The Wayback Machine - https://web.archive.org/web/20071023072344/http://www.darkreading.com:80/
Dark Reading Registration Ad - Top Left
Register today and you could win a Sirius Satellite Radio
 
CELEBRATE THE INDUSTRY'S MOST COMPREHENSIVE SECURITY SITE FOR IT PROS
Become a registered user today (it's free!) and you'll get security alerts, news, information, and tools from the brightest minds in the business. And, just for signing up, you'll be automatically registered to win one of 10 Sirius Satellite Radios we're giving away in the next few days!
Register Today!
CSI ANNUAL CONFERENCE
November 3-9, 2007
Washington, DC
BLOG
Looking
Into
Forensics
COLUMN
Phishing's
Future
Scapegoats
REPORT
5 Signs of
Attack
USER PROFILE
Crypto
Makes the
Grade
CSI REPORT
12th Annual CSI Survey
Online Poker World Rocked by Hack
OCTOBER 22, 2007 | Chief of Absolute Poker site says 'consultant' developed method to look at others' hole cards without their knowledge
CLICK HERE FOR MORE
Webinars
OCTOBER 24, 2007
Security Update: eCards, Email Threats and Compliance
WEBINAR CALENDAR
More Events
OCTOBER 22 - 26, 2007
Interop New York 2007
MORE EVENTS CALENDAR
CSI Conferences
NOVEMBER 5 - 7, 2007
CSI 34th Annual Computer Security Conference and Exhibition
Security's largest, most comprehensive program anywhere
CSI CONFERENCES CALENDAR
Live Events
NOVEMBER 27, 2007
Future of Carrier Ethernet: Eastern Europe
DECEMBER 6, 2007
The Future of Cable Business Services
LIVE EVENTS CALENDAR
Security Product Directory
Including 204 products and 69 companies
ACCESS DATA
LIST YOUR COMPANY
LICENSE THE DIRECTORY
Application scanning  |  Application Security  |  Attacks / Exploits / Threats  |  Authentication  |  Botnets  |  Browser security  |  Computer crime  |  Consultants  |  Content filtering  |  Cross-site scripting  |  DOS  |  Encryption  |  End-user monitoring   |  Host Protection  |  Identity management  |  IDS  |  Industry Trends   |  IPS  |  Law enforcement  |  Legal & Regulatory Topics  |  Legislation  |  Malware  |  Managed services  |  Market Research  |  Messaging Security  |  Microsoft  |  PCI  |  Penetration testing  |  Penetration testing  |  Perimeter Security  |  Phishing  |  Policy management  |  Security Administration / Management  |  Security Industry  |  Security Services  |  Social engineering  |  Spam  |  SQL injection  |  Storage Security  |  Stored data losses  |  Symantec  |  Trojans  |  User privacy  |  Viruses  |  Vulnerabilities  |  Vulnerability assessment  |  Vulnerability management  |  Vulnerability Management  |  Web services security  |  Worms
I've seen some companies
going to more of a
preventive approach by
doing heavy background
checking on new hires - ...
Upstart Takes New Tack on Digital Signatures
JOIN THE TALK
MOST POPULAR
SEND US A TIP
OCTOBER 22, 2007 | TriCipher's new MySignatureBook enables multiple signers to authorize a single document electronically
Study: ID Thieves Get Their Hands Dirty
OCTOBER 22, 2007 | Research on US Secret Service identity theft cases shows criminals used more manual methods
Spammers Convicted in $2M Loan Fraud Scheme
OCTOBER 19, 2007 | Fraudsters collected 'advance fees' from borrowers who couldn't get conventional loans
Research Shows Image-Based Threat on the Rise
OCTOBER 18, 2007 | New Purdue University research shows steganography, long considered a minor threat, may be on the rise
Study: ID Fraud Varies With Victims' Income Level
OCTOBER 18, 2007 | 'Economic divide' may lead businesses to develop more customized defenses for different customer types, Javelin research says
No Breach, No Foul
OCTOBER 17, 2007 | Businesses may not be required to fix vulnerabilities on their Websites � until it's too late
MORE SECURITY NEWS
DERBY, UK | One in Six PCs Infected
SUPERIOR, CO | StillSecure Opens Cobia to Developers
PORTLAND, OR | DeviceWall Becomes Content-Aware
POST FALLS, ID | TriGeo Merges Biz Intelligence, SIEM
MECHANICSBURG, PA | ICSA Labs Certifies Four Products
LONDON | RSA Announces SecurID for Symbian OS
PITTSBURGH | Nortel Joins Carnegie Mellon's CyLab
SEATTLE | Lockdown Announces Enforcer Upgrade
PALO ALTO, CA | Voltage Security Closes $12M in Financing
SAN FRANCISCO | nCircle Adds PCI Compliance Solution
MORE NEWSFEED
METASPLOIT BLOG
Cracking The iPhone (Part 3)
OCTOBER 22, 2007 | HD Moore released more details on how to hack the iPhone using Metasploit, including how to patch the libtiff vulnerability in iPhone using Metasploit's ipwn shell
CNET
NSA Cooperation: OK For Email, IM Companies?
OCTOBER 22, 2007 | New Senate bill would also protect email providers, search engines, ISPs, and IM providers from lawsuits for cooperating with NSA surveillance
INFOWORLD
Storm Worm Now Just a Squall
OCTOBER 22, 2007 | A network security analyst at UC San Diego says Storm's infections have been shrinking steadily
SCHNEIER ON SECURITY BLOG
Detecting Credit Card Fraud With Checksums
OCTOBER 22, 2007 | How to put a checksum into the bill total to ensure servers don't tamper with tip totals
WIRED
Exclusive: I Was a Hacker for MPAA
OCTOBER 22, 2007 | Robert Anderson tells how the Motion Picture Association of America promised him money and power for confidential information on TorrentSpy
HEISE SECURITY
RealPlayer Plug-In Poses danger
