Review by Jason Haddix
Today we showcase a new web application scanner called Netsparker (http://www.mavitunasecurity.com/), and believe us when we say that we put this app through the ringer.
There’s a big distinction between testing a tool against dummy apps in a lab and using it first hand against a large environment. Luckily for us we got to do both.
Over the course of a month we ran several engagements and specifically watched Netsparker’s performance compared to other tools we Continue reading →
Review by Joel Dubin, CISSP
The Payment Card Industry Data Security Standard (PCI DSS) has taken it on the chin recently. With several high profile breaches of credit card numbers, some critics of the industry standard have said it either isn’t strong enough, or should be abolished altogether. But as Dr. Anton Chuvakin and Branden Williams correctly point out in the second edition of their book, PCI Compliance: Understand and Implement Effective PCI Data Security Standard Compliance (http://www.amazon.com/dp/1597494992?tag=thedigitalcon-20 Continue reading →
Way back in late 2006, when the social Web was just starting and Twitter was but a mere messaging Web site, along MyBlogLog, which gave us the concept of a social Web profile and creating a community around your Web site.
The idea was a good one, and oh so Continue reading →
Looks like someone with an Android handset visited cleverhack earlier today… Notice that Google has a special version of the search engine interface for Android (hint: click on the referrer). This seems to be the latest build of Android at 2.0.1, had no idea Google was using the AppleWebKit framework though. The screen size is also generous, too. Resolution : 854 x 480
Color Depth : 32 bits
Host: 75.209.219.99 Continue reading →
SANS Security 550 – Information Reconnaissance: Competitive Intelligence and Online Privacy (http://www.sans.org/info/51609)
A pessimistic view of the Internet: A network that enables every human to be within a few milliseconds from every psychopath and criminal on earth.
Bryce Galbraith of Layered Security (http://blog.layeredsec.com/), a SANS certified instructor, has authored a new one-day course titled “Information Reconnaissance: Competitive Intelligence and Online Privacy.” Continue reading →