Archive for December, 2007

Merry Christmas!

Merry Christmas everyone! I hope you all have a safe and happy holiday. Have fun and drink and eat well! I can’t wait to eat some real food after being away at school all semester.
Thanks for the continued support this year as we have grown to over 300 RSS subscribers, it’s been a good one. […]

Testing for randomness and predictability using Burp Sequencer

Sorry I haven’t posted in forever. Dre’s been covering for me while I’ve been super busy with finishing up school, reading, work, and other projects. I think Dre’s packed more information in the last month than I did all year. 2007 Security Testing Tools in Review alone is worth a third or fourth reading.
Anyways, here’s […]

Spread the OWASP Holiday Cheer

Linux.com is running a feature article on Building Secure Web Applications with OWASP. We’re trying to Slashdot it, so everybody who reads this — go and do that right now!
The article is good and features quotes from Josh Sweeney of SecurityDistro.com. I met Josh at the VERIFY 2007 Conference in Washington DC about […]

Cross-site scripts are the cockroaches of the Internet

I made an epic post to the LSO forums a few minutes ago. I felt the need to re-post a portion of it here. While meeting Joe earlier this evening, who is one of the founders of LearnSecurityOnline, I was inspired to think and write about XSS and a variety of other web […]

Ajax Security opens up a whole new can of worms

Update on the TS/SCI Security Blog
First of all, I would like to announce that I will be retiring the long, diluted threads that have recently appeared on the TS/SCI Security Blog. This is the last of the “longer” threads I’ve been saving up for our readers before I embark on a new journey.
What should […]