<?xml version="1.0" encoding="UTF-8"?>

<!-- generator="wordpress/2.0.3" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	>

http://www.ngssoftware.com<channel>
	<title> NGSSoftware news</title>
	<link>/news/ </link>
	<description>NGS In The News</description>	<pubDate>Tue, 20 May 2008 13:48:46 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.3</generator>
	<language>en</language>
			<item>
		<title>SC AWARDS EUROPE 2008: Winners announced</title>
		<link>http://www.ngssoftware.com/news/sc-awards-europe-2008-winners-announced/ </link>
		<comments>http://www.ngssoftware.com/news/sc-awards-europe-2008-winners-announced/#comments</comments>
		<pubDate>Wed, 23 Apr 2008 14:15:04 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/news/sc-awards-europe-2008-winners-announced/</guid>
		<description><![CDATA[&#8220;The accolade for Best Security Company went to UK based NGSSoftware. A beaming  David Litchfield, the managing director, accepted the award from Lumension’s  Andrew Clarke. &#8221;
Read the full article at SC Magazine.
NGSSoftware&#8217;s Press Release.

]]></description>
			<content:encoded><![CDATA[<p>&#8220;The accolade for Best Security Company went to UK based NGSSoftware. A beaming  David Litchfield, the managing director, accepted the award from Lumension’s  Andrew Clarke. &#8221;</p>
<p><a target="_blank" href="http://scmagazine.com/uk/news/article/804222/sc-awards-europe-2008-winners-announced/">Read the full article at SC Magazine</a>.</p>
<p><a target="_blank" href="http://www.ngssoftware.com/press-releases/ngssoftware-wins-best-security-company-at-sc-awards-2008/">NGSSoftware&#8217;s Press Release</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/sc-awards-europe-2008-winners-announced/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>David LeBlanc&#8217;s 15 Most Influential Security People</title>
		<link>http://www.ngssoftware.com/news/david-leblancs-15-most-influential-security-people/ </link>
		<comments>http://www.ngssoftware.com/news/david-leblancs-15-most-influential-security-people/#comments</comments>
		<pubDate>Tue, 18 Mar 2008 06:42:59 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/news/david-leblancs-15-most-influential-security-people/</guid>
		<description><![CDATA[&#8220;Same thing for SQL – used to be a security mess, now it&#8217;s really solid – and  thanks to NGS for helping&#8221;
Read the full article at David LeBlanc&#8217;s Web Log.

]]></description>
			<content:encoded><![CDATA[<p>&#8220;Same thing for SQL – used to be a security mess, now it&#8217;s really solid – and  thanks to NGS for helping&#8221;</p>
<p>Read the full article at <a target="_blank" href="http://blogs.msdn.com/david_leblanc/archive/2008/02/14/15-most-influential-security-people.aspx">David LeBlanc&#8217;s Web Log</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/david-leblancs-15-most-influential-security-people/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>How to combat the Sans Institute&#8217;s top 10 security threats</title>
		<link>http://www.ngssoftware.com/press-releases/how-to-combat-the-sans-institutes-top-10-security-threats/ </link>
		<comments>http://www.ngssoftware.com/press-releases/how-to-combat-the-sans-institutes-top-10-security-threats/#comments</comments>
		<pubDate>Mon, 14 Jan 2008 13:58:59 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>press releases</category>
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/press-releases/how-to-combat-the-sans-institutes-top-10-security-threats/</guid>
		<description><![CDATA[Read the latest article from NGSSoftware&#8217;s Tim Mullen at ComputerWeekly.com.
&#8220;If one were to go back through the archives of the Sans Institute&#8217;s Top Threats lists, some of which I have contributed to, one would find the range of threats and vulnerabilities shifting and changing through the years along with the ever-changing security landscape itself - [...]]]></description>
			<content:encoded><![CDATA[<p>Read the latest article from NGSSoftware&#8217;s Tim Mullen at <a target="_blank" href="http://www.computerweekly.com/Articles/2008/01/14/228871/how-to-combat-the-sans-institutes-top-10-security-threats.htm">ComputerWeekly.com</a>.</p>
<p>&#8220;If one were to go back through the archives of the Sans Institute&#8217;s Top Threats lists, some of which I have contributed to, one would find the range of threats and vulnerabilities shifting and changing through the years along with the ever-changing security landscape itself - writes Timothy Mullen, vice-president of consulting services at NGSSoftware.&#8221;
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/press-releases/how-to-combat-the-sans-institutes-top-10-security-threats/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>Survey finds thousands of database servers open to attack</title>
		<link>http://www.ngssoftware.com/news/survey-finds-thousands-of-database-servers-open-to-attack/ </link>
		<comments>http://www.ngssoftware.com/news/survey-finds-thousands-of-database-servers-open-to-attack/#comments</comments>
		<pubDate>Wed, 14 Nov 2007 10:32:33 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/news/survey-finds-thousands-of-database-servers-open-to-attack/</guid>
		<description><![CDATA[&#8220;Litchfield said. &#8220;Whilst it&#8217;s not possible to say how many of these systems are engaged in a commercial function, with just under half a million servers accessible there is clearly potential for external hackers and criminals to gain access to these systems and to sensitive information.&#8221;"
Read the full article at SearchSecurity.com.

