On ZDNet: Twitter on your intranet
827 Resources for

vulnerability

  • Subscribe to this listing via:
  • RSS
  • Email

TechRepublic Resources

Security news roundup: Apple's DNS patch flawed
This week's security events includes news that the DNS patch released by Apple is flawed, a warning about the ease with which eavesdroppers can listen in to most wireless phone conversations, critical holes discovered in K9 Web Protection, and a DOS vulnerability in F-PROT's virus scanner. by Paul Mah
Tags: Phone, DNS, Vulnerability, Apple Inc., F-PROT, Scanners, Domain Names, Security, Wi-Fi, Wireless, Hardware, Peripherals, Internet, Paul Mah
Blog posts 2008-08-03
Security news roundup: Tool lets you resolve location of rogue Wi-Fi users
This week's security events includes news of a security update to the popular Thunderbird e-mail client, news of a buffer overflow in BEA WebLogic, exploits for DNS vulnerability released, and a tool that allows you to resolve the actual physical location of rogue Wi-Fi users. by Paul Mah
Tags: DNS, Vulnerability, Mozilla Thunderbird, Wi-Fi, Exploit, Tool, MoocherHunter, Security, Wireless, Paul Mah
Blog posts 2008-07-27
How FreeBSD makes vulnerability auditing easy: portaudit
Find out how FreeBSD's portaudit tool goes a long way toward helping you maintain a secure system, simply and easily. by Chad Perrin
Tags: Linux Distribution, FreeBSD, Vulnerability, Auditing, UNIX, Open Source, Operating Systems, Security, Software, Chad Perrin
Blog posts 2008-06-24
Is your site safe from SQL injection attacks?
Microsoft and HP announced yesterday that they are providing free tools to help network administrators to deal with the increase in SQL injection attacks over the last six months. by Andy Moon
Tags: Vulnerability, SQL, SQL Injection, Attack, Programming Languages, Security, Databases, Software Development, Software/Web Development, Enterprise Software, Software, Data Management, Andy Moon
Blog posts 2008-06-24
Security news roundup: New vulnerability affects Firefox 3
This week's security roundup includes a new vulnerability discovered in Firefox, Microsoft admitting to a mistake with a recent Bluetooth patch, the lack of any progress at cracking the Gpcode.ak ransomware, and the loss of NHS laptops that could expose the personal particulars of up to 30,000 patients. by Paul...
Tags: Mozilla Firefox 3.0, Mozilla Firefox, Patient, Vulnerability, Microsoft Corp., Laptop Computer, NHS Laptop Theft, Web Browsers, Notebooks, Security, Internet, Hardware, Notebooks & Tablets, Paul Mah
Blog posts 2008-06-23
Vulnerability counting revisited: a hypothetical example
Vulnerability counting is, in many cases, worse than useless as a means of quantifying the security of the software. I've made this point before, but this article tries a different approach to making it: demonstration by hypothetical example. by Chad Perrin
Tags: Developer, Vulnerability, FooOS, BarOS, Security, Chad Perrin
Blog posts 2008-06-19
Security news roundup: Nuclear power plant shutdown attributed to a single computer
Here's a collection of recent security vulnerabilities, alerts, and news, covering a new version of VLC media player, an unpatched Sun Solaris network library vulnerability, an update from VMware, a free security configuration for VMware ESX, and news of a nuclear power plant shutdown attributed to a single computer. by...
Tags: Nuclear Energy, Vulnerability, VMware Inc., Security Vulnerability, Nuclear Power Plant, Computer, VLC User, Security, Paul Mah
Blog posts 2008-06-09
How should we handle security notifications?
A team of researchers at Carnegie-Mellon University studied the statistical relationship between rates of identity fraud and laws that require customers to be notified when there's been a security breach. As a security professional, this should raise a question in your mind: What should breach notification laws achieve? by Chad...
