Blog Home  Home Feed your aggregator (RSS 2.0)  
SecureDeveloper.com - Tuesday, June 10, 2008
Code is COMBAT !
 
 Tuesday, June 10, 2008

With more than 100 million Web applications deployed in the world, perhaps fewer than 5 percent of are being tested for security vulnerabilities. We offer three simple steps to help you secure your Web applications

Read Here - Enterprise Systems | Three Steps to Web Application Safety

Tuesday, June 10, 2008 4:31:57 PM (GMT Standard Time, UTC+00:00)  #    Comments [0]    |  Trackback

php_bugs

The PHP 5.2.6 release (download here) corrects at least four documented security flaws of varying severity

  • An unspecified error in the FastCGI SAPI can be exploited to cause a stack-based buffer overflow.
  • An unspecified error exists in processing incomplete multibyte characters within "escapeshellcmd()."
  • A security issue is caused due to an unspecified error. No further information is currently available.
  • An error in cURL can be exploited to bypass the "safe_mode" directive.
  • A boundary error in PCRE can potentially be exploited by malicious people to cause a DoS or compromise a vulnerable system.
  • Tuesday, June 10, 2008 2:46:21 AM (GMT Standard Time, UTC+00:00)  #    Comments [0]    |  Trackback
     Sunday, June 08, 2008

    CyberCriminal

    In a June 2007 report, the U.S Government Accountability Office (GAO) described cybercrime as “having significant economic impacts and a threat to U.S. national security interests”:

    · A 2005 FBI survey estimated that U.S. businesses lost $67.2 billion because of cyber crime.

    · The estimated losses associated with identity theft in 2006 are $49.3 billion.

    As software becomes the target for criminals, it is more critical than ever to make security an integral part of the software development process. Ever since Bill Gates’ 2002 Trustworthy Computing memo Microsoft has been infusing security into its software development lifecycle with the goal of protecting customers by reducing the number and severity of vulnerabilities in code.

    Introducing: The Microsoft Security Development Lifecycle (SDL)

    The Microsoft SDL is the industry-leading software security assurance process. A Microsoft-wide initiative and a mandatory policy since 2004, SDL has played a critical role in embedding security and privacy in Microsoft software and culture. Combining a holistic and practical approach, SDL introduces security and privacy early and throughout the development process. . It has led Microsoft to measurable and widely-recognized security improvements in flagship products such as Windows Vista and SQL Server.

    Go to www.microsoft.com/sdl to learn more about the Microsoft SDL and how you can leverage SDL resources and best practices to “bake security in” to your software applications.

    Sunday, June 08, 2008 1:06:18 PM (GMT Standard Time, UTC+00:00)  #    Comments [0]   News  |  Trackback
     Thursday, June 05, 2008
    Links to Developer Security Resources
    Thursday, June 05, 2008 1:40:19 AM (GMT Standard Time, UTC+00:00)  #    Comments [0]   Content  |  Trackback
    Copyright © 2009 Joe Stagner. All rights reserved.