Secure Upload Methods in PHP
Here’s how to deal with file upload attacks against sites developed in PHP, and how to write more secure code to prevent these attacks. In most Web applications, developers provide upload file functionality…
Securing Apache, Part 4: Cross-site Tracing (XST) & Cross-site History Manipulation (XSHM)
This series of articles addresses the Web security concerns of information security experts, systems administrators and all those who want to jump-start their careers in this domain. This time we will delve deeper…
App Inventor: Develop Android Apps in a Jiffy
Here’s introducing Google’s new App Inventor service (the beta version) to design graphic applications for the Android platform. The Android in question is 1.5 Cupcake, running on an Openmoko FreeRunner GTA02, though you…
Securing Apache, Part 3: Cross-Site Request Forgery Attacks (XSRF)
Intended for information security experts, systems administrators, and all those concerned about Web security, this third article in the series moves on from SQL injection and XSS to how to secure Web applications…
BackTrack 4: A One-Stop Shop for Security Analysis and Learning
Computer security analysts have plenty of tools available nowadays to evaluate the security of corporate networks, servers and applications. These include Linux distributions specialising in security assessment, system recovery and digital forensic investigations….
Securing Apache, Part 2: XSS Injections
In the previous article in this series, we started our journey to a secured Apache by dissecting its internals. We then looked at various attacks against Web applications via injection flaws, beginning with…
Automate Testing Web Apps with WebTest
WebTest lets developers write XML-based test suites so quickly, it’s almost fun! Virtually everyone uses a browser every time the computer is switched on — the browser has become an integral part of…
Website Vulnerabilities and Nikto
Nikto is an open source Web server vulnerability scanner that performs comprehensive tests for over 6,100 potentially dangerous files/CGIs, checks for outdated versions of over 950 servers, and for version-specific problems on over…





