Defensive Web Programming
Web Address: http://www.diigo.com/list/jaykul/defensive-webYou are here: Diigo Home > Joel Bennett > Joel Bennett's lists
Items:16 | Visits:26
Category:Computers & Internet | Tags:Web, Programming, Hacking, Security
Created:on 2008-07-22 | Updated:on 2008-07-23
Links that came up during Security Innovations training course and other research
-
Security Innovation - Application Security, Risk Assessment and Risk Mitigation
These are the guys teaching the courst on Defensive Web Programming
more fromwww.securityinnovation.com
-
1Expand
Parosproxy.org - Web Application Security
Paros is for people who need to evaluate the security of their web applications. Which is a proxy that allows you to intercept and modify all HTTP and HTTPS data for the purposes of testing.
more fromwww.parosproxy.org
-
1Expand
Introducing the Anti-Cross Site Scripting Library - ASP.NET Forums
Asp.Net forum post announcing the Anti-Cross Site Scripting (XSS) library from Microsoft, with links to downloa.d and documentation
more fromforums.asp.net
-
OWASP Validation Project - OWASP
OWASP CSRF Guard - protects a web application from Cross-Site Request Forgery attacks through the use of a unique random request token...
more fromwww.owasp.org
-
Napkin - 0x90.org
This URL is blocked by the Xerox proxy... but it's the home of the napkin app shown during class on Tuesday.
more fromwww.0x90.org
-
Sha1, MD4, URL, Base64, Base85 and MD5 Decoder / Encoder
A web-based alternative to Napkin for encoding strings...
more fromtools.web-max.ca
-
OWASP Encoding Project
The Reform library provides a solid set of functions for encoding output for the most common context targets in web applications (e.g. HTML, XML, JavaScript, etc). The library also takes a conservative view of what are allowable characters based on historical vulnerabilities, and current injection techniques.
more fromwww.owasp.org
-
Holodeck - Software Testing using Fault Injection - Security Innovation
Holodeck - allows you to simulate faults like out-of-memory, high latency, etc, and in geneal take full control over a simulated windows and .net API environment to test your applications.
more fromwww.securityinnovation.com
-
Security Renegades's blog
John's blog ...
more fromblogs.csoonline.com
-
Information Risk Management: Tools & Resources: Vulnerability Scanning Program
The vulnerability scanning program is an integral part of the information security risk assessment process. Scans are conducted against environmental components: servers (OS), databases, and web applications. Vulnerability scanning may be conducted from an internal or external location to identify weaknesses within the environment and mitigate against them before they can be exploited.
more fromxww.internal.world.xerox.com

