<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Web App Security (webappsec) Mailing List</title>
<link>http://seclists.org/#webappsec</link>
<atom:link href="http://seclists.org/rss/webappsec.rss" rel="self" type="application/rss+xml" />
<description>Provides insights on the unique challenges which make web applications notoriously hard to secure.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re: Internal servers, web application firewalls, and learning modes</title><description>Posted by Preston Connors on Dec 02&lt;p&gt;


&lt;p&gt;
I would create a Dial-Up VPN scenario where your users can dial in to
&lt;br /&gt;
your Internal network over a secured VPN connection. That way you would
&lt;br /&gt;
not have to reconfigure your Internal network and harden your webapps.
&lt;br /&gt;
You can use a high level of encryption over your dial-up VPN ensuring
&lt;br /&gt;
that the...</description>
<link>http://seclists.org/webappsec/2008/q4/0034.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0034.html</guid>
<pubDate>Tue, 02 Dec 2008 13:47:23 -0500</pubDate></item>
<item><title>Internal servers, web application firewalls, and learning modes</title><description>Posted by Dan Lynch on Dec 2&lt;p&gt;


&lt;p&gt;
Sorry for the long post. My questions are at the end, but first, take a
&lt;br /&gt;
minute to see the hard limitations in our environment.
&lt;br /&gt;
&lt;p&gt;My organization has no in house specialized web expertise, not in web
&lt;br /&gt;
development, or code audit, or web application vulnerability assessment.
&lt;br /&gt;
None. In the current...</description>
<link>http://seclists.org/webappsec/2008/q4/0033.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0033.html</guid>
<pubDate>Tue, 2 Dec 2008 08:14:25 -0800</pubDate></item>
<item><title>NASSCOMs Biggest Information Security Summit - Supported by OWASP India</title><description>Posted by Soi Dhruv on Nov 27&lt;p&gt;


&lt;p&gt;
Dear Members,
&lt;br /&gt;
 
&lt;br /&gt;
I just wanted to bring it to your kind notice that a biggest information
&lt;br /&gt;
security summit is being organized by NASSCOM in Hyderabad, India on
&lt;br /&gt;
December 2nd-3rd 2008. Summit features some of the top-notch information
&lt;br /&gt;
security experts who would be addressing some really painful...</description>
<link>http://seclists.org/webappsec/2008/q4/0032.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0032.html</guid>
<pubDate>Thu, 27 Nov 2008 15:25:58 +0530</pubDate></item>
<item><title>Re: A Question of Quality</title><description>Posted by Alexander Bermudez on Nov 30&lt;p&gt;


&lt;p&gt;
Pride of ownership may very well be the reason for lack of adequate QC and 
&lt;br /&gt;
Security control but my take is that it might have something to do with 
&lt;br /&gt;
security professionals not doing a good enough job of selling the value of 
&lt;br /&gt;
security in the SDLC. If the decision makers could be educated on the...</description>
<link>http://seclists.org/webappsec/2008/q4/0031.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0031.html</guid>
<pubDate>Sun, 30 Nov 2008 08:32:03 -0800</pubDate></item>
<item><title>RE: New Whitepaper - .NET Framework Rootkits:  Backdoors inside your Framework</title><description>Posted by Erez Metula on Nov 14&lt;p&gt;


&lt;p&gt;
Hi Ragan,
&lt;br /&gt;
Performance seems to be the main cause for the lack of signature check (although the overhead penalty occurs once per loaded DLL).
&lt;br /&gt;
I also believe that Microsoft did some threat modeling and came to the right conclusion that since the checking mechanism is in the hands of the...</description>
<link>http://seclists.org/webappsec/2008/q4/0030.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0030.html</guid>
<pubDate>Fri, 14 Nov 2008 12:14:23 +0200</pubDate></item>
<item><title>New Whitepaper - .NET Framework Rootkits:  Backdoors inside your Framework</title><description>Posted by Erez Metula on Nov 13&lt;p&gt;


