-
1
-
-
77955219882
-
-
[Online]. Available: http://blogs.zdnet.com/security/?p=3514
-
StrongWebmail CEO's mail account hacked via XSS. ZDNet. [Online]. Available: http://blogs.zdnet.com/security/?p=3514
-
StrongWebmail CEO's Mail Account Hacked Via XSS
-
-
-
4
-
-
77955206201
-
-
Payment Card Industry Security Standards Council. [Online]. Available
-
Approved Scanning Vendors. Payment Card Industry Security Standards Council. [Online]. Available: https://www.pcisecuritystandards.org/pdfs/asv report.html
-
Approved Scanning Vendors
-
-
-
5
-
-
77955223656
-
-
[Online]. Available
-
VUPEN Security. [Online]. Available: http://www.vupen.com
-
-
-
-
6
-
-
77955211998
-
-
Dept. of Homeland Security National Cyber Security Division. [Online]. Available
-
National Vulnerability Database. Dept. of Homeland Security National Cyber Security Division. [Online]. Available:http://web.nvd.nist.gov
-
-
-
-
8
-
-
84873832099
-
-
[Online]. Available
-
Web Application Security Scanner Evaluation Criteria. Web Application Security Consortium. [Online]. Available: http://projects.webappsec.org/Web- Application-Security-Scanner-Evaluation-Criteria
-
Web Application Security Consortium
-
-
-
9
-
-
77955205925
-
-
[Online]. Available
-
OWASP Top Ten Project. Open Web Application Security Project. [Online]. Available: http://www.owasp.org/index.php/Category:OWASP-Top-Ten-Project
-
Open Web Application Security Project
-
-
-
10
-
-
84873832099
-
-
[Online]. Available
-
Web Security Threat Classification. Web Application Security Consortium. [Online]. Available: http://www.webappsec.org/projects/threat/
-
Web Application Security Consortium
-
-
-
11
-
-
77955199688
-
-
[Online]. Available
-
Common Weakness Enumeration. [Online]. Available: http://cwe.mitre.org
-
-
-
-
12
-
-
74249123619
-
Xcs: Cross channel scripting and its impact on web applications
-
New York, NY, USA: ACM
-
H. Bojinov, E. Bursztein, and D. Boneh, "Xcs: cross channel scripting and its impact on web applications," in CCS '09:Proceedings of the 16th ACM conference on Computer and communications security. New York, NY, USA: ACM, 2009, pp. 420-431.
-
(2009)
CCS '09:Proceedings of the 16th ACM Conference on Computer and Communications Security
, pp. 420-431
-
-
Bojinov, H.1
Bursztein, E.2
Boneh, D.3
-
13
-
-
77955178987
-
-
[Online]. Available
-
Common Vulnerabilities and Exposures. [Online]. Available: http://cve.mitre.org
-
-
-
-
14
-
-
77955208377
-
Black ops of PKI
-
August
-
D. Kaminsky, "Black Ops of PKI," BlackHat USA, August 2009.
-
(2009)
BlackHat USA
-
-
Kaminsky, D.1
-
15
-
-
78649901040
-
More tricks for defeating SSL
-
August
-
M. Marlinspike, "More Tricks For Defeating SSL," BlackHat USA, August 2009.
-
(2009)
BlackHat USA
-
-
Marlinspike, M.1
-
16
-
-
85027442855
-
Our favorite XSS filters and how to attack them
-
August
-
E. V. Nava and D. Lindsay, "Our Favorite XSS Filters and How to Attack Them," BlackHat USA, August 2009.
-
(2009)
BlackHat USA
-
-
Nava, E.V.1
Lindsay, D.2
-
17
-
-
77955199184
-
-
[Online]. Available
-
Open Web Application Security Project. [Online]. Available: http://www.owasp.org
-
-
-
-
18
-
-
77955216234
-
-
[Online]. Available
-
Web Application Security Consortium. [Online]. Available: http://www.wasc.org
-
-
-
-
19
-
-
84873832099
-
-
[Online]. Available
-
Web Application Security Statistics. Web Application Security Consortium. [Online]. Available: http://projects.webappsec.org/Web-Application-Security- Statistics
-
Web Application Security Consortium
-
-
-
20
-
-
35449004893
-
Sound and precise analysis of web applications for injection vulnerabilities
-
G. Wassermann and Z. Su, "Sound and precise analysis of web applications for injection vulnerabilities," SIGPLAN Not., vol. 42, no. 6, pp. 32-41, 2007.
-
(2007)
SIGPLAN Not
, vol.42
, Issue.6
, pp. 32-41
-
-
Wassermann, G.1
Su, Z.2
-
21
-
-
77950880816
-
Securing web applications with static and dynamic information flow tracking
-
New York, NY, USA: ACM
-
M. S. Lam, M. Martin, B. Livshits, and J. Whaley, "Securing web applications with static and dynamic information flow tracking," in PEPM '08: Proceedings of the 2008 ACM SIGPLAN symposium on Partial evaluation and semantics-based program manipulation. New York, NY, USA: ACM, 2008, pp. 3-12.
