<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet type="text/xsl" media="screen" href="/App_Themes/default/rss.xslt"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:evnet="http://www.mscommunities.com/rssmodule/"><channel><title>Comment Feed for Stephen Toulouse - Tour around Microsoft's Security Response Center (TheChannel9Team on Channel 9)</title><atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/posts/thechannel9team/stephen-toulouse-tour-around-microsofts-security-response-center/rss/default.aspx" /><image><url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url><title>Comment Feed for Stephen Toulouse - Tour around Microsoft's Security Response Center (TheChannel9Team on Channel 9)</title><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/</link></image><description>Stephen Toulouse - Tour around Microsoft's Security Response Center</description><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/</link><language>en-us</language><pubDate>Sun, 15 May 2005 22:28:56 GMT</pubDate><lastBuildDate>Sun, 15 May 2005 22:28:56 GMT</lastBuildDate><generator>EvNet (EvNet, Version=1.0.3608.3122, Culture=neutral, PublicKeyToken=null)</generator><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>&lt;P&gt;We do not "get off" on claiming that 30 days is a standard time to expect a fix. We actually think that 60 days is the timeframe for producing a fix. That is why on our upcoming advisories page we only start listing vulnerability patches as being&amp;nbsp;overdue after the 60 day mark, not 30 as you incorrectly state.&lt;BR&gt;&lt;BR&gt;If you want to get specific about it though Microsoft is actually apart of an industry group whom wrote a specificion on vulnerability reporting and vendor handling of reported vulnerabilities. Within that standard Microsoft and other companies in the industry agree that:&lt;/P&gt;
&lt;P&gt;"The appropriate timeframe will vary from case to case, but it is important to set a target. By convention, thirty (30) calendar days (measured from the date the Vendors acknowledges receipt of the VSR to deliver of the fix) has been established as a good starting point for the discussions, as it often provides an appropriate balance between timeliness and thoroughness." [1]&lt;BR&gt;&lt;BR&gt;So as you can see the 60 day window that eEye uses is actually *longer* than the general industry guidelines as set by Microsoft and other security companies.&lt;BR&gt;&lt;BR&gt;Reasonable amount of time? Should take them a year to fix vulnerabilities? If you believe that then the secretly encoded brainwashing images within channel 9 productions is finally starting to pay off.&lt;BR&gt;&lt;BR&gt;Signed,&lt;BR&gt;Marc Maiffret&lt;BR&gt;Chief Hacking Officer&lt;BR&gt;eEye Digital Security&lt;BR&gt;T.949.349.9062&lt;BR&gt;F.949.349.9538&lt;BR&gt;&lt;a href="http://eeye.com/Retina"&gt;&lt;U&gt;http://eEye.com/Retina&lt;/U&gt;&lt;/a&gt; - Network Security Scanner&lt;BR&gt;&lt;a href="http://eeye.com/Iris"&gt;&lt;U&gt;http://eEye.com/Iris&lt;/U&gt;&lt;/a&gt; - Network Traffic Analyzer&lt;BR&gt;&lt;a href="http://eeye.com/SecureIIS"&gt;&lt;U&gt;http://eEye.com/SecureIIS&lt;/U&gt;&lt;/a&gt; - Stop known and unknown IIS vulnerabilities &lt;/P&gt;
&lt;P&gt;[1] - &lt;a href="http://www.oisafety.org/"&gt;http://www.oisafety.org/&lt;/a&gt;&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&amp;nbsp;&lt;/P&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=67084</link><pubDate>Sun, 15 May 2005 22:28:56 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=67084</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/67084/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>We do not "get off" on claiming that 30 days is a standard time to expect a fix. We actually think that 60 days is the timeframe for producing a fix. That is why on our upcoming advisories page we only start listing vulnerability patches as being&amp;nbsp;overdue after the 60 day mark, not 30 as you&amp;#8230;</evnet:previewtext><dc:creator>mmaiffret</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/67084/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>What about this seemingly important security issue with Media DRM:&lt;BR&gt;Hackers hijack Microsoft DRM - ZDNet UK News at &lt;a href="http://news.zdnet.co.uk/communications/networks/0,39020345,39183787,00.htm"&gt;http://news.zdnet.co.uk/communications/networks/0,39020345,39183787,00.htm&lt;/a&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=34498</link><pubDate>Thu, 13 Jan 2005 12:50:46 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=34498</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/34498/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>What about this seemingly important security issue with Media DRM:Hackers hijack Microsoft DRM - ZDNet UK News at http://news.zdnet.co.uk/communications/networks/0,39020345,39183787,00.htm</evnet:previewtext><dc:creator>nektar</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/34498/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>&lt;STRONG&gt;Hacker:&lt;BR&gt;&lt;BR&gt;A slang term for a computer enthusiast.