Articles

Hackers Slurp over a million user accounts from Washington Post

July 14th, 2011

 -  

The Washington Post website has been hit with a double security breach. Hackers have made off with around 1.3 million user IDs and email address from (continue reading...)

How Much Web Security is Enough?

July 6th, 2011

 - A good web application security environment is one that balances security with convenience. Nothing more and nothing less; (continue reading...)

The Cure for Many Web Application Security Ills

June 29th, 2011

 - One of the things I’ve learned throughout my career is that many solutions to the problems we face in IT, security and software development (continue reading...)

Security By Design: Preventing Data Breaches Early and Often

May 19th, 2011

 - With Sony, Epsilon and even Barracuda Networks (a security company) dominating the news cycle when it comes to data breaches, it makes you wonder:  if it can happen to them, can it happen to my (continue reading...)

Barracuda Networks Breached

May 5th, 2011

 - Introduction
On April 11th 2011, at nine in the evening, Barracuda Networks posted a grim entry on their blog. (continue reading...)

Low-Hanging Fruit Becomes Big News with the 2011 Verizon Data Breach Report

May 3rd, 2011

 - The 2011 Verizon Data Breach Investigations Report is out. Yeah, yeah, yeah – yet another report telling us what a bad state of security we’re in (continue reading...)

But Compliance is Someone Else’s Job!

April 28th, 2011

 - Regulatory ‘compliance’ – it’s a dirty word in business today. Perhaps that’s because we’re being force-fed more and more rules that various governing bodies believe (continue reading...)

MySQL.com Victim of SQL Injection Attack

April 20th, 2011

 - Introduction
On 27th March 2011 a message was posted on the popular Full Disclosure mailing list exposing a recent hack against the website mysql.com. This vulnerability was apparently also reported by a hacker called TinKode, who (continue reading...)

Barracuda Attack: Never Let Your Security Guard Down

April 14th, 2011

 - Six days ago, Barracuda Networks, a major player in the information security space, experienced a breach via its public-facing web site, which compromised sensitive company data.It is important to note that attack took place during (continue reading...)

Epsilon Breach Reinforces Need for Security Management of Third Parties

April 13th, 2011

 - Most CSOs go to great lengths to develop iron-clad security policies, implement the most cutting-edge solutions and partner with the right integrators and security solutions providers to make sure that their most precious assets are (continue reading...)

Don’t Overlook the Importance of Authenticated Testing

March 31st, 2011

 - Would you want to rely a home inspector’s analysis of just the outside of a new home you’re considering (continue reading...)

Preventing XSS Attacks

March 22nd, 2011

 - Cross Site Scripting (XSS) attacks are amongst the most common types of attacks against web applications. XSS attacks all fall under the same category however a more detailed look at the techniques employed during XSS (continue reading...)

Cross Site Scripting Attacks

March 15th, 2011

 - 
Hackers are constantly experimenting with (continue reading...)

You can’t change what you tolerate

March 10th, 2011

 - Attending a recent meeting I heard one of the speakers say “You can’t change what you tolerate.” Apparently it’s a quote from Cesar Millan (the dog whisperer) (continue reading...)

RSA 2011: Serious Business at the Greatest (Security) Show on Earth.

February 25th, 2011

 - Without a doubt, the annual RSA conference is the premier gathering of key security leaders from both industry and government.  It is what I like to call “The Greatest (Security) Show on Earth.”  From vendors (continue reading...)

Testing for weak passwords: a common oversight without a great solution

February 16th, 2011

 - Typically when we think of Web security testing vulnerabilities such as SQL injection, cross-site scripting and (continue reading...)

Taking Stock of the NASDAQ Breach

February 14th, 2011

 - One of the bigger data breach stories dominating the headlines as we head into RSA 2011 is the NASDAQ breach. While this is considered a “high-profile” breach, the real, behind-the-scenes story is that the (continue reading...)

Cloud Security: Key Discussion Topic at RSA 2011 and Beyond

February 7th, 2011

 - It’s pretty hard these days to do a Google News search on the topic of “application security” and not run into hundreds of stories about cloud security.   As the RSA 2011 news cycle starts to (continue reading...)

I wouldn’t want to be a developer these days

February 3rd, 2011

 - Are you a software developer? If so, I don’t envy you.  Of all the possible positions working in and around IT, you’ve arguably got the toughest one. I’ve witnessed it over the years while performing (continue reading...)

Copyright © 2012 The Security Blog. All rights reserved.