<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Technology Blog &#187; web access control</title>
	<atom:link href="http://www.emate-econtent.org/tag/web-access-control/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.emate-econtent.org</link>
	<description>Online Technology News Analysis</description>
	<lastBuildDate>Thu, 22 Dec 2011 01:40:14 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Citibank Hacked</title>
		<link>http://www.emate-econtent.org/technology-news/internet-news/citibank-hacked/</link>
		<comments>http://www.emate-econtent.org/technology-news/internet-news/citibank-hacked/#comments</comments>
		<pubDate>Sat, 11 Jun 2011 14:15:30 +0000</pubDate>
		<dc:creator>hamid</dc:creator>
				<category><![CDATA[Internet News]]></category>
		<category><![CDATA[credit card information]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[web access control]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://www.emate-econtent.org/?p=455</guid>
		<description><![CDATA[<p><a href="http://www.emate-econtent.org/technology-news/internet-news/citibank-hacked/">Citibank Hacked</a></p><p>Latest news state that hackers had broken in to the online account site of Citibank and credit card details, account numbers, and email addresses have been compromised. According to a statement issued by Citigroup, about one percent of the credit card information of their customers has been viewed by the intruders. Citibank boasts an impressive [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.emate-econtent.org/technology-news/internet-news/citibank-hacked/">Citibank Hacked</a></p><p>Latest news state that hackers had broken in to the online account site of <strong>Citibank</strong> and credit card details, account numbers, and email addresses have been compromised. According to a statement issued by <a href="http://www.citi.com/citi/homepage/">Citigroup</a>, about one percent of the credit card information of their customers has been viewed by the intruders.</p>
<p><strong><a href="http://www.emate-econtent.org/wp-content/uploads/img-thing.jpg" rel="lightbox[455]" title="Citibank Hacked"><img class="alignright size-full wp-image-456" src="http://www.emate-econtent.org/wp-content/uploads/img-thing.jpg" alt="" width="300" height="300" /></a>Citibank</strong> boasts an impressive client base of over 21 million credit card customers within North America. The attack was detected when conducting a routine monitoring session. However, exact information on the number of accounts faced the breach were not yet revealed.</p>
<p>However, the information stolen includes a great deal of personal information with the potential to lead to identity theft. Among the compromised data were social security numbers, birth dates, card security codes and even card expiration dates as per the announcement made by the bank.</p>
<p>Sheila Bair, chair of the Federal Deposit Insurance Corporation commented on the matter. According to her statement, both the banks and federal regulators have to remain in constant vigilance to avoid situations such as this from repeating in the future. She further stated that the FDIC and other federal agencies are developing new rules to encourage banks to pay special attention to improve their online security.</p>
<p>However, the attack on <strong>Citibank</strong> is not the only attack of its kind to be reported within the last few weeks. One June 1<sup>st</sup>, <a title="Google Chrome’s Market Share Expected To Rise With New OS" href="http://www.emate-econtent.org/applications/google-chrome-market-share-expected-to-rise-with-new-os/">Google Inc. </a>stated that several personal Gmail accounts belonging to senior U.S. government officials and military personnel were attacked while broadcaster PBS confirmed that the network’s website was hacked on 30<sup>th</sup> May. The widely publicized attack on <a title="Sony Offers Reward to Identify PSN Hackers" href="http://www.emate-econtent.org/technology-news/sony-offers-reward-to-identify-psn-hackers/">Sony’s PSN </a>saw millions of users data compromised and an extended offline period followed by numerous crashes and glitches.</p>
<p>Sean Kevelighan, a spokesman for <strong>Citibank</strong> stated that they are currently contacting affected clients and are tightening their security to prevent future attacks.</p>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emate-econtent.org/technology-news/internet-news/citibank-hacked/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Top 10 Web Security Threats - Part 1</title>
		<link>http://www.emate-econtent.org/security/top-10-web-security-threats-part-1/</link>
		<comments>http://www.emate-econtent.org/security/top-10-web-security-threats-part-1/#comments</comments>
		<pubDate>Sat, 29 Mar 2008 03:42:36 +0000</pubDate>
		<dc:creator>sheri</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[buffer overflows]]></category>
		<category><![CDATA[cross site scripting]]></category>
		<category><![CDATA[encryption]]></category>
		<category><![CDATA[hack attacks]]></category>
		<category><![CDATA[Operating Systems]]></category>
		<category><![CDATA[security vulnerabilities]]></category>
		<category><![CDATA[session cookies]]></category>
		<category><![CDATA[web access control]]></category>
		<category><![CDATA[web applications]]></category>
		<category><![CDATA[web browser]]></category>
		<category><![CDATA[web security]]></category>

		<guid isPermaLink="false">http://www.emate-econtent.org/security/top-10-web-security-threats-part-1/</guid>
		<description><![CDATA[<p><a href="http://www.emate-econtent.org/security/top-10-web-security-threats-part-1/">Top 10 Web Security Threats - Part 1</a></p><p>The Internet and web are becoming increasingly vulnerable with the advancement of technologies and skills of the people who use it for wrong reasons. When compared to early stage hack attacks, recent methods of attacking are very much advance and complex. But there are some techniques used even today introduced some decades ago. Let’s have [...]</p>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.emate-econtent.org/security/top-10-web-security-threats-part-1/">Top 10 Web Security Threats - Part 1</a></p><p>The Internet and web are becoming increasingly vulnerable with the advancement of technologies and skills of the people who use it for wrong reasons. When compared to early stage hack attacks, recent methods of attacking are very much advance and complex. But there are some techniques used even today introduced some decades ago. Let’s have a look at the top 10 web security vulnerabilities in out list.</p>
<p>First - Unvalidated Input. The information that comes from the web browser is not validated by the web application. This way, a third party can alter the web request and pass incorrect or harmful information to the web browser.</p>
<p>Second - <a href="http://httpd.apache.org/docs/1.3/howto/auth.html" target="_blank">Broken Access Control</a>. Even though lot of web applications have frameworks implemented for access control and role authentication, some of these rules are not used effectively in the web application. So mistakenly a regular user maybe assigned higher level of authority.</p>
<p>Third - Broken Authentication and Sessions management. As we know, if you log in to a web application, a unique session is created for you. If this sessions details are not protected correctly (by a technique such as <a href="http://computer.howstuffworks.com/encryption.htm" target="_blank">encryption</a>), some one can steal it and misuse. This way, attackers can compromise password, keys, session cookies etc.</p>
<p>Fourth - Cross Site Scripting (XSS) - A well-known web site that is trusted by end-users can be used by an attacker to transport an attack to the end user. By clicking a link of the trusted website, the end user actually executes a code written by an attacker in another web application or web site. This way, an attacker can disclose the session details, attack the end users machine and provide incorrect content and fool the end user.</p>
<p>Fifth - Buffer Overflows. This is one of the very common and familiar types of attack. This is not common only for web application but also for operating systems. For web applications, an attacker may send a chunk of data which crashes the web application and taken control of some of it’s processes. There are some programming and scripting languages that does not validate whether the data stream id too much and it can crash the web application (Ex: CGI, libraries, drivers and web application server components).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.emate-econtent.org/security/top-10-web-security-threats-part-1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