&lt;/STRONG&gt; Among professional programmers, the term hacker implies an amateur or a programmer who lacks formal training. Depending on how it used, the term can be either complimentary or derogatory, although it is developing an increasingly derogatory connotation. The pejorative sense of hacker is becoming more prominent largely because the popular press has co-opted the term to refer to individuals who gain unauthorised access to computer systems for the purpose of stealing and corrupting data. Hackers, themselves, maintain that the proper term for such individuals is cracker.&lt;BR&gt;&lt;BR&gt;&lt;a href="http://http://www.google.com/search?hl=en&amp;amp;lr=&amp;amp;oi=defmore&amp;amp;q=define:Hacker"&gt;http://http://www.google.com/search?hl=en&amp;amp;lr=&amp;amp;oi=defmore&amp;amp;q=define:Hacker&lt;/a&gt;&lt;BR&gt;&lt;BR&gt;bleh...&lt;BR&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=34208</link><pubDate>Tue, 11 Jan 2005 19:25:56 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=34208</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/34208/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Hacker:A slang term for a computer enthusiast. Among professional programmers, the term hacker implies an amateur or a programmer who lacks formal training. Depending on how it used, the term can be either complimentary or derogatory, although it is developing an increasingly derogatory connotation.&amp;#8230;</evnet:previewtext><dc:creator>veganopolis</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/34208/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>Thanks Microsoft for the new anti-spyware beta 1.&lt;BR&gt;&lt;BR&gt;Nice tool :)</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=34005</link><pubDate>Mon, 10 Jan 2005 03:20:33 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=34005</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/34005/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Thanks Microsoft for the new anti-spyware beta 1.Nice tool :)</evnet:previewtext><dc:creator>chuawenching</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/34005/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>We all know they are in a catch 22. If they release too soon and there
is even a small problem the get slammed. If they do the necessary
regression testing, it takes time and they get slammed. Nice.&lt;br&gt;
&lt;br&gt;
Jorgie&lt;br&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=34001</link><pubDate>Mon, 10 Jan 2005 01:27:29 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=34001</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/34001/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>We all know they are in a catch 22. If they release too soon and there
is even a small problem the get slammed. If they do the necessary
regression testing, it takes time and they get slammed. Nice.

Jorgie</evnet:previewtext><dc:creator>Jorgie</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/34001/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>&lt;BLOCKQUOTE&gt;&lt;div&gt;KosherCoder wrote:&lt;/div&gt;&lt;div&gt;Extremely slow compared to what?&lt;br&gt;I saw one vulnerability on that eeye site that was several months "overdue", and they listed only one other outstanding.&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;br&gt;
Whoaa there wilba.&amp;nbsp; I was only asking a question, not launching an inquisition.&lt;br&gt;
&lt;br&gt;
Compared to time.&amp;nbsp; Those two you saw weren't the only two in the
past.&amp;nbsp; There used be be many that were over 260days from being
notified of the problem.&amp;nbsp; Wouldn't a malious hacker find out how
to exploit a system in 260+ days?&amp;nbsp; I think so.&lt;br&gt;
&lt;br&gt;
I don't know how long it would take EEYE to remove the advisory to
fixed status, once the patch came out, so maybe they're a little slow.&lt;br&gt;
&lt;br&gt;
&lt;BLOCKQUOTE&gt;&lt;div&gt;KosherCoder wrote:&lt;/div&gt;&lt;div&gt;Where
do they get off claiming that 30 days is a standard time to expect a
fix? They have no idea how long a fix could take.&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;br&gt;
Other software vendors have pulled it off in time.&amp;nbsp; Of course we
don't know if they were the same complexity.&amp;nbsp; When you release an
OS, when do you stop testing it for bugs?&amp;nbsp; Some exploits effect
all versions of MS OS's and MS has had plenty of time to look for bugs
in the older OS's.&lt;br&gt;
&lt;br&gt;
Don't get lazy because one OS might not be supported anymore.&amp;nbsp; If
Win2K was builtt/based on the NT kernal and that kernal has a fault,
should we look into that, even though that original kernal is not
supported anymore?&lt;br&gt;
&lt;br&gt;
You can think what you like, All I'm saying is don't fob of the
important issues that someone raises here.&amp;nbsp; Microsoft/Channel nine
has come to ask US, what we think, and that exactly what I'm doing!&lt;br&gt;
&lt;br&gt;
PS:&amp;nbsp; If software was perfect, I wouldn't have a job.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33903</link><pubDate>Sun, 09 Jan 2005 01:43:18 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33903</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/33903/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>KosherCoder wrote:Extremely slow compared to what?I saw one vulnerability on that eeye site that was several months "overdue", and they listed only one other outstanding.
