Posts

HTTP Parameter Pollution

Lessons Learned from Time's Most Influencial Poll Abuse: Part 1

Newebappitis

Scanner and WAF Data Sharing

Twitter Worm - Cross-site Request Forgery Attacks

Blended Attacks: Reflected XSS Attack via SQL Injection

Anti-Automation Example: Facebook Friend Throttling

Why Did Our Web Application Crash? Leveraging WAF Logging Data

Fixing Both Missing HTTPOnly and Secure Cookie Flags

Helping Protect Cookies with HTTPOnly Flag

Lessons Learned from Zone-H Statistics Reports