Email Alerts
-
Apple releases QuickTime security fix
The popular QuickTime multimedia application is afflicted with at least seven security flaws, but Apple has released an update to fix them. Article
-
How to test an e-commerce Web site's security and privacy defenses
Assessing the security of e-commerce sites means checking up on their associated servers, databases and applications. In this expert response, Michael Cobb explains where to start. Ask the Expert
-
Can fuzzing identify cross-site scripting (XSS) vulnerabilities?
Fuzzing may find weaknesses in software, but the testing process can't find every flaw. Ed Skoudis explains what other tools are necessary when looking for cross-site scripting vulnerabilities. Ask the Expert
-
Can Snort stop application-layer attacks?
Even though Snort can add an important layer of defense for applications, it won't fix the underlying problem of poorly written ones. Michael Cobb reveals a more efficient technique for patching up XSS and SQL injection vulnerabilities. Ask the Expert
-
New attack methods target Web 2.0, VoIP
Researchers have found new evidence that attackers are targeting Web 2.0 applications and VoIP with increased vigor. Companies are ill-prepared to meet the threat, they say. Article
-
HP issues advisories, plugs holes
HP's System Management Homepage is vulnerable to cross-site scripting attacks, according to advisories issued Tuesday. Article
-
How Russia became a malware hornet's nest
Security experts Eugene Kaspersky and Gadi Evron explain how the Russian economy and lax police work helped make it a malware hotbed. Article
-
Google fixes Gmail zero-day
Google plugged a cross-site scripting flaw that could have been exploited to silently forward emails and contacts from a remote user's account. News
-
Serious Google Gmail flaw exposes sensitive user data
A cross-site scripting vulnerability in Gmail allows attackers to silently forward emails and view sensitive data. Article
-
Cybercriminals employ toolkits in rising numbers to steal data
The market is increasing for crimeware toolkits that help cybercriminals avoid detection and exploit flaws, according to new research from security vendor, Finjan. Article
Security Management Strategies for the CIO