<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>CGISecurity - Website and Application Security News</title>
    
    <link rel="alternate" type="text/html" href="http://www.cgisecurity.com/" />
    <id>tag:typepad.com,2003:weblog-1694854</id>
    <updated>2013-05-10T09:27:35-07:00</updated>
    <subtitle>All things related to website, database, SDL, and application security since 2000.
</subtitle>
    <generator uri="http://www.cgisecurity.com/">CGISecurity</generator>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="self" type="application/atom+xml" href="http://feeds.feedburner.com/typepad/1216429516s8517/news" /><feedburner:info uri="typepad/1216429516s8517/news" /><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com/" /><entry>
        <title>WASC Announcement: Static Analysis Technologies Evaluation Criteria Published</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/fsO0T5RPlqI/wasc-announcement-static-analysis-technologies-evaluation-criteria-published.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2013/05/wasc-announcement-static-analysis-technologies-evaluation-criteria-published.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883301901c079c38970b</id>
        <published>2013-05-10T09:27:35-07:00</published>
        <updated>2013-05-10T09:28:22-07:00</updated>
        <summary>The Web Application Security Consortium (WASC) is pleased to announce the Static Analysis Technologies Evaluation Criteria. The goal of the SATEC project is to create a vendor-neutral set of criteria to help guide application security professionals during the process of acquiring a static code analysis technology that is intended to be used...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Announcements" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Security Tools" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="WASC" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2013/05/wasc-announcement-static-analysis-technologies-evaluation-criteria-published.html</feedburner:origLink></entry>
    <entry>
        <title>Poll: How do you rank the importance of a vulnerability?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/PUod9IYsN-w/poll-how-do-you-rank-the-importance-of-a-vulnerability.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2013/01/poll-how-do-you-rank-the-importance-of-a-vulnerability.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a288833017ee727218e970d</id>
        <published>2013-01-09T15:37:36-08:00</published>
        <updated>2013-01-09T15:38:09-08:00</updated>
        <summary>I've added a new poll to the WASC linkedin group that a few of you may be interested in. Specifically asking how people rank the importance of vulnerabilities. Poll Link http://www.linkedin.com/groups/How-do-you-rank-importance-83336.S.202840840</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Research" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="SDL" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vulns" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2013/01/poll-how-do-you-rank-the-importance-of-a-vulnerability.html</feedburner:origLink></entry>
    <entry>
        <title>Five pieces of advice for those new to the infosec industry</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/PmyegwU3i_M/five-pieces-of-advice-for-those-new-to-the-infosec-industry.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2012/09/five-pieces-of-advice-for-those-new-to-the-infosec-industry.html" thr:count="3" thr:updated="2012-11-01T23:53:06-07:00" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a288833017ee3e2ee43970d</id>
        <published>2012-10-31T11:24:31-07:00</published>
        <updated>2012-10-31T21:21:22-07:00</updated>
        <summary>I've worked in the security field in various roles (script kiddie, security researcher, incident response, application security engineer, security consultant, strategy, etc..) and thought I'd share a few points to those of you starting out in the security industry. Things are worse than you expect The reality is that companies, even large...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Commentary" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Development" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Funny" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Incidents" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Rant" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="SDL" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2012/09/five-pieces-of-advice-for-those-new-to-the-infosec-industry.html</feedburner:origLink></entry>
    <entry>
        <title>Security Industry Plagiarism: Finding 3 examples in 5 minutes with Google </title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/f_aZYZncF24/detecting-plagiarism-with-google-and-book-search.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2012/01/detecting-plagiarism-with-google-and-book-search.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a288833015437d07740970c</id>
        <published>2012-01-07T23:11:50-08:00</published>
        <updated>2012-01-09T23:59:39-08:00</updated>
        <summary>UPDATE: One of the authors has posted two responses including an apology (accepted). I was taught in grade school that if you plan on writing something, never plagiarize. If you want to republish portions of existing content ensure you properly quote/reference them, and never represent this content as your own original work....</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Books" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Commentary" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Forensics" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Funny" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Off Topic" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Rant" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Site News" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="XSS" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2012/01/detecting-plagiarism-with-google-and-book-search.html</feedburner:origLink></entry>
    <entry>
        <title>Quick defcon/blackhat preparation list</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/hO6zjrKVsDs/quick-defconblackhat-preperation-list.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2011/07/quick-defconblackhat-preperation-list.html" thr:count="2" thr:updated="2011-08-04T23:43:40-07:00" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a288833015434107d2b970c</id>
        <published>2011-07-28T13:25:19-07:00</published>
        <updated>2011-07-28T14:32:48-07:00</updated>
