From Web Application Defender Cookbook Foreword:
"To all defenders, I leave you in Ryan’s accomplished and capable hands. His reputation speaks for itself. Ryan is one of the original defenders. He has contributed more than anyone else in web security to define the role of the defender. And he’s one of the best field practitioners I’ve ever seen."
Jeremiah Grossman
Posts
Blended Attacks: Reflected XSS Attack via SQL Injection
- Get link
- X
- Other Apps
Anti-Automation Example: Facebook Friend Throttling
- Get link
- X
- Other Apps
Why Did Our Web Application Crash? Leveraging WAF Logging Data
- Get link
- X
- Other Apps
Fixing Both Missing HTTPOnly and Secure Cookie Flags
- Get link
- X
- Other Apps
Helping Protect Cookies with HTTPOnly Flag
- Get link
- X
- Other Apps
Lessons Learned from Zone-H Statistics Reports
- Get link
- X
- Other Apps
More PCI Confusion: How Should WAFs Handle ASV Traffic?
- Get link
- X
- Other Apps
Mass SQL Injection Attacks Now Targeting PHP Sites
- Get link
- X
- Other Apps
On Your Marks, Get Set, Go: Vulnerability Mitigation Race
- Get link
- X
- Other Apps
Microsoft and Oracle Helping "Time-to-Fix" Problems
- Get link
- X
- Other Apps
Integrating Vulnerability Scanners and Web Application Firewalls
- Get link
- X
- Other Apps