Posts

Blended Attacks: Reflected XSS Attack via SQL Injection

Anti-Automation Example: Facebook Friend Throttling

Why Did Our Web Application Crash? Leveraging WAF Logging Data

Fixing Both Missing HTTPOnly and Secure Cookie Flags

Helping Protect Cookies with HTTPOnly Flag

Lessons Learned from Zone-H Statistics Reports

More PCI Confusion: How Should WAFs Handle ASV Traffic?

Mass SQL Injection Attacks Now Targeting PHP Sites

On Your Marks, Get Set, Go: Vulnerability Mitigation Race

Microsoft and Oracle Helping "Time-to-Fix" Problems

Integrating Vulnerability Scanners and Web Application Firewalls