Archive for the ‘LINKS’ Category.

The SOAP Opera Progresses – Helping XML to Rule the World

The SOAP Opera Progresses – Helping XML to Rule the World
-by Michael F. Reed

An important emerging standard in the web arena, known as SOAP (Simple
Object Access Protocol), originally developed by Microsoft, has achieved
a new milestone. Since IBM joined in support for the SOAP standard with
increased security, SOAP may replace DCOM, and possibly even CORBA
eventually. The W3C consortium has just released a new version, 1.2,
which will be widely accepted and adopted by vendors.

New worm encrypts .exe files

New worm encrypts .exe files. CW360.com Aug 31 2001 11:49AM ET [via Moreover Computer security news]

A Stateful Inspection of FireWall-1 (paper)

Sun shows off new version of StarOffice

An Audit of Active Directory Security

Aaron Sullivan, Security Focus:

An Audit of Active Directory Security:

Part One: An Overview of Active Directory and Security [August 1, 2001]

Part Two: Understanding the Security Implications of Active Directory Default Settings [August 29, 2001]

Security software: blind lead blind

Security software: blind lead blind. Commentary by Elias Levy

It’s incredible that in this day and age some of the most popular security products, products that are marketed as protecting you from the evils of computers, are so badly designed.

Case in point: The many antivirus products that failed to detect and stop the highly effective SirCam worm, even when updated with the latest signatures and when configured correctly.

Symantec’s Norton Antivirus for Gateways v2.x, Norton Antivirus POP email scanner, and TrendMicro’s InterScan VirusWall Standard and CVP editions version 3.51 build 1321 for Windows NT all failed to block SirCam. Why? Because all products “failed open,” i.e., when they encountered email messages they couldn’t handle properly, they sent them through by default.



[via The Register]

Microsoft: Dos and Don’ts of Client Authentication on the Web

Web Application Security:

White Hat Defcon9 presentation: Web Application Security

MIT (Fu, Sit, Smith, Feamster): Dos and Don’ts of Client Authentication on the Web

More cross-site scripting vulnerabilities

More cross-site scripting vulnerabilities from
White Hat Security:

Hotmail STYLE CSS Vulnerability [08.15.2001]

Another MS Hotmail Security Issue with further widespread implications [08.24.2001]

Radio Waves Zap Zebra Mussels

Radio Waves Zap Zebra Mussels. Zebra mussels, a particularly hearty invasive species, have caused millions of dollars in damage to U.S. boats and power plants. Scientists may now have a way to combat the pesky mollusks. From the Environment News Service. [Wired News]

Offensive Trojan horse can disable systems