"There will be no more updates for Firefox 3.0.x," Mozilla, the last update will be Firefox 3.0.19, due March 30 http://bit.ly/aiouLB
14 minutes ago by abhishekkatiyar on topsyZDNet is available in the following editions:
Researcher offers new examples of how bad guys are exploiting flaws.
At LinuxWorld today, SPI Dynamic's senior security engineer, Matt Fisher, talked about the vulnerabilities of Web 2.0.
His talk, although not much different from that of his colleagues Billy Hoffman and Brian Sullivan last week at Black Hat, offered some new examples of what criminals are doing online, armed with little more than a desktop browser. Cross-site scripting attacks are the Number one threat, according to the Mitre organization, in part because they are so easy to do.
In particular, Fisher singled out social-networking sites. Because the site depends on user content, the site allows users to upload HTML code, and in most cases, any HTML code. Knowing this, Fisher said someone could put a malicious script code into a blog post where it would sit until someone came along and read it. What bad could possibly happen from that, you might wonder? Fisher said that when someone in a corporate environment opens it, the attacker can then execute code inside the corporate perimeter on the internal network.
If that attack is too passive, Fisher suggested another scenario. In this scenario an attacker embeds malicious JavaScript into a customer help ticket. The help ticket is archived inside the corporate network. Every time a customer-support technician opens the help ticket, the code infects his or her desktop, and potentially, the corporate network.
Unlike operating system vulnerabilities, which can be addressed with a patch, cross-site scripting attacks are not generic; they are specific to the Web application. The key to mitigating these attacks is to limit what end users can and cannot do on the site. That sounds simple, but newer Web 2.0 sites often do not check for common, even old-school methods of attack.
"There will be no more updates for Firefox 3.0.x," Mozilla, the last update will be Firefox 3.0.19, due March 30 http://bit.ly/aiouLB
14 minutes ago by abhishekkatiyar on topsy[TECH] URL Shorteners slow Web redirection. - http://bit.ly/bySnWK @zdnetasia
1 hour 1 minute ago by danielcktan on twitterURL shorteners are great but they can slow web redirection & you pray it would never go down http://bit.ly/bySnWK via @zdnetasia
1 hour 29 minutes ago by angahsin on twitterTemasek Holdings eyeing tech stocks, indicating optimistic outlook on IT sector. http://bit.ly/aM7VwU
1 hour 58 minutes ago by zdnetasia on twitterWeb redirection through universal resource locator (URL) shorteners is adding extra seconds to page load time http://bit.ly/czbZxe
1 hour 58 minutes ago by abhishekkatiyar on topsyChinese agencies cry foul over Google. http://bit.ly/by6rwV
2 hours 4 minutes ago by zdnetasia on twitterThe Pirates of The Philippine Islands get slammed. http://bit.ly/a1NJlf
2 hours 25 minutes ago by larsjeppesen on topsyChina's enterprise software market is predicted to achieve a compound annual growth rate of 14.6% from 2008 to 2013 http://bit.ly/9rXQlL
2 hours 26 minutes ago by abhishekkatiyar on topsyall of sg's isps have been practising compulsory invisible proxy for all home subscribers at their backend since many years back alre...
5 hours 22 minutes ago by melvinchia on Web filters mean bad news for businessit is not to good for china.
Proactol
Salesforce.com is giving 5,000 developers access to its social networking and collaboration platform http://bit.ly/9dbNw5
8 hours 15 minutes ago by abhishekkatiyar on topsyRT @zdnetasia: HP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6
8 hours 37 minutes ago by LiruChan on twitterFor those with a computer science background, or interested in the high performance computing scene: http://bit.ly/9vFC3i
9 hours 2 minutes ago by zdnetasia on twitterHP touts new products and management and productivity tools to address business computing pain points. http://bit.ly/dudgA6
9 hours 10 minutes ago by zdnetasia on twitter** S'pore govt launches traffic Web app. http://www.zdnetasia.com/s-pore-...
10 hours 48 minutes ago by juiceliving on twitterthe new look site is very nice @zdnetasia @zdnetaustralia
14 hours 26 minutes ago by susan_m on twitterBig up to my peeps at www.ZDNet.com.au (and www.ZDNetasia.com and www.ZDNet.com.uk). Loving the redesign!
14 hours 42 minutes ago by randolphramsay on twitterMcAfee steps up cloud assurance - Zd Net Asia.com
http://www.zdnetasia.com/mcafee-...
Interesting take on social analystics. http://www.zdnetasia.com/blogs/w...
1 day 7 minutes ago by zatso on twitterVery good explanation of JMX
1 day 12 minutes ago by Babith B on Managing applications with JMXThe reaction to a report issued Tuesday by Flurry Analytics managed to completely overlook some interesting news--the Android-based Motorola Droid outsold the original iPhone over the same period of time following their respective launches--to focus instead on the sales numbers for the Nexus One.
1 day 15 minutes ago by lonemavericks on diggsAnother ZTE story....
1 day 17 minutes ago by Moderate Your Greed on Philippines opens bid for final 3G licenseWe at www.fifosys.com have also seen a growth in IT outsourcing and anticipate it as a growing field.
1 day 50 minutes ago by sarah Jane on Companies' outsourcing spend to increaseI agree with you. The iSiVaL is super portable and TVs can't expand their image size. I recorded a video that might bring some ideas to...
1 day 21 minutes ago by Jesse B Andersen on Buying a projector? Try an LED TV insteadhermm... he deserved it.. he shud not talk abt sensitive things like tat, well, he shud think twice before saying all those things, event...
1 day 59 minutes ago by ... on Facebook user charged in MalaysiaPassword manager tools are potential security threat. Criminals who hack into the computer can use the password manager to log onto any s...
2 days 59 minutes ago by ohanae on What defaults should random password generators use?I've found the cross platform utility unetbootin to be rather handy for this kind of thing as well.
2 days 33 minutes ago by Jim on Use Live USB Creator to install Fedora 12 from a USB stickThanks for the article. I think the debug command has an "\" after "C:" it should say w32tm /debug /enable /file:C:\l...
2 days 34 minutes ago by Roger Biefer on Manage time accuracy with W32Tmavailable in singapore now
http://www.portablemall.com.sg/goods-71-Microsoft+Zune+HD+32GB+-+Platinum.html
How about just using http://www.random.org/strings/? It is very configurable, satisfies all of the flexibility requirements you have ment...
2 days 16 minutes ago by Varun V Nair on What defaults should random password generators use?Wi-Fi as the "Rodney Dangerfield of wireless", is a catchy metaphor, but it's already been used. In fact, it was the title of a...
2 days 15 minutes ago by Martin Suter on Selina Lo: Wired up for Wi-Fi in AsiaDear Sir/Madam, I am Narasimha Rao.L. From bangalore India , i searching job in abroad , in electronics field, i have 6+ years exp....
3 days 17 minutes ago by Anonymous on Hot tech jobs in SingaporeGood article, computational aspect of acquired knowledge from the social platform is really questionable, given that there are a lot of p...
3 days 23 minutes ago by JN on What will social analytics say about your company?The Desktop Virtualization Revolution is here!
Find our more with Citrix Simplicity is Power
2010 IT Salary & Skills Report
Find out the salary range of IT professionals. Join activeTechPros for free access to the report.
The Internet Show 2010, 21-22 Apr 2010, Singapore
FREE admission for visitors who pre-register online. Register Today!