30.12.2012 Views

download issue 27 here - Help Net Security

download issue 27 here - Help Net Security

download issue 27 here - Help Net Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Employees admit they would steal data when leaving a job<br />

Employees openly admit they would take company data, including customer<br />

data and product plans, when leaving a job, according to Harris Interactive.<br />

The online survey probed 1,594 full- and part-time employees and contractors<br />

in the United States and Great Britain about their attitudes toward accessing<br />

and viewing of company-owned data. (www.harrisinteractive.com)<br />

Publicly trusted secure e-mail certificates<br />

PCI standard changes ahead<br />

Entrust adds publicly trusted secure e-mail certificates to its certificate management<br />

service, enabling digital signature capabilities and encryption of emails<br />

and other documents. Based on the X.509 certificate standard, Entrust<br />

Secure E-mail Certificates enable standards-based S/MIME capabilities.<br />

(www.entrust.com)<br />

The PCI <strong>Security</strong> Standards Council published documentation highlighting the<br />

expected changes to be introduced with version 2.0 of the PCI DSS and PA-DSS<br />

in October 2010. Version 2.0 of PCI DSS and version 2.0 of PA-DSS do not introduce<br />

any new major requirements. (www.pcisecuritystandards.org)<br />

Millions of Coldfusion sites need to apply patches<br />

ProCheckUp were able to access every file including username and passwords<br />

from a server running ColdFusion. This was completed through a directory traversal<br />

and file retrieval flaw found within ColdFusion administrator. A standard<br />

web browser was used to carry out the attack, knowledge of the admin password<br />

is not needed. (www.procheckup.com)<br />

D-Link routers get DNSSEC and CAPTCHA protection<br />

D-Link enhanced its router security by incorporating both CAPTCHA<br />

and DNSSEC to guard against hacking, worms, viruses and other<br />

malicious Web attacks. (www.dlink.com)<br />

Loss of personal information as stressful as losing a job<br />

Americans feel most vulnerable about the loss or theft of their personal or financial<br />

information. Fifty-four percent of Americans said the prospect of losing<br />

this data “extremely concerned” them (based on a rating of eight or higher on<br />

a 10-point scale). Losing personal or financial information ranked similar to<br />

concern over job loss (53 percent) and not being able to provide healthcare<br />

for their family (51 percent). (www.antiphishing.org)<br />

www.insecuremag.com ! ! 7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!