Posts

We've been blind to attacks on our Web sites

Challenges to webappsec - lightweight development

Generic Remote File Inclusion Attack Detection

WAF Bypass Issues: Poor Negative and Positive Security

WAF Detection with wafw00f

HTTP Parameter Pollution

Lessons Learned from Time's Most Influencial Poll Abuse: Part 1

Newebappitis

Scanner and WAF Data Sharing

Twitter Worm - Cross-site Request Forgery Attacks

Blended Attacks: Reflected XSS Attack via SQL Injection