Security Log
Computerworld -
CA Reveals Antivirus Flaw
Computer Associates International Inc. disclosed a serious security flaw in its antivirus products. The bug, which affects the Vet antivirus engine underlying CA's enterprise and consumer security software, could be exploited by a remote attacker via a specially crafted Microsoft Word document to cause a heap overflow and execute malicious code, according to CA. Enterprise users received a patch at the beginning of this month.
Files Encrypted, Held Hostage
A hacker has found a way to encode computer files and hold them hostage until the victim pays for a decoder tool, said Websense Inc., which uncovered the extortion attempt. But there's a way to avoid paying ransom: Lurhq Corp. said it found the encryption scheme relatively easy to break.
Security Bookshelf
Silence on the Wire: A Field Guide to Passive Reconnaissance and Indirect Attacks, by Michal Zalewski (No Starch Press, 2005).
When I first flipped open this book, I was intimidated by the author's use of a somewhat complex mathematical equation to determine the type of browser used to send IP packets. But I became fascinated by his approach to network security from a reconnaissance point of view; most security books focus on attacks. Though the book probably isn't for entry-level security pros, senior analysts and engineers will find it useful. Most chapters start with an interesting anecdote before getting down to some fairly technical details. Zalewski's explanations make it clear that he's tops in the industry.
-- Mathias Thurman

Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
A Truly Global HCM System
Learn about a system built with advanced object-oriented technology that support multi-national requirements and costs less to implement, maintain and upgrade....
Usability Is Everything
Learn what sets Workday's HR and Payroll solutions apart from the competition....
Moving Beyond Monolithic - What's Next for Enterprise Application Architectures?
This white paper reviews the current state of enterprise application architecture and presents a prediction on what might come next....
SaaS at Flextronics, Inc.
Dave Smoley, CIO of Flextronics, discusses the real value of software-as-a-service and why he chose Workday for his HR solution....
The Shortcut Guide to Managing Certificate Lifecycles
(Source: Thawte) If you have ever shopped for a certificate, you know that there is a wide selection of products and vendors from...
Agile Enterprise Content Management (ECM) for Rapid ROI
Find out how combining ECM and BPM will help adress issues about content rich business processes....
MarketVibe: Communications and Collaboration Needs at Business Organizations
In April 2009, IT and business leaders were invited to participate in a survey on business communications and collaboration solutions. The goal of...
Modernizing the IT Infrastructure
(Source: Oracle) There is a lot of legacy in many government IT systems today - legacy hardware, legacy software platforms, and legacy skills...
The Value of Network and Application Visibility by Aberdeen
This survey-based paper analyzes best practices for improving application visibility and analysis. This paper can help serve as a guideline for organizations looking...
Taking the Service Desk to the Next Level
Listen to this conversation with Doug Mueller to learn how standards and processes have evolved to bring us the service desk of today...
Subscribe to Computerworld