]]></description>
			<content:encoded><![CDATA[<p>&#8220;Litchfield said. &#8220;Whilst it&#8217;s not possible to say how many of these systems are engaged in a commercial function, with just under half a million servers accessible there is clearly potential for external hackers and criminals to gain access to these systems and to sensitive information.&#8221;"</p>
<p><a target="_blank" href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1281896,00.html">Read the full article at SearchSecurity.com</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/survey-finds-thousands-of-database-servers-open-to-attack/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>Thousands of Unprotected Databases Litter the Internet</title>
		<link>http://www.ngssoftware.com/news/thousands-of-unprotected-databases-litter-the-internet/ </link>
		<comments>http://www.ngssoftware.com/news/thousands-of-unprotected-databases-litter-the-internet/#comments</comments>
		<pubDate>Wed, 14 Nov 2007 10:26:10 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/advisories/thousands-of-unprotected-databases-litter-the-internet/</guid>
		<description><![CDATA[&#8220;The findings represent a &#8220;significant risk,&#8221; according to David Litchfield, the security researcher who authored the report. &#8220;With just under half a million servers accessible, there is clearly potential for external hackers and criminals to gain access to these systems and to sensitive information,&#8221; he said. &#8221;
Read the full article at eWeek.com.

]]></description>
			<content:encoded><![CDATA[<p>&#8220;The findings represent a &#8220;significant risk,&#8221; according to David Litchfield, the security researcher who authored the report. &#8220;With just under half a million servers accessible, there is clearly potential for external hackers and criminals to gain access to these systems and to sensitive information,&#8221; he said. &#8221;</p>
<p><a target="_blank" href="http://www.eweek.com/article2/0,1895,2217123,00.asp">Read the full article at eWeek.com</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/thousands-of-unprotected-databases-litter-the-internet/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>Half Million Database Servers Lack Firewall Security</title>
		<link>http://www.ngssoftware.com/news/half-million-database-servers-lack-firewall-security/ </link>
		<comments>http://www.ngssoftware.com/news/half-million-database-servers-lack-firewall-security/#comments</comments>
		<pubDate>Wed, 14 Nov 2007 10:23:07 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/news/half-million-database-servers-lack-firewall-security/</guid>
		<description><![CDATA[&#8220;Litchfield took a look at just over 1 million randomly generated Internet Protocol [IP] addresses, checking them to see if he could access them on the IP ports reserved for Microsoft SQL Server or Oracle&#8217;s database. The results? He found 157 SQL servers and 53 Oracle servers. Litchfield then relied on known estimates of the [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Litchfield took a look at just over 1 million randomly generated Internet Protocol [IP] addresses, checking them to see if he could access them on the IP ports reserved for Microsoft SQL Server or Oracle&#8217;s database. The results? He found 157 SQL servers and 53 Oracle servers. Litchfield then relied on known estimates of the number of systems on the Internet to arrive at his conclusion: &#8220;There are approximately 368,000 Microsoft SQl Servers&#8230; and about 124,000 Oracle database servers directly accessible on the Internet,&#8221; he wrote in his report, due to be made public next week.&#8221;</p>
<p><a target="_blank" href="http://www.pcworld.com/businesscenter/article/139622/half_million_database_servers_lack_firewall_security.html">Read the full article at PCWorld.com</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/half-million-database-servers-lack-firewall-security/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>Black Hat 2007: New database forensics tool could aid data breach cases</title>
		<link>http://www.ngssoftware.com/news/black-hat-2007-new-database-forensics-tool-could-aid-data-breach-cases/ </link>
		<comments>http://www.ngssoftware.com/news/black-hat-2007-new-database-forensics-tool-could-aid-data-breach-cases/#comments</comments>
		<pubDate>Fri, 03 Aug 2007 08:07:02 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/news/black-hat-2007-new-database-forensics-tool-could-aid-data-breach-cases/</guid>
		<description><![CDATA[&#8220;A new database forensics tool being developed by database security guru David Litchfield could help data breach investigators build evidence against attackers.
itchfield, managing director at UK-based NGS (Next Generation Security) Software Ltd. plans to release the Forensic Examiners Database Scalpel. The new tool is designed for Oracle database management systems and automates the process of [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;A new database forensics tool being developed by database security guru David Litchfield could help data breach investigators build evidence against attackers.</p>
