Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10


Around The Web

SEARCH SECURITY
Basic Database Security: Step by Step
Forget fancy encryption techniques, event correlation or forensic analysis -- institute a clear, actionable and pragmatic approach to database security

IT PRO
Review of New DB Security Solution
LogLogic's new database security solution with vPatches and a look at whether it can protect your databases without impacting SLAs

MARKET SCAN
Staff Could Pose Risk To Data Security
Marketing firms' employees could pose accidental or malicious threats to database security

BANGOR DAILY NEWS
Court To Decide What Time, Trouble Are Worth In Hannaford Breach
It's up to the Maine Supreme Judicial Court to decide whether Hannaford Bros. customers will recover damages for the time and trouble it took them to straighten out their bank or credit card accounts

USA TODAY
IBM Puts Focus On Database Hackers With Guardium Acquisition
IBM's purchase of Guardium is the latest sign that attacks of corporate database are likely to continue to escalate

BUSINESS WEEK
EU to Give U.S. Bank Transaction Data
The European Parliament's Justice and Home Affairs Council is set to decide on a draft agreement between the EU and U.S. under the so-called "SWIFT agreement" that provides the U.S. ongoing access to European banking data for anti-terrorism investigations

MX LOGIC BLOG
FreeBSD Hit With Local Root Vulnerability, Patch Rushed Into Service
A major flaw affecting the local root system of the open-source operating system FreeBSD would give an attacker full administrative rights

INFOWORLD
If Oracle And Sun Merge, Customer Negotiations Could Get Tricky
If Oracle's acquisition of Sun goes through, Oracle would become the most powerful open source vendor in the market today, according to Gartner

NETWORK WORLD
The Fruit of the Poisoned Tree
Looking at the debate over whether to hire criminal hackers as security experts

PHILLY.COM
Hospital Laptop Stolen, Data May Be Breached
A laptop stolen from an employee of the Children's Hospital of Philadelphia contained Social Security numbers and other personal information on 943 people

HOMELAND STUPIDITY
FBI Database Error Results In Firing
An error in a national criminal record database cost a senior accountant at the Social Security Administration her job

CNET
Amazon's In-Cloud Database Gets MySQL Option
Amazon.com unveiled a new option called Amazon RDS for companies that want to store information in a database in the cloud

HINDU BUSINESS ONLINE
Wrong Technology Can Mean Poor ROI
Sybase exec talks gaps in database security and information management

GOVINFOSECURITY
Interior Fails Big Time in FISMA Audit
The Interior Department inspector general says the department once again has failed to comply with the Federal Information Security Management Act (FISMA) in fiscal 2009

DEFENSE SYSTEMS
DOD Approves New Credentials For Security Professionals
The Defense Department has approved new credentials for information security professionals, and will result in over 100,000 DoD personnel obtaining these the new certifications

COMPUTER WEEKLY
Guardian Jobs Database Attack Demonstrates Difficulties Of Database Security
The hack of The Guardian's jobs database demonstrates the difficulty in safeguarding any personal data

INFOWORLD
Rise In Online Attacks Poses Challenge For African Banks
Most African banks have legacy systems, which poses a security challenge in online services

COMPUTERWORLD
CDC Adopts New, Near Real-Time Flu Tracking System
The Center for Disease Control is now tracking data on 14 million patients from physician practices and hospitals that is stored on a relational database hosted by GE Healthcare

SC MAGAZINE
Judge Denies Lawsuit Deal Over TD Ameritrade Breach
A U.S. District Court judge denied a proposed lawsuit settlement over the 2007 hack of TD Ameritrade's database that exposed personal information of 6.3 million customers

VIRTUALIZATION JOURNAL
Will You Comply Or Just Check The Box?
PCI-DSS affects everyone and some smaller retailers are less PCI-savvy and compliant than others


Best Of Web Archive:
Most Recent | 1| 2| 3| 4| 5| 6| 7| 8| 9| 10








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)