Here are several new pieces I’ve written on Web site/application security. Lots of angles and considerations:
There’s more to web security than meets the eye
Web passwords are often the weakest link
To validate or not, is that the question?
Protecting FTP services running on your Web server
The critical Web-based systems that are going untested and unsecured
Good Web Security Tools and Why They Matter
Web security is like the layers of an onion
And, probably my favorite (a big, big security oversight):
You need to test your marketing site too!
You know the deal….Be sure to check out for links to all of my information security whitepapers, podcasts, webcasts, books and more.