Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10


Around The Web

DATABASE JOURNAL
Mapping SQL Server Features to Oracle Database
Logins, server roles, and credentials are key elements in mapping SQL Server features back into Oracle databases

CHANNELWEB UK
Guardium Staves Off FUD Missiles
Security vendor denies ??claims that it will be more focused on integrating with IBM database platforms

ESECURITY PLANET
HSBC Confirms Massive Database Security Breach
HSBC says a data theft it first uncovered last year impacted more than 24,000 people, or 15 percent of its total clients, a far cry from the 10 customers it originally said were affected

THE EPOCH TIMES
Privacy Fears Over U.K. Medical Database
Medical records of over 1 million Britons were uploaded to a controversial health database without their knowledge, British Medical Association (BMA) warned

PAKISTAN DAILY TIMES
No Foreign Agency, Consulate Has Access To Database: NADRA
The National Database and Registration Authority (NADRA) in Pakistan says database is highly secure and even local and provincial governments can't access it

SC MAGAZINE UK
LogLogic DSM
Database security is often left out of the ??data protection compliance equation because to monitor database activity, auditing must be enabled and many administrators will not do this due to concerns about performance

ZDNET
Oracle Releases Out-Of-Band Patch For Server Hole
Oracle has issued an update that patchesr a server flaw that can be exploited over a network without the use of a username

EWEEK
IBM Defends DB2 Against Ellison's 'Ignorant' Remarks
Bernie Spang, IBM's director of product strategy, criticizes some of Oracle CEO Larry Ellison's remarks about IBM's DB2 database software

FINEXTRA
Finance Firms To Spend Bilions On Risk Management: Survey
The top 100 financial institutions will spend over $100 billion a year implementing risk governance frameworks by 2012, according to research from Deloitte

THE REGISTER
Google Doppelganger Casts Riddle Over Interwebs
Google in October silently launched a new net domain that is now the 44th most visited domain on the Internet -- Google says it's for identifying servers on its network

PENN STATE LIVE
Malware Continues To Be A Challenge To Computer Security
As identity theft continues to be a serious problem nationwide, Penn State has experienced computer breaches due to malware as well

GAINESVILLE.COM
AvMed: Data Of 208,000 At Risk After Gainesville Theft
Two company laptops were stolen from AvMed Health Plans' corporate offices in Gainesville, potentially compromising the personal information of more than 200,000 current and former subscribers, as well as their dependents

BANK INFOSECURITY
Payroll Processor Reveals Data Breach
Ceridian says 27,000 of its customers are at risk after an attacker breached the ??company's payroll system last December

H ONLINE
Vulnerability In Samba Provides Access To Files
A flaw in the free Samba file and printer server can be exploited to attain access to files outside of predefined paths, and attackers can gain access to the system's root directory

TMCNET
PSU Hit In Cyber Attack
The Social Security numbers of about 30,000 people became vulnerable after malicious software attacked Penn State University computers before the holidays

PC WORLD
Oracle Critical Patch Update Includes 24 Fixes
Oracle on Tuesday will release an update that includes 24 security fixes for its database, application server and other products

SQL MAGAZINE
Staying Abreast of SQL Server Database Trends in 2010
Keep on top of increasing movement toward cloud services, stepped up database virtualization, and growth in hacking tools that allow swift random attacks on data

TECH TARGET
Preventing Internal Oracle Database Security Threats
Oracle shops whould rely on strict background checks -- both criminal and credit -- to ensure that they hire honest database administrators

CTO EDGE
Encryption: The Last Line of Database Defense
Encryption features in SQL Server 2008 are powerful, so consider using them as part of your overall security strategy

EWEEK
Four Database Security Tips for Dealing with SQL Injections
Fix the code, educate developers, scan code, and ensure proper configuration management


Best Of Web Archive:
Most Recent | 1| 2| 3| 4| 5| 6| 7| 8| 9| 10








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)