Application Security
News
- +
WabiSabiLabi may close 0day auction site 30/10/2008 13:17:00
WabiSabiLabi may close down its online marketplace for security vulnerabilities.WabiSabiLabi may shut down its online marketplace for security vulnerabilities, focusing instead on the line of OneShield unified threat management (UTM) appliances it developed with Italian defense company EuroTech. - +
IBM, Secret Service, others study identity/cybercrime issues 09/10/2008 10:09:00
Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking. - +
Companies own up to virtual security blind spot 02/10/2008 11:05:00
VMWorld attendees reveal vast majority of companies have little or no security in place for their virtual systems.The vast majority of companies have little or no security in place for their virtual systems. That is a scary statistic revealed in a survey of attendees at the recent VMWorld 2008 conference in Las Vegas. - +
Malware infects space station laptops 28/08/2008 08:15:00
Not the first time, says NASA; astronauts load up Norton AntiVirusMalware has managed to get off the planet and onto the International Space Station, NASA confirmed yesterday. And it's not the first time that a worm or virus has stowed away on a trip into orbit. - +
New attack against multiple encryption functions 22/08/2008 10:01:00
New mathematical attack works against a broad range cryptographic functions.Unless you're a dyed in the wool cryptographic geek you probably didn't know that there was a Crypto conference, or even a chain of worldwide crypto conferences that take place each year. Fortunately, for the most of us that aren't crypto geeks there are a handful of very highly skilled people who are; they can take the highly theoretical and complex mathematical proofs and arguments that make up most of modern cryptographic and cryptanalytic research and put it into plain language. - +
Kaminsky: Many ways to attack with DNS 07/08/2008 08:47:13
Dan Kaminsky says that SSL sites are also vulnerable to the DNS flaw he discovered.There were 6 a.m. calls from Finnish certificate authorities and also some pretty harsh words from his peers in the security community, even an accidentally leaked Black Hat presentation, but after managing the response to one of the most highly publicized Internet flaws in recent memory, Dan Kaminsky said Wednesday that he'd do it all over again. - +
Apple gets bruised in vulnerability report 05/08/2008 18:42:56
IE more secure than Firefox: X-Force reportApple has taken the place of Microsoft for disclosing more vulnerabilities than any other vendor, according to an IBM security report. - +
Exploit reveals the darker side of automatic updates 31/07/2008 10:58:00
A new exploit called Evilgrade can take advantage of automatic updaters to install malicious code on unsuspecting systemsA recent study of Web browser installations showed that far too few are up to date with the latest security patches. And browsers aren't alone; as my dear old mum can attest, it can be hard to keep up with OS and application patches when all you want to do is use your computer for work. It should come as no surprise that many PCs are vulnerable to security exploits that could otherwise be prevented. - +
DNS bug tattler not the first to guess flaw details 24/07/2008 08:33:50
Two weeks of silence helped, says researcher who found critical flawThe researcher whose speculation led to an early disclosure of information about a critical flaw in the Domain Name System (DNS), the Internet's traffic cop, wasn't the first to come close to the truth, said the security expert who found the bug and organized a massive patching effort. - +
Open-source software a security risk, study claims 22/07/2008 08:39:15
"Go into this with your eyes wide open," says Howard Schmidt, former White House cybersecurity czar.Open source software is a significant security risk for corporations that use it because in many cases, the open source community fails to adhere to minimal security best practices, according a study released Monday. - +
SQL attacks lobs onto pro tennis site 02/07/2008 11:52:19
Wimbledon perfect time for crook's criminal racket.Visitors to the Association of Tennis Professionals Web site have potentially been infected with spyware after apparent lax security allowed a malicious script to be injected across its pages. - +
Japanese military loses data again 02/07/2008 08:17:21
Japan's Self Defense Force lost sensitive data on joint US-Japan military exerciseJapan's Self Defense Force lost sensitive data pertaining to a joint US-Japan military exercise last year, the Ministry of Defense said Tuesday. - +
Microsoft, HP ship tools to protect Web sites from hackers 25/06/2008 09:55:21
Three tools help sites ward off growing SQL injection attacksMicrosoft and Hewlett-Packard on Tuesday unveiled free tools to help Web developers and site administrators defend against the rapidly growing number of SQL injection attacks that aim to hijack legitimate sites. - +
Firefox 3 'Download Day' cripples Mozilla site 18/06/2008 07:46:46
Enthusiasm around Firefox 3 sends EU, US Mozilla Web sites in a spinMozilla's big plan on Tuesday to set a world record for downloads with the Firefox 3 browser hit a snag when its Web site would not work properly. - +
Safari 'carpet bomb' attack code released 11/06/2008 08:50:52
Attack code that exploits the "Safari Carpet Bombing" attack has been posted.A hacker has posted attack code that exploits critical flaws in the Safari and Internet Explorer Web browsers.
Features
- +
Security and the generational divide 11/08/2008 08:55:38
Why 'stay off my network, you rotten kids!' isn't a good coping strategyThe generation gap. It's a term that has been used for decades to describe the differences between people in various age groups. Corporations are constantly considering what makes different generations tick when it comes to recruiting and retaining employees. But security experts say companies also need to examine age-based perspectives and habits when it comes to risk assessment and policies. - +
How secure is secure enough? 29/07/2008 07:44:00
Are your information security plans too big, too small or just right? Here are five steps to help you decide.If there is a Holy Grail in the information security industry, it surely is the answer to the question, "How secure is secure enough?" - +
When security staffers fail up 23/07/2008 09:40:52
Containing the painfully unqualified or essentially overwhelmedThink your security staffers are trustworthy? Competent? Knowledgeable? Ask a security professional for horror stories and you might think again. - +
How CAPTCHA got trashed 15/07/2008 09:02:49
The wiggly words are now most useful for malware authorsCAPTCHA used to be an easy and useful way for Web administrators to authenticate users. Now it's an easy and useful way for malware authors and spammers to do their dirty work. - +
Stupid user tricks: IT admin follies 17/06/2008 09:05:55
IT heroes toil away unsung in miserable conditions -- unsung, that is, until they make a colossally stupid mistakeFor those of us who make our living behind a keyboard in IT, it's hard to imagine a more time-tested vulnerability than the end-user. Armed with network access, these IT viruses wreak havoc nearly everywhere you look -- havoc borne of tech idiocy. - +
10 essential (and free!) security downloads for Windows 29/05/2008 09:42:31
Stay safe from prying eyes and bad guysTo use an Internet-connected computer is to be insecure and place your privacy in danger. Spyware, viruses, Trojans and assorted malware are everywhere on the Net, trying to hop onto your PC and cause damage. Snoopers want to get at your personal information for nefarious purposes, such as identity theft. - +
Five steps to successful and cost-effective penetration testing 28/05/2008 08:57:20
Spending your time and money wellWhether you hire outside consultants or do the testing yourself, here are some tips for making sure your time and money are well spent. - +
Five free pen-testing tools 28/05/2008 09:04:38
The best things in life are ...Security assessment and deep testing don't require a big budget. Some of most effective security tools are free, and are commonly used by professional consultants, private industry and government security practitioners. Here are a few to start with. - +
The darker side of Webmail 29/04/2008 10:02:55
Web-based e-mail may be exposing you to privacy and security problems you didn't expectWeb-based e-mail is booming. Services such as Gmail, Yahoo Mail and Hotmail are convenient, accessible and, best of all, free. Many of us have come to rely on them without giving it a second thought. - +
10 security threats to watch for 14/04/2008 10:17:22
Virtual servers, public Web sites and mobile devices are increasingly popular targetsThere are lots of ways business networks can be compromised, and more are developing all the time. They range from technology exploits to social engineering attacks, and all can compromise corporate data, reputation and the ability to conduct business effectively. - +
20 useful IT security Web sites 08/04/2008 09:50:41
How to foil hackers, protect users and prepare for the inevitable robot uprisingBookmarking these sites will help you protect your network, comply with government regulations and stay ahead of all the latest threats. - +
The top 10 security land mines 18/03/2008 10:45:07
The 10 most common security land mines that experts say you need to avoid.Many companies spend a small fortune and deploy a small army to secure themselves from the many security threats lurking these days. But all those efforts can come to naught when making any of these common mistakes. The results can range from embarrassing to devastating, but security experts say that all are easily avoidable. - +
Be prepared: ActiveX attacks will persist 20/02/2008 09:15:27
Flaws in the technology, poor development practice, and a large user base add up to big risksA recent string of high-profile ActiveX vulnerabilities caused the US Computer Emergency Readiness Team (US-CERT) to advise users to disable the ubiquitous Microsoft browser plug-in technology altogether. The vectors for these recent exploits include a third-party image uploading tool used on both the Facebook and MySpace social networking sites, and flaws found in Yahoo's Music Jukebox, Real Networks' RealPlayer, and Apple's QuickTime. - +
Apps accelerators tackle security 30/11/2007 11:01:12
Apps accelerators tackle securityCompanies that specialize in helping businesses speed delivery of their applications and Web content are increasingly involving themselves in IT security as the continued proliferation of systems-defense technologies has become a potential roadblock to the performance and quality of the services they already provide. - +
A Pothole on Wall Street 28/05/2007 09:29:34
A financial services CISO ponders a huge, unchecked vulnerability in how the industry processes market newsI'm a CISO who has worked in the US financial services industry both as a regulator and for a large services company. In this column I'm going to let you in on one of the biggest, dirtiest secrets in the industry: The companies that get the least amount of scrutiny from financial regulators actually present some of the greatest risks for systemic financial market manipulation and fraud. I'm talking about financial news and brokerage service companies.
