News (32)

Security guru wants access to bug databases

Security expert Ross Anderson has called for empirical research to be conducted into whether open source or closed source software is more secure, and into the impact that development practices such as extreme programming (XP) have on code quality. Read more »

Software should defend itself: Oracle CSO

Applications will have to defend themselves from attack in the future, according to Oracle's chief security officer Mary Ann Davidson. Read more »

Oracle fixes bugs with mega patch

Oracle on Tuesday released fixes for a laundry list of security vulnerabilities in many of its software products. Read more »

Microsoft probes report of IE flaw

A new flaw in Internet Explorer could be exploited to launch spoof-based attacks, or access and change data on vulnerable PCs, security experts have warned. Read more »

Study: Few bugs in MySQL database

A source-code analysis of the MySQL database, a popular open-source program at the heart of many Web sites, revealed few bugs compared with the number found in commercial code, testing company Coverity said Friday. Read more »

JavaScript bug hunting tool demonstrated

A security researcher at ShmooCon on Saturday demonstrated, but did not release, a tool that turns the PCs of unknowing Web surfers into hacker help. Read more »

Developers fast to fix open-source bugs

Developers have quickly fixed many bugs in popular open-source packages that were flagged as part of a US government-sponsored bug hunt. Read more »

Oracle sews up multiple security holes

As part of its quarterly patch cycle, Oracle on Tuesday released fixes for a long list of security vulnerabilities in many of its products. Read more »

Oracle plugs 65 security holes

As part of its quarterly patch cycle, Oracle on Tuesday in the US released fixes for 65 security vulnerabilities that affect many of its products. Read more »

Oracle's oops on security flaw

Oracle accidentally let slip details last week on a security flaw it has yet to patch. Read more »

Features (30)

Bug hunters, software firms in uneasy alliance

Although many software makers promote responsible disclosure, it isn't universally backed by the security community. Critics say it could make security companies lazy in patching. Full disclosure of flaws is better is preferred. Read more »

Diagnose Perl CGI bugs

Capturing and replaying Web transactions with Perl is an ideal way to trap and diagnose weird data problems that occasionally happen. ZDNet Australia examines what this technique entails and introduces a small module that shows some ways to put it to work. Read more »

Analyse MySQL databases with SQLyog

MySQL Server enthusiasts can now take advantage of an interface similar to SQL Server's Query Analyser. SQLyog provides the functionality for free. Read more »

Develop secure software at the application level

Protect your application from input overflow and underflow attacks, and from other common tactics with these development techniques. Read more »

Why would anyone choose Windows over Linux?

Why would anyone choose Windows over Linux? This article lists some of the advantages of Linux over Windows. Read more »

Build Web applications without writing code

This article gives an overview of Iceberg -- a tool for building Web application without writing code. Read more »

Interview: The importance of being Erlang

He's one of the few developers in Australia with experience working in Erlang, the functional programming language which is gaining fans for its handling of parallel processing and creating distributed systems. We sat down with Andre Pang to see what all the fuss was about. Read more »

Consider these factors before using Enterprise JavaBeans

Still on the fence about whether to invest time and energy into learning and applying EJB technology? Read more »

Gosling looks down Sun's open road

James Gosling discusses Sun's decision to release Java under the General Public License, whether open source is more secure than proprietary software, how IT departments can cut development costs, and why Microsoft still owns the desktop. Read more »

Set up Web-based e-mail quickly using SquirrelMail

A good alternative to a traditional client/server-based e-mail solution is to simply set up one that's Web-based. In this article, Jack Wallen shows how to configure Web-based e-mail quickly and easily using SquirrelMail. Read more »

Blog (1)

Attack Modeling vs Threat Modeling

[blogs:] -- Traditional Threat Modeling from an adversarial approach is actually Attack Modeling. So what is Threat Modeling then and how does it differ from Attack Modeling? Read more »

Log in


Sign up | Forgot your password?

What's on?