Search results for all lists

10000 messages found
Sort by
List: websecurity@lists.webappsec.org
From: Michal Zalewski
 
Re: [WEB SECURITY] CSRF: Flash + 307 redirect = Game Over
Thu, Feb 10, 2011 9:38 PM
As with much of the web, there isn't one (and if there was, it would probably have nothing to do with reality). That said, it is commonly understood, and enforced by most places (e.g., XMLHttpRequest), that websites should not be able to make cross-domain requests with arbitrary HTTP headers without some sort of a mutual consent (e.g., CORS).
List: websecurity@lists.webappsec.org
From: Robert A.
 
Re: [WEB SECURITY] file scheme handling of the "|" character
Tue, Jun 21, 2011 7:53 PM
http://www.cgisecurity.com/2010/03/random-firefox-url-handling.html Regards, - Robert > > -Chris > > > _______________________________________________ > The Web Security Mailing List > > WebSecurity RSS Feed > http://www.webappsec.org/rss/websecurity.rss > > Join WASC on LinkedIn http://www.linkedin.com/e/gis/83336/4B20E4374DBA > > WASC on Twitter > http://
List: websecurity@lists.webappsec.org
From: cr0hn
 
[WEB SECURITY] [Tool] new release GoLismero 2.0 beta 3
Thu, Feb 13, 2014 3:36 PM
It's currently geared towards web security, but it can easily be expanded to other kinds of scans. The most important feature is that it can run external tools and feedback their results. Strictly speaking, GoLismero doesn't require installation - only its dependencies do.
List: websecurity@lists.webappsec.org
From: Stefano Di Paola
 
[WEB SECURITY] DOMinator - The DOMXss Analyzer Tool - is finally public
Wed, May 18, 2011 5:12 PM
Stefano Di Paola Software & Security Engineer Owasp Italy R&D Director Web: www.wisec.it Twitter: http://twitter.com/WisecWisec ..................
List: websecurity@lists.webappsec.org
From: Abhijeet Patil
 
[WEB SECURITY] [Announcement] ClubHack Mag Issue 22- November 2011 Released
Sun, Nov 13, 2011 1:35 PM
This issue covers following articles:- 0x00 Tech Gyan - Looking Into the Eye of the Bits 0x01 Tool Gyan - Ravan – JavaScript Distributed Computing System 0x02 Mom's Guide - Best Practices of Web Application Security 0x03 Legal Gyan - Law relating to Cyberterrorism 0x04 Matriux Vibhag - OWASP Mantra’s MoC Crawler 0x05 Poster - Ravan Check http://chmag.in/ for
List: websecurity@lists.webappsec.org
From: DefenseCode
 
[WEB SECURITY] DefenseCode Security Advisory: Magento Commerce CSRF, Stored Cross Site Scripting #2
Thu, Oct 5, 2017 9:44 AM
All users are strongly advised to update to the latest available version. https://magento.com/security/patches/magento-2016-and-219-security-update 5. Credits ========== Discovered by Bosko Stankovic (bosko@defensecode.com)   6.
List: tacomaart@list.cityoftacoma.org
From: Syed K. Jamal
 
Tacoma Lit Fest: Vendor application is closing
Wed, Mar 11, 2026 11:21 PM
://form.jotform.com/252497864986178> to build Tacoma's creative economy* *All Things Creative: Join our newsletter <https://www.zeffy.com/en-US/newsletter-form/grit-city-studio-newsletter-all-things-creative-and-cinematciallyyours>* *Linktree <https://linktr.ee/gritcitystudio>*
List: ctbirds@lists.ctbirding.org
From: Jim Dugan
 
More help needed fighting neonics now
Thu, Feb 27, 2025 7:45 PM
To find your State Rep, please do a web search for “find your CT State Representative" And for more info on Neonics, please visit CT Pesticide Reform online. For additional info on Second Generation Rodenticides, please do a web search for "CT Audubon Society rat and mouse poisons also kill hawks and owls”, or at numerous other places online.
List: websecurity@lists.webappsec.org
From: Erik Peterson
 
Re: [WEB SECURITY] Artificial Intelligence vs. Human Intelligence on finite amounts of possible outcomes
Wed, Feb 2, 2011 2:59 AM
Automated Web application testing would be easy(tm) if it wasn't for the edge cases, of which there are legion. Oh and because web technology is re-inventing itself every 6 months, anything you create that worked 6 months ago, will become broken sooner or later, thus the cycle of edge cases is, for all practical purposes, infinite.
List: wasc-satec@lists.webappsec.org
From: Arthur Hicken
 
Re: [WASC-SATEC] Setup and Runtime dependencies wasc-satec Digest, Vol 15, Issue 1
Mon, Mar 11, 2013 3:50 PM
Analysis for Fun and Profit <https://plus.google.com/communities/102740030842791003286>