        <summary>A couple of people had asked me what are some things that you can do prior to attending hacker cons such as Blackhat and Defcon. Kurt Cobain said it best "Just because you're paranoid, doesn't mean they're not after you'. Here's a short list (albeit not complete as I don't plan to...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Events" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Funny" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2011/07/quick-defconblackhat-preperation-list.html</feedburner:origLink></entry>
    <entry>
        <title>Summary of Google+ browser security protections</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/dApjRCHIpUg/summary-of-google-browser-security-protections.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2011/07/summary-of-google-browser-security-protections.html" thr:count="1" thr:updated="2012-10-31T22:49:47-07:00" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883301543409c1d8970c</id>
        <published>2011-07-27T10:03:26-07:00</published>
        <updated>2012-11-29T09:29:14-08:00</updated>
        <summary>Ray "Vanhalen" Kelly has written a post describing the security mechanisms used by Google+, as well as compares them to facebook. In particular he reviews each HTTP protection header and provides a good explanation of the purpose of each protection. Link: https://www.barracudanetworks.com/blogs/labsblog?bid=1743</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Browsers" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2011/07/summary-of-google-browser-security-protections.html</feedburner:origLink></entry>
    <entry>
        <title>Paper: Web Application finger printing Methods/Techniques and Prevention</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/q7JsWr8VVBs/paper-web-application-finger-printing-methodstechniques-and-prevention.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2011/07/paper-web-application-finger-printing-methodstechniques-and-prevention.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a2888330153901404c9970b</id>
        <published>2011-07-21T13:51:40-07:00</published>
        <updated>2011-07-21T13:51:40-07:00</updated>
        <summary>Anant Shrivastava has posted a whitepaper providing a rundown of application fingerprinting methodologies, as well as comparisons of various tools such as W3af, BlindElephant, and Wapplyzer. "This Paper discusses about a relatively nascent field of Web Application finger printing, how automated web application fingerprinting is performed in the current scenarios, what are...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Research" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2011/07/paper-web-application-finger-printing-methodstechniques-and-prevention.html</feedburner:origLink></entry>
    <entry>
        <title>Oracle website vulnerable to SQL Injection</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/JU4NFEsuhV4/oracle-website-vulnerable-to-sql-injection.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2011/07/oracle-website-vulnerable-to-sql-injection.html" thr:count="1" thr:updated="2011-07-27T11:41:00-07:00" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a288833014e899fad3a970d</id>
        <published>2011-07-05T15:21:44-07:00</published>
        <updated>2011-07-05T15:21:44-07:00</updated>
        <summary>Someone has published a SQL Injection in labs.oracle.com at http://www.thehackernews.com/2011/07/oracle-website-vulnerable-to-sql.html . That is all.</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Funny" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Incidents" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vulns" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2011/07/oracle-website-vulnerable-to-sql-injection.html</feedburner:origLink></entry>
    <entry>
        <title>WASC Announcement: 'Static Analysis Tool Evaluation Criteria' Call For Participants</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/9_T8WuzgHzE/wasc-announcement-static-analysis-tool-evaluation-criteria-call-for-participants.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2011/06/wasc-announcement-static-analysis-tool-evaluation-criteria-call-for-participants.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a288833014e896db9c3970d</id>
        <published>2011-06-27T12:26:08-07:00</published>
        <updated>2011-06-27T12:42:14-07:00</updated>
        <summary>I sent the following out to The Web Security Mailing List (which I moderate) announcing a new WASC Project. "The Web Application Security Consortium is pleased to announce a new project "Static Analysis Tool Evaluation Criteria (SATEC)". Currently WASC is seeking volunteers from various sections of the community including security researchers, academics,...</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Announcements" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Research" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="SDL" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Security Tools" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="WASC" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2011/06/wasc-announcement-static-analysis-tool-evaluation-criteria-call-for-participants.html</feedburner:origLink></entry>
    <entry>
        <title>Results of internet SSL usage published by SSL Labs</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/typepad/1216429516s8517/news/~3/0ywrkLeitbA/results-of-internet-ssl-usage-published-by-ssl-labs.html" />
        <link rel="replies" type="text/html" href="http://www.cgisecurity.com/2011/05/results-of-internet-ssl-usage-published-by-ssl-labs.html" thr:count="2" thr:updated="2011-06-22T16:45:57-07:00" />
        <id>tag:typepad.com,2003:post-6a00e553aa1a28883301538eb65af4970b</id>
        <published>2011-05-25T09:53:19-07:00</published>
        <updated>2011-06-22T16:45:32-07:00</updated>
        <summary>Ivan Ristic (of modsecurity fame) has published the results of an evaluation against over 900,000 websites supporting SSL. The goal of this evaluation was to see how people really use/misuse ssl in the wild, as well as report on the usage of browser protections such as the Secure cookie flag, and Strict-Transport-Security....</summary>
        <author>
            <name>Robert A.</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Browsers" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cryptography" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="IndustryNews" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Research" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Vulns" />
        
        


    <feedburner:origLink>http://www.cgisecurity.com/2011/05/results-of-internet-ssl-usage-published-by-ssl-labs.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 -->
