Showing posts with label AppSec. Show all posts
Showing posts with label AppSec. Show all posts

Tuesday, November 15, 2011

Inspecting HTTPS traffic on gateways

INTRODUCTION

In the past, security devices inspecting application content for attack patterns, misuse or malware, had been blind to encrypted traffic and due to this encrypted protocols like Hypertext Transfer Protocol Secure (HTTPS) have been a safe method used by attackers to bypass security inspection. Though reverse proxies and Web Server modules have been there for long, but they only inspect incoming traffic i.e. connections made to protected web servers in the organization. Inspecting outgoing traffic or traffic of connections made by users to outside world servers, not protected by the device, had been on the wish lists. Devices these days come with the capability to inspect Secure Sockets Layer (SSL) based outgoing traffic, however there are some concerns enabling such kind of inspection. In this article we cover some basics of SSL, the challenges in inspecting SSL traffic, and also see how Check Point's HTTPS Inspection feature starting from R75.20 is able to inspect HTTPS traffic at the gateway. After reading this article you will know the pros and cons of enabling SSL inspection on a gateway.

Read further or download the entire document in PDF format below:
Inspecting HTTPS Traffic on Gateways

Tuesday, June 1, 2010

Web Attackers will have a tough time now!

The attackers have surely moved their focus on web applications but this team is now fully prepared to detect and analyze any intrustion happening through their web applications. They've acquired these skills by going through a specialized training from K-Secure.

Wednesday, April 21, 2010

OWASP Top 10 - 2010 released

Want to get started with application security? OWASP (The Open Web Application Security Project) has released the list of ten most critical web application security risks.

Top 10
------
A1: Injection
A2: Cross-Site Scripting (XSS)
A3: Broken Authentication and Session Management
A4: Insecure Direct Object References
A5: Cross-Site Request Forgery (CSRF)
A6: Security Misconfiguration (New)
A7: Insecure Cryptographic Storage
A8: Failure to Restrict URL Access
A9: Insufficient Transport Layer Protection
A10: Unvalidated Redirects and Forwards (New)

More on Top 10 is given here - OWASP Top 10