<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Token Kidnapping</title><link>http://blogs.technet.com/msrc/archive/2009/04/14/token-kidnapping.aspx</link><description>Hello everyone, As you can see from the April 2009 release summary, we addressed the Token Kidnapping issue with bulletin MS09-012 . This issue allowed an attacker to gain full control of a server if the attacker can first run malicious code on the server</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Token Kidnapping | Security News</title><link>http://blogs.technet.com/msrc/archive/2009/04/14/token-kidnapping.aspx#3226418</link><pubDate>Tue, 14 Apr 2009 22:06:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3226418</guid><dc:creator>Token Kidnapping | Security News</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.nhanblogger.com/security/2009/04/token-kidnapping/"&gt;http://www.nhanblogger.com/security/2009/04/token-kidnapping/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Token Kidnapping - Fixed</title><link>http://blogs.technet.com/msrc/archive/2009/04/14/token-kidnapping.aspx#3226550</link><pubDate>Wed, 15 Apr 2009 07:20:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3226550</guid><dc:creator>Server: Microsoft-IIS/7.0\r\n </dc:creator><description>&lt;p&gt;A year ago... Cesar Cerrudo presented a serious vulnerability via evalvation of privilege involving the&lt;/p&gt;
</description></item><item><title>Token Kidnapping - Fixed</title><link>http://blogs.technet.com/msrc/archive/2009/04/14/token-kidnapping.aspx#3226551</link><pubDate>Wed, 15 Apr 2009 07:22:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3226551</guid><dc:creator>Server: Microsoft-IIS/7.0\r\n </dc:creator><description>&lt;p&gt;A year ago... Cesar Cerrudo presented a serious vulnerability via evalvation of privilege involving the&lt;/p&gt;
</description></item><item><title>Boletim MS09-012 e Token Kidnapping</title><link>http://blogs.technet.com/msrc/archive/2009/04/14/token-kidnapping.aspx#3226697</link><pubDate>Wed, 15 Apr 2009 15:21:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3226697</guid><dc:creator>Negócio de Risco</dc:creator><description>&lt;p&gt;A Microsoft divulgou ontem 8 novos boletins de seguran&amp;#231;a , corrigindo 23 vulnerabilidades diferentes.&lt;/p&gt;
</description></item><item><title>Token Kidnapping fixed</title><link>http://blogs.technet.com/msrc/archive/2009/04/14/token-kidnapping.aspx#3227718</link><pubDate>Fri, 17 Apr 2009 23:29:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3227718</guid><dc:creator>Nazim's IIS Security Blog</dc:creator><description>&lt;p&gt;I had gone into a little detail about explaining token kidnapping in an earlier post . Despite all the&lt;/p&gt;
</description></item><item><title>Nieuws t/m week 17 - 2009</title><link>http://blogs.technet.com/msrc/archive/2009/04/14/token-kidnapping.aspx#3234409</link><pubDate>Sun, 03 May 2009 12:12:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3234409</guid><dc:creator>Bob's Nieuws</dc:creator><description>&lt;p&gt;De afgelopen periode was nogal een periode van veranderingen. Zo was er de bijna overname van Sun door&lt;/p&gt;
</description></item></channel></rss>