Vulnerabilities / Threats

12/1/2017
10:00 AM
Connect Directly
Twitter
Twitter
RSS
E-Mail
100%
0%

Security Geek Gift Guide

Fun gifts for cybersecurity co-workers and bosses alike.
Previous
1 of 10
Next

Deck the halls and get to shopping! It's that time of year again, but this time there's no need to scratch your head and desperately wonder what to get the security geeks in your life. We've got you covered with this gift guide, which offers up different ideas based on what kind of security pro you're shopping for. 

So kick back and check out these gift ideas. 

 

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Previous
1 of 10
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
12/18/2017 | 7:14:20 PM
Password Notebook
FWIW, while the password notebook -- clearly labeled and marketed as such -- is utterly ridiculous, many cybersecurity experts have long been reversing the traditional wisdom and advising that people do write their passwords down...just so long as they don't store the written password in an open or obvious place (such as in a top desk drawer, stuck to a computer monitor or keyboard, or in a clearly marked "password notebook").

Of course, the whole purpose of writing down passwords as an enhanced security tactic is that it allows you to have better and more entropic passwords. If you're still going to have passwords like "jordan23" (let alone "password1" or "123456"), you're not doing yourself much good.
Election Websites, Back-End Systems Most at Risk of Cyberattack in Midterms
Kelly Jackson Higgins, Executive Editor at Dark Reading,  8/14/2018
Intel Reveals New Spectre-Like Vulnerability
Curtis Franklin Jr., Senior Editor at Dark Reading,  8/15/2018
Australian Teen Hacked Apple Network
Dark Reading Staff 8/17/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-15504
PUBLISHED: 2018-08-18
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. The server mishandles some HTTP request fields associated with time, which results in a NULL pointer dereference, as demonstrated by If-Modified-Since or If-Unmodified-Since with a month greater than 11.
CVE-2018-15505
PUBLISHED: 2018-08-18
An issue was discovered in Embedthis GoAhead before 4.0.1 and Appweb before 7.0.2. An HTTP POST request with a specially crafted "Host" header field may cause a NULL pointer dereference and thus cause a denial of service, as demonstrated by the lack of a trailing ']' character in an IPv6 a...
CVE-2018-15492
PUBLISHED: 2018-08-18
A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification.
CVE-2018-15494
PUBLISHED: 2018-08-18
In Dojo Toolkit before 1.14, there is unescaped string injection in dojox/Grid/DataGrid.
CVE-2018-15495
PUBLISHED: 2018-08-18
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.