Archive for the 'Articles' Category
Sunday, March 11th, 2007
Anurag Agarwal continued his series of Reflections on web security superstars by presenting Ivan Ristic, the man who put ModSecurity on the map of mandatory security controls. Just like before, Anurag covers all the articles, books, tools and great contributions to the information security made by Ivan Ristic.
Share This
Leave Comment » | Posted in Web Applications, Articles
Monday, March 5th, 2007
Cursor Injection - A New Method for Exploiting PL/SQL Injection and Potential Defences David Litchfield, NGSSoftware , released this paper which describes a new method whereby an attacker, seeking to exploit a SQL injection flaw in an Oracle database server, may do so without the need to create an auxiliary inject function in order to execute arbitrary SQL.
Share This
Leave Comment » | Posted in Sql Injection, Articles
Sunday, March 4th, 2007
Anurag Agarwal released the third article from the series of mini biographies called Reflection which so far presented Amit Klein and RSnake ;
Share This
Leave Comment » | Posted in Web Applications, Articles
Sunday, March 4th, 2007
Well, having the SQL server call home to your machine is cool enough (bye bye firewall) , but the paper’s author, Cesar Cerrudo went a step forward . These are the main topics covered by his paper :
Share This
Leave Comment » | Posted in Sql Injection, Articles
Tuesday, February 27th, 2007
It seems that debate over the automatic tools vs. manual penetration tools raises serious questions within the government agencies.South Carolina and Delaware already use Core Impact, other might follow:
Share This
Leave Comment » | Posted in Penetration Testing, Articles
Monday, February 26th, 2007
Nick Baskett wrote an interesting article in it-observer about best practices when hiring an external penetration testing consultant. I hope that more and more business decision makers will apply his advices :
Share This
Leave Comment » | Posted in Penetration Testing, Articles
Friday, February 23rd, 2007
If there is any mention of XSS, there is a big chance RSnake’s name or its cheat sheet is mentioned along with it. His contribution in the web application security awareness is legendary.
Share This
Leave Comment » | Posted in Web Applications, Articles
Tuesday, February 20th, 2007
ABC News reports on a new attack vector targeted at broadband routers / acces points : Drive-By Pharming.
Share This
Leave Comment » | Posted in Web Applications, Articles
Thursday, February 15th, 2007
The February 2007 10th issue of (IN)SECURE Magazine is out ! The topics which are covered include : Microsoft Windows Vista: significant security improvement? Review: GFI Endpoint Security
Share This
Leave Comment » | Posted in Articles
Monday, February 12th, 2007
The (in) famous Adobe Acrobat Reader Plugin Universal PDF XSS is the scariest vulnerability discovered this year because it can turn any pdf into an XSS attack vector.
Share This
Leave Comment » | Posted in Web Applications, Articles
Pages (5): « 1 2 [3] 4 5 »