
Sponsored White Papers, Webcasts, and Downloads
ZDNet Resources
- Apple monster update fixes iPhone, Safari, Mac OS X flaws
- LAS VEGAS -- Apple has issued a monster update with patches for about 50 security vulnerabilities affecting iPhone, Safari and Mac OS X users.In a race against the clock, the company rushed out iPhone v1.0 with fixes for four different vulnerabilities that could allow hackers to take full control of...
- Tags: Zero-day attacks, Windows Vista, Vulnerability research, Viruses and Worms, Spyware and Adware, Responsible disclosure, Pen testing, Patch Watch, Open source, Mozilla, Metasploit, McAfee, Hackers, Google, Digital rights management, Data theft, Browsers, Botnets, Black Hat, Apple
- Blog posts 2007-07-31
- German hacker denied entry into U.S. for Black Hat training
- Thomas Dullien, a prominent security researcher who has been a fixture at the annual Black Hat security conference, has been denied entry into the U.S. to attend and conduct training at this year's confab.Dullien left, a German reverse engineering whiz known in hacker circles as "Halvar Flake," said he was...
- Tags: Zero-day attacks, Windows Vista, Vulnerability research, Viruses and Worms, Responsible disclosure, Pen testing, Patch Watch, Passwords, Microsoft, Metasploit, Hackers, Exploit code, Digital rights management, Data theft, Cisco, Browsers, Botnets, Black Hat
- Blog posts 2007-07-29
- Some great security apps are still free
- Last week, I wrote dismissively about Symantec adding a $29.99 a year price tag on its new Norton AntiBot technology, calling it a bit of a con job to sell all these different security tools to protect users against malware.Well, it turns out that there are some great FREE security...
- Tags: Data theft, Browsers, Botnets, Apple, Digital rights management, Exploit code, Firefox, Hackers, McAfee, Metasploit, Mozilla, Open source, Passwords, Patch Watch, Pen testing, Privacy, Rootkits, Spam and Phishing, Spyware and Adware, Viruses and Worms, Vulnerability research, Wi-Fi security, Zero-day attacks
- Blog posts 2007-07-25
- CEO out in Core Security shake-up
- Core Security Technologies, one of a handful of companies hawking penetration testing tools to businesses, is looking for a new CEO to replace Paul Paget.According to an analyst report from The 451 Group, there are red flags about the future of Core after news emerged that Paget and product manager...
- Tags: Zero-day attacks, Vulnerability research, Spyware and Adware, Responsible disclosure, Pen testing, Patch Watch, Passwords, Open source, Microsoft, Metasploit, Hackers, Google, Firefox, Exploit code, Digital rights management, Data theft, Browsers, Botnets, Black Hat
- Blog posts 2007-07-23
- Firefox raises barrier to cross-site scripting attacks
- Mozilla has quietly fitted a new security feature into the latest Firefox update, adding the ability for the browser to prevent cross-site scripting attacks.The change, which was not officially announced, implements httpOnly cookies in Firefox 2.0.0.5, the most recent refresh of the open-source browser.Web application security experts are welcoming the...
- Tags: Zero-day attacks, Windows Vista, Wi-Fi security, Vulnerability research, Viruses and Worms, Spyware and Adware, Spam and Phishing, Rootkits, Responsible disclosure, Pen testing, Patch Watch, Passwords, Open source, Mozilla, Microsoft, Hackers, Google, Firefox, Exploit code, Digital rights management, Data theft, Browsers, Botnets, Apple
- Blog posts 2007-07-19
- Symantec puts price tag on anti-botnet tool
- Symantec's new Norton AntiBot utility is now out of beta, promising to remove zombies from for-profit botnets scourge in exchange for $29.99 a year.The anti-botnet tool see previous coverage here is being marketed as "complementary solution to existing antivirus or security suites," adding yet another application to the list of...
- Tags: Zero-day attacks, Vulnerability research, Viruses and Worms, Symantec, Spyware and Adware, Spam and Phishing, Rootkits, Responsible disclosure, Pen testing, Patch Watch, Passwords, Open source, Microsoft, Metasploit, Hackers, Google, Firefox, Exploit code, Digital rights management, Data theft, Browsers, Botnets
- Blog posts 2007-07-17
- Microsoft should block that IE > Firefox attack vector
- The ongoing confusion over the IE -> Firefox security vulnerability that introduces a nasty attack vector for Windows users with both browsers installed has raised a serious question about the responsibility of software vendors to protect its customers.First, a quick recap: Thor Larholm releases proof-of-concept for what he calls an...
