THE CENZIC BLOG

DarkReading - All Stories

DarkReading

Copyright 2007, CMP Technology.


Fri, 3 Sep 2010 11:26:00 EDT

Tech Insight: Retooling Vulnerability Scanning, Penetration Testing For IPv6

Traditional host discovery via network scanning won't work with IPv6, but alternative methods are available

Thu, 2 Sep 2010 15:06:00 EDT

Five Ways To Stop Mass SQL Injection Attacks

The best practices for mitigating this popular form of attack often are not being deployed

Thu, 2 Sep 2010 14:40:00 EDT

IPv6 Transition Poses New Security Threats

Next-generation IP protocol comes with more security as well as some potential flaws of its own

Wed, 1 Sep 2010 17:32:00 EDT

Networked Scanners Offer A Window Into The Enterprise, Researcher Says

Emerging Web-based features make it possible to capture document contents remotely from networked scanners, researcher says

Wed, 1 Sep 2010 16:44:00 EDT

U.S. Businesses Could Lose Up To $1 Billion In Online Banking Fraud This Year

Small- to midsized businesses taking the biggest hit, experts say, but consumer banking customers could be next in the bull's eye

Wed, 1 Sep 2010 11:58:00 EDT

Product Watch: Verizon, VMware Team Up With Hybrid Cloud Service

New Verizon service offers private public-cloud option

Tue, 31 Aug 2010 17:40:00 EDT

Could USB Flash Drives Be Your Enterprise's Weakest Link?

The Pentagon last week conceded that a USB flash drive carried an attack program inside a classified U.S. military network. Could your company be next?

Tue, 31 Aug 2010 17:09:00 EDT

Delaware Contractor Mistakenly Posts Personal Data Of 22,000 Employees

State of Delaware contractor Aon mistakenly posts personal data of 22,000 retirees without randomization, officials say

Tue, 31 Aug 2010 14:04:00 EDT

IBM Corrects Unpatched Vulnerability Numbers After Google Challenge

X-Force Team at IBM revises data on vendors with most unpatched bugs in recent IBM X-Force 2010 Mid-Year Trend and Risk Report

Mon, 30 Aug 2010 15:59:00 EDT

Major Disruption of Pushdo Botnet Wasn't The Original Goal

Botnet's spam traffic cut by 80 percent

Mon, 30 Aug 2010 15:55:00 EDT

China, Taiwan Nab 450 Suspects In Biggest Fraud Raid Ever

Law enforcement authorities in China, Taiwan seize cash, fraud "manuals" from alleged telecom fraud ring

Fri, 27 Aug 2010 14:01:00 EDT

Four Best Practices For Tokenization

Going beyond Visa's best practices guide

Thu, 26 Aug 2010 14:27:00 EDT

Mariposa Botnet Operators Didn't Bite In 'Cookie-Stuffing' Offer

Ecommerce fraud technique siphons commission, referral fees from website affiliates

Wed, 25 Aug 2010 17:03:00 EDT

Careful With That Third-Party Web Widget

Smaller businesses are more likely to use third-party Web applications on their websites -- and they are less likely to scan such code

Wed, 25 Aug 2010 16:50:00 EDT

California Legislation Would Require Companies To Specify The Data Exposed In Breaches

New legislation sitting on Governor Arnold Schwarzenegger's desk raises issue of standard breach notifications

Tue, 24 Aug 2010 14:46:00 EDT

DNSSEC Will Drive Certificate Market

While DNNSEC will improve domain authentication, certificates still needed to verify the brand

Mon, 23 Aug 2010 16:45:00 EDT

Mobile Devices Threaten Enterprises From Within

Security researchers are focusing increasingly on mobile devices. The result: your next insider attack could come from a smartphone

Mon, 23 Aug 2010 15:56:00 EDT

United Nations Website Contains SQL Injection Flaws Three Years After Hack, Researcher Says

Bug used in infamous 2007 defacement fixed, but additional SQL injection bugs remain

Fri, 20 Aug 2010 15:33:00 EDT

Tech Insight: Using Network Segmentation And Access Control To Isolate Attacks

The right network design can protect against hidden threats from embedded systems and rogue access points as well

Fri, 20 Aug 2010 12:57:00 EDT

Tiger Team Sends DHS Suggestions On How To Better Safeguard Patient Privacy

19-page letter recommends that the HIT Policy Committee adopt the guidelines set out in the Fair Information Practices

Thu, 19 Aug 2010 13:28:00 EDT

Intel To Purchase McAfee For $7.68 Billion In Cash

Security experts skeptical of hardware-based security strategy

Thu, 19 Aug 2010 13:20:00 EDT

Slideshow: Fashion Statements from DEFCON 2010

Tattoos, mohawks, sheep, and 'pimp' necklaces were just some of the scenes from the hacker conferences in Las Vegas earlier this month.

Wed, 18 Aug 2010 17:52:00 EDT

Researcher Cracks ReCAPTCHA

Homegrown algorithms for cheating Google's reCAPTCHA released earlier this month

Wed, 18 Aug 2010 15:17:00 EDT

Ferreting Out Rogue Access Points And Wireless Vulnerabilities

To comply with regulations, companies increasingly must scan their wireless networks -- a third of which have rogue APs or other insecurities

Tue, 17 Aug 2010 17:32:00 EDT

Mass Drive-By Attack Used Web Widget

Attack used a different spin on mass injection, targeted hosting provider Network Solutions Inc.

