Disclaimer: The opinions of the columnists are their own and not necessarily those of their employer.
Executive Women's Forum - Information Security, Risk Management and Privacy

Tag Archives: Vulnerability Commentary

bloginfosec.com Interviews Jeremiah Grossman on Web App Security

– One of the many blogs on which I keep a close eye is that of Jeremiah Grossman. His expertise is in web application security. I made his acquaintance at the 16th Annual NY Metro ISSA conference and had the good fortune to watch his Cross Site Request Forgery (CSRF) presentation. I had the chance…

Spidey Gives Goblin Ping of Death? An Enemy Toy BSOD!

– The Mega Bloks Spiderman toy shows a BSOD in the Goblin’s lab. One can see the blue screen on the main website here. I couldn’t believe it until I saw it on the main Mega Bloks site. According to Mega Bloks: Inside the Secret Lab, the new Goblin has created the ultimate device to make…

Exclusive: Tribeca Film Festival has Software Glitch

– (Update 4/8/2007 - 3:12PM): A representative from TFF contacted me as a professional courtesy and explained the measures they are taking to correct the issue and prevent it in the future. As an organization they are really responsive and care about their customers. It’s my professional…

Attack Vectors Through the Pragmatic Use of Steganography

– The BBC reports that Fujitsu has discovered pragmatic uses for steganography. Unfortunately, by redirecting the mobile phone’s browser automatically, this could lead to using these images as attack vectors. Here are some quotes from the BBC report: “The key is to take the yellow hue…

Patent No. 7,124,197: ARP Poisoning Hack!

– Can one patent a hack? Great question: report here. …