<p>itchfield, managing director at UK-based NGS (Next Generation Security) Software Ltd. plans to release the Forensic Examiners Database Scalpel. The new tool is designed for Oracle database management systems and automates the process of sifting through mountains of system metadata to discover the cause and extent of a data security breach.&#8221;</p>
<p><a target="_blank" href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1266525,00.html">Read the full article at SearchSecurity.com</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/black-hat-2007-new-database-forensics-tool-could-aid-data-breach-cases/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>Researchers Flag VoIP Exploits at BlackHat</title>
		<link>http://www.ngssoftware.com/news/researchers-flag-voip-exploits-at-blackhat/ </link>
		<comments>http://www.ngssoftware.com/news/researchers-flag-voip-exploits-at-blackhat/#comments</comments>
		<pubDate>Fri, 03 Aug 2007 08:03:41 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/news/researchers-flag-voip-exploits-at-blackhat/</guid>
		<description><![CDATA[&#8220;Barrie Dempster, senior security consultant at NGS Software, who also gave a presentation on the topic of VOIP security at Black Hat, commented that the iSec Partners exploits against H.323 and IAX represented valuable research. But he added that if these exploits are possible based on network sniffing, the first order of concern should be [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Barrie Dempster, senior security consultant at NGS Software, who also gave a presentation on the topic of VOIP security at Black Hat, commented that the iSec Partners exploits against H.323 and IAX represented valuable research. But he added that if these exploits are possible based on network sniffing, the first order of concern should be that an attacker is sniffing the network.&#8221;</p>
<p><a target="_blank" href="http://www.pcworld.com/article/id,135432-c,webtelephonyconferencing/article.html">Read the full article at PCWorld.com</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/researchers-flag-voip-exploits-at-blackhat/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>VoIP Vandals</title>
		<link>http://www.ngssoftware.com/news/voip-vandals/ </link>
		<comments>http://www.ngssoftware.com/news/voip-vandals/#comments</comments>
		<pubDate>Fri, 03 Aug 2007 08:00:40 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/news/voip-vandals/</guid>
		<description><![CDATA[&#8220;VoIP is about convergence. The idea is that you save money and resources and time,&#8221; said Barrie Dempster, a senior security consultant at Next Generation Security Software who made a presentation at the conference. &#8220;But convergent systems give you more avenues of attack, more ways in. It&#8217;s not a secure environment.&#8221;
Read the full article at [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;VoIP is about convergence. The idea is that you save money and resources and time,&#8221; said Barrie Dempster, a senior security consultant at Next Generation Security Software who made a presentation at the conference. &#8220;But convergent systems give you more avenues of attack, more ways in. It&#8217;s not a secure environment.&#8221;</p>
<p><a target="_blank" href="http://www.forbes.com/technology/2007/08/02/voip-security-flaws-tech-internet-cx_ag_0802techvoip.html">Read the full article at Forbes.com</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/voip-vandals/feed/ </wfw:commentRSS>
		</item>
		<item>
		<title>ActiveX flaws plague SAP GUI</title>
		<link>http://www.ngssoftware.com/news/activex-flaws-plague-sap-gui/ </link>
		<comments>http://www.ngssoftware.com/news/activex-flaws-plague-sap-gui/#comments</comments>
		<pubDate>Mon, 09 Jul 2007 14:28:36 +0000</pubDate>
		<dc:creator>NGS</dc:creator>
		
	<category>news</category>
		<guid isPermaLink="false">http://www.ngssoftware.com/news/activex-flaws-plague-sap-gui/</guid>
		<description><![CDATA[&#8220;Two critical ActiveX flaws have been discovered in EnjoySAP, German business software vendor SAP AG&#8217;s new graphical user interface designed to improve the end user experience.
The discovery was made by security researcher Mark Litchfield of UK-based Next Generation Security (NGS) Software, who said the flaws could be remotely exploited by an attacker to gain access [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Two critical ActiveX flaws have been discovered in EnjoySAP, German business software vendor SAP AG&#8217;s new graphical user interface designed to improve the end user experience.</p>
<p>The discovery was made by security researcher Mark Litchfield of UK-based Next Generation Security (NGS) Software, who said the flaws could be remotely exploited by an attacker to gain access to a user&#8217;s system.&#8221;</p>
<p><a target="_blank" href="http://searchsecurity.techtarget.com/originalContent/0,289142,sid14_gci1263410,00.html">Read the full article at SearchSecurity.Com</a>.
</p>
]]></content:encoded>
			<wfw:commentRSS>http://www.ngssoftware.com/news/activex-flaws-plague-sap-gui/feed/ </wfw:commentRSS>
		</item>
	</channel>
</rss>
