Sponsored Links
Security Guards & Patrol
Los Angeles & Orange County Commercial Industrial 800-994-2482
Security Product Industry
Research an industry- Competitors, trends, sics, naics & more. Try it.
SQL Injection used in Heartland, 7-Eleven and Hannaford Breaches
Blog | www.gdssecurity.com | Aug 19, 2009
Having recently seen our book SQL Injection Attacks and Defense come out, it is very timely indeed to see in the news of the recent indictment of Albert Gonzalez that SQL Injection played a key part in the Heartland Payment Systems, 7-Eleven, and Hannaford Brothers breaches, as well as for two
Tech expert offers three plays on cyber security
Blog | www.bloggingstocks.com | May 29, 2009
Filed under: Newsletters, Stocks to Buy, Obama PicksWith
http://www.bloggingstocks.com/2009/05/29/tech-expert-offers-three-plays-on-cyber-security/
Hannaford Breach May Presage '08 Trend - Washington Post
Blog | blog.washingtonpost.com | Mar 19, 2008
The latest news on computer, technology and network security issues. A blog by washingtonpost.com reporter Brian Krebs. Visit www.washingtonpost.com/technology.
http://blog.washingtonpost.com/securityfix/2008/03/hannaford_breach_may_presage_0.html
Key Principles in Writing Secure Code Webinar
Blog | feedproxy.google.com
We just wrapped up a webinar titled “Key Principles in Writing Secure Code” for one of our training partners, Intense School. The target audience was primarily folks involved with application development looking for an introduction to Application Security.
http://feedproxy.google.com/~r/GdsSecurityBlog/~3/Tsvcm0E8qCg/
The Logic behind Measuring IT Security ROI | Measure, control and improve IT security
There is a need for businesses to measure IT security ROI, whether they like it or not. This is a worthy investment enterprises should consider taking on. Seldom would you find a business that does not have an existing IT department in the corporate world nowadays.
http://www.aks-labs.com/blog/the-logic-behind-measuring-it-security-roi.htm
Sponsored Links
Corporate Security
Risk organization for developing security strategy plans.
Creating a Patch for Human Stupidity
Blog | www.gdssecurity.com | Apr 8, 2009
Social engineers use old tricks and new to bypass firewalls and other conventional IT security defences by taking advantage of human weakness or kindness to attack secure buildings, machine rooms, or trading floors from inside. This gives them access to information and data that they simply
http://www.gdssecurity.com/l/b/2009/04/08/creating-a-patch-for-human-stupidity/
OWASP Boston Slides and SPF Public Demo Site
Blog | www.gdssecurity.com | Dec 4, 2008
The slide deck from the Tamper Proofing Web Applications at Runtime talk I gave last night at the OWASP Boston meeting are now available for download.We also released version 1.0.1 of SPF earlier this week and have a public SPF demo site running .NET PetShop v4 from MSDN. [...]
http://www.gdssecurity.com/l/b/2008/12/04/owasp-boston-slides-and-spf-public-demo-site/
When ASP.NET EventValidation Doesn’t Work
Blog | www.gdssecurity.com | Mar 19, 2009
As a developer or security tester, it is important to know how built-in security mechanisms like EventValidation work. Starting with version 2.0 of the .NET Framework, Microsoft introduced the concept of “EventValidation” for validating PostBack data. The principal behind EventValidation is fairly
http://www.gdssecurity.com/l/b/2009/03/19/when-aspnet-eventvalidation-doesnt-work/
Source Boston IIS7 Slides Posted
Blog | www.gdssecurity.com | Mar 17, 2009
My slides from the Source Boston conference last week have been posted for public consumption. The talk discussed some of the cool new built-in features of IIS7, like the Integrated Request Pipeline and Request Filtering. Additionally, it covered the new modular architecture of IIS7 and discussed
http://www.gdssecurity.com/l/b/2009/03/17/source-boston-iis7-slides-posted/
Key Principles in Writing Secure Code Webinar
Blog | www.gdssecurity.com | Oct 29, 2008
We just wrapped up a webinar titled Key Principles in Writing Secure Code for one of our training partners, Intense School. The target audience was primarily folks involved with application development looking for an introduction to Application Security. Here are some of the key
http://www.gdssecurity.com/l/b/2008/10/29/key-principles-in-writing-secure-code-webinar/