OCTOBER 22, 2007 | A previously unknown vulnerability in RealPlayer is currently being exploited
COMPUTERWEEKLY
Hacker Uses Public APIs to Breach eBay
OCTOBER 22, 2007 | EBay says the hacker who accessed and disabled user accounts last week did so using public APIs used by merchants to build e-commerce sites that interface with eBay
Cha-Cha-Cha-Changes With Tripwire Enterprise 7
OCTOBER 22, 2007 | Auditing software helps track unauthorized or unwanted modifications to servers, networks
MORE BEST OF THE WEB
1 |  Re: stop worrying about the data - Kesty
2 |  Advantage: Bad Guys - mdgutchess
3 |  A good reference book - Kesty
4 |  What does that have to do with Debugging? - Kesty
5 |  Re: Solidcore has a great tool for Windows - bergeron
6 |  Wow. - darkreading4
7 |  Solidcore has a great tool for Windows - solidcore
8 |  Ooooh! PCI is enough! - wifiwoof
9 |  NAC trends - domwilde
10 |  NAC trends - domwilde
11 |  misleading subject line - always lurking
12 |  Re. Retailer PCI Rebellion - CFGrayIII
13 |  Re: DDoS Attack - jsawyer
14 |  AB 779 is ill-advised - benjaminwright
15 |  Another facet of convergence - carywms
16 |  Re: DDoS Attack - jsawyer
17 |  DDoS Attack - kpc2garner
18 |  stop worrying about the data - sentrysam
19 |  Insider attacks ARE offensive, but - ru_trustified
20 |  anti-DDoS - Andre Gironda
SEARCH MESSAGE BOARDS   |   START YOUR OWN BOARD
MESSAGE BOARDS EXPLAINED
RANKED FROM THE LAST MONTH
3 |  Debugging Your Bug Software
1 |  Advantage: Bad Guys
1 |  Phishing's Future Scapegoats
1 |  Insider Attacks Put IT Security on the Offensive
SEARCH MESSAGE BOARDS   |   START YOUR OWN BOARD
MESSAGE BOARDS EXPLAINED
FROM THE EDITORS AT NETWORK COMPUTING
Review: Blue Lane VirtualShield
JUNE 1, 2007 | When put to the test, Blue Lane�s unique patching approach is an effective way to protect against remotely exploitable vulnerabilities targeting VMware
Review: Enzo's Database Extrusion Monitor
MAY 21, 2007 | Enzo 2006 may work well for small orgs with few databases, but it could become an implementation nightmare for enterprises
Ubuntu Linux vs Windows Vista: The Battle for Your Desktop
MAY 4, 2007 | Testers tried out both Vista and Ubuntu on individual PCs to see which works better. Here's who won
Analysis: Enterprise Key Management
MAY 1, 2007 | How to keep keys manageable and safe, as well as what to look for in an enterprise key management system
Review: Lockdown Networks Enforcer 4.2.7
MAY 1, 2007 | Lockdown integrates syslog events but stumbles on several key features, such as event suppression and management
MORE PRODUCT REVIEWS
Five Signs That You're Under a Targeted Attack
SEPTEMBER 20, 2007 | Clues that your organization is in the bull's eye might be right under your nose
Eight Sure-Fire Ways to Beat a Security Audit
AUGUST 23, 2007 | Experts share tips on how to avoid the most common pitfalls in an audit
MORE REPORTS
Download AppScan 6.5 today! 7 day free trial from Watchfire
FREE Sophos Threat Detection Test
Is your AV catching everything it should? Free virus, spyware and adware scan.
Find Consulting Jobs
Access Pre-Qualified Projects from Top Businesses. Register Now!
Register here for valuable IT Audit White Paper
Learn about auditing, compliance and operational efficiency with tips from Quest�s new white paper.
Identity Management Featuring Leading Analyst Firm
In this video presentation, learn how identity management is helping companies meet their business initiatives by driving new online revenue opportunities, securely extending businesses beyond four walls, and helping corporations to mitigate risk
Free Membership: ITIL WP Downloads
Browse Through ITIL Papers And Download Topics Of Interest. Become A More Well Informed IT Buyer.
BUY A LINK NOW
Evil Bits
BY JOHN SAWYER
Forensics Tools: A Closer Look
OCTOBER 22, 2007
4:15 PM -- Low-cost and open-source tools may significantly expand your forensics options
Firewalled
BY TIM THE ENCHANTER
Advantage: Bad Guys
OCTOBER 19, 2007
2:45 PM -- As long as rules and practices leave loopholes, it's a cybercriminal's market
I Shadow
BY KELLY JACKSON HIGGINS
Microsoft Developers' School of Hard Knocks
OCTOBER 18, 2007
1:55 PM -- Software giant provides tips on what to do - and what not to do - when building more secure apps
Snake Bytes
BY RSNAKE
'Secret' Workshop Explores Future of Malware
OCTOBER 16, 2007
1:00 PM -- Malware will get worse before it gets better
CS Island
BY ROBERT RICHARDSON
'Defenestration' Testing
AUGUST 23, 2007
4:26 PM -- Does your organization even know what secrets it's supposed to be keeping?
MORE BLOGS
Rob Enderle
PRESIDENT, ENDERLE GROUP
Phishing's Future Scapegoats
OCTOBER 17, 2007
If they don't act soon, frequently-phished companies may be held liable for crimes committed in their names
Gary McGraw
CTO, CIGITAL
Online Games & the Law
OCTOBER 11, 2007
US law struggles to keep up with new capabilities in collaborative computing environments
Nathan Spande
INDEPENDENT CONSULTANT
Rethinking Vulnerabilities
SEPTEMBER 18, 2007
In an increasingly networked world, it's time to take a closer look at distributed systems security
Gary McGraw
CTO, CIGITAL
Mobile Insecurity
SEPTEMBER 14, 2007
It's just a matter of time before mobile devices fall victim to new - and major - exploits
MORE COLUMNS