Whoaa there wilba.&amp;nbsp; I was only asking a question, not launching an inquisition.

Compared to time.&amp;nbsp; Those two you&amp;#8230;</evnet:previewtext><dc:creator>dnrfan</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/33903/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>&lt;P&gt;Just send me your name and address via email at &lt;a href="http://channel9.msdn.commailto:rscoble@microsoft.com&gt;rscoble@microsoft.com&lt;/a&gt; and I'll get two out. Thanks!&lt;BR&gt;&lt;BR&gt;Hardware team is coming up soon!&lt;/P&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33902</link><pubDate>Sun, 09 Jan 2005 00:35:46 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33902</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/33902/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Just send me your name and address via email at rscoble@microsoft.com and I'll get two out. Thanks!Hardware team is coming up soon!</evnet:previewtext><dc:creator>scobleizer</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/33902/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>Thanks, Scoble. I didn't want to be greedy and ask for two for the same house, not that mine is here yet. I've sent 2 postcards and two emails and the 9guy still doesn't want to come to Philly. At first I thought maybe he had a bad experience here before and doesn't want to come, but now I'm beginning to suspect my mailman. ;)&lt;BR&gt;&lt;BR&gt;She's excited to get one and will send a card on Monday.&lt;BR&gt;&lt;BR&gt;Anyway, I meant to say earlier that this is the best kind of video - visiting an entire team, walking the halls, meeting everyone. Keep these coming!&lt;BR&gt;&lt;BR&gt;Request: The hardware teams. MS keyboard and mouse.&lt;BR&gt;Which makes me think, where did the wireless broadband team go? I hope they were absorbed into other departments.</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33901</link><pubDate>Sun, 09 Jan 2005 00:01:04 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33901</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/33901/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Thanks, Scoble. I didn't want to be greedy and ask for two for the same house, not that mine is here yet. I've sent 2 postcards and two emails and the 9guy still doesn't want to come to Philly. At first I thought maybe he had a bad experience here before and doesn't want to come, but now I'm&amp;#8230;</evnet:previewtext><dc:creator>KosherCoder</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/33901/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>Kosher, have her send me a postcard and I'll send her a 9Guy. &lt;BR&gt;&lt;BR&gt;Robert Scoble&lt;BR&gt;c/o Microsoft&lt;BR&gt;One Microsoft Way&lt;BR&gt;Redmond, WA 98052</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33894</link><pubDate>Sat, 08 Jan 2005 18:10:36 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33894</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/33894/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Kosher, have her send me a postcard and I'll send her a 9Guy. Robert Scoblec/o MicrosoftOne Microsoft WayRedmond, WA 98052</evnet:previewtext><dc:creator>scobleizer</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/33894/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>&lt;BLOCKQUOTE&gt;&lt;div&gt;dnrfan wrote:&lt;/div&gt;&lt;div&gt;&lt;BR&gt;Microsoft are extremely slow to release fixes/patches after being alerted to serious flaws.&amp;nbsp; Why is this?&lt;BR&gt;&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;BR&gt;&lt;BR&gt;Extremely slow compared to what?&lt;BR&gt;&lt;BR&gt;I saw one vulnerability on that eeye site that was several months "overdue", and they listed only one other outstanding.&lt;BR&gt;&lt;BR&gt;Where do they get off claiming that 30 days is a standard time to expect a fix? They have no idea how long a fix could take. The problem could be really deep, or require extensive regression testing to prevent other problems created by the one "fix".&lt;BR&gt;&lt;BR&gt;So, it comes back to the old question: Speed, Cost, Reliability. Pick two.