Mon, 16 Aug 2010 19:47:00 EDT

Inside Verizon's Insider Threat Data

Verizon Business' latest Data Breach Investigations Report shows insiders as a growing threat -- but increase comes from a selective data set

Fri, 13 Aug 2010 13:35:00 EDT

Six Healthcare Data Breaches That Might Make Security Pros Sick

Most of the healthcare industry's biggest recent IT security breaches could have been avoided, experts say

Thu, 12 Aug 2010 17:07:00 EDT

A Peek At The Next Version Of PCI

Clarifications but no big changes -- but that's what concerns some security experts

Wed, 11 Aug 2010 21:50:00 EDT

Small And Midsize Businesses Look For Ways To Cut Compliance Costs

Strapped for cash, SMBs seek strategies to achieve IT security compliance on a shoestring

Wed, 11 Aug 2010 13:58:00 EDT

Six Florida Colleges Victims Of Widespread Data Breach

SSNs, other personal data of students, employees were inadvertently exposed -- and viewed -- online

Wed, 11 Aug 2010 12:00:00 EDT

New Mobile Security Threat: Fingerprint Oil

Oily residue left on touchscreen mobile devices may help an attacker deduce password

Tue, 10 Aug 2010 16:35:00 EDT

Targeted Attack Nets 3,000 Online Banking Customers

Major financial institution's commercial and consumer customers bilked of more than $1 million so far

Tue, 10 Aug 2010 08:18:00 EDT

Healthcare Suffers More Data Breaches Than Financial Services So Far This Year

Lax handling of data, storage of it, and access to databases biggest culprit

Mon, 9 Aug 2010 15:47:00 EDT

Microsoft Investigates New Zero Day Reported In Windows Kernel

Windows 7 and Vista also contain this new heap overflow vulnerability, according to security researcher reports

Sun, 8 Aug 2010 23:20:00 EDT

Flawed Deployments Undermine Kerberos Security

Researchers find practical problems that can weaken secure authentication via popular Kerberos standard

Fri, 6 Aug 2010 22:30:00 EDT

Tech Insight: Building The Right Defense Against Social Engineering

DEFCON capture the flag contest shows that humans are still the enterprise's weakest security link

Thu, 5 Aug 2010 16:47:00 EDT

Social Engineers Successfully Gather Info

The Defcon18 contest worked well -- too well -- its organizers say

Thu, 5 Aug 2010 13:15:00 EDT

Slide Show: Barnaby Jack Hits The Jackpot With ATM Hack

Barnaby Jack, director of research at IOActive, at Black Hat USA in Las Vegas last week demonstrated attacks that would allow a criminal to compromise ATMs in order to steal cash, copy customers' ATM card data, or learn master passwords of the machines

Wed, 4 Aug 2010 17:43:00 EDT

Holy Zeus! Popular Botnet Rules As New Exploits Come Online

Researchers identify two new botnets, both built on Zeus botnet development kit

Wed, 4 Aug 2010 15:18:00 EDT

Cloud-Based Denial Of Service Attacks Looming, Researchers Say

Two consultants at DEFCON conference use a handful of virtual servers in Amazon's EC2 cloud to take down an SMB's network

Wed, 4 Aug 2010 14:55:00 EDT

Researchers Throw Down Vulnerability-Disclosure Gauntlet

TippingPoint's Zero Day Initiative (ZDI) program institutes deadline of six months for vendors to fix bugs -- or else the bugs get published

Wed, 4 Aug 2010 11:12:00 EDT

Majority Of IS Pros OK With Government Online Spying: Sophos

In addition, 49% think "crippling denial of service attacks against another country's communication or financial websites" is OK during wartime

Tue, 3 Aug 2010 17:36:00 EDT

Building Botnets For Fun And Profit

Creating a botnet business can be lucrative -- and isn't as hard as you might think, Black Hat speaker says

Tue, 3 Aug 2010 12:31:00 EDT

Ghost In The Machine: Database Weaknesses Expose SAP Deployments

Attacker can create a nearly undetectable user account in SAP once he or she gains unauthorized access

Tue, 3 Aug 2010 12:30:00 EDT

Researcher Reads RFID Tag From Hundreds Of Feet Away

Demonstration raises privacy and security concerns with RFID EPC Class 1 Generation 2 used in some passport cards, inventory tags, and drivers' licenses

Mon, 2 Aug 2010 17:46:00 EDT

Metasploit To Get More Powerful Web Attack Features

Rapid7 sponsors open-source w3af web assessment and exploit project

Sat, 31 Jul 2010 18:36:00 EDT

Researcher Intercepts GSM Cell Phones During Defcon Demo

In the wake of pressure from the FCC, security expert demonstrates major GSM hack

Fri, 30 Jul 2010 14:54:00 EDT

Former NSA, CIA Director Says Intelligence-Gathering Isn't Cyberwar

Efforts to crack U.S. cyberdefenses are standard operating procedure in the intelligence game, Hayden tells Black Hat audience

Fri, 30 Jul 2010 13:43:00 EDT

Most SSL Sites Poorly Configured

Half of all SSL servers run older, insecure version of SSL; attacks against HTTPS browser sessions detailed at Black Hat

Fri, 30 Jul 2010 08:50:00 EDT

Black Hat USA 2010: Complete Coverage

A round-up of articles leading up to and live coverage from Black Hat USA 2010, July 24 to 29, Law Vegas