CALENDAR
PARTNER-UP
Dan Kaminsky
Flaws: Back to the Future
Jennifer Granick
Is That Legal?
Adam Laurie
The Dangers of RFID
Jim Christy
Meet the Fed
Johnny Long
No-Tech Hacking
Gadi Evron
Lessons In Cyberwar
Rootkit Debate
Can It Be Detected?
Custom Programming
Dark Reading Editorial
Dark Reading's repository of intel on IT security. More of a 'megabase' than a database, Dark Entries lets you dig for information, or share your expertise. The choice is yours, grasshopper.
12th Annual CSI Survey
The average cost of cybercrime has more than doubled in the past year, according to the 2007 CSI Computer Crime and Security Survey
MORE
8.23.2007
Crypto Makes the Grade at Baylor
University taps PGP to protect faculty, staff laptops � and to comply with state laws in the event of data loss
MORE
7.20.2007
Cigna Goes on a Role
Health benefits provider automates upkeep of its role-based user access control
MORE
Position: GUI Software Engineer
Company: Hayes Group LLC
Location: Baltimore, MD
Posting Date: 10/16/2007
MORE INFO
Position: DSP Software Engineer
Company: Ajilon Consulting
Location: King Of Prussia, PA
Posting Date: 10/15/2007
MORE INFO
Position: .Net Developer
Company: Associated Electric Cooperative, Inc.
Location: Springfield, MO
Posting Date: 10/17/2007
MORE INFO
Position: Software Development Engineer
Company: Integral Systems, Inc
Location: Lanham, MD
Posting Date: 10/14/2007
MORE INFO
Position: 3D System Software Engineer
Company: NVIDIA
Location: Santa Clara, CA
Posting Date: 10/13/2007
MORE INFO
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)
ENTERPRISE VULNERABILITIES
Vulnerability: VMWare VMware Server
Published: 2007-10-22
Severity: HIGH
Description: unspecified
vulnerability in vmware
server before 1.0.4 causes
user passwords to be
recorded in cleartext in
server logs, which might
allow local users go gain
privileges.

