Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10


Around The Web

EXECUTIVEGOV
Federal Health Benefits Database a Security Risk?
Some within the healthcare industry wonder if a new database rolled out by the feds will unduly risk citizen data.

GOVINFOSECURITY
AG Sues WellPoint Over Breach
The attorney general of Indiana is suing healthcare firm WellPoint for $300,000 for failing 32,000 citizens too late about a critical database breach.

SOFTPEDIA
Personal Info of Louisiana Certified First Responders Possibly Compromised
The Louisiana Department of Health and Hospitals (DHH) announced a breach that affects 56,000 emergency medical technicians within the state.

THE PHILADELPHIA INQUIRER
Medical-Data Breach Said To Be Major
Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan was responsible for losing a flash drive containing a database with sensitive information of 280,000 people.

DIGITAL JOURNAL
Thousands Of Passwords Exposed In Ontario School Board Hack
A 15-year-old student used a SQL injection attack to attack a Thames Valley District School Board database containing passwords of 27,000 students.

CIO MAGAZINE
Data Base Security On A Cloud Computing Environment And LANWAN Security Of Database On A Cloud Computing Environment
A practitioner offers advice on securiting databases in a cloud environment.

IOUG
Oracle User Group Surveys Users On Security Patching
The Independent Oracle Users Group is conducting its second security assurance survey to get a feel for database security patching practices in the enterprise--the last survey results were released in February 2009

NZ HERALD NEWS
Customer Database Breach Hellishly Simple
A New Zealand-based pizza chain exposed the customer details of UK politicians, comedians, and hundreds of thousands of other regular folk in its database through poor security on its e-commerce site

STOREFRONTBACKTALK
Too Much Encrypt = Cyberthief Gift
Security experts explain how encrypting too much of a customer database containing credit card information can actually expose the entire data store to a relatively easy crack by hackers

PATRIOT LEDGER
Mishaps Expose Weakness In Health Record System
The recent boom in healthcare database breaches this year are exposing weaknesses in the chain of custody for sensitive patient records

COMPUTERWORLD
Verizon: Data Breaches Often Caused By Configuration Errors
A recent security report found that the majority of big data breaches over the past years were caused by configuration errors in IT infrastructure, including databases

ARS TECHNICA
Newly Detected SQL Injection Attack Snags Apple In Wide Net
A new flare up of mass SQL injection attacks has infected over a million websites with malicious links and iframes. Among the most high-profile victims is Apple

THE PLAIN DEALER
Anthem Security Breach, Payday Fraud May Be Linked
A massive database breach that exposed 640,000 consumer records at Anthem Blue Cross Blue Shield disclosed this summer is showing real-world ramification for those affected

CIO MAGAZINE
Five Advantages of Unified Information Access (UIA)
Unified Information Access can help enterprises better secure the unstructured sensitive data that lies outside the boundaries of the typical database

TECHNEWS WORLD
Porn's Lessons on the Plentiful Possibilities of Perl and PHP
Sys admins overseeing adult websites know about scripting and scalability -- keep your database clean, embrace open source for as many commodity components as possible, and only use the latest technology if it adds actual value to your site

BUSINESSWEEK
Seven Reasons To Care About SQL Server 2008 R2
SQL Server 2008 R2 is worth a closer look -- StreamInsight and Master Data Services should gain traction right away, while others such as SQL Server SysPrep and DACPAC need some further baking

WIVB
Database To Keep Child Porn Off Sites
Attorney General Andrew M. Cuomo announced database that will be used by social networking sites to keep child pornography off the Internet

PENN LIVE
Bills Target Builders' 'Illegal Work Force'
American Civil Liberties Union of Pennsylvania, others, question the accuracy and security of the data contained in the E-Verify system

CULT OF MAC
Enhance iPhone and iPad Security with SplashID
SplashID for iPhone is a lightweight database application that securely stores bank account numbers, credit card numbers, e-mail accounts, frequent flier accounts, identification, insurance, memberships, software serial numbers, Web logins, and passwords

BUSINESSWEEK
Businesses Confront the Cloud Security Threat
As they embrace the cloud, companies remain skittish about entrusting data and computing tasks to outside vendors


Best Of Web Archive:
Most Recent | 1| 2| 3| 4| 5| 6| 7| 8| 9| 10








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)