News
IT security
-
August 16, 2005
16
Aug'05
Reduce risks of disaster recovery testing
Untested business continuity plans can leave your firm in the lurch, but taking down live environments is risky and complicated.
-
August 10, 2005
10
Aug'05
Strategic Storage: Storage security -- Change old habits and stop data theft
-
August 06, 2005
06
Aug'05
Trusted Computing Group releases server specs
The Trusted Computing Group released a new set of trusted server specifications it hopes will help vendors protect their platforms against security breaches.
-
August 02, 2005
02
Aug'05
Raising risk prospects with a new SQL injection threat
"Inference attacks" could deliver up your so-called secure database to an attacker.
-
July 31, 2005
31
Jul'05
Attack: USB could be the death of me
Seemingly innocent Universal Serial Bus driver bugs may allow device attacks that many won't see coming, according to Black Hat presenters.
-
July 28, 2005
28
Jul'05
Sarbox compliance costing companies
Companies’ required investments to attain compliance with the Sarbanes-Oxley data security legislation has come at the expense of dealing with other security threats, according to the Information Security Forum (ISF).
-
July 27, 2005
27
Jul'05
Cisco, Black Hat litigation comes to a close
The vendor and partner ISS settle their dispute over a presentation that resulted in criminal charges and cease and desist orders.
-
July 26, 2005
26
Jul'05
VeriSign raises stakes in battle for threat intelligence
Not to be outdone by 3Com's "Zero-Day Initiative," VeriSign says it'll shell out more cash for hackers who provide vulnerability intelligence.
-
July 26, 2005
26
Jul'05
Experts weigh in on spyware's defining moment
We asked IT professionals to review the spyware definitions proposed by a coalition of tech firms and security organizations. They found plenty of room for improvement.
-
July 26, 2005
26
Jul'05
VoIP encryption to have 'Pretty Good Privacy
-
July 24, 2005
24
Jul'05
Authentication takes a bite out of spam
Network and messaging experts offer helpful ammunition for network managers waving the white flag in the battle against spam.
-
July 21, 2005
21
Jul'05
Users look for value boost from Microsoft licence rejig
Software Assurance needs to offer better support, say IT directors
-
July 21, 2005
21
Jul'05
Sarbox draining corporate security budgets
Corporate investment to comply with the Sarbanes-Oxley data security legislation has come at the expense of dealing with other security threats, according to the Information Security Forum (ISF).
-
July 21, 2005
21
Jul'05
Can alcohol mix with your key personnel?
I persuaded our MD to hire a dedicated IT security expert. I am pleased with his work, but on several occasions he has smelled strongly of drink. How do I nip this in the bud?
-
July 20, 2005
20
Jul'05
Pop quiz: E-mail security
Find out how much you know about securing your organization's e-mail.
-
July 12, 2005
12
Jul'05
Sarbox challenge drains security budgets
International corporate spending on compliance with the Sarbanes-Oxley data security legislation has come at the expense of dealing with other security threats, according to the Information Security Forum.
-
July 06, 2005
06
Jul'05
This is not your father's hacker
While Sasser author Sven Jaschan awaits the outcome of his trial this week in Germany, a new cybercrime report explains why the teenager is becoming an anachronism.
-
July 06, 2005
06
Jul'05
PING with Karen Worstell
The Microsoft CISO discusses how she keeps Redmond and its products secure.
-
July 04, 2005
04
Jul'05
Sasser author issues courtroom confession
Sven Jaschan's mea culpa was expected after he earlier admitted to creating the last major malware outbreak more than a year ago.
-
June 21, 2005
21
Jun'05
Continuing education options for CISSPs: Top 10 ways to earn CPEs
Who says you can't have fun while earning CPE credits? Check out the top 10 ways to meet CISSP® and SSCP continuing professional education requirements.
-
June 13, 2005
13
Jun'05
Gartner underscores five overblown threats
Two Gartner analysts debunk five overhyped security risks they claim are causing companies to miss out on some key emerging technologies.
-
June 07, 2005
07
Jun'05
Latest Mytob worms phish for trouble
Mytob's data-drumming tactics and the appearance of new Trojan horse programs add to concern that the underground is perfecting ingredients for a major attack.
-
June 06, 2005
06
Jun'05
Spyware removal checklist
A step-by-step guide on how to remove spyware using antispyware tools including Spybot -- Search and Destroy, and HijackThis.
-
June 06, 2005
06
Jun'05
Know your enemy: Why your Web site is at risk
In this Lesson 1 technical paper from Web Security School, guest instructor Michael Cobb outlines the threats to Web sites and who is behind them.
