201 members
46 members
14 members
64 members
32 members
28 members
Loading feed
The purpose of this articel to describe substantive audit procedure related to IT audit. This article will cover the following areas:
* The objective of substantive procedures
* The risk factors
*
Posted on July 4, 2008 at 7:30pm — 2 Comments
For those who read my article Cracking access to Bank this paper may be interesting from the securing transactions point of view.
As we identified that that the m
Posted on June 9, 2008 at 4:38pm —
Why hackers do not like script-kiddeis ? May be you think that hackers hate tham just because guys do not know how to intrude the system or do not know how to craft an exploit... may be... some of kiddies really annoying. However, nobody was born clever. And if we ju
Posted on June 9, 2008 at 10:00am — 4 Comments
The purpose of this article is to show the real threat for banks' clients that use on-line banking services for processing bank documents and transactions in "real-time". On-line banking services are used in our days by 99% of legal entities. In my practice I have see
Posted on June 7, 2008 at 7:00pm — 4 Comments
Be careful! Once you scanned your workstation using TrendMicro HOUSECALL this ActiveX component will stay in your system. That means that anyone can exploit this vulnerability. The vulnerable methods are listed below:
showAlert()
setOption()
isOptionAvail
Posted on June 6, 2008 at 4:30am —
Do you know what is Client-Bank application ? That is electronic transaction system that allows to work with bank account through the Internet. The on of the types of Client-Bank applications is the web-based client bank, that check signatures and e-tokens data using the ActiveX control. I reviewed the one (http://bssys.com/eng).
The result was (integer overflow):
Exception Code: ACCESS_VIOLATION
Disasm: 1D0BB96 MOV EDI,[ESI+3C] (
Posted on June 6, 2008 at 4:00am —
Yesterday I was really surprised to know that Aeroflot has operational vulnerability in reservation of tickets process (the part of tickets sales). As it happens Aeroflot allows to perform tickets reservations via WEB and this reservations include desired s
Posted on June 4, 2008 at 4:00am — 2 Comments
What are the risks and why we always looking for controls? How can we pass controls over and what do we need it for? These questions are normal! I am going to describe simplified audit procedures related to Information Technologies and Information Security audits.
Posted on June 2, 2008 at 8:30am —
Posted on May 31, 2008 at 2:00pm —
Posted on May 31, 2008 at 1:11pm — 1 Comment
© 2009 Created by pdp on Ning. Create a Ning Network!