Aleksei Tiurin, June 2018 – At ZeroNights 2017 conference, Security Researcher Aleksei Tiurin spoke about “Deserialization vulnerabilities in various languages”. For his presentation, he used an interesting article about two serialization packages of Node.js. Aleksei showed them as examples of vulnerable implementations of the deserialization processes. In this article, he shows the results of his own research and a new approach of attacking deserialization in JS.
Matt Conran, March 2018 – With the arrival of new General Data Protection Regulation (GDPR) legislation, security professionals must become data-centric. As a result, they no longer rely on traditional practices to monitor and protect data along with the web applications that act as a front door to the user’s personal data. As on May 25, 2018, the European Union’s (EU’s) GDPR will come into play. A single supervisory authority will be used, rather than a separate one for each EU member state. It will provide a well-needed framework that will govern the way the personal data is gathered, stored and used.
Agathoklis Promodou, January 2018 – In this mini guide, author Agathoklis Promodou looks the world’s most popular (Server-side) Web Programming Language – PHP. Like other programming languages, PHP can be exposed to a number of vulnerabilities – this mini guide examines some of the problems that should be considered every time you set out to write a PHP script so you can ensure your site is secure. These are the problems which, with well-written code, can be effectively mitigated.
Rafay Baloch, January 2018 – In this white paper, author Rafay Baloch looks at various forms of Domain Fronting along with a few other techniques that can be utilized for circumventing firewalls, Deep Packet Inspection devices and captive portals. He dissects a well-known internet censorship bypass known as PSIPHON and demonstrates how it utilizes Domain Fronting for bypassing Captive Portals.
Acunetix, March 2017 – In this white paper, we focus on two widely known and used protocols in computer security, SSL and TLS. We describe what is TLS/SSL, take a brief look at its history, describe some of the terminology, explain TLS/SSL certificates and their use, we look at establishing an SSL connection and look at possible TLS/SSL vulnerabilities and attacks.
Acunetix, July 2016 – In this white paper, we will focus on how to create a more secure environment for MySQL server, which is currently the second most popular database management system (DBMS), in order to prevent common attacks, as well as to mitigate the attack vector of other vulnerabilities. For the purposes of this article we have setup a machine running Ubuntu 16.04 LTS (Xenial Xerus) and MySQL 5.7. We have also edited our hosts file to point ‘example.com’ to the IP address of our test machine.
Acunetix, July 2016 – A web-shell is a malicious script used by an attacker with the intent to escalate and maintain persistent access on an already compromised web application. In this White Paper, we look at common functions used to execute shell commands in PHP, possible tricks attackers can use to keep web shells under-the-radar, and tips on detection and prevention.
Acunetix, February 2016 – Drupal is a very popular Content Management System (CMS) on the Internet today. Drupal sites, especially ones running older versions of the CMS or it’s modules are a ripe target for attackers. In this White Paper, we detail a few measures which can be taken to address the basic security holes or malpractices that are commonly present in thousands of Drupal sites.
Acunetix, February 2016 – Joomla! sites, especially ones running older versions of the CMS or it’s modules are a ripe target for attackers. In this White Paper, we detail a few measures which can be taken to address the basic security holes or malpractices that are commonly present in thousands of Joomla! web applications.
Acunetix, January 2016 – Defence in depth is a principle of adding security in layers in order to increase the security posture of a system as a whole. In other words, if an attack causes one security mechanism to fail, the other measures in place take arms to further deter and even prevent an attack.
Acunetix, February 2015 – WordPress sites are notoriously lacking when it comes to security. Be it due to an insufficient security expertise of the developer, or the use of one of the many plugins available (of which the security cannot be guaranteed). This White paper gives top tips on how to keep the WordPress application secure.
Acunetix, December 2014 – If you’re a healthcare entity in the United States, then you’ll certainly be familiar with HIPAA. This Whitepaper deals with the most important aspects for healthcare providers, insurers and other health related entities – keeping patient information secure and to know when, how much and with who the information can be shared.
Acunetix, January 2010 – In this white paper we explain in detail how to do a complete website security audit and focus on using the right approach and tools. We describe the whole process of securing a website in an easy to read step by step format; what needs to be done prior to launching an automated website vulnerability scan up till the manual penetration testing phase.
Acunetix, November 2014 – This white paper details the Payment Card Industry (PCI) compliance standard and the security threats which brought about the need to standardize the protection of customer credit card data.
Acunetix, May 2009 – This white paper shows how and why the widely used file upload forms are a major security threat. It also states some recommendations on how to securely code such file upload forms, and how these can be checked with Acunetix web vulnerability scanner for vulnerabilities.
Acunetix, September 2008 – This white paper shows how Acunetix AcuSensor Technology increases accuracy by combining black box scanning techniques with feedback from sensors placed inside the source code while the source code is executed.
Acunetix, October 2007 – This white paper examines the technology behind Web Services, how the system is made available to the user, and the way connections are made to back-end (and therefore sensitive) data. These different elements come together to make Web Services a portal for users to access data, but also provide different entry points which may be exploited for illegitimate purposes.
Acunetix, May 2007 – This white paper explains the Payment Card Industry Compliance standard in real detail, and the security threats which brought about the need to standardize the data protection of both merchants and customers.