-
June 06, 2005
06
Jun'05
Developer's active content delivery checklist
Rules for developing secure dynamic content for an IIS Web server.
-
June 05, 2005
05
Jun'05
Quiz: Secure Web directories and development, answer No. 3
Quiz: Secure Web directories and development, answer No. 3
-
June 05, 2005
05
Jun'05
Quiz: Secure Web directories and development, answer No. 4
Quiz: Secure Web directories and development, answer No. 4
-
June 05, 2005
05
Jun'05
Quiz: Secure Web directories and development, answer No. 5
Quiz: Secure Web directories and development, answer No. 5
-
June 05, 2005
05
Jun'05
Quiz: Secure Web directories and development, answer No. 1
Quiz: Secure Web directories and development, answer No. 1
-
June 05, 2005
05
Jun'05
Quiz: Secure Web directories and development, answer No. 2
Quiz: Secure Web directories and development, answer No. 2
-
June 05, 2005
05
Jun'05
Analysts say 'cloudy' forecast is OK
-
June 05, 2005
05
Jun'05
Compliance shouldn't be a primary security driver
-
June 05, 2005
05
Jun'05
Quiz: Secure Web directories and development
Evaluate your knowledge of Web threats and how to defeat them. Questions cover security risks of dynamically created content and proper security management.
-
June 04, 2005
04
Jun'05
Top tools for testing your online security, part 2
Michael Cobb explains what tools are helpful in maintaining Web security, including security scanners, benchmarking tools, monitoring services and online resources.
-
June 04, 2005
04
Jun'05
Top tools for testing your online security
Learn a structured approach for Web security that can make your security management tasks easier and increase your chances of success.
-
June 04, 2005
04
Jun'05
Life at the edge part 3: Resistance to failure
Learn how architecture, protocol and application-level protections work together to safeguard a Web infrastructure.
-
June 04, 2005
04
Jun'05
Life at the edge part 4: When things go wrong
A checklist and other hints to protect your Web servers from a worst-case scenario.
-
June 04, 2005
04
Jun'05
Life at the edge part 2: Divide and conquer with DMZs
Learn how a DMZ works and how it can protect Web servers.
-
June 03, 2005
03
Jun'05
Quiz: Identify and analyze Web server attacks, answer No. 5
Quiz: Identify and analyze Web server attacks, answer No. 5
-
June 03, 2005
03
Jun'05
Quiz: Identify and analyze Web server attacks
Test your knowledge of the material covered in the "Identify and analyze Web server attacks" section of Intrusion Defense School.
-
June 03, 2005
03
Jun'05
Quiz: Identify and analyze Web server attacks, answer No. 3
Quiz: Identify and analyze Web server attacks, answer No. 3
-
June 02, 2005
02
Jun'05
Quiz: Web attack prevention and defense
Test your knowledge of the material covered in Web attack prevention and defense, including the fundamentals of securing a Web server.
-
June 01, 2005
01
Jun'05
Zombie machines used in 'brutal' SSH attacks
IT managers use SSH to gain secure access to remote computers. Hackers are using it to crack your network, with help from their zombie friends.
-
May 31, 2005
31
May'05
Network configuration: IIS SMTP mail relay service and Microsoft Exchange Server
Learn how to use the IIS SMTP mail relay service to prevent spammers from directly interacting with your Microsoft Exchange Server.
-
May 29, 2005
29
May'05
Patching resource kit
From vulnerability scanning to patching flubs, here's a collection of other helpful resources to ensure your patching efforts are effective.
-
May 23, 2005
23
May'05
Pre-CISSP: Options for the security newbie
Shon Harris advises novice security practitioners on the value of entry-level certifications -- and good, old-fashioned experience -- in preparation for the CISSP®.
-
May 17, 2005
17
May'05
Should the government define spyware?
Who's best qualified to define what is and isn't spyware -- your congressman or your online user community? Security experts say no entity can do it alone.
-
May 17, 2005
17
May'05
Some vendors get labeled as spyware pushers
To win the battle with spyware, you must be able to spot it. That's not as easy as you think.
-
May 11, 2005
11
May'05
A new era of computer worms: Wireless mobile worms
In this excerpt of Chapter 9 from "The Art of Computer Virus Research and Defense," author Peter Szor dissects the Cabir worm.
-
April 14, 2005
14
Apr'05
Who should be on (and off) the hook for ID theft?
An influential cryptographer and a panel of technologists today debate how best to fight false authentication and fraudulent transactions.