english deutsch
Cross Site Scripting
'Cross-site scripting' tears holes in Ne, Apache: Cross Site Scripting Info, Bypassing Javascript Filters - The Flash Attack, CERT Advisory CA-2000-02: Malicious HTML Tags Embe, CERT/CC: How To Remove Meta-characters From User-S, CNN.com: Schwab's Site Could be Vulnerable, Cross Site Scripting Vulnerabilities, iDefense iALERT White Paper: Evolution of Cross-Si, Information on Cross-Site Scripting Security Vulne, InfoWorld Opinions: Cross-site Scripting
Are Secure Internet Transactions Really Secure?
This paper describes how many small business claim to be offering a secure order form, when in fact, they really are not. The paper shows how the insecurity occurs, and offers a few solutions to the problem.
Cgisecurity.com
This site is designed to help user to learn about what kinds of security risks exist and how to prevent them from happening.
CIAC: Unix NCSA httpd Vulnerability
An advisory detailing a vulnerability that has been discovered in the NCSA WWW server software (httpd).
Client Side Trojan
By clicking on maliciously formed HTML tags users can unknowingly perform undesirable actions.
COAST Hotlist: Security in the WWW
A collection of links related to WWW security.
Download Accessdiver
Detect security failures on any kind of web sites.
DuoWorks UK Ltd
WebAlarm anti web defacement software.
Hacking Exposed: Web Applications
Book that covers how to hack web applications, and how to secure against the attacks detailed. Author profiles, links to tools referenced in the book and reviews.
Internet Explorer Automatic Web Script Form Filler
Software for automatic security and functionality testing of web sites. Record and replay your web surfing, form filling and downloading. Supports command line options via batch files, scripts and windows task scheduler.
Microsoft TechNet Security - Web Site Security
Provides technical how to information and links to other security resources.
Northfell
Article on website hacking covering footprinting, IP scanning and an example IIS hack. Also has computer security weblog and an overview of BS7799.
Phrack: Against the System - Rise of the Robots
Michal Zalewski theorizes how Web crawlers can be exploited to inadvertently attack remote systems.
screamingCobra
Free application for remote vulnerability discovery in unknown CGI scripts. Includes mailing list, documentation, news, and source code.
Shockwave Security Alert
Lists potential privacy issues or security holes created by Shockwave and solutions for them.
The Open Web Application Security Project
How to build, design and test the security of web appplications and web services
The WWW Security FAQ
Includes securing your server, protecting confidential documents on your site, safe CGI programming, client security, and privacy.
Total Simplicity
Total Simplicity is a full on technical company providing hosting, custom programming, security, and online stores.
W3C Security Resources
Provides an overview of web security and links to security initiatives such as PICS Signed Labels, and XML-DSig.
W3Schools.com: Web Security
Covers basic privacy issues.
Web Security: A Matter of Trust
Collection of original articles.
Web Spoofing
Full text of a paper discussing an 'attack' that threatens both privacy and data integrity. Written by Edward W. Felten, Dirk Balfanz, Drew Dean, and Dan S. Wallach. Available in various formats including PDF and Postscript.
Web Workshop - Untangling Web Security
Using IIS to configure and maintain Web security.
WebAgain
Protects a web site from defacement and automatically repairs hacked pages.
World Wide Web (in)Security
Demonstrations of security risks and advice for safe use of a web browser.