Welcome Guest. | Log In| Register | Membership Benefits

Editorial Contacts

Editors

General email address for all editorial staff: editors@darkreading.com

Tim Wilson
Tim Wilson
Site Editor (Oakton, Va.)
One of Dark Reading's founding editors, Tim has spent more than 24 years as an IT journalist, industry analyst, therapist, and bartender. Tim has previously served as the business editor for Network Computing, chief of reporters at InternetWeek, and executive editor at DataTrends Publications, where he authored at least one book stating that TCP/IP had no future.
Wilson@DarkReading.com
703-262-0680

Kelly Jackson Higgins
Kelly Jackson Higgins
Senior Editor (Charlottesville, Va.)
Kelly has been a writer and editor in the IT industry for 21 years. She was one of the first reporters to cover an emerging protocol called TCP/IP and earned mocking derision from her editors for telling them it might have real future in networking. More recently, Kelly was a contributing editor for Network Computing and Secure Enterprise magazines.
Higgins@DarkReading.com
434-960-9899

Bloggers and Columnists

Rob Enderle
Rob Enderle is president and principal analyst of the Enderle Group, a technology advisory firm. Previously, he was a senior research fellow for Forrester Research and Giga Information Group and senior analyst for Dataquest. He also worked at IBM, where he managed projects in security, finance, internal audits, competitive analysis, marketing, M&A, and planning. Enderle sits on the advisory councils for Lenovo, AMD, HP, Dell, Philips, Toshiba, and the Trusted Computing Group.

 
Robert Graham learned hacking as a toddler from his grandfather, a WW-II codebreaker. His first IDS was written more than 10 years ago designed to catch Morris-worm copycats. He is the author of several pending patents in the IDS field. He is the author of well-regarded security-related documents http://www.robertgraham.com/pubs and is a frequent speaker at conferences. IRL, he is the co-founder, CTO, and chief-architect at Network ICE (now owned by ISS).

 
David Maynor is a research engineer with the ISS Xforce R&D team, where his primary responsibilities include reverse engineering high risk applications, researching new evasion techniques for security tools, and researching new threats before they become widespread. Before ISS, Maynor spent the 3 years at Georgia Institute of Technology (GaTech), with the last two years as a part of the information security group as an application developer to help make the sheer size and magnitude of security incidents on campus manageable. Before that, Maynor contracted with a variety of different companies in a widespread of industries ranging from digital TV development to protection of top 25 websites to security consulting and penetration testing to online banking and ISPs.

Rich Mogull
Rich Mogull is founder and principle analyst at Securosis, LLC. Prior to founding Securosis, Rich spent seven years as one of the leading security analysts with Gartner, wher he advised thousands of clients. He is one of the world's premier authorities on data security technologies and has covered issues ranging from vulnerabilities and threats, to risk management frameworks, to major application security.

Sara Peters
Sara Peters joined the Computer Security Institute (CSI) in 2005, taking on a security beat that includes both policy issues (like Web vulnerability disclosure legislation and the Payment Card Industry Data Security Standard) and technological issues (like Windows Vista security and third-party patching). Prior to her work in information security, she served as associate director of communications at Princeton University's School of Engineering and Applied Science, writing and editing their quarterly magazine. She began her reporting career in a small newspaper chain after graduating from Rutgers University with a B.A. degree in journalism.

Robert Richardson
Robert Richardson has served as Director at CSI since 2003, having worked IT in various capacities for twenty years. He's given keynote presentations on three continents, often speaking about the CSI Computer Crime and Security Survey, an undertaking he directs each year. Based outside Philadelphia, he occasionally serves as an adjunct teacher of computer science at Swarthmore College. Prior to CSI, Richardson served as Senior Editor of CMP's Communications Convergence magazine for two years, where his beats included telecom security, wireless, Internet messaging, and next-generation phone systems.

John H. Sawyer
John H. Sawyer is a Senior Security Engineer on the IT Security Team at the University of Florida. When John's not fighting flaming, malware-infested machines or performing autopsies on blitzed boxes, he can usually be found hanging with his family, bouncing a baby on one knee and balancing a laptop on the other.

Nathan Spande
Nathan Spande is an independent security consultant who has implemented security in medical systems during the dotcom boom and bust and suffered through federal government security implementations.

Steve Stasiukonis is vice president and founder of Secure Network Technologies Inc. His background in information security began as co-founder of Network Audit Systems, where he helped develop and launch a network security assessment tool called NetAuditor. In 1999, he sold the company to Armor Holdings and took over marketing Technology Risk Management, a suite of information security products and services used in financial, manufacturing and healthcare industries.

Corporate Headquarters:
Dark Reading, a TechWeb publication
600 Community Drive
Manhasset, NY 11030
516-562-5000 (phone)






Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:blazeds, coldfusion, flex data services, lifecycle
Published:2010-02-15
Severity:Medium
Description:Unspecified vulnerability in BlazeDS 3.2 and earlier, as used in LiveCycle 8.0.1, 8.2.1, and 9.0, LiveCycle Data Services 2.5.1, 2.6.1, and 3.0, Flex Data Services 2.0.1, and ColdFusion 7.0.2, 8.0, 8.0.1, and 9.0, allows remote attackers to obtain sensitive information via vectors that are associated with a request, and related to injected tags and external entity references in XML documents.
Vulnerability:odyssey access client
Published:2010-02-15
Severity:High
Description:Stack-based buffer overflow in dsInstallerService.dll in the Juniper Installer Service, as used in Juniper Odyssey Access Client 4.72.11421.0 and other products, allows remote attackers to execute arbitrary code via a long string in a malformed DSSETUPSERVICE_CMD_UNINSTALL command to the NeoterisSetupService named pipe.
Vulnerability:acrobat, acrobat reader, adobe air, flash player
Published:2010-02-15
Severity:High
Description:Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.
Vulnerability:adobe air, flash player
Published:2010-02-15
Severity:Medium
Description:Adobe Flash Player before 10.0.45.2 and Adobe AIR before 1.5.3.9130 allow remote attackers to cause a denial of service (application crash) via a modified SWF file.
Vulnerability:dokuwiki
Published:2010-02-15
Severity:Medium
Description:Directory traversal vulnerability in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12-25b allows remote attackers to list the contents of arbitrary directories via a .. (dot dot) in the ns parameter.


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)