News (104)

Firm offers new tools for database security

Security software developer Guardium is expected to formally announce Monday a new suite of integrated security applications for databases, a market that's gaining traction in the current regulatory environment. Read more »

Oracle 10g release two arrives

This month should see the release of the a more secure version of Oracle's grid database. Read more »

Oracle patches 45 security vulnerabilities

In its latest quarterly patch cycle, Oracle has released 45 fixes for various security flaws. Read more »

Oracle sews up multiple security holes

As part of its quarterly patch cycle, Oracle on Tuesday released fixes for a long list of security vulnerabilities in many of its products. Read more »

Oracle plugs 65 security holes

As part of its quarterly patch cycle, Oracle on Tuesday in the US released fixes for 65 security vulnerabilities that affect many of its products. Read more »

Oracle no longer a 'bastion of security': Gartner

Analyst group Gartner has warned administrators to be "more aggressive" when protecting their Oracle applications because they are not getting enough help from the database giant. Read more »

IBM brings management tools to mainframe

IBM later this year plans to release management tools for its mainframe server, including a "federated" security application for logging onto several systems at once. Read more »

Microsoft looks to extinguish LAMP

The threat of open source web application software has led the software giant to produce smaller, cheaper versions of some of its tools. Read more »

Oracle's Beehive buzzes at OracleWorld

Oracle unveiled a new open enterprise software application on Monday in the US, designed to improve the way users collaborate and communicate on projects. Read more »

Most Oracle database admins don't apply patches?

Around 70 percent of Oracle database professionals say they have never applied a security patch, according to database security firm Sentrigo. Read more »

Features (202)

SQL Server: Design for security from the start

Security in the development of a SQL Server database must be a priority right from the start, beginning with the design process. Familiarise yourself with these guidelines before you start your next project and you will prepare a more secure database application. Read more »

Web application security frameworks (WASF), Part 2: Database lookup

Often, you will want parts of your Web application to be exclusive to certain users. This access distinction requires the use of Web application security frameworks. Continuing our series on Web app security, we explore the database lookup framework. Read more »

Web application security frameworks (WASF), Part 1: Introduction

Often you will want parts of your Web application to be exclusive to certain users. This access distinction requires the use of Web application security frameworks. This first article in the series introduces you to the three most often used methods. Read more »

Develop secure software at the application level

Protect your application from input overflow and underflow attacks, and from other common tactics with these development techniques. Read more »

How to build secure ASP.NET applications

ASP.NET provides several ways to protect your Web-based app from attack. Here's an overview of authentication, authorisation, and role-based security. Read more »

Develop applications that prevent intrusion

Designing secure applications requires developers to look beyond their own code. Accessing APIs or COM objects or establishing system privileges can result in security vulnerabilities that can be prevented. Read more »

Follow these steps to secure your data layer

A secure data layer is essential for a truly secure application. Learn how to nurture a secure environment for the pivotal Data tier of your application with the correct tools. Read more »

Designing secure intranet applications

During the design phase, engineering and security teams must work together to ensure intranet applications meet the established security standards. Read more »

Add security to applications by using JAAS

Java Authentication and Authorization Service (JAAS) provides the ability to implement the two things that any decent security system needs: authentication and authorisation. See how JAAS may save you time and effort the next time you need to add security to your Java app. Read more »

Do you need an application server?

If you're big on technology trends, you may be considering which application server to put in place. But the first question you should ask is whether you truly need one. Read more »

Blog (4)

The 2008 Trends and Threats to Internet security

Lana Kovacevic [blogs:webanatomy] -- I recently came across the IBM Internet Security Systems X-Force 2008 Mid-Year Trend Statistics report, which outlines issues affecting internet security, including application vulnerabilities, phishing, malware and spam. Read more »

Salesforce's new AIR toolkit

Staff [blogs:syslog] -- Following the announcement that Salesforce will provide a free toolkit for Adobe Flex and AIR development on its Force.com platform, I spoke to the company’s Doug Farber, the Vice President of Operations, Asia Pacific about its functionality and other issues surrounding the toolkit. Read more »

Google Gears screenshots

Brendon Chase [blogs:codemonkeybusiness] -- Here is a bit of eye candy of the new Google Gears installation and sample code. Read more »

Attack Modeling vs Threat Modeling

[blogs:] -- Traditional Threat Modeling from an adversarial approach is actually Attack Modeling. So what is Threat Modeling then and how does it differ from Attack Modeling? Read more »

Log in


Sign up | Forgot your password?

What's on?