Sponsored White Papers, Webcasts, and Downloads
ZDNet Resources
- U.S. Army servers breached by Turkish hackers
- U.S. Army servers breached by Turkish hackers A question that puzzles meWhy on Earth is an US Army's Ammunition Plant and an US Army Corps of Engineers running insecure software from M$, more precisely Microsoft SQL Server?Presumably there are many other critical US institutions running dangerous software from M$. The...
- Tags: Databases, SECURITY, Servers, server, SQL injection, Turkish Hackers, SQL, Microsoft SQL Server, Microsoft Corp., vulnerability, U.S. Army
- Discussion threads 2009-06-01
- High-profile New Zealand websites hacked
- High-profile New Zealand websites hacked "and no one hates Microsoft more than linux fanboys."Eh? How 'bout iFanbois?RE: High-profile New Zealand websites hacked Had to be a linux fanboy. No one else would commit such a horrible crime and we know what a bunch of ruthless savages linux users can be....
- Tags: Scripting languages, Programming languages, Operating systems, UNIX, SECURITY, OPEN SOURCE, SQL injection, SQL, Linux, High-profile New Zealand website, vulnerability, linux fanboy, fanboy, SQL Injection vulnerability
- Discussion threads 2009-04-21
- Hackers hijack DNS records of high profile New Zealand sites
- Hackers hijack DNS records of high profile New Zealand sitesHackers hijack DNS records of high profile New Zealand sitesThis shows that linux users have no respect for others. When they target Microsoft like this it only makes them and their community look bad. And then they wonder why nobody...
- Tags: Domain names, Scripting languages, Operating systems, UNIX, OPEN SOURCE, Linux, DNS Records, Mac Zealots, wet paper bag, paper bag, PHP, SQL injection, DNS, SQL, operating system
- Discussion threads 2009-04-21
- International Kaspersky sites susceptible to SQL injection attacks
- According to a security group going under the name of TeamElite, the international sites of Kaspersky Iran (kasperskylabs.ir), Taiwan (web.kaspersky.com.tw) and South Korea (kasperskymall.co.kr) are susceptible to SQL injection attacks, allowing the injection of malicious iFrames and potentially assisting malicious attackers into obtaining sensitive data from the web sites in...
- Tags: Web, SQL, Web Site, SQL Injection, Web Site Development, Channel Management, Web Technology, Security, Internet, Marketing, Dancho Danchev
- Blog posts 2009-03-10
- Black market for zero day vulnerabilities still thriving
- One would assume that popular sources for zero day vulnerabilities+Poc's such as Full-Disclosure, Bugtraq or Milw0rm are the primary sources for obtaining responsibly or irresponsibly released flaws. They'd be wrong. The black market for zero day vulnerabilities and the concept of over-the-counter OTC trade of zero day flaws, has been...
- Tags: Web, Vulnerability, Web Application, SQL Injection, Exploit, Day Vulnerability, E-shop, Security, Dancho Danchev
- Blog posts 2008-11-02
- What Is SQL Injection?
- SQL injection is a technique used to take advantage of non-validated input vulnerabilities to pass SQL commands through a Web application for execution by a backend database. Attackers take advantage of the fact that programmers often chain together SQL commands with user-provided parameters, and can therefore embed SQL commands inside...
- Tags: SQL, SQL Injection, SecPoint, Programming Languages, Databases, Software Development, Software/Web Development, Enterprise Software, Software, Data Management
- White papers 2008-09-13
- Sony PlayStation's site SQL injected, redirecting to rogue security software
- The latest high trafficked web site to fall victim into the continuing waves of massive SQL injection attacks courtesy of copycats and the ASProx botnet, is Sony's PlayStation U.S site according to a recent post at SophosLabs's blog : "Researchers at IT security firm Sophos have warned lovers of...
- Tags: Sony Corp., Domain, SQL, Sony Playstation, SQL Injection, Hacker, Programming Languages, Game Players, Databases, Security, Software Development, Software/Web Development, Consumer Electronics, Personal Technology, Enterprise Software, Software, Data Management, Dancho Danchev
- Blog posts 2008-07-02
- Microsoft ships free code auditing tools to thwart SQL injection attacks
- Microsoft ships free code auditing tools to thwart SQL injection attacksSQLs failureSQL's #1 failure is its ailing concept that a single string is a sufficient API. Its stronger APIs are left in disuse by those who advocate this policy. Injection follows.I've never heard of a perl script falling...
- Tags: Programming languages, Databases, Scripting languages, Scrawlr, auditing, Microsoft Corp., SQL, SQL injection
- Discussion threads 2008-06-24
- Microsoft ships free code auditing tools to thwart SQL injection attacks
- On the heels of a dramatic rise in SQL injection attacks linked to drive-by malware downloads, Microsoft has released aimed at helping Webmasters and IT administrators block and eradicate this attack class. According to a security advisory from the Redmond, Wash. software giant, the tools are...
- Tags: Vulnerability, Auditing, SQL, Microsoft Corp., SQL Injection, Tool, Scrawlr, Programming Languages, Security, Databases, Software Development, Software/Web Development, Enterprise Software, Software, Data Management, Ryan Naraine
- Blog posts 2008-06-24
- Michael Howard on SQL Injection and my concerns on the most recent attacks
- Michael Howard on SQL Injection and my concerns on the most recent attacksvotes are off8 votes right now: No for 1st is 100% & Yes is 13%, same for 2nd, exception Yes & No percentages are switched. Poll bug?now they're goodAt 9 votes, they show up correctlyWeirdStrange... wonder what happened.-Nate
- Tags: SECURITY, Michael Howard, SQL injection, SQL
- Discussion threads 2008-05-29
- Michael Howard on SQL Injection and my concerns on the most recent attacks
- So, in catching up with blogs after vacation, I went and had a peak at Michael Howard's web log, and was glad to see another post from him. His posts are very insightful I just wish he would post more. So, way back on May 16th (old news now, but still...
