Stories by: Roger A. Grimes
- +
Security software developers need SDL, too 09/07/2008 10:11:49
The headline seems a bit melodramatic, "Antivirus tools pave the way for malware". A company called n.runs AG is claiming to have found hundreds of security holes in multiple antivirus programs, which can be exploited by the very malware the products are supposed to protect you against. The company's press release implies that many of the holes have to do with the way various antivirus programs parse inspected data files. Not surprisingly, n.runs AG has a solution they can sell worried companies. - +
Hacking tools: A new version of BackTrack helps ethical hackers 30/06/2008 10:57:21
Version 3.0 of BackTrack has been released. BackTrack is a Linux-based distribution dedicated to penetration testing or hacking (depending on how you look at it). It contains more than 300 of the world's most popular open source or freely distributable hacking tools. - +
Are you a computer security professional? 11/06/2008 11:17:55
You know you're a computer security professional when: - +
Titus Labs helps stop e-mail slips 02/06/2008 08:15:16
The news media is full of stories about e-mails and documents that were better off not sent. Last year an airline CEO accidentally sent an ultra harsh e-mail to complaining customers, the text of which was obviously not intended for the customers. Frustrated employees frequently send embarrassing internal memorandum to public news sources. And is there an e-mail user who hasn't regretted accidentally sending an e-mail to an unintended party? Whether e-mail or documents are sent intentionally or not, it is clear that content intended for a restricted audience is being shared with unauthorized parties on a regular basis. - +
Notes from AusCERT 2008 26/05/2008 11:34:08
I've had the pleasure of speaking and attending this year's AusCERT 2008 security conference held in Gold Coast, Australia. If you've never been to Australia, you're missing some of the best that life has to offer, and I feel the same way about the conference. Although a bit smaller than most US security conferences, it's intentionally kept small (around 1,000 participants) and makes up in quality speaker presentations and vendor participation what it lacks in headcount. One of the great attributes of the typical Aussie is their aversion to marketing hype, along with their ability to "cut the fat off a chicken" (as my grandmother used to say) and pull out the salient points. If a vendor tries to push marketing fluff about their product too much, they are likely to get verbally assailed rugby-style. Here are some of my favorite notes and quotes from selected speakers: - +
ZoneAlarm ForceField: Compromised in sixty seconds 22/05/2008 09:45:47
Check Point Software's new Web browser security software, called ZoneAlarm ForceField, integrates a host-based firewall, anti-spyware, Web site rating, anti-phishing, and keylogger-jamming into a limited virtualization environment with the elegant user interface you've come to expect from the ZoneAlarm brand. Its goal is to provide superior anti-malware protection against the increasingly prevalent and complex threats posed to Internet surfers. - +
Defending "Fixing the Internet" 19/05/2008 10:10:39
Last week I publicly released a white paper called Fixing the Internet: A Security Solution in this blog. - +
Fixing the Internet 12/05/2008 11:37:35
Long-time readers know that I often rant about how insecure the Internet is, and how few solutions will do anything to change that equation during the next 5 to 10 years. I've also recommended a handful of solutions over the years, and accepted the resulting criticism that goes along with proposing big ideas. - +
Zero-second exploits 06/05/2008 12:04:48
Microsoft SQL server hasn't had a public vulnerability announcement since 2004. The SQL Slammer worm struck in 2005, but the hole the worm exploited had been patched six months before. The holes that MS-Blaster and Code Red worm attacked had been patched, too. But back just a few years ago, no one really cared about patching really. We just didn't patch. - +
Be careful with transitive trust 28/04/2008 11:10:28
I just got through reading about another hugely popular, legitimate Web site hosting malicious code that redirects visitors to a malicious Web site. Once redirected, the new Web site runs a fake virus scanner and -- surprise, surprise -- finds multiple malware programs on the user's computer as it offers to install new "anti-virus" software to the end-user. Of course, users foolish enough to install the software end up installing what is likely to be the only malicious program on their computer. - +
Virtual machines aren't really more secure 21/04/2008 10:35:01
I've been at several recent conferences where virtual machine (VM) and security "experts" were telling audiences how VM technology can be used to improve computer security. Wow! They are either drunk on the marketing Kool-Aid, misinformed, or simply trying to misrepresent VM capabilities to sell more product.
Additional Resources
Executive Guides
Whitepapers
Read up on the latest ideas and technologies from companies that sell hardware, software and services. Business Mashups: Build and deploy applications without the need for professional developers
Microsoft 2008 Mission Critical IT
You Deserve Better than Spreadsheets
ALM for the Enterprise - Serena’s Approach to ALM 2.0
Business Mashups: The 10 Commandments
From Business Needs to Business Mashups in 3 simple steps
A Guide to Next-Generation Backup, Recovery and Archive
The value of Project Portfolio Management
Zones
Zones provide focussed content from Computerworld and leading technology partners.Videos
Computerworld news
WebCasts
Newsletter Subscription
RSS Feeds
ARN Polls
Market Place
Computerworld Member Login
Beyond Virtualisation - The Roadmap to 2012
CIO Breakfast Briefing
8:30am - 10:30am
Brisbane | 22 July | Sofitel Brisbane
Sydney | 23 July | Four Seasons Hotel
Canberra | 24 July | The Hyatt
Attend and discover:
- What happens after virtualisation
- The benefits automation drives
- When automated infrastructures will emerge
- What the roadmap to 2012 looks like
- How to deliver an automated architecture
- How to maximise your investment in virtualisation
- +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future. - +
Data Management Edition #9: Data centre makeover 24/04/2008 07:43:06
This week CW Live looks at the death of the old style data centre which is undergoing its first makeover in more than 30 years.
Satyam’s Q1 revenue up by 43% and Net Profit by 45% YoY; revises revenue and EPS guidance upwards for FY09 2008-07-18 16:58:00+10
Informatica Reports Record Second Quarter Results 2008-07-18 13:01:00+10
Tumbleweed Releases MailGate 3.6 2008-07-18 10:01:00+10
Convergys to Acquire Intervoice, Enhancing Leadership in Relationship Management 2008-07-17 14:41:00+10
Borland Management Solutions Put the "M" in Application Lifecycle Management 2008-07-17 13:43:00+10
Whitepaper
Extending Business Solutions across the Organisation
It is difficult for companies to overcome business challenges when employees are not connected to their business management solution. Discover Microsoft Dynamics Client for Microsoft® Office and SharePoint® Server and connect Microsoft Dynamics more closely with personal productivity solutions and much more.
Enterprise IT Buyer's Guide
Sponsored Links












