Four skills that will make you a better Web security professional

Four skills that will make you a better Web security professional

People who are at the top of their games such as Formula One engineers, neurosurgeons, stunt pilots and so on have one thing in common: they all have finely-tuned technical skills. This is not just specific knowledge of what they … [+]

Why all the hoopla over the Twitter onMouseOver flaw?

Why all the hoopla over the Twitter onMouseOver flaw?

The recent publicity and ranting about Twitter’s onMouseOver flaw* got me thinking about our perception of software quality and expectations of risk. Why is there no room for error when Twitter makes a mistake yet we put up with so … [+]

How to check if your application is vulnerable to the ASP.NET Padding Oracle Vulnerability

How to check if your application is vulnerable to the ASP.NET Padding Oracle Vulnerability

Everybody’s talking about the ASP.NET Padding Oracle vulnerability released a few days ago at the ekoparty Security Conference. However, until now there wasn’t enough information on how do you check if your application is vulnerable or not. Yesterday, Duncan Smart … [+]

Why do so many people buy into "checklist" audits?

Why do so many people buy into "checklist" audits?

Probably my biggest pet peeve related to application security is the claim by many (typically management) that “We know we’re secure, we just had an audit”. I can’t tell you how many times I’ve seen this situation. Management will require … [+]

Directory Traversal in Axigen v7.4.1 running on Windows

Directory Traversal in Axigen v7.4.1 running on Windows

We are continuing with the list of security vulnerabilities found in a number of web applications while testing our latest version of Acunetix WVS v7 . In this blog post, we will look into the details of a very serious … [+]

Ways to avoid email floods when running Web vulnerability scans

Ways to avoid email floods when running Web vulnerability scans

If you’ve ever ran a Web vulnerability scan you’ve likely experienced this situation. You fire up your scanner, tweak your settings, and click Start. The next thing you know people in customer service, marketing, IT, etc. are wondering why they’re … [+]

SQL Injection and XSS vulnerabilities in CubeCart version 4.3.3

SQL Injection and XSS vulnerabilities in CubeCart version 4.3.3

We are continuing with the list of security vulnerabilities found in a number of web applications while testing our latest version of Acunetix WVS v7 . In this blog post, we will look into the details of a number of … [+]

Web Security problems in Zenphoto version 1.3

Web Security problems in Zenphoto version 1.3

We are continuing with the list of security vulnerabilities found in a number of web applications while testing our latest version of Acunetix WVS v7 . In this blog post, we will look into the details of a number of … [+]

Security vulnerabilities in Pligg CMS version 1.0.4

Security vulnerabilities in Pligg CMS version 1.0.4

While beta testing the latest version of Acunetix WVS v7, we found a large number of security vulnerabilities in various web applications. In the following days we will publish some of these vulnerabilities.  Note that we will not publish vulnerabilities … [+]

Getting developers on board with security - once and for all

Getting developers on board with security – once and for all

Making Web application security work is more than simply telling developers they need to write better code. We can scream “Write better code!” and “Integrate security into the application lifecycle!” at developers until end of time but that’s not going … [+]