Jeremiah Grossman

A page to show up #1 on Google when searching for "Jeremiah" (Currently #4).
Only the prophet and TV show left!
I have the edge, TV show is cancelled and the prophet isn't generating any new content.

The prophet, TV show, and that pesky Owyang guy going down!
A page to show up #1 on Google when searching for "Jeremiah Grossman", and it FINALLY has!

Friday, April 16, 2010

Best of Application Security (Friday, Apr. 16)

Ten of Application Security industry's coolest, most interesting, important, and entertaining links from the past week -- in no particular order.
  • Apache Foundation Hit by Targeted XSS Attack + Internal investigation + Associated Atlassian breach
  • CSRF Isn’t A Big Deal - Duh!
  • Network Solutions Hack: Secure File Permissions Matter + Sucuri Analysis
  • OWASP RFP Criteria Project
  • IE 8 Security Features Could Be Turned Against Users + Slides & PoC
  • Next-Generation Clickjacking Attacks Revealed + Tool
  • Brokerage Firm Fined $375,000 for Unsecured Data
  • Researcher Uncovers (Another) Major Facebook Security Exploit
  • New Full Disclosure, Website Vulnerabilities Database
  • Chrome Phishing
  • 5 Reasons HTTPOnly won't save you
Posted by Jeremiah Grossman at 3:00 PM No comments:

Friday, April 09, 2010

Best of Application Security (Friday, Apr. 9)

Ten of Application Security industry's coolest, most interesting, important, and entertaining links from the past week -- in no particular order.=
  • Microsoft SDL version 5
  • Force.com Secure Cloud Development
  • Stroke triggered XSS and StrokeJacking
  • German Government Pays Hacker For Stolen Bank Account Data
  • CAPEC-333: WASC Threat Classification 2.0
  • WAF Confusion Continues
  • Serious New Java Flaw Affects All Current Versions of Windows + Advisory
  • Safari Integer Overflow Aids Inter Protocol Exploitation
  • OWASP AIR + Flash Security Projects
  • Prion 1.1 - Polymorphic XSS Worm
Posted by Jeremiah Grossman at 2:00 PM No comments:

Friday, April 02, 2010

Best of Application Security (Friday, Apr. 2)

Ten of Application Security industry's coolest, most interesting, important, and entertaining links from the past week -- in no particular order.
  • Mozilla: Plugging the CSS History Leak
  • $43m slot machine win a 'mistake' says Colorado casino
  • OWASP Podcast: Ed Bellis (eCommerce) #63 and Andy Ellis (Availability) #64
  • Web application scanning with skipfish
  • Should the Government Stop Outsourcing Code Development?
  • Journalists in China say Yahoo accounts hacked
  • WASC Web Hacking Incident Database Project Update
  • I’m in ur 4sq, snarfin ur password — Part II
  • How Facebook is Adding an Identity Layer to the Internet
  • Firefox 3.6 FileAPI Exif Injection
Posted by Jeremiah Grossman at 1:00 PM No comments:
Newer Posts Older Posts Home
Subscribe to: Posts (Atom)

About Me

My Photo
Jeremiah Grossman
Jeremiah Grossman is the founder and Chief Technology Officer of WhiteHat Security [My Resume]
View my complete profile

Subscribe

Posts
Atom
Posts
All Comments
Atom
All Comments

Presentations

  • Mo' Money Mo' Problems
  • Get Rich or Die Trying
  • Top Ten Web Hacking Techniques (2008)
  • Website Security Statistics Report (Q1'09)

White Papers

  • Website Security 101
  • Vulnerability Assessment Plus Web Application Firewall (VA+WAF)
  • Technology Alone cannot Defeat Website Attacks: Understanding Technical vs. Logical Vulnerabilities
  • Top 5 Myths of Website Security
  • Seven Business Logic Flaws That Put Your Website At Risk
  • Cross Site Scripting (XSS) Worms and Viruses
  • Cross Site Request Forgery (CSRF)
  • Automated Scanning vs the OWASP Top Ten
  • 10 Things You Should Know about Website Security

Twitter Updates (@jeremiahg)

Twitter Updates

    follow me on Twitter

    (IN)SECURE Magazine

    (IN)SECURE Magazine

    My Links

    • WhiteHat Security
    • Web Application Security Consortium
    • GGAFL
    • OWASP [San Jose]
    • CGI Security
    • ha.ckers.org
    • Maui Tours
    • Maui Real Estate

    Blog Archive

    • ►  2013 (1)
      • ►  January (1)
    • ►  2012 (2)
      • ►  April (1)
      • ►  January (1)
    • ►  2011 (18)
      • ►  December (1)
      • ►  June (1)
      • ►  May (1)
      • ►  March (3)
      • ►  February (5)
      • ►  January (7)
    • ▼  2010 (62)
      • ►  December (9)
      • ►  November (2)
      • ►  October (1)
      • ►  September (3)
      • ►  August (2)
      • ►  July (5)
      • ►  June (5)
      • ►  May (3)
      • ▼  April (3)
        • Best of Application Security (Friday, Apr. 16)
        • Best of Application Security (Friday, Apr. 9)
        • Best of Application Security (Friday, Apr. 2)
      • ►  March (6)
      • ►  February (12)
      • ►  January (11)
    • ►  2009 (75)
      • ►  December (7)
      • ►  November (5)
      • ►  October (8)
      • ►  September (5)
      • ►  August (11)
      • ►  July (6)
      • ►  June (4)
      • ►  May (5)
      • ►  April (4)
      • ►  March (4)
      • ►  February (5)
      • ►  January (11)
    • ►  2008 (117)
      • ►  December (6)
      • ►  November (2)
      • ►  October (2)
      • ►  September (8)
      • ►  August (8)
      • ►  July (10)
      • ►  June (16)
      • ►  May (16)
      • ►  April (19)
      • ►  March (11)
      • ►  February (4)
      • ►  January (15)
    • ►  2007 (195)
      • ►  December (5)
      • ►  November (19)
      • ►  October (11)
      • ►  September (10)
      • ►  August (13)
      • ►  July (22)
      • ►  June (17)
      • ►  May (25)
      • ►  April (18)
      • ►  March (21)
      • ►  February (12)
      • ►  January (22)
    • ►  2006 (123)
      • ►  December (11)
      • ►  November (21)
      • ►  October (20)
      • ►  September (29)
      • ►  August (16)
      • ►  July (15)
      • ►  June (3)
      • ►  January (8)
    • ►  2005 (99)
      • ►  November (2)
      • ►  October (3)
      • ►  September (5)
      • ►  August (9)
      • ►  July (14)
      • ►  June (15)
      • ►  May (13)
      • ►  April (9)
      • ►  March (11)
      • ►  February (7)
      • ►  January (11)
    • ►  2004 (14)
      • ►  December (7)
      • ►  November (6)
      • ►  June (1)
    • ►  2001 (2)
      • ►  November (1)
      • ►  March (1)
    Picture Window template. Powered by Blogger.