<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Microsoft Warns of Serious MS-SQL 2000 &amp; 2005 Vulnerability</title>
	<atom:link href="http://www.darknet.org.uk/2008/12/microsoft-warns-of-serious-ms-sql-2000-2005-vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk/2008/12/microsoft-warns-of-serious-ms-sql-2000-2005-vulnerability/</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Sat, 21 Nov 2009 06:04:59 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Bogwitch</title>
		<link>http://www.darknet.org.uk/2008/12/microsoft-warns-of-serious-ms-sql-2000-2005-vulnerability/#comment-125282</link>
		<dc:creator>Bogwitch</dc:creator>
		<pubDate>Wed, 24 Dec 2008 00:31:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1337#comment-125282</guid>
		<description>I&#039;m all for responsible disclosure but I&#039;m not sure that SEC Consult Vulnerability Lab has acted responsibly in this case.
They should have forced Microsoft&#039;s hand way earlier than this, seven months is an unacceptable delay.

There also seems to be a disconnect here...
To quote: Marc Maiffret, director of professional services, with The DigiTrust Group, a security consulting firm. “It is rather low risk given other vulnerabilities that exist,”

If the vulnerability allows the execution of remote code, I don&#039;t see this as low risk.</description>
		<content:encoded><![CDATA[<p>I&#8217;m all for responsible disclosure but I&#8217;m not sure that SEC Consult Vulnerability Lab has acted responsibly in this case.<br />
They should have forced Microsoft&#8217;s hand way earlier than this, seven months is an unacceptable delay.</p>
<p>There also seems to be a disconnect here&#8230;<br />
To quote: Marc Maiffret, director of professional services, with The DigiTrust Group, a security consulting firm. “It is rather low risk given other vulnerabilities that exist,”</p>
<p>If the vulnerability allows the execution of remote code, I don&#8217;t see this as low risk.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: navin</title>
		<link>http://www.darknet.org.uk/2008/12/microsoft-warns-of-serious-ms-sql-2000-2005-vulnerability/#comment-125277</link>
		<dc:creator>navin</dc:creator>
		<pubDate>Tue, 23 Dec 2008 15:07:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1337#comment-125277</guid>
		<description>I&#039;d read about this a few weeks back on an underground forum and a few haxors claimed tht they had exploited it successfully....but I din&#039;t know it had been discovered in April!! 7 whole months...sheesh!!</description>
		<content:encoded><![CDATA[<p>I&#8217;d read about this a few weeks back on an underground forum and a few haxors claimed tht they had exploited it successfully&#8230;.but I din&#8217;t know it had been discovered in April!! 7 whole months&#8230;sheesh!!</p>
]]></content:encoded>
	</item>
</channel>
</rss>
