Archive for the 'Articles' Category
Sunday, February 11th, 2007
Anurag Agarwal announced a series of professional portraits of the gurus in Web Applications Security .
Quoting Anurag :
Every friday i will present a major player from the web application security field and outline his contributions to the industry.
The series of mini biographies is called Reflection and this week’s security superstar was Amit Klein. […]
Share This
Leave Comment » | Posted in Web Applications, Articles
Friday, February 9th, 2007
The new buzz of the Google Webmaster Tools’ Link has spread like wildfire. However, this great tool had a serious vulnerability which permitted to gain access to the links statistics of any website.
Share This
Leave Comment » | Posted in Web Applications, Articles
Thursday, February 8th, 2007
Bruce Schneier released a great essay on the Psychology of Security exploring how psychology can help explain the difference between the feeling of security and the reality of security.
Share This
Leave Comment » | Posted in Articles
Friday, January 26th, 2007
Testing Fault Injection in Local Applications proves to be a great resource for describing the local resources and interprocess communication,
Share This
Leave Comment » | Posted in Articles
Friday, January 19th, 2007
These are the best online resources in web application security :
Share This
Leave Comment » | Posted in Web Applications, Articles
Thursday, January 18th, 2007
An ingenious way of breaking the same-origin policy by undermining dns-pinning :
Share This
1 Comment » | Posted in Web Applications, Articles
Tuesday, January 16th, 2007
The Cross-site Request Forgery FAQ has been released to address some of the common questions and misconceptions regarding this commonly misunderstood web flaw.
Share This
Leave Comment » | Posted in Web Applications, Articles
Sunday, January 14th, 2007
Here is a good resource on the good, the bad and the ugly of using NetBIOS NULL Sessions as attack target
Share This
Leave Comment » | Posted in Null Sessions, Articles
Wednesday, January 10th, 2007
an interesting article on automated vulnerability scanners and the limitations of these tools in finding real life web application vulnerabilities .
Share This
Leave Comment » | Posted in Penetration Testing, Web Applications, Articles
Tuesday, January 9th, 2007
The following column was published on SecurityFocus today:
PHP apps: Security’s Low-Hanging Fruit
by Kelly Martin
published 2007-01-08
PHP has become the most popular application language on the web, but common security mistakes by developers are giving PHP a bad name. Here’s how PHP coding errors have become the new low-hanging fruit for attackers, contributing to the phishing problems […]
Share This
2 Comments » | Posted in Web Applications, Php, Articles
Pages (5): « First ... « 1 2 3 [4] 5 »