News (48)

Mozilla celebrates 10th birthday with a security flaw

The Mozilla Foundation is celebrating what it regards as its 10th anniversary this week. Read more »

Apple's Leopard hacked in 30 seconds

Apple's Leopard has been hacked within 30 seconds using a flaw in Safari, with rival OSes Ubuntu and Vista so far remaining impenetrable in the CanSecWest PWN to OWN competition. Read more »

Firefox phishing vulnerability discovered

A newly discovered flaw in Firefox could allow cybercriminals to take advantage of Web surfers. Read more »

Microsoft outlines IE7 security plans

Microsoft is tightening up the way its Internet Explorer browser handles HTTPS for version 7, which is used to secure online transactions, in an attempt to give people more protection online. Read more »

Exploit code makes IE flaw more dangerous

The threat posed by a critical flaw in Internet Explorer has been ratcheted up by the release of a program designed to exploit the vulnerability, security researchers warned on Thursday. Read more »

Flawed Safari browser endangers Windows users

Two security flaws have been found in the recently released Windows version of Apple's Safari browser — despite Apple's attempts to increase the user-base for Safari, its small size will help protect users, say security experts. Read more »

Security flaw discovered in latest Firefox update

Vulnerability researcher Ronald van den Heetkamp published a directory traversal flaw in Firefox version 2.0.0.12, just hours after Mozilla release the latest version of its browser. Read more »

Microsoft patches zero-day Windows Media flaw

Microsoft on Tuesday in the US released seven security updates with patches for 11 security vulnerabilities, most of which affect the Windows operating system. Read more »

Firefox add-on Greasemonkey slips up

The Mozilla Foundation is making available an update for a critical security flaw in Greasemonkey, an extension to the Firefox browser. Read more »

Major graphics flaw threatens Windows PCs

Microsoft published on Tuesday a patch for a major security flaw in its software's handling of the JPEG graphics format and urged customers to use a new tool to locate the many applications that are vulnerable. Read more »

Features (13)

Windows' HTML converter vulnerability rated Critical

A problem has been discovered in the way Windows handles HTML file conversion during cut-and-paste. This buffer overrun could allow an attacker to run rogue code. Read more »

Develop a VoiceXML solution using BeVocal

VoiceXML (VXML) is a markup language like HTML. The difference is that a phone browser rather than a Web browser renders VXML. Get started with this article. Read more »

Clickjacking: Potentially harmful web browser exploit

Clickjacking has the potential to redirect unknowing users to malicious websites or even spy on them. We all need to be aware of clickjacking and how to avoid its trappings. Read more »

When will Microsoft fully embrace Web standards?

I recently revisited the issue of using Web standards when working with Microsoft SharePoint 2007 and Outlook 2007. The products' lack of adherence to Web standards was surprising given the advancements incorporated in Internet Explorer 7. Read more »

Bug hunters, software firms in uneasy alliance

Although many software makers promote responsible disclosure, it isn't universally backed by the security community. Critics say it could make security companies lazy in patching. Full disclosure of flaws is better is preferred. Read more »

IE is evolving, but is it enough?

Microsoft's Internet Explorer Web browser is in the process of getting its first significant update in two years this week, as part of the company's overhaul of its operating system. Read more »

Are keywords the answer for font sizing?

With font sizes in CSS, you have three choices: absolute measurements, relative measurements, and keywords. Here's why we think keywords are the best compromise Read more »

The secrets of open source security

The Linux vs. Windows security debate is a contest of examples, which stand in place of the concepts that comprise a larger, more fundamental question of what the security benefits and detriments are for the open source and closed source development models. Read more »

Get a grip on your site traffic with ClickTracks

The market is flooded with click-stream analysis tools, and each one claims to provide you with data. See why ClickTracks may be head and shoulders above the rest. Read more »

Develop secure software at the application level

Protect your application from input overflow and underflow attacks, and from other common tactics with these development techniques. Read more »

Blog (1)

What to expect from Rich Internet Applications

Matt Overington [blogs:bricksandmortar] -- I had a look this week at what the developers claim to be the world's largest Adobe Flex application. Read more »

Log in


Sign up | Forgot your password?

What's on?