Home > Security Topics > Application Security > Web Security > Web Application Security (Also see Web Access Control)
Security Topics:
EMAIL THIS
 TOPICS HOME   BROWSE ALL SECURITY TOPICS   SECURITY INFO CENTERS   RESOURCE CENTERS     RSS FEEDS 

Web Application Security (Also see Web Access Control)


Browse this section for the latest news,expert advice and learning tools on Web application security, including common threats and methods for protecting against them.
IN THIS TOPIC:  NEWS (81) , EXPERT TECHNICAL ADVICE (72) , REFERENCE & LEARNING (15) , MAGAZINE CONTENT (9) , WEBCASTS (1) , DEFINITIONS (12)

MUST READ
Web Application Attacks Learning Guide
LEARNING GUIDE - This guide explains how Web application attacks occur, identifies Web application attacks, and provides Web application security tools and tactics to protect against them.

  NEWS: 1 - 3 of 81
Microsoft tools won't be quick fix for SQL injection attacks
SearchSecurity.com | 25 Jun 2008
ARTICLE - Microsoft's security advisory will help raise awareness about secure software coding, but it won't stop the onslaught of SQL injection attacks, experts say.
HP aims at IBM with application vulnerability scanning as service
SearchSecurity.com | 29 May 2008
ARTICLE - HP offers application scanning as a service to meet IBM's Watchfire AppScan OnDemand software. Interest is being driven by the growing use of Web applications.
Kaminsky on DNS rebinding attacks, hacking techniques
SearchSecurity.com | 14 May 2008
ARTICLE - Noted network security researcher Dan Kaminsky, director of penetration testing at IOActive shares his research on Web-based attack techniques.
VIEW ALL NEWS ON WEB APPLICATION SECURITY (ALSO SEE WEB ACCESS CONTROL)

  EXPERT TECHNICAL ADVICE: 1 - 3 of 72
WEB APPLICATION SECURITY (ALSO SEE WEB ACCESS CONTROL) EXPERTS
Michael Cobb
Founder and Managing Director, Cobweb Applications Ltd.
ASK A QUESTION
New defenses for automated SQL injection attacks
12 Jun 2008
TIP - By automating SQL injection attacks, hackers have found a way to expedite the process of finding and exploiting vulnerable websites. The old defenses may not be enough.
Webmail security: Best practices for data protection
Submitted By: SearchSecurity.com | 13 May 2008
TIP - Sandra Kay Miller offers webmail defense strategies that can solve authentication problems and prevent attacks involving cross-site scripting, buffer overflows and phishing.
Tracing malware's steps with RE:Trace
30 Apr 2008
TIP - In this tip, contributor Noah Schiffman gives an overview of the new RE:trace framework, and discusses how the tool can be used to discover and exploit application vulnerabilities.
VIEW ALL EXPERT TECHNICAL ADVICE ON WEB APPLICATION SECURITY (ALSO SEE WEB ACCESS CONTROL)

  REFERENCE & LEARNING: 1 - 3 of 15
Information security book excerpts and reviews
SearchSecurity.com | 22 May 2008
INFORMATION SECURITY BOOKSHELF - Visit the Information Security Bookshelf for book reviews and free chapter downloads.
Quiz: Could you detect an application attack?
SearchSecurity.com | 10 Jul 2006
SECURITY QUIZ - Test your application security awareness, review common application attacks and learn how to improve application layer logging to detect and protect against these attacks.
Information Security Quizzes
SearchSecurity.com | 26 Jun 2006
SECURITY QUIZ - Test your knowledge of everything security, from network security to regulatory compliance, with our collection of quizzes.
VIEW ALL REFERENCE & LEARNING ON WEB APPLICATION SECURITY (ALSO SEE WEB ACCESS CONTROL)

  MAGAZINE CONTENT (free subscription required): 1 - 3 of 9
Web security gateways keep Web-based malware at bay
Information Security Magazine | 01 Apr 2008
FEATURES - Web Security Gateways - A new breed of integrated technology takes Web-based malware off the menu.
Comparative Product Review: Six Web Application Firewalls
Information Security Magazine | 01 Mar 2008
FEATURES - No longer can security managers focus only on perimeter and host security. The application has become the prime target for hackers. We review six leading Web application firewalls that help deliver your critical apps ...
Internet Security
Information Security Magazine | 01 May 2007
HOT PICK & PRODUCT REVIEWS - FaceTime Communications' FaceTime Internet Security Edition
VIEW ALL MAGAZINE CONTENT ON WEB APPLICATION SECURITY (ALSO SEE WEB ACCESS CONTROL)

  WEBCASTS: 1 - 1 of 1
Simplify Your Security Decision - Vendor Webcast

VIEW WEBCAST
PREMIERED:   05 OCT 2004, 12:00 EDT (16:00, GMT)
SUMMARY:   Today's security threats are more sophisticated, frequent and dangerous than ever before. Traditional antivirus and firewall point products are no longer capable of providing adequate protection. Learn how to simplify this decision with a unified, proactive approach to internet security.
VIEW ALL WEBCASTS ON WEB APPLICATION SECURITY (ALSO SEE WEB ACCESS CONTROL)

  DEFINITIONS: 1 - 3 of 12
JavaScript hijacking
20 Jun 2007
WORD - JavaScript hijacking is a technique that an attacker can use to masquerade as a valid user and read sensitive data from a vulnerable Web application, particularly one using Ajax (Asynchronous JavaScript and XML). Nearly all ...
threat modeling
14 Feb 2006
WORD - Threat modeling is a procedure for optimizing network security by identifying objectives and vulnerabilities, and then defining countermeasures to prevent, or mitigate the effects of, threats to the system. In this context, a ...
dictionary attack
21 Apr 2005
WORD - A dictionary attack is a method of breaking into a password-protected computer or server by systematically entering every word in a dictionary as a password. A dictionary attack can also be used in an attempt to find the key ...
VIEW ALL DEFINITIONS ON WEB APPLICATION SECURITY (ALSO SEE WEB ACCESS CONTROL)

SEE ALSO - Topics Related to Web Application Security (Also see Web Access Control): 
Browser Security, Web Services Security and SOA Security, URL Filtering, Mobile Code (Active X, JavaScript), Web Server Security, SSL & TLS


TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts