ðòïåëôù 


  áòèé÷ 


Apache-Talk @lexa.ru 

Inet-Admins @info.east.ru 

Filmscanners @halftone.co.uk 

Security-alerts @yandex-team.ru 

nginx-ru @sysoev.ru 

  óôáôøé 


  ðåòóïîáìøîïå 


  ðòïçòáííù 



ðéûéôå
ðéóøíá














     áòèé÷ :: Security-alerts
Security-Alerts mailing list archive (security-alerts@yandex-team.ru)

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[security-alerts] FYI: Know your Enemy: Web Application Threats



> -----Original Message-----
> From: full-disclosure-bounces@xxxxxxxxxxxxxxxxx 
> [mailto:full-disclosure-bounces@xxxxxxxxxxxxxxxxx] On Behalf 
> Of Gadi Evron
> Sent: Sunday, February 25, 2007 11:29 AM
> To: bugtraq@xxxxxxxxxxxxxxxxx
> Cc: php-wars@xxxxxxxxxxxxxxxxxxxxxx; full-disclosure@xxxxxxxxxxxxxxxxx
> Subject: [Full-disclosure] Know your Enemy: Web Application Threats
> 
> Jamie Riden, Ryan McGeehan, Brian Engert and Michael Mueter 
> just released
> an Honeynet paper on Web security called: Know your Enemy: Web
> Application Threats
> 
> You can find their paper here:
> http://honeynet.org/papers/webapp/
> 
> The paper is very good, and deals with all kinds of web 
> threats such as
> SQL Injection and XSS. Of most interest to me were the Code 
> Injection and
> Remote Code-Inclusion due to my own research in that field.
> The Honeynet paper deals with many issues other than these, and
> is most definitely recommended reading.
> 
> Jamie Riden has written a paper on web honey pots in the 
> past. These guys
> know what they are talking about.
> 
>       Gadi.
> 
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
> 



 




Copyright © Lexa Software, 1996-2009.