Simple PHP 5.3+ Bcrypt class and functions — Gist
december 2011 by soypunk
This is a very simple wrapper for bcrypt (see: http://codahale.com/how-to-safely-store-a-password/) -- sadly it requires PHP 5.3. Maybe not so sadly because this is one of those technology fundamentals that may force those on PHP 5.2 to move the needle up a little faster.
php
security
bcrypt
for-oris
december 2011 by soypunk
DOMCrypt Demo
february 2011 by soypunk
DOMCrypt is a Firefox extension that adds 'window.crypt' to each browser window. With 'crypt', you can generate a public and private key pair, encrypt data and decrypt data. All of the encryption operations are handled by low-level NSS libraries written in C. This is not a javascript-in-content solution. (NSS handles all of the SSL operations in many modern browsers.)
firefox
extension
security
february 2011 by soypunk
aphyr/tund - GitHub
january 2011 by soypunk
"SSH reverse tunnel daemon"
ssh
security
software
opensource
january 2011 by soypunk
Index of /playground/demos/http/002
february 2010 by soypunk
ahh, gimmicky test cases are fun. this kinda thing is a real problem though.
security
html
from delicious
february 2010 by soypunk
funkatron's inspekt at master - GitHub
november 2009 by soypunk
validation and filtering library
php
security
opensource
from delicious
november 2009 by soypunk
Major IE8 flaw makes 'safe' sites unsafe - The Register
november 2009 by soypunk
It was only a matter of time...
ie8
microsoft
security
css
from delicious
november 2009 by soypunk
Cross-domain policy file usage recommendations for Flash Player | Adobe Developer Connection
november 2009 by soypunk
Facebook and Myspace hit by what I've always assumed is a totally misunderstood system.
flash
security
from delicious
november 2009 by soypunk
Bug 14248 - Webkit shows "Unsafe Javascript attempt to acesss the frame.......... . Domains must match"
february 2009 by soypunk
Currently running into this as well...
webkit
javascript
security
february 2009 by soypunk
Twitter Don't Click Exploit
february 2009 by soypunk
Someone's already hacked around the hack Twitter put in place to prevent the "don't click" exploit. Fun!
web
security
twitter
february 2009 by soypunk
tmin - Google Code
february 2009 by soypunk
"A quick and simple tool to minimize the size and syntax of complex test cases in automated security testing. The tool is somewhat related to delta, a more featured general-purpose optimizer - but is meant specifically for dealing with unknown or complex data formats (without the need to tokenize and re-serialize testcases), for hands-off detection of security fault conditions, and for easy integration with UI testing harnesse"
security
testing
february 2009 by soypunk
Origin Header for CSRF Mitigation
january 2009 by soypunk
"This document describes the use of the Origin header for mitigating cross-site request forgery (CSRF) vulnerabilities in web sites. To help sites defend against CSRF attacks, user agents send a Origin header with HTTP requests that identifies the origin that initiated the request. If the user agent cannot determine the origin, the user agents sends the value null."
http
security
january 2009 by soypunk
Browser Security Handbook - Google
december 2008 by soypunk
"This document is meant to provide web application developers, browser engineers, and information security researchers with a one-stop reference to key security properties of contemporary web browsers. Insufficient understanding of these often poorly-documented characteristics is a major contributing factor to the prevalence of several classes of security vulnerabilities."
google
web
html
javascript
browser
security
mozilla
firefox
opera
chrome
webkit
ie
december 2008 by soypunk
Fire Eagle : Developer
october 2008 by soypunk
"you _must not_ use embedded rendering controls to present the OAuth process with Yahoo! and Fire Eagle."
oauth
security
web
browser
iphone
october 2008 by soypunk
IEBlog : IE8 Security Part VI: Beta 2 Update
september 2008 by soypunk
"Sending the new X-Content-Type-Options response header with the value nosniff will prevent Internet Explorer from MIME-sniffing a response away from the declared content-type."
ie
html5
web
security
september 2008 by soypunk
Super .htaccess file | CodeIgniter Forums
july 2008 by soypunk
For pesky shared hosts (not mine thankfully) that don't let you place files outside of the web root
codeigniter
php
apache
security
july 2008 by soypunk
Make Create: Google Backdoor
december 2006 by soypunk
Doesn't describe a backdoor to Google - but how masking yourself as "Googlebot" will give you access to a lot of registration-only content
google
web
security
hacks
december 2006 by soypunk
related tags
apache ⊕ auth ⊕ bcrypt ⊕ browser ⊕ chrome ⊕ codeigniter ⊕ commuity ⊕ csrf ⊕ css ⊕ education ⊕ extension ⊕ extensions ⊕ firefox ⊕ flash ⊕ for-oris ⊕ for_ldc_graff ⊕ google ⊕ hacks ⊕ hmac ⊕ html ⊕ html5 ⊕ http ⊕ identity ⊕ ie ⊕ ie8 ⊕ iphone ⊕ javascript ⊕ microsoft ⊕ mozilla ⊕ networking ⊕ oauth ⊕ openid ⊕ opensource ⊕ opera ⊕ osx ⊕ php ⊕ presentation ⊕ privacy ⊕ pubcookie ⊕ rss ⊕ security ⊖ services ⊕ social ⊕ software ⊕ sql ⊕ ssh ⊕ testing ⊕ twitter ⊕ UI ⊕ video ⊕ w3c ⊕ web ⊕ webkit ⊕ whatwg ⊕ widgets ⊕ wifi ⊕ windows ⊕ wordpress ⊕ xhr ⊕ xss ⊕ yahoo ⊕Copy this bookmark: