24 Jun 2008 @ 10:18 PM 

Microsoft Security Advisory (954462): Rise in SQL Injection Attacks Exploiting Unverified User Data Input

Microsoft is aware of a recent escalation in a class of attacks targeting Web sites that use Microsoft ASP and ASP.NET technologies but do not follow best practices for secure Web application development. These SQL injection attacks do not exploit a specific software vulnerability, but instead target Web sites that do not follow secure coding practices for accessing and manipulating data stored in a relational database. When a SQL injection attack succeeds, an attacker can compromise data stored in these databases and possibly execute remote code. Clients browsing to a compromised server could be forwarded unknowingly to malicious sites that may install malware on the client machine.

Mitigating Factors:  This vulnerability is not exploitable in Web applications that follow generally accepted best practices for secure Web application development by verifying user data input.

  • Share/Save/Bookmark
Tags Categories: Security Posted By: jmiles
Last Edit: 24 Jun 2008 @ 10 18 PM

EmailPermalinkComments (0)

 This doesn’t seem appropriate, so I hope it’s not true and is just some hysteria.  I would expect that all published info could to be taken into account in a hiring decision.

Employers who check out job candidates on MySpace could be legally liable | View from the Cubicle | TechRepublic.com
If a potential employer uses a social networking site to check out a job candidate and then rejects that person based on what they see, he or she could be charged with discrimination.

  • Share/Save/Bookmark
Tags Categories: Infrastructure Posted By: jmiles
Last Edit: 20 Jun 2008 @ 07 23 AM

EmailPermalinkComments (0)
 10 Jun 2008 @ 10:58 PM 

Microsoft Security Bulletin Summary for June 2008
This bulletin summary lists security bulletins released for June 2008.

  • Share/Save/Bookmark
Tags Categories: Security Posted By: jmiles
Last Edit: 10 Jun 2008 @ 10 58 PM

EmailPermalinkComments (0)
 06 Jun 2008 @ 8:39 PM 
Tags Categories: Security Posted By: jmiles
Last Edit: 06 Jun 2008 @ 08 39 PM

EmailPermalinkComments (0)
 05 Jun 2008 @ 4:52 AM 

 Here’s a technique that works some of the time to solve one of the most pesky problems…

A simple fix for Microsoft Update problems | Tech of all Trades | TechRepublic.com


Microsoft Windows … One of the endearing and annoying features of this ubiquitous OS is the monthly patch update process. Most of the time it occurs seamlessly. It just kind of works in the background when you’re not looking. However, there are times when it rears its ugly head and demands attention.

  • Share/Save/Bookmark
Tags Categories: Infrastructure, Security Posted By: jmiles
Last Edit: 05 Jun 2008 @ 01 55 PM

EmailPermalinkComments (0)
 02 Jun 2008 @ 6:35 AM 

 This is a great article with lots of real-world technology and product reviews and advice.  Look especially at CIO and author John Halamka’s “self pilot” partway down the page.

How I Learned to Stop Worrying and Love Telecommuting
…Given these facts, [the author believes] IT leaders are obligated to explore the entire spectrum of flexible work arrangements including telecommuting, homesourcing (a combination of outsourcing and telecommuting), virtual teams, and replacing travel with teleconferencing. Staffing an office from 8 a.m. to 5 p.m. doesn’t make sense if it requires employees to spend hours in traffic.

  • Share/Save/Bookmark
Tags Categories: Advanced, Infrastructure, Leadership Posted By: jmiles
Last Edit: 02 Jun 2008 @ 09 39 AM

EmailPermalinkComments (0)
\/ More Options ...
Change Theme...
  • Users » 4
  • Posts/Pages » 191
  • Comments » 5
Change Theme...
  • VoidVoid
  • LifeLife
  • EarthEarth
  • WindWind « Default
  • WaterWater
  • FireFire
  • LightLight

About Jim Miles



    No Child Pages.

Contact



    No Child Pages.

Case Studies



    No Child Pages.

Prioritized Approach to PCI



    No Child Pages.