Search results for all lists

10000 messages found
Sort by
List: websecurity@lists.webappsec.org
From: James Manico
 
Re: [WEB SECURITY] How are you tackling CSRF?
Sun, Apr 24, 2011 8:27 PM
More here: https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)_Prevention_Cheat_Sheet Jim Manico On Apr 23, 2011, at 3:59 PM, "MustLive" wrote: 2. Protecting only POST requests with tokens, but not GET. It looks like some web developers are lazy (or it's hard for them) to add tokens to GET requests.
List: websecurity@lists.webappsec.org
From: Anurag Agarwal
 
Re: [WEB SECURITY] SQL injection in cookies variable
Sun, Aug 28, 2011 7:50 PM
The injection could be done via forms, url, cookies, web services, etc but the data has to go to a database. So any material on sql injection is relevant here as well. So you may want to get more context on what is it that you are trying to do via cookies.
List: websecurity@lists.webappsec.org
From: Ehlers, Chris
 
Re: [WEB SECURITY] Looking for advice about questionable web application practice.
Tue, Oct 9, 2012 4:48 PM
SECURITY] Looking for advice about questionable web application practice.
List: websecurity@lists.webappsec.org
From: lee jimmy
 
Re: [WEB SECURITY] Looking for advice about questionable web application practice.
Wed, Oct 10, 2012 1:25 AM
Regards -Jimmy *From:* websecurity [mailto:websecurity-bounces@lists.webappsec.org] *On Behalf Of *Burton, Jim *Sent:* 2012年10月10日 0:16 *To:* 'websecurity@lists.webappsec.org' *Subject:* [WEB SECURITY] Looking for advice about questionable web application practice. Our state’s Governor’s office recently started a health clinic for state employees.
List: websecurity@lists.webappsec.org
From: Darren Bounds
 
Re: [WEB SECURITY] Social login / federated identity
Mon, Oct 15, 2012 7:51 PM
https://groups.google.com/forum/?fromgroups#!forum/oauth http://oauth.net/2/ http://tools.ietf.org/html/rfc5849 http://hueniverse.com/ https://groups.google.com/forum/?fromgroups#!forum/openid http://wiki.openid.net/ http://openid.net/specs/openid-authentication-2_0.html http://openid.net/connect/ FYI: OpenID is basically extinct.
List: time-nuts@lists.febo.com
From: Didier Juges
 
Re: [time-nuts] HP E1938 Web Page
Wed, Aug 29, 2007 12:34 AM
> > > _______________________________________________ > time-nuts mailing list -- time-nuts@febo.com > To unsubscribe, go to > https://www.febo.com/cgi-bin/mailman/listinfo/time-nuts > and follow the instructions there.
List: websecurity@lists.webappsec.org
From: Mike
 
Re: [WEB SECURITY] Password-less login ?
Mon, Jan 28, 2013 11:31 PM
. > > When accessing through https what will upstream proxies log ? Just > the encrypted url right ?
List: websecurity@lists.webappsec.org
From: Rohit Sethi
 
[WEB SECURITY] 5 Key Design Decisions That Affect Security in Web Applications
Thu, Feb 10, 2011 5:01 PM
We just put together a post primarily aimed at architects and lead developers of web apps. Check it out: http://labs.securitycompass.com/index.php/2011/02/10/5-key-design-decisions-that-affect-security-in-web-applications/ -- Rohit Sethi Security Compass http://www.securitycompass.com twitter: rksethi
List: websecurity@lists.webappsec.org
From: Prasad Shenoy
 
Re: [WEB SECURITY] Looking for advice about questionable web application practice.
Wed, Oct 10, 2012 5:05 PM
I’m a Unix server admin, not a security pro, so I am certainly not up to date on best practices for Web apps.
List: websecurity@lists.webappsec.org
From: rgutie01 (at) gmail.com
 
Re: [WEB SECURITY] Sliverlight
Mon, Nov 5, 2012 3:39 PM
http://blog.gdssecurity.com/labs/2009/11/19/wcf-binary-soap-plug-in-for-burp.html https://github.com/GDSSecurity/WCF-Binary-SOAP-Plug-In On Mon, Nov 5, 2012 at 7:16 AM, Vernon Jones wrote: > Hi All > > I currently looking for a Silverlight wep app security scanner, the proxy > that I know of that interprets WCF packets is CAT.