<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.fiercecio.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>cross site scripting</title>
 <link>http://www.fiercecio.com/tags/cross-site-scripting</link>
 <description></description>
 <language>en</language>
<item>
 <title>Google faces security hurdles in the enterprise</title>
 <link>http://www.fiercecio.com/story/google-faces-security-hurdles-in-the-enterprise/2007-07-16?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;P&gt;Google seems to be everywhere these days, but as the search giant moves into the enterprise, they&#039;re facing much of the same security scrutiny as those who have gone before them. Researchers at Ponemon Institute are expected to release a report today that outlines the concerns among IT professionals regarding the overall security of Google Desktop, the company&#039;s PC search utility, specifically within the confines of business operations. Their research revolves around a cross-site scripting vulnerability reported and subsequently patched by Google in February; the authors of the report say that their work underscores a growing level of concern over the company&#039;s rapidly expanding footprint in the enterprise. In a survey of more than 600 IT security specialists who indicated that they were familiar with the Google Desktop vulnerability, an overwhelming 71 percent said that they believe that the product likely harbors other security flaws. The company is trying to address security through its acquisitions of software vendors and has sponsored malware research projects such as Stopbadware.org.&lt;/P&gt;
&lt;P&gt;For more on Google&#039;s security challenge in the enterprise:&lt;BR&gt;- read all the details in this&amp;nbsp;&lt;EM&gt;Infoworld.&lt;/EM&gt; &lt;A href=&quot;http://www.infoworld.com/article/07/07/12/Mounting-scrutiny-for-Google-security_1.html&quot;&gt;Article &lt;BR&gt;&lt;/A&gt;&lt;/P&gt;

</description>
 <comments>http://www.fiercecio.com/story/google-faces-security-hurdles-in-the-enterprise/2007-07-16#comments</comments>
 <category domain="http://www.fiercecio.com/tags/business-operations">Business Operations</category>
 <category domain="http://www.fiercecio.com/tags/cross-site-scripting">cross site scripting</category>
 <category domain="http://www.fiercecio.com/tags/footprint">footprint</category>
 <category domain="http://www.fiercecio.com/tags/google">Google</category>
 <category domain="http://www.fiercecio.com/tags/google-desktop">Google Desktop</category>
 <category domain="http://www.fiercecio.com/tags/malware">Malware</category>
 <category domain="http://www.fiercecio.com/tags/mergers-and-acquisitions">Mergers and Acquisitions</category>
 <category domain="http://www.fiercecio.com/tags/outlines">outlines</category>
 <category domain="http://www.fiercecio.com/tags/protective-measures">Security</category>
 <category domain="http://www.fiercecio.com/tags/security-flaws">security flaws</category>
 <category domain="http://www.fiercecio.com/tags/software-vendors">software vendors</category>
 <category domain="http://www.fiercecio.com/tags/vulnerability">Vulnerability</category>
 <pubDate>Sun, 15 Jul 2007 20:01:39 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">4091 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Choosing a good application security tool</title>
 <link>http://www.fiercecio.com/story/choosing-a-good-application-security-tool/2006-08-04?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;P&gt;Anyone building a application knows the value of quality assurance testing. But many organizations may not realize the additional aspect of testing a new application&#039;s security power. As experts relate, today&#039;s QA teams need to bring security to the top of the agenda and make sure that new code and software development is free of SQL injection and cross-site scripting. The first step is finding the right security testing tool and an automated product is a good choice. Find out the 11 questions you need to answer before finalizing the product buy.&lt;/P&gt;
&lt;P&gt;For more on a good application security tool:&lt;BR&gt;- take a look at this &lt;A href=&quot;http://security.itworld.com/4367/060802webappsecurity/page_1.html&quot;&gt;article&lt;/A&gt; at &lt;EM&gt;Securityitworld.com&lt;/EM&gt;&lt;/P&gt;

</description>
 <category domain="http://www.fiercecio.com/channel/business-intelligence">Business Intelligence</category>
 <category domain="http://www.fiercecio.com/tags/cross-site-scripting">cross site scripting</category>
 <category domain="http://www.fiercecio.com/channel/data-management-storage">Data Management/Storage</category>
 <category domain="http://www.fiercecio.com/channel/it-security">IT Security</category>
 <category domain="http://www.fiercecio.com/tags/security-tool">security tool</category>
 <category domain="http://www.fiercecio.com/tags/software-development">software development</category>
 <category domain="http://www.fiercecio.com/channel/it-strategy-planning">Strategy &amp;amp; Planning</category>
 <pubDate>Thu, 03 Aug 2006 20:01:35 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">1807 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Firefox patches deemed &quot;highly critical&quot;</title>
 <link>http://www.fiercecio.com/story/firefox-patches-deemed-highly-critical/2006-07-28?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;P&gt;It&#039;s got to be a tough work week over at Mozilla as the browser maker releases 13 security patches for Firefox, eight of which are deemed &quot;critical.&quot; And one researcher terms the entire patch update as &quot;critical&quot; for enterprises since two thirds of the vulnerabilities are tied to JavaScript and can let hackers initiate cross-site scripting and dump nasty code on vulnerable systems in a slew of ways.&lt;/P&gt;
&lt;P&gt;For more on the Firefox security patches:&lt;BR&gt;- see this &lt;A href=&quot;http://www.informationweek.com/news/showArticle.jhtml;jsessionid=T4DHHIUOD1Y1AQSNDLRSKH0CJUNN2JVN?articleID=191502530&quot;&gt;article&lt;/A&gt; at &lt;EM&gt;InformationWeek&lt;/EM&gt;&lt;/P&gt;

