Click here

Security News: Archive: March 2004 

Malicious Cisco Code Circulating

The release of a hacking toolkit to exploit security holes in Cisco products has sent the networking giant scrambling.

It's a (Real) Buffer Overflow Problem

RealNetworks confirms a potential root exploit flaw in multiple Helix Universal Server products.

Personal Quarantine Manager Lists Spam Held at Gateway

A new function included in Tumbleweed Communications' gateway-based Email Firewall enables individual mail recipients to view a list of blocked messages to see which ones should be sent through to them.

Six Apart Trains Guns on 'Comment Spam'

The blog tools vendor plans to roll out an open online authentication system to fight the growing scourge of comment spam.

Zone Labs' Integrity 4.0 Grabs Top Security Award

Datamation readers vote Zone Labs' Integrity 4.0 enterprise firewall and central policy management software as the top security product in our Product of the Year Awards.

Vericept Adds Fraud, Identity Theft Protection

A fraud and identity theft protection package added to enterprise risk management products from Vericept helps companies safeguard customer data such as Social Security numbers, credit card numbers and other personal information.

Generate Memorable Passwords, Automatically!

Generating automatic passwords for your users is a common programming scenario. However, due to the techniques typically employed, most autogenerated passwords end up looking like YPSWW9441 - which, although highly secure, also end up completely unmemorable.

Apache Server Upgrade Tightens Security

Version 2.0.49 of the open source HTTP server offers the latest in bug fixes to prevent denial of service attacks.

Security, Manageability Drive Cisco Upgrades

The network equipment giant unveils a slew of new products and capabilities for its venerable switch line.

NetSec Adds FISMA Reporting Compliance Service

Managed security service provider NetSec announces a new compliance reporting and tracking service aimed at helping government agencies meet the requirements of the Federal Information Security Management Act.

Windows XP SP2 Turns 'On' Pop-up Blocking

Microsoft's coming XP service pack adds a new Windows Security Center and a significant change to the default settings for pop-up blocking in IE.

Plan to Fight Back Against Hackers Causes Stir

A new security company is running with the idea that it's simply not enough to protect a corporate network anymore. They say it's time to fight back. But analysts worry that attacking back will cause even more trouble.

Xacta Improves Compliance Reporting Software

Xacta Corp. releases an upgrade to its security risk management products directed at the government and commercial sectors.

MX Logic Offers Email Defense Gateway to Service Providers

MX Logic, which has sold its Email Defense Gateway system as a managed service to users in the enterprise, government and resellers, is now offering a version for service providers.

Sanctum Updates AppScan Security Testing Tool

Applications security vendor Sanctum Inc. releases a new version of its flagship AppScan tool that features automatic testing of application-specific vulnerabilities related to Web services applications incorporating XML and SOAP.

StillSecure's Latest Adds Quick-scan Vulnerability Assessment

Network security products vendor StillSecure updates its vulnerability management systems software to include a feature designed to enable one-time, on-demand scans with little to no setup.

Cisco Network Admission Control White Paper: The Development of the Self-Defending Network

Learn how to leverage network infrastructure to limit damage from viruses and worms and allow your organization to provide network access to endpoint devices, such as PCs, PDAs, and servers that fully comply with established security policy.

Recovery After a Security Breach

Review best practices for disaster recovery. Topics include: • Implementing an 'incident response process' after a security breach • Compiling useful information for law enforcement • Assessing damage or loss

Guardian Digital Upgrades Secure Mail Suite

The 3.0 version of Secure Mail Suite from Guardian Digital includes a content and policy enforcement engine that addresses user privacy, spam and virus protection, corporate policy enforcement and content analysis.

Disaster Recovery Planning

Learn how to plan for disaster recovery in the Wide Area Network (WAN) environment.

Network Security: Embedded in Network, Integrated in Product

This paper discusses network evolution which is driving the need for security functionality integrated in the network infrastructure and embedded throughout the network.

SAFE Worm Mitigation

This document discusses the recently released Microsoft RPC DCOM attack and the W32/Blaster worm and their effects on the network and its hosts.

Cisco's Bundle of Virus-Fighters

The company combines enterprise security tools and network infrastructure in a quest to develop a 'self-defending network.'

Linux Privilege Escalation Hole Detected

The flaw carries a 'critical' rating and could be exploited to give an attacker full super-user privileges.

HP Plugs 'Critical' Tru64 UNIX Flaws

A successful exploit could lead to remote system takeover.

Buffer Overflow Detected in Adobe Reader

Security researchers have issued warnings for a 'high risk' vulnerability in some versions of the popular Adobe Acrobat Reader.

Content Alarm 1.0 Monitors Exiting Content

Content security start-up Tablus Inc. announces version 1.0 of Content Alarm, a content monitoring, reverse-firewall appliance that employs computational linguistics to detect violations.

Sigaba Bolsters Enterprise Security

A new partnership brings instant messaging applications into the realm of secure e-mail.