Skip to main content

Posts

Showing posts with the label security

Google+ Rolls Out Restricted Communities for Corporate Users

Google this week rolled out a new Google+ security feature for organizations intended to help them keep certain conversations private from the larger Web. Much like Microsoft's Yammer, Google+ restricted communities will only allow access to approved employees. "Whether it's designs of your beta product or notes from your team off-site, anything you post will remain restricted to the organization," Google+ product manager Michael Cai wrote in a blog post. Community administrators can decide whether the site will remain open to everyone at the company, or kept private by invitation only. Google+ also allows for people outside of your domain — clients, agencies, business partners — to join the conversation.

Do More to Prevent DNS DDoS Attacks

In recent weeks, numerous high profile organizations and financial institutions have been targets of massive service disruption attacks.  Several of these attacks are characteristically similar to attacks against top level domain name servers in 2006.  ICANN’s Security and Stability Advisory Committee published an Advisory, SAC008 [PDF, 963 KB]: Distributed Denial of Service (DDoS) Attacks, shortly after the 2006 incidents.  Recommendations from that Advisory remain relevant today.  DDoS attacks commonly use IP addresses that are not allocated to the subscriber or IP addresses from reserved/private space to make it difficult to identify sources of attack traffic. This is called IP address spoofing. Access service providers or corporations should apply network ingress filtering (described in SAC004 and recommended by the Internet IAB in BCP038) to prevent spoofing. Squelching attack traffic close to its origins has the added benefit of relieving ISPs from forward...

MySQL Vulnerability Allows Attackers to Bypass Password Verification

Security researchers have released details about a vulnerability in the MySQL server that could allow potential attackers to access MySQL databases without inputting proper authentication credentials. The vulnerability is identified as CVE-2012-2122 and was addressed in MySQL 5.1.63 and 5.5.25 in May. However, many server administrators might not be aware of its impact, because the changelog for those versions contained very little information about the security bug. The vulnerability can only be exploited if MySQL was built on a system where the memcmp() function can return values outside the -128 to 127 range. This is the case for Linux systems that use an SSE-optimized glibc (GNU C library). If MySQL was built on such a system, the code that compares the cryptographic hash of a user-inputted password to the hash stored in the database for a particular account will sometimes allow authentication even if the supplied password is incorrect. The probability of triggerin...