Welcome Guest. | Log In| Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10


Around The Web

CIO
Plans To Migrate LAPD To Google's Cloud Apps Dropped
Google and systems integrator Computer Science Corp. were unable to meet the stringent security requirements of the FBI's Criminal Justice Information Systems

HEALTHDATA MANAGEMENT
Laptop Stolen, 1,500 Patients Affected
In another failure of the human-factor of database security, a laptop containing two large databases of patient information was stolen from a clinic at the University of Mississippi

PCWORLD
Dazzlepod Offers Stratfor Customers A Way To Check On Anonymous Hack
Malaysia-based Web development company Dazzlepod has released an online tool designed to check email addresses against a database of compromised addresses so that customers of recently attacked Stratfor can find out if their information was lost

ITPROPORTAL
Rift Developer Trion Worlds Hacked
Trion Worlds, developer of the MMO Rift, has revealed that its entire database, including encrypted passwords, names, dates of birth, and fragmented credit-card data was taken

WASHINGTON EXAMINER
Virginia Database With Social Security Numbers Available To Public For 10 Years
State claims that the info has not been used in a criminal manner, since the database was never indexed on a search engine

GOVINFOSECURITY
Different Degrees Of Breach Response
The ruling of a federal appeals court that individuals affected by the 2007 Hannaford data breach can sue individually and seek compensation for nonfraud-related damages has left CIOs with a cold feeling in their stomachs

EWEEK
Stratfor Denies Anonymous Compromised Client List
Stratfor representatives have claimed that, instead of a privileged client list, Anonymous was successful only in getting the personal information of individuals who bought their publications in the past

NEW YORK TIMES TECHNOLOGY BLOG
Insurance Against Cyber Attacks Expected To Boom
Massive data breaches suffered by major corporations cost big bucks, even more so once the lawsuits start to fly

PCMAG
Android Trojan Sends SMS About Arab Spring Revolt
An unknown group or individual distributed a compromised version of Islamic prayer app AlSalah last week

BUSINESS INSURANCE
Data Breach Ruling May Signal Change In Approach
An appellate decision to allow a class action suit against Hannaford Bros. for its 2008 data breach proves to be a rare case where judges ruled in favor of consumers seeking more than just the standard credit monitoring make-up from companies that expose their information

HELP NET SECURITY
WineHQ Database Breached; Fedora Project Forces Password Change
Hackers were able to steal the complete login database for the open source Wine Application Database and Buzgzilla

NATIONAL POST
Pan Am Officials Deny Database Breach
Pan American Games officials say that the reports of a database containing personal information of journalists covering the event are not true, in spite of the fact that said journalists received warning emails from an outside source saying their information was breach that included some pieces of personal information

SEARCH SECURITY
Comparing Relational Database Security And NoSQL Security
The non-relational, BASE properties of a NoSQL database favored by sites such as Facebook and Amazon help these sites deal with extremely large data sets, scalability and availability, but these databases do not have the maturity or robustness of security of relational databases

NETWORK WORLD
Database Security: More Than DAM
A truly comprehensive database security program has many more moving parts than just monitoring -- organizations need to consider tools and processes that enable hardened configurations, separation of duties, privileged user controls and encryption among the important factors of necessary to create a successful program

INFORMATION WEEK
Oracle Releases NoSQL Database, Advances Big Data Plans
Oracle is jumping head-first into the fray for big data dominance with the announcement at Oracle Open World that in the first quarter of 2012 it will release a Big Data Appliance based on the company's launch of Oracle NoSQL during the annual show

V3.CO.UK
EU And US Put Security Defenses To The Test In Cyber Atlantic Exercise
The U.S. and EU engaged in a simulated exercise that tested how well Europe could withstand attacks on government database and power management systems

CTO EDGE
Beating The Breach: 10 Best Practices For Database Security And Compliance
A look at some of the most important best practices for database security, including discovery, monitoring the application layer in addition to the database, managing entitlements better and automating compliance processes

EWEEK
Mitsubishi Heavy Network Most Likely Compromised By Spear-Phishing Attack
The Japanese defense contractor found that the compromised systems were being controlled remotely, and speculation about the attack has named techniques such as SQL injection or leaked credentials as a possible foothold for the hackers

THE REGISTER
Three More Charged In Anonymous Hack Spree Probe
Three men face 15 years in prison each in connection with their involvement with Anonymous, LulzSec, and People's Liberation Front organizations. More specifically, the men were charged for attacks against Sony Pictures and the County of Santa Cruz earlier this year

TG DAILY
Hacked MySQL Dishes Out Malware To Visitors
Hackers used the BlackHole Java exploit pack to download and execute malicious code on the computers of Windows users visiting the website of the MySQL database management system


Best Of Web Archive:
Most Recent | 1| 2| 3| 4| 5| 6| 7| 8| 9| 10








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)