- The WWW Security FAQ - http://www.w3.org/Security/Faq/
Includes securing your server, protecting confidential documents on your site, safe CGI programming, client security, and privacy.
- Are Secure Internet Transactions Really Secure? - http://www.jsweb.net/paper.htm
This paper describes how many small business claim to be offering a secure order form, when in fact, they really are not. The paper shows how the insecurity occurs, and offers a few solutions to the problem.
- Cgisecurity.com - http://www.cgisecurity.com/
This site is designed to help user to learn about what kinds of security risks exist and how to prevent them from happening.
- Client Side Trojan - http://www.zope.org/Members/jim/ZopeSecurity/ClientSideTrojan
By clicking on maliciously formed HTML tags users can unknowingly perform undesirable actions.
- CIAC: Unix NCSA httpd Vulnerability - http://www.ciac.org/ciac/bulletins/f-11.shtml
An advisory detailing a vulnerability that has been discovered in the NCSA WWW server software (httpd).
- Download Accessdiver - http://www.accessdiver.com
Detect security failures on any kind of web sites.
- Shockwave Security Alert - http://www.webcomics.com/shockwave/
Lists potential privacy issues or security holes created by Shockwave and solutions for them.
- W3C Security Resources - http://www.w3.org/Security/
Provides an overview of web security and links to security initiatives such as PICS Signed Labels, and XML-DSig.
- World Wide Web (in)Security - http://www.swcp.com/~mccurley/danger/danger.html
Demonstrations of security risks and advice for safe use of a web browser.
- Total Simplicity - http://www.totalsimplicity.com
Total Simplicity is a full on technical company providing hosting, custom programming, security, and online stores.
- DuoWorks UK Ltd - http://www.duoworks.com
WebAlarm anti web defacement software.
- Web Spoofing - http://www.cs.princeton.edu/sip/WebSpoofing/
Full text of a paper discussing an 'attack' that threatens both privacy and data integrity. Written by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach. Available in various formats including PDF and Postscript.
- Internet Explorer Automatic Web Script Form Filler - http://www.internetmacro.com
Software for automatic security and functionality testing of web sites. Record and replay your web surfing, form filling and downloading. Supports command line options via batch files, scripts and windows task scheduler.
- screamingCobra - http://cobra.LucidX.com/
Free application for remote vulnerability discovery in unknown CGI scripts. Includes mailing list, documentation, news, and source code.
- WebAgain - http://www.lockstep.com/products/webagain/wa-product.html
Protects a web site from defacement and automatically repairs hacked pages.
- Northfell - http://www.northfell.com/
Article on website hacking covering footprinting, IP scanning and an example IIS hack. Also has computer security weblog and an overview of BS7799.
- Hacking Exposed: Web Applications - http://www.webhackingexposed.com/
Book that covers how to hack web applications, and how to secure against the attacks detailed. Author profiles, links to tools referenced in the book and reviews.
|