全部
总排名: 11180
 ha.ckers.org web application security lab
Web Application Security Blog
RSS地址: http://ha.ckers.org/blog/feed/
共有3篇文章被收藏推荐
收录于2007-06-26
认领 报错 推荐
最新文章
精华文章
9位订阅者
HTTPOnly Fix In MSXML   2008-11-12 06:28
I’m happy to announce that Microsoft has released MS08-069 today. It’s got a lot of changes in it, but one in particular that I’ve been tracking for about a year now. MSXML has made a change so that HTTPOnly cookies cannot be read by XMLHTTPRequest within IE. Why is that good? It makes it so that JavaScript can no longer steal cookies that try to protect themselves. That’s a good...
Lifelock Protects You from Clickjacking   2008-11-04 07:43
Well, now I’ve seen everything. Just when I didn’t think I could ever be amazed more by attempts of overselling and snake oil, I get hit with this. Apparently Lifelock now purports to protect you from clickjacking. For those of you who don’t recall, Lifelock is the service that protects your identity, except for that one time when it doesn’t. But that’s neither here nor there and...
Security Expert Rehabilitation   2008-10-23 05:34
In light of my last gloom and doom post, I wanted to turn the tables and add some humor. A while back a bunch of us came up with the concept of a security expert rehabilitation program. Once we give up security and go back to manual labor we need to re-acclimate ourselves to the rest of society. So, in no particular order, here’s what the rehabilitation program might look like: Step 1:...
Apocalyptic Vulnerability Percentages - FUD 101   2008-10-13 04:46
I’ve spent a long time in the trenches and recently I’ve been getting more and more jaded - if that’s even possible. I’m sure at least once a week someone in the office hears me utter the nearly completely useless comment, “everything’s broken anyway, who cares?” Now I think it’s time I actually explain myself. In the last decade and a half that I’ve been in interested in...
More McAfee Snakeoil Ranting   2008-10-11 12:31
I know a lot of people are just tired of the same old PCI ASV rant that really surfaced last year, but I got an email today and I thought it was worth a re-post. Mike Bailey sent this over and I re-printed it with his permission: I’m hoping you’re interested in this, seeing as your sites were the source of a lot of the original Hacker Safe/McAfee Secure drama. Russ McRee and I have been...
收录该频道的主题秀
网络安全(542)
 鬼仔 创建于2008-01-03

鲜果日志  工具箱  帮助  | 联系我们  英雄帖   隐私保护  合作伙伴
Copyright©2004-2008 XianGuo.com 天健出品 京ICP备07018601号