<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Web App Security</title>
    <link>http://seclists.org/#webappsec</link>
    <atom:link href="http://seclists.org/rss/webappsec.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>Provides insights on the unique challenges which make web applications notoriously hard to secure, as well as attack methods including SQL injection, cross-site scripting (XSS), cross-site request forgery, and more.</description>
    <pubDate>Tue, 09 Mar 2010 01:00:04 GMT</pubDate>
    <lastBuildDate>Tue, 09 Mar 2010 01:00:04 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/42</link>
    <description>&lt;p&gt;Posted by Yu Qu on Mar 08&lt;/p&gt;Hi, Peine and others:&lt;br&gt;
 &lt;br&gt;
I have encountered similar problems too, my suggestion is please try to google the alphabetic strings like this: &lt;br&gt;
 &lt;br&gt;
&amp;quot;sql injection vulnerability CVE site:web.nvd.nist.gov jsp&amp;quot;&lt;br&gt;
 &lt;br&gt;
I believe that some positive results can be found. I'm also looking forward to other suggestions, thx! &lt;br&gt;
 &lt;br&gt;
Best wishes!&lt;br&gt;
 &lt;br&gt;
------------------------------------&lt;br&gt;
&lt;br&gt;
Yu Qu&lt;br&gt;
&lt;br&gt;
Ph.D. Candidate Student&lt;br&gt;
&lt;br&gt;
Ministry of Education Key Lab for Intelligent...&lt;br&gt;</description>
    <pubDate>Tue, 09 Mar 2010 00:58:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/42</guid>
  </item>


