Why Would Someone Hack Your Website

by Andrew Barber 17. June 2011 11:01
There are many reasons why someone would hack your website. I list some of the most common ones here. No matter how small your website is, it has value to hackers, and its security is important! [More]

Notes on an XSRF Vulnerable Site

by Andrew Barber 13. September 2010 15:30
A discussion of an XSRF vulnerability I recently discovered which seemed, at first blush, not to exist at all. [More]

Random Stuff Learned/Remembered Lately

by Andrew Barber 4. April 2010 20:47
A few small items; Grub menu.lst AUTOMAGIC entries, Global.asax in ASP.NET and Paranoid hosts.deny doing bad things! [More]

HTTPS Web Sites: Just One Per IP?

by Andrew Barber 14. December 2009 07:06
It is commonly understood that you can only have a single HTTPS (SSL/TLS) web site per IP address. This article describes why and how you can have many SSL/TLS web sites on a single IP address, and why you might not want to do it anyway. [More]

Sometimes Standards Matter; GET and POST, and WebApp Security

by Andrew Barber 29. June 2009 12:04
A review of the security implications of using GET/Query String or POST/Forms values in a web application. [More]

Targeted SQL Injection Attacks Observed

by Andrew Barber 30. April 2009 11:42
Notes and observations about some recently observed attempts at SQL Injection attacks. [More]

Implementing Encryption in Applications

by Andrew Barber 28. March 2009 02:57
Describing some of the basics for developers who want to use encryption in their programs. [More]

Macs and Malware; Pirates and Trojans!

by Andrew Barber 27. January 2009 10:08
A reminder about personal computer security, using a Mac OSX Trojan horse as an example. [More]

When is Secure Code Not Secure Code?

by Andrew Barber 24. January 2009 15:20
Avoiding some common security software coding mistakes which arise from a mis-guided or ill-informed attempt to improve security. [More]

The Client is in the Hands of the Enemy

by Andrew Barber 17. January 2009 13:51
A couple of days ago, I put up a post about the SANS/CWE list of 2009's Top 25 Most Dangerous Programming Errors, and noted I would cover some of the items individually. Today, I will briefly cover a couple that are somewhat related, in regards to the title of this entry. What I hope to get across... [More]
Disclaimer
The opinions expressed herein are my own personal opinions and do not represent those of my partners, clients or contractors in any way.

© Copyright 2013 AndrewBarber.com