</description>
 <category domain="http://www.fiercecio.com/tags/cross-site-scripting">cross site scripting</category>
 <category domain="http://www.fiercecio.com/tags/firefox">Firefox</category>
 <category domain="http://www.fiercecio.com/tags/initiate">initiate</category>
 <category domain="http://www.fiercecio.com/channel/it-best-practices">IT Best Practices</category>
 <category domain="http://www.fiercecio.com/channel/it-security">IT Security</category>
 <category domain="http://www.fiercecio.com/tags/thunderbird">Mozilla</category>
 <category domain="http://www.fiercecio.com/channel/it-networking">Networking</category>
 <category domain="http://www.fiercecio.com/tags/researcher">researcher</category>
 <category domain="http://www.fiercecio.com/tags/security-fixes">security patches</category>
 <category domain="http://www.fiercecio.com/channel/it-web-services">Web Services</category>
 <pubDate>Thu, 27 Jul 2006 20:01:37 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">1753 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Security blind spot: Web applications</title>
 <link>http://www.fiercecio.com/story/security-blind-spot-web-applications/2006-07-20?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;P&gt;For all its greatness, today&#039;s Web is also the big hornet&#039;s nest in every security manager&#039;s world as Web applications pose the greatest security threat, according to a new report from Fortify Software. The problem is that people don&#039;t know as much about security when it comes to Web applications as compared to other threats. Notably, viruses, worms and other hacking malware have been the primary focus in keeping enterprise data safe. But as the report notes, bot storms pose a huge security risk to Web applications, as does cross-site scripting.&lt;/P&gt;
&lt;P&gt;For more on the Web application security issues:&lt;BR&gt;- take a look at this &lt;A href=&quot;http://www.techworld.com/security/news/index.cfm?newsID=6482&amp;pagtype=all&quot;&gt;article&lt;/A&gt; at &lt;EM&gt;Techworld&lt;/EM&gt;&lt;/P&gt;

</description>
 <category domain="http://www.fiercecio.com/channel/business-intelligence">Business Intelligence</category>
 <category domain="http://www.fiercecio.com/tags/cross-site-scripting">cross site scripting</category>
 <category domain="http://www.fiercecio.com/channel/it-security">IT Security</category>
 <category domain="http://www.fiercecio.com/tags/malware">Malware</category>
 <category domain="http://www.fiercecio.com/channel/it-networking">Networking</category>
 <category domain="http://www.fiercecio.com/tags/security-risk">security risk</category>
 <category domain="http://www.fiercecio.com/tags/techworld">techworld</category>
 <category domain="http://www.fiercecio.com/tags/security-threats">Threat Management</category>
 <category domain="http://www.fiercecio.com/tags/viruses">Viruses</category>
 <category domain="http://www.fiercecio.com/tags/web-applications">web applications</category>
 <category domain="http://www.fiercecio.com/channel/it-web-services">Web Services</category>
 <category domain="http://www.fiercecio.com/tags/worm">Worms</category>
 <pubDate>Wed, 19 Jul 2006 20:01:35 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">1685 at http://www.fiercecio.com</guid>
</item>
<item>
 <title>Researcher finally gets his security warning heard</title>
 <link>http://www.fiercecio.com/story/researcher-finally-gets-his-security-warning-heard/2006-06-29?utm_medium=rss&amp;utm_source=rss&amp;cmp-id=OTC-RSS-FC0</link>
 <description>&lt;P&gt;When executives and security leaders at Microsoft and Amazon were told about vulnerabilities related to the two companies&#039; Web sites, the security warnings went unheeded and ignored. So the researcher who discovered the flaws took his message to the Web and guess what? Microsoft is working on patching the cross-site scripting vulnerability and Amazon is working to fix the bugs related to its retailing site.&lt;/P&gt;
&lt;P&gt;For more on getting the security message across:&lt;BR&gt;- read this &lt;A href=&quot;http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9001507&quot;&gt;article&lt;/A&gt; from &lt;EM&gt;IDG&lt;/EM&gt;&lt;/P&gt;

</description>
 <category domain="http://www.fiercecio.com/tags/amazon">amazon</category>
 <category domain="http://www.fiercecio.com/tags/bugs">bugs</category>
 <category domain="http://www.fiercecio.com/channel/business-intelligence">Business Intelligence</category>
 <category domain="http://www.fiercecio.com/tags/cross-site-scripting">cross site scripting</category>
 <category domain="http://www.fiercecio.com/channel/it-security">IT Security</category>
 <category domain="http://www.fiercecio.com/tags/microsoft">Microsoft</category>
 <category domain="http://www.fiercecio.com/channel/it-networking">Networking</category>
 <category domain="http://www.fiercecio.com/tags/researcher">researcher</category>
 <category domain="http://www.fiercecio.com/tags/security-leaders">security leaders</category>
 <category domain="http://www.fiercecio.com/tags/vulnerability">Vulnerability</category>
 <category domain="http://www.fiercecio.com/channel/it-web-services">Web Services</category>
 <pubDate>Wed, 28 Jun 2006 20:01:37 -0400</pubDate>
 <dc:creator />
 <guid isPermaLink="false">1542 at http://www.fiercecio.com</guid>
</item>
</channel>
</rss>
