Sign in
The Connected Information Security Group
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search
Tags
Anti-XSS
BPM
CAT.NET
CISG
Frameworks and Platforms
ISO
OWASP
Product Management
Program Management
Royal Holloway
Secure Coding
Security Standards
Software Requirements
UX
Archive
Archives
April 2009
(1)
March 2009
(1)
February 2009
(2)
January 2009
(4)
December 2008
(9)
November 2008
(1)
October 2008
(8)
September 2008
(17)
August 2008
(7)
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
The Connected Information Security Group
How To: Detect Cross Site Scripting Vulnerabilities using XSSDetect
Posted
over 5 years ago
by
cisg
5
Comments
RV again... Last time we saw how to fix a cross site scripting (XSS) vulnerability. This time we look at how we can detect cross site scripting vulnerabilities using automated tools. Being the most common vulnerability found in web applications, it is...
The Connected Information Security Group
Which ASP.NET Controls Need HTML Encoding?
Posted
over 5 years ago
by
cisg
4
Comments
RV here... Last time we saw some some real world XSS examples. This time we will look at which common ASP.NET controls require encoding. Some controls in ASP.NET automatically encode certain properties when rendered, not all the controls do the same....
The Connected Information Security Group
Real World XSS Vulnerabilities in ASP.NET Code
Posted
over 5 years ago
by
cisg
6
Comments
RV here again... From couple of weeks we have been seeing some XSS vulnerabilities in asp.net code. Today I wanted to show you guys some real world examples ranging from property assignments, data binding and JavaScript building. For each example, I will...
The Connected Information Security Group
Performance Analysis Reveals Char[] Array is Better than StringBuilder
Posted
over 5 years ago
by
cisg
5
Comments
Anil Chintala here... I told you in my previous blog about AntiXSS Output Encoding methodology and why I think it is better than .NET framework's encoding methods in preventing XSS vulnerabilities. Although, AntiXSS is superior in restricting XSS vulnerabilities...
The Connected Information Security Group
SQL Injection - Are Stored Procedures Really Safe?
Posted
over 5 years ago
by
cisg
3
Comments
Vineet Batta here.... SQL Injection explained : SQL injection attack is the way to manipulate the SQL statement (insert malicious code) from applications to query or execute commands against the database. This can allow an attacker to not only steal data...
The Connected Information Security Group
Trip Report : Day Two of Gartner BPM Conference
Posted
over 5 years ago
by
cisg
2
Comments
Hi Marius here again with highlights from day 2 of the Gartner BPM conference. Back of the Napkin You may have heard of the book called The Back of the Napkin : Solving Problems and Selling Ideas with Pictures. It’s one of the latest books creating...
The Connected Information Security Group
Client-Side Scripting Languages Support in AntiXSS
Posted
over 5 years ago
by
cisg
0
Comments
Anil Chintala here... Recently I was asked about a question on client-side scripting language support in AntiXSS library. Q: Does AntiXSS library support client-side Java Script language? Yes, AntiXSS does provide support for client side scripting languages...
The Connected Information Security Group
Trip Report : Day One of Gartner BPM Conference
Posted
over 5 years ago
by
cisg
1
Comments
Marius Grigoriu here.... I am a Program manager with CISG and in keeping with good program management its straight down to business. Today was the first official day of the Gartner BPM Conference at Washington DC and I am posting daily trip reports. In...
The Connected Information Security Group
Obfuscation Explained...
Posted
over 5 years ago
by
cisg
3
Comments
Hi Vineet Batta here.... Background Programs written for .NET are relatively easy to reverse engineer. You can use free tools like Lutz Roeder's .NET Reflector to load .NET assemblies and view all the code (IL) contained within them. This is not in any...
The Connected Information Security Group
Checklists and Mnemonics
Posted
over 5 years ago
by
cisg
1
Comments
Dennis Groves here.... The most common list is the to-do list , and it is the one we are all most familiar with and so the real value of a checklist is often very misunderstood . Aviation and medicine make heavy use of them. Computer programs are basically...
The Connected Information Security Group
Trip Report : Day Three of Gartner BPM Conference
Posted
over 5 years ago
by
cisg
1
Comments
Marius here again..... Highlights: On average, 80% of the IT budget goes toward maintenance and only 20% goes to new projects. On top of that, IT budgets keep shrinking year after year. This creates a big challenge in funding large initiatives like BPM...
The Connected Information Security Group
Beauty Aint Necessarily in the Eye of the Beholder
Posted
over 5 years ago
by
cisg
1
Comments
There's a truism that says, "beauty is in the eye of the beholder." I'm here to tell you that that's not precisely the case; that the quality of beauty is not subjective. Beauty is clearly definable, and universally understandable...
The Connected Information Security Group
Doing What You Want, Not What You Have To!
Posted
over 5 years ago
by
cisg
1
Comments
Birm here..... As I go about my daily routine, I talk a lot with people directly involved in software design and development. It’s become clear that based on their training and experience, each person has a different take on what constitutes “user...
The Connected Information Security Group
Designing Whole Systems
Posted
over 5 years ago
by
cisg
1
Comments
Hi Dennis Groves here...... Recently I was questioned over a comment I made about a USB key being functionally equivalent to a Smart Card in a discussion about bit-locker . I of course not understand that they are technically not equivalent. Smart cards...
The Connected Information Security Group
There's a LOT More to Building Security Software than Software Security
Posted
over 5 years ago
by
cisg
0
Comments
Mark Curphey here..... I often get asked exactly what I do for a living at Microsoft. Many people associate my name with OWASP , my personal blog and software security in general. When I say I am a PUM (Product Unit Manager) and run a team that...
The Connected Information Security Group
How Do you Get from Theoretical Physics to Information Security?
Posted
over 5 years ago
by
cisg
1
Comments
Hi Andreas Fuchsberger here.....and no this is not a new Seinfield commercial! The much anticipated and televised switch-on of the Large Hadron Collider (LHC) at CERN made me realise again how little we know about life and how much there is still for...
The Connected Information Security Group
It’s All About the Persona(s)
Posted
over 5 years ago
by
cisg
1
Comments
Birm here… Has this ever happened to you? It’s happened to me. You sit down to write an application that looks great and works even better. The UI you’ve designed is a model of esthetics and efficiency. You’ve demo’d it to...
Page 1 of 1 (17 items)