Articles

Mobile Application Security: New Frontier in Security

January 31st, 2011

 - Hackers are an evolutionary group of people who are always looking for new and innovative ways to breach applications, steal vital customer data and wreak havoc on the Web.  For years, hackers have targeted Windows (continue reading...)

We May Not Be Facing a Full-Scale Cyber War, But The Battle Rages On

January 23rd, 2011

 - Many industry and government leaders have been discussing how the U.S. is now facing a full-scale cyber war and potential repercussions – from U.S. transportation, energy and communications systems being brought to a standstill, (continue reading...)

How often should you test your web applications?

January 19th, 2011

 - Periodic and consistent security checks – that’s the recipe for effective Web security, right? We hear this “best practice” recommendation all the time. It’s true but (continue reading...)

Real Physical Security

January 18th, 2011

 - This is very interesting in so many ways…very representative of the security controls in many organizations.   What’s the weakest link in your security program?Courtesy of Rogers Security Blog (continue reading...)

How to choose a web vulnerability scanner

January 4th, 2011

 - A must read interview for anyone who is interested in evaluating web vulnerability scanners.  In this interview we discuss the process of choosing a web vulnerability scanner and underline several factors that should be taken (continue reading...)

10 great ways to get hacked in the New Year

December 29th, 2010

 - It’s that time of year for us to get inundated with all those Top 10 lists to help us achieve this, prevent that and so on. (continue reading...)

Assessing the “Hidden” Dangers of Application Security

December 18th, 2010

 - By Greg Reber, CEO, AsTech ConsultingAlthough the gulf oil spill is fading from public consciousness, it is an apt metaphor for IT professionals who ignore application security at their peril. In the case of the (continue reading...)

Which scan policy should you use to find everything that matters?

December 13th, 2010

 - If only Web application security were black and white. We could simply load our scanner without thinking anything through, enter the URL, (continue reading...)

Google XSS Flaw in Website Optimizer Scripts explained

December 9th, 2010

 - This week thousands of system administrators who make use of Goolge products will open their inbox to see an email from Google explaining that (continue reading...)

DOM based Cross-site Scripting vulnerabilities

December 6th, 2010

 - While a traditional cross-site scripting vulnerability occurs on the server-side code, document object model based cross-site scripting is a type of vulnerability which affects the script code in the client’s browser.
DOM or the document object (continue reading...)

Statistics from a phisher’s list

November 30th, 2010

 - Yesterday night I was following some security related forums and some person posted a phishing kit for a popular bank from Romania.  A phishing (continue reading...)

Facebook’s Big Security Problem Could Be Its Downfall

November 29th, 2010

 - By Greg Reber, CEO, AsTech ConsultingFacebook application developers were recently suspended after being caught selling user information to data brokers. While it is no secret that Facebook makes its profits off of (continue reading...)

HTTP Post Denial Of Service: more dangerous than initially thought

November 22nd, 2010

 - Wong Onn Chee and Tom Brennan from OWASP recently published a paper* presenting a new denial of service attack against web servers.
What’s special about this (continue reading...)

Notable changes in PCI DSS 2.0 affecting Web application security

November 18th, 2010

 - “Clarification, additional guidance, and evolving requirements” – welcome to the new PCI standards! Hot off the press are the new PCI DSS and PA-DSS requirements which (continue reading...)

Application Security; Don’t get caught off guard with dangerous assumptions

November 9th, 2010

 - Don’t get caught off guard. We hear that statement all the time with regards to information security. Sadly, as many businesses have experienced, such talk is (continue reading...)

Preventing phishing attacks is not just a technical issue

October 26th, 2010

 - A client of mine who’s a security administrator for a business in the financial industry contacted me recently about some odd behavior he was seeing (continue reading...)

Internet Voting Trial Thwarted by Hackers

October 18th, 2010

 - The District of Columbia recently attempted to give the opportunity to a number of people who live or work overseas to be able to (continue reading...)

Four skills that will make you a better Web security professional

October 14th, 2010

 - People who are at the top of their games such as Formula One engineers, neurosurgeons, stunt pilots and so on have one thing in common: (continue reading...)

Why all the hoopla over the Twitter onMouseOver flaw?

September 27th, 2010

 - The recent publicity and ranting about Twitter’s onMouseOver flaw* got me thinking about our perception of software quality and expectations of risk. Why is there no (continue reading...)

How to check if your application is vulnerable to the ASP.NET Padding Oracle Vulnerability

September 22nd, 2010

 -  Everybody’s talking about the ASP.NET Padding Oracle vulnerability released a few days ago at the ekoparty Security Conference. However, until now there wasn’t enough (continue reading...)

Copyright © 2012 The Security Blog. All rights reserved.