- Tags: Apple, Botnets, Browsers, Data theft, Digital rights management, Google, Metasploit, Microsoft, Mozilla, Open source, Passwords, Patch Watch, Pen testing, Responsible disclosure, Vulnerability research, Windows Vista, Zero-day attacks
- Blog posts 2007-07-11
- Breaking open the iPhone
- Hardware hackers at iFixit are disassembling the iPhone in real time, providing the first look inside the belly of the beast. Hop on over and enjoy the show.
- Tags: Vulnerability research, Pen testing, Hackers, Digital rights management, Data theft, Apple
- Blog posts 2007-06-29
- TippingPoint heading for IPO door
- Less than three years after shelling out $430 million to acquire TippingPoint, 3Com plans to spin out the unit in a planned IPO later this year.The IPO plan, according to 3Com chief executive Edgar Masri, allows the networking vendor to "focus more closely on its core business." ...
- Tags: Vulnerability research, Responsible disclosure, Privacy, Pen testing, Patch Watch, Metasploit, Hackers, Exploit code, Digital rights management, Data theft, Browsers, Black Hat
- Blog posts 2007-06-29
- Rutkowska faces '100% undetectable malware' challenge
- At last year's Black Hat security conference, stealth malware researcher Joanna Rutkowska caused a stir with the introduction of Blue Pill, a new technology she claims can create malware that remains "100 percent undetectable."This year, a group of her peers will challenge Rutkowska to prove it, arguing that a...
- Tags: Zero-day attacks, Windows Vista, Vulnerability research, Viruses and Worms, Spyware and Adware, Rootkits, Responsible disclosure, Punditocracy, Pen testing, Patch Watch, Open source, Microsoft, Metasploit, Hackers, Exploit code, Digital rights management, Data theft, Browsers, Botnets, Apple
- Blog posts 2007-06-27
- Code execution hole haunts RealPlayer, HelixPlayer
- RealNetworks has issued a security fix for a gaping hole in its flagship RealPlayer software but, strangely, the company has not issued a security advisory to warn its millions of customers.Instead, the required warning came from the researchers at iDefense Labs who found a remotely exploitable security hole affecting both...
- Tags: Zero-day attacks, Vulnerability research, Viruses and Worms, Responsible disclosure, Pen testing, Patch Watch, Open source, Metasploit, Hackers, Exploit code, Digital rights management, Data theft, Browsers, Botnets
- Blog posts 2007-06-27
- The iPhone security non-story
- David Maynor is hoarding his Safari browser flaws with his eyes on the iPhone.As far back as January, hackers were asking questions about the iPhone CPU and preparing for attack scenarios.The first hacker that breaks into the iPhone will generate lots of headlines/publicity but that's right about where this story...
- Tags: Zero-day attacks, Vulnerability research, Viruses and Worms, Spyware and Adware, Spam and Phishing, Responsible disclosure, Punditocracy, Pen testing, Patch Watch, Passwords, Open source, Metasploit, Hackers, Exploit code, Digital rights management, Data theft, Browsers, Botnets, Apple
- Blog posts 2007-06-26
- There's a hole in your laptop, dear HP, dear HP
- The Help and Support Center utility that ships with HP laptops might be giving help to all the wrong people.According to a brief note from HP, there's a very serious vulnerability in the utility that could be used by hackers to seize control of Windows XP machines."[This update fixes] a...
- Tags: Botnets, Browsers, Data theft, Digital rights management, Exploit code, Hackers, Metasploit, Microsoft, Patch Watch, Pen testing, Piracy, Responsible disclosure, Rootkits, Viruses and Worms, Vulnerability research, Zero-day attacks
- Blog posts 2007-06-14
- Apple plugs three Safari for Windows holes
- Apple has responded swiftly to the discovery of vulnerabilities in its new Safari for Windows browser, rushing out fixes for a trio of potentially dangerous security flaws.The new Safari 3.0.1 Public Beta confirms and fixes a remote code execution hole found by Danish hacker Thor Larholm and two other undocumented...
- Tags: Zero-day attacks, Vulnerability research, Viruses and Worms, Spyware and Adware, Spam and Phishing, Responsible disclosure, Pen testing, Patch Watch, Passwords, Open source, Metasploit, Hackers, Firefox, Exploit code, Digital rights management, Data theft, Browsers, Botnets, Apple
- Blog posts 2007-06-14
- 'Critical' Vista, IE 7 patches highlight MS security updates
- This month's batch of patches from Microsoft includes six bulletins covering at least 15 vulnerabilities, including several critical code execution holes in Windows Vista and Internet Explorer 7.In all, Redmond pushed out four critical bulletins with fixes for flaws that could put Windows users at risk of complete PC takeover...