-
(2008)
PEPM '08: Proceedings of the 2008 ACM SIGPLAN Symposium on Partial Evaluation and Semantics-based Program Manipulation
, pp. 3-12
-
-
Lam, M.S.1
Martin, M.2
Livshits, B.3
Whaley, J.4
-
22
-
-
77949879017
-
Automatic creation of SQL injection and cross-site scripting attacks
-
Vancouver, BC, Canada, May 20-22
-
A. Kiėzun, P. J. Guo, K. Jayaraman, and M. D. Ernst, "Automatic creation of SQL injection and cross-site scripting attacks," in ICSE'09, Proceedings of the 30th International Conference on Software Engineering, Vancouver, BC, Canada, May 20-22, 2009.
-
(2009)
ICSE'09, Proceedings of the 30th International Conference on Software Engineering
-
-
Kiezun, A.1
Guo, P.J.2
Jayaraman, K.3
Ernst, M.D.4
-
23
-
-
33751027156
-
Pixy: A static analysis tool for detecting web application vulnerabilities (short paper)
-
[Online]. Available
-
N. Jovanovic, C. Kruegel, and E. Kirda, "Pixy: A static analysis tool for detecting web application vulnerabilities (short paper)," in 2006 IEEE Symposium on Security and Privacy, 2006, pp. 258-263. [Online]. Available: http://www.iseclab.org/papers/pixy.pdf
-
(2006)
2006 IEEE Symposium on Security and Privacy
, pp. 258-263
-
-
Jovanovic, N.1
Kruegel, C.2
Kirda, E.3
-
24
-
-
19944365247
-
Securing web application code by static analysis and runtime protection
-
New York, NY, USA: ACM
-
Y.-W. Huang, F. Yu, C. Hang, C.-H. Tsai, D.-T. Lee, and S.-Y. Kuo, "Securing web application code by static analysis and runtime protection," in WWW '04: Proceedings of the 13th international conference on World Wide Web. New York, NY, USA: ACM, 2004, pp. 40-52.
-
(2004)
WWW '04: Proceedings of the 13th International Conference on World Wide Web
, pp. 40-52
-
-
Huang, Y.-W.1
Yu, F.2
Hang, C.3
Tsai, C.-H.4
Lee, D.-T.5
Kuo, S.-Y.6
-
25
-
-
34250673645
-
Secubat: A web vulnerability scanner
-
S. Kals, E. Kirda, C. Kruegel, and N. Jovanovic, "Secubat: a web vulnerability scanner," in WWW '06: Proc. 15th Int'l Conf. World Wide Web, 2006, pp. 247-256.
-
(2006)
WWW '06: Proc. 15th Int'l Conf. World Wide Web
, pp. 247-256
-
-
Kals, S.1
Kirda, E.2
Kruegel, C.3
Jovanovic, N.4
-
26
-
-
56549119554
-
Leveraging user interactions for in-depth testing of web applications
-
S. Mcallister, E. Kirda, and C. Kruegel, "Leveraging user interactions for in-depth testing of web applications," in RAID '08: Proc. 11th Int'l Symp. Recent Advances in Intrusion Detection, 2008, pp. 191-210.
-
(2008)
RAID '08: Proc. 11th Int'l Symp. Recent Advances in Intrusion Detection
, pp. 191-210
-
-
Mcallister, S.1
Kirda, E.2
Kruegel, C.3
-
27
-
-
76649142367
-
Protecting a moving target: Addressing web application concept drift
-
F. Maggi, W. K. Robertson, C. Kr̈ugel, and G. Vigna, "Protecting a moving target: Addressing web application concept drift," in RAID, 2009, pp. 21-40.
-
(2009)
RAID
, pp. 21-40
-
-
Maggi, F.1
Robertson, W.K.2
Kr̈ugel, C.3
Vigna, G.4
-
29
-
-
77955214170
-
-
[Online]. Available
-
Powerfuzzer. [Online]. Available: http://www.powerfuzzer.com/
-
-
-
-
30
-
-
77955208628
-
-
[Online]. Available
-
CIRT.net Nikto Scanner. [Online]. Available: http://cirt.net/nikto2
-
-
-
-
31
-
-
77955213907
-
-
[Online]. Available
-
WebGoat Project. OWASP. [Online]. Available: http://www.owasp.org/index. php/Category:OWASP-WebGoat-Project
-
-
-
-
32
-
-
77955190033
-
-
McAfee Corp. [Online]. Available
-
HacmeBank. McAfee Corp. [Online]. Available: http://www.foundstone.com/ us/resources/proddesc/hacmebank.htm
-
-
-
-
33
-
-
77955179762
-
-
AltoroMutual Bank. Watchfire Corp. [Online]. Available
-
AltoroMutual Bank. Watchfire Corp. [Online]. Available:http://demo. testfire.net/
-
-
-
-
34
-
-
77955218299
-
-
[Online]. Available
-
Larry Suto. Analyzing the Accuracy and Time Costs of Web Application Security Scanners. [Online]. Available: http://ha.ckers.org/files/Accuracy-and- Time-Costs-of-Web-App-Scanners.pdf
-
-
-
Suto, L.1
-
35
-
-
50049110333
-
Testing and comparing web vulnerability scanning tools for sql injection and xss attacks
-
vol. 0
-
J. Fonseca, M. Vieira, and H. Madeira, "Testing and comparing web vulnerability scanning tools for sql injection and xss attacks," Pacific Rim Int'l Symp. Dependable Computing, IEEE, vol. 0, pp. 365-372, 2007.
-
(2007)
Pacific Rim Int'l Symp. Dependable Computing, IEEE
, pp. 365-372
-
-
Fonseca, J.1
Vieira, M.2
Madeira, H.3
|