Tags: Software, Personally Identifiable Information, Vulnerability, Microsoft Corp., Notification Law, Security, Chad Perrin
Blog posts 2008-06-06
Find and fix weak OpenSSL/OpenSSH keys: Debian-based Linux vulnerability
A recent vulnerability was found in the OpenSSL package as provided by Debian and Debian-based Linux distributions, such as Ubuntu, that broke the effectiveness of the OpenSSL PRNG Predictable Random Number Generator. This vulnerability caused OpenSSL to generate weak keys for anything relying on OpenSSL, including SSL certificates, OpenSSH keys,...
Tags: OpenSSL, Linux, Perl, Vulnerability, Debian, OpenSSH, Debian Team, Ssl/Tls, Operating Systems, Open Source, Security, Software, Vincent Danen
Blog posts 2008-05-19
Security news roundup: Spybot Search & Destroy scans for rootkits, multiple patches from Apple
Here’s a collection of recent security vulnerabilities and alerts, which covers news that Spybot Search & Destroy now comes with the ability to detect rootkits, a re-release of a patch that affects Microsoft Office Excel 2003 SP2 and SP3, a slew of patches from Apple, and a warning from Microsoft...
Tags: Microsoft Word, Vulnerability, Detail, Patch Management, Apple Inc., SpyBot, Microsoft Corp., RootAlyzer, RootAlyzer Tool, Rootkits, Spyware, Spyware, Adware & Malware, Microsoft Windows, Patches, Security, Operating Systems, Software, Paul Mah
Blog posts 2008-03-23
Security news roundup: Backdoor found in Cisco's IPM, Mifare Classic RFID cracked
Here’s a collection of recent security vulnerabilities and alerts, which covers patches for multiple products from Adobe, a backdoor discovered in Cisco's IPM, an IFRAME exploit that showed up at Trend Micro's Web site, and news that the Mifare Classic RFID has been cracked. Adobe releases...
Tags: Adobe Systems Inc., Allaire ColdFusion, Trend Micro Inc., Vulnerability, Cisco Systems Inc., Technology, Sun Solaris, Development Tools, Security, Operating Systems, Software, Software Development, Software/Web Development, Paul Mah
Blog posts 2008-03-16
Security news roundup: Java update, Windows login bypass tool released
Here's a collection of recent security vulnerabilities and alerts, which covers a new Java update, the release of a Windows login bypass tool, multiple vulnerabilities in CUPS that can lead to DoS attacks, and details of the upcoming Patch Tuesday. New Java update fixes security vulnerabilities ...
Tags: Microsoft Outlook, Sun Microsystems Inc., Vulnerability, Microsoft Corp., Tool, Microsoft Windows, Programming Languages, Java, FireWire, Productivity, Microsoft Office, Security, Operating Systems, Software, Software Development, Software/Web Development, Consumer Electronics, Personal Technology, Office Suites, Paul Mah
Blog posts 2008-03-09
Security news roundup: March 2
Here's a collection of recent security vulnerabilities and alerts, which covers Symantec releasing security fixes for both its Backup Exec for Windows Server and the Symantec Scan Engine products, a critical hole found in the ICQ 6 instant messaging client, and a new version of Wireshark that resolves flaws in...
Tags: Symantec Corp., ICQ, Version, Vulnerability, Symantec Backup Exec, Security, Paul Mah
Blog posts 2008-03-02
Goolag security tool uses Google to scan sites for vulnerabilities
Goolag Scanner is a Web auditing tool released by the hacker group Cult of Dead Cows. The tool uses the prowess of the search engine to surface vulnerabilities on Web sites. A quote from the cDc Web site: "It's no big secret that the Web is...
Tags: Google Inc., Web, Vulnerability, Auditing, Hacker, Tool, Security Tool, Goolag Scanner, Goolag, Productivity, Scanners, Hacking, Security, Hardware, Peripherals, Arun Radhakrishnan
Blog posts 2008-02-27
Security news roundup: February 24
