News (23)

Safari 3.2 includes antiphishing tools

Without fanfare, Apple has apparently added antiphishing to its Safari 3.2 release. Read more »

Security tool aims to stop drive-by installs

Veterans of antispyware specialist PestPatrol have developed a new tool that throws up roadblocks for so-called drive-by installs of malicious code onto vulnerable PCs. Read more »

Google plans 'Chrome' browser

Search giant Google has confirmed it will shortly unveil a new Web browser dubbed 'Chrome' and based on code from the Webkit project. Read more »

China's Firefox growth kicks Aussies off top user list

Australia has missed out making it into a list of countries containing the most Firefox users, with the number of Chinese users of the browser taking over Australian ones between November and December. Read more »

Massive SQL-based Web attack decoded

The SANS Internet Storm Center has published details about the massive SQL-based Web attack that occurred over the weekend. Read more »

Microsoft probes report of IE flaw

A new flaw in Internet Explorer could be exploited to launch spoof-based attacks, or access and change data on vulnerable PCs, security experts have warned. Read more »

JavaScript bug hunting tool demonstrated

A security researcher at ShmooCon on Saturday demonstrated, but did not release, a tool that turns the PCs of unknowing Web surfers into hacker help. Read more »

Oracle urges customers to patch Web apps

Database software maker Oracle warned customers using the most recent version of its e-commerce program of a flaw that puts their systems at risk. Read more »

Firebird database readies SMP release

The open source project, which was created when Borland open sourced Interbase in 2000, is due to release a version of its database with full SMP support allowing enterprises greater scalability. Read more »

Browser flaws biggest software security risk

Cross-site scripting flaws are now the most common vulnerabilities according to security experts. Read more »

Features (57)

Bulletproof persistent cookies to increase security

Web browser cookies can enhance the user experience by providing additional functionality and ease of use. However, from an administration point of view, cookies are a security concern. Encrypt your cookies with this simple technique. Read more »

Security in the Web 2.0 Era

At the Gartner Symposium ITxpo 2008 in Sydney this week, Andrew Walls, the research director and security analyst at Gartner presented "Security in the Age of E-Commerce and Web 2.0". Read more »

Designing secure intranet applications

During the design phase, engineering and security teams must work together to ensure intranet applications meet the established security standards. Read more »

Develop a VoiceXML solution using BeVocal

VoiceXML (VXML) is a markup language like HTML. The difference is that a phone browser rather than a Web browser renders VXML. Get started with this article. Read more »

Web application security frameworks (WASF), Part 1: Introduction

Often you will want parts of your Web application to be exclusive to certain users. This access distinction requires the use of Web application security frameworks. This first article in the series introduces you to the three most often used methods. Read more »

Avoid security vulnerabilities in your CGI programs

CGI makes creating Web-executable programs quick and easy--both for you and for hackers. Learn about some of the explicit security vulnerabilities of CGI and how to avoid them. Read more »

CGI wrappers for Apache-based apps can boost security

CGI scripts represent a big potential security risk in Web development, but using CGI wrappers can help insulate your servers from attack. Here's an outline of how to create CGI wrappers to protect an Apache Web server. Read more »

Setting up directory security using ASP and IIS

Phillip Perkins was recently asked to create a solution for providing folder access and security on a Web site. Find out how he completed his assignment using code that worked for Windows 2000 Server with Internet Information Services (IIS) 5.0. Read more »

Take the proper steps to secure ActiveX controls

ActiveX controls are useful, but they can be a security risk if proper steps aren't taken. Find out how to mitigate risks and what alternatives exist. Read more »

Practical Web service security in .NET

Learn how to secure a Web service using VS.NET. Our sample code will enable you to prevent unauthorised users from accessing the service. Read more »

Blog (3)

The 2008 Trends and Threats to Internet security

Lana Kovacevic [blogs:webanatomy] -- I recently came across the IBM Internet Security Systems X-Force 2008 Mid-Year Trend Statistics report, which outlines issues affecting internet security, including application vulnerabilities, phishing, malware and spam. Read more »

Salesforce's new AIR toolkit

Staff [blogs:syslog] -- Following the announcement that Salesforce will provide a free toolkit for Adobe Flex and AIR development on its Force.com platform, I spoke to the company’s Doug Farber, the Vice President of Operations, Asia Pacific about its functionality and other issues surrounding the toolkit. Read more »

Google Gears screenshots

Brendon Chase [blogs:codemonkeybusiness] -- Here is a bit of eye candy of the new Google Gears installation and sample code. Read more »

Log in


Sign up | Forgot your password?

What's on?