Feb 10 2009

Website Security Without Breaking the Bank?

An anonymous reader writes “I do my own Web design and have a few websites — MySQL, PHP, CSS, HTML, that kind of thing. It’s simple, amateur stuff, but I would love to have some reasonable ways to assess their security myself and patch the big holes, or possibly enlist someone to do ‘white hat’ work to assist me. I have absolutely no idea how to proceed. I don’t want to get mired in a never-ending paranoia-fueled race to patch holes before the hackers find them, but on the other hand, I don’t want my websites to look like Swiss cheese. Right now, I wouldn’t know what kind of cheese they look like: Swiss, Havarti, or hard as Parmesan. How can I take reasonable steps to protect these websites myself? What books has the community found useful? What groups (if any) can offer me inexpensive white-hat hacking that won’t end up costing me a first-born child? Or am I better off just waiting until a problem arises and then fixing it?”

Read more of this story at Slashdot.

Share

Feb 10 2009

CA GRC Manager 2.0 Looks to Bring Uniformity to Risk Management – eWeek


Sarbanes-Oxley Compliance Journal

CA GRC Manager 2.0 Looks to Bring Uniformity to Risk Management
eWeek – 6 hours ago
CA has updated its GRC Manager tool with new features meant to help companies unify their risk management, security and compliance efforts.
CA unveils GRC Manager 2.0 for risk management GCN.com
CA GRC Manager 2.0 Improves Enterprise-wide Risk IQ for Better WELT ONLINE
eWeek
all 15 news articles
Share

Feb 10 2009

Scientists unravelling mysteries of Saskatchewan meteorite – CBC.ca


CBC.ca

Scientists unravelling mysteries of Saskatchewan meteorite
CBC.ca – 5 hours ago
On Nov. 28, Ellen Milley posed with fragments of a 10-tonne meteorite she found in a small pond approximately 40 kilometres from Lloydminster, Sask.
Footage key to understanding meteorite's origins Canada.com
all 4 news articles
Share

Feb 10 2009

Metasploit Hacking Tool To Get Services-Based Model

ancientribe writes “Metasploit hacking tool creator HD Moore told Dark Reading that the open-source hacking tool soon will come with back-end services-based features aimed at offloading resource-intensive penetration testing tasks. This is a departure for the software-oriented Metasploit, and Moore and company just may be on to something: it turns out commercial penetration testing tool vendors are looking at adding services-based versions of their software. Immunity Inc. will do so this year, and Core Security Technologies is considering doing so as well.”

Read more of this story at Slashdot.

Share

Feb 9 2009

CA GRC Manager 2.0 Looks to Bring Uniformity to Risk Management – eWeek


Sarbanes-Oxley Compliance Journal

CA GRC Manager 2.0 Looks to Bring Uniformity to Risk Management
eWeek – 1 hour ago
CA has updated its GRC Manager tool with new features meant to help companies unify their risk management, security and compliance efforts.
CA unveils GRC Manager 2.0 for risk management GCN.com
CA GRC Manager 2.0 Improves Enterprise-wide Risk IQ for Better WELT ONLINE
eWeek
all 15 news articles
Share

Feb 9 2009

Obama To Name Melissa Hathaway Cybersecurity Chief

hargrand writes “President Obama has found the cyber tsar to head his new White House office of cybersecurity. According to US press reports this morning, an announcement expected later today will confirm Melissa Hathaway is to come in as cyber chief, after being cyber coordination executive for the director of national intelligence.”

Read more of this story at Slashdot.

Share

Feb 9 2009

Antivirus firm confirms hackers breached site – Computerworld


Inquirer

Antivirus firm confirms hackers breached site
Computerworld – 1 hour ago
By Gregg Keizer February 9, 2009 (Computerworld) Kaspersky Lab, a Moscow-based security company, admitted today that a database containing customer information had been exposed for almost 11 days and that it only learned of the breach when Romanian
Kaspersky Lab Pours Cold Water on Claims of Data Breach By Hacker eWeek
Hacker cracks Kaspersky Security site USA Today
PC World – CNET News – Dark Reading – Inquirer
all 53 news articles
Share

Feb 9 2009

50 Extremely Useful JavaScript Tools

Below, you’ll find 50 excellent tools to help you achieve various tasks involved in authoring JavaScript code. You’ll find useful tools to speed up your coding processes, including debugging tools to hunt down places where your scripts break, unit testing and validation tools to test your scripts in various situations, security vulnerability scanne

Share

Feb 9 2009

Windows 7 UAC flaws and how to fix them

A number of security flaws have been found in Windows 7’s streamlined UAC—flaws that Windows Vista is immune to—prompting a series of surprising responses from Microsoft. We take a look at what the flaws are, and what’s being done about them.

Share

Feb 8 2009

Robotic Smart Buildings Under Development

The Small Robotics Building project utilizing smart infrastructure technology and robotics, the companies are creating an automated living environment that can handle such duties as reception, deliveries, cleaning, and security, without the need for human intervention

Share