<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MattJay Security &#187; vulnerability</title>
	<atom:link href="http://www.mattjaysecurity.com/category/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mattjaysecurity.com</link>
	<description>The musings of a young information security professional on current security events.</description>
	<lastBuildDate>Thu, 25 Mar 2010 04:01:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=abc</generator>
		<item>
		<title>RBS WordPay SQL Injection [LiquidMatrix]</title>
		<link>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/#comments</comments>
		<pubDate>Thu, 10 Sep 2009 18:06:24 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[Breach]]></category>
		<category><![CDATA[SQL Injection]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=73</guid>
		<description><![CDATA[My most recent post over at LiquidMatrix Security Digest Royal Bank of Scottland Group might be feeling a bit exposed this afternoon&#8230; RBS WordPay, a system that processes millions of payments daily has been compromised. It looks like the database is just dying to give up names, credit card numbers, email addresses, and all sorts [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/kilts-1.jpg"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/kilts-1-298x300.jpg" alt="Kilts" title="Kilts" width="298" height="300" class="aligncenter size-medium wp-image-7326" /></a></p>
<p><strong>My most recent post over at <a href="http://www.liquidmatrix.org/blog/">LiquidMatrix Security Digest</a></strong></p>
<p>Royal Bank of Scottland Group might be feeling a bit exposed this afternoon&#8230;</p>
<p>RBS WordPay, a system that processes millions of payments daily has been compromised.  It looks like the database is just dying to give up names, credit card numbers, email addresses, and all sorts of juicy information to whoever asks for it. Unu has a great write up of the vulnerability with plenty of juicy screenshots on his <a href="http://unu1234567.baywords.com/2009/09/10/rbs-wordpay-hacked-full-database-acces/">blog</a>.</p>
<p>Here is a real kicker for you:</p>
<blockquote><p>
The next picture is awesome, but really what we see. In the picture appear user, host and password in mysql database, user table. But look well to the first user webphp, surrounded me. We have % to host and NOTHING in the password !!! I mean we have a user password NULL and % to host, that means that we can log on his account, the MySQL server without password, from any IP.
</p></blockquote>
<p><a href="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/RBS_SQLi.jpg"><img src="http://www.liquidmatrix.org/blog/wp-content/uploads/2009/09/RBS_SQLi-300x217.jpg" alt="RBS_SQLi" title="RBS_SQLi" width="300" height="217" class="aligncenter size-medium wp-image-7324" /></a></p>
<p>There is also some fun poked at Bill Gates which never hurts.</p>
<p><a href="http://unu1234567.baywords.com/2009/09/10/rbs-wordpay-hacked-full-database-access/">Article Link</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/09/rbs-wordpay-sql-injection-liquidmatrix/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>How Smart is Your Grid?</title>
		<link>http://www.mattjaysecurity.com/2009/03/how-smart-is-your-grid/#utm_source=feed&amp;utm_medium=feed&amp;utm_campaign=feed</link>
		<comments>http://www.mattjaysecurity.com/2009/03/how-smart-is-your-grid/#comments</comments>
		<pubDate>Mon, 23 Mar 2009 06:33:00 +0000</pubDate>
		<dc:creator>Matt Johansen</dc:creator>
				<category><![CDATA[cyberdouchery]]></category>
		<category><![CDATA[smart grid]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://www.mattjaysecurity.com/?p=8</guid>
		<description><![CDATA[My latest post over at Liquidmatrix Security Digest: So in an utter disregard for buzzwords, CNN Homeland Security Correspondent Jeanne Meserve has dwelled into James&#8217; land of cyberdouchery. The article entitled &#8220;Smart Grid may be vulnerable to hackers&#8221; briefly discusses the United States and it&#8217;s respective power companies anxiously deploying a high-tech power grid while [...]]]></description>
			<content:encoded><![CDATA[<p><a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_gq8ASTy40oI/ScctgP_6E7I/AAAAAAAAADI/iUQ38UmcEi8/s1600-h/blackout.jpg"><img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 282px;" src="http://4.bp.blogspot.com/_gq8ASTy40oI/ScctgP_6E7I/AAAAAAAAADI/iUQ38UmcEi8/s320/blackout.jpg" alt="" id="BLOGGER_PHOTO_ID_5316267917207802802" border="0" /></a><br />My latest post over at <a href="http://www.liquidmatrix.org/blog">Liquidmatrix Security Digest</a>:</p>
<p>So in an utter disregard for buzzwords, CNN Homeland Security Correspondent Jeanne Meserve has dwelled into <a href="http://www.liquidmatrix.org/blog/about/">James&#8217;</a> land of <b>cyberdouchery</b>.  The <a href="http://www.cnn.com/2009/TECH/03/20/smartgrid.vulnerability/">article</a> entitled &#8220;Smart Grid may be vulnerable to hackers&#8221; briefly discusses the United States and it&#8217;s respective power companies anxiously deploying a high-tech power grid while simultaneously raping the words &#8220;cyber&#8221; and &#8220;smart&#8221;.</p>
<p>Power companies are installing new automated meters at an astonishing rate which seems to be the first step in the roll out. The eventual goal is to improve electricity efficiency and reliability using sensors on your home meters that talk back to the power grid.  President Obama is on board dishing out $4.5 billion towards all this.</p>
<p>So where does the problem lie?</p>
<p>Well some interesting quotes throughout the article define the issue very clearly. One of our friends at <a href="http://www.inguardians.com/">InGuardians</a>, <a href="http://www.inguardians.com/info/#Skoudis">Ed Skoudis</a> chimed in stating,<br />
<blockquote> &#8220;I think we are putting the cart before the horse here to get this stuff rolled out very fast.&#8221; </p></blockquote>
<p> Also, Matt Spaur, a product marketing analyst added my favorite tidbit,<br />
<blockquote> &#8220;Any network can be hacked.&#8221; </p></blockquote>
<p>All in all, this is obviously a huge security issue and if you even remotely (no pun intended) glanced at <a href="http://www.imdb.com/title/tt0337978/">Live Free or Die Hard</a> you&#8217;d get the picture. Electric grids are all ready &#8220;hackable&#8221; you just have to not be afraid of heights and be a huge fan of rubber. The automation wouldn&#8217;t necessarily create many new vulnerabilities, it would most definitely increase the risk by increasing the likelihood and severity of exploitation.</p>
<p>With this system in place there really is no room for &#8220;roll it out and patch it later.&#8221; We can all hope that the money makers take their time on this one and do it right.</p>
<p><a href="http://www.cnn.com/2009/TECH/03/20/smartgrid.vulnerability/">Article Link</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.mattjaysecurity.com/2009/03/how-smart-is-your-grid/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
