Mais Encore

Aller au contenu | Aller au menu | Aller à la recherche

lundi 7 juin 2010

OWASP ModSecurity Core Rule Set

OWASP ModSecurity Core Rule Set: "

Hello OWASP Leaders. I wanted to let you all know that a new version of the OWASP ModSecurity Core Rule Set (CRS) is now available (v2.0.7).

(Via Jeff Williams Blog.)

Technorati Tags: , , ,

mercredi 2 juin 2010

Inline Detection of Evil JavaScript

Inline Detection of Evil JavaScript: "Exploit kits are a much more common threat on the web than they used to be. In order to evade detection, the kits frequently contain logic to obfuscate, or hide, the meaning behind the content that they serve to the victim. Additionally, with each visit to the exploit page, the obfuscation techniques will differ slightly so that static, content signatures will be unable to detect the threat. Other threats contain obfuscated JavaScript (JS) which sets up the page to exploit a vulnerability and launch a payload (for example, 'spraying' the heap with shellcode). Still other threats inject obfuscated JS into legitimate sites, which after decoding embeds a hidden (0-pixel) IFrame to malicious content. As we have seen in the past, the JS encodings vary greatly with each incident, and many instances are encoded multiple times and may contain non-standard JS (reference past blog posts, such as

(Via Zscaler Research blog.)

Technorati Tags: , , , ,

lundi 31 mai 2010

Now available: Microsoft SDL version 5

Now available: Microsoft SDL version 5: "

Jeremy Dallman here to announce that we are releasing the latest version of the Microsoft Security Development Lifecycle process guidance – Version 5 (SDLv5).

(Via Microsoft SDL blog.)

Technorati Tags: , , ,

dimanche 30 mai 2010

OWASP AppSec Research 2010

OWASP AppSec Research 2010

It's time to create a digital storm and invite the world to OWASP AppSec Research 2010 this summer. We have a fabulous program and will celebrate with a gala dinner at Stockholm City Hall (http://international.stockholm.se/Tourism-and-history/The-Famous-City-Hall/Events-and-receptions/Rent-the-Halls).

(Via OWASP Blog.)

Technorati Tags: ,

The OWASP Top Ten and ESAPI – Part 6 – Cross Site Request Forgery (CSRF)

The OWASP Top Ten and ESAPI – Part 6 – Cross Site Request Forgery (CSRF): "No Gravatar

This article will describe how to protect your J2EE application from Cross Site Request Forgery (CSRF/XSRF) attacks using ESAPI. As with all of the detail articles in this series, if you need a refresher on OWASP or ESAPI, please see the intro article The OWASP Top Ten and ESAPI.

(Via John Melton Blog.)

Announcing the MSF-Agile+SDL Process Template for TFS 2010 - The Security Development Lifecycle - Site Home - MSDN Blogs

Announcing the MSF-Agile+SDL Process Template for TFS 2010 - The Security Development Lifecycle - Site Home - MSDN Blogs: ""

(Via http://blogs.msdn.com/b/sdl/Microsoft SDL Blog.)

Static Analysis Worst Practices

Static Analysis Worst Practices

(Via James McGovern Blog.)

Nouvelle catégorie

Ajout d'une nouvelle catégorie pour vous faire partager mes bons (et moins bons ? ) liens sur la sécurité applicative.
Un petit équivalent a mes RT twitter, meme si certains liens ne sont pas forcément sur twitter

Denim Group, Ltd.: OWASP San Antonio Slides for OpenSAMM Presentation Online

Denim Group, Ltd.: OWASP San Antonio Slides for OpenSAMM Presentation Online: "Denim Group, Ltd.

(Via .)

Metasploit Class Videos  (Hacking Illustrated Series InfoSec Tutorial Videos)

Metasploit Class Videos  (Hacking Illustrated Series InfoSec Tutorial Videos): "