| Home Page |
|||||
Somnath Guha Neogi - ArticlesSecure use of cookiesTo understand the importance of cookies it is imperative to understand what they are primarily used for .Cookies do not act maliciously on your computer systems. They are merely text files that can be deleted at any time - they are not plug ins nor are they programs. Cookies cannot be used to spread viruses and they cannot access your hard drive. This does not mean that cookies are not relevant to a user's privacy and anonymity on the Internet. Importance of Penetration testing in achieving PCI DSS compliancePenetration testing is addressed by PCI DSS Requirement 11.3 and is significantly different from the PCI DSS Requirement 11.2 which addresses internal and external Vulnerability Assessment. Difference between safe and unsafe check plugins in NessusTo perform a security assessment without causing any harm to the production environment,we need to have a clear understandings of the difference between 'Safe' and 'Unsafe' checks.This article describes the differences between 'Safe' and 'Unsafe' check plugins for the most popular vulnerability scanner Nessus. Web 2.0 Security Testing ApproachWeb 2.0 can be defined as the evolving trend of www technologies and web design that aim to enhance creativity, communications, secure information sharing, collaboration and functionality of the web1. 0. In contrast to the static nature of Web 1.0, Web 2.0 systems rely heavily upon user generated content. In fact, Web 2.0 has been described as the “participatory Web.” For example blogs and photo sharing services enable consumers to add and update their own content. Secure ASP.NET coding practice for three most critical vulnerabilities in Web ApplicationASP.NET provides several exciting security controls, but these need to be understood properly and used wisely. Failing to use the ASP.NET functions properly results in an insecure web application. We see therefore that ASP.NET does not exempt the programmer from following coding standards and procedures in order to write safe and secure application code. Seceurity Testing For Online Tour & Travel WebsitesThis article will try to cast your attention towards how we test online tour and travel sites in iViZ. Here in iViZ we emphasize more on finding out new classes of business logic vulnerabilities which would directly bring in huge financial loss or impersonation of users for an organization. Here in iViZ we developed a customize framework which is in itself quite exceptional from the traditional Web Application Security testing approaches.
|
|||||
|
Article Categories
|
|
||||
|
|
|||||