  <item>
    <title>RE: [WEB SECURITY] Re: Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/41</link>
    <description>&lt;p&gt;Posted by Calderon, Juan Carlos (GE, Corporate, consultant) on Mar 08&lt;/p&gt;Yeah, Steve's is just a nice approach, my experience is the same, you&lt;br&gt;
will hardly find a non vulnerable custom application.&lt;br&gt;
&lt;br&gt;
Besides you will improve your internal systems security, but fix them&lt;br&gt;
fast or you could suddenly have those vulnerabilities exploited in&lt;br&gt;
production and some grades changed :).&lt;br&gt;
&lt;br&gt;
Regards,&lt;br&gt;
JC &lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
From: Steve Pinkham [&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:steve.pinkham&quot;&gt;mailto:steve.pinkham&lt;/a&gt; () gmail com] &lt;br&gt;
Sent: Lunes, 08 de Marzo de 2010 12:04 p.m.&lt;br&gt;
To:...&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 23:34:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/41</guid>
  </item>
  <item>
    <title>Re: Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/40</link>
    <description>&lt;p&gt;Posted by Morgan Reed on Mar 08&lt;/p&gt;Sounds like the right approach, though I'm not aware of any Java based CMS.&lt;br&gt;
&lt;br&gt;
I'd suggest your best bet is to go trawling some of the various&lt;br&gt;
vulnerability databases around the place for a suitable candidate.&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It's Finally Here - The Cenzic Website HealthCheck. FREE.&lt;br&gt;
Request Yours Now! &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;...&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 23:28:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/40</guid>
  </item>
  <item>
    <title>Re: [WEB SECURITY] Re: Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/39</link>
    <description>&lt;p&gt;Posted by Steve Pinkham on Mar 08&lt;/p&gt;Rogan Dawes wrote:&lt;br&gt;
 &amp;gt; Unfortunately, your first requirement seems to suggest against your&lt;br&gt;
 &amp;gt; suggestion. :-)&lt;br&gt;
 &amp;gt;&lt;br&gt;
 &amp;gt; As an open source app, the student would be able to see the change logs,&lt;br&gt;
 &amp;gt; and any security announcements for the app, and would be able to make&lt;br&gt;
 &amp;gt; use of those to identify known vulnerabilities in that version of the &lt;br&gt;
app.&lt;br&gt;
 &amp;gt;&lt;br&gt;
 &amp;gt; I suggest you look for a project that may have had a history of&lt;br&gt;
 &amp;gt;...&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 23:24:32 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/39</guid>
  </item>
  <item>
    <title>Security BSides Austin - sponsors needed!</title>
    <link>http://seclists.org/webappsec/2010/q1/38</link>
    <description>&lt;p&gt;Posted by Benjamin Tomhave on Mar 08&lt;/p&gt;Hi folks,&lt;br&gt;
&lt;br&gt;
We need your help. We're still looking for sponsors for this weekend's&lt;br&gt;
Security BSides Austin, which is set to occur the same day as the&lt;br&gt;
kickoff for SxSW Interactive (a major developer conference). We have&lt;br&gt;
official sponsorship from Astaro and Panda, plus a couple unofficial&lt;br&gt;
sponsors. We'd love to see your organization involved, too! We're hoping&lt;br&gt;
for a successful inaugural event in Austin, TX, so that next year we can&lt;br&gt;
become officially...&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 23:18:10 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/38</guid>
  </item>
  <item>
    <title>Re: Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/37</link>
    <description>&lt;p&gt;Posted by Marc-André Laverdière on Mar 08&lt;/p&gt;You can have a try at Securibench. Some of the apps in there don't run without &lt;br&gt;
some serious armtwisting though, but its good enough for manual review and &lt;br&gt;
static analysis.&lt;br&gt;
&lt;br&gt;
Marc-André Laverdière&lt;br&gt;
Software Security Scientist&lt;br&gt;
Innovation Labs, Tata Consultancy Services&lt;br&gt;
Hyderabad, India&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It's Finally Here - The Cenzic Website HealthCheck....&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 23:13:24 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/37</guid>
  </item>
  <item>
    <title>Re: Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/36</link>
    <description>&lt;p&gt;Posted by Federico Maggi on Mar 08&lt;/p&gt;        OWASP's WebGoat Project has designed a non-trivial web application in Java, exactly for this purpose.&lt;br&gt;
&lt;br&gt;
Ciao,&lt;br&gt;
-- Federico&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It's Finally Here - The Cenzic Website HealthCheck. FREE.&lt;br&gt;
Request Yours Now!&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;
--------------------------------------&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 23:07:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/36</guid>
  </item>
  <item>
    <title>Re: Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/35</link>
    <description>&lt;p&gt;Posted by Kvetch on Mar 08&lt;/p&gt;Check out Daffodil CRM - &lt;a  rel=&quot;nofollow&quot; href=&quot;http://sourceforge.net/projects/daffodilcrm/&quot;&gt;http://sourceforge.net/projects/daffodilcrm/&lt;/a&gt;&lt;br&gt;
It has SQL injection, XSS and some coding opportunities.&lt;br&gt;
&lt;br&gt;
Nick Baronian&lt;br&gt;
&lt;br&gt;
This list is sponsored by Cenzic&lt;br&gt;
--------------------------------------&lt;br&gt;
Let Us Hack You. Before Hackers Do!&lt;br&gt;
It's Finally Here - The Cenzic Website HealthCheck. FREE.&lt;br&gt;
Request Yours Now!&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.cenzic.com/2009HClaunch_Securityfocus&quot;&gt;http://www.cenzic.com/2009HClaunch_Securityfocus&lt;/a&gt;&lt;br&gt;
--------------------------------------&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 23:04:36 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/35</guid>
  </item>
  <item>
    <title>Re: Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/34</link>
    <description>&lt;p&gt;Posted by Wagner Elias on Mar 08&lt;/p&gt;OWASP Broken Web App Project contains WebGoat an app vulnerable in Java.&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project#tab=Project_Details&quot;&gt;http://www.owasp.org/index.php/OWASP_Broken_Web_Applications_Project#tab=Project_Details&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Regards&lt;br&gt;
&lt;br&gt;
2010/3/8 Holger Peine &amp;lt;Holger.Peine () fh-hannover de&amp;gt;:&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 22:52:04 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/34</guid>
  </item>
  <item>
    <title>Need a real Java web application with vulnerabilities</title>
    <link>http://seclists.org/webappsec/2010/q1/33</link>
    <description>&lt;p&gt;Posted by Holger Peine on Mar 08&lt;/p&gt;Hello,&lt;br&gt;
&lt;br&gt;
I have a student who wants to perform a mostly manual security review&lt;br&gt;
of some Java web application as his master's thesis work. I am well&lt;br&gt;
aware of pedagogical, deliberately insecure applications like Webgoat&lt;br&gt;
and many others. However, we need a real application for this:&lt;br&gt;
&lt;br&gt;
- Real code, since the job should create a realistic experience for&lt;br&gt;
  the student, and the results should not be readily available&lt;br&gt;
  in advance (as with Webgoat etc.)&lt;br&gt;
&lt;br&gt;
-...&lt;br&gt;</description>
    <pubDate>Mon, 08 Mar 2010 12:40:13 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/33</guid>
  </item>