Case Studies
- +
Uni fortifies Western Front with IDS 22/02/2008 20:11:00
Nurtured NAC keeps malware outThe University of Western Sydney (UWS) has today gone live with a managed Intrusion Detection System (IDS) for its 5000 users.
Interviews
- +
Bogus security promises and how to detect them 14/03/2008 10:13:00
Data leakage, smartphone malware, hotspot threats are discussed by security analyst Nick SelbyWhat is true enterprise security and how do you get it? Bogus promises by vendors are all too common. In this interview, outspoken security analyst Nick Selby humorously tackles the truth about data leakage products, smartphone protection, hotspot threats and the word "solution." Nick Selby leads The 451 Group's Enterprise Security Practice. Selby also serves as The 451 Group's Director of Research Operations and is on the faculty of the Institute for Applied Network Security.
Opinions
- +
Cutting Through the Spin of Recent Vulnerability Disclosures 13/10/2008 10:53:00
The FUD surrounding the ClickJacking and TCP/IP vulnerabilities has the world seemingly frozen in fear. But once you cut through the spin, the vulnerabilities aren't all that they were made out to be.There are a few highly publicised vulnerabilities at the moment which haven't completely been disclosed and which, it is claimed, could threaten the whole Internet as-we-know-it. Only, when the vulnerabilities are finally disclosed, it seems that the whole incident has been somewhat Chicken Little. - +
Are we about to witness a real OS X virus? 24/07/2008 14:27:59
Intego might have stumbled across an OS X specific virus being offered for auction that targets a previously unknown ZIP archive vulnerability.Mac antivirus maker, Intego, have published an interesting alert about a potential OS X virus that an enterprising individual is trying to sell through auction. With absolutely no technical information to go on, the antivirus maker is treating the announcement with caution. - +
Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21
BackTrack is the quickest way to get access to hundreds of (legal) hacking toolsVersion 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools. - +
A resurgent Denial of Service threat emerges 11/06/2008 19:12:24
Something new might be emerging from the underground.A less known part of the recent ARP attack against H D Moore's MetaSploit site was an attempted Denial of Service attack that coincided with the successful ARP attack. - +
Zero-second exploits 06/05/2008 12:04:48
The number of days between a vendor patch being released and the malware exploit being announced has shrunkMicrosoft SQL server hasn't had a public vulnerability announcement since 2004. The SQL Slammer worm struck in 2005, but the hole the worm exploited had been patched six months before. The holes that MS-Blaster and Code Red worm attacked had been patched, too. But back just a few years ago, no one really cared about patching really. We just didn't patch. - +
Attackers are thinking outside the box 17/04/2008 11:19:36
How to predict what the next attack will look likeIn the adversarial environment of information security, new types of attacks emerge constantly. Just recently, a very highly targeted phishing attack against CEOs used the pretext of a federal grand jury subpoena to lure executives to a site hosting malware. Let's face it: Most of the innovation in this industry is on the other side, the "dark" side. We are unfortunately forced to keep reacting to new ingenious attacks every few years. - +
What spooks Microsoft's chief security advisor 27/03/2008 11:12:24
Application exploits, virtualization security are big concernsMicrosoft's US general manager/chief security advisor for its National Security Team thinks like a true security professional: In every bit of good news, Bret Arsenault wonders what bad news could be lurking behind it. - +
Code name: Secure software 13/03/2006 14:34:47
Code writers now occupy the front line in the battleground of software security as the defense shifts from perimeter protection to prevention function that's built in during the application development phase.
Additional Resources
CSO Online Member Login
EXCOM scores back-to-back award trifecta 2008-12-01 10:46:00+11
“Just Graphics” isn’t enough any more 2008-11-28 15:02:00+11
Why Sealy’s management sleep soundly at nights... 2008-11-28 11:18:00+11
Capture and Digitize Your Treasure Moments ~ Compro VideoMate C200 USB A/V Capture Stick 2008-11-26 12:37:00+11
Net 24 slashes backup window by two-thirds 2008-11-26 10:28:00+11
Sponsored Links
PC World
Buying Guides
Latest Products
Good Gear Guide
Buying Guides
Computerworld
ARN


