» tagged pages
» logout

sorted by: recent | see : popular
Content Tagged with Microsoft + Security

JSON Hijacking and How ASP.NET AJAX 1.0 Avoids these Attacks - ScottGu's Blog

Recently some reports have been issued by security researchers describing ways hackers can use the JSON wire format used by most popular AJAX frameworks to try and exploit cross domain scripts within browsers. Specifically, these attacks use HTTP GET requests invoked via an HTML <script src=""> include element to circumvent the "same origin policy" enforced by browsers (which limits JavaScript objects like XmlHttpRequest to only calling URLs on the same domain that the page was loaded from), and then look for ways to exploit the JSON payload content.

json: del.icio.us/tag/json

DNS Vulnerability Now in the Wild

Dan Kaminsky's upcoming Black Hat preso on the recently discovered DNS cache posioning vulnerability has just been upstaged by its release into the wild.

technology: dzone.com: tech links

Understanding the Web browser threat by Stefan Frei

Addressing the issues of the lack of up-to-date browser usage on PCs

Firefox: del.icio.us/tag/firefox

Free Download: SQL Injection Code Analyzer

Microsoft has just released a free utility to help developers analyze ASP code for SQL Injection vulnerabilities. Earlier this year, several public sites went down when hackers unleashed a series of bots to find and exploit servers where developers did not correctly code their applications/pages to prevent SQL Injection attacks.

technology: dzone.com: tech links

CNET News.com, 06.07.2008: Still more reasons to avoid Internet Explorer - Defensive Computing

by Michael Horowitz: A few recent stories highlighted a bedrock of Defensive Computing - if you surf the web on a Windows computer, you are safer using Firefox as opposed to Internet Explorer.

Firefox: del.icio.us/tag/firefox

Microsoft Security Advisory Alert: SQL Injection Attacks

Microsoft is aware of a recent escalation in a class of attacks targeting Web sites that use Microsoft ASP and ASP.NET technologies but do not follow best practices for secure Web application development. These SQL injection attacks do not exploit a specific software vulnerability, but instead target Web sites that do not follow secure coding practices for accessing and manipulating data stored in a relational database.

technology: dzone.com: tech links

Troubleshooting Kerberos Errors

This white paper can help you troubleshoot Kerberos authentication problems that might occur in a Microsoft Windows Server 2003 operating system environment&lt;sep/&gt;

kerberos: del.icio.us/tag/Kerberos

6 free security tools you shouldn't live without

Six free security tools that all IT folks should know about and use.

technology: dzone.com: tech links

Page 1 | Next >>