al3x + infosec   50

SecDocs
IT Security and Hacking knowledge base
infosec  documentation  presentation  archive 
february 2010 by al3x
Moth
"a VMware image with a set of vulnerable Web Applications and scripts"
infosec  education  vmware  virtualmachine  webapp 
july 2009 by al3x
NaCl
"a new easy-to-use high-speed software library for network communication, encryption, decryption, signatures, etc."
crypto  infosec  library  java  python 
july 2009 by al3x
Automated Protocol Reverse Engineering
"At the end of the day you are likely to still be doing a significant amount of reverse engineering manually, however employing one or more of the automated tools and techniques prior to this undertaking can certainly clear away some of the low-hanging fruit and give you some momentum in the correct direction."
reversing  protocol  network  analysis  infosec 
january 2009 by al3x
XSS (Cross Site Scripting) Prevention Cheat Sheet
"a simple positive model for preventing XSS using output escaping/encoding properly"
cheatsheet  javascript  xss  infosec  web 
january 2009 by al3x
pcapr
"a repository of [...] packets, providing full-text search, automatic tagging, viewing and editing of these packets"
packet  capture  social  pcap  network  infosec  search  tagging  couchdb  jquery 
january 2009 by al3x
CWE/SANS Top 25 Most Dangerous Programming Errors
"a list of the most significant programming errors that can lead to serious software vulnerabilities"
infosec  programming  reference  list  errors  testing 
january 2009 by al3x
How To Suck at Information Security
"The following list presents common information security mistakes and misconceptions, so you can avoid making them."
infosec  list  advice 
january 2009 by al3x
MD5 considered harmful today
"We have identified a vulnerability in the Internet Public Key Infrastructure (PKI) used to issue digital certificates for secure websites. As a proof of concept we executed a practical attack scenario and successfully created a rogue Certification Authority (CA) certificate trusted by all common web browsers. This certificate allows us to impersonate any website on the Internet, including banking and e-commerce sites secured using the HTTPS protocol."
ssl  cryptography  md5  infosec  pki 
december 2008 by al3x
Cryptol
"a domain specific language for the design, implementation and verification of cryptographic algorithms, developed over the past decade by Galois for the United States National Security Agency"
programming  language  cryptography  haskell  infosec 
december 2008 by al3x
Google Browser Security Handbook
"This document is meant to provide web application developers, browser engineers, and information security researchers with a one-stop reference to key security properties of contemporary web browsers."
google  web  infosec  book  browser 
december 2008 by al3x
Deputy
"a C compiler that is capable of preventing common C programming errors, including out-of-bounds memory accesses as well as many other common type-safety errors"
c  infosec  programming  compiler  check 
december 2008 by al3x
google-caja
Makes JavaScript safe(-ish?) for IFRAMEs and widgets and such.
google  caja  javascript  infosec 
december 2008 by al3x
Unicornscan
"a new information gathering and correlation engine built for and by members of the security research and testing communities"
infosec  network  scanner  opensource 
october 2008 by al3x
Fast flux
"a DNS technique used by botnets to hide phishing and malware delivery sites behind an ever-changing network of compromised hosts acting as proxies"
network  dns  infosec  botnet  malware 
august 2008 by al3x
iPwn
"reliable, pre-configured platforms that work with cutting-edge security software"
laptop  linux  infosec 
july 2008 by al3x
Ross Anderson's Home Page
Security economics is so totally my jam.
infosec  compsci  economics  academic  research 
july 2008 by al3x
SecUrls
"The Information Security Industry at a Glance". Meh, could be better.
infosec  aggregator 
july 2008 by al3x
ratproxy
"A semi-automated, largely passive web application security audit tool, optimized for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-ini
infosec  google  ajax  csrf  http  testing  proxy 
july 2008 by al3x
the tls report
"delivers the tools, information, and visibility to reveal problems in TLS configurations and offer better alternatives so folks can improve their security posture and make sure it stays improved"
ssl  web  infosec  reference 
june 2008 by al3x
The problem(s) with OpenID
I'm fairly neutral about OpenID, and I think the spec itself is fairly explicit about not attempting to solve the problems listed herein. That said, there's a ton of real-world, right-now problems to tackle here.
openid  Identity  authentication  criticism  infosec  phishing 
march 2008 by al3x
codepad
"a pastebin that runs your code for you".
programming  web  social  infosec 
march 2008 by al3x
Steal This Wi-Fi
Bruce Schnier sez: open your home wi-fi network. I just wish my current ISP (Yginition) wouldn't send a nastygram every time I sustain 400k/sec down.
infosec  wireless 
january 2008 by al3x
Prevx
"Prevx's Community Intrusion Prevention (CIP) system identifies malicious code by its 'behavior' and is able to neutralize whole classes of malware before it ever has a recognized signature"
infosec  malware 
december 2007 by al3x
XSS | Musings
a Ruby implementation of the sanitization approach taken in the Universal Feed Parser. to be incorporated into acts_as_sanitized ASAP.
ruby  infosec  xss 
march 2007 by al3x
XSSed
XSS (cross-site scripting) information and vulnerable websites archive
infosec  xss  list 
february 2007 by al3x
ATLAS Dashboard: Global Summary
"a sub-set of the intelligence derived from the ATLAS sensor network on host/port scanning activity, zero-day exploits and worm propagation, security events, vulnerability disclosures and dynamic botnet and phishing infrastructures"
infosec  network  monitoring  trends 
february 2007 by al3x
Damn Vulnerable Linux
The most vulnerable and exploitable operating system ever
linux  distribution  infosec  exploits  humor 
november 2006 by al3x
ArpSpyX
Monitor Arp Traffic on OS X
infosec  mac  network 
april 2006 by al3x
SecLists
Security Mailing List Archive
infosec  list 
june 2005 by al3x
djeaux :: RSS newsfeeds
rss feeds for popular infosec lists and sites
infosec  rss 
june 2005 by al3x

Copy this bookmark:



description:


tags: