Posts

WAF Detection with wafw00f

HTTP Parameter Pollution

Lessons Learned from Time's Most Influencial Poll Abuse: Part 1

Newebappitis

Scanner and WAF Data Sharing

Twitter Worm - Cross-site Request Forgery Attacks

Blended Attacks: Reflected XSS Attack via SQL Injection

Anti-Automation Example: Facebook Friend Throttling

Why Did Our Web Application Crash? Leveraging WAF Logging Data

Fixing Both Missing HTTPOnly and Secure Cookie Flags

Helping Protect Cookies with HTTPOnly Flag