XML White Papers
Command Injection in XML Signatures and Encryption
Overview The XML Digital Signature (XMLDSIG) and XML Encryption (XMLENC) standards are complex protocols for securing XML and other content. Among its complexities, the XMLDSIG standard specifies various "Transform" algorithms to identify, manipulate and canonicalize signed content and key material. Unfortunately, the defined transforms have not been rigorously constrained to prevent their use as attack vectors, and denial of service or even arbitrary code execution are probable in implementations that have not specifically guarded against such risks.
| Publisher | Information Security | File Format | |
|---|---|---|---|
| Date Published | July 2007 | ||
| Format | White Papers | ||
| Topics | |||
Web Server Improvements with Microsoft Server 2008
This is another in our series about Microsoft Longhorn, also known as Server 2008. In this series we break down the most important components of Longhorn and give listeners the...
Adobe LiveCycle solutions for intuitive user experiences
With AdobeŽ LiveCycleŽ Enterprise Suite (ES2) software, organizations like yours can easily deploy intuitive user experiences, using flexible guides and RIAs to help increase customer satisfaction and achieve a lower...
Home Retailer Implements New Store Locator With Avaya Interactive Response (IR) and RSI IVR Solutions and Services
A leading national large-format retailer of home textiles, housewares and decorative home accessories has over 400 stores in the United States and Canada. The home retailer's expansion made limitations inherent...
Advanced Java Memory Analysis with JProbe
Memory issues in Java applications can cripple performance and cost your business time and money - so proper Java memory analysis is crucial. However, identifying Java memory leaks isn't easy...
Understanding The Critical Role Of Device Management And Security In Your Business' Mobile Strategy
In January 2009, Sybase commissioned Forrester Consulting to assess the importance of mobile device management and, in particular, mobile security and the associated issues that keep CXOs up at night. While...



