08-13-2010 17:31
ColdFusion directory traversal FAQ (CVE-2010-2861)

A new Adobe hotfix for ColdFusion has been released recently. The vulnerability which was discovered by Richard Brain, was rated as “Important” by Adobe and could affect a large number of Internet-facing web servers. The FAQ bellow is meant to shed some light on this vulnerability so that ColdFusion administrators can understand what they’re up against.
Finally, by producing this FAQ I will attempt to explain why (at least on certain setups) this vulnerability shou ...
Feedproxy Security
08-03-2010 20:36
Website Vulnerability Assessments: Good, Fast, or Cheap - Pick Two
Website vulnerability assessments are part of any mature secure software development lifecycle. Today software, especially web-based software, is being updated at ever increasing speeds with the adoption of agile and other iterative development methodologies. To fit security into that fast paced life-cycle, application security must find a way to fit within the delivery requirements AND constraints. Upon immediately reading the headline, software managers will be well familiar with what I'm gett ...
Feedproxy Security
-
Sophos: The correct CV(or malware)
-
Sophos: To infinity and beyond
-
Sophos: FakeAV, now with sounds