Menu

Skip to content
  • Home
    • Surviving The Week
    • About
      • Contact
  • Podcasts (AppSec)
    • Hands On Series
    • Infosec Place
    • Podcast Setup
  • Web Hacking Survival Kit
    • Free SQL Injection Tool
    • SQL Injection Cheat Sheet
    • Injection Cheat Sheet
    • Pentesting Tools
    • Browser Extensions
    • News Sources
  • PodPress
    • podPress Donors
    • Donor Club
    • PodPress Tutorial
    • PodPress ChangeLog
  • Dev
    • PodPress
    • phpGroupware
    • INNRevival Installer
  • NT OBJECTives
    • NTOSpider
    • NTOEnterprise
    • NTO On-Demand
    • NTODefend
Anonymous Hacked & Defaced MIT in the Name of Aaron Swartz

Anonymous Hacked & Defaced MIT in the Name of Aaron Swartz

Much has been written this week on the sad story of Aaron Swartz and the Anonymous hack executed in his name. This story has affected many people in the IT community. Anonymous hackers, hacked &…

Full Article →

Posted by: Nauman Ashraf // Misc // January 18, 2013 // Comment
Surviving the Week 1/18/13

Surviving the Week 1/18/13

A Lesser Cross-Site Scripting Attack Greater Than Your Regex Security A lot of developers rely on regex to protect against XSS. The following article demonstrates different mechanisms on how developers use regex and how they…

Full Article →

Posted by: NTO Research Team // Surviving The Week // January 18, 2013 // Comment
2013 Security B-Sides San Francisco Voting

2013 Security B-Sides San Francisco Voting

Voting for Security B-Sides San Francisco presentations is in full swing. Be sure to vote for your favorites talks. We’re partial to these two talks by Dan Kuykendall! The Pineapple Express: Live mobile application hacking demonstration….A speeding bullet…

Full Article →

Posted by: Kim Dinerman // Misc, NT OBJECTives // January 15, 2013 // Comment
Application Security That Works

Application Security That Works

My buddy, Jim Broome over at DirectDefense wrote this great blog post, “Security that Works: Even on a Budget.” They have posted two blogs in the series. The first one covers “Hacking Attempts“ and the second focuses on…

Full Article →

Posted by: Dan Kuykendall // Misc // January 14, 2013 // Comment
Surviving the Week 1/11/13

Surviving the Week 1/11/13

NTLM Challenge Response is 100% Broken Security researcher Mark Gamache has used Moxie Marlinspike’s Cloudcracker to derive hashes from captured NTLM handshakes, resulting in successful pass-the-hash attacks. It’s been going on for a long time,…

Full Article →

Posted by: NTO Research Team // Misc // January 11, 2013 // Comment
Surviving the Week 1/4/13

Surviving the Week 1/4/13

SSNs, Salary Information Exposed In Breach of Army Servers Computer hackers have illegally gained access to personal information of more than 36,000 people connected to Army commands formerly based at Fort Monmouth. An Army spokeswoman…

Full Article →

Posted by: NTO Research Team // Surviving The Week // January 4, 2013 // Comment
Surviving the Week 12/28/12

Surviving the Week 12/28/12

The 2012 Web Session Intelligence & Security Report: Business Logic Abuse Edition The business logic abuse scenarios presented by the Ponemon Institue are web scraping, account hijacking, click fraud, botnets causing denial of service, electronic…

Full Article →

Posted by: NTO Research Team // Surviving The Week // December 28, 2012 // Comment
Surviving the Week 12/21/12

Surviving the Week 12/21/12

HTML5 Definition Complete, W3C Moves to Interoperability Testing and Performance The 5th revision of HTML is regarded as the future of web markup language. The long awaited specs for HTML5 have been finalized. This week,…

Full Article →

Posted by: NTO Research Team // Surviving The Week // December 21, 2012 // Comment
XSS & CSRF with HTML5 – Attack, Exploit, and Defense (OWASP AppSecUSA Presentation Review)

XSS & CSRF with HTML5 – Attack, Exploit, and Defense (OWASP AppSecUSA Presentation Review)

This very useful talk was as much an education in HTML5 for me as it was an education on how HTML5 can be abused. I am coming up to speed on HTML5 concepts. Shreeraj Shah…

Full Article →

Posted by: M. J. Power // Misc // December 21, 2012 // Comment
Get Off Your AMF & Don’t REST on JSON (OWASP AppSecUSA Presentation Review)

Get Off Your AMF & Don’t REST on JSON (OWASP AppSecUSA Presentation Review)

First off, in the spirit of full disclosure, two points: One is that this talk took place at the same time as the Shreeraj Shah talk I attended, but I did indeed effectively attend this…

Full Article →

Posted by: M. J. Power // Misc // December 18, 2012 // Comment
Page 3 of 20‹ Previous12345678Next ›Last »

Search

Follow Us

 Facebook Google+ Twitter LinkedIn YouTube RSS E-mail

By OBREAKSL penny stocks

NTOSpider - FREE TRIAL
Is Your Scanner Like the Emperor’s New Clothes? - White Paper
Free SQL Injection Tool - NTO SQL Invader

Archives

Categories

  • 2013 B-Sides San Francisco (4)
  • AMF – Flash Remoting (1)
  • Application Security Strategies (2)
  • Attack Types (1)
  • CSRF/XSRF Tokens (1)
  • Gartner (1)
  • Google Web Toolkit (GWT) (1)
  • Hands On Series (3)
  • HTML5 (1)
  • Infosec Place (14)
  • Interactive Application Security Testing (IAST) (2)
  • JSON (2)
  • Misc (60)
  • Mobile (7)
  • Network (4)
  • NT OBJECTives (20)
  • Physical (1)
  • Podcasting (11)
  • Podcasts (AppSec) (33)
  • podPress (10)
  • REST (1)
  • RSA (2)
  • Securing Mobile Applications (1)
  • Securing Web Services (1)
  • Security (59)
  • Security Conference Presentation Summaries (2)
  • Side channel attacks (1)
  • Surviving The Week (52)
  • Tales from the Web Scanning Front (4)
  • Watch Your SaaS (1)
  • Web App Sec (81)
  • XSS (1)

Recent Comments

  • Dan Kuykendall on Mobile App Security – Application Security’s “Where’s Waldo”
  • Mobile hacker on Mobile App Security – Application Security’s “Where’s Waldo”
  • NT Obejctives on Web Application Security Scanning – The Art of Automation
  • Kim Dinerman on Payback on Web Attackers: Web Honeypots (OWASP AppSecUSA Presentation Review)
  • Simon Roses Femerling on Payback on Web Attackers: Web Honeypots (OWASP AppSecUSA Presentation Review)

Tags

2013 San Francisco B-Sides @jimio Application Security Application Security Program Tips & Tricks Application security re-scans Application security reporting B-Sides Botnets BSidesLV Cert-Pinning CRIME and BEAST SSL/TLS Attacks Defcon Dynamic Application Security Testing Gartner Ghost in the Wires HTML5 intrustion prevention system IPS Iran drone hack Kevin Mitnick Magic Quadrant Metasploit Mobile NT OBJECTives NTODefend NTOSpider OWASP AppSecUSA Reducing scan times RSA RSA 2012 securing mobile applications Securing web services Security Conference Presentation Summaries SQL Injection SQL Server SSL Surviving The Week Tales from the Web Scanning Front Transport layer security at Twitter Twitter WAF Watch Your SaaS Web Appplication Firewall Web App Sec Wine
© 2013 Man Vs WebApp