[SC-L] Dark Reading - CERT Seeks Secure Coding Input

2006-07-25 Thread Robert C. Seacord
Speaking of interesting articles from Dark Reading: http://www.darkreading.com/document.asp?doc_id=99807&WT.svl=news1_1 This is relatively early exposure for this effort. I am hoping to engage the folks on this list (and elsewhere) in this effort in the fall once the public wiki is stood up. I

Re: [SC-L] Forwarded: PHP encryption for the common man

2006-07-25 Thread mikeiscool
On 7/26/06, Kenneth Van Wyk <[EMAIL PROTECTED]> wrote: > > FYI, I saw an interesting article today on IBM's web site detailing how to > (and how NOT to) use encryption within PHP code. Those interested can find > the article at: > > http://www-128.ibm.com/developerworks/library/os-php-encrypt/inde

[SC-L] Forwarded: PHP encryption for the common man

2006-07-25 Thread Kenneth Van Wyk
FYI, I saw an interesting article today on IBM's web site detailing how to (and how NOT to) use encryption within PHP code.  Those interested can find the article at:http://www-128.ibm.com/developerworks/library/os-php-encrypt/index.html?ca=drs-Cheers,Ken Kenneth Van WykKRvW Associates, LLChttp://w

Re: [SC-L] Dark Reading - Application and Perimeter Security - Hacking the Vista Kernel - Security News Analysis

2006-07-25 Thread SC-L Subscriber Dave Aronson
Pete Shanahan [mailto:[EMAIL PROTECTED] writes: > I'm just wondering how flawed the implementation of the windows > paging model is that it would allow for this kind of breach. The > standard model I'm familiar with would simply flush the page from > memory, and would not keep a copy in the ex

Re: [SC-L] Dark Reading - Application and Perimeter Security - Hacking the Vista Kernel - Security News Analysis

2006-07-25 Thread Pete Shanahan
Hang on a minute, I thought you had to have administrator access before you were permitted raw access to the hard drive. The createfile documentation tells us that opening a physical disk / Volume requires that the caller must have administrative privileges. I'm just wondering how flawed the impl

[SC-L] Dark Reading - Application and Perimeter Security - Hacking the Vista Kernel - Security News Analysis

2006-07-25 Thread Kenneth Van Wyk
Here's an interesting article from Dark Reading regarding a software attack on the existing Vista beta:http://www.darkreading.com/document.asp?doc_id=99780&f_src=darkreading_section_296I noticed, in particular, that the attack is against a design weakness of Vista -- "The attack doesn't use your ty