SEARCH RESULTS
 
Showing 1-10 of 49 records
 
Expand article

Automatic Patch-Based Exploit Generation is Possible: Techniques and Implications

2008-04-28 15:41:41 by Editor in Help Net Security - Articles
 
The automatic patch-based exploit generation problem is: given a program P and a patched version of the program P', automatically generate an exploit for the potentially unknown vulnerability present
 
 
 
 
 
Expand article

SQL Injection Attacks Against Automatic License Plate Scanners

2008-04-29 15:21:34 by schneier in Schneier on Security
 
This picture is almost certainly Photoshopped, and a joke, but it's certainly a clever idea. As automatic license plate scanners become more common, why not get a SQL injection attack as a plate Reminds me of this xkcd cartoon
 
 
 
 
 
Expand article

Making a file with an automatic key in iSeries with DDS keyword

2008-05-09 12:42:32 by Kent Milligan in WhatIs: Enterprise IT tips and expert advice
 
If you want to create an automatic key using a DDS keyword on AS/400, Kent Milligan explains that any native writes performed against an SQL table created with an identity table will result in DB2 generating identity values
 
 
 
 
 
Expand article

Supporting your family, friends, and neighbors

2008-02-13 17:45:40 by Steve Riley in Steve Riley on Security
 
...automatic update client is running whenever you visit your FFN. This feature exists for them and minimizes the amount of work you need to do. Let Microsoft take care of patch management for your FFNoutsource it to us by making sure that all computers are downloading and installing updates automatically Simply using a firewall and installing...
 
 
 
 
 
Expand article

Introducing Google's online security efforts

The Article has images
2007-05-21 09:43:00 by A Googler in Google Online Security Blog
...automatic updates for your operating system as well your browsers, browser plugins and other applications you are using. Automatic updates ensure that your computer receives the latest security patches as they are published. We also recommend that you run an anti-virus engine that checks network traffic and files on your computer for known...
 
 
 
 
 
Expand article

Fuzz Testing at Microsoft and the Triage Process

2007-09-20 18:52:00 by sdl in The Security Development Lifecycle
 
...automatic triaging our fuzz testing tools perform. In this post, I'd like to shed some light on how we monitor for program failures when fuzzing parsers and how the recent animated cursor bug, MS07-017 caused us to revisit and ultimately improve our fuzzing tools Background For our purposes, fuzz testing is a method for finding program...
 
 
 
 
 
Expand article

Wrapping up Threat Modeling

2008-02-14 22:51:35 by sdl in The Security Development Lifecycle
 
...automatic, because theres a whole set of tasks you can ignore while the automatic transmission handles them for you. In my approach, this relates pretty closely to the concept of flow. If youre so focused on rules and jargon, you cant focus on what you should be building. Cool, well-designed features to help your customers In Conclusion We...
 
 
 
 
 
Expand article

Binary Analysis Seminar At UC Berkeley

2008-02-01 14:50:21 by Chris Wysopal in Zero in a bit
 
...automatically extracting security related properties from them. In particular, I will describe the two central research directions of BitBlaze: (1) the design and development of the underlying BitBlaze Binary Analysis Platform, and (2) applying the BitBlaze Binary Analysis Platform to addressing real-world security problems, including...
 
 
 
 
 
Expand article

NSA Attacks West Point! Relax, It's a Cyberwar Game

2008-05-10 01:00:00 by David Axe in Wired Security
 
...automatic" versus "custom," says Eric Dean, a civilian programmer and instructor. He adds that while automatic tools that do most of their own work are certainly easier, custom tools that allow more manual tweaking are more effective. "I expect one of the 'lessons learned' will be the use of custom tools instead of automatics Even with a...