• 01 Apr 2009

    WebInspect – the Mac Daddy Web app scanner?

    I've recently covered two of my favorite, yet lesser-known, Web vulnerability scanners: Acunetix Web Vulnerability Scanner and N-Stalker Web Application Security Scanner. Two worthy products indeed. Now I'd like to shed some light on HP's WebInspect. I've been using WebInspect since before testing Web sites/apps was cool. In fact, WebInspect was one the original commercial Web scanners. It may have even been the first. Anyway, I started a relationship with ...

    Continue Reading...
  • 20 Mar 2009

    My latest security content

    I've got some new information security content you may be interested in.First off, here's an article I wrote for SearchWinIT.com:Will a degree or certification help enhance your IT career?...and one I wrote for SearchEnterpriseDesktop.com:Why should Windows shops use Microsoft Baseline Security Analyzer?...and finally a webcast I just recorded for SearchSoftwareQuality.com:Essential Elements of Web Application Penetration TestingAs always, check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts ...

    Continue Reading...
  • 10 Mar 2009

    My latest security content

    I have some new information security content that you may be interested in. First, here's an article I wrote for SearchSQLServer.com:The fine line between not encrypting your databases and breach notification...and two articles I wrote for SearchSoftwareQuality.com:Using the Firefox Web Developer extension to find security flawsCloud computing and application security: Issues and risksEnjoy!Also, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and ...

    Continue Reading...
  • 10 Mar 2009

    Gem of a Web application security book

    It's three years old but Andres Andreu has put together a gem of a book on Web security testing:It covers Web apps, some commercial scanners, and practically every open source tool available for Web security testing. It also has some of the best coverage I've seen on testing Web services.Andres must've had a lot of time on his hands when he wrote it...I know firsthand how much effort it takes ...

    Continue Reading...
  • 05 Mar 2009

    Acunetix – a very good Web scanner that keeps getting better

    OK, it didn't *just* get better...it's been out for several months - but I've just now gotten a chance to really sit down with it and take it for a spin and write a post about it. I'm talking about Acunetix Web Vulnerability Scanner version 6.NOTE_BEFORE_I_BEGIN: I don't do formal "reviews" but you know how excited I get over cool tools. I found something in this one that I thought ...

    Continue Reading...
  • 19 Feb 2009

    25 Most Dangerous Programming Errors???

    Check them out here. I like the concept of the Top 25...it certainly helps spread the word...but who are they kidding when they talk about the Top 25's "major" impacts?!The site claims:*Software buyers will be able to buy much safer software.*Programmers will have tools that consistently measure the security of the software they are writing.*Colleges will be able to teach secure coding more confidently.*Employers will be able to ensure they ...

    Continue Reading...
  • 19 Feb 2009

    My latest security content

    Here's my latest stuff. First off, here are two articles I wrote for SearchEnterpriseDesktop.com:Sysinternals tools: A must-have for every Windows security toolbox...an article I wrote for SearchSoftwareQuality.com:Web application security gaps not fixed in 2008...and an article I wrote for SearchEnterpriseLinux.com:Five common Linux security vulnerabilities you may be overlookingIn the meantime, be sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcasts, webcasts, screencasts and more....

    Continue Reading...
  • 10 Feb 2009

    The ultimate irony?

    Looks like Kaspersky is the latest "victim" of a Web hack. Perhaps an example of focusing too much on one area of information security and not paying attention to the other things that matter??BTW, I just came across a site you may be interested in. It's kind of like the Privacyrights.org Chronology of Data Breaches...yet another way for us to keep up with what's going on out there - at ...

    Continue Reading...
  • 12 Jan 2009

    My latest security content

    Welcome to the first real (i.e. productive) week back in the New Year. These have been stacking up a bit while I've been out fighting this sinus junk that everyone seems to have. So here you go.First off, here's an article I wrote for SearchSoftwareQuality.com:Five predictions for Web security trends and changes for 2009And here's an article I wrote for SearchEnterpriseDesktop.com:Building credibility and getting others on your sideFinally, here's a ...

    Continue Reading...
  • 02 Dec 2008

    My latest security content

    Here's a Q&A I put together with the author of a great new book on Web security testing:Recipe for successful Web application security testingHere's a podcast I recorded for SearchEnterpriseDesktop.com:Security Policies for Windows Systems...and here's an article I was interviewed for SearchCIO-Midmarket.com that you may find interesting:SOA, SaaS and SOAP: CIOs drowning in sea of IT acronymsBe sure to check out www.principlelogic.com/resources.html for all of my information security articles, podcast ...

    Continue Reading...