</p>
]]></description>
            <pubDate>Thu, 29 Jun 2006 22:14:00 +0100</pubDate>
        </item>
        <item>
            <title>Flaw in Microsoft AntiSpyware Beta 1</title>
            <link>http://www.gotroot.com/article274-Flaw-in-Microsoft-AntiSpyware-Beta-1</link>
            <description><![CDATA[<p>The current version of Microsoft AntiSpyware<a href="tiki-editpage.php?page=AntiSpyware" title="Create page: AntiSpyware" class="wiki wikinew">?</a> Beta 1 (version 1.0.701) contains a bug which causes issues for multiple users of a Windows XP system.
</p>

<p>Symptoms of the issue are:
1)  When a user logs in, they recieve an "Unexpected Error; quitting" messagebox.
2)  When uninstalling or installing MSAS, the user recieves an "Error 1904.Module C:\Program Files\Microsoft Antispyware\XXXXXXXX.dll failed to (un)register. HRESULT -2147220473" on multiple dlls, even when they are an Administrator.
</p>

<p>The issue arises from improper registry key permissions.
</p>

<p>We have come up with a non-optimal workaround for the issue (click Read More...), and we are currently working on a more advanced solution.
</p>

<p>We have not tested MSAS for the issue on other systems at this time.
</p>
]]></description>
            <pubDate>Wed, 25 Jan 2006 23:03:00 +0100</pubDate>
        </item>
    </channel>
</rss>

