News (64)

Security guru wants access to bug databases

Security expert Ross Anderson has called for empirical research to be conducted into whether open source or closed source software is more secure, and into the impact that development practices such as extreme programming (XP) have on code quality. Read more »

UK Defence enlists ID thieves to place 600,000 recruits

The Ministry of Defence has admitted losing the details of 600,000 people after the theft of a laptop from a Royal Navy officer in Birmingham last week. Read more »

Firm offers new tools for database security

Security software developer Guardium is expected to formally announce Monday a new suite of integrated security applications for databases, a market that's gaining traction in the current regulatory environment. Read more »

Oracle patches 45 security vulnerabilities

In its latest quarterly patch cycle, Oracle has released 45 fixes for various security flaws. Read more »

Microsoft probing ActiveX attacks targeting Access feature

Microsoft has issued a security advisory warning about targeted attacks being launched that exploit a hole in the ActiveX control for the Snapshot Viewer in the Microsoft Access database management system. Read more »

MySQL issues security fix

MySQL has issued a security update to address flaws in its client-server protocol that could allow a malicious attacker to exploit buffer overflow vulnerabilities and gain access to sensitive information. Read more »

US Homeland Security still infected with Trojans?

The man in charge of IT security for the US Homeland Security department may lose his job after the revelations that his department's IT systems have misconfigured firewalls, suspicious botnet activity, trojans and virus infections. Read more »

Massive SQL-based Web attack decoded

The SANS Internet Storm Center has published details about the massive SQL-based Web attack that occurred over the weekend. Read more »

Oracle tool to rein in database admins

Database administrators don't always need access to the information in the databases they're managing, so Oracle has created a tool to protect it. Read more »

US Senate moves to legalise 'illegal NSA spying'

Google, Yahoo, MSN along with other search and e-mail companies may no longer be acting illegally if they spy on their customers and then share that information with the National Security Agency. Read more »

Features (166)

Grant Web servers secure database access

Allowing Web clients to access a database is a delicate matter that should not be attempted lightly or without careful consideration. Read more »

Secure SQL Server: Identify user issues

In this article we'll explore basic methods of logins, users, roles, and groups and the possible management strategies you can use to set up user access to your database. Read more »

Security models made easy

The right level of security to allow end-users access your applications can be a tough job in a dynamic enterprise environment. Here are some tips to help you sleep easier at night. Read more »

Control access to .NET Web services

Web services can present problems caused by unauthorised access. These validation methods can help you reduce the risk. Read more »

Upsizing an existing Microsoft Access database

The Upsizing Wizard in Microsoft's Access database software makes transforming to SQL Server mostly painless. But even the wizard needs fine-tuning for a smooth transition. Find out how to overcome some of the limitations. Read more »

Make managed code work with .NET's CAS

Developers and administrators can set permission and trust levels with code access security (CAS), while allowing the code to execute effectively. Read more »

Maximising IIS logging

Multiple options for logging user access activity are available when you manage Microsoft IIS Web servers. Here are several logging options. Read more »

Alpha Five: A prototyping tool to rival Access?

Could the relatively unknown tool, Alpha Five, beat out Microsoft Access as the king of the prototyping world? Check out our review and decide for yourself. Read more »

Secure SQL Server: Installing for security

Securing SQL Server is vital to the design of any database system. Learn how to install SQL securely, protect data, and ensure its validity. Read more »

Web application security frameworks (WASF), Part 2: Database lookup

Often, you will want parts of your Web application to be exclusive to certain users. This access distinction requires the use of Web application security frameworks. Continuing our series on Web app security, we explore the database lookup framework. Read more »

Blog (3)

The 2008 Trends and Threats to Internet security

Lana Kovacevic [blogs:webanatomy] -- I recently came across the IBM Internet Security Systems X-Force 2008 Mid-Year Trend Statistics report, which outlines issues affecting internet security, including application vulnerabilities, phishing, malware and spam. Read more »

Lets Shindig!

Lana Kovacevic [blogs:webanatomy] -- At this year's Google Developer Day in Sydney, Dan Peterson and John Hjelmstad talked about Apache Shindig, an open source implementation of OpenSocial and gadgets. Read more »

Salesforce's new AIR toolkit

Staff [blogs:syslog] -- Following the announcement that Salesforce will provide a free toolkit for Adobe Flex and AIR development on its Force.com platform, I spoke to the company’s Doug Farber, the Vice President of Operations, Asia Pacific about its functionality and other issues surrounding the toolkit. Read more »

Log in


Sign up | Forgot your password?

What's on?