September 2006 - Posts

How Prevalent Are SQL Injection Vulnerabilities?
[Update 01.31.07 - A follow up blog on the prevalence of XSS vulnerabilities has now been posted.] [Update 01.17.07 - This blog is now also available as a webcast .] Earlier this month, Mitre revealed that web application vulnerabilities have now claimed Read More...
Posted 26 September 06 01:01 by Erik | 84 Comments   
Filed under
What is Google Binary Search and Should We Fear It?
Background The so-called Google Binary Search (GBS) gained a fair bit of press attention in July 2006, when PC World published an article entitled ' Google's Binary Search Helps Identify Malware '. In the article, Websense revealed that they Read More...
Posted 14 September 06 02:46 by Erik | 12 Comments   
Filed under ,
Microsoft Black Tuesday - September 2006
Well, it's the second Tuesday of the month, a day that I affectionately refer to as 'Black Tuesday'. Today is the day that Microsoft unleashes their latest set of patches and system administrators scramble to apply them, but this time around, Read More...
The Invisible Hand of 'Responsible Disclosure'
This morning, I read an interesting survey on the meaning of responsible disclosure conducted by Federico Biancuzzi . He did a solid job of pulling together the major players including software vendors, independent researchers and commercial vulnerability Read More...
0day Attacks: Part Deux
I was pleased with the debate generated from my September 1st blog posting "Why all the hype about 0day" . The Slashdot conversation was an active one and there were several solid points made regarding the risks of 0day vulnerabilities vs. known Read More...
Posted 05 September 06 10:34 by Erik | 0 Comments   
Filed under
Why All The Hype About 0day?
The term "0day" has the power to make sys admins cringe. It the greatest fear of anyone tasked with protecting critical assets - a problem without an easy solution. Why? No, seriously why? 0day is a neon sign in the middle of Times Square. Once Read More...
Posted 01 September 06 11:29 by Erik | 7 Comments   
Filed under