- Tags: Web, SQL, SQL Injection, Attack, Michael Howard, SQL Payload, SDL, Programming Languages, Databases, Security, Software Development, Software/Web Development, Enterprise Software, Software, Data Management, Nathan McFeters
- Blog posts 2008-05-29
- Tracking down the Storm Worm malware
- What is the current state of Storm Worm activity, how many infected IPs are found to host the malware on a daily basis, which are the latest domains used by the Storm Worm, and which countries have the largest infected population? You can easily find that out, if you keep...
- Tags: Malware, SQL, SQL Injection, TrustedSource, Spyware, Adware & Malware, Cyberthreats, Security, Programming Languages, Software Development, Software/Web Development, Dancho Danchev
- Blog posts 2008-05-26
- Over 1.5 million pages affected by the recent SQL injection attacks
- Over 1.5 million pages affected by the recent SQL injection attacksSo...Was this the programmers' fault? That's the tale that was trotted out with the previous 0.5 million SQL-injected sites story.
- Tags: Programming languages, SECURITY, SQL, SQL injection
- Discussion threads 2008-05-20
- Over 1.5 million pages affected by the recent SQL injection attacks
- In an attempt to mitigate the impact of the recent waves of SQL injection attacks, and provide more transparency into the approximate number of affected pages, the Shadowserver Foundation is starting to maintain a list of all the malicious domains used in the continuing efforts by copycats to inject as...
- Tags: Domain, SQL, SQL Injection, Shadowserver, Security, Dancho Danchev
- Blog posts 2008-05-20
- The Storm Worm would love to infect you
- The Storm Worm malware is back in the game, with its most recent campaign currently active and trying to entice users into executing iloveyou.exe by spamming them with links to already infected hosts acting as web servers, next to SQL injecting malicious domains into legitimate sites for the campaign to...
- Tags: JavaScript, SQL, Worm, SQL Injection, Host, Storm Worm, Storm Worm Malware, Scanners, Cyberthreats, Scripting Languages, Programming Languages, Security, Databases, Viruses And Worms, Hardware, Peripherals, Software/Web Development, Web Development, Software Development, Enterprise Software, Software, Data Management, Dancho Danchev
- Blog posts 2008-05-19
- Fast-Fluxing SQL injection attacks executed from the Asprox botnet
- Fast-Fluxing SQL injection attacks executed from the Asprox botnetExfiltration?Dancho, are you seeing any exfiltration of data through these mass SQL Injection attacks? I have a few clients who have been hit as well.-Nate
- Tags: Tools & Techniques, SECURITY, Fast-Fluxing SQL injection attack, Asprox, software
- Discussion threads 2008-05-19
- Fast-Fluxing SQL injection attacks executed from the Asprox botnet
- The botnet masters behind the Asprox botnet have recently started SQL injecting fast-fluxed malicious domains in order to enjoy a decent tactical advantage in an attempt to increase the survivability of the malicious campaign. I first assessed the Asprox botnet in January, and again in April when it started scaling...
- Tags: Microsoft .NET, Domain, SQL, SQL Injection, Asprox, Com, Programming Languages, Phishing, Databases, Security, Software Development, Software/Web Development, Spam And Phishing, Enterprise Software, Software, Data Management, Dancho Danchev
- Blog posts 2008-05-19
- Redmond Magazine Successfully SQL Injected by Chinese Hacktivists
- Irony at its best. It appears that Redmond - The Independent Voice of the Microsoft IT Community, formerly known as Microsoft Certified Professional Magazine is currently flagged as a badware site, and third-party exploit detection tools are also detecting internal pages as exploit hosting ones, in this particular case Mal/Badsrc-A....
- Tags: Redmond, SQL, SQL Injection, F**k, Mal/Badsrc-A, Programming Languages, Databases, Security, Software Development, Software/Web Development, Enterprise Software, Software, Data Management, Dancho Danchev
- Blog posts 2008-05-16
- News to know: Psystar; IT Dojo; Microsoft moral; SQL Injection attacks; Ubuntu
- Notable headlines: David Morgenstern: Is Psystar Mac clone using the Kalyway boot hack? IT Dojo: Create your own bootable USB flash drive for Windows XP Mary Jo Foley: Microsoft internal memo details Windows 7-Windows Live ties Another reason...
- Tags: Ubuntu, Google Inc., Larry Dignan, Information Technology, Microsoft Office, Yahoo! Inc., SQL, Microsoft Corp., SQL Injection, Microsoft Windows, Microsoft Windows XP, Operating Systems, Strategy, Software, Management
- Blog posts 2008-04-29
- Developers at fault? SQL Injection attacks lead to wide-spread compromise of IIS servers
- Developers at fault? SQL Injection attacks lead to wide-spread compromise of IIS serversAh yes, the technology me-too'smaking the most basic of errors.On a less dangerous level, if you look at the HTML & CSS source of web sites, the most appallingly written ones are most often on IIS.This is...
- Tags: SECURITY, Microsoft IIS Server, SQL injection, HTML, CSS, SQL, Microsoft Corp., server
- Discussion threads 2008-04-28
Smartphones
-
Last year, many businesses deferred the purchase of new laptops in favor of smartphones, and why not? Offering phone, calendar, email, IM and Web access, they're arguably the most practical business tools. Check out the latest CNET Reviews of Blackberry devices for all the knowledge you need to make an intelligent choice.
-
Sleek. Thin. Light.
-
With its full keyboard and high-res screen, the BlackBerry® Curve 8900 is the perfect fit for your work and your life.
Learn more
White Papers and Webcasts