Vulnerability: VMWare VMware Server, VMWare VMWare Workstation, VMWare VMWare Player
Published: 2007-10-22
Severity: HIGH
Description: unquoted
windows search path in the
authorization and other
services in vmware player
1.0.x before 1.0.5 and 2.0
before 2.0.1, vmware server
before 1.0.4, and
workstation 5.x before 5.5.5
and 6.x before 6.0.1, might
allow local users to gain
privileges via mal...

Vulnerability: VMWare VMWare Workstation, VMWare VMWare Player
Published: 2007-10-22
Severity: HIGH
Description: unspecified
vulnerability in vmware
player 1.0.x before 1.0.5
and 2.0 before 2.0.1, and
workstation 5.x before 5.5.5
and 6.x before 6.0.1,
prevents it from launching,
which has unspecified
impact, related to untrusted
virtual machine images.

Vulnerability: RealNetworks RealPlayer
Published: 2007-10-22
Severity: HIGH
Description: stack-based
buffer overflow in the
database component in
mpamedia.dll in realnetworks
realplayer 10.5 and 11 beta
allows remote attackers to
execute arbitrary code, as
demonstrated via the import
method to the ierpctl
activex control in
ierpplug.dll.

Vulnerability: Artmedic Webdesign Artmedic CMS
Published: 2007-10-22
Severity: MEDIUM
Description: incomplete
blacklist vulnerability in
index.php in artmedic cms
3.4 and earlier allows
remote attackers to execute
arbitrary php code via a (1)
unc share pathname, or a (2)
ftps, (3) ssh2.sftp, or (4)
ssh2.scp url, in the page
parameter, for which php
remote f...

Copyright © 2000-2007 CMP Media LLC - All rights reserved.
RSS FEED  |   ARCHIVE  |   FREE NEWSLETTER  |   ORDER REPRINTS  |   ADVERTISE WITH US  |   TECHWEB  |   CONTACT US  |   USER PREFERENCES  |   HELP
Companies
3Com (14), Aventail (7), CA (13), Check Point (26), Cisco (116), Enterasys (5), F-Secure (6), F5 (3), HP (13), IBM (86), Intel (6), ISS (27), Juniper (32), Alcatel-Lucent (1), McAfee (129), Microsoft (950), NetIQ (2), Nokia (3), Nortel (6), Oracle (30), Qualys (2), RSA (35), Secure Computing (14), Sun (6), Symantec (219), Trend Micro (16), VeriSign (30)

Application and Perimeter Security
802.11x (44), Anomaly detection (55), Anti-spam (106), Application quality assurance (20), Application scanning (72), Auditing (25), AVDL (1), Buffer overflows (83), CERT (7), Consultants (88), Cross-site scripting (118), CVE (7), Database encryption (50), Digital vaults (7), DOS (133), EAP/LEAP (1), Email gateways (62), Encryption (88), Filtering (45), Firewalls (215), FIRST (1), HIPAA (72), Host-based IDS (38), Host/server configuration (14), Host/server encryption (6), IDS (11), IDS (129), IM (48), IPS (210), ISO 17799 (8), Key management (51), Least-privilege user (37), License management (27), Malware (857), NAC (215), Network IDS (29), NIST (16), OWASP (11), OWASP (6), Patch management (226), PCI (114), Penetration testing (114), Phishing (447), PKI (36), Rootkits (80), SAML (2), Software metering (3), Source-code auditing (52), SOX (72), SSL (146), Systems integrators (7), VPNs (207), Vulnerability assessment (405), Web App Security Consortium (6), Web App Security Consortium (13), Web application firewall (58), Web services security (265), WLANs (256), Worms (223), WPA (12), XML (26)

