Welcome Guest. | Log In | Register | Membership Benefits
Best Of Web Archive:
Most Recent | 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10


Around The Web

NEWS.COM.AU
One In Five Australians Victim Of Credit Card Fraud, Hackers
Over 1.5 million credit cards have been stolen and 1.2 million people's bank accounts have been compromised in Australia

IT STOCK ANALYST
Oracle Releases New Version of Secure Backup Platform
Oracle has released Oracle Secure Backup 10.3, a centralized tape backup management solution, which provides virtual tape library support through server-less tape duplication

WIRED
FBI's Data-Mining System Sifts Airline, Hotel, Car-Rental Records
A data-mining system built by the FBI ??for hunting terrorists is being used in hacker and domestic criminal investigations

EWEEK
Database Security Truths: Orgs Still Struggling to Herd Info
The volume of databases and access controls companies must track for compliance reasons makes it hard for them to effectively manage them

CNET
Ellison: Oracle Won't Spin Off MySQL
Oracle chief says company will retain MySQL in Sun merger, and that MySQL doesn't compete with Oracle's database

THE GOV MONITOR
Database Security Questioned In The UK
A large UK government database of real estate properties that includes over 800k digital photos of homes and property details such as roof balconies and parking spaces raises both physical and cybersecurity concerns

THE REGISTER
Database Containing 1.8m UK Postcode Locations Leaks Online
WikiLeaks claims to be hosting a database of over 1.8 million UK postal codes and geographic data

MSNBC
A New Tool To Fight Identity Theft
The ID Score database helps banks, retailers, government agencies, and healthcare providers prevent fraud

SOFTPEDIA
The Internet Archive Leaks Member Data
A hacker has disclosed a SQL injection vulnerability in the Internet Archive project Website that exposes sensitive information about registered members

FEDERAL COMPUTER WEEK
Authentication Said Key To Cybersecurity
A top Department of Homeland Security official said the ability to authenticate computer users, devices, and processes is a major part of the department's vision for improved computer security

REUTERS
Hacking Oracle's Databases Will Soon Get Easier
New exploit on Metasploit will be unveiled next week at Black Hat conference

AUSTRALIAN IT
HSBC Fined $6 Million In Britain For Data Loss
Europe's biggest bank censured for "careless" handling of data on tens of thousands of customers

GLOBAL SECURITY MAGAZINE
New Vulnerabilities May Affect Oracle Databases
Patch expected this month

BLOOMBERG
Canada Emails Show Broader Suspicion Of Data Leaks
Economic statistics somehow being disseminated before they are officially released, officials say

THE INDUSTRY STANDARD
Oracle's Security Solution For Banks
Controls help limit database administrators' access to sensitive information

HELP NET SECURITY
Take Action Against The Increase In SQL Injection Attacks
Network Box offers advice to protect organizations from rising tide of SQL injection

V3.CO.UK
Industry Group Tackles Software Supply Chain
Safecode leads effort to prevent software from being compromised during sourcing, distribution

SOPHOS.COM
Security Threat Report Looks At Dangers Ahead
SQL injection attacks continue to grow in popularity, researchers say

eWEEK
How To Secure Sensitive Data Before A Layoff Occurs
Up-to-date auditing of data is a must, experts say

COMPUTERWORLD NEW ZEALAND
New Zealand Privacy Administrator Calls For DNA Database Oversight
Agency will look to step up security following revelation of data breach


Best Of Web Archive:
Most Recent | 1| 2| 3| 4| 5| 6| 7| 8| 9| 10








Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)