The Web Security Mailing List (2006 August)
- Re: [WEB SECURITY] JavaScript Malware, port scanning, and beyond
- From: Amit Klein (AKsecurity)
- RE: [WEB SECURITY] JavaScript Malware, port scanning, and beyond
- [WEB SECURITY] [Administrative] List slow down
- RE: [WEB SECURITY] JavaScript Malware, port scanning, and beyond
- From: Amit Klein (AKsecurity)
- Re: [WEB SECURITY] JavaScript Malware, port scanning, and beyond
- [WEB SECURITY] XSS at Netcraft.com
- Re: [WEB SECURITY] JavaScript Malware, port scanning, and beyond
- From: Amit Klein (AKsecurity)
- Re: [WEB SECURITY] JavaScript Malware, port scanning, and beyond
- From: Amit Klein (AKsecurity)
- Re: [WEB SECURITY] Detecting, Analyzing, and Exploiting Intranet Applications using JavaScript
- Re: [WEB SECURITY] JavaScript Malware, port scanning, and beyond
- From: Amit Klein (AKsecurity)
- [WEB SECURITY] Autocomplete attribute
- From: Benjamin Hawkes-Lewis
- Re: [WEB SECURITY] Autocomplete attribute
- From: Andrew van der Stock
- [WEB SECURITY] Announcement: Feed Injection in Web 2.0: Hacking RSS and Atom Feed Implementations [Whitepaper]
- [WEB SECURITY] Article about HttpOnly
- Re: [WEB SECURITY] Article about HttpOnly
- Re: [WEB SECURITY] Article about HttpOnly
- Re: [WEB SECURITY] Article about HttpOnly
- Re: [WEB SECURITY] Autocomplete attribute
- From: Benjamin Hawkes-Lewis
- [WEB SECURITY] Ruby On Rails 1.1.5 Released to Address Critical Vulnerability
- [WEB SECURITY] Sending multipart/form-data requests from Flash (with arbitrary headers)
- From: Amit Klein (AKsecurity)
- RE: [WEB SECURITY] Ruby On Rails 1.1.5 Released to Address Critical Vulnerability
- [WEB SECURITY] RE: Ruby On Rails 1.1.5 Released to Address Critical Vulnerability
- [WEB SECURITY] Re: Ruby On Rails 1.1.5 Released to Address Critical Vulnerability
- Re: [WEB SECURITY] RE: Ruby On Rails 1.1.5 Released to Address Critical Vulnerability
- [WEB SECURITY] Top sites for Application security news
- [WEB SECURITY] Re: [Full-disclosure] Top sites for Application security news
- [WEB SECURITY] Re: [Full-disclosure] Top sites for Application security news
- Re: [WEB SECURITY] Re: [Full-disclosure] Top sites for Application security news
- RE: [WEB SECURITY] Top sites for Application security news
- [WEB SECURITY] Re: [Full-disclosure] Top sites for Application security news
- From: Alice Bryson <abryson@xxxxxxxxxxxxx>
- Re: [WEB SECURITY] Top sites for Application security news
- [WEB SECURITY] Secure coding guidelines
- Re: [WEB SECURITY] Top sites for Application security news
- RE: [WEB SECURITY] Secure coding guidelines
- [WEB SECURITY] Web app ? : Lieberman's site
- RE: [WEB SECURITY] Secure coding guidelines
- RE: [WEB SECURITY] Secure coding guidelines
- Re: [WEB SECURITY] Secure coding guidelines
- [WEB SECURITY] Bypassing script filters with variable-width encodings
- RE: [WEB SECURITY] Article about HttpOnly
- Re: [WEB SECURITY] Article about HttpOnly
- RE: [WEB SECURITY] Secure coding guidelines
- Re: [WEB SECURITY] Article about HttpOnly
- [WEB SECURITY] Re: [Full-disclosure] Re: [WEB SECURITY] Top sites for Application security news
- [WEB SECURITY] Re: [Full-disclosure] Re: [WEB SECURITY] Top sites for Application security news
- Re: [WEB SECURITY] Article about HttpOnly
- From: Amit Klein (AKsecurity)
- [WEB SECURITY] (somewhat) breaking the same-origin policy by undermining dns-pinning
- [WEB SECURITY] Technical note: under some conditions, it's possible to steal HTTP credentials using Flash
- From: Amit Klein (AKsecurity)
- RE: [WEB SECURITY] Article about HttpOnly
- [WEB SECURITY] "hack-me" Ajax apps?
