Sign In
Bryan Sullivan's Web Blog
Thoughts on web application security
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
bluehat
CSRF
REST
sql injection
waf
XHR
XMLHttpRequest
XSRF
xss
Archive
Archives
August 2008
(1)
June 2008
(1)
May 2008
(2)
April 2008
(1)
March 2008
(1)
MSDN Blogs
>
Bryan Sullivan's Web Blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Bryan Sullivan's Web Blog
REST and XSRF, Part One
Posted
over 4 years ago
by
bryansul
1
Comments
Hi everyone. In case you missed my talk at Black Hat , “REST for the Wicked”, I wanted to give you the Cliffs Notes version here. This will be a two-part post; the first will deal with attack techniques and the second will describe appropriate design...
Bryan Sullivan's Web Blog
Show some respect to XSS
Posted
over 4 years ago
by
bryansul
1
Comments
StickyMinds.com has just posted an article of mine on the dangers of XSS . (Although they still have my old bio from when I worked at HP, I'll have to get that changed!)
Bryan Sullivan's Web Blog
SQL injection in classic ASP
Posted
over 4 years ago
by
bryansul
0
Comments
In light of the recent wake of SQL injection attacks on ASP sites, I'd like to highlight some relevant resources for learning about and responding to the threat. Bala Neerumalla has written a detailed document for preventing SQL injection in ASP (that...
Bryan Sullivan's Web Blog
Web Application Firewalls in Practice - or - Yes, Jeremiah, Secure Software Does Matter
Posted
over 4 years ago
by
bryansul
2
Comments
There's been a lot of renewed interest in web application firewalls lately. In the past, I haven't been a huge fan of WAFs - they always seemed to me to be just a band-aid stuck on the sucking chest wound of insecure code. But I bumped into Jeremiah Grossman...
Bryan Sullivan's Web Blog
Cross-domain XHR will destroy the internet
Posted
over 4 years ago
by
bryansul
5
Comments
Ok, maybe “destroy the internet” is a little harsh. But let’s take a look the impact that implementation of the current W3C working draft for cross domain access would have on browser security. Some people might argue that there’s no more risk from cross...
Bryan Sullivan's Web Blog
BlueHat shows some love to web app security
Posted
over 4 years ago
by
bryansul
3
Comments
If you haven't heard yet, BlueHat v7 is dedicating the entire block of morning sessions to web app security issues. I'll be there, talking about my first 30 days as the new web app sec guy on the SDL team. Hope to see you there!
Page 1 of 1 (6 items)