-
1
-
-
70349279698
-
-
David Airey. Google's Gmail security failure leaves my business sabotaged, December 2007. http://www. davidairey.co. uk/google-gmail-security- hij ack/.
-
David Airey. Google's Gmail security failure leaves my business sabotaged, December 2007. http://www. davidairey.co. uk/google-gmail-security- hij ack/.
-
-
-
-
2
-
-
70349281202
-
-
Robert Auger. The cross-site request forgery (CSRF/XSRF) FAQ, 2007. http: //www.cgisecurity.com/articles/csrf-faq.shtml.
-
Robert Auger. The cross-site request forgery (CSRF/XSRF) FAQ, 2007. http: //www.cgisecurity.com/articles/csrf-faq.shtml.
-
-
-
-
3
-
-
34250013678
-
A face is exposed for AOL searcher no. 4417749.
-
August
-
Michael Barbaro and Tom Zeller Jr. A face is exposed for AOL searcher no. 4417749. The New York Times, August 2006. http://www.aytimes.com/2006/ 08/09/ technology/09aol.htm.
-
(2006)
The New York Times
-
-
Barbaro, M.1
Zeller Jr., T.2
-
4
-
-
85055250091
-
-
Adam Barth, Collin Jackson, and John C. Mitchell. Securing frame communication in browsers. In In Proceedings of the 17th USENIX Security Symposium(USENIX Security 2008), July 2008.
-
Adam Barth, Collin Jackson, and John C. Mitchell. Securing frame communication in browsers. In In Proceedings of the 17th USENIX Security Symposium(USENIX Security 2008), July 2008.
-
-
-
-
6
-
-
84869623424
-
-
Douglas Crockford. JSONRequest, 2006. http://json.org/JSONRequest.html.
-
(2006)
-
-
-
8
-
-
84869619643
-
-
Rogan Dawes. Session Fixation, 2008. http://www.owasp.org/index.php/ Session-Fixation-Protection.
-
(2008)
Session Fixation
-
-
Dawes, R.1
-
12
-
-
41949093741
-
-
December 2007
-
Brad Fitzpatrick, David Recordon, Dick Hardt, Johnny Bufu, Josh Hoyt, et al. OpenlD authentication 2.0, December 2007. http://openid.net/specs/openid- authentication-2-0.html.
-
OpenlD authentication 2.0
-
-
Fitzpatrick, B.1
Recordon, D.2
Hardt, D.3
Bufu, J.4
Hoyt, J.5
-
13
-
-
85013748296
-
-
Seth Fogie, Jeremiah Grossman, Robert Hansen, Anton Rager, and Petko D. Petkov. XSS Attacks: Cross Site Scripting Exploits and Defense. Syngress, 2007.
-
Seth Fogie, Jeremiah Grossman, Robert Hansen, Anton Rager, and Petko D. Petkov. XSS Attacks: Cross Site Scripting Exploits and Defense. Syngress, 2007.
-
-
-
-
14
-
-
84869622814
-
-
Mozilla Foundation, September
-
Mozilla Foundation. Security advisory 2005-58, September 2005. http://www.mozilla.org/security/ announce/2005/mfsa2005-58.html.
-
(2005)
Security advisory
, vol.2005 -58
-
-
-
15
-
-
70349271940
-
-
Google. Security for GW'T Applications, http: //groups.google.com/group/ Google-Web-Toolkit/ web/security-for-gwt-applications.
-
Google. Security for GW'T Applications, http: //groups.google.com/group/ Google-Web-Toolkit/ web/security-for-gwt-applications.
-
-
-
-
17
-
-
84869631925
-
-
Block Referer headers in Firefox, October
-
Elliotte Rusty Harold. Privacy tip #3: Block Referer headers in Firefox, October 2006. http://cafe.elharo.com/privacy/privacy-tip-3 -block-referer- headers-in-firefox/.
-
(2006)
Privacy tip
, Issue.3
-
-
Rusty Harold, E.1
-
21
-
-
84869601207
-
-
August
-
Dan Holevoet. Changes to inline gadgets, August 2008. http://igoogledeveloper.blogspot.com/ 2008/08/changes-to-inlined-gadgets.html.
