<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:s="http://updates.zdnet.com/">
<channel>
	<title><![CDATA[aviv raff Resources | ZDNet]]></title>
	<link><![CDATA[http://updates.zdnet.com/tags/aviv+raff.html]]></link>
	<description><![CDATA[White papers, case studies, technical articles, and blog posts relating to aviv raff]]></description>
	<s:counts start="0" returned="9" found="9" />
	<language>en-us</language>
	<item>
		<title><![CDATA[Coming in July: Month of Twitter Bugs]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=3632]]></link>
		<description><![CDATA[A well-known security researcher plans to use the month of July to expose serious vulnerabilities in the Twitter ecosystem.    The Month of Twitter Bugs, a project which launches on July 1, is the handiwork of Aviv Raff left, a researcher known for his work on Web-based security...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Mon, 15 Jun 2009 11:00:24 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/twitter.html"><![CDATA[Twitter]]></category>
		<category domain="http://updates.zdnet.com/tags/aviv+raff.html"><![CDATA[Aviv Raff]]></category>
		<category domain="http://updates.zdnet.com/tags/web+2.0.html"><![CDATA[Web 2.0]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/internet.html"><![CDATA[Internet]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[CSRF vulnerability allows Twitter 'follow' abuse]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=1611]]></link>
		<description><![CDATA[Last week, TechCrunch's Jason Kincaid wrote about an obvious Twitter vulnerability that allowed a user called "johng77536" to game the popular micro-blogging service to add thousands of followers subscribers in a short period of time.    The "johng77536" account has since been disabled but a security researcher tracking...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Thu, 31 Jul 2008 13:22:45 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/twitter.html"><![CDATA[Twitter]]></category>
		<category domain="http://updates.zdnet.com/tags/aviv+raff.html"><![CDATA[Aviv Raff]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[iPhone vulnerable to phishing, spamming flaws]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=1541]]></link>
		<description><![CDATA[Security researcher Aviv Raff left has discovered a pair of basic design flaws that could turn your iPhone into easy bait for malicious phishing and spamming attacks.    According to an advisory from Raff, the iPhone's Mail and Safari applications are susceptible to a URL Spoofing vulnerability which...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Wed, 23 Jul 2008 11:58:28 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/apple+iphone.html"><![CDATA[Apple iPhone]]></category>
		<category domain="http://updates.zdnet.com/tags/apple+safari.html"><![CDATA[Apple Safari]]></category>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/spamming.html"><![CDATA[Spamming]]></category>
		<category domain="http://updates.zdnet.com/tags/flaw.html"><![CDATA[Flaw]]></category>
		<category domain="http://updates.zdnet.com/tags/aviv+raff.html"><![CDATA[Aviv Raff]]></category>
		<category domain="http://updates.zdnet.com/tags/phishing.html"><![CDATA[Phishing]]></category>
		<category domain="http://updates.zdnet.com/tags/spam.html"><![CDATA[Spam]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/spam+and+phishing.html"><![CDATA[Spam And Phishing]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[Aviv Raff drops an 0-day for IE 7.0 and 8.0b on XP]]></title>
		<link><![CDATA[http://talkback.zdnet.com/5208-12691-0.html?forumID=1&threadID=47678&messageID=887776&start=0]]></link>
		<description><![CDATA[Aviv Raff drops an 0-day for IE 7.0 and 8.0b on XPVista is NOT affected because UAC and IE7's protected modeVista is NOT affected because there're UAC and IE7's protected mode.Yet another reason to use Vista!Actually...Aviv Raff states on his blog that it is affected for Information disclosure, but that's...]]></description>
		<s:doctype><![CDATA[Discussion threads]]></s:doctype>
		<pubDate>Thu, 15 May 2008 01:45:00 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/microsoft+windows+vista+%2528longhorn%2529.html"><![CDATA[Microsoft Windows Vista (Longhorn)]]></category>
		<category domain="http://updates.zdnet.com/tags/aviv+raff.html"><![CDATA[Aviv Raff]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+internet+explorer+7.html"><![CDATA[Microsoft Internet Explorer 7]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+windows+vista.html"><![CDATA[Microsoft Windows Vista]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+windows+xp.html"><![CDATA[Microsoft Windows XP]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+internet+explorer.html"><![CDATA[Microsoft Internet Explorer]]></category>
	</item>
	<item>
		<title><![CDATA[Aviv Raff drops an 0-day for IE 7.0 and 8.0b on XP]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=1101]]></link>
		<description><![CDATA[I've been busy all day and just haven't been able to get to it until now, but Aviv Raff is a seriously bad man.Â  I follow his blog religiously as he always has some cool stuff going on and a lot of it tends to be thought provoking for other...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Wed, 14 May 2008 21:28:15 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/html.html"><![CDATA[HTML]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+windows+xp.html"><![CDATA[Microsoft Windows XP]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+internet+explorer+7.html"><![CDATA[Microsoft Internet Explorer 7]]></category>
		<category domain="http://updates.zdnet.com/tags/blog.html"><![CDATA[Blog]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+internet+explorer.html"><![CDATA[Microsoft Internet Explorer]]></category>