&lt;BR&gt;&lt;BR&gt;MS has made tremendous strides in being responsive to security concerns. No code is perfect, and they're doing a good job of patching the holes, in a reasonable time.&lt;BR&gt;&lt;BR&gt;BTW - another great vid, guys. My 12 year old is starting to get into C9. Loves the vids and wishes she could have a 9guy. ;)&lt;BR&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33888</link><pubDate>Sat, 08 Jan 2005 14:55:12 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33888</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/33888/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>dnrfan wrote:Microsoft are extremely slow to release fixes/patches after being alerted to serious flaws.&amp;nbsp; Why is this?Extremely slow compared to what?I saw one vulnerability on that eeye site that was several months "overdue", and they listed only one other outstanding.Where do they get off&amp;#8230;</evnet:previewtext><dc:creator>KosherCoder</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/33888/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>&lt;BLOCKQUOTE&gt;&lt;div&gt;nektar wrote:&lt;/div&gt;&lt;div&gt;Any news on the recent and still unpatch Windows
holes? I heard that two out of the 3 also affect XP SP2.&lt;/div&gt;&lt;/BLOCKQUOTE&gt;&lt;br&gt;
Here are some from EEYE.&lt;br&gt;
&lt;br&gt;
&lt;a href="http://www.eeye.com/html/research/upcoming/index.html"&gt;http://www.eeye.com/html/research/upcoming/index.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
and past ones...&lt;br&gt;
&lt;br&gt;&lt;a href="http://www.eeye.com/html/research/advisories/index.html"&gt;
http://www.eeye.com/html/research/advisories/index.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Microsoft are extremely slow to release fixes/patches after being alerted to serious flaws.&amp;nbsp; Why is this?&lt;br&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33875</link><pubDate>Sat, 08 Jan 2005 10:53:17 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33875</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/33875/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>nektar wrote:Any news on the recent and still unpatch Windows
holes? I heard that two out of the 3 also affect XP SP2.
Here are some from EEYE.

http://www.eeye.com/html/research/upcoming/index.html

and past ones...

http://www.eeye.com/html/research/advisories/index.html

Microsoft are&amp;#8230;</evnet:previewtext><dc:creator>dnrfan</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/33875/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>Any news on the recent and still unpatch Windows holes? I heard that two out of the 3 also affect XP SP2.</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33871</link><pubDate>Sat, 08 Jan 2005 09:32:56 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33871</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/33871/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Any news on the recent and still unpatch Windows holes? I heard that two out of the 3 also affect XP SP2.</evnet:previewtext><dc:creator>nektar</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/33871/Trackback.aspx</trackback:ping></item><item><title>Re: Stephen Toulouse - Tour around Microsoft's Security Response Center</title><description>&lt;P&gt;Half-Life 2.&amp;nbsp; Nifty.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description><comments></comments><link>http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33864</link><pubDate>Sat, 08 Jan 2005 03:35:29 GMT</pubDate><guid isPermaLink="false">http://channel9.msdn.com/posts/TheChannel9Team/Stephen-Toulouse-Tour-around-Microsofts-Security-Response-Center/?CommentID=33864</guid><evnet:views>0</evnet:views><evnet:viewtrackingurl>http://channel9.msdn.com/33864/WebViewBug.aspx?EVT=0</evnet:viewtrackingurl><evnet:previewtext>Half-Life 2.&amp;nbsp; Nifty.
&amp;nbsp;</evnet:previewtext><dc:creator>BinaryBoy</dc:creator><slash:comments>0</slash:comments><wfw:commentRss></wfw:commentRss><trackback:ping>http://channel9.msdn.com/33864/Trackback.aspx</trackback:ping></item></channel></rss>