Powered By InformationWeek Business Technology Network
 








Info-Tech Research Group
A specialist in small and medium-sized businesses, Info-Tech offers a different perspective than research houses that focus on the Fortune 1000.



Video
Blogs

Evil Bytes
BY John H. Sawyer
Internal vs. External Penetration Testing
November 19, 2008
04:33 PM -- In the past, I've talked about the merits of penetration testing (a.k.a. pen-testing) and several related tools. One thing I've not covered much is the difference between internal and external pen-testing. Today's Webcast, "Zen and the Art of Maintaining an Internal Penetration Testing Progr ...

Hacked Off
BY Rob Enderle
Death of the AV Vendor: Microsoft Offers Free AV
November 18, 2008
08:55 PM -- The fundamental problem with the AV market is that it makes antivirus vendors as much a part of the problem as they are a part of the solution. They are motivated to promote exposures to create a market for their offerings, and the end result has been a massive increase in malware and an inability by the ecosystem to effectively combat it. This ...

Dark Dominion
BY Kelly Jackson Higgins
My Spammers Didn't Get the Memo That They Were Toast
November 13, 2008
03:54 PM -- It has been a week that seemed like the good guys might finally be winning -- something -- in the cybercrime war. First, there were reports of a 65-plus percent drop in spam volume after a Web hosting firm known for hosting botnets, spamme ...

CS Island
BY Kristen Romonovich
Sandboxes and Surfing With Google Chrome
October 27, 2008
09:00 AM -- Google designed Chrome to be faster, more stable and most importantly, more secure than other Web browsers. So with these features in mind, Google Chrome was built from scratch to be a Web browser designed for today’s web application users. As more businesses venture into the cloud, it’s becoming increasingly important that your browser doesn’t cra ...

MORE BLOGS



CSI Report
13th Annual CSI Survey
Targeted attacks, DNS exploits are on the rise, according to the 2008 CSI Computer Crime and Security Survey
MORE

User Profiles
8.22.2008
Life Insurer Takes New Approach to Two-Factor Authentication
Cryptocard technology helps Kansas City Life get the handle on a thorny access problem
MORE
5.30.2008
Stanford Medical School's Rx: Anomaly Detection
Appliance helps minimize bot, malware infections
MORE

Jobs
Position: Senior Security Analyst
Company: Cal Poly Pomona
Location: Pomona, CA
Posting Date: Posted 11/13/2008
MORE INFO
Position: DC Systems Technician I
Company: Lowes
Location: Lebanon, OR
Posting Date: Posted 11/13/2008
MORE INFO
Position: NetBSD Software Developer
Company: Protingent Staffing
Location: Palo Alto, CA
Posting Date: Posted 10/30/2008
MORE INFO
Position: Senior Database Administrator
Company: Beyond.com
Location: King Of Prussia, PA
Posting Date: Posted 11/13/2008
MORE INFO
Position: ASIC Design
Company: D. E. Shaw Research
Location: New York, NY
Posting Date: Posted 10/23/2008
MORE INFO


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)


Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:image_gallery
Published:2008-11-12
Severity:High
Description:SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Vulnerability:edirectory
Published:2008-11-12
Severity:High
Description:Use after free vulnerability in the NetWare Core Protocol (NCP) feature in Novell eDirectory 8.7.3 SP10 before 8.7.3 SP10 FTF1 and 8.8 SP2 for Windows allows remote attackers to cause a denial of service and possibly execute arbitrary code via a sequence of "Get NCP Extension Information By Name" requests that cause one thread to operate on memory after it has been freed in another thread, which triggers memory corruption, aka Novell Bug 373852.
Vulnerability:league_module
Published:2008-11-12
Severity:Medium
Description:Cross-site scripting (XSS) vulnerability in the League module for PHP-Nuke, possibly 2.4, allows remote attackers to inject arbitrary web script or HTML via the tid parameter in a team action to modules.php.
Vulnerability:myforum
Published:2008-11-12
Severity:High
Description:Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1) myforum_login and (2) myforum_pass cookies to 1.
Vulnerability:ro002_router
Published:2008-11-12
Severity:High
Description:Sweex RO002 Router with firmware Ts03-072 has "rdc123" as its default password for the "rdc123" account, which makes it easier for remote attackers to obtain access. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.