Posts marked with “security”

Sandcastles & Security

by · July 27, 2010

1
 

After playing with Flex off and on for a couple of months, I decided I would try to break it. I’m not a security guy at heart, but I’ve listened closely and improved my own stuff, so I quickly came up with four ways that I might be able to cause problems with Flex. Here are my results with each. To be clear, it is not my goal to be a nefarious troublemaker and break everything. My goal is to find out where things could break.

 

Modsecurity: Why it matters to PHP

by · July 9, 2010

4
 

ModSecurity Handbook:The Complete Guide to the Popular Open Source Web Application Firewall by Ivan Ristic. What is ModSecurity in the first place? Why does it matter to you? What makes this book important to the practice of web application design?

 

Google's new microblogging tool has lots of security holes…on purpose

by · May 26, 2010

0
 

Google Labs, in cooperation with Google Code University, has released a new microblogging tool called Jarlsberg, and like its namesake cheese, it’s full of holes. Security holes. Google hopes you use Jarlsberg to learn best practices on how to make your own software more secure.

 

Netsparker Community Edition released

by · April 14, 2010

3
 

Netsparker is an automated security scanner which promises the elimination of false positives. How does it achieve such a result?

 

Possible vulnerabilities found in PHP session IDs

by · April 9, 2010

1
 

A new advisory warns that a lack of entropy is making session hijacking easier, but only under certain circumstances. Core developer Ilia Alshanetsky gives us the straight dope.

 

Google releases skipfish

by · March 22, 2010

0
 

Google has released a web applications scanner that automatically outlines security issues.

 

Month of PHP Security 2010

by · March 1, 2010

0
 

The Month of PHP Bugs was a unique event in the PHP landscape that fixed a large number of security issues. Now a call for papers has started for a new, larger initiative.