Snifula banking Trojan battles local Japanese security product
Snifula variant blocks image on bank’s website advising users to install PhishWall security software.
Snifula variant blocks image on bank’s website advising users to install PhishWall security software.
このブログではウェブサイトやその上で動作しているウェブアプリケーションの脆弱性について紹介すると共に注意喚起をする目的でまとめられています。
今回は代表的なWebアプリケーション脆弱性であるクロスサイトリクエストフォージェリについて解説をしています。
このブログではウェブサイトやその上で動作しているウェブアプリケーションの脆弱性について紹介すると共に注意喚起をする目的でまとめられています。
今回は代表的なWebアプリケーション脆弱性であるディレクトリトラバーサルについて解説をしています。
The latest news in the SSL and web browser industries is Google’s plans to deprecate SHA-1 in a unique way on upcoming releases of Chrome starting with version 39. Considerably different from Microsoft’s plans that were announced in November 2013, Google plans on placing visual marks or placing a block within the browser; all based on the version of the browser, date of use and certificate’s expiration date.
Here is what you need to know first:
What we expect to see with future Chrome releases:
Chrome 39 (Beta release: 26 September 2014, tentative production release: November 2014):
Chrome 40 (Beta release: 7 November 2014, tentative production release: post-holiday season):
Chrome 41 (Q1-Q2 2015):
Here is a matrix to help you understand the dates:
|
Sample Expiration Dates |
||||
Chrome Version (Beta dates) |
SHA-1 (Dec 31 2015) |
SHA-1 (Jan 1 – May 31 2016) |
SHA-1 (Jun 1 – Dec 31 2016) |
SHA-1 (Jan 1 2017 and beyond ) |
Recommended: SHA-2 |
Chrome 39 (Sept. 2014) |
|||||
Chrome 40 (Nov. 2014) |
|||||
Chrome 41 (Q1 2015) |
Moral of the story: Move to SHA-2, especially if your SSL certificate expires after December 2015.
What you need to do.
For more in-depth information, instructions, and assistance please refer to our knowledge center article on this subject. For a list of SHA-2 supported and unsupported applications review this list from the CA Security Council.
Read our SHA-2 webpage for the tools, steps to take, and a list of FAQs that can be generally applicable across all browsers.
Trend Micro Security 2015 supports multiple devices across all platforms to improve consumer security and privacy
Ability to scan and block malicious apps prior to installation on device provides users with superior security
Apple Pay の登場によって POS システムのセキュリティが向上する可能性がありますが、攻撃者も新しい技術のセキュリティについて徹底的にテストすると考えられます。
Apple está incursionando al mercado de los pagos. Recientemente, Apple dio a conocer dos nuevos modelos de iPhone, además del Apple Watch. Durante el anuncio Apple también presentó los detalles de Apple Pay, opción que permitirá a los usuarios realizar pagos usando la tecnología inalámbrica Near Field Communication (NFC).
The arrival of Apple Pay could help improve point-of-sale security but attackers are also likely to severely test the security of the new technology.
Read more…
Guest Blogger: John Monnett, V.P. & Partner, Secure128
Website Security Platinum Partner
Shopping Cart Abandonment is a Staggering 70%
In 2014 we’re living through an online revolution. When I started my university undergrad work in 1991, there was virtually no such thing as “e-commerce” as we know it today. In 2014, worldwide business-to-consumer ecommerce sales are estimated to reach nearly $1.5 Trillion.
How can those of us SMB owners capture a share of the ecommerce market most efficiently? There are many contributors to that conundrum, but one of the simplest ways to decrease website shopping cart abandonment is by increasing the level of trust that visitors have in your website—from the moment they arrive. Shopping cart abandonment rates average a staggering 70%, and a key driver of abandonment is lack of visitor trust at the moment of truth: the transaction.
How Can SMBs Compete and Reduce Shopping Cart Abandonment?
Most SMB website operators don’t have the same level of brand recognition and trust that companies like Ebay, Bank of America and Symantec have built over time. Instead, sites like ours only have a brief moment to establish the same, irrefutable level of confidence as the big names. We need to leverage a combination of credible tools like the Extended Validation green bar, an HTTPS “always on” encrypted site and trust seals from Symantec, the leader in online trust. They help us:
• Secure our websites properly
• Prove our legal identity to visitors
• Align our web properties with the most recognizable security brands
We do business with Symantec because they have an extensive portfolio full of “Right for Me” solutions to help Secure128 and our customers. They have the right solution for every SSL/website security need to help inspire the same level of trust as our larger, widely recognized competitors and to level the playing field. So instead of trying to compete on brand recognition against the larger, more established companies, we can absolutely compete on trust and security.
Always On SSL + Extended Validation: A Powerful Advantage for SMBs
Securing our websites is most effectively done with encryption via SSL Certificates. And now “Always On SSL” with HTTPS encryption is becoming the security standard of web giants such as Paypal, twitter, facebook, etc. Even to the point that now Google is boosting rankings for HTTPS/SSL websites . Deploying SSL certificates across all website properties is no longer an option; it’s a requirement of operating an effective and secure business online. From a revenue increase perspective, the problem is that basic SSL certificates (also called DV or Domain Validated SSL) provide encryption only. The biggest mistake most website operators make is only encrypting their websites and providing visitors no way of verifying their true business identity.
For example, when shopping online for that perfect gift, your search lands you on a website you’ve never heard of with no easy way to verify who really owns and operates the website. Only Extended Validation (EV) SSL Certificates were created to bridge the gap between encryption AND ownership validation of websites. EV SSL Certificates not only verify domain ownership, but also the legal and governmental business registration status of the certificate/website owner. This information is then displayed at the browser URL level:
A simple click on the padlock will verify the physical location where each EV SSL website organization is registered to do business. The EV SSL functionality standards are standardized by a Certificate Authority / Browser regulatory group, and audited annually for Webtrust certification. Now, what does this mean to a website visitor and potential online customer? It means that no matter how non-technical they may be, the green URL bar displaying the website’s legal owner is going to be hard to miss, and has been proven to instill more trust in the website’s visitors and increase conversion rates.
The Leader in Online Trust, Always the Right Solutions
With every Certificate Authority offering their own brand of EV SSL options, decisions in making the selection that is right for your business comes down to both price and which brand is going to be most recognizable to your site visitors. In an independent 2013 survey by the Baymard Institute, all three of Symantec’s EV capable SSL branded site seals were ranked in the top 7 most recognized (Symantec, thawte & GeoTrust).
When you look at Symantec’s complete solutions portfolio, you’ll see the widest range of value, functionality and proven results for Symantec’s three SSL brands, especially when it comes to EV products. Symantec is is quite flexible for all website budgets making it easy to choose the right solution for you. For high volume web properties, brand recognition and performance issues take priority which makes Symantec’s industry-first Elliptic Curve Cryptography (ECC) Algorithm my EV SSL option of choice for larger e-commerce sites.
In the bigger picture, all of us web based business operators are trying to achieve similar goals of growing website traffic, boosting conversion rates, and increasing our online sales revenues. All of us invest significant resources into our websites in terms of design & development, marketing, advertising, security, etc.
Given those common goals, if I could tell you that by converting your entire sitemap to HTTPS using Extended Validation SSL from one of Symantec’s globally recognized brands (Symantec, thawte, or GeoTrust), you could significantly increase your online sales revenue and only increase your annual budget by a fraction of a percentage… would you do it?
My fellow website operators, that’s exactly what I’m telling you!