Jeremiah Grossman

A page to show up #1 on Google when searching for "Jeremiah" (Currently #5).
The prophet, TV show, and that pesky Owyang guy going down!

A page to show up #1 on Google when searching for "Jeremiah Grossman", and it FINALLY has!

Friday, August 28, 2009

Best of Application Security (Friday, Aug. 28)

Ten of Application Security industry's coolest, most interesting, important, and entertaining links from the past week -- in no particular order. Regularly released until year end. Then the Best of Application Security 2009 will be selected!
  • Apache.org Compromised
  • Are Web Application Security Testing Tools a Waste of Time and Money?
  • When Mass SQL Injection Worms Evolve...Again
  • Homegrown Application Security Program
  • Mass SQL injection attacks still scaling up
  • Research: 80% of Web users running unpatched versions of Flash/Acrobat
  • Altered Sears Web Site Offers Grill to 'Cook Babies'
  • Businesses Reluctant to Report Online Banking Fraud
  • Massive Twitter Cross-Site Scripting Vulnerability
  • Flash attack vectors (and worms)
Posted by Jeremiah Grossman at 7:21 AM
Share: Digg | Delicious | Stumble | Technorati | Reddit | XML

1 comments:

Fangqi (Sophia) Sun said...

I really like these "Best of Application Security" posts. Way to go!

August 28, 2009 11:40 AM

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

About Me

My Photo
Jeremiah Grossman
Jeremiah Grossman is the founder and Chief Technology Officer of WhiteHat Security [My Resume]
View my complete profile

Subscribe

Posts
    Atom
Posts
Comments
    Atom
Comments

Presentations

  • Mo' Money Mo' Problems
  • Get Rich or Die Trying
  • Top Ten Web Hacking Techniques (2008)
  • Website Security Statistics Report (Q1'09)

White Papers

  • Website Security 101
  • Vulnerability Assessment Plus Web Application Firewall (VA+WAF)
  • Technology Alone cannot Defeat Website Attacks: Understanding Technical vs. Logical Vulnerabilities
  • Top 5 Myths of Website Security
  • Seven Business Logic Flaws That Put Your Website At Risk
  • Cross Site Scripting (XSS) Worms and Viruses
  • Cross Site Request Forgery (CSRF)
  • Automated Scanning vs the OWASP Top Ten
  • 10 Things You Should Know about Website Security

Twitter Updates (@jeremiahg)

Twitter Updates

    follow me on Twitter

    (IN)SECURE Magazine

    (IN)SECURE Magazine

    My Links

    • WhiteHat Security
    • Web Application Security Consortium
    • GGAFL
    • OWASP [San Jose]
    • CGI Security
    • ha.ckers.org
    • Maui Tours
    • Maui Real Estate

    Blog Archive

    • ▼  2009 (67)
      • ►  November (4)
        • Best of Application Security (Friday, Nov. 20)
        • Best of Application Security (Friday, Nov. 13)
        • OWASP Top 10 (2010 release candidate 1)
        • Best of Application Security (Friday, Nov. 6)
      • ►  October (8)
        • Best of Application Security (Friday, Oct. 30)
        • Black Box vs White Box. You are doing it wrong.
        • Best of Application Security (Friday, Oct. 23)
        • Best of Application Security (Friday, Oct. 16)
        • Best of Application Security (Friday, Oct. 9)
        • All about Website Password Policies
        • Cloud/SaaS will do for websites what PCI-DSS has n...
        • Best of Application Security (Friday, Oct. 2)
      • ►  September (5)
        • Best of Application Security (Friday, Sep. 25)
        • Best of Application Security (Friday, Sep. 18)
        • Best of Application Security (Friday, Sep. 11)
        • Best of Application Security (Friday, Sep. 4)
        • Outsourcing and Top-Line Security Budget Justifica...
      • ▼  August (11)
        • Production-Safe Website Scanning Questionnaire
        • Best of Application Security (Friday, Aug. 28)
        • Best of Application Security (Friday, Aug. 21)
        • Website VA Vendor Comparison Chart
        • Web Security is about Scalability
        • I'm going to Miami
        • Web pages Detecting Virtualized Browsers and other...
        • Overcoming Objections to an Application Security P...
        • Best of Application Security (Friday, Aug. 14)
        • Security Religions and Risk Windows
        • Best of Application Security (Friday Edition)
      • ►  July (6)
        • Bump into me at Black Hat
        • OWASP Podcast #32 pulls no punches
        • Picks for BlackHat 2009
        • The Best of Application Security 2009 (Mid-Year)
        • The Most (Potentially) Lucrative Vulnerabilities
        • Why vulnerable code should be fixed even after WAF...
      • ►  June (4)
        • WhiteHat is Hiring
        • Legalize It (Hacking GOV and MIL website)
        • Results, Unicode Left/Right Pointing Double Angel ...
        • Clickjacking 2017
      • ►  May (5)
        • 5 great Web security blogs you haven't heard of
        • WAFs and anti-SDL assumptions
        • Real-World website vulnerability disclosure & patc...
        • 8 reasons why website vulnerabilities are not fixe...
        • Mythbusting, Secure code is less expensive to deve...
      • ►  April (4)
        • Software Security grew to nearly 500M in 2008
        • Website threats and their capabilities
        • Disagree with the Concept or Implementation?
        • New cert program for Application Security Speciali...
      • ►  March (4)
        • Website security needs a strategy
        • Quick Wins and Web Application Security
        • Detecting Private Browsing Mode
      • ►  February (5)
      • ►  January (11)
    • ►  2008 (117)
      • ►  December (6)
      • ►  November (2)
      • ►  October (2)
      • ►  September (8)
      • ►  August (8)
      • ►  July (10)
      • ►  June (16)
      • ►  May (16)
      • ►  April (19)
      • ►  March (11)
      • ►  February (4)
      • ►  January (15)
    • ►  2007 (195)
      • ►  December (5)
      • ►  November (19)
      • ►  October (11)
      • ►  September (10)
      • ►  August (13)
      • ►  July (22)
      • ►  June (17)
      • ►  May (25)
      • ►  April (18)
      • ►  March (21)
      • ►  February (12)
      • ►  January (22)
    • ►  2006 (123)
      • ►  December (11)
      • ►  November (21)
      • ►  October (20)
      • ►  September (29)
      • ►  August (16)
      • ►  July (15)
      • ►  June (3)
      • ►  January (8)
    • ►  2005 (99)
      • ►  November (2)
      • ►  October (3)
      • ►  September (5)
      • ►  August (9)
      • ►  July (14)
      • ►  June (15)
      • ►  May (13)
      • ►  April (9)
      • ►  March (11)
      • ►  February (7)
      • ►  January (11)
    • ►  2004 (14)
      • ►  December (7)
      • ►  November (6)
      • ►  June (1)
    • ►  2001 (2)
      • ►  November (1)
      • ►  March (1)