- [WEB SECURITY] [Fwd: InterScout Web Forensics Tool Released as Freeware]
- Re: [WEB SECURITY] "hack-me" Ajax apps?
- RE: [WEB SECURITY] "hack-me" Ajax apps?
- [WEB SECURITY] Registration Now Open!: 3rd Annual US OWASP AppSec Conference - Oct 16-18 2006 - Seattle, WA
- [WEB SECURITY] Technical note by Amit Klein: "Sending arbitrary HTTP requests with Flash 7/8 (+IE 6.0)"
- From: Amit Klein (AKsecurity)
- [WEB SECURITY] Re: [SC-L] Registration Now Open!: 3rd Annual US OWASP AppSec Conference - Oct 16-18 2006 - Seattle, WA
- [WEB SECURITY] Registration Now Open!: Security OPUS Infosec Conference - Oct 2-5 2006 - San Francisco, CA
- [WEB SECURITY] World Summit on Intrusion Prevention
- Re: [WEB SECURITY] World Summit on Intrusion Prevention
- [WEB SECURITY] RE: World Summit on Intrusion Prevention
- [WEB SECURITY] Corsaire White Paper: Assessing Java Clients with the BeanShell
- [WEB SECURITY] DDOS extortion
- [WEB SECURITY] Re: "hack-me" Ajax apps?
- From: Andrew van der Stock
- [WEB SECURITY] Mitnick's website hacked (again)
- [WEB SECURITY] Google Redirect URL actively used for Phishing
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- [WEB SECURITY] WiKID 2.1.1 released
- Re: [WEB SECURITY] Google Redirect URL actively used for Phishing
- [WEB SECURITY] RE: Environment for testing WebApp Security Scanners
- Re: [WEB SECURITY] RE: Environment for testing WebApp Security Scanners
- Re: [WEB SECURITY] RE: Environment for testing WebApp Security Scanners
- RE: [WEB SECURITY] RE: Environment for testing WebApp Security Scanners
- RE: [WEB SECURITY] RE: Environment for testing WebApp Security Scanners
- RE: [WEB SECURITY] RE: Environment for testing WebApp Security Scanners
- RE: [WEB SECURITY] RE: Environment for testing WebApp Security Scanners
- RE: [WEB SECURITY] RE: Environment for testing WebApp Security Scanners
- [WEB SECURITY] Problem about detecting "SMTP command injection", i.e. cr lf chars in web forms
- [WEB SECURITY] Re: Problem about detecting "SMTP command injection", i.e. cr lf chars in web forms
- From: Jorge Augusto Senger
- [WEB SECURITY] Hacme Casino v1.0
- [WEB SECURITY] Resources for testing hosted/ASP sites
- RE: [WEB SECURITY] Resources for testing hosted/ASP sites
- [WEB SECURITY] Time Parameter For Expiration of the Session
- Re: [WEB SECURITY] Time Parameter For Expiration of the Session
- Re: [WEB SECURITY] Article about HttpOnly
- Re: [WEB SECURITY] Article about HttpOnly
- [WEB SECURITY] MySpace "private" profiles unmasked
- [WEB SECURITY] AT&T Online store hacked (19,000 exposed CC #'s)
- [WEB SECURITY] Doorman@JUMPERZ.NET Released
Brought to you by http://www.webappsec.org
Search this site
|