releases

Acunetix Web Vulnerability Scanner Product Releases

docs & FAQs

Acunetix technical documentation and FAQ

news

Acunetix Company and Web Security news, & Press Releases

events

Acunetix Webinars, Events and Training around the world

web security zone

Everything you need to know about Web Security

Home » Archive by Category

Articles in articles

Statistics from a phisher’s list
November 30, 2010 – 5:55 pm | 2 Comments
Statistics from a phisher’s list

Yesterday night I was following some security related forums and some person posted a phishing kit for a popular bank from Romania.  A phishing kit is a collection of scripts to help a script kiddie …

HTTP Post Denial Of Service: more dangerous than initially thought
November 22, 2010 – 8:47 pm | 17 Comments
HTTP Post Denial Of Service: more dangerous than initially thought

Wong Onn Chee and Tom Brennan from OWASP recently published a paper* presenting a new denial of service attack against web servers.
What’s special about this denial of service attack is that it’s very hard to …

Notable changes in PCI DSS 2.0 affecting Web application security
November 18, 2010 – 9:26 pm | One Comment
Notable changes in PCI DSS 2.0 affecting Web application security

“Clarification, additional guidance, and evolving requirements” – welcome to the new PCI standards! Hot off the press are the new PCI DSS and PA-DSS requirements which take effect January 1, 2011. So, if you work …

Application Security; Don’t get caught off guard with dangerous assumptions
November 9, 2010 – 8:56 pm | No Comment
Application Security; Don’t get caught off guard with dangerous assumptions

Don’t get caught off guard. We hear that statement all the time with regards to information security. Sadly, as many businesses have experienced, such talk is cheap. Obviously no one wants their Web site to …

Preventing phishing attacks is not just a technical issue
October 26, 2010 – 8:13 pm | No Comment
Preventing phishing attacks is not just a technical issue

A client of mine who’s a security administrator for a business in the financial industry contacted me recently about some odd behavior he was seeing on his network. Apparently numerous spidering/mirroring requests were being sent …

Internet Voting Trial Thwarted by Hackers
October 18, 2010 – 4:56 pm | No Comment
Internet Voting Trial Thwarted by Hackers

The District of Columbia recently attempted to give the opportunity to number of people who live or work overseas to be able to cast their vote remotely. To do this a secure E-Voting website costing over $300,000 was built. On Tuesday, September 28 2010 the first public trial run was launched. Thirty-six hours later the voting system was hacked by a student. It took nearly three days for D.C officials to realize that their system was compromised. The trial was immediately suspended and red-faced engineers and politicians quickly scrambled to find out how this breach could possibly have happened.

Four skills that will make you a better Web security professional
October 14, 2010 – 9:24 pm | No Comment
Four skills that will make you a better Web security professional

People who are at the top of their games such as Formula One engineers, neurosurgeons, stunt pilots and so on have one thing in common: they all have finely-tuned technical skills. This is not just …

Why all the hoopla over the Twitter onMouseOver flaw?
September 27, 2010 – 8:21 pm | One Comment
Why all the hoopla over the Twitter onMouseOver flaw?

The recent publicity and ranting about Twitter’s onMouseOver flaw* got me thinking about our perception of software quality and expectations of risk. Why is there no room for error when Twitter makes a mistake yet …

How to check if your application is vulnerable to the ASP.NET Padding Oracle Vulnerability
September 22, 2010 – 5:04 pm | 9 Comments
How to check if your application is vulnerable to the ASP.NET Padding Oracle Vulnerability

Everybody’s talking about the ASP.NET Padding Oracle vulnerability released a few days ago at the ekoparty Security Conference. However, until now there wasn’t enough information on how do you check if your application is …

Why do so many people buy into “checklist” audits?
September 20, 2010 – 9:23 pm | One Comment
Why do so many people buy into “checklist” audits?

Probably my biggest pet peeve related to application security is the claim by many (typically management) that “We know we’re secure, we just had an audit”. I can’t tell you how many times I’ve seen …