- Tags: Zero-day attacks, Windows Vista, Vulnerability research, Responsible disclosure, Pen testing, Patch Watch, Passwords, Microsoft, Metasploit, Hackers, Exploit code, Digital rights management, Data theft, Browsers, Botnets
- Blog posts 2007-06-12
- Windows vs Linux security report card redux
- Orlando, Florida -- Jeff Jones has expanded his project to count security flaws publicly reported and fixed in the major workstation operating systems and his latest numbers show Windows Vista has by far the best security profile when compared to the major Linux distributions.Jeff Jones, security strategy director in Microsoft's...
- Tags: Apple, Black Hat, Botnets, Browsers, Data theft, Digital rights management, Exploit code, Firefox, Google, McAfee, Microsoft, Mozilla, Open source, Passwords, Patch Watch, Pen testing, Piracy, Responsible disclosure, Vulnerability research, Windows Vista, Zero-day attacks
- Blog posts 2007-06-06
- Mozilla downplays Zalewski's Firefox flaws
- Mozilla security chief Window Snyder is pouring cold water on a claim by an independent researcher that there's a major security hole in the Firefox browser.A day after Michal Zalewski went public with details of Firefox vulnerabilities he thinks could lead to code execution attacks, Snyder responded with a note...
- Tags: Zero-day attacks, Vulnerability research, Viruses and Worms, Spyware and Adware, Spam and Phishing, Rootkits, Responsible disclosure, Pen testing, Patch Watch, Passwords, Open source, Mozilla, Metasploit, Hackers, Google, Firefox, Exploit code, Digital rights management, Data theft, Browsers, Botnets
- Blog posts 2007-06-05
- Microsoft security guru: Get fuzzing
- Orlando, Florida -- Microsoft security whiz Michael Howard is urging developers in the Windows ecosystem to adopt fuzz testing as a critical part of the software creation process, stressing that the use of fuzzers can dramatically reduce the number of potential security vulnerabilities.Howard, co-author of a book on Microsoft's mandatory...
- Tags: Zero-day attacks, Windows Vista, Vulnerability research, Responsible disclosure, Punditocracy, Piracy, Pen testing, Patch Watch, Passwords, Open source, Microsoft, Metasploit, McAfee, Hackers, Google, Firefox, Exploit code, Digital rights management, Data theft, Browsers, Botnets
- Blog posts 2007-06-05
- Gaping holes exposed in fully-patched IE 7, Firefox
- Polish hacker Michal Zalewski has ratcheted up his ongoing assault on Web browser security models, releasing details on serious flaws in fully patched versions of IE 6, IE 7 and Firefox 2.0.Zalewski, a well-respected security researcher, published demos of four different browser vulnerabilities on the Full Disclosure mailing list, warning...
- Tags: Zero-day attacks, Vulnerability research, Spyware and Adware, Rootkits, Responsible disclosure, Privacy, Pen testing, Patch Watch, Passwords, Mozilla, Microsoft, Metasploit, Hackers, Google, Firefox, Exploit code, Digital rights management, Data theft, Browsers, Botnets, Black Hat
- Blog posts 2007-06-04
- Beware of that man between you and your Google Desktop
- Last month, I wrote a piece about Robert Hansens Mr-T (Master Recon-Tool), a powerful tool that harvests data leaking out of Web browsers. In the post, I talked about how these types of reconnaissance tools could be combined with sniffers and information from vulnerability databases to lay the groundwork...
- Tags: Zero-day attacks, Vulnerability research, Viruses and Worms, Spyware and Adware, Spam and Phishing, Rootkits, Responsible disclosure, Pen testing, Patch Watch, Passwords, Open source, Mozilla, Metasploit, Hackers, Google, Firefox, Exploit code, Digital rights management, Data theft, Browsers, Botnets
- Blog posts 2007-06-01
-
-
Smart Tech
Expert advice on innovations in healthcare and the green technologies that make it happen.
Find out more
-
Smart Business
Discussion and advice on management issues that revolve around making your world smarter and more useful.
More Smart Advice
-
Smart People
The best and worst moves in the management and strategy trenches.
Learn More
White Papers and Webcasts