SEARCH RESULTS
 
Showing 1-10 of 49 records
 
Expand article

Automating web application security testing

2007-07-16 11:40:00 by Panayiotis Mavrommatis in Google Online Security Blog
 
Posted by Srinath Anantharaju, Security Team Cross-site scripting (aka XSS) is the term used to describe a class of security vulnerabilities in web applications. An attacker can inject malicious scripts to perform unauthorized actions in the context of the victim's web session. Any web application that serves documents that include data from...
 
 
 
 
 
Expand article

Web Server Software and Malware

The Article has images
2007-06-05 09:30:00 by Niels Provos in Google Online Security Blog
Posted by Nagendra Modadugu, Anti-Malware Team In this post, we investigate the distribution of web server software to provide insight into how server software is correlated to servers hosting malware binaries or engaging in drive-by-downloads We determine server operating system by examining the 'Server:' HTTP header reported by most web...
 
 
 
 
 
Expand article

The Type of Lock Needed Has Changed

2007-01-22 00:00:00 by Chris Parkerson in Speaking of Security, the RSA Blog and Podcast
 
The focus on the perimeter has led to a reduction in breaches caused by traditional hacking. But this focus has also left everything inside the perimeter vulnerable to breaches that are more commonly affecting today's businesses -- lapses or breakdowns in internal processes, disgruntled employees walking off with laptops, mistakes by couriers...
 
 
 
 
 
Expand article

TEMPEST

2007-12-28 00:00:00 by Editor in Infosec Writers Latest Security Papers
 
Chris Gates from 'Learn Security Online' submits this paper on Electronic and electromechanical information-processing equipment that can produce unintentional intelligence-bearing emanations, commonly known as TEMPEST
 
 
 
 
 
Expand article

Control collaboration dont inhibit

2008-01-10 00:00:00 by HASH0x8470688 in Network World on Security
 
Web 2.0-inspired communities and social-networking tools are migrating into the enterprise and bringing with them risks that many organizations are unprepared to address. The challenge is to balance the business value of the new tools with the reality of risk management and compliance Register for a WAN Acceleration Technology Primer ...
 
 
 
 
 
Expand article

Watching the registrars

2008-01-11 00:00:00 by Mark Gibbs in Network World on Security
 
Network Solutions has once again shown that it can't be trusted in its role as a domain name registrar Register for a WAN Acceleration Technology Primer Advertisement This paper explores the differences between commonly used WAN acceleration technologies
 
 
 
 
 
Expand article

10,000 Web sites rigged with advanced hacking attack

2008-01-14 00:00:00 by HASH0x8b6b9bc in Network World on Security
 
A sophisticated hacking scheme seen early last year is affecting an increasing number of Web servers, including one owned by a major online advertising company, the chief technology officer of Finjan Software said Monday Register for a WAN Acceleration Technology Primer Advertisement This paper explores the differences between commonly used...
 
 
 
 
 
Expand article

Ikea closes global spam gap

2008-01-15 00:00:00 by HASH0x8b0cf4c in Network World on Security
 
The global furniture giant Ikea has closed a serious security gap that for an unknown period of time gave hackers and phishers a free rein to exploit the company's mail server Register for a WAN Acceleration Technology Primer Advertisement This paper explores the differences between commonly used WAN acceleration technologies
 
 
 
 
 
Expand article

Webroot reboots e-mail security service

2008-01-17 00:00:00 by HASH0x8b102cc in Network World on Security
 
Webroot has launched its first 'software-as-a-service' e-mail security offering, designed to secure messaging for the underserved SMB market Register for a WAN Acceleration Technology Primer Advertisement This paper explores the differences between commonly used WAN acceleration technologies
 
 
 
 
 
Expand article

FBI warns of rise in phone-based 'vishing' attacks