SEARCH RESULTS
 
Showing 1-10 of 47 records
 
Expand article

Another Windows Vista Privilege Escalation Vulnerability

2007-02-06 12:24:25 by Editor in Endpoint Security: Translating Policy Into Reality
 
Another Windows Vista Privilege Escalation Vulnerability
 
 
 
 
 
Expand article

E-discovery error leads to loss of attorney-client privilege

2008-06-09 00:00:00 by HASH0x8b161d0 in Network World on Security
 
A federal judge in Maryland ruled late last month that a company being sued for copyright infringement waived attorney-client privilege for 165 documents accidentally disclosed to opposing counsel during the e-discovery process
 
 
 
 
 
Expand article

Another Windows Vista Privilege Escalation Vulnerability

2007-02-06 12:24:25 by Editor in Endpoint Security: Translating Policy Into Reality
 
Another Windows Vista Privilege Escalation Vulnerability
 
 
 
 
 
Expand article

Intel Update For BIOS Protects From Privilege Escalation Vulnerability Discovered By Rutkowska

2008-08-28 17:29:25 by CyberInsecure in CyberInsecure.com
 
Intel has shipped a BIOS update with a fix for a privilege escalation vulnerability that was discussed by Rutkowska at the Black Hat briefings earlier this month but details on the exploit were withheld until Intel could release its patch. The patch is rated important and is available to download. According to Intels advisory, software running
 
 
 
 
 
Expand article

Mashup of the Titans

2008-06-25 17:29:25 by Gunnar Peterson in 1 Raindrop
 
...privilege: Where feasible, a protection mechanism that requires two keys to unlock it is more robust and flexible than one that allows access to the presenter of only a single key. The relevance of this observation to computer systems was pointed out by R. Needham in 1973. The reason is that, once the mechanism is locked, the two keys can be...
 
 
 
 
 
Expand article

Turning on cruise control

2008-01-18 07:26:00 by Keith Brown in Security Briefs
 
...privilege account , but that account didn't have permissions to write to the CruiseControl log file, didn't have credentials to download files from our subversion repository, didn't have permissions to write those files to the working directory or deploy to the deployment folder. So here's the key: instead of debugging all of this using...
 
 
 
 
 
Expand article

Training People on Threat Modeling

2008-03-14 23:11:12 by sdl in The Security Development Lifecycle
 
...Privilege) doesnt make a very memorable acronym. Memorable is important when training people. Our reviewers have raised this as an issue, and d love to get feedback from our readers. How can we ensure that the software we build has the right level of logging and audit-ability? What evocative words can we use, and can you help us come up with...
 
 
 
 
 
Expand article

Limiting Process Privileges Should Be Easier

2007-11-09 10:00:00 by Security Retentive in Security Retentive
 
...privileges for a process/service. I think it still isn't quite to the default-deny and allow only what you want stage, but interesting nonetheless Limiting Service Privileges in the Solaris 10 Operating System Privilege Debugging in the Solaris 10 Operating System Windows Server 2008 Microsoft has introduced service hardening and reduced...
 
 
 
 
 
Expand article

Notes from IEEE Web 2.0 Security and Privacy Workshop (W2SP2008)

2008-05-27 22:45:00 by Security Retentive in Security Retentive
 
...privilege level. Plugins cannot be constrained in what they can do, etc I haven't seen any analysis yet comparing what MS did with IE7 on Vista in protected mode as compared to OP or Kapil's work. It is pretty clear that MS didn't fully segment IE7, but I wonder how close they got to ideal on the sandboxing side of things That said, I think...