Welcome Guest. | Log In| Register | Membership Benefits


SMB Security Tech Center

ATMs At Risk, Researcher Warns At Black Hat
Barnaby Jack demonstrates remote and local exploits that work on popular bank machines

Texas Firm Says It Holds A Patent On Spam Filtering
Lanier Law Firm files suit against 36 companies, including top security tool vendors

Tech Insight: How To Cut Security Costs Without A Lot Of Pain
Everything from trading costly training for local conferences to outsourcing some security tasks can save money --- but first carefully consider the options

MORE SMB SECURITY TECH CENTER STORIES



Vulnerability Management Tech Center

Malware Authors Leave Their Fingerprints On Their Work, Black Hat Researcher Says
Careful study of malware can help experts recognize its source and protect against it

Microsoft Launches 'Coordinated' Vulnerability Disclosure Program
Microsoft abandons controversial 'responsible disclosure' term, supporting public disclosure of unpatched bug details when attacks hit

Researcher Pinpoints Widespread Common Flaw Among VxWorks Devices
Diagnostics service feature in VxWorks OS kept activated in some VoIP, DSL, SCADA systems leaves them open to attack

MORE VULNERABILTY MANAGEMENT TECH CENTER STORIES



Database Security Tech Center

Researcher Exposes Massive Automated Check Counterfeiting Operation Out of Russia
'Big Boss' operation used VPN-tunneling botnet, Zeus Trojan, database-hacking, and money mules to help print and cash phony checks

Sourcefire Rolls Out Open-Source 'Razorback'
New platform aimed at better detecting and defending against advanced, targeted attacks

One Breach = $1 Million To $53 Million In Damages Per Year, Report Says
New Ponemon report studies real attack cases and their financial fallout; new Digital Forensics Association study tallies five-year public breach data

MORE DATABASE SECURITY TECH CENTER STORIES



Security Services Tech Center

Internet Infrastructure Reaches Long-Awaited Security Milestone
The DNS root is now officially signed with security protocol DNSSEC -- next comes development, penetration-testing of the technology

Enterprise Security Market To Grow Nearly 14 Percent In 2010, Study Says
Outlook for 2011 also looks bullish, according to industry research firm Canalys

FTC Slaps Twitter Down Hard For Lax Security, Privacy Violations
Social networking site's claims will be scrutinized for 20 years; security program will be audited for 10 years

MORE SECURITY SERVICES TECH CENTER STORIES



Insider Threat Tech Center

'App Genome Project' Exposes Potential Smartphone Risks
Researchers from Lookout will present their findings thus far in study of freebie Android, iPhone apps

Report: British Ministry Of Defense Lost More Than 1,000 Storage Devices In Two Years
Many of the devices were unencrypted; other agencies also at risk

RSA Reports Address Rise In Enterprise Adoption Of Consumer Technologies
Survey of IT and security pros shows most organizations giving end users more leeway and influence in social networking, gadgets

MORE INSIDER THREAT TECH CENTER STORIES









Free Vulnerability Management Trial
Qualys is offering a free 14-day trial of its vulnerability management solution, which helps enterprises identify, fix, and report on network security threats.

Free Security Tools from Sophos
Scan for security risks, threats, rootkits and unauthorized applications.

Info-Tech Research Group
A specialist in small and medium-sized businesses, Info-Tech offers a different perspective than research houses that focus on the Fortune 1000.





            


                                                   
Blogs

Evil Bytes
BY John H. Sawyer
Conquering Large Web Apps With Solid Methodology
July 21, 2010
02:16 PM -- This is one of those weeks where I'm trying to wrap up as much as possible before I'm out of the office for Black Hat, BSides, and Defcon. One of those things on my list is a Web application assessment for a client that's a monstrous, open-source beast with subapplications bolted on from all over the place and tons of places for vulnerabilities to ...

SophosLabs Insights
BY Graham Cluley
Block Windows Shortcut Exploit Without Losing Your Shortcut Icons
July 26, 2010
11:31 AM -- Here at SophosLabs we've been working out the best way to protect computer users against the zero-day flaw that has hit all versions of Windows.

Hacked Off
BY Gadi Evron
Killed By Code: The FDA And Implantable Devices Security
July 26, 2010
06:19 AM -- A new report from the Software Freedom Law Center deals with the security implications of bionic medical devices being implanted into the human body.

Security Views
BY Jennifer Jabbusch
Four Must-Have SMB Security Tools
July 28, 2010
10:12 PM -- Regardless of their size, many SMBs still need to meet strict compliance regulations, such as PCI and HIPAA. In addition to any special requirements, there are a few security technologies every small business should have in place. Here are my four SMB security must-haves.

Dark Dominion
BY Kelly Jackson Higgins
Security BSides Grows, But Not Too Much
July 23, 2010
05:10 PM -- The security "unconference" is back in Vegas, and this time the setting is a gated private resort with multiple swimming pools and a sand beach, and the number of attendees signed up so far for the free -- yes, free -- event has doubled. But that doesn't mean Security BSides will lose the intimate vibe that its organizers envisioned and encouraged ...

CS Island
BY Robert Richardson
There's A Recipe For That
June 15, 2010
11:09 AM -- Back in the dark ages when I was a programmer, I became horribly fascinated with a tool called make. It was a tool for dealing with the complexities of, well, making finished executable code.

MORE BLOGS



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)


Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:afpl ghostscript, ghostscript fonts, gpl ghostscript
Published:2010-07-22
Severity:High
Description:Buffer overflow in gs/psi/iscan.c in Ghostscript 8.64 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document containing a long name.
Vulnerability:small pirate
Published:2010-07-22
Severity:High
Description:Multiple SQL injection vulnerabilities in Small Pirate (SPirate) 2.1 allow remote attackers to execute arbitrary SQL commands via (1) the id parameter to the default URI in an rss .xml action, or the id parameter to (2) pag1.php, (3) pag1-guest.php, (4) rss-comment_post.php (aka rss-coment_post.php), or (5) rss-pic-comment.php.
Vulnerability:small pirate
Published:2010-07-22
Severity:Medium
Description:Cross-site scripting (XSS) vulnerability in Small Pirate (SPirate) 2.1 allows remote attackers to inject arbitrary web script or HTML via an onmouseover action in an img BBCode tag within a url BBCode tag.
Vulnerability:com jvideo
Published:2010-07-22
Severity:High
Description:SQL injection vulnerability in the JVideo! (com_jvideo) component 0.3.11c Beta and 0.3.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the user_id parameter in a user action to index.php.
Vulnerability:adpeeps
Published:2010-07-22
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdPeeps 8.5d1 allow remote attackers to inject arbitrary web script or HTML via the (1) uid parameter, (2) uid parameter in a login_lookup action, (3) uid parameter in an adminlogin action, (4) campaignid parameter in a createcampaign action, (5) type parameter in a view_account_stats action, (6) period parameter in a view_account_stats action, (7) uid parameter in a view_adrates action, (8) accname parameter in an account_confirmation action, (9) loginpass parameter in an account_confirmation action, (10) e9 parameter in a setup_account action, (11) from parameter in an email_advertisers action, (12) message parameter in an email_advertisers action, (13) idno parameter in an edit_ad_package action, (14) Advertiser Name field, (15) First Name field, (16) Last Name field, (17) Address field, (18) Phone Number field, (19) Password Hint field, or (20) URL field; and (21) allow remote authenticated users to inject arbitrary web script or HTML via an unspecified form associated with a view_adrates action.