Vulnerabilities Content on InfoQ
Latest featured content about Vulnerabilities

- Topics
- Security Assessment,
- Security,
- Vulnerabilities,
- Threat Modeling
In this IEEE article, author John Diamant talks about how to improve security quality of software applications using a proactive approach with techniques like Security requirements gap analysis and Architectural threat analysis in the early phases of software development life cycle.

- Topics
- Intel,
- SOA Platforms,
- Cloud Security,
- Companies,
- Casestudy,
- SOA,
- Operations,
- Stories & Case Studies,
- Enterprise Architecture,
- Architecture,
- Security,
- Cloud Computing,
- Agile,
- Infrastructure,
- Vulnerabilities
This article, from Intel, discusses significant new threats to host agents, outlines a generic architecture for malware detection, based on enhanced cloud computing, describes how Intel platform technologies can be used to enhance computing solutions, and ends with a threat analysis of the approaches presented. Malware that masks its presence from traditional security agents is the article focus.

- Topics
- Intel,
- Companies,
- Cloud Security,
- SOA Platforms,
- SOA,
- Cloud Computing,
- Architecture,
- Enterprise Architecture,
- Security,
- Vulnerabilities,
- Software Troubleshooting
Botnets are the latest scourge to hit the Internet and this article defines a botnet (a collection of distributed computers or systems that has been taken over by rogue software), examines the botnet life cycle, and presents several promising anti-botnet defense strategies including canary detectors, white lists, and malware traces.
News about Vulnerabilities
- Topics
- ASP.NET MVC,
- Ruby,
- ASP.NET,
- Dynamic Languages,
- .NET,
- Languages,
- Programming,
- Ruby on Rails,
- Vulnerabilities
GitHub was recently compromised by a vulnerability in Ruby on Rails know as mass assignment. This vulnerability is thought to not only affect a large number of Ruby-based websites, but also those using ASP.NET MVC and other ORM-backed web frameworks.
- Topics
- Glassfish,
- Ruby,
- Application Servers,
- Java,
- Dynamic Languages,
- ASP.NET,
- Languages,
- .NET,
- PHP,
- Programming,
- Web Servers,
- Tomcat,
- Vulnerabilities
Security researcher Alexander Klink and Julian Wälde revealed a serious vulnerability that until recently affected the vast majority of web server. The attack only requires a single HTTP request that is specially designed to create hash code collisions in POST form data. When first discovered this attack affected Python, Ruby, PHP, Java, and ASP.NET, but vendors have been working on patches.
- Topics
- Ruby,
- Java,
- Dynamic Languages,
- .NET,
- Languages,
- Programming,
- Security,
- Vulnerabilities,
- Web Server
Using a Padding Oracle (PO) attack a malicious user can access encrypted data such as cookies, state, membership password, etc. According to Juliano Rizzo and Thai Duong, two software engineers specialized in security, the security vulnerability affects JavaServer Faces, Ruby on Rails, ASP.NET and other technologies and platforms.
- Topics
- Javascript,
- Web Development,
- Dynamic Languages,
- Languages,
- IBM,
- Programming,
- Architecture,
- Companies,
- Security,
- PDF,
- Vulnerabilities
IBM has published the IBM X-Force® 2010 Mid-Year Trend and Risk Report August 2010 (112 pages long, free registration required) containing detailed information about the security vulnerabilities and exploits of 2010, such as JavaScript and PDF obfuscation, the current security threat trends in the enterprise, and a look into the future.
- Topics
- Ruby,
- Java,
- Dynamic Languages,
- Languages,
- .NET,
- Google,
- Programming,
- Security,
- Architecture,
- Vulnerabilities,
- Companies
For those who have wondered what it is like to hack into another system, Google has created a special lab named Jarlsberg containing a web application full of security holes ready to be exploited by developers who want to learn hands-on what are some of the possible vulnerabilities, how malicious users use them and what can be done to prevent such exploits.
- Topics
- .NET,
- Programming,
- Vulnerabilities,
- Security,
- Firefox,
- Browsers,
- Architecture,
- Internet Explorer
A security vulnerability that has hit Internet Explorer through .NET has also hit Firefox. The culprit for Firefox, a .NET add-on, has been put on Mozilla’s blocked list.
- Topics
- Intel,
- Encryption,
- HTTP,
- SOA Platforms,
- Companies,
- Cloud Security,
- W3C,
- Cryptography ,
- Operations,
- SOA,
- Security,
- Specifications,
- Cloud Computing,
- Infrastructure,
- Architecture,
- Enterprise Architecture,
- Vulnerabilities,
- Interviews
David Durham, manager of Intel's Security and Cryptography Research group, was recently interviewed on the subject of Internet and Computer Security. The interview covers a wide range of topics including the "monetization of malware," Cloud-based detection of malware, security of data stored in the Cloud, "Botnets in the Dark Cloud," and malware as a tool in geo-politics.
- Topics
- Ruby on Rails,
- Ruby,
- Dynamic Languages,
- Languages,
- Programming,
- Security,
- Vulnerabilities,
- Rails
There has been a buzz around the Ruby on Rails community lately with discovered security vulnerabilities and subsequent updates every Rails developer should be made aware.