Creating a Web Application Vulnerability Management Program

Creating a Web Application Vulnerability Management Program

Continuous web application vulnerability scanning isn't a standard practice. It should be! Here are my thoughts on making it happen.

Read more »

Continuous Integration Security Testing

Continuous Integration Security Testing

A comparison of 4 free and open source web application vulnerability scanners for inclusion in a continuous integration (CI) process for automated security testing.

Read more »

PCI DSS Compliance: A High Level View

PCI DSS Compliance: A High Level View

These are my high level notes for completing a self-assessment questionnaire (SAQ) for PCI DSS compliance for an SMB. From figuring out what merchant level you are, to determining scope, to reporting your results to your acquiring bank - here's how to get it done.

Read more »

Derbycon: SQLi Presentation

Derbycon: SQLi Presentation

Here is the SQLi presentation I gave at Derbycon.

Read more »

Detecting SQL Injection Vulnerabilities

Detecting SQL Injection Vulnerabilities

How to detect SQLi vulnerabilities, examples of web application errors that indicate SQLi, and an introduction to web application vulnerability scanners.

Read more »

Where to Find Me

NoVa OWASP: April 11

By

The NoVa chapter of OWASP is meeting on 4/11. Topic: Impact of IPv6 On Your Applications.

Read more »

ISSA Meeting: February 21

By

NoVa ISSA Chapter Meeting! Topic: The Beauty of Surveillance.

Read more »

Security MBA: January 7

By

Come and enjoy some security news while drinking an icy cold refreshment.

Read more »