InfoQ

InfoQ

Topic/Tag specific view

Vulnerabilities Content on InfoQ


Latest featured content about Vulnerabilities

Resilient Security Architecture

Topics
Security

In this IEEE article, author John Diamant talks about how to improve security quality of software applications using a proactive approach with techniques like Security requirements gap analysis and Architectural threat analysis in the early phases of software development life cycle.

Enhanced Detection of Malware

Topics
Security,
Operations,
Cloud Computing,
Architecture

This article, from Intel, discusses significant new threats to host agents, outlines a generic architecture for malware detection, based on enhanced cloud computing, describes how Intel platform technologies can be used to enhance computing solutions, and ends with a threat analysis of the approaches presented. Malware that masks its presence from traditional security agents is the article focus.

The Dark Cloud: Understanding and Defending against Botnets and Stealthy Malware

Topics
Security,
Architecture,
Software Troubleshooting

Botnets are the latest scourge to hit the Internet and this article defines a botnet (a collection of distributed computers or systems that has been taken over by rogue software), examines the botnet life cycle, and presents several promising anti-botnet defense strategies including canary detectors, white lists, and malware traces.

News about Vulnerabilities

Major Denial of Service Vulnerability Affects Most Web Servers

Topics
Java,
Web Servers,
.NET,
Ruby

Security researcher Alexander Klink and Julian Wälde revealed a serious vulnerability that until recently affected the vast majority of web server. The attack only requires a single HTTP request that is specially designed to create hash code collisions in POST form data. When first discovered this attack affected Python, Ruby, PHP, Java, and ASP.NET, but vendors have been working on patches.

Padding Oracle Affects JSF, Ruby on Rails, ASP.NET

Topics
Security,
Java,
.NET,
Ruby

Using a Padding Oracle (PO) attack a malicious user can access encrypted data such as cookies, state, membership password, etc. According to Juliano Rizzo and Thai Duong, two software engineers specialized in security, the security vulnerability affects JavaServer Faces, Ruby on Rails, ASP.NET and other technologies and platforms.

IBM X-Force Report: Enterprise Security Exploits Are Rising

Topics
Security,
Javascript,
Architecture

IBM has published the IBM X-Force® 2010 Mid-Year Trend and Risk Report August 2010 (112 pages long, free registration required) containing detailed information about the security vulnerabilities and exploits of 2010, such as JavaScript and PDF obfuscation, the current security threat trends in the enterprise, and a look into the future.

Learning About Security Vulnerabilities by Hacking Google’s Jarlsberg

Topics
Security,
Java,
.NET,
Architecture,
Ruby

For those who have wondered what it is like to hack into another system, Google has created a special lab named Jarlsberg containing a web application full of security holes ready to be exploited by developers who want to learn hands-on what are some of the possible vulnerabilities, how malicious users use them and what can be done to prevent such exploits.

A .NET Security Vulnerability Has Affected Firefox

Topics
Security,
Architecture,
.NET

A security vulnerability that has hit Internet Explorer through .NET has also hit Firefox. The culprit for Firefox, a .NET add-on, has been put on Mozilla’s blocked list.

Internet Security: an Interview with David Durham

Topics
Security,
Operations,
Cloud Computing,
Architecture

David Durham, manager of Intel's Security and Cryptography Research group, was recently interviewed on the subject of Internet and Computer Security. The interview covers a wide range of topics including the "monetization of malware," Cloud-based detection of malware, security of data stored in the Cloud, "Botnets in the Dark Cloud," and malware as a tool in geo-politics.