Web Application Security

Creating a Web Application Vulnerability Management Program

Creating a Web Application Vulnerability Management Program

Continuous web application vulnerability scanning isn't a standard practice. It should be! Here are my thoughts on making it happen.

Read more »

Continuous Integration Security Testing

Continuous Integration Security Testing

A comparison of 4 free and open source web application vulnerability scanners for inclusion in a continuous integration (CI) process for automated security testing.

Read more »

Derbycon: SQLi Presentation

Derbycon: SQLi Presentation

Here is the SQLi presentation I gave at Derbycon.

Read more »

Detecting SQL Injection Vulnerabilities

Detecting SQL Injection Vulnerabilities

How to detect SQLi vulnerabilities, examples of web application errors that indicate SQLi, and an introduction to web application vulnerability scanners.

Read more »

SQL Injection Defined

SQL Injection Defined

What SQL injection is, implications of SQLi, how prolific the issue is, and a few real world examples of SQLi attacks.

Read more »

Breaking Into Web Application Security

Breaking Into Web Application Security

A collection of resources to answer the question "how do I get into information security?"

Read more »

Web Application Security Presentation

Web Application Security Presentation

Here is the talk I gave at the Columbus OWASP chapter's last quarterly meeting.

Read more »

Detecting Cross Site Scripting Vulnerabilities

Detecting Cross Site Scripting Vulnerabilities

You can find XSS vulnerabilities in a variety of ways; including manual testing, proxying web traffic, browser extensions, and web application vulnerability scanners.

Read more »

History of Cross Site Scripting

History of Cross Site Scripting

XSS attacks were first seen almost immediately after JavaScript was released, but exploded after Samy brought down MySpace. Today, it is at the top of OWASP's list of web application security risks.

Read more »

Cross Site Scripting Defined

Cross Site Scripting Defined

What XSS is, types of XSS, how prolific the issue is, and a few real world examples of XSS attacks.

Read more »

Where to Find Me

NoVa OWASP: April 11

By

The NoVa chapter of OWASP is meeting on 4/11. Topic: Impact of IPv6 On Your Applications.

Read more »

ISSA Meeting: February 21

By

NoVa ISSA Chapter Meeting! Topic: The Beauty of Surveillance.

Read more »

Security MBA: January 7

By

Come and enjoy some security news while drinking an icy cold refreshment.

Read more »