Welcome Guest. | Log In | Register | Membership Benefits

All Deep Inspection Stories

Tech Insight: Building A SOC, From Outsourcing To DIY


January 22, 2012
Building blocks for developing the most effective security operations center

Tech Insight: What To Do When Your Business Partner Is Breached


January 06, 2012
Vendors and contractors play an important role in your business. But what happens when a partner’s systems are compromised? Here are a few tips

Tech Insight: Managing Mobile Mayhem


December 16, 2011
Enterprise options for encrypting and wiping mobile devices and portable storage

APT Or Not APT? Discovering Who Is Attacking The Network


November 21, 2011
Corporate networks face a variety of attacks every day. Yet, pinpointing the most serious attacks are no easy matter

Six Deadly Security Blunders Businesses Make


October 26, 2011
It's the subtle little things that can lead to big security breaches

Physical, Logical Security Worlds Continue Slow Convergence


September 26, 2011
Organizations responsible for building security and organizations responsible for computer security begin to converge inside many enterprises

Disclosure In The APT Age


September 07, 2011
Yet another widespread advanced persistent threat-type campaign has hit the federal government

Can Data Breaches Kill?


August 12, 2011
When data is sensitive enough, its exposure has the potential to be fatal.

Tech Insight: How To Respond To A Denial-Of-Service Attack


July 21, 2011
Your organization can't prevent an overwhelming denial of service attack, but you can minimize its impact. Here's how.

Enemy At The Loading Dock: Defending Your Enterprise From Threats In The Supply Chain


July 15, 2011
The suppliers, contractors, and other outside parties with which you do business can create a serious security risk. Here's how to keep this threat in check

Tech Insight: Tips For Implementing Two-Factor Authentication


June 17, 2011
How and where two-factor authentication should -- and should not -- be deployed

Tech Insight: Finding And Securing Your Enterprise's Most Sensitive Data


May 20, 2011
The headlines are full of companies facing serious data breaches. Here are some basic steps to protect your enterprise's critical data -- and stay out of the news

Five Stories Over Five Years That Shaped Security


May 03, 2011
Dark Reading commemorates its fifth anniversary with retrospectives on organized crime, USB sticks, the "soupnazi," and APTs

Diary Of A Breach


April 08, 2011
It's 10:00. Do you know where your data is? Before you answer, take a look at our intrusion timeline.

Hacking The APT


February 22, 2011
Google, SRA, Mandiant, McAfee execs share advanced persistent threat war stories

Survey: Half Of Americans Concerned With Medical Record Security Risks


February 10, 2011
SafeNet says consumers need a better understanding of who can access their personal data

Five Ways To Get Rational About Risk


January 26, 2011
Seat of the pants is no way to prioritize security spending and set project precedence. But that's exactly how some CISOs are doing business.

Why Don't Firewalls Work?


December 23, 2010
Even the best firewalls may fail an audit – or get hacked – if your enterprise doesn't follow proper change and configuration management practices. Here's a look at some of the common pitfalls that trip up firewall administrators

Tech Insight: The Five Stages Of Vulnerability Management


October 29, 2010
Like grief, enterprise security vulnerability management can be a heart-wrenching and complex challenge. Here's a roadmap that may help you get from denial to acceptance

Security's Risk And Change Management Tools: Drawing A Picture Of Security Posture


October 14, 2010
Apps that track and manage change and configuration of firewalls and other security systems are finding a home as security and risk monitoring tools in large enterprises

Stuxnet Heralds New Generation of Targeted Attacks


September 23, 2010
Power plants no longer considered immune to infection, and targeted attacks become more precise

Forensics Out Of Reach For Most Small To Midsize Organizations


September 08, 2010
Software-as-a-service, managed forensics services needed

What To Do When Your Database Gets Breached


August 09, 2010
Your organization's database has been compromised. What should you do now? A new report offers some answers

Tech Insight: IT Security's Most Time-Consuming Tasks


July 09, 2010
Picking the right tools can help save time and streamline

Why Can't Johnny Develop Secure Software?