Here’s a collection of recent security vulnerabilities and alerts, which covers Opera releasing an update that patches three security vulnerabilities, multiple flaws found and fixed in EMC RepliStor, Symantec patching Veritas Storage Foundation, the presence of design weaknesses in wireless LAN VoIP handsets, and hard disk enclosures that fails to...
Tags: Opera Software, Hard Drive, VERITAS Software Corp., VERITAS Storage Foundation, Vulnerability, Problem, EMC Corp., Encryption, Authentication, Wireless, Flaw, Data, Badge, Goerge, Security, Storage, Hardware, Paul Mah
Blog posts 2008-02-24
Security news roundup: February 17
Here's a collection of recent security vulnerabilities and alerts, which covers a serious vulnerability fixed in ClamAV, FreeBSD closing a couple of vulnerabilities, additional flaws discovered in Cisco IP telephony products, critical vulnerabilities found in Adobe Flash Media Server, and how Vista SP1 proves to be a low hurdle to...
Tags: Adobe Systems Inc., Attacker, Vulnerability, Microsoft Windows Vista, Flaw, PE, Security, Paul Mah
Blog posts 2008-02-17
Security threats in a unified world
Amid all the excitement surrounding the unification of our communications technologies, the issue of security sometimes gets lost in the shuffle. Maybe some are assuming that the threats are the "same old, same old" that plague those same communications methods in their more stand-alone forms. But it's that and more....
Tags: SIP, VoIP, Attacker, IM, Vulnerability, Unified Communications, Encryption, Attack, UC, E-mail E-mail, Instant Messaging, E-mail, Session Initiation Protocol (SIP), Security, Internet, Online Communications, Emerging Technologies, Deb Shinder
Blog posts 2008-02-15
Security vulnerabilities abound at Adobe
As with many other software vendors, Adobe has found itself rife with security vulnerabilities in a number of its products. A recently patched series of flaws in Acrobat, the longtime standard for Web documents, has already infected thousands, according to some researchers. Some older versions of Acrobat are still waiting...
Tags: Adobe Systems Inc., Adobe Acrobat, Vulnerability, Malware, Spyware, Adware & Malware, Cyberthreats, Security, Viruses And Worms, Andy Moon
Blog posts 2008-02-12
Security news roundup: February 10
Here's a collection of recent security vulnerabilities and alerts, which covers a vulnerability in the multiuser version of the popular WordPress, a new release of the Windows client for Skype that fixes several vulnerabilities, critical vulnerabilities found in Sun's Java Runtime Environment, a memory corruption vulnerability found in IBM's DB2...
Tags: Attacker, Vulnerability, Skype Technologies S.A., Wordpress, News, IBM Corp., WordPress MU 1.3.1, Skype Security Bulletin, Security, Paul Mah
Blog posts 2008-02-10
Security news roundup: February 3
Here’s a collection of recent security vulnerabilities and alerts, which covers multiple unpatched vulnerabilities in the open sourced Mambo CMS, Gento's vulnerability to DOS and remote exploitation, the availability of an update for a disclosed flaw in the UltraVNC client, a security hole in Cisco's Wireless Control System, Security leaks...
Tags: Mambo, Gentoo, Vulnerability, Informix Software, Server, IBM Corp., Bruter, Security, Paul Mah
Blog posts 2008-02-03


PC Troubleshooter Resource Guide, Fifth Edition
Ensure you have the solutions you need to troubleshoot power supplies, CPUs, video cards, disk drives, CD and DVD drives, motherboards, sound cards, USB issues, monitors, printers, laptops, network connections, spyware, Windows XP and more.
Buy Now
500 Things Every Technology Professional Needs to Know
Did you know Microsoft's RegClean does not work with XP but you can use shareware to clean your registry? Did you know most wireless access points don't have encryption enabled by default? Did you know there are 500 tidbits of information contained in TechRepublic's 500 Things Every Technology Professional Needs to Know that will help you become a successful IT professional.
Buy Now

SmartPlanet