		<category domain="http://updates.zdnet.com/tags/aviv+raff.html"><![CDATA[Aviv Raff]]></category>
		<category domain="http://updates.zdnet.com/tags/blogging.html"><![CDATA[Blogging]]></category>
		<category domain="http://updates.zdnet.com/tags/web+browsers.html"><![CDATA[Web Browsers]]></category>
		<category domain="http://updates.zdnet.com/tags/internet.html"><![CDATA[Internet]]></category>
		<category domain="http://updates.zdnet.com/tags/nathan+mcfeters.html"><![CDATA[Nathan McFeters]]></category>
	</item>
	<item>
		<title><![CDATA[Skype: Video chat feature meets code execution vulnerability]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=819]]></link>
		<description><![CDATA[Updated below: Aviv Raff, a security researcher, has found a flaw in Skype that could allow an attacker to control your PC.    On his blog, Raff explains the following:  Skype uses Internet Explorer web control within the application to render internal and external HTML pages. Examples...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Fri, 18 Jan 2008 03:21:33 -0800</pubDate>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/skype+technologies+s.a..html"><![CDATA[Skype Technologies S.A.]]></category>
		<category domain="http://updates.zdnet.com/tags/video.html"><![CDATA[Video]]></category>
		<category domain="http://updates.zdnet.com/tags/flaw.html"><![CDATA[Flaw]]></category>
		<category domain="http://updates.zdnet.com/tags/aviv+raff.html"><![CDATA[Aviv Raff]]></category>
		<category domain="http://updates.zdnet.com/tags/corporate+communications.html"><![CDATA[Corporate Communications]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/marketing.html"><![CDATA[Marketing]]></category>
		<category domain="http://updates.zdnet.com/tags/larry+dignan.html"><![CDATA[Larry Dignan]]></category>
	</item>
	<item>
		<title><![CDATA[Despite AOL's claim, AIM worm hole still wide open]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=542]]></link>
		<description><![CDATA[There's a nasty worm hole in America Online's standalone AIM instant messaging software that won't be patched until the middle of October.    AOL claims that the vulnerability, which allows a remote attacker to launch executable code without any user action, has been patched in the latest beta...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Thu, 27 Sep 2007 08:43:11 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/aol+instant+messenger.html"><![CDATA[AOL Instant Messenger]]></category>
		<category domain="http://updates.zdnet.com/tags/america+online+inc..html"><![CDATA[America Online Inc.]]></category>
		<category domain="http://updates.zdnet.com/tags/im.html"><![CDATA[IM]]></category>
		<category domain="http://updates.zdnet.com/tags/vulnerability.html"><![CDATA[Vulnerability]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+internet+explorer.html"><![CDATA[Microsoft Internet Explorer]]></category>
		<category domain="http://updates.zdnet.com/tags/aviv+raff.html"><![CDATA[Aviv Raff]]></category>
		<category domain="http://updates.zdnet.com/tags/instant+messaging.html"><![CDATA[Instant Messaging]]></category>
		<category domain="http://updates.zdnet.com/tags/web+browsers.html"><![CDATA[Web Browsers]]></category>
		<category domain="http://updates.zdnet.com/tags/security.html"><![CDATA[Security]]></category>
		<category domain="http://updates.zdnet.com/tags/internet.html"><![CDATA[Internet]]></category>
		<category domain="http://updates.zdnet.com/tags/online+communications.html"><![CDATA[Online Communications]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[Unpatched QuickTime-to-Firefox flaw dings IE too]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=514]]></link>
		<description><![CDATA[Security researcher Aviv Raff has found a way to use the one-year-old and still unpatched QuickTime vulnerability to automate XAS cross application scripting attacks against users of Microsoft's Internet Explorer.    To demonstrate the attack scenario, Raff embedded a rigged QuickTime file on Google's BlogSpot to force a...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Fri, 14 Sep 2007 11:30:22 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/apple+quicktime.html"><![CDATA[Apple QuickTime]]></category>
		<category domain="http://updates.zdnet.com/tags/microsoft+internet+explorer.html"><![CDATA[Microsoft Internet Explorer]]></category>
		<category domain="http://updates.zdnet.com/tags/attack.html"><![CDATA[Attack]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
	<item>
		<title><![CDATA[Storm Worm botnet could be world's most powerful supercomputer]]></title>
		<link><![CDATA[http://blogs.zdnet.com/security/?p=493]]></link>
		<description><![CDATA[Nearly nine months after it was first discovered, the Storm Worm Trojan continues to surge, building what experts believe could be the  world's most powerful supercomputer.    The Trojan, which uses a myriad of social engineering lures to trick Windows users into downloading malware,  has successfully...]]></description>
		<s:doctype><![CDATA[Blog posts]]></s:doctype>
		<pubDate>Thu, 06 Sep 2007 08:54:52 -0700</pubDate>
		<category domain="http://updates.zdnet.com/tags/operation.html"><![CDATA[Operation]]></category>
		<category domain="http://updates.zdnet.com/tags/supercomputer.html"><![CDATA[Supercomputer]]></category>
		<category domain="http://updates.zdnet.com/tags/malware.html"><![CDATA[Malware]]></category>
		<category domain="http://updates.zdnet.com/tags/worm.html"><![CDATA[Worm]]></category>
		<category domain="http://updates.zdnet.com/tags/ryan+naraine.html"><![CDATA[Ryan Naraine]]></category>
	</item>
</channel>
</rss>