-
(2008)
Changes to inline gadgets
-
-
Holevoet, D.1
-
22
-
-
70349284230
-
Defeating frame busting techniques
-
http: //crypto. Stanford, edu/f ramebust
-
Collin Jackson. Defeating frame busting techniques, 2005. http: //crypto. Stanford, edu/f ramebust/.
-
(2005)
-
-
Jackson, C.1
-
24
-
-
48349084659
-
Protecting browsers from DNS rebinding attacks
-
November
-
Collin Jackson, Adam Barth, Andrew Bortz, Weidong Shao, and Dan Boneh. Protecting browsers from DNS rebinding attacks. In Proceedings of the 14th ACM Conference on Computer and Communications Security (CCS 2007), November 2007.
-
(2007)
Proceedings of the 14th ACM Conference on Computer and Communications Security (CCS 2007)
-
-
Jackson, C.1
Barth, A.2
Bortz, A.3
Shao, W.4
Boneh, D.5
-
31
-
-
70349276479
-
-
Amit Klein. Exploiting the XMLHttpRequest object in IE-Referrer spoofing and a lot more..., September 2005. http: //www.cgisecurity.com/lib/ XmlHTTPRequest.shtml.
-
Amit Klein. Exploiting the XMLHttpRequest object in IE-Referrer spoofing and a lot more..., September 2005. http: //www.cgisecurity.com/lib/ XmlHTTPRequest.shtml.
-
-
-
-
32
-
-
70349288883
-
-
Peter-Paul Koch. Frame busting. http://www.quirksmode.org/j s/framebust.html.
-
Peter-Paul Koch. Frame busting. http://www.quirksmode.org/j s/framebust.html.
-
-
-
-
38
-
-
70349299622
-
-
Microsoft. XDomainRequest object. http://msdn2.microsoft.com/en-us/ library/ cc288060(VS.85).aspx.
-
Microsoft. XDomainRequest object. http://msdn2.microsoft.com/en-us/ library/ cc288060(VS.85).aspx.
-
-
-
-
39
-
-
84869625969
-
-
http://wp.netscape.com/newsref/std/cookie-spec.html
-
Netscape. Persistent client state: HTTP cookies. http: //wp.netscape.com/newsref/std/cookie-spec.html.
-
Persistent client state
-
-
-
40
-
-
70349291868
-
-
Greg Pass, Abdur Chowdhury, and Cay ley Torgeson. A picture of search. In InfoScale '06: Proceedings of the 1st International Conference on Scalable Information Systems, 2006.
-
Greg Pass, Abdur Chowdhury, and Cay ley Torgeson. A picture of search. In InfoScale '06: Proceedings of the 1st International Conference on Scalable Information Systems, 2006.
-
-
-
-
42
-
-
0003533519
-
-
IETF Internet Draft. February 2008
-
Yngve Pettersen. HTTP state management mechanism v2. IETF Internet Draft. February 2008. http://www.ietf.org/internet-drafts/ draft-pettersen-cookie-v2- 02.txt,
-
HTTP state management mechanism v2
-
-
Pettersen, Y.1
-
43
-
-
70349279695
-
-
phpBB. http://phpbb.com/.
-
phpBB. http://phpbb.com/.
-
-
-
-
45
-
-
56549121497
-
-
Ruby on rails, http://www.rubyonrails.org/.
-
Ruby on rails
-
-
-
46
-
-
84869612603
-
-
September
-
Secunia. Microsoft Internet Explorer "XMLHTTP" HTTP request injection, September 2005. http://secunia.com/advisories/16942/.
-
(2005)
Microsoft Internet Explorer XMLHTTP
-
-
-
48
-
-
84869604931
-
-
Trac. http://trac.edgewall.org/.
-
Trac
-
-
-
50
-
-
70349293417
-
Nick Hopper Manuel Blum, and John Langford. CAPTCHA: Using hard AI problems for security
-
Luis von Ahn, Nick Hopper Manuel Blum, and John Langford. CAPTCHA: Using hard AI problems for security. In Eurocrypt 2003.
-
Eurocrypt 2003
-
-
Luis von Ahn1
-
51
-
-
70349290322
-
-
Weilin Zliong. Session Fixation, 2008. http: //www.owasp.org/index.php/ Session-Fixation.
-
Weilin Zliong. Session Fixation, 2008. http: //www.owasp.org/index.php/ Session-Fixation.
-
-
-
|