HTTP Parameter Pollution - a Newer Class of Injection Attack

HTTP Parameter Pollution – a Newer Class of Injection Attack

Nowadays, many components from web applications are commonly run on the user’s computer (such as JavaScript), and not just on the application’s provider server (such as Servlets). As time goes by, there is the need for web applications to provide … [+]

A complete guide to securing a website

A complete guide to securing a website

To secure a website or a web application, one has to first understand the target application, how it works and the scope behind it.  Ideally, the penetration tester should have some basic knowledge of programming and scripting languages, and also … [+]

Web Application Firewalls do not replace secure development and operation of web applications

In eval($WAF); whitepaper, L. Nothdurfter, W.Neudorfer and M. Kirchner from the University of Applied Sciences Upper Austria, explain in detail how they evaluated the capabilities of some leading WAF’s (web application firewalls), and concluded that although a WAF can raise … [+]

Why File Upload Forms are a major security threat

File upload forms, nowadays can be found allover the internet.  In social network web applications, such as Facebook and Twitter, in blogs, forums, e-banking sites, YouTube and also in corporate support portals, to give the opportunity to the end user … [+]

Finding the right web application scanner; why black box scanning is not enough

This white paper shows how Acunetix AcuSensor Technology increases accuracy by combining black box scanning techniques with feedback from sensors placed inside the source code while the source code is executed. Thanks to this innovative technology there are many advantages … [+]

Web Services – The technology and its security concerns

This white paper examines the technology behind Web Services, how the system is made available to the user, and the way connections are made to back-end (and therefore sensitive) data. These different elements come together to make Web Services a … [+]

Acunetix Publishes PCI Compliance Guide

Acunetix Publishes PCI Compliance Guide

The paper aims to help companies meet impending PCI requirements London, UK – May 30, 2007 – Businesses that rely on payment by credit cards are required to comply with the PCI security standards by September 2007. Non compliance could result … [+]

The Payment Card Industry Compliance

Securing both Merchant and Customer data This white paper introduces the Payment Card Industry Compliance standard, and the security threats which brought about the need to standardize the data protection of both merchants and customers. The internet is no longer … [+]

Are AJAX applications vulnerable to Hack Attacks?

This paper reviews AJAX technologies with specific reference to JavaScript and Ajax Security.  It briefly documents the kinds of vulnerability classes that should raise security concerns among developers, website owners and the respective visitors. The proposed solution suggests auditing AJAX … [+]

Audit your Website security with Acunetix Web Vulnerability Scanner

A practical “how to” using Acunetix Web Vulnerability Scanner – Auditing the security of your website with Acunetix WVS is easy. Acunetix WVS performs most of the steps in an automated manner and therefore giving you a good idea of … [+]