SecDocs
february 2010 by al3x
IT Security and Hacking knowledge base
infosec
documentation
presentation
archive
february 2010 by al3x
YubiKey and OpenID: Two great tastes that taste better together
january 2009 by al3x
This could actually talk me into not loathing OpenID.
infosec
yubikey
usb
multifactor
openid
january 2009 by al3x
Automated Protocol Reverse Engineering
january 2009 by al3x
"At the end of the day you are likely to still be doing a significant amount of reverse engineering manually, however employing one or more of the automated tools and techniques prior to this undertaking can certainly clear away some of the low-hanging fruit and give you some momentum in the correct direction."
reversing
protocol
network
analysis
infosec
january 2009 by al3x
XSS (Cross Site Scripting) Prevention Cheat Sheet
january 2009 by al3x
"a simple positive model for preventing XSS using output escaping/encoding properly"
cheatsheet
javascript
xss
infosec
web
january 2009 by al3x
CWE/SANS Top 25 Most Dangerous Programming Errors
january 2009 by al3x
"a list of the most significant programming errors that can lead to serious software vulnerabilities"
infosec
programming
reference
list
errors
testing
january 2009 by al3x
How To Suck at Information Security
january 2009 by al3x
"The following list presents common information security mistakes and misconceptions, so you can avoid making them."
infosec
list
advice
january 2009 by al3x
MD5 considered harmful today
december 2008 by al3x
"We have identified a vulnerability in the Internet Public Key Infrastructure (PKI) used to issue digital certificates for secure websites. As a proof of concept we executed a practical attack scenario and successfully created a rogue Certification Authority (CA) certificate trusted by all common web browsers. This certificate allows us to impersonate any website on the Internet, including banking and e-commerce sites secured using the HTTPS protocol."
ssl
cryptography
md5
infosec
pki
december 2008 by al3x
Cryptol
december 2008 by al3x
"a domain specific language for the design, implementation and verification of cryptographic algorithms, developed over the past decade by Galois for the United States National Security Agency"
programming
language
cryptography
haskell
infosec
december 2008 by al3x
Google Browser Security Handbook
december 2008 by al3x
"This document is meant to provide web application developers, browser engineers, and information security researchers with a one-stop reference to key security properties of contemporary web browsers."
google
web
infosec
book
browser
december 2008 by al3x
Deputy
december 2008 by al3x
"a C compiler that is capable of preventing common C programming errors, including out-of-bounds memory accesses as well as many other common type-safety errors"
c
infosec
programming
compiler
check
december 2008 by al3x
google-caja
december 2008 by al3x
Makes JavaScript safe(-ish?) for IFRAMEs and widgets and such.
google
caja
javascript
infosec
december 2008 by al3x
Mac OS X Single User Mode Root Access
december 2008 by al3x
Close the hole.
mac
root
infosec
password
december 2008 by al3x
Unicornscan
october 2008 by al3x
"a new information gathering and correlation engine built for and by members of the security research and testing communities"
infosec
network
scanner
opensource
october 2008 by al3x
SecUrls
july 2008 by al3x
"The Information Security Industry at a Glance". Meh, could be better.
infosec
aggregator
july 2008 by al3x
ratproxy
july 2008 by al3x
"A semi-automated, largely passive web application security audit tool, optimized for an accurate and sensitive detection, and automatic annotation, of potential problems and security-relevant design patterns based on the observation of existing, user-ini
infosec
google
ajax
csrf
http
testing
proxy
july 2008 by al3x
The problem(s) with OpenID
march 2008 by al3x
I'm fairly neutral about OpenID, and I think the spec itself is fairly explicit about not attempting to solve the problems listed herein. That said, there's a ton of real-world, right-now problems to tackle here.
openid
Identity
authentication
criticism
infosec
phishing
march 2008 by al3x
Steal This Wi-Fi
january 2008 by al3x
Bruce Schnier sez: open your home wi-fi network. I just wish my current ISP (Yginition) wouldn't send a nastygram every time I sustain 400k/sec down.
infosec
wireless
january 2008 by al3x
Prevx
december 2007 by al3x
"Prevx's Community Intrusion Prevention (CIP) system identifies malicious code by its 'behavior' and is able to neutralize whole classes of malware before it ever has a recognized signature"
infosec
malware
december 2007 by al3x
XSS | Musings
march 2007 by al3x
a Ruby implementation of the sanitization approach taken in the Universal Feed Parser. to be incorporated into acts_as_sanitized ASAP.
ruby
infosec
xss
march 2007 by al3x
Same-Origin Policy Part 1: Why we’re stuck with things like XSS and XSRF/CSRF
february 2007 by al3x
hella thorough look at a bunch of webappsec issues
webapp
infosec
xss
csrf
ajax
february 2007 by al3x
ATLAS Dashboard: Global Summary
february 2007 by al3x
"a sub-set of the intelligence derived from the ATLAS sensor network on host/port scanning activity, zero-day exploits and worm propagation, security events, vulnerability disclosures and dynamic botnet and phishing infrastructures"
infosec
network
monitoring
trends
february 2007 by al3x
Damn Vulnerable Linux
november 2006 by al3x
The most vulnerable and exploitable operating system ever
linux
distribution
infosec
exploits
humor
november 2006 by al3x
sla.ckers.org web application security forum
september 2006 by al3x
brutal vulnerability disclosures. good work.
infosec
webapp
xss
vulnerability
research
september 2006 by al3x
related tags
academic ⊕ advice ⊕ aggregator ⊕ ajax ⊕ analysis ⊕ archive ⊕ authentication ⊕ blog ⊕ book ⊕ botnet ⊕ browser ⊕ c ⊕ caja ⊕ capabilities ⊕ capture ⊕ cheatsheet ⊕ check ⊕ community ⊕ compiler ⊕ compsci ⊕ conference ⊕ couchdb ⊕ criticism ⊕ crypto ⊕ cryptography ⊕ csrf ⊕ database ⊕ distribution ⊕ dns ⊕ documentation ⊕ e ⊕ economics ⊕ education ⊕ encryption ⊕ errors ⊕ exploits ⊕ forum ⊕ fuzzer ⊕ google ⊕ haskell ⊕ http ⊕ humor ⊕ i18n ⊕ Identity ⊕ infosec ⊖ java ⊕ javascript ⊕ jquery ⊕ jvm ⊕ krews ⊕ language ⊕ laptop ⊕ library ⊕ linux ⊕ list ⊕ mac ⊕ malware ⊕ md5 ⊕ monitoring ⊕ multifactor ⊕ network ⊕ openid ⊕ opensource ⊕ owasp ⊕ packet ⊕ password ⊕ pcap ⊕ pgp ⊕ phishing ⊕ pki ⊕ presentation ⊕ programming ⊕ protocol ⊕ proxy ⊕ python ⊕ rails ⊕ reference ⊕ research ⊕ reversing ⊕ root ⊕ rss ⊕ ruby ⊕ scanner ⊕ search ⊕ security ⊕ social ⊕ sql ⊕ ssl ⊕ tagging ⊕ testing ⊕ towatch ⊕ trends ⊕ usb ⊕ utf8 ⊕ video ⊕ virtualmachine ⊕ vmware ⊕ vulnerability ⊕ web ⊕ webapp ⊕ windows ⊕ wireless ⊕ xss ⊕ yubikey ⊕Copy this bookmark: