Jeremiah Grossman

A page to show up #1 on Google when searching for "Jeremiah" (Currently #5).
The prophet, TV show, and that pesky Owyang guy going down!

A page to show up #1 on Google when searching for "Jeremiah Grossman", and it FINALLY has!

Friday, October 09, 2009

Best of Application Security (Friday, Oct. 9)

Ten of Application Security industry's coolest, most interesting, important, and entertaining links from the past week -- in no particular order. Regularly released until year end. Then the Best of Application Security 2009 will be selected!
  • null-prefix certificate for paypal
  • Statistics from 10,000 leaked Hotmail passwords
  • OWASP Interview with Andy Steingruebl
  • Web Application Security Scanner Evaluation Criteria Version 1.0
  • All about Website Password Policies
  • 9 Ways to Improve Application Security After an Incident
  • CSS History Hack Used To Ban Torrent Users
  • BSIMM Begin
  • Identifying Denial of Service Conditions Through Performance Monitoring
  • XSS Protection by Default in Rails 3.0
Posted by Jeremiah Grossman at 7:34 AM
Share: Digg | Delicious | Stumble | Technorati | Reddit | XML

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

About Me

My Photo
Jeremiah Grossman
Jeremiah Grossman is the founder and Chief Technology Officer of WhiteHat Security [My Resume]
View my complete profile

Subscribe

Posts
    Atom
Posts
Comments
    Atom
Comments

Presentations

  • Mo' Money Mo' Problems
  • Get Rich or Die Trying
  • Top Ten Web Hacking Techniques (2008)
  • Website Security Statistics Report (Q1'09)

White Papers

  • Website Security 101
  • Vulnerability Assessment Plus Web Application Firewall (VA+WAF)
  • Technology Alone cannot Defeat Website Attacks: Understanding Technical vs. Logical Vulnerabilities
  • Top 5 Myths of Website Security
  • Seven Business Logic Flaws That Put Your Website At Risk
  • Cross Site Scripting (XSS) Worms and Viruses
  • Cross Site Request Forgery (CSRF)
  • Automated Scanning vs the OWASP Top Ten
  • 10 Things You Should Know about Website Security

Twitter Updates (@jeremiahg)

Twitter Updates

    follow me on Twitter

    (IN)SECURE Magazine

    (IN)SECURE Magazine

    My Links

    • WhiteHat Security
    • Web Application Security Consortium
    • GGAFL
    • OWASP [San Jose]
    • CGI Security
    • ha.ckers.org
    • Maui Tours
    • Maui Real Estate

    Blog Archive

    • ►  2010 (17)
      • ►  February (6)
        • Where's WhiteHat? Re: Scanner Comparisons
        • Best of Application Security (Friday, Feb. 5)
        • Web 2.0 Pivot Attacks
        • Converting unimplementable Cookie-based XSS to a p...
        • The Web won’t be safe, let alone secure, unless we...
        • Be Ready -- With Answers
      • ►  January (11)
        • Best of Application Security (Friday, Jan. 29)
        • WASC RSA Meet-Up 2010!
        • Best of Application Security (Friday, Jan. 22)
        • Best of Application Security (Friday, Jan. 15)
        • Web-based systems vs. Advanced Persistent Threat
        • Top Ten Web Hacking Techniques of 2009 (Official)
        • Best of Application Security (Friday, Jan. 8)
        • In absense of a security strategy
        • To disable IE8's XSS Filter or not?
        • WASC Threat Classification to OWASP Top Ten RC1 Ma...
        • Best of Application Security (Friday, Jan. 1)
    • ▼  2009 (75)
      • ►  December (7)
        • Best of Application Security (Friday, Dec. 25)
        • (Fortify + WhiteHat = Fortify on Demand) or (1 + 1...
        • Best of Application Security (Friday, Dec. 18)
        • Attention security researchers! Submit your new 20...
        • Why Microsoft should consider retroactively instal...
        • Best of Application Security (Friday, Dec. 11)
        • Best of Application Security (Friday, Dec. 4)
      • ►  November (5)
        • Best of Application Security (Friday, Nov. 27)
        • Best of Application Security (Friday, Nov. 20)
        • Best of Application Security (Friday, Nov. 13)
        • OWASP Top 10 (2010 release candidate 1)
        • Best of Application Security (Friday, Nov. 6)
      • ▼  October (8)
        • Best of Application Security (Friday, Oct. 30)
        • Black Box vs White Box. You are doing it wrong.
        • Best of Application Security (Friday, Oct. 23)
        • Best of Application Security (Friday, Oct. 16)
        • Best of Application Security (Friday, Oct. 9)
        • All about Website Password Policies
        • Cloud/SaaS will do for websites what PCI-DSS has n...
        • Best of Application Security (Friday, Oct. 2)
      • ►  September (5)
        • Best of Application Security (Friday, Sep. 25)
        • Best of Application Security (Friday, Sep. 18)
        • Best of Application Security (Friday, Sep. 11)
        • Best of Application Security (Friday, Sep. 4)
        • Outsourcing and Top-Line Security Budget Justifica...
      • ►  August (11)
        • Production-Safe Website Scanning Questionnaire
        • Best of Application Security (Friday, Aug. 28)
        • Best of Application Security (Friday, Aug. 21)
        • Website VA Vendor Comparison Chart
        • Web Security is about Scalability
        • I'm going to Miami
        • Web pages Detecting Virtualized Browsers and other...
        • Overcoming Objections to an Application Security P...
      • ►  July (6)
      • ►  June (4)
      • ►  May (5)
      • ►  April (4)
      • ►  March (4)
      • ►  February (5)
      • ►  January (11)
    • ►  2008 (117)
      • ►  December (6)
      • ►  November (2)
      • ►  October (2)
      • ►  September (8)
      • ►  August (8)
      • ►  July (10)
      • ►  June (16)
      • ►  May (16)
      • ►  April (19)
      • ►  March (11)
      • ►  February (4)
      • ►  January (15)
    • ►  2007 (195)
      • ►  December (5)
      • ►  November (19)
      • ►  October (11)
      • ►  September (10)
      • ►  August (13)
      • ►  July (22)
      • ►  June (17)
      • ►  May (25)
      • ►  April (18)
      • ►  March (21)
      • ►  February (12)
      • ►  January (22)
    • ►  2006 (123)
      • ►  December (11)
      • ►  November (21)
      • ►  October (20)
      • ►  September (29)
      • ►  August (16)
      • ►  July (15)
      • ►  June (3)
      • ►  January (8)
    • ►  2005 (99)
      • ►  November (2)
      • ►  October (3)
      • ►  September (5)
      • ►  August (9)
      • ►  July (14)
      • ►  June (15)
      • ►  May (13)
      • ►  April (9)
      • ►  March (11)
      • ►  February (7)
      • ►  January (11)
    • ►  2004 (14)
      • ►  December (7)
      • ►  November (6)
      • ►  June (1)
    • ►  2001 (2)
      • ►  November (1)
      • ►  March (1)