Tag: webappsec
w3af Technical Segment on PaulDotCom Tonight
by seth on Mar.12, 2009, under Security
Just wanted to let you all know that I will be a guest on the PaulDotcom Security Weekly podcast tonight. I will be leading a technical segment on w3af, which is a very nifty free/open source tool for web application scanning/exploitation. Should be loads of fun!
The live stream should go up around 1845 EDT with the show starting around 1900EDT. Further details can be found here: http://pauldotcom.com/security-weekly/
Hope to see you there.
Seth Misenar
SANS Protecting Your Web Apps
by seth on Mar.10, 2009, under SANS, Security
SANS Protecting Your Web Apps: Two Big Mistakes and 12 Practical Tips to Avoid Them
Not sure when this was released, but I am sure that it was pretty recently. From the title I wasn’t really expecting much, but was pleasantly surprised by the clarity with which the tips were explained. Frank Kim and Ed Skoudis co-authored this pithy 6 page paper.
Here is the description from the SANS Reading Room:
Many web application vulnerabilities are a direct result of improper input validation and output filtering, which leads to numerous kinds of attacks, including cross-site scripting (XSS), SQL injection, command injection, buffer overflows and many others. This article describes some of the best defenses against such attacks, which every Web application developer should master.
This offering looks to be part of a new series from SANS entitled, Working Papers in Application Security. I am looking forward to future papers if they are written as lucidly as this one.
Good work, Frank and Ed.
Here is the link to get the document: http://www.sans.org/reading_room/application_security/protecting_web_apps.pdf
SANS Phoenix 2009
by seth on Dec.15, 2008, under SANS, SANS Teaching
Seth Misenar will be teaching SANS 401: Security Essentials and 538: Web App Pen Testing Immersion at SANS Phoenix 2009.
SEC401: Security Essentials
3/23/2009-3/28/2009
SEC538: Web Application Pen Testing Immersion
3/29/2008-3/30/2009
SANS Secure Europe 2009 – Amsterdam
by seth on Dec.15, 2008, under SANS, SANS Teaching
Seth Misenar will be teaching SANS 542: Web Application Penetration Testing at SANS Secure Europe 2009 – Amsterdam
SEC542: Web Application Penetration Testing
5/11/2009-5/16/2009