Sponsored White Papers, Webcasts, and Downloads
ZDNet Dictionary Definition
- Attacker
- A person or other entity such as a computer program that attempts to cause harm to an information system; for example, by unauthorized access or denial of service. Human...
- Full Attacker Definition >>
ZDNet Resources
- Mozilla slaps band-aid on 11 Firefox flaws
- Mozilla has joined this week's patchapalooza with the release of a Firefox update to fix 11 documented security vulnerabilities. Six of the 11 issues are in advisories rated "critical" because of the risk of code execution attacks that could allow hackers to take complete control of a...
- Tags: Mozilla Firefox, Attacker, Flaw, JavaScript, Web Browser, Mozilla Corp., Firefox 3.0.11, Web Browsers, Security, Internet, Ryan Naraine
- Blog posts 2009-06-12
- Google plugs 'high risk' WebKit holes in Chrome
- Google has shipped a Chrome browser update to fix two serious security issues in WebKit. According to Google Chrome program manager Mark Larson, the most serious of the two flaws could allow hackers to execute harmful code in the browser's sandbox. It is rated "high severity."...
- Tags: Google Inc., Attacker, Web Browser, Google Chrome, Sandbox, Web Browsers, Security, Internet, Ryan Naraine
- Blog posts 2009-06-11
- Microsoft warns of new server vulnerability
- Microsoft warns of new server vulnerability Both Apache and IIS are pretty secureVery few actual vulneralities are found in any of the products. I would wager a bet that 99.999% of successful attacks from the latest years were through the application layer or a misconfiguration.I agree with you.My response was...
- Tags: OPEN SOURCE, SECURITY, server, Microsoft Corp., Apache Software Foundation, attacker, software
- Discussion threads 2009-05-19
- Critical security hole in Google Chrome
- For the second time in two weeks, Google has shipped a new version of its Chrome browser to fix a pair of serious security vulnerabilities. One of the two flaws carry a "critical" rating because of the risk of code execution with the privileges of the logged...
- Tags: Google Inc., Attacker, Web Browser, Google Chrome, Web Browsers, Security, Internet, Ryan Naraine
- Blog posts 2009-05-06
- Adobe plugs hole in Flash Media Server
- Adobe has shipped a Flash Media Server patch to fix a vulnerability that allowed attackers to execute remote procedures in Flash Media Interactive Server or Flash Media Streaming Server. The update is available for Adobe Flash Media Streaming Server 3.5.1, Adobe Flash Media Interactive Server 3.5.1...
- Tags: Adobe Systems Inc., Attacker, Media Server, Server, RPC, Security, Networking, Ryan Naraine
- Blog posts 2009-05-01
- Five 'must-secure' Web app vulnerabilities
- Security holes in the Apache Geronimo Application Server and SAP cFolders headline a list of five serious Web app vulnerabilities that demand immediate attention. According to Mark Painter from the HP Security Laboratory, the Geronimo flaws expose users to a variety of attack vectors that could lead...
- Tags: Novell Inc., Apache Geronimo, Attacker, Vulnerability, XSS, Web Application, SAP AG, Attack, Authentication Credential, SAP cFolders SAP cFolders, CS Whois Lookup CS Whois Lookup, Security, Ryan Naraine
- Blog posts 2009-04-29
- Mozilla patches a dozen Firefox vulnerabilities
- Mozilla has shipped a refresh of its flagship Firefox browser to fix a dozen documented vulnerabilities that expose users to URL spoofing, cross-site scripting, code injection and code execution attacks. The most serious fix (MFSA 2009-14) covers four browser engine and JavaScript engine crashes where Mozilla's developers...
- Tags: Mozilla Firefox, Attacker, Vulnerability, Patch Management, Web Browser, Mozilla Corp., Memory Corruption, Web Browsers, Security, Internet, Ryan Naraine
- Blog posts 2009-04-22
- New Skype Vulnerability Discovered
- A new phishing attack demonstrated by the folks over at Secure Science allows hackers to gain access to a user's Skype client and then pose as a financial institution or proxy outbond calls. The technique is called "SkypeSkrayping†and is similar to a phishing attacking only a bit more interactive:...
- Tags: Attacker, Vulnerability, Skype Technologies S.A., Phishing, Security, Viruses And Worms, Spam And Phishing, Dave Greenfield
- Blog posts 2009-04-13
- Attackers pounce on Microsoft PowerPoint zero-day
- Attackers are using rigged PowerPoint files to exploit an unpatched vulnerability in Microsoft's presentation software, according to warning late Thursday from the software maker. In a pre-patch advisory, Microsoft described the attacks as "limited and targeted," the kind of language that suggests it is being used to...
- Tags: Attacker, Microsoft PowerPoint, Microsoft Corp., Microsoft Office, Office Suites, Software, Ryan Naraine
- Blog posts 2009-04-02
- Web 2.0 Expo: Top ten Web hacking techniques
- A large portion of the Web 2.0 Expo attendees are focused on content. They want to create better, more engaging content for social media programs and Web engagement with their customers. But the Web and application developers behind this content need to know how to secure it. This is what...
- Tags: Technique, Web, Web 2.0, Hacking, Attacker, Attack, Clickjacking, Channel Management, Security, Marketing, Jennifer Leggio
- Blog posts 2009-04-01
- A Link Signature Based DDoS Attacker Tracing Algorithm Under IPv6
- The ipv6 security architecture, IPSec, plays a positive role in the protection of IPv6 networks. To some special attacks, especially DDoS attacks, IPSec appears relatively weak, because IPSec can only defend against DDoS attacks that spoof their source addresses. In cases where attackers launch DDoS attacks with their real identity,...
