Blogs about: Application Security

Featured Blog

LAN Party anyone? Let’s volunteer to hack Government websites...1 comment

Matthew Flick wrote 2 weeks ago: Would I volunteer my time? Sure, why not. Is it really a good or realistic idea to have our Military … more →

Tags: Government, Penetration Testing

Application Security as a Risk Management Exercise1 comment

Jim wrote 2 weeks ago: One of the biggest hurdles to creating a comprehensive security plan is, to my mind, where to begin … more →

Tags: Security, risk managmeent, software security

Questions About "Proxy" Authentications

completosec wrote 1 month ago: Summary: “When is it appropriate to use an ‘application ID’ to authenticate with t … more →

Tags: Access-Control, authentication

Cross Site Scripting Anonymous Browser (XAB) Proof-of-Concept Released

Matthew Flick wrote 1 month ago: Today I finally found the time to release the XAB Proof-of-Concept code. An apology to those of you … more →

Tags: Black Hat, XAB

Technologies for application-level security

o24int wrote 1 month ago: As attacks become more financially motivated and as organisations get better at securing their netwo … more →

Tags: Vulnerability Management, analyse applications, Data masking, joseph feiman, level security, research vice, sast tools, Security testing, security vulnerabilities

Mass Misunderstanding in Global Business -- Can It Happen on The Information Security Front

completosec wrote 1 month ago: Leaders in many industries seem to employ hope, and a belief in “what others are doing” … more →

Tags: Information Security, leadership, malicious code, Risk Management, vulnerabilities

Impressions from Common '09

systemisecurity wrote 1 month ago: We’re back from Common, the annual “meeting of the minds” for Power i experts, and … more →

Tags: System i News & Events, AP-Journal, common, Compliance Evaluator, IBM i, IBM i Security, IBM Power System, iSecurity, Journaling

Microsoft update 3 buletine sigurie

NAKO Ergest wrote 2 months ago: Microsoft ka bere disa update ne 3 nga buletinet, me saktesisht : * MS09-012 – Important * MS0 … more →

Tags: Security, Microsoft, MS08-069, MS08-076, MS09-012, security bulletin

Strong password management for the mobile user

manojmastiff wrote 2 months ago: Truly strong passwords are necessary to protect our information, but they can be a pain to generate, … more →

Application Security: The Missing Pillar of Software Quality

manojmastiff wrote 2 months ago: Hi all today while reading some application security news I came across one application security whi … more →

Vulnerabilitete ne Adobe Acrobat

NAKO Ergest wrote 2 months ago: Jane publikuar 2 vulnerabilitet te reja te Adobe Acrobat, te cilat afektojne te gjitha versionet e k … more →

Tags: O-Day

What Motivates C-Level Executive Investments in Security?2 comments

completosec wrote 2 months ago: Boards of financial services corporations appear to exist in a bubble that isolates them from most o … more →

Tags: Culture, data leakage, Information Security, leadership, Risk Management, vulnerabilities

2009 Data Breach Investigations Report--by Verizon Business Incident Response

completosec wrote 2 months ago: “2009 Data Breach Investigations Report” was released this week.  It is a 52-page study … more →

Tags: data leakage, Information Security, input validation, malicious code, Output Encoding, Risk Management, vulnerabilities

Shrinking Budgets: Application Security Tools vs Process Tradeoff1 comment

akshay aggarwal wrote 2 months ago: An all too familiar scene repeated itself two weeks ago. My good friend & CISO of a mid-sized te … more →

Tags: Information Technology, leadership, SDL, SDLC, Security, Strategy, Tools

Loss of Data Trail = Loss of 5M Euros1 comment

systemisecurity wrote 3 months ago: Check out this noteworthy real-life security story: a major European high-tech company (we’ll … more →

Tags: Importance of System i Security, audit trail, Auditing, data security, data trail, System i

String-Matching in a Web Application Firewall [WAF]

completosec wrote 3 months ago: In a review of a loaner web application firewall, a colleague noticed that it seemed to be regex-cen … more →

Tags: Error Handling, vulnerabilities

Streaming Announcements

cleartext wrote 3 months ago: Well March has been a BUSY month but I just wanted to post a bit of info out here about what’s … more →

Tags: speaking engagements, event, PCI, Podcasts, OWASP, SPSP, ¹C¤sª±¤ô, BSIMM, OpenSAMM

What is Information Security and How Does it Help?

completosec wrote 3 months ago: A peer recently pointed me to a discussion about information security as a “business enabler. … more →

Tags: Culture, Information Security, leadership, Risk Management

Application Security Risk Assessments7 comments

Chris Hayes wrote 3 months ago: I have so many topics and thoughts that I want to communicate on this blog. I could write for days o … more →

Tags: OWASP, PCI DSS, Risk analysis, Risk Assessment


Have your say. Start a blog.

See our free features →

Related Tags
All →

Follow this tag via RSS

Find other items tagged with “application-security”:
Technorati Del.icio.us IceRocket