The Web Security Mailing List (2006 November)
- [WEB SECURITY] standards for session tokens,
Brian Eaton
- [WEB SECURITY] Should software vendors come clean about application vulnerabilities?,
Anurag Agarwal
- [WEB SECURITY] XSS Question,
jfvanmeter
- [WEB SECURITY] Browser Port Scanning without JavaScript,
Jeremiah Grossman
- [WEB SECURITY] Verification Mechanism,
shadi . aljawarneh
- [WEB SECURITY] Google flaw adds phishing hole to Web sites,
Emilio Casbas
- [WEB SECURITY] Vulnerability Scanning Web 2.0 Client-Side Components,
bugtraq
- [WEB SECURITY] The state of JavaScript Hacking,
pdp (architect)
- [WEB SECURITY] AttackAPI 2.0 alpha,
pdp (architect)
- [WEB SECURITY] ANNOUNCE: WSGI XSS Prevention Middleware,
Richard Moore
- [WEB SECURITY] Help with OWASP Session hijack challenge,
Ankur Jindal
- [WEB SECURITY] Sesion hijacking impossible with SSL client authentication?,
Holger.Peine
- [WEB SECURITY] RE: "off topic" : tools to automatically check the availbility of a website,
s4tan
- [WEB SECURITY] Question about URL parameters,
Colleen Kirtland
- [WEB SECURITY] Java Swing Application Security,
Dharmesh Mehta
- [WEB SECURITY] SIFT Web Services Security Testing Framework,
Daniel Grzelak
- RE: [WEB SECURITY] Challenges faced by automated web application,
Enis Karaarslan
- [WEB SECURITY] Challenges faced by automated web application security assessment tools,
bugtraq
- [WEB SECURITY] timing out user sessions,
Evert | Rooftop
- <Possible follow-ups>
- Re: [WEB SECURITY] timing out user sessions,
Anurag Agarwal
[WEB SECURITY] Web Application Security Professionals Survey,
Jeremiah Grossman
Re: [WEB SECURITY] SiteKey,
teracci2002
[WEB SECURITY] How to find a user accessing my website,
Anurag Agarwal
[WEB SECURITY] measuring coverage,
Chris Weber
[WEB SECURITY] Educational write-up by Amit Klein: "A Refreshing Look at Redirection",
Amit Klein
RE: [WEB SECURITY] Can WAF's block CSRF?,
Tom Spector
Brought to you by http://www.webappsec.org