<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Updated Undercover Exploit List</title>
	<atom:link href="http://spiresecurity.com/?feed=rss2&#038;p=401" rel="self" type="application/rss+xml" />
	<link>http://spiresecurity.com/?p=401</link>
	<description>Risk and Cybersecurity Analysis</description>
	<lastBuildDate>Wed, 21 Aug 2013 23:28:51 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.5.1</generator>
	<item>
		<title>By: Steve Christey</title>
		<link>http://spiresecurity.com/?p=401&#038;cpage=1#comment-607</link>
		<dc:creator>Steve Christey</dc:creator>
		<pubDate>Sun, 11 Feb 2007 07:15:24 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=401#comment-607</guid>
		<description><![CDATA[CVE-2006-2286 is for a PHP exploit that was discovered in the wild; see the extensive forum discussion at http://www.dokeos.com/forum/viewtopic.php?t=6848


]]></description>
		<content:encoded><![CDATA[<p>CVE-2006-2286 is for a PHP exploit that was discovered in the wild; see the extensive forum discussion at <a href="http://www.dokeos.com/forum/viewtopic.php?t=6848" rel="nofollow">http://www.dokeos.com/forum/viewtopic.php?t=6848</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Christey (CVE)</title>
		<link>http://spiresecurity.com/?p=401&#038;cpage=1#comment-606</link>
		<dc:creator>Steve Christey (CVE)</dc:creator>
		<pubDate>Wed, 09 Aug 2006 01:00:54 +0000</pubDate>
		<guid isPermaLink="false">http://spiresecurity.com/blog/?p=401#comment-606</guid>
		<description><![CDATA[CVE-1999-0977 is for an sadmind vulnerability that was first detected in the wild; the references demonstrate this:

http://www.security.nnov.ru/1999/december/sadmin.html

And on Tuesday Aug 8, 2006, advisory MS06-040 says &quot;When the security bulletin was released, Microsoft had received information that this vulnerability was being exploited&quot; but also says that there had been no public disclosure.  That makes it undercover in my book.

There are probably at least a dozen web application vulns that were exploited before disclosure, but only the vulnerability databases see that stuff buried in vendor forums, and since it&#039;s only been a curiosity, so it hasn&#039;t been tracked closely.  I&#039;ll notify you when I see them.

The MySpace Samy worm and other XSS worms probably count, but since that&#039;s not in enterprise software, it might be a slightly different beast than what you&#039;re talking about.

]]></description>
		<content:encoded><![CDATA[<p>CVE-1999-0977 is for an sadmind vulnerability that was first detected in the wild; the references demonstrate this:</p>
<p><a href="http://www.security.nnov.ru/1999/december/sadmin.html" rel="nofollow">http://www.security.nnov.ru/1999/december/sadmin.html</a></p>
<p>And on Tuesday Aug 8, 2006, advisory MS06-040 says &#8220;When the security bulletin was released, Microsoft had received information that this vulnerability was being exploited&#8221; but also says that there had been no public disclosure.  That makes it undercover in my book.</p>
<p>There are probably at least a dozen web application vulns that were exploited before disclosure, but only the vulnerability databases see that stuff buried in vendor forums, and since it&#8217;s only been a curiosity, so it hasn&#8217;t been tracked closely.  I&#8217;ll notify you when I see them.</p>
<p>The MySpace Samy worm and other XSS worms probably count, but since that&#8217;s not in enterprise software, it might be a slightly different beast than what you&#8217;re talking about.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
