Archive for January, 2007
Tuesday, January 30th, 2007
(OWASP) has released the first draft of the 2007 edition of the Ten Most Critical Web Application Security Vulnerabilities. Over the years, this document has turned into a de facto web application vulnerability checklist.
Share This
Leave Comment » | Posted in Web Applications
Saturday, January 27th, 2007
Ever wondered how could you find all the sub-domain hosts starting your search just from the domain name ?
Share This
Leave Comment » | Posted in Fingerprinting, Tools
Saturday, January 27th, 2007
Java Source Code Audit tools
Share This
Leave Comment » | Posted in Code Audit, Web Applications, Tools
Saturday, January 27th, 2007
Because a lot of web applications rely on the session id for all the authentication and authorization , knowing the strength of the algorithm behind the session ID generation is essential.
Share This
Leave Comment » | Posted in Web Applications, Tools
Friday, January 26th, 2007
The first step is to decompile the .swf file and extract as many resources as possible.
Share This
Leave Comment » | Posted in Web Applications, Tools
Friday, January 26th, 2007
Testing Fault Injection in Local Applications proves to be a great resource for describing the local resources and interprocess communication,
Share This
Leave Comment » | Posted in Articles
Sunday, January 21st, 2007
Anti-Spyware program for Mac OS X, MacScan. Version 2.3 adds a blacklisted cookie scanner.
Share This
Leave Comment » | Posted in Mac OS X
Friday, January 19th, 2007
These are the best online resources in web application security :
Share This
Leave Comment » | Posted in Web Applications, Articles
Friday, January 19th, 2007
OWASP is happy to announce the first release of OWASP Pantera - Web
Assessment Studio. Pantera is a mix between a pentest proxy, an application
scanner, and an intelligent analysis framework. Pantera’s goal is to leave
the analysis and automatic (repetitive) stuff to the engine, leaving only
the important decisions to the security expert.
Great tool !
OWASP Pantera Web […]
Share This
Leave Comment » | Posted in Penetration Testing, Web Applications, Tools
Friday, January 19th, 2007
The Open Web Application Security Project (OWASP) is dedicated to finding and fighting the causes of insecure software. Everything here is free and open source.
OWASP has released the Security Testing Guide v2 .At 270 pages, this guide is already a must-have for most developers and penetration/application testers, but we want to take it one step […]
Share This
Leave Comment » | Posted in Penetration Testing, Framework, Web Applications
Pages (3): [1] 2 3 »