Showing posts with label WebAppSec. Show all posts
Showing posts with label WebAppSec. Show all posts
Tuesday, June 1, 2010
Web Attackers will have a tough time now!
Wednesday, April 21, 2010
OWASP Top 10 - 2010 released
Want to get started with application security? OWASP (The Open Web Application Security Project) has released the list of ten most critical web application security risks.
Top 10
------
A1: Injection
A2: Cross-Site Scripting (XSS)
A3: Broken Authentication and Session Management
A4: Insecure Direct Object References
A5: Cross-Site Request Forgery (CSRF)
A6: Security Misconfiguration (New)
A7: Insecure Cryptographic Storage
A8: Failure to Restrict URL Access
A9: Insufficient Transport Layer Protection
A10: Unvalidated Redirects and Forwards (New)
More on Top 10 is given here - OWASP Top 10
Top 10
------
A1: Injection
A2: Cross-Site Scripting (XSS)
A3: Broken Authentication and Session Management
A4: Insecure Direct Object References
A5: Cross-Site Request Forgery (CSRF)
A6: Security Misconfiguration (New)
A7: Insecure Cryptographic Storage
A8: Failure to Restrict URL Access
A9: Insufficient Transport Layer Protection
A10: Unvalidated Redirects and Forwards (New)
More on Top 10 is given here - OWASP Top 10
Monday, February 16, 2009
Workshop at Cert-In
Cert-In had organized a one day Workshop on "Application Security : Latest Trends" which was conducted on 30th January, 2009. The objective of the workshop was to create awareness among Indian IT Infrastructure and user organisations on the latest trends in Application Security. Delegates were from Government, Corporate and critical sector organizations.
We were invited to present on Defense Mechanisms where I gave an overview of the various ways of protecting web applications with more focus on web application firewalls. My presentation is available here - WAS Defense Mechanisms
We were invited to present on Defense Mechanisms where I gave an overview of the various ways of protecting web applications with more focus on web application firewalls. My presentation is available here - WAS Defense Mechanisms
Wednesday, October 1, 2008
Friday, July 18, 2008
Web Application Security Awareness Workshop
K-Secure and Blueinfy conducted this workshop in Mumbai which was very much appreciated by the participants. The same workshop covering the following topics will be conducted on 5 Aug in Mumbai and 6 Aug in Pune
· Web Security and attacks on the rise
· Know your enemy
· Corporate at risk - real life cases
· Web application security fundamentals
· Web components and security
· Developing Security around SDLC
· Industry best practices for architects and designers
· Threat modeling and methodologies
· Attack vectors and overview
· Top 10 attacks like SQL injection, XSS etc.
· Exploitation and Impact on corporate
· Next generation attacks - Web 2.0
· Defense methodologies
· Securing web applications and site
· Secure coding
· Application layer firewalls
· Live hacks and attacks - Demos
Interested participants can contact at info@ksecure.net
Web site: www.ksecure.net
· Web Security and attacks on the rise
· Know your enemy
· Corporate at risk - real life cases
· Web application security fundamentals
· Web components and security
· Developing Security around SDLC
· Industry best practices for architects and designers
· Threat modeling and methodologies
· Attack vectors and overview
· Top 10 attacks like SQL injection, XSS etc.
· Exploitation and Impact on corporate
· Next generation attacks - Web 2.0
· Defense methodologies
· Securing web applications and site
· Secure coding
· Application layer firewalls
· Live hacks and attacks - Demos
Interested participants can contact at info@ksecure.net
Web site: www.ksecure.net
Subscribe to:
Posts (Atom)






