Apple defuses Safari “Carpet Bomb”

Friday, June 20th, 2008

Apple has closed four security holes in the Windows version of its Safari browser with the release of version 3.1.2. The fixes include the browser's "Carpet Bomb" behaviour of placing downloaded files on the desktop by default and without asking the user's permission. In association with with Internet Explorer – ...

Successful 802.1X Every Time

Friday, June 20th, 2008

It’s not rocket science, but any time we mingle and intertwine four or five different pieces of technology, there’s always the potential for a mess… or at least a misconfiguration or two along the way. Don’t know what 802.1X is? Check out the recent 802.1X technology primer. If you’re planning to, ...

Desktop virtualisation gets military-grade security

Friday, June 20th, 2008

Tresys Technology has released a desktop virtualisation platform with a difference - it is designed from the ground up for organisations needing tight security, including military bodies. Tresys, which has a track record of providing military systems, said its VM Fortress can cut costs for organisations which would like to implement ...

Firefox 3 suffers its first vulnerability

Wednesday, June 18th, 2008

Less than one day after its launch, Firefox 3 has a vulnerability. According to Tipping Point's Zero Day Initiative, the vulnerability, which it rates as critical, was reported within the first five hours of Firefox 3's release. "Once the vulnerability was verified in TippingPoint's DVLabs and acquired from the researcher, the vulnerability ...

The Extended HTML Form attack revisited

Wednesday, June 18th, 2008

"HTML forms (i.e. <form>) are one of the features in HTTP that allows users to send data to HTTP servers. An often overlooked feature is that due to the nature of HTTP, the web browser has no way of identifying between an HTTP server and one that is not an ...