Archive for the 'Articles' Category

Web App Security Hall Of Fame - Meet the Gurus

Anurag Agarwal announced a series of professional portraits of the gurus in Web Applications Security .
Quoting Anurag :
Every friday i will present a major player from the web application security field and outline his contributions to the industry.
The series of mini biographies is called Reflection and this week’s security superstar was Amit Klein. […]

Share This

Secret Feature / Vulnerability in Google Webmaster Tools

The new buzz of the Google Webmaster Tools’ Link has spread like wildfire. However, this great tool had a serious vulnerability which permitted to gain access to the links statistics of any website.

Share This

How good are you at making security trade-offs ?

Bruce Schneier released a great essay on the Psychology of Security exploring how psychology can help explain the difference between the feeling of security and the reality of security.

Share This

Security Assessment of Local Applications

Testing Fault Injection in Local Applications proves to be a great resource for describing the local resources and interprocess communication,

Share This

Web application security resources

These are the best online resources in web application security :

Share This

Hacking the Intranet with JavaScript Anti-DNS Pinning

An ingenious way of breaking the same-origin policy by undermining dns-pinning :

Share This

The Cross-site Request Forgery FAQ

The Cross-site Request Forgery FAQ has been released to address some of the common questions and misconceptions regarding this commonly misunderstood web flaw.

Share This

NetBIOS NULL Sessions Explained

Here is a good resource on the good, the bad and the ugly of using NetBIOS NULL Sessions as attack target

Share This

Automated Scanner vs. The OWASP Top Ten

an interesting article on automated vulnerability scanners and the limitations of these tools in finding real life web application vulnerabilities .

Share This

SecurityFocus Article - PHP apps: Security’s Low-Hanging Fruit

The following column was published on SecurityFocus today:
PHP apps: Security’s Low-Hanging Fruit
by Kelly Martin
published 2007-01-08
PHP has become the most popular application language on the web, but common security mistakes by developers are giving PHP a bad name. Here’s how PHP coding errors have become the new low-hanging fruit for attackers, contributing to the phishing problems […]

Share This
Pages (5): « First ... « 1 2 3 [4] 5 »
Close
E-mail It