June 16, 2010
Enterprises, vendors struggle to find the best methods for developing secure software

6 Hot And Sought-After IT Security Skills


May 13, 2010
What companies and government agencies are really looking for in today's IT security professional

Security Services Improve, But Bargains Few


April 27, 2010
Price of security services isn't dropping, but enterprises are getting more bang for the buck, experts say

'Operation Aurora' Changing The Role Of The CISO


March 16, 2010
The targeted attacks out of China against Google and other U.S. firms have forced some chief information security officers to reach out to their counterparts in other organizations and confidentially share their attack, forensics information

Microsoft, Researchers Team Up And Tear Down Major Spamming Botnet


February 25, 2010
Unprecedented court order helped dismantle Waledac, the second-generation iteration of the Storm botnet: here's how the undercover operation went down

Anatomy Of A Targeted, Persistent Attack


January 27, 2010
New report provides an inside look at real attacks that infiltrated, camped out, and stole intellectual property, proprietary information -- and their links to China

More Researchers Going On The Offensive To Kill Botnets


January 11, 2010
Another botnet bites the dust, and more researchers looking at more aggressive ways to beat cybercriminals

Attack Of The RAM Scrapers


December 18, 2009
Beware of malware aimed at grabbing valuable data from volatile memory in point-of-sale systems

Hacking Privileged Database User Access


November 13, 2009
How to provide least user privilege to your privileged database users

DIY: Defending Against A DDoS Attack


October 14, 2009
Proactive self-defense can make DDoS attacks less painful and damaging

Social Networks Fight Back


September 03, 2009
How major social networks MySpace and Facebook are building up security -- and where their weakest links remain

Mega-Breaches Employed Familiar, Preventable Attacks


August 18, 2009
Alleged mastermind behind Heartland, Hannaford's, and 7-11 breaches used SQL injection, sniffers, custom malware in attacks

After Years Of Struggle, SaaS Security Market Finally Catches Fire


July 28, 2009
Software as a service security market finally ripe, oldest providers say

Least-Privilege Technology Still Swimming Upstream, But Making Progress


July 10, 2009
Least-privilege technology struggles to overcome conventional approaches to PC security

What Obama's Cybersecurity Plans Mean For Businesses


June 01, 2009
Administration's new cybersecurity policies could yield new security regulations and incentives for enterprises, experts say

The Rocky Road To More Secure Code


April 08, 2009
A wave of secure coding initiatives have been launched, but will they result in less vulnerable applications?

6 Tips For Doing More Security With Less


February 26, 2009
Ways to squeeze more out of your security budget in trying times

Four Threats For '09 That You've Probably Never Heard Of (Or Thought About)


December 31, 2008
lesser-known security threats for 2009

Insiders Pose New Threats In Down Economy


December 04, 2008
Insider data theft and malicious attack are rising with employee discontent due to the economic downturn

The Seven Deadliest Social Networking Hacks


August 26, 2008
Think you know who your real online friends are? You could be just a few hops away from a cybercriminal in today's social networks

Hacker's Choice: Top Six Database Attacks


May 08, 2008
It doesn't take a database expert to break into one

DR's 10 Most Popular Stories Ever (Second Edition)


May 02, 2008
A look at the top stories from our first two years, including coolest hacks, biggest botnets, and a thumb drive exploit that readers just can't put down

A Peek at Snort 3.0


March 20, 2008
Next-generation of open source platform will be more than just IDS/IPS

The World's Biggest Botnets


November 09, 2007
What makes three of today's largest botnets tick, what they're after - and a peek at the 'next' Storm

Security's School of Hard Knocks


September 21, 2007
Security pros share five of the toughest lessons they've ever learned, and they've got the scars to prove them

Five Signs That You're Under a Targeted Attack


September 20, 2007
Clues that your organization is in the bull's eye might be right under your nose










Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:ssl-vpn end-point interrogator/installer activex control
Published:2010-11-03
Severity:High
Description:Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method.
Vulnerability:gvim
Published:2010-11-03
Severity:High
Description:Untrusted search path vulnerability in VIM Development Group GVim before 7.3.034, and possibly other versions before 7.3.46, allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse User32.dll or other DLL that is located in the same folder as a .TXT file. NOTE: some of these details are obtained from third party information.
Vulnerability:cforms
Published:2010-11-03
Severity:Medium
Description:Multiple cross-site scripting (XSS) vulnerabilities in wp-content/plugins/cforms/lib_ajax.php in cforms WordPress plugin 11.5 allow remote attackers to inject arbitrary web script or HTML via the (1) rs and (2) rsargs[] parameters.
Vulnerability:links, wsn links, wsn links
Published:2010-11-03
Severity:High
Description:Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.
Vulnerability:deluxebb
Published:2010-11-03
Severity:Medium
Description:SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the xthedateformat parameter in a register action, a different vector than CVE-2005-2989, CVE-2006-2503, and CVE-2009-1033.



Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)