&lt;p&gt;
Paper Name
&lt;br /&gt;
===========
&lt;br /&gt;
&lt;p&gt;.NET Framework Rootkits - Backdoors inside your Framework 
&lt;br /&gt;
Author: Erez MetulaÑ
&lt;br /&gt;
 
&lt;br /&gt;
&lt;p&gt;Paper Description
&lt;br /&gt;
=================
&lt;br /&gt;
&lt;p&gt;The paper introduces a new method that enables an attacker to change the .NET language, and to hide malicious code inside its core.
&lt;br /&gt;
It covers...</description>
<link>http://seclists.org/webappsec/2008/q4/0029.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0029.html</guid>
<pubDate>Thu, 13 Nov 2008 18:07:33 +0200</pubDate></item>
<item><title>On-Demand Penetration Testing Webcasts with Ed Skoudis of SANS</title><description>Posted by sfa_at_securityfocus.com on Nov 11&lt;p&gt;


&lt;p&gt;
As a security pro, it&#39;s important to periodically stop, take a break, and refuel your brain. Once per month, Core Security Technologies does the same thing and invites industry thought leaders to share their insights through educational webcasts offering security testing tips, tricks and...</description>
<link>http://seclists.org/webappsec/2008/q4/0028.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0028.html</guid>
<pubDate>11 Nov 2008 16:02:02 -0000</pubDate></item>
<item><title>Re: A Question of Quality</title><description>Posted by Yousef Syed on Nov 4&lt;p&gt;


&lt;p&gt;
Hi Marco, All,
&lt;br /&gt;
I think the first time that I really got into the whole quality at the
&lt;br /&gt;
code level was waay back in 2000 when I was involved in my first
&lt;br /&gt;
Extreme Programming project.
&lt;br /&gt;
It was mandated that all methods follow Design by Contract
&lt;br /&gt;
(http://en.wikipedia.org/wiki/Design_by_contract), so...</description>
<link>http://seclists.org/webappsec/2008/q4/0027.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0027.html</guid>
<pubDate>Tue, 4 Nov 2008 00:26:06 +0100</pubDate></item>
<item><title>Re: A Question of Quality</title><description>Posted by Daniël W. Crompton on Nov 4&lt;p&gt;


&lt;p&gt;
2008/11/2 Robert Hajime Lanning &amp;lt;robert.lanning_at_gmail&amp;#46;com&amp;gt;:
&lt;br /&gt;
&amp;gt; On Thu, Oct 30, 2008 at 4:55 PM, Yousef Syed &amp;lt;yousef.syed_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt;&amp;gt; Why isn&#39;t Quality Assumed?
&lt;br /&gt;
&amp;gt;&amp;gt; Why isn&#39;t Security Assumed?
&lt;br /&gt;
&amp;gt;&amp;gt; Why are these concepts thought of as add ons...</description>
<link>http://seclists.org/webappsec/2008/q4/0026.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0026.html</guid>
<pubDate>Tue, 4 Nov 2008 11:53:40 +0100</pubDate></item>
<item><title>New Whitepaper - quotContinuing Business with Malware Infected Customersquot</title><description>Posted by WebAppSec on Nov 3&lt;p&gt;


&lt;p&gt;
Hi List,
&lt;br /&gt;
&lt;p&gt;I figured I&#39;d try sharing a new paper I completed and posted to my site
&lt;br /&gt;
yesterday.
&lt;br /&gt;
&lt;p&gt;The paper is based off some of the work I&#39;ve been discussing at various
&lt;br /&gt;
conferences recently in relation to the man-in-the-browser attack vectors,
&lt;br /&gt;
and their effect on financial Web applications - in...</description>
<link>http://seclists.org/webappsec/2008/q4/0025.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0025.html</guid>
<pubDate>Mon, 3 Nov 2008 10:29:37 -0500</pubDate></item>
<item><title>CSRF attacks against OAuth</title><description>Posted by Jake Spekle on Nov 3&lt;p&gt;