  <item>
    <title>SamuraiWTF 0.8 released</title>
    <link>http://seclists.org/webappsec/2010/q1/32</link>
    <description>&lt;p&gt;Posted by Kevin Johnson on Mar 05&lt;/p&gt;Hi all,&lt;br&gt;
&lt;br&gt;
I have just finished releasing SamuraiWTF 0.8.  It is available at &lt;a  rel=&quot;nofollow&quot; href=&quot;http://samurai.inguardians.com&quot;&gt;http://samurai.inguardians.com&lt;/a&gt; &lt;br&gt;
  and is a huge update.  It includes metasploit, target applications  &lt;br&gt;
and tons of tool updates.  It is now DVD sized as it has out grown the  &lt;br&gt;
CD release.&lt;br&gt;
&lt;br&gt;
Thank you&lt;br&gt;
Kevin Johnson and the SamuraiWTF project team&lt;br&gt;
&lt;br&gt;
Senior Security Analyst&lt;br&gt;
InGuardians, Inc.&lt;br&gt;
office: 202.448.8958&lt;br&gt;
cell: 904.403.8024&lt;br&gt;</description>
    <pubDate>Sat, 06 Mar 2010 01:09:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/32</guid>
  </item>


  <item>
    <title>removing version identifying attribution data</title>
    <link>http://seclists.org/webappsec/2010/q1/31</link>
    <description>&lt;p&gt;Posted by Robin Wood on Mar 04&lt;/p&gt;With a lot of open source web apps there is usually some kind of file&lt;br&gt;
or comment block in the code that identifies the author and gives&lt;br&gt;
attribution. The problem with most of these is that they end up&lt;br&gt;
leaking information about the version of the app being used.&lt;br&gt;
&lt;br&gt;
I'm very keen on keeping attribution in place and wouldn't want to&lt;br&gt;
release software without giving due credit but at the same time I'd&lt;br&gt;
rather not expose my clients to data leakage which I...&lt;br&gt;</description>
    <pubDate>Fri, 05 Mar 2010 01:47:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/31</guid>
  </item>


  <item>
    <title>Vulnerabilities Animated Clips</title>
    <link>http://seclists.org/webappsec/2010/q1/30</link>
    <description>&lt;p&gt;Posted by Maty Siman on Mar 03&lt;/p&gt;One of the biggest challenges of the security community is to build true&lt;br&gt;
SDLC (Secure development Life Cycle).&lt;br&gt;
The biggest obstacle is that application developers at large lack the&lt;br&gt;
know-how and motivation to address application risk.&lt;br&gt;
At Checkmarx labs we thought that a new approach to application developers&lt;br&gt;
might help them cross the barrier.&lt;br&gt;
We have developed as a pilot including two short animated clips that should&lt;br&gt;
help developers understand a...&lt;br&gt;</description>
    <pubDate>Wed, 03 Mar 2010 14:50:33 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/30</guid>
  </item>
  <item>
    <title>Advanced PHP Hacking</title>
    <link>http://seclists.org/webappsec/2010/q1/29</link>
    <description>&lt;p&gt;Posted by Laurent OUDOT at TEHTRI-Security on Mar 03&lt;/p&gt;Hi,&lt;br&gt;
&lt;br&gt;
I'd like to announce a Security Master's Dojo course during next&lt;br&gt;
CanSecWest 2010 in Vancouver (March 22-26 2010).&lt;br&gt;
&lt;br&gt;
Title: Advanced PHP Hacking (!)&lt;br&gt;
&lt;br&gt;
PHP is a worldwide web language used by individuals as well as companies&lt;br&gt;
(Facebook...). This session aims at providing a hands-on focused PHP&lt;br&gt;
Hacking experience. After this course, you will really know how&lt;br&gt;
attackers work and move through PHP hax0ring so that they can jump&lt;br&gt;
deeper down to your...&lt;br&gt;</description>
    <pubDate>Wed, 03 Mar 2010 14:42:21 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/29</guid>
  </item>


  <item>
    <title>Re: Cookie Secure Attribute - Clarification</title>
    <link>http://seclists.org/webappsec/2010/q1/28</link>
    <description>&lt;p&gt;Posted by 51l3n73y3s on Mar 01&lt;/p&gt;I would make the attribute as Secure and then also set the requireSSL of the &lt;br&gt;
form to true. In this way the server will discard it if it's over HTTP.&lt;br&gt;
&lt;br&gt;
Regards, Sandeep&lt;br&gt;
&lt;br&gt;
--------------------------------------------------&lt;br&gt;
From: &amp;quot;arvind doraiswamy&amp;quot; &amp;lt;arvind.doraiswamy () gmail com&amp;gt;&lt;br&gt;
Sent: Sunday, February 28, 2010 12:23 PM&lt;br&gt;
To: &amp;lt;webappsec () securityfocus com&amp;gt;&lt;br&gt;
Subject: Re: Cookie Secure Attribute - Clarification&lt;br&gt;
&lt;br&gt;
This list is...&lt;br&gt;</description>
    <pubDate>Tue, 02 Mar 2010 00:02:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/webappsec/2010/q1/28</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