- Tags: Algorithm, IPv6, Attacker, Distributed Denial Of Service, IPSec, VPNs, Security, Networking
- White papers 2009-04-01
- Scribattle Lite 1.0.2 (Mobile)
- Fight off wave after wave of alien attackers, using your fingertips to do battle with swarms of Scri, furious Flingers, and pernicious Pents. Exclusively on iPhone and iPod Touch! Scribattle is a fast-paced game where you must help your warriors defend their planet from a hostile invasion. Use touch controls...
- Tags: Attacker, Mobile, Wave, Scribattle, Security
- Software downloads 2009-03-17
- One-year-old (unpatched) Windows 'token kidnapping' under attack
- Exactly one year after a security researcher notified Microsoft of a serious security vulnerability affecting all supporting version of Windows (including Vista and Windows Server 2008), the issue remains unpatched and now comes word that there are in-the-wild exploits circulating. The vulnerability, called token kidnapping (.pdf), was...
- Tags: Attacker, Server, Microsoft Corp., Attack, Microsoft Windows, Security, Operating Systems, Software, Ryan Naraine
- Blog posts 2009-03-16
- URL rewriting can help thwart Web app attacks
- A Microsoft Web application security specialist is suggesting an offbeat defense-in-depth strategy to protect Web sites and applications from cross-site scripting XSS and cross-site request forgery XSRF attacks. According to Bryan Sullivan, security program manager for Redmond's Security Development Lifecycle team, Web developers should consider URL Rewriting...
- Tags: Hyperlink, Attacker, Vulnerability, XSS, Web Application, Attack, Microsoft Web Application Security Specialist, Bryan Sullivan, E-mail, Security, Online Communications, Ryan Naraine
- Blog posts 2009-02-27
- Heads-up: Critical Adobe Flash Player patch coming
- [ UPDATE: Here's the official alert from Adobe with information on the patch. It covers a total of five vulnerabilities and affects Flash Player 10.0.12.36 and earlier ] Sometime later today, Adobe will issue a patch for at least one critical vulnerability affecting its ubiquitous Flash Player. ...
- Tags: Adobe Systems Inc., Shockwave, Attacker, Vulnerability, Macromedia Flash Player, Adobe Flash Player, iDefense, Shockwave Flash, Security, Patches, Ryan Naraine
- Blog posts 2009-02-24
- Inside Microsoft's February patch batch
- Guest post by Eric Schultze It's a seemingly light batch of patches this month, trailing an even lighter, single patch release in January. Two critical items were released -- including patches for Internet Explorer 7 and Microsoft Exchange Server. Additionally, two "important" items...
- Tags: Microsoft Visio, Attacker, Microsoft SQL Server, Microsoft Exchange Server, Microsoft Internet Explorer 7, Patch Management, Microsoft Corp., MS09-002, MS09-003, MS09-004, MS09-005, Patches, Servers, Security, Databases, Hardware, Enterprise Software, Software, Data Management, Ryan Naraine
- Blog posts 2009-02-11
- Kaspersky suffers attack on support site, no apparent data breach
- Word came out this weekend that the U.S. support site for the AV Vendor Kaspersky Labs was compromised by attackers. Earlier this week an attacker used a SQL Injection attack to compromise a section of the usa.kaspersky.com website and posted a list of database tables fetched via...
- Tags: Kaspersky Lab, Attacker, Attack, Kaspersky, Security, Databases, Enterprise Software, Software, Data Management, Adam O'Donnell
- Blog posts 2009-02-09
- Mozilla plugs 7 security holes in Firefox
- Mozilla's flagship Firefox 3 browser has undergone another security makeover to fix at least 7 documented security vulnerabilities that expose users to malicious hacker attacks. The Firefox 3.0.6 upgrade patches at least two critical Firefox flaws that may lead to arbitrary code execution attacks and another "high...
- Tags: Mozilla Firefox, Attacker, Vulnerability, JavaScript, Severity, Web Browser, Mozilla Corp., Firefox 2 Release, Web Browsers, Security, Internet, Ryan Naraine
- Blog posts 2009-02-04
- MS Patch Tuesday: 3 critical SMB vulnerabilities
- Microsoft today shipped a solitary bulletin with patches for at least three documented security flaws in the Microsoft Server Message Block SMB Protocol. The three vulnerabilities, rated "critical" on Windows 2000, Windows XP and Windows Server 2003, exposes Windows users to remote code execution attacks, Microsoft said...
- Tags: Attacker, Vulnerability, Patch Management, Microsoft Corp., Worm, Small And Medium Business, Microsoft Windows, Security, Cyberthreats, Viruses And Worms, Operating Systems, Software, Ryan Naraine
- Blog posts 2009-01-13
- Live Baiting for Service-Level DoS Attackers
- Denial-of-Service DoS attacks remain a challenging problem in the Internet. In a DoS attack the attacker is attempting to make a resource unavailable to its intended legitimate clients. Furthermore, in order to employ massive attack power, the attacker usually launches a Distributed Denial of Service DDoS attack, in which several...
- Tags: Denial Of Service, Attacker, Attack, Security
- White papers 2009-01-01

Introducing SmartPlanet
-
-
Find thought-provoking progressive ideas on topics that intersect with technology, business and life.
Visit Today
-
-
Technology, perspective, and insights shaping the world
-
Learn innovative and practical skills for your business and your life. SmartPlanet offers 360 degree coverage that you need to feel connected to the information that matters to the world at large.
Go to SmartPlanet
White Papers and Webcasts