The Wayback Machine - https://web.archive.org/web/20081202115154/http://www.darkreading.com:80/

Powered By InformationWeek Business Technology Network
 




Best Of The Web

LA TIMES
Cyberattack On Defense Department Computers Raises Concerns
DECEMBER 1, 2008  | Malware-borne attack, thought to be from inside Russia, hit combat zone computers and the U.S. Central Command overseeing Iraq and Afghanistan

DAILY PENNSYLVANIAN
Victoria's Secret Competition Gets Hacked
DECEMBER 1, 2008  | Two Drexel University students wrote a Perl script that could log 1,500 votes per second on the Victoria's Secret Web site gathering votes to select the first college to be added to its Pink Collegiate Collection

FOXNEWS.COM
World Bank Removes Chief Information Officer Following Cyberattacks
DECEMBER 1, 2008  | The World Bank drops a vice president in the wake of a series of computer hacks

LIQUIDMATRIX SECURITY DIGEST
CBS.com Compromised
DECEMBER 1, 2008  | An iFrame loads another malicious script from a remote server controlled by criminals in Russia, causing a possible installation of malware

SOPHOS
Facebook Data Loss Fiasco
DECEMBER 1, 2008  | Facebook has managed to lose some users' settings controlling when they should be e-mailed

INFORMATIONWEEK
U.S. Army Goes Bot Hunting
DECEMBER 1, 2008  | New software funded by a grant from the U.S. Army Research Office and developed by SRI International promises to provide users with more insight into what their computers are up to -- namely spotting bot activity

DAILY TECH
Spam Increasing Again After Shutdown Of Hosting Company
DECEMBER 1, 2008  | Since Sunday, spam volume rose around 37 percent of the original amount before McColo was pulled offline

NEOWIN
Chinese Internet Giant Hit With Scandal
DECEMBER 1, 2008  | China's largest search giant has been accused by the state-run media of allowing unlicensed medical providers to buy high search rankings

More Best Of Web




Info-Tech Research Group
A specialist in small and medium-sized businesses, Info-Tech offers a different perspective than research houses that focus on the Fortune 1000.



Video
Blogs

Evil Bytes
BY John H. Sawyer
Cheat Sheets For Responders and Server Administrators
December 1, 2008
03:18 PM -- It's not uncommon that organizations experience security breaches during the holidays. Malicious attackers who are determined to get in aren't going to take time off. They also know that there is most likely a skeleton crew, or less, manning the operations, so their activities have a greater chance of going unnoticed. Hopefully, none of you returne ...

Dark Dominion
BY Tim Wilson
How Are We Doing? Dark Reading Seeks Your Input
November 26, 2008
02:37 PM -- Dear Readers,
If you've been clicking through the pages of Dark Reading regularly for the past several weeks, you've probably noticed lots of changes. As
we told you back in October, the site has undergone an overhaul that included moving to a new serve ...


Hacked Off
BY Rob Enderle
Death of the AV Vendor: Microsoft Offers Free AV
November 18, 2008
08:55 PM -- The fundamental problem with the AV market is that it makes antivirus vendors as much a part of the problem as they are a part of the solution. They are motivated to promote exposures to create a market for their offerings, and the end result has been a massive increase in malware and an inability by the ecosystem to effectively combat it. This ...

CS Island
BY Kristen Romonovich
Sandboxes and Surfing With Google Chrome
October 27, 2008
09:00 AM -- Google designed Chrome to be faster, more stable and most importantly, more secure than other Web browsers. So with these features in mind, Google Chrome was built from scratch to be a Web browser designed for today�s web application users. As more businesses venture into the cloud, it�s becoming increasingly important that your browser doesn�t cra ...

MORE BLOGS



CSI Report
13th Annual CSI Survey
Targeted attacks, DNS exploits are on the rise, according to the 2008 CSI Computer Crime and Security Survey
MORE

User Profiles
8.22.2008
Life Insurer Takes New Approach to Two-Factor Authentication
Cryptocard technology helps Kansas City Life get the handle on a thorny access problem
MORE
5.30.2008
Stanford Medical School's Rx: Anomaly Detection
Appliance helps minimize bot, malware infections
MORE

Jobs
Position: Senior Security Analyst
Company: Cal Poly Pomona
Location: Pomona, CA
Posting Date: Posted 11/13/2008
MORE INFO
Position: Web Application Developer
Company: US Civilian Research and Development
Location: Arlington, VA
Posting Date: Posted 11/20/2008
MORE INFO
Position: Sr Network Analyst
Company: Hebrew Rehabilitation Center
Location: Boston, MA
Posting Date: Posted 11/18/2008
MORE INFO
Position: ITE Project Manager
Company: Lowes
Location: Mooresville, NC
Posting Date: Posted 11/20/2008
MORE INFO
Position: Project Manager
Company: Shure Incorporated
Location: Niles, IL
Posting Date: Posted 11/7/2008
MORE INFO


Briefing Centers
POWERFUL INFORMATION
AT YOUR FINGERTIPS
(SPONSORED LINKS)


Bugs
ENTERPRISE VULNERABILITIES
Vulnerability:safari
Published:2008-11-17
Severity:High
Description:Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.
Vulnerability:safari
Published:2008-11-17
Severity:Low
Description:Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser's page cache.
Vulnerability:safari
Published:2008-11-17
Severity:Medium
Description:The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that "launch local files."
Vulnerability:java system messaging server
Published:2008-11-17
Severity:Medium
Description:Cross-site scripting (XSS) vulnerability in Sun Java System Messaging Server 6.2 and 6.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2007-2904.
Vulnerability:logical domain manager
Published:2008-11-17
Severity:Medium
Description:Sun Logical Domain Manager (aka LDoms Manager or ldm) 1.0 through 1.0.3 displays the value of the OpenBoot PROM (OBP) security-password variable in cleartext, which allows local users to bypass the SPARC firmware's password protection, and gain privileges or obtain data access, via the "ldm ls -l" command, a different vulnerability than CVE-2008-4992.