Posts

Showing posts from 2009

Identifying Denial of Service Conditions Through Performance Monitoring

WASC Honeypots - Apache Tomcat Admin Interface Probes

Distributed Brute Force Attacks Against Yahoo

Identifying Anomalous Behavior

WASC Distributed Open Proxy Honeypot Update - XSS in User-Agent Field

WASC WHID 2009 Bi-Annual Report - Social Media Sites Top Most Attacked Vertical Market

We've been blind to attacks on our Web sites

Challenges to webappsec - lightweight development

Generic Remote File Inclusion Attack Detection

WAF Bypass Issues: Poor Negative and Positive Security

WAF Detection with wafw00f

HTTP Parameter Pollution

Lessons Learned from Time's Most Influencial Poll Abuse: Part 1

Newebappitis

Scanner and WAF Data Sharing

Twitter Worm - Cross-site Request Forgery Attacks