Archive for the 'Web Applications' Category

PHP vs. PHP. Live bugs every day during March

It seems that Esser’s initiative to disclose one PHP vulnerability each day during March 2007 is unpopular among core PHP developers, especially for Zeev Suraski, co-creator of PHP and chief technology officer of Zend, which manages PHP development.

Drive-By Pharming - Let me fine tune your DNS entries

ABC News reports on a new attack vector targeted at broadband routers / acces points : Drive-By Pharming.

Here is the definitive fix for Universal PDF XSS Vulnerability

The (in) famous Adobe Acrobat Reader Plugin Universal PDF XSS is the scariest vulnerability discovered this year because it can turn any pdf into an XSS attack vector.

Alarming WordPress Security Vulnerabilities

Due to the really huge install base, I really hope that the folks at wordpress.org issue a patch quickly to address these vulnerabilities.

How to Turn Firefox Into an Attack Webserver

amazing that this nifty tool supports Server-side JS, GET, POST, uploads, Cookies, SQLite and AJAX.

Web App Security Hall Of Fame - Meet the Gurus

Anurag Agarwal announced a series of professional portraits of the gurus in Web Applications Security .
Quoting Anurag :
Every friday i will present a major player from the web application security field and outline his contributions to the industry.
The series of mini biographies is called Reflection and this week’s security superstar was Amit Klein. [...]

Secret Feature / Vulnerability in Google Webmaster Tools

The new buzz of the Google Webmaster Tools’ Link has spread like wildfire. However, this great tool had a serious vulnerability which permitted to gain access to the links statistics of any website.

Ten Most Critical Web Application Security Vulnerabilities

(OWASP) has released the first draft of the 2007 edition of the Ten Most Critical Web Application Security Vulnerabilities. Over the years, this document has turned into a de facto web application vulnerability checklist.

Java Source Code Audit Tools

Java Source Code Audit tools

Stompy - Web Session ID Algorithm Analyzer

Because a lot of web applications rely on the session id for all the authentication and authorization , knowing the strength of the algorithm behind the session ID generation is essential.

Pages (7): « First ... « 3 4 5 [6] 7 »