&lt;p&gt;
I came across this blog post this morning and thought it was
&lt;br /&gt;
interesting and worth posting here:
&lt;br /&gt;
&lt;p&gt;http://blog.cliqset.com/2008/11/02/csrf-and-oauth/
&lt;br /&gt;
&lt;p&gt;Considering what OAuth is designed for, it seems like CSRF attacks
&lt;br /&gt;
against it could prove to be quite fruitful for an attacker.
&lt;br /&gt;
&lt;p&gt;-
&lt;br /&gt;
JS
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/webappsec/2008/q4/0024.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0024.html</guid>
<pubDate>Mon, 3 Nov 2008 09:23:18 -0500</pubDate></item>
<item><title>Re: A Question of Quality</title><description>Posted by Robert Hajime Lanning on Nov 2&lt;p&gt;


&lt;p&gt;
On Thu, Oct 30, 2008 at 4:55 PM, Yousef Syed &amp;lt;yousef.syed_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Why isn&#39;t Quality Assumed?
&lt;br /&gt;
&amp;gt; Why isn&#39;t Security Assumed?
&lt;br /&gt;
&amp;gt; Why are these concepts thought of as add ons to Applications and Services?
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Why do they need to be specified, when they...</description>
<link>http://seclists.org/webappsec/2008/q4/0023.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0023.html</guid>
<pubDate>Sun, 2 Nov 2008 11:24:06 -0800</pubDate></item>
<item><title>The Month of Burp Pr0n</title><description>Posted by PortSwigger on Nov 2&lt;p&gt;


&lt;p&gt;
Users of Burp Suite will no doubt be pleased to learn that work on the next
&lt;br /&gt;
version is at an advanced stage, and this is scheduled for release in
&lt;br /&gt;
December. This will be a major upgrade with numerous enhancements to
&lt;br /&gt;
existing tools, and the addition of some brand new ones.
&lt;br /&gt;
&lt;p&gt;Every day during...</description>
<link>http://seclists.org/webappsec/2008/q4/0022.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0022.html</guid>
<pubDate>Sun, 2 Nov 2008 12:00:29 -0000</pubDate></item>
<item><title>A Question of Quality</title><description>Posted by Yousef Syed on Oct 31&lt;p&gt;


&lt;p&gt;
Why isn&#39;t Quality Assumed?
&lt;br /&gt;
Why isn&#39;t Security Assumed?
&lt;br /&gt;
Why are these concepts thought of as add ons to Applications and Services?
&lt;br /&gt;
&lt;p&gt;Why do they need to be specified, when they should be taken for granted?
&lt;br /&gt;
&amp;nbsp;- Input Validation
&lt;br /&gt;
&amp;nbsp;- Boundary Conditions
&lt;br /&gt;
&amp;nbsp;- Encrypt Data as necessary
&lt;br /&gt;...</description>
<link>http://seclists.org/webappsec/2008/q4/0021.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0021.html</guid>
<pubDate>Fri, 31 Oct 2008 01:55:31 +0100</pubDate></item>
<item><title>FINAL NOTICE: OWASP Portugal EU Summit</title><description>Posted by Dave Wichers on Oct 27&lt;p&gt;


&lt;p&gt;
Itâs almost hereâ¦.one of the most important events in OWASP history, the 2008 Summit!  
&lt;br /&gt;

&lt;br /&gt;
http://www.owasp.org/index.php/OWASP_EU_Summit_2008 
&lt;br /&gt;

&lt;br /&gt;
OWASP Summit EU 2008 is a worldwide gathering of OWASP leaders and key industry
&lt;br /&gt;
players to present and discuss the latest OWASP tools and...</description>
<link>http://seclists.org/webappsec/2008/q4/0020.html</link><guid isPermaLink="true">http://seclists.org/webappsec/2008/q4/0020.html</guid>
<pubDate>Mon, 27 Oct 2008 21:13:30 -0400</pubDate></item>
</channel></rss>