Desktop Security
Anti-spam (106), Antivirus (254), Application Security (814), Attacks / Exploits / Threats (1304), Authentication (557), Browser security (496), Digital certificates (47), Digital signatures (28), Disk encryption (39), DRM (45), Encryption (426), File/folder encryption (28), Identity management (208), IM (48), Malware (857), Messaging Security (399), PGP (4), Phishing (447), Rootkits (80), S/MIME (2), Security Administration / Management (1216), Social engineering (220), Spam (416), Spyware (186), Tokens (58), Trojans (230), User privacy (933), Viruses (274), VOIP security (88), Vulnerabilities (1876), Vulnerability Management (336), Worms (223)

Discovery and management
Anomaly detection (55), Application scanning (72), AVDL (1), Black Hat (94), COBIT (8), Consultants (88), Content filtering (109), CVE (7), End-user monitoring (165), Filtering (45), FISMA (17), HIPAA (72), Host intrusion prevention (93), Host-based IDS (38), IDS (11), IDS (129), IPS (210), ISACA (1), ISO 17799 (8), Log aggregation (29), Network IDS (29), OWASP (11), OWASP (6), PCI (114), Penetration testing (114), Penetration testing (108), SAML (2), SIM/SEM (129), Source-code auditing (52), SOX (72), Vulnerability assessment (405), Vulnerability management (543), Web App Security Consortium (6)

Host security
802.11x (44), Application quality assurance (20), Authentication (557), Backup security (48), Biometrics (122), Buffer overflows (83), Digital certificates (47), Disk encryption (39), Encryption (426), End-user monitoring (165), HIPAA (72), Host anti-spam (59), Host anti-spyware (82), Host antivirus (74), Host intrusion prevention (93), Host Protection (290), Host-based IDS (38), Host/server configuration (14), Host/server encryption (6), Host/server patching (9), IDS (11), IEEE (4), ISO 17799 (8), Least-privilege user (37), License management (27), NAC (215), P2P management (21), Patch management (226), PGP (10), Port control (10), Single sign-on (49), Smart cards (59), Software metering (3), SOX (72), Systems integrators (7), TCG (17), Tokens (58), User privacy (933), Vulnerability Management (336), WPA (12)

Security services
Agency application (2), Application quality assurance (20), Application scanning (72), AVDL (1), COBIT (8), Consultants (88), FISMA (17), HIPAA (72), ISO 17799 (8), Managed services (205), PCI (114), Penetration testing (108), PKI (36), Policy management (291), SIM/SEM (129), Source-code auditing (52), SOX (72), Systems integrators (7)

Storage Security
AES (10), Backup security (48), COBIT (8), Database encryption (50), DES (3), Digital vaults (7), Disk encryption (39), Encryption (88), File/folder encryption (28), FIPS-140-2 (1), FISMA (17), Hashing algorithms (12), HIPAA (72), Host/server encryption (6), Identity management (70), ISO 17799 (8), Key management (51), Law enforcement (578), Legislation (190), Offsite backup (19), PCI (114), PKI (36), SOX (72), Stored data losses (214), Systems integrators (7), Triple DES (3), User privacy (933)

Wireless Security
802.11x (44), AES (10), Auditing (25), COBIT (8), Credential service provider (6), DES (3), Digital certificates (47), Digital signatures (28), DOS (133), EAP/LEAP (1), FISMA (17), Hashing algorithms (12), HIPAA (72), Host/server encryption (6), IEEE (4), IETF (9), ISO 17799 (8), Key management (51), NAC (215), Network IDS (29), PCI (114), Penetration testing (108), PKI (36), Port control (10), Tokens (58), Triple DES (3), VPNs (207), Vulnerability assessment (405), WLANs (256), WPA (12)