I've been pretty busy the past few months which has resulted in zero site updates. The good news is I've kicked off the next phase of the WASC Threat Classification and our first update is the completion of the TC's missing crypto section.
Topics
Tags
- Announcements (85)
- Articles (51)
- Blue Team (2)
- Books (1)
- Browsers (77)
- Buzzwords (30)
- Commentary (44)
- Compliance (9)
- Cryptography (17)
- CSRF (32)
- Defense (80)
- Demo (2)
- Development (88)
- Events (33)
- Flash (13)
- Forensics (15)
- Funny (96)
- Incidents (213)
- IndustryNews (387)
- Interviews (15)
- Metrics (17)
- Off Topic (29)
- Papers (19)
- Purple Team (1)
- Rant (49)
- Red Team (2)
- Research (166)
- Reviews (17)
- SDL (50)
- Security Tools (113)
- SEO (15)
- Site News (21)
- Surveys (7)
- Tools (29)
- Uncategorized (87)
- Vendors (37)
- Vulns (169)
- WASC (48)
- Web Application Firewalls (18)
- Worms (32)
- XSS (84)
Favorite Links
- Security Templates (New)
- The Web Application Security Consortium
- QA Security
- The Web Security Mailing List
- Romain Gaucher’s Blog
- Jeremiah Grossman’s Blog
Popular Pages
WASC Threat Classification
- Abuse of Functionality
- Application Misconfiguration
- Brute Force Attack
- Content Spoofing
- Credential/Session Prediction
- Denial of Service
- Directory Indexing
- Information Leakage
- Remote File Inclusion Attack
- Routing Detour Attack
- SOAP Array Abuse
- XML Attribute Blowup
- XML Injection
- XML External Entity Attack