Responding to DoS attacks at the web layer

Are you ready to respond to DoS attacks at the web layer? In this article, Kevin Beaver shares an anecdote from his own experience whilst highlighting some important steps to take. First things first; responding to DoS attacks at the … [+]

Did you know that there are risks associated with third-party software?

The Risks Associated with Third-Party Software Components

I was recently contacted by a colleague in an information security leadership position who was concerned about his developers using some third-party plug-ins for an enterprise application they were rolling out. His developers wanted to install these third-party components in … [+]

What do you do when you can't find every web vulnerability?

What Happens when you can’t Find Every Web Vulnerability?

On one end of the application security and IT audit spectrum we have people that overlook the obvious and critical stuff. But just as dangerously, on the other end of the spectrum we have people who want us to find … [+]

Incident Response Plan Template – The Essential Elements

Incident Response Plan Template – The Essential Elements

Incident response is the art (and science) of responding to computer security-related breaches. Interestingly, most organizations I deal with don’t have a documented incident response plan. The last thing you want to do during and after a security breach is … [+]

How to set (and keep) your web security goals for 2013

How to Set (and Keep) Your Web Security Goals for 2013

Can you believe it’s time again for those New Year’s resolutions? It’s always great to start the New Year with a fresh set of to-do items that you’re finally going to get around to doing. The problem, however, is that … [+]

Practice Makes Perfect

Your Scanning Experience Determines Your Scanning Success

You know the saying about riding a bicycle – do it once and you’ll remember it forever? That may be true for bicycles, but it’s certainly not the case when it comes to web security testing. The tools we use … [+]

Finding Web Flaws is not Point and Click

Finding Web Flaws is not Point and Click

Successful web security testing is not as simple as point and click. Unfortunately, many people treat it as such. The thought process goes something like this: 1.    Load web vulnerability scanner. 2.    Enter URL to scan. 3.    Click Go. 4.   … [+]

What can Developers do to Better Protect PII?

What can Developers do to Better Protect PII?

A client of mine recently asked me if I had any Web development related tips for dealing with Personally Identifiable Information (PII). With this being an information security 101 type question, I had to think about it for a bit. … [+]

Should you Test Development, Staging or Production?

Should you Test Development, Staging or Production?

You’ve heard me say that planning is half the battle with Web security assessments. I’m finding that more and more people are on board with thinking things through in advance but there’s still one area that’s not getting the attention … [+]