sstrudeau + security   40

skipfish - Project Hosting on Google Code
A fully automated, active web application security reconnaissance tool. Key features:
google  scanner  security  testing  web 
march 2010 by sstrudeau
A List Apart: Articles: The Problem with Passwords
technique for progressive masking of user-entered password
ui  web  password  input  masking  progressive  security  ux 
february 2010 by sstrudeau
Addslashes(): don't call it a comeback
on protecting against multi-byte mysql injection attacks with php addslashs/addcslashes/...
php  mysql  security  escape  injection  attack  defense  performance 
june 2008 by sstrudeau
The Open Security Model, Drupal and ExpressionEngine on Security | Lullabot
Yes, Drupal has way more security advisories than Expression Engine but that's because EE doesn't report them (and they're easy to find)
drupal  expressionengine  cms  php  security  policy  practice 
june 2008 by sstrudeau
ActiveX Security: Improvements and Best Practices
I love MS security. "mark as safe only if you are safe" ... *sigh*
activex  conrol  security  ie7  approved  ie  yellowbar 
may 2008 by sstrudeau
Google Code University - Google Code
Google sponsored material covering * AJAX Programming * Distributed Systems * Web Security * Languages
learning  code  ajax  mapreduce  security  web  c++  java  python 
march 2008 by sstrudeau
Goolag
cDc tool for scanning domain(s) via Google for unwittingly exposed data
goolag  security  hack  scan  software 
february 2008 by sstrudeau
Dangers of remote Javascript
perl.com gets burned by a 3rd party .js they used; the owner lost their domain, a porn purveyor bought it and modified the .js to redirect to the porn site.
js  javascript  domain  web  security  policy 
january 2008 by sstrudeau
Miron’s Weblog » OpenSocial insecurity - no user to app authentication
"no user authentication! Any user can forge anybody else’s identity when interacting with any OpenSocial application. As it currently stands, it is not possible to write secure social applications on the platform."
via:vielmetti  opensocial  api  security  authentication 
november 2007 by sstrudeau
IEBlog : Internet Explorer 7 Update
Yay! Windows pirates will now get IE7 regardless of their "genuine advantage" status
via:revgeorge  ie  ie6  ie7  security  update  windows  validation  browser  thank-jebus 
october 2007 by sstrudeau
AIR:HTML Security FAQ - Adobe Labs
Adobe AIR security model FAQ -- pretty good overview of the security flaws in common ajax and ajax-like techniques. Doubley dangerous in the context of an app with direct access to the system. Interesting proposed solution.
javascript  ajax  security  adobe  air  browser  model  documentation  faq  reference 
october 2007 by sstrudeau
Why cell phones are still grounded
Nice analysis/overview of why mobile phones are banned on airplanes (basically, it's easier & cheaper for the gov't, airlines and carriers to just keep the ban in place)
mobile  phones  airlines  airplanes  faa  fcc  ban  security  interference 
august 2007 by sstrudeau
PHP Security Consortium: PHP Security Guide: Form Processing
Nice overview of safe form handling in php; specifically the last section with example on how to attach unique tokens to form POSTs that must match token in the session
php  security  xss  token  crumb  cookie  example 
may 2007 by sstrudeau
PHP: Filter Functions - Manual
Turn on default filters for incoming user data on your web app ... protects against XSS by default. In php 5.2 and in PECL for php 5.1
filter  php  xss  security  php5  oscms2007 
march 2007 by sstrudeau
'Re: OpenSSH Certkey (PKI) adding CAL (online verification)' - MARC
nice if you run a whole bunch of servers with shared SSH access and you like to use key-based auth...
ssh  openssh  security  keys  key  management  tool  cal  access 
december 2006 by sstrudeau
the cool hunter - IN-LOCK
stake that screws into the ground to give you something to lock your bike to in absense of a lightpost. :)
bicycle  bike  motorcycle  scooter  lock  security  stake  cool  wishlist  travel 
august 2006 by sstrudeau
Belarc
use to inventory & audit (security) PCs
inventory  pc  windows  security 
june 2005 by sstrudeau

related tags

access  actionscript  activex  adobe  air  airlines  airplanes  airport  ajax  antispam  apache  api  approved  article  attack  authentication  backup  ban  bicycle  bike  bikes  bookmarklet  browser  bytecode  c++  cal  captcha  clickjack  clickjacking  cms  code  comment  conrol  cookie  cool  criticism  critique  crumb  defense  disk  documentation  domain  drupal  electronics  email  encryption  error  escape  example  explanation  exploit  expressionengine  faa  failure  faq  fcc  filter  firewall  flash  floss  form  framebuster  framebusting  gate  generator  geolocation  google  goolag  hack  hole  holepunching  howto  https  humor  identity  ie  ie6  ie7  illustration  imap  injection  input  interference  inventory  ipsec  ipsecctl  java  javascript  js  jsonp  key  keys  learning  list  location  lock  locks  lolcats  mail  management  mapreduce  masking  mobile  model  motorcycle  mysql  nat  network  networking  openbsd  openid  opensocial  openssh  oscms2007  osx  parkinglot  password  pc  performance  phishing  phones  php  php5  policy  politics  powerpoint  practice  precondition  presentation  progressive  proxy  python  rails  random  recipe  recommended  reference  ruby  s3  sample  scan  scanner  scooter  secure  security  server  slides  software  spam  ssh  ssl  stake  tcp  technique  testing  textdrive  textpattern  thank-jebus  token  tool  travel  tsa  udp  ui  unix  update  ux  validation  vendor  via:revgeorge  via:vielmetti  vm  vpn  web  windows  wishlist  workaround  write32  writing  xss  yellowbar